The board asks whether the company has a backup supplier. You say yes. Procurement has negotiated another contract, finance has opened another vendor account, and the resilience slide now contains two logos. Everyone has done something measurable. Nobody has yet asked the driver which bridge he uses.
That is the problem with counting suppliers as proof of supply chain resilience. A second company may protect you from the first company's insolvency or production failure. If both deliveries require the same transport corridor, a closure can interrupt both. The paperwork diversified faster than the goods.
For a founder, this becomes a governance question surprisingly quickly. Who has to discover the shared dependency? Who pays to reduce it? And who can approve the expensive workaround while the normal route is unavailable? The last question deserves an answer before someone starts a group chat called “urgent alignment”.
What the Kyiv attacks actually disrupted
On October 3, 2026, AP reported that Russian attacks had killed at least six people across Ukraine and damaged Kyiv's Northern Bridge. Earlier assaults had forced full or partial closures of three of the capital's six road bridges over the Dnipro. The six deaths were reported across Ukraine, not as a death toll from the bridge strike.AP
Kyiv's official updates give the operational detail. At 7:39 a.m., the city reported damage to the road surface and trolleybus contact network, with traffic from the left bank to the right bank closed. By 11:19 a.m., three lanes were operating in that direction and one in the reverse direction. At 12:25 p.m., trolleybus routes had resumed, with delays. The city subsequently reported two people injured in the strike.KYIV
These were attacks on a city where people needed to travel, work and reach services. The commercial implication sits within that human reality: infrastructure damage can interfere with many organisations simultaneously, including organisations whose own premises remain intact.
The reports do not establish that half of Kyiv's transport capacity disappeared. Bridges differ in capacity, restrictions can be partial, and access changes during repairs. Nor do they establish that a particular pair of suppliers failed. The shared-supplier problem is the management inference we should test, rather than a claim about an unnamed Ukrainian business.
A company's continuity plan can therefore fail without a supplier becoming insolvent or its factory being destroyed. The factory may be functioning and the goods may be ready. Getting them to the customer is another dependency, with its own conditions.
Two contracts can still produce one failure
Procurement has a reasonable reason to like two suppliers: competitive tension. A founder has a less reasonable reason to like the same arrangement: it produces a green square in the board pack. The temptation is to let the useful purchasing decision do a second job for which nobody has checked its qualifications.
Consider an illustrative scenario, unrelated to any identified Kyiv business. Supplier A provides 60% of one essential input; supplier B provides 40%. Both use the same bridge corridor to reach your receiving site. There is no usable alternative route at the moment of closure, and no shipment is already beyond the bottleneck.
Closing that corridor interrupts 100% of incoming replenishment for this input. You still have two contracted suppliers. You now have zero usable delivery routes for their scheduled shipments. Existing stock may keep production running temporarily, so zero replenishment does not mean zero output that instant.
The comparison below holds supplier count constant while changing access. Its percentages refer only to this input's incoming supply in the hypothetical, never to Kyiv's road capacity.
Illustrative scenario
The supplier count survives. The delivery route does not.
Two contracted suppliers provide no incoming replenishment when their only usable corridor closes; existing inventory can still support output temporarily.
Suppliers, usable corridors, and share of one input's replenishment · Authored assumptions
Before the hypothetical closure. Count the contracts. Two suppliers remain contracted both before and after the event. A vendor-count dashboard can stay unchanged.
Step 1 of 3
Count the contracts
Two suppliers remain contracted both before and after the event. A vendor-count dashboard can stay unchanged.
Before
Before the hypothetical closure
Contracted suppliers
2
Usable delivery corridors
1 shared corridor
Incoming replenishment
100% of this input's normal supply
Trigger
The shared corridor becomes unavailable
- Count the contracts: Two suppliers remain contracted both before and after the event. A vendor-count dashboard can stay unchanged.
- Trace the shared route: Both suppliers depend on the same corridor. Closing it disables both delivery paths at once.
- Measure what can arrive: Incoming replenishment falls to zero. Available inventory can buy time, but another signature on the vendor list cannot reopen the route.
Complete turning point
Before
Before the hypothetical closure
Contracted suppliers
2
Usable delivery corridors
1 shared corridor
Incoming replenishment
100% of this input's normal supply
Trigger
The shared corridor becomes unavailable
After
After closure, before a fallback is activated
- Unchanged
Contracted suppliers
2
The supplier register is unchanged; it does not measure route availability.
