De cloud kan worden gebombardeerd
English version: scroll down
We zijn gewend geraakt aan het idee dat onze data veilig is omdat die in de cloud staat. Geen servers meer onder het bureau. Geen tapes in een kluis. Geen datacenter op het eigen bedrijfsterrein. Onze data staat bij Amazon, Microsoft, Google of een andere grote cloudprovider. Die beschikken over duizenden servers, meerdere datacenters en uitgebreide backup- en replicatiesystemen.
Veiliger kan bijna niet, zo lijkt het. Totdat er een raket of drone op een datacenter valt.
Dat is precies wat in 2026 in het Midden-Oosten gebeurde. Iraanse aanvallen beschadigden datacenters van Amazon Web Services in Bahrein en de Verenigde Arabische Emiraten. Maanden later kwam de harde conclusie: AWS kon bepaalde data en resources die uitsluitend in de getroffen regio stonden niet meer herstellen. De schade had meerdere Availability Zones geraakt en was groter dan de regionale redundantie waarvoor AWS was ontworpen.
Dat is een ongemakkelijke constatering. De cloud is niet immaterieel. De cloud is een verzameling fysieke gebouwen. En die gebouwen staan ergens.
Redundantie is geen onkwetsbaarheid
De cloud heeft ons een belangrijke verbetering gebracht. Een defecte server hoeft niet langer een probleem te zijn. Als één machine uitvalt, neemt een andere het over. Als één datacenter problemen heeft, kan een tweede datacenter de belasting overnemen. Maar daarmee ontstaat een subtiel verschil tussen redundantie en weerbaarheid.
Drie kopieën van je data in drie datacenters zijn een uitstekende bescherming tegen een kapotte server. Maar wat gebeurt er wanneer een oorlog, aardbeving, overstroming of grootschalige stroomstoring meerdere datacenters in dezelfde regio raakt? Dan blijkt geografische spreiding minstens zo belangrijk als technische redundantie.
De AWS-gebeurtenis maakt dat pijnlijk zichtbaar. De provider zelf stelde vast dat de fysieke schade meerdere Availability Zones had getroffen en de grenzen van de regionale architectuur had overschreden. De vraag die iedere organisatie zich daarom zou moeten stellen is niet: “Staat mijn data in de cloud?”. Maar: “Waar staat mijn tweede kopie als de hele regio verdwijnt?”
Oekraïne laat hetzelfde zien
De oorlog in Oekraïne maakt die vraag nog concreter. Daar zijn inmiddels ook datacenters en telecominfrastructuur fysiek getroffen. Recente aanvallen hebben opnieuw datacenters in Kyiv en andere infrastructuur beschadigd. Maar juist daar wordt het verschil tussen backup en continuïteit zichtbaar. Een datacenter kan verdwijnen zonder dat daarmee noodzakelijkerwijs de data verdwijnt. Als gegevens elders zijn gerepliceerd en diensten vanuit een andere locatie kunnen worden voortgezet, is het fysieke verlies van een datacenter niet hetzelfde als het digitale einde van een organisatie.
Dat is een belangrijk onderscheid. Een backup beschermt je data. Een uitwijk beschermt je organisatie. En daarmee komen we bij een land dat al veel eerder over deze vraag heeft nagedacht.
Estland: de digitale staat moet kunnen vluchten
Ik schreef eerder over wat we kunnen leren van e-Estonia. Estland is een van de meest verregaand gedigitaliseerde landen ter wereld. Identiteit, belastingen, bedrijfsregistratie, grondregistratie, rechtspraak en talloze andere overheidsdiensten zijn digitaal georganiseerd. Maar Estland heeft een bijzonder probleem. Het is een klein land, direct aan de Russische grens. Daarom stelde het zich niet alleen de vraag hoe een digitale overheid efficiënt kan functioneren, maar ook:
Wat gebeurt er met de digitale staat als de fysieke staat wordt aangevallen?
Het antwoord zijn de Estse Data Embassies. In o.a. Luxemburg staat in hun ambassade een beveiligd datacenter waarin strategisch belangrijke Estse datasets worden opgeslagen. De Data Embassy is daarmee niet alleen een backup. De infrastructuur is ontworpen om in een crisissituatie ook kritieke digitale overheidsdiensten te kunnen ondersteunen. Estland noemt het expliciet een middel om de “digital continuity” van de staat te garanderen.
