This incident reveals the urgent need for vendor diversification and stringent regulatory oversight in cloud services, including defence clouds, such as Australia’s TS Cloud. Relying on a single primary provider for an asset as critical as the defence cloud increases the risk of widespread disruptions. If a similar failure to the CrowdStrike outage occurred during wartime, the consequences could be catastrophic, potentially crippling all allied systems simultaneously and compromising defence networks.
The CrowdStrike event casts a long shadow over Australia’s partnership with AWS on the TS Cloud. Despite ostensibly inevitable discussions about multi-vendor strategies among defence authorities during the tendering process, taxpayers are largely left in the dark. There’s a glaring lack of transparency regarding AWS's partnerships and potential outsourcing within Australia. And accountability in the event of a top-secret data breach remains murky. In the CrowdStrike outage, Microsoft distanced itself despite a significant MS Windows failure in this situation. Who will be held accountable if defence data leaks from the AWS-managed cloud?
One thing is certain: in the software world, no company is immune to failure. Glitches are inevitable, often striking at the worst possible moments. This underscores the urgent need for transparency, diversification, and robust regulatory oversight to protect Australia’s digital infrastructure and national security.
The CrowdStrike outage is also a reminder for Australia to move more aggressively towards a multi-vendor cloud environment, both legislatively and operationally, to enhance resilience and reduce the impact of any single point of failure. By building and training a workforce tasked with managing complex digital multi-vendor operations, and leveraging its sovereign capabilities to manage such an environment, Australia can foster competition, innovation, and greater security.
In an increasingly interconnected world where avoiding cloud storage platforms is neither possible nor advised, the stakes for Australia are high: national security could be compromised if the cloud’s maintenance and operations are not diversified. Australia must safeguard its national security interests by ensuring its cloud ecosystem incorporates efficient built-in systems and operational redundancy, alongside multiple layers of protection enabled by multi-vendor support applications. Doing so is not only responsible but also necessary to ensure Australia can harness modern cloud technologies while mitigating risks and enhancing its cyber resilience.