
Iranian strikes damaged Amazon Web Services data centers and infrastructure in the United Arab Emirates and Bahrain in March, disrupting cloud services and causing power and connectivity problems. The damage contributed to service disruptions and an extended recovery process, Reuters reported. In April, Iran's Islamic Revolutionary Guard Corps publicly claimed it had targeted an Amazon cloud-computing facility in Bahrain.
The episode prompted a proposal to give the U.S. government a clearer role in protecting selected digital infrastructure, including facilities private companies own outside U.S. territory. The argument comes from Kate Monroe, a Marine Corps veteran, CEO of Vetcomm and author of "The Race to Save America." Her proposed fix runs through Congress, national-security agencies and companies that operate systems ordinary people and institutions depend on.
Private infrastructure, state priorities
Monroe argues that national defense can no longer be understood only through borders, military bases and forces stationed abroad. Data centers, cloud-computing systems and telecommunications networks may sit thousands of miles from the United States, yet support military logistics, financial markets, communications, government systems and artificial intelligence. Hospitals, logistics companies and energy providers also rely on interconnected systems.
Federal law already defines critical infrastructure broadly, covering physical or virtual systems and assets whose destruction or incapacity could seriously affect national security, economic security, public health or safety. Monroe argues that some data centers could carry national-security importance comparable to a traditional defense facility. In that framing, privately owned computing capacity becomes part of the state’s strategic map.
The article proposes that Congress create a narrow designation for exceptionally important American-owned or American-controlled digital infrastructure. The government would identify a relatively small number of facilities whose destruction or prolonged incapacitation could seriously threaten U.S. national or economic security. Companies operating designated facilities would face high standards for cybersecurity, physical security, supply-chain integrity, redundancy and resilience, along with cooperation with U.S. national-security agencies.
A designation, and consequences
The proposal wouldn’t turn an overseas data center into U.S. territory. A government designation wouldn’t make a facility in Bahrain sovereign American territory, Monroe says. Instead, the designation would spell out consequences for deliberate attacks and, she argues, could help deter them.
Possible consequences include sanctions, asset freezes, diplomatic measures and defensive cyber operations. The article also raises additional measures authorized by Congress, depending on the circumstances and attribution. The goal shouldn’t be automatic escalation to military conflict. It’s to make consequences clear enough to discourage attacks. Congress would define the framework; the administration would work with allies on reciprocal protections for strategically important infrastructure overseas.
President Donald Trump's June 2026 National Security Presidential Memorandum on artificial intelligence directed the national-security enterprise to accelerate AI adoption and strengthen partnerships with private industry, according to the article. That reliance creates vulnerabilities: an adversary could attack the data center where AI computing occurs, disrupt its electricity, compromise communications infrastructure or target its supply chain.
The systems people rely on
The article says Russia has demonstrated willingness to use cyber operations and infrastructure attacks as instruments of state power; China has invested heavily in cyber capabilities and studied vulnerabilities created by U.S. reliance on interconnected systems; and Iran has shown willingness to use cyber and other asymmetric capabilities against U.S. interests. A power grid, port, telecommunications network, financial system or computing infrastructure supporting critical services could become a target.
No grassroots response, mutual-aid effort or community-led protection appears in the proposal. Its answer is institutional: Congress sets a designation, agencies coordinate with companies, and allies pursue reciprocal protections. Yet the services at stake extend well beyond those institutions. An attack could begin with lost computing capacity, a disrupted communications network or the failure of a system on which millions rely—not troops crossing a border or missiles striking a military installation.