The bad news is that I'd be out of a job if I chose your service in this instance. 47 hours is two full days. For an entire cluster to be down for that long is just unacceptable. Rebuilding a cluster from the last-known-good backup should not take that long, unless there are PBs of data involved; dividing such large data stores into separate clusters/instances seems warranted. Solution archs should steer customers to multiple, smaller clusters (sharding) whenever possible. It is far better to have some customers impacted (or just some of your customer's customers) than have all impacted, in my not so humble opinion.
And, if the data size is smaller, you may want to trigger a full rebuild earlier in your DR workflows just as an insurance policy.
The good news is that only a single cluster was impacted. When the "big boys" go down, everything is impacted... but customers don't really care about that.
Not sure if this impacted customer had other instances that were working for them?