TL;DR: At approximately 7:40 AM ET on July 24, 2026, AWS us-west-2 (Oregon) lost external connectivity for roughly 80 minutes, taking Apple Pay, DoorDash, Reddit, Hulu, and PlayStation Network offline; a handful of AWS Direct Connect customers through the Westin Building Exchange Seattle saw a 1 hour 17 minute tail. Per TechTimes coverage, this is AWS's third significant outage in three months — following the May 2026 Azure/AWS multi-cloud outage and the July 16 AWS CloudFront VPC-origins failure. IncidentHub recorded 9 confirmed cascade incidents across 7 downstream providers during the July 24 event. For NC small businesses — Piedmont Triad manufacturers on cloud ERP, Triangle professional services on Google Workspace + Microsoft 365, Charlotte-metro distributors on Shopify/HubSpot — the message is that the "hyperscaler = always up" assumption is broken and the BCDR plan needs to reflect it.
Key takeaway: Cloud outages are now expected, not exceptional. Forrester projects at least two major multi-day hyperscaler outages in 2026, and July's cadence (one AWS incident every ~10 days) validates the forecast. NC SMBs should treat the July 24 event as a live-fire test: if it took your business more than 15 minutes to identify impact, more than 60 minutes to communicate to customers, or more than 4 hours to restore critical workflows, your BCDR plan needs a Q3 rework.
Need a two-week BCDR gap assessment against the July 2026 outage timeline? Contact Preferred Data Corporation at (336) 886-3282 for a right-sized multi-region resilience review. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.
What Exactly Happened During the July 24, 2026 AWS Outage?
At 7:40 AM ET on July 24, AWS lost network routing between the us-west-2 region (Portland/Boardman/Hillsboro data centers) and the Seattle Metro exchange. Per IncidentHub's post-mortem summary, AWS attributed the fault to the networking hardware carrying routing between the region and the Seattle Metro. AWS's own status message during the incident — "connectivity within the region was not affected by this event" — confirms the failure was at the boundary, not inside compute or storage.
Three specific effects flowed from the incident:
- Customer impact window. ~20 minutes of complete external-connectivity loss for most workloads; a 1 hour 17 minute tail for customers whose Direct Connect path routed through EqSe2 (the Westin Building Exchange, Seattle).
- Cascade failures. IncidentHub recorded 9 confirmed cascade incidents across 7 providers, and 3 possible cascades at 3 more — including Apple Pay, Hulu, Reddit, DoorDash, and PlayStation Network.
- Communications drag. Even after AWS's network path restored, several downstream SaaS platforms took an additional 30-90 minutes to work through queued transactions and re-establish upstream dependencies.
The July 24 event followed the July 16 AWS CloudFront outage tied to VPC origins misbehavior, which affected static-asset delivery and API gateway paths across many customer-facing SaaS platforms. Two AWS incidents in eight days is not a random cluster; it is the operating environment for the rest of 2026.
Why Are NC SMBs Uniquely Exposed to Hyperscaler Outages?
Three structural reasons NC SMBs feel these outages harder than enterprises.
- Single-region SaaS purchases. Most SMB SaaS purchases default to a single region (typically us-east-1 or us-west-2). Enterprises negotiate multi-region deployments with active/active failover; SMBs get a single-region SLA that reads well on paper but offers no protection against exactly this class of event.
- Downstream dependency density. A typical NC SMB with 50 employees runs 30-70 SaaS applications. When AWS us-west-2 drops, the SMB does not lose one application — it loses the 15-30 apps whose vendors happen to run there, plus the 5-10 apps whose vendors run in us-east-1 but depend on us-west-2 microservices they did not disclose to the customer.
- Limited in-house incident response. Per demandsage's internet-outage tracker, the median cost of downtime is $9,000/minute for enterprises, but SMBs face the same clock without the same detection tooling or vendor-escalation muscle. The July 24 event's first 20 minutes vanished before most SMBs even confirmed which of their apps were affected.
The convergence is what Forrester's 2026 outage forecast called "the new normal," and it lands hardest on the segment least equipped to plan around it.
What Should NC SMBs Do in the 30 Days After the July 24 Outage?
Five moves in decreasing order of universal applicability.
- Run a "July 24 replay" gap assessment. Walk the timeline: at 7:40 AM ET on a Thursday, which of your critical workflows would have failed? How quickly would you have known? What would you have told customers? Most NC SMBs discover in the replay that (a) they did not know which apps depend on us-west-2, (b) they had no pre-drafted customer-communication template, and (c) they had no runbook for graceful degradation.
