Cloud Sovereignty Framework: Making Digital Sovereignty Measurable
Cloud Sovereignty Framework: Measurable Digital Sovereignty for the EU
Blog
Cloud-Native Insights & Expertise
Discover our latest articles about cloud-native technologies, Kubernetes, DevOps, and modern software development. From practical tutorials to in-depth analyses.
Latest Blog Posts
Stay up to date with our latest articles about cloud-native technologies, Kubernetes, and DevOps.
1219 posts
Cloud Sovereignty Framework: Measurable Digital Sovereignty for the EU
On October 5, 2025, it was revealed that an external support provider for the platform **Discord** was the target of a cyberattack. Personal data of users who had contacted Discord support in recent weeks was stolen. According to Discord, the core platform was not affected. The attack focused exclusively on the systems of the contracted service provider.
Data Act: Cloud Switching and Data Portability from September 2025
With the pilot project to introduce the AI assistant **F13**, Saarland is taking a remarkably clear path towards a digitally sovereign administration. Originally developed in Baden-Württemberg, the solution was specifically designed for the public sector, focusing on data protection, transparency, and control by governmental bodies.
Cyber Resilience Act: Requirements for Software Products from 2027
DORA: Digital Operational Resilience for Financial Service Providers
NIS-2 requirements and practical implementation for 18 critical sectors
On October 1, 2025, a data protection incident came to light that further shook trust in the digital credit industry: Schufa subsidiary **Forteil**, operator of the **Bonify** service, confirmed that **unauthorized access to user identification data** had occurred. This was not about abstract metadata or technical logs, but real personal data: **identity documents, addresses, photos, and video recordings**, captured during the **video identification process**.
Privacy by Design: Technical Implementation of GDPR Requirements
Overview of the EU regulatory landscape for software and cloud hosting
Cloudflare is far more than just a CDN provider. In addition to performance optimization and security features, the platform offers numerous tools that can be creatively used to address individual requirements in modern infrastructure setups—without necessarily relying on the paid Enterprise features.
With the **Digital Networks Act (DNA)**, the EU is preparing one of the most profound reforms of its telecommunications sector. The aim is to overcome regulatory fragmentation, accelerate investments in future-proof network infrastructures, and strengthen Europe's digital competitiveness on a global scale.
On September 24, 2025, SAP and OpenAI announced a new partnership: *OpenAI for Germany*. The goal is to bring artificial intelligence "made for Germany" to the public sector – responsibly, legally compliant, and sovereign. The project is supported by SAP and operated through their subsidiary Delos Cloud – based on Microsoft Azure technology.
The Reuters report is making waves: Nvidia plans to invest up to $100 billion in OpenAI. A move that impresses not only by its sheer scale but also by the structure of the deal. Nvidia aims not only to provide capital but also to supply the necessary hardware—thus securing the foundation for OpenAI's future data centers.
Hyperscalers have shaped the digital world like few other models. With the promise of unlimited scaling, global availability, and seemingly endless innovation, they have dominated an entire generation of IT strategies. However, upon closer inspection, little remains of this narrative: The business model of hyperscalers is still almost exclusively based on the sale of hardware—compute, storage, network traffic. Nicely packaged, globally distributed, encapsulated in APIs, but at its core, it's still the same logic: You rent machines.
When discussing digital sovereignty and modern IT infrastructures today, Kubernetes is unavoidable. In just a few years, this open-source project has evolved from a container orchestrator to a de facto standard, comparable in significance to the Linux kernel. To understand why, one must examine its architecture and take the parallels seriously.
Cloud-native software development is more than just a set of methods. It describes a paradigm that designs applications to function reliably in highly dynamic infrastructures—environments where servers, databases, and networks no longer exist statically but can be provisioned and removed via API.
On September 18, *golem.de* reported a security vulnerability in **Microsoft Entra ID**, discovered by security researcher Dirk-Jan Mollema, who described it as "probably the most significant Entra ID security vulnerability" of his career. Registered as **CVE-2025-55241** and rated as critical with a **CVSS score of 9.0**, the case exemplifies how vulnerable central identity and access platforms can be.
The news is making waves: Several npm packages from CrowdStrike – a company known for security and protection – have been compromised. What might seem like a footnote is actually a massive wake-up call for the entire software industry. This is a continuation of the **"Shai-Halud" campaign**, which had already been noted during the **Tinycolor attack**.
In recent years, *Cloud First* has been considered an almost unshakeable maxim. Companies of all sizes were encouraged to move their infrastructure to the public cloud as quickly as possible to ensure scalability, innovation, and competitiveness. For many, this sounded like a simple formula: the more cloud, the better. However, it has become apparent that this approach does not always deliver the promised solution—in fact, it raises new questions that are increasingly being critically discussed.
The European Union is on the verge of enacting one of the most profound intrusions into digital privacy since the inception of the internet. The draft law for the so-called "Chat Control," officially the "Regulation to Prevent and Combat Child Sexual Abuse," initially appears to be a necessary protective measure. However, in reality, it is a proposal that not only undermines encrypted communication but also questions the fundamental rights of hundreds of millions of EU citizens.
Since September 8th, concrete evidence has emerged that a number of extremely widespread NPM packages — including *debug*, *chalk*, *ansi-styles*, *supports-color*, and other core components of the Node.js ecosystem — have been compromised. According to public accounts, the maintainer was tricked via phishing into a fake NPM support domain, leading to the release of new, tampered versions that, in total, are downloaded billions of times weekly across the entire set, potentially infiltrating virtually every modern frontend, backend, and CI/CD pipeline.
At the end of July 2025, Meta released its latest quarterly figures – alongside strong revenues (22% growth to $47.52 billion, profit increase of 36% to $18.34 billion), Mark Zuckerberg primarily delivered one message: "Superintelligence" is within reach. Meta aims to "create a personal superintelligence for all people in the world."
The security of software supply chains is one of the central topics in IT security today. Companies are under increasing pressure to ensure transparency, traceability, and reliability of the software they use. A key tool in this regard is the **Software Bill of Materials (SBOM)**, complemented by automated scanning for known vulnerabilities – **Common Vulnerabilities and Exposures (CVE)**.