Sections

Commentary

Podcast

Building resilience in concentrated cyber ecosystems | The TechTank Podcast

Stephanie K. Pell, Diana L. Burley, and
Diana L. Burley Senior Vice President of Research
Rhea Siers
Rhea Siers Cyber Risk Adviser and Former Senior Intelligence Official

August 17, 2026


  • Cyber risk in an interconnected environment is increasingly complex for organizations to assess and address.
  • Navigating such challenges elevates the question of vendor concentration, which can introduce certain risks but also provide important strengths.
Elise Racine & Digit / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/
Elise Racine & Digit / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/

TechTank, a biweekly podcast from the Center for Technology Innovation at Brookings, explores today’s most consequential technology issues. Moderators Nicol Turner Lee and Darrell West speak with experts and policymakers to share data, ideas, and policy solutions that address the challenges of our digital world.

Cyber risk in an interconnected environment is increasingly complex for organizations to assess and address. Strategic choices can shape both cybersecurity risk and resilience. The question of vendor concentration—an organization’s reliance on a single supplier or platform—is part of the risk calculus.  

While vendor concentration can present certain risks, it can also deliver strength through unified controls and coordinated defense. A recent paper, informed by discussions with senior leaders immersed in cybersecurity risk management with both public and private sector experience, argues that resilience, which “treats concentration and diversity as strategic levers, backed by redundancy, contingency, and fast recovery,” should be an organization’s guiding objective. 

In this episode of the TechTank podcast, guest host and Brookings fellow Stephanie Pell is joined by the paper’s coauthors, Diana Burley, senior vice president of research at Brookings, and Rhea Siers, a cyber risk adviser and former senior intelligence official, to discuss their findings along with the implications of their research in an artificial intelligence (AI)-enabled risk environment. 

Listen to the episode and subscribe to the TechTank Podcast on Apple, Spotify, or Acast 

Transcript

[00:00:00] CO-HOST NICOL TURNER LEE: You’re listening to TechTank, a biweekly podcast from the Brookings Institution exploring the most consequential technology issues of our time. From racial bias in algorithms to the future of work, TechTank takes big ideas and makes them accessible.

 

[00:00:25] GUEST HOST STEPHANIE PELL: Welcome to the Tech Tank Podcast. I’m guest host Stephanie Pell, a fellow in Governance Studies at The Brookings Institution. Assessing and addressing cyber risk in an interconnected environment is increasingly complex for organizations big and small. As digital ecosystems and supply chains expand, strategic choices can shape both cybersecurity risk and resilience across an enterprise. The question of vendor concentration, that is, how reliance on a single supplier or platform might shape risk and resilience, is often raised, especially because organizations often lack visibility into how cyber threats or failures might propagate. Today, I’m joined by Diana Burley, senior vice president of research here at Brookings. Prior to coming to Brookings, Diana was vice provost for research and innovation at American University, where she also led the Khan Cyber and Economic Security Institute and served as a member of the faculty. I am also joined by Diana’s co-author, Rhea Siers, who has 30 years of operational, legal, and policy experience in the U.S. intelligence community, is an advisor on cyber risks and threats, and is a member of the adjunct faculties at George Washington University and Johns Hopkins University. They’re here to discuss a paper they published at the end of last year titled “Resilience Rules: Securing the Enterprise in Concentrated Systems.” Welcome, Diana and Rhea, and thank you for joining me.

 

[00:02:14] GUEST RHEA SIERS: Thank you for having us.

 

[00:02:14] GUEST DIANA BURLEY: Thank you.

 

[00:02:16] GUEST HOST STEPHANIE PELL: To start off, can you talk about some of the real-world scenarios that organizations face and how such scenarios and the attendant cyber risks lead us into a discussion of vendor concentration and resilience?

 

[00:02:34] GUEST DIANA BURLEY: I’ll start off, and then I will turn it over to Rhea. When we first think about real-world scenarios, we’re thinking about how organizations are functioning in these highly dense and opaque supply chain environments where security risk is heavily interconnected. You can’t really think about an organization in isolation because all of the connections between the organizations matter for how they are able to secure the products and services that they are providing. And so when we think about c- vendor concentration, we think about the fact that up and down the supply chain, the different companies are all using the same software applications, corporate applications, cloud providers, service providers, and so therefore they become vulnerable to an attack on, that particular vendor. It impacts all of the different in, organizations throughout the supply chain, and that’s what makes, the risk amplified when we talk about concentrated environments.

