Sovereign Cloud Germany: Digital Sovereignty for the Public Sector

Azure CAF & Cloud Migration, Resilience, Security 25th Feb 2026 Martin-Peter Lambert
Sovereign Cloud Germany: Digital Sovereignty for the Public Sector

Updated August 2026: the sovereign-cloud market in Germany has moved. The AWS European Sovereign Cloud has been live since January 2026 (Brandenburg region, EU-only operating entity), Delos Cloud brings the Microsoft stack under German operator control for the public sector, STACKIT and IONOS offer European-controlled platforms, the Deutsche Verwaltungscloud (DVC) has become a product of the IT-Planungsrat, and the BSI published C5:2026 in April. The three pillars below are unchanged — the options for implementing them are much broader.

What Does Digital Sovereignty Mean?

Digital sovereignty is the ability to control one’s own IT infrastructure and data with self-determination. For the public sector, this is not a luxury but a necessity. It is about controlling citizen data, independence from individual providers, and compliance with German and European legal norms (GDPR, Schrems II).

A sovereign cloud in Germany provides the technical and organisational framework to ensure this control. It combines the innovative power of global hyperscalers (like Azure, AWS and GCP) or European platforms with the strict requirements of German and European law.

The Three Pillars of Digital Sovereignty

Sovereign cloud architecture: data residency, control and transparency, key management

1. Data Residency

  • What it is: The guarantee that data and metadata are stored and processed exclusively within a defined geographical area (e.g., Germany or the EU).
  • Why it matters: Prevents access by foreign authorities based on laws like the US CLOUD Act. Ensures compliance with GDPR.
  • Implementation: Use of cloud regions in Germany (e.g., Frankfurt, Berlin, Brandenburg). Contractual assurances from the provider. Note that residency alone does not prevent access by the operator or by third-country law — see pillars 2 and 3.

2. Control & Transparency

  • What it is: The ability to seamlessly control and log access to data and systems, including access by the cloud provider itself.
  • Why it matters: Creates trust. Enables proof of compliance (BSI C5, GDPR, NIS2).
  • Implementation: Strict access controls (Zero Trust, MFA), comprehensive logging, EU-only operating staff, use of external control bodies (e.g., data trustees).

3. Key Management

  • What it is: Control over the cryptographic keys used to encrypt data. Whoever holds the key, controls the data.
  • Why it matters: It is the ultimate lever for data sovereignty. Even if a provider could access the encrypted data, they cannot read it without the key.
  • Implementation: Bring Your Own Key (BYOK) or Hold Your Own Key (HYOK), where the keys remain within your own infrastructure. We compare both models in Cloud Key Management: BYOK vs. HYOK in Azure and GCP.

Quick Checklist: Digital Sovereignty

PillarKey QuestionImplemented?
Data ResidencyIs all data guaranteed to be in Germany/EU?
ControlDo we have full control over all access?
TransparencyIs all access logged completely?
Key ManagementDo we control the cryptographic keys?
ExitCould we move to another provider, and have we tested it?
ComplianceAre the requirements of GDPR, BSI C5, NIS2 etc. met?

To-Do List for a Sovereign Cloud Strategy

  1. Immediately: Classify the protection needs of the data.
  2. Week 1: Define the requirements for digital sovereignty per workload (residency, operational control, legal immunity).
  3. Week 2: Evaluate the market for sovereign cloud offerings (AWS European Sovereign Cloud, Delos Cloud, STACKIT, IONOS, T-Systems, Azure and GCP sovereign controls).
  4. Month 1: Establish a strategy for data residency and key management.
  5. Month 2: Adapt the BSI-compliant cloud security concept accordingly.
  6. Month 3: Start a pilot project in a sovereign cloud environment.

Sovereign Offerings: Hyperscalers and European Platforms

The major providers have recognised the need and offer dedicated solutions — and European platforms have matured:

  • AWS European Sovereign Cloud: A physically and logically separate AWS cloud in the EU, operated by an EU entity with EU-resident staff, live since January 2026.
  • Microsoft Cloud for Sovereignty / Delos Cloud: Data residency and enhanced controls on Azure; Delos Cloud delivers the Microsoft stack under German operator control for the public administration.
  • Google Cloud Sovereign Solutions: Similar guarantees for data location and control, often in partnership with local providers (e.g., T-Systems).
  • STACKIT, IONOS, Open Telekom Cloud: European-owned and -operated platforms, increasingly used for public-sector and KRITIS workloads.

These offerings are an important step but require careful examination of operator model, service parity, key model, exit capability and cost. Cloud consulting for public authorities helps to validate the providers’ promises and find the right solution for your needs.

The Role of BSI C5 and IT Baseline Protection

Digital sovereignty and compliance go hand in hand. Being BSI C5 compliant is a basic requirement for a sovereign cloud. The controls in the C5 catalogue cover many aspects of sovereignty, especially in the areas of transparency and operational security — and C5:2026 adds tenant isolation, confidential computing and supply-chain criteria.

IT Baseline Protection consulting helps to integrate the BSI’s requirements into the cloud architecture. An ISO 27001 certification based on IT Baseline Protection demonstrates the effectiveness of the implemented measures.

Insight42: Your Guide to Digital Sovereignty

The path to a sovereign cloud is complex. We navigate you safely through the technological, legal, and organisational challenges. We know the offerings, the pitfalls, and the success factors.

We help you develop a strategy tailored to your specific protection needs — from data residency to external key management. Secure, BSI C5 compliant, and future-proof.

Take control. See our Souveräne Cloud Beratung (German) or contact us to request a Sovereign Cloud Assessment.

