Data was supposed to be free of borders. Today, a growing number of organizations are asking different questions: whose jurisdiction their data falls under, who can switch off their access, and what the bill will look like the day they decide to move it elsewhere.
Table of Contents
Armed conflicts, trade wars, sanctions and an intensifying technology race now shape how organizations approach cybersecurity and data protection. According to the World Economic Forum’s Global Cybersecurity Outlook 2026, 66% of organizations have modified their cybersecurity strategy because of geopolitical instability, and 64% explicitly account for geopolitically motivated attacks in their risk mitigation plans.
The tone has changed since the first shock. In the 2023 edition of the same report, 93% of cyber leaders expected geopolitical instability to trigger a far-reaching, catastrophic cyber event within two years. Three years later, the conversation has moved from alarm to adaptation. Geopolitical risk is no longer treated as a one-off disruption but as a structural element of the threat landscape. Organizations have not stopped worrying. They have started planning.
When the threat is physical: the AWS Middle East precedent
Cyberattacks have been a permanent feature of the war in Ukraine since day one. What happened in the Gulf in 2026 was new. In early March, during the military escalation between the United States, Israel and Iran, Iranian drones struck AWS facilities in the UAE and Bahrain. Two facilities in the UAE were hit directly; in Bahrain, a strike nearby caused structural damage, power disruption and water damage from fire suppression systems. In April, a second availability zone in Bahrain went down, taking the entire region offline.
The most important part of the story came six months later. In September 2026, AWS stated that it is unable to restore access to resources and data hosted exclusively in the affected UAE availability zone (mec1-az2) and in the Bahrain region (me-south-1). The customers who came through it intact were, for the most part, those who had copies of their data outside the affected region.
Spreading workloads across availability zones protects you against a fire in a building. It does not protect you against a war in a country.
For architects, the lesson is concrete: geographic and jurisdictional separation of recovery copies is a design requirement, not a premium option. The 3-2-1 rule gains a new dimension: at least one copy should sit beyond the blast radius of a regional conflict, and ideally under a different legal regime.
Jurisdiction is now a technical parameter
Physical risk is only one side of the equation. The other is legal. The relationship between the European Union and the United States has become more transactional, with tariffs and export controls increasingly used as policy tools. As a result, a growing share of European buyers now evaluate non-EU cloud providers not only as technology partners, but as a potential exposure point for their technological sovereignty.
The most frequently cited instrument is the US CLOUD Act. It allows US law enforcement to require US-based providers to hand over data in their possession, custody or control, regardless of where that data is physically stored. In practice, data of a European customer kept on a server in Warsaw or Frankfurt remains within reach of US jurisdiction if the provider is a US company. This is no longer a theoretical debate: in June 2025, the General Counsel of Microsoft France told a French Senate inquiry under oath that he could not guarantee customer data would never be transferred to US authorities without French consent.
Less discussed, but equally relevant, is Section 702 of FISA, which permits US intelligence agencies to collect communications of non-US persons located outside the United States without an individual court order.
A third risk is the most operational one: a provider can be compelled to stop serving a customer. In 2025, after the US imposed sanctions on the International Criminal Court in The Hague, media reported that ICC Chief Prosecutor Karim Khan had lost access to his Microsoft-hosted email and moved to Swiss provider Proton. Microsoft denied that it had suspended services to the Court itself. Regardless of the exact sequence of events, the outcome was unambiguous: in October 2025, the ICC announced it would replace Microsoft Office with openDesk, a sovereign suite developed by Germany’s Centre for Digital Sovereignty (ZenDiS).
The commercial dimension: lock-in priced in
Not every sovereignty risk comes from governments. Some come from the vendor’s pricing department. Broadcom’s licensing overhaul after the VMware acquisition remains the textbook example. A CloudBolt survey of 302 IT decision-makers published in February 2026 found that 89% see rising VMware prices as a major source of disruption, 86% are actively reducing their VMware footprint, and 85% remain concerned about future pricing. Individual customers have reported increases far above the average.
Hyperscalers use a subtler mechanism: egress fees. Moving data into the cloud is typically free, but every gigabyte that leaves it is billed. At AWS’s standard internet data transfer rate of $0.09/GB, moving 10 TB out of the platform costs roughly $912.60. For comparison, a physical 10 TB drive costs around $200. At petabyte scale, egress becomes a de facto exit barrier.
Regulation is starting to close that gap. Under the EU Data Act, cloud providers operating in the EU will no longer be allowed to charge switching or egress fees for customers changing providers from 12 January 2027. The rule covers IaaS, PaaS and SaaS. It removes a cost barrier, but not the technical one: portability still depends on whether your recovery data is stored in open, platform-independent formats you control.
Europe moves from rhetoric to procurement
The starting position is challenging. According to Synergy Research Group, European providers hold only about 15% of their home cloud market, down from 29% in 2017, while Amazon, Microsoft and Google together control around 70%. Spending patterns are shifting fast, though. Gartner forecasts that sovereign cloud IaaS spending in Europe will grow by 83% in 2026, to about $12.6 billion, and nearly double again to $23.1 billion in 2027.
| Indicator | Value | Source |
| European providers’ share of the European cloud market | ~15% (29% in 2017) | Synergy Research, 2025 |
| Share held by AWS, Microsoft and Google combined | ~70% | Synergy Research, 2025 |
| Sovereign cloud IaaS spending in Europe, 2026 | $12.6B (+83% YoY) | Gartner, Feb 2026 |
| Sovereign cloud IaaS spending in Europe, 2027 (forecast) | $23.1B | Gartner, Feb 2026 |
| Organizations that changed cyber strategy due to geopolitics | 66% | WEF GCO 2026 |
The public sector is leading the way. Denmark’s Ministry of Digitalisation has begun moving from Microsoft Office to LibreOffice, and the country’s two largest municipalities, Copenhagen and Aarhus, are phasing out Microsoft systems. The German state of Schleswig-Holstein is migrating tens of thousands of public servants to open-source tools, with a full move from Windows to Linux planned. The goal is the same in every case: meet national data protection requirements and reduce exposure to extraterritorial control.
