A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Cybersecurity Director / CISO at Nederlandse Spoorwegen
On the Edge of Autonomy: European Critical Infrastructures and Cloud Sovereignty


Author Bio: Dimitri van Zantvliet is the cybersecurity director and CISO of Dutch Railways (Nederlandse Spoorwegen). He's also Co-Chair of the Dutch and European Rail ISACS and European Railway CISO Forum, a cyber columnist/author and a regular speaker at international conferences, chair of the Dutch CISO Foundation and member of the supervisory board of the Dutch Anti Online Child Abuse foundation OffLimits.
Dimitri holds an international master’s degree in business administration and cyber certificates such as CISSP, CRISC, CISA, CISM, CDPSE, CIPP/E, CIPM and FIP.
In the rapidly evolving world of cybersecurity, critical infrastructure sectors across Europe increasingly leverage cloud technology to enhance operational efficiency, resilience and innovation. As the chief information security officer (CISO) of a leading European railway operator, I am acutely aware of the unique cybersecurity challenges and considerations we face, particularly in the realm of cloud security. This article explores the delicate balance between the need for sovereign cloud solutions and the realities of the dominant market power wielded by large cloud service providers within the context of European critical infrastructure.
The strategic importance of cloud security for European critical infrastructures cannot be overstated. Cloud technologies offer unprecedented scalability, flexibility and efficiency, enabling us to manage vast datasets, deploy advanced analytics for predictive maintenance, and enhance customer experiences. However, the adoption of cloud services also introduces complex security challenges that must be walked with care, especially given the heightened risks associated with critical infrastructure systems.
One of the primary concerns for European critical infrastructure operators is the necessity for sovereign cloud solutions. Sovereignty in cloud services refers to the ability to have complete control over data and operations: where it is stored, how it is processed, and who can access it. This is not merely a matter of data protection; it's a matter of national security. European regulations, such as the GDPR, NIS2 and the CSA EUCS, mandate strict data residency and privacy requirements, which become even more critical when dealing with the sensitive information that underpins our continent's energy and transport networks.
‘Sharing best practices, threat intelligence, and technological innovations will enable us to collectively enhance the security and sovereignty of our critical infrastructures.’
The drive towards digital sovereignty has been further amplified by the European Union's efforts to reduce dependency on non-European technology providers. Initiatives like Gaia-X aim to create a federated data infrastructure that upholds European standards for data sovereignty, transparency and interoperability. As operators of critical infrastructure, we are encouraged to prioritise solutions that align with these values, ensuring that our cloud architectures support the strategic autonomy of the European digital economy.
However, the reality of the current cloud ecosystem presents a significant challenge. The market is dominated by a few large, predominantly non-European, cloud service providers. These providers offer robust, mature solutions that are difficult to match in terms of reliability, performance and global reach. Their economies of scale allow for cost efficiencies and a pace of innovation that is challenging for smaller, sovereign cloud initiatives to compete with. Moreover, the comprehensive nature of their offerings, from infrastructure to platform and software services, creates a convenience and integration advantage that is highly attractive for complex, multi-faceted operations that many critical infrastructure operators need.
This dominance poses a conundrum for European critical infrastructure operators. On the one hand, we have a strategic and regulatory imperative to adopt cloud solutions that ensure data sovereignty and align with European values. On the other hand, we must walk a thin line in a market shaped by a few powerful providers whose solutions are often indispensable for our operational needs.
The balance, therefore, lies in a strategic, multi-faceted approach to cloud security and sovereignty. First, it involves actively participating in and supporting European cloud initiatives, contributing to the development of a competitive, sovereign cloud ecosystem. Second, it requires a pragmatic engagement with large cloud service providers, leveraging their capabilities while implementing robust data governance, encryption, and access controls to protect sensitive information. This dual strategy must be underpinned by continuous risk assessment, ensuring that our cloud architectures evolve in alignment with emerging threats and regulatory changes.
Moreover, collaboration is key. By working together with other operators, regulatory bodies, and technology providers, we can foster a more resilient and sovereign cloud landscape. Sharing best practices, threat intelligence, and technological innovations will enable us to collectively enhance the security and sovereignty of our critical infrastructures.
In conclusion, as European critical infrastructure operators, we are on the edge of autonomy, navigating a complex landscape where strategic imperatives for sovereignty intersect with market realities. By adopting a nuanced, collaborative approach to cloud security, we can ensure that our move to the cloud not only enhances our operational capabilities but also aligns with the broader strategic goals of digital autonomy and resilience. I am positive we can achieve that together!