

Risk analysis in IT Management nowadays is spectacularly bad.
If you become dependent on a 3rd supplier then their survival as a company is now a risk for you. It doesn’t matter how good the reliability you have contracted with them - if they go under whatever penalities in the contract for failing to deliver said reliability will never be paid.
You might even be at risk of them simply chosing to close that division - small company signing a service supply contract with a big company: good luck getting a contract where the parent company (rather than whatever paper company they spun up for that business area) actually has to pay you stiff penalties if they fuck you over.
As soon as mission critical anything is outside your company, a lot of otherwise irrelevant things become operational risks for your company.
This is why you don’t put your mission critical anything on an external Cloud supplier.
You know, stuff like the only copy of 70 years of TV history that’s actually just 50TB and would’ve fit a bunch of Hard Disks or Backup tapes.



Yeah, even having learned to explain this shit in the IT Consultancy language of “supply contracts” and “mission critical”, it’s still not guaranteed that I’ll convince a manager to avoid or at least account for the higher exposure to outside risks when subcontracting certain things.
Nowadays, with 3 decades of experience in the Industry, I honestly think that the majority of managers, no matter how high in a company, are either incompetent as fuck or simply manage with as priority maximizing their next bonus in the full knowledge that they’re leaving traps for the next one to solve and if they do blow up during their own time, they’ll still personally end up better off by going for bonus-today-problem-tomorrow than refraining from doing so.