Digital sovereignty becomes a priority of cybersecurity strategies

Partager
Digital sovereignty becomes a priority of cybersecurity strategies
"Cybersecurity is increasingly about determining who and what an organization can trust" Adam Marrè, CISO at Arctic Wolf.

Geopolitical tensions are increasingly influencing the choice of cybersecurity providers. 3 out of 4 organizations in Europe have adapted their cyber strategy to the geopolitical context. And the origin of the suppliers and the place where the data is stored weighs more heavily on decisions.

The geopolitical context is increasingly influencing the way European organizations organize their cybersecurity and choose their protection solutions.

According to the "AI & Cybersecurity Trends Report 2026", carried out by Sapio Research on behalf of Arctic Wolf, no less than 70% of organizations in Europe, the Middle East and Africa say that geopolitical developments have had a direct impact on their cybersecurity strategy. The origin of suppliers also weighs more heavily on their decisions. Nearly half of organizations (49%) report actively assessing region and supplier risks.

More specifically, organizations examine the country where the provider is established, the location where the data is stored and the governments that may require access to it. The study thus shows that the evaluation of cybersecurity solutions is no longer based solely on their technical capabilities: geopolitical dependencies are now also involved in risk analysis. According to Arctic Wolf, geopolitics has gone from being a context factor to an issue for boards of directors.

 Priority to digital sovereignty

Digital sovereignty is now a growing place in cybersecurity strategies. Among the organizations surveyed in Europe, 48% make it a major priority of their IT and cybersecurity strategy. While 40% of respondents consider it important. The issue of digital sovereignty therefore plays an important role for nearly 9 out of 10 organizations.

The report also tells us that organizations in the EMEA region are increasingly attaching importance to the geographical origin of service providers. Thus, 83% of them trust a cybersecurity provider more when its Security Operations Center (SOC) is located in Europe.

Only a very small minority of organizations indicate that a European SOC is reducing its confidence.

"Cybersecurity is increasingly about determining who and what an organization can trust," says Adam Marrè, head of information systems security at Arctic Wolf.

Organizations re-evaluate their suppliers in the face of the CLOUD Act

The Artic Wolf report also teaches us that organizations are weighing the technological benefits and legal and geopolitical risks associated with the control of their data by foreign actors. This arbitration now has concrete consequences for their purchasing decisions. In addition to the 49% who actively assess the risks associated with regions and suppliers, 23% of European organizations say they have already changed suppliers or excluded certain regions due to geopolitical changes. Only 8% say that geopolitics has no influence on their choice of cybersecurity technologies.

Among the factors cited by organizations in the EMEA region is the American CLOUD Act. As a reminder, this law may, in certain circumstances, allow US authorities to access data under the control of American technology companies, even when this data is stored outside the United States.

The report also mentions a hearing of Microsoft France in the French Senate. The company was asked about its ability to ensure that the data of its French customers would never be transmitted at the request of the US authorities. According to the report, such events have prompted organizations to take a closer look at the countries and suppliers from which they buy their technologies.

"European organizations want to know whether a technology effectively protects their environment, but also where their data is, which jurisdiction their supplier reports and where security operations are actually carried out," says Adam Marrè at Artic Wolf.

The fact that 83% of them place more trust in a supplier with a SOC in Europe shows how concrete these considerations have become. It is precisely for this reason that, as soon as we arrived on the European market, we wanted to accompany our European customers from the region. This is what we have been doing for some time with our Frankfurt SOC. Digital sovereignty is not an abstract political concept: it is an integral part of cyber risk management. "

This development is not limited to Europe. In Asia-Pacific and Japan, 59% of organizations say they are looking more carefully at supplier risks due to the geopolitical context.

In addition, 20% have actually changed suppliers or ended their collaboration with certain service providers. Here, too, organizations are paying more attention to where solutions are developed, where data are stored and applicable jurisdictions.

CTA Image

SAVE THE DATE - October 15, 2026 Hi Site, Grimbergen (Brussels)

Enregistrez-vous! - Register Here !

Lire la suite