The debate around digital sovereignty is heating up again. This time, not just around hyperscalers such as Microsoft, Google, and Amazon Web Services, but smaller software vendors, open-source platforms, and European alternatives too.
And honestly, that’s healthy.
After years of “cloud first,” the market is finally asking mature questions:
- Who actually develops our software?
- Which laws apply to our vendors?
- Who controls the source code, signing keys, and updates?
- How dependent do we want to become on one ecosystem?
- What does “European” even mean in a global software supply chain?
But somewhere in that discussion, we also risk going too far.
Open Source Isn’t a Magic Security Blanket
A persistent misconception is that open source is automatically safer than commercial software.
It sounds logical: “The source code is visible, so problems will naturally be discovered.”
The reality is less romantic.
Modern software consists of:
- millions of lines of code,
- hundreds of dependencies,
- CI/CD pipelines,
- package repositories,
- container images,
- external libraries,
- automatic update mechanisms.
Nobody reviews all of that manually. Almost nobody could.
The XZ Utils backdoor painfully demonstrated how even a widely trusted open-source project could be gradually infiltrated through human relationships of trust.
That wasn’t a Hollywood hack. It was a supply-chain attack against mature Linux environments.
So no: “open source” alone isn’t a security strategy.
But Neither Is Blind Trust
On the other hand, a reflex sometimes emerges in which every non-European vendor suddenly becomes a strategic risk.
That’s too simplistic as well.
If we’re consistent, almost every major technology platform falls under some form of foreign legislation from one part of the world or another:
- The U.S. CLOUD Act
- Chinese cybersecurity legislation
- Russian state influence
- European data-retention and oversight frameworks
Perfect digital independence practically no longer exists.
The real question isn’t:
“Which flag flies over the headquarters?”
But:
“How do we manage risk in a mature way?”
Risk Is About Context
Not every workload has the same risk profile.
A marketing website is different from:
- a hospital information system,
- an insurance platform,
- a government environment,
- an energy company,
- a financial institution.
That’s why black-and-white thinking works poorly in cybersecurity.
A mature approach considers:
- data classification,
- legal exposure,
- operational dependence,
- security maturity,
- auditability,
- incident response,
- encryption,
- identity governance,
- logging and monitoring,
- exit strategies,
- supplier governance.
That’s exactly what frameworks such as DORA, NIS2, and ISO 27001 increasingly emphasize.
The Irony of the Discussion
The irony is that many organizations worry about geopolitical origins while they haven’t even put the basics in place.
They debate “digital sovereignty” while:
- MFA still isn’t enabled everywhere—or is deliberately disabled for executives because it’s such a hassle,
- supplier management is incomplete,
- shadow IT is growing,
- patch management is falling behind despite piles of tools,
- logging is missing,
- privileged access is barely controlled or enabled by default.
Sometimes that discussion feels like arguing about barricading the front door while the back door stands wide open.
What About Microsoft?
That inevitably brings us to Microsoft.
Is Microsoft perfect? No.
But it is demonstrably one of the most scrutinized, audited, and regulated technology companies in the world.
Microsoft invests billions in:
- compliance,
- European data-boundary solutions,
- transparency reporting,
- security engineering,
- privacy controls,
- sovereign cloud initiatives,
- audit frameworks,
- regulatory alignment.
That doesn’t mean organizations should become uncritically dependent on one vendor.
But it also means “American” doesn’t automatically mean “unsafe.”
Especially when many European organizations aren’t internally mature enough to operate alternatives securely and manageably.
Digital Sovereignty Is Ultimately About Control
Not emotion. Not geopolitical slogans. Not vendor-bashing.
It’s about control. Control over:
- data,
- identity,
- access,
- dependencies,
- continuity,
- exit options,
- governance,
- operational risk.
Perhaps that’s the mature conversation we should be having.
Not:
“Which vendor do we trust blindly?”
But:
“Which risks do we consciously accept, which do we mitigate, and where is the right balance for our organization?”
Originally published on LinkedIn. View all blog posts.