Europe Does Not Need to Produce Everything to Be Sovereign

"Prevention is cheaper than a breach"

Back to Blog

Europe Does Not Need to Produce Everything to Be Sovereign

Cyber Security, Resilience and Technological Sovereignty at a Time When Dependence Is Becoming a Strategic Vulnerability

The European debate on technological sovereignty often begins with the wrong question. It asks whether Europe can produce enough chips itself, develop its own cloud infrastructure, build competitive artificial intelligence models, secure sufficient computing capacity and reduce its reliance on technology companies outside the European Union. These are all legitimate questions, but none of them, on its own, determines whether a technological system is genuinely sovereign. Sovereignty in the modern digital economy cannot mean complete self-sufficiency, because virtually no state, company or region now operates outside global technology chains. A much more precise question is therefore: how much dependence can a system tolerate while still retaining the ability to make decisions independently, continue to function and change direction when circumstances change?

That question leads directly to the distinction between cyber security, cyber resilience and technological sovereignty. These concepts are connected, but they are neither synonyms nor stages in a simple linear progression in which one begins where the previous one ends. Modern cyber security already encompasses continuity, incident management, supply-chain protection, the human dimension of security, recovery and risk management. Among its core cyber risk-management measures, NIS2 explicitly lists incident handling, business continuity, backup and disaster recovery, crisis management, supply-chain security, human resources security and the assessment of the effectiveness of the measures applied.

Yet there is an important difference between protecting a system and enabling it to preserve its purpose. Cyber security seeks to reduce the likelihood and consequences of compromise. Cyber resilience goes a layer deeper and asks what happens to an organisational or societal function when an adverse event nevertheless occurs. NIST therefore defines cyber resiliency not merely as the ability of a system to recover after an attack, but as its ability to anticipate, withstand, recover from and adapt to adverse conditions and attacks. The European framework for the resilience of critical entities follows an even broader logic: resilience includes the ability to prevent, protect against, respond to, resist, mitigate, absorb, adapt to and recover from an incident.

This represents a significant shift in thinking. A system is no longer mature simply because it is difficult to compromise. It is mature when the compromise of one of its parts does not automatically cause the loss of its core function. Cyber resilience therefore cannot be reduced to disaster recovery or to the question of how quickly a server or application can be returned to production. It begins much earlier, with anticipation and preparedness; continues through the capacity to tolerate disruption and preserve continuity; and ends only when the system has not merely recovered, but also changed on the basis of what it has learnt.

In this sense, we might speak of five connected capabilities: anticipation, incident tolerance, continuity, recovery and adaptation. Yet there is another element that does not belong to only one phase, but runs through all of them: dependency management.

It is precisely here that the connection between resilience and technological sovereignty begins.

Resilience is not enough if it is borrowed
Resilience is not enough if it is borrowed

Resilience is not enough if it is borrowed

An organisation may have a highly mature cyber security capability. It may have a sophisticated SOC, effective detection capabilities, segmentation, backups, redundant systems, automated response procedures and thoroughly tested recovery plans. At the same time, its identity systems may depend on a single provider, its key business systems on a single cloud ecosystem, its analytics on several SaaS platforms, and an increasing number of its functions on external AI models, APIs and computing capacity.

Such an organisation may be highly resilient to individual types of cyber attack, yet remain strategically vulnerable if there is no realistic alternative to the technology on which that resilience is built.

DORA has recognised this problem particularly clearly in the financial sector. In addition to requiring documented business continuity, response, restoration and recovery mechanisms, the Regulation requires an assessment of concentration risk where a critical or important function is supported by an ICT provider that cannot easily be replaced. This is far more significant than a routine question about the contractual relationship with a supplier, because the underlying issue is whether, in a crisis, the organisation genuinely has freedom of choice or whether its decision-making capacity is merely formal.

At that point, technological sovereignty ceases to be a geopolitical slogan and becomes an operational question.

Europe does not need to produce every component itself in order to be sovereign, just as a company does not need to develop every part of its own technology stack in order to control its own business operations. Such complete technological autarky would be both economically irrational and practically unattainable. The modern digital economy rests on specialisation, international exchange, partnerships, standards and complex value chains.

But there is a fundamental difference between using someone else’s technology and being unable to function without it.

Technological sovereignty should therefore not be measured solely by asking where a technology comes from. It is far more important to measure the degree of control over the consequences of dependence on that technology. The European Commission now defines tech sovereignty as Europe’s ability to act independently in the digital world by developing and controlling key technologies, data and infrastructure, while reducing dependence on suppliers outside the EU. The scale of the problem is serious: according to Commission data from 2026, the European Union relies on countries outside the EU for more than 80 per cent of key digital products, services, infrastructure and intellectual property.

This does not, however, mean that the answer is to close the European market or reject international partners. On the contrary, strategic autonomy means precisely the ability to cooperate without losing the freedom to make decisions. The European Parliament links technological sovereignty to the ability to design, develop and scale digital technologies, but also to autonomous decision-making, cooperation with trusted partners, diversification of supply chains, openness and interoperability.

Put differently, openness and sovereignty are not opposites. The problem arises when openness ceases to be a choice because no alternative remains.

Sovereignty is not the absence of dependence, but the absence of a point of coercion
Sovereignty is not the absence of dependence, but the absence of a point of coercion

Sovereignty is not the absence of dependence, but the absence of a point of coercion

Every modern technological system depends on other systems. Cloud services depend on energy; energy depends on control systems and communications networks; telecommunications depend on physical infrastructure; data centres depend on equipment and chips; business applications depend on identity systems and APIs; and AI depends on computing capacity, models, data, energy and specialised processors. Even a company that owns a significant share of its own infrastructure remains part of a wider ecosystem whose individual elements it cannot directly control.

Dependence in itself is therefore not evidence of weakness. Weakness arises when a dependency is critical, concentrated, not readily visible, difficult to replace and so deeply embedded that its disruption can halt a core function.

Here lies the essential difference between interdependence and strategic dependence. Interdependence can increase the capabilities of all actors involved because it enables specialisation, knowledge exchange and shared technological progress. One-sided critical dependence produces something else: leverage. The actor controlling a component without which another actor cannot continue does not even need to intend to use that leverage. A commercial decision, a provider ceasing to operate, a geopolitical dispute, a regulatory conflict, an incident, sanctions, a change in terms of use or technological obsolescence can be enough to turn what was previously efficient into a strategic vulnerability.

I would therefore define technological sovereignty differently from technological self-sufficiency: sovereignty is not the absence of dependence, but the absence of a point of coercion.

Yet even the formal possibility of exiting a relationship with one supplier is not enough. Genuine autonomy does not exist merely because a contract permits migration. There must be the technical capacity to carry it out, systems sufficiently interoperable to allow data and functions to be transferred, sufficient alternative capacity to take them over, people able to execute the transition, and a migration timeframe that does not endanger the critical function.

Autonomy therefore begins not when an alternative exists on the market, but when it is possible to move to that alternative quickly enough to avoid losing what is critical to an organisation or society.

In this sense, portability, interoperability, substitutability and recovery time become not merely technical characteristics of a system, but indicators of sovereignty.

It is no coincidence that, in 2026, the European Parliament called for systematic mapping of Europe’s critical dependencies, covering data storage, identity and payment systems, communications platforms, software, protocols and standards. In the same document, interoperability and open standards are explicitly linked to preventing vendor lock-in, while, in the cloud sector, the document calls for the removal of barriers to switching and the diversification of providers.

This marks a fundamental change in the European debate. It is no longer enough to know who our supplier is. We need to know how capable we are of functioning without that supplier.

The most dangerous dependency may not be immediately visible

It would be an even greater mistake to view dependency management solely through the relationship between a company and its direct suppliers. Today’s digital systems have multi-layered and often opaque interdependencies. A supplier that an organisation regards as reliable and as part of a diversified supply base may at the same time depend on the same cloud infrastructure, identity provider, software library, equipment manufacturer or upstream service as its supposed alternative.

In that case, two alternatives on paper may in reality represent one and the same point of failure.

ENISA is increasingly recognising this exact issue as an operational problem. Threat Landscape 2025, based on an analysis of 4,875 incidents, records an increase in the exploitation of critical dependency points in digital supply chains, with attackers using the interconnectedness of systems to amplify the impact of their activities. ENISA warns that the exploitation of cyber dependencies will remain strategically relevant and that cyber threat activity will continue to evolve through convergence, automation and industrialisation.

Cyber Europe 2026 demonstrated how far this logic has already moved beyond the theoretical realm. The simulated incidents in rail and maritime systems were assessed not only in terms of the compromise of an individual system, but also in terms of the consequences transmitted across connected transport, economic and societal functions. It was in this context that ENISA emphasised that the cyber dependencies of Europe’s critical infrastructure have become an operational reality.

This is why it is no longer enough to speak only of supplier dependency. We need to speak of systemic dependency.

An organisation must understand not only whom it depends on, but also whom its suppliers depend on; where several different chains converge on the same infrastructure; which functions share the same single point of failure; and what cascading effect would arise if a problem crossed the boundary of one sector. At the level of a state or of the Union, this becomes even more complex because energy, telecommunications, financial, transport and digital systems are no longer separate worlds. They form a single interdependent system in which disruption to one layer can alter the ability of all the others to function.

In this context, cyber resilience is no longer only a question of one organisation’s ability to recover from an attack. It becomes a question of the entire ecosystem’s ability to absorb disruption without a systemic loss of critical functions.

Future Cyber Maturity - Differently Measured - ACS
Future Cyber Maturity – Differently Measured – ACS

Technological control without legal control is not full sovereignty

One further dimension is often obscured in discussions of technological sovereignty by the focus on chips, cloud services and AI infrastructure: legal jurisdiction.

Data may be physically stored in Europe while the company operating the infrastructure remains subject to the law of another jurisdiction. A European institution may use a technology service that technically meets high security standards, but questions of data access, the jurisdiction of courts or a provider’s obligations towards the authorities of third countries cannot always be resolved by encryption, segmentation or a contractual clause.

The European Parliament therefore explicitly stressed in January 2026 that the EU must remain sovereign in the application of its own law in the digital space. In relation to sovereign cloud services, it also warned that problems arising from the extraterritorial effect of binding legal regimes cannot be resolved through technical discussions alone.

This sets an important boundary in our understanding of sovereignty. Technological control without legal control is not full sovereignty, just as legal sovereignty without the technological capacity to implement decisions remains limited.

European technological sovereignty therefore has at least three simultaneous dimensions: the ability to develop or obtain the necessary technology; the operational ability to preserve continuity and change technological direction when necessary; and the legal ability to ensure that European rules remain applicable to digital resources and functions of strategic importance.

Only by bringing these dimensions together can genuine control emerge.

There is no sovereign infrastructure without people who know how to run it

One of the most dangerous illusions in this debate would be the assumption that sovereignty can be purchased through the procurement of European technology.

It cannot.

If an organisation buys infrastructure that it cannot independently design, maintain, monitor, protect, reconfigure or restore without permanent external dependence, part of its critical capability still resides outside the organisation. The same is true of a state and of the European Union.

Human capital is therefore an integral part of technological sovereignty, not merely a labour-market issue.

The latest 2026 State of the Digital Decade report reveals precisely this weakness. ICT specialists accounted for around 5 per cent of total employment in the EU during 2025, only half of Europe’s 2030 target. At the same time, the Commission states that SMEs continue to encounter barriers to adopting advanced digital technologies precisely because of a lack of skills, infrastructure, access to data and other resources.

Sovereignty therefore cannot be outsourced in its entirety. Partners and external experts can be used, but a certain level of critical knowledge must remain within the system that seeks to retain the ability to make decisions independently.

Put differently, sovereignty cannot be bought if the capability required to exercise it has already been outsourced.

This is particularly important in cyber security, where formal ownership of infrastructure means little if an organisation lacks sufficient expertise to understand an anomaly, assess its consequences, make a decision under pressure, manage recovery or recognise that, after an incident, the system should no longer be restored to its previous state.

The human element is therefore not external to cyber resilience. It is part of the resilience architecture itself.

AI simultaneously increases capability and creates new dependence
AI simultaneously increases capability and creates new dependence

AI simultaneously increases capability and creates new dependence

Artificial intelligence further intensifies each of these problems because it acts as a dual multiplier.

