Group Purchasing
Group Purchasing

Resiliency and Business Continuity in the Cloud Era

Resiliency and Business Continuity in the Cloud Era (PDF, 1.83MB)Published: 21 May, 2025
Created by:

Thank You To Our Sponsor

Resiliency and Business Continuity in the Cloud Era, published by SANS Institute in May 2025, examines the disaster recovery and business continuity risks organizations face as cybersecurity controls move to the cloud. The white paper draws on recent cloud provider outages, industry statistics, and regulatory frameworks to outline how organizations can build resilient, multicloud security strategies that hold up when cloud services fail.

Key findings:

  • 99% of cloud security failures will result from human error through 2025, according to Gartner
  • 93% of enterprises report downtime costs exceeding $300,000 per hour
  • Approximately 90% of cybersecurity risks remained uninsured as of late 2022
  • 47% of all data breaches targeted cloud-based systems in 2025, a 5% increase from the previous year
  • 71% of organizations cite data loss and leakage as a primary concern with cloud services
  • The Microsoft Azure OpenAI service outage in July 2024 lasted over 20 hours across multiple regions
  • The AWS Kinesis service disruption in July 2024 lasted nearly seven hours and disrupted logistics and financial services relying on real-time data streaming
  • The Zscaler outage on October 25, 2022, lasted close to four hours and left many users unprotected from online threats
  • The Cloudflare service interruption on February 6, 2025, lasted 59 minutes and affected services including R2 object storage, Stream, and Images

The paper finds a persistent gap between how much organizations depend on cloud-based security controls and how prepared they are for those controls to fail. Most enterprises lack failover mechanisms, multicloud redundancy, or offline fallback options for critical functions like IAM, threat detection, and secure web gateways, even as the financial and operational cost of downtime continues to climb. Regulatory pressure from frameworks like DORA, NIST 800-53, and CISA's cloud resilience guidance is pushing this from a best practice into a compliance requirement. This white paper synthesizes third-party industry research and documented cloud outages from 2022 through 2025 rather than an original SANS survey. Cited data sources include Gartner, Veritis, Queue-IT, and the Carnegie Endowment for International Peace.

FAQ

Gartner reports that through 2025, 99% of cloud security failures will result from human error, underscoring the need for better training and access controls.

According to polls collated by Queue-IT, 93% of enterprises report downtime costs exceeding $300,000 per hour. 

In 2025, 47% of all data breaches targeted cloud-based systems, a 5% increase over the previous year. 

No — as of late 2022, approximately 90% of cybersecurity risks remained uninsured, highlighting a significant gap in risk management. 

Notable outages include the Zscaler outage in October 2022 (nearly four hours), the AWS Kinesis disruption in July 2024 (nearly seven hours), the Microsoft Azure OpenAI outage in July 2024 (over 20 hours), and the Cloudflare service interruption in February 2025 (59 minutes).

Meet Your Author

Dave Shackleford
Dave Shackleford

Dave Shackleford

Senior Instructor

Cybersecurity leader Dave Shackleford combines decades of enterprise defense, cloud security, and hands-on consulting experience to help students master real-world security operations and modern threat defense.

Read more about Dave Shackleford