Geopolitical friction and the pressures of the Digital Operations Resilience Act (DORA) are driving a defensive reflex across the globe. Businesses and nations are retreating into the perceived safety of sovereign clouds and data localisation. From France banning US-owned video-conferencing tools for public officials to the EU’s push for “technological sovereignty,” nations are pulling up the drawbridge and building digital walls to keep data safe inside.
However, this shift creates a dangerous analogue fallacy by assuming that in a hyper-connected world, geographical location equates to security. The reality is that data sovereignty is an illusion of safety that masks the real issue: the integrity of the software itself.
An Open Source Paradox
The reality of modern computing is that while your data might sit in a local server in Paris or London, the software processing it is a global patchwork. Open source now forms the foundation of 90% of modern applications. It is a borderless superpower for teams that has accelerated innovation, while also creating a massive, distributed attack surface that requires constant monitoring.
This complexity creates a visibility problem. A single modern application relies on hundreds of transitive dependencies (the code that your code relies on), meaning developers often do not know who wrote the code or whether or not it has been tampered with. And while all code contains bugs and vulnerabilities, some malicious, some not, in 2024 alone, approximately 40,000 common vulnerabilities and exposures (CVEs) were identified.
This represents a fivefold increase over the last decade. These vulnerabilities expose organisations to attacks capable of compromising entire software supply chains, regardless of where the data is hosted. A compromised library or malicious backdoor in an open-source component does not care if it is running on a US hyperscaler or a sovereign local cloud. If the code is compromised, the location of the data is irrelevant.
Security Behind Imaginary Walls
While regulations such as DORA and escalating political tensions have accelerated the retreat into data localisation, this approach fundamentally misses the mark. It creates a dangerous analogue fallacy, which assumes that the data’s geographic location alone is enough to protect against rising threats. This isolationist logic mirrors an outdated 20th-century mindset by attempting to impose physical borders on a borderless reality. You simply cannot secure a global software supply chain by building local digital walls.
Modern enterprise thrives on agility and the collaborative power of the open source model. A mature security strategy for 2026 must embrace tools that verify the integrity of every line of code. True resilience comes from provenance and traceability. We must know exactly where a component originated, who created it, and whether or not it was altered before being put into production. Increasing visibility into the software stack, rather than just the server’s postcode, is what allows governments and businesses to innovate with confidence.
Recommended reading
- What Will AI Sovereignty Look Like?
- BT Launches UK Digital Sovereignty Services As Data Concerns Mount
- Open Rights Group Urges UK to Ditch US Tech in Data Sovereignty Push
Location vs Integrity
The cost of prioritising location over integrity is becoming painfully clear. High-profile disruptions such as M&S, JLR, as well as the AWS outage, rarely stem from where the data is hosted. Rather, they are triggered by the weakest links in the ecosystem: unpatched libraries, compromised build systems, and opaque supply chains.
Consider the Zellis cyberattack involving the MOVEit transfer tool, which impacted major entities like British Airways and the BBC. The compromise did not occur because data crossed a border; it happened because of a zero-day vulnerability in the file transfer software itself. When the underlying code is flawed, a sovereign cloud is just a more expensive place to be compromised.
To build true resilience in 2026, the conversation must shift. Security is no longer just a perimeter to defend or a box to draw around the data. We must treat the code we use every day as the critical infrastructure it is. This requires a pragmatic transition toward ensuring that no vulnerability goes undetected and no source remains untraced. Accepting that modern code is inherently global and designing security to reflect this is the only scalable way to survive and thrive in modern computing.