Data Protection Impact Assessment (DPIA) for the Cloud: A Guide for Public Authorities

Resilience, Security 23rd Feb 2026 Martin-Peter Lambert
Data Protection Impact Assessment (DPIA) for the Cloud: A Guide for Public Authorities

Why a DPIA is Mandatory for Cloud Projects

The cloud offers enormous opportunities, but it also poses risks to data protection. The General Data Protection Regulation (GDPR) therefore requires a Data Protection Impact Assessment (DPIA) when there is a high risk to the rights and freedoms of natural persons. For the public sector, which works with sensitive citizen data, this is almost always the case for cloud projects.

A DPIA is not an obstacle; it is a tool for risk minimisation. It forces a systematic engagement with data protection and creates legal certainty for your cloud project. A missing DPIA can lead to significant fines and the halting of the project.

When Exactly is a DPIA Required?

Article 35 of the GDPR is clear. A DPIA is required, in particular, for:

  • Large-scale processing of special categories of data (e.g., health data).
  • Systematic and extensive evaluation of personal aspects (profiling).
  • Large-scale monitoring of publicly accessible areas.

The German Data Protection Conference (DSK) has published a positive list of processing activities for which a DPIA is generally required. The use of cloud services for specialised procedures with large amounts of data often falls into this category.

A four step staircase illustrating the DPIA process

The 4 Steps of a Data Protection Impact Assessment

A DPIA follows a structured process. It is not a one-time document but a living process.

Step 1: Systematic Description

  • What? What data is being processed?
  • Why? What is the purpose of the processing?
  • Who? Who are the parties involved (controller, processor)?
  • How? What technologies and processes are being used?

Step 2: Assessment of Necessity and Proportionality

Is the processing truly necessary for the purpose? Are there milder, more data-minimising alternatives? The legal basis must be clear.

Step 3: Risk Assessment

What are the risks to the data subjects (citizens)? (e.g., unauthorised access, data loss, discrimination). The likelihood of occurrence and the severity of the potential harm are assessed.

Step 4: Remedial Measures

What technical and organisational measures (TOMs) will be taken to minimise the risks? This includes encryption, access controls, and contractual arrangements with the cloud provider. We show how to implement them in Azure and GCP in GDPR-Compliant Cloud Usage: TOMs in Azure and GCP.

Quick Checklist: DPIA for the Cloud

StepKey QuestionDone?
1. DescriptionIs the processing completely described?
2. NecessityIs the legal basis clear and the processing proportionate?
3. Risk AssessmentAre the risks to data subjects identified and assessed?
4. MeasuresAre effective remedial measures defined?
5. DocumentationIs the entire DPIA comprehensibly documented?
6. ConsultationMust the Data Protection Officer or the supervisory authority be consulted?

To-Do List for the DPIA

  1. Immediately: Clarify whether a DPIA is mandatory for the cloud project.
  2. Week 1: Appoint a responsible team for the DPIA.
  3. Week 2: Involve the Data Protection Officer at an early stage.
  4. Month 1: Begin the systematic description of the processing.
  5. Month 2: Conduct the risk assessment.
  6. Month 3: Define remedial measures with the cloud service provider and the IT security team.
  7. Ongoing: Update the DPIA whenever the system changes.

The Challenge: Third-Country Transfers

Since the Schrems II ruling, data transfers to the US and other third countries have become complex. Cloud providers like Microsoft (Azure), Amazon (AWS) and Google (GCP) are US companies. A DPIA must explicitly assess this risk — including the possibility of access under the US CLOUD Act regardless of where the data centre is located.

Remedial measures for this include:

  • Standard Contractual Clauses (SCCs): The standard mechanism, but often not sufficient on its own.
  • Additional TOMs: Strong encryption (ideally with your own keys – BYOK/HYOK), pseudonymisation, anonymisation.
  • Sovereign Cloud Options: Use of EU-operated platforms and contractual assurances — see Sovereign Cloud Germany.

Insight42: Your Partner for the Cloud DPIA

A DPIA for cloud services requires legal, technical, and procedural knowledge. We connect these worlds. Our Data Protection Impact Assessment consulting is practice-oriented and tailored to the public sector.

We help you identify risks, define effective measures, and design your cloud projects to be legally compliant, in line with BSI C5 and IT Baseline Protection.

Make your data protection future-proof. See NIS2 & Cloud Security Beratung (German) or contact us.

BSI C5 Cloud Certification: A Guide for Public Authorities

Resilience, Security, Sovereignty Series 20th Feb 2026 Martin-Peter Lambert
BSI C5 Cloud Certification: A Guide for Public Authorities

Updated August 2026: the BSI published C5:2026 in April 2026. It adds criteria for container management, tenant isolation, confidential computing, post-quantum cryptography and supply-chain security, and aligns the catalogue with ISO 27001:2022, NIS2 and the European EUCS scheme. Attestations with a reference date or audit period starting after mid-2027 will be measured against C5:2026 — plan the transition now.

What is BSI C5?

BSI C5 (Cloud Computing Compliance Criteria Catalogue) is the German standard for cloud security, developed by the Federal Office for Information Security (BSI). It defines minimum requirements for cloud services and is effectively mandatory for the public sector, for health data under § 393 SGB V, and increasingly for any organisation that has to evaluate cloud suppliers under NIS2.

Is cloud migration for the public sector possible without BSI C5? It’s risky. Tenders for cloud migration usually demand it, and the procurement process for cloud service providers verifies the attestation. Strictly speaking there is no “C5 certification” — C5 is attested by an auditor under IDW PS 951 / ISAE 3000. The market uses both terms; in tenders, ask for a “C5 Type 2 attestation”.

The Structure of BSI C5

BSI C5 comprises 17 requirement domains, from organisation to incident management. Each domain contains specific controls that must be demonstrated.

The 17 Domains at a Glance:

Information Security Organization, Security Policies, Human Resources, Asset Management, Physical Security, Operations Security, Identity and Access Management, Cryptography, Communication Security, Portability and Interoperability, Procurement and Development, Supplier Relationships, Security Incident Management, Compliance, Data Protection, Product Security, Interoperability.

