Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

When the Cloud Goes Dark: How Securiti and Veeam Helped Customers Maintain Continuity After the recent AWS UAE Outage

Author

Mukul Hinge

Director Product Marketing at Securiti

Listen to the content

This post is also available in: Arabic

Executive Summary: In March 2026, drone strikes physically damaged AWS data centers in the UAE - rendering standard disaster recovery mechanisms ineffective and leaving dozens of organizations unable to access mission-critical data. For Securiti customers in the region, the combination of pre-built cross-cloud data intelligence, rapid engineering response, and compliance-governed migration meant the difference between days of regulatory exposure and restoration within hours of customer approval. This post details what happened, why conventional cloud resilience architectures weren't enough, and how Securiti navigated a scenario the industry had never encountered at this scale, to help customers maintain business continuity, saving potentially millions of dollars.

In early March 2026, two Amazon Web Services (AWS) data centers in the UAE were struck by drones amid escalating regional conflict. The attacks caused structural damage, triggered fire suppression systems, and disrupted power infrastructure - taking down critical services such as EC2, DynamoDB, Lambda, and S3 across the Middle East region. A third facility in Bahrain sustained collateral damage later on March 23rd. Recovery efforts for AWS UAE were underway by late March 3, but on both occasions, AWS itself acknowledged that the broader operating environment in the region remained unpredictable.

This incident exposed a blind spot in standard cloud resilience strategies: Multi-AZ architectures protect against facility-level failure, not regional collapse, especially when regulatory constraints prevent cross-region failover. Recovery depended less on infrastructure redundancy and more on pre-existing, governed cross-cloud data visibility.

For dozens of organizations, including fintech platforms, retail operators, logistics providers and others, this wasn't just an abstract infrastructure story but rather a full-scale data emergency. AWS advised affected customers to fail over to unaffected regions, which was great for customers who had built their architecture to do so, but a major challenge for the companies that hadn't.


Why Multi-Availability Zone (AZ) Deployments Weren't Enough This Time

To understand why so many organizations were caught flat-footed, it helps to understand what the standard playbook for disaster recovery looks like for AWS Availability Zones

AWS AZs are distinct physical data center facilities within a single geographic region, connected by high-bandwidth, low-latency private networking. The architecture is designed so that a failure in one AZ - a power outage, a cooling failure, a hardware fault - doesn't propagate to the others. Running a Multi-AZ deployment means your Relational Database Service (RDS) (which automates common administrative tasks like hardware provisioning, patching, backups, and monitoring) has a standby replica in a second facility, your Elastic Compute Cloud ( EC2) instances are spread across zones, and your load balancer automatically routes traffic around an unhealthy target. For the overwhelming majority of cloud incidents, such as hardware failures, localized power events, network partitions - this architecture is excellent and works exactly as intended.

The critical limitation is geographic proximity. AZs within a single region are typically located within a radius of roughly 100 kilometers of each other. That proximity is a deliberate engineering trade-off: it keeps inter-AZ latency low enough to support synchronous replication and real-time failover. But it also means that a physical event of sufficient scale- a natural disaster, a regional power grid failure, or, in this case, targeted drone strikes - can affect all AZs in a region simultaneously.

That is precisely what happened between March 1-3, 2026. The drone strikes didn't hit a single facility. They hit multiple data centers across the me-central-1 (UAE) region in close succession, with the me-south-1 (Bahrain) region sustaining damage from a nearby strike as well. Customers running textbook Multi-AZ architectures - spreading workloads across three availability zones, maintaining standby database replicas, using auto-scaling groups - experienced the same outage as customers running single-AZ deployments. Their failover logic had nowhere to fail over to.

Compounding the problem was the AWS Snapshots failure mode. EBS snapshots - the incremental, point-in-time backups that organizations rely on for disaster recovery and volume restoration - are stored in Amazon S3 within the same region. These native snapshots were no longer a viable recovery path - the physical strikes had throttled S3 and DynamoDB so severely that the storage layer underpinning those backups was itself unavailable.

As a result, Mission-critical data went dark and business continuity was jeopardized.

With EC2 compute instances offline and DynamoDB tables unreachable, customers couldn't access the data their applications depended on. For fintech operators, that meant payment processing pipelines stalled. For retail platforms, it meant order management systems went dark. Every hour of downtime carried both direct revenue consequences and growing regulatory exposure - particularly for organizations subject to UAE data residency requirements, GDPR, or financial services compliance mandates.

Why This Was Especially Hard to Recover From

Three constraints collided at once:

  1. Regional cloud services were degraded, not just individual facilities.
  2. Native recovery mechanisms depended on those same services.
  3. Data residency and sovereignty rules eliminated default cross-region failover options.

For organizations subject to strict regulatory requirements, restoring availability by simply moving data elsewhere was not an option. Availability and compliance were in direct tension.

This is where many recovery efforts stalled.

How Securiti Responded: An Unconventional Recovery Playbook

With the standard recovery paths unavailable, Securiti's engineering team executed a multi-track recovery operation in parallel, working around each constraint rather than waiting for AWS to resolve them.

Track 1 - Cross-region data access via Bahrain. Because regional S3 was unreachable and snapshots were inaccessible through normal means, the team established a VPC peering connection between the damaged UAE region and AWS me-south-1 in Bahrain. This created a network path to surviving instance storage that bypassed the degraded S3 layer. Approved customer data was then backed up directly to S3 buckets in the EU region - establishing a clean, geographically separate copy outside the conflict zone for the first time.

Track 2 - Direct EKS and SSM access to surviving infrastructure. The team identified EKS nodes that had survived the partial damage to me-central-1c and accessed them directly via AWS Systems Manager (SSM), avoiding the need for public network paths or healthy EC2 bastion infrastructure. Through this access, engineers reached the underlying databases and performed local backups to the UAE S3 - capturing data that would otherwise have been lost if the remaining infrastructure degraded further.

Track 3 - Cross-cloud redundancy in Azure. Simultaneously, and independently of the AWS recovery tracks, the team established backup copies of critical customer data in Microsoft Azure. This was a deliberate hedge against the possibility of a total AWS ME failure - ensuring that even if the situation in both the UAE and Bahrain deteriorated completely, a secondary copy existed on an entirely separate cloud provider with no dependency on AWS infrastructure in the region.

Migration to EU: Getting Customers Back Online Without Breaking the Rules

With data secured across multiple locations, the team moved to restore customer service. The process was deliberate, compliance-first, and faster than the alternative would have been without pre-existing EU infrastructure.

Veeam's legal team was consulted before any cross-border data movement occurred. Given that affected customers operated under strict UAE data residency requirements, moving tenant data to EU infrastructure required explicit customer consent - not assumed authorization. Approval was sought and documented for each impacted customer before migration began.

The EU cloud infrastructure was already operational. Because Securiti runs production environments across multiple regions as part of its standard multi-cloud architecture, the EU environment required no provisioning time. It was live, tested, and ready to receive tenant data.

Once customer approvals were secured, specific tenant datasets were migrated to the EU environment and restored. Customers were back online within a matter of hours from the point of approval - not days. For customers with ongoing data residency concerns about operating from EU infrastructure, Securiti offered temporary EU hosting as an explicitly time-bounded arrangement while a longer-term UAE recovery path was evaluated. Secondary copies remained in Azure as a live failsafe against any further strikes or cascading failures in the AWS Middle East footprint.

Before any cross-border data movement occurred, customer consent was obtained and documented. Because Securiti already operated a production-grade EU environment, there was no delay in provisioning new infrastructure. Approved customer datasets were migrated and restored quickly, allowing operations to resume in hours rather than days.

For customers with ongoing data residency concerns, EU hosting was offered as a temporary, explicitly time-bound measure, not a permanent shift. Secondary cross-cloud copies remained in place as a safeguard against further instability.

Why This Worked

The Role of Data Discovery and Cross-Cloud Visibility

The speed of the recovery was not accidental. A critical enabler was Securiti's continuously maintained, cloud-agnostic data catalog - which meant that when the UAE region went dark, the team already knew precisely which datasets were hosted in the affected availability zones, which workloads depended on them, what sensitivity classifications those assets carried, and which regulatory frameworks governed them. That triage took minutes, not days.

For the compliance dimension of the response - determining which customers needed to be consulted before data movement, which regulatory notifications might be required, and which EU destination buckets were permissible under each customer's residency obligations - this pre-existing data intelligence was the difference between a structured, defensible response and a chaotic one.

Governed Migration, Not Just Fast Migration

The EU restoration was fast in part because the compliance groundwork had already been laid. Securiti's platform maintained classification and lineage continuity across the migration, meaning that the regulatory metadata built up over months of operation in the UAE environment traveled with the data to its new home. Compliance teams did not need to re-classify assets from scratch post-recovery or reconstruct data maps for regulators after the fact. The restored EU environment was compliant on arrival, not compliant eventually.

The Compounding Cost of Unpreparedness

It's worth being direct about what the alternative looks like. Organizations without a real-time, cross-cloud data catalog faced a manual discovery process that, in complex environments, can take weeks. Without governed migration tooling, compliance teams had to manually review every data movement decision - a bottleneck that extended downtime. And without automated breach assessment capabilities, legal and compliance teams operated in a fog, unsure which regulators to notify, by when, and about what.

Regulatory penalties for delayed breach notification under frameworks like GDPR can reach into the tens of millions of euros. Operational downtime costs for a mid-size fintech processing regional payments can run into six figures per hour. The financial calculus of preparedness versus recovery is not close.

Lessons Learned/What This Event Clarifies

The AWS UAE outage is a reminder that cloud infrastructure is not immune to physical-world disruption. Conflict, natural disaster, and cascading infrastructure failure are not edge cases to be engineered around in theory - they are scenarios that require tested, automated, cross-cloud response capabilities.

Also, it is worth noting that the lesson is not that Multi-AZ is the wrong architecture. It remains an essential baseline practice and should be the minimum deployment standard for any production workload. The lesson is that Multi-AZ solves a different problem than the one organizations faced on March 2. It is a facility-level resilience mechanism, not a regional one. Protecting against regional failure requires either cross-region data replication - so that backups exist outside the affected geography - or active-passive multi-region architecture, where a secondary region can absorb traffic if the primary disappears entirely.

For organizations with data residency obligations, neither path is as simple as flipping a switch. Replicating regulated data to another region requires that the destination region satisfies the same sovereignty and adequacy requirements as the source. Failing over to an unvetted region to restore availability can create a compliance violation even as it solves an operational one. This is the intersection where infrastructure resilience, data security and governance converge - and where having pre-built, policy-governed cross-cloud capabilities becomes the difference between a rapid, compliant recovery and a protracted scramble.

Securiti's ability to mobilize quickly for affected customers wasn't just a function of incredible engineering effort in the moment; it was also a function of work done in advance: data assets discovered, classified, cataloged, and governed before any crisis arrived.

When the infrastructure failed, the data intelligence didn't.

To learn how Securiti can help your organization, contact us or explore our cross-cloud data and AI platform.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Latest
View More
One Unrevoked Key, 37.5 Million People: What the Coupang data breach reveals about data access
Executive summary In June 2026, South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.68 billion won (approximately $409 million) which was the largest...
More Tools Does Not Mean Faster or More Accurate Insights View More
More Tools Does Not Mean Faster or More Accurate Insights
An access-review tool flags an account with more privilege than its role needs: routine, filed, forgotten. That same week, a separate scan shows that the same...
Data Security Posture Management (DSPM) Best Practices View More
Data Security Posture Management (DSPM) Best Practices
Explore DSPM best practices for discovering sensitive data, reducing exposure, governing access, prioritizing risk, and strengthening enterprise data security.
View More
The Future of DSPM: Why it’s essential?
Explore why DSPM is becoming essential for modern data security, helping organizations discover sensitive data, reduce exposure, govern access, and prepare securely for AI.
View More
Green-Light AI, Not Data Exposure
Learn the five critical data-layer controls enterprises need to prevent sensitive data exposure and enable secure, scalable AI agent adoption.
Agentic AI Readiness View More
Agentic AI Readiness: Why Your Enterprise Needs a New Data Security Paradigm
Learn how to secure Agentic AI by discovering sensitive data, mitigating AI risks, and building an enterprise-ready AI security strategy.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
"The Algorithm Did It" Is Now Dead in Court View More
“The Algorithm Did It” Is Now Dead in Court
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New