<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <copyright>Copyright TechTarget - All rights reserved</copyright>
        <description>ComputerWeekly’s best articles of the day</description>
        <docs>https://cyber.law.harvard.edu/rss/rss.html</docs>
        <generator>Techtarget Feed Generator</generator>
        <language>en</language>
        <lastBuildDate>Wed, 30 Sep 2026 19:56:57 GMT</lastBuildDate>
        <link>https://www.computerweekly.com</link>
        <managingEditor>editor@computerweekly.com</managingEditor>
        <item>
            <body>&lt;p&gt;I’m once again overnighting in Brick Lane. It seems to have been a theme this year as I visit new venues in my role as &lt;a href="https://www.computerweekly.com/resources/Data-Centre"&gt;datacentre and cloud&lt;/a&gt; reporter. I have grown to appreciate this bit of inner east London in ways I did not when I lived south of the river in the 1990s. The social mix, the shops, the history that sits in street names and on the facade of many buildings, the curry houses and &lt;a href="https://www.beigelbake.co.uk/"&gt;beigel bakeries&lt;/a&gt;, remnants of the rag trade beside phone repair counters, all of it stacked against brick that has seen a dozen different Londons.&lt;/p&gt; 
&lt;p&gt;This morning I wake too early, with a million ideas turning in my head. I write notes, fire off emails, get breakfast and head for Tobacco Dock to attend &lt;a href="https://www.computerweekly.com/news/366651384/Everpure-survey-88-of-executives-fear-data-sovereignty-failures"&gt;Everpure Accelerate London&lt;/a&gt;.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;I’m early, and shepherded to the coffee stand in the open-air central courtyard. Above me, the sky. Just in front of me, the old wooden roof – a cantilevered, half-glazed, labyrinthine framework. The coffee is welcome, and I stand beneath early blue skies and cool down from the 15-minute walk on a surprisingly warm morning.&lt;/p&gt; 
&lt;p&gt;Around me gather other early starters – mostly Everpure people, a few keen partners and consultants, one or two obvious geeks who might be happier facing a dark mode code editor than actual people. This is the cast of a technology event in 2026 – the partners, the executives, the geeks, the lifers, the drivers, the pushers, the welcomers, the facilitators. Some dress up, some do not, a few just a little over the top.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="A fortress for a leaf"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;A fortress for a leaf&lt;/h2&gt;
 &lt;p&gt;The building around us carries its own credentials. Tobacco Dock began life as a bonded warehouse. Daniel Asher Alexander, a prison architect, designed its high, fortress-like perimeter walls. Tobacco and imported spirits carried heavy duties as taxed luxuries, so the whole site doubled as a vault against smugglers and river thieves. The walls rise high and blank. Storage has always had a security problem.&lt;/p&gt;
 &lt;p&gt;It is also a problem of fragility. Tobacco leaf is hygroscopic: it drinks moisture from the air. Too damp, and the leaf breeds mould and rots. Too dry, and it loses its oils, turns brittle, and shatters to dust. So the builders raised great brick-and-timber warehouses to buffer the swings of the outside climate, and beneath the tobacco floors they cut vaulted cellars, kept at a constant 15.5°C. Two hundred years ago, keeping a leaf intact was an engineering discipline.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="The problem of scale"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The problem of scale&lt;/h2&gt;
 &lt;p&gt;I fall into conversation with Rich, a partner whose firm deploys and maintains Everpure storage, mostly for financial technology (fintech) customers. His challenges are “other vendors”, “keeping costs down”, and customers who want to “do more with less”. Then there is artificial intelligence (AI) – the problem of scale – and the chief executives who, as he puts it, “just want to do AI for AI’s sake”.&lt;/p&gt;
 &lt;p&gt;I’m reminded of a recent article in which &lt;a href="https://www.computerweekly.com/feature/AI-promises-a-productivity-windfall-who-will-reap-the-benefits"&gt;I looked into the future of AI&lt;/a&gt; and MIT professor Daron Acemoglu’s characterisation of exactly this – as “so-so automation” that just replicates what humans do rather than augments them.&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Thirty years against a hobby"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Thirty years against a hobby&lt;/h2&gt;
 &lt;p&gt;Then there is Eric, who works for a manufacturing company. He’s here to explore Portworx, Everpure’s container management platform. His big challenge at the moment is the shift from VMware to &lt;a href="https://www.computerweekly.com/opinion/Azure-Local-Disconnected-looks-the-part-for-sovereignty-It-isnt"&gt;Azure Local&lt;/a&gt;, which has been ordered from on high because of the &lt;a href="https://www.computerweekly.com/blog/CW-Developer-Network/CloudBolt-analysis-Mass-VMware-exodus-yet-to-come-but-unwind-underway"&gt;cost of VMware&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;How about AI? His managers keep saying, “Yeah, we need AI”, but he has to push back. “If we start doing that,” he says, “it has to sit on a stable footing, with compliance and everything else done properly.” He is not against the technology; he is against the hurry. He describes a massive data lake and the difficulty – the risk – of wading into it and starting to interrogate the thing, pulling on a thread that turns out to be holding something else together. Meanwhile, Azure Local, he tells me, is like “going back to the Stone Age”.&lt;/p&gt;
 &lt;p&gt;It is a fascinating conversation. He brings 30 years of software engineering experience, and I bring my bits-and-pieces, hobby-acquired knowledge, using tools he’s not come across, like Streamlit, Vercel and Firebase, that now let us build web applications with far less faff than in the past. He’s very experienced and very skilled, and the world we’re in is now removing – or maybe just moving – where the skill lies in IT.&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="The parallel nobody drew"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The parallel nobody drew&lt;/h2&gt;
 &lt;p&gt;I’m a little disappointed that no one on stage drew the storage parallel of the building we are in. The smugglers and river thieves of the 19th century have their descendants in ransomware crews and extortion cartels. The security walls look different now – sovereignty, compliance, the right to know where your data sits – and the fragility is digital rather than botanical. But the link is there.&lt;/p&gt;
 &lt;p&gt;By late morning the courtyard thins. The wooden roof holds its pattern against the sky and conversations tail off around me. I head for the tube, chatting to an old colleague and through the feet-thick portal beneath the hog’s head adorning its high wall.&amp;nbsp;&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more IT event travelogues&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/IT-event-dive-Through-AWS-public-sector-symposium-revolving-door"&gt;IT event dive – through the AWS public sector symposium revolving door&lt;/a&gt;: What goes on in the gaps between reporting on vendor events, with a morning spent absorbing thousands of words at the AWS Public Sector AI Symposium in London&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/news/366643633/Datacentre-dive-From-rust-belt-to-megawatt-AI-factory"&gt;Datacentre dive – from rust belt to megawatt AI factory&lt;/a&gt;: We visited Terawulf’s Lake Ontario 750MW datacentre development. Photos and recordings weren’t allowed, so we took notes and wrote them up in more traditional ways&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>Inside a 200-year-old bonded tobacco warehouse, Everpure’s Accelerate London delegates wrestle with competition, orders from on high and AI for AI’s sake</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/HeroImages/East-wall-Tobacco-Dock-Wapping-Ethan-Doyle-White.jpg</image>
            <link>https://www.computerweekly.com/feature/IT-event-dive-AI-for-its-own-sake-at-Tobacco-Dock-with-Everpure</link>
            <pubDate>Wed, 30 Sep 2026 10:30:00 GMT</pubDate>
            <title>IT event dive: AI for its own sake at Tobacco Dock with Everpure</title>
        </item>
        <item>
            <body>&lt;p&gt;“Inherent sovereignty is a fallacy … we’re talking more about operational sovereignty.”&lt;/p&gt; 
&lt;p&gt;That’s the view of Wojciech Stramski, chief executive of Beyond.pl, who spoke at this week’s &lt;a href="https://www.computerweekly.com/news/366651462/Everpure-adds-data-management-capabilities-for-production-AI"&gt;Everpure Accelerate London&lt;/a&gt; event at Tobacco Dock.&lt;/p&gt; 
&lt;p&gt;Beyond.pl has spent more than two decades as a Polish colocation and managed cloud provider, serving about 500 customers and drawing about 30% of its traditional revenue from the wider European market. Last year it deployed what it calls central and eastern Europe’s first commercial AI factory, which paired Nvidia DGX SuperPOD compute with 3PB of Everpure FlashBlade//S500 R2 storage on the company’s 100MW campus in Poznań.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Stramski said &lt;a href="https://www.computerweekly.com/resources/Data-Centre"&gt;the datacentre&lt;/a&gt; – marketed as &lt;a href="https://www.computerweekly.com/ezine/Computer-Weekly/Inside-the-AI-factory-of-the-future"&gt;an AI factory&lt;/a&gt; – runs at a power usage effectiveness of 1.2, against a regional peer average of around 1.5, and ranks among the top 500 supercomputers globally. It plans to scale up in the first half of next year, with plans to add four times its current graphics processing unit (GPU) capacity as it moves from B200 to B300 and GB300 Nvidia GPUs, and integrates the B300 with its existing Everpure storage.&lt;/p&gt; 
&lt;p&gt;Stramski’s argument is that sovereignty is less about where data physically sits than who can reach it. For European organisations, he said, &lt;a href="https://www.computerweekly.com/feature/Is-cloud-data-sovereignty-all-just-a-case-of-Trust-me-bro"&gt;the real sovereignty risk&lt;/a&gt; is the US and its hyperscalers, not Russia. But he noted there is, for now, no real alternative to US hardware such as Nvidia’s.&lt;/p&gt; 
&lt;p&gt;That tension plays out in an unexpected way in Poznań. “The majority of the customers, actually US customers, were inbounding into the factory to deliver sovereign services for their European base,” he said.&lt;/p&gt; 
