Press "Enter" to skip to content

Sovereignty as a Service – on the Security Policy Implications of Frictionless Technology Choices

When one of Sweden’s most security-critical authorities seeks expertise in American cloud technology, it reveals more than a simple recruitment need. Open sources, legal dependencies and geopolitics intertwine to form an uncomfortable question: just how sovereign is our digital preparedness?

“Do you want to make a difference to society and contribute to Sweden’s independence in the world? We are now looking for an Azure technician with a focus on the development, operation and management of FRA’s cloud solutions. Does this sound like something for you? Apply now!”

This is the wording of an advertisement issued by the National Defence Radio Establishment (FRA). The FRA is a Swedish intelligence agency under the Ministry of Defence, tasked with collecting and analysing signals in electronic communications.

Organisational infrastructure is rarely as well protected as one might imagine. Through open sources – such as job advertisements, technical requirement profiles and procurement documents – it is entirely possible to gradually construct a clear picture. Each individual detail may be harmless in isolation, but their combined effect is far more revealing.

When a public authority requests expertise in specific technological ecosystems, such as cloud platforms or vendor-specific identity solutions, it becomes possible to make reasonable assumptions about dependencies and architecture, for example. This may not reveal everything in exact terms, but one does not need complete information in order to conduct strategic analysis.

Thus, organisations’ own requirements for transparency – or simple carelessness, for that matter – create opportunities for infrastructural mapping. This does not, of course, mean that classified information has been, or will be, exposed. But it does make matters considerably easier for anyone with such intentions, all else being equal.

Microsoft is subject to US jurisdiction

If we assume that Azure is being used by a security-conscious authority, we must also assume that such use is restricted. That it concerns support functions, development environments or application hosting without any interaction with classified information, rather than the cloud storage of such data.

This does not, however, change the fact that Microsoft (which provides Azure) is subject to US jurisdiction. This means that political decisions in the United States can affect the room for manoeuvre of a Swedish authority, regardless of where data is physically stored or how well it is encrypted.

Consequences of non-compliance

In the event of a political conflict between the United States and Sweden – for example, if one party seeks control over Greenland – consequences may arise both with and without active coercive measures. Uncertainty regarding future access, changes in contractual terms or limited support all create a structural vulnerability.

If we further assume that the authority has a technical dependency on Azure (or other Microsoft services), this can, of course, be used as a means of political pressure. The ability to rapidly replace or dismantle such dependencies is limited, particularly in terms of time.

I do not wish to believe that the FRA stores classified data via Azure. Nevertheless, it should be noted that the fact that Azure has data centres for cloud storage in Sweden does not alter the ability of the US authorities to gain access to that data under the Cloud Act.

Without digital sovereignty, there is no sovereignty

Open sources thus enable reasonable assumptions about infrastructure and vendor lock-in, while legal and political control over those vendors creates risks that simply cannot be mitigated through technical safeguards alone.

It is difficult not to note the irony that this advertisement appears on the very same day that Trump openly expresses his dissatisfaction with Sweden and threatens punitive tariffs in order to force compliance in the Greenland issue.

What will be the next step if we do not comply?