Transcript
and you only start looking at it from the technical perspective, which is, oh, okay, I have a data center here, I need to have a data center there, or I'm going to replicate my data and so on, I think that you're not necessarily starting on the right foot. It is absolutely essential to have the technical discussion, but you need to understand what are the legal implications of why, or rather, so first of all, why do you need to have data sovereignty in place? And what is the outcome you want to achieve with that? So it is a joint effort between your risk and compliance organization, your information security organization, and your IT organization. Hello, everyone, and welcome to Strive, the podcast where we explore what it means to be cyber-ready one conversation at a time. My name is Alex Zinnen. I lead Commvault's service provider managed services business as well as our digital sovereignty initiative. If this is the first episode on the Strive series on digital sovereignty, it's a topic that moved fast from being a simple compliance checkbox to something that company boards are generally wrestling with. I've been leading the company's sovereignty strategy for a while now, so clearly I have some opinions and understanding of where the conversations and frameworks are moving, where moving right, moving wrong, but as we get into the depth of it, we will get into the architectures and design questions in the later episode, but today I wanted to start the series by bringing an outside perspective. Our guest today is Max Martellaro, who has been watching this space closely from the EMEA vantage point, and Max, welcome to the podcast. Thank you for having me, it's a pleasure. Absolutely, thank you, and I wanted to start with the perspective on what sovereignty actually means. The word sovereignty is not new, but recently over the last probably two, three years, it's been in the mouth of every hyperscaler and every service provider on their websites, but from your perspective, how you see that, what does it really mean? Sovereignty, what does it actually require legally, technically, operationally? What is your view on that high level? Yeah, thanks again, and I hope that we're gonna have some good opinions because I'm also opinionated about that sort of thing from different perspective. So the first thing I want to say, I'm working for Ospium Data Group, is that we are not a legal consultancy, right? So take anything I may say which has legal implication with a huge grain of salt, please. So if we look at it from a legal perspective, what we're talking about here is primarily looking at what is the jurisdiction in which the operations are happening, right? So if you're saying that you're a sovereign solution and you're based in France or in Germany, so my first expectation, the first thing I'm gonna look like is are you really operating from Germany or from France? That's what I would say, maybe to put it in plain words, right? So that's an important aspect. There are a lot of caveats to that. The other aspect is, of course, what does it mean? If we take sovereignty as a term itself, it means I am sovereign, I make my own decisions, I am not influenced by anything going on outside, right? So that's what I would say to frame the legal aspect. From a technical perspective, there again, we might have some kind of lines blurring and there we can say, what are we talking about? Are we talking about the location where a data center is technically located and built? Are we looking at the technology that is inside the data center? Are we talking about the hardware, about the software, the operating system? Are we talking about cloud services that are provided and so on, right? And we're also talking about the data, so there's quite a lot to kind of unpack here. Are we able to protect ourselves from foreign interference or not with this technology stack? And I mean, I could go on and on, but if we start with the definition here and we are going to end on what it means operationally, to me, that means, how do we operate? How do we run this stack? And by how we run it, it means what kind of people am I hiring inside the team? Are we kind of making them go through background checks? What are their citizenships? Is the team located here? Is it located offshore and so on? So there's quite a lot, but I hope that gives you already a bit of an idea of how I do see things or how do we see things at Osmium with my business partner, Arian Timmerman. Thank you, Max. And I think it's going to be pretty much aligned with how we view that, because as we started to tackle the problem of sovereignty overall, we realized that, hey, look, it's not going to be a binary switch on or off, right? There is aspects, there is different dimensions of sovereignty. And for us, it was important to establish a common vocabulary, a common framework that we could apply actually to multiple different geographies, to different markets, and how we define it as a collection of main pillars, data locality, technological sovereignty, operational sovereignty, jurisdictional sovereignty, which I think is very much aligned with what you just described. But kind of as we analyze the