In July 2024, CrowdStrike sent out a faulty security-software update. About 8.5 million Windows devices went down. Organizations that had no connection to one another suddenly faced the same blue screen, at the same time, for the same reason.
The failure did not start in Microsoft's Azure cloud. It came from a security product installed across a vast number of systems. That distinction mattered technically, but it offered little comfort to anyone trying to restore a machine. A component that most users never saw had become a common point of failure across companies and industries.
Three years earlier, AWS had shown how the same problem could develop inside a cloud platform. In December 2021, congestion in an internal network in its US-EAST-1 region spread into monitoring, internal DNS, authorization services, and parts of the EC2 control plane. Services that looked separate to customers still relied on shared systems underneath.
Neither incident became a UK financial-stability crisis. Both exposed the mechanism regulators fear. A bank can operate its own apps, controls, and recovery plans while sharing an identity service, network layer, security tool, or subcontractor with many of its peers. If that common layer fails, institutions that appear separate can go down together.
Cloud computing can make an individual bank more resilient. Large providers offer specialist security teams, geographic redundancy, rapid patching, and infrastructure that may be stronger than systems maintained entirely in-house.
The picture changes when hundreds of firms make the same sensible choice. Risk that once sat inside separate data centers begins to collect around a smaller number of providers and technical components. A problem in a shared control plane or identity system can then travel across firms instead of staying inside one.
A 2024 survey by the Bank of England and the Financial Conduct Authority gives one indication of that concentration. Among the cloud-provider names reported by respondents, the three most frequently named accounted for about 73%. The figure is not a market-share estimate and does not mean that three providers host 73% of critical workloads. It shows how often the same names recur in firms' reported dependencies.
This is also the limit of traditional outsourcing supervision. A regulator can ask each bank how it manages a supplier, yet still miss the full network of customers, subcontractors, internal services, and common failure points inside the supplier itself. Seeing the system requires access at the provider level.
On July 10, 2026, HM Treasury designated Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited, and Oracle Corporation UK Limited as Critical Third Parties, or CTPs. The designations took effect on July 13, when the Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority began overseeing them directly.
The legal framework was already in place. Parliament created the statutory powers in the Financial Services and Markets Act 2023. Regulators published final rules in November 2024, and those rules took effect on January 1, 2025. The July 2026 action applied them to named companies for the first time.
The boundary is narrow. The designation covers systemic services supplied to the UK financial sector, not every product or global operation of Amazon, Alphabet, Microsoft, or Oracle. It does not turn a cloud company into a bank, grant it regulatory approval, or guarantee that its services are secure. HM Treasury can add other providers later if their disruption could threaten financial stability or confidence in the system.
The change is direct visibility. Regulators can now examine governance, risk management, supply-chain dependencies, cyber resilience, change controls, service mapping, incident management, and plans for an orderly termination of services at the provider itself. They no longer have to reconstruct the provider's risk profile from the partial view available to each customer.
The first deadlines arrive quickly. A newly designated CTP must submit an interim self-assessment within three months, followed by annual assessments. For the first four providers, that puts the initial filing around October 13, 2026.
Scenario testing must take place at least once a year. The provider has to show whether its systemic services can continue through a severe but plausible disruption. A separate incident-management exercise must be held within 12 months of designation, using a representative group of financial-sector customers. Later exercises generally take place at least every two years.
Real incidents trigger initial, intermediate, and final reports. Regulators generally expect the final report within 30 working days after an incident is resolved, although the rule does not impose a fixed statutory deadline. A provider that needs longer must say when the report will arrive.
For Microsoft, Amazon, Google, and Oracle, the immediate work will be organizational: dedicated regulatory governance, better maps of services and dependencies, more formal testing, stronger incident reporting, and evidence that important services can recover within acceptable limits. Contracts with financial firms are also likely to become more specific about audit rights, regulatory access, subcontractors, data portability, termination support, and recovery planning.
Banks and insurers do not get to hand over responsibility. They still have to select providers, understand their dependencies, test business continuity, and maintain workable recovery and exit plans. A second cloud contract does not automatically solve the problem if both environments share identity, networking, software, or operational teams.
The first self-assessments and exercises will show whether the new regime can uncover shared weaknesses that individual firms could not see. The practical test is whether direct access gives regulators a usable map of those dependencies before the next major outage.
Disclaimer: This article is for informational and research purposes only and does not constitute any investment advice.
Nasdaq's Proposed $5 Million MVLS Rule: From Getting Listed to Staying Qualified
U.S. IPO Trends, SPAC Activity, and Listing Regulatory Rules
What Insurance Does a Public Company Actually Need?