RC RANDOM CHAOS

Rubble where the records used to be

A cloud provider states some Middle East data cannot be restored after a strike - what permanent loss means for board-level accountability and recoverability.

· 8 min read
Rubble where the records used to be

A cloud provider has informed customers that some data held in its Middle East facilities cannot be restored following a physical strike attributed to Iran. This is not an outage. An outage implies interruption followed by recovery. What has been stated is that certain data cannot be restored - a matter of permanence, not availability. For a board, the distinction is the entire matter. Downtime is measured in hours and recovered through failover. Non-restorable data is measured in obligations that no longer have a source of truth behind them. The provider’s own position is the material fact here: restoration is not possible for some portion of the data held in the affected facilities.

What this means at the level that governs the organisation is that a dependency assumed to be effectively permanent has produced a permanent loss. The exposure is defined by whatever the organisation placed in those facilities and cannot reconstruct elsewhere. That may include records the business is legally required to retain, evidence it would rely on in dispute, or operational data it cannot recreate from any other system. Which of these apply to any given customer cannot be determined from available information. The scale of the loss, the number of customers affected, and the categories of data involved are not confirmed. What is confirmed is that the provider has stated some data is gone.

The reason this reaches the board rather than staying inside a technical function is that it converts a supplier’s operational event into the organisation’s own accountability. Regulators, auditors, and counterparties do not accept the loss of a provider as a defence for the loss of a record. If a required record is unrecoverable, the obligation attached to it does not disappear; it transfers to the organisation that held it. The provider absorbs the incident. The customer absorbs the consequence. That asymmetry is the exposure, and it exists independently of how the data came to be unrecoverable.

The assumption that this event challenges is one that most boards have never been asked to examine directly. The prevailing understanding has been that placing data with a hyperscale provider makes loss a non-event - that durability was purchased along with the service and that recovery was, in effect, outsourced. Resilience became something the organisation consumed rather than something it owned. Under that assumption, ‘in the cloud’ was treated as a synonym for ‘recoverable,’ and the question of whether an independent copy existed under the organisation’s own control was rarely raised at board level.

That assumption held because, in ordinary operation, it was rarely tested to failure. Provider durability figures are expressed against equipment failure and routine fault, and against those conditions they have generally performed. The result was a quiet transfer of responsibility: the organisation retained the obligation to preserve its records while ceding the means of preserving them to a third party, on the understanding that the third party would not lose them. That understanding was never a control the organisation could enforce. It was a reliance the organisation could not verify.

The weakness in the assumption is that durability against component failure is not the same as durability against the loss of a facility. The two are different risks, and the second was largely absent from the board-level view of cloud dependency. Resilience was measured in replication and redundancy within the provider’s design, on the premise that the physical estate itself was not a variable. Whether that replication extended beyond the affected region, and whether any independent copy existed outside the provider’s control, cannot be determined from available information and is not confirmed for the affected data.

What changed is that the physical estate did become a variable. A strike attributed to Iran affected facilities in the Middle East, and the provider has stated that some data in those facilities cannot be restored. This moves the question from availability to permanence and demonstrates, through the outcome itself, that provider durability and organisational recoverability are not the same property. The system did not prevent the permanent loss of data for the affected customers. That is the observable result. The internal design of the provider’s resilience, and why restoration is not possible in these cases, cannot be determined from available information and is not the organisation’s to attribute.

The change is not that a new type of threat was discovered. Physical and geopolitical risk to infrastructure in high-risk regions was always present. The change is that the consequence has now been confirmed to reach the data layer, not merely the service layer. A regional physical event has produced a data-permanence outcome, and that connection - between where infrastructure physically sits and whether records can be recovered - is now established by the event rather than treated as remote. For any organisation with data concentrated in a single high-risk region and no independent copy under its own control, the same outcome is possible. Whether that description applies to the organisation is a question the board should now require answered.