Type 1 vs. Type 2 Attestation

BSI C5 has two attestation types, and the difference is important.

Type 1 Attestation

This assesses the appropriateness of the controls at a specific point in time.
– Are the controls designed?
– Are they implemented?

Type 2 Attestation

This assesses the effectiveness of the controls over a period of at least six months.
– Do the controls work?
– Are they being followed?

For public authorities, a Type 2 attestation is usually required. It offers more assurance and demonstrates continuous compliance.

Quick Checklist: BSI C5 Readiness

DomainCheckpointStatus
OrganizationISMS Established
PoliciesSecurity Policies Documented
PersonnelAwareness Training Conducted
AssetsInventory Complete
AccessIAM Implemented
CryptographyEncryption Active
LoggingLogging Enabled
IncidentProcess Defined

To-Do List for BSI C5 Attestation

  1. Month 1: Conduct a gap analysis.
  2. Month 2: Create an action plan.
  3. Months 3-6: Implement controls.
  4. Month 7: Perform an internal audit.
  5. Month 8: Conduct an external pre-audit.
  6. Months 9-10: Undergo the Type 1 audit.
  7. Months 11-16: Operational phase.
  8. Month 17: Undergo the Type 2 audit.

The Path to Attestation

Becoming BSI C5 compliant is a project. It requires planning, resources, and expertise.

Step 1: Gap Analysis

Where do you stand today? Which controls are missing? IT baseline protection consulting helps with the assessment. The gap analysis shows the way forward.

Step 2: Action Planning

  • What measures are necessary?
  • In what order? With what budget?
  • Who owns each measure, and when is it due?

Step 3: Implementation

  • Controls are introduced
  • Processes are established
  • Documentation is created
  • The BSI-compliant cloud security concept is developed

Step 4: Audit

An auditor conducts the review. The controls are tested. Evidence is collected. The attestation is issued. We cover this phase in detail in Preparing for a BSI C5 Audit: Practical Tips for the Public Sector.

Cloud Providers and BSI C5

Major cloud providers like Azure, GCP, and AWS hold BSI C5 attestations. But that’s not enough to claim that using them makes you compliant — quite the opposite. Because of the shared responsibility model, you still need to implement the corresponding user-side controls and operate them correctly. Only then can you be C5-compliant.

Azure migration and GCP migration must consider BSI C5. An Azure Landing Zone and a GCP Landing Zone should incorporate BSI C5 controls from day one. The Cloud Adoption Framework helps with this.

Insight42 BSI C5 Services

We guide public authorities and cloud providers to BSI C5 compliance, from gap analysis to the audit. We deliver the BSI-compliant cloud security concept and its technical implementation from a single source — with experience in BSI C5 and IT-Grundschutz projects for the public sector, and continuous-compliance managed services after the attestation.

Become BSI C5 compliant. See our BSI C5 Beratung (German) or contact us to book a C5 readiness call.

Entra ID Migration for Public Authorities: The Path to Zero Trust

AI In The Public Sector, Azure CAF & Cloud Migration, Growth, Resilience, Sovereignty Series 18th Feb 2026 Martin-Peter Lambert
Entra ID Migration for Public Authorities: The Path to Zero Trust

Identity is the New Perimeter

Firewalls alone are no longer enough. Employees work from anywhere. Cloud services are distributed. Identity has become the central security anchor. Zero Trust is the answer.

This is particularly relevant for the public sector, where sensitive citizen data must be protected. A migration to Microsoft Entra ID creates the foundation for SSO, MFA and Conditional Access — and covers a substantial part of the identity and access management criteria in BSI C5, IT-Grundschutz and NIS2.

What Zero Trust Means

Zero Trust is a security model: never trust, always verify. Every access attempt is checked. Every identity is validated.

It sounds strict, and it is. But it works. Attacks are made more difficult. Lateral movement is prevented. A BSI-compliant cloud security concept recommends this approach.

The Pillars of Zero Trust

Verify Identity

Who is accessing the resource? Is the person who they claim to be? Multi-Factor Authentication is mandatory. Passwords alone are not enough.

Validate Device

From which device is the access coming? Is it managed? Is it compliant? Conditional Access checks these factors.

Minimise Access

The principle of least privilege applies. Only necessary rights, only for the necessary time. Just-in-Time access becomes the standard.

Monitor Activities

Every access is logged. Anomalies are detected. Automated responses are triggered.

Quick Checklist: Zero Trust Implementation

ComponentActionPriority
MFAEnable for all usersCritical
SSOSet up Single Sign-OnHigh
Conditional AccessCreate baseline policiesHigh
PIMImplement Privileged Identity ManagementHigh
Device ComplianceDefine device policiesMedium
App ProtectionConfigure application protectionMedium
MonitoringMonitor sign-in logsMedium

To-Do List for Entra ID Migration

  1. Immediately: Enable MFA for administrators.
  2. Week 1: Take inventory of identities.
  3. Week 2: Define the SSO strategy.
  4. Week 3: Plan Conditional Access policies.
  5. Month 1: Migrate a pilot group.
  6. Month 2: Roll out to all users.
  7. Month 3: Implement PIM.

SSO Simplifies and Secures

Single Sign-On is not a luxury; it is a security feature. Fewer passwords mean less risk. Users use strong passwords because they only need one.

Entra ID enables SSO for thousands of applications, both in the cloud and on-premises. SAML, OAuth, and OpenID Connect are all supported — which is why identity is usually the first workload in a public-sector cloud migration.

Implementing MFA Correctly

Multi-Factor Authentication is mandatory. BSI C5 compliance without MFA? Impossible. IT-Grundschutz and NIS2 require it as well.

