Is It Time to Challenge the Cloud-First Mindset?
Digital Sovereignty in an Age of Outages
By Andy James, CEO, Custodian360
Over the past decade, “cloud-first” stopped being a strategy and became a doctrine.
Boards echo it. Vendors push it. Consultants swear by it, and many businesses, especially SMEs, accepted it as unquestionable truth.
But truth demands scrutiny. And in 2025, scrutiny is long overdue.
This is where the uncomfortable reality comes in that the industry keeps glossing over:
If you do not know where your data lives, who controls it, or what risk you inherit…
you don’t own your infrastructure, someone else does.
After the AWS and Azure outages last month, that truth is no longer inconvenient.
It is unavoidable.
Cloud-First: A Great Idea… Until It Isn’t
If we are totally honest, the cloud-first movement was not born out of ignorance. It delivered real, measurable value:
- Low upfront costs
- Faster deployments
- Easy scalability
- Global accessibility
- “Built-in” resilience
Cloud-first made sense. It still makes sense in many areas.
But somewhere along the way, cloud-first turned into cloud-only, and that’s where the cracks began to show.
The Outages No One Wants to Talk About
In October, Azure went down because of a configuration issue tied to DNS.
Hours of global disruption. Productivity tools offline. Airport systems affected. No fallback.
A week earlier, AWS suffered a control-plane software bug that caused mass downtime across thousands of services, retailers, platforms and business-critical operations.
Both outages lasted mere hours, but the impact will be felt for years.
Because they exposed the dirty secret of cloud-first:
➡️ Your redundancy is only as strong as your provider’s weakest moment.
➡️ Your backup may fail at the exact same time as your production environment.
➡️ Your “resilience” is still someone else’s infrastructure.
When everyone builds on the same two hyperscale clouds, systemic risk is not theoretical, it is engineered.
Digital Sovereignty: We Are Losing It Without Even Realising
We talk endlessly about data security, availability, encryption, governance…
but very few leaders can confidently answer questions like:
- Exactly where does your data live today?
- Who has legal jurisdiction over it at 3am during a critical incident?
- How many third parties, and AI models, touched it before you saw it?
- If AWS London fails, does your “backup” exist inside the same blast radius?
This is digital sovereignty.
And too many UK organisations have surrendered it, quietly, gradually, conveniently.
Hyperscale Clouds Are Now a Single Point of Global Failure
As AWS, Azure, and GCP centralise the world’s infrastructure, they create irresistible targets.
Attackers know it. Researchers know it. The industry knows it.
Recent research shows:
- 62% of organisations have vulnerable AI packages running inside their cloud estate
- Newly discovered vulnerabilities in hyperscale environments are rising every year
- Ransomware-as-a-Service is optimised specifically for cloud-first businesses
We have built the world’s digital economy on shared compute, shared routing, shared identity stacks, shared AI workloads and shared platform dependencies.
A cyberattack on a single hyperscaler is not a “company outage.”
It is a national resilience crisis.
We treat cloud platforms like utilities, always on, always there.
But utilities are regulated, diversified, backed by national infrastructure planning.
Cloud is not.
We Must Ask the Question No Vendor Wants to Hear:
Should We Still Default to Cloud-First?
Not abandon. Not reject.
But challenge.
Because a strategy becomes dangerous when it becomes unquestioned.
Blind cloud-first adoption creates:
- Vendor lock-in with no clear exit
- Single points of failure disguised as resilience
- Increased regulatory exposure
- Loss of visibility and control
- Risk of simultaneous production + backup failure
- Dependency on someone else’s crisis management timeline
When the outage hits, the glossy cloud marketing does not matter.
The bill afterwards does.
There Are Alternatives — We Just Stopped Talking About Them
It’s time to bring back balance and technical sovereignty:
On-Premises
Full control. Predictable cost. Zero shared risk.
Colocation
Your hardware, professional hosting environment, stable costs.
Bare Metal
Performance, isolation, and reduced blast radius.
Edge / Fog / Mesh
Local-first processing, ultra-resilient, minimal central dependency.
Hybrid & Multi-Cloud
Diversification, redundancy, vendor independence, true resilience.
We do not need to swing the pendulum away from cloud.
We need to stop pretending cloud is infallible.
The Path Forward: A New Digital Contract
Cloud-first got us here.
Cloud-smart, cloud-resilient, sovereignty-first must take us forward.
Here are my thoughts on this:
1. Every organisation must know exactly where their data lives.
No exceptions. No assumptions.
2. Redundancy must exist outside the blast radius of your primary provider.
Backups inside the same hyperscaler are not resilience, they are a hope.
3. Business continuity cannot depend on a single global vendor.
Not for compute. Not for identity. Not for storage. Not for AI.
4. Digital sovereignty must return to the boardroom.
Not as a compliance checkbox, but as a strategic pillar.
5. Leaders must challenge the default mindset.
Cloud-first is not a law. It’s a choice.
And choices should be re-evaluated, especially after failure.
If We Don’t Fix This Now, Outages Will Only Get Bigger
AI-driven threats are escalating.
Multi-tenant platforms are expanding.
More national infrastructure now runs on a handful of cloud providers.
We have created an architecture where one bug can break the internet.
Where one misconfiguration can ground airports.
Where one outage can simultaneously disable your production and your backup.
That is not resilience.
It is fragility at scale.
And ignoring it will never make it safer.
Final Thought
I am not anti-cloud.
I am pro-control, pro-resilience, and pro-accountability.
The cloud-first movement changed the world, and that deserves respect.
But as outages grow, threats evolve, and AI expands the attack surface faster than any security team can keep up.
It is time for leaders to stop treating cloud-first as inevitable, and start treating digital sovereignty as non-negotiable.
Because if your business does not know where its data lives,
it does not know where its risks live either.
— Andy James
CEO, Custodian360