What a surprise for the EU 😱 😉 A recently published expert opinion commissioned by the German Federal Ministry of the Interior has sparked a pivotal discussion on data governance and sovereignty. According to the report, US authorities can exert far-reaching access rights to cloud data managed by US-based companies, even when that data is stored in European data centers and administered through local subsidiaries. This is because legal instruments such as the Stored Communications Act extended by the Cloud Act and Section 702 of FISA focus on the provider’s control, not the physical location of the servers. This finding is a firm reminder that simply hosting data on European soil does not guarantee protection from extraterritorial legal claims. It reveals structural risks in relying on dominant foreign cloud providers for sensitive data and critical digital infrastructure. For Europe to truly uphold its data protection principles and strategic autonomy, the conversation must go beyond compliance checklists and contractual assurances. We need stronger investment in #opensource digital infrastructure and indigenous technologies that reduce dependency on non-European platforms. Open source fosters transparency and auditability while enabling communities and businesses to build on systems that are not bound by foreign legal systems. If #digitalsovereignty is to mean more than a buzzword, we must accelerate our efforts towards resilient, interoperable, and locally governed alternatives. Only then Europe can ensure that its data is governed by the laws and values that its citizens and organisations expect. Source: https://lnkd.in/dtpXiwYN
Trust in cloud security and sovereignty
Explore top LinkedIn content from expert professionals.
Summary
Trust in cloud security and sovereignty means having confidence that your data is safe, private, and governed by local laws—not just where it’s stored, but also who controls access and the rules for handling it. As businesses and governments grow concerned about international regulations and foreign access to cloud data, they’re seeking new ways to ensure true control and compliance in digital environments.
- Prioritize local control: Choose cloud services managed and governed within your own country to reduce risks of foreign legal access and to protect sensitive information.
- Diversify cloud strategy: Use a mix of different cloud providers, including private and sovereign options, so you can maintain flexibility and avoid relying on any single international company.
- Evaluate transparency: Seek providers that openly share their practices and compliance measures, making it easier to understand where your data lives and how it’s protected.
-
-
What happens if the new US Government tears up the Cloud Act? Experience shows that without any warning they aren’t shy about ripping up international agreements (trade or otherwise). There’s growing concern that we could wake up one morning to find that the Cloud Act and associated digital sovereignty frameworks are gone with one stroke of a pen. This isn’t abstract fear-mongering. It’s a very real risk. Personally, I’d hate to be sitting in front of a Select Committee, or my CEO, explaining why we didn’t have a Plan B. If these legal protections disappear, UK and EU organisations could become non-compliant overnight, just by continuing to store or process personal data in US-owned public cloud infrastructure. That includes M365, AWS, Azure, Google Workspace, Oracle, Salesforce, Dropbox, the list goes on. All your data would be exposed to extraterritorial US surveillance or seizure, with no meaningful legal route to challenge it under UK or EU law. The EU–US Data Privacy Framework is already on shaky ground. If the US withdraws (again), UK firms relying solely on public cloud could be left stranded, with data protection regulators forced to respond. So, what’s the low-risk path forward? It’s hybrid cloud (on premise or hosted). But done properly and not a panicked knee jerk reaction, where the non-public cloud components are delivered and governed locally by you, or a UK-based provider under domestic law. Right workload, right place, right time... (and supporting UK businesses to grow and become future unicorns), growing our tax base and helping communities. This doesn’t just mindlessly tick compliance boxes. It also brings greater control, clearer governance, and a meaningful reduction in business risk. In this climate, that’s not a nice-to-have… it’s beyond essential. Even if you disagree, its gotta be worth documenting why internally. Don't leave yourself exposed, it could be very career limiting. Can I sell it to you? Nope, not my bag. But there are plenty of awesome local providers who deserve your attention that I can point you at.
