Skip to content
Search

Latest Stories

Submit Guest Post

How the UK is making Microsoft, Google, Amazon and Oracle answer for cloud outages

Microsoft, Google, Amazon and Oracle will face direct oversight as Britain tightens rules for critical cloud providers

UK Cloud Outages

The UK has brought four major cloud providers under direct oversight to strengthen the resilience of its financial system

iStock
  • The UK has designated Microsoft, Google, Amazon and Oracle as critical third-party suppliers to the financial sector.
  • The firms will come under direct regulatory oversight from July 13.
  • The move aims to reduce risks from cyber attacks and major technology outages.

The UK is tightening its grip on the technology companies that power much of the country's financial system, placing four of the world's biggest cloud providers under direct regulatory oversight.

The UK cloud regulation move will see Microsoft, Google, Amazon and Oracle designated as critical third-party suppliers to Britain's financial sector from July 13. The government says the new framework is designed to strengthen the resilience of banks, insurers and financial market infrastructure as they become increasingly dependent on cloud computing.


The designation covers Microsoft Ireland Operations Ltd, Google Cloud EMEA Ltd, Amazon Web Services EMEA SARL and Oracle Corporation UK Ltd.

Cloud giants face closer scrutiny

Under the new regime, the companies will be jointly supervised by the Bank of England, the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA).

They will be required to carry out resilience testing, conduct regular self-assessments and report major operational incidents to regulators. The measures are intended to reduce the risk of widespread disruption if a major cloud provider experiences a cyber attack, system failure or prolonged outage.

The UK government said banks, insurers and financial market infrastructure are becoming increasingly reliant on cloud services. A disruption at one major provider could affect several financial institutions simultaneously, potentially interrupting services relied on by businesses and consumers, as quoted in a government statement.

The new rules also place greater responsibility on cloud providers to demonstrate that they can withstand operational shocks and recover quickly when incidents occur.

A growing focus on digital resilience

Britain's approach differs from that of the European Union, which designated 19 technology and service providers under a similar framework in November. Rather than adopting the same list, the UK has initially focused on the cloud providers considered most critical to the country's financial system.

Responding to the announcement, a Google Cloud spokesperson reportedly said the new Critical Third Party framework could strengthen the long-term resilience of the UK's financial ecosystem while improving transparency and trust between regulators, financial firms and technology providers.

For the companies involved, the designation is expected to bring closer regulatory scrutiny and greater accountability for major outages or cyber incidents that could affect financial services. While the government has framed the changes as a resilience measure, industry observers suggest the additional compliance requirements could also increase operating costs over time.

Add EasternEye As Your Trusted Source
preferred source on google news

More For You

Asos hacked

ASOS says hackers accessed customer information but not passwords or payment card details

iStock [Representational image]

ASOS hack exposed what millions of customers were searching for. Here’s what we know

  • ASOS says hackers accessed names, addresses, phone numbers and email details.
  • Recent customer search histories, including terms such as “glamorous wide fit”, were also exposed.
  • Passwords and payment card information were not accessed, according to ASOS.

ASOS has revealed that hackers gained access to millions of customers’ recent search histories, as well as names, addresses, phone numbers and email details, in a cyber attack on the online fashion retailer.

Searches including “glamorous wide fit”, “ASOS petite” and “reclaimed vintage” were among the information accessed, according to reports. The disclosure gives a clearer picture of the breach after ASOS initially said only basic personal information may have been affected.

Keep ReadingShow less