different regulatory aspects and different approaches that countries and regions take, we pretty much map it to those four categories and we analyze it from that perspective. As you see it, Max, where do you think the organizations have most of the, or most likely have the blind spots as we think through what sovereignty really means? Well, it's going to vary from org to org, I guess, but I think that the most misunderstood thing, when we hear at least big hyperscalers or CSPs talk about data sovereignty, is the legal and jurisdictional aspect, right? We tend to see a lot of emphases on, we have a EU-based data center, we have, you know, EU personnel and so on, but, you know, when things go sour, you're going to get into litigation, right? And what is going to be the key thing here is, you know, who's taking a decision to judge on what is right and wrong, and then who can apply pressure. And you know that we'll get to that later in the conversation about geopolitical anxiety, as you very nicely put it. We're going to get into that. So I think that these are the key aspects, right? Technically, I think that everybody seems to understand what's, you know, what's going on. But, you know, over to you, because I think we have quite a lot to impact today. That's right, that's right, exactly. It's interesting. I think the notion of sovereignty is not a new one, right? We've seen sovereignty in the telecom environment where certain countries were, or vendors of the certain countries were prohibited from playing in the markets. We've seen GDPR, right, as maybe a certain aspect or flavor of sovereignty and so on. Do you see that those are related to each other with the sovereignty as we see today as well? I would say that there is a kind of a link between those at the very least, right? So, you know, GDPR is a privacy and consumer rights protection law in the EU. And so it kind of dictates, you know, how you handle customer data, what rights customers have. It also has some kind of implication from a data locality perspective or rather cross-border sharing of the data. You know, I mean, this is really controversial. There's been some, you know, cross-border acts with the US which were, you know, then rebuked. But the relationship is there anyways because you have legislation in the EU. So you have the GDPR, which is at the union level, and then you have specific country laws, right? You have the BDSG in Germany. I'll try to say it, Bundesdatengesetz, right? I get bonus points for that. So it says where you store data from German customers. So you have a data locality obligation and that data locality obligation is a sort of, you know, sovereign requirement. You cannot store your data wherever you want. You may have, you know, other sort of regulations that come into play here. So I would say that, yes, there is a relationship somehow between GDPR and data sovereignty. I wanted to talk about specifically what's happening in EMEA, right? From your perspective, you're right in the middle there. What do you think is pushing EMEA right to the forefront of digital sovereignty? What have European governments, enterprises, overall the community, what have they learned about sovereignty that is so different from, let's say, North American or Asia Pacific or other markets that is really pushing them to be very, very serious about it, especially in the last few years? What's your view? So that is a huge question and I do have a long answer to that, but let's make sure you correct me so I'm not kind of missing the point, right? So we do have a thing we are actually aware of in the EMEA region. We are not a technology leader on the hardware side and we are definitely not a technology leader on the cloud side and we are neither a technology leader on the software side, although we may want to argue around that, right? But overall, we are, like every company in the world, we are using technology massively. It fuels all of our companies and systems and so on and processes, business processes, but we do not own the stack. We have no control over that. So we are acutely aware that we are dependent on foreign technology and the push for sovereignty wasn't that important still if you think about it a few years ago when we had, let's say, a relatively relaxed kind of geopolitical situation. And there's always been a sort of, you know, cooperation or would I say competition is the right word between the US and the EU, but it was rather, you know, mild and in terms and so on. The changes we've seen recently on the politics side and although I do follow geopolitics, I'm not claiming to be an expert here. I'll just focus on the technology side. We are in a situation now where anything can happen. We have no kind of limits or boundaries anymore. What seemed impossible could happen the day after, right? So organizations, especially governments, are also trying to figure out how do we hedge against that risk? Because in the end, my perspective on that and one shared by Ariane as well is that we see data sovereignty more as a kind of a risk-based topic for conversation, right? It's not just that much about the fact that we want to own our stuff. It's just that we want to continue doing