Introduction
Prolinx, The UK Sovereign Cloud Company, hosted a focussed event at Tech UK on the 22 May to explore the relationships between sovereign data, security and resilience in Defence and Government. Following a keynote from Ed McCutcheon, Chief Architect for Government at Government Digital Services, a panel discussion was chaired by Sara Sharkey CBE, Prolinx Strategy Director.
Relevance of Sovereignty
UK sovereignty refers to the United Kingdom’s authority to govern itself without external interference, encompassing political, legal, and economic independence. In today’s rapidly evolving geopolitical landscape, sovereignty has become increasingly relevant, particularly as nations grapple with the rise of artificial intelligence (AI) and its implications for data, security, and resilience in Defence and Government.
The ability to control and secure national data, maintain independent decision-making processes, and protect critical infrastructure has become central to national sovereignty. As global power dynamics shift and cyber threats intensify, the UK must ensure its technologies, particularly AI systems, are developed and governed in alignment with national values and strategic interests, safeguarding its autonomy and operational integrity in an era of digital competition and hybrid threats.
Sovereign Data
The interconnectedness of systems, organisations, and nations that generate, store and process sensitive data brings the debate around data sovereignty into sharp focus. For the MOD and Government departments, the risks of foreign access, interception or manipulation of data stored or processed abroad could severely impact critical national-strategic capabilities. Control of data residency and access is essential to achieving UK data sovereignty for Defence and Government. Hosting nationally important data within trusted and assured, UK owned and managed data centres ensures sensitive data remains under UK jurisdiction and limits exposure to foreign legislation, which can compel international service providers to disclose data – even when hosted within the UK.
Science and technology (S&T) research data and intellectual property within industry and academia is a vital component of Defence and Government’s technological design and development. Research portfolios directly drive innovation and solutions to many of the UK’s most urgent national security issues. The National Armaments Directorate will prioritise and align Defence’s research priorities with UK universities and industry. The sovereignty and protection of research data is critical to solving Defence’s identified problems.
The UK must ensure that it’s technology providers including cloud service providers and operate solely within the framework of UK regulatory oversight with transparent governance. However, data sovereignty, security and resilience considerations must be expanded beyond geographical factors. Globalised supply chains and a dependency on other nations is hard-wired into the UK’s national fabric, impacting sovereignty. These dependencies are far-reaching, impactful and multi-faceted:
- Our NATO commitments and shared endeavours.
- International Trade agreements.
- Multi-national partnerships for capability delivery, e.g. GCAP, AUKUS
- Technology and telecommunications operators with dependencies on infrastructure and software that is anchored offshore.
- Supply chains, including minerals, manufacturing and energy provision that are not and can not be fully sovereign capabilities due to availability, skills and knowledge and capacity constraints.
- Supply chains and their fragility (COVID 19) and potential as threat vectors.
The Scope of Sovereignty Considerations (as defined by Ed McCutcheon) – State of Digital Government Review, GDS, Jan 25
Geographical, legal, people, resilience, AI sovereign capacity, intellectual property, partnership sovereignty, capability.
Security
NCSC’s 2024 Annual Report showed a substantial increase in the quantity of cyber-attacks being reported to NCSC, with 89 considered nationally significant, including 12 critical incidents. With Cyberspace and the electromagnetic spectrum (CyberEM) recognised as an operational domain for warfare, the Strategic Defence Review (SDR) 2025 identifies the technologies that are driving the most disruptive changes to the cyber threat landscape. Nation-states, terrorist groups, and third-party proxies are a persistent threat to the UK, the MOD, and the defence industry that supports it.
The SDR places the UK onto a war-fighting readiness, with the ambition to have closer ties between industry suppliers and the MOD as part of a whole-of-society approach to achieving an ‘integrated force’.
It can be reasonably anticipated that industry partners to Defence will continue to be targeted through cyberspace by adversaries and malignant actors as they attempt to steal intellectual property, disrupt communications, and deny access to critically sensitive data. Cybersecurity is a critical function of any organisation, but even more so for those working in or around Defence and Government. Mitigating the threats posed by AI, quantum technologies and cyber-attack are now in the calculus when developing a cybersecurity strategy. It is vital that organisations understand where their data is located, how that data is protected and how they will react in the event of a significant attack. As the UK moves to a war-fighting readiness, the impact of inadequate cybersecurity controls and a successful cyber-attack goes beyond financial and reputational damage for Defence, Government and industry, but has the very real possibility of endangering life and risking operational success.
