Amazon in September acknowledged that some customer data had been permanently lost.
In this case, the cause was the Iran war, which knocked out multiple Amazon data centers in Bahrain and the UAE.
“The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand,” the company said in a statement.
For global businesses, add this to the list. September has been full of AI concerns and doomerism driven by AI cybersecurity concerns, researcher declarations, and demonstrations of power by swarms of AI agents.
With AI governance lagging implementation and third-party partnerships a leading source of cybersecurity risk, today’s PTP Report takes on the question of resilience vs disruption.
What services would your company be able to move off of in the event of outages, cost spikes, or excessive risk?
We also consider vendor lock-in risks from the cloud to SaaS to AI.
Resilience and technology dependency risk
Every time there’s a major outage that causes problems to cascade and multiple global businesses to lose critical functionality, the conversation starts up again: How can companies reduce their critical dependencies?
In the summer of 2024, it was a CrowdStrike update tied to Microsoft systems that paralyzed airports, financial institutions, healthcare providers, and media outlets.
Last summer it was Google Cloud, where a policy change update caused mayhem that cascaded into Cloudflare.
October saw an AWS outage paralyze huge chunks of the internet followed nine days later by Microsoft Azure, with these once again derailing some financial services, healthcare providers, air traffic, and telecom.
And while each was a story of striking, global impact (none caused by cyberattack or AI, btw), smaller events, like the outage of dozens of major services (including Apple Pay, DoorDash, and Hulu) in July 2026 due to a single network connectivity issue, are commonplace.
In all these cases, multiple major companies suffered due to an issue happening somewhere beyond their control.
In a 2026 Economist Enterprise survey of senior tech and operations executives at medium-sized and large US enterprises across seven sectors, third-party failures were identified as the largest source of tech disruption experienced over the past year, listed above both internal failures and external cyberattacks.
Less than 10% indicated getting visibility into third party or supply chain issues before they happen, with 51% saying they learned only when at the start and 39% only after they’d already occurred.
This made these issues more unexpected than both security threats (61% before, 27% during, 11% after) and internal issues.
Testing, too, is problematic, with only around half noting they’d formally tested outages to cloud providers over the past year, and just 38% testing critical integration failures (with 21% testing AI-system failures).
And only 34% independently assess the resilience of their critical technology providers.
Of course, technological sprawl is a growing cybersecurity risk (see below), and can also be a large waste of money, as AI infusions expand on what many tools can accomplish and cause further overlap.
The Capgemini Research Institute noted the scope of this overall concern, finding that 93% of global organizations surveyed have discussed digital sovereignty at the board level, with two-thirds aiming for a practical, “resilient interdependence” or a selective mix of controlling their own critical technologies paired with strategic partnerships.


As critical technologies like cloud, SaaS, and AI merge and shift from being tools to extensive supply chain services, making difficult decisions around their management, risk, cost, and control become ever more critical.
Cloud vendor lock-in and data portability
We’ve written before about the startling concentration of cloud service providers. And while the exact figures vary by source and the details of exactly what’s being compared, the big three hyperscalers combine for more than 60% of the market (AWS, Azure, Google Cloud), with the next closest competitors not even being close.
Of course, scale alone isn’t necessarily a problem, as it should mean more reliability and security investments, for example.
But as these few companies also become providers of managed services relative to data storage, analytics, and of course AI, it becomes harder to simply shift to another provider, regardless of the risks or costs.
Even for companies already running multi-cloud footprints, it’s not a feasible cloud migration strategy to simply commit to shifting from one to the other, with applications often coupled (sometimes unexpectedly) to a provider’s specific platform.
Business get tied to an identity layer, for example, or a vendor’s unique tooling. The problems are often architectural and also designed to get businesses to stay and grow their investments.
So how can businesses avoid cloud vendor lock-in?
Sound design principles stress decoupling, reusability, and portability, and this all applies.
But shifting one’s data is rarely so straightforward. That takes a carefully considered cloud exit strategy, as workloads are tied to cloud providers by things like data formats, tooling for APIs, and proprietary services.
Though all of these, too, can be navigated.
How can enterprises reduce AI vendor lock-in?
Ironically, AI may be creating an even more extreme example of concentration, with Menlo Ventures estimating Anthropic, OpenAI, and Google accounted for 88% of enterprise LLM use via APIs in 2025.
Coding offerings are heavily cloud-based (more than 72% of the market share, per Mordor Intelligence), with JetBrains Research finding (May–July 2026) that work use was dominated by just a few offerings with Claude Code (39%), GitHub Copilot (21%), OpenAI Codex (16%), and Cursor (12%) at the top of the list.
Pricing concerns have also been a big adjustment for many companies, as we’ve covered repeatedly in our AI roundups. Companies across industries note finding their AI charges unexpected or hard to estimate, and in the arena of coding, again, some heavy users like Uber and Microsoft reported they’d exhausted entire budgets for the year in just a few months.
For AI-native applications, Zylo reported that spending was up 108% for 2026 year-over-year and 393% among large enterprises.
AI is metered by tokens, the volume of which, by task, can be notoriously difficult to budget. Recent New York Times reporting demonstrated how different LLMs can use vastly different numbers even on the same query, with OpenAI’s GPT-5.5 using 14 times more than GPT-3.5 and more than eight times more than GPT-4o.
