Cybersecurity insights on the global Amazon outage from a national TV interview with cybersecurity expert, Jim Kay, CEO of IT Networks.
When the global giant Amazon Web Services (AWS) experienced an unprecedented outage last week, millions of users around the world suddenly discovered how dependent modern business has become on the cloud. From small accounting platforms to global enterprise systems, entire operations were brought to a standstill.
Following the incident, I was invited to share expert insights on national television, Network 10 News+ — to help business leaders make sense of what happened, why it spread globally, and what lessons can be drawn for Australian companies. In line with time restrictions in news programming, my answers to some very real concerns were less informative than I would have liked.
So, this post aims to explore in more depth the important questions, the Network 10 News+ hosts, Denham Hitchcock and Amelia Brace, asked on behalf of the Australian public.
Because, while costly and undesirable, this incident is a powerful lesson in how every business needs to think about cybersecurity, moving forward.
Q1. Can you help us understand why this spread around the world? Shouldn’t there be backups when one data centre goes down?
Absolutely, and that’s what makes this outage so significant.
Major providers like Amazon Web Services, or AWS, are designed with multiple layers of redundancy — both within local data centres and across global regions. So, when an outage of this scale occurs, it usually points to something affecting a common system or service that ties those regions together, rather than just one location going offline.
To put it simply, AWS doesn’t rely on one data centre: it is more like a network of thousands of servers all over the world. But sometimes, a software update, a configuration issue, or a shared control system can create what’s called a “cascade effect” — where a single error ripples through multiple regions.
What’s important now is that AWS will be conducting a full post-incident analysis to pinpoint what failed and how to prevent it.
The takeaway: Events like this remind all of us — whether you’re running a small business or a global platform — that not just relying on one provider but designing systems with multi-cloud redundancy — a backup across different platforms, not just within one.
Q2. Was it a glitch or a hack — and would they tell us the truth if it was a hack?
This is a question we all ask when something big like this happens.
Based on what’s been shared so far, there’s no indication this was a cyberattack. It’s being treated as an internal systems issue — what we’d call an operational or technical fault rather than a breach.
Now, could a company hide a hack? In theory, no. Major providers like AWS are under strict regulatory obligations globally. If customer data or systems were compromised, they must disclose it. What’s more likely here is a technical failure that had wide-reaching impact because so many businesses depend on AWS.
But I think there’s a bigger lesson for business leaders watching the interview. AWS isn’t the one that most of us buy our software subscriptions from. We buy from vendors — accounting systems, CRMs, booking apps — and it’s those companies who choose to rely entirely on one hosting provider.
So, the question isn’t just “what happened to AWS?”. It’s actually: “why didn’t our software vendors design their systems to stay up when AWS goes down?”.
The takeaway: Redundancy and business continuity need to be built in from the start, not added as an afterthought.
Q3. What’s the difference between a glitch and a hack?
A glitch is essentially an accident — a technical failure or a human error that disrupts a system’s normal operation. It could be anything from a faulty update, a configuration change, a hardware failure, or even a simple programming oversight.
A hack, on the other hand, is intentional – a deliberate attempt to steal, disrupt, or extort. It involves a person or group deliberately breaching systems to steal data, disrupt operations, or demand ransom. The motivations are very different — one is a mistake; the other is malicious.
The challenge for organisations like AWS is that in the early hours of any outage, the symptoms can look similar — systems go down, users lose access. It takes time for engineers to confirm whether they’re dealing with an internal failure or an external attack. The difference comes down to forensics: what traces are left behind, and whether there’s evidence of an external intrusion.
The takeaway: a glitch is an accident. A hack is a crime. The first requires better systems; the second requires stronger defences.
Q4. What is the cost of an outage like this?
It’s difficult to quantify, because the impact ripples through the entire digital economy. Every business relying on affected cloud applications loses productivity and revenue. We’ve seen businesses around the world unable to process orders, access data, or even run payroll.
For small and medium-sized businesses, it’s not just about dollars — it’s lost time, frustrated staff, and shaken customer confidence. The financial cost is recoverable. The trust cost takes longer. On a larger scale, some analysts estimate that global outages of this nature can easily run into hundreds of millions of dollars per hour once you factor in lost transactions and the cost of recovery.
The real cost, however, isn’t just financial — it’s operational and reputational. Customers lose confidence quickly in systems they can’t access.”
The takeaway: Downtime costs money, but the bigger loss is trust.
Q5. If this cost hundreds of millions of dollars, who takes the hit?
Unfortunately, the pain is shared across the chain. In today’s interconnected world, an outage at the infrastructure level ripples through every layer — from the data centre right down to the local business trying to run payroll.
Businesses that couldn’t operate take the immediate hit. Software vendors who host their apps on AWS face customer backlash and potential compensation claims.
AWS itself will absorb reputational costs and operational expenses to fix the problem — but financially, the biggest burden usually falls on the businesses that depend on these systems. For example, if your accounting software or ERP was down all day, you’ve lost time, momentum, and possibly data integrity.
In a digital world, even small interruptions cascade quickly. The further you are from the source — the hosting platform — the less control you have, but the more you feel the impact.
The takeaway: When the cloud goes down, the losses fall like rain — they reach everyone.
Q6. Do you think the impact on Amazon was significant?
Yes, enormous — not just financially, but reputationally.
AWS underpins much of the global internet, from startups to major enterprises, so any global outage damages confidence in the reliability of the world’s largest cloud provider.
Financially, AWS will recover — they have the scale, the engineering expertise, and the transparency processes to regain trust. But reliability is the currency of the cloud. Once shaken, that confidence takes time to rebuild with questions from customers: could this happen again?
The takeaway: The reputational cost, in many ways, outweighs the direct financial hit. Reliability is the currency of the cloud, and events like this spend that currency quickly.
Q7. As we move further into the digital age, what does the future look like for cyber safety?
The risk landscape is evolving faster than most businesses realise. For every high-profile outage we hear about, there are hundreds of smaller incidents every day — both accidental and malicious.
The sheer scale of digital transformation means even small missteps can have global consequences. We’re living in an always-online world, and with that comes always-on risk. The number of digital services and connected devices, and automated systems has exploded — and every one of those is a potential point of failure or entry for attackers.
We’ll continue to see both accidental outages and deliberate attacks. The difference now is scale — one small mistake or intrusion can affect millions instantly.
The good news is that cybersecurity frameworks, artificial intelligence, and automation are also improving our ability to detect and respond faster.
What businesses need to understand is that cyber resilience — not just cybersecurity — is the future.
This future isn’t about avoiding disruption altogether; it’s about designing systems that can absorb shocks, recover quickly, and keep operating even when something goes wrong.
The takeaway: Digital risk is here to stay — resilience is the next evolutionary stage of security.
Q8. How can businesses guard against these incidents? Is it even possible?
Think of it as an annual health check for your business systems. You can’t protect what you don’t measure.
You can’t eliminate risk completely, but you can absolutely manage and minimise it. The key is measurement and maturity.
Every organisation should regularly assess their cybersecurity posture against recognised standards — such as ISO 27001, the NIST framework, or Australia’s own Essential Eight.
These frameworks provide a structured way to measure your defences. They help identify gaps and prioritise improvements. Think of it as an annual health check for your business systems.
Beyond that, it’s about culture — making security awareness part of everyday business operations. Technology is only as strong as the people who use it responsibly.
The takeaway: you can’t protect what you don’t measure. Having cybersecurity maturity is your new business fitness.
Q9. As a cybersecurity expert, what advice do you give to Australian SMEs with limited budgets for cyber defences?
That’s a great question, because most Australian businesses are small or medium-sized — and they don’t have the luxury of big IT or cybersecurity budgets. But good cyber hygiene doesn’t have to be expensive. It’s about discipline and visibility rather than throwing money at technology.
The first thing I tell my clients is: know your risks. Most cyber incidents happen because of really simple gaps — weak passwords, unpatched systems, or staff clicking on malicious links. These are things you can address with training, good processes, and affordable tools.
Second, measure where you are. Use a recognised framework — like the Australian Cyber Security Centre’s ‘Essential Eight.’ It’s a practical checklist that helps you focus on what matters most: backups, patching, access control, and multi-factor authentication. You can start small and build from there.
Third, build resilience, not just defences. Assume something will go wrong at some point. So have tested backups, clear recovery plans, and someone accountable for managing incidents.
For small and medium businesses, cybersecurity doesn’t need to be about expensive technology. Good cyber hygiene is about consistency, not cost.
Start with the basics:
- Train your people — most breaches start with human error.
- Enforce strong passwords and secure multi-factor authentication.
- Keep software updated and maintain secure, resilient and tested backups.
- Measure your maturity against the Essential Eight.
And that’s where managed service providers like us come in: to make sure our clients are protected, monitored, and prepared — without needing an enterprise-sized budget.
The takeaway: Cybersecurity for small business isn’t about spending big — it’s about getting the basics right and doing the right things consistently.
Final Thoughts
The October 2025 AWS outage was a stark reminder of how interconnected our world has become. No provider, however large, is immune to technical failure. But resilience — both technical and operational — is something every business can control.
The reality is – every business is now a digital business. You don’t need to be perfect — you just need to be harder to breach than the next target. Awareness and readiness are your best defenses.
This outage is a wake-up call for every business that runs online. Cloud computing is powerful, and resilience, while it’s the only defence, isn’t automatic — it has to be designed. Whether you’re a global enterprise or a local business, your digital uptime depends on planning for when, not if, something fails.
The final takeaway: Digital risk is here to stay — and resilience is the new security.
Watch the full Network 10 News Interview here.
I trust you will find this helpful. Remember: you already are a target, so don’t wait till you are hit. Get the right help to be prepared.
If you have any questions or want to find out where you stand, reach out to my team to discuss.