Since October 2022, Azure – one of the big three cloud providers – has experienced 18 incidents including issues with networks, power, VMs, storage, and data access logs. This shows why having alternative backups of Azure-based data is important. It’s a fundamental supplier risk management strategy and provides a logical air gap between production data and backup copies. It also ensures that your organization can remain operational if anything happens to your primary cloud service.
Risks of the shared responsibility model
Organizations often assume that migrating to a cloud service provider means that the provider is responsible for their continuity and availability. That’s not the case for public cloud infrastructure as a service, which requires users to implement many of the security and resilience measures themselves.
For backup, you need to set up and configure it yourself. You may find the default options don’t meet the standards you would keep in your own data centres. For instance, you may find you only have limited retention options and no way to keep a copy in another cloud.
To reach a level of protection you are comfortable with, you might need to add another backup technology or invest significant resources in adapting the cloud-native tools. You can spend time on solution design and architecture and on building out your monitoring and alerting; but that’s an additional overhead for your internal teams. It means dividing their time and attention between that and their day-to-day roles. Backup, unfortunately, is often deprioritised over value-adding projects. That can stretch resources, leave gaps in availability and expertise, and means human error is more likely.
Configuration errors
Azure configurations (as with any IaaS) cover a huge variety of services and functions. Getting them right can be complex, and there’s always the possibility of making a mistake. Relying on a cloud service provider without having a secondary backup, separate from your production environment, means that a mistake can also affect your backups – leaving you with nothing to recover from.
Human error in cloud accounts can lead to mass data deletion and allow access to attackers who can then encrypt your data. We’ve seen it happen. In a worst-case scenario, guarantee your business can remain operational from a different backup. To eliminate the possibility of a configuration error, you need a backup that is completely isolated from your production infrastructure.
Risk management best practice
Azure is the most popular public cloud for migrating back-office systems (often Microsoft servers). You have all the tools available to create resilience yourself. But, while it often appears that moving to the cloud takes away old IT challenges like backup, often the default cloud-native tools aren’t sufficient.
It’s a fundamental tenet of supplier risk management to not rely on a single supplier. Keeping a copy of your backups outside Azure and isolated from your production environment is central to good risk management. A common refrain is that Azure is too big to fail: “Microsoft couldn’t possibly lose my data”. But it happens. User error, cyber attack or even platform outages all happen. Make sure that whatever happens, your business will continue.
The author
James Watts is Managing Director at Databarracks.