- Changed
Usable delivery corridors
0
The only currently usable corridor is closed to both suppliers.
- Changed
Incoming replenishment
0% of this input's normal supply
The interrupted 60% and 40% shares account for all incoming supply of this input. This is not a statement about immediate production output.
Guided steps
Step 1
Count the contracts
Two suppliers remain contracted both before and after the event. A vendor-count dashboard can stay unchanged.
Step 2
Trace the shared route
Both suppliers depend on the same corridor. Closing it disables both delivery paths at once.
Step 3
Measure what can arrive
Incoming replenishment falls to zero. Available inventory can buy time, but another signature on the vendor list cannot reopen the route.
Methodology
Compare the instant before closure with the period after closure and before an alternative is activated. These are hypothetical supply shares, not Kyiv transport-capacity estimates.
Sources
View data and methodology
Methodology
Compare the instant before closure with the period after closure and before an alternative is activated. These are hypothetical supply shares, not Kyiv transport-capacity estimates.
| Fact | Before | After | Status | Sources |
|---|---|---|---|---|
| Contracted suppliers | 2 | 2 | Unchanged | — |
| Usable delivery corridors | 1 shared corridor | 0 | Changed | — |
| Incoming replenishment | 100% of this input's normal supply | 0% of this input's normal supply | Changed | — |
Trigger
The shared corridor becomes unavailable
- Count the contracts: Two suppliers remain contracted both before and after the event. A vendor-count dashboard can stay unchanged.
- Trace the shared route: Both suppliers depend on the same corridor. Closing it disables both delivery paths at once.
- Measure what can arrive: Incoming replenishment falls to zero. Available inventory can buy time, but another signature on the vendor list cannot reopen the route.
Assumptions
- Supplier A provides 60% and supplier B 40% of one essential input's incoming supply.
- Both suppliers use the same bridge corridor to the receiving site.
- The corridor closes completely in this hypothetical; no alternative is immediately usable and no shipment is already beyond the bottleneck.
- Both supplier contracts remain in place. Existing stock is separate from incoming replenishment.
This is a common-cause failure: one event disables several options because they share something necessary. The dependency might sit outside either vendor's legal boundary. Two carriers can use the same terminal. Two factories can draw from the same electricity network. Two software vendors can require the same identity service before your staff can use them.
NIST's federal information-system contingency guide makes the telecom version explicit: alternate services should reduce shared single points of failure, and provider separation should account for exposure to the same hazards.NIST The principle travels well beyond federal IT, although the guide is not a rule imposed on every startup.
Independence always needs a named scenario. A different crossing might survive a local road closure while remaining exposed to the same regional power outage. A geographically distant provider might escape that outage while depending on the same software control system. “Independent” without an event attached is an adjective with an unusually generous expense account.
Keep the second supplier. Just stop giving the contract credit for risks it does not reduce. That distinction also improves negotiation: you can ask what additional route or reserved capacity you are actually buying, instead of paying a resilience premium for another account manager.
Ask what both vendors need before they can serve you
A supplier questionnaire usually asks whether a continuity plan exists. This is wonderfully convenient for the supplier: the question can be answered by possessing a document. Your customer will eventually ask for the goods, which requires a different kind of preparation.
Start with one important customer outcome, such as delivering a particular spare part or processing a payment. Trace the resources needed to deliver it. Request evidence about the actual supplying site and service, because a corporate headquarters address says little about where your order is produced or your data is processed.
Use a compact dependency record:
| Dependency | Evidence to request | What would make the backup useful? |
|---|---|---|
| Physical delivery | Origin site, actual corridor, terminals and receiving location | A practicable route outside the disrupted corridor, with capacity available |
| Electricity and fuel | Supply arrangements, tested backup duration and replenishment access | Enough independent energy to deliver the promised service during the scenario |
| Communications and software | Underlying providers, regions, identity and administrative access | A recovery path that remains reachable when the primary dependency fails |
| Critical subcontractors | The facility or provider performing the indispensable step | A qualified substitute with usable capacity and an activation process |
Ask for dated evidence, an owner and the point at which the answer must be refreshed. Where a vendor cannot disclose sensitive details, seek a scoped assurance about the specific shared-risk scenario. Record the remaining uncertainty. An unknown dependency should stay visible to the board; colouring the cell green does not constitute discovery.
Cloudflare supplied a concrete digital example on June 12, 2025. Its incident report described a third-party storage failure affecting Workers KV, which several Cloudflare products depended on for configuration, authentication or asset delivery. Access identity-based logins failed during the incident. Cloudflare said DNS, cache and proxy services were not directly affected.CF
That distinction matters. A dependency can disable several important products without disabling every product sold by the company. Assess the service you actually need. Brand-level claims about a provider being either “up” or “down” can obscure the relevant failure.
Cloudflare also accepted responsibility for its chosen dependencies and architecture, despite the external trigger.CF That is a useful posture for your own customer conversation. “Our vendor's vendor” explains a mechanism. After the third possessive, it begins to sound like an attempt to leave the room.
The FCA's March 2026 review found that some firms' mapping concentrated too heavily on technology and needed to include people, facilities, processes and other dependencies. These are observations about regulated financial firms, with a useful lesson for operators elsewhere.FCA A backup office staffed by people who cannot reach it is worth discovering during planning.
Measure the time until usable service returns
The phrase “available on request” deserves a follow-up. Available in a catalogue, available for dispatch and available at your loading dock are different states. Sales can move between them in one sentence. Your shipment will take longer.
Extend the same hypothetical. You hold three days of accessible, usable stock at a constant consumption rate. A previously qualified alternative corridor can deliver replenishment five days after you authorise it. Assume no other arrivals and that the disrupted route remains unavailable throughout that period.
Even an immediate decision leaves a minimum two-day gap: five days to arrival minus three days of stock. An approval delay lengthens it. The backup exists, and it still fails to maintain uninterrupted output under these assumptions.
Separate the elapsed time into stages you can observe: detection, authorisation, supplier mobilisation, transit, then receiving and any necessary acceptance checks. Some work can happen in parallel. Measure the critical path rather than adding every departmental estimate and pretending the result is a tested recovery time.
This changes what you buy. You might hold more of the critical input near the consuming site, reserve earlier transport capacity, qualify a substitute product, or agree which customer orders can be deferred. Each choice has a cost. Extra stock ties up cash and can become obsolete. Reserved capacity can expire unused. Reduced service imposes a real consequence on customers.
Also measure the quantity that returns. A fallback covering 30% of required throughput does not restore a business that needs 80% to honour its essential commitments. These percentages are screening examples, not universal thresholds. Define the minimum service level for your own product and the consequences below it.
Our analysis of CPKC's route optionality examines why control of useful routes can create choices. For continuity planning, the next question is whether your company can exercise that choice at the volume and time required.
Ask a reserve provider how competing customers are allocated capacity during a widespread disruption. A letter saying it can normally accommodate you is weak evidence about a day when everyone calls. Several customers may each believe they have exclusive emotional access to the same spare truck.
Compare the premium with the consequences of doing less: lost contribution from cancelled orders, additional fulfilment costs, cash tied up and customer harm. Keep revenue and profit separate. Do not count every delayed sale as permanently lost, or add the same loss again under a different heading to make the fallback look affordable.
Then decide which gap you can tolerate and which you must fund. A documented choice to accept a limited interruption is more useful than a promise of uninterrupted service unsupported by the operating plan.
Give someone permission to buy the expensive answer
The fallback price arrives above budget. Operations wants to act. Finance wants evidence. The founder wants everyone to use judgement, preferably in a way that will look obvious in retrospect. A committee is formed around a decision whose value is declining while the committee finds a time.
Your continuity plan needs a decision right as concrete as its transport route. The Basel Committee's banking guidance calls for disruption plans to define responsibilities, succession of authority, decision processes and activation triggers. It also calls for assessing whether critical third parties can actually be substituted.BASEL Those are banking principles; the governance design is useful without pretending every founder is subject to them.
For the illustrative scenario, suppose using the qualified alternative requires US$60,000 of incremental spending. A previously adopted delegation allows the operations lead to commit up to US$75,000 of aggregate incremental spending per incident once the documented delivery trigger occurs. The finance lead has the same authority only as the named alternate if the operations lead is unavailable. The limit belongs to the incident, so switching decision-makers does not reset it.
Assume the company has already checked the delegation against its governing documents and financing restrictions. The trigger is credible evidence that the normal corridor cannot meet the next committed delivery and that the qualified alternative is usable. The authorised decision-maker records the evidence and sends an immediate notice to the CEO. Commitments above the cap require the board's specified approval process.
The board receives a spend-and-service report within 24 hours. The emergency delegation expires after 72 hours unless renewed, while commitments validly made during that window remain commitments. These amounts and deadlines are design inputs for the example, not recommended limits for every company.
The matrix separates authority to commit the money from the right to be informed. Under these assumptions, the US$60,000 decision can proceed within the delegation; the operations lead does not need to collect reassuring reactions from everyone shown in the notification column.
Illustrative scenario
Who can authorise the US$60,000 alternative?
The operations lead can commit the premium within the assumed delegation; finance substitutes if that lead is unavailable, and notification is separate from approval.
US dollars of aggregate incremental spending per incident · Authored assumptions
Step 1 of 3
Make the purchase executable
The US$60,000 premium fits within the illustrative US$75,000 cap. The operations lead may act when the documented trigger is met.
Operations lead · Commit spending within US$75,000 cap
May authorise the US$60,000 premium
Previously adopted emergency delegation
- Threshold
- US$75,000 aggregate incremental spending per incident
- Condition
- Documented delivery trigger and usable qualified alternative
- Duration
- 72 hours from activation unless renewed
- Exception
- Does not override external consent or payment requirements
Finance lead (alternate) · Commit spending within US$75,000 cap
May authorise as the named alternate
Substitute authority, not a second approval requirement
- Threshold
- Same incident cap; prior commitments count
- Condition
- Operations lead unavailable and activation conditions met
- Duration
- Same 72-hour window unless renewed
- Exception
- No extra spending allowance from changing approver
Board · Approve spending above the cap
Must approve commitments exceeding the cap
Reserved escalation under the assumed policy
- Threshold
- Aggregate incremental spending above US$75,000
- Condition
- Use the board's specified approval process before commitment
CEO · Receive activation notice
Is informed immediately
Notification, not an additional approval gate
- Condition
- Decision-maker records and communicates the activation evidence
Board · Review spending and service outcome
Receives the spend-and-service report
Oversight after activation
- Condition
- Assess the decision using evidence available when it was made
- Duration
- Within 24 hours
Complete decision rights matrix
Operations lead · Commit spending within US$75,000 cap
May authorise the US$60,000 premium
Previously adopted emergency delegation
- Threshold
- US$75,000 aggregate incremental spending per incident
- Condition
- Documented delivery trigger and usable qualified alternative
- Duration
- 72 hours from activation unless renewed
- Exception
- Does not override external consent or payment requirements
Operations lead · Approve spending above the cap
No stated right
Operations lead · Receive activation notice
No stated right
Operations lead · Review spending and service outcome
No stated right
Finance lead (alternate) · Commit spending within US$75,000 cap
May authorise as the named alternate
Substitute authority, not a second approval requirement
- Threshold
- Same incident cap; prior commitments count
- Condition
- Operations lead unavailable and activation conditions met
- Duration
- Same 72-hour window unless renewed
- Exception
- No extra spending allowance from changing approver
Finance lead (alternate) · Approve spending above the cap
No stated right
Finance lead (alternate) · Receive activation notice
No stated right
Finance lead (alternate) · Review spending and service outcome
No stated right
CEO · Commit spending within US$75,000 cap
No stated right
CEO · Approve spending above the cap
No stated right
CEO · Receive activation notice
Is informed immediately
Notification, not an additional approval gate
- Condition
- Decision-maker records and communicates the activation evidence
CEO · Review spending and service outcome
No stated right
Board · Commit spending within US$75,000 cap
No stated right
Board · Approve spending above the cap
Must approve commitments exceeding the cap
Reserved escalation under the assumed policy
- Threshold
- Aggregate incremental spending above US$75,000
- Condition
- Use the board's specified approval process before commitment
Board · Receive activation notice
No stated right
Board · Review spending and service outcome
Receives the spend-and-service report
Oversight after activation
- Condition
- Assess the decision using evidence available when it was made
- Duration
- Within 24 hours
Guided reading
1. Make the purchase executable
The US$60,000 premium fits within the illustrative US$75,000 cap. The operations lead may act when the documented trigger is met.
2. Remove the unavailable approver
Finance substitutes for an unavailable operations lead. It does not add another signature or reset the spending cap.
3. Separate escalation from notification
Above-cap spending requires board approval. Within-cap action triggers immediate CEO notice and a board report within 24 hours.
View data and methodology
Methodology
An illustrative internal delegation, not a statement of default corporate powers. Actual governing documents, financing restrictions and payment controls must support the arrangement.
| Actor | Action | Right | Strength | Threshold | Condition | Duration | Exception | Source |
|---|---|---|---|---|---|---|---|---|
| Operations lead | Commit spending within US$75,000 cap | May authorise the US$60,000 premium | Previously adopted emergency delegation | US$75,000 aggregate incremental spending per incident | Documented delivery trigger and usable qualified alternative | 72 hours from activation unless renewed | Does not override external consent or payment requirements | — |
| Finance lead (alternate) | Commit spending within US$75,000 cap | May authorise as the named alternate | Substitute authority, not a second approval requirement | Same incident cap; prior commitments count | Operations lead unavailable and activation conditions met | Same 72-hour window unless renewed | No extra spending allowance from changing approver | — |
| Board | Approve spending above the cap | Must approve commitments exceeding the cap | Reserved escalation under the assumed policy | Aggregate incremental spending above US$75,000 | Use the board's specified approval process before commitment | — | — | — |
| CEO | Receive activation notice | Is informed immediately | Notification, not an additional approval gate | — | Decision-maker records and communicates the activation evidence | — | — | — |
| Board | Review spending and service outcome | Receives the spend-and-service report | Oversight after activation | — | Assess the decision using evidence available when it was made | Within 24 hours | — | — |
- Make the purchase executable: The US$60,000 premium fits within the illustrative US$75,000 cap. The operations lead may act when the documented trigger is met.
- Remove the unavailable approver: Finance substitutes for an unavailable operations lead. It does not add another signature or reset the spending cap.
- Separate escalation from notification: Above-cap spending requires board approval. Within-cap action triggers immediate CEO notice and a board report within 24 hours.
Assumptions
- The qualified alternative requires US$60,000 of incremental spending, with no prior spending against this incident's US$75,000 cap.
- The company has validly adopted the delegation after checking governing documents and financing restrictions.
- Activation requires credible evidence that the normal corridor cannot meet the next committed delivery and the qualified alternative is usable.
- The finance lead is the named alternate only when the operations lead is unavailable; changing approvers never resets the aggregate cap.
- The CEO receives immediate notice; the board receives a spend-and-service report within 24 hours.
- Delegated authority to make new commitments expires after 72 hours unless renewed; valid existing commitments remain binding. Payment access and required controls are separately tested.
Payment needs its own rehearsal. Confirm that an authorised person can release the transfer, access the bank and satisfy required controls during the disruption. Internal approval without usable cash or payment access leaves the carrier waiting. Your company has authorised a purchase in the same sense that a restaurant customer has authorised dinner by feeling hungry.
Check where the board's powers and other approval rights actually sit before adopting the delegation. An emergency label does not itself amend a financing agreement or supply a missing consent. The aim is to resolve those constraints while there is time to do so.
After an incident, judge the decision against the evidence available when it was made. If a manager follows the agreed trigger and the bridge reopens early, the premium may look unnecessary afterwards. Punishing that manager teaches the next one to wait. The board then gets the spending discipline it rewarded, complete with the delayed shipment.
Test the plan with the approver unavailable
A tabletop exercise becomes suspiciously pleasant when every participant is present, every vendor answers and the scenario ends immediately after management says it would activate the plan. That tests whether senior people can agree with their own presentation.
Run a narrower, less flattering exercise. Remove one shared dependency from an important customer service. Make the usual approver unavailable. Ask the team to produce the evidence that the alternative works and demonstrate the approval path, including how payment would be released. Simulate the transaction where a real commitment would be inappropriate.
Record the time taken to obtain a usable quote and confirm capacity. Check whether the supposed backup uses the same corridor. Open the current instructions through the recovery access method. Identify which customer commitments remain achievable and which require a timely conversation.
The FCA's 2026 observations favour realistic testing that connects findings to remediation and board investment decisions.FCA For your company, turn each failed step into a named action with a cost and a completion date. A test that exposes a gap has produced information; hiding it to preserve the green status wastes the exercise.
Put the unresolved choices in the next board pack. Show the affected service, shared dependency, minimum acceptable delivery level, tested recovery time, cost of the alternative and person authorised to activate it. Include the date of the evidence. This lets directors decide whether to pay, change the customer promise or accept the exposure.
Reserve capacity will look idle until it is needed. Make that purchase explicit so the next cost review can assess the risk being reintroduced. Otherwise, a saving will be celebrated by people who were never shown what the money was buying.
Before the next continuity review, ask the owners of your primary and backup supply arrangements to trace one critical delivery together. Mark where their routes converge. If both still need the same bridge, put the funded alternative and its authorised decision-maker on the agenda before approving another green square.