Het bijzondere is dat deze digitale ambassade juridisch onder Estse controle staat, hoewel de servers fysiek buiten Estland staan. Estland heeft daarmee een interessante gedachte geïntroduceerd: De digitale staat hoeft niet op hetzelfde grondgebied te staan als de fysieke staat. Dat is een veel diepere gedachte dan een traditionele backup. Het is digitale uitwijk.
Van uitwijk naar decentralisatie
Maar ook de Data Embassy heeft nog een centraal uitgangspunt. Er is een primaire infrastructuur. Er is een externe locatie. En daar zit een interessante volgende stap. Wat als we niet één primaire plek en één uitwijkplek hebben? Wat als de digitale infrastructuur zelf uit een netwerk van vele onafhankelijke plaatsen bestaat? Daar begint het Web3-verhaal.
In mijn eerdere blogs over Web3 heb ik beschreven hoe het internet zich langzaam ontwikkelt van centrale platforms naar meer gedistribueerde architecturen. Niet alles hoeft meer bij één centrale provider, in één database of op één server te staan. Data kan worden verdeeld over verschillende nodes. Identiteit kan loskomen van één platform. Transacties kunnen worden vastgelegd in een gedistribueerd netwerk. Blockchain kan de integriteit en herkomst van gegevens aantoonbaar maken, terwijl gedistribueerde opslag grote hoeveelheden data over verschillende locaties kan verspreiden.
Web3 is daarmee niet simpelweg een nieuwe versie van de cloud. Het is een andere manier om naar digitale infrastructuur te kijken. De cloud zegt: Ik zorg dat mijn centrale infrastructuur zeer betrouwbaar is. Web3 zegt: Misschien moeten we minder afhankelijk zijn van centrale infrastructuur. Dat is een fundamenteel verschil.
De volgende afhankelijkheid: de verbinding
Maar daarmee zijn we er nog niet. Want stel dat data over duizenden nodes verspreid staat. Dan moeten die nodes elkaar nog steeds kunnen bereiken. Ook het netwerk zelf kan immers kwetsbaar zijn. Een glasvezelkabel kan worden doorgesneden. Een telecomnetwerk kan uitvallen. Een regio kan zonder elektriciteit komen te zitten. Een oorlog kan fysieke communicatie-infrastructuur beschadigen. Daarom hoort bij de ontwikkeling van Web3 nog een andere revolutie: de decentralisatie van connectiviteit. Daar komt Starlink in beeld.
Satellietcommunicatie maakt het mogelijk om verbindingen te leggen zonder volledig afhankelijk te zijn van de lokale glasvezel- en telecominfrastructuur. Oekraïne gebruikt satellietcommunicatie inmiddels nadrukkelijk als aanvulling op zijn terrestrische netwerken. Kyivstar heeft bijvoorbeeld samen met Starlink satellietconnectiviteit uitgebreid naar miljoenen gebruikers. Ook in 2026 wordt in Oekraïne gewerkt aan satellietcommunicatie die mobiele diensten kan ondersteunen wanneer terrestrische dekking ontbreekt.
Dat is een belangrijke ontwikkeling. Want uiteindelijk heb je voor een werkelijk robuuste digitale infrastructuur vier vormen van onafhankelijkheid nodig:
-
-
- gedistribueerde data
- gedistribueerde verwerking
- gedistribueerde identiteit
- en gedistribueerde connectiviteit
-
Van cloud naar netwerk
Als je de ontwikkeling van de afgelopen decennia terugkijkt, zie je eigenlijk een opmerkelijke beweging. Eerst hadden we: één server. Daarna: één datacenter. Daarna: meerdere datacenters. Daarna: cloudregio’s met Availability Zones. Estland voegde daar een geografische uitwijk aan toe: een digitale staat buiten de eigen landsgrenzen. Web3 gaat vervolgens een stap verder: een netwerk van gedistribueerde nodes.
En satellietnetwerken voegen daar een nieuwe laag aan toe: connectiviteit die niet volledig afhankelijk is van de fysieke infrastructuur op de grond. De richting is daarmee opvallend duidelijk. Niet steeds grotere centrale systemen, maar steeds meer spreiding. Niet één plek die alles moet kunnen overleven, maar een netwerk waarin het verdwijnen van één plek niet langer het verdwijnen van het geheel betekent.
