(Image credit: bogitw/Pixabay.)
The future, as William Gibson said, is already here but not evenly distributed. That places significant pressure on organizations as they prepare for what comes next in a rapidly changing business climate, even as they manage the complexities of existing environments in a highly regulated insurance industry.
New technologies can be terrific, but they can also introduce new risks along with new takes on old ones. On a recent Monday morning while on holiday in Venice, I woke to the news of an AWS outage broadly impacting business services across many geographies. It was very reminiscent of a day last year when my morning newsfeed in Scotland highlighted the CrowdStrike event which paralyzed many for a time. News reports in Europe, which was impacted during business hours, highlighted just how far-reaching the consequences of this outage were.
By noon in Italy, or 6 a.m. in New York, it appeared that services were recovering. That said, however, it once again highlights how the whole nature of disaster recovery and business continuity have fundamentally changed in the era of cloud computing. While a cloud service provider likely has better overall availability than most companies can deliver on their own—and this availability has dramatically changed what DR/BC plans include—the reality is that when things go wrong, they can do so in spectacular fashion.
Evolving Risks in a Concentrated Cloud Ecosystem
For insurance carrier CIOs and their IT organizations, this once again highlights the new challenges that can come with emerging technologies. There’s nothing to indicate this was a cyber event, and recovery seemed to move quickly, allowing services to gradually return to normal as the day unfolded in the United States. Throughout the day, however, my own email feed was filled with reported outages and slowdowns as insurance ecosystem vendors brought capabilities back online and struggled with the impact of an uneven AWS recovery. This was not an “instant on” moment, making it reminiscent of what my teams dealt with in recovering our own data centers during difficult times, including the terrorist attack in New York on 9/11/2001. In the end, it appears to have been a DNS error issue that was the root cause of the outage.
But while appreciation for the recovery pace is appropriate, it is still proper to step back and consider new lessons learned from this which can come at a relatively low cost. For example, what would have happened if this had persisted for days instead of hours? What if it had happened at midday instead of midnight for Americans? What if there had been a cyberattack component to it, more reminiscent of the Scattered Spider attacks that were a clear lowlight for 2025?
Vendor Management and the Next Phase of Continuity Planning
Another aspect of this most recent outage that is worth remembering is that there’s a vendor-management angle to consider. As reported by The New York Times, rising cloud computing costs from providers like AWS, Microsoft, and Google have led some companies to revise implementation plans and repatriate some workloads. Even in those instances, however, the reliance on third parties for mission-critical functions can lead to unexpectedly adverse outcomes. The model works surprisingly well when all the components are operating normally. Business-continuity plans need to focus on what happens when they don’t. Procurement functions need to focus on avoiding unnecessary risks. Low price may not really mean “best solution.”
This also highlighted how much power has been concentrated in the hands of a very small number of companies—and how fragile the system can be when problems emerge. Which is yet another reminder of the wisdom shared by President Kennedy in 1962: the best time to fix your roof is when the sun is shining. The good news is that we have all been forewarned.
Planning Ahead, While the Sun Is Still Shining
While having mostly dodged major issues this time, the operative phrase is “this time.” This all represents one more thing to bake into 2026 budgets and plans. As every CIO knows, there are no dull moments. Ever.
And my being out of the country for both of these events? Correlated but not causal. Perhaps something I will bake into my own future vacation planning.


