Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Knowledge
  2. Insights
  3. Blog
Blog
22.09.2026
min read

Digital sovereignty must be measured in recovery time, not by the flag on the vendor’s website

The degree of digital control becomes clear when something fails. It does not show up in the sales material or the data processing agreement, but at three in the morning, when the most important service is down and someone has to answer: “What do we do now?”

<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >Digital sovereignty must be measured in recovery time, not by the flag on the vendor’s website</span>
Sicra_Portrait_Crop_1200x1500px_4808
Oddbjørn SkaugeChief Information Officer
Forward thinking CIO focused on practical and effective approaches to information security.

We recently worked with an organization that had done everything right on paper. It had a Norwegian vendor, a data center in Norway, and an agreement requiring that its data could be exported. When the organization tested the export, it received a file that none of its own systems could read. It was also told that the only person who could restore the environment was on vacation for two weeks. The flag was Norwegian, but the control was not there.

Digital sovereignty is often reduced to which country the vendor comes from and where the data center is located. That is relevant, but it says little about what an organization can do when a critical service goes down. NSM Director Arne Christian Haugstøyl advised in February against putting all your eggs in one basket, regardless of who owns the basket. It is about concentration risk, not nationality.

The outages at AWS and Azure in October 2025 brought Norwegian organizations to a standstill for hours, regardless of where their data was stored. The addresses of the data centers did not help. What did help was knowing what had stopped, who could do something about it, and how long it would take before the services were back up.

How to test your vendor dependency

A vendor can fail in two ways. It can be down, as AWS and Azure were. Or it can stop providing services to you because of sanctions, changed terms, bankruptcy, or an order from the authorities in the country where the vendor is based.

One metric covers both scenarios: How long does it take before the most important service is operational again without the vendor’s help? Most organizations have a backup plan. Fewer have tested whether they can actually restore the service.

The goal is not to eliminate all dependency, but to know which dependencies you have accepted and make sure the measures are proportionate to how critical the service is. Can you revoke and restore privileged access without the vendor? Have you tested recovery of the most critical service? Do you know how long it will take? Can data and configuration be exported in a format that can be used in another environment? Has this been tested in practice? Is the necessary expertise available to take over, and is there a plan to end the dependency on a vendor?

The board must know the critical dependencies

In April, the Storting asked the government to map Norway’s digital dependencies on an ongoing basis, with the first report due by the end of 2026. The proposals for a government cloud and an exit strategy from Microsoft 365 did not receive a majority. That is a sensible sequence: first understand the dependencies, then make a decision. Boards should do the same for their own organizations.

The board should not choose the technical architecture. But it should know which digital services the organization cannot operate without, who controls them, and how quickly operations can be restored. That leads to better investment decisions. A cheap solution becomes expensive if data, expertise, and workflows become locked into one vendor. A more expensive solution may be the right choice if it provides better visibility, easier recovery, and a credible plan for switching vendors.

The same logic applies to AI services, and things move faster there. They are quick to adopt and inexpensive at first. But once data, workflows, and decision logic are built into a platform, it can quickly become very expensive if you want to switch AI vendor or platform.

Need Assistance?

We are happy to have a non-binding conversation. 
Contact us

Explore more

How to choose the right SOC services in 2026
Blog

How to choose the right SOC services in 2026

Seven questions to ask before choosing a SOC service and managed SOC provider.
Sicra SOC strengthens your organization’s cybersecurity
Blog

Sicra SOC strengthens your organization’s cybersecurity

Sicra Managed SOC monitors your IT environment around the clock and responds to cyber threats.
How Sicra SOC detects cyber threats
Blog

How Sicra SOC detects cyber threats

How Sicra SOC detects and responds to cyber threats before they cause significant damage.
Sicra’s first intern gets the opportunity to work closely with the leadership team
Blog

Sicra’s first intern gets the opportunity to work closely with the leadership team

Oscar Dennett is Sicra’s first intern, working closely with company management.

Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact
Tel: +47 648 08 488
E-mail: firmapost@sicra.no

Drammensveien 151, 0277 Oslo

Follow us on Instagram

Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
iso9001-white-removebg-preview
ISO 9001 compliance
Sicra Footer Logo
Sicra © 2025
Privacy Policy