But MFA must be user-friendly. Authenticator apps are standard. Biometrics where possible. Hardware tokens (FIDO2) for high security and phishing resistance.

Conditional Access makes MFA intelligent. Not for every login, only when there is a risk. Unknown device? MFA. Unusual location? MFA. We cover the policy design in detail in Conditional Access and MFA: Intelligent Access Control for the Public Sector.

Protecting Privileged Identities

Administrators are prime targets. Their accounts have extensive rights. Privileged Identity Management (PIM) protects them.

The principle is Just-in-Time access. Rights are activated only when needed, for a limited time, and with approval. A BSI-compliant cloud security concept and KRITIS cloud security both demand these controls.

Insight42 Identity Services

We plan and implement Entra ID migrations with Zero Trust as the default: SSO strategy, MFA rollout, Conditional Access baselines, PIM and monitoring — from strategy to operation, including managed identity services for public authorities.

Secure your identities. See NIS2 & Cloud Security Beratung (German) or contact us.

Azure ExpressRoute for Public Authorities: A Secure Connection to the Cloud

AI In The Public Sector, Resilience, Sovereignty Series 16th Feb 2026 Martin-Peter Lambert
Azure ExpressRoute for Public Authorities: A Secure Connection to the Cloud

Why ExpressRoute is Essential for Public Authorities

The public internet is not an option. Sensitive government data requires dedicated connections. An Azure ExpressRoute setup provides this security through private lines, guaranteed bandwidth, and low latency.

Cloud migration for the public sector demands reliable connectivity. A datacenter migration to Azure only works with a stable connection. ExpressRoute delivers both: security and performance.

Azure ExpressRoute architecture for public authorities: on-premises datacenter, carrier, private peering, Azure landing zone
Azure ExpressRoute architecture

What Azure ExpressRoute Offers

ExpressRoute is a private connection that completely bypasses the internet. Data flows over dedicated lines, with carrier partners providing the infrastructure.

For the public sector, this means the communication-security criteria of BSI C5 are easier to meet. The BSI-compliant cloud security concept can point to secure connectivity, strengthening KRITIS cloud security.

Understanding the Architecture

ExpressRoute Circuit — The circuit is the physical connection linking your data center to Microsoft. Various bandwidths are available, from 50 Mbps to 100 Gbps.

Peering Types — Private Peering connects to Azure VNets, while Microsoft Peering reaches Microsoft 365. Both can be used in parallel.

Redundancy — High availability requires redundancy. Two circuits at different locations ensure automatic failover in case of an outage, meeting government SLAs.

Quick Checklist: ExpressRoute Setup

StepTaskResponsible
1Determine Bandwidth NeedsIT Department
2Select Carrier PartnerProcurement
3Order CircuitCarrier
4Configure AzureCloud Team
5Set Up RoutingNetwork Team
6Implement RedundancyCloud Team
7Activate MonitoringOperations

To-Do List for Secure Connectivity

  1. Today: Analyse current bandwidth usage.
  2. This Week: Research carrier options.
  3. This Month: Create the ExpressRoute design.
  4. Quarter 1: Commission the circuit.
  5. Quarter 2: Start migration over ExpressRoute.

Mastering Hybrid Scenarios

Not everything moves to the cloud at once. Hybrid architectures are a reality. ExpressRoute connects both worlds, allowing on-premises and Azure to work together.

A VMware to Azure migration particularly benefits, as large data volumes are transferred quickly. Replication runs in the background, and the cutover occurs without significant downtime.

Security at All Levels

ExpressRoute is private by design, but it is not encrypted by default. Additional measures — MACsec on the circuit, IPsec tunnels over ExpressRoute, or application-level TLS — provide the encryption that BSI C5 and IT-Grundschutz expect even on dedicated lines.

IT-Grundschutz recommends defence in depth: ExpressRoute is one layer, complemented by firewalls, segmentation and identity-based access control.

Costs and Procurement

Azure ExpressRoute has two cost components: Microsoft charges for the circuit, and the carrier charges for the line. Both must be budgeted.

A cloud framework agreement can simplify procurement, and a cloud migration tender should include connectivity from the start so that total migration costs stay transparent.

Insight42 Connectivity Services

We plan and implement ExpressRoute, from needs analysis to operation, as part of our Azure migration consulting — and our managed services monitor the connection proactively for SLA-compliant operation. For multi-cloud environments see Multi-Cloud Connectivity: Combining ExpressRoute and Google Cloud Interconnect.

Connect securely. See Cloud Migration Beratung (German) or contact us.

ISO 27001 Based on IT-Grundschutz: The Royal Road for Public Authorities

Resilience, Security 15th Feb 2026 Martin-Peter Lambert
ISO 27001 Based on IT-Grundschutz: The Royal Road for Public Authorities

Why IT Baseline Protection is the Standard for Public Authorities

The BSI’s IT Baseline Protection (IT-Grundschutz) is more than a recommendation; it is the de facto standard for information security in German public administration. It offers concrete measures, field-tested building blocks, and a clear methodology, which makes it incredibly valuable.

An ISO 27001 certification is internationally recognised and demonstrates a functioning Information Security Management System (ISMS). Combining these two worlds is ideal: the specific guidelines of IT Baseline Protection fulfil the abstract requirements of ISO 27001.

The Synergy of IT Baseline Protection and ISO 27001

ISO 27001 requires an ISMS but does not specify how to implement it. IT Baseline Protection provides exactly that: a detailed guide. Those who implement IT Baseline Protection have already done most of the work for an ISO 27001 certification.

The advantages of this combination:

  • Concrete and Field-Tested: IT Baseline Protection offers ready-made building blocks.
  • BSI-Recognised: The methodology is well-established within the German public sector.
  • Efficient: It avoids duplication of effort.
  • Internationally Recognised: The ISO 27001 certification builds trust.
A five step staircase leading to an ISO 27001 certification badge

The Path to Certification

Step 1: Structural Analysis — Which information, processes, and IT systems need protection? The structural analysis defines the scope of the ISMS.

Step 2: Protection Needs Assessment — How critical is the data? Normal, high, or very high? The protection needs assessment evaluates the requirements for confidentiality, integrity, and availability.

Step 3: Modelling According to IT Baseline Protection — The identified systems are mapped to the building blocks of the IT-Grundschutz Compendium. The result is a list of relevant requirements.

Step 4: Basic Security Check — This is a gap analysis. Which requirements are already implemented? Where are the gaps? The basic security check identifies the need for action.

Step 5: Implementation and Audit — The gaps are closed. The ISMS is put into practice. An external auditor verifies conformity and issues the ISO 27001 certificate.

Quick Checklist: ISO 27001 Based on IT Baseline Protection

PhaseTaskStatus
1. PreparationDefine Scope
2. AnalysisConduct Structural Analysis
3. AssessmentDetermine Protection Needs
4. ModellingMap IT Baseline Protection Building Blocks
5. Gap AnalysisPerform Basic Security Check
6. ImplementationExecute Action Plan
7. AuditCertification Audit

To-Do List for Project Managers

  1. Immediately: Secure management commitment.
  2. Week 1: Appoint an ISMS team.
  3. Week 2: Commission IT Baseline Protection consulting.
  4. Month 1: Start the structural analysis.
  5. Month 2: Complete the protection needs assessment.
  6. Quarter 2: Conduct the basic security check.
  7. Quarters 3-4: Implement measures.
  8. Next Year: Plan the certification audit.

IT Baseline Protection in the Cloud

The principles of IT Baseline Protection also apply in the cloud, but the implementation differs. Responsibility is shared. Cloud providers (Azure, AWS, GCP) deliver a secure foundation, while the authority is responsible for secure configuration and use (Shared Responsibility Model).

An ISO 27001 certification based on IT Baseline Protection for cloud workloads is possible. It requires a clear understanding of responsibilities, and BSI C5 requirements are integrated here. We map the building blocks to concrete cloud services in IT Baseline Protection in the Cloud: Shared Responsibility in Practice.

Insight42: Your Partner for IT Baseline Protection

We support ISO 27001 projects based on IT Baseline Protection for the public sector — from the initial analysis to successful certification and beyond, with managed services for continuous security and compliance.

Start on the secure path. See BSI C5 Beratung (German) or contact us.

AI Won’t Replace People. Bad Incentives Will.

AI In The Public Sector, Azure CAF & Cloud Migration, Sovereignty Series 13th Feb 2026 Martin-Peter Lambert
AI Won’t Replace People. Bad Incentives Will.

The real danger isn’t intelligent machines—it’s incompetent governance. Systemic incentives have a far greater impact than technology alone. True ROI comes from building AI and automation that augments your team, on a cloud foundation you actually control. This article argues why “AI won’t replace people, bad incentives will” should be the real focus of the debate.

AI is Capital: Treat It Like Capital

The discourse surrounding Artificial Intelligence is dominated by futuristic fantasies, obscuring a critical reality: AI is a form of capital — part of the new cloud capital, but more potent. Its value is realised not in the lab but in its effective deployment. The true measure of AI is its impact on the customer and the bottom line. As a professional services company, Insight42 focuses on building AI and automation solutions that deliver tangible business results.

AI as capital: value is realised in deployment, not in the lab

23. AI is not magic; it’s applied statistics plus compute plus workflow integration.

The mystique surrounding AI is a marketing gimmick. The value is unlocked by its application to solve a real-world problem. Demos are easy; deployment is hard. Our expertise in building BI, data warehouses, automation, data analytics and AI focuses on the practical, operational challenges of making AI work in your specific business context.

24. ROI lives in process redesign, not model accuracy.

A highly accurate AI model that isn’t integrated into a redesigned business process is a worthless curiosity. The real return on investment comes from rethinking how work gets done. This is a management challenge. As your partner, we help you with the process redesign necessary to realise the full potential of your investment in AI and automation.

25. The bottleneck is humans-in-the-loop design.

The most effective AI systems augment humans, not replace them. The bottleneck in AI adoption is the design of the human-computer interface. When we build internal tools or AI agents, our focus is on creating a seamless user experience that empowers your team to make better decisions, faster.

26. The first AI win is usually “time back,” not headcount down.

The initial impact of AI is the automation of tedious tasks, freeing up human workers for higher-value activities. This increases productivity and employee satisfaction. Our professional services for building AI and automation aim to empower your workforce, not replace it.

The Model Economy: Costs, Risks, and Rents

The rise of AI has created a new economic landscape. Navigating this requires a partner who understands not just the technology, but also the underlying economics, from the cost of your cloud migration to the long-term resilience of your models.

The model economy: inference cost, data gravity and open models

27. Inference cost is the new unit economics.

The cost of running an AI model in production can quickly spiral out of control. When building your cloud for AI, we design cost-aware architectures that minimise inference costs without sacrificing performance, ensuring your AI initiatives are profitable.

28. Data gravity will decide winners.

Data has mass. The winners in the AI economy will be those who can place their computing resources close to their data. Our cloud migration services are designed with data gravity in mind, helping you choose the right architecture to minimise latency and egress costs.

29. Open models reduce monopoly pricing pressure.

Open-weight models are a powerful force for competition. As part of our services for building AI, we leverage open-source technologies where appropriate to reduce costs and prevent vendor lock-in, giving you more control over your technology stack.

30. AI safety is governance of incentives, not just policies.

A safe AI is one governed by incentives aligned with human values. This requires a focus on truthfulness and auditability — logged decisions, traceable sources and clear approval points, the same principles we build into every production agent.

