#13: The Cloud Sovereignty Myth: What "Encrypted in Europe" Actually Means
Failed to add items
Add to basket failed.
Add to wishlist failed.
Remove from wishlist failed.
Adding to library failed
Follow podcast failed
Unfollow podcast failed
-
Narrated by:
-
By:
That's the answer that almost every European company gives when asked about cloud security. According to Clémence Caron, however, it's worth almost nothing. The real question is never where your data sits. It's who can be compelled to access it, regardless of the server's location. In this episode of Follow the White Rabbit, Link11 CISO Kofi Osae-Attah sits down with Clémence Caron, a cloud and AI security specialist at Google Cloud. Clémence started her career engineering security for naval vessels. In this episode, she and Kofi talk about what digital sovereignty requires and how checkbox compliance is quietly letting through.
The conversation is refreshingly candid, especially for someone who works for a hyperscaler. Clémence doesn't sell sovereignty as a product. She frames it as a risk-tiered decision that depends entirely on what you're protecting and from whom. Her thesis is clear: You can't fight AI-speed attacks with human-speed defenses. However, before companies can implement automated detection, they must first address issues that cost almost nothing, such as misconfigured service accounts. Misconfigured service accounts, Shared admin privileges. They lack a documented incident response process. These are the basics that, if done right, would stop most attacks before they start.
The sharpest moment comes when Kofi asks whether real digital sovereignty is achievable. Her answer differs from what cloud marketing would tell you: You'll never be fully independent, and that's probably fine, if you choose your risks wisely. Sovereignty isn't a checkbox or a setting. It's a series of deliberate decisions about what you need to protect, what you're willing to lose, and how quickly you can recover if something goes wrong.
Takeaways- Location does not equate to control. Data stored in a European data center can still be accessible under foreign law. The important questions are who can be compelled to access the data and whether encryption and key management can prevent that access.
- You cannot fight AI-speed attacks with human-speed responses. A human analyst looking at 500 alerts per minute will always be too late. Automation is no longer optional. However, none of this matters if your service accounts have admin access to everything.
- The basics are still the first line of defense: Least privilege. Patching. Key rotation. Documented incident response. These measures aren't exciting, but they stop most attacks before they can be detected. They're also inexpensive.
- Compliance is a starting point, not a finish line. Certifications can force companies to start thinking about security. However, if the goal is merely to check a box rather than to understand risk, you've created paperwork, not protection.
- Sovereignty is a spectrum, not an on/off switch. From public cloud with managed encryption to fully air-gapped on-prem, there is no single right answer. The right answer depends on what needs to be available and confidential and how quickly you can recover if something goes wrong.
Subscribe to Follow the Rabbit
If this episode changed the way you think about cloud security, digital sovereignty, or the difference between compliance and real protection, share it! Subscribe on your preferred platform and share it with your cloud and compliance teams, as well as with anyone who thought that keeping data in Europe was sufficient.
LinksClémence Caron – Cloud & AI Security Specialist, Google Cloud
CLOUD Act – US Law & Its Implications for European Data
BSI: Cloud Computing Security Recommendations