Ben Farrell shared the latest CIPS Pulse Survey this week and gave his LinkedIn community a closer look at what it found. It is worth reading in full. A few messages came through clearly: supply-chain anxiety sitting near the highest levels CIPS has ever recorded; geopolitics — conflict in the Middle East, and a renewed rise in concern over Ukraine — as the defining risk; nearly 80% of respondents concerned about cyber attacks across their supply chains; organizations redesigning their networks by diversifying suppliers, extending strategic partnerships, and holding more inventory; and tariffs now shaping procurement planning for a third of organizations, with a further 37% actively monitoring. Dr. John Glen, CIPS’s Chief Economist, summed the findings up as an economy still vulnerable to stagflationary pressure: weak confidence, elevated costs, and persistent geopolitical risk.
It is a sobering snapshot, and an accurate one. I want to add something to it — not a competing view, but a longer lens.
Because when I read those five findings, I do not see five separate risks. I see five strands of one pattern.
Five strands, one pattern
I have written for years about something I call Strand Commonality™ — the idea that seemingly unrelated disruptions are rarely isolated. They share underlying strands: concentrated dependencies, ungoverned relationships, points of fragility that reappear again and again wearing different costumes. The sources of disruption rotate — a pandemic, a war, a cyber breach, a tariff, a fire at a single plant. The structure underneath them does not.
That distinction changes what resilience means. If disruption is now the operating environment rather than the exception — which is exactly what the Pulse survey reports — then resilience can no longer be measured only by how fast you respond to the shock in front of you. It has to be measured by how well your operating model holds as the source of the shock keeps changing.
Here is what I mean, finding by finding — with the contemporaneous record for each. The point is not that any single one was predicted. The point is that the pattern has been legible for a long time.
1. “A new normal” — permanent disruption
The survey’s headline is that disruption has become constant rather than exceptional.
That was already the argument in 2009, in a post examining what a global pandemic would do to supply chains. The illustration then was a small, low-cost component whose shortage could paralyze a large share of Japanese auto production — a tiny dependency with an outsized blast radius — set against a McKinsey survey showing supply-chain risk rising sharply while companies under-invested in mitigating it. The specific threat that year was a pandemic. The structural lesson — that concentrated dependencies turn small events into large ones — was already the real story, and it had nothing to do with the particular shock.
2. Geopolitics as the defining risk
The survey names geopolitics — the Middle East, and a renewed rise in Ukraine concern — as the biggest risk.
In 2022, I wrote about a Rotax engine, built by a Canadian-owned company, found in an Iranian-made drone Russia was using over Ukraine. The question that post asked was not a geopolitical one. It was a procurement one: how deep into the supply chain does procurement’s responsibility extend? Geopolitical risk, in other words, doesn’t arrive as foreign policy. It arrives as a traceability-and-governance problem several tiers down the supply chain — which is precisely where procurement lives, and precisely where it is hardest to see.
3. Cyber
Nearly 80% of respondents flagged cyber attacks across their supply chains.
I have been writing about one specific angle of this — procurement as the enterprise’s biggest cyber gateway — for a long time, most recently in a 2024 post that itself reaches back to a 2010 interview I did with cybersecurity expert Richard Stiennon. The through-line across those fourteen years is simple and unfashionable: the breach rarely enters through the firewall. It enters through a supplier relationship no one was governing. Third-party risk is the “us” in the old Pogo line — we have met the enemy, and he is us. The tooling changes every few years. The ungoverned-relationship gap does not.
4. Redesigning the network — diversification and single-source risk
The survey reports organizations diversifying suppliers, extending partnerships, and holding more inventory.
The cleanest illustration of why is more than a decade old, and it remains the most-read article I have ever published: the Nokia-Ericsson case study. When a 2000 fire at a Philips chip plant contaminated both companies’ chip supply, Ericsson accepted the supplier’s one-week estimate, took no action, and lost roughly $400 million and lasting market share. Nokia had diversified, re-engineered its phones to accept alternate chips, and moved fast — and its profits rose 42% that year. Same fire. Same supplier. Opposite outcomes. The variable was not the shock. It was whether the operating model had built in the ability to absorb it. That the post remains my most-read, fifteen years on, tells you the lesson is enduring, not new.
5. Tariffs
A third of organizations say tariffs are already affecting their planning; another 37% are watching closely.
In 2025 I published “100 Years of Tariffs and Supply Chains,” which sits on top of earlier posts from 2009 and 2024 and reaches back to the 1930 Smoot-Hawley Act. The recurring finding across a century is the one that matters here: the tariff is not what determines the damage. The structure of the supply chain when the tariff lands is. Linear, concentrated chains take the full blow. Diversified, buffered ones bend and absorb. Which is the same lesson as the Philips fire, wearing a different costume — a tariff instead of a flame.
What the pattern tells us
Read together, the five findings are not five problems. They are one problem in five forms: concentrated dependency and ungoverned relationship, exposed by whatever this quarter’s shock happens to be. That is what Strand Commonality™ is meant to surface — and it is why the CIPS survey, read as a longitudinal signal rather than only a quarterly one, is so valuable. It is measuring the symptoms rotating across a structure that stays put.
Which brings me to the actionable point, and it is not “predict the next shock.” Nobody can reliably do that, and chasing it is a trap. The durable move is the opposite: stop trying to forecast the source and start hardening the structure — the dependencies, the concentrations, the relationships that every one of these shocks travels through. Build an operating model whose logic holds regardless of which strand lights up next. The headlines will keep changing. The foundations do not.
My thanks to Ben Farrell and the CIPS team for the survey — it is a genuinely valuable read of where the profession’s attention sits right now. What I would offer alongside it is only this: the attention is on five risks; the work is on the one pattern beneath them.
Truth Is Believing. Accuracy Is Knowing. Outcome Is Proof.™
-30-
tcummins
July 9, 2026
Identifying the challenges is one thing: being equipped or having the authority to address them is another. Have you not read our reports on geopolitical disruption? You really should.
piblogger
July 9, 2026
Please send me a copy, Tim.