top of page
yava_white_logo.png

93% of Boards Are Discussing Digital Sovereignty. Only 14% Can See the Full Dependency Chain

Sep 10
5 min read

New Capgemini research shows digital sovereignty has reached the boardroom, while fresh concern around subsea cables demonstrates why understanding the physical and technological dependencies behind critical services is becoming increasingly important.


Submarine cable-laying ship docked at Bremerhaven, with large cable-handling equipment and industrial machinery visible on deck.
The digital economy ultimately depends on physical infrastructure, including the subsea cables connecting countries, data centres and communications networks.

Digital sovereignty has moved rapidly up the corporate agenda.


Research published by Capgemini on 8 September found that 93% of organisations have discussed digital sovereignty at board level.


Yet only 14% report having end-to-end visibility across the dependencies in their wider technology ecosystem.


Those two numbers capture a significant challenge.


Organisations increasingly understand that control over critical technology matters. Many still lack a complete picture of what their most important services depend on.

Cloud providers are one part of that picture.


Behind a critical digital service can sit identity systems, data centres, network carriers, fibre routes, electricity supplies, software vendors, hardware manufacturers, integration partners and specialist engineers.


A weakness several layers down the chain can still reach the end user.


Digital Sovereignty Has Become An Operational Issue


Capgemini's research is based on a survey of 1,300 business and technology executives.


It found that 59% believe full digital sovereignty is unrealistic, while two thirds favour a model Capgemini describes as resilient interdependence: retaining control over critical technologies while continuing to work with strategic partners.


That reflects how most large technology environments already operate.


Modern organisations rely on extensive ecosystems of cloud services, software, hardware, communications infrastructure and third parties.


The challenge is knowing where those dependencies create unacceptable exposure.


Capgemini found that 86% of organisations have significant exposure to foreign or externally controlled supply chains.


Switching can also take time. Some 36% said moving away from a critical technology provider would take more than 12 months, while one in ten reported having no viable alternative provider at all.


Those findings turn sovereignty from an abstract policy question into something more immediate.


If a critical supplier became unavailable tomorrow, what would happen next?


The Dependency Chain Eventually Reaches The Physical World


Events reported this week provide a useful reminder.


On 10 September, Reuters reported that Britain, Norway and the United States had disrupted what Western officials described as a Russian operation involving vital subsea fibre-optic cables near Svalbard.


According to the report, Russian submersibles linked to the country's deep-sea warfare capability had simulated an operation around cables connecting Svalbard with mainland Norway. The cables remained intact.


The incident matters because subsea infrastructure carries enormous volumes of digital traffic between countries.


Cloud computing feels remote to the user. International connectivity still has to travel through cables.


Data appears instantly on a screen. Somewhere behind that interaction sit physical facilities, electricity supplies, networks and equipment.


The further organisations move into cloud computing, AI and connected operations, the more important that underlying dependency chain becomes.


Can You Map What Keeps A Critical Service Alive?


Sumit Dubey, Partner and Head of Asia at YAVA, says many organisations understand their immediate suppliers far better than the infrastructure behind them:

“A lot of organisations can name their cloud provider. Far fewer can map everything that has to work for one critical service to stay live: identity, connectivity, power, the data centre, specialist suppliers and the people who know how to recover it. You have to follow that chain much further than the application.”

A useful dependency map therefore starts with the business service.


Take something the organisation genuinely needs to keep running: payments, passenger processing, emergency communications, industrial production or access to a core government system.


Then work backwards.


  • Which applications support it?

  • Where are they hosted?

  • Which identity systems control access?

  • How does traffic reach the environment?

  • Which network providers and physical routes are involved?

  • Where does the electricity come from?

  • What specialist hardware is required?

  • Who can repair or replace it?

  • How quickly could an alternative be brought online?


This process frequently reveals dependencies that were invisible when the organisation looked only at the application architecture.


Supplier Concentration Changes The Resilience Calculation


The Capgemini finding that one in ten organisations has no viable alternative to a critical provider deserves particular attention.


Some dependencies are difficult to remove.


Moving a major workload can take months. Specialist hardware may come from a small number of manufacturers. Regulatory constraints may limit where data can move. Replacing an integration partner may require people who understand years of accumulated technical decisions.


The goal for organisations should therefore be to understand where concentration exists and what can be done about it.


Sometimes an alternative provider is realistic.


Elsewhere, resilience may mean keeping spare components, creating an independent communications route, retaining internal expertise or designing a manual operating procedure that allows a critical process to continue temporarily.


For major infrastructure operators, the answer may also involve redundancy across physical sites.


The right response depends on the consequence of losing the dependency.


The 14% Figure Matters


Board-level conversations about sovereignty are useful.


Operational visibility determines what an organisation can actually do with them.


If a company lacks end-to-end knowledge of its technology ecosystem, decisions around resilience, procurement and risk inevitably rely on partial information.


That becomes particularly important during periods of geopolitical tension.


Governments can impose new requirements. Suppliers can become unavailable. Sanctions can affect technology access. Physical infrastructure can be disrupted. A vendor can suffer an outage far outside the organisation's direct control.


Knowing the dependency chain gives leadership more options before one of those events occurs.


What Should Technology Leaders Do Now?


The first step is to identify the services whose interruption would create the greatest operational, financial or safety consequences.


From there, map the dependencies beneath each one.


A practical review should answer four questions.


  1. What has to keep running? Prioritise critical business and operational functions rather than attempting to map every technology equally.


  1. What does it depend on? Trace applications, infrastructure, connectivity, identity, suppliers, facilities, power and specialist people.


  1. Where are the single points of failure? Identify components or providers where one failure could interrupt the whole service.


  1. How does recovery actually work? Document the alternative and test whether it can be activated in the time available.


A secondary connection provides resilience only when it can carry the required traffic. A backup environment helps only when workloads can actually move. A recovery partner needs the people, permissions and equipment required during the incident.

Testing turns the dependency map into something operational.


Sovereignty Is Increasingly About Choices Under Pressure


Capgemini's findings show how far digital sovereignty has moved into mainstream business strategy.


The most revealing statistic may still be the 14%.


An organisation with a clear view of its dependencies can decide where additional control is worth the investment, where partnerships remain sensible and where redundancy or alternative arrangements are required.


An organisation without that view has fewer choices when conditions deteriorate.


For governments, infrastructure operators and businesses running critical systems, that makes dependency visibility a strategic capability.


Because every digital service eventually relies on something physical, operational or human that has to keep working.


FAQs


What is digital sovereignty?

Digital sovereignty describes the degree of control an organisation retains over critical data, technology, infrastructure and operations, including its ability to manage dependencies on external providers.


How many organisations discuss digital sovereignty at board level?

Capgemini's September 2026 research found that 93% of organisations surveyed had discussed digital sovereignty at board level.


How many organisations can see their full technology dependency chain?

Only 14% of organisations surveyed by Capgemini reported end-to-end visibility into dependencies across their wider technology ecosystem.


Why does dependency mapping matter?

Dependency mapping helps organisations identify the technology, infrastructure, suppliers and people required to keep a critical service running. It can expose single points of failure and support better continuity and recovery planning.


How can organisations improve digital resilience?

Start with critical services, map the technology and physical dependencies beneath them, identify concentrated exposures, establish alternatives where possible and test recovery arrangements under realistic conditions.

Comments


bottom of page