Estonia went further, and earlier. In 2017, it signed an agreement with Luxembourg to establish the world’s first data embassy: a government-controlled data centre abroad, holding copies of critical state registries and systems. Like a diplomatic mission, it enjoys immunity and inviolability. The host country cannot physically seize, inspect or block the Estonian data stored there. It is, in essence, a sovereign off-site recovery copy for an entire state, and other countries may well follow the model.
At EU level, the European Commission proposed the Cloud and AI Development Act (CADA) on 3 June 2026. Its cloud sovereignty framework introduces four “Union assurance levels” for providers serving the public sector, ranging from a baseline to the strictest tier, which requires no third-country control and control over software components. Public tenders would also have to consider “Union added value” as a non-price criterion. The proposal is still in negotiation, but the direction is clear: sovereignty is becoming a procurement requirement, not a marketing claim.
Five questions to ask any “sovereign” data protection vendor
European vendors have their moment, and the market has responded with a wave of offerings labelled “sovereign” and “European”. Many of them sound remarkably similar. A label is not an architecture. Before signing, ask:
- Jurisdiction: Which legal entity controls the software, the support channel and any cloud components, and which laws can compel that entity to disclose data or suspend service?
- Connectivity: Does the product require periodic license validation or a permanent connection to the vendor’s infrastructure to keep working?
- Platform dependency: Can you recover workloads to open platforms such as OpenStack, or are you tied to a single hypervisor or cloud vendor?
- Isolation: Are immutable and air-gapped copies part of the product, or an add-on you need to build yourself?
- Exit: In what format are recovery copies stored, and what will it cost, in time and money, to move them?
Ready to protect your data?
How Storware approaches sovereignty
Storware is a European vendor, headquartered in Poland. We do not see technological sovereignty as a “made in Europe” sticker, but as a set of architectural and commercial choices.
Open platforms first: OpenStack
OpenStack is one of the foundations of European sovereign cloud. Storware Backup and Recovery integrates natively with the OpenStack dashboard through a Horizon plugin, with Skyline integration options also available. Tenants can manage protection policies, schedules and restores without leaving their cloud console. This lets managed service providers build Backup-as-a-Service and DRaaS offerings on open infrastructure, without dependence on proprietary virtualization platforms.
Hardware under our control
Beyond software, Storware delivers its own backup appliances, assembled, tested and configured in-house, without third-party integrators. For European customers, deployment takes a single day. Outside Europe, local partners install the hardware and connect it remotely to Storware, so we retain full control over the software being deployed.
Isolation and immutability by design
Storware Backup and Recovery supports immutable backup protection and air-gapped data protection, including isoLayer, our own isolation mechanism built on an XFS-based storage layer. Recovery copies stay out of reach of ransomware and of compromised administrator credentials, which keeps business continuity under your control.
Perpetual licensing: independence that is contractual, not just technical
Storware does not follow the industry-wide shift to subscription-only models and still offers perpetual licenses. For some customers it is simply the better economic choice. For others, especially in defence, it is a matter of independence: no recurring license validation, and no requirement for the system to call home to the vendor. In environments where such connections are prohibited, this is often a qualifying criterion.
Storware Cloud with a fully European option
Storware Cloud is delivered with three partners: Canada-based N-able, Portugal-based Vawlt, and Seagate (Lyve Cloud). Customers who require a 100% European supply chain are served by a configuration that excludes N-able, even though N-able’s infrastructure physically runs in European Equinix data centres. Vawlt, founded in 2018, distributes data across multiple clouds at once, keeping it available even if one provider fails. Customers choose the clouds they use and can restrict storage to providers with EU regions, from EU regions of global hyperscalers to European providers such as OVHcloud, IONOS or Scaleway.
Channel first, local by default
Storware is moving from direct sales to a channel-first strategy, partly because sovereign projects require local-language support. One example is a ready-made Romanian user interface, developed after Storware and Red Hat jointly won the tender for Romania’s EU-funded government cloud.
Conclusion: sovereignty as risk management
Geopolitics has ended the idea that data is an asset detached from borders and politics. Organizations now assess not only the security of a technology, but also the jurisdiction of its vendor, the physical location of their data, sanctions exposure and the risk of losing access to a service. The AWS Middle East outage, the CLOUD Act debate and the Data Act deadline all point to the same conclusion: digital sovereignty is no longer a political slogan. It is a component of risk management and business continuity planning.
This opens a real opportunity for European vendors, provided they can prove maturity. Storware has been building data protection technology for more than a decade. Today, its codebase also powers solutions offered by global technology leaders, including Dell, IBM and OpenText. That is the kind of proof sovereignty needs: European engineering, trusted at global scale, and kept under European control.
Planning a sovereign recovery strategy for OpenStack or a multi-hypervisor environment? Talk to a Storware expert or explore Storware Backup and Recovery documentation.

