EN
Where’s my data? Data sovereignty in the cloud
In this video, Niels van Ingen, Keepit’s SVP of Business Development and Strategy, joins Dark Reading’s Terry Sweeney to explore the growing importance of data sovereignty. Together, they discuss why organizations—not SaaS providers—remain responsible for their data, the risks of ignoring shared responsibility, and how digital sovereignty is reshaping cloud strategy.
View transcript
Welcome to the Dark Reading News Desk here at Black Hat USA 2025. I'm Terry Sweeney, contributing editor with Dark Reading, and joining me now is Niels van Ingen, Senior Vice President of Business Development and Strategy with Keepit. Niels, thanks so much for joining us on the News Desk. Hi Terry, nice to be here for sure. We are talking data sovereignty, which is a term that is creeping into the SOC vernacular. Define that term for viewers who may be new to it. Yeah, so data sovereignty, I've been in this space for a long time, especially around data management, and data sovereignty has been around for a long time. Most of the time people actually talk about data residency. So data sovereignty is really like the legal authority of a region or country to control the data. So I think the data residency is really where it applies. But the interesting part right now is that actually you have to think beyond data sovereignty, you have to really think about digital sovereignty. So that brings us then to its application here. It's become a critical concern for organizations who are operating in say a multi-cloud or SaaS heavy environments. Why is it a concern particularly in those areas? Yeah, and it really comes back to the adoption. And I would say it's multi-cloud. And obviously what we're seeing, one of the things we're seeing, and this is globally happening around SaaS adoption, that 2028, 2030, 75% of business outcomes are going to be delivered via SaaS. Add AI sprawl to that, and basically customers are starting to have problems understanding, well, where is my data? Where are the services? Can I actually run if certain things are not there where they're supposed to be? And that really ties back into the issue around digital sovereignty, understanding what you have and controlling what you have to make sure you can achieve your business outcomes. Is it more of a... There are more examples of where there's challenges around that based on political climate, economic climate. The term data sovereignty also suggests there's a compliance angle to this. Is that accurate? It's a big part of the compliance angle. So if you think about, for example, in Europe around GDPR and how you deal with data, that's also coming back to data residency, but also going beyond just the data itself. Also think about software hardware infrastructure. What are the dependency? And does it actually meet the regulatory and legal requirements? Yeah. Thank you for that. Shifting gears slightly, I can imagine the risks are numerous, but talk about some of the risks associated with assuming that your SaaS provider is taking full responsibility for your data. What are some of the big problems with that assumption? The biggest part with the assumption is that, and this is coming back to a lot of times when customers move to SaaS, they think they take over the whole problem. But most SaaS providers have a shared responsibility model where the SaaS provider provides basically the service, but your data and the outcomes that is still your responsibility. And so if you're not sure about what's happening there, then ultimately, if, for example, the SaaS provider loses the data or makes it available to third parties where it shouldn't, you don't have recourse. You can't control the outcomes around those pieces. And that becomes, there's big examples, but there's also small examples. So for example, in Europe, we just had the case where we have a judge who was trying to get a judge as part of the Hay Court, part of Microsoft. There happened something between the US and a particular judge, and all of a sudden access was removed for that judge to their data in M365. Well, that impacts outcomes ultimately. Sure. How fluent with this term data sovereignty are SaaS providers themselves? What's your assessment there? I think it's a hidden factor. The SaaS provider is not necessarily open about this stuff as to where your data is. Ultimately, does your data have an address? And most, it's kind of vague, right? So we've seen many cases, and this is also part, if you think about it from a legal perspective, where you have to define, for example, your sub-processes as part of your DTO, your data protection agreements, where you think your data is in one place and it ends up something different, but it then causes issues for customers down the line. So for example, we see this with support tools where you try to set up operations in Europe, you think your data is there, but it ends up in the US. Well, there's consequences to it. There's consequences to that. Sure. So again, maybe the best advice for CISOs and SOC professionals is watch your assumptions. Watch your assumptions and make sure you're very, very clear on the problem you're trying to solve. Because I think a lot of times, and this is also what you're seeing with SaaS sprawl, but certainly also with AI sprawl, we all run towards the solution, but what is it that we're really solving and what should the scope be, short and long term, to make sure you understand what you're getting into? What are some of the solutions? Can organizations say design backup architectures that maintain sovereignty over their data, regardless of where it's stored? What's your sense there? No, it plays all the way through. So even if you think about, for example, backup, which should be a source of truth basically, you still need to make sure and do the due diligence on if I take backup, where does it actually end up? Do I have control