The only backup that counts is the one you have already restored
On 15 September 2026, Amazon Web Services wrote that it could not restore access to resources and data hosted exclusively in its Bahrain region. The three availability zones of that region were damaged by Iranian strikes, in March and then in April. Its own documentation states that those zones all sit within a hundred kilometres of one another.

Between 2021 and 2024, I ran around a hundred audits of public administrations in Wallonia, under a ministerial mandate. The question of backups always came up at the same point in the morning, and the answer came back with a regularity that ended up interesting me more than the question itself. It is in the cloud. Nobody was lying, nobody was trying to dodge, and nobody knew where the second copy was, who had last restored it, or what would remain if the building holding the first one ceased to exist.
The same reflex exists outside work. We delete a photo without thinking, we close a laptop knowing everything is synced, we hand ten years of accounts to an online tool whose hosting page we have never read. The word cloud switches off part of the reasoning, while it designates somebody else's computer, sitting in a building that somebody can reach.
What Amazon wrote on 15 September
AWS determined that it was not able to restore access to resources and data hosted exclusively in the region concerned. For the United Arab Emirates, the sentence covers one of the three availability zones, mec1-az2. For Bahrain, it covers the entire region.
The damage spanned several availability zones and exceeded what regional and multi-zone services are designed to withstand, the company writes. The first strikes hit one Bahrain zone and two facilities in the Emirates in early March 2026, in a conflict that had opened in late February. In April, a second Bahrain zone was hit and the region became unavailable. The provider's Israeli and Saudi sites stayed outside the perimeter. An update on Bahrain is announced for early 2027.
Six months separate the first strikes from that publication. During those six months, the case looked like a long outage, with a status dashboard, incident messages and teams at work. On 15 September it closed without restoring anything. Amazon can buy machines, replace racks, rebuild a building, and none of those investments recreates information whose last copy has gone.
AWS states that most customers in both regions had moved their workloads before the losses became final, by restoring backups or copying data that remained accessible. Those who held a copy elsewhere went through an expensive migration. For the others, the word exclusively was about them.
Why do three availability zones not make three places?
An availability zone, in the AWS definition, is one or more discrete data centres, with redundant and separate power, networking and connectivity, inside a region. Generators and cooling equipment are not shared between zones, and each zone depends on a different electrical substation. That separation has prevented a considerable number of incidents nobody ever heard about.
The same documentation adds that the zones of a single region all remain within a hundred kilometres of one another, linked by dedicated fibre that allows synchronous replication with a latency of a few milliseconds. Proximity is the price of performance, and AWS writes it down.
A hundred kilometres is enough against a local flood, against the failure of a substation, against a building fire. Faced with a campaign of strikes aimed at a geographical area, the distance shrinks to a margin of error.
S3 Standard spreads data across several devices in at least three zones of a single region, with an advertised durability of 99.999999999 %, and the service is designed to preserve data in the event of the loss of an entire zone. The reference scenario is therefore the loss of one zone. The eleven nines describe resistance to equipment failure, and an entire region disappearing falls outside that frame. The S3 One Zone-IA class, which stores in a single zone only, falls outside it faster still.
Counting copies tells you nothing. The useful question is what can disappear during the same event, and that list appears neither on a sales page nor on an invoice.
Strasbourg, the night of 9 to 10 March 2021
On the night of 9 to 10 March 2021, the SBG2 data centre of OVHcloud burned down in Strasbourg.
SAS France Bâti Courtage, a construction broker, had taken out an automated backup option. The three replicas sat in the same place as the main server and burned with it. On 3 February 2023, the Lille Métropole commercial court ordered OVHcloud to pay 101,102 euros, holding that by storing the three replicas in the same place as the main server, the host had not met its contractual obligations.
The same court ruled on a second case on 16 March 2023, for 153,837 euros. The company Bluepad believed its production data was at SBG1 and its backups at SBG2. Both sat in the same building. The backup server was recovered after the fire, then restarted by engineers with purge scripts that erased what it still held.
What « physically isolated » means to a court of appeal
OVHcloud appealed. The Douai Court of Appeal handed down its ruling on 24 April 2025 and set aside force majeure, on the grounds that a fire is among the risks a data centre operator must anticipate.
The rest of the decision favours the host. The contract stated that the backup option was « physically isolated » from the infrastructure hosting the server. The court read that expression as separated from what is adjacent, without finding in it any requirement of geographical distance. Nothing contractually obliged OVHcloud to replicate backups across two distant sites, and a customer who wanted that could subscribe to a disaster recovery plan, a separate and paid offer. The breach of the backup obligation was upheld, gross negligence was set aside, and compensation was cut to the contractual cap of 1,800.48 euros.