Misschien is de cloud dus niet het eindstation
De gebeurtenissen in het Midden-Oosten zijn daarom meer dan een waarschuwing voor IT-managers. Ze laten zien dat we een belangrijk onderscheid moeten maken tussen beschikbaarheid en continuïteit. Een cloudprovider kan buitengewoon betrouwbaar zijn en toch niet bestand tegen een gebeurtenis waarvoor het ontwerp nooit bedoeld was. Een backup kan bestaan en toch onvoldoende zijn.
Een tweede datacenter kan beschikbaar zijn en toch te dicht bij het eerste staan. Of dezelfde energie centrale gebruiken. Een gedistribueerd netwerk kan bestaan en toch afhankelijk zijn van één fysieke verbinding. De echte vraag is daarom steeds: Waar zit mijn single point of failure?
Misschien is dat wel de ontwikkeling die we de komende jaren gaan zien. De cloud was een enorme stap vooruit omdat we onze data niet langer zelf hoefden te beheren. De volgende stap kan zijn dat we ook minder afhankelijk worden van de fysieke en organisatorische plek waar die cloud zich bevindt. Estland laat zien hoe een digitale staat buiten zijn eigen grenzen kan voortbestaan.
Web3 laat zien hoe data, identiteit en transacties over een gedistribueerd netwerk kunnen worden georganiseerd. Starlink laat zien hoe ook connectiviteit zich steeds meer van de fysieke infrastructuur op de grond kan losmaken. Een raket kan een datacenter vernietigen. Een oorlog kan een regio uitschakelen. Een kabel kan worden doorgesneden.
Maar misschien hoeft daarmee niet ook onze digitale wereld te verdwijnen. De cloud heeft ons geleerd om server-onafhankelijk te denken. Estland leert ons geografisch onafhankelijk te denken. Web3 leert ons centraal-onafhankelijk te denken. En satellietnetwerken leren ons uiteindelijk misschien zelfs netwerk-onafhankelijk te denken.
De cloud was nooit het eindstation. De toekomst is misschien geen wolk, maar een netwerk van wolken — verspreid over de wereld en verbonden door een infrastructuur die zelf steeds minder afhankelijk is van één fysieke plaats.
Photo by Edu Raw
—————————- Translated by ChatGPT ——————————
The Cloud Can Be Bombed
From AWS and Estonia to Web3 and Starlink: the search for a digital world without a single point of failure
We have become accustomed to thinking that our data is safe because it is in the cloud. No more servers under the desk. No tapes in a safe. No server room in the basement. Our data sits with Amazon, Microsoft, Google or another major cloud provider. These companies operate thousands of servers, multiple data centers and sophisticated backup and replication systems.
It is hard to imagine anything safer. Until a missile or drone hits a data center.
That is essentially what happened in the Middle East in 2026. Iranian attacks damaged Amazon Web Services facilities in Bahrain and the United Arab Emirates. Months later came the uncomfortable conclusion: AWS was unable to recover some customer data and resources that had been stored exclusively in the affected region. That is an uncomfortable realization. The cloud is not immaterial. The cloud is a collection of physical buildings. And those buildings are somewhere.
Redundancy is not resilience
The cloud has brought us an enormous improvement in reliability. A failed server no longer needs to be a disaster. If one machine goes down, another can take over. If one data center has a problem, another can continue the workload. But there is an important difference between redundancy and resilience. Three copies of your data in three data centers are excellent protection against a failed server. But what happens when a war, earthquake, flood or large-scale power failure affects several data centers in the same geographical region?
Suddenly, geographical distribution becomes just as important as technical redundancy.The AWS incident makes this painfully clear. The infrastructure was designed to survive certain failures, but the physical damage crossed the boundaries of what regional redundancy could protect against. So the question every organization should be asking is no longer: “Is my data in the cloud?”. It is: “Where is my second copy if the entire region disappears?”
Ukraine shows the same principle
The war in Ukraine provides another powerful example. Data centers and communications infrastructure have been physically damaged by attacks. Yet the destruction of a data center does not necessarily mean the destruction of the data stored there. If information is replicated elsewhere, and services can be restarted from another location, the physical loss of a data center does not have to become a digital catastrophe.
That distinction matters. A backup protects your data. A failover strategy protects your organization. And this brings us to a country that has been thinking about this problem for much longer.
