There is an old AWS quote that has aged in a particularly interesting way.
In 2017, CBS asked AWS executive Matt Wood a rather pointed question:
CBS: “I don’t mean to give anyone ideas, but let’s say I figured out that one of these unmarked buildings was an AWS data center, and I blew it up. Are you saying that it’s so backed up and redundant that you probably wouldn’t notice?”
AWS: “Yeah, you wouldn’t notice. I mean, we might be a bit upset, but you wouldn’t notice!”
Nine years later, somebody effectively ran the experiment, although on a much larger scale than the loss of a single building, and people did, in fact, notice. //
I Guess Maybe Now They’ll Do 3-2-1 Backups
The gold standard for data protection is “3 copies, 2 different kinds of media, 1 of which is offsite”.
I’m all for the cloud, but if it’s important data and you’re limited to keeping all of your cloud data in one set of buildings…then for pity’s sake, have off-site backups. You don’t need to have another failover site ready to light up if Amazon goes down for you, but you shouldn’t lose the data. Replicate it off-site. I mean, forget even acts of war – what if hackers get into your systems? Into Amazon’s systems? What if an employee goes rogue? What if, what if…
A replicated off-site solution with ransomware protection and disk snapshots (or heaven forbid, tape!) doesn’t mean you can restore service quickly, but it means you won’t lose the data. In other words, go ahead and say “if we have to go to that dire situation, we’re not promising a recovery time objective (RTO). But we are promising a Recovery Point Objective (RPO).”
Losing data sucks.