The essentials: CRITIS regulation is forcing operators to reassess cloud dependency and shift back towards locally controlled backup strategies.
The Bitkom Cloud Report 2026 documents a growing discrepancy between cloud adoption and regulatory requirements for cloud infrastructure. CRITIS operators must redesign their backup and resilience strategies and cannot rely entirely on public cloud providers.
The Bitkom Cloud Report 2026 reveals a widening divergence between the proliferation of cloud services in German enterprises and increased demands for data sovereignty. For operators of critical infrastructures (CRITIS), this creates a structural tension: cloud platforms offer scalability and cost efficiency, but simultaneously generate dependencies in data sovereignty and availability.
New legislative requirements – particularly through the NIS2 Directive and national CRITIS regulations – mandate that operators exercise greater control over their data infrastructure. This applies especially to scenarios involving ransomware attacks, cloud provider outages, or geopolitical tensions that could jeopardise access to services. Data protection and disaster recovery outside public cloud environments has become a key focus of risk management.
The consequence is a renaissance of decentralised backup architectures: operators of critical infrastructures are re-evaluating on-premises solutions and hybrid models to maintain control over recovery processes and secure access chains independent of third-party cloud providers. This is not about abandoning cloud entirely, but rather about deliberate compartmentalisation: cloud for operations and scaling, on-premises or private infrastructure for critical backup and recovery processes.
Source: www.security-insider.de · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.