The pitch for vendor consolidation arrives in two parts, and the second deserves an argument.
Part one is the savings. Commit more spend to fewer platforms and you get a discount, usually low to mid teens. Procurement earns its budget on that alone.
Part two: "it gives us leverage with the vendor." Leverage comes from your ability to walk away, and consolidation is the act of selling that ability. You get paid once, at signature. The vendor enjoys it at every renewal after.
Zylo's 2026 index found 79% of IT leaders faced a price increase at renewal last year, and routine uplifts on sticky applications have drifted from 5-7% toward 15% and above. AT&T alleged in court that Broadcom quoted a 1,050% increase on VMware.
Then the part that never appears in the business case: correlated failure. One faulty CrowdStrike update in July 2024 took down 8.5 million Windows machines, with $5.4bn of direct loss to US Fortune 500 firms by Parametrix's estimate. In October 2025, a race condition in DynamoDB's DNS automation broke us-east-1 for fifteen hours, and plenty of companies who believed they were multi-region found their identity or queueing quietly lived in Northern Virginia. Nine days later, Azure Front Door. Three weeks after that, Cloudflare.
Change Healthcare is the one I think about most: one clearing house touching one in three US patient records. Ransomware hit, providers went weeks without cash flow, UnitedHealth booked $2.457bn in costs. Your real failure domain is the vendor, not the availability zone.
So price it as a trade. Probability of a disabling incident in a year, times the share of your operation inside that vendor's blast radius, times your cost per hour of downtime, times expected hours. ITIC puts an hour above $300,000 for over 90% of large enterprises. Put that annual figure next to the discount in currency, not percentages, and add a modelled 15% renewal uplift in year three. Often the discount stops looking like savings and starts looking like payment for risk you never quoted.
Regulators got there from another direction. DORA designated its first nineteen critical ICT providers in November 2025, including AWS, Microsoft, Google and SAP. The EU Data Act bans switching charges and egress fees from 12 January 2027, making exit cheaper than ever. Worth auditing auto-renewals for anything locking you past that date.
The other side is fair. Running two vendors costs money and migrations fail badly. Birmingham City Council's Oracle Fusion programme went from about £19m to an estimated £216m. A theoretical exit is not leverage.
Which is why the old answer holds. When IBM forced Intel to license the 8086 to AMD in 1982, it was paying a premium to keep a second source alive.
Consolidate where the discount genuinely covers the exposure. Just say out loud what you are buying, and what you are selling to get it.
Vendor consolidation as negotiating leverage: the concentration risk research file
TL;DR
- The CFO's consolidation savings are real but modest (single-digit to mid-teens percentage discounts for volume commitment) and they erode at renewal once you cannot credibly leave; per Zylo's 2026 SaaS Management Index, 79% of IT leaders experienced a price increase at renewal in the past 12 months, and locked-in customers have faced increases ranging from Salesforce's 9% list rise up to the 1,050% quote VMware/Broadcom reportedly gave AT&T.
- The countervailing cost is correlated failure and blast radius: single-provider incidents in 2024 to 2025 (CrowdStrike, Change Healthcare, Synnovis, AWS us-east-1, Azure Front Door, Cloudflare) each took down thousands of organisations at once, with the CrowdStrike event alone estimated by Parametrix at $5.4bn of direct loss to US Fortune 500 firms and the Change Healthcare attack costing UnitedHealth about $2.457bn and touching roughly 190 million people.
- Regulators now treat concentration as systemic risk: EU DORA designated its first 19 critical ICT providers on 18 November 2025, the UK critical third parties regime took effect 1 January 2025, and the EU Data Act bans cloud switching and egress fees from 12 January 2027, all of which make a credible exit cheaper to preserve and therefore strengthen the case for keeping one.
Key findings
- Consolidation buys a one-time discount, not a durable one. Volume commitments earn discounts, but the discount curve flattens and reverses at renewal once the exit threat is gone. Zylo's 2026 index (a survey of 218 IT leaders) found 79% saw a price increase at renewal in the last 12 months, and routine renewal uplifts have moved from 5 to 7% historically to 15%+ on sticky apps.
