Survivable Hybrid Cloud

Designing Resilient Architectures for Critical Infrastructure

PhD Research by R. Alan Axford

6 Case Studies
£3.7B Total Impact Analyzed
3 Interactive Tools
0 External Dependencies

⚠️ Critical Research Finding

Analysis of six major 2025 incidents reveals a paradigm shift: Modern infrastructure failures stem from configuration errors, supply-chain vulnerabilities, and identity-layer attacks—not hardware failures or capacity limits.

This research develops practical frameworks and working tools enabling organisations to maintain operational continuity during catastrophic third-party service failures, including war scenarios and nation-state attacks on critical infrastructure.

📊

Case Studies

Detailed analysis of 6 major incidents from 2025: AWS, JLR, M&S, Renault, Cloudflare, and Gainsight. Combined economic impact exceeding £3.7 billion.

Explore Case Studies →
🎓

Research Proposal

Comprehensive PhD research proposal addressing systemic third-party risk in critical infrastructure through design-science methodology.

Read Proposal →
🛠️

Assessment Tools

Interactive tools for dependency scanning, risk assessment, and vendor evaluation. 100% offline-capable, practicing defensive coding principles.

Launch Tools →
📚

Educational Guides

Comprehensive references on web dependencies, third-party risks, and defensive IT principles. Practical mitigation strategies included.

Learn More →
💡

Proposed Solutions

Survivable hybrid cloud architectures, defensive IT frameworks, and strategic retreat models for critical infrastructure resilience.

View Solutions →
⚔️

War Scenarios

Planning frameworks for catastrophic failures: internet infrastructure attacks, cloud provider seizure, and critical infrastructure protection.

Explore Scenarios →

Key Research Findings

🔴 Configuration Over Infrastructure

Modern failures stem from automation logic errors, not hardware failures. Cloudflare: 27-minute outage from config error.

⚠️ Supply Chain Cascades

Shared suppliers create cross-competitor vulnerabilities. Renault/JLR: same Tier-2 supplier compromised both.

💥 Identity-Layer Attacks

OAuth token hijacking bypasses platform security. Gainsight: ~200 orgs exposed via stolen credentials.

📚 Economic Scale

Single incidents impact national GDP. JLR: £1.3B loss reduced UK Q3 GDP by 0.1%.

🛡️ Defensive IT Philosophy

This research platform demonstrates its own thesis: Critical infrastructure must not depend on external services for core functionality.

  • Zero CDN dependencies - All assets locally hosted
  • No external fonts - System fonts only
  • No analytics tracking - Privacy by design
  • No authentication services - Self-contained architecture
  • 100% offline capable - Works on isolated networks

If the internet fails, this research remains accessible. That's the point.

About This Research

Researcher Profile

R. Alan Axford brings 30+ years of financial-sector systems consulting experience, specialising in large-scale software integration, operational resilience, and continuity planning. Academic qualifications include B.Sc. Electronic Engineering (1973) and M.Sc. Software Engineering.

Research Status

This website documents ongoing pre-doctoral research commenced November 2025 following the AWS Global/London Region outage of 20 October 2025. Weekly incident analysis continues, expanding the evidence base for proposed PhD research on survivable hybrid cloud architectures.

Research Approach

Employing design-science methodology to develop, implement, and validate practical solutions. Working prototypes and assessment tools demonstrate immediate applicability while contributing to academic knowledge. Research addresses not only current operational risks but emerging threats including nation-state attacks on critical infrastructure.