Louis Zezeran
24. sept 2026
Everyone Wants Digital Sovereignty. Almost Nobody Can Define It.
Say “digital sovereignty” in a European boardroom right now and heads nod immediately. Ask five people in that room what it means, and you will get five different answers — and that, according to Jesper Olsen, is precisely the problem.
In this pre–Nordic Baltic Security Summit episode of the NEVERHACK Cybercast, recorded in the Tallinn studio the day before the conference, host Louis Zezeran sits down with Jesper Olsen, Chief Security Officer for EMEA North at Palo Alto Networks, for a conversation that pushes back against the prevailing mood. Europe has had its wake-up call. The cloud migration everyone celebrated a few years ago suddenly looks like a liability, geopolitics has turned old assumptions upside down, and the reflex answer is: bring it all home.
Jesper’s argument is not that this reflex is wrong. It is that it is unexamined — and that acting on an unexamined reflex is how organisations end up spending enormous effort mitigating the risk they can see while ignoring the one that will actually hurt them.
As Louis puts it in the intro, this is a point of view designed to challenge your initial assumptions. It succeeds.
Sovereignty Is Not One Thing — It’s Five
The most immediately useful thing in this episode is a framework. Jesper, who spent part of his career inside government and defence, describes how his own understanding of sovereignty evolved. In defence, sovereignty originally meant total isolation: complete, supreme control over a closed system. Then the mission changed. Information exchange with allies became essential, both militarily and commercially, and sovereignty-as-isolation simply stopped being achievable.
What replaced it was a more granular model, built on five distinct dimensions:
- Data sovereignty — where your data resides, who can read it, who can cut you off from it.
- Legal sovereignty — which jurisdictions and legal frameworks your arrangements are genuinely subject to.
- Technology sovereignty — the software, the source code, the update pipeline, and the hardware underneath it all.
- Operational sovereignty — who actually runs the thing day to day, and from where.
- Economic sovereignty — whether the commercial and funding model behind your supplier survives a change in political weather.
The value of splitting sovereignty into five buckets is that it turns a slogan into a set of answerable questions. Very few organisations need maximum sovereignty across all five dimensions. A government department might need it in several places. A commercial enterprise almost certainly does not. As Jesper frames it, the real question is: which knob do we need to turn, how far, and for what specific purpose?
That is the shift from sovereignty as posture to sovereignty as risk management.
“Informed Interdependence” — The Core Idea
Louis names the concept that sits at the heart of Jesper’s summit talk: informed interdependence.
You are going to have dependencies. Data dependencies, system dependencies, supply chain dependencies that reach outside your organisation and outside your control. The goal is not to eliminate them — for most organisations that is neither possible nor desirable — but to know them. Map them. Rank them. Then, for each one, ask the uncomfortable question: what happens if this breaks?
Jesper walks through the technology layer to show how deep it goes. You exchange data — fine. But what about the system doing the exchanging? Did you build it? Does someone outside your control maintain it? What happens when the updates stop arriving? And what about the metal it runs on — the servers, the networking equipment? Produced in country? Almost certainly not.
Louis pushes this into the military domain with the kill switch question that has haunted European defence procurement: could the supplier of an advanced weapons system disable it remotely? Jesper’s answer is less about the specific rumour and more about the principle. This is an economic sovereignty question as much as a technical one. Does that weapons system exist at all without the host nation’s defence contracts and continued cooperation? If the two states become adversaries, what do you actually own?
The Risk You’re Watching vs the Risk That Will Hit You
This is where the episode earns its contrarian billing.
The dominant European anxiety, Louis says plainly, is: what if we put everything in AWS or Azure and the Americans come and look through our stuff? And Jesper agrees that the concern is real — including at citizen level, where national health data moving into hyperscaler infrastructure to enable AI processing raises legitimate questions about whether personal information becomes subject to a foreign government’s wishes.
But he separates two very different failure modes, and ranks them:
- Someone else reads your data. Serious for organisations sitting on proprietary knowledge — corporate espionage and nation-state data extraction are real, and Unit 42 has tracked exactly this kind of activity. Less critical for most individuals.
