Early-bird Discount
expires in
Register Now

Blog

Third-Party Risk Reality Check: A Practical Tabletop Exercise for Supply Chain Disruptions

Blog Post

Third-Party Risk Reality Check: A Practical Tabletop Exercise for Supply Chain Disruptions

Jonathan Care
Sep 25, 2025

Executive Summary 

The recent cyberattack affecting major European airports through a third-party check-in provider serves as a stark reminder of our interconnected digital dependencies. When Brussels, Berlin, and Heathrow airports experienced simultaneous disruptions, the root cause wasn't a direct attack on their infrastructure—it was a single point of failure in their shared supply chain. This incident provides a perfect template for organizations to stress-test their own third-party risk response capabilities through a focused 60-minute tabletop exercise. 

The Wake-Up Call: When Suppliers Become Single Points of Failure 

The airport incident follows a disturbingly familiar pattern: a critical third-party platform experiences a cyber-related outage, and every downstream organization scrambles to maintain operations. The cascading impact forces manual workarounds, degrades service quality, and triggers a complex web of communication challenges across vendors, partners, and customers. 

This scenario isn't unique to aviation. Every organization relying on SaaS platforms, managed service providers, or cloud infrastructure faces similar exposure. The question isn't whether such an incident could affect your organization—it's whether you're prepared to respond effectively when it does. 

A Practical Tabletop Exercise Framework 

Based on the European airport incident, here's a structured tabletop exercise that any organization can deploy to test their third-party incident response capabilities. 

Scenario Foundation 

Core Premise: A critical third-party platform essential to your operations experiences a major outage with unknown recovery timeline. Initial indicators suggest a cyber-related disruption, potentially ransomware, at the provider level. 

Threat Actor Profile: Attribution remains pending, but operational indicators align with criminal ransomware groups targeting high-value service providers for maximum downstream impact. The vendor confirms a "cyber-related disruption" but provides limited technical details due to ongoing investigation. 

Exercise Objectives 

  1. Rapid Crisis Activation: Test the speed and effectiveness of incident and crisis management protocols, including establishment of joint vendor coordination bridges 
  2. Operational Resilience: Evaluate ability to maintain critical services in degraded mode while managing capacity constraints 
  3. Stakeholder Management: Assess regulatory reporting readiness and crisis communication coordination across multiple stakeholders 

Three-Phase Exercise Structure 

Phase 1: Detection, Activation, and Escalation (Minutes 0-20) 

Scenario Injects: 

  • 08:10: Vendor status page switches to "major outage affecting all regions" 
  • 08:15: Support tickets triple as downstream impacts cascade 
  • 08:25: Partner organization executive extends invitation to vendor's emergency cross-company coordination bridge 

Critical Decision Points: 

  • Who has authority to declare a crisis, and what specific triggers mandate escalation? 
  • Who owns the vendor relationship during crisis mode, and how do they balance information gathering with operational response? 
  • What immediate decisions must be made before full situational awareness is achieved? 

Success Metrics: 

  • Time from detection to crisis declaration 
  • Time to establish unified command structure 
  • Clarity of initial resource allocation decisions 

Phase 2: Continuity of Critical Processes (Minutes 20-40) 

Scenario Injects: 

  • Manual workaround procedures sustain only 35% of normal throughput 
  • Contractual SLA breach projected within 90 minutes without prioritization 
  • Vendor offers partial service restoration with acknowledged stability risks 

Critical Decision Points: 

  • What constitutes the minimum viable capacity for each critical business process? 
  • Which offline procedures or alternate workflows exist, and who can authorize their activation? 
  • How will extended operations be staffed to prevent team burnout during multi-day incidents? 

Success Metrics: 

  • Documented minimum viable capacity thresholds 
  • Time to activate alternative processes 
  • Resource sustainability planning for extended incidents 

Phase 3: Reporting and Communications (Minutes 40-60) 

Scenario Injects: 

  • Regulatory early warning notification deadline approaches 
  • Key customers demand detailed explanations and mitigation timelines 
  • Social media speculation incorrectly attributes outage to your systems rather than the vendor 

Critical Decision Points: 

  • What specific thresholds and timers govern regulatory notifications, and who provides final approval? 
  • What single-paragraph external statement accurately explains the situation while maintaining stakeholder confidence? 
  • How do we ensure message alignment across vendor, partners, and our own communications? 

Success Metrics: 

  • Regulatory notification decision timeline 
  • Message consistency across channels 
  • Speed of social media misconception correction 

Key Takeaways and Implementation Guidance 

This tabletop exercise addresses the three fundamental questions leadership needs answered before any third-party incident: 

  1. Who would we call? Clear escalation paths and vendor crisis contacts must be pre-established, not discovered during an incident. 
  2. How do we keep serving? Degraded mode operations and manual workarounds require advance planning and regular testing. 
  3. What do we say? Pre-drafted communication templates and clear approval chains prevent messaging delays when minutes matter. 

Scheduling for Success 

Run this exercise during normal business hours with key stakeholders present. The 60-minute investment will reveal critical gaps in third-party incident response capabilities before they're exposed during an actual crisis. Consider conducting this exercise quarterly, rotating through different critical vendors to build comprehensive response capabilities. 

Beyond the Tabletop 

While this exercise provides valuable insights, organizations should complement it with: 

  • Regular updates to vendor dependency mapping 
  • Contractual reviews ensuring appropriate incident notification requirements 
  • Technical controls monitoring third-party service health 
  • Regular communication drills with critical vendors 

Ready or not, Take-off time approaches 

The European airport incident shows that third-party risks aren't just theoretical; they're real operational challenges that need practical preparation. This tabletop exercise turns a recent real-world event into concrete steps for better readiness. Organizations that spend 60 minutes on this exercise today may avoid hours or even days of chaos when their critical supplier faces inevitable disruptions tomorrow. 

The question for every CISO, risk manager, and business continuity professional is simple: Will you be ready when your vendor's status page turns red? 


KuppingerCole Analysts AG
Mr. Care served as a Senior Director Analyst at Gartner until 2022, accumulating 33 years of industry experience. During his tenure, he was a top-rated analyst responsible for defining the Fraud market and leading Gartner’s Insider Threat and Risk research. Prior to his stint at Gartner, Mr Care worked as a Security Engineer at Sun Microsystems for two years, a Senior Consulting Manager at Verisign for two years, and in Product Risk Research at Visa Europe for four years. Mr. Care holds several industry accolades and certifications, including as a Certified Fraud Examiner, PCI DSS-qualified forensic Investigator, PCI DSS-qualified security Assessor, PCI Payment Applications-Qualified Security Assessor, U.K. Government-Accredited Penetration Tester, and U.K. Government-Listed Security Advisor.​ Mr. Care is a writer for Dark Reading.  In addition to his cybersecurity career, Mr. Care is also an independent composer and songwriter, producing tracks for film/TV productions as well as streaming works. His music studio is based in Ancora, Portugal.
Almost Ready for the ICCID 2025?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.