AWSCIO BriefingsRetrospectives

CIO Brief: Cloud Concentration Risk Is Back on the Board Agenda

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from October 2025, written in 2026 with the benefit of hindsight.

The short version: On October 20, 2025, an AWS outage in its busiest region disrupted banks, airlines, games and smart home devices for most of a day. It was the third major outage in that region in under a decade. Concentration risk in the cloud is a board-level topic again.

Why it keeps happening

Cloud regions are extremely reliable, but not perfectly so. AWS's US-EAST-1 region hosts a huge share of internet services and some AWS-wide functions. Complex automated systems occasionally fail in unexpected ways — and when they do, the impact spreads.

The business impact

  • Revenue loss for customer-facing services.
  • Operational disruption for internal tools, even if your own systems run elsewhere — through SaaS providers that depend on AWS.
  • Regulatory scrutiny in sectors with operational resilience rules (for example, financial services regulations in the EU and UK).

Questions to ask your team

  • Which of our critical services, and which of our critical SaaS providers, depend on a single AWS region?
  • How did the October 2025 outage affect us, and what did we learn?
  • Which services would justify multi-region resilience, and at what cost?
  • When did we last test failover?

What good looks like

A clear map of regional dependencies (including suppliers), funded resilience for the most critical services, tested failover, and documented risk acceptance for the rest.

The decision

Use the October 2025 outage as a prompt: ask for a short report on its impact on your business and costed options for the services that matter most.

aws outage october 2025 impactAWS us-east-1 outage 20252025

More on this story