If systems designed to withstand war cannot cope with sustained physical attacks, civilian bit barns have little chance. The episode also underlines a familiar but easily neglected lesson: resilience within one cloud region is not the same thing as maintaining an independent backup elsewhere.
Physical destruction is not the only threat. A major outage of the UK air traffic control system in September, which stranded hundreds of thousands of passengers and led to thousands of flight cancellations, was reportedly triggered by a military aircraft filing an incompatible flight plan. Presumably Flight Lieutenant Bobby Tables has been reprimanded.
The apparent failure to validate the flight plan data was not the worst of it. NATS, which runs the UK's air traffic control system, reportedly told airports and airlines that no backup system was available because it was undergoing a "complete overhaul." Nor was there a backup of the live data, supposedly because of the "vast amounts" involved.
If your system produces too much data to back up, you had better be running a particle collider or a giant telescope. Otherwise, you may be in the wrong business. More charitably, backup strategies are complicated, expensive, and difficult to test. They also suffer from the insurance problem: while nothing is going wrong, management sees only capital and operating expenditure with no obvious return. //
The development of marine insurance in 14th-century Italian city-states spread risk and helped make what became today's global trading network viable. The loss of a vessel was no longer an existential disaster for its owner. Provided insurers understood and priced the risks correctly, the market could grow in lockstep with mercantile activity. Data resilience has a similar dynamic, although it is rarely described in those terms. Modern IT would be impossible without it, and moving off-premises amounts to sharing some of that risk with an outside provider. //
It may take the combination of geopolitical instability and intense competition for storage to make enterprises perform similar calculations about their own precious cargoes of information. When AWS can lose an entire region and critical national infrastructure can fail without an adequate backup, those risks have plainly not been priced in properly. There is no global market where AWS, NATS, or your organization can buy the data equivalent of war-risk insurance, although imagining what one might look like suggests some intriguing possibilities.
Until something like that happens, we'll have to play by the old rules. Work through what happens if your primary data store disappears. Match backup provision to the actual risks, and if you cannot afford to protect all the data your organization needs to survive, determine how to survive with less. Backups, like insurance, are all too easy to let slide.