Human Rights and High Performance Can Be Allies

A commitment to human rights can be a source of competitive advantage, building the trust essential for the widespread adoption of AI. This requires a focus on security and transparency.

Governing AI incentives: due process and operational transparency

31. Due process for automated decisions isn’t “red tape”—it’s legitimacy.

As AI makes increasingly important decisions, the need for due process is paramount. The ability to challenge an automated decision is a fundamental requirement — and under the EU AI Act a legal one for high-risk systems. Our approach to building AI includes creating systems with clear audit trails and human oversight.

32. Transparency must be operational, not philosophical.

True transparency is about understanding the inputs, outputs, and consequences. It’s about creating clear escalation paths. When building BI, data warehouse or AI systems, we prioritise operational transparency to ensure your systems are trusted and adopted.

Build an AI-Powered Future That Works for Your Business

Is your AI strategy built for the future? At Insight42, we design and implement AI strategies that are powerful, profitable, and responsible:

Contact us for a consultation and let Insight42 help you build an AI-powered future that drives real business value.

Data Isn’t the New Oil. That Lie Is Costing Europe Billions.

Azure CAF & Cloud Migration, Growth, Resilience, Sovereignty Series 12th Feb 2026 Martin-Peter Lambert
Data Isn’t the New Oil. That Lie Is Costing Europe Billions.

Oil gets burned once. Data compounds—or rots. “Data is the new oil” is a metaphor that businesses and policy makers cannot afford to keep believing. The difference between compounding and rotting is your strategy for data analytics, BI and AI — built on a sovereign cloud architecture.

Stop Worshipping Volume; Start Pricing Usefulness

The metaphor “data is the new oil” has led to a misguided obsession with hoarding information. The truth is, its worth is determined by the quality of its curation and the incentives that govern its lifecycle. Turning raw data into profit requires a partner capable of building BI, data warehouse automation, data analytics and AI systems that create value from information assets.

A rusty oil derrick versus a vibrant, glowing digital tree: data compounds or rots

12. More data is not better data.

We are drowning in information but starved for wisdom. Junk data is an inflation tax on your analytics, corrupting models and leading to flawed decisions. Quality, not quantity, is the true multiplier of productivity. Our BI and data warehouse automation work starts with a solid foundation of clean, reliable data, so that your AI and analytics initiatives are built for success.

13. Data value is contextual, not inherent.

The value of data is determined by the problem it solves. This is why centralised data strategies often fail. A more effective approach is empowering users with the right tools. Insight42 helps you build the data analytics platforms that connect the right data to the right users at the right time.

14. Most “data strategies” fail because nobody can answer: “Who profits if this works?”

If the people creating and maintaining data don’t have a clear reason to do so, the data will be poor quality. A successful data strategy aligns the incentives of data producers with data consumers. When we build a BI, data warehouse or AI solution, we start by defining the business value and aligning incentives to ensure project success.

15. If data isn’t productised, it’s just digital clutter.

To unlock the true value of data, it must be treated as a product. This means clear ownership, SLAs, and version control. Without this product-oriented mindset, your data lake becomes a swamp. Insight42’s approach to building data platforms is to treat every dataset as a product, with a clear lifecycle and purpose.

Property Rights for the Digital Age

The concept of property rights is the foundation of a free society. In the digital age, we must extend this to personal data, which requires robust security and a rights-first approach to technology, from your core infrastructure to your customer-facing applications.

A digital factory processing raw data into valuable insights

16. Personal data is not a corporate resource; it’s a delegated privilege.

Personal data is a reflection of an individual’s identity. A rights-first approach to data governance is not only ethical; it’s good for business. Our security services ensure that your data handling practices build the trust essential for long-term customer relationships.

Endless pages of legal jargon are not meaningful consent. This is a design problem. When building customer-facing portals and applications, we focus on creating intuitive interfaces that empower users to make informed decisions about their data.

18. Data minimisation is security and cost control.

The best way to protect data is to not have it. Collecting data “just in case” increases breach risk and cloud storage costs. Our cloud migration and data strategy services emphasise data minimisation as a core principle for security and cost control.

19. Auditability is the new credibility.

In a world of deepfakes, proving the provenance and lineage of data is the new standard of credibility. A verifiable audit trail — data lineage, signed artefacts, immutable logs — is essential for trust and for regulators alike.

Data Spaces That Create Growth, Not Committees

Europe’s ambition for a single market for data is worthy, but it must be decentralised and business-friendly. This requires a modern approach to cloud and data architecture.

A decentralised, federated data network across Europe

20. Federation beats centralisation for Europe.

A centralised approach to data sharing is a non-starter. A federated model, where data remains under the owner’s control, is the only viable path. Our expertise in sovereign cloud architectures can help you design a federated data strategy that respects sovereignty and minimises risk.

21. Standards are economic infrastructure.

The digital economy must be built on a common standard of data exchange. When we undertake a cloud migration or build a new data analytics platform, we use open standards and APIs to ensure your systems are interoperable and future-proof.

22. Trust frameworks must be lighter than the value they unlock.

If compliance costs exceed the benefits, markets fail. The frameworks governing data spaces must be business-friendly. Insight42 helps you navigate these regulations, ensuring your AI and data analytics projects remain innovative and profitable.

Turn Your Data from a Liability into a Competitive Asset

Is your data strategy built on a foundation of sand? Insight42 helps you unlock the true value of your data:

Contact us for a consultation and let Insight42 help you build a data-driven future that is both compliant and competitive.

Sovereignty Without Freedom Is Just Bureaucracy: Build a Digital Republic of Individuals.

Resilience, Sovereignty Series 10th Feb 2026 Martin-Peter Lambert
Sovereignty Without Freedom Is Just Bureaucracy: Build a Digital Republic of Individuals.

