CIO Brief: Concentration Risk in a Single Cloud Region
Retrospective: this article looks back at events from December 2021, written in 2026 with the benefit of hindsight.
The short version: In December 2021, a problem in one AWS region disrupted major services like Netflix, Disney+ and Amazon's own deliveries for much of a day. Many companies run everything in that single region. That concentration is a business risk boards increasingly ask about.
What concentration risk means
If all of your critical systems run in one cloud region, an outage in that region takes down your business, regardless of how well your own systems are built. Regional outages are rare — but they happen, and they've happened repeatedly in the most popular AWS region.
The business impact
- Revenue loss during outages.
- Customer frustration, especially when competitors stay online.
- Regulatory scrutiny in sectors with operational resilience rules, such as financial services.
Questions to ask your team
- Which of our critical services depend on a single cloud region?
- How long could we tolerate each one being down?
- What would multi-region resilience cost for the most critical services?
- When did we last test recovery?
What good looks like
Each critical service has an agreed recovery target, a design that meets it, and a recent test showing it works. Less critical services have documented, accepted risk.
The decision
Ask for costed options for the two or three services where a full-day outage would hurt most. Multi-region for everything is rarely justified; for those few services, it often is.
- The AWS us-east-1 Outage of December 2021: When the Control Plane Fails Incident Teardowns
- How to Plan Multi-Region Failover for Critical AWS Workloads How-To & Hardening
- Multi-Region Disaster Recovery Test Checklist How-To & Hardening