Natural hazards, public cloud regions, provider outages, and standing geopolitical watchpoints — on one canvas, pulled live from the agencies that publish them, with every source named. Nothing loads until you press the button.
Most risk programs hold geography as a text field. The business impact analysis names a site, the vendor register names a hosting region, the continuity plan names a recovery location — and none of those three fields are ever compared to each other, or to what is happening in the world today. The moment you put them on a shared coordinate system, questions that were invisible become obvious: how many of our critical processes recover into the same metro, how many of our vendors sit in the region that just flooded, whether our failover target is two hundred miles from our primary or two.
This map is a public demonstration of that idea, not a product. It plots the hazard picture and the cloud footprint that every organization shares, because those are the two layers anyone can verify. The version that matters is the one where the third layer is your sites, your vendors, and your recovery targets — and where the concentration you find is your own.
Everything here is deliberately auditable. Each signal names the agency that published it and links back to the record. Where a provider does not expose a feed a browser can legitimately read, this map says so rather than quietly routing around it. That is the same standard I would hold a vendor's risk dashboard to.
Shape carries category — circles are events that happened, squares are infrastructure, diamonds are standing political conditions. Colour carries severity, and nothing else.
Floods, cyclones, earthquakes, volcanic activity, wildfire and drought from GDACS, USGS, NASA EONET, and the US National Weather Service. Colour is the publishing agency's own alert level, not mine — I do not re-score other people's science.
Every announced AWS, Azure, and Google Cloud region, drawn from published documentation. Google Cloud incidents are read live and light up the specific regions they affect. Hover any region for its code and geography.
A short, hand-maintained watchlist of chokepoints and conflict zones with real operating consequences — shipping lanes, semiconductor concentration, subsea cable corridors. Curated and dated, and labelled as such rather than dressed up as a feed.
Live UK FCDO travel advice for every country that hosts a public cloud region — so a region's dot carries its jurisdiction's advisory level alongside its provider. A travel advisory isn't an outage signal; it speaks to staff movement, vendor site visits, audit access, and duty of care around infrastructure you depend on. The US State Department publishes the same thing but without cross-origin headers, so it isn't readable here.
Eight thresholds, each stating what normal looks like before it reports. That is the difference between a monitoring board and a news feed — a green row is evidence a threshold was checked, not an absence of information. They read across every other layer: a severe hazard within 300 km of a cloud region, a Kp index above 5, a CVSS 9 with a high exploitation probability.
Space weather from NOAA — the Kp index and the R/S/G storm scales that quietly degrade GNSS timing, HF comms and satellite operations. Plus the week's highest-severity CVEs from NVD, scored by CVSS and by FIRST's EPSS: how bad it would be, next to whether anyone is actually exploiting it. Neither is geographic, so both get a readout rather than a pin.
Live status for the providers a control environment quietly runs on — Cloudflare, GitHub, Slack, Twilio, Datadog, Snowflake, Stripe, DigitalOcean. They publish a global status rather than a located one, so they get a rail instead of a pin.