Open Source Conference Luxembourg

Digital sovereignty lessons from defence and intelligence environments

Digital sovereignty is often reduced to data residency, European hosting or the use of open-source software. In defense and intelligence environments, that definition is not sufficient.

For organisations whose communications must remain available during political conflict, supply-chain disruption, network isolation or the failure of a trusted vendor, sovereignty becomes an operational requirement: Can the organisation continue to communicate when external dependencies are no longer available - or no longer trustworthy?

Drawing on anonymized examples from customer projects in the military and intelligence sector, this talk examines what digital sovereignty looks like under real operational pressure. It explores architectural control, disconnected and restricted environments, identity ownership, software supply chains, update sovereignty, protocol compatibility and the ability to replace a vendor without replacing every client and workflow at the same time.

The central lesson is simple:

Digital sovereignty is not where a system is hosted. It is the ability to understand it, operate it, secure it and continue without permission from a third party.


The military and intelligence sectors provide an unusually clear test for digital sovereignty. Their systems must function under conditions that most commercial platforms are not designed for: restricted networks, limited or prohibited cloud connectivity, classified data, national security requirements, long operational lifecycles and the possibility that a previously trusted supplier may suddenly become unavailable.

In these environments, questions that are often treated as theoretical become very practical:

  • Can the system operate without a permanent connection to the vendor?
  • Who controls identities, encryption keys, updates and administrative access?
  • Can security patches be inspected, tested and distributed through controlled channels?
  • Does the organisation understand the complete software supply chain?
  • Can the platform continue running if licences, sanctions, export restrictions or geopolitical relationships change?
  • Can an alternative provider take over operations without rebuilding the entire environment?
  • Is the environment capable to deal with various data restictions / tenant-oriented structures?

Using anonymised and non-classified examples from military and intelligence customer engagements, Michael Kromer, CTO of grommunio, will show how these requirements influence real technology decisions.

Michael Kromer

Michael Kromer is an IT architect and CTO at grommunio. Since 1998, he has been developing security and communications solutions for companies, government agencies, and critical infrastructure (e.g., intelligence services and the military). As a self-proclaimed nerd when it comes to firewalls, Linux, BSD, TCP/IP—and pretty much anything that contains at least one ESP32—he explains complex technical topics in an easy-to-understand, practical way and spices up his explanations with (sometimes bad ;)) humor.