
Field Notes
False Redundancy: The Geopolitical Risk Inside Multi-Region Cloud Architecture
TL;DR: Three 2025 hyperscaler outages and a French certification rule show multi-region cloud deployments often share one identity layer, control plane, or jurisdiction underneath.
Key takeaways:
- AWS's October 2025 DynamoDB DNS failure broke Redshift authentication in every region, costing US businesses up to 650 million dollars.
- Google Cloud's June 2025 Service Control crash disabled more than 60 products across four continents within two hours.
- Azure Front Door's October 2025 configuration error propagated globally and took roughly eight and a half hours to mitigate.
- France's SecNumCloud rule caps non-EU shareholding at 39 percent, barring AWS, Azure, and Google Cloud from trusted status regardless of hosting location.
On October 20, 2025, a race condition inside a DNS automation system in Amazon Web Services' Northern Virginia region left the DynamoDB regional endpoint pointing at an empty record. Within minutes, Redshift clusters in every AWS region, from Frankfurt to Sydney, began failing user authentication, because Redshift resolves IAM user groups through an API call routed back to us-east-1. The architecture was multi-region. The failure was not.

The Geostrategic Anatomy of a 'Distributed' Outage
Three incidents inside thirteen months show that multi-region architecture routinely collapses into one shared-fate zone whenever the dependency underneath the workload, not the workload itself, is the actual unit of failure.
- Amazon Web Services, October 19-20, 2025: A latent race condition in DynamoDB's DNS management system produced an incorrect empty DNS record for the regional endpoint. Amazon's own post-event summary, "Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia (US-EAST-1) Region," confirms Redshift clusters worldwide failed authentication because Redshift "used an IAM API in the N. Virginia Region to resolve user groups." Analytics firm Parametrix estimated the outage cost US businesses up to 650 million dollars.¹
- Google Cloud, June 12, 2025: A policy change pushed to Service Control, the global authorization layer that checks nearly every Google Cloud and Workspace API call, carried unhandled blank fields that triggered a null pointer crash. Google's incident report notes the change replicated to every regional deployment "within seconds," and the crash hit more than 60 Google Cloud and Workspace products across the Americas, Europe, Asia-Pacific, and the Middle East simultaneously.²
- Microsoft Azure, October 29, 2025: An inadvertent tenant configuration change inside Azure Front Door, the control-plane layer fronting Azure Portal, Microsoft 365, and Entra ID, bypassed a validation safeguard built to catch exactly that kind of error and propagated globally. Microsoft's status history records impact to Entra ID, Purview, Defender, Intune, and core compute services worldwide, with mitigation not confirmed until 00:05 UTC on October 30, roughly eight and a half hours after customer impact began.³
- France, ongoing since March 2022: The SecNumCloud v3.2 certification caps non-EU shareholding at 39 percent collectively and 25 percent individually, with no non-EU veto or majority board control, and requires EU-based personnel for support functions. The Information Technology and Innovation Foundation documents that this effectively bars AWS, Azure, and Google Cloud from "trusted" status for French public-sector and critical-infrastructure workloads, regardless of which EU region hosts the data, and that Paris is pushing the same terms into the EU-wide EUCS scheme.⁴

The Geostrategic Logic of Shared Fate
The pattern across the three outages is structural, not accidental. Providers built regions to survive a fire, a flood, or a bad rack in one facility. They did not build the identity plane, the control plane, or the policy engine to survive a bad deployment, because those systems are deliberately singular: a customer needs one authorization decision, not three regional variants that could drift out of sync and produce inconsistent access control. That design choice is sound engineering and a source of geopolitical risk that most resilience reviews never price. A company running production in us-east-1, eu-west-1, and ap-southeast-1 has bought three power grids and three physical facilities. It has not bought three identity systems, three control planes, or three legal jurisdictions, and often not three sets of subcontractors either, since the same firms supply cooling, backup diesel, and network operations across a provider's regional footprint. When Redshift called back to Virginia for a group lookup, region choice stopped mattering for eleven hours. When Service Control crashed, sixty products failed on every continent inside the same two-hour window. Grid, control-plane, identity, jurisdictional, and subcontractor diversity are five separate axes; resilience programmes typically test only the first, then report the result as full geographic redundancy to a board with no way to check the claim.

