19 views
1 hour ago

Beyond Compliance: Data Sovereignty

Cyber Sentintels Aug Cover Story

As geopolitical risks, AI adoption and cyber threats reshape enterprise priorities, data sovereignty has evolved beyond compliance. Industry experts explain why digital sovereignty, Zero Trust, AI governance and cyber resilience have become interconnected pillars of business resilience, digital trust and long-term competitive advantage.

In not-so-distant past, data sovereignty was discussed primarily within legal and privacy teams, largely regarded as a compliance issue.

Today, it has become a core boardroom priority, affecting cloud strategy, AI adoption, cyber resilience and business continuity.

Data is widely considered the most valuable corporate asset. As geopolitical tensions accelerate and governments tighten control over data governance, enterprises are rethinking how they manage, protect and govern their data.

Renton D’Souza, Managing Director, Gulf at Westcon-Comstor.
Renton D’Souza, Managing Director, Gulf at Westcon-Comstor.

The discussion has shifted beyond where data resides to who controls it, which laws govern it, and whether organisations can maintain operations if political, legal or technological circumstances suddenly change. “The conversation has moved well beyond legal and compliance teams. Boards and C-suite leaders want assurance that they understand where critical data resides and how quickly they can adapt to changing requirements,” says Renton D’Souza, Managing Director, Gulf at Westcon-Comstor.

Good governance creates confidence in the data itself.
Renton D’Souza
Managing Director Gulf
Westcon-Comstor.

There is unanimity among industry experts that this transformation is redefining enterprise technology strategies worldwide.

Data sovereignty has traditionally been associated with data residency, with organisations focusing on keeping information within national borders. However, as digital ecosystems have evolved, data residency alone is no longer sufficient. “Given today’s converging geopolitical, regulatory and operational risk factors, company leaders have quickly grasped that data sovereignty no longer equates to data residency; it is a more complex principle, encompassing legal authority over data, how it is accessed or shared, and whose jurisdiction it falls under,” says Patrick Smith, Field CTO EMEA at Everpure

Gerald Beuchelt, Chief Information Security Officer at Acronis, argues that enterprises must think beyond geography. Modern sovereignty encompasses encryption key ownership, administrative access, auditability and the ability to recover services quickly when legal or operational conditions change.

“Data residency is the easy 20% of sovereignty knowing which country your servers sit in. The harder 80% is control: who holds the encryption keys, who has standing administrative access, whether your audit trail survives a change of cloud provider, and whether backups live under the same jurisdiction rules as production data,” says Gerald Beuchelt.

The uncertainty surrounding international data transfer mechanisms illustrates the challenge. Legal frameworks that once enabled data to move across the Atlantic including Safe Harbor and Privacy Shield—have already been struck down. At the same time newer arrangements continue to face fresh challenge. Henceforth, organisations are not in a position to assume today’s compliance model can be invalidated tomorrow.

This instability is leading to more investment in hybrid cloud architectures, regional deployments and contingency planning that allow critical workloads to be relocated if regulatory conditions change.

Sovereignty today is fundamentally about understanding jurisdictional risk rather than simply choosing where data is hosted. This view has been shared by Will Davies – Deputy CISO and Head of Enterprise Security at Endava.

Organisations increasingly need visibility into which governments, providers or subcontractors may ultimately influence access to their information. “At Endava, we run a dedicated Geopolitical Task Force precisely because operating across multiple jurisdictions demands knowing which legal regimes apply, and whether a government, provider or subcontractor could affect your access,” says Will Davies.


From compliance to business resilience

Regulatory compliance continues to be a critical driver. At the same time organisations are increasingly recognising that effective governance delivers tangible business value beyond avoiding fines.

Will Davies, Deputy CISO and Head of Enterprise Security, Endava.
Will Davies, Deputy CISO and Head of Enterprise Security, Endava.

Effective governance accelerates procurement, enhances customer confidence and improves operational efficiency by providing organisations with a clear understanding of the data they hold, where it resides and how it can be used

As AI adoption accelerates, trusted data has become a strategic imperative. Poor governance compromises the quality and reliability of AI models, whereas well-managed information enables organisations to deploy artificial intelligence with greater confidence, accuracy and accountability.

Zero Trust doesn’t make you compliant on its own,
Will Davies
Deputy CISO and Head of Enterprise Security
Endava.

Renton D’Souza of Westcon-Comstor observes that businesses are beginning to treat data as a strategic asset rather than a regulatory burden. As organisations seek to monetise information, improve customer experiences and develop AI-driven services, confidence in data quality has become a competitive differentiator. “Good governance creates confidence in the data itself, which means organisations can use it more effectively across the business,” says Renton D’Souza. “That’s important because many organisations are looking to turn data into a competitive advantage.”

Increasingly, robust privacy practices are enabling organisations to enter new markets more quickly, simplify operations and build greater customer trust.


AI: Opportunity and responsibility

Artificial intelligence has rapidly become central to cybersecurity and governance strategies, offering significant improvements in automation, threat detection and compliance management.

