
More than 60 percent of UK companies depend on cloud services for critical business functions, and that figure climbs above 80 percent among FTSE 100 firms, according to a new report from the Cyber Monitoring Centre, a nonprofit focused on systemic digital risk. The report, titled The Cost of Downtime: UK Exposure to Cloud Infrastructure Failure, argues that this concentration of dependence has turned cloud infrastructure into a potential single point of failure for the broader British economy.
The Numbers Behind the Risk
The research singles out two Amazon Web Services regions as the largest aggregation points for potential disruption to UK businesses: the European region in Dublin (eu-west-1) and the primary US region in Northern Virginia (us-east-1). Researchers estimate that a 24-hour outage in the Dublin region could result in revenue losses of £1 billion for affected UK firms, while a comparable outage in the Virginia region could cost around £650 million. Critically, those figures cover only the direct users of those cloud services and do not account for downstream supply chain impacts.
The report notes that 80 percent of UK cloud-dependent businesses rely on one or more of the three dominant providers: AWS, Microsoft Azure, and Google Cloud. Half of FTSE 100 companies are concentrated in UK and Ireland cloud regions, while smaller businesses tend to lean even more heavily on those same regional deployments.
Multi-Region Strategies Are Not a Full Fix
Many organizations believe that deploying workloads across multiple cloud regions protects them from outages. The report cautions that this assumption can be misleading. Even firms with multi-region architectures may retain hidden dependencies on a single region if core platform services route through it.
That concern is not hypothetical. An October outage in AWS us-east-1, triggered by a flaw in the DNS management system for DynamoDB, caused failures across dependent AWS services. The disruption spread beyond the US, affecting Lloyds Banking Group and UK government services among others. AWS stated at the time that it would look for additional ways to avoid a similar event and reduce recovery time.
The report also warns that multi-cloud strategies do not automatically eliminate risk. Companies using several providers often still concentrate their most critical workloads in a small number of regions, creating complexity without meaningfully distributing exposure.
Calls for Coordinated Action
Cyber Monitoring Centre CEO Will Mayes framed the issue as one requiring systemic responses rather than individual company decisions. “This concentration creates systemic vulnerabilities that require coordinated action from companies, insurers, regulators, and policymakers to manage effectively,” he said. “This isn’t about stepping back from the cloud; it’s about recognizing that cloud is now part of our critical infrastructure and designing, governing, and investing accordingly.”
The report highlights a related visibility problem: many businesses lack a clear picture of which providers and regions they depend on, and which revenue streams are exposed if those services go down. Addressing that gap is identified as a priority step before any broader risk management strategy can be effective.
Insurance provider Parametrix contributed to the research, drawing on its monitoring network covering the performance and availability of critical digital infrastructure. The findings arrive alongside broader concerns about UK public sector reliance on US cloud operators, including questions raised by the US CLOUD Act and the political risks that dependency carries.