Summary
The core message of this session is that digital dependency should not only be measured by vendors, systems, or cloud providers, but also by jurisdiction: if a country’s legal or political influence over a provider can create operational impact, that exposure belongs explicitly in enterprise risk management. Jeroen Gaiser and Domenico Essoussi introduce “single country of failure” as a practical reframing of digital sovereignty and autonomy. Rather than proposing a new grand framework, they argue for adding a country-influence dimension to existing risk models so boards can make decisions based on structured exposure, not fluctuating geopolitical headlines.
The speakers build the case through geopolitical examples. They begin with the 2019 U.S. restriction that prevented China from using Android in the same way as before, emphasizing that the impact was not only about a phone operating system but also updates, app distribution, and the wider mobile app ecosystem. They then move closer to The Hague with the International Criminal Court example, describing how sanctions against individuals can have organizational consequences. The point is not to focus on the United States specifically; the speakers explicitly say this is not “Trump bashing” and that many countries can influence digital systems because key parts of digitization are concentrated geographically.
They expand the risk lens beyond familiar IT assets. Examples include Israeli dominance in some call-center software, connected Yutong buses that could affect public transport, warnings from Dutch intelligence services about connected cars, and American and Chinese “webcams” driving around the Netherlands. The talk compares this concentration to the Dutch disease: the Netherlands once became economically dependent on gas because it was easy and profitable, while other industries weakened. In technology, relying on foreign-developed software, cloud, and infrastructure has similarly been easy—often “one license click away”—but that convenience can create hidden geopolitical fragility.
The practical proposal is to integrate jurisdictional dependency into familiar risk practices, especially those already aligned with ISO 31000. The speakers recommend starting with known critical assets, then mapping the supply chain more broadly than paid suppliers, including free or bundled services such as Let’s Encrypt. They stress that organizations should define their own geopolitical profile rather than pursue maximum digital sovereignty by default. Finally, they introduce an exposure assessment approach using time-to-effect: how quickly a sanction or access loss could affect critical services. The example of an Indian refinery losing Microsoft 365 access after four days following an EU sanctions package illustrates how messy cross-jurisdictional dependencies can be—and why they still need to be mapped.
Key Topics
5 key topics from Domenico Essoussi and Jeroen Gaiser at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Add country influence to enterprise risk registers.
- Map free and bundled providers, not only paid suppliers.
- Assess how fast jurisdictional disruption impacts critical services.
- Align single-country exposure analysis with ISO 31000.
- Prioritize sovereignty work based on your geopolitical profile.
“If jurisdictional dependence can cause operational impact, it should really be an explicit part of your enterprise risk management model.”
Up Next


Next in agenda
The good, the bad, and STIX/TAXII



Also on digital sovereignty
Digital sovereignty: the hard way or the highway?


Also on cyber resilience
