"30% of CISOs at CAC 40 companies are already convinced of the risks posed by foreign solution providers," according to the Choiseul Institute*.
While previously a little-known issue for businesses, security vulnerabilities stemming from non-European cybersecurity solutions are becoming a reality for many companies. Europe is taking a tougher stance in the face of this threat. New European regulations are being rolled out one after another, and European cybersecurity sovereignty has become a top priority. The goal is clear: to strengthen European resilience, particularly for critical infrastructure, and to protect the data of European citizens.
At first glance, aspirations for European sovereignty may seem far removed from your company's day-to-day concerns. However, they impact you every day, and mitigating the risks associated with foreign cybersecurity solutions is already a very real challenge for your business.
*Cybersecurity, a prerequisite for all economic sovereignty, June 2022
- GDPR, NIS2… Companies facing European compliance requirements
- Data protection: your company's true challenge
GDPR, NIS2… Companies facing European compliance requirements
Meeting legal obligations and ensuring all compliance requirements are met has become a major challenge for every company and organization. To strengthen European cybersecurity sovereignty, the European Union is issuing numerous new regulations: NIS2, DORA, the Cyber Solidarity Act, the Cyber Resilience Act, and more. The General Data Protection Regulation (GDPR) remains the text that impacts your company the most, but the arrival of the NIS2 directive at the national level (by September 2024 at the latest) will bring new, even heavier obligations. However, there is a way to ease the compliance burden weighing on companies.
The European Union's General Data Protection Regulation (GDPR) applies directly to cybersecurity. All companies that process the personal data of EU citizens are subject to it. In this context, it requires companies to protect personal data against potential data breaches and cyberattacks by adopting appropriate security measures. The European obligation to adopt cybersecurity measures to comply with GDPR requirements is very burdensome for companies, as failure to comply with its provisions can lead to financial penalties of up to 4% of a company's total global annual turnover or 20 million euros.
Alongside this, the cyber world and companies located in Europe must prepare to comply with the NIS2 directive. To be transposed into each national legislation by September 2024, NIS2 aims to ensure the security of networks and information systems. Stricter than its 2016 predecessor, the NIS directive, it applies to a wider range of sectors and companies. Complying with it has become an urgent matter for most businesses. NIS2 imposes high security requirements, notably by requiring the creation of a list of risk management measures and implementing an obligation for companies to report significant incidents within 24 hours.
With NIS2, companies will be forced to step up their cybersecurity game to meet compliance requirements. There are solutions to avoid being overwhelmed by European standards. Most European cybersecurity tools guide you toward ISO/IEC 27001, GDPR, and NIS2 compliance, whereas non-European cybersecurity players do not include this by default. The most advanced solutions are already NIS2-compliant.
Data protection: your company's true challenge
GDPR compliance and user data protection might initially be seen solely as an additional compliance constraint for companies. However, the issue of data protection goes further. Data collection without prior consent also directly affects companies and is an issue that often goes unnoticed.
The question of European cybersecurity sovereignty is closely linked to data sovereignty. Its goal is to ensure that your data and its usage are not subject to foreign law. Your company's regulatory compliance depends on its location, and this is especially true for your company's data. Different laws apply depending on your location, where your data is stored, and where it is transferred. Therefore, the laws of several countries may apply to your data. And unfortunately, not all legislation is designed with data protection in mind…
The most well-known extraterritorial law regarding cybersecurity is the controversial Cloud Act (Clarifying Lawful Overseas Use of Data Act) adopted in 2018. With the Cloud Act, U.S. authorities can access data stored abroad by U.S. companies without authorization from the country where that data is stored. Thanks to the Cloud Act, U.S. authorities have legal access to all data collected by U.S. companies, provided that this data is stored in a U.S. company's cloud. Consequently, even if your company is located in Europe, where your data is legally protected, a U.S. cybersecurity solution could grant U.S. authorities access to your data if it is stored in their cloud.
Industrial espionage via foreign security solutions is becoming a real risk for companies. This risk also applies if your solution has chosen a U.S. host: the most common hosts, such as AWS or Azure, are therefore affected. This is where European sovereignty takes on its full importance and protects your company's future. Choosing cybersecurity solutions subject to legislation that does not work in your favor is, nowadays, a direct risk to your company. Thanks to European sovereignty and European cybersecurity solutions hosted outside the U.S., your data remains in Europe and your company is protected.
Compliance, data, and more
Secure and ethical by Design, TEHTRIS is committed to its clients. TEHTRIS solutions allow you to meet compliance requirements and protect your data by being hosted outside the U.S. Unlike competing cybersecurity solutions, TEHTRIS has designed its products so that it cannot view or copy your files, taking your company's security even further.

