BOOK A CALL

Cloud Cost and Vendor Risk: What a CTO Should Review Every Quarter

cloud & infrastructure Sep 08, 2026

Cloud spend is one of the few line items in a scaling business that grows almost invisibly. Nobody signs off on it the way they'd sign off on a new hire, it just accumulates, contract by contract, team by team, until finance asks why the bill doubled and nobody can give a clean answer.

At the same time, the vendors behind that spend, cloud providers, SaaS tools, managed services, are quietly becoming the biggest concentration of operational risk in the business. If one of them has an outage, a breach, or a sudden licensing change, it doesn't stay their problem. It becomes yours, on their timeline, not yours.

Most £5-50m businesses don't have anyone whose job it is to look at this properly, on a schedule, before it becomes urgent. That's usually because the CTO role, where one exists, is stretched across delivery and hiring and the day job, and a quarterly vendor and cost review is the first thing to slip.

Here's the review we'd run, and what we look for in each part of it.

1. Actual spend against what you committed to

Most cloud contracts now involve some form of committed spend or reserved capacity in exchange for a discount. The problem is that commitments are usually set once, at renewal, and then nobody checks whether actual usage is tracking against them until the next bill arrives. Quarterly, you want a clean answer to three questions: are we using what we committed to, are we paying for capacity we no longer need, and is our discount rate still competitive against what we'd get if we renegotiated today. Businesses that do this well typically find a meaningful share of spend sitting in commitments that no longer match usage, though the exact number depends entirely on how the environment has changed since the last renewal.

2. Vendor concentration risk

This is the question boards rarely ask and CTOs rarely volunteer: what happens to us if this one vendor has a bad month? For most scaling businesses, that's not an abstract question, it's usually one cloud provider and two or three SaaS tools that the whole business depends on. Quarterly, map which vendors would cause genuine operational disruption if they went down for a day, had a security incident, or changed their pricing model overnight. If the answer to "could we operate without this vendor for 48 hours" is no, and you haven't tested that assumption, that's the finding worth taking to the board.

3. What's coming up for renewal, and on what terms

Contract renewal dates have a habit of arriving as a surprise, and price-escalation clauses are often written in a way that makes the real number hard to see at signing. A quarterly review should produce a simple forward-looking list: what renews in the next two quarters, what the renewal terms actually say about price increases, and which of those conversations need to start now rather than thirty days before the deadline. Vendors negotiate harder when they know you're not paying attention. A CTO who can walk into a renewal conversation with usage data and a credible alternative in hand gets a materially different outcome than one who can't.

4. Data portability and exit cost

Ask, for each critical vendor: if we had to leave in 90 days, what would that actually cost us, in migration effort, in data egress fees, in rebuilding integrations. Some vendors make this easy. Many, deliberately or not, make it expensive enough that "we're stuck" becomes the default answer nobody says out loud. Knowing that cost in advance changes your negotiating position and your risk appetite.

5. Shadow provisioning

In most scaling businesses, someone outside the core engineering team has a company card and access to sign up for cloud resources or SaaS tools without going through procurement. That's not a discipline problem, it's a visibility problem, and it usually means real spend and real risk sitting outside whatever review you think you're running. A quarterly pass should include reconciling actual billed vendors against the ones your central register knows about.

6. Vendor resilience and security posture

Finally, for the vendors that matter most, ask what you'd genuinely want to know before a client asked you the same question about your own business: are they independently audited, do they subcontract critical functions further down the chain, and have they had a public incident in the last 18 months. You don't need to police every vendor to this standard, but the ones your business would struggle without deserve this level of scrutiny at least once a year, reviewed as part of the same quarterly cadence.

None of this is exciting work, and that's exactly why it doesn't happen without someone owning it. A fractional CTO who's run this review across several businesses tends to spot the drift faster, because they've seen what normal actually looks like elsewhere.

Get actionable advice every Saturday

The CTO’s Playbook

Join 3,267 CEOs, COOs & developers already getting actionable advice, stories, and more.