Digital sovereignty is determined during the recovery process

October 7, 2026

Backup, recovery and digital sovereignty are often still regarded as separate disciplines within organisations. In an emergency, however, it becomes clear just how closely they are linked. Any organisation that, following a cyber-attack, is unable to determine for itself where data is stored, who is authorised to access it and how critical systems are to be restored, has only limited digital sovereignty.

Cyber resilience is not determined solely by whether backups are in place. Rather, the decisive factor is whether a company can regain control of its systems following an attack and bring them back online within the required legal and operational frameworks.

Mark Molyneux, Field CTO at Commvault, highlights this in a recent commentary on ITWelt.at. He succinctly sums up his central argument: “Sovereignty without resilience is incomplete and leaves gaps.”

This connection becomes particularly apparent in the case of ransomware attacks. A technically available backup alone is not sufficient if recovery points lie outside the prescribed legal jurisdictions, access rights are not clearly regulated, or if recovery requires service providers that do not meet the relevant sovereignty requirements. Companies must therefore clarify, even before an incident occurs, where their data is backed up, who is authorised to restore it, and in what order business-critical systems must be brought back online.

Not every workload requires the same level of sovereignty

At the same time, Molyneux argues against the approach of aiming for the highest possible level of technological independence across the board for all applications. Depending on the criticality, regulatory requirements and risk profile of a workload, a different level of control may be required. A customer database places different demands on availability, data locality and recovery than, for example, an internal collaboration platform.

This risk-based approach is also gaining significance from a regulatory perspective. Since 11 September 2026, the European Cyber Resilience Act (CRA) has already imposed reporting obligations for actively exploited vulnerabilities and serious security incidents involving products with digital elements. Among other things, manufacturers must issue an early warning within 24 hours. The remaining key obligations under the CRA will come into force from December 2027.

For businesses, this entails a more comprehensive challenge: digital sovereignty must not be reduced to the question of which data centre data is stored in. It also encompasses access rights, encryption, dependencies on service providers and, above all, the ability to regain operational capability under one’s own control following a security incident.

Sovereignty is therefore not demonstrated during normal operations, but particularly in a crisis. Anyone who plans backup, recovery, governance and data sovereignty separately risks, in an emergency, creating dependencies precisely where rapid and controlled decisions would be necessary.

Related Articles

Share This