A risk assessment and threat analysis typically requires a definition of who the adversary is and what the risk of using any service is in regard to that adversary.
Reasons I heard for a lot of companies to not use GCP/AWS/Github simply were: It is a US company, it will be very easy for CIA to retrieve that data (https://en.wikipedia.org/wiki/CLOUD_Act) or poison the service, let's use XYZ local provider.
And the ironic thing is that these local providers had either a terrible reliability record or poor security posture so a mildly competent mediocre hacker would be able to compromise the data which is being defended against CIA. Not once in tens of engagements I came across a calculated measure of defending against nation-state vs run-of-the-mill malware.