For years, security teams viewed digital sovereignty as an abstract legal constraint or a political statement of intent. That era is over. Driven by stricter regulation, the uncontrolled rise of AI and growing service disruption risks, sovereignty has become a core pillar of IT resilience.
For CISOs, the goal is not to embrace an anti-cloud dogma or isolate the organisation from the rest of the world. It is to control dependencies, ensure compliance and guarantee business continuity.
Here are four priority workstreams to help CISOs embed digital sovereignty into their scope of responsibility.
1. Regulatory compliance as a driving force (NIS2, DORA and GDPR)
In practice, legal requirements remain the primary catalyst for digital sovereignty projects. The European regulatory framework has become considerably stricter, imposing end-to-end traceability:
-
Control over the “digital supply chain” (NIS2/DORA): CISOs are now accountable for the security of their service providers. The question is no longer simply where data is stored, but who maintains the systems and holds remote administration privileges. Technical support based outside the EU creates an immediate sovereignty gap.
-
Cross-border transfers (GDPR): Personal data flows outside the European Economic Area require strict legal and technical safeguards, with potentially severe penalties for non-compliance.
2. Operational sovereignty: Neutralising extraterritorial risk
What concerns CISOs most is not so much the physical location of a server as the fact that providers may be subject to extraterritorial laws, such as the US CLOUD Act or foreign intelligence legislation.
-
The “sovereign enclave” approach: Bringing everything back in-house is neither financially nor operationally viable. The most effective strategy is based on segmentation: 80% of the IT estate remains in the public cloud to preserve business agility, while the most critical 20% is isolated in protected environments such as sovereign clouds or on-premises infrastructure.
-
Use of demanding qualification schemes: For ultra-critical data, qualified solutions — such as SecNumCloud in France or ENISA certifications at European level — provide an effective shield.
-
Encryption key management: Sovereignty requires exclusive ownership and control of encryption keys. Encryption only delivers real value if the customer retains full control of the HSM (Hardware Security Module), with no possible access for the cloud provider.
3. Disaster recovery and control over vendor lock-in
Digital sovereignty is, above all, about freedom of choice. If a software vendor or hosting provider unilaterally changes its pricing, restricts services because of geopolitical tensions or suffers a major outage, the IT system must be able to survive.
-
Reversibility as a disaster recovery requirement: The ability to migrate a critical environment from cloud A to cloud B must be formalised and tested regularly. Exit costs (egress fees) and dependencies on proprietary components must be taken into account from the architecture phase onwards.
-
Native interoperability of security tools: A defence chain made up of closed solutions that cannot communicate with one another leads to critical information loss during an incident. Interoperability ensures that one component can be replaced without causing visibility across the entire IT estate to collapse.
-
Encryption and air-gapped backups: The disaster recovery plan requires physical and logical backups that are completely isolated from the primary production infrastructure to withstand ransomware attacks.
4. Controlling Shadow AI and Shadow SaaS
The widespread and informal adoption of generative AI tools (LLMs) by business teams creates an immediate risk of intellectual property leakage.
-
Protecting data assets: Sending source code, financial data or contracts to a public AI model hosted abroad is tantamount to relinquishing sovereignty over those assets.
-
Deploying controlled alternatives: Rather than blocking innovation, CISOs should provide sovereign AI enclaves — such as open-source models hosted on-premises or in qualified private clouds — and rigorously audit access to the SaaS applications used across the organisation.
Conclusion: From dogma to risk-based management
For CISOs, digital sovereignty is not a barrier to digital transformation; it is its safeguard. By mapping dependencies, segmenting critical data and demanding genuine interoperability between tools, the security function does more than meet compliance requirements: it safeguards the organisation’s long-term resilience and strategic independence.
Contact us
Do you have any questions about an article? Do you need help solving your IT issues?
Contact an expertStay in control with the DEEP & OVH Sovereign Cloud
Protect your critical data and applications in a local sovereign cloud environment, hosted in DEEP’s Tier IV data centres in Luxembourg and operated by our experts. Reduce dependencies, simplify compliance and strengthen the long-term resilience of your information systems.

Other articles in the category Trends
Technology Trends 2026: AI, Cybersecurity and Digital Trust
Explore the key technology trends shaping 2026: AI maturity, cybersecurity, data governance, digital sovereignty and enterprise resilience.
Published on
05 January 2026
Helping companies acquire a genuine data culture
Implementing a “Data Intelligence” approach within your organisation is a major project, which entails considering many aspects of the technology. If you want to adopt a data analysis process or, ultimately, use artificial intelligence or machine learning throughout your organisation, you first need to be familiar with your data and have full control over it.
Published on
12 September 2023
7 key technological trends and developments in 2023
Accompany us, and our partner Splunk, to find out about the trends and technological developments to watch out for in the coming months.
Published on
03 April 2023








Our experts answer your questions
Do you have any questions about an article? Do you need help solving your IT issues?