/

Topics

/

Business Continuity

Business Continuity

Leaders

A new item for the board agenda: seven in ten are investing, three in ten are in control

Sep 30, 2026

Digital sovereignty is moving off the IT compliance list and onto the board's risk agenda. Vivicta's Nordic Digital Sovereignty Survey 2026, published on 22 September, finds that seven in ten organisations expect to increase their sovereignty investment over the next twelve months, while fewer than three in ten are confident they control their critical data.

Not long ago, the CIO of a large Swedish company told Vivicta's CEO Satu Kiiskinen what his single highest priority was. It was knowing where the company's business-critical data actually sits. He knew a moment would come when the executive team and the board would ask him that question, and he wanted the answer ready.

The question stopped being technical

Digital sovereignty means an organisation's ability to retain control and decision-making authority over its critical data, systems and operational continuity, including when the operating environment changes.

The definition might sound like an IT matter. According to Kiiskinen, that is precisely the problem. In executive teams and boardrooms the subject is still treated too often as a compliance and technology question. Her own view is different: this is first and foremost about business continuity, risk management and the capacity to keep operating when conditions shift.

“It’s clear that sovereignty has become an increasingly important priority in the current geopolitical environment. Digital sovereignty has become a leadership priority linked to business continuity and risk management, and it’s no longer seen as just a compliance issue”
Satu Kiiskinen
Satu KiiskinenCEO, Vivicta

The gap is not in the budget

The survey, run by Vivicta in collaboration with the research company Kairos Future, drew 320 senior decision-makers and key advisers in Finland, Sweden and Norway between June and July 2026. All worked in organisations employing more than 500 people.

The findings describe a subject that is recognised but not yet governed:

  • 70 per cent expect sovereignty-related investment to increase over the next 12 months.

  • 46 per cent have a formal, explicit sovereignty strategy.

  • 29 per cent strongly believe they control their critical data to a sufficient standard.

This, Kiiskinen says, is the most interesting result in the dataset. The subject is recognised, it is discussed, and organisations are willing to put money behind it. The capability still does not match the ambition. A gap has opened between intent and execution.

For a board, that is a familiar situation in unfamiliar clothing: an investment decision is coming up on a matter that too often has no strategy, no named owner and no metric.

Finland invests most. Sweden is further ahead on strategy.

Seventy-four per cent of Finnish organisations plan to increase investment, more than in Norway (69 per cent) or Sweden (68 per cent). On strategy the order reverses: a formal sovereignty strategy exists at 53 per cent of Swedish organisations, 44 per cent of Finnish ones and 39 per cent of Norwegian ones.

On control of critical data, Finland leads the comparison at 35 per cent, with Sweden and Norway at 26 per cent. Finland is ahead of its Nordic peers, and still only one Finnish organisation in three strongly believes it has sufficient control of its critical data.

Sweden, Kiiskinen notes, put sovereignty on the table some time ago. The CIO in the opening example represents that stage: the question is no longer whether the subject matters, but whether the organisation can answer when asked.

The opportunity is competitiveness.

Kiiskinen does not frame the subject as a threat. She sees it primarily as an opportunity to strengthen an organisation's resilience and competitiveness, and, ultimately, shareholder value.

Artificial intelligence connects to this directly. When the AI conversation runs hot and business benefits are wanted quickly, control of data determines whether AI can be adopted in a governed way, with risks identified in advance rather than reconstructed afterwards. Twenty-seven per cent of respondents rank AI, data use and control of decision-making among their most important sovereignty priorities. Seventeen per cent see AI as a new obstacle to data control.

On the risk side, Kiiskinen names one above the others: excessive dependency on individual providers.

Respondents agree. Dependency on external service providers tops the entire list of obstacles at 28 per cent. Cost and the complexity of an organisation's own environment follow at 23 per cent each, vendor lock-in at 16 per cent, and the absence of a strategy, owner or governance model at 14 per cent.

Dependency is rarely anyone's decision. It accumulates. Each individual choice was defensible at the time, and the result is a structure no one designed. It becomes visible only when something has to change quickly.

Full control is not the goal

Kiiskinen is careful not to overstate what the survey shows.

Complete sovereignty across every system is neither realistic nor the point, Kiiskinen says. What matters is distinguishing what is business-critical from what is not. The organisations that find a sensible balance are the ones that find resilience when conditions change

The data supports her. Only 8 per cent of respondents consider standard or global cloud sufficient for all critical workloads, and exactly the same share require full national sovereignty with elevated security. Everyone else sits somewhere in between. Seventeen per cent have not assessed the question at all.

“Ultimately, sovereignty is about freedom of action: the ability to remain in control when technology, suppliers or circumstances change. Organisations that find the right balance will be better positioned to innovate, grow and manage risk simultaneously”
Satu Kiiskinen
Satu KiiskinenCEO, Vivicta

What the board should ask

Kiiskinen does not present this as an easy topic for a board. The natural route onto the agenda, she says, runs through the audit committee, as part of risk management and business continuity. That does not mean it stays there. The whole board needs to take an interest.

Five questions a board can put to management at its next meeting:

  1. Do we share a view of which data is business-critical to us?

  2. Which systems are business-critical, and do we understand the difference between the two?

  3. Where does our business-critical data actually reside, and how is it governed?

  4. Who has access to it?

  5. To what extent are our data, systems and decision-making genuinely under our own control, and which part of our preparedness is an assumption rather than something tested?

None of these requires technical expertise to ask. On the evidence of this survey, many organisations would struggle to answer them.

Which leaves one question on the table, and it belongs to the board rather than to IT: are boards challenging management hard enough, before the next disruption reveals the real state of their readiness?

Stay on the pulse, catch the signals

Subscribe to Listeds Leadership Intelligence Platform:

  • leader and company database access

  • email alerts

  • career, boards and interim opportunities

Our Pulse newsletter

Your weekly leadership intelligence briefing.

What happened, why it matters, and what to watch across every CEO, board, and executive move in Nordic listed companies, starting with Finland. Fast, factual, and to the point.

Delivered every Monday.

By signing up, you agree to our Privacy Policy