business. We want to continue running the show without disruptions, right? So just like you will be doing disaster recovery, business continuity, this becomes part of that perspective. So I would say that this is kind of the main driver that we're seeing over there, right? If you think about, you know, if you think about other jurisdictions or other regions, it's somehow different. A U.S. company, it's totally oblivious to what we're talking about here. You know, they have the technology, they have the government backing them and so on. Business as usual, no problem. You're in North America, you're somehow bound to that big neighbor, which is over there, and you don't have that much of a margin, you know, to do things. The Latin American region, you know, APAC or, you know, even late-time APAC and so on, there's something over there, but let's say they're not exactly into the same aspects. I mean, if you look at it, again, I don't want to deep dive too much into that, but if you're located in the Southeast Asia, you do have ready access, you know, to semiconductors and so on. So, you know, anyway, let's maybe, you know, yeah, I would say, yeah. So I would put it there, maybe if you have a perspective on that specifically, I mean, if we align on views or if you see things differently. Yes, definitely. I mean, there's definitely, we see a lot more regulatory pressure, and I think the perception of the market is that the Europe EMEA perceives themselves to be much more exposed than in other regions, right? And there is more sensitivity there, which was driving an evolving set of regulations and government actions. And I meant to talk to you about this as well, since you're right in the middle of it. How do you see that progression and evolution of the regulatory framework, what's happening in EMEA? So this is moving. This seems to be moving fast, maybe not fast enough based on, you know, where you are. If you're on the hyperscaler side, you might be happy about that. If you're on the other end, you might not be happy about that, but we kind of start seeing some grassroots initiatives, you know, by local governments or cities, larger cities that are taking action on their own and decide they're going to move to a specific stack. There was an initiative recently, I think a couple of months ago from France as well, where they decided to build their own, you know, open source based stack for government services. So this is clearly evolving, but not to the point maybe where there is a clear uniform regulation across the board at the EU level. That said, there are some regulations, I would say around data sovereignty for cloud providers, but it's still kind of very disjointed. I mean, overall, I would say that the overall feeling is a feeling of being threatened somehow, right? So we realize that things could go wrong and soar quite fast. And we see regulations evolving at the EU level, as well as at the country level, as you said, right? Driven by different perspectives, I guess, and different perception of the threat in each particular country. Exactly. And it's a very important thing to point out, right? The European Union is not necessarily a very solid and compact unified block. It's still made of, you know, various countries, 27, 28, I forgot how many we have now, but anyways, a lot of different perspective. And you can see it in the context of the global tensions, which are happening, for example, with the war in Ukraine or other things. The perspective, even though you would say that everybody's showing a unified block, the strategic perspective of a country like France is not necessarily the same as Germany has and so on, right? France has always wanted to have some kind of strategic autonomy on things. So this is really going to evolve, you know, from country to country. Right. And it does seem to me that it is there to stay. I mean, as you and I know, it is much easier to pass the regulation and legislation than to withdraw it. So that's why we're taking it so seriously. This is not just a temporary phenomena. It will define the market for the foreseeable future. And what's interesting is also is that in your research, Osmium, you identified data sovereignty as one of the top trends, right? In the data protection transcape. Is regulatory pressure the main drivers there? Do you think that it's ranking it so high or is there something else there? Well, you know, the regulatory aspect is important. The geopolitical anxiety, I love the way you put it. It's very, very, you know, nice and fluffy, I would say even. I would say, yeah, the strategic, the geopolitical tension is very important as well. But one thing to be said, you know, in all fairness, right, the research, and I mean, the goal, what we're doing is we're really trying to focus on giving an EMEA perspective to things, right? So that's the way we see things as analysts and that's the way we see things in EMEA, right? So it's a perspective in the end. But from that perspective, yes, it is a blend of both regulatory pressure, which is, I would say, quite not there yet. It has started thanks to GDPR and those data locality requirements, but it's going to keep going on and also the