- Map your SaaS-to-region dependency graph. Every SaaS vendor's status page discloses their hosting region. Build a simple spreadsheet: app → primary region → failover behavior → your business function. This 3-hour exercise typically reveals 5-15 apps concentrated in one region that a competent architecture would spread across two.
- Move DNS to a resilient provider with health-checked failover. If your business-critical DNS is at your domain registrar (GoDaddy, Namecheap, Google Domains), move to a provider with health-checked failover (Route 53, Cloudflare, NS1). This one change often converts a 45-minute customer-facing outage into a 90-second one.
- Prove your backup restores work — this quarter. Backups you have never tested are not backups. Per PDC's business continuity guidance for NC manufacturers, the annual restore test is the single most valuable BCDR exercise. Schedule it in Q3, document the RTO you actually achieved, and gap-close before Q4 renewals.
- Diversify customer-communication channels. If your only outage-day channel is a status page hosted on the same infrastructure that just failed, you have no channel. Establish a second-independent-provider status page (Statuspage, Better Uptime, or a plain static-hosted page on a different DNS) and pre-authorize SMS/email templates.
Executed together, the five moves convert the next hyperscaler outage from a "we did not know / could not communicate / could not recover" event into a "we detected, communicated, degraded gracefully, and restored" event.
Multi-Region vs Multi-Cloud: What Is Actually Right for a 50-Seat NC SMB?
The following comparison shows the practical fit for a typical NC SMB.
| Strategy | Setup Cost | Ongoing Cost | RTO Achievable | Right For |
|---|---|---|---|---|
| Single-region, no plan | $0 | $0 | 2-24 hours (vendor SLA) | Nobody in 2026 |
| Single-region + tested runbook | ~$3-8K one-time | ~$500-1,500/mo | 30-90 minutes | Very small SMB (<20 seats) |
| Multi-region (same cloud) | ~$8-25K one-time | ~$1,500-4,500/mo (10-30% cloud spend uplift) | 5-20 minutes | Most NC SMBs (25-150 seats) |
| Multi-cloud (2 hyperscalers) | ~$40-120K one-time | ~$4,500-12,000/mo (40-80% cloud spend uplift) | 1-5 minutes | Regulated verticals, high-transaction commerce |
| On-prem + cloud hybrid | Variable (existing hw) | Depends on refresh cycle | 15-60 minutes | Manufacturers with existing infra investment |
For most NC SMBs, multi-region within a single cloud is the right answer: it captures 80-90% of the resilience benefit at 15-25% of the cost of a full multi-cloud architecture. Multi-cloud is genuinely correct for regulated financial-services SMBs, high-volume commerce, and firms with contractual multi-provider requirements — but for the Piedmont Triad manufacturer, the Triangle law firm, or the Charlotte distributor, disciplined single-cloud multi-region beats undisciplined multi-cloud every time.
Which NC SMB Verticals Should Prioritize the Q3 BCDR Refresh?
Four segments face concentrated exposure and belong at the front of the Q3 review queue.
- Piedmont Triad manufacturers on cloud ERP (NetSuite, SAP S/4, Sage Intacct, Foundation Software cloud). Order entry, shipping, and payroll all collapse the moment the ERP's region drops. A single-region ERP is a business-continuity red flag that most SMBs do not recognize until an outage.
- Triangle professional services on Microsoft 365 + Google Workspace with heavy dependency on cloud file storage. The July 24 event did not hit either primary email tenant directly, but the cascade impact on connected apps (DocuSign, Zapier, HubSpot) made the workday materially worse for 90 minutes.
- Charlotte-metro distributors and e-commerce operators running Shopify + a warehouse-management SaaS + a payment processor. Every one of those vendors is a single-region SaaS by default, and a cascade outage can turn a normal shipping day into a 4-hour hold-and-recover event.
- Regional healthcare and dental practices on cloud PM/EHR systems. HIPAA does not exempt outage-day mistakes, and paper-degradation runbooks are the single most-overlooked BCDR asset in the vertical. Per HHS OCR's 2026 risk-management enforcement expansion, documented contingency planning is now inspection-ready evidence, not a nice-to-have.
What Does a Right-Sized NC SMB BCDR Plan Actually Look Like?