Nicky Stewart on single points of failure and competition:
“For many, digital and data sovereignty is becoming more important than ever, even if it means different things to different stakeholders. Prolinx’s thought provoking and excellent event was a great opportunity to hear and understand the many perspectives on this important topic. But wherever you stand on the sovereignty spectrum and whatever your sovereignty needs, restoring competition and choice to the broken cloud and AI market is the foundational first step.”
Resilience
Data resilience as part of a broader sovereign strategy in UK Defence and Government will require a combination of policy, technology, infrastructure, and strategic partnerships that ensure the continuity, integrity and availability of critical data. During a time of national crisis or cyber-attack, the ability of any organisation to continue with operations and recover in a timely manner is an imperative that must be planned for, war-gamed and exercised frequently.
Data resilience goes hand-in-hand with data sovereignty, ensuring that data is not only controlled within UK jurisdiction but is also secure, recoverable, and dependable when facing threats to its availability. In the current security climate, facing the threats identified within SDR 2025, data resilience within a broader strategy for Defence, Government and industry should include:
- Secure, sovereign infrastructure.
The recognition of UK data centres as CNI is a good first step. Data centre infrastructure and sovereign cloud platforms must have resilience and security by design at their core. Failover mechanisms and back-ups and redundancy that ensures that data is accessible and available in the event of an attack (physical or cyber) or disruption. A competitive market place for cloud and digital infrastructure services is critical; one that encourages diversity of supply chain, UK and EU backed businesses to support a hybrid eco-system that offers choice and sovereign autonomy.
- End-to-end encryption and access control.
The UK’s most critical and sensitive data must be protected by UK sovereign encryption, UK nationals, and use NCSC CAPS assured products. Attribute and/or Identity Based Access Controls (A/IBAC) supported by continuous monitoring and threat detection are vital for preventing unauthorised access to data and maintaining integrity of information. - Interoperability without sacrificing control.
Global connectivity and partnerships make interoperability a key operational requirement. Consideration to data classification, federated data-sharing architectures, and the use of secure exchange protocols can mitigate the risks associated with interoperability. - Strong legal and regulatory frameworks.
The UK Government must continue to refine the regulations around data residency and the obligations of suppliers. Critical infrastructure should mandate resiliency standards and audit compliance across the defence and national security sectors. - Skilled workforce and trusted ecosystem.
Sustainable data resilience is dependant upon people as much as the technology that underpins it. UK domestic talent, with appropriate security clearances, will mitigate threats associated with workforce.
Sovereign Autonomy has to be a national backstop with a hybrid technology architecture and portfolio of services that enables the UK to act independently of other actors. Which nation / global actor owns the virtual kill switch to either maintain UK access to data or to deny access to data.
Linc Taylor on risk mitigation and resilience:
“Within Defence and Government, there is a need to diversify technology, cloud services, and data centres to mitigate the associated security risks of outages, disruptions or a cyber-attack.”
Summary
The scope of sovereignty considerations must include geography, people, national and international suppliers and technology operators, intellectual property whilst also being mindful of our allies and partnerships. Our national data is critical and requires safeguards to ensure sovereign security and autonomy and national resilience. The cyber threat to our data and information systems is acute; our need to process and gain information advantage from our data has never been more urgent. If we are not able to exert sovereign control, maintain security and plan for resilience this will impact our nation’s ability to influence and exert both hard and soft power over the next decades. The emphasis for Defence, Government, industry, and academia therefore, must be on ensuring that UK sovereign capabilities are included in their strategies and plans.
Prolinx
Prolinx is a UK sovereign cloud services provider to Defence, Government, Academia and Industry. Operating across the security tiers with UK sovereign data centres and a security cleared workforce, Prolinx provides turnkey cloud hosting, data services, and cybersecurity solutions to some of the UK’s most critical use-cases. Prolinx operates a continuous cyber security operations centre in support of its MOD-connected, assured platforms, enabling sovereignty, security and resilience for mission-critical, no-fail operational data requirements.
27 Years of experience.
Over two decades of experience delivering secure cloud solutions.
100% UK Sovereign.
A British-owned SME with assured UK sovereign data centres delivered by highly-skilled, security cleared UK workforce.
24/7 Support.
Continuous support (NOC & SOC) for our Citadel Secure and Citadel Red Services.