geopolitical tension. I think that when you see what the, you know, U.S. government has done, calling it U.S. government to simplify, right? But, you know, this order to disconnect that judge from the hag from Microsoft 365, it might seem anecdotal, but I think it shows the power of what you can do. So as someone in the executive branch of the U.S. government, you can impose on a multinational company that they have to cut access to a service. So we will get to that later, but you think about the implication of that scale, right? So this is, yes. It represents a significant risk. Yeah, exactly. So that is why we have flagged that as a very important topic for organizations. That's something we'll have to- I think this nicely leads into our kind of next section of the ecosystem and that is the reality check. In your research, you specifically pointed out, like one of the conclusions is that any U.S. operated cloud provider carries, still carries residual sovereignty risk, regardless of where the actual data centers are located. Can you speak more about this? Yeah, so again, with the disclaimer that we are not lawyers, right? There are several aspects to that. The first one, we were getting back to what we discussed at the beginning. In fact, there is jurisdictional, right? So if you are incorporated, I don't know, typically in Delaware or one of those states which have very, very permissive laws, very much in favor of companies, then whatever happens, even putting aside the fact that someone will flip the switch off and you're done with your whole cloud infrastructure, you need to deal with the legal implications in the United States. So the U.S. law is in effect applying and you may have, you know, some legal implications or legal obligations to fulfill, but this could be, and again, I'm not a lawyer, this could become null and void because you've voluntarily accepted by signing a contract with a U.S. company or an end user license agreement that you will subject yourself to the regulation of that state or that country. That's the first aspect. The second aspect is if you think about the technical implications of what it means, right? So example, they say, yeah, we're running, we have a cloud which is running in the European Union. I'm not going to name any of the three hyperscalers or the four, five plus which are around, but what is that really running entirely in isolation out of the European Union? By that, what I mean is that you might have backend dependencies that you're not aware of. So think about the fact that any U.S. East One outage on Amazon is typically going to impact most, if not all of Amazon AWS infrastructure, right? So is there anything that goes back to that? Even if we put aside the geopolitical risks, if there is something that happens in the U.S. at the infrastructure layer, it might be cascading all the way down to the European Union. And then you have all of those other implications which are about what services are sending that over there. Is there any telemetry data? Where are we employing and so on? I mean, it could go on and on. Right, yes. Thanks, Max. It makes a lot of sense. And then what we've observed is also that there is two distinct approaches that companies take in offering the digital sovereignty offerings. One is to establish or attempt to establish local operations that get as close to qualifying for local sovereign offering as possible. The other is to rely on the local partners, such as service providers and so on. And by the way, Commvault, we take both approaches simultaneously, where we are deploying our Commvault cloud services within the sovereign offerings of the hyperscalers. And then we're partnering up with the service providers. I wanted to know your view. How do these correlate? Are they addressing the same market? Are they going to be comparable? Is it going to be different from the perceptional standpoint? Like, what are your thoughts on the two approaches here? I mean, I would say both approaches have their pros and cons. I mean, if you are a, the first thing is the economical aspects, right? If you have a huge contract with AWS, Microsoft, Google, and you have credits or whatever, then you've already kind of committed that money upfront or you are going to commit it anyways. It's budgeted, it's here in your sheets, whatever. So you have a rationale to kind of spend that money that is already committed versus going to a specific, you know, local cloud provider, right? At the same time, you could argue, as we've already done a couple of times already in this conversation, the fact that it's not going to be 100% perfect. On the other hand, you might have some very specific stringent requirements could be whatever regulated application, let's say, or you have super critical, ultra sovereign requirements and now we're talking about governments or the defense industry, we're not talking about, you know, business as usual stuff. And there you may have a very vested interest in partnering with a country-specific service provider that you know, that has its people on the ground, that historically has ties with the government or whatever. So I think that there is a merit in considering both approaches