top of page

Security Blog

Cloud outages: How dependent are SMEs on their IT providers?

  • 2 hours ago
  • 5 min read

The cloud has long been part of the basic infrastructure for many SMEs. Email, accounting, payroll, order processing and entire industry-specific applications no longer necessarily run on a server in the company's own premises, but at specialised providers. In many cases this is practical – and often safer than operating everything in-house.


But recent years have also shown what happens when such a service suddenly becomes unavailable.


Four incidents – four very different consequences


Microsoft 365: On 31 August 2026, Exchange Online was affected by a major outage. Users reported problems accessing mailboxes and sending and receiving email. Heise reported on the incident and referred to Microsoft's incident number EX1464935. For many companies the disruption was relatively short, but it once again showed how quickly an everyday cloud service can become a bottleneck.


Blue Yonder: In November 2024, software provider Blue Yonder was hit by a ransomware attack. Its solutions are used for supply chains, merchandise management, workforce planning and scheduling, among other things. At Starbucks, systems for staff scheduling and time tracking were affected; data required for payroll processing had to be handled partly manually. Reuters reported on the consequences of the attack. For some customers, the effects continued for weeks.


CDK Global: The dependency became even clearer in June 2024 at US provider CDK Global. The industry platform is used by thousands of car dealers for sales, workshops, vehicle inventory, customer data and other business processes. After a cyberattack, key services were severely disrupted for around two weeks. Dealers fell back on paper, Excel, telephone calls and other manual processes. Ars Technica documented the two-week emergency operation and reported more than 15,000 affected dealer locations.


Infoniqa / Sage Switzerland: Switzerland saw a comparable case in 2025. Infoniqa, which had acquired Sage Switzerland in 2021, fell victim to a cyberattack in early August. In Switzerland, the ONE Start Cloud was particularly affected. Heise reported that the cloud solution was unavailable; one reader had reported an outage lasting more than a week. Inside IT later wrote about effects Infoniqa had been dealing with for more than two weeks.


The common denominator: the provider's outage becomes the customer's problem


The four cases differ significantly in cause, duration and affected systems. What they have in common is something else: while the central services were unavailable, customers could no longer perform certain tasks or could only do so with considerable workarounds.


A technical disruption at the provider can therefore very quickly become an operational risk for the customer.


Cloud is still often the right solution for SMEs


This does not mean that SMEs should once again operate all their systems themselves. On the contrary: professional cloud providers can often deliver infrastructure, updates, monitoring, redundancy and security measures better and more economically than a small company with limited IT resources could do on its own.


Cloud solutions are therefore sensible in many cases and can even be safer than a poorly maintained local environment. The key is to understand the resulting dependencies and manage them consciously.


How long can the company do without a service?


Not every system is equally critical. For a trades business, an email outage lasting a few hours or perhaps even several days may be inconvenient but still manageable. Work can continue, customers can be reached by phone and a quotation can be sent later if necessary.


For another company, 24 hours without email may already have serious consequences – for example when important deadlines, time-critical submissions or a large share of customer communication depend on it. In that case, it may make sense to keep a prepared alternative available.


Companies that can do without a service for several days or even longer do not necessarily need an immediately available replacement system. But they should know at what point they want to switch to Plan B – and approximately how long implementing that plan will take.


This second figure is often forgotten: if a replacement system takes five days before it can be used productively, the decision to activate it must not be made only on the fifth day of the outage.


With ERP and industry-specific solutions, every day can count


The situation is different for systems that are filled with new business data every day by many employees. An industry application or ERP continuously accumulates orders, quotations, working hours, invoices, material movements, customer data and payroll information.


Even a single day of downtime can mean that information has to be entered later, processes bridged manually or entire work steps reconstructed afterwards. It is therefore all the more important to know how long such an outage is acceptable and what information must be available for emergency operations.


Business data must remain accessible in the long term


In addition to short-term operational capability, there is a second question: the long-term availability of data. In Switzerland, certain records – including accounting books and accounting vouchers – must be retained for ten years. Electronically stored records must be capable of being made readable at any time during this period. This follows from Art. 958f Swiss Code of Obligations.


So the question “Does our cloud provider have a backup?” is not enough on its own. Companies should also clarify whether their essential business data can be kept available independently of the provider and whether those data can actually be used again in an emergency.


And what if the provider never comes back?


The possibility that a provider can disappear permanently is not purely theoretical. In 2020, Winterthur-based data centre operator Grapin Data Center went bankrupt. Customers had to relocate their systems; at one point there was even a risk that power to the data centre could be cut. Inside IT reported at the time on the short-notice “evacuation” of customer infrastructure.


A company does not even have to go bankrupt for this to happen. RapidShare is an example: the Zug-based file host was once among the world's most visited websites. In 2015, the company decided to discontinue the active service. The remaining accounts were subsequently deleted. Inside IT reported on the end of the Swiss file host.


For the customer, the reason is ultimately secondary. Whether a cyberattack, bankruptcy, strategic withdrawal or another restriction is responsible, what matters is whether the company's own data and processes can continue when the original provider is no longer available.


An independent backup is more than a second copy


For particularly important cloud systems, it can therefore make sense to back up data outside the actual platform as well – for example with an independent third-party provider or on separate infrastructure.


It is not enough merely to check whether a copy exists. Just as important is the format in which the data are available and whether they can be read, analysed or transferred into another solution without the original system.


A backup that can only be restored into the same application that is no longer available provides only limited independence in such a scenario.


Autonomy means knowing your dependencies


A good cloud strategy therefore does not mean avoiding the cloud or duplicating every system. It means understanding a company's dependencies and making a conscious decision for the important ones: How long may the service be unavailable? When is Plan B activated? How long will implementation take? Where are the necessary data – and do they remain usable independently of the provider?


vNext supports companies in making precisely these dependencies and data flows visible: where important data are located, how they are backed up and how they can continue to be used in the long term or after a provider disappears.


Cloud is not the problem. It becomes critical when a company only discovers its dependency after the service has already failed.
 
 

Kontaktieren Sie uns

vNext, Patschär 7, 7306 Fläsch

Tel. +41 81 710 50 85

Ihr Profi für Websites und unbeschreibliches Foto Design
Ihr Partner für unvergessliche Events und Momente mit Ihren liebsten.
Wenn es Vertrauen braucht ist PSD Ihr Partner.

Wir arbeiten mit den besten Partnern zusammen

© 2023 by vNext GmbH

bottom of page