If “sovereignty” means more centralised control, you didn’t save Europe. True freedom requires security, decentralisation, and systems built to be resilient — and exited — by design.

The Individual is the Smallest Minority

The quest for “digital sovereignty” is fraught with peril. If the end result is a larger bureaucracy, we have not achieved freedom. True sovereignty begins with the individual. In the digital age, this means building an infrastructure of freedom — security, backup, disaster recovery and resilience that protect individual rights in the digital realm.

A single holographic figure within a personal, transparent energy shield

33. Rights are not granted by platforms or states; they’re protected from them.

This is the cornerstone of a free society. Our rights to privacy and property are inherent. Security engineering builds the technical safeguards that protect these rights, ensuring your systems are a fortress for your users and your business.

34. Free speech needs infrastructure, not slogans.

A truly free society requires an infrastructure of free speech: decentralised, interoperable, and censorship-resistant. This is an engineering challenge, not a policy slogan.

35. Identity should be user-controlled and portable.

If your identity is controlled by a platform, your speech is merely permissioned. A user-controlled, portable identity system is the foundation of a free digital society — and, in enterprise terms, the reason identity architecture deserves more attention than any other cloud decision.

36. Encryption is human-rights infrastructure.

Privacy is not a luxury. Encryption is the technology that makes privacy possible — end-to-end, in transit and at rest, with keys you control. See BYOK vs. HYOK.

Competition is a Civil Liberty in Digital Markets

Competition is the freedom to choose. In the digital age, where monopolies can form rapidly, robust competition is more urgent than ever. This requires technical solutions that enable choice — a core principle of how we design cloud migrations.

Interoperability between digital platforms

37. Monopolies don’t need censorship laws to shape speech; they just change algorithms.

The only effective remedy for algorithmic censorship is choice. Systems built on open standards ensure you are never locked into a single vendor.

38. Interoperability is the “freedom of assembly” for software.

Interoperability is the enemy of the walled garden. When building BI, data warehouse, automation or AI platforms, we prioritise interoperability to ensure your systems can communicate and share data freely and securely.

39. Data portability is the right to emigrate.

If you cannot take your data with you, you are a hostage. A true right to data portability must be simple and enforceable. Our cloud migration services are designed to ensure your data is always portable, giving you the ultimate freedom to choose the best provider.

Europe’s Future Tasks: Security That Doesn’t Turn into Control

As Europe builds its digital future, it must not trade freedom for security. The most secure systems are often the most decentralised.

A decentralised network resiliently repelling attackers

40. Security must be measurable and decentralised.

The only viable approach to security is a decentralised one, based on Zero Trust principles. Security assessments and implementation help you move beyond perimeter-based thinking to a modern, measurable security posture for your entire infrastructure.

41. Public digital systems should be “auditable by default.”

Transparency is the best disinfectant. Public digital systems should be designed to be auditable — logged, signed and verifiable by design.

42. Teach sovereignty as capability: build, verify, exit, repeat.

True sovereignty is a dynamic capability. It is the ability to build your own systems, verify their integrity, and exit relationships that no longer serve your interests. That is exactly the capability our sovereign cloud consulting is built to transfer to you.

Build a Digital Future That is Both Secure and Free

Are you ready to build a more free and sovereign digital future? Insight42 builds secure, resilient, and decentralised digital systems:

Contact us for a consultation and let Insight42 help you build a digital future that is not only secure, but also free.

Europe, Stop Renting Your Future: The Cloud Dependency Trap Nobody Wants to Price In

AI In The Public Sector, Azure CAF & Cloud Migration, Sovereignty Series 10th Feb 2026 Martin-Peter Lambert
Europe, Stop Renting Your Future: The Cloud Dependency Trap Nobody Wants to Price In

If your compute, storage, and identity rails are leased, your “sovereignty strategy” is just a press release. True independence requires a cloud strategy with a priced-in exit — and a clear path to digital freedom.

The Bill You Don’t See (Until It’s Due)

For too long, European enterprises have approached cloud adoption as a purely technical decision. This is a profound and costly mistake. The reality is that the cloud is a balance-sheet decision, with hidden liabilities that can cripple an organisation’s financial health and strategic independence. As Milton Friedman taught, incentives are everything. When your provider’s incentives aren’t aligned with yours, you need a partner on your side of the table.

The hidden bill of cloud dependency

1. Cloud is a balance-sheet decision, not a tech preference.

The allure of the cloud is its apparent simplicity. However, this masks liabilities like vendor lock-in and punitive egress fees. These are financial risks. A true accounting of cloud costs must include the cost of data extraction and the risk of service disruption. Our cloud migration assessments include a comprehensive financial analysis so that your move to the cloud is not only technically sound but also financially prudent, with a clear view of the total cost of ownership.

2. The cheapest cloud is often the most expensive option.

The siren song of low unit costs has lured many enterprises onto the rocks of cloud dependency. The initial savings are often eroded by escalating fees and the difficulty of migrating. The “cheap” cloud becomes an expensive landlord. A wise IT leader looks beyond the initial price to long-term resilience and cost control.

3. If you can’t leave in 90 days, you don’t have a supplier—you have a landlord.

A true supplier relationship is one of voluntary exchange. If you are unable to switch providers, you are a tenant. The ability to exit is the ultimate guarantee of fair pricing. We design exit strategies from day one — and test them — so that you maintain control and flexibility.

4. Resilience beats optimisation when geopolitics enters the room.

The pursuit of efficiency at all costs is dangerous. A resilient cloud strategy prioritises redundancy and diversification, ensuring business continuity no matter the external conditions.

Hardware is Strategy (Whether You Admit It or Not)

Europe’s digital ambitions are built on a foundation of sand. A true digital sovereignty strategy must begin with a clear-eyed assessment of the hardware reality.