and maybe blending. The key thing is that there is no kind of perfect situation. Definitely. Yeah, I think we'll probably get to that because I have some ideas on, you know, what good looks like, so maybe we'll discuss that. It's definitely not a binary switch. And there is, you know, my personal view is that there will never be 100% sovereignty, right? For the topics that you and I discussed at the beginning of the global economy, global relationships and dependencies and so on. And our view is that the decision about which service to go with will be a business trade-off. A trade-off between the cost, the risks and compliance and the level of compliance and level of exposure. From your standpoint and what you are seeing, I'm sure you're engaged with a multitude of providers and potential customers, the end users in Europe. From your perspective, how do enterprises evaluate the services that they see? Let's say if I'm a CIO, CISO of a company and a hyperscaler comes to me or a service provider comes to me, what are the pointed questions, the first order questions that I should be asking them, you think? Yeah, so maybe I want to jump back on what you said before, before I get into your question, right? I think that there's one thing which I learned over my career in IT, starting from the humble, you know, grassroots of being a system administrator, who thinks that a technical solution solves everything. You always end up in the end discussing about business use case, you know, efficiency of the solution and how much money you can throw at the problem, right? And you inevitably get to the point where, yes, you could live in a perfect Goldilocks world or zone where you have the most sovereign solution, whatever, but is it economical to pursue? Does it address your business problems and so on, right? So if you're talking about, you're hosting your application to book, you know, I don't know, meeting rooms or coffee lunches or whatever in the cloud, I guess you don't really have a sovereignty problem to address, right? If you have very confidential plans about your business because you're competing against Airbus, against Boeing, for example, you have a totally different challenge to sort out. So now getting back to your question, which is about what people are typically looking for. I don't have a crystal ball, unfortunately, but what we've seen at Osmium, we know when we engage with Ariane and others about with the customers, about what we see there, it kind of depends on the audience, right? I mean, here we are talking about CIOs and CISOs and those people naturally have a kind of a business oriented mindset, right? How do we help the business? How do we help sort out the problem? But it's going to depend on the audience. And if you are talking with IT people, they are typically going to, I'm an IT guy as well, so we're typically going to start looking at, okay, what does it mean technically? What do we need to do here? What do you, you know, so typically when the organizations are discussing about sovereignty, you know, they're going to think about the data locality of the data center. They're going to take it as a geolocation thing. Is it located in Paris? Is it located in Frankfurt? Whatever. And maybe they're going to start thinking about some other collateral stuff like, you know, data movement, where are we replicating our data? I mean, that might be interesting in the context of cyber resiliency and so on, right? So that's some of this stuff. But the thing that is sometimes overlooked is what are we actually running in the cloud? You know, why do we need to put it here, over there, and so on, what kind of application we're running, right? So, and I think that you mentioned that before we had the conversation, before we started recording in the, you know, kind of concept for the idea of this episode, is the, let me think on that. It was the part around what organizations should do. I think that you can have a discussion with your service provider or a cloud provider, a hyperscaler, about data sovereignty, but I think that you first need to understand what you're trying to achieve, right? So if they come in and they tell you, yeah, we have a super new sovereign cloud, yeah, fine, let them talk, good. But I don't think that that's the right moment to start engaging them and having a deeper conversation. I think you need to start looking at what you have in house and what you want to address. That was my next question, like if I'm a CISO, and hopefully you and I have given them enough information to now go back and look at whether they're doing things right. And let's say if I'm a CISO and I know like, oh my God, look, I haven't actually gone deep enough, right? So is this where you start? Are you start with the applications or maybe you start with different classes of data, how sensitive those classes are and so on, like maybe continue on your thoughts trail there. Yeah, so there is a thing that Ariane coined, I think a few months ago, when we're having a conversation with some vendors. And the thing that he came up with was, you need to have a data strategy. And I think that's precisely that. I think you need to have a strategy in place