And tokens alone are just part of an effective measurement of AI costs and gains.
[PTP’s CEO and Founder will be releasing an article soon on the emerging discipline of tokenomics and getting more effective calculations of AI cost and return.]
And in this arena too, switching models isn’t always as simple as it seems, especially when a harness or proprietary software is involved.
Model routing is gaining ground for this reason, with companies opting to avoid solutions that are locked or hard coded to a single provider.
Routers enable switching an LLM based on need, model performance, latency, and cost, with some also including fallback options in the event a system is down or inaccessible.
These can directly help companies limit their dependency on a single solution.
And of course, the hyperscaler cloud providers are also providing routing options, included in offerings like Microsoft Foundry and Amazon Bedrock.
But here again, a routing system can serve as a dependency gateway and the results often aren’t perfectly substitutable.
Different companies also have different privacy practices, though these routing options point to a tantalizing possibility: interoperability that lets you shift your work from one provider to another provider in a time of need.
Assessing a potential SaaS exit strategy
For many companies, software-as-a-service (SaaS) providers pose a different problem: a difficulty in tracking all of them and their risks, costs, and overlap.
Zylo’s 2026 SaaS Management Index found that while companies may be reducing or at least holding steady in the number of SaaS partnerships (the average organization now using 305 different apps), their spend keeps rising, up 8% over 2025 to an average of $55.7 million.
Much has been made of how AI has enabled some companies to move off some of their SaaS partnerships. But at the same time, other providers are infusing AI into the offerings in a bid to assist clients with governance of both AI and data use.
Critical in this area is having a clear understanding of what’s in use across the business and how much depends on each platform.
SaaS data migration, if needed, must be carefully mapped for potential disruption across integrations, as well as impacts on cost and security.
Cybersecurity, regulations, and technology vendor risk management
Security risks are a major drive for consolidating partnerships, and for good reason.
Verizon’s 2026 Data Breach Investigations Report (DBIR) puts numbers on the disturbing trend, with more breaches consistently coming through third-party relationships.


Europe’s Digital Operational Resilience Act (DORA) put a risk management framework in place specifically to address these risks for financial institutions and the firms that provide them with services.
Included among its requirements are analyses of how disruptions will impact a business, data backup and recovery plans with overall continuity, incident response and reporting, and resilience testing that specifically covers third-party risks.
It requires the mapping of third-party dependencies and diversification in some cases so that a firm is not too dependent on a single partner.
Conclusion: The importance of technology vendor assessments
Gartner has profiled several problems that companies face from heavily fragmented IT services:
- Decreased innovation speed
- Increased integration debt
- Increased third-party risk
- Constrained AI deployment
In other words, consolidation and unification of tech and data, where possible, make it easier to find gaps in coverage, ensure better security and faster recovery, and also make it easier to get more value and impact from AI.
But as discussed here already, consolidation won’t necessarily reduce one’s dependency.
SaaS vendor lock-in, for example, can accompany a move to fewer, smaller partners in exchange for a more far-reaching and integrated solution from a single player.
Being technologically self-sufficient may be a hopeless dream in today’s tech landscape, but understanding where critical dependencies exist, what alternatives are possible, and where potential failure is just too costly to risk may be the next best thing.
It’s a far cry from being blindsided by sudden outages that disrupt the entire business without recourse.
Peterson Technology Partners (PTP) helps businesses answer questions like these and make these decisions. We can help map dependencies, consolidate data, compare alternatives, and handle integration and migration work that’s needed to get you where you need to be.
References
Iran strikes on Amazon data centers caused permanent loss of customer data, Ars Technica
Technology Resilience Index: Are US firms ready for today’s technology hazards?, Economist Enterprise & AT&T
Digital Sovereignty: From policy ambition to executive imperative, Capgemini Research Institute
How to secure the digital future: Resilience, trust and leadership, World Economic Forum
Managing the Evolving Dynamics of Digital Platform Lock-In, Boston Consulting Group
The Building Blocks Hidden in A.I.: How Tokens Work, The New York Times
What is the Digital Operational Resilience Act (DORA)?, IBM
FAQs
How do businesses assess technology vendor dependency?
Measuring dependencies usually begins by mapping one’s own critical systems, data, integrations, and workflows for ties to partners. Available alternatives and the time, operational hit, and cost to switch can then be measured and evaluated where applicable.
What is SaaS vendor lock-in?
When a business finds it too hard or expensive to move from one software-as-a-service provider to another because of proprietary data structures, customizations, or dependencies as discussed above, they can be said to be locked in to the provider.
How do you create a cloud exit strategy?
Companies planning to migrate off one cloud service must first identify critical workloads and their current dependencies on the service. Alternatives can then be assessed, with tests conducted and migration time and costs estimated. Procedures must also be put in place to ensure a smooth transition whole maintaining operations during the change.
What are the risks of AI vendor lock-in?
As with SaaS, AI providers are not all the same, and dependencies can arise from software harnesses, APIs, pricing structures, privacy policies, and model capabilities. While model routers are popular for many use cases and companies are increasingly finding ways to use varying solutions in areas like coding, in some use cases it can be much harder to change AI providers.
The risks are higher costs, reduced performance, privacy and security issues, and excessive dependency on a single lab in a time of high-speed change.


