eco - Verband der deutschen Internetwirtschaft e.V.

09/30/2026 | News release | Distributed by Public on 10/01/2026 04:57

Interview: Digital Sovereignty Starts with the Hardware

Digital sovereignty is often associated with cloud services, software and control over data. Prof. Georg Sigl, Director of Fraunhofer AISEC, starts at an earlier point: for him, technological sovereignty begins with the chips on which digital systems are built. In this interview, he explains why trustworthy hardware, diversified supply chains and in-house chip design expertise are crucial and what companies can do to reduce their dependence on individual manufacturers.

You can find out more about the topic "Digital Sovereignty: From the Sensor to the Cloud" in Mr Sigl's presentation at the eco Internet Security Days on 14 October in Munich!!

Digital sovereignty begins at the hardware level. If you cannot ensure that data and programs are processed correctly and securely in the chips, this poses a problem, particularly where critical infrastructures are controlled or safety properties could be compromised. Furthermore, all software security measures rely on hardware security functions. Even in cloud systems using Confidential Computing, you still have to trust the manufacturer of the chips. It is only the cloud provider that no longer has to be assumed to be trustworthy. Another problem arises from digital products, almost all of which are now connected to the Internet. The servers are usually located in the manufacturer's country and are therefore beyond the reach of European legal standards. The ability to install software updates, which is essential for security updates, also increases the risk that unwanted modifications could subsequently be made to the product via this interface.

Fraunhofer AISEC conducts extensive work on trustworthy electronics and the security of hardware and supply chains. How much technological independence does Europe need when it comes to key components such as chips?

As with any externally sourced component, the most important thing is to avoid becoming dependent on a single supplier. This requires a very detailed understanding of semiconductor supply chains. Monocultures must also be avoided; in other words, chips should always be available from multiple sources, even if this may require additional development work for the product manufacturer. Devices such as computers and network components should likewise be sourced from different manufacturers, even if this increases maintenance costs and may mean foregoing manufacturer-specific features that deviate from established standards.

Europe should focus in particular on strengthening its chip design capabilities. Firstly, this requires considerably less investment than chip manufacturing and is the key lever for greater independence. Having chips produced by different manufacturers spreads the risk associated with dependencies.

Another advantage of developing chips in-house is that you know what they contain and can therefore eliminate the risk of built-in backdoors or even Trojans. The availability of open-source architectures such as RISC-V and freely available implementations makes it easier to get started with chip design.

Another important factor is having the necessary analysis capabilities. We must be able to analyse supplied chips in terms of their security and trustworthiness. This requires very well-equipped laboratories capable of analysing even the most advanced chips for their built-in functions and potential side channels.

At the Internet Security Days in Munich, you'll examine digital sovereignty from a technical perspective - from the chip to the cloud. What should companies bear in mind if they want to gain more control over their digital infrastructure?

In my view, the most important thing is to avoid monocultures and becoming dependent on hardware or software from individual manufacturers.

A certain degree of supplier diversity reduces the risk of outages and attacks. Furthermore, greater flexibility enables companies to respond quickly to crises. This flexibility is also a commercial factor: if you are dependent on a single supplier, the consequences will become apparent no later than the next licence negotiation or when ordering new chips.

eco - Verband der deutschen Internetwirtschaft e.V. published this content on September 30, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on October 01, 2026 at 10:57 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]