The Fragilities of the Cloud and Europe's Decisions
di Roberto BaldoniLa versione in italiano
The incident on Friday the 19th highlighted how negligence can expose the fragility of global cloud infrastructures to accidental failures. Imagine what could have happened if the outage had been caused by a coordinated cyberattack. In this case, the cause and mitigation measures were immediately known, and the damage was still impressive at an estimated $5 billion. The outage was triggered by negligence on CrowdStrike's part, which released a faulty automatic update to millions of computers. The update operates at the core (kernel) of the operating system (Microsoft Windows) and was not sufficiently tested to ensure its security. An error in such an update can cause the kernel and thus the entire operating system to crash, which was the case for 8.5 million computers. According to Microsoft sources cited by the Wall Street Journal, this mode of operation stems from a 2009 agreement with the European Commission that called for equal privileged access to the op…
La versione in italiano
The incident on Friday the 19th highlighted how negligence can expose the fragility of global cloud infrastructures to accidental failures. Imagine what could have happened if the outage had been caused by a coordinated cyberattack. In this case, the cause and mitigation measures were immediately known, and the damage was still impressive at an estimated $5 billion. The outage was triggered by negligence on CrowdStrike's part, which released a faulty automatic update to millions of computers. The update operates at the core (kernel) of the operating system (Microsoft Windows) and was not sufficiently tested to ensure its security. An error in such an update can cause the kernel and thus the entire operating system to crash, which was the case for 8.5 million computers. According to Microsoft sources cited by the Wall Street Journal, this mode of operation stems from a 2009 agreement with the European Commission that called for equal privileged access to the operating system for Microsoft and third-party products. This justification may have been valid in 2010, but in 15 years it would have been possible to reorganize the operating system software to allow third-party applications to function without interacting directly with the kernel, as Apple did in 2020.
These fragilities and negligence are also stem from a software market where time-to-market and performance take precedence over reliability and security. In addition, university education often favors trendy technology courses, such as machine learning today, over fundamental disciplines like software engineering and system reliability, making them optional and less frequented courses. It is therefore not surprising that human errors and failures in digital infrastructures are more common than one might think, even if they are generally contained and of a smaller scale compared to the CrowdStrike outage.
There is an inherent systemic fragility in the concentration of the cloud operator market. Less than a handful of operators manage on average,hundreds of millions of customers each. This near-monopoly tends to exclude new competitors from the market and creates lock-in situations for users. In addition, any incident or outage affects millions of users, including citizens and critical infrastructure. Today, these operators are real “single points of failure” for our society. It is therefore a priority to increase the number of cloud operators in order to foster a more competitive and resilient market. A larger number of operators would not only reduce the risk of large-scale outages, but also promote better practices in the areas of security, reliability, interoperability and diversification of providers. These elements should be at the heart of market policies.
Finally, we live in a complex geopolitical era where there is no longer a level playing field in the global market. Having a national private cloud sector capable of competing globally has become crucial. The cloud now represents a nation's data vault, the nervous system of critical infrastructure, and the enabling platform for access to and integration of new technologies such as AI, quantum computing, supercomputers, and IoT, making it the primary, indispensable asset for strategic autonomy. In an increasingly volatile and isolationist global context, major technology players will feel the full weight of their governments' political decisions. Not having at least one national cloud operator exposes a nation to dependency, for example, for access to new technologies or applications. This also includes decisions on which areas of the cloud to prioritize for reactivation, as cloud infrastructures will be the first targets of physical and cyber attacks in the event of a hybrid threat or declared crisis to destabilize or paralyze the adversary.
In 2020, Ursula von der Leyen stated: "Europe must build an autonomous and secure cloud computing infrastructure to protect the data of its citizens and businesses." As repeatedly highlighted on these pages, individual member states do not have the scale and economic potential to foster the creation of such technological giants. Only a unified European industrial and capital strategy and an ambitious industrial plan with adequate resources can enable the creation of globally competitive cloud industrial ecosystems in Europe, allowing new companies to fully exploit the power of a truly European single market. To achieve these goals, the EU must reform its operational rules towards greater integration. Any delay could leave us unprepared for future crises. We must transition from a Europe of regulation to a Europe of industry, especially in critical sectors such as digital, space and defense. The time has come to turn words into actions.