Considering cloud downtime insurance?

Issue 7 2022 Information Security, Infrastructure, Security Services & Risk Management

Cloud downtime insurance has taken off in recent years, and with good reason. Downtime insurance providers cover clients for short-term cloud outages, network crashes and platform failures that last up to 24 hours. And they happen often.


Byron Horn-Botha.

Cloud insurance provider Parametrix notes that, on average, one of the three major public cloud providers – Microsoft Azure, AWS and Google Cloud – has an outage lasting at least 30 minutes every three weeks.

As cloud computing becomes ubiquitous, more companies are exposed to incidents that cause downtime, which can be disastrous. Gartner cites the average cost of IT downtime at a staggering $5600 a minute. Let’s also factor in the additional costs that don’t necessarily show up as monetary losses, such as the cost of an interruption that pulls IT people away from their regular work to get your company back up and running.

It is one reason why cloud downtime insurance can be a helpful safety net for businesses, but it is not a complete solution. It’s important to remember that this kind of insurance can’t guarantee that your business remains in operation during a period of downtime. Whilst it will cover any short-term losses you incur, it will not cover the loss of goodwill, damage to your brand reputation, and loss of customer loyalty when your business can’t deliver.

So, the bottom line is that instead of placing 100% reliance on cloud downtime insurance, businesses need to put strategies in place if they are to weather the cloud downtime storm and other unexpected events.

1: Have a sound recovery plan

Think your data is safe and secure when you move it to a cloud provider? Think again. Last year, a fire at the data centre of French web hosting service OVHcloud (Europe’s largest cloud provider) caused the loss of massive amounts of customer data. It impacted government agencies, e-commerce companies and banks, to name just some entities.

Backing up your data to the cloud or on-premise is a critical and cost-effective first step in any disaster recovery plan – but this is only the beginning. It would help if you also had a plan to recover your data in an emergency quickly. You must also test your recovery plan often. You should simulate disruptions and see how well your recovery plan works. You should also regularly test your backup images and address any problems.

2: Implement your backup and recovery solution

Cloud security is not solely the responsibility of your cloud provider. It’s your responsibility as well. Cloud providers usually promise to secure their infrastructure and services. But securing operating systems, platforms and data is your responsibility. Read the small print.

Cloud providers will not guarantee the safety of your data. No matter what cloud platform you use, the data is still owned by you, not the provider. Many cloud providers recommend that their customers use third-party software to protect their data.

You can comprehensively secure your data with a reliable cloud backup and recovery solution. You can also get the control you need. You should implement a cloud backup and recovery solution that protects your data by automatically backing up your information every 15 minutes, giving you multiple recovery points. It also guarantees that your data is continuously protected while providing quick access and visibility 24/7.

3: Be proactive: be data resilient

A lot of companies don’t test their data recovery plans. Many don’t even have a recovery plan, which is very short-sighted. It is crucial to be proactive, not reactive, and, above all, data-resilient.

A data resilience strategy ensures business continuity in the event of a disruption. It is built on recovery point objectives (RPOs) and recovery time objectives (RTOs), and you should regularly test to guarantee that the RPOs and RTOs can be achieved.

Your RPO determines your backup frequency. In essence, it’s your tolerance for data loss. Some organisations can tolerate a data loss of 24 hours, so they back up their data every 24 hours. Their RPO is 24. Other businesses, such as those in finance and healthcare, absolutely cannot tolerate a data loss of 24 hours. Their RPOs are set to milliseconds.

Your RTO measures the downtime you can accept between a data loss and recovery. It’s how long you can be down before your business incurs severe damages. Your RTO determines your disaster recovery plan investment. If your RTO is one hour, you need to invest in solutions that get you back up and running within that hour.

Establishing your RPO and RTO, and then implementing the solutions you need to achieve them, are the keys to data resilience.

Final takeaway

We live in a world of growing cybersecurity threats, more frequent natural disasters, and black swan events arriving in flocks. Every day, organisations are brought to their knees out of the blue. That’s why more of them are purchasing cloud downtime insurance. But it is critical to understand that this type of insurance alone does not constitute a data protection plan. It is best viewed as an accessory to your backup and recovery efforts. Never consider it a replacement.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Upgrade your PCs to improve security
Information Security Infrastructure
Truly secure technology today must be designed to detect and address unusual activity as it happens, wherever it happens, right down to the BIOS and silicon levels.

Read more...
Open source code can also be open risk
Information Security Infrastructure
Software development has changed significantly over the years, and today, open-source code increasingly forms the foundation of modern applications, with surveys indicating that 60 – 90% of the average application's code base consists of open-source components.

Read more...
DeepSneak deception
Information Security News & Events
Kaspersky Global Research & Analysis researchers have discovered a new malicious campaign which is distributing a Trojan through a fake DeepSeek-R1 Large Language Model (LLM) app for PCs.

Read more...
Fastest PCIe Gen 5.0 NVMe SSD
Products & Solutions Infrastructure
Sandisk has unveiled the WD_BLACK SN8100 NVMe SSD with PCIe Gen 5.0 technology, an internal SSD delivering speeds up to 14 900 MB/s and capacities up to 4 TB, with 8 TB solutions available soon.

Read more...
SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...
Unified storage solution
Products & Solutions Infrastructure
CASA Software has announced the local availability of Nexsan’s upgraded unified storage solution, Unity NV4000, which is ideal for mixed workloads, from virtualisation and video surveillance to secure backup and recovery.

Read more...
Almost 50% of companies choose to pay the ransom
News & Events Information Security
This year’s Sophos State of Ransomware 2025 report found that nearly 50% of companies paid the ransom to get their data back, the second-highest rate of ransom payment for ransom demands in six years.

Read more...
Survey highlights cost of cyberdamage to industrial companies
Kaspersky Information Security News & Events
The majority of industrial organisations estimate their financial losses caused by cyberattacks to be over $1 million, while almost one in four report losses exceeding $5 million, and for some, it surpasses $10 million.

Read more...
Digital economy needs an agile approach to cybersecurity
Information Security News & Events
South Africa is the most targeted country in Africa when it comes to infostealer and ransomware attacks. Being at the forefront of the continent’s digital transformation puts South Africa in the crosshairs for sophisticated cyberattacks

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.