What remains unconfirmed must be stated as plainly as what is known. The volume of data lost is not confirmed. The specific customers and record categories affected are not confirmed. Whether recoverable copies exist elsewhere for any given organisation cannot be determined from available information. There is no evidence presented that would allow the extent of the loss to be bounded from the outside. The one fact on which board attention should rest is the provider’s own statement that some data cannot be restored - and the recognition that the obligations attached to that data did not move when the data was lost.

The mechanism that converts a supplier’s event into the organisation’s permanent loss is the absence of a recovery path the organisation itself controls. For the affected data, provider durability operated as the sole guarantee of recoverability. When the facilities were struck, nothing external to the provider’s own estate stood between the event and the outcome the provider has now stated. The result indicates that, for that data, recoverability existed only where the loss occurred. Whether an independent copy existed elsewhere cannot be determined from available information.

What the arrangement allowed at runtime is the material point. Availability controls - failover, replication, redundancy within a provider’s design - address interruption. They restore a service that is expected to return. They do not address a facility whose contents cannot be restored at all. The distinction between a control for availability and a control for permanence is not academic; it is the difference the outcome has now demonstrated. The system did not prevent the permanent loss of data for the affected customers. That is the observable result, and it stands independently of why restoration is not possible, which is not the organisation’s to attribute.

A reliance of this kind cannot be enforced, because durability that is consumed rather than operated cannot be verified by the party consuming it. No evidence has been presented that an independent, organisation-controlled copy existed for the affected data, and its existence cannot be determined from available information. Where such a copy does not exist, the provider’s statement is the final position on recoverability, and the organisation holds no separate means of contesting it. The exposure, therefore, is not defined by the strike. It is defined by whether recoverability ever rested anywhere the organisation could reach without the provider.

This is not confined to one provider, one region, or one event. The broader environment it exposes is any estate in which data is concentrated in a single location and recoverability depends entirely on the provider’s own durability. For every such arrangement, the same outcome is possible, because the same single point governs whether records survive. What the event establishes is that the link between where infrastructure physically sits and whether data can be recovered is real rather than remote. That link was previously treated as unlikely enough to sit outside the board-level view. It is now demonstrated.

The pattern in oversight is that durability figures were read as recoverability guarantees across the whole estate. Those figures are expressed against equipment failure and routine fault, and against those conditions they have generally performed. They do not describe the loss of a facility, and the gap between the two was rarely surfaced where portfolio risk is decided. Resilience was measured in the provider’s design rather than in recovery the organisation could independently verify. That is a measurement problem, and it is not specific to the affected data - it applies wherever the same assumption was carried.

The exposure this reveals is portfolio-wide and largely unquantified. Which records sit in single-region, provider-dependent arrangements, and which of those could not be reconstructed from any source the organisation controls, is a question most boards cannot answer from available information today. The number of organisations in that position, and the categories of data involved, are not confirmed. The pattern is not the strike. It is the concentration and the unverifiable reliance that the strike brought into view - conditions that persist across suppliers, regions, and workloads until each is examined directly.

What must be true going forward is narrow and non-negotiable. Recoverability must be a property the organisation can demonstrate without reference to any single provider or facility. An independent copy under the organisation’s own control, verifiable by the organisation, is the condition that separates a supplier incident from a permanent organisational loss. Where that condition is not met for a given record, the exposure for that record is total, and no provider assurance changes it. This is a condition to be enforced and evidenced, not a posture to be assumed.

The obligations attached to records do not move when the records are lost. Regulators, auditors, and counterparties do not accept a provider’s loss as a defence for the organisation’s loss. The provider absorbed the incident; the organisation retains the consequence and the accountability. What must be true is that the organisation can identify which records it is required to preserve and can show that their preservation does not rest on a single point that can be removed by one event. Absent that, the accountability sits with a board that cannot evidence it discharged the duty.

Access defines exposure, and concentration without an independent, verifiable copy defines the ceiling of what can be lost. Resilience consumed from a provider is not resilience the organisation owns, and a copy that cannot be verified is not a copy that can be relied upon. The provider has stated that some data cannot be restored. The only defensible position is one in which that statement, wherever it recurs across the estate, is not the last word the organisation holds on its own records.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.