Supply chain resilience: five lessons from a disruptive 2025
From Red Sea disruption to concentrated cloud outages, last year was an unusually clean test of how resilient your suppliers really are. The results were not flattering.
Across 2025, the combination of shipping disruption, geopolitical re-routing, ransomware events at managed service providers and two material public-cloud outages gave most large organisations a series of involuntary stress tests. The lessons cluster around a few hard truths.
First, the concentration most firms worry about is one layer too high. Your direct suppliers may be diversified; their suppliers often are not. Sub-tier visibility is where the genuine risk now lives.
Second, contracted recovery times rarely survive contact with a real incident. The RTO in your master services agreement and the RTO your supplier can actually deliver during a sector-wide event are different numbers, and you should be testing the second one.
Third, the firms who came through 2025 best had pre-positioned alternatives — second sources, manual fallbacks, capacity reservations — not just plans to find them. Fourth, communications discipline mattered more than capability; the suppliers who told the truth early kept customers. Fifth, exercising with your critical suppliers, not just your own teams, is no longer optional.
Related services
More insights
Keep reading.
Related thinking from the Oakwood team.
Operational resilience: what 'beyond March 2025' actually looks like
The FCA's transitional period has closed. The interesting question now isn't whether you're compliant — it's whether the framework you built is doing any real work.
Why most business continuity plans fail under pressure
The plan is rarely the problem. The problem is the gap between the document and the organisation's ability to operate it.
What the First Year of DORA Has Taught Us About Operational Resilience in Financial Services
The Digital Operational Resilience Act has been in force since January 2025. Fourteen months on, patterns are emerging about what works, what does not, and where organisations are still falling short. This article examines the practical lessons from the first year of DORA compliance.