- The blast radius of a single provider is now measured in thousands of organisations and billions of dollars per incident. CrowdStrike (July 2024) hit about 8.5 million Windows devices and is estimated at $5.4bn direct loss to US Fortune 500 firms. The October 2025 AWS us-east-1 event and the October 2025 Azure Front Door event each cascaded worldwide from a single control-plane fault.
- Healthcare is the cautionary case. The Change Healthcare ransomware attack (February 2024) disrupted a clearing house that processes about a third of US patient records; Synnovis (June 2024) took down NHS pathology in south east London and has been formally linked to a patient death.
- The exit threat is the whole game. The classic industrial answer is the second source (IBM forcing Intel to license the 8086/8088 to AMD in 1982). Once you consolidate, the vendor knows your best alternative is weak, and the economics of the next renewal shift decisively toward them.
- You can price the trade. Combine outage probability, blast radius and downtime cost (ITIC: over 90% of large enterprises put an hour of downtime above $300,000; 41% at $1m to $5m) into an annualised loss expectancy and set it against the consolidation discount and the migration cost of rebuilding an exit.
Details
A) Recent single-provider outages with cross-industry impact
CrowdStrike, 19 July 2024. A faulty content update to the Falcon sensor crashed about 8.5 million Microsoft Windows devices worldwide. Microsoft VP David Weston, in a 20 July 2024 blog, said "we currently estimate that CrowdStrike's update affected 8.5 million Windows devices, or less than one percent of all Windows machines." The bad update was reverted after 78 minutes but recovery took days because each machine needed hands-on remediation. Parametrix (in "CrowdStrike's Impact on the Fortune 500") estimated total direct losses to US Fortune 500 companies (excluding Microsoft) at $5.4bn, with healthcare the hardest hit at $1.938bn and banking at $1.149bn; it put the weighted average loss at $44m per affected Fortune 500 company and estimated about a quarter of the Fortune 500 (124 to 125 firms) were hit. Delta cancelled about 7,000 flights over five days, affecting 1.3 million passengers, and sued CrowdStrike for over $500m; CrowdStrike countersued, blaming Delta's own outdated systems. Cirium counted roughly 16,896 flight cancellations globally over 72 hours. This is the cleanest possible example of correlated failure: one vendor, one update, millions of endpoints down at once.
Change Healthcare / UnitedHealth, 21 February 2024. ALPHV/BlackCat ransomware hit Change Healthcare, a UnitedHealth (Optum) subsidiary. The American Hospital Association states it "annually processes 15 billion health care transactions, touching 1 in every 3 patient records," and Change's own pre-acquisition filings described a network transacting clinical records for over 112 million unique patients (more than a third of the US population) across roughly 900,000 physicians, 33,000 pharmacies, 5,500 hospitals and 600 laboratories. Intruders entered on 12 February 2024 through a Citrix remote access portal that lacked multi-factor authentication. UnitedHealth paid a $22m ransom. The company disclosed about 190 to 193 million individuals affected (the largest US healthcare data breach on record) and total costs rising to about $2.457bn by the Q3 2024 earnings report. Kodiak Solutions estimated the value of claims submitted dropped $6.3bn for its 1,850 hospital and 250,000 physician clients in the first three weeks alone. Providers went weeks without cash flow; UnitedHealth advanced over $6.5bn in loans. This is the single best healthtech illustration of concentration: one clearing house, one attack, the whole US payment rail for medicine frozen. [1]
Synnovis, 3 June 2024. The Qilin ransomware group hit Synnovis, the pathology provider (a SYNLAB joint venture with Guy's and St Thomas' and King's College Hospital trusts) for south east London NHS. More than 10,000 to 11,000 appointments and about 1,710 operations were disrupted or postponed; a national O-negative blood shortage followed because pathology could not do blood matching. In June 2025 King's College Hospital confirmed the disruption contributed to a patient death. NHS data linked nearly 600 patient safety incidents to the attack, including two cases of severe harm. Synnovis only completed its 18-month forensic review and began notifying affected patients in November 2025; CaseMatrix estimated data on more than 900,000 patients was leaked. [2]
AWS us-east-1, 20 October 2025. A race condition in DynamoDB's automated DNS management emptied the DNS records for the DynamoDB API endpoint in Northern Virginia, cascading across dozens of dependent services (EC2, Lambda, IAM, SQS). Disruption ran about 15 hours. Downdetector logged millions of reports; affected names included Snapchat, Reddit, Venmo, Roblox, Fortnite, Coinbase, Ring, and in the UK, Lloyds Bank, HMRC and National Rail. CyberCube estimated insured losses up to $581m. The key lesson repeated across write-ups: many "multi-region" customers still failed because their data stores or control-plane dependencies lived only in us-east-1.
