The EU Preparedness Union Strategy, issued by the European Commission as a Communication in 2024, establishes digital continuity as a foundational element of European crisis resilience. Where earlier frameworks treated cyberattacks and infrastructure disruption as sectoral concerns, the Strategy frames them as whole-of-society threats that demand pre-positioned, operationally tested responses. For compliance officers, CISOs and IT decision-makers in essential and important entities, this reframing carries immediate implications: foreign-cloud dependency is no longer a risk to be managed at the margin; it is a structural vulnerability that regulators, and increasingly policymakers, expect to see addressed before a crisis occurs.
What the EU Preparedness Union Strategy demands of critical digital infrastructure operators
The Strategy sets an expectation that operators of critical digital infrastructure can sustain regulated operations across three distinct disruption scenarios: sustained internet or connectivity outages, coordinated hybrid attacks targeting multiple infrastructure layers simultaneously, and the involuntary or forced loss of access to foreign-controlled cloud platforms.
Each scenario has a different threat vector, but they share a common dependency: organisations that have offloaded authentication, storage, communication and workflow tooling to US-headquartered hyperscalers face a single point of geopolitical failure. The Strategy’s whole-of-government risk framework explicitly anticipates scenarios in which access to foreign-controlled systems may be interrupted not by the operator’s choice but by regulatory action, geopolitical escalation or adversarial interference with cross-border data infrastructure.
The Strategy also reinforces the EU Cyber Solidarity Act’s mutual-assistance logic: member states and regulated operators are expected to have pre-agreed response postures, not improvised reactions. ENISA’s Cybersecurity Stress-Test Handbook provides the methodological backbone for how those postures are validated.
NIS-2 Article 21 and the minimum resilience posture for essential entities
NIS-2 Article 21 of Directive 2022/2555 defines the security measures that essential and important entities must implement, and business continuity sits explicitly within its scope, covering backup management, disaster recovery and crisis management as non-optional obligations.
The relationship between the Preparedness Union Strategy and Article 21 is one of policy amplification rather than legal duplication. The Strategy sets the threat picture; Article 21 defines the measurable minimum. Together they establish a resilience posture that has three non-negotiable properties: the continuity plan must be documented, it must be tested against realistic scenarios, and it must be proportionate to the entity’s actual risk exposure. A financial services firm that processes payment instructions or a hospital that holds patient records cannot satisfy Article 21 with a plan that assumes internet connectivity will always be available.
According to ENISA’s NIS Investment Report 2024, approximately 37 percent of surveyed essential entities in the EU had not conducted a full continuity test in the prior 12 months. That figure indicates that a substantial share of entities nominally covered by NIS-2 remain out of compliance with one of its most concrete requirements.
The EU Council, framing the rationale for NIS-2, stated: “The security of network and information systems is essential for the functioning of the internal market and must be treated as a matter of public order.” That framing is consequential: it signals that competent authorities are expected to treat untested continuity plans not as administrative shortfalls but as public-order risks.
Hybrid-threat scenarios and the attack surface created by foreign-cloud dependency
The Preparedness Union Strategy’s threat taxonomy includes hybrid attacks that operate below the threshold of armed conflict but are designed to degrade critical infrastructure. Three specific vectors are particularly relevant to digital continuity: GPS spoofing, BGP hijacking and submarine cable severance.
| Hybrid threat vector | Primary digital continuity impact | Amplified by foreign-cloud dependency? | Mitigated by sovereign on-premises infrastructure? |
|---|---|---|---|
| GPS spoofing | Timestamp corruption in PKI, logging systems and financial settlement | Yes: cloud-based time services inherit the spoofed signal | Partial: local NTP with hardware time sources reduces exposure |
| BGP hijacking | Traffic rerouting away from legitimate cloud endpoints; authentication failures | Yes: all cloud-dependent authentication paths become unreachable or interceptable | Substantial: on-premises identity and DNS remove the dependency on external routing |
| Submarine cable severance | Loss of transatlantic or inter-European connectivity; cloud platform unreachable | Critical: US-hosted hyperscalers become entirely inaccessible | Full: locally hosted workloads continue without any cross-border data flow |
ENISA’s Threat Landscape 2023 reported that 42 percent of critical infrastructure organisations experienced at least one significant disruptive cyberattack during the year. Hybrid techniques, including BGP manipulation and GPS interference, have been documented in multiple incident reports involving state-affiliated actors operating in the European theatre.
An organisation whose authentication, email, collaboration and file storage all depend on a US-headquartered cloud provider has effectively delegated its operational continuity to infrastructure it neither controls nor can inspect. When BGP hijacking redirects traffic or a cable cut removes transatlantic capacity, that delegation becomes a hard failure with no internal fallback.
Designing an offline-capable fallback operating mode
An offline-capable fallback is not a disaster recovery plan stored in a binder. It is a pre-tested operational configuration that allows an entity to continue regulated workflows without any external connectivity for a defined minimum period, typically 72 hours as a starting point aligned with NIS-2 incident reporting timelines.
The architecture requires four independently functioning components. First, local authentication: a directory service deployed on-premises that can issue and validate credentials without contacting any cloud-based identity provider. Second, air-gapped or network-isolated backup repositories with verified, regularly tested restoration procedures. Third, on-premises DNS resolution, so that internal services can locate each other without querying external resolvers that may be unreachable or compromised. Fourth, documented runbooks that have been rehearsed by actual operations staff, not just IT teams, covering how to conduct regulated activities including audit logging and access-control enforcement during the blackout.
