At the ASF, there is an infrastructure team that manages those type of issues. They work hard and do a lot of good but unfortunately, there was a disconnect back in 2009 and a backup request was not implemented correctly.
An untested backup is not a backup. Some people only ever seem to learn that the hard way.
To be honest, given the popularity of SA and the relative importance of the sa-update service it's astonishing that such a SPOF with such a lax management routine was allowed to occur.