Azure Front Door, 29 October 2025. Nine days after the AWS event, an inadvertent tenant configuration change (a software bug let an invalid config bypass safety checks) propagated across Azure's global edge fabric, producing DNS and routing failures. Microsoft 365, Outlook, Xbox, Minecraft, Copilot and third-party customers including Alaska Airlines, Starbucks, Costco and NatWest were hit for roughly 8 to more than 12 hours. Downdetector logged more than 30,000 reports in the first hour. [3]
Cloudflare, 18 November 2025. A database permissions change caused a query to return duplicate rows, doubling the size of a Bot Management feature file that then exceeded a memory limit and crashed proxies globally. Core traffic was down from 11:20 to about 14:30 UTC, fully resolved by 17:06 (about 5 hours 38 minutes). X, ChatGPT, Spotify, Canva and others went down; Downdetector logged over 2.1 million reports. Cloudflare had further, shorter outages on 5 December 2025 and 20 February 2026, underscoring the recurring pattern.
Fastly, 8 June 2021. A latent software bug from a 12 May deployment was triggered by a valid customer configuration change and caused about 85% of Fastly's network to return errors. Detected within one minute; 95% of the network was back within 49 minutes. Major sites down included Amazon, Reddit, Spotify, the New York Times, the Guardian, the Financial Times, and the UK's gov.uk. [4]
Telco single-supplier failures. Optus (Australia), 8 November 2023: about 10 million mobile customers plus roughly 400,000 fixed-line lost service for about 12 to 14 hours after a BGP routing event; the ACMA found 2,145 people could not reach the Triple Zero emergency line and imposed penalties over A$12m; the CEO resigned. Rogers (Canada), 8 July 2022: about 12 million customers (roughly a third of Canada) lost service for around 24 hours after a router configuration error flooded the core network; 911 calls failed and Interac debit and e-transfer went down nationwide. [5]
Cloud concentration and systemic modelling. Synergy Research Group's Q1 2026 tracker put AWS at 28%, Microsoft Azure at 21% and Google Cloud at 14%, a combined share of more than 60% (rendered as roughly 63%) of the global cloud infrastructure market; Synergy chief analyst John Dinsdale noted "in Q1 the cloud market growth rate increased for the tenth successive quarter," with spend of $129bn in the quarter, up 35% year on year. Lloyd's of London, with AIR Worldwide, modelled that a top US cloud provider going down for three to six days would drive about $15bn of economic loss (95% confidence interval $11bn to $19bn) and up to $3bn of insured loss, with firms outside the Fortune 1000 bearing 63% of the economic loss. A separate 2023 Lloyd's systemic scenario modelled a major financial payments cyberattack at up to $3.5trn of global economic loss over five years. These are modelled scenarios, not realised losses, and Lloyd's-linked modeller Parametrix has argued the older cloud scenario needs updating.
B) Regulatory pressure on concentration risk
EU DORA. In force from 17 January 2025. It creates direct EU-level oversight of critical ICT third-party providers (CTPPs), each assigned a Lead Overseer among the ESAs (EBA, ESMA, EIOPA). On 18 November 2025 the ESAs published the first list of 19 designated CTPPs, including AWS, Microsoft, Google Cloud, Oracle, SAP and Deutsche Telekom. Non-compliance can trigger periodic penalty payments of up to 1% of average daily worldwide turnover per day of breach. DORA also requires financial entities to maintain a register of information on ICT contracts, to assess concentration risk (Article 29), and to have documented exit strategies.
UK critical third parties regime. The Bank of England, PRA and FCA published PS16/24 (FCA PS24/16) on 12 November 2024, with rules effective 1 January 2025. HM Treasury designates CTPs under powers in the Financial Services and Markets Act 2023; regulators recommend candidates. The regime was explicitly informed by the CrowdStrike incident. It sits on top of the earlier operational resilience regime (PS21/3) with impact tolerances. The Bank of England had already flagged cloud concentration in its Financial Stability Report.