-
The European Commission has just done something that didn't exist a year ago: it has made digital sovereignty measurable. Its new Cloud Sovereignty Framework — clarified in a follow-up published on 1 June after heavy interest from public administrations and IT firms — turns an abstract principle into procurement criteria you can actually score. Two mechanisms sit at the core: → A Sovereignty Effectiveness Assurance Level (SEAL), running from SEAL-0 (no sovereignty) to SEAL-4 (a full EU supply chain, chips to software). SEAL-2 maps to data sovereignty, SEAL-3 to technological autonomy, SEAL-4 to full sovereignty. → An overall sovereignty score across 48 defined criteria, grouped into eight categories: strategic, legal and jurisdictional, data and AI, operational, supply chain, technological, security and compliance, and environmental sustainability. This was no paper exercise. The framework was used to award a €180M sovereign cloud tender in April to four European providers — Post Telecom (with OVHcloud and CleverCloud), StackIT, Scaleway, and a Proximus-led group using S3NS, Clarence and Mistral. Why it matters for us: before this, sovereignty was a sales conversation built on adjectives. Now there's a shared scoring language clients will increasingly expect us to speak. Worth reading if you're anywhere near a sovereignty discussion. Framework explained: https://lnkd.in/ewMe5hdd
-
Europe is finally asking the right question — but it’s still early in the game. The €180M sovereign cloud initiative is not the destination. It’s table stakes. Digital sovereignty is not a hosting problem. It’s a control problem. And control does not live in infrastructure — it lives in the layer above it. The real battleground is the trust and control layer: Who owns identity? -Who governs authentication and authorization? -Who controls cryptographic keys? -Who enforces policy across systems? -Who guarantees provenance, traceability, and continuity? That layer defines whether sovereignty is declared… or actually executed. This is where Europe has a unique strategic opportunity. Because European Business Wallets, Digital Product Passports, and Trusted AI are not just digital tools — they are control primitives for a new economic architecture. They enable: → Programmable trust → Verifiable ecosystems → Cross-border interoperability with embedded compliance In other words: they operationalize sovereignty at scale. But there is a non-negotiable constraint most strategies are still underestimating: If it’s not quantum-resilient, it’s not sovereign. Any identity or trust system built today on vulnerable cryptography has a built-in expiration date. So the mandate is clear: 👉 Move from sovereign infrastructure to sovereign control 👉 Design from day one for a post-quantum world 👉 Treat identity and trust as core strategic infrastructure, not as features Because the future won’t be defined by who owns the cloud. It will be defined by who controls the logic of trust across the entire digital stack.
-
🌍 The Shift in Europe: Moving Away from US Hyperscalers 🌩️ As geopolitical concerns, data sovereignty, and pricing instability grow, European companies are making bold moves in their cloud strategies—and the implications are massive. Over the past 15 years, reliance on public cloud giants like AWS, Microsoft, and Google has skyrocketed. But now, we’re seeing a strategic pivot unfolding across Europe, as organizations mitigate risks and embrace alternative solutions to protect their future. 🎯 Why the shift? ✅ Data Sovereignty: Stricter data protection laws like GDPR and fears over compliance with laws like the US CLOUD Act are driving demand for European-managed cloud solutions and sovereign cloud providers. Organizations are prioritizing control over their sensitive data and leaning into platforms that support their unique privacy needs. ✅ Security and Trust: Concerns over potential government interference, espionage, and vendor lock-in are making European businesses rethink their current reliance on US-based hyperscalers. The rising interest in diverse, multi-cloud strategies and locally governed services reflects the growing importance of trust in cloud decisions. ✅ Economic Predictability: Increasing costs from hyperscalers have raised concerns about long-term pricing stability. Enterprises are recognizing that forward-looking cloud strategies need to include providers that prioritize pricing transparency and tailored solutions. 🎯 What’s the result? A diverse and dynamic cloud ecosystem is emerging in Europe, leaning on open-source technologies, sovereign cloud providers, and tailored private cloud solutions. Platforms like OpenStack and others are paving the way for digital transformation without compromising on compliance or strategy. As businesses explore these new approaches, multi-cloud strategies, hybrid environments, and innovative pricing models are becoming essential for mitigating risks and staying competitive within an ever-evolving cloud landscape. 📢 This shift isn’t just about technology—it’s about geopolitics, trust, and long-term business resilience. Let’s embrace a future where diversity in cloud ecosystems fosters innovation, enhances security, and ensures sovereignty. What are your thoughts on this shift towards sovereign and multi-cloud solutions? 💭 Let’s discuss! #CloudComputing #DataSovereignty #SovereignCloud #MultiCloud #Geopolitics #Innovation
Why Europe Is Fleeing The Cloud
https://www.youtube.com/
-
Europe just sent a message to every hyperscaler, SaaS giant, and foreign cloud provider on the planet: “Your data center may be in our country. But your jurisdiction may not be.” The Netherlands blocking Kyndryl’s acquisition of Solvinity is a much bigger story than one Dutch cloud provider. This is the first real sovereign cloud line in the sand from a major Western ally against a US tech company. And Kyndryl isn’t some random startup. It’s IBM DNA. Enterprise infrastructure royalty. But none of that mattered. Why? Because Solvinity helps run DigiD, the digital identity backbone millions of Dutch citizens use for taxes, healthcare, pensions, and government services. In other words: critical national infrastructure. (NL Times) The issue wasn’t where the servers sit. It was who ultimately controls the company. That’s the new reality of cloud. For years, “data residency” was enough. Keep workloads local, add compliance language, maybe throw in a sovereign region marketing slide and call it a day. Now governments are realizing something: If a company falls under another nation’s laws, the infrastructure is never fully sovereign. The CLOUD Act changed the conversation. European governments know that American firms can still face legal demands from US authorities, even if the data physically stays in Europe. (Taylor Wessing) This is why sovereign cloud suddenly went from niche procurement jargon to geopolitical strategy. And this is only the beginning. Expect more: National AI infrastructure mandates Local ownership requirements “Trusted operator” certifications Government pressure to reduce dependence on US hyperscalers European cloud alliances and regional AI stacks More scrutiny around digital identity systems, healthcare data, telecom infrastructure, and critical SaaS The irony? The cloud industry spent 15 years convincing everyone location didn’t matter. Now location, jurisdiction, ownership, and control matter more than ever. We’re entering the era of geopolitical architecture. Cloud is no longer just IT infrastructure. It’s foreign policy with APIs. Cc David Linthicum
-
🇺🇸🇪🇺✈️ Airbus wants a sovereign #EU cloud to keep its sensitive #data out of reach of #USA regulation, especially the Cloud Act. #Sovereignty won’t happen unless the market needs it. The recent Air France-Starlink episode made that clear. ☝️ What has changed is the geopolitical context. Rising tensions under the Trump administration make it a necessity for European firms to secure continued access to their data in case of escalation and to limit unwanted access enabled by the US #Cloud Act. That law allows US authorities to request data held by US companies even when it is hosted outside the US. This is why Airbus wants to avoid Microsoft, Amazon, and Google for its most critical applications. 📊 Airbus estimates an 80% chance of finding a fully European solution. If it works at this scale, it will show that sovereign cloud can work in practice, and others may follow. The big change is that the market now needs #sovereign solutions, whereas previous initiatives were politically driven (and mostly failing).
