Major retail bank (pattern case) · 2014 · cost index 4/5

The ESB hub that became the outage

Hours of nationwide payment and branch downtime; remediation and audit costs in the tens of millions

What happened

Enterprise Service Bus was sold as loose coupling. In production it became the one throat to choke: every payment, account lookup, and branch terminal route flowed through a clustered middleware layer nobody fully understood until it fell over on a Tuesday.

Failure mode

Hub-and-spoke integration masquerading as SOA maturity. Teams published WSDL and called it decoupling while the ESB team became a human change-control bottleneck. A botched deployment or certificate rotation took down channels that had nothing to do with the "fixed" service.

Lesson

If your architecture diagram has one box in the middle of everything, you built a monolith with XML and worse on-call. Prefer boring HTTP, clear ownership, and blast-radius limits over ceremonial orchestration.

Sources

  • IBM WebSphere / Oracle Service Bus outage postmortems (industry pattern)
  • Gartner — ESB hub risks in retail banking
  • FCA / PRA outage reporting themes

Related tech

← All cases

© 2026 Fadstack · Shane Code

Opinionated history · not a ranking