UAE facilities directly struck: 2 (Source: AWS status update as reported by Reuters and InfoWorld (September 29, 2026))
Every resilience design has an edge
Ship builders split a hull into watertight compartments. One breach then does not sink the vessel. The design fails only when damage hits more compartments than the builder planned for.
Cloud providers use the same idea. They split a region into availability zones. Each zone is a separate group of data centers, built to fail on its own.
This week, Amazon Web Services said where that idea stopped working. The lesson for executives is simple. A resilience promise covers only the failures its designers pictured. Anything beyond that is your risk.
What AWS has said
The facts here come from an InfoWorld column by David Linthicum. He relays a Reuters report on an AWS status update. We have not seen the update itself.
In that account, AWS says it cannot bring its Bahrain region back. The war involving Iran caused the damage.
Linthicum dates the trouble to March. He says it followed Iranian missile and drone strikes on Israel and on Gulf states that host US bases.
Two AWS facilities in the UAE were hit directly. A drone strike near a Bahrain facility also damaged equipment. By April, a second Bahrain zone had failed. That left the whole region effectively unusable.
Why multi-zone design was not enough
AWS said the Bahrain damage reached several zones at once. In its own words, it "exceeded what our regional and multi-AZ services are designed to withstand."
Boards should note this. Many companies treat a multi-zone setup as the end of the resilience job. It guards against a local fire or a power failure. AWS now says it did not cover this event.
Linthicum argues that no provider could have engineered around a drone strike. That seems fair. It also means the fix cannot come from the provider alone.
A timeline measured in months
The UAE problem is narrower. One of the three zones there cannot be recovered. Anything that lived only in that zone, called mec1-az2, is affected.
AWS has told officials in both countries. It is also assisting customers who want to run their work in other regions.
AWS expects to share a UAE update in the coming months. Its Bahrain update will wait until early 2027. Work that stopped in March could stay stuck for close to a year.
The provider you do not know you use
Linthicum names a second risk. He writes that big outages at AWS and Microsoft in 2025 cost many companies billions of dollars.
Many of those companies did not use those clouds directly. They bought software from a vendor that ran on one of them.
So your exposure may sit two steps away. Your payroll, CRM or logistics vendor may rely on a region you have never reviewed. You have no contract with the provider that actually failed.
The column is an opinion piece. The 2025 loss figures are Linthicum's, and he gives no breakdown. The Bahrain and UAE details rest on the AWS update as Reuters reported it.
Questions to put to your team
First, can we list which critical services run in which cloud regions? Include our vendors' services. Linthicum says most enterprises last year could not answer this without weeks of digging.
Second, would our design survive the loss of a whole region, not just a zone? Spreading across regions costs more. Weigh that against the cost of a year without service.
Third, have we tested the loss of a full region, vendors included? Are our backups kept apart from the failure, both physically and logically? Can we restore within our stated recovery time and data-loss limits?
Linthicum still calls the cloud the right choice for most workloads. Nothing here argues for leaving it. It argues for reading the fine print on what "resilient" covers.
A recovery plan is a claim about the future. Test it before an event tests it for you.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: InfoWorld.





