Shared resilience. What the contract does not cover when the plant stops
The first installment described how industrial operations have been accumulating dependencies on external services that rarely appear in their risk analyses. This second part addresses the relationship with those providers, of what they guarantee and what no one guarantees, and of the sovereignty questions worth asking before contract renewal and not after the incident.
Shared responsibility, seen from the shop floor
All major cloud service providers base their relationship with the client on a shared responsibility model where the provider is accountable for the security and availability of its platform, and the client is accountable for what they build and configure on top of it, their access controls, their data, and their backups.
The model is reasonable and well documented, but when read from a plant, the gap between both responsibilities becomes visible, because the continuity of the manufacturing process depends on the combination of both elements plus the network that connects them, and no one guarantees that unless it has been explicitly engineered.
The service level agreement figures contribute to that false sense of security. A 99.9% availability allows for nearly nine hours of downtime per year within contract, and whoever suffers them does not get to choose when they hit the production schedule. The standard compensation for breach of contract is calculated based on the service fee and not on the hourly cost of an idle production line, which in the Spanish mid-market industry can exceed by several orders of magnitude what is paid for that service in an entire year.
The contract is designed to protect the commercial relationship, whereas plant continuity requires the tools addressed in the third installment.
Third parties, fourth parties, and concentration risk
Dependency, moreover, is almost never single-tiered. The traceability platform contracted by the factory runs, in turn, on one of the major infrastructure providers; the machinery manufacturer provides its remote support from a third-party platform and a different jurisdiction; and the integrator that maintains the MES subcontracts its own infrastructure.
When an organization maps out its actual dependencies, it usually discovers that behind each direct provider there are two or three indirect ones it has never heard of and with which it holds no contractual relationship whatsoever.
At a national scale, that chain also converges toward very few names. A substantial share of the digital services used by European industry rests on a handful of infrastructure platforms, and that concentration turns an incident at a single provider into a potentially systemic event, as demonstrated by the October 2025 outage without any attacker involved.
Under these conditions, resilience behaves like a shared ecosystem property rather than an individual attribute of each organization, and it is governed with visibility across the entire chain.
Sovereignty and reversibility, the exit questions
The debate over technological sovereignty is usually framed in geopolitical terms, but for an industrial management team, it translates into very grounded questions. Where process data physically resides and under which jurisdiction, which legislation governs an access request from a third country, what happens to historical information if the provider changes ownership or terms, and how much it would cost to leave.
The reversibility of a service, understood as the ability to recover data in a usable format and replace the function within an acceptable timeframe, is negotiated with peace of mind before signing and with great difficulty after five years of accumulated dependency. In most cases, a better-negotiated contract and a written exit plan are enough to turn that dependency into a reversible decision.
The digital supply chain enters the agenda
None of this happens in a regulatory vacuum anymore. The European cybersecurity framework, with the NIS2 directive as its centerpiece, requires essential and important entities to manage supply chain risk, and that obligation is cascading downstream through contractual channels. Questionnaires to industrial suppliers, incident notification clauses, and evidence requirements are already circulating throughout the Spanish productive fabric, regardless of whether the supplier falls directly within the scope of the regulation or not
Five questions for an industrial management team
In closing, there are five questions that any executive committee should be able to answer without calling an extraordinary meeting.
-
-
Which external services does production depend on today, specifically by name?
-
How long can each critical process operate without each one of them?
-
Who would find out about that outage first, and how much advance notice would the provider give according to the contract?
-
When was the last time the recovery of data held by third parties was tested?
-
What would it cost, in time and money, to replace the most critical provider on the list?
-
Organizations capable of answering all five remain a minority, and the third installment will focus on the capabilities that make it possible to move from intuition to a documented response.
Maribel Perozo
Business Development Manager at Aire, member of the Industrial Cybersecurity Center community.