The discussion about digital sovereignty often gets stuck in a false opposition. Either everything belongs in your own server halls, or it makes no difference where it sits. This chapter argues that both positions miss the question that actually matters, what the organisation can keep doing the day a dependency falls away. A bank in Europe was forced to shut down when sanctions against its parent company led cloud providers to cut off email and core systems overnight. The bank had followed every rule. What it lacked was a way forward.
The chapter opens by defining the term and separating it from neighbouring ideas such as data localisation, which is often confused with sovereignty but solves something else. Then it maps Swedish dependencies, which functions in society and business rest on a handful of foreign suppliers. The legal grey zone gets a substantial section, because that is where the hard questions live. What happens when a supplier is subject to legislation that conflicts with Swedish law, and who decides which weighs heavier? After that come sovereignty within total defence, EU ambitions in the area, and the double risk of pricing power and operational disruption, two expressions of the same dependency. The later sections are the most practical. What an organisation can actually do, why pragmatism beats purism, and what a realistic exit plan contains. Open source is treated as a strategic precondition rather than an ideological choice. How dependencies are handled in the supplier chain is taken further in chapter 18 on supply chain security.
The question has moved from a matter of principle to a matter of operations. Sanctions, changed licence terms and sudden price shifts have shown that dependency has consequences long before any conflict arises. For entities covered by the Cybersecurity Act it also becomes a continuity question, since the ability to keep delivering is one of the requirement areas and supervision may well ask how it is secured.
This page shows what the chapter covers and why the dependencies deserve to be mapped. The assessment model, the legal boundaries and the concrete alternatives are in chapter 7 of the book.
Sovereignty is not measured in what you own, but in what you can keep doing when a supplier falls away.
Key insights
- Sovereignty is a question of freedom of action, not ownership. The question is what you can do if the supplier falls away.
- Dependencies rarely arise through one big decision, but through many small ones nobody has added up.
- Pricing power and operational risk are two sides of the same dependency and belong in the same analysis.
- Open source is a strategic precondition rather than an ideological choice, because it preserves the ability to switch.
- Purism is expensive and often unrealistic. Pragmatism with known exit routes is the sustainable path.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
Sovereignty assessment
Assess a service or supplier against the sovereignty dimensions, from appendix E.
System tools
Tool categories and alternatives, including Swedish and European options.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.