On the one hand, it increases attackers’ capabilities: it accelerates content creation, enables the scaling of social engineering, improves automation and reduces the cost of certain offensive activities. ENISA already records the use of LLM systems to improve phishing and automate social engineering activities, while also warning of a rise in attacks on the AI supply chain.

On the other hand, the same AI becomes a dependency multiplier for organisations that adopt it.

The more business decisions, cyber analytics, software development, customer services, production processes, administration and infrastructure management rely on AI, the more functions become dependent on models, data, APIs, cloud infrastructure, specialised processors, computing power, electricity and a relatively small number of technological ecosystems.

This gives rise to a paradox of particular importance to Europe: it is possible to become more technologically advanced and more strategically dependent at the same time.

For precisely this reason, under the European Tech Sovereignty Package of June 2026, the Commission brings semiconductors, AI, cloud and open-source strategy together within a single policy framework. The objective is not merely to develop more European products, but to increase Europe’s capabilities and broaden choice in critical technological fields at a time when demand for computing is rising sharply because of AI.

The 2026 data illustrate the scale of the challenge clearly: the EU currently holds around 9 per cent of the global semiconductor market, while the target for 2030 is 20 per cent; approximately one fifth of European companies already use AI, and AI adoption rose by 48 per cent during 2025 compared with the previous year. The more deeply AI is integrated into the European economy, the less the infrastructure on which it rests can be regarded merely as a competitiveness issue, and the more it becomes a question of continuity and strategic autonomy.

Europe’s AI strategy should therefore not end with the question of whether Europe can build its own foundation model. We need to understand the entire capability chain: compute, chips, energy, data, models, open-source components, cloud, edge infrastructure, cyber security, and the people able to develop and control all of it.

Sovereignty in one layer does not negate critical dependence across all the other layers.

Future cyber maturity will have to be measured differently

If we accept that cyber security, cyber resilience and technological sovereignty are three connected but distinct layers of capability, the way in which we measure technological maturity will also have to change.

Traditional indicators, such as the number of vulnerabilities, detection time, response time, service availability or the number of incidents, remain important. But they do not answer the question of how capable an organisation really is of continuing to operate when its technological environment changes.

We need to know how long a critical function can survive without a particular service, how dependent it is on a single supplier or jurisdiction, how long it takes to move to an alternative, whether data are portable, how interoperable the systems are, whether genuinely independent alternatives exist, and whether the organisation can continue operating in a degraded mode while restoration is under way.

We also need to understand the other side of dependence: who depends on us, and what consequences our own outage could have for the wider system.

When resilience is viewed in this way, a backup is no longer sufficient evidence of recovery capability, just as the existence of a second supplier is not automatic proof of diversification. Multi-cloud means little if both environments share the same critical identity infrastructure. Two suppliers do not represent genuine alternatives if both depend on the same upstream service. An exit clause is not an exit strategy if migration takes longer than the organisation can withstand being without a critical function.

Precisely for this reason, cyber resilience will increasingly be measured less by whether we succeeded in restoring the previous state and more by whether we emerged from an incident with a more capable system.

Adaptation is decisive here. An organisation that, after a serious incident, faithfully reconstructs the same environment that enabled the incident may have recovered technically, but it has not increased its resilience. A resilient system uses disruption as information: it changes its architecture, privileges, processes, controls, supplier relationships, decision-making procedures and the assumptions on which the previous model was built.

Recovery restores the function. Adaptation changes the conditions under which the next incident will attempt to threaten it.

Europe therefore need not choose between global integration and technological sovereignty
Europe therefore need not choose between global integration and technological sovereignty

Europe therefore need not choose between global integration and technological sovereignty

The greatest mistake would be to conclude that Europe must build its strategic autonomy by withdrawing from global technology ecosystems. The history of innovation shows the opposite: openness, knowledge exchange, competition and international cooperation are among the principal drivers of technological progress.

But cooperation means something different when a choice exists.

Europe can use non-European cloud services, processors manufactured in Asia, American software, global AI models and technology developed in partner countries while simultaneously increasing its technological sovereignty, provided that critical functions are not tied to a single irreplaceable point outside its control.

