Cloud storage providers are, on the whole, more reliable than the infrastructure most organisations could operate themselves. Their outages make headlines because they are rare, not because they are common. The risk that does justify attention is the quiet one: a single provider holding both the live copy of business data and every copy of the backup of that data, with the assumption that the provider's internal resilience removes the need for an independent second copy.
That assumption fails for three distinct reasons. The first is account compromise. A credential breach that reaches administrative level can result in deletion of both data and backups inside a single session, and recovery depends entirely on the provider's retention window. The second is misconfiguration. Retention policies are often set once and then forgotten; we have seen cases where the retention window was shorter than the interval between audits that would have caught the error. The third is billing or contractual dispute, during which access to data can be suspended or lost with short notice.
None of these scenarios requires any technical failure on the provider's side. All of them are in scope of the risks a business has to manage for itself.
The practical answer is not to distrust the provider, but to maintain at least one copy of business-critical data outside the provider's administrative boundary. That copy does not need to be large or expensive; it needs only to be independent, regularly refreshed, and occasionally test-restored. The cost is modest. The alternative, as we see regularly, is a recovery engagement under time pressure.