Patrick Smith, Field CTO EMEA at Everpure.
Patrick Smith, Field CTO EMEA at Everpure.

There is not a shadow of doubt that AI is highly effective at analysing vast volumes of security telemetry, correlating events across multiple systems and identifying anomalies that human analysts might overlook.
By reducing alert fatigue and automating repetitive governance functions such as data classification and policy monitoring, AI allows security teams to concentrate on genuine threats.

Data sovereignty no longer equates to data residency.
Patrick Smith
Field CTO EMEA
Everpure.

However, AI cannot replace accountability.

Human oversight remains essential, particularly where decisions have legal, operational or security consequences. Organisations must understand which data feeds AI systems, maintain transparency around automated decisions and ensure outputs remain explainable and auditable.

As AI agents increasingly gain access to enterprise environments, governance must also extend beyond human identities to machine identities, requiring new approaches to access control and risk management.


Zero Trust

If AI represents the future of cybersecurity, Zero Trust provides the architecture that supports it.

This shift reflects the changing nature of cyberattacks. Instead of targeting perimeter defences, attackers are increasingly exploiting compromised identities, exposing the limitations of traditional security models.
Zero Trust addresses this reality through continuous verification, least-privilege access, segmentation and ongoing monitoring. Rather than assuming the network is secure, it verifies every user, device and workload before granting access. The objective is not simply preventing breaches but limiting the damage once attackers gain access.

Zero Trust provides organisations with stronger visibility into who accessed sensitive information, how access was granted and whether unusual behaviour occurred. These capabilities also support regulatory compliance, audit readiness and forensic investigations.

Yet all three organisations caution against treating Zero Trust as a technology purchase or compliance checklist. “Zero Trust doesn’t make you compliant on its own, and it’s not a checklist of tools. It’s a guiding principle for making better security decisions, consistently,” says Will Davies of Endava.


Cyber resilience extends beyond backup

According to the majority of experts cyber resilience has overtaken prevention as the primary objective. Organisations are veering round to the view that security controls will eventually fail. Since rapid recovery and business continuity are central objectives of cyber resilience, the real question is how quickly they can recover while maintaining business operations.

That recovery depends on much more than maintaining backup copies.

Gerald Beuchelt, Chief Information Security Officer at Acronis.
Gerald Beuchelt, Chief Information Security Officer at Acronis.

Immutable, air-gapped backups, tested recovery procedures, identity protection, supply chain resilience and coordinated incident response have all become essential components of modern resilience strategies.
Resilience not simply an IT responsibility. It should be viewed as a business capability involving executive leadership, legal teams, operational departments and technology functions.

Data residency is the easy 20% of sovereignty.
Gerald Beuchelt
Chief Information Security Officer
Acronis.

Organisations that regularly test continuity plans against realistic scenarios, including ransomware attacks, cloud outages and supplier failures, are significantly better positioned to minimise operational disruption.

“Test continuity plans against real scenarios such as ransomware, outages, supplier compromise and more, with not just security professionls, but also executives and legal in the room,” says Will Davies.


Sovereignty evolves into digital strategy

Today data sovereignty is a subset of the broader concept of digital sovereignty. Organisations are seeking greater control over cloud infrastructure, AI platforms, digital services and the technology ecosystems. They are not focusing solely on where information is stored.

This evolution reflects growing concerns around geopolitical uncertainty, supply chain dependencies and long-term operational resilience. These are widely recognised drivers, alongside regulatory changes and concerns over foreign jurisdiction.


A boardroom agenda for the AI era

What was once regarded as a regulatory conversation has evolved into a strategic leadership challenge.
Boards are increasingly asking whether their organisations have sufficient visibilities into where critical data resides, who controls it, how quickly essential services can be restored following a disruption and whether technology investments are resilient to sifting geopolitical conditions.

Enterprises can no longer approach data sovereignty, AI governance, Zero Trust and cyber resilience in isolation. Together, they have become core pillars of modern digital trust.

The role of technology leaders has evolved beyond compliance. They must demonstrate that their technology architecture is resilient enough to withstand legal uncertainty, cyber threats and geopolitical disruption, while continuing to drive innovation and business growth.

As the digital landscape becomes increasingly fragmented, sovereignty has evolved beyond a regulatory requirement to become a strategic driver of enterprise resilience and competitive advantage.

Leave a Reply

Don't Miss

(L-R) Adam Davison, Senior Director, Vendor Acquisition at Westcon-Comstor and Scott Musson, VP of Worldwide Channel at Sonar.

Westcon-Comstor and Sonar partner to secure AI code development

Westcon-Comstor has signed a multi-region distribution agreement with Sonar to bring AI
Craig Robertson, Head of Partners in EMEA LatAm at Everpure.

Everpure appoints Craig Robertson as Head of Partners for EMEA and LatAm

Everpure has appointed Craig Robertson as Head of Partners for EMEA and

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy