A bank relies on a critical software-as-a-service provider that, in turn, runs entirely on a single major cloud platform that several of the bank's other key suppliers also use. The information security manager is briefing the board on what makes this arrangement particularly dangerous beyond the direct provider relationship. Which risk should the manager highlight as the primary governance concern?
- AVendor lock-in risk, because the contractual switching costs of leaving the software-as-a-service provider have grown high enough to weaken the bank's negotiating position over time.
- BData residency risk, because the upstream platform may store the bank's processed records in a jurisdiction whose privacy regime differs from the bank's home regulator's rules.
- CShadow IT risk, because business units may have procured the software-as-a-service provider without routing the engagement through the formal security review and approval process.
- DFourth-party concentration risk, because many of the bank's critical suppliers depend on the same underlying platform, so one failure there could disrupt several services at once. Correct
Why A is wrong: Tempting because lock-in is a genuine sourcing concern, but it speaks to commercial leverage, not the systemic outage exposure created by shared upstream dependence.
Why B is wrong: Tempting because residency is a real compliance issue with cloud chains, but it is a localised legal exposure, not the cross-supplier aggregation risk the scenario centres on.
Why C is wrong: Tempting because unsanctioned procurement is a common failing, but the provider here is already a known critical supplier, so shadow IT does not describe the stated exposure.
Why D is correct: Correct because shared reliance on one upstream platform creates a common point of failure across multiple suppliers, an aggregation exposure the direct contract does not address.