By Craig Savage | September 24, 2026

Buying tools is not the same as being protected. The industry has known this for years. It is only now, with artificial intelligence accelerating every part of the threat landscape, that the cost of the confusion is becoming impossible to ignore.

There is a particular kind of confidence that comes from a well-populated security dashboard. Patch compliance above ninety percent. Alerts triaged. Vendor contracts renewed. The CISO sleeps reasonably well. The board is told that the organization is secure, and the board, not unreasonably, believes it.

Then something gets in.

It always gets in. The question, the only question that has ever mattered, is what happens next. And on that question, a remarkable number of organizations have spent a great deal of money while remaining almost entirely unprepared.

A comfortable industry built on comfortable assumptions

For the better part of two decades, enterprise security has operated on a settled arrangement. Vendors identify threats. Vendors build products to address those threats. Organizations buy those products, follow the advisories, apply the patches, and trust that the resulting posture is something approximating safe.

It was never quite true, but it was defensible. The timelines were forgiving enough that a diligent team could keep up. Exploits took weeks to develop. The window between disclosure and weaponization was wide enough to act.

Artificial intelligence has closed that window considerably.

Vulnerability discovery is faster. Exploit development, once the domain of nation-state actors and well-funded criminal groups, is being compressed by tooling that requires neither deep expertise nor significant investment. The gap between a researcher publishing a finding and an attacker deploying it against live infrastructure has, in some recent cases, collapsed to hours.

Meanwhile, the environments those attackers are targeting have grown almost incomprehensibly complex. The average enterprise now depends on hundreds of SaaS applications, thousands of API connections, and an identity surface that sprawls across cloud providers, third-party integrations, and remote workforces that nobody fully mapped when they were building it.

Security teams are not failing through incompetence. They are failing through a model that was designed for a simpler world.

What sovereignty actually means

The term security sovereignty tends to provoke a reflexive objection. It sounds like isolationism, a retreat from managed services, a rejection of vendor partnerships, a return to building everything in-house. That is not what is being argued here.

The argument is more precise, and in some ways more demanding.

A sovereign security organization is one that understands its own environment well enough to make its own decisions. It knows which systems are genuinely critical and which are merely expensive. It knows which trust relationships, between internal systems, with third parties, across cloud providers, carry material risk that hasn’t been examined in years. It knows, when something goes wrong at two in the morning, who has the authority to act, what they’re authorized to do, and whether the tools they need are actually under their control.

Outsourcing is not the enemy of sovereignty. Outsourcing judgment is.

Security sovereignty is ultimately about maintaining control over security outcomes, even when the technology, infrastructure, or services involved are provided by others.

An organization can run on AWS, buy its endpoint detection from CrowdStrike, and contract its threat monitoring to an MSSP. That is, in many cases, the right decision. What it cannot do is hand those same parties the responsibility for understanding what a breach would cost, deciding which risks are acceptable to carry, or knowing how to keep operating when the controls it bought turn out not to be sufficient.

Those responsibilities do not transfer. They never did.

The question nobody is asking

Most security programs, if you examine how they report upward, are still organized around a single question: are we patched?

It is not a bad question. It is simply insufficient, and in some organizations, it has become a substitute for harder thinking rather than a complement to it.

A fully patched environment can be comprehensively exposed. An organization can have exemplary patch compliance, a respected threat intelligence feed, and a well-staffed SOC, and still have no clear answer to questions that would be asked in the first hour of a serious incident.

What do we implicitly trust that we haven’t looked at closely? If something moves laterally from that system, where does it go? Which of our SaaS accounts, API tokens, and third-party integrations represent genuine exposure rather than theoretical risk? Who, specifically, can revoke access to our most sensitive systems, and how long does that actually take?

These are not exotic questions. They are the operational baseline of a security posture worth having. The discomfort is that answering them requires a quality of internal knowledge that no vendor can provide, no dashboard can generate, and no contract can substitute for.

Two ideas, one missing piece

Two frameworks have done more than most to sharpen how the industry thinks about this.

Zero Trust, now well past the point of being fashionable, makes a simple but radical demand: stop assuming that anything inside your perimeter is safe. Challenge everything. Remove implicit trust from systems, users, and connections that accumulated it through habit rather than verification.

Exposure management adds necessary rigor to prioritization. A critical vulnerability in an isolated development environment is not the same as a moderate vulnerability in an internet-facing system adjacent to sensitive data. Treat them the same and you will always be doing the wrong work urgently.

Both frameworks are right. Neither resolves the central problem, which is that applying either of them requires judgment, informed, contextual, organizationally grounded judgment about what matters, what can wait, and what the business can and cannot survive.

That judgment cannot be purchased. It has to be developed, maintained, and owned. The organizations that are building it now will be the ones with options when the next serious incident arrives. The ones that haven’t will be waiting for a vendor to tell them what to do.

The measure of it

Sovereignty, in the end, is not measured in certifications or tooling investments or how quickly a team can close a ticket. It is measured in capability under pressure.

Can the organization detect a compromise on its own, before a third party notifies it? Can it contain the damage, understand the blast radius, revoke the access, isolate the affected systems, before an incident becomes a crisis? Can it keep operating while that containment is underway, without waiting for infrastructure it doesn’t control to become available again?

These are the questions that separate organizations that have genuinely invested in security from those that have invested in the appearance of it.

The next phase of the threat landscape will be faster, more automated, and less forgiving of the gap between the two. The organizations that navigate it will be the ones that understood, before they needed to, what they were actually defending, what they were genuinely exposed to, and whether the decisions were theirs to make.

Control, in other words. Not as a product. As a capability.

The debate around AI and cybersecurity has focused heavily on what attackers can now do. The more important question is whether defenders are building organizations capable of responding to it. In an era where compromise is increasingly assumed, control is what determines whether an incident becomes a disruption or a crisis.

Craig Savage
Written By Craig Savage
Craig Savage Craig Savage leads cybersecurity at Spinnaker Support, bringing extensive experience in security transformation, Zero Trust, compliance and enterprise risk. His career includes leadership and consulting roles at Accenture, Capgemini, VMware and VMware Carbon Black. He is a recognized cybersecurity speaker and advisor known for aligning resilient security strategies with business priorities.