Your biggest single point of failure
doesn’t work for you.
Exercise it anyway.
Somewhere in your vendor list is a dependency your business cannot survive losing: a BPO processing your transactions, a platform running your operations, a supplier nobody can replace in a quarter.
A third-party exercise puts that dependency to the test, jointly with the vendor in the room, or from your side alone, with an independent read on how they would actually perform.
Almost nobody else offers this. We have done it.
- Joint exercises with your critical vendors, facilitated by an independent third party: us
- BPO failure, vendor software compromise, logistics disruption, and sole-source supplier loss
- An honest evaluation of the vendor’s response, not their marketing
What We Hear
“Our vendor swears they have a plan. We’ve never seen it work.”
“If that BPO goes down, half our operation goes with it. Their SOC 2 doesn’t tell me what happens at hour six.”
“Contract says they’ll notify us in 24 hours. In their last incident, we found out from a customer.”
“Third-party risk sends questionnaires. Nobody has ever tested the actual relationship.”
Composite statements from real client and prospect conversations. Questionnaires and attestations measure paperwork.
An exercise measures what happens when your incident becomes their incident, and the seam between two companies takes the strain.
Two Ways to Run It
- The joint exercise. Your team and the vendor’s team in the same scenario, facilitated by us as the independent party. Tests notification timelines, escalation between companies, joint decision-making, and who tells the customer. Both sides get findings; you also get our independent read on how the vendor performed. Few vendors are ever asked. The strong ones say yes.
- The dependency exercise. Your team alone, against the loss or compromise of a critical third party. Tests your detection of vendor failure, workarounds, contractual levers, alternate suppliers, and customer communications when the cause isn’t yours but the impact is.
Scenarios
- Business process outsourcing failure: your BPO stops processing, mid-cycle
- Vendor software or firmware compromise moving into your environment
- Third-party data breach with your customers’ data in it
- Logistics or sole-source supplier disruption
- The AI-era version: a vendor’s exposure in an AI-accelerated vulnerability storm (links AI spoke)
Built from your actual vendor map and contracts, not a generic supply chain story.
When Organizations Call Us
- Third-party risk has matured past questionnaires and wants evidence
- A vendor’s incident just became your incident, and the seams showed
- A regulator, auditor, or enterprise customer is asking how you test critical dependencies
- Concentration risk landed on the board agenda
- A strategic partnership is deep enough that both sides want to rehearse together
2
companies in one exercise: yours and your critical vendor’s, with independent facilitation
40+
after-action recommendations adopted by a single client
4–6 wks
from kickoff to both teams in the exercise
What You Get
- A scenario built from your actual vendor map, contracts, and notification requirements
- Independent facilitation both companies can trust
- Findings for your side, and in joint exercises, an independent evaluation of the vendor’s response
- After-action report with prioritized recommendations, including contract and SLA gaps the exercise exposed
- Evidence for regulators, auditors, and customers that you test your critical dependencies
Frequently Asked Questions
How do we get a vendor to participate in a joint exercise?
Usually through the relationship owner and the contract. Strong vendors say yes because it deepens the partnership and they get findings too. We help you frame the invitation, and independent facilitation makes it safe for both sides.
What does a third-party exercise cost?
Dependency exercises run from the facilitated tabletop tier, starting at $25,000. Joint exercises with a vendor are scoped after a consultation, driven by the number of teams, companies, and scenario complexity.
Will the vendor see our findings?
No. Your findings are yours. In a joint exercise each company receives its own report, and you additionally receive our independent evaluation of the vendor’s response. What is shared between companies is agreed before design starts.
Can we exercise a vendor dependency without the vendor?
Yes. The dependency exercise runs your team alone against the loss or compromise of a critical third party: workarounds, contractual levers, alternate suppliers, and customer communications. No vendor participation required.
Does this satisfy third-party risk management requirements?
It strengthens them. Regulators and enterprise customers increasingly want evidence that critical dependencies are tested, not just assessed. The after-action report documents the test, the findings, and the fixes, including contract and SLA gaps the exercise exposed.
Which vendor should we exercise first?
The one whose failure you cannot work around: a BPO processing core transactions, a platform running operations, or a sole-source supplier. If concentration risk is on your board agenda, start there. We help you pick in the first conversation.
The dependency you can’t survive losing deserves more than a questionnaire.
Fifteen minutes with a practitioner gets you a straight answer
on which vendor to exercise first and how to bring them to the table.