Hardware as strategy: chips, energy and firmware

5. No chips, no sovereignty.

Without a robust domestic semiconductor industry, Europe will remain a digital vassal. This is a matter of national security — and, at enterprise level, a reason to reduce dependency on single-source suppliers wherever the architecture allows it.

6. Energy is the new compute moat.

A stable and affordable supply of energy is the new moat that will protect a nation’s digital infrastructure. Data-centre energy efficiency and stability belong in every long-term cloud cost model.

7. Security starts below the OS.

Firmware, the supply chain, and trusted execution environments are the new front lines of cybersecurity. A secure cloud is secure from the silicon up — see Building on Bedrock, Not Sand.

A European Cloud That Isn’t a Bureaucratic Cosplay

The dream of a sovereign European cloud is noble, but it is in danger of becoming a bureaucratic nightmare. A true sovereign cloud is about control, interoperability, and the right to exit.

A shield protecting a network of servers: sovereign cloud as control of keys and identity

8. Sovereign cloud isn’t “local hosting.” It’s control of keys, identity, and enforcement boundaries.

True sovereignty lies in the control of encryption keys and user identities. Robust identity and access management and customer-controlled key management give you that control — whichever provider hosts the hardware.

9. Interoperability is the antidote to monopoly rent.

Open standards and portable applications are the keys to a competitive cloud market. Our migration strategies prioritise interoperable technologies, including containerisation and open-source solutions, to prevent vendor lock-in.

10. Procurement can create a market—or kill one.

By prioritising outcomes like portability and auditability, governments can create a more competitive cloud market. We help clients define procurement requirements that foster innovation and give them the flexibility to choose best-of-breed solutions.

11. Build a “right to exit” into every public IT programme.

The most pro-competition policy is a universal “right to exit.” Every IT contract should include a clear exit provision. We help you negotiate these terms to ensure your long-term freedom and control.

Take Control of Your Digital Future with Insight42

Is your organisation trapped in the cloud dependency cycle? Don’t just move to the cloud—migrate with a strategy:

Contact us for a consultation and let Insight42 help you take the first step towards true digital independence.

Cloud Migration Roadmap for the Public Sector: The Path to Digital Sovereignty

AI In The Public Sector, Resilience, Sovereignty Series 9th Feb 2026 Martin-Peter Lambert
Cloud Migration Roadmap for the Public Sector: The Path to Digital Sovereignty

Why Public Authorities Need a Cloud Strategy Now

The digital transformation of public administration is at a turning point. A cloud-first approach is no longer an option; it is a necessity. German authorities must act, and time is of the essence — the Deutsche Verwaltungscloud has become a product, sovereign offerings from AWS, Delos, STACKIT and IONOS are live, and BSI C5:2026 sets the new bar.

A well-designed Cloud Migration Roadmap provides the foundation. It connects technical requirements with regulatory mandates, placing BSI C5 compliance at the core. The ultimate goal is to achieve digital sovereignty in the cloud.

Cloud migration roadmap for the public sector: five phases from assessment to operations

Understanding the Challenge

Public institutions face unique hurdles. A Data Protection Impact Assessment (DPIA) for the cloud is mandatory. IT-Grundschutz must be involved from the start. The procurement of cloud service providers follows strict regulations.

A multi-cloud strategy offers flexibility: Azure and GCP migrations can proceed in parallel, the Cloud Adoption Framework for Azure provides proven methodology, and sovereign platforms complete the ecosystem for workloads with the highest protection needs.

The 5-Phase Approach to Cloud Migration

Phase 1: Assessment and Analysis — Every successful migration begins with an inventory. What workloads exist? What are the dependencies? What protection needs does each carry?

Phase 2: Strategy and Architecture — This is where the actual roadmap is developed. Azure Landing Zone or GCP Landing Zone? Often, the answer is both. Multi-cloud enables freedom of choice.

Phase 3: Compliance and Security — BSI C5 requirements are defined. A BSI-compliant cloud security concept is created. ISO 27001 based on IT-Grundschutz forms the basis.

Phase 4: Migration and Implementation — The datacenter migration is performed step-by-step in waves. VMware-to-Azure migrations use proven tooling. A fixed-price migration offer provides planning security.

Phase 5: Operations and Optimisation — Managed services take over routine operations and ensure availability. Continuous improvement becomes the standard.

Quick Checklist: Cloud Migration Roadmap

StepActionTimeline
1Create Workload InventoryWeek 1-2
2Document Compliance RequirementsWeek 2-3
3Evaluate Cloud ProvidersWeek 3-4
4Plan Landing ZoneWeek 4-6
5Launch Pilot ProjectWeek 6-8
6Finalise Rollout PlanWeek 8-10

To-Do List for Decision-Makers

  1. Today: Appoint an internal cloud champion.
  2. This Week: Initiate an IT landscape assessment.
  3. This Month: Commission an independent cloud readiness assessment.
  4. Quarter 1: Conduct a BSI C5 gap analysis.
  5. Quarter 2: Prepare the cloud migration tender.

Why Multi-Cloud Makes Sense for Public Authorities

A single sovereign cloud alone is often not enough. Specialised services require flexibility. The Deutsche Verwaltungscloud can be combined with Azure, GCP, the AWS European Sovereign Cloud or STACKIT — per workload, by protection need.

The advantages are clear: no vendor lock-in and the best solution for every use case. A cloud framework agreement enables rapid procurement, and comparable offers keep migration costs predictable. We go deeper in Multi-Cloud Strategy for the Federal Administration.

The Next Step

A professional Cloud Migration Roadmap is complex. It requires expertise in technology, compliance and procurement law. Insight42 supports public authorities on this journey, from the initial analysis to ongoing operations — with BSI C5, IT-Grundschutz and NIS2 built into the architecture.

Ready for the first step? See Cloud Migration Beratung (German) or contact us for a non-binding initial consultation.