ao link
Business Reporter
Business Reporter
Business Reporter
Search Business Report
My Account
Remember Login
My Account
Remember Login

DigitalTransformationTalk: Data Sovereignty in practice - securing critical operations 

On 30 April 2026, DigitalTransformationTalk host Kevin Craine was joined by Michael Taylor, Data, Technology, & AI Leader, Siemens; Luke O’Brien, Principal Engineer (Cyber Defence), NATO; and Adam Gale, Field CTO for AI and Cyber Security, NetApp. 

Views on news 

The European Commission has awarded a 180 million euro ($212 ​million) tender for sovereign cloud services to four European ‌providers for a six-year period, as part of a push to reduce the bloc’s dependence on non-European technology. The providers were selected based on their alignment with the Commission’s Cloud Sovereignty Framework, for which they had ​to ensure that non-EU entities have limited control over the ​technologies they use or the services they provide, the Commission said.  

 

Protecting data from breaches and quantum attacks 

Control and security are closely intertwined aspects of a business. If the business loses control over its data, it’ll impair its sovereignty too. One of the most likely ways of how sovereignty can get damaged is through a cyber-attack. As the threat surface is growing rapidly thanks to AI, businesses must deploy AI-powered tools too to combat bad actors. However, to protect data, first you must classify it based on its criticality, as well as understand where it resides. Implementing and verifying data sovereignty is challenging, especially for a multi-membered international organisation such as NATO, where interoperability is key to efficient and impactful operation.  

 

To meet emerging demand, cloud providers are also addressing the issue of data sovereignty by launching separated services from their US-based operation. Less regulated businesses, however,  tend to opt for a hybrid system when it comes to data sovereignty, with their most critical data stored on their premises and the rest in the cloud. AI-powered user behaviour analytics tools with low false positive rates are instrumental in preventing cyber-attacks leveraging AI. AI tools also excel at detecting data being extracted from a data base. Once a breach has been detected, the company must get its SIEM partner to stop the user, close the firewall port and lock down the system affected. The back-up system must be scanned too to see whether criminals have installed something there or tried to cover their tracks by deleting logs. This is an important step in order to avoid restoring dirty data to the system from back-ups. DORA also calls for creating a document containing the steps of an incident response, an exercise which will also help fill the gaps that the business may currently have in its recovery plan.  

 

The next major challenge for the data security industry will be quantum computing. 70 per cent of companies say that they are not ready for quantum era cyber security threats yet. Quantum is also one among the nine emerging disruptive technologies defined by NATO. The alliance is already changing algorithms vulnerable to quantum attacks into quantum-ready ones. Criminals harvest-now-and-decrypt-it-later approach is also posing a huge future threat. If you have quantum-proof encryption, make sure you know where your keys are – who holds them, what nationality they are and whether they are part of the organisation? When assessing third-party providers for data sovereignty compliance, first establish your sovereignty point – the balance between what data must be stored on premises and which can go to the cloud, then look at one of the main frameworks to see what is missing – engineers, software updates, etc. You can also check whether a provider already has a strategy for data sovereignty in place.  

 

The panel’s advice 

  • The focus in cyber security has shifted now from prevention to response and recovery.  
  • Tailor your approach to sovereignty to suit your sector-specific or geographical needs. Start by mapping your critical data flow. 
  • Have a physical copy of your recovery plan to prepare for starting to recover from an attack off-line.  
  • Limit the scope of any potential attacks by decreasing its blast radius.  
  • Rather than investing in expensive hardware to get quantum ready, start with small things.  
  • To learn more about quantum readiness, read NIST guidelines.  
  • To learn more about Zero Trust, click here
Business Reporter

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543