US. The Federal Reserve, OCC and FDIC issued final Interagency Guidance on Third-Party Relationships: Risk Management on 6 June 2023 (Federal Register 9 June 2023, 88 FR 37920; OCC Bulletin 2023-17; Fed SR 23-4). The Federal Reserve's 2024 Cybersecurity and Financial System Resilience Report flagged growing systemic risk from concentration on a few technology providers. The underlying legal hook is the Bank Service Company Act plus FFIEC guidance. [6]
Cross-supervisory bodies. The FSB has acknowledged that concentration in one or a few providers is not automatically a systemic problem, a point AWS has cited approvingly in its FSB submission. Bank of England and ECB/ESRB work continues to track the percentage of the sector dependent on the same handful of providers.
Healthcare specific. After Change Healthcare, the US Senate Finance Committee held "Hacking America's Health Care: Assessing the Change Healthcare Cyber Attack and What's Next" on 1 May 2024, with UnitedHealth CEO Andrew Witty testifying. Chairman Ron Wyden said the hack "could have been stopped with cybersecurity 101." Committee leaders framed the risk as healthcare consolidation "creating fewer redundancies and more vulnerability to the entire system if an entity with significant market share at any level of the system is compromised." HHS's ASPR became the designated sector risk management agency for healthcare and launched work to map single points of failure across health IT. In the UK, NHS England ran the Synnovis response; NIS2 in the EU adds parallel obligations for essential and important entities including health. [7]
Egress fees and the EU Data Act. The Data Act entered into force 11 January 2024, applies from 12 September 2025, caps switching charges at direct cost during a transition period, and bans switching charges and data egress fees entirely from 12 January 2027. In 2024, AWS, Google Cloud and Microsoft all announced free egress for customers leaving. Ordinary operational egress is not abolished; only switching-related egress. Egress is reported to be about 6% of cloud storage cost on average.
UK CMA cloud investigation. Referred by Ofcom (which ran a market study finding AWS and Microsoft dominant with limited competition). The CMA published its final decision on 31 July 2025, finding competition "not working well" and three adverse effects: egress fees, Microsoft's software licensing practices (Microsoft charges higher wholesale prices for its software on AWS and Google than on Azure), and technical barriers plus committed spend discounts. It found each of AWS and Microsoft held 30 to 40% of the UK market in 2024. It estimated more effective competition could save customers over £400m a year. Rather than impose remedies directly, the CMA recommended Strategic Market Status investigations under the DMCC Act, with the CMA Board due to decide in Q1 2026.
ERP and core platform migration failures. Birmingham City Council's Oracle Fusion migration (from SAP) went from an original budget of about £19m to an estimated £216.5m by April 2026 per the Sheffield University Audit Reform Lab; the failure contributed to the council's Section 114 (effective bankruptcy) notice in September 2023 and left it unable to file auditable accounts or detect fraud for 18 months. Lidl abandoned a seven-year SAP eLWIS project in 2018 after writing off about €500m (about $600m) and reverting to its legacy system. Gartner has projected that over 70% of ERP projects launched by 2027 will fall short of their business case. These illustrate that the exit or migration you might rely on as leverage is itself expensive and failure-prone.
Renewal price increases for locked-in customers. VMware/Broadcom is the sharpest case: after the $61bn acquisition closed November 2023, Broadcom ended perpetual licences and bundled products into subscriptions. AT&T alleged a 1,050% price increase in litigation; CISPE/ECCO reported European increases of 800% to 1,500% and cumulative increases over 1,000%; Fidelity's November 2025 lawsuit warned of outage risk to 50 million customers; Siemens, Tesco and the Dutch Ministry of Infrastructure also litigated. CISPE filed an EU antitrust complaint and challenged the merger clearance. Salesforce raised list prices an average of 9% in 2023 (its first list rise in seven years, effective August 2023, across Sales, Service, Marketing, Industries and Tableau; for example Enterprise Edition moved from $150 to $165 per user per month) and a further average 6% effective 1 August 2025; its Agentforce agent product launched at $2 per conversation in October 2024, then shifted to consumption-based Flex Credits (about $0.10 per action) in May 2025. Oracle is known for audit-driven true-ups. [8]
Academic framing. Shapiro and Varian's Information Rules (1999) formalised the total cost of switching (the buyer's switching cost plus the new supplier's cost) and argued that a customer's value to a vendor is roughly the total switching cost. Analyst rules of thumb often put migration cost as a multiple of annual licence spend.
