Almaty is Kazakhstan’s financial center and one of the most seismically hazardous cities in Central Asia. Strong earthquakes in 1887 and 1911 destroyed a large part of the city’s buildings. Felt shocks are recorded here regularly: in January 2024 the intensity in the city reached about 5, and residents left their homes during the night.
For banks and fintech companies this is a question of business continuity and geographic redundancy of data. If the primary and backup IT infrastructure sit in the same city, a disaster recovery plan protects against a server failure, but not against an event that affects the whole region.
Below are four cases in which a natural or man-made disaster stopped data centers, and the conclusions they carry for disaster recovery (DR) in Kazakhstan.
Case 1. Pangyo, 2022: one site, five days to recover
On 15 October 2022 the battery compartment of the uninterruptible power system caught fire at the SK C&C data center in Pangyo, South Korea. About 32,000 servers of Kakao, the country’s largest IT ecosystem, were running at the site.
The KakaoTalk messenger, the Kakao Pay payment service and the KakaoBank mobile bank stopped. Financial services were unavailable for about 10 hours; full recovery of the ecosystem took 127 hours. The financial-market regulator opened a review of how KakaoBank, Kakao Pay and Kakaopay Securities acted in the first hours of the outage. A co-chair of Kakao resigned.
In December 2022 the Korean parliament required operators of large digital services to have a data-backup system and a disaster action plan.
Takeaway. Redundancy inside a single site does not protect against an event that takes the whole site down. A recovery plan that has not been tested under real load does not work when the incident happens.
Case 2. New York, 2012: backup power in the same risk zone
On 29–30 October 2012 Hurricane Sandy raised the water level in Lower Manhattan by more than 4 meters. Basements of several large data centers flooded, including those at 75 Broad Street and 33 Whitehall Street.
Generators at the sites were running, but the pumps that fed diesel fuel sat in the flooded basements. Some operators shut the equipment down. Major media outlets, including Gawker and BuzzFeed, lost connectivity. At one site, clients and staff spent several days carrying fuel up the stairs to the generators by hand.
Takeaway. A site’s backup systems share its natural hazards. Protection from a regional event comes only from a backup site in another region.
Case 3. Turkey, 2023: an intact data center with no connectivity is useless
After the earthquakes of 6 February 2023, internet traffic in Kahramanmaraş Province fell by 94%, and in Gaziantep by 57%. Telecom operators deployed mobile base stations, generators and satellite links.
Takeaway. A disaster hits more than the building. It also hits the power grid and the backbone routes around it. Even a site that survives inside the disaster zone can be unreachable. For DR, the unit of risk is the region, not the building.
Case 4. Almaty: a risk that cannot be ruled out
According to the National Scientific Center for Seismological Observations and Research of the Ministry of Emergency Situations of the Republic of Kazakhstan, earthquakes of magnitude above 8 are possible in the Almaty area, and the exact date and strength of such an event cannot be predicted. About one third of Kazakhstan’s territory is classified as seismically hazardous.
The USGS earthquake catalog for 1976–2026 shows where that risk is concentrated: epicenters of strong earthquakes (magnitude 5.5 and above) cluster in the south and east of the country, in the Tien Shan, the Dzungarian Alatau and the Altai. Within a 450 km radius of Astana, no earthquake of magnitude 5 or above has been recorded in 50 years; the nearest epicenter of magnitude 5.5 or above is 793 km away.

USGS earthquake catalog, 1976–2026: epicenters of magnitude 5.5 and above. Within 450 km of Astana, no earthquake of magnitude 5 or above was recorded in 50 years.
What these cases share
One site is a single point of failure. Redundancy of servers, power and cooling inside a building does not help if the building itself is unavailable.
A backup in the same risk zone shares the fate of the primary site. A flood, an earthquake or a failure in the power system takes both sites down at the same time.
An untested plan does not work. Switching over to the backup site has to be rehearsed regularly under load, not kept in a document.
What the regulator requires in Kazakhstan
Information-security requirements for banks (Resolution of the Board of the National Bank of the Republic of Kazakhstan No. 48 of 27 March 2018) oblige banks to provide backup storage of data sufficient to restore a working copy of their information systems. In reporting to the regulator, banks disclose whether backup data-processing centers exist, how they are equipped and supplied, and whether they are ready.
The document does not say where the backup center must be placed. That choice stays with the bank — and it is what determines whether the DR setup protects against a regional event.
Where to place the backup site
For banks and fintech companies whose primary infrastructure is in the seismically active regions of the south and east, the logical choice is a backup data center (a second data center) in another region of the country, outside the seismic hazard zone: a different natural-risk profile, a different power system and different backbone routes, but the same jurisdiction. That covers the regional risk and keeps the data inside Kazakhstan.
Akashi Data Center is being built in Astana with this task in mind: independent power inlets, four independent optical entries, and an engineering architecture that is both fault-tolerant and disaster-resilient. The project is certified by the Uptime Institute to Tier IV (Certification of Design Documents); certification of the constructed facility comes after commissioning. Launch of the first phase is planned for 2027; placement of backup environments is being discussed as a reservation (colocation and rack rental).