Softline IT

Sovereign cloud vs. global hyperscalers: Choosing for critical business data in Ukraine

Sovereign cloud: What it means for Ukrainian business

A sovereign cloud is a cloud infrastructure that complies with national regulatory requirements for data storage, processing, and transfer within a country's borders. Its core principle is that all hosted data is subject to the exclusive control of the state where it was collected, and its processing adheres to national legislation. This model emerged in response to growing geopolitical risks and the need for data confidentiality, especially after the discovery of mass surveillance programs that allowed foreign governments to access data regardless of its physical location.

For Ukrainian businesses, a sovereign cloud offers several advantages. Firstly, it guarantees data localization within Ukraine or approved jurisdictions, which is critical for compliance with local legislation, including requirements for protecting restricted information and critical infrastructure data. Secondly, data access control is governed by Ukrainian law, minimizing the risks of foreign legal acts, such as the US CLOUD Act. Thirdly, sovereign cloud providers in Ukraine, like GigaCloud and De Novo, actively implement architectures that meet the requirements of the Integrated Information Security System (KSZI) and international standards such as ISO 27001, PCI DSS, and hold VMware Sovereign Cloud Provider status. This ensures a high level of physical security and resilience against cyberattacks, along with Ukrainian-language support and the ability to sign contracts with a Ukrainian legal entity.

Global hyperscalers in the Ukrainian context: Opportunities and risks

Global hyperscalers such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) are leaders in the global cloud market, offering unprecedented scalability, a wide range of innovative services, and a global infrastructure. These platforms enable companies to rapidly deploy and scale IT infrastructure, access advanced technologies like artificial intelligence and machine learning, and ensure high service availability worldwide.

However, for Ukrainian businesses, especially for hosting critical data, using global hyperscalers carries significant risks. The key issue is jurisdiction and data sovereignty. For example, the US CLOUD Act allows US government agencies to demand data disclosure from American cloud providers, regardless of where the servers are physically located. This means that even if a Ukrainian company's data is stored in a hyperscaler's data center in Europe, it could potentially fall under US jurisdiction, which contradicts the logic of data protection and Ukrainian legislation. Geopolitical risks also play a significant role, creating dependence on decisions made outside Ukraine and potential restrictions on data or service access. While hyperscalers offer a high level of security at the infrastructure level, responsibility for data protection at the application and configuration levels lies with the client, requiring substantial internal expertise.

Selection criteria: How to evaluate a provider for critical data

Choosing a cloud provider for critical data in Ukraine requires a thorough analysis based on several key criteria:

  • Cost (TCO): Evaluate not only direct tariffs but also the total cost of ownership (TCO), including migration, management, support, and potential penalties for non-compliance with regulatory requirements. Sovereign providers often offer more transparent pricing models with fixed monthly rates.
  • SLA (availability, recovery): Ensure that the Service Level Agreement (SLA) guarantees the necessary level of availability (e.g., 99.95% or higher) and clearly defines Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for Disaster Recovery as a Service (DRaaS).
  • Data localization (Ukraine): For critical data, especially those subject to state regulation or critical infrastructure requirements, the physical location of data centers in Ukraine is a priority. Some Ukrainian providers also offer hosting in the EU for geographical dispersion.
  • Certifications and compliance: The provider must have relevant Ukrainian certifications (KSZI, State Service of Special Communication and Information Protection certificate) and international ones (ISO 27001, PCI DSS, GDPR, NIST). This confirms the maturity of security and compliance systems.
  • Geographical dispersion and DR capabilities: The availability of multiple geographically dispersed availability zones within Ukraine and/or the EU is important for ensuring disaster resilience and business continuity. Pay attention to DRaaS offerings.
  • Support level: Evaluate the quality, language, and response time of customer support. For Ukrainian companies, Ukrainian-language support and understanding of local specifics can be a significant advantage.
  • Legal jurisdiction and data protection: Contract terms must clearly define the jurisdiction under which the data falls. Ukrainian sovereign providers enter into contracts with a Ukrainian legal entity, ensuring data protection in accordance with national legislation.
  • Resilience to cyberattacks and physical threats: Assess the provider’s security measures, including physical data center protection (Tier III/IV), DDoS protection systems, Multi-Factor Authentication (MFA), data encryption, and the presence of SIEM and PAM systems.

