• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to primary sidebar
  • Skip to footer

Before Header

Bryghtpath

Business Continuity and Crisis Management Consultants

  • About
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity Software
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises & Simulations
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Coaching
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
        • Resilience as a Service
          • Business Continuity as a Service (BCaaS)
        • Case Studies & Results
        • Industries
  • Insights
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • Book – From Panic to Poise: Crisis Management in the Modern World
          • Book – The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • About
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity Software
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises & Simulations
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Resilience as a Service
      • Business Continuity as a Service (BCaaS)
    • Other Capabilities
      • Coaching
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
    • Case Studies & Results
    • Industries
  • Insights
  • Products
    • Books
      • Book – From Panic to Poise: Crisis Management in the Modern World
      • Book – The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

Third Party Exercises

You are here: Home / Capabilities / Crisis Exercises & Simulations / Third Party Exercises

Your biggest single point of failure
doesn’t work for you.

Exercise it anyway.

Somewhere in your vendor list is a dependency your business cannot survive losing: a BPO processing your transactions, a platform running your operations, a supplier nobody can replace in a quarter.

A third-party exercise puts that dependency to the test, jointly with the vendor in the room, or from your side alone, with an independent read on how they would actually perform.

Almost nobody else offers this. We have done it.

  • Joint exercises with your critical vendors, facilitated by an independent third party: us
  • BPO failure, vendor software compromise, logistics disruption, and sole-source supplier loss
  • An honest evaluation of the vendor’s response, not their marketing

Schedule an Initial Consultation

Read the Joint Exercise Case Study

What We Hear

“Our vendor swears they have a plan. We’ve never seen it work.”

“If that BPO goes down, half our operation goes with it. Their SOC 2 doesn’t tell me what happens at hour six.”

“Contract says they’ll notify us in 24 hours. In their last incident, we found out from a customer.”

“Third-party risk sends questionnaires. Nobody has ever tested the actual relationship.”

Composite statements from real client and prospect conversations. Questionnaires and attestations measure paperwork.

An exercise measures what happens when your incident becomes their incident, and the seam between two companies takes the strain.

Two Ways to Run It

  • The joint exercise. Your team and the vendor’s team in the same scenario, facilitated by us as the independent party. Tests notification timelines, escalation between companies, joint decision-making, and who tells the customer. Both sides get findings; you also get our independent read on how the vendor performed. Few vendors are ever asked. The strong ones say yes.
  • The dependency exercise. Your team alone, against the loss or compromise of a critical third party. Tests your detection of vendor failure, workarounds, contractual levers, alternate suppliers, and customer communications when the cause isn’t yours but the impact is.

Scenarios

  • Business process outsourcing failure: your BPO stops processing, mid-cycle
  • Vendor software or firmware compromise moving into your environment
  • Third-party data breach with your customers’ data in it
  • Logistics or sole-source supplier disruption
  • The AI-era version: a vendor’s exposure in an AI-accelerated vulnerability storm (links AI spoke)

Built from your actual vendor map and contracts, not a generic supply chain story.

Browse the Scenario Library

When Organizations Call Us

  • Third-party risk has matured past questionnaires and wants evidence
  • A vendor’s incident just became your incident, and the seams showed
  • A regulator, auditor, or enterprise customer is asking how you test critical dependencies
  • Concentration risk landed on the board agenda
  • A strategic partnership is deep enough that both sides want to rehearse together

2

companies in one exercise: yours and your critical vendor’s, with independent facilitation

40+

after-action recommendations adopted by a single client

4–6 wks

from kickoff to both teams in the exercise

TechnologyShared Risk, Shared Response: Enhancing Crisis Coordination with a Strategic Third PartyA joint crisis and continuity exercise put a company and its primary service provider in the same scenario, with an independent evaluation of how the vendor performed.Read the case study →TechnologyFrom Disruption to Action: Preparing a Technology Firm’s C-Suite for CrisesA C-Suite exercise built around a major vendor disruption tested the decisions leadership faces when the failure isn’t yours but the impact is.Read the case study →Healthcare TechnologyFaster Than the Patch: Preparing a Healthcare Technology Company for AI-Accelerated ThreatsThe vendor surface was one of three fronts in this AI-accelerated vulnerability storm exercise: third parties and firmware the client had zero patch control over.Read the case study →
Explore Our Case Studies

What You Get

  • A scenario built from your actual vendor map, contracts, and notification requirements
  • Independent facilitation both companies can trust
  • Findings for your side, and in joint exercises, an independent evaluation of the vendor’s response
  • After-action report with prioritized recommendations, including contract and SLA gaps the exercise exposed
  • Evidence for regulators, auditors, and customers that you test your critical dependencies

Frequently Asked Questions

How do we get a vendor to participate in a joint exercise?

Usually through the relationship owner and the contract. Strong vendors say yes because it deepens the partnership and they get findings too. We help you frame the invitation, and independent facilitation makes it safe for both sides.

What does a third-party exercise cost?

Dependency exercises run from the facilitated tabletop tier, starting at $25,000. Joint exercises with a vendor are scoped after a consultation, driven by the number of teams, companies, and scenario complexity.

Will the vendor see our findings?

No. Your findings are yours. In a joint exercise each company receives its own report, and you additionally receive our independent evaluation of the vendor’s response. What is shared between companies is agreed before design starts.

Can we exercise a vendor dependency without the vendor?

Yes. The dependency exercise runs your team alone against the loss or compromise of a critical third party: workarounds, contractual levers, alternate suppliers, and customer communications. No vendor participation required.

Does this satisfy third-party risk management requirements?

It strengthens them. Regulators and enterprise customers increasingly want evidence that critical dependencies are tested, not just assessed. The after-action report documents the test, the findings, and the fixes, including contract and SLA gaps the exercise exposed.

Which vendor should we exercise first?

The one whose failure you cannot work around: a BPO processing core transactions, a platform running operations, or a sole-source supplier. If concentration risk is on your board agenda, start there. We help you pick in the first conversation.


The dependency you can’t survive losing deserves more than a questionnaire.

Fifteen minutes with a practitioner gets you a straight answer
on which vendor to exercise first and how to bring them to the table.

Schedule an Initial Consultation

Explore Business Continuity Exercises

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Exercises & Simulations
  • Crisis Management
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Resilience as a Service
    • Business Continuity as a Service (BCaaS)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model®
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.