top of page
  • Writer's pictureAmri Tarsis

Is Cloud Outage Insurable ?



Yes, Cloud providers invest heavily in best-in-class infrastructure to improve availability and ensure their customers have the best experience with minimal disruption. According to the Datacenter Annual Outage Analysis 2024 by Uptime Institute, they have observed a "downward trend in the frequency and severity of outages relative to the overall growth in IT" in 2023. However, the Crowdstrike outage incident in July 2024 makes us think about the risk of a massive Cloud outage and how to get protected against it. This article reviews data about cloud providers' outages, mitigation strategies, and insurance options.


In the same report, Uptime Institute highlights that only 4% of the data center outages were severe among the companies researched, with root causes varying from Power outages (the majority) to informational security (less probable). Analyzing data centers provides a good insight into the risks of operating such technology infrastructure and the risks any Cloud Provider may face. On the other hand, ThousandEyes, a Cisco company, in "The Internet Outage Survival Guide" eBook, describes a different perspective of outages, looking at those incidents comprehensively. ThousandEyes tracks the internet traffic from point A to point B to detect the causes of service unavailability and explain the cause of any internet downtime from a SaaS provider to a Cloud Provider. One of the threats cloud providers face, for example, that may cause interruption of services is a cyber attack called DDoS, which is "a deliberate attempt to take the services offline or deny legitimate users access to a service by overwhelming it with a large number of requests simultaneously." According to the same research, this was the explanation for making Wikipedia unavailable for more than 9 hours in 2019.


Why should cloud downtime be a concern?


According to the Insurance company Parametrix, in the Cloud Outage Risk Report 2023, Amazon AWS us-east-1 region concentrates many Fortune 500 companies relying on Cloud for different services. They estimate that a 24-hour outage could cause 3.4 Billion dollars in losses.


When analyzing Cloud downtime in specific, Parametrix has observed an increase in Cloud downtime despite the downward trends for data centers reported by Uptime Institute. Critical severity increased from 29 to 40 events, with six outages worldwide over 10 hours.


Two Notable Cloud Outage Incidents in 2023


Several significant cloud outages have been observed in recent years, underscoring the vulnerability of even the most robust cloud providers,


AWS Outage | June 13, 2023 (Source: ThousandEyes)


"On June 13, Amazon Web Services (AWS) experienced a more than two-hour incident that impacted a number of services in the US-EAST-1 region. The disruption was observed around 6:50 PM (UTC) and appeared mostly resolved by 8:40 PM (UTC). ThousandEyes observed an increase in latency, server timeouts, and HTTP server errors impacting the availability of applications hosted within AWS"


Google Cloud | April 23, 2023(Source : Parametrix)


"Google Cloud's Paris region (europe-west9) went offline for about a day. Durations differed for each service, each with its recovery process. Parametrix monitoring detected errors in all zones within the region. The root cause was a fire in a battery room resulting in a water leak."


How Cloud downtime can impact your company?


Cloud downtime occurs when cloud services become unavailable, preventing businesses from accessing their data and applications. Such outages can have far-reaching consequences, including:


  1. Operational Disruption: Critical business operations can stop, affecting everything from customer service to internal processes.

  2. Financial Losses: The inability to conduct business during downtime can result in lost revenue, missed opportunities, and potential penalties for failing to meet contractual obligations.

  3. Reputational Damage: Customers expect reliability. Frequent or prolonged outages can erode trust and damage a company's reputation.

  4. Data Loss and Security Risks: Downtime can lead to data loss or expose vulnerabilities that cybercriminals might exploit.


Cloud Provider's Liability and Compensation for Unavailability


The standard customer service agreement with Cloud Providers includes clauses like "Hold Harmless" and "Limitations of Liability," releasing the Cloud Provider for any consequence that a cloud downtime may cause in your operations, such as losses related to business interruption. Some Cloud Providers offer a 100% Credit for the amount they charge you if the system is available less than 95% of the time, but this amount may be far from the losses you may experience with a Cloud downtime.


How do you calculate your company's risk for a Cloud downtime?


Understanding your assets hosted by the cloud providers and the potential loss magnitude of cloud downtime is a starting point for decomposing the risk and adequately estimating it with higher accuracy. Suppose your company heavily relies on Cloud providers to operate daily with high monetization associated to the cloud services, for example a eCommerce operations. In that case, you should consider contingencies such as redundancy, including a multi-cloud strategy to be supported by more than one Cloud Provider, as well as have a business continuity plan to potentially operate even without the availability of the Cloud Provider.


Is Cloud downtime Insurable ?


As previously discussed, a DDoS Cyberattack trying to disrupt specific services may affect more than one Cloud Provider, which doesn't eliminate the risk of an outage with the redundancy approach. To transfer the residual risk of an outage, Parametrix Insurance has a unique solution offering Cloud Downtime insurance. Different from traditional insurance, which is designed to recover losses, Parametrix, as the name suggests, is a "parametric" insurance, which means that once AWS, Google, or Azure is offline, you receive the coverage. You have the freedom to use it to recover business interruption losses or to pay your customers in connection with any SLA you have to commit and have failed to do so because of the unavailability of the Cloud Provider.


Learn more about Cloud Downtime Insurance : https://www.zyberinsurance.com/cloud-downtime-insurance


Sources :

Annual Outage Analysis 2024 - Uptime Institute

The Internet Outage Survival Guide eBook - ThousandEyes (Cisco)

Cloud Outage Risk Report 2023 - Parametrix Insurance



26 views

Comments


bottom of page