D) Economics and game theory of negotiating leverage
How much consolidation actually saves. Procurement platform data suggests real but bounded discounts: Zylo reports organisations save on average about 16.8% at renewal when they negotiate proactively, and that 12-month deals average 16.4% savings versus 14% at 24 months and 13% at 36 months, so longer commitments buy predictability more than price. Tropic data puts initial AI pricing uplifts at 20 to 37%, reducible by about 55% through disciplined negotiation, but still landing about 12% above pre-AI baselines.
Counter-evidence: discounts erode at renewal. Zylo's 2026 index found 79% of IT leaders faced a price increase at renewal in the past 12 months; the same index found 78% experienced unexpected charges tied to consumption-based or AI pricing models, and 61% cut projects because of unplanned SaaS cost increases. Vendors are sunsetting legacy SKUs and unwinding loyalty discounts. Routine renewal uplifts have risen from 5 to 7% to 15%+ on business-critical apps. This is the mechanism by which the leverage argument eats itself: the deeper the consolidation, the weaker the exit threat, and the higher the renewal.
BATNA and the second source. The negotiation concept is BATNA (best alternative to a negotiated agreement); consolidation deliberately weakens your BATNA. The classic industrial precedent is the second source: IBM required Intel to license the 8086/8088 to a domestic second source, and Intel signed AMD in February 1982; when Intel later withheld the 386 to end second-sourcing, litigation followed and AMD won the right to make the Am386. The strategic point is that large buyers historically paid a premium to keep a credible alternative alive.
Multi-cloud and portability overhead. Gartner is blunt that a multi-cloud strategy "increases the complexity and cost of IT" and specifically "increases the direct cost of cloud services because it actually reduces discounts due to lower-volume commitments to each provider." Gartner reports about 76% of enterprises already use more than one public cloud. There is no widely published single percentage for the overhead of a portability layer; the honest framing is that portability is expensive insurance whose main quantified cost is lost volume discounts plus engineering and skills. [9][10]
Pricing an outage against the savings. Splunk/Oxford Economics (June 2024, "The Hidden Costs of Downtime") put downtime at $400bn a year across the Global 2000, about 9% of profits, roughly $200m per company, about $9,000 per minute or $540,000 per hour for that cohort. ITIC's 2024 Hourly Cost of Downtime Survey (which polled 1,000+ firms from November 2023 to mid-March 2024) found the average cost of a single hour of downtime now exceeds $300,000 for over 90% of mid-size and large enterprises, and 41% put hourly downtime at $1m to over $5m; EMA/BigPanda put average downtime at about $14,056 per minute, up to $23,750 for large enterprises. These let the reader convert an outage into money and set it against a consolidation discount.
E) Frameworks for pricing the trade
Concentration measurement. The Herfindahl-Hirschman Index (sum of squared shares) can be applied to a supplier portfolio to quantify concentration; if all spend sits with one vendor the index is at its maximum. SRE literature uses "blast radius" (the set of systems that fail when one component fails) and "failure domain" (the boundary within which a fault is contained); the AWS and Azure incidents are textbook cases of a control-plane failure whose blast radius exceeded customers' assumed failure domains.
Expected loss maths. A simple annualised loss expectancy is: probability of a disabling incident per year, times the fraction of your operation exposed (blast radius), times the cost per hour of downtime, times expected hours. Set that number against the annual consolidation discount. If the discount is, say, single-digit percentage of spend and a multi-day single-vendor outage would cost multiples of that, the trade is unfavourable even before renewal risk.
Real options framing. A credible exit is a real option; its value rises with vendor pricing power and volatility. You can preserve the option cheaply by keeping a small second-vendor footprint, negotiating contractual exit and data-portability rights (now reinforced by the EU Data Act from 2027 and DORA exit-strategy requirements), avoiding proprietary APIs and data formats, and keeping data in portable formats. The cost of the option is the lost volume discount plus some engineering overhead; the payoff is a real BATNA at renewal and a smaller blast radius.