Comparative table: Sovereign cloud vs. global hyperscalers for Ukraine

CriterionSovereign cloud (Ukraine)Global hyperscalers (AWS, Azure, GCP)
Cost (TCO)Transparent pricing models, often fixed rates, payment in UAH. Can be more optimal for predictable workloads.Flexible pay-as-you-go models, complex pricing, payment in foreign currency. Can be more expensive for critical data due to additional security and compliance services.
SLA (availability, recovery)High availability guarantees (Tier III/IV data centers, 99.95%+), clear RPO/RTO for DRaaS.Very high global SLAs, but RPO/RTO for DRaaS may require additional configurations and costs.
Data localization (Ukraine)Data stored in data centers within Ukraine, ensuring full compliance with local legislation.Data may be stored in data centers outside Ukraine (e.g., EU), creating jurisdiction risks despite physical location.
Certifications and complianceKSZI, ISO 27001, PCI DSS, NIST, VMware Sovereign Cloud Provider. State Service of Special Communication and Information Protection certificate.Wide range of international certifications (ISO, SOC 2, HIPAA, GDPR), but compliance with Ukrainian KSZI may be more complex or absent.
Geographical dispersion and DR capabilitiesMultiple availability zones in Ukraine (Kyiv, Lviv), possibility of geo-redundancy in the EU, DRaaS offerings.Global network of data centers, extensive DR capabilities, but with potential legal risks for data leaving Ukraine.
Support levelUkrainian-language support, deep understanding of local specifics and regulatory requirements.Global support, may be multilingual, but less adapted to the Ukrainian context and regulations.
Legal jurisdiction and data protectionData falls under Ukrainian jurisdiction, contracts with a Ukrainian legal entity, protection according to national legislation.Data may fall under the jurisdiction of the provider’s country of origin (e.g., USA via CLOUD Act), even if physically located in another country.
Resilience to cyberattacks and physical threatsTier III/IV data centers, comprehensive cybersecurity measures (DDoS, PAM, SIEM, encryption, MFA), experience working under wartime threats.High level of cybersecurity and physical infrastructure protection, but potential risks associated with foreign government access to data.

Implementation and migration strategies: Minimizing risks

Deciding to place critical data in the cloud requires not only choosing a provider but also developing a clear implementation and migration strategy. The first step should be a comprehensive risk assessment that considers data sensitivity, regulatory requirements, and potential threats. To minimize risks, Ukrainian companies are increasingly considering hybrid and multi-cloud strategies, which allow combining the benefits of sovereign cloud solutions for the most critical data with the capabilities of global hyperscalers for less sensitive workloads.

An important element of the strategy is planning for Disaster Recovery as a Service (DRaaS) and a Business Continuity Plan (BCP). DRaaS ensures rapid recovery of IT infrastructure and data in case of failures or disasters, using cloud resources for replication and restoration of critical services. It is necessary to consider the geographical dispersion of DR sites, preferably in different availability zones or even in different countries (Ukraine and the EU), to ensure maximum resilience.

The role of a system integrator in this process is crucial. Experts can help companies audit their current infrastructure, assess compliance with legal requirements, choose an optimal cloud strategy, plan and execute secure migration, and develop and implement business continuity plans. Softline IT assists in planning and implementing cloud solutions: from current state audit to an agreed-upon change plan. This allows companies to effectively manage risks, ensure business continuity, and protect critical data in the face of ongoing challenges.

Softline IT helps teams plan and implement cloud and hybrid solutions, from an assessment of the current environment to an agreed change plan.

Sources used

  1. 01dev.uadev.ua
  2. 02denovo.uadenovo.ua
  3. 03onecloudplanet.comonecloudplanet.com
  4. 04karachun.com.uakarachun.com.ua
  5. 05livebusiness.com.ualivebusiness.com.ua
Tags