Internet down — the cloudy lessons from Azure and AWS outages

Nearly 10 years ago, CIO influencer Brian Greenberg infamously said that “there is no cloud, it’s just someone else’s computer”. This week, millions have been questioning the wisdom of putting all their computing eggs in that one basket.

The latest outage, impacting the Microsoft Azure cloud platform, was, Microsoft has confirmed, due to Domain Name Server (DNS) issues. I, dear reader, was not surprised: it’s always DNS.

It was DNS that went down last week when Amazon Web Services (AWS) suffered a massive outage and took large swathes of the internet with it.

Not all incidents are cyber attacks, but the consequences can be similar in terms of downtime, loss of service, loss of revenue – and the inevitable impact on brand reputation.

So, what lessons must we learn from this week of DNS disasters? What’s the cloudy takeaway that we simply cannot ignore any longer? That, as with any security strategy, a single point of failure is a very bad thing.

“As if we needed reminding, this is further proof that relying on a handful of major cloud providers creates serious vulnerabilities across the internet and puts whole economies at risk in the process,” Raphael Auphan, COO at Proton, told TechFinitive.

“The only answer for the UK, Europe and elsewhere is to prioritize digital sovereignty, in other words, to develop their own native services.”

Plan for disaster

I’m not sure I’d go quite that far, but the eggs in one basket argument cannot be ignored when it comes to cloud service reliance.

As Mark Odom, Senior Solutions Engineer, Black Duck, told me: “Important services should use automatic failover to ensure business continuity in the event that their providers experience an outage.”

In other words, it’s your disaster recovery plan, stoopid. These need to be both fluid and dynamic if we are to deal with what could be an increasingly significant issue such as this.

Finally, I spoke to Graeme Stewart, Head of Public Sector at Check Point. “While [the Microsoft Azure outage] appears to be a configuration fault rather than a cyber attack, incidents like this highlight how fragile our online infrastructure really is.”

Vigilance is key, Stewart continued: “Outages are often exploited by scammers sending fake update or security messages. For organisations, this is a reminder to stress test systems, diversify providers and ensure offline continuity plans are ready before the next disruption hits.”

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.