Cloud concentration risk: what October 2025 taught SMEs
Cloud and SaaS adoption solved scale and convenience for smaller organisations. But when identity, storage, collaboration, backup and recovery all depend on a handful of external providers, a single disruption can stop operations. October 2025 made that abstract risk concrete — twice, in nine days.
Two outages, nine days apart
On 20 October 2025, a fault in an AWS US-EAST-1 subsystem took down a long list of consumer and business services and public systems for hours. Nine days later, on 29 October, a configuration error in Azure Front Door cascaded globally — and critically, it disrupted Entra (Azure AD) token issuance, meaning authentication itself failed. Sites and apps that were otherwise healthy could not sign users in.
Neither was the first. The CrowdStrike update in July 2024 had already grounded flights and reverted hospitals to paper. The pattern is consistent: one provider, one change, a wide blast radius. For a smaller organisation with no independent path, the only option during these windows is to wait.
What concentration risk actually is
Concentration risk is not an argument against the cloud — the cloud delivers real scale and convenience. It is the observation that cloud-only architecture stacks several critical dependencies onto the same few suppliers. When storage, identity, collaboration and recovery share a provider, that provider becomes a single point of failure for the whole operation. The October events were notable precisely because one of them removed authentication, the control that gates access to everything else.
For regulated organisations this is no longer just an operational worry. DORA requires financial entities to manage ICT third-party risk and document an exit strategy; NIS2 imposes duty-of-care obligations and personal accountability; the EU Data Act gives customers a right to switch providers — or move to their own infrastructure — without lock-in. Continuity has moved from good practice to a scored, sometimes statutory, requirement.
The missing layer: an independent recovery path
The fix is not to abandon the tools that work. It is to add a customer-controlled continuity layer alongside them, so that critical files and workflows stay accessible when an external provider, identity service or SaaS account is disrupted. In practice that means a few concrete capabilities:
- An independent local restore path for critical data
- A local copy of records that does not depend on a single SaaS backup
- A fallback for authentication during identity-provider disruption
- Secure, auditable file exchange that survives provider outages
- A documented, testable exit and recovery strategy
This is the role OC Zeus is built for: a managed edge-continuity appliance that keeps storage, exchange, backup and recovery under customer control, working alongside Microsoft 365, Google Workspace and the rest of your stack — not replacing them. The goal is simple: turn a provider outage from a shutdown into a disruption you can ride out.
Score your own concentration risk
We'll walk your workflows, compliance scope and current setup, and map a customer-controlled recovery path that fits what you already run.