Discussions around digital sovereignty have largely focused on cloud infrastructure. However, since many cyber security tools are now delivered as cloud services, an equally important question is what are the potential risks of relying on a non-sovereign security operations platform?
As organizations adopt AI-driven Security Operations (SecOps), Extended Detection and Response (XDR), Security Information and Event Management (SIEM), and Cloud-Native Application Protection Platforms (CNAPP), they are becoming dependent on security control planes that aggregate telemetry, automate response actions, and increasingly make autonomous security decisions. These platforms are the operational nerve center for cybersecurity.
The question is most acute in Europe, where customers face a complex regulatory environment and where the leading SecOps platforms are supplied by vendors headquartered outside the EU.
This raises a new challenge: SecOps Sovereignty.
From Cloud Sovereignty to SecOps Sovereignty
In previous blogs on cloud sovereignty, I identified four categories of sovereignty risk: data, technology, operational, and infrastructure. For SecOps the same lens applies, but data concerns are best framed as a legal-jurisdiction question and technology dependencies as a supply-chain question, giving four somewhat different categories:

In some respects, the risks are amplified because security platforms hold privileged visibility and control across the entire enterprise.
Unlike regular cloud workloads, SecOps platforms collect and analyze:
- Security events
- Network telemetry
- Identity data
- Vulnerability information
- Incident records
- Threat intelligence
In many cases, they can also take direct actions such as isolating endpoints, blocking users, modifying firewall rules, or shutting down workloads.
The sovereignty risks related to these systems can therefore not only affect data confidentiality but also threaten operational resilience.
Legal Risk
Risk: Unauthorized but legal access to SecOps related data.
Most leading SecOps platforms are operated by US-headquartered vendors, placing European customers' security telemetry within the reach of US legal process. This creates familiar concerns regarding extraterritorial legislation and foreign government access requests. Security telemetry often contains sensitive information about organizational structures, network architectures, privileged users, and critical assets.
For regulated sectors such as healthcare, financial services, defense, and critical infrastructure, exposure of this data may present a greater risk than exposure of ordinary business data.
The issue extends beyond data residency. Even if security data remains physically within Europe, questions remain regarding who can access it, under what legal authority, and whether foreign governments can compel disclosure through legislation that applies to the vendor.
Operational Risk
Risk: Loss of access to SecOps capabilities and data during periods of geopolitical tension.
Modern SecOps platforms now typically operate as centralized SaaS control planes.
Security teams rely on them to investigate incidents, orchestrate responses, and manage automated detection capabilities. If access to these platforms is disrupted by sanctions, export controls, geopolitical disputes, or vendor decisions, security operations may be significantly impaired.
As geopolitical tensions increase, organizations are evaluating whether critical digital services remain available during periods of international conflict or regulatory confrontation.
Organizations must therefore ask:
- Can we continue to detect threats if the service becomes unavailable?
- Can we access historical security telemetry?
- Can we export rules, playbooks, and threat intelligence?
- Can we operate independently during a geopolitical crisis?
These questions are familiar from cloud sovereignty debates, but acquire new urgency when the system being disrupted is the one detecting attacks.
Infrastructure Risk
Risk: Loss of access to SecOps capabilities and data.
Security operations platforms depend on cloud infrastructure, data processing facilities, networking services, and AI infrastructure.
Even where a security vendor offers regional hosting, dependencies may still exist on foreign-owned infrastructure, global management planes, or externally controlled AI services.
The sovereignty question therefore extends beyond where logs are stored to encompass the entire operational stack that processes, correlates, and analyzes security data.
Supply Chain Risk
Risk: Loss of Trust in the SecOps data and capabilities.
SecOps platforms incorporate multiple layers of third-party dependencies:
- Threat intelligence providers
- AI and machine learning services
- Cloud infrastructure providers
- Open-source components
- Managed detection services
This creates complex supply chain dependencies that may not be visible to customers.
A sovereign SecOps strategy therefore requires transparency regarding who operates critical services, who controls updates, where AI models are hosted, and how dependencies are governed.
As with cloud sovereignty, supplier diversity and architectural openness become important mitigations.
The CNAPP Challenge
CNAPP are becoming the control plane for the AI-native business but are mostly US-owned. This creates a particularly interesting sovereignty challenge.
By design, CNAPP solutions aggregate data across cloud environments, identities, workloads, Kubernetes clusters, application pipelines, and security controls. They have become the single source of truth for cloud security posture and risk management.
This concentration of visibility creates significant value but also increases sovereignty concerns.
Organizations evaluating CNAPP solutions should therefore consider:
- Where security telemetry is processed
- Who controls the management plane
- Whether customer-controlled encryption is available
- How data portability is supported
- What happens during a geopolitical disruption
- Whether AI-driven analysis can operate within sovereign boundaries
As CNAPP platforms become increasingly AI-enabled, sovereignty considerations will extend to model training, inference locations, and control over security-related AI systems.
Palo Alto Networks and Deutsche Telekom: A New Direction
In June 2026, Palo Alto Networks and Deutsche Telekom announced Sovereign Cortex with T Security, a service that brings Palo Alto Networks' AI-driven Cortex SecOps platform to European regulated industries with sovereignty controls independently governed by Deutsche Telekom.
The significance of this announcement is not simply that data remains within Europe. Rather, it reflects a broader recognition that security operations platforms have themselves become sovereignty-sensitive infrastructure.
The announced offering combines Palo Alto Networks' security analytics and AI capabilities with Deutsche Telekom acting as a European trust anchor, providing governance and operational controls aligned with European sovereignty requirements. The initial target for this includes organizations in healthcare, financial services, the public sector, and critical national infrastructure.
Whether such approaches fully mitigate sovereignty concerns remains open to debate. Sovereign Cortex is itself hosted on Deutsche Telekom's Sovereign Google Cloud Platform, with Telekom Security holding the encryption keys in its own data centers: this layered architecture illustrates how difficult it is to separate European SecOps fully from US-controlled infrastructure. However, the announcement signals that the market is beginning to recognize SecOps sovereignty as an important distinct requirement.
Final Thoughts
The next phase of digital sovereignty will not be defined solely by cloud infrastructure.
As organizations increasingly rely on AI-driven security operations, sovereignty concerns must extend to platforms that monitor, analyze, and protect their digital environments. Security operations systems are becoming critical national and organizational infrastructure.
The key question is no longer: "Where is my data?"
Instead, organizations must ask:
"Who controls my security operations, who can access them, and will they continue to function when geopolitical conditions deteriorate?"
SecOps sovereignty is about ensuring that organizations retain control of their security posture, incident response capabilities, and cyber resilience regardless of legal, political, or geopolitical disruption.
As sovereignty debates move beyond cloud infrastructure and into cybersecurity operations, SecOps and CNAPP platforms will the EU Cloud Sovereignty Framework be enough.
Join a KuppingerCole Impact Day to get practical insights on identity, security, and digital transformation.