Estonia: the digital state needs an escape route
I have written before about what we can learn from e-Estonia. Estonia is one of the world’s most digitally advanced countries. Identity, taxation, company registration, land records, courts and many other government services are deeply integrated into digital infrastructure. But Estonia faces a particular strategic reality. It is a small country on the border of Russia. So Estonia asked a question that goes beyond digital efficiency:
What happens to a digital state if its physical territory is attacked or becomes inaccessible? One answer is Estonia’s Data Embassy. In Luxembourg, Estonia maintains a highly secure data facility containing strategically important government data. It is more than a conventional backup. The concept is designed to support the continuity of critical digital government services outside Estonia itself. The idea is remarkable: The digital state does not necessarily have to reside on the same territory as the physical state. This is more than disaster recovery. It is digital continuity.
From failover to decentralization
But the Data Embassy still represents a particular architecture. There is a primary infrastructure. There is an external fallback. What if we take the next step? What if there is no single primary location at all? What if digital infrastructure consists of a network of many independent locations? That is where the Web3 story becomes relevant.
In my earlier writing about Web3, I described the gradual transition from centralized platforms toward more distributed architectures. Data, identity, transactions and computing do not necessarily have to depend on one central provider or one central database. Data can be distributed across nodes. Digital identity can become less dependent on a single platform. Blockchain can provide a shared mechanism for establishing integrity and provenance, while distributed storage can spread information across multiple locations.
Web3 is therefore not simply a new version of the cloud. It represents a different way of thinking about digital infrastructure. The cloud says: Make the central infrastructure extremely reliable. Web3 asks: What if we become less dependent on central infrastructure in the first place? That is a fundamental shift.
The next dependency: connectivity
But there is another problem. Imagine data distributed across thousands of nodes. Those nodes still need to communicate. The network itself can become a point of failure. A fiber-optic cable can be cut. A telecom network can fail. A region can lose power. A war can destroy physical communications infrastructure. This is where another transformation becomes important: the decentralization of connectivity.
And this is where Starlink enters the story. Satellite connectivity makes it possible to establish communications without being completely dependent on local fiber, cellular infrastructure or national telecom networks. The experience of Ukraine has demonstrated how valuable such alternative connectivity can become when terrestrial infrastructure is disrupted. This adds another layer to the resilience equation.
Because ultimately, a truly resilient digital infrastructure requires several kinds of independence:
-
-
- distributed data
- distributed computing
- distributed identity
- and distributed connectivity.
-
From cloud to network
If we look back at the evolution of digital infrastructure, an interesting pattern emerges. First there was: one server. Then: one data center. Then: multiple data centers. Then: cloud regions with multiple availability zones. Estonia added another layer: a digital state with infrastructure outside its own borders. Web3 takes the next step: a network of distributed nodes. And satellite networks add another dimension: connectivity that is less dependent on physical infrastructure on the ground.
The direction is striking. Not simply bigger centralized systems. But increasing distribution. Not one location that has to survive everything. But a network in which the loss of one location does not mean the loss of the whole system.
Perhaps the cloud is not the destination
The events in the Middle East are therefore more than a warning for IT managers. They force us to distinguish between availability and continuity. A cloud provider can be extraordinarily reliable and still be vulnerable to an event it was never designed to withstand. A backup can exist and still be insufficient. A second data center can be available and still be too close to the first. And a distributed network can still depend on a single physical communications route. The fundamental question is therefore always:
Where is my single point of failure?
Perhaps this is the next major phase of digital infrastructure. The cloud was a huge step forward because we no longer needed to manage our own physical servers. The next step may be to become less dependent on the physical and organizational location of the cloud itself. Estonia shows how a digital state can continue outside its own territory. Web3 shows how data, identity and transactions can increasingly be organized across distributed networks. Starlink shows how connectivity itself can become less dependent on terrestrial infrastructure.
A missile can destroy a data center. A war can disable an entire region. A cable can be cut. But perhaps none of these events should be capable of destroying our digital world. The cloud taught us to think server-independent. Estonia teaches us to think geographically independent. Web3 teaches us to think less centrally dependent. And satellite networks may ultimately teach us to think network-independent. The cloud was never the final destination.
Perhaps the future is not one cloud, but a network of clouds — distributed around the world and connected through an infrastructure that itself becomes increasingly independent of any single physical location.
#digitalresilience #cloudcomputing #Web3 #blockchain #decentralization #datacenters #cybersecurity #digitalcontinuity #Estonia #eEstonia #Starlink #distributedinfrastructure #cloudsecurity #datasecurity #futureofinternet