Security and sovereignty: A data imperative

Security-and-sovereignty:-Evolving-architectural-principles-for-a-data‑centric-future

ISJ hears exclusively from Eric Avery, Global Head of Data and Infrastructure at Sumo Logic about security, sovereignty and data.

The modern security and sovereignty challenge

Security and sovereignty are deeply intertwined. It is not enough to ask where solutions run.

The real challenge lies in where the data lives, how it is protected, how it remains localised to meet regulatory expectations and how privacy and integrity are maintained throughout its lifecycle.

As organisations operate across hybrid and multi‑cloud environments, maintaining both compliance and control has become a balancing act between operational agility and regulatory discipline.

Modern legislation underscores this dual focus on security and sovereignty.

The European Union’s General Data Protection Regulation (GDPR) started this process by defining strict requirements for how personal data is collected, processed and transferred.

GDPR then became a guide for other countries to adopt in their regulation.

The Network and Information Security 2 Directive (NIS2) expanded cybersecurity and incident reporting duties to a wider set of essential service providers.

The Digital Operational Resilience Act (DORA) introduced mandatory operational resilience standards for financial institutions and technology partners.

Together, these frameworks institutionalise what security professionals already know: Data protection, privacy and resilience are the foundation of digital sovereignty.

The expanding cost of secure sovereignty

IDC forecasts global spending on sovereignty‑related services and technology will exceed $400 billion by 2030, reflecting the scale of investment required to secure and govern critical data responsibly.

Yet this cost does not need to jeopardise innovation.

The key is designing secure, well‑architected solutions that build sovereignty principles into infrastructure, governance and data management from the start.

When security and sovereignty are treated as design objectives – rather than afterthoughts – organisations can meet regulatory expectations while controlling cost and complexity.

For example, well‑designed systems integrate encryption, localisation and compliance automation to ensure that data remains both protected and accessible to those that need to use it, as well as operating this infrastructure in a cost‑efficient way.

Requirements for secure sovereignty

To operate in a compliant and resilient manner, teams must consider:

  • Where Data Infrastructure runs: Assess workload placement and cloud provider regions to ensure computing stays within approved jurisdictions without compromising performance
  • What Data is stored: Identify sensitive or regulated data and apply localisation, segmentation and encryption tailored to jurisdictional needs
  • How Data Is processed: Apply encryption and identity frameworks aligned with GDPR and NIS2, ensuring that only authorised entities process or access data
  • How Privacy Is maintained: Embed privacy‑by‑design principles so that protection persists regardless of where infrastructure resides

This approach reframes sovereignty based on active governance of data lifecycles, not just looking at residency compliance.

Sovereignty is something that you support over time, not that you think about once.

Current state – How companies operate today

Most organisations now blend public, private and sovereign cloud infrastructures to balance control with scale.

Cloud services bring flexibility but also multilayered sovereignty challenges when data crosses borders or falls under different compliance regimes.

Many technology providers now offer “sovereign cloud” options that preserve customer control over data residency, encryption keys and administrative oversight.

This approach helps enterprises meet both security and compliance needs.

Still, the responsibility lies with the organisation. True data sovereignty demands that businesses maintain awareness of where their data sits, how it moves and who can access it.

Cloud partnerships should therefore be evaluated not only on performance and cost but also on sovereignty readiness.

This is the ability to guarantee locality, privacy and security end‑to‑end when you are asked for that information.

That ask can come at any time.

Planning for sovereign deployments

Decisions around sovereign deployment will influence long‑term architecture and risk strategy.

Organisations must weigh resilience and compliance against interoperability when choosing how and where to host workloads.

A sovereign architecture must not only meet today’s regulatory expectations but also remain adaptable to future changes in data privacy and security regulation.

Security and risk leaders sit at the intersection of compliance and innovation. Their task is to ensure that sovereignty strategies enhance – not hinder – business growth.

Key steps include:

  • Mapping data flows and aligning localisation with risk appetite
  • Automating policy enforcement for encryption, access and logging
  • Integrating sovereignty considerations into supply‑chain and vendor risk management programs
  • Embedding cost‑efficiency into compliance design through intelligent architecture and automation

Security and sovereignty are two sides of the same coin, reinforcing each other in protecting data, trust and resilience.

These are evolutions of established architectural best practices tailored to modern regulatory expectations.

By focusing beyond infrastructure to the data itself – its location, protection, locality and privacy – organisations can build the secure, compliant and cost‑effective foundations necessary for the next era of trusted digital operations.

1-ISJ- Security and sovereignty: A data imperative

Eric Avery is Global Head of Data and Infrastructure at Sumo Logic, where he leads the company’s IT infrastructure, cloud operations, data engineering and analytics departments. Prior to joining Sumo Logic, he led IT and cloud operations teams at Delphix and Infor and he is currently an Advisor to AWS through the company’s Marketplace operations based on managing one of AWS’s largest customer operations.

Share this content

Latest Issue

Connect with us

Free digital subscription

Receive the latest breaking news straight to your inbox