Cloud-based IAM solutions provide clear benefits for both the customers and the vendors. There is, however, the question of what happens if the cloud-based IAM solution becomes unavailable. This could be due to a number of reasons: IAM vendor has an outage or the connection between the customer to the cloud IAM is interrupted somehow (I'm looking at you, dragging ship anchor...).
Any good disaster recovery plan must account for complete or partial outages—not only of internal systems but also third-party resources. Regulations such as DORA and NIS2 mandate not only technical controls like multi-factor authentication (MFA) but also require organizations to be resilient in the face of service disruptions.
This makes questions like, "What happens if our cloud MFA provider becomes unavailable, and how do we recover from that?" extremely relevant.
So… what’s your plan in the event of an outage? You do have one—besides "Wait and hope it'll come back soon," right?