 

[00:03:44] GUEST RHEA SIERS: And I really wanna emphasize this because I think we almost see this as a critical law of cyber physics. Reducing the risk for one party usually relocates it rather than removes it. And it often gets pushed downstream to smaller suppliers who simply can’t handle the load. But in terms of what we saw of examples raised by our subjects, we saw a continuing drumbeat of pressure to meet financial constraints, operational pressures, and oversight and governance concerns. when something does go wrong, when there is a serious incident, there is sometimes a problem organizationally when there is no technically some backup when you are dependent on a specific operating system or a specific piece of software, and this really, aggravates the situation as well.

 

[00:04:42] GUEST HOST STEPHANIE PELL: So you referenced your subjects or participants. I wanna turn specifically to your research paper and, have you talk about the particular research questions you were grappling with, how your research proceeded, and who your study participants were. What kinds of organizations or companies did they represent?

 

[00:05:08] GUEST RHEA SIERS: So I’ll discuss the research question a bit and the methodology and the participants. The purpose was not the standard kind of dry theoretical trade-offs between concentration and diversification. The focus of the research question and the interviews we did was really how senior enterprise leaders actually manage and engage risk on the ground when it comes to concentration. So in terms of the methodology, we used a two-part integrative approach, which involved a structured literature review, and then was followed by targeted focus groups and interviews. we kept the framework for those interviews around six core operational dimensions, and these really are the dimensions and issues that organizations and leaders weigh when they think about concentration and diversity. And they include operational overhead, business continuity, economic and societal factors, user experience, workforce readiness, and global strategic risk. In terms of the demographics of the group we engaged, we focused on 15 elite senior professionals. It’d be chief information security officers, chief technology officers, managing directors, program leaders. And all of them spanned cross-sector environments, which would include government, finance, technology, cloud services, education, and law.

 

[00:06:44] GUEST DIANA BURLEY: I would just add in terms of the professionals that we engaged in this study, they were also, multinational. We had most of our participants had experience working, within the, the United States and abroad, either because they worked at companies based in, in, outside of the United States or because they worked with na- multinational companies that, had experience across borders. And because they were senior professionals, they also all had experience in multiple sectors, even within the United States. They had worked in policy, in, within government, and within the private sector. So they really brought a, a very large range of experiences, to bring to bear to the study.

 

[00:07:35] GUEST HOST STEPHANIE PELL: And what were some of the key themes and challenges that you heard from your study participants?

 

[00:07:42] GUEST DIANA BURLEY: I’ll start with some of the key themes and, challenges. One was a visibility gap. the participants talked about the fact that there are blind spots in their ability to look down the supply chain and understand the amount of exposure the systems really have to vulnerabilities and to, to cyber attacks. As one of our study participants put it, “I have no way of knowing my impact radius.” They really, especially as they get to the third and fourth order, parts of the supply chain, they could not see, where their vulnerabilities lie. They also talked about the illusion of simplification, and this is while even when you’re thinking about flattening the vendor stack and recognizing that when you flatten that vendor stack in terms of concentration, it does bring you some short-term relief. That simplification often abstracts away and obscures critical underlying system complexities. And so this really goes to the notion that Rhea talked about just a few moments ago, where you’re pushing risk downstream, you’re not necessarily getting rid of it. And I’ll say a third, a third challenge that our participants really focused on was that there’s an incomplete metric. Concentration is an important and a critical facet of risk, but it is an incomplete proxy for it. And so understanding that measuring vendor counts alone does not show you the true nature of your operational exposure, certainly doesn’t give you a sense of the exposure that goes beyond your, beyond your borders and down your supply chain. And so they really talked about the fact that it is very difficult to understand just how much vulnerability actually exists in your tech stack

 

[00:09:38] GUEST RHEA SIERS: And I’ll dig a little deeper on all those points Diana made. I’ll start with the simplification and consolidation advantages. the simplification drives concentration, so obviously allows for unified control, centralized dashboard, automated threat intel sharing, and streamlined patch management and oversight. Diana also alluded to the supply chain danger, so we’re not just talking first tier here. The- there are significant vulnerabilities on the fourth- and fifth-party relationships which are, which the people we interviewed recognized, very clearly. There’s also something called the Frankenstein effect, which is over-diversification, it essentially backfires. If there’s an uncoordinated multi-vendor patch, it creates an operational mess with inconsistent security protocols and massive configuration gaps, and this is often seen when there is a serious incident of some sort. It does not have to be a concentration risk type of incident. It can be any type of cyber incident and I do think that our subjects really believe that resilience is the key principle here, and we can talk more about that later. And the other area that I think both Diana and I have seen a lot of is the impact on the workforce. Now, a lot of people discuss the impact on the workforce these days concerning AI, but let’s talk about it in terms of concentration. The pro, the positive of it, is that concentrating the tech stack narrows the scope of tech training that’s required. It allows your staff to build deeper expertise in a single ecosystem. That can be very effective and important. The other side of that, of course, the con, is that organizations become entirely dependent on occasion on outsourced vendor knowledge, and you can see how that could lead to problems down the road. So that would be the deeper dive in some of the things that we heard from those that we interviewed.

 

[00:11:49] GUEST HOST STEPHANIE PELL: So I wanna dig a little bit deeper then on this idea of resilience as a principle that seemed to emerge as one of the core findings of the paper. Can you talk a little bit more about that?

 

[00:12:04] GUEST RHEA SIERS: I think that there is somewhat of a knee-jerk reaction, not just in terms of concentration, but in all response to incidents where, there’s a view that you have to, immediately solve the problem and, kinda move on. There’s never this precursor, or there often is not a precursor of looking where the potential risk is, addressing that risk ahead of time, and matching the technical, the cyber risk, both to compliance issues and of course to business issues, continuity of business. That’s the piece of resilience that we hear most often from cyber professionals that is the most important for them, and frankly, the most complex to dig into and to, to be able to even, include in your governance and your procedures.

 

[00:12:58] GUEST DIANA BURLEY: Yeah, if I can follow on that, because I, think it’s really important to emphasize that when we’re talking about cyber risk, we are talking about a single facet of business risk. And so when you talk about concentration, and you think about it only from a cyber risk perspective, it doesn’t allow you to really think through what will make your company or your enterprise resilient across all of the different facets of risk that you face. And so as we began to, unbundle this very complex, tapestry of challenges, of risk, what our participants just talked about over and over again were the trade-offs that are made when you make different decisions. And that’s how we ended up getting to this idea of risk of, resilience as a, as the core principle. Because as you continue to move down the discussion of the various types of risks and the various types of trade-offs that need to be made, you realize that there is no silver bullet. There is no one way that is the best way. It really becomes a question of balancing and ensuring that depending on the specific details of your situation, and the environment, and the supply chain, and the products, and the training, and all of these different factors, putting them together in a way that allows your enterprise to recover from challenges and to continue moving forward is really the name of the game.

 

[00:14:41] GUEST HOST STEPHANIE PELL: To that point, this notion of simplification and consolidation advantages, how s- how did you find that organizations were seeking simplification and consolidation, but addressing the risks inherent in, moving in those sorts of directions?

 

[00:15:09] GUEST RHEA SIERS: I somewhat relate to this as kind of organizations or a- or even federal agencies choosing vendor consolidation as a practical prerequisite, not just for simplification, but for compliance. And so if you think about things like identity and access management, there are multiple syst- systems, there are, federal network directives on zero trust and, similar conditional access. When you would try to achieve that across, legacy vendors, across, really across the, the globe, it’s operationally impossible. So that’s where simplification, as an example, I would say, comes in, and was one of the things that was shared with U.S. pretty, pretty often, actually.

 

[00:16:00] GUEST DIANA BURLEY: I would say one thing too that we haven’t talked about yet, but that certainly came up in the study and, in, in the months since, and that is the notion of digital sovereignty, and recognizing that simplification is not just about the system per se or the technical infrastructure of the system. It’s also about understanding how the use of the technology relates to the political environment, the global political environment, and, the, the laws and regulations that sit within individual countries. And so that is a component of simplification as well that has to be considered when you’re thinking through the questions of resilience.

 

[00:16:45] GUEST RHEA SIERS: And there’s a great example of this going on right now, that we discussed and d- as we did our after discussions on the study with the round table and others, we talked about France, and specifically its perception that it is, that it has concentration risk due to the fact that I think U.S. big tech controls about 65% of Europe’s, cloud market, for example. And so France has increasingly mandated these local alternatives, replacing all kinds of tools like Teams and Zoom. And the question is, what is the impact of that going to be on, on concentration risk? And it’s, of course, impossible to know that at the moment, but I think there are a couple things we need to study and watch. There are a couple things they’re doing, like they’re migrating, this massive health data hub, from Microsoft to, I think it’s Iliad. I think it’s called Scaleway. and there are severe internal concentration risks when you have this kind of internal by French mandate. There’s a domestic monopoly trap, highly consolidated, so a single physical attack, fire, cyberattack, operational outage could paralyze in public services. And then there’s the issue that we continue to worry about across the cyber’s, arena, and that’s the innovation and capacity gap. And so that’s another thing we need, to consider when we start looking at the digital sovereignty issue as well