-
𝗘𝘂𝗿𝗼𝗽𝗲’𝘀 𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝘁𝗼 𝗮𝗰𝘁 𝗶𝘀 𝗶𝗻𝗰𝗿𝗲𝗮𝘀𝗶𝗻𝗴𝗹𝘆 𝗱𝗲𝗰𝗶𝗱𝗲𝗱 𝗶𝗻 𝘁𝗵𝗲 𝗰𝗹𝗼𝘂𝗱. Today, together with Frederic Munch, Sopra Steria, I published a joint guest article in Table.Briefings on why digital sovereignty has become an operational question. Cyber threats, regulatory complexity and geopolitical tension are converging. Digital infrastructure is no longer just an efficiency layer. It determines whether governments, institutions and critical industries remain capable of acting under pressure. The real dilemma is not whether to move to the cloud. It is how to do so without losing control. Many organisations hesitate because jurisdiction, accountability and decision rights are not clearly anchored in cloud architectures. And that hesitation is understandable. At the same time, staying outside modern architectures limits scalability, resilience, and AI adoption. Inaction creates risk just as much as unmanaged dependency does. This is exactly where the sovereignty debate must mature - and where European technology providers such as SAP play a critical role in anchoring operational control within cloud architectures. Digital sovereignty is not about isolation. It is about: 🔹Operational control by design. 🔹Clear legal frameworks embedded in architecture. 🔹Defined decision rights across partners. 🔹Accountability that holds under stress. Europe has the technology and the industrial base. What matters now is execution. That is the shift we argue for in our article: moving from abstract sovereignty debates to concrete governance models that work in practice.
-
🧼 Is your "Sovereign Cloud" actually sovereign, or is it just "Sovereignty Washing"? Here is a hard truth for CISOs: If your cloud provider says "Your data stays in Germany" but their support team in Seattle has root access... you aren't sovereign. If your provider says "Bring Your Own Key" but their software has to decrypt your data in memory to process it... you aren't sovereign. If your provider is a "local partner" but the underlying stack is licensed closed-source code from a US giant subject to FISA 702... you aren't sovereign. We have created a massive industry of "Compliance Theater." We are checking boxes to satisfy NIS2, while ignoring the technical reality that US tech stacks are fundamentally under US jurisdiction. Stop buying the label. Audit the architecture. #CyberSecurity #CISO #CloudArchitecture #SovereignCloud #Compliance
-
🚨 ☁️ - New Recorded Future Insikt Group report! This research examines how cloud intrusions are converging on a consistent pattern: adversaries rarely need to deploy traditional malware once they obtain a valid identity. The operational pivot is quiet but consequential. Access now precedes tooling. After authentication, attackers increasingly rely on native platform functionality to enumerate environments, manipulate backups, alter encryption states, and move data through sanctioned workflows. From the system’s perspective the activity is compliant. The infrastructure does exactly what it was designed to do, just for the wrong principal. What emerges is a different kind of compromise. Historically an intrusion introduced foreign code into a trusted environment. In cloud environments the attacker instead borrows trust from the environment itself. Detection therefore becomes less about identifying artifacts and more about interpreting intent, which is a far less stable signal. Administrative behavior, automation, and malicious action begin to occupy the same telemetry space. That shift quietly reshapes response and policy. Attribution frameworks built around infrastructure and tooling struggle when the operational layer is indistinguishable from legitimate enterprise administration. Actions that produce real operational impact can occur through standard consoles, tokens, and APIs. The observable evidence increasingly looks like misused governance rather than external penetration. The dependence on shared platforms compounds this effect. A single compromised vendor or federated identity can propagate access across multiple tenants, turning what would once have been an isolated incident into a cross organizational event with systemic characteristics. The boundary between incident response and resilience planning narrows accordingly. Cloud security is therefore drifting away from the traditional model of defending systems toward validating authority. The practical question is less whether an environment was breached and more whether the actor operating inside it had the right to act at all.