Global supply chains have never been so interconnected, or so vulnerable. Geopolitical tensions, cyberattacks, climate-related disruptions, economic volatility and logistics interruptions can halt the supply of finished products, semi-finished goods or critical raw materials, generate unexpected costs and damage corporate reputation within a matter of days. In this environment, pursuing efficiency at all costs is no longer sustainable without an equally strong focus on resilience.
The latest data confirms the severity of the situation: supply chain attacks have more than doubled over the past year, with global losses reaching tens of billions of dollars. A significant percentage of organisations have experienced at least one security incident linked to a third-party supplier or a component within their supply chain. Vendors, service providers and cloud platforms are no longer simply business partners: they are extensions of an organisation’s attack surface.
Beyond Document-Based Due Diligence
The traditional supplier risk management model—based on periodic questionnaires, certifications and annual audits—has proven structurally inadequate in the face of rapidly evolving threats. Document-based due diligence provides a static snapshot of an environment that changes in real time: a supplier may be fully compliant at the time of an audit and find itself facing financial instability, conflicts of interest or a cyber compromise just a few weeks later.
More mature organisations are therefore moving towards a continuous monitoring model that integrates multiple sources of information: real-time geopolitical and security alerts, weather and environmental risk data, cyber threat intelligence, and reporting on regulatory, sanctions and legislative developments.
This approach requires not only appropriate technological tools, but above all analytical expertise capable of transforming a continuous flow of information into prioritised, actionable insights.
Concentration Risk and Hidden Dependencies
The consolidation of the technology market—particularly across cloud services, AI and fintech infrastructure—around a limited number of global providers is creating significant concentration risks. When a small number of providers support a large number of organisations, a single upstream incident can have systemic downstream consequences.
Organisations therefore need to map not only their direct suppliers, but also second- and third-tier dependencies that may introduce otherwise invisible vulnerabilities.
The rapid adoption of artificial intelligence adds another layer of complexity. AI model supply chains, the provenance of training data and embedded decision-making engines are creating a new class of third-party dependencies that few organisations have yet begun to assess systematically.
The Evolving Regulatory Landscape
2026 marks the convergence of several regulatory developments that are elevating supply chain security from an operational best practice to a compliance requirement.
Regulation (EU) 2022/2554, commonly known as DORA (Digital Operational Resilience Act), is entering its second year of full application across the European financial sector, with growing expectations regarding the oversight of critical third-party providers. Regulators across multiple jurisdictions are also intensifying their scrutiny of supply chain compliance in relation to human rights, sustainability and transparency. One example is Directive (EU) 2024/1760, commonly referred to as the CSDDD or CS3D (Corporate Sustainability Due Diligence Directive), despite its implementation having been postponed to 2029.
For Italian and European companies, supply chain risk management is therefore no longer confined to procurement or IT. It has become a board-level responsibility spanning governance, compliance, risk management and corporate strategy.
Building an Intelligence-Led Supply Chain
An effective Supply Chain Security programme is built around several key principles: comprehensive visibility across the supplier ecosystem, with suppliers segmented according to their operational criticality; risk-based due diligence combining document verification with open-source intelligence and continuous reputational monitoring; rapid-response mechanisms capable of isolating a compromised supplier within a timeframe consistent with the speed at which threats can propagate; and exit planning, supported by tested contingency plans for every critical supplier.
Integrating OSINT into supplier risk management provides a significant advantage. The ability to identify weak signals—such as a supplier’s emerging financial instability, changes in its ownership structure, exposure to sanctions, presence in compromised datasets, or activism and protests affecting production areas—allows organisations to anticipate crises rather than simply react to them.
How Kriptia Can Help
Kriptia provides organisations with its established expertise in counterparty analysis and due diligence across 192 countries worldwide, offering a Continuous Supplier Intelligence service that goes beyond traditional document-based verification.
Through advanced OSINT methodologies, proprietary digital platforms and a global network of analysts, Kriptia conducts in-depth reputational screening and continuously monitors risk indicators affecting critical suppliers—from financial instability and sanctions exposure to geopolitical risk and cyber compromise.
The resulting actionable intelligence reports feed directly into the decision-making processes of procurement, compliance and risk management teams.





















































