UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location

UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location
andrew.gertz@t…
Fri, 09/18/2026 – 16:52

Data Security
Cloud Security

Sebastien Pavie |  VP Sales Southern EMEA at Thales
More About This Author >

Cloud has changed how organisations think about resilience, scale and innovation. It has also changed how they need to think about control.

For years, much of the cloud sovereignty conversation has centred on location: where is the application hosted, where is the data stored and which cloud region has been selected? Those questions still matter, particularly in the UK, where organisations across government, telecommunications, critical national infrastructure, financial services, healthcare and the wider public sector need to consider data residency, operational resilience and supplier risk.

But location alone does not answer the most important control questions. Who can access sensitive data? Where are the cryptographic keys protecting it generated and stored? Who controls those keys? How are they used, backed up and destroyed? And can security, compliance and risk teams clearly demonstrate how that control is maintained?

Sovereignty needs to go beyond where infrastructure sits. Organisations also need clear governance and control over the cryptographic trust their critical digital services depend on.

A cloud region is not the whole control boundary

Selecting a UK cloud region is an important step, but it does not provide a complete control model on its own. Cloud and hybrid services depend on multiple layers of protection spanning applications, APIs, identities, signing, certificate authorities, databases, transactions and software supply chains. Across all of these environments, cryptographic keys are a critical point of control.

If an organisation cannot clearly explain where those keys are generated, how they are protected, who can use them, where they are backed up and how access is governed, the assurance story is incomplete. For organisations with UK data residency, governance and sovereignty objectives, that distinction matters. Cloud location answers one question. Key control answers another: who controls the cryptographic keys protecting sensitive services and data?

Why this matters now

The UK cloud conversation is evolving. Organisations are being asked to modernise and move faster while demonstrating stronger governance over sensitive services and third-party dependencies. Regulatory and assurance expectations are also putting greater focus on data protection, resilience, access and control.

UK GDPR brings data protection and transfer considerations into scope, while the NCSC Cloud Security Principles provide a framework covering areas including asset protection, governance, resilience and auditability. Telecommunications providers also need to consider obligations under the Telecommunications Security Act. Public sector organisations have security classification requirements to consider, and financial services organisations face expectations around outsourcing, third-party risk and operational resilience.

The detail varies by organisation and sector, but security, compliance and risk teams increasingly need to show where sensitive assets are protected, how access is governed, how services remain resilient and how cryptographic keys are controlled. For cloud programmes, that means looking beyond location and at the wider control model.

HSM-backed trust, delivered in a cloud model

Hardware security modules have long been used to provide high-assurance protection for cryptographic keys and operations across use cases such as PKI, certificate authorities, application and database encryption, digital signing, code signing, identity systems and high-value transactions.

Cloud adoption does not remove the need for that level of trust. It creates demand for more ways to consume it. Thales Data Protection on Demand (DPoD) provides a cloud marketplace for Thales HSM, data security and encryption services. UK-hosted availability now extends that model locally, beginning with Luna Cloud HSM as the first UK-hosted service available through DPoD.

With UK-hosted Luna Cloud HSM, customer keys are generated, stored, used, backed up and destroyed in the UK. UK-based high availability and disaster recovery capabilities also support resilience and continuity within the UK. For security and compliance teams, that provides a much clearer answer to a fundamental question: where and how is the cryptographic key lifecycle managed? The value is not just UK location. It is local key control and resilience combined with the flexibility of consuming high-assurance HSM capabilities as a cloud service.

The hybrid reality

Most organisations are not moving neatly from on premises to cloud. Some critical systems remain on premises, others

[…]
Content was trimmed to protect the source. Please visit the original article for the full text.

This article has been indexed from Thales CPL Blog Feed

Read the original article: