Cloud-based disruptions highlight risks for SA Financial Services
In recent weeks, South Africa experienced disruptions in its digital infrastructure due to multiple 'undersea events' impacting fibre optic cables off the coast of West Africa and the Red Sea. These incidents, caused by dragging anchors, resulted in prolonged latency issues, hindering access to essential cloud-based services such as Microsoft Teams and Outlook. For businesses

Cloud-based disruptions highlight risks for SA Financial Services

In recent weeks, South Africa experienced disruptions in its digital infrastructure due to multiple ‘undersea events’ impacting fibre optic cables off the coast of West Africa and the Red Sea. These incidents, caused by dragging anchors, resulted in prolonged latency issues, hindering access to essential cloud-based services such as Microsoft Teams and Outlook. For businesses relying on these services, the disruptions posed serious risks to productivity, revenue, and profit.
Cloud computing and Software as a Service (SaaS) have emerged as pivotal drivers of digital transformation globally, with South African businesses and government entities increasingly embracing cloud migration. While local Cloud Service Providers (CSPs) exist, major players like Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) dominate the industry, instilling confidence in companies considering cloud adoption. However, the reliance on distant CSPs and third-party SaaS providers introduces additional layers of risk into the software supply chain.
“Cloud-based SaaS applications are undeniably the future,” remarks Guy Krige, Executive Risk Consultant at ESCROWSURE. Investment in South African data centres is escalating, with AWS establishing its African hosting headquarters in Cape Town and a projected capex of R46-billion by 2029. Despite the benefits of cloud computing, including scalability, rapid deployment, and predictable costs, businesses must recognize that cloud adoption does not eliminate risk entirely. Therefore, robust plans for business continuity and disaster management are imperative to navigate the expanded risk landscape effectively.
A critical vulnerability for businesses relying on SaaS solutions is their dependence on the software supplier for critical services. The relationship with the CSP, configuration of the cloud environment, and access to software source code are typically controlled by the SaaS provider, leaving clients vulnerable in the event of supplier insolvency or service disruption.
Krige emphasizes, “If your SaaS provider fails to pay the CSP, your operations are at risk. Without direct access to the CSP or essential documentation, businesses are left vulnerable unless they have a SaaS Escrow solution in place.”
What is SaaS Escrow?
Similar to Software Escrow, SaaS Escrow forms a vital component of Business Continuity and IT-specific Disaster Recovery Plans. A trusted third-party safeguards critical data, including source code and login credentials, and ensures access during predefined trigger events, such as supplier insolvency. In the case of SaaS Escrow, firms like ESCROWSURE facilitate direct communication with CSPs and assume payment responsibilities for client tenancy in the cloud for up to three months.
Krige concludes, “It’s imperative for businesses to recognize the heightened risks associated with cloud-hosted solutions. With regulatory standards like the Joint Standard for IT Governance and Risk Management coming into effect, comprehensive business continuity plans, including SaaS Escrow, are essential for South African banks and insurers to mitigate risks effectively.”