over it? Because a big part, for example, SaaS backup or backup in general is different from production systems. Shipments are a point in time. Certainly in SaaS. Your SaaS backup is your whole history. It's like a time machine, all your data from all this time with all the changes. So it becomes really important to make sure you control that data source and make sure where it is, who has control, and how you go about it as far from a management perspective. Going back to the SaaS providers, again, are they fluent in these issues? No. I don't think they're fluent at all. Because, again, most SaaS providers. and SaaS providers solve for specific issues. And you sort of have a series of unintended consequences because these SaaS providers become ecosystems and it all starts to get interconnected. And AI is actually making this problem worse. So you start talking about fabrics, interconnectivity. Well, how do you control that? As a customer, you need to be, again, do your due diligence, really understanding what you're signing up for, where things end up, and does that meet ultimately your requirements from a business perspective in terms of cost and risk, but also regulatory requirements. It doesn't sound like their contracts are particularly flexible. It sounds like it's a hard template. Is that accurate? Correct. Yes, you can't really negotiate with SaaS fans because they deliver the service in a certain way, which again, is not just about a data piece. It goes software, infrastructure, all these types of pieces. So you don't have a ton of control, hence why, again, it's really important to focus on what is the problem you're really trying to solve versus, again, adopting lots and lots of solutions that actually might make your problems much bigger and worse down the road. Niels, talk about some of the controls or architectures that you'd recommend to ensure recoverability, even if, for some reason, your primary cloud provider is compromised. Yeah, so the core requirements, and this has been true for backup for a long, long time, is that you should have your production data separated from your backup data, right? So if you take it out from a production file and put it right back, that doesn't make a lot of sense. I think the other key piece in the world we live in nowadays, because if you look at attack services, and obviously, we see more and more ransomware, insider threats, bigger mistakes, because AI is starting to do stuff that we didn't really intend it to do, then you have to think about making sure that your backups and your data, which is really a corporate memory, is always available, and mutability, and then dedicated to that becomes really important. I think the second part that's really important is SAS is fundamentally different than on-prem, like what we're used to, in file service, database, and so on, all service databases and all that kind of stuff, and that everything is going through API. So there's a lot of talk about backup. There's not enough talk about recovery. And that really matters because ultimately that's why you do backup ultimately. So performance characteristics, how do you actually go about recovering? How do you make it available when bad things happen is absolutely something that customers need to dive in more. And today I would say that's often overlooked. It's more a checkbox feature. Well, you raise a good point. Backup and recovery are often used interchangeably. And I think that's off base. But I did want to go back to your comment about AI and ask you to what degree does AI muddy this whole data sovereignty picture? It's absolutely massive because, and this has happened for some years, it actually started with SaaS. I think AI makes it actually much, much worse because if you look, for example, at SaaS statistics, right? So most companies, reasonable size, have about 100 different apps. IT is only sort of a lot, it's only approved about 40% of that. Now, if you look at what's happening in companies, there's actually a challenge around adopting AI because the controls are not there, but what are users doing? Users are doing whatever they want, right? So they did the corporate data, copied into the LLMs, and then you have no idea where it ends up. So as companies, we kind of have lost control at this point, where data ends up, which then undermines, obviously, this whole idea of sovereignty, both from a digital and from a data perspective. And that's going to be the, I think in my mind, that's the big problem we need to solve to really get to, you know, really fulfill the promise of AI as to what we can do with it, which is really not just automation and augmentation, it's really about transformation, you know, yet again. All right. Niels, real briefly, take us out with some thoughts on how you validate that you maintain true ownership of your SaaS applications or the shared responsibility models. What's true there? It all starts with, again, understanding the scope of the problem you're trying to solve. So be very, very clear on that. And then do your due diligence, you know, when you start, actually, where does the data up? Who has the controls? What are the data management policies? Are we meeting regulatory and legal requirements, country or, you know, vertical specific? And then make the correct decision, because this is not a short-term decision where you say we take a checkbox and then we shift. This is a really impactful long-term decision, because you can't just shift from one vendor to another when you talk about a big corpus. Well, some new sobriety around data sovereignty and working with SaaS professionals, Niels, thanks so much for joining us on the Dark Reading News Desk. It was a pleasure, Terry. Thank you very much. We've been talking with Niels van Ingen of Keepit. This has been Terry Sweeney for the Dark Reading News Desk. Thanks for joining us for this segment. We'll see you next time.