By Bill Murphy  ·  Powered by Colony Spark

THE OPERATIONS
BRIEF

 

ISSUE #19  ·  JULY 30, 2026

 
 

Most critical vendor lists are still organized around what enters the building. The operation now depends just as heavily on what enters the workflow: ERP partners, cloud platforms, AI providers, the one certified technician within driving distance. Any of them can stop order flow. Most of them are not on the same list.

This issue is about the register that puts them there, and the questions it forces you to answer.

Bill

 

THE SHIFT

The Critical Vendor List Is Too Short.

The list tracks what enters the building. The dependency tracks what enters the workflow.

Tennant Company made the distinction impossible to ignore. Its North America ERP cutover in November 2025 introduced what CEO David Huml called “severe system functionality issues that limited our ability to enter orders, ship products, and service our customers.” Order management, production scheduling, fulfillment, and inventory visibility all suffered. Tennant put the damage at roughly $30 million in Q4 net sales and about $22 million in adjusted EBITDA (SEC Form 8-K, Feb 2026). That is not an IT inconvenience. It is a production and revenue stoppage caused by a digital dependency.

Three signals from 2026

· 65% of large companies now rank third-party and supply-chain vulnerabilities as their greatest cyber-resilience challenge (up from 54% in 2025). Only 33% comprehensively map their supply-chain ecosystems (WEF Global Cybersecurity Outlook 2026).

· 83% of executives expect partner networks to expand over the next one to three years. Only 18% have third-party risk management fully integrated with enterprise risk management (KPMG Global TPRM Survey, March 2026).

· 16% of organizations don’t track the creation of new AI-related identities. Fewer than 25% have formal creation or removal policies. Service accounts, API keys, tokens, certificates, and AI-agent credentials now outnumber human identities (Cloud Security Alliance, 2026).

The 65% figure is a large-company number, not an SMB benchmark. The lesson travels down-market anyway. Concentration is dangerous when dependencies are not visible, and the AI identity layer is expanding faster than most procurement functions can see.

The shift is not from supplier risk to technology risk. It is from category-based reviews to operational-dependency reviews. The operators pulling ahead ask the same four questions of every dependency: what stops, how long does recovery take, who owns the response, and what bypass has been tested.

Steel, ERP, cloud hosting, an AI agent, and the only certified technician in the region belong on one list if any can halt the same order.

 

FROM THE FLOOR

Manage lock-in through architecture.

Steve Bronson, CIO of Southern Glazer’s Wine & Spirits, on keeping options open

Steve Bronson is CIO at Southern Glazer’s Wine & Spirits, the largest US wine and spirits distributor. Speaking with TechTarget in March, he drew the distinction between operators who lose control of their dependencies and those who preserve them.

“Vendor lock-in is a real risk, and it’s not going away. The key is managing it through architecture.”

Steve Bronson

CIO, Southern Glazer’s Wine & Spirits  ·  TechTarget, March 2026

Bronson’s approach: define core ecosystems across HR, supply chain, and ERP, and give the third party design authority inside that core. Around it, use service layers, redundancy, and bypass paths to keep the key decisions reversible.

The takeaway

The distinction is sharper than “avoid lock-in.” Define the core, assign authority, preserve a bypass, and keep every high-impact decision reversible.

 

THE STACK

The Critical Dependency Register.

One list for every outside dependency that can stop the operation.

Same fields, same review, same accountability, whether the dependency is a supplier, a system, or a single certified person.

Build one living register for every outside dependency that can interrupt an operating workflow. Physical suppliers, ERP and software platforms, cloud and SaaS, AI providers and agents, contractors, credentialed specialists. All in one place, all scored the same way.

What each row records

· The dependency and the workflows or sites it affects.

· Operational impact and recovery time. Scored against outcomes: degraded work, delayed shipment, stopped line, stopped order flow, customer-service failure.

· Business owner and technical owner. Two names, not a department.

· Fallback plan and last fallback test date. Untested does not count as tested.

· Contract, credential, license, or certification expiration. The dates that quietly turn a working dependency into a broken one.

What the operator gets out of it

Four outputs, every cycle

1. Heatmap. High-impact dependencies with no tested fallback, ranked.

2. Change log. New integrations, providers, credentials, contractors, expiring certifications.

3. Owner queue. Overdue fallback tests and unresolved single points of failure, by name.

4. Drill calendar. A short list of the few dependencies whose failure would stop orders, production, or shipping.

Cadence: weekly exception check, monthly owner attestation, quarterly fallback drill for the highest-impact rows. Refresh the register whenever a supplier, integration, owner, contract, credential, AI agent, or certified role changes.

Two paths to build it

Path 1: Internal build

Start with one value stream, order entry through shipment. Put operations, procurement, IT, finance, HR, quality, and service in one working session. List every external dependency at each handoff and score it against the shared fields. Do not mark a fallback complete without an owner and a test date. A spreadsheet or lightweight database is enough for the first cycle.

Path 2: ERP or partner build

Use the existing ERP partner or supply-chain consultant to map integrations, scheduled jobs, connectors, custom workflows, privileged roles, support paths, and manual bypasses. Give that partner design authority inside the defined core (Bronson’s point). The operator retains ownership of impact scores, recovery targets, and risk acceptance. Strong partners add change alerts and fallback testing after go-live.

Put every dependency that can stop order flow on one list before the next outage writes it for you.

 

THE OPERATIONS BRIEF

By Bill Murphy  ·  Powered by Colony Spark

Already have a critical dependency register? Or watching a client find out the hard way what should have been on it? Hit reply, I read every one. Bill

Colony Spark · 170 Mason Street · Greenwich, Connecticut 06830, United States