Digital sovereignty is now an operating requirement, not a policy aspiration

A practical framework for CISOs navigating data control, vendor dependency, and continuity obligations in an era of geopolitical disruption.

AI-generated illustration depicting incident for the story: Digital sovereignty is now an operating requirement, not a policy aspiration

A practical framework for CISOs navigating data control, vendor dependency, and continuity obligations in an era of geopolitical disruption.

Summary

  • Europe’s three largest cloud providers held roughly 70 percent of the market last year; European providers collectively held around 15 percent — a concentration that creates strategic dependency, not just competitive imbalance.
  • A Zscaler-commissioned survey found 73 percent of respondents had delayed or cancelled transformation initiatives because of digital sovereignty concerns, prolonging legacy risk and weakening cyber readiness.
  • Ransomware incidents across Europe rose sharply year-on-year: Spain up 116 percent, Germany up 74 percent, Belgium up 73 percent, Italy up 53 percent, and France up 34 percent.
  • The UK’s National Cyber Security Centre reported a 130 percent rise in ‘nationally significant’ incidents over the past year.
  • A three-part outcome-based framework — control, choice, and continuity — is proposed as a way to pursue sovereignty without freezing modernisation.

From boardroom abstraction to operational constraint

Digital sovereignty has moved off the policy discussion paper and into procurement decisions, regulatory compliance programmes, and technology strategy. Sanctions risk, legal divergence, and cyber disruption are now variables that boards must account for. The absence of a single agreed definition of sovereignty should not be read as an absence of intent — the direction of travel is clear, even where the destination remains contested.

The concentration problem

Across Europe last year, the three leading cloud providers accounted for around 70 percent of the market, while European providers collectively held roughly 15 percent. That concentration is not, in itself, a security failure. However, it represents a strategic dependency that can become acute when legal regimes diverge, when access is contested, or when a geopolitical shock narrows the room to manoeuvre. Critically, it amplifies what analysts describe as the ‘ripple effect’: disruption at a small number of providers cascades across thousands of organisations and supply chains simultaneously.

The cost of delay

The common response among organisations caught between sovereignty pressure and transformation programmes has been to pause. A Zscaler-commissioned survey found 73 percent of respondents had delayed or cancelled transformation initiatives as a result of digital sovereignty concerns. That pause dynamic is counterproductive. It extends exposure to legacy risk, weakens cyber readiness, and leaves organisations less able to absorb ransomware, supply chain compromise, or a sudden shift in cross-border rules — precisely the scenarios sovereignty policy is meant to guard against.

The threat environment reinforces the urgency

Separate Zscaler ThreatLabz data records rising ransomware attack volumes across Europe: Spain up 116 percent year-on-year, Germany up 74 percent, Belgium up 73 percent, Italy up 53 percent, and France up 34 percent. The UK’s National Cyber Security Centre reported a 130 percent rise in nationally significant incidents over the past year. Fifty-two percent of IT executives surveyed believe their current security measures are insufficient against existing and emerging threats, including agent-based AI and quantum computing. AI is also giving adversaries greater speed, scale, and sophistication. The question, as the source material notes, is not whether disruption happens but whether systems can withstand it.

An outcome-based framework: control, choice, and continuity

The article proposes three practical dimensions for operationalising sovereignty. Control means enforceable governance over who can access data, who administers systems, where logs are stored, how keys are managed, and what subcontractors can see. It is not about isolation. Choice means maintaining credible alternatives if assumptions about a vendor or jurisdiction break down. This is achieved through architecture and contracts that preserve data portability, full supply-chain transparency, and pre-agreed exit paths that can be executed under time pressure — not simply by procuring duplicate systems. Continuity means keeping critical services running through any form of disruption. It becomes measurable through recovery time objectives, tested failover, supplier-failure drills, and exercises that simulate jurisdiction-change scenarios.

Mandate outcomes, not vendors

The most constructive sovereignty requirements focus on what controls an organisation must have — not which vendors it must buy. Prescriptive vendor mandates raise costs, increase compliance friction, and restrict access to leading technology without necessarily improving resilience. The French government’s reported restriction of certain foreign-made video conferencing tools in favour of a domestic alternative illustrates how quickly sovereign policy can become a procurement constraint, but the broader lesson is that outcome-based rules create room for organisations to use global platforms safely while meeting local requirements, without halting modernisation.

Roles and responsibilities

The framework assigns clear accountabilities. Boards should define what ‘sovereign enough’ means for their organisation and require regular reporting and testing tied to resilience outcomes. CEOs and COOs should treat sovereignty as a continuity matter and fund the modernisation that reduces brittle legacy dependency. CIOs and CISOs should map and minimise third-party access, implement localisation and multi-region resilience where required, and build plans for supplier failure and jurisdiction-change scenarios. Regulators should clarify definitions, harmonise requirements where possible, and create compliance pathways that reward modernisation rather than incentivise delay.

Why it matters

For CISOs, digital sovereignty is no longer a government relations concern — it sits directly in the risk register. Supply-chain concentration, jurisdictional ambiguity, and rising ransomware volumes mean the organisation’s ability to maintain control over data and keep critical services running is under simultaneous pressure from regulatory change and adversarial activity. The 73 percent delay rate in transformation programmes is particularly relevant: pausing modernisation to manage sovereignty complexity often leaves organisations more exposed, not less. CISOs who treat sovereignty as a continuity and governance problem — rather than a procurement ideology — are better placed to satisfy regulators, reduce dependency risk, and maintain cyber readiness at the same time.

What to do now

  • Map all third-party and subcontractor access to sensitive systems and data, identify where administrative control sits, and document which jurisdictions are involved in your critical service delivery chain.
  • Audit current vendor contracts for data portability provisions and pre-agreed exit paths; identify programmes where lock-in has effectively become a dependency strategy.
  • Build and test continuity plans specifically for supplier-failure and jurisdiction-change scenarios, with defined recovery time objectives and documented failover procedures.
  • Establish a decision gate for every programme stalled by sovereignty concerns: redesign the architecture, apply mitigating controls, or exit the dependency on a defined timeline — do not allow delay to become the default outcome.
  • Work with your board to define what ‘sovereign enough’ means for your organisation’s risk appetite, then tie reporting and testing cadences to resilience outcomes rather than vendor or product compliance.
  • Engage with regulators and industry groups to advocate for outcome-based sovereignty requirements — enforceable access controls, portability, and tested continuity — rather than vendor-prescriptive mandates that raise costs without improving resilience.

Sources