Recommendations
- Quantify before you consolidate. Build the annualised loss expectancy (incident probability x blast radius x downtime cost per hour) and compare it directly to the consolidation discount in pounds, not percentages. If the modelled annual outage exposure exceeds the discount, the consolidation is destroying value even before renewal effects. Threshold to change the decision: a discount large enough (typically well into double-digit percentage of total spend) to cover both modelled outage exposure and the cost of maintaining a credible exit.
- Price the renewal, not just year one. Assume loyalty discounts unwind and model a 15%+ renewal uplift on business-critical, hard-to-leave platforms, plus the VMware/Broadcom tail risk of a step-change increase. Negotiate an annual uplift cap and a rate lock now, while you still have an alternative.
- Keep a credible second source. Follow the IBM/Intel/AMD logic: retain a small but real footprint with a second vendor (or a documented, rehearsed migration path) so your BATNA is genuine. Budget the lost volume discount as the insurance premium.
- Use the regulation as leverage and as a deadline. Exploit the EU Data Act (switching and egress fees banned from 12 January 2027), DORA exit-strategy and concentration-risk obligations, and the CMA's cloud findings to negotiate exit rights, portability and better renewal terms. Audit contracts now for auto-renewal clauses that could lock you in past January 2027.
- Engineer against blast radius. Treat the region or the provider as the failure domain, not the availability zone. Test failover for real (the AWS incident exposed many firms whose "multi-region" setups still depended on us-east-1). For a healthtech company, prioritise the systems where downtime maps to patient safety, as Synnovis and Change Healthcare show that the cost there is not only financial.
Caveats
- Several loss figures are modelled or vendor-sponsored. The CrowdStrike $5.4bn (Parametrix) and AWS $581m (CyberCube) are insurer estimates, not audited losses. Lloyd's $15bn and $3.5trn figures are scenario models with wide confidence intervals. The Splunk $400bn downtime figure is vendor-sponsored (Splunk sells observability) and ITIC/EMA numbers are survey-based and self-reported.
- Some outage detail comes from secondary blogs and aggregators rather than primary post-mortems. Where possible rely on the primary source (Cloudflare's own blog, Fastly's own post-mortem, AWS and Microsoft incident reports, ACMA and CRTC for the telcos).
- Cloud market share varies slightly by analyst and quarter; Synergy's Q1 2026 (28/21/14) is used here, but some aggregators report divergent Azure figures.
- Litigation claims (Delta v CrowdStrike, AT&T v Broadcom, Fidelity v Broadcom) are allegations; the 1,050% and 1,500% figures are as claimed by customers or trade bodies, and vendors dispute them.
- The consolidation-savings figures from Vendr, Zylo and Tropic come from procurement vendors who benefit from portraying savings as achievable; treat as directional.
- Dates are current to late July 2026; the CMA SMS decision was expected in Q1 2026 and DORA designations will be reviewed annually, so both may have moved.
- Nixon Peabody + 5 — https://www.nixonpeabody.com/insights/alerts/2025/11/12/change-healthcare-cybersecurity-breach-impact-on-healthcare-providers
- NHS England + 5 — https://www.england.nhs.uk/london/synnovis-ransomware-cyber-attack/
- Medium + 2 — https://medium.com/@traverlington/when-the-cloud-falls-microsoft-azure-outage-october-29-2025-97d0cae1b6e7
- Fastly + 3 — https://www.fastly.com/blog/summary-of-june-8-outage
- GeoBlackout + 5 — https://geoblackout.com/au/report/internet/optus
- ICBA + 3 — https://www.icba.org/w/interagency-guidance-for-bank-risk-management-of-third-party-relationships
- senate + 2 — https://warren.senate.gov/newsroom/videos/watch/at-hearing-warren-blasts-united-health-ceo-for-monopolistic-practices-that-harm-patients
- Substack + 3 — https://summitstocks.substack.com/p/does-salesforce-have-pricing-power
- Gartner — https://www.gartner.com/en/documents/5219163
- IT Convergence — https://www.itconvergence.com/blog/multi-cloud-strategies-the-2025-2026-primer/
Commissioned from our research desk. Subject to final editorial discretion.