advanced 1 min answer Multiple choice

Concentration on one cloud provider is a recognised risk. Is multi-cloud the answer?

concentration-riskmulti-cloudexitresiliencecloud
Pick one
Show the full answer Hide the answer

Why uniform multi-cloud usually fails as a response

Running everything on two providers means using the lowest common denominator of both — no managed services with meaningful differences, abstraction layers that add complexity and their own failure modes, and two platforms to operate, secure and staff.

The complexity introduced frequently causes more incidents than the concentration risk it mitigates. And the mitigation is often illusory: teams run on two providers with an active-passive design whose failover has never been exercised, which is a documented capability rather than a real one.

What actually reduces the risk

  • A tested exit plan for critical services, with the extraction and rebuild path exercised at least once. An untested plan is an assumption.
  • Criticality tiering, so the expensive treatment applies to the small set of services where an extended provider outage would be existential.
  • Data portability, which is the part that matters most and is usually achievable — compute can be rebuilt, data cannot be recreated.
  • Avoiding gratuitous lock-in in the places where the cost of avoiding it is low, while deliberately accepting it where a managed service delivers real value.
  • Multi-region within a provider, which addresses most realistic availability scenarios at a fraction of the cost of multi-provider.

The honest framing

Concentration risk is primarily about the provider failing as a business or as a relationship, not about an outage. Outages are addressed by multi-region. The concentration concern is a supervisor's concern about systemic dependence, and it is answered by demonstrable exit capability rather than by parallel operation.