For about four hours on a Tuesday morning, a large portion of the internet stopped working.
Not dramatically. There was no error message explaining what had happened. Sites simply hung, then timed out. Payment systems failed silently. A hospital’s scheduling software returned a blank screen. Somewhere, a support team began fielding calls it had no answer for.
The cause, it emerged later, was a configuration change at a single company — one that most of the people affected had never heard of, and could not have named if asked.
This is the part of the internet nobody looks at. Not the apps, not the websites, but the layer underneath them: the routing, the caching, the domain resolution, the certificate authorities. The plumbing. It works so reliably that it has become invisible, and invisibility has been very good for the small number of companies that own it.
The map nobody draws
Ask someone to describe the internet’s structure and they’ll usually describe the visible part — the platforms, the browsers, the services they use daily. That layer is genuinely competitive. There are dozens of options for almost everything.
The layer underneath is not.
We spent several weeks pulling apart the dependency chains of a sample of widely-used services: what they run on, what that runs on, and what sits beneath that. The exercise is harder than it sounds. Companies don’t publish this. Infrastructure relationships are disclosed inconsistently, if at all, and the deeper you go, the thinner the public record becomes.
What emerges is a pyramid that narrows sharply. Thousands of services at the top. A few dozen meaningful providers in the middle. And at the base, a handful of companies on which a startling proportion of everything above them silently depends.
How it happened, without anyone deciding it should
There was no conspiracy here, and that’s the genuinely interesting part. Nobody set out to build a chokepoint.
Infrastructure has enormous economies of scale. The cost of serving the ten-thousandth customer is a rounding error next to the cost of building the system in the first place. That economics rewards size relentlessly, and it punishes the mid-sized competitor who is large enough to have real costs but too small to spread them.
So the middle emptied out. Not through any single dramatic acquisition, but through a slow, unremarkable series of them — the kind that clear regulatory review easily, because at the time each one looked small.
Reviewed individually, every one of those deals was defensible. Reviewed as a sequence, they describe a market that no longer exists in any competitive sense.
What the concentration actually costs
The obvious risk is the one everyone noticed in March: correlated failure. When many independent-looking services rest on the same foundation, they are not independent. They only appear that way until the foundation moves.
The less obvious cost is the one that never makes the news. Concentrated infrastructure is a concentrated point of leverage — over pricing, over terms, over who gets served at all. A company that controls a layer everyone needs doesn’t have to do anything dramatic with that power for the power to be real.
What happens next
The honest answer is: probably nothing, for a while.
Infrastructure is boring. It has no constituency. It generates no outrage until it fails, and when it fails, the outrage lasts about a news cycle before everyone goes back to work.
But the March outage was not an anomaly. It was a demonstration. The structure that produced it hasn’t changed, and on current trends, it is still consolidating.