The Illusion of Isolation
Most risk assessment frameworks share a common assumption: that the entity under evaluation can be understood in isolation. A supplier is rated on its financials. A counterparty is scored on its credit history. A jurisdiction is assessed on its political stability. Each is treated as a standalone unit, evaluated against a checklist, and assigned a score. The assumption is that if each part is sound, the system is sound.
This assumption is wrong. In a connected world, the single points of failure are not within entities—they are between them.
How Single Points of Failure Actually Work
A single point of failure is not a weakness in one company. It is a structural property of a network. When a critical node sits on a path that many other nodes depend on, the failure of that one node propagates through the system. The node itself may be financially healthy, well-managed, and highly rated. That does not matter. What matters is its position.
Consider the semiconductor shortage of 2020–2023. The problem was not that any single chipmaker was mismanaged. The problem was that global automotive supply chains had converged on a small number of fab facilities for a specific class of chips. When demand patterns shifted, that convergence became a choke point. Every manufacturer that had optimised for cost by consolidating suppliers was exposed simultaneously. Traditional risk assessment, which had evaluated each supplier individually and found them acceptable, had failed to model the dependency structure that made the system fragile.
The Three Blind Spots of Traditional Risk Assessment
1. No network context. Traditional frameworks evaluate entities, not relationships. A supplier with an A+ credit rating is considered low-risk regardless of whether it is the sole source for a critical component, or one of twelve. The risk lives in the topology, not the entity.
2. Static assessment in a dynamic system. Risk assessments are typically conducted annually or quarterly. But supply chain topology changes constantly—new suppliers are added, alternates are discontinued, ownership changes hands. A risk profile that was accurate in January may be meaningless by March. The system does not wait for the next review cycle.
3. No propagation modelling. Traditional frameworks ask "can this entity fail?" They do not ask "if this entity fails, what else fails?" The cascading effect—the most consequential dimension of supply chain risk—is absent from the model. A single Tier 3 supplier failure can halt a Tier 1 manufacturer if no alternative exists, and traditional assessment will not have flagged it because the Tier 3 supplier was below the assessment threshold.
The Real Cost of Getting It Wrong
The cost of these blind spots is not theoretical. The automotive industry lost an estimated $210 billion in revenue during the semiconductor shortage. The Suez Canal blockage in 2021 held up $9.6 billion in trade per day. The Colonial Pipeline ransomware attack disrupted fuel supplies across the US East Coast. In each case, the root cause was not the failure of a single entity—it was the failure of the system to absorb that single entity's disruption.
These events are not anomalies. They are the predictable consequence of building tightly coupled, highly optimised supply networks without modelling their structural fragility. The more efficient the network, the less slack it carries, and the faster a disruption propagates.
A Network-First Approach
At Forreast, we approach supply chain risk as a network problem. Our WorldGraph maps over two million entities and the relationships between them, allowing us to identify choke points, single-source dependencies, and concentration risks that traditional assessment cannot see. We score risk not just on the entity, but on its position: how many paths depend on it, how easily those paths can be rerouted, and what the downstream impact of its failure would be.
This requires continuous monitoring, not periodic assessment. It requires graph traversal, not spreadsheet aggregation. And it requires accepting that the most dangerous risks are not the ones you can see on a company's balance sheet—they are the ones embedded in the structure of the system itself.
The Choice
Organisations have a choice. They can continue using risk frameworks designed for a less connected era, evaluating entities in isolation and being surprised when the system behaves in ways the framework could not predict. Or they can adopt an approach that models the world as it actually is: interconnected, dynamic, and structurally fragile in ways that only become visible when you look at the whole graph.
The cost of the first approach is paid in supply disruptions, lost revenue, and competitive disadvantage. The cost of the second is an investment in understanding that pays dividends the moment the next disruption arrives. Because there is always a next disruption. The only question is whether you will see it coming.