ETSI EN 301 406 and related ETSI resilience standards provide technical specifications for communication system resilience that inform how local voice, messaging and signalling infrastructure should be architected to function in isolation. These standards are relevant beyond telecommunications: they describe the principle that each node must be capable of autonomous operation, which applies equally to identity, DNS and backup systems in a sovereign stack.
Tabletop exercises, DORA TLPT and joint continuity drills
The Preparedness Union Strategy endorses multi-actor crisis simulation as a validation mechanism, not merely a training exercise. For regulated entities, this maps directly onto two binding test requirements: NIS-2 Article 21’s implicit requirement that continuity measures be proportionate and demonstrably effective, and DORA Article 26’s explicit mandate for threat-led penetration testing (TLPT) of significant financial entities at least every three years.
DORA TLPT, aligned with the TIBER-EU methodology, differs from conventional penetration testing in that it simulates live adversary behaviour against production systems using threat intelligence specific to the entity being tested. A financial entity using a sovereign infrastructure provider must ensure that its TLPT scope includes the provider’s environment and the integration points between them, not just the entity’s own endpoints.
The ENISA Cybersecurity Stress-Test Handbook provides a structured format for multi-actor drills that sovereign hosting providers and their regulated customers can adapt. A joint continuity drill structured around a submarine cable severance scenario, for example, should test: whether the customer’s fallback authentication works without the provider’s internet-facing services; whether the provider’s Swiss-hosted environment continues to serve EU customers without transatlantic routing; and whether incident logs generated during the exercise are sufficient to satisfy a post-incident audit by a competent authority under NIS-2.
Joint exercises also satisfy the Preparedness Union Strategy’s whole-of-government coordination expectation. A sovereign provider that has pre-agreed exercise schedules with multiple essential-entity customers can demonstrate to national competent authorities that its infrastructure has been stress-tested at a realistic operational scale.
Swiss-hosted sovereign architecture for EU customer continuity during cross-border disruption
A Swiss-hosted sovereign environment designed to maintain service to EU customers during geopolitical disruption or emergency network-isolation measures requires both physical and logical architecture choices that are made before the disruption occurs.
At the physical layer, the data centre must have on-site power generation capable of operating for at least 72 hours without grid connection, diverse fibre entry points from at least two physically separate cable routes, and no single upstream provider that itself depends on US-controlled transit capacity. Swiss jurisdiction is significant here: under the revised Federal Act on Data Protection (FADP), in force since September 2023, Swiss providers cannot be compelled to hand over data under the US CLOUD Act or FISA 702, which removes a specific legal attack surface that persists even in EU-based deployments of US-headquartered hyperscalers.
At the logical layer, the environment must be designed so that EU customer workloads including file access, authentication, communication and workflow tooling continue to function if the cross-border network path between Switzerland and the EU is severed or isolated. This means caching authentication tokens with sufficient validity windows, replicating DNS zones locally within each site, and ensuring that any application dependencies on external APIs are either eliminated or mirrored locally.
IBM’s Cost of a Data Breach Report 2024 recorded the average cost of a data breach at USD 4.88 million, the highest figure in the report’s history. That figure does not capture regulatory fines, reputational damage or the operational cost of an extended continuity failure. The European Commission, in the 2024 Preparedness Union Strategy Communication, stated plainly: “Preparedness is not a luxury or a niche concern. It is a fundamental responsibility of governments and of society as a whole.” For essential entities still evaluating whether sovereign infrastructure is worth the investment, the cost calculus is increasingly clear.
FAQ
Does the EU Preparedness Union Strategy create direct legal obligations for private-sector organisations?
The 2024 Commission Communication is a policy framework rather than directly binding legislation. Its obligations become enforceable through existing instruments such as NIS-2, DORA and the CER Directive. Organisations subject to those sectoral laws must already satisfy the continuity requirements the Strategy articulates; the Strategy adds political urgency and cross-sector coordination expectations on top.
What specifically does NIS-2 Article 21 require regarding business continuity?
Article 21 of Directive 2022/2555 requires essential and important entities to implement measures covering backup management, disaster recovery and crisis management. These measures must be proportionate to the risk, and competent authorities can audit their effectiveness. A plan that has never been tested against a realistic disruption scenario is unlikely to satisfy the proportionality requirement.
How does DORA Article 26 differ from NIS-2 continuity obligations for financial entities?
DORA Article 26 mandates threat-led penetration testing for significant financial entities at least every three years, using methodologies aligned with TIBER-EU. Unlike NIS-2’s broader continuity framing, TLPT specifically simulates adversary behaviour against live production systems, which makes it a more operationally intensive requirement. Financial entities subject to DORA must satisfy both frameworks simultaneously.
Why does Swiss hosting under the revised FADP reduce foreign-jurisdiction risk compared to EU-based hyperscalers?
Swiss law does not include a provision equivalent to the US CLOUD Act, which compels US-based providers to hand over data stored anywhere in the world in response to US law enforcement requests. Swiss providers operating solely under the revised FADP are bound by Swiss data-secrecy obligations and cannot be compelled under US or other foreign statutes. This jurisdictional separation removes a specific attack surface that persists even in EU-datacenter deployments of US-headquartered hyperscalers.
What is the minimum architecture for an offline-capable fallback that satisfies NIS-2 continuity expectations?
At minimum: on-premises identity and authentication that does not depend on cloud-based identity providers; air-gapped or network-isolated backup repositories with tested restoration procedures; local DNS resolution that does not rely on external resolvers; and documented runbooks that have been exercised in a connectivity-blackout simulation. The fallback must allow regulated workflows, including audit logging and access-control enforcement, to continue without any external connectivity.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
