|
Getting your Trinity Audio player ready...
|
Boards Prepare for Digital Infrastructure Shocks Amid Rising Cyber Risk, Capgemini Survey Finds
Corporate boards that once treated digital infrastructure as a background operational concern are now putting it on the same level as energy supply and physical logistics, according to a new survey from consulting firm Capgemini. The findings, based on responses from executives at 1,300 large organizations across 11 countries, suggest that dependence on cloud providers, data centers, and telecommunications networks has moved from an assumed convenience to a recognized strategic vulnerability, one that now requires the kind of board-level oversight and contingency planning previously reserved for physical supply chain risk.
Nicolas Gaudilliere, the Capgemini executive who led the study, summed up the shift plainly, saying there used to be a general sense of these risks but that they have now become concrete. That distinction matters. For years, conversations about digital dependency were often theoretical, framed around what could go wrong in a worst-case scenario rather than what had actually happened. The survey suggests that period is over, and boards are now responding to incidents that have already occurred rather than hypothetical ones.
Gaudilliere pointed directly to recent geopolitical events as the catalyst for that change, citing attacks on data centers and telecommunications infrastructure during the conflicts in Ukraine and the Middle East as examples of risks that have become impossible to ignore. Those conflicts turned what had largely been an abstract cybersecurity conversation into a demonstration of how quickly physical attacks on digital infrastructure can disrupt operations for organizations that never expected to be directly affected by a regional conflict. When data centers and network infrastructure become military targets, companies relying on that infrastructure for everyday operations inherit a risk they had little role in creating and even less ability to control.
That realization is pushing some organizations toward concrete structural changes rather than just updated risk registers. The survey noted that companies including aerospace manufacturer Airbus have already begun adjusting their operations to reduce dependency on specific technologies and providers, a move that reflects a broader trend of large organizations trying to build in redundancy rather than relying on a single vendor or a single geographic region for critical digital services. For a company like Airbus, which operates across multiple countries and depends heavily on interconnected digital systems for design, manufacturing, and supply chain coordination, reducing single points of failure is not a minor operational tweak, it is a fundamental shift in how technology procurement decisions get made at the executive level.
Central to the survey’s findings is the concept of digital sovereignty, a term that has gained traction across corporate and government circles over the past few years but has often lacked a clear, actionable definition. Charles-Pierre Astolfi, chief information officer at France’s National Institute of Geographic and Forest Information, offered a more grounded explanation, describing digital sovereignty as fundamentally about substitutability, meaning the practical ability to replace a critical technology or provider when circumstances demand it. That framing shifts the conversation away from abstract questions of who owns or controls a given piece of technology and toward a more operational question: if a provider becomes unavailable or unreliable, how quickly can an organization pivot to an alternative without disrupting its core business.
Gaudilliere was careful to note that this concern is not confined to any single region or geopolitical alignment. He said the issue is not a geographical notion and that the framing is not about opposing countries against one another. Instead, he argued, the real question organizations need to answer is less about who supplies a given technology and more about whether they retain the practical ability to switch providers if circumstances require it. That distinction is important because it reframes digital sovereignty as a resilience and business continuity issue rather than a purely political one, making it relevant to organizations across the United States, Europe, and Asia regardless of their specific geopolitical alignment.
The survey’s data on how difficult that switching actually is reveals just how exposed many organizations currently are. Nearly half of the organizations surveyed said replacing a critical technology provider would take between three months and a year, while more than a third estimated it would take longer than a year entirely. Those numbers translate directly into risk exposure. If a critical cloud provider, chip supplier, or network operator becomes unavailable due to a cyberattack, export control change, or geopolitical disruption, a majority of large organizations would be stuck for months, and a significant minority would be stuck for over a year, before they could realistically transition to an alternative. In an environment where AI infrastructure, export controls on advanced technology, and regional conflicts are all evolving quickly, that kind of lag time represents a serious operational vulnerability that many boards are only now beginning to fully grasp.
Rather than pursuing wholesale replacement strategies for every critical technology provider, which the survey suggests would be prohibitively expensive and logistically unrealistic for most organizations, companies appear to be focusing their resilience efforts more narrowly. The emphasis has shifted toward retaining control over the assets that would be hardest to replace or recreate if access were suddenly disrupted, specifically proprietary data, trained AI models, and other intellectual property that represents years of accumulated organizational knowledge. That focus makes practical sense. A company can often switch cloud computing vendors given enough time and budget, but reconstructing a proprietary AI model trained on years of internal data, or recovering intellectual property that existed only within a compromised system, is a fundamentally different and often irreversible kind of loss.
This shift also has implications for how boards are staffing themselves. Broader industry commentary tied to the survey noted that data center and infrastructure-adjacent boards are refreshing their composition more quickly than in the past specifically to close gaps in technical and resilience expertise, suggesting that traditional corporate governance experience alone is no longer considered sufficient for overseeing digital infrastructure risk at the board level. That trend points toward a longer-term change in corporate governance itself, where technical fluency around cloud architecture, supply chain resilience, and cybersecurity is becoming a baseline expectation for board members rather than a specialized skill delegated entirely to a chief information officer or chief technology officer.
Taken together, the Capgemini findings describe an inflection point rather than a one-time warning. Digital infrastructure has quietly become as strategically important to large organizations as energy grids and physical logistics networks, and the geopolitical events of the past few years have made that dependency, and its risks, impossible for corporate boards to keep treating as someone else’s problem.