First, know your complete dependency chain, including your SaaS providers and infrastructure partners, down to the cloud regions and availability zones they run on. Most enterprises discovered last year that they couldn’t answer the question “Which of my critical services depend on AWS?” without weeks of investigation. If your provider’s data center is destroyed, whether by fire, flood, or a missile, you need to know exactly what’s exposed—and before it happens, not after.
Second, design for region loss, not just zone loss. Multi-AZ deployment is table stakes, but Bahrain demonstrates that availability zones are not invulnerable to large-scale physical damage. Genuinely resilient architectures span cloud regions and, in some cases, multiple providers, with data replication and automated failover. Yes, this costs more. Ask yourself what a year of unavailability would cost you, and the math usually changes quickly.
Third, test your recovery like you mean it. A plan that has never been exercised is a document, not a capability. Run game days that simulate the loss of an entire region, including the SaaS providers in your supply chain. Verify your backups exist in a location physically and logically independent of the failure domain. Can you actually restore from them within your stated recovery time and recovery point objectives? The enterprises that came through the 2025 outages best were the ones that had rehearsed failure, not the ones with the thickest disaster recovery binders.