The word isolated belongs to everyday language as much as to technical vocabulary, and the seller's reading prevailed. A company signing a backup clause today without having its supplier spell out in writing what it means by isolated is buying that risk.
Are your photos backed up, or only synced?
You see a photo on your phone, on your computer and on your tablet. It appears to exist in three places. The impression comes from a sync function doing exactly what it was built for, keeping a collection consistent across several devices.
Apple documents it. A photo deleted on one device is deleted everywhere you use iCloud Photos, with thirty days to recover it from the Recently Deleted folder, after which it disappears permanently. The support page states that synced photos are not copied into the device's iCloud backup, and recommends keeping separate copies of your photo library.
Deletion travels the same path as addition. A file visible on three screens has been made accessible, which settles a question of convenience and leaves the question of its preservation entirely open. Getting it back after a deletion, the loss of an account, an unpaid bill or the destruction of its hosting depends on an arrangement nobody puts in place for you.
The cloud is somebody else's computer, and that computer is somewhere
The buildings hit in March were hit by military strikes, in a conflict that opened in late February 2026. The availability of a commercial service depended on a military decision taken elsewhere.
That dimension sits badly with an obligation we collectively demanded. Localisation requirements force many organisations to keep their data in a given country. AWS addresses the subject in its disaster recovery documentation: where a locality has only one region, the provider indicates that it is possible to use the availability zones of that region as separate locations, which can help meet data residency requirements.
Bahrain had one region. The pattern that has just failed is the one the documentation presents as an acceptable answer to a regulatory constraint.
I have defended digital sovereignty for years and I continue to defend it. It loses its value as soon as it produces architectures that concentrate risk. Three copies within a hundred-kilometre radius, on the edge of a conflict zone, protect a legal category and leave the data exposed. The same provider writes in the same document that backing up to another region costs little compared with the other multi-region options.
What DORA and NIS2 already require, and what almost nobody restores
The NIS2 directive lists business continuity, backup management, disaster recovery and crisis management among the measures essential and important entities must take, in Article 21(2)(c). The text goes into no architectural detail, and leaves the entity to demonstrate that its measure is proportionate to the risk.
The DORA regulation is more precise for the financial sector. Its Article 12 requires backup policies specifying the scope of the data covered and a minimum frequency based on the criticality of the information, with periodically tested restoration procedures. Paragraph 3 requires restoration to take place on systems physically and logically separated from the source system. Entities other than microenterprises must also maintain redundant ICT capacities.
The useful criterion arrives in paragraph 5, reserved for central securities depositories: their secondary processing site must be at a geographical distance from the primary site sufficient for it to bear a distinct risk profile. The formula therefore exists in European positive law, locked inside the narrowest paragraph of the article. The whole rest of the market works with the word separated, which Douai has just reminded us can mean the room next door.
AWS writes in its disaster recovery guide that the only recovery path that works is the one you take frequently. The same document warns against rarely exercised recovery paths, against configuration drift in the standby region, against insufficient service quotas that are discovered on failover day. It adds that continuous replication protects against certain disasters without protecting against corruption or deletion of data, unless you have versioning or point-in-time recovery.
Across some forty NIS2 and CyFun compliance engagements, I have read a great many compliant backup policies, and very few full restore reports dated less than twelve months ago.
What would actually protect
Asking every user to audit the architecture of every service they use would shift the burden onto the person holding the least information. The useful demand is addressed to the provider, and it fits into a few written requirements.
The contract, or its technical annex, states the region and availability zone where each copy resides, under their exact identifier, of the me-south-1 or mec1-az2 kind. A provider name is not a location, a mention of a continent is not a region.
The provider gives the date of the last real restore, meaning the moment this precise dataset was brought back up on a separate system, with the time it took, the volume missing and the name of the person who ran the operation. A green execution report establishes none of those four things.
The contractual cap is written in euros, next to an estimate of what losing the data is worth to the organisation. Douai set that cap at 1,800.48 euros in a case where the first instance had assessed the loss at 101,102 euros. A director who knows both figures can make a decision. One who knows only the first discovers the second in court.
Then comes the annual exercise, run with the primary region declared unavailable, on production or on a faithful copy, followed by a report listing what did not work. An exercise that succeeds on the first attempt has probably tested nothing.
