All articles
CybersecuritySovereigntyCloud

The Cyber Paradox: Sovereign Security on Dependent Ground

Europe has built genuinely good cyber defenders. The problem is where they stand.

Ilke Tosunoğlu
Ilke TosunoğluJune 4, 20268 min readUpdated July 20, 2026
A glowing EU shield of EDR, MDR and SOC capabilities standing on cracked ground whose foundations are labelled US cloud, identity backplane, and telemetry. The shield is only as sovereign as the dependent ground beneath it.

Part of the pillar series Sovereignty You Can Actually Operate.

Of all the layers in Europe's technology stack, cybersecurity is the one where the continent looks strongest. It has credible, scaled vendors: endpoint and anti-malware champions, some of the world's larger managed-detection providers, real depth in operational-technology security, privileged-access management, and cryptography. If you only read the vendor logos, you'd conclude Europe is doing fine here.

Then you look underneath, and the paradox appears. The high-value control planes of modern security (cloud-native security, hyperscale threat telemetry, identity, and the data layers behind detection and response) are overwhelmingly US-controlled. Worse, Europe's own security tools frequently run on the very US clouds, operating systems, and identity systems they are meant to protect. A cyber crisis in those layers wouldn't just be a security incident. It would be a sovereignty incident, expressed through the security stack itself.

Where Europe is genuinely strong

Let's give credit first, because the strength is real. Europe fields security vendors with global reach and growing revenue.

Vendor Base Scale signal
ESET Slovakia "Europe's biggest privately held cybersecurity company"; 2024 enterprise revenue +21% (ESET)
Bitdefender Romania ~$435M revenue in 2024, up 11% (ZF)
Orange Cyberdefense France €1.22bn revenue in 2024; 18 SOCs, 3,000+ experts (Orange)
WithSecure, HarfangLab, Sekoia, WALLIX, Stormshield FI/FR EDR, SOC/XDR, PAM, network security; ANSSI-qualified

This is a real industry. But notice the shape of it: Europe's strength is concentrated in services and labour (managed detection, SOCs, consulting, operational security) and in specific product niches. As the European Parliament's dependency study puts it plainly, "US and Israeli vendors dominate tools such as firewalls, identity management, and SIEM systems, while EU firms specialise mainly in services" (EP, 2025).

The dependent substrate

Here is the layer the logos don't show. The most valuable, most defensible parts of the security market, the control planes, are US-held, and they're the ground everything else runs on.

  • Detection data layers. North America accounts for 41.8% of global XDR revenue, and the top five XDR vendors, Palo Alto Networks, CrowdStrike, Microsoft, SentinelOne, and Trend Micro, hold 50–60% of the market (MarketsandMarkets). The leading SIEM platforms, Splunk (Cisco), Microsoft Sentinel, and IBM QRadar, are all US-owned.
  • Identity. The dominant enterprise identity backplane is Microsoft Entra ID, and the economics are a moat: enterprise-license bundling makes identity effectively free with the productivity suite, so displacing it means replacing the whole stack that authenticates through it. When Entra has a bad day, everything authenticated through it has a bad day.
  • Endpoint and OS. The most-deployed endpoint-security platforms are Microsoft Defender for Endpoint and CrowdStrike Falcon, both running on Windows and an operating system with 1bn+ active devices (Microsoft). That OS is the substrate European tools defend, and often run on.

The most authoritative statement of the paradox comes from the German Institute for International and Security Affairs (SWP), whose 2025 analysis is titled, simply, Europe's Cybersecurity Depends on the United States. Its sharpest finding: even if Europe built a full "EuroStack," "large parts of the cybersecurity information ecosystem and markets for cybersecurity products would remain dominated by the United States" (SWP, 2025). Sovereign cloud alone does not fix the security layer.

Two stacked panels. "Where Europe is strong": endpoint, MDR/MSSP, OT security, IAM/PAM and cryptography, with European vendors. "The dependent substrate" beneath it, on cracked ground: cloud-native security, XDR/SIEM telemetry, the identity backplane and endpoint OS, all US-controlled. Caption: sovereign security must include the ground it runs on.

The proof is already on the record

This isn't theoretical. In July 2024, a single US security vendor's faulty update crashed roughly 8.5 million Windows devices worldwide, the largest IT outage in history, grounding airlines and disrupting hospitals and banks (CISA; Microsoft). The tool that took the endpoints down was the security tool, running kernel-level on a US OS. In October 2025, a configuration fault in a US identity/edge service rippled through collaboration platforms, airline check-in, and public-sector systems (The Register).

And in April 2025, US funding for the CVE vulnerability database (a piece of shared global infrastructure the entire industry depends on) nearly lapsed. It was restored, but "only for eleven months and on a limited basis," prompting the EU to stand up its own vulnerability database (SWP). The dependency runs all the way down to the reference data.

Why Europe's defenders struggle to reach the substrate

The gap isn't talent; it's scale and capital. Europe generates about 17% of new global enterprise value but captures only 10% of exit value, and European venture funding sits near $44bn a year against roughly $375bn of underfunding over the last decade (Atomico, State of European Tech 2025). The control-plane layers are winner-take-all: telemetry improves with scale, identity compounds with installed base, and network effects make catch-up "an impossible hill to climb" for latecomers, as the EP study puts it. Add an EU cybersecurity workforce gap of roughly 299,000 (ISC2, 2024), and you have an industry that produces excellent defenders who still, too often, plug into someone else's backplane.

The way out: sovereignty has to reach the substrate

The resolution to the paradox is not "buy European security tools." It's to make sure the ground those tools run on is sovereign too: EU-hosted infrastructure, EU-controlled identity, EU-held keys and telemetry. A European EDR that reports into a US-controlled data layer, or runs on a US identity system, has moved the logo without moving the dependency.

This is exactly why we built the way we did. Command (Soveryne's security-program workspace, with controls mapped and evidenced across People, Organization, and Technology, and threat intelligence triaged against your own controls) runs entirely on the Soveryne Cloud Foundation: EU-hosted, operated by an EU entity, EU-held keys, EU-sovereign AI inference, no US-jurisdiction subprocessor in the data path. The telemetry, the identity, the evidence, and the keys stay in jurisdiction. And because we're built by offensive specialists, the defences are designed the way attackers actually break them, the subject of our companion technical post.

Sovereign security that runs on dependent ground isn't sovereign. It's just better-branded dependency.

FAQ

Isn't European cybersecurity already strong? In services and specific product niches, yes: Europe has real, scaled vendors. But the high-value control planes (cloud-native security, XDR/SIEM telemetry, identity, endpoint OS) remain US-dominated, and European tools often run on them.

What is the "cyber paradox"? That Europe's defensive security industry, its relative strength, frequently depends on the very US clouds, operating systems, and identity systems it is meant to protect, so a failure or coercion in those layers becomes a security and sovereignty crisis.

Does building a European sovereign cloud fix cybersecurity dependence? Not on its own. As SWP Berlin notes, much of the cybersecurity product and threat-intelligence ecosystem would remain US-dominated even with a European cloud. Sovereign security must also cover identity, telemetry, keys, and the tools themselves.

What does "sovereign security" actually require? EU-hosted infrastructure, EU-controlled identity, EU-held encryption keys, EU-controlled detection telemetry, not just EU-branded tools running on foreign backplanes.


A shield is only as sovereign as the ground it stands on. See security operations that run on EU-sovereign infrastructure end to end: explore Command and the Soveryne Cloud Foundation.

Sources