top of page
  • X
  • Facebook
  • Linkedin
  • Instagram
Search

The Cloud Has A Physical Attack Surface And Nobody On The Board Owns It

Updated: Jul 27


Earlier this year attackers went after Amazon's cloud in the Middle East and never touched a server. They used drones. They hit the power and the supporting infrastructure the facilities depend on, damaged nearby systems around Bahrain, and knocked capacity offline across multiple availability zones. No zero-day. No stolen credential. No malware. Just the oldest idea in warfare, which is that you break the thing your enemy leans on and let the rest fall over on its own.


We have spent years on both sides of this. We break into buildings for a living and we sit in the vCISO chair helping companies decide what is actually worth defending. Here is what that combination taught us. The cloud sold everyone a security model that is almost entirely digital, and the physical foundation holding it up is the part nobody on the board actually owns.


Look at where the money and attention have gone. Identity, encryption, zero trust, endpoint detection, patch cadence. All digital, all above the waterline. Now ask one plain question about your most important workload. Where does the electricity come from. Who owns the airspace over the building. What happens to your failover if the substation two miles down the road goes dark. Most executives cannot answer, because those questions live under facilities, or under a cloud provider's service agreement nobody reads, or under no one at all.


That gap is not bad luck. It is the org chart. The CISO owns "security." Facilities owns "the building." The transformer down the road and the open sky above the roof belong to neither. Attackers read org charts better than most defenders do. When we plan against a target, the firewall is almost never the soft path. The soft path is the loading dock, the HVAC intake, the power feed, the fiber vault behind a gate somebody left unlocked. The cloud did not remove that soft path. It industrialized it, concentrated it into a handful of buildings, and put it behind an SLA most companies treat as a promise instead of a risk.


We talk about confidentiality and integrity constantly and quietly treat availability like an operations problem. It is a security property. Denial is an attack. A cheap drone, a rifle round through a transformer, a backhoe through a fiber run, these land the same blow as a ransomware detonation, which is your business stops, except there is nothing to decrypt and no ransom note to negotiate down. And unlike ransomware, most incident response plans have no play for it, because the threat model stopped at the network edge and never walked outside to look at the wall.


Here is the part that should worry anyone carrying real continuity risk. Your disaster recovery plan probably assumes a physical independence it does not have. Regions and availability zones share more underneath them than the marketing admits, the same grids, the same transit corridors, sometimes the same sky. If one physical event can degrade your primary and your backup at the same moment, you do not have redundancy. You have two copies of the same risk and a slide that says otherwise.


You do not fix this by buying a box. You fix it by dragging the threat model past the keyboard. A few places to start.

  • Map the physical dependencies of your most important workloads. Know where the power, cooling, connectivity, and airspace actually sit for the regions you run in, not the ones on the marketing map.

  • Push your cloud provider past the brochure. Ask about power redundancy, backup fuel, and counter-drone posture at your specific region, and get the answers in writing.

  • Prove your failover is actually independent. If your primary and your backup can be taken out by the same substation, the same storm, or the same drone, fix that before you touch anything else.

  • Wargame denial, not just breach. Drop a physical disruption scenario into your next tabletop and watch how fast the incident response plan runs out of road.


Every one of those is a starting point, not a finish line. The hard part is finding where the single points of failure actually overlap, the spot where one power feed, one fiber path, and one patch of open sky all fail together, and that takes someone reading the physical and the digital at the same time.


The lesson of those drone strikes is not that data centers need taller fences. It is that the wall between physical security and cyber security has become the vulnerability itself. The attacker does not care which budget line you filed the risk under. They will walk through whichever door you forgot you owned, and lately that door is a power feed and a patch of unwatched sky.


If you cannot say who owns the airspace over your primary region, or what happens to your business the day its power goes away, that is not a facilities gap and it is not an IT gap. It is a security gap, and it needs one person looking at both halves at the same time. That is the assessment almost nobody runs, and it is the one we do.


Red Cell Security does offensive testing, physical security assessments, and vCISO advisory for companies that would rather find the soft path before someone else does.


If you want to pressure-test where your physical and digital risk actually overlap, reach out at operations@redcellsecurity.org or book time at https://outlook.office365.com/book/redcellsecurity@redcellsecurity.org/

 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.

© 2026 by Red Cell Security, LLC.

Phone

Email

Connect

  • X
  • Facebook
  • LinkedIn
  • Instagram
bottom of page