That leaves the case of vendors building on top of a host. The shared responsibility model published by AWS splits obligations between the provider, which protects the infrastructure, and its customer, who keeps responsibility for data, applications and their configuration, with variations depending on the services used. That split is documented and legitimate. It provides no explanation to the freelancer who entrusted ten years of files to the software built on top, who chose neither the region nor the failover architecture, and who may not know the name of the company storing her files. That translation belongs to the vendor, and almost nobody writes it.
On 10 March 2021, a building burned in Strasbourg and three copies burned with it. On 24 April 2025, a court of appeal ruled that the word isolated had never promised distance. On 15 September 2026, Amazon wrote that it could not return what had been entrusted to it. The new machines, meanwhile, always arrive.
Further reading
- The AWS incident: it was not an outage, it was a reality check
- When the internet coughs, everyone catches a cold: why the Cloudflare outage concerns us all
- NIS2 in 2026: France falls behind
- Cybersecurity: for a real and civic digital sovereignty
- Concrete steps, by user profile, are gathered on etrecyber.fr.
Sources
- Reuters, Amazon's AWS is unable to restore access to Bahrain, one UAE cloud data zone after war, 15 September 2026.
- WIRED, Customer Data Permanently Lost in Iran Strikes on Amazon Data Centers, 17 September 2026, and The Register, AWS says wartime damage means some Middle East cloud resources are gone for good, 16 September 2026.
- The National, Amazon Web Services unable to restore Bahrain data network knocked out by Iran, 15 September 2026, for the timeline of the strikes and the scope of the sites spared.
- Amazon Web Services, AWS Fault Isolation Boundaries, Availability Zones section, and Amazon S3 Data Durability, user documentation.
- Amazon Web Services, Disaster Recovery of Workloads on AWS: Recovery in the Cloud, sections on what differs in the cloud, recovery options and testing disaster recovery.
- Amazon Web Services, Shared Responsibility Model, compliance page.
- Lille Métropole commercial court, judgment of 3 February 2023, SAS France Bâti Courtage v OVHcloud, and judgment of 16 March 2023, Bluepad v OVHcloud, reported by Le Monde Informatique and Blocks and Files.
- Douai Court of Appeal, ruling of 24 April 2025, OVHcloud v SAS France Bâti Courtage, analysed by LeMagIT and Le Monde Informatique.
- Apple, Set up and use iCloud Photos, Apple support, French version.
- Regulation (EU) 2022/2554 (DORA), Article 12, and Directive (EU) 2022/2555 (NIS2), Article 21(2)(c).
Frequently asked questions
Is my data lost if my host loses an entire region?
It is if the lost region held the only copy, which is exactly what the AWS wording about resources and data hosted exclusively in the region concerned refers to. An organisation that held a copy in another region, or with another provider, went through an outage and a restore operation without permanent loss.
What exactly is an availability zone?
AWS defines it as one or more discrete data centres, with redundant and separate power, networking and connectivity, inside a region. Zones in the same region share neither generators nor electrical substations, which protects them from each other for local incidents. They all remain within a hundred kilometres of one another, which limits how far that protection reaches against a large-scale event.
Is the responsibility not first and foremost the customer's?
Contractually, yes, and the Douai ruling confirms it for the part concerning the distance between backups. The AWS shared responsibility model also places data protection on the customer's side. The objection loses its force as soon as the end customer differs from the one who signed the hosting contract: the freelancer using an online tool lives with an architectural choice they did not make and that nobody ever explained to them.
Do the GDPR or NIS2 require a backup outside the region?
Neither text sets a distance. NIS2 requires business continuity, backup management and disaster recovery among its risk management measures, leaving the entity to demonstrate that its arrangement is proportionate. DORA is the only one to state an explicit distance criterion, reserved for the secondary processing site of central securities depositories, which must present a distinct risk profile.
How do I check that a backup is actually recoverable?
By restoring it, onto a system physically and logically separated from the source system, until you have a working service and data that somebody verifies. The useful report states the date, the time it took, the volume missing relative to the moment of the simulated disaster, and the list of what failed on the first attempt. A test limited to reading the archive without restoring it proves nothing usable.
Should we leave the cloud and go back to hard drives?
Changing where data is kept does not determine what protects it, and setting the word cloud against the word local avoids the only useful question. Two providers that depend on the same building offer one protection against the destruction of that building, while two distant sites of a single provider offer two. Independence is judged on what can fall together, and the number of logos on a contract does not measure it.

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