 

[00:18:33] GUEST DIANA BURLEY: And just one more aspect of that, and that is the global supply chain. Because while we have talked about the supply chain and the fact that even when we’re not thinking about the global supply chain specifically, we’re saying our participants were saying they already had no idea what their impact radius was. It’s not clear that they can get visibility into the, the third, fourth, or fifth level down. So you can imagine that in a situation like in France, I can imagine that even as they, mandate that they have to use technologies and, products that are made in France, that is at the top level. What happens when you start moving down the supply chain and deal with the questions around interoperability? And so that’s also another, another opportunity for this Frankenstein effect to occur, unwittingly. And when you think that you are reducing risk in one area, you end up really, creating additional risk and, hurting your enterprise

 

[00:19:48] GUEST HOST STEPHANIE PELL: So not to add yet another facet to this risk discussion, but as you reflect on your discussions with participants about the risks and benefits of vendor concentration, how do you think AI impacts risk calculations for organizations?

 

[00:20:08] GUEST RHEA SIERS: Oh, I’ll start on that. so it, it shifts the core, obviously. AI removes traditional layered tech stacks, so there’s an immense concentration dependency on just a few shared foundational architectures and core hosting platforms. what we heard from leaders we spoke to was that they were very concerned about AI products escaping chain of custody scrutiny. That’s not what Claude was per se, but I’m gonna use it as an example in just a second. so the underlying foundational model for AI might be vetted. the commercial products that are built on top of them com- really completely lack visibility and data governance. So a single flaw in a frontier model, the cutting-edge model, could cause immediate cascading failures globally. So I just wanna differentiate because, there’s been a lot of talk the last few weeks about the Claude containment incidents. they were operational and what are called harness failures. So there was a breakdown in the surrounding software infrastructure to restrict it, including boundaries, and thus it escaped. This is an inherent governance issue as well as an operational issue, and it is related to concentration risk as well.

 

[00:21:39] GUEST DIANA BURLEY: And I want to… I wanna take us back maybe 10 years because whenever a new technology, emerging tech comes out, we, address the challenges as if they’re brand-new challenges. And in fact, you think about the internet, and you think about the, the, Apple platform and the Android platform and the Google s- platform and the stores and whether, the apps that were available within the stores had been properly vetted and, whether they were introducing vulnerabilities onto the platforms, and that’s really what we’re dealing with again, in this AI space. And so as Rhea said, even if the foundational model has been vetted, that doesn’t mean that the commercial products that you’re using have been. And so it just adds another layer of complexity, that we need to really think through as we begin to use these tools even more, on the data, the proprietary data often that we have within our pr- enterprises.

 

[00:22:41] GUEST RHEA SIERS: And, what’s the pragmatic fix? Of course, that’s the most difficult question, and we talked about this with, those we interviewed and with folks who’ve reviewed the study. and I’m an attorney, so I will say that one of the things has to be building explicit contractual terms that cover, regular model audits and data portability, but we just haven’t really settled, not just in AI but across the cyber arena, on what that constitutes. And for example, if we want strict end-to-end chain of custody tracking for all AI-enabled vendor products, how are we gonna do that? And, I think, actually Diana can, talk a little bit about what we already have in term of frameworks, but this is the ongoing question of industry standards over mandates.

 

[00:23:39] GUEST DIANA BURLEY: Yeah, and I, think it too, it also reflects the question that many of our participants, laid out, which, what are the metrics? How are we really looking at this? How are we measuring risk? And, if we focus on this question around industry standards, we can begin to think through some of the best practice frameworks, like NIST, like ISO. But the, real issue is, who is putting those standards forward? Are these industry-led standards? Are these government mandates? If they’re government mandates, are they by country or is this some type of international body? And, I can tell you that the individuals, who participated in our round table, who were very much like the participants, in terms of background, those that we interviewed in our study, certainly preferred the idea of industry-led standards. That, the individuals who really understand the technology and understand what it will take to, to reign in, the kind of behavior that, that we need to think critically about are the ones who come together and put these standards in place.

