Digital dependency has become an operational risk
A Capgemini Research Institute survey of 1,300 executives across 11 countries found that most organisations now see complete digital sovereignty as unrealistic. The practical priority is resilience: retaining control of critical data, AI models and workloads when access to a provider is disrupted.
Nearly half estimated that replacing a critical technology provider would take between three months and one year. More than one-third expected it to take longer than a year. Recent attacks on telecommunications and data-centre infrastructure have made those dependencies harder to dismiss.
A digital service can be as critical as the physical asset
Airports, highways, utilities, ports and industrial operators increasingly depend on cloud platforms, communications networks, AI models and specialist software for monitoring, maintenance, planning and incident response.
If one of those services becomes unavailable, the consequences can move quickly from the digital environment into physical operations. An owner may still possess the infrastructure while losing access to the information or control capability needed to operate it safely.
The European Union's Data Act includes measures intended to make switching between data-processing providers easier. Contractual portability, however, does not prove that a complex operational system can be transferred within an acceptable time.
The real test is whether the service can be replaced
Multi-provider architectures, open interfaces and portable data formats can reduce lock-in. They may also introduce cost, duplicated capability, inconsistent controls and additional cyber exposure.
The answer is not indiscriminate duplication. Owners should identify which services are genuinely critical, define the minimum safe operating state and establish how data, configurations, models and decision rights would transfer under pressure.
Resilience must be demonstrated before it is needed
KIS PLUS LTD's view is that digital substitutability should become part of asset-management assurance. Procurement should establish ownership of data and interfaces, usable export formats, exit support, transition times and the ability to maintain essential operations during change.
The UAE's reported reconsideration of a concentrated 5 GW AI campus following attacks in the Gulf reinforces the wider point: resilience is weakened by excessive concentration, whether it sits in one site, one platform or one supplier.
A backup is not a resilience strategy if it cannot restore the service, decisions and operating context the asset actually requires. The appropriate response must reflect asset criticality, consequence of failure and the cost of maintaining a viable alternative.
The next proof points
- Tested supplier-exit plans in infrastructure procurement
- Measurable switching and recovery times
- Portable operational data and AI models
- Independent assurance of fallback capability
- Transition costs allocated before disruption occurs
- Assessments covering geographical and supplier concentration

