Skip to main content
    Breaking newsCyber SecurityBusiness Strategy

    When war reaches the cloud: why geopolitical risk belongs on every CISO's radar

    A cloud region damaged by strikes, six months on and still unrecoverable – with customer data permanently gone. Conflict abroad is now an IT incident at home.

    Frank Mathieson
    18 September 2026
    6 min read

    For years, "resilience planning" in IT meant patching known vulnerabilities, segmenting networks, and preparing for the usual suspects: ransomware gangs, phishing crews, and the occasional nation-state espionage campaign. That framing is now dangerously incomplete.

    Reuters reported this week that Amazon's AWS is unable to restore access to its Bahrain cloud region and one availability zone in the UAE, more than six months after both facilities were damaged in strikes during the Iran conflict earlier this year. AWS has confirmed that customers with data hosted exclusively in the affected zones have permanently lost access to it, and a full rebuild of the Bahrain site isn't expected before early 2027. This is not a software bug or a misconfigured firewall.

    It is kinetic, physical warfare producing a permanent, unrecoverable outage in the world's most heavily engineered cloud infrastructure.

    Two incidents, one pattern

    It sits alongside a string of incidents this year showing the same pattern: conflict abroad translating directly into disruption at home.

    Controllers at the water works

    Over the summer, Iran-linked groups including CyberAv3ngers targeted programmable logic controllers at water and wastewater utilities across at least a dozen US states, exploiting known flaws in Rockwell, Schneider Electric and Siemens equipment that had simply never been patched or taken off the internet. Operators avoided a genuine public-safety crisis only by falling back to manual control.

    One underlying story

    Two very different failure modes, one drone strike on a data centre and one exploited PLC, but the same underlying story: geopolitical conflict is no longer a background risk to digital operations, it is now a direct and immediate attack vector.

    The question patching doesn't answer

    This matters for how organisations think about their cyber posture. Reducing attack surface and staying on top of vulnerability management remain essential, but they answer the question "can someone break in through a known weakness?" They don't answer "what happens to us if our cloud region, our supplier, or a piece of critical infrastructure we depend on is taken offline by a conflict we have no control over?"

    That's a resilience and continuity question, not a patching question, and it needs deliberate attention rather than an annual document refresh.

    The line between "world news" and "IT incident" has effectively disappeared.

    Four questions to ask about your own infrastructure

    None of these needs a consultant to ask. All four are uncomfortable to answer honestly.

    Where does your data physically live?

    Not which provider – which regions and zones. If every copy of something sits in one place, you are one event away from the outcome AWS customers are living with now.

    What are your single points of failure?

    Across cloud architecture and supply chain both. Concentration risk usually hides one step beyond the suppliers you actually invoice.

    Does your plan survive permanent loss?

    Most continuity plans assume a few hours of downtime and a provider who comes back. Test yours against prolonged or permanent loss of a region or a provider instead.

    Is geopolitics in your risk register?

    If ransomware and phishing are named and conflict-driven disruption isn't, the register reflects last decade's threat model rather than this one.

    Where we come in

    This is precisely the gap HowTech is built to close. We work with organisations to go beyond conventional vulnerability and patch management, mapping cloud and third-party concentration risk, stress-testing continuity plans against real-world scenarios rather than generic ones, and building resilience strategies that treat geopolitical disruption as a first-class risk alongside ransomware and phishing.

    That work usually sits across our cyber security consultancy and our wider technology consultancy engagements. If recent events have shown anything, it's that the line between "world news" and "IT incident" has effectively disappeared. HowTech can help you plan for that reality before it arrives on your own doorstep.

    Source: Reuters, "Amazon's AWS is unable to restore access to Bahrain, one UAE cloud data zone after war", 15 September 2026 – reuters.com

    How resilient is your setup, really?

    We map cloud and supplier concentration risk, stress-test continuity plans against scenarios that actually happen, and put geopolitical disruption on the risk register alongside ransomware.

    Related insights

    Why the Cyber Security and Resilience Bill reaches into ordinary supply chains.

    What the Five Eyes warning on frontier AI models means for your business.

    Real migration costs, phases and lessons from an insurance SME.