 

[00:24:55] GUEST RHEA SIERS: And let me, I, I think I mentioned it at the top of this that, there were a couple of recent events that are examples of this, and the suspension of DOD’s, CMMC requirements, the, cybersecurity maturity model certification. And so this is supposed to apply to all mandatory third-party audits. Yes, it’s amazing I remembered what that acronym stand- stood for. this is about compliance though and, not standards. And, reducing risk, as I said before, sometimes relocates it instead of removed it. And if we wanna do this effectively, we have to do both together. And we have to decide when we’re gonna do it, and we don’t have the luxury of time. we don’t have it at all, especially when we’re talking about some of the AI effects.

 

[00:25:51] GUEST HOST STEPHANIE PELL: So understanding that we don’t have the luxury of time, what is your actionable advice for organizations today?

 

[00:26:02] GUEST DIANA BURLEY: The first thing that, that I think came through both the roundtable and the study was that organizations should not fight concentration. It’s not a question of concentration being good or bad, it’s really about resilience. And so you don’t want to avoid vendor concentration for the sake of avoidance, but you want to make sure that you are engineering adaptive defenses around it so that you are thinking critically about all of the facets of enterprise risk, not just those that happen to, to come along with a particular type of, vendor.

 

[00:26:44] GUEST RHEA SIERS: And I would say that one of the fundamental takeaways from the study that bears on this that people should keep in mind is it’s kind of a paradox. concentration obviously can amplify catastrophic systemic risk, but it’s the only way to build real defensive strength. And so you have to balance those two. And you… Diana and I have done a lot of work, I would say, on a multidisciplinary level, and I find myself going back to that, even about concentration risk. As I, I think I said before, it’s not just about governance, it’s not just about operations, it’s about, business operation, business preparedness, and the ability to exist in, in, in this arena. And we don’t, always do it that way, and that’s understandable, because sometimes we’re dealing just with incidents. But it’s not a holistic approach, and the holistic approach doesn’t just ap- apply to cyber concentration risk, obviously. It applies across all cybersecurity. And this is just another example and another wake-up call to why we need this kind of approach.

 

[00:27:56] GUEST HOST STEPHANIE PELL: So Diana and Rhea, as, as we finish up for today, do you have any closing thoughts or ideas that you’d like to share?

 

[00:28:05] GUEST DIANA BURLEY: First, thank you for giving us this platform. We are very excited to be able to share this work. It was, a, a long time coming and putting this study together. And I will say that, outside of what we have talked about in terms of managing, risk and thinking about resilience, I also wanna add in that as we think about supply chains and we think about the breadth of organizations that are in these supply chains and we look at very large organizations to very small ones, that is something that we have to keep in mind as we begin to look at questions around, resiliency and questions around concentration. Because as we add more regulation, as we add more requirements for, these organizations, it, just becomes, a challenge to ensure that at each level of institution, at each level of the supply chain, that we’re effectively able to navigate, to navigate all of those questions. And so re- remember that resilience is not just about a single entity, but it’s really about an entire market, even beyond, a, an individual supply chain.

 

[00:29:26] GUEST RHEA SIERS: And I would add that I think one of the things that was very apparent to me during the interviews was the thoughtfulness of these leaders in cyber about this issue. They’ve lived it, they’ve done it, but they’re also trying to think their way through it. And, I’ve been in both the public and private sector environments, and I understand that some of the issues that have been raised here, have got to be addressed from all angles.

[00:29:58] And when we talk to the experts about it, they have some great views. For example, the issue of, regulations ver- versus standards, that we need to take the time to further listen to and perhaps to assist in the formulation of those thoughts.

 

[00:30:15] GUEST HOST STEPHANIE PELL: Diana and Rhea, thank you for joining me today. It was really interesting to hear about your research that involved actual discussions with, Rhea, as you said it, people who are living these issues and having to make decisions on a daily basis. You can learn more about this topic by reading Diana and Rhea’s paper, “Resilience Rules: Securing the Enterprise in Concentrated Ecosystems”, which is available at TechTank on the Brookings site, accessible at brookings.edu. Please explore more in-depth content on tech policy issues at TechTank, also accessible at brookings.edu. This concludes another episode of the TechTank podcast. Thank you for listening.

 

[00:31:08] CO-HOST NICOL TURNER LEE: Thank you for listening to TechTank, a series of roundtable discussions and interviews with technology experts and policymakers. For more conversations like this, subscribe to the podcast and sign up to receive the TechTank newsletter for more research and analysis from the Center for Technology Innovation at Brookings.

Participants

The Brookings Institution is committed to quality, independence, and impact.
We are supported by a diverse array of funders. In line with our values and policies, each Brookings publication represents the sole views of its author(s).