Five components, each with a Q3-achievable target.
- Written incident-response runbook covering detection, triage, customer-communication, degradation, and restoration. 8-12 pages, tested quarterly. Most NC SMBs either have nothing here or have a 40-page PDF nobody has read since 2023.
- Tested backup restore with a documented recovery-time objective (RTO) and recovery-point objective (RPO). Test annually at minimum; quarterly for regulated verticals.
- Multi-region posture on business-critical SaaS. Ask every vendor: "What is your default region? Do you offer multi-region deployment, and at what cost?" For the 3-6 vendors whose failure would stop your business, the answer needs to be multi-region.
- Resilient DNS with health checks and failover. Registrar-provided DNS is the most common single point of failure NC SMBs do not realize they have.
- Cyber insurance BCDR alignment. Modern cyber insurance underwriting rewards documented BCDR posture with premium reductions; per the cyber insurance 96% MFA mandate playbook, the same discipline that reduces ransomware risk reduces outage risk.
Ready for a two-week BCDR gap assessment for your NC business? Contact Preferred Data Corporation at (336) 886-3282. Serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.
Frequently Asked Questions
What time did the July 24, 2026 AWS outage start and how long did it last?
The outage began at approximately 7:40 AM ET on Thursday, July 24, 2026, in AWS's us-west-2 (Oregon) region. Per IncidentHub's post-mortem, the primary customer impact window was ~20 minutes for most workloads and 1 hour 17 minutes for customers routing through the Westin Building Exchange Seattle. Downstream SaaS platforms (Apple Pay, DoorDash, Reddit, Hulu, PlayStation Network) took an additional 30-90 minutes to work through queued transactions.
Was this the same AWS outage as May 2026?
No. The May 2026 event was a broader Azure/AWS multi-cloud incident (covered in PDC's May 2026 business continuity blog). The July 16 event was an AWS CloudFront VPC-origins failure. The July 24 event was an us-west-2 external-connectivity failure. Per TechTimes' reporting, this is the third significant AWS incident in three months.
How much did the July 24 outage cost the average affected small business?
There is no single answer, but a useful benchmark: an SMB running 30 SaaS applications with a normal Thursday-morning transaction rate typically loses $2,000-$15,000 in direct revenue plus 2-6 hours of employee time during an 80-minute cascade outage. The larger cost — brand, customer trust, contract SLA exposure — is difficult to measure but often exceeds the direct revenue loss by 2-3x for customer-facing SMBs.
What is the difference between multi-region and multi-cloud?
Multi-region means running your workload in two or more geographic regions of the same cloud provider (e.g., AWS us-west-2 + us-east-1). Multi-cloud means running across two or more providers (e.g., AWS + Azure). Multi-region protects against regional failures like July 24; multi-cloud additionally protects against provider-wide failures. For most NC SMBs, multi-region within a single cloud captures the majority of the resilience benefit at a fraction of the cost.
Should I move off AWS after three outages in three months?
Almost certainly not. AWS's SLA and operational track record over multi-year horizons remains best-in-class, and Azure and Google Cloud have both experienced comparable outage clusters. The right response is not to switch providers but to build resilience against provider outages — multi-region posture, tested runbooks, resilient DNS, diversified customer-communication channels. Switching providers without changing architecture just moves the exposure to a different vendor.
What does PDC's BCDR gap assessment actually cover?
The assessment is a two-week engagement that (1) inventories your SaaS-to-region dependencies, (2) walks the July 24 replay against your business to establish current RTO/RPO, (3) tests your backup restores end-to-end, (4) evaluates DNS resilience and failover posture, (5) drafts or refreshes your incident-response runbook, and (6) delivers a 90-day gap-closure plan sized to your Q3-Q4 IT budget. Typical engagement scope is 25-150 seats.
Related Resources
- The July 24, 2026 AWS us-west-2 Outage post-mortem — IncidentHub
- AWS CloudFront July 16 outage analysis — Pagerly
- Forrester 2026 hyperscaler outage forecast — OpenMetal
- Preferred Data Managed IT Services
- Preferred Data Cloud Solutions
- Preferred Data Business Continuity & Disaster Recovery
- Related: Azure/AWS May 2026 Cloud Outage — Business Continuity
- Related: Business Continuity Planning for NC Manufacturers 2026
- Related: Cloud Outage Resilience Multi-Cloud Strategy 2026