Group Purchasing
Group Purchasing

Resiliency and Business Continuity in the Cloud Era

Resiliency and Business Continuity in the Cloud Era (PDF, 1.83MB)Published: 21 May, 2025
Created by:

Thank You To Our Sponsor

Resiliency and Business Continuity in the Cloud Era, published by SANS Institute in May 2025, examines the disaster recovery and business continuity risks organizations face as cybersecurity controls move to the cloud. The white paper draws on recent cloud provider outages, industry statistics, and regulatory frameworks to outline how organizations can build resilient, multicloud security strategies that hold up when cloud services fail.

Key findings:

  • 99% of cloud security failures will result from human error through 2025, according to Gartner
  • 93% of enterprises report downtime costs exceeding $300,000 per hour
  • Approximately 90% of cybersecurity risks remained uninsured as of late 2022
  • 47% of all data breaches targeted cloud-based systems in 2025, a 5% increase from the previous year
  • 71% of organizations cite data loss and leakage as a primary concern with cloud services
  • The Microsoft Azure OpenAI service outage in July 2024 lasted over 20 hours across multiple regions
  • The AWS Kinesis service disruption in July 2024 lasted nearly seven hours and disrupted logistics and financial services relying on real-time data streaming
  • The Zscaler outage on October 25, 2022, lasted close to four hours and left many users unprotected from online threats
  • The Cloudflare service interruption on February 6, 2025, lasted 59 minutes and affected services including R2 object storage, Stream, and Images

The paper finds a persistent gap between how much organizations depend on cloud-based security controls and how prepared they are for those controls to fail. Most enterprises lack failover mechanisms, multicloud redundancy, or offline fallback options for critical functions like IAM, threat detection, and secure web gateways, even as the financial and operational cost of downtime continues to climb. Regulatory pressure from frameworks like DORA, NIST 800-53, and CISA's cloud resilience guidance is pushing this from a best practice into a compliance requirement. This white paper synthesizes third-party industry research and documented cloud outages from 2022 through 2025 rather than an original SANS survey. Cited data sources include Gartner, Veritis, Queue-IT, and the Carnegie Endowment for International Peace.

FAQ

Meet Your Author

Dave Shackleford
Dave Shackleford

Dave Shackleford

Senior Instructor

Cybersecurity leader Dave Shackleford combines decades of enterprise defense, cloud security, and hands-on consulting experience to help students master real-world security operations and modern threat defense.

Read more about Dave Shackleford