Digital sovereignty means control
Interview on digital sovereignty with Michael Pütz
Digital sovereignty is often used as a guiding concept for resilient IT. In practice, though, many companies still lack an overview of their critical dependencies. About control, exit capability, and the Mittelstand.
Digital sovereignty in business: ambition and reality
Digital sovereignty is a widely used term, both politically and economically. What does it actually mean for businesses?
For businesses, digital sovereignty means, above all, control. That means control over their own data, over critical business processes, and over the technical dependencies those processes rely on. As long as a company can't reliably answer where its data is stored, who has access to central systems, how easily providers can be switched, and what failure risks exist, that control is missing.
Is this ambition already being implemented sufficiently in German companies?
In my assessment: clearly not. Many companies continue to operate with strong dependencies, for example on individual cloud platforms, international security vendors, or outsourced operating models, where essential parts of control no longer lie within their own sphere of influence. In many cases, digital sovereignty is still not an operational management topic, but rather a communication term. Management often hasn't sufficiently grasped that this is primarily about the ability to act in a crisis.
Critical dependencies and exit capability
Which dependencies do you currently consider particularly critical?
First, the dependency on individual cloud services and platform providers. When core applications, data, and security functions are heavily concentrated with one provider, this creates not just technical but also strategic lock-in effects. The second issue is exit capability. Many companies only realize late how difficult a switch becomes once data, processes, interfaces, and operating logic are tightly bound to one platform. On top of that, European data centers run by international providers may partly ease the location question, but they don't automatically resolve the question of control, accountability, and structural dependency.
You explicitly extend this topic to cybersecurity as well. Why?
Because a security strategy isn't reliable without knowledge of your own dependencies. Companies often still operate with an understanding of protection that's too focused on prevention. In reality, you have to assume today that attacks are fundamentally possible. What matters, then, isn't just whether an attack happens. What matters more is whether real damage results from it. Any company that doesn't know which systems are critical, which partners are involved, and how communication, detection, and response work in an emergency, cannot effectively manage that risk.
Sovereign intrusion detection
Sovereign intrusion detection Text: Our deception technology detects attackers before damage occurs, developed and patented in Germany, with no data flowing to international platforms. Discover our solutions for sovereign IT security.
Lösungen entdeckenNo real control
What's the maturity level like in German companies?
Our assessment is that 80 to 90 percent of companies have no real control over their cybersecurity and sovereignty strategy. That shows up in technical gaps and, even earlier, in basic understanding. We regularly see executives or decision-makers equate an existing firewall with modern deception. That's no longer enough today. There's a significant difference between classic perimeter security and a resilient detection and response capability.
80–90% of companies have no real control over their cybersecurity and sovereignty strategy.
Mittelstand: high risk, limited ability to steer
Is this primarily a problem for the Mittelstand?
It's especially visible in the Mittelstand, because specialized internal resources are often missing there, and security responsibility runs alongside other tasks. At the same time, mid-sized companies are economically highly dependent on functioning IT-supported operations. So the risk is high, but the ability to steer it is often limited. That's why this topic is economically relevant.
How can companies orient themselves when internal expertise is lacking?
Then you need partners who work on this topic in a specialized and continuous way. Companies don't make fundamental decisions in other areas without the right expertise either. From my perspective, it's important to look at concrete operating and support models. In an emergency, what matters is whether contacts are available, whether communication works quickly, and whether legal and operational responsibilities are clear. So it can make a lot of sense to prioritize providers with headquarters, support, and contacts in Germany, or at least in the EU.
Do you have any questions? Would you like a demo?
We look forward to hearing from you.
Your contact partner
Michael Pütz