Capgemini’s survey of executives at 1,300 large organizations across 11 countries found that geopolitical tensions, export controls and cyber threats are pushing digital infrastructure resilience and sovereignty to the board level. Forty-four percent of organizations now treat digital sovereignty as a board priority, with companies seeking greater control over proprietary data, AI models, intellectual property and other critical workloads; Airbus has reportedly begun reducing dependencies on key technologies and providers.
Organizations are adopting risk-based measures rather than pursuing complete technological independence, including contingency planning, portable architectures, auditability, supplier exit options and alternatives to single providers. Full sovereignty remains impractical for 59% of respondents because of foreign-provider dependence, limited alternatives, weak supply-chain visibility and lengthy migrations: nearly half said replacing a critical provider would take three months to a year, while more than one-third estimated it would take longer than a year.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
According to the Capgemini report, Airbus began making changes to reduce its dependencies on key technologies and providers.
Capgemini published research based on executives at 1,300 large organizations in 11 countries, finding that geopolitical tensions, export controls, and cyber threats have increased scrutiny of critical digital-infrastructure dependencies. The survey reported that organizations are applying board oversight, contingency planning, and investment to these risks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.