↓Skip to main content
  1. Articles/

Twin-datacentre continuity was built for accidents, not coordinated attacks

·4 mins

Kyiv shows what changes when an attacker can choose which sites to hit, and why the decision has to come before the need is visible.

In September 2026, Russia began striking datacentres and internet providers in and around Kyiv. About 100,000 households lost their connection for a time. A strike on a large telecom operator killed four people. Moscow called the targets military communications. Analysts at the Institute for the Study of War read the campaign as economic: after ports, railways and logistics, the digital backbone of the economy.

The damage stayed limited. The Guardian explained why: Ukraine’s internet is spread over many providers, so no single strike takes down a city. When one provider was hit, others took over.

For a European boardroom, the lesson sits in that detail.

We already plan for losing a datacentre #

Most critical services in Western Europe run on a familiar design. Two datacentres, some distance apart, with data copied between them. If one burns down, floods or loses power, the other carries on. Regulators ask for it, auditors check it, and it works.

So the first reaction to Kyiv is a reasonable one: we have that covered. Losing a datacentre, even to a physical attack, is already on the risk register.

It is covered as an accident. The design assumes one site fails and the other keeps running. Fire, flood and power cuts play along, because they hit one place at a time. An attacker does not have to.

What is new #

Physical attacks on buildings are old. Three things together are new.

The first is intent. A state now treats commercial datacentres and internet providers as targets in their own right, to hurt an economy rather than an army. That moves them from the list of things that might break to the list of things someone wants to break.

The second is coordination. The strikes around Kyiv hit several sites in the same campaign. An attacker who wants a service gone does not have to pick one of its datacentres. They can pick all of them.

The third is cost. Drones are cheap, and sabotage is cheaper. Reaching a building no longer takes an air force.

Each of these on its own is manageable. Together they break the one assumption the twin-site design rests on: that the second site will still be there.

Why concentration changes the maths #

Kyiv held because an attacker would have needed to hit a very large number of targets to take the city offline. The shape of the network did the defending, and most of that shape was never designed for war. It grew that way.

Much of Western Europe’s critical digital infrastructure grew the other way. Payments, banking and public services moved onto fewer firms, fewer platforms and fewer sites. Those were good decisions. They cut cost, simplified control and made supervision easier.

They also shortened the attacker’s list. When a service runs from a small number of sites, a coordinated attack needs a small number of hits. The fallbacks often sit on that same short list: the second datacentre, the recovery team in the same city, the partner that would take over the customers.

Every recovery plan counts on something still running. Accidents leave something running. A coordinated attack is aimed at leaving nothing.

Why now #

The case for deciding now is about timing.

Kyiv moved this threat from hypothetical to demonstrated, in a war. Western Europe is not at war, and nobody can say when or whether it arrives here. The fixes run on a slower clock. Adding a site far enough away, moving a core platform, or building a way to recover that does not lean on the production estate takes years of budget cycles, contracts and migrations. That long lead time is what makes not knowing expensive.

When the fix takes longer to build than the threat might take to arrive, the decision has to come before anyone can see the need. Waiting for certainty means deciding after the choice has gone.

Most governance re-opens a decision when the system itself changes: it grows, more comes to depend on it, the stakes rise. Few organisations have a rule that re-opens a decision because the world outside changed, and there is no settled answer to who should pull that trigger.

The question to take back #

Architecture is the set of decisions where being wrong is expensive. The architect’s job is to keep the cost of reversing them visible to the people who sign for it.

Twin-site continuity was designed around losing one datacentre and keeping the other. Would we design it the same way today, knowing an attacker can choose both?

The savings from consolidation are real, and they can stay. What changes is that someone now signs for the risk those savings bought.