Blog

Is a sovereign cloud really more secure?

Why “sovereign” doesn’t automatically mean “safer.”

by Simon Lackerbauer

Head of cyber security

May 29, 2026

In our last blog post, we explored why companies are considering the move to a sovereign cloud; today, we’ll take a closer look at how such a decision is supported and validated from the perspective of security and data protection.

Setting aside the question of whether there are any differences at all between cloud models and their evaluation, in this article we will examine the factors that are always essential to the decision-making process.

To this end, we will examine a generic decision-making process that can be used to analyze whether migrating to a sovereign cloud is necessary or advisable.

Overview of the Decision-Making Process

The following diagram illustrates the seven steps, ranging from problem formulation through information gathering and evaluation to implementation and monitoring. It is important to note that this process is cyclical—after monitoring, or at regular intervals, it may be necessary to go through the process again in order to respond to changing conditions.

In this article, we have highlighted and discussed the most relevant factors to consider from the perspective of information security and data protection.

Basis for Decision

In the following section, we will examine whether and how the considerations highlighted in the process described above differ between a sovereign cloud and a public cloud.

Analysis of the legal basis

A common misconception is the conflation of data residency and data sovereignty—a topic we explore in detail in our blog post on cloud terminology . What is clear, however, is that neither of these characteristics can replace a well-thought-out security strategy, even though they are always part of it. The decisive factor is the applicable law, which governs both the cloud provider and the user.

Cloud Terms

Blog

Cloud Terms Explained

by Patrik Huber

Experience has shown that the identified legal bases rarely explicitly prohibit the use of a cloud operating model; rather, they outline general requirements. However, these are usually limited to generic statements, such as ensuring an “appropriate” level of protection. Only in certain cases, such as the preservation of official secrecy, does the mere listing of the legal bases already provide an indication of the measures to be taken.

Even if the potential cloud provider is subject to domestic law, subcontractors operating in other jurisdictions may come into play—for example, as part of “follow-the-sun” support models. All these scenarios must be carefully examined. In the Swiss context, particularly relevant for the financial sector—in conjunction with the well-known American hyperscalers—are the Swiss-US Data Privacy Framework as well as FINMA Circulars 2018/3 (Outsourcing) and 2023/1 (Operational Risks and Resilience).

Risk Assessment and Business Impact Analysis

This activity analyzes the criticality of the processed data and its impact on the business.

The implementation process is, in turn, completely independent of the choice of (cloud) operating model. Typically, this analysis identifies specific measures tailored to the particular situation, which can serve as guidelines for implementing the necessary TOMs. This allows potential implementation challenges to be identified at a very early stage of the project.

Potential reputational damage, in particular, warrants attention. Data access by foreign authorities—even if legally permissible—can cause lasting damage to the trust of customers and partners. A Data Protection Impact Assessment (DPIA) helps systematically assess the risks to personal data and define appropriate countermeasures, while a Business Impact Analysis provides the same assessment for business data.

Evaluation of Cloud Providers

Despite the limitations mentioned, data residency is still a sensible first criterion for screening potential providers. Whether a provider can store data in the desired country is a pragmatic starting point for further evaluation.

The likelihood of actual lawful access or politically motivated service changes by foreign governments is low in most cases—but it should still be factored into the risk assessment. Far more meaningful than the location of data centers is an assessment based on a structured checklist of controls and certifications. Certifications and audit reports such as ISO 27001 or SOC 2 Type II provide concrete information about the provider’s actual security level, even outside of any lawful access scenarios.

Onboarding the provider after selection

Once a provider has been selected that can fully comply with residency and sovereignty requirements, the next step is to design the actual security measures.

Baselining TOMs

The first step is to define and document the necessary technical and organizational measures (TOMs). The baselining process determines which security controls apply to the selected provider and the specific workloads. This baseline serves as a reference point for all subsequent reviews and audits.

Initial Risk Analysis for Operations and Transition

Migrating to a cloud environment involves specific risks that must be proactively addressed. These include migration risks such as incompatibilities, performance degradation, or service interruptions during the transition. The risk of data loss must also be assessed and minimized through appropriate measures.

A robust backup and recovery plan is essential from the very beginning—not just after the migration is complete. In addition, structured testing must ensure that all systems and processes function as expected after the migration.

Supplier Management and Exit Strategy

Contractually guaranteed audit rights are essential, particularly in regulated industries. These must be established in writing prior to migration and should not have to be negotiated after the fact.

One aspect that is often underestimated but critical is the exit strategy. This should already be in place and documented before the first workload is migrated. The exit strategy is not a static document; rather, it must be continuously updated to account for technological changes and new dependencies.

Conclusion: Needs- and risk-based decision-making

The key question, then, is not “On-premises or public cloud?”, but rather: Does the security architecture of the chosen model meet actual needs, and can the provider demonstrate that it meets the necessary controls?

A common misconception needs to be corrected: A sovereign cloud requires no fewer controls and measures—nor are they fundamentally different—than other cloud operating models. Anyone who believes that choosing a sovereign cloud automatically puts them on the safe side is falling prey to a dangerous fallacy. The due diligence requirements remain the same.

atrete supports companies as an impartial consultant in making this decision. Since atrete has no partnerships with cloud providers, it recommends only the level of control that is actually necessary—no more and no less. This independence is a key advantage that consulting firms with provider partnerships cannot offer.

However, in addition to security considerations, cost is also a key factor in choosing the right cloud model. We will address this topic in the next part of this blog series.