THALES BLOG

UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location

September 18, 2026

Sébastien Pavie Sébastien Pavie | Vice President of Sales for EMEA, Thales More About This Author >

Cloud has changed how organisations think about resilience, scale and innovation. It has also changed how they need to think about control.

For years, much of the cloud sovereignty conversation has centred on location: where is the application hosted, where is the data stored and which cloud region has been selected? Those questions still matter, particularly in the UK, where organisations across government, telecommunications, critical national infrastructure, financial services, healthcare and the wider public sector need to consider data residency, operational resilience and supplier risk.

But location alone does not answer the most important control questions. Who can access sensitive data? Where are the cryptographic keys protecting it generated and stored? Who controls those keys? How are they used, backed up and destroyed? And can security, compliance and risk teams clearly demonstrate how that control is maintained?

Sovereignty needs to go beyond where infrastructure sits. Organisations also need clear governance and control over the cryptographic trust their critical digital services depend on.

A cloud region is not the whole control boundary

Selecting a UK cloud region is an important step, but it does not provide a complete control model on its own. Cloud and hybrid services depend on multiple layers of protection spanning applications, APIs, identities, signing, certificate authorities, databases, transactions and software supply chains. Across all of these environments, cryptographic keys are a critical point of control.

If an organisation cannot clearly explain where those keys are generated, how they are protected, who can use them, where they are backed up and how access is governed, the assurance story is incomplete. For organisations with UK data residency, governance and sovereignty objectives, that distinction matters. Cloud location answers one question. Key control answers another: who controls the cryptographic keys protecting sensitive services and data?

Why this matters now

The UK cloud conversation is evolving. Organisations are being asked to modernise and move faster while demonstrating stronger governance over sensitive services and third-party dependencies. Regulatory and assurance expectations are also putting greater focus on data protection, resilience, access and control.

UK GDPR brings data protection and transfer considerations into scope, while the NCSC Cloud Security Principles provide a framework covering areas including asset protection, governance, resilience and auditability. Telecommunications providers also need to consider obligations under the Telecommunications Security Act. Public sector organisations have security classification requirements to consider, and financial services organisations face expectations around outsourcing, third-party risk and operational resilience.

The detail varies by organisation and sector, but security, compliance and risk teams increasingly need to show where sensitive assets are protected, how access is governed, how services remain resilient and how cryptographic keys are controlled. For cloud programmes, that means looking beyond location and at the wider control model.

HSM-backed trust, delivered in a cloud model

Hardware security modules have long been used to provide high-assurance protection for cryptographic keys and operations across use cases such as PKI, certificate authorities, application and database encryption, digital signing, code signing, identity systems and high-value transactions.

Cloud adoption does not remove the need for that level of trust. It creates demand for more ways to consume it. Thales Data Protection on Demand (DPoD) provides a cloud marketplace for Thales HSM, data security and encryption services. UK-hosted availability now extends that model locally, beginning with Luna Cloud HSM as the first UK-hosted service available through DPoD.

With UK-hosted Luna Cloud HSM, customer keys are generated, stored, used, backed up and destroyed in the UK. UK-based high availability and disaster recovery capabilities also support resilience and continuity within the UK. For security and compliance teams, that provides a much clearer answer to a fundamental question: where and how is the cryptographic key lifecycle managed? The value is not just UK location. It is local key control and resilience combined with the flexibility of consuming high-assurance HSM capabilities as a cloud service.

The hybrid reality

Most organisations are not moving neatly from on premises to cloud. Some critical systems remain on premises, others move to public cloud, and applications and services increasingly span multiple platforms and SaaS environments. That makes consistency important. A different model of cryptographic control for every environment adds complexity at exactly the point where security and governance teams need greater clarity.

For organisations already using Luna HSMs on premises, Luna Cloud HSM on DPoD provides another deployment option. Established HSM strategies can be extended into cloud and hybrid environments while maintaining a consistent approach to protecting cryptographic keys. Existing Luna Cloud HSM customers can also move workloads to the UK-hosted environment where UK key lifecycle control is required. This is not about replacing one deployment model with another. It is about giving organisations more choice in how they consume HSM capabilities while maintaining the trust model their sensitive services require.

Sovereignty also means being ready for change

Cryptography is entering a significant period of change as organisations prepare for the transition to post-quantum cryptography. They will need to understand where cryptography is used, which systems depend on it, and how algorithms, keys, certificates and cryptographic services can evolve over time.

That makes crypto agility increasingly important. As post-quantum capabilities become part of these environments, having a clear model for where keys are held, how they are governed and how cryptographic services are consumed should make it easier to adopt new standards without adding unnecessary complexity.

Post-quantum readiness may not be the immediate driver for every organisation, but it reinforces the same point: effective key control today puts organisations in a stronger position to adapt tomorrow.

From cloud adoption to cloud confidence

Cloud sovereignty cannot be reduced to a postcode. Data location matters, but so do key lifecycle, access governance, jurisdiction, resilience and auditability.

Organisations need to understand how those elements work together and be able to demonstrate that control to security teams, boards, regulators and auditors. With UK-hosted Luna Cloud HSM delivered through DPoD, they can consume proven Luna HSM capabilities through a UK-hosted cloud service, with UK key lifecycle control and UK-based high availability and disaster recovery supporting sovereignty, governance, resilience and data residency objectives.

Ultimately, cloud sovereignty is not defined by location alone. Organisations need to be able to explain, demonstrate and defend how they control the keys and trust services protecting their most critical digital operations.

Learn more about the UK-Hosted Luna Cloud HSM for Cloud Sovereignty.