01 Insights
Guides for decisions you only make once
Six topics IT leaders cannot avoid right now: NIS2, sovereignty, cloud costs, AI infrastructure, VMware and private cloud. Written by the team that takes over operations afterwards, not by an agency.
02 By topic
The NIS2 directive: who is in scope and what has to be built
The NIS2 directive does not apply directly. It reaches organisations through the act each member state passes, and Germany’s has been in force since 6 December 2025, without a transition period and for around 29,500 organisations. This page sets out who is covered, which duties follow and what they mean for backup, recovery and day-to-day operations. It does not replace legal advice.
Read the guideDigital sovereignty: location, access and operations held apart
Sovereignty is usually argued as a question of location: where do the servers stand? In practice it is decided by two further questions. Who can gain access under which law, and who operates the platform in a way that lets you change the architecture without anyone else agreeing. This article separates the three levels and shows which evidence the NIS2 directive and its national implementations now require.
Read the guideCloud costs: where they come from and when an exit pays off
Cloud costs rarely rise where the load rises. They rise along data paths, in reserved capacity and in contract details that appear in no plan. This article sets out how total cost of ownership is calculated honestly, which levers work without moving anything, and at what point an exit becomes economic.
Read the guideSovereign AI is decided in the infrastructure, not in the model
Sovereign AI is not a property of the model. Whether an AI initiative runs securely, verifiably and economically depends on the layer beneath it: compute, storage, network, platform and operations. This article sets out what belongs to that layer, which obligations from the GDPR and the EU AI Act reach through into the architecture, and when self-hosted inference beats an API.
Read the guideVendor lock-in: how to spot it and how to undo it
A lock-in goes unnoticed for as long as the price is right. It becomes visible when the vendor changes the terms and nobody can say what a switch would cost. This piece sets out the forms of vendor lock-in, the warning signs, Broadcom and VMware as the object lesson, and the one criterion that can actually be tested: exit capability.
Read the guideCloud compliance: how to tell a compliant cloud from a claim
Almost every provider page promises cloud compliance, and almost none of them means the same thing by it. This text sorts out what compliance is actually made of, why a European data centre on its own is too thin a criterion, and which options really sit between your own server room, a private cloud and the public cloud.
Read the guide03 Fasttrack analysis
Rather talk it through?
Fifteen minutes to put your questions on NIS2, costs or migration into perspective. Not a sales call, no follow-up calls.
15 minutes · not a sales call · book directly in the calendar

Book a call