Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - GRC - Sovereignty vs Convenience
GRC Articles Business and Policy Security

Sovereignty vs Convenience

Nick CaseBy Nick CaseSeptember 23, 20265 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Sovereignty vs Convenience
Share
Facebook Twitter LinkedIn Email Copy Link
TL;DR (AI Generated)

While 99% of enterprise decision-makers across EMEA believe data sovereignty is important, almost three-quarters admit it is being pushed aside in favour of rolling out AI more quickly.

It is about recognising that organisations handling sensitive information may benefit from working with suppliers operating under the same legal framework, the same regulatory environment and the same expectations around governance.

These questions become even more important as AI systems consume increasing volumes of business data and organisations seek to demonstrate greater accountability for how that information is used.

Basic summary
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Technology decisions have traditionally been driven by functionality, price, and ease of use. If a solution met the business need and integrated with existing systems, it was usually considered the right choice. Who owns the service provider and which legal jurisdiction governs rights to the service rarely features in procurement discussions.

That is beginning to change.

Questions around digital sovereignty are moving out of the IT department and into the boardroom. Organisations are asking not just where their data is stored, but who ultimately has access to it, which laws apply to it and whether they have sufficient control over one of their most valuable business assets.

This isn’t about fearmongering or suggesting organisations should abandon cloud technology. It’s about recognising that convenience and control are not always the same thing.

Recent research commissioned by Veeam highlights just how conflicted organisations have become. While 99% of enterprise decision-makers across EMEA believe data sovereignty is important, almost three-quarters admit it is being pushed aside in favour of rolling out AI more quickly. The report also found that UK organisations are particularly aware of the risks, with almost half identifying AI data as their biggest visibility gap.

Those findings tell an interesting story.

Business leaders understand that data matters. They understand that governance matters. Yet when commercial pressures, innovation and speed enter the equation, sovereignty is often viewed as something that can be addressed later.

The problem is that later tends to arrive much sooner than expected.

As organisations embrace AI, expand supply chains and collaborate with more external partners, they are generating and sharing more information than ever before. Every one of those interactions raises a simple question: Do you know where your data is actually going?

Many organisations assume that because they are headquartered in the UK, their information remains there as well. In reality, that is not always the case. Data may be processed, routed or accessed through multiple jurisdictions before it reaches its destination. For most users, this happens invisibly, but that does not mean it is irrelevant.

Jurisdiction matters because different countries operate under different legal frameworks. Organisations can spend considerable time ensuring they comply with UK legislation, only to discover that the technology they rely on is subject to overseas laws and obligations beyond their control.

For businesses operating in regulated sectors, that should not be viewed as a technical issue. It is a governance issue.

Boards spend significant time discussing operational resilience, supply chain risk and business continuity. Digital sovereignty belongs in the same conversation because it ultimately comes down to trust. Can you confidently explain where sensitive information resides, who could potentially access it and which legal framework applies if questions are ever asked?

Increasingly, customers are asking those same questions of their suppliers.

This is particularly relevant as organisations review their technology supply chains. The conversation is no longer simply about whether a service is secure. It is also about who owns it, who supports it and where accountability sits.

That is why British organisations should not be afraid to ask whether British-built security offers advantages beyond compliance.

Choosing a UK-owned provider is not about turning away from international innovation. Nor is it about suggesting overseas technology cannot be trusted. It is about recognising that organisations handling sensitive information may benefit from working with suppliers operating under the same legal framework, the same regulatory environment and the same expectations around governance.

Digital sovereignty should be viewed as both a commercial and ethical principle.

Commercially, organisations gain greater confidence over how sensitive information is handled and where responsibility sits. Ethically, they are demonstrating to customers, partners and stakeholders that they have carefully considered how information is managed throughout its lifecycle, rather than simply accepting the default settings of a global platform.

Convenience has undoubtedly driven much of the digital transformation we’ve seen over the last decade. Cloud platforms have enabled organisations to scale quickly, collaborate more effectively and embrace flexible ways of working. None of that should be dismissed.

However, convenience should not replace informed decision-making.

Asking where data is stored is no longer enough. Organisations should also understand where it travels, which countries it passes through and which legal frameworks may apply along the way. These questions become even more important as AI systems consume increasing volumes of business data and organisations seek to demonstrate greater accountability for how that information is used.

Digital sovereignty is unlikely to become the deciding factor in every technology purchase. Nor should it. Functionality, security, value and usability will always remain important considerations.

But sovereignty deserves a place alongside them.

Digital sovereignty isn’t about creating unnecessary barriers or avoiding global technology providers. It’s about making informed decisions. Businesses should know where their data is, who could potentially access it and what that means for their organisation. Those conversations are becoming an increasingly important part of good governance.

Nick Case
Nick Case
Nick Case is a lapsed astrophysicist who found his way into IT security in 2002, when he founded penetration testing company Securability. His career in technology spans more than 35 years, from writing 6502 assembly and selling Unix systems to building hardware and developing security solutions. In 2013, Nick helped found DOQEX, which initially started life as an ISO 27001 consultancy. It quickly evolved into developing its own technology, becoming the security software vendor and service provider it is today.

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    Mastering Information Security Governance Frameworks

    March 28, 202412 Mins Read

    Navigate Cloud Computing Risk Management Successfully

    March 17, 202412 Mins Read

    Simplifying Cloud Computing Compliance: Key Strategies

    March 17, 202412 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}