The Geostrategic Stakes for Boards
For CROs in manufacturing, energy, and technology, this reframes the resilience question a board should be asking. "Are we multi-region" is the wrong question if the answer does not name which identity provider, which control-plane operator, and which regulatory authority sits underneath every region on the architecture diagram. The AWS incident cost US firms an estimated 650 million dollars in roughly fifteen hours, not because companies lacked redundant compute, but because the redundancy stopped at the identity layer.¹ France's SecNumCloud regime points to a slower, structurally identical exposure: one sovereign certification can reclassify an entire hyperscaler's regional footprint for regulated workloads at once, independent of physical geography, subcontractor status, or which specific data center a workload runs in. Manufacturing and energy operators running industrial control systems on a single hyperscaler face the same exposure twice over. First is the shared identity and control-plane risk documented above; second is whichever jurisdiction eventually decides that provider's regional footprint no longer qualifies as trusted for critical infrastructure. Firms with regulated operations in the EU, or single-vendor cloud strategies anywhere, should map which of their "diversified" workloads still share one identity provider, one control-plane operator, or one jurisdiction test. They should underwrite that concentration the way they would price a single-facility outage, not treat the region count on a slide as proof of resilience.
Fortius Intel note: Multi-region deployment answers a physical question, not a governance one. Boards that conflate the two are carrying a shared-fate exposure they have not measured.
Methodology: Analysis draws on Amazon Web Services' October 2025 post-event summary, Google Cloud's June 2025 incident report, Microsoft Azure's October 2025 status history, Parametrix's October 30, 2025 loss estimate, and the Information Technology and Innovation Foundation's May 2025 analysis of France's SecNumCloud certification. All cited sources are publicly available.
Footnotes
1 Amazon Web Services, Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia (US-EAST-1) Region, AWS, October 2025. DynamoDB DNS race condition, October 19-20, 2025; Redshift global authentication failures via us-east-1 IAM API dependency. Available at https://aws.amazon.com/message/101925/
2 Google Cloud, Google Cloud Incident #ow5i3PPK96RduMcb1SsW, Google Cloud Status Dashboard, June 12-13, 2025. Service Control null pointer crash from a May 29, 2025 code deployment, affecting 60+ products globally. Available at https://status.cloud.google.com/incidents/ow5i3PPK96RduMcb1SsW
3 Microsoft, Azure Status History, Tracking ID QNBQ-5W8, Microsoft Azure, October 29-30, 2025. Azure Front Door tenant configuration error; Entra ID, Purview, Defender, Intune and compute services impacted worldwide; mitigation confirmed 00:05 UTC October 30, 2025. Available at https://azure.status.microsoft/status/history/?trackingId=QNBQ-5W8
4 Information Technology and Innovation Foundation, France's Cloud Service Restrictions, ITIF, May 25, 2025. SecNumCloud v3.2 shareholding and personnel requirements effectively excluding US hyperscalers from trusted-status certification. Available at https://itif.org/publications/2025/05/25/france-cloud-service-restrictions/
5 Henry Gale, AWS outage will cause up to $650 million in US financial losses: Parametrix, The Insurer, October 30, 2025. Parametrix loss estimate for the October 20, 2025 AWS us-east-1 outage. Available at https://www.theinsurer.com/cyber-risk/news/aws-outage-will-cause-up-to-650-million-in-us-financial-losses-parametrix-2025-10-30/
About the author
Shekhar Attri, Co-Founder & CTO. An Indian Army Special Forces veteran with 21 years of service and a gallantry medal, Shekhar's corporate security advisory work spans Singapore, India, the Philippines, and the UAE, alongside PhD research on machine intelligence under incomplete information.