Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Media
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Financial Services
    • Healthcare
    • Higher Education
    • Infrastructure
    • Manufacturing
    • Nonprofit Organizations
    • Real Estate
    • Sports & Stadiums
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • DEI Strategic Services

      Providing our clients with legal, strategic, and practical advice to make transformational changes in their organizations.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Articles
    4. Conducting a health check on cloud-based supplier agreements in light of the AWS outage

      Articles

    Article

    Conducting a health check on cloud-based supplier agreements in light of the AWS outage

    Oct 22, 2025

    LinkedInX (Twitter)EmailCopy URL

    This week’s outage is a wake-up call: Is your organization truly prepared for a provider-side disruption?

    Authors

    • Andrew L. Share

      Partner, Office Managing Partner, Manchester
      • Office+1 603.628.4053
      • ashare@nixonpeabody.com
      Andrew L. Share

    The recent Amazon Web Services (AWS) outage and resulting widespread Internet disruption serves as a stark reminder for companies using cloud services, highlighting risks of single points of failure, the criticality of multi-region redundancy, and the need for thorough risk assessment in software-as-a-service (SaaS) adoption. Companies relying on cloud solutions should, therefore, take this moment to re-examine their technical safeguards and contractual protections.

    What happened: Summary of this week’s AWS disruption

    On the morning of October 20, 2025, AWS experienced a major outage in its US-EAST-1 region with immediate and far-reaching impact. This led to significant disruptions across major platforms, affecting financial services, educational institutions, healthcare systems, airlines, smart home devices, social media, and various other applications. While Amazon quickly identified and resolved the issue, the event demonstrates that even mature providers with robust systems and processes remain vulnerable to failures that are difficult to isolate in real time.

    Redundancy: Architecting for the provider’s bad day

    For customers, the outage highlighted several urgent issues: business operations were disrupted; multiple services and geographies were impacted; and resolution required provider-side fixes beyond the customer’s control. Therefore, customers must consider how to mitigate such risks.

    One item to consider is whether single-provider or multi-provider redundancy is appropriate for a customer’s requirements. For cloud users, redundancy involves implementing backup systems and alternative resources to ensure service availability during failure. Within a single provider, regional distribution can reduce an outage radius. Cross-provider redundancy (i.e., the use of multiple vendors), however, can offer additional protection against provider-wide disruptions but may require the implementation of complex system segmentation.

    SLAs: Ensuring credits are not your only remedy

    Beyond technical safeguards, customers must ensure that contractual protections reflect operational realities. While service level agreements (SLA) are often framed as a mark of a provider’s confidence, standard SLA credits (typically a small percentage of monthly fees) rarely cover actual damages from multi-hour disruptions. Customers affected by this week's disruption undoubtedly faced lost revenue, diminished loyalty, decreased site traffic, and service inability to end-users. For platforms unable to process transactions, financial firms with inaccessible accounts, or educational institutions whose students couldn't submit assignments, damages surely far exceeded standard service credits.

    Customers should carefully review how SLA credits are measured and applied. For example, if a contract treats SLA credits as the sole remedy, a customer may be limited to nominal credit despite severe operational harm. In addition to SLA credits, customers should consider whether it is necessary to preserve the right to pursue additional remedies for outages exceeding defined thresholds or resulting from provider negligence, repeated breaches, or failures to meet specific commitments (e.g., security, disaster recovery, data durability).

    Disaster recovery, data protection, and change management

    This week’s incident also highlights the need to align disaster recovery and data protection provisions with actual provider practices. Customers need to consider whether and how to address recovery point objective (RPO) and recovery time objective (RTO), data durability commitments, and geographic replication. Customers who rely on provider-managed backup and restore processes should understand the dependency chain, particularly if the backup/restore systems can be impaired by the same failures that affect production.

    Shared responsibility and operational playbooks

    Cloud resilience is a shared responsibility. Providers own infrastructure and managed-services resilience, while customers own application resilience and architectural choices. The right response to this week’s outage is not to abandon cloud services but to ensure adoption occurs with full awareness, proportionate risk allocation, and contractual controls.

    Additionally, customers should consider preparing incident playbooks that assume provider-side failures. These playbooks should define escalation paths, internal and external communications, business continuity steps, and criteria for invoking failover.

    Conclusion

    Regardless of the financial and reputational consequences of this week’s outage, it serves as a reminder that even world-class providers that provide the core of the Internet’s backbone can suffer complex, multi-service disruptions that materially impact customers. Usage and reliance on cloud and SaaS-based services are not going to diminish, and, thus, the prudent response for customers is to harden both their systems and contracts. Use this incident to reassess redundancy, reevaluate SLAs, and reset expectations. Doing so now will position your organization to withstand the next provider-side event with less downtime, fewer surprises, and better recourse.

    Practices

    Corporate & FinanceMergers, Acquisitions, and Corporate Transactions Intellectual Property TransactionsTechnology Transfer

    Industries

    Technology

    Insights And Happenings

    • Alert

      2024 HSR Annual Report: Trends and enforcement insights for M&A

      Sep 26, 2025
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Cookie Preferences
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Purchase Order Terms & Conditions
    • Nixon Peabody International LLC
    • PAL
    © 2025 Nixon Peabody. All rights reserved