Kevin Dominik Korte: IT Innovation Strategist, Board Member. Expert in identity management, AI and open-source solutions.
The age of global cloud services is coming to an end. Incidents like Microsoft allegedly sharing emails belonging to the Dutch civil service point to a deeper issue that enterprise leaders continue to underestimate: our assumptions about technology no longer match the world we operate in.
For decades, organizations have built digital strategies on a set of implicit beliefs: that hyperscalers are inherently secure and work in their best interests, that cloud platforms reduce risk and act as neutral parties, and that compliance equals safety. These assumptions were not entirely wrong in the past, but they are increasingly misaligned with today’s geopolitical, technological and operational realities.
The Collapse Of Implicit Trust
Scale does not guarantee control. In fact, it often introduces new layers of opacity. When governments entrust sensitive communications to global platforms, they are not just outsourcing infrastructure. They are inheriting, or buying into, complex dependencies that extend beyond their jurisdiction.
What makes such incidents particularly concerning is the systemic nature of the risk. Cloud ecosystems are deeply interconnected. Identity systems, logging mechanisms and API integrations form a web where a single misconfiguration, vulnerability or cross-border connection can cascade across tenants and borders.
This is where traditional security and ownership thinking break down. Many organizations still operate under a perimeter-based mindset. Just as the physical border defines their office, they believe their domain defines the network. In reality, IT infrastructure has become increasingly decentralized.
These changes require a shift in how we look at our IT set-up, both from a technical and philosophical angle. Trust must become dynamic and verifiable, not simply assumed. Likewise, organizations cannot outsource accountability for governance and resilience to vendors. Cloud providers are partners, but preserving visibility, control and informed decision-making remains an internal responsibility.
The Importance Of Sovereignty
For years, sovereignty was often framed as a political or regulatory concern. The corollary was that it could be addressed through data residency requirements or contractual safeguards.
Sovereignty is fundamentally about control. Who can access your data? Under what conditions? And perhaps most importantly, who can compel access? In a world where legal jurisdictions intersect with cloud architectures, these questions cannot be answered with simple checkboxes.
Organizations must therefore start recognizing that sovereignty is not a feature but an architectural outcome. It requires deliberate design choices, from encryption strategies to workload placement to deliberate vendor diversification.
Sovereignty does not mean abandoning global platforms altogether, though. It means engaging with them differently. The aim is to understand their operational boundaries, their legal exposures and their failure modes. It also means investing in hybrid and multi-cloud strategies, not as buzzwords for slick marketing, but as tangible mechanisms to build resilience and retain control.
The assumption that one provider can meet all the various technical, legal and strategic requirements of an entity—whether it’s an enterprise or a government organization—is increasingly untenable.
Why Vendor Dependencies Are An Increasing Risk
As enterprises layer more services, integrations and automation into their environments, vendor dependencies, including in AI, become both a necessity and a liability. When a single vendor controls essential parts of your ecosystem and offers no portability, it creates a dependency that is hard to break. Likewise, dependencies open the door for excuses. “It’s just too hard to migrate” becomes the argumentative fig leaf to accept shortcomings rather than push for change.
What’s more, dependencies can also hide complexity, create blind spots and obscure accountability. In many cases, tech teams are not failing due to a lack of skill or effort. They are operating within systems that are inherently difficult to understand.
This is where a new set of assumptions must emerge. Simplicity is a strategic advantage, and so is control. Open source can also play an important role by increasing transparency and reducing dependence on proprietary tooling. While they are not a substitute for sound architecture or governance, they can give organizations greater flexibility and leverage as their technology environments evolve.
The hard truth is that leaders need to ask more probing questions about the technologies they adopt. Not just “What does this enable?” but “What does this obscure?” Not just “How fast can we deploy?” but “How well can we understand and govern what we deploy?”
From Convenience To Conscious Design
Perhaps the most pervasive assumption that needs to change is the idea that convenience should drive architectural decisions. The rise of cloud computing has conditioned organizations to prioritize speed and ease of use. While this has unlocked tremendous innovation, it has also introduced systemic fragility.
When abstractions become so high-level that underlying risks are no longer visible, organizations lose the ability to make informed decisions. Luckily, the path forward is not about roundly rejecting modern platforms but engaging with them more consciously. This means investing in internal expertise and open source, even when outsourcing infrastructure. It means building capabilities to validate, audit and challenge vendor assumptions. And it means recognizing that resilience comes from solid design and quality engineering.
A changing world does not simply demand new technologies. What we need is new thinking. The organizations that I believe will thrive are not those that adopt the largest number of promising tools, but those that question the assumptions behind them and then act on their insights.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


