Summary
- The October 2025 AWS outage exposed how dependent digital services have become on concentrated cloud infrastructure.
- Robert Kraal argues payment resilience depends on modular architecture, real-time visibility, and failover design, rather than where systems are hosted.
- DORA’s focus on concentration risk raises pressure on payment businesses to test substitutes, exit plans, and dependency management.
By Robert Kraal, Co-Founder of Silverflow
On 20 October 2025, a fault in a single Amazon Web Services region took a large part of the digital economy offline for most of the day. Customers around the world found themselves locked out of banking apps and online services, after a DNS failure inside one data centre in northern Virginia cascaded through the many systems that quietly depend on it. In the UK, the disruption reached from high-street banking to the tax authority’s own services.
For anyone running payments, the episode was a useful and uncomfortable reminder. It also invited the wrong conclusion.
The tempting lesson is that critical systems do not belong in the cloud, and that the older, on-premises way of doing things was somehow safer. That reading confuses location with resilience. A payment platform is not robust because it sits in a data centre you happen to own. It is robust because of how it is designed, how quickly it detects trouble and how gracefully it fails over when a dependency breaks.
Legacy architecture in a cloud-based world
Judged on those terms, a great deal of legacy payment infrastructure is not resilient at all. Much of it still runs on batch-based, tightly coupled architecture built for a different era of commerce. Systems of that kind tend to fail opaquely and recover slowly. When something breaks, operators often hear about it from their customers before their own monitoring tells them, and restoring service can mean waiting for the next processing cycle rather than rerouting in the moment. Age is not the same as reliability.
Regulators have arrived at a similar view from a different direction. The EU’s Digital Operational Resilience Act, in force since January 2025, is built around the concept of concentration risk: the danger that too much of the financial system rests on too few providers. In November 2025, European supervisors named nineteen critical technology providers, including the major cloud platforms, and placed them under direct oversight. DORA does not instruct firms to abandon the cloud. It instructs them to understand their dependencies, to be able to substitute a provider, and to hold an exit plan that has genuinely been tested.
That is an architecture requirement dressed as a compliance one and it reaches well beyond the hyperscalers. A payment business that routes every transaction through one processor, over one connection, on one rigid stack has a concentration problem of its own, whatever the rulebook chooses to call it. If that single path degrades, the traffic has nowhere else to go.
From modularity to resilience
This is where the design conversation matters far more than the cloud conversation. Resilience comes from modularity: the ability to assemble a payments stack from components that can be observed, isolated and replaced without rebuilding everything around them. It comes from real-time data, so that a problem shows up in seconds rather than at the close of a batch. And it comes from the freedom to route around a failing element, whether that element is a scheme connection, an acquirer or an underlying service.
None of this is an argument for complexity for its own sake. The purpose of modern, cloud-native infrastructure is the opposite: to replace a tangle of patches, middleware and point-to-point integrations with something simpler and more transparent. At Silverflow, our starting position has always been that payments belong on a single, data-rich connection to the card networks rather than on decades of accumulated workarounds. The resilience benefit is not incidental. A system you can see into clearly, and change without fear, is a system you can recover quickly.
The businesses that came through October 2025 in the best shape were not the ones that had sworn off the cloud. They were the ones that understood their dependencies, kept alternatives ready, and had built for failure rather than assuming it away.
That is the real work of digital resilience and it will not be settled by the next outage or the next regulation. Firms that treat payment infrastructure as a strategic asset, designed deliberately for continuity, will spend far less time explaining to customers why the money stopped moving. The rest will keep learning the same lesson, one outage at a time.
| About the author | |
|---|---|
|
Robert Kraal is one of the few people in the world with over 30 years of experience in online payments. After completing his degree in Geophysics, he started his career at Bibit, the first global Payment Service Provider (PSP) which was acquired by RBS/Worldpay. At RBS/Worldpay he went on to lead account management, before moving on to Google Netherlands. He joined Adyen in 2010 in the role of COO, where he was responsible for building and running the global acquiring and processing service. As Co-founder and Business Development of Silverflow, Robert is responsible for maintaining relationships with the card schemes, acquirers, PSPs and regulators. |
|