around what kind of data, what kind of footprint you have in your organization. And of course, that always necessarily ties back to the business processes, the applications that you're running and so on. You need to understand your landscape, what are the key business processes you're running, how they're critical to supporting your operations or not. So it is not very far away from what you would do in defending a business continuity plan in the end, right? Because you need to make sure that your business can operate, survive and thrive in case of an advert event. And if you take the risk-based perspective, then data sovereignty event, data sovereignty risk is one of the risk, just like you could have a flood, a natural disaster, a terrorist attack, whatever happens. A data sovereignty attack, just like you have criminal groups, you could have a state-sponsored denial of service by cutting the access to your cloud provider. If you look at it from this purely approach, and how do I defend against that? How do I understand? And to understand that, just like you do the same, your crown jewels and your applications, you are doing exactly the same when you start having the data sovereignty conversation. That's how we're approaching as well. We think that as part of the sovereignty conversation, we absolutely have to address resiliency. And this goes into both cyber resiliency and business resiliency overall. I mean, as you mentioned, the businesses need to be able to recover from the adverse type of events of different classes, including sovereignty-related ones. And gonna go on into, I guess, a little bit to my next question. Ignoring cyber resiliency is one of the mistakes. Ignoring resiliency overall is one of the mistakes. Are there other mistakes that you would like to warn our listeners about that they should avoid as they get on the journey about sovereignty? What do you think? Well, I was pointing out to that a bit in the beginning. This is definitely not a technical only question. If you start discussing data sovereignty and you only start looking at it from the technical perspective, which is, oh, okay, I have a data center here, I need to have a data center there, or I'm going to replicate my data and so on, I think that you're not necessarily starting on the right foot. It is absolutely essential to have the technical discussion, but you need to understand what are the legal implications of why, or rather, so first of all, why do you need to have data sovereignty in place? And what is the outcome you want to achieve with that? So it is a joint effort between your risk and compliance organization, your information security organization, and your IT organization, right? The three need to work hand in hand. You know, whether you have a data compliance officer, a data officer, CDIO, whatever is the term these days, those people need to work hand in hand, and they need to work hand in hand in the benefit of the organization, right? So I would say to me, that's the main maybe mistake or shortcut would be to treat these as a purely technical topic. It is not. Exactly. Max, thank you so much. I know it was, we only have 30 minutes, and it's a huge area to cover in a short conversation like that. We will continue this series, but thank you, Max, so much. It's very insightful. Thank you very much. The goal here is to decompose and kind of to separate marketing from reality and give our listeners, our viewers, a bit of a practical perspective of what sovereignty is really and is not and how to approach it. And I think you did absolutely fabulously. Thank you, Max. Really appreciate it. Thank you so much. It's been a pleasure. All right. So from the very beginning, let's see. Okay. Got it. Okay. All right. Hello, everybody. And welcome to Strive, the podcast where we explore what it means to be cyber ready, one conversation at a time. My name is Alex Zinin with Commvault, and I am leading Commvault's MSP, service provider business, as well as the digital strategy. Do that again. You still with me? You still with me? All right. Hello, everyone. And welcome to Strive, the podcast where we explore what it means to be cyber ready, one conversation at a time. My name is Alex Zinin with Commvault. I lead Commvault's service provider managed services business, as well as our digital sovereignty initiative. If this is the first episode on the Strive series on digital sovereignty, it's a topic that moved fast from being a simple compliance checkbox to something that company boards are generally wrestling with. I've been leading the company's sovereignty strategy for a while now. So clearly I have some opinions and understanding of where the conversations and frameworks are moving, we're moving right, moving wrong. But as we get into the depth of it, we will get into the architectures and design questions in the later episode. But today I wanted to start the series by bringing an outside perspective. Our guest today is, our guest today is Max Martillaro, the co-founder and chief research officer of the Osmium Data Group. Max, welcome to Strive. Thank you. Is it better? Yeah, I shouldn't have to talk like that anyways. Okay, so you can, you can cut it. Okay.