Building Your Geopolitical Firewall Before You Need One
- By Winston Thomas
- November 26, 2025

Where does your corporate sovereignty end? Is it with cloud hosting that your office uses for its room booking system? Or the patient records feeding a healthcare AI? The difference between those two data points and knowing where to draw the line is now the defining, existential challenge for infrastructure leaders in 2026.
“The question that needs to be asked, and maybe it’s slightly philosophical, is where do you draw the line?” reiterates Matthew Oostveen, chief technology officer for Asia Pacific and Japan at Pure Storage. “Where is the point where you’re willing to cede your sovereignty?”
In today’s world, where regulators are rolling out data sovereignty and localization initiatives that turn every cross-border workflow into a compliance nightmare, this is no theoretical exercise. Service disruption has shifted from possibility to inevitability, and geopolitical moves can shut down operations overnight. For storage engineers and data infrastructure leaders, the challenge goes beyond mere compliance – it’s about building genuine operational independence before circumstances force your hand.
The illusion of immunity
Most organizations would love to treat compliance as a finish line, but Oostveen hasn’t met many senior leaders who believe that’s realistic. “There’s a sense of inevitability that it pivots, and that it changes, and that organizations are inevitably a cork in the ocean of compliance and regulation that changes consistently,” he explains.
The reality is messier than any compliance framework suggests. Data sprawls everywhere, from edge, cloud and core to laptops and mobile devices. Building walls around everything does not offer true operational independence. Instead, it’s really about having the data infrastructure flexibility to move workloads when regulations shift, when geopolitical tensions escalate, or when a foreign government’s legislative reach suddenly extends into your data center.
“[Data infrastructure flexibility] is about empowering customers, giving them choice, and allowing them to avoid lock-in where possible,” Oostveen notes. But where most enterprises fall short is when they try to achieve this with infrastructure decisions made by predecessors years ago, often locked into long-term contracts with cloud providers that predate current geopolitical realities.
Interested in knowing more about architecting your data infrastructure for data sovereignty? Join Matthew Oostveen and leading practitioners as they discuss the same article topic online on 15 January 2026. To register or find more information about this webinar, which is part of the Pure Leadership Series, click here.
The sovereign stack triage
For large organizations, there could be over 1,000 applications of all sizes and importance spread across the entire company. The idea of assessing and securing all of them can overwhelm IT teams who are already overstretched. Oostveen’s advice is more pragmatic: don’t make this solely an IT problem.
“It should be done in collaboration with the CDO, with support of the CEO and the board, as well as the legal and compliance divisions,” he says. Stack-rank applications by sovereign criticality. Healthcare AI models trained on patient records? Top of the list. The office room booking system? Probably not.
But drawing that line requires architectural flexibility. That’s where the hybrid approach becomes essential. It provides a practical framework for balancing sovereignty requirements against operational agility. Technologies like S3-compatible object storage in sovereign data centers, container orchestration with stateful storage capabilities, and infrastructure that can bind together investments across geographies become the building blocks of resilience.
Unmasking the cloud’s true owner
When evaluating sovereign solutions, storage engineers typically focus on SLAs and certifications. However, Oostveen argues that the critical question is simpler and more fundamental: who actually owns the solution or the service provider?
“If you’re truly sovereign, my view is that you (the solution provider) are a company that is owned and operated exclusively within the borders of that particular jurisdiction,” he explains. A Singaporean company in a Singaporean data center, bound by Singaporean law — that’s sovereignty. However, if that entity is owned by a foreign company, such as Tencent, Alibaba, or U.S. hyperscalers, it’s subject to the legislation of multiple jurisdictions.
“Understanding the ownership structure is probably the most important component,” Oostveen says. It’s due diligence that matters more than any feature checklist.
The head gasket opportunity
Here’s Oostveen’s prediction for 2026: virtually no organizations in the Asia Pacific will undertake IT transformation projects based solely on sovereignty concerns. The lift is too heavy, the disruption too significant.
Instead, he expects the focus to shift to “plus sovereignty” projects, which are initiatives that tackle sovereignty alongside other pressing needs. Think cost extraction plus sovereignty, security plus sovereignty, or cloud repatriation plus sovereignty.
He uses a car analogy: “I take my classic V12 Jag down to the garage for a head gasket replacement. It’s 10 hours of work just to get to the engine. While they have the covers off, let’s change those valves, inspect those pistons, and replace anything that’s likely to fail soon. Sure, there’s extra cost, but I’ve gotten a lot more accomplished.”
This is the practical reality for infrastructure leaders. If you’re going to assess workloads, analyze data placement, and redraw architectural boundaries, you might as well address performance bottlenecks, extract cloud waste, and strengthen security posture at the same time.
Failing to predict, winning through choice
Nobody can predict exactly what AI regulations or critical infrastructure mandates will look like in 24 months. After DeepSeek’s emergence earlier this year, that uncertainty is clearer than ever. The answer isn’t perfect foresight, but having an architectural choice.
“If [uncertainty] is the case, then choice is what matters,” Oostveen says. “[It is about] being able to have a flexible underlying infrastructure that enables you to head in any number of particular directions depending on the forces that are placed upon it.”
For storage engineers, this means infrastructure that supports multiple billing models, enables container mobility with stateful storage, and meshes data investments across distributed locations. It’s about building resilience into the foundation, not scrambling to add it when geopolitics force your hand.
Vendors are beginning to realize the importance of this type of resilience. For example, Pure Storage is rearchitecting its data sovereignty strategy around its Enterprise Data Cloud architecture and tools, such as Pure Fusion. The idea is to empower customers to control where their data sits, who can touch it, and how fast it can move. The unified platform allows them to create a stack-rank strategy — keeping critical workloads sovereign while leveraging the public cloud for the rest without being locked into any single provider’s political jurisdiction or proprietary stack.
More importantly, such initiatives acknowledge a fundamental truth: the geopolitical firewall isn’t a static perimeter you build once. It is the constant, fluid architecture of strategic retreat, built to ensure your operations outlive any government’s mandate.
Image credit: iStockphoto/bowie15
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.