- You lose access to your data or your services. In Jesper’s assessment, this carries the higher probability and the higher business impact.
And he adds a third, uncomfortable observation that reframes the whole debate. If a well-resourced state cyber force wants your data, geography is a speed bump, not a wall. If it sits in Europe rather than the US, they don’t have the legal instrument — so they break in instead. In a hyper-connected world, with vulnerabilities disclosed faster than organisations can patch and criminals weaponising them faster still, your data is accessible at some point unless organisations change their pace dramatically. Location is not the control you think it is.
The practical implication: if the cloud provider that runs your enterprise applications is switched off, your business stops. That is a technology, operational and legal sovereignty problem — and data has nothing to do with it.
Demand Transparency. Then Read the Contract Properly.
Jesper is notably direct about what the industry owes its customers. The transparency that has not been forthcoming from big tech is process transparency: what happens when a government — any government — requests data? How many times has it happened? Who asked? What was handed over, and what was refused? And crucially, what prevents data being handed over without the customer ever knowing? That, he argues, is what individuals and organisations should be demanding — and one of the strongest reasons to keep having the sovereignty conversation at all.
On contracts, there is an actionable tip that many organisations miss. Too many accept standard terms because they assume they have no choice. But the major cloud providers do maintain legal frameworks covering EU law alongside US law — you have to ask for them. Leverage scales with spend, and Jesper is honest about why: Palo Alto Networks has around 90,000 customers globally and could not honour 90,000 bespoke contracts. A customised contract nobody can actually fulfil is just paper and a future jurisdiction fight. But that doesn’t mean you stay silent — customers should be pushing to influence the standards.
The Sovereignty Paradox: Go Local, Get Blind
The sharpest insight in the episode comes near the end. If every nation builds and runs everything locally, nobody has global oversight anymore — and global oversight is what currently protects everyone.
When a Palo Alto Networks sensor anywhere in the world detects something new, that knowledge propagates to global customers in minutes. Remove cross-border telemetry sharing and that early-warning system degrades. Cybercriminals, Jesper notes, do not respect borders — they simply hop around them.
Louis tests this hard, suggesting threat intelligence is essentially a one-way street: just send it to me, I don’t need to send anything back. Jesper’s response is the episode’s best correction. Palo Alto Networks already encounters governments and military organisations that refuse to share telemetry on sovereignty grounds. No telemetry in, no threat intelligence out. The protective patterns that firewalls rely on are built from that shared insight.
And this is where data differentiation matters. Data is not just data. An IP address tied to nothing, existing across many countries, is not a sovereignty crisis. Asset telemetry — manufacturer, last update date, exposure — is what determines whether a live-exploited vulnerability gets prioritised in time to save you. Treating every byte with identical paranoia costs you protection and buys you very little.
The alternative Jesper puts forward is community-driven security: to fight internationally organised adversaries, defenders must be able to operate internationally too.
Europe’s Harder Question
The conversation widens into economics. Europe’s AI models are not competing at the frontier, regulatory interpretation fragments across member states even where standards are clear, and the US operates as one market under one umbrella. Louis, who has run businesses that hit the ceiling in Estonia’s one-million-person market, knows the gap intimately. Jesper’s train metaphor lands: Europe isn’t missing the train, but it risks riding in the last carriage — and with self-improving models close, the gap widens. And if full sovereignty is the goal, follow it all the way down: do we have the energy, the silicon, the raw materials to stand alone?
Why This Episode Matters
Because “bring it all back to Europe” is a slogan, and slogans don’t survive contact with a risk register. This episode gives you the vocabulary — five layers, informed interdependence, data differentiation — to have a sharper, more honest sovereignty conversation with your board, your regulator and your suppliers. Map your dependencies. Rank loss-of-access alongside loss-of-confidentiality. Ask your providers the transparency questions. And think twice before cutting yourself off from the global intelligence that keeps you safe.
Listen to the full episode now, explore more at the NEVERHACK website, and subscribe to the NEVERHACK Cybercast so you never miss an episode.