This entails developing European capabilities where a strategic risk exists, but also adopting a far more disciplined approach to interoperability, open standards, data portability, diversification, open-source ecosystems, human capital, legal jurisdiction and the genuine ability to move to alternative solutions.

Europe’s objective should therefore not be to eliminate all dependencies. That is neither possible nor desirable.

The objective should be to eliminate dependencies that can become points of coercion.

This is where cyber security, cyber resilience, strategic autonomy and technological sovereignty converge in a much broader idea of technological power. Cyber security protects digital assets and capabilities. Cyber resilience ensures that a critical function survives even when disruption occurs. Strategic autonomy ensures that genuine options exist for changing direction, while technological sovereignty preserves the ability to decide on key technological issues without the coercion that arises from uncontrolled dependence.

None of these capabilities is sufficient on its own.

An organisation may be well protected against cyber threats, yet entirely unprepared to continue operating after a serious disruption. It may have exceptional resilience, yet base that resilience on technology that it cannot replace. It may own its own infrastructure but lack sufficient expertise to maintain and protect it. It may even have a European supplier and believe that it has thereby resolved the question of sovereignty, although that supplier itself depends on the same global technology chain from which the organisation supposedly wished to separate.

Maturity therefore does not emerge from choosing one of these dimensions, but from connecting them.

Perhaps this is why we will have to change the very definition of technological power in the years ahead. It will not be measured solely by the number of patents, the scale of cloud infrastructure, the volume of computing power or the market share of European technology companies. It will also have to encompass a system’s ability to preserve its function when one of its parts fails, to change supplier when necessary, to retain legal control over critical data, to have people capable of managing its infrastructure independently, and to adapt after disruption faster than the risk environment changes.

Europe, then, does not need to produce everything itself in order to be sovereign.

But it must know what it depends on. It must understand how critical each of those dependencies is, who controls them, which jurisdiction they fall under and what cascading consequences would follow from their disruption. It must have alternatives where the cost of having none is too high; and where a complete alternative is not rational, there must be sufficient tolerance, redundancy and adaptive capacity to preserve the critical function.

This may be the most important distinction between apparent and genuine resilience.

An apparently resilient system functions while its assumptions remain valid.

A genuinely resilient system can continue even when those assumptions change.

That is why the greatest cyber vulnerability of the future may not be one that an attacker finds in code. It may not have a CVE identifier, appear in a vulnerability scanner or be resolved by the next security patch. It may be hidden much deeper, in the architecture of our business operations, infrastructure and society: in technology that we believed was merely one of the services we use, until the moment we discover that we can no longer continue without it.

And the moment there is no realistic possibility of continuing without one supplier, one platform, one state or one technological ecosystem, we are no longer speaking only about technological dependence.

We are speaking about the boundary of our autonomy.

And it is at that boundary that Europe’s true technological sovereignty will be measured in the years ahead.

Sources

1. NIST, SP 800-160 Vol. 2 Rev. 1 – Developing Cyber-Resilient Systems: A Systems Security Engineering Approach, 2021.

2. Directive (EU) 2022/2555 – NIS2, in particular Article 21 on cyber risk-management measures.

3. Directive (EU) 2022/2557 – Critical Entities Resilience Directive, the definition of resilience and the framework for the resilience of critical entities.

4. Regulation (EU) 2022/2554 – DORA, in particular the provisions on continuity, response, recovery and ICT third-party concentration risk.

5. ENISA, Threat Landscape 2025, analysis of 4,875 incidents and trends relating to AI, automation and the exploitation of cyber dependencies.

6. ENISA, Cyber Europe 2026: All eyes on the EU’s collective response and resilience, 11 June 2026.

7. European Parliament, European technological sovereignty and digital infrastructure, adopted on 22 January 2026.

8. European Commission, Strengthening Europe’s Tech Sovereignty, 2026.

9. European Commission, European Technological Sovereignty Package, 3 June 2026.

10. European Commission, 2026 State of the Digital Decade, August 2026.


Originally published by Advanced Cyber Security on .

Source: Read this article on LinkedIn ↗

Back to Blog

Scroll to top