&lt;p&gt;Beyond.pl reassures its own customers on the basis that it cannot see their data, and collects only telemetry from the infrastructure. Stramski said that, as a Polish entity governed by Polish and European Union law, the US government cannot compel the company to hand over customer data. That distinction, he argued, is what makes the offering genuinely sovereign in operational terms, even while the silicon underneath remains American.&lt;/p&gt; 
&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;Read more about data sovereignty&lt;/h3&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Is-cloud-data-sovereignty-all-just-a-case-of-Trust-me-bro"&gt;Is cloud data sovereignty all just a case of ‘Trust me, bro’?&lt;/a&gt; Hyperscaler cloud is inherently global. Does that make data sovereignty unattainable – especially given the powers US courts hold? We grilled the hyperscalers in an attempt to find out.&lt;/li&gt; 
   &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Selective-sovereignty-Why-balance-beats-lockdown-in-the-data-debate"&gt;Selective sovereignty: Why balance beats lockdown in the data debate&lt;/a&gt;. Everpure CTO Patrick Smith argues data sovereignty demands selective control, balancing strict workload rules with global cloud speed rather than an all-or-nothing lockdown.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;The wider context is a European push to rebuild domestic capacity. Beyond.pl participates in European Commission initiatives, including the &lt;a href="https://commission.europa.eu/topics/competitiveness/competitiveness-coordination-tool-projects/ai-gigafactories_en"&gt;AI Gigafactories programme&lt;/a&gt; to deploy five or six sovereign AI factories for the EU, though Stramski conceded the region’s cloud alternatives are not yet as advanced as the US hyperscalers.&lt;/p&gt; 
&lt;p&gt;Poland’s appeal, he said, is time to market. “Time to market is now the key element for AI,” said Stramski.&lt;/p&gt; 
&lt;p&gt;The country has only around 200MW of live datacentre capacity right now, but, he said, it also has the biggest energy construction programme in Europe, and it can permit a project in two or three years, against three to five years in Iberia and Scandinavia. Beyond.pl also plans to feed 60MW of recovered heat from its Poznań campus into the city’s district heating network, which Stramski noted is the second largest in Europe after Germany’s.&lt;/p&gt; 
&lt;p&gt;He said the sovereignty conversation only began in earnest about 18 months ago, and is now trickling down from banks and healthcare into manufacturing, logistics and retail. Yet, he conceded, the demand picture remains uneven: European enterprises’ appetite for AI capacity is, in his view, very small, with AI labs and hyperscalers taking up much of the factory’s compute rather than the region’s own businesses.&lt;/p&gt; 
&lt;ul class="default-list"&gt;&lt;/ul&gt;</body>
            <description>Beyond.pl built central Europe’s first sovereign AI factory on Everpure and Nvidia kit – now its CEO argues the real issue is operational sovereignty, not where the box sits</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/Hero%20Images/Europe-map-adobe.jpeg</image>
            <link>https://www.computerweekly.com/news/366651440/Inherent-sovereignty-is-a-fallacy-says-Beyondpl-AI-factory-exec</link>
            <pubDate>Wed, 30 Sep 2026 10:00:00 GMT</pubDate>
            <title>‘Inherent sovereignty is a fallacy’ says Beyond.pl AI factory exec</title>
        </item>
        <item>
            <body>&lt;p&gt;Some 88% of enterprise leaders believe a data sovereignty failure could cost them their jobs, research from &lt;a href="https://www.computerweekly.com/feature/Selective-sovereignty-Why-balance-beats-lockdown-in-the-data-debate"&gt;storage and data management supplier Everpure&lt;/a&gt; has found.&lt;/p&gt; 
&lt;p&gt;The &lt;em&gt;Global data sovereignty report 2026&lt;/em&gt;, released at Everpure’s Accelerate event in London this week, drew on a Vanson Bourne survey of 2,100 C-suite and IT leaders across the UK, France, Germany, Australia, Japan, South Korea, Singapore and India in June. It found 91% worry about financial and reputational damage, but 64% of organisations operate without a formal &lt;a href="https://www.computerweekly.com/feature/The-geography-trap-Why-a-cloud-region-is-no-substitute-for-data-sovereignty"&gt;data sovereignty strategy&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;The report frames the result as a “sovereignty gap” – executive &lt;a href="https://www.computerweekly.com/resources/IT-risk-management"&gt;recognition of risk&lt;/a&gt; running far ahead of operational readiness. Some 90% of organisations recognise &lt;a href="https://www.computerweekly.com/news/366645336/Data-dive-Kill-switch-and-catch-up-can-Europe-close-the-sovereignty-gap"&gt;data sovereignty as a business concern&lt;/a&gt;, but 62% lack visibility into who can access, control and manage their data. Everpure said many also focus on the wrong risks: 47% cite cyber security as a leading driver, while only 26% flag service disruption from political uncertainty and 9% prioritise protection from extraterritorial data access.&lt;/p&gt; 
&lt;p&gt;Alex McMullan, Everpure’s chief technology officer for international, said: “Senior leaders understand their jobs are on the line over data sovereignty, yet many are still focused on the wrong risks. Sovereignty is not simply about where data is stored, but having full visibility and control over it through modern data management. Who can access data, which jurisdictions apply and whether business-critical data or services could be disrupted are key questions every organisation should be asking.”&lt;/p&gt; 
&lt;p&gt;Everpure calls the answer “sovereignty by design” – a shift from national to corporate sovereignty and applying controls according to the risk profile of each dataset, application and workload. Patrick Smith, Everpure’s chief technology officer, said: “Our recommendation is to embrace a sovereignty by design approach – dealing with sovereignty from an overall strategic view, not a tactical view.”&lt;/p&gt; 
&lt;p&gt;Everpure said its Data Intelligence software supports the model by discovering, classifying and contextualising enterprise data across its platform, public clouds, software-as-a-service (SaaS) applications and third-party storage. That, it argued, gives organisations the visibility to decide how data should be governed and protected, rather than treating sovereignty as a routine cyber security or compliance exercise. Everpure said a third of organisations now tie sovereignty to their artificial intelligence (AI) initiatives, making data control a precondition for adoption rather than an afterthought.&lt;/p&gt; 
&lt;p&gt;Rahiel Nasir, research director and lead analyst for worldwide digital sovereignty at IDC, said the issue has become a board-level concern: “Digital sovereignty has moved from a compliance conversation to a critical board-level concern. The challenge for executives is not just about knowing where their data is hosted. It is about being in total control of all data access and transfers, including all metadata.”&lt;/p&gt; 
&lt;p&gt;Everpure said the findings show sovereignty has shifted from a compliance cost to a question of resilience and competitive advantage, as geopolitical uncertainty and the push to adopt AI raise the stakes for where and how data is stored, processed and accessed.&lt;/p&gt; 
&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;Read more about data sovereignty&lt;/h3&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Is-cloud-data-sovereignty-all-just-a-case-of-Trust-me-bro"&gt;Is cloud data sovereignty all just a case of ‘Trust me, bro’?&lt;/a&gt; Hyperscaler cloud is inherently global. Does that make data sovereignty unattainable, especially given the power US courts hold? We grilled the hyperscalers in an attempt to find out.&lt;/li&gt; 
   &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/This-rise-of-the-splinternet-Data-sovereignty-risks-and-responses"&gt;The rise of the splinternet? Data sovereignty risks and responses&lt;/a&gt;: We explore the political, legal and economic risks that data sovereignty fractures pose to global digital infrastructure.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt;</body>
            <description>An Everpure survey of 2,100 C-suite and IT leaders across eight countries finds 90% recognise the risk, yet 64% lack a formal strategy to close ‘the sovereignty gap’</description>
            <image>https://cdn.ttgtmedia.com/visuals/searchITChannel/systems_channel/itchannel_article_020.jpg</image>
            <link>https://www.computerweekly.com/news/366651384/Everpure-survey-88-of-executives-fear-data-sovereignty-failures</link>
            <pubDate>Wed, 30 Sep 2026 05:20:00 GMT</pubDate>
            <title>Everpure survey: 88% of executives fear data sovereignty failures</title>
        </item>
        <item>
            <body>&lt;div class="imagecaption alignLeft"&gt;
 &lt;img src="https://cdn.ttgtmedia.com/rms/computerweekly/CW-60-anniversary-logo-white-400px.jpg" alt="Computer Weekly 60th anniversary logo" width="226" height="117"&gt;
&lt;/div&gt; 
&lt;p&gt;&lt;i&gt;On 22 September 2026, Computer Weekly turns 60. To mark the milestone, we asked some of our friends - experts, parliamentarians, IT leaders and suppliers - for their perspectives on how tech has changed their lives over six decades. What's changed the most for you since then?&lt;/i&gt;&lt;/p&gt; 
&lt;p&gt;In 1978, I was 18 years old, finishing high school in a small town north of Toronto, and holding university offers in three subjects - physics, engineering and computer science. I picked computer science for a simple reason - I thought it might lead to the most creative changes in society in my lifetime.&lt;/p&gt; 
&lt;p&gt;Nearly 50 years on, I would say the hunch held up. Though I concede it is no longer a slam dunk, quantum technology and gene engineering are still in the running. But &lt;a href="https://www.computerweekly.com/blog/Cliff-Sarans-Enterprise-blog/An-era-of-post-Moores-Law-computing"&gt;Moore’s law&lt;/a&gt;, Jensen’s gaming cards and &lt;a href="https://www.techtarget.com/ai/tip/History-of-generative-AI-innovations-spans-9-decades"&gt;Geoff Hinton’s backpropagation&lt;/a&gt; make a good case for computer science.&lt;/p&gt; 
&lt;p&gt;It was a strange bet at the time. My parents were teachers who had never touched a computer. In 1978, the IBM PC was still three years away, and about the only place an ordinary person encountered computing was at the bank, where the tellers had terminals and the first cash machines were appearing.&lt;/p&gt; 
&lt;p&gt;My own hands-on experience amounted to tinkering with a friend’s Commodore PET after school. But that was enough. What drew me in was the blank sheet. A field so new that almost everything worth doing hadn’t been done yet. My parents didn’t resist. Their view was - you want to go to university, and that’s a good thing.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="A sight of things to come"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;A sight of things to come&lt;/h2&gt;
 &lt;p&gt;I earned my bachelor’s degree in applied mathematics at the University of Waterloo, Ontario and it was there, in the mid-1980s, that I got my first real look at what was to come - an account that let me send email to friends around the world. In 1985, email was largely unknown. The internet is still, I think, the biggest change technology has made to how we live, even if I maintain to this day that typing on a glass screen was a step backwards.&lt;/p&gt;
 &lt;p&gt;After graduating, I was working in telecommunications, half-heartedly weighing up graduate school, when two phone calls arrived. One was from a professor at Carnegie Mellon who wanted me to work on legged robots. The other was from David Patterson at Berkeley, recruiting students to help build a complete high-performance computer system, part of the project that made &lt;a href="https://www.computerweekly.com/news/366541622/RISC-Q-rises-to-software-ecosystem-challenge"&gt;Reduced Instruction Set Computing (RISC)&lt;/a&gt; famous.&lt;/p&gt;
 &lt;p&gt;Legged robots sounded like mechanical engineering; RISC sounded like computer science. So, I said yes to Patterson and moved 3,000 miles from central Canada to the west coast of California. Berkeley was also a wonderful place to be a 24-year-old.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Glamorous problems"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Glamorous problems&lt;/h2&gt;
 &lt;p&gt;In 1987, I needed a PhD topic. The glamorous problems on the project all seemed to have been taken, and almost nobody was doing serious research on high-performance storage, so I took it. The timing turned out to be everything.&lt;/p&gt;
 &lt;p&gt;Storage then meant washing-machine-sized drives designed for mainframes. But the PC had created demand for small, cheap disks with a standard interface, SCSI, and it struck us that if you put enough of them together, you could beat the washing machine on performance and reliability.&lt;/p&gt;
 &lt;blockquote&gt; 
  &lt;div class="imagecaption alignLeft"&gt;
   &lt;img src="https://cdn.ttgtmedia.com/rms/computerweekly/Garth Gibson Headshot 2.png" alt="Photo of Garth Gibson, chief technology and AI officer at VDURA" width="146" height="180"&gt;
  &lt;/div&gt; 
  &lt;p&gt;&lt;span style="font-size: 14pt;"&gt;&lt;strong&gt;&lt;span style="color: #34495e;"&gt;“If I were 18 again today, I would choose AI because it feels exactly the way computing felt to me in 1978 - a green field, low-hanging fruit everywhere, the future visibly unwritten”&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; 
  &lt;p&gt;&lt;span style="color: #34495e;"&gt;&lt;em&gt;Garth Gibson&lt;/em&gt;&lt;/span&gt;&lt;/p&gt; 
 &lt;/blockquote&gt;
 &lt;p&gt;That idea became &lt;a href="https://www.techtarget.com/it-infrastructure/tip/Key-differences-in-software-RAID-vs-hardware-RAID"&gt;RAID - redundant arrays of inexpensive disks&lt;/a&gt; - and in 1988, David Patterson, Randy Katz and I published the RAID paper.&lt;/p&gt;
 &lt;p&gt;The moment I knew RAID mattered wasn’t about seeing a citation count. It was a Seagate person walking through our door with a photocopy of the technical report before the work had even appeared in the major academic venues, saying their customers wanted to buy this now.&lt;/p&gt;
 &lt;p&gt;And yet the low point happened after the high. In 1990, I was writing my dissertation on the graveyard shift, arriving at four in the afternoon and leaving at four in the morning, my only daily engagement the department secretaries at my day’s start. Two-and-a-half years on from the paper, I couldn’t yet see any real commercial success, and I remember thinking, why am I doing this? Who needs a PhD?&lt;/p&gt;
 &lt;p&gt;But about a year later, RAID was everywhere, the ACM recognised my dissertation among the best of its year, and the market it created grew to something like $10bn.&lt;/p&gt;
 &lt;p&gt;The industry even quietly renamed the “I” from “inexpensive” to “independent” disks; nobody wanted to sell something labelled cheap. The lesson I take from that time is how close together the lowest point and the breakthrough can sit.&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="Stop hiding"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Stop hiding&lt;/h2&gt;
 &lt;p&gt;The second yes was to HT Kung, who recruited me to Carnegie Mellon after my PhD. There, I became convinced that storage needed to stop hiding inside file servers and become a first-class citizen of the network.&lt;/p&gt;
 &lt;p&gt;That conviction became the &lt;a href="https://www.computerweekly.com/feature/SAN-vs-NAS-For-AI-virtual-machines-and-containers"&gt;network-attached secure disks (NASD)&lt;/a&gt; project in 1995, and when its team of graduates scattered, the ideas went with them - into the first specification of what became Lustre, into the first versions of the Google File System, whose paper became the blueprint for Hadoop’s HDFS, and into Panasas (now VDURA), the company I co-founded to build the PanFS parallel file system and propose pNFS as a standard.&lt;/p&gt;
 &lt;p&gt;When Roadrunner, the world’s first petascale supercomputer, made its debut, it was running our file system. Today’s AI boom runs on parallel file systems for the same reason - GPUs devour data faster than any single server can feed them. An observation from 1995 became mandatory.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Full circle"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Full circle&lt;/h2&gt;
 &lt;p&gt;The wheel has come full circle. By 2012, AI computing had outgrown a single desktop, and as a distributed-systems person, I was pulled in to help make it bigger, eventually saying yes to Geoff Hinton and serving as the inaugural president and CEO of the Vector Institute for AI in Toronto.&lt;/p&gt;
 &lt;p&gt;If I were 18 again today, I would choose AI because it feels exactly the way computing felt to me in 1978 - a green field, low-hanging fruit everywhere, the future visibly unwritten. In AI the hardest open questions are no longer all technical. Who is liable when a computer does harm, for example? Now, at least in the US, we wait until enough damage is done and let the courts work it out. We can do better than that, and I’m glad serious research is going into it.&lt;/p&gt;
 &lt;p&gt;So, if you ask me for the one moment that stands out from a lifetime in technology, it isn’t the paper, or the award, or the supercomputer. It’s saying yes to a hunch at 18 about where the creativity would be, to new offers and new challenges. The digital revolution didn’t just change my life. It kept inviting me somewhere new, and the trick, it turns out, was simply to keep accepting the invitation.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Garth Gibson is chief technology and AI officer at VDURA, a professor of computer science at Carnegie Mellon University, and the co-creator of RAID storage technology. &lt;/i&gt;&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read all of Computer Weekly's 60th anniversary essays&lt;/h3&gt; 
   &lt;p&gt;Technology is changing the way we live and work like never before – touching people’s lives every day, opening up new opportunities and creating new challenges.&lt;/p&gt; 
   &lt;p&gt;So for our 60&lt;sup&gt;th&lt;/sup&gt; anniversary, we wanted to reflect on the human stories of how the digital revolution has changed the lives of some of the key leaders and influencers in tech today. Read our full collection of essays, which offers a unique set of insights and perspectives into the changes we have seen during Computer Weekly's first 60 years.&lt;/p&gt; 
   &lt;h2&gt;&lt;a href="https://www.computerweekly.com/essentialguide/CW60-How-technology-has-changed-our-lives-over-60-years"&gt;CW@60 - How technology has changed our lives over 60 years&lt;/a&gt;&lt;/h2&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>Computer science offered seemingly limitless creative possibility for Garth Gibson 50 years ago - much as AI does now. But not everyone invented RAID storage along the way</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/article/hard-disks-2-adobe.jpg</image>
            <link>https://www.computerweekly.com/feature/CW60-Saying-yes-the-choices-that-carried-me-from-a-Commodore-PET-to-AI</link>
            <pubDate>Thu, 10 Sep 2026 05:00:00 GMT</pubDate>
            <title>CW@60: Saying yes - the choices that carried me from a Commodore PET to AI</title>
        </item>
        <item>
            <body>&lt;div class="imagecaption alignLeft"&gt;
 &lt;img src="https://cdn.ttgtmedia.com/rms/computerweekly/CW-60-anniversary-logo-white-400px.jpg" alt="Computer Weekly 60th anniversary logo" width="226" height="117"&gt;
&lt;/div&gt; 
&lt;p&gt;&lt;i&gt;On 22 September 2026, Computer Weekly turns 60. To mark the milestone, we asked some of our friends - experts, parliamentarians, IT leaders and suppliers - for their perspectives on how tech has changed their lives over six decades. What's changed the most for you since then?&lt;/i&gt;&lt;/p&gt; 
&lt;p&gt;I was born two years before Computer Weekly and for the first couple of decades of my life, our worlds did not intersect at all. I didn’t see a computer until I was 19 and working in a tool distribution company in Birmingham where we checked stock in and out on a green-screen mainframe.&lt;/p&gt; 
&lt;p&gt;I was a user, except occasionally I was roped into the daily routine of taking out the disks. The machines were the size of a washing machine, the disks a foot across, with a big clamp-and-close handle you swung shut.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;That was the extent of my IT life for another decade, during which I was a toolmaker in Birmingham, and my world was strictly Industry 1.0. There were CNC (computer numerical control) machines in the shop, but I had nothing to do with them beyond asking someone to make me a part now and then.&lt;/p&gt; 
&lt;p&gt;An access course carried me into university in my mid-twenties, and then I got my first computer: an &lt;a href="https://www.valoroso.it/en/olivetti-prodest-pc1-msdos/"&gt;Olivetti green screen&lt;/a&gt; with 5.25” disks. I used it to write essays. There was nothing else you could do with it.&lt;/p&gt; 
&lt;p&gt;After university - BA Middle East history, MSc Africa / Asia politics - I worked in journalism almost from the start, on various publications. I laid out pages and wrote articles on PCs and Macs. I was still very much a user.&lt;/p&gt; 
&lt;p&gt;Three or four years later, I got my first PC. I went on the internet via a noisy modem, and got into downloading music through Napster and Limewire. It opened a world of exploration I could not afford before, when a record meant money I did not really have.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Still a user"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Still a user&lt;/h2&gt;
 &lt;p&gt;In 1997 my journey brought me to Computer Weekly. I worked there as a sub-editor, production editor, then reporter. My background dictated I would report on IT in manufacturing, so I covered ERP and MRP, visited oil refineries, the Longbridge car plant in Birmingham, an iron ore mine in Sweden. I was still a user of technology but becoming a professional observer too.&lt;/p&gt;
 &lt;p&gt;That phase lasted for seven years, before I went freelance and moved to the north of England.&lt;/p&gt;
 &lt;p&gt;Now I was responsible for my own PC, and I quickly learned to fix what went wrong. Two HDD failures in the space of months forced me to delve deeper into the guts of the PC and its components, and I soon became comfortable Googling my way through problems.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;By the late-2000s I had become &lt;a href="https://www.scribd.com/document/96427569/UK-Q3"&gt;storage editor&lt;/a&gt; for what would become soon Computer Weekly’s parent company. It was a space I’d largely adopted because everyone else considered it too boring.&lt;/p&gt;
 &lt;p&gt;I got to dive deeper into the tech, and was even given the chance to do a week’s course in storage technology certified by the industry body.&lt;/p&gt;
 &lt;p&gt;But in my relationship to IT, I was largely a user or an observer, and that held until the late 2010s.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="The practitioner"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The practitioner&lt;/h2&gt;
 &lt;p&gt;Somewhere along the way, an interest in football – I was coaching our boy’s football team by this time – coincided with the rise of “citizen analysts” of football data. I was amazed at what people could do – turning raw football statistics into charts and graphics. And it resonated with me, because I never quite trusted my impressions when watching football and craved the grounding that numbers and patterns and arrows on a pitch graphic gave me.&lt;/p&gt;
 &lt;blockquote&gt; 
  &lt;div class="imagecaption alignLeft"&gt;
   &lt;img src="https://cdn.ttgtmedia.com/rms/computerweekly/Antony-Adshead-April26-140x180px.jpg" alt="Photo of Computer Weekly journalist Antony Adshead"&gt;
  &lt;/div&gt; 
  &lt;p&gt;&lt;span style="font-size: 14pt;"&gt;&lt;strong&gt;&lt;span style="color: #34495e;"&gt;“ Instead of being in the tactical weeds of coding or writing, I oversee an LLM-powered worker that can assess and summarise vast volumes of source material, locally and on the internet”&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; 
  &lt;p&gt;&lt;span style="color: #34495e;"&gt;&lt;em&gt;Antony Adshead&lt;/em&gt;&lt;/span&gt;&lt;/p&gt; 
 &lt;/blockquote&gt;
 &lt;p&gt;To do any of it, I needed software, so I taught myself &lt;a href="https://www.r-project.org/"&gt;R, the open source data science software&lt;/a&gt;. It was a long process – several months of pain simply learning it, and more when building things. When something did not work, my only recourse was &lt;a href="https://stackoverflow.com/questions/tagged/r"&gt;Stack Overflow&lt;/a&gt;, and hoping someone's problem somewhere in the world had intersected with mine.&lt;/p&gt;
 &lt;p&gt;Sometimes a whole afternoon or a day slipped by before I found the fix for a single line holding everything up. But it was a great introduction to programming, because everything had to happen by hand. I also learned some Python.&lt;/p&gt;
 &lt;p&gt;That ability to fix computers and work with data soon collided with a newer part of my life: I had become a trustee for &lt;a href="https://www.mumsinneed.com/"&gt;Mums In Need&lt;/a&gt;, the domestic abuse charity my wife started in 2014. It is a small organisation – fewer than 10 employees – but still has real IT requirements, and I became board member with special responsibility for IT, which gives some flavour of the concerns of a real CIO. I was the person with the hands-on knowledge of software and the strategic IT overview my work at Computer Weekly gave me.&lt;/p&gt;
 &lt;p&gt;One milestone, still ongoing, was the case management system I built for the caseworkers who support our service users. It runs on &lt;a href="https://about.appsheet.com/home/"&gt;Google AppSheet&lt;/a&gt;, a low-code platform, and replaced a clunky, bought-in casework system that was far too widely scoped and never really suited the work Mums In Need actually did. Inevitably, shadow IT in the form of Google Sheets had grown up around it. What we wanted was to bring all that data together – to gather it, to build reports and, crucially, to build good evidence for the funding applications on which charities are utterly dependent.&lt;/p&gt;
 &lt;p&gt;So I moved from user and observer to practitioner – first tactically, learning R and doing data analysis as a football hobby – then doing data science for the charity and building software around data, and with the leadership remit an IT board member might hold in any organisation. Mums In Need is small and my work very part time, but the overhead is real and covers the gamut from data protection and data backup to developing systems to handle the organisation's information.&lt;/p&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="The agent overseer"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The agent overseer&lt;/h2&gt;
 &lt;p&gt;The latest phase of my evolution has been as an everyday user of large language models (LLMs) in my role as acting datacentre and cloud editor with Computer Weekly, in particular when I have my data journalism hat on.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;I hesitate to call it AI. It’s a glorified autocomplete, even if the frontier models are very, very powerful. Really what we’re doing is leveraging LLMs, and at best and in the most critical environments, learning how to work with their limitations.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;I’d been using “one-shot” browser-chat AI for some time, but had long thought there must be a better way. You can set up persistent chats to guide Gemini or ChatGPT with a “master prompt” but it soon forgets what you tell it. You can get them to help writing R scripts for example, but they never truly know what you’re doing because they live in one window while Rstudio is in another.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;I knew “agentic” was the next big thing and that I needed AI to work more as a copilot – that is, literally having vision and the means to execute actions in the folders / environment I’m working in - but had struggled to gain any traction.&lt;/p&gt;
 &lt;p&gt;Two encounters really gave me a kick up the backside. &lt;span&gt;I met a developer friend in the pub one night, where he told me of the work he had been doing with agentic AI. He had a job scraping some specific data from every council in the country. The scraper worked autonomously; if it encountered a failure, it rebuilt itself to work around the issue. It all worked with "skills" he said, and markdown files. I hadn't got a clue what he was talking about and felt like I'd arrived in a time machine from 1956.&lt;/span&gt;&lt;/p&gt;
 &lt;p&gt;A couple of weeks later I was at a Google event. A Google employee was sat next to me, laptop open on his knees during a keynote. I tried desperately to look as if I wasn’t looking and caught glimpses of a fleet of agents at work in different panes – researching, checking, working. I thought - I need to know how to do that.&lt;/p&gt;
 &lt;p&gt;A few months later – and taking inspiration from the likes of &lt;a href="https://www.youtube.com/@JEVanClief"&gt;Jake Van Clief&lt;/a&gt; and &lt;a href="https://github.com/mattpocock"&gt;Matt Pocock&lt;/a&gt; – a lot of my work revolves around an LLM inside a code editor, and using markdown-based workflow and skills files, that help me research, conduct data analysis, write drafts, and where needed, verify quotes and check facts.&lt;/p&gt;
 &lt;p&gt;It seems obvious to me that such setups are a good fit for many types of relatively unstructured work because the LLM provides the intelligence to bring structure. IDE-integrated, agentic workflows are commonplace in software engineering. If the enterprise can use such code editors to generate and maintain vast codebases, it is a dead-cert candidate for spheres such as research and article or report drafting, where the concept of “diffing” is easily transferable and possible at high speed and reliably with a capable LLM.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;The challenge is to keep the LLM on track through the ability to guide the workflow and to compensate for the context window and memory limitations that even frontier models carry.&lt;/p&gt;
 &lt;p&gt;The end result is a setup that allows me to handle vast amounts of information - multiple datasets of multiple types, PDFs, CSVs, markdown, whatever it can read. Meanwhile, its agentic capabilities can spin up R and Python scripts for intermediate checks or as part of persistent data pipelines for perpetual use. Via &lt;a href="https://www.techtarget.com/ai/tip/How-the-Model-Context-Protocol-simplifies-AI-development"&gt;MCP servers&lt;/a&gt; it can carry out research on the internet and add to the dataset. Its outputs can be checked against source material and finished articles can be compared to its drafts so it can build your requirements into the markdown-based documents that guide its workflow.&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="Not yet the culmination"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Not yet the culmination&lt;/h2&gt;
 &lt;p&gt;So, what’s my role as I do this? I feel sometimes I’ve become more like the editor now. I’m taking strategic decisions all day long. Instead of being in the tactical weeds of coding or writing, I oversee an LLM-powered worker that can assess and summarise vast volumes of source material, locally and on the internet. Its brain can work with far more sources than I can, so I guide it to investigate angles and report back, tweak lines of research on my instruction, edit its written and graphical outputs.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;But I am glad I learned to code before all this arrived, because to use an LLM for this kind of work it is essential to have some idea of what it is doing – to see where it might have gone wrong, and to troubleshoot when things do not come out as you expected. That depends on knowing what happens at the code window level. It’s the equivalent of knowing your subject matter when it comes to editorial decisions.&lt;/p&gt;
 &lt;p&gt;And so that’s where I’m at now in my journey in IT. It’d be foolish to call it a culmination. Things move so fast and who knows where we’ll be in a year’s time. I’m sure there’s a lot more I could explore.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read all of Computer Weekly's 60th anniversary essays&lt;/h3&gt; 
   &lt;p&gt;Technology is changing the way we live and work like never before – touching people’s lives every day, opening up new opportunities and creating new challenges.&lt;/p&gt; 
   &lt;p&gt;So for our 60&lt;sup&gt;th&lt;/sup&gt; anniversary, we wanted to reflect on the human stories of how the digital revolution has changed the lives of some of the key leaders and influencers in tech today. Read our full collection of essays, which offers a unique set of insights and perspectives into the changes we have seen during Computer Weekly's first 60 years.&lt;/p&gt; 
   &lt;h2&gt;&lt;a href="https://www.computerweekly.com/essentialguide/CW60-How-technology-has-changed-our-lives-over-60-years"&gt;CW@60 - How technology has changed our lives over 60 years&lt;/a&gt;&lt;/h2&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>Computer Weekly's acting datacentre and cloud editor – and data journalist – Antony Adshead traces his tech evolution from green-screen mainframes and DIY coding to steering agentic AI</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/HeroImages/using-AI-agent-chatbot-Looker-Studio-adobe.jpg</image>
            <link>https://www.computerweekly.com/feature/CW60-The-long-gestation-of-a-data-nerd-and-agent-overseer</link>
            <pubDate>Mon, 07 Sep 2026 03:00:00 GMT</pubDate>
            <title>CW@60: The long gestation of a data nerd and agent overseer</title>
        </item>
        <item>
            <body>&lt;p&gt;Organisations are increasingly recognising they already possess the data needed to realise AI’s transformative potential. But, the challenge is no longer data acquisition. The focus is now on activating enterprise data through continuous, governed pipelines that power every stage of the AI lifecycle, from model training and fine-tuning to inference, automation, and advanced analytics.&lt;/p&gt; 
&lt;p&gt;This is where &lt;a href="https://www.computerweekly.com/resources/Data-centre-capacity-planning"&gt;the AI factory&lt;/a&gt; needs to become a foundational layer of the emerging AI infrastructure landscape. AI factories provide the capabilities needed to operationalise and scale AI across the enterprise. In the words of &lt;a href="https://www.computerweekly.com/news/366570992/Nvidia-CEO-sees-shift-in-datacentres-to-AI-generation-factories"&gt;Nvidia CEO Jensen Huang&lt;/a&gt;, this marks a fundamental shift in how organisations build and deploy intelligent systems: “AI is now infrastructure, and this infrastructure, just like the internet, just like electricity, needs factories,” he said, at last year’s Computex event.&amp;nbsp;&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;From AI experimentation to industrialised intelligence&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;An AI factory is a unified, automated operating model that enables organisations to build, deploy, and scale AI through a fast, repeatable, and above all trusted process. It integrates the core capabilities required to operationalise AI at enterprise scale, including data pipelines, MLOps, infrastructure orchestration, governance, security, and continuous monitoring, into a single, end-to-end platform.&lt;/p&gt; 
&lt;p&gt;At the heart of a successful AI factory is a trusted data foundation. It provides the operational backbone that ensures data quality, availability, governance, and secure access across complex hybrid and multi-cloud environments. With this foundation in place, organisations can move beyond isolated proofs of concept to industrialise AI, scaling trusted, enterprise-wide capabilities that deliver measurable business outcomes with speed, resilience, and confidence.&lt;/p&gt; 
&lt;p&gt;Compute powers AI. Data creates value. As organisations move from AI experimentation to enterprise-scale deployment, the limiting factor &lt;a href="https://www.computerweekly.com/news/366649734/Why-AI-may-need-fewer-datacentre-GPUs-than-you-think"&gt;is no longer GPU capacity&lt;/a&gt;. Rather, it’s the ability to continuously provide trusted, resilient data. Recent innovations across the infrastructure ecosystem have cemented the AI factory as the blueprint for enterprise AI. Yet despite the focus on accelerated computing, the true differentiator is the trusted data infrastructure that keeps AI running reliably, securely, and at scale.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;From compute capacity to AI capability&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;Organisations are investing millions in AI infrastructure, but GPUs create value only when they have continuous access to the right data. GPU starvation has become one of the costliest (and still least visible) barriers to AI at scale. The initial instinct is often to add more compute, yet the true bottleneck typically lies in the underlying data infrastructure: &lt;a href="https://www.computerweekly.com/feature/Storage-technology-explained-AI-and-the-data-storage-it-needs"&gt;fragmented storage&lt;/a&gt;, disconnected platforms, inefficient data movement, and inconsistent governance that leave high-value AI resources underutilised.&lt;/p&gt; 
&lt;p&gt;The AI factory overcomes these challenges by treating data as a continuously flowing production asset, not something confined to disconnected systems. Rather than stitching together isolated AI tools, organisations are creating integrated pipelines that connect data ingestion, engineering, analytics, model development, and inference into a single operational framework. This shift transforms AI from a series of projects into an enterprise capability. In the end, AI factories are built on compute resources that consist of powerful GPU clusters and associated CPUs, but they succeed because of data infrastructure.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;Making data work harder for AI&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;Every unnecessary copy creates additional cost. To overcome this challenge, organisations are increasingly shifting toward architectures that bring AI workloads closer to the data rather than continuously moving petabytes between fragmented systems. By reducing data movement, enterprises can improve performance, simplify governance, accelerate model development, and maintain a single trusted source of truth. This data-centric approach is critical to the AI factory model, ensuring GPU resources remain productive, infrastructure operates efficiently, and AI investments deliver greater business value.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;Trust is now as critical as performance&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;While GPU efficiency remains a central focus of AI discussions, organisations are facing a parallel challenge: protecting sensitive data from growing threats such as ransomware, corruption, and unauthorised access. As enterprises deploy AI against sensitive operational data, intellectual property, healthcare records, financial information, and public sector datasets, security and governance become fundamental design considerations. The question is no longer just, “Can we run AI?” It is, “Can we run AI with the confidence that our data remains secure, governed, and compliant?”&lt;/p&gt; 
&lt;p&gt;As generative AI becomes a core component of enterprise operations, organisations require confidence that their data remains secure, controlled, and governed throughout its lifecycle. This means having complete visibility into where data resides, who can access it, how it is protected, and how policies are consistently applied across hybrid environments.&lt;/p&gt; 
&lt;p&gt;Trust in the AI factory extends beyond security alone. It requires a data foundation where the information powering AI models is accurate, protected, and governed by design, regardless of where data is stored or where workloads run. As AI moves from experimentation into mission-critical decision-making, governance must become an integral capability embedded across the entire data pipeline, not a control applied after the fact.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;Sovereign infrastructure enables enterprise AI&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;Many enterprises are rethinking the assumption that public cloud is the default destination for every AI workload. Increasingly, hybrid architectures are becoming the foundation for enterprise AI, enabling organisations to run data and workloads in the environments best suited to their business, regulatory, and performance requirements: whether on-prem, in sovereign cloud environments, or across multiple cloud providers. This approach provides the flexibility to scale AI while maintaining consistent governance, security, and operational control.&lt;/p&gt; 
&lt;p&gt;Data sovereignty extends far beyond regulatory compliance. It is a dynamic, strategic capability that allows organisations to retain control over one of their most valuable assets while maintaining the flexibility to deploy AI where it delivers the greatest business value. Whether data resides on-prem, in sovereign cloud environments, or across multiple cloud providers, enterprises need a consistent approach to security, governance, and management across the entire AI factory.&lt;/p&gt; 
&lt;p&gt;A sovereign AI strategy is about creating the trusted foundation that enables innovation at scale. By allowing governance policies to follow the data wherever it resides, organisations can build AI environments that are secure, flexible, and aligned with business, regulatory, and operational requirements.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;Cyber Resilience: A core capability of the AI factory&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;AI systems are only as trustworthy as the data they consume, making data protection and integrity essential to successful AI operations. If training datasets are corrupted, encrypted by ransomware, or unintentionally modified, the impact can extend from degraded model performance to compromised business decisions.&lt;/p&gt; 
&lt;p&gt;For this reason, cyber resilience must be built into the foundation of AI infrastructure. Immutable storage, ransomware protection, and rapid recovery capabilities ensure that the data powering AI remains protected, recoverable, and trustworthy throughout its lifecycle. In the AI factory, resilience is not an optional safeguard, it is a core capability that enables organisations to operate AI with confidence. Resilient infrastructure provides the foundation for AI factories, enabling organisations to innovate at scale with confidence.&amp;nbsp;&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;The future AI factory is built around data&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;The excitement surrounding AI factories is well deserved. They mark a shift from isolated AI experimentation to industrialised, repeatable AI operations that can scale across the enterprise. The organisations achieving the greatest impact are those establishing continuous data pipelines, enabling enterprise data to be ingested, prepared, governed, analysed, and transformed into actionable intelligence with minimal friction. Yet an exclusive focus on GPUs risks missing the larger opportunity: AI success depends not only on accelerated compute, but on the trusted data infrastructure that enables it.&lt;/p&gt; 
&lt;p&gt;Compute resources will continue to matter, but the next phase of AI advantage will be determined by the quality of the data infrastructure beneath it. Organisations that succeed will be those that build AI factories on trusted foundations: agile architectures that combine high performance with governance, resilience, operational simplicity, and sovereignty.&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;Paul Speciale is chief marketing officer at Scality.&lt;/em&gt;&lt;/p&gt; 
&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;Read more about AI factories&lt;/h3&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Is-it-time-to-build-an-AI-factory"&gt;Is it time to build an AI factory?&lt;/a&gt; If artificial intelligence is to deliver real benefits, firms need to scale its deployment. Developing an internal AI factory, akin to a digital factory model used by some, is one option&lt;/li&gt; 
   &lt;li&gt;&lt;a href="https://www.computerweekly.com/news/366643673/Datacentre-dive-AI-factory-power-draw-changes-the-grid-calculus"&gt;Datacentre dive: AI factory power draw changes the grid calculus&lt;/a&gt;. We look at energy as the key driver – and bottleneck – in development, and why water use is less of an issue now datacentres use liquid cooling over air cooling&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;ul class="default-list"&gt;&lt;/ul&gt; 
&lt;p&gt;&lt;/p&gt;</body>
            <description>AI factories shift enterprises from isolated AI experiments to scaled operations. Success depends less on raw GPU compute and more on trusted, secure, and governed data infrastructure.</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/HeroImages/AI-automation-robot-smart-devices-elenabsl-adobe.jpg</image>
            <link>https://www.computerweekly.com/opinion/AI-factories-will-depend-on-a-reliable-data-infrastructure</link>
            <pubDate>Tue, 01 Sep 2026 05:20:00 GMT</pubDate>
            <title>AI factories will depend on a reliable data infrastructure</title>
        </item>
        <item>
            <body>&lt;p&gt;Here is a question most enterprise storage teams have not yet asked themselves: If regulated &lt;a href="https://www.computerweekly.com/resources/Software-as-a-Service-SaaS"&gt;data cannot leave a jurisdiction&lt;/a&gt;, does the same rule apply to a model trained on it? The contributors Computer Weekly consulted for this article answered with an unambiguous yes – and argued that the implications reach well beyond compliance.&lt;/p&gt; 
&lt;p&gt;In this&amp;nbsp;&lt;a data-saferedirecturl="https://www.google.com/url?q=https://www.computerweekly.com/feature/The-geography-trap-Why-a-cloud-region-is-no-substitute-for-data-sovereignty&amp;amp;source=gmail&amp;amp;ust=1787927797844000&amp;amp;usg=AOvVaw1UGDHgNsCQ1JP2PZDHsNYx" target="_blank" href="https://www.computerweekly.com/feature/The-geography-trap-Why-a-cloud-region-is-no-substitute-for-data-sovereignty" rel="noopener"&gt;second part of a two-part series&lt;/a&gt;, Computer Weekly digs deeper into the responses to a set of questions that originated from discussions around&amp;nbsp;&lt;a data-saferedirecturl="https://www.google.com/url?q=https://www.a3communicationspr.com/homepage/events/technology-live/&amp;amp;source=gmail&amp;amp;ust=1787927797844000&amp;amp;usg=AOvVaw3aiprAoM1CspdkKPUK1730" target="_blank" href="https://www.a3communicationspr.com/homepage/events/technology-live/" rel="noopener"&gt;Technology Live!&lt;/a&gt;&amp;nbsp;events and which was opened out to an expanded list of storage&amp;nbsp;suppliers. These comprised execs from the storage, backup and legal sectors and deal with the state of data sovereignty and where it heads over the next 12 to 18 months.&lt;/p&gt; 
&lt;p&gt;Their answers sketch a forward picture that is more complex and more commercially significant than the first part of the debate. Sovereignty, they argue, is no longer just about keeping data safe from foreign courts. It is about who controls the intelligence derived from that data, who can monetise it and who can offer contractual guarantees that turn architectural independence into a market advantage.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The model inherits the data"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The model inherits the data&lt;/h2&gt;
 &lt;p&gt;If regulated data cannot leave a jurisdiction, the contributors argue, &lt;a href="https://www.computerweekly.com/news/366646018/Kaniskha-Narayan-takes-on-AI-sovereignty-in-Burnham-cabinet"&gt;the same logic applies to a model trained on it&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;“This is the sovereignty frontier that almost no one has adequately addressed, and it is going to become one of the most contested questions in data governance over the next two years,” says Aleksander Ragel, CEO and co-founder of Leil Storage.&lt;/p&gt;
 &lt;p&gt;“If you train a model on sovereign data – patient records, financial transactions, classified research – does the model inherit the sovereignty constraints of its training data?” he adds. “Legally, the answer is evolving. Practically, it should, because model weights encode statistical representations of that data, and in some cases, training data can be partially reconstructed from the model itself.”&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;TL;DR – key points about data sovereignty&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;A model trained on sovereign data inherits that data’s sovereignty.&amp;nbsp;&lt;/li&gt; 
    &lt;li&gt;AI models, outputs and derived insights are sovereign assets.&lt;/li&gt; 
    &lt;li&gt;Sovereign architecture must be built for a fragmented, multi-jurisdiction world.&lt;/li&gt; 
    &lt;li&gt;Sovereignty is moving from compliance cost to competitive edge.&lt;/li&gt; 
    &lt;li&gt;Real control means knowing, protecting, recovering and proving your data.&lt;/li&gt; 
    &lt;li&gt;Sovereignty service-level agreements (SLAs) will become the next procurement differentiator.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
 &lt;p&gt;Ragel frames the challenge as an end-to-end sovereignty chain – the raw data, the training pipeline, the model weights, the inference outputs and the derived insights – where a single link processed outside the organisation’s jurisdictional control compromises the whole chain. That carries direct infrastructure implications, particularly for the warm tier of storage that houses training datasets – “too active for tape, too voluminous for flash”, in Ragel’s words.&lt;/p&gt;
 &lt;p&gt;Paul Speciale, chief marketing officer at Scality, extends the argument across the full artificial intelligence (AI) lifecycle: “If your training data corpus is regulated, then the model weights derived from it, the embeddings indexed from it, &lt;a href="https://www.computerweekly.com/feature/RAG-AI-Do-it-yourself-says-NYC-data-scientist"&gt;the RAG pipelines&lt;/a&gt; retrieving from it and the inference outputs based on it are all carrying along the sovereignty of their source, since you can’t strip jurisdiction by transformation.&lt;/p&gt;
 &lt;p&gt;“A fine-tuned model trained on EU patient data is, in effect, an EU asset, and running its inference path through a foreign GPU [graphics processing unit] cloud reopens every question the training-data architecture tries to close.”&lt;/p&gt;
 &lt;p&gt;The practical consequence, he argues, is that “training, fine-tuning, inference, KV cache, embeddings, checkpoints and long-term retention all need to sit inside the same jurisdictional boundary as the source data, preferably under one operating model and layer” – something he expects to become “an explicit requirement in regulated, industry RFPs [request for proposals]” in the next year.&lt;/p&gt;
 &lt;p&gt;Tvrtko Fritz, CEO of euroNAS reflects the prevailing view. "As AI becomes increasingly embedded in business processes, organisations need to broaden their understanding of data sovereignty,” he says. “The discussion can no longer be limited to the raw data itself. Sovereignty should also extend to the insights generated from that data, the models trained on it, and the intellectual property embedded within AI systems.”&lt;/p&gt;
 &lt;p&gt;The AI sovereignty question, in other words, is not a theoretical edge case. It is the natural destination of the control-over-location logic – and it leads directly to the economic dimension.&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="Built for fragmentation"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Built for fragmentation&lt;/h2&gt;
 &lt;p&gt;If AI workloads must sit inside the same jurisdictional boundary as their source data, the architecture beneath them must be built for &lt;a href="https://www.computerweekly.com/feature/This-rise-of-the-splinternet-Data-sovereignty-risks-and-responses"&gt;a fragmented, jurisdictionally bound world&lt;/a&gt; by design. The contributors identify converging imperatives: Federated autonomy, physical-layer awareness and jurisdictional alignment treated as a procurement criterion.&lt;/p&gt;
 &lt;p&gt;Ragel calls for federated-but-autonomous storage clusters that operate independently in each jurisdiction, with no shared control plane and no cross-border metadata leakage – and for platforms that stop abstracting away the hardware. “In a sovereignty context, that abstraction is a liability,” he says. “You need a storage architecture that understands which drives hold which data, how that data is distributed across physical nodes, and how to manage data placement with jurisdictional intent.”&lt;/p&gt;
 &lt;p&gt;Speciale echoes the federated model, adding: “Default to regional autonomy: Each jurisdiction gets its own data plane for storage, keys, identity, audit. And each one should be able to operate independently if the global connection is severed.” The pattern, he says, is “multi-jurisdiction by design: distributed by default, governed centrally, with the data plane enforced by infrastructure rather than asserted by contract”.&lt;/p&gt;
 &lt;p&gt;Alexander Lefterov, founder and CTO of Tiger Technology, keeps the priority on the control plane. “Prioritise the control plane first – if you do not govern your own data lifecycle policies, the rest of your sovereignty investment is built on sand. The most critical change is establishing clear data visibility and lineage. Organisations cannot protect or control data they do not understand.”&lt;/p&gt;
 &lt;p&gt;Valery Guilleaume, CEO of Nodeum, adds the mobility dimension: “The key architectural shift is moving from fixed, region-based storage to policy-driven data mobility across jurisdictions. Enterprises need to separate storage from control, so governance, access rules and auditability stay consistent no matter where data moves or is accessed.”&lt;/p&gt;
 &lt;p&gt;The suppliers best positioned to deliver these architectures transparently – because their platforms are designed for jurisdictional containment rather than retroactively constrained – are likely to &lt;a href="https://www.computerweekly.com/feature/Breaking-the-stranglehold-Responses-to-data-sovereignty-risk"&gt;define the procurement conversations&lt;/a&gt; of the next several years.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="From cost centre to competitive edge"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;From cost centre to competitive edge&lt;/h2&gt;
 &lt;p&gt;If the AI sovereignty chain and the architectural shifts define the technical response, the economic case turns sovereignty from a defensive posture into an offensive strategy.&lt;/p&gt;
 &lt;p&gt;Shimon Ben-David, CTO at WEKA, locates the value at the point of inference. “The value of AI is delivered at inference,” he says. “When you serve it to users at scale, that’s where the economics matter. Control your own data and the infrastructure that serves it during inference, and you control how efficiently your AI runs and what it costs.”&lt;/p&gt;
 &lt;p&gt;He adds: “Run inference on infrastructure you don’t control, and you inherit its inefficiencies, paying for capacity you can’t optimise. As token consumption grows, that cost compounds and the gap between controlling your infrastructure and not controlling it widens with every token you produce. The organisations that treat control over their own data and AI infrastructure as an economic asset will turn it into a competitive moat.”&lt;/p&gt;
 &lt;p&gt;Speciale sees sovereignty moving from cost centre to market-access precondition. “A European bank, a French hospital network, a German automaker, a UK government supplier – none of them can win new contracts without demonstrable control over where their data lives and who can reach it,” he says. Organisations that can credibly promise “your data, your jurisdiction, your keys, our infrastructure”, he adds, earn a confidence hyperscaler-only competitors cannot match. “In an AI world where customer data is the moat, that guarantee is increasingly the product.”&lt;/p&gt;
 &lt;p&gt;Fritz draws out the link between sovereignty and value. "Data sovereignty is increasingly changing how organisations think about value,” he says. “Traditionally, data was viewed primarily as an operational asset that needed to be stored, protected, and managed efficiently. Today, many organisations recognise that their data, the knowledge derived from it, and the expertise embedded within their processes represent some of their most important competitive assets.”&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="The test of real control"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The test of real control&lt;/h2&gt;
 &lt;p&gt;If sovereignty is becoming a value driver, the obvious question is what qualifies as genuine control. The contributors converge on a definition more demanding than most current storage and backup models can satisfy.&lt;/p&gt;
 &lt;p&gt;Ragel distils it to four simultaneous conditions: “You know where every byte of data physically resides; no external party can access it without your explicit authorisation; your ability to operate, recover and migrate is not dependent on any third party’s continued cooperation; and you can prove all of the above to a regulator.”&lt;/p&gt;
 &lt;p&gt;The last criterion is where most of the industry falls short. Most current models, he argues, fail on at least two of the four – cloud storage on jurisdictional independence, traditional on-premise on operational independence, and nearly all legacy architectures on provability.&lt;/p&gt;
 &lt;p&gt;Martin Kunze, founder and CMO of Cerabyte, frames the gap in terms of what most storage systems were designed for: “Computational performance, not for secure, permanent, sovereign data preservation.”&lt;/p&gt;
 &lt;p&gt;Lefterov reaches the same conclusion, arguing that organisations must know where their data is, decide what happens to it at every lifecycle stage, recover it independently of any single supplier and prove it to an auditor. “Most backup and cloud-first models today fail on at least two of those four,” he says.&lt;/p&gt;
 &lt;p&gt;The gap between the definition of control and the reality of current infrastructure is, in effect, the commercial opportunity.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="The contractual horizon"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The contractual horizon&lt;/h2&gt;
 &lt;p&gt;If the definition of control exposes the gap, the natural commercial response is a contractual instrument that makes sovereignty guarantees enforceable. The contributors see &lt;a href="https://www.computerweekly.com/feature/Is-cloud-data-sovereignty-all-just-a-case-of-Trust-me-bro"&gt;sovereignty SLAs&lt;/a&gt; as the most significant market development of the next 18 months.&lt;/p&gt;
 &lt;p&gt;Ragel describes sovereignty SLAs as “the most commercially interesting development. We will see procurement teams demanding contractual guarantees about jurisdictional exposure, control-plane independence, and data access vectors – not just uptime percentages. Vendors that can offer this transparently, because their architecture is inherently sovereign rather than retroactively constrained, will win.”&lt;/p&gt;
 &lt;p&gt;Speciale agrees, framing SLAs as “the natural next step in contracts – not just uptime and recovery time, but jurisdictional guarantees, disclosure-order notification, and proof-of-placement evidence. The vendors who can deliver them will define the next decade of the storage market.”&lt;/p&gt;
 &lt;p&gt;Lefterov expects SLAs within 18 months: “Start asking your vendors for sovereignty SLA commitments now – organisations that normalise these expectations in procurement will shape what the market delivers over the next two years.”&lt;/p&gt;
 &lt;p&gt;Weijdema sees “early forms of sovereignty service commitments likely to emerge in vendor agreements, although consistency will continue to evolve”. The sequencing that emerges is consistent: in-region defaults arrive first, multi-jurisdiction architectures follow as standard, sovereignty SLAs emerge within 18 months as the procurement differentiator, and AI data-origin tagging takes longest to mature.&lt;/p&gt;
 &lt;p&gt;The commercial arc is clear, according to these contributors. Sovereignty began as a compliance obligation – now, it is becoming an architectural property and is heading towards being a contractual guarantee – one that will separate the storage market into those who can offer it and those who cannot.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more about data sovereignty&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/news/366645336/Data-dive-Kill-switch-and-catch-up-can-Europe-close-the-sovereignty-gap"&gt;Data dive: Kill switch and catch-up – can Europe close the sovereignty gap?&lt;/a&gt; As the US demonstrates it can wield an AI ‘kill switch’, the EU and UK unleash a wave of sovereign tech measures. Can state-led industrial policy bridge a $2tn revenue chasm?&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/This-rise-of-the-splinternet-Data-sovereignty-risks-and-responses"&gt;The rise of the splinternet? Data sovereignty risks and responses&lt;/a&gt;: We explore the political, legal and economic risks that data sovereignty fractures pose to global digital infrastructure, from sanctions-driven cloud lockouts to jurisdictional conflicts.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Is-cloud-data-sovereignty-all-just-a-case-of-Trust-me-bro"&gt;Is cloud data sovereignty all just a case of 'Trust me, bro'?&lt;/a&gt;: An analysis of whether contractual sovereignty guarantees from hyperscale cloud providers offer meaningful protection or merely cosmetic reassurance to European customers.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Breaking-the-stranglehold-Responses-to-data-sovereignty-risk"&gt;Breaking the stranglehold: Responses to data sovereignty risk&lt;/a&gt;: How UK public sector procurement patterns entrench large cloud incumbents, and what policy interventions aim to break that cycle.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>In part two of a two-part series, Computer Weekly talks to 10 storage suppliers and a lawyer about the next frontier in data sovereignty – from AI model sovereignty to the sovereign SLAs that could redefine the storage market</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/Hero%20Images/data-information-1-adobe.jpeg</image>
            <link>https://www.computerweekly.com/feature/Sovereigntys-next-chapter-Why-AI-makes-sovereignty-a-competitive-advantage</link>
            <pubDate>Fri, 21 Aug 2026 08:09:00 GMT</pubDate>
            <title>Sovereignty’s next chapter: Why AI makes sovereignty a competitive advantage</title>
        </item>
        <item>
            <body>&lt;p&gt;The Natural History Museum’s (NHM’s) “living laboratory” garden has collected more than 11 million &lt;a href="https://www.computerweekly.com/resources/Infrastructure-as-a-Service-IaaS"&gt;environmental data records&lt;/a&gt; in its first year, feeding readings from more than 50 sensors into the Museum’s Amazon Web Services (AWS)-powered Data Ecosystem.&lt;/p&gt; 
&lt;p&gt;The sensors in the Nature Discovery Garden continuously capture temperature and humidity to track microclimate variation, underwater acoustic recordings from the pond, birdsong and ambient urban noise such as traffic.&lt;/p&gt; 
&lt;p&gt;During June’s heatwave, soil sensors in the garden’s woodland areas recorded temperatures 10°C cooler than the paved areas of the Darwin Centre Courtyard, giving researchers evidence for how trees, shade, soil moisture and permeable surfaces can help cities adapt to rising temperatures.&lt;/p&gt; 
&lt;p&gt;The readings feed a Data Ecosystem built on AWS cloud technologies, which collects, processes and shares millions of observations from sensors, imagery and other scientific sources. In practice, that means an &lt;a href="https://www.computerweekly.com/feature/Natural-History-Museum-deploys-sensor-network-to-decode-urban-biodiversity-with-AWS"&gt;internet of things (IoT) data pipeline&lt;/a&gt; in which devices publish telemetry to a message broker such as AWS IoT Core, streamed through a service such as Kinesis into an &lt;a href="https://www.computerweekly.com/feature/Storage-technology-explained-What-is-S3-and-what-is-it-good-for"&gt;S3&lt;/a&gt;-based &lt;a href="https://www.computerweekly.com/feature/Cloud-data-lakes-Where-do-they-fit-and-what-are-their-benefits"&gt;data lake&lt;/a&gt;, then processed, catalogued and analysed with tools such as Athena and SageMaker – including machine learning models that classify birdsong and other acoustic recordings.&lt;/p&gt; 
&lt;p&gt;Ed Baker (pictured), acoustic biology researcher at the Natural History Museum, said: “We call the Museum gardens a living laboratory, and the sensor network and AWS Data Ecosystem have made this a reality. By collecting millions of data points, from temperature and humidity to birdsong and underwater sound, we can build a far richer picture of how urban nature responds to various pressures and becomes more resilient to future environmental challenges.”&lt;/p&gt; 
&lt;p&gt;The museum is now expanding the network into its Evolution Garden, an area with higher visitor footfall and a contrasting planting style, to study how visitor activity and habitat design influence biodiversity.&lt;/p&gt; 
&lt;p&gt;Long-term monitoring since 1995 has recorded more than 3,500 species in the gardens, with a further 90 identified since they reopened in 2024, including the emperor moth and the small red-eyed damselfly.&lt;/p&gt; 
&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;Read more about cloud and sustainability&lt;/h3&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Natural-History-Museum-deploys-sensor-network-to-decode-urban-biodiversity-with-AWS"&gt;Natural History Museum deploys sensor network to decode urban biodiversity with AWS&lt;/a&gt;: We look at how the Museum’s sensor network and AWS Data Ecosystem turn a London garden into a living laboratory for urban biodiversity research.&lt;/li&gt; 
   &lt;li&gt;&lt;a href="https://www.computerweekly.com/news/366644373/Data-dive-Dodgy-data-derails-datacentre-water-debate"&gt;Data dive: Dodgy data derails datacentre water debate&lt;/a&gt;: We investigate how poor-quality data undermines claims about datacentre water consumption.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;The project is part of a wider pattern of deployments of environmental sensor networks allied to cloud data platforms. &lt;a href="https://www.technologyreview.com/2022/08/19/1057848/array-of-things-goes-global/"&gt;In Chicago, the Array of Things&lt;/a&gt; deployed hundreds of urban sensing nodes publishing open data through a cloud portal; in Germany, the &lt;a href="https://www.nature4.org/"&gt;Ammod automated multisensor stations and the Nature 4.0 project&lt;/a&gt; combine networked sensors with machine learning for biodiversity monitoring. The NHM reports that its Data Ecosystem has scaled to accommodate a 200% increase in use since the network was switched on.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Hilary Tam, sustainability leader for EMEA at AWS, said: “The Natural History Museum is showing what’s possible when science and cloud technology come together. As the sensor network grows, the AWS-powered Data Ecosystem is able to scale to enable researchers to connect millions of environmental observations, revealing patterns that would otherwise remain invisible.”&lt;/p&gt; 
&lt;p&gt;For enterprise IT leaders, the project is a reminder that the sensor-to-data-lake-to-machine-learning architecture is now cheap and standard enough to run in a museum garden, and so increasingly available for smart-city and infrastructure monitoring. But the hard part is not collection – it’s curation.&lt;/p&gt; 
&lt;p&gt;As Computer Weekly has reported, &lt;a href="https://www.computerweekly.com/news/366644373/Data-dive-Dodgy-data-derails-datacentre-water-debate"&gt;poor-quality data can derail environmental analysis&lt;/a&gt;, and the same rigour around sustainable IT and its environmental footprint applies to any organisation turning sensor telemetry into decisions.&lt;/p&gt;</body>
            <description>More than 50 sensors feed temperature, humidity and acoustic readings into the Museum’s AWS Data Ecosystem, which found woodland soils stayed 10°C cooler in June’s heatwave</description>
            <image>https://cdn.ttgtmedia.com/rms/computerweekly/Ed-Baker-Acoustic-Biology-Researcher-NHM.jpg</image>
            <link>https://www.computerweekly.com/news/366648981/Natural-History-Museums-living-laboratory-logs-11-million-environmental-records-in-first-year</link>
            <pubDate>Mon, 17 Aug 2026 10:30:00 GMT</pubDate>
            <title>Natural History Museum’s ‘living laboratory’ logs 11 million environmental records in first year</title>
        </item>
        <item>
            <body>&lt;p&gt;The ongoing legal dispute between supermarket chain &lt;a href="https://www.computerweekly.com/news/366644902/Tesco-offloads-VMware-and-CA-software-as-Broadcom-case-rolls-on"&gt;Tesco and Broadcom/VMware&lt;/a&gt; illustrates the challenges IT departments are likely to face if they plan to migrate to an alternative hypervisor.&lt;/p&gt; 
&lt;p&gt;The contract dispute with VMware has led Tesco to take the decision to replace its entire virtual server estate with an alternative hypervisor by 2027. In its filing, Tesco said the timeframe of the migration has created operational and commercial risk, as well as resulting in “material cost and disruption to the business”.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Tesco said it has incurred additional costs as it needed to develop or buy functionality and support interoperability that was only available on VMware. In particular, Tesco said the Veeam backup and Zerto’s data security products it uses are not currently interoperable with any other server virtualisation platforms.&lt;/p&gt; 
&lt;p&gt;Following completion of its acquisition of VMware in November 2023, Broadcom &lt;a href="https://www.computerweekly.com/news/366630061/Broadcom-bundles-private-AI-into-VCF-adds-security-automation"&gt;consolidated VMware products&lt;/a&gt; into product bundles such as VMware Cloud Foundation (VCF) and rolled out subscription-based pricing.&lt;/p&gt; 
&lt;p&gt;Some VMware customers, like Tesco, have been negatively impacted by these changes, which has not only seen them having to buy VMware products they do not use because they are included in the product bundle, but they have also seen a price hike due to licensing costs of the VMware product bundle.&lt;/p&gt; 
&lt;p&gt;Tesco’s claim concerns a five-year contract it originally signed in 2021 for VMware and VMware support. Broadcom refused to fulfil the contract, claiming the products the supermarket chain had purchased under its original agreement were no longer available.&lt;/p&gt; 
&lt;p&gt;While it is unclear from the legal filings which hypervisor platforms Tesco has selected, what is clear is that the product is not a like-for-like replacement, and the retailer is having to do remedial work to get it working.&amp;nbsp;&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The AHV alternative to VMware"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The AHV alternative to VMware&lt;/h2&gt;
 &lt;p&gt;Nutanix is among the companies that have seen an uptick in interest following the changes made to VMware following the Broadcom acquisition. The company, which established itself as a hyperconverged IT infrastructure provider alternative offering a lower cost and simplified alternative to PC servers, has spent the past few years upselling the benefit of its VMware alternative, its &lt;a href="https://www.techtarget.com/searchitoperations/tip/Compare-Nutanix-AHV-vs-VMware-ESXi-in-the-hypervisor-battle"&gt;Acropolis hypervisor&lt;/a&gt; (AHV), based on KVM open source virtualisation software.&lt;/p&gt;
 &lt;p&gt;When asked about how much progress has been made certifying third-party products with AHV, Rajiv Ramaswami, chief executive officer of Nutanix, said: “We probably have something close to 1,500 appliances and other products that are certified today, such as the Cisco Unified Communications appliance.”&lt;/p&gt;
 &lt;p&gt;With regards to backup, which is an area Tesco found challenging due to these products often relying on VMware application programming interfaces (APIs) for deep integration with the hypervisor, Ramaswami claimed that Veeam, Rubrik and other backup software providers are all certified work with Nutanix, as are firewalls from the likes of Palo Alto, Fortinet and Checkpoint. “We have been working with them for many years,” he said, adding that over the past 10 years, Nutanix has built out a technology ecosystem around its KVM-based hypervisor.&lt;/p&gt;
 &lt;p&gt;He said that while Veeam has had “basic integration” with AHV for a long time, the integration was behind VMware’s, which was much more established. However, he added: “When you talk to Veeam today, it’s a very different thing. They say their integration with Nutanix is on par with VMware integration. I was with the Veeam CEO a couple of weeks ago and we’ve been building the ecosystem over time.”&lt;/p&gt;
 &lt;p&gt;While the Tesco legal filing shows the company expects interoperability issues will eventually be resolved as software providers expand the level of integration they provide with non-VMware platforms, it is clear that this is a work in progress.&lt;/p&gt;
 &lt;p&gt;Some products, like Veeam, provide plug-ins to enable deep integration. But the reality is that there will inevitably be choices and compromises software providers will make when deciding which of their products are certified for a given hypervisor and the level of integration they are prepared to provide. These decisions have a material impact on the ease of deployment and performance of VMware virtualisation migrations.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more about VMware migrations&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/news/366633154/OpenInfra-Summit-Europe-Migrating-off-VMware"&gt;Migrating off VMware&lt;/a&gt;: With Broadcom’s focus on VMware Cloud Foundation subscriptions, OpenStack is being positioned as the open source alternative.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/opinion/Gartner-Symposium-2025-VMware-NSX-migration-tips"&gt;VMware NSX migration tips&lt;/a&gt;: How should organisations approach migrating off VMware NSX.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>VMware integration with third-party backup software improves performance and reduces admin. Alternative hypervisors are often less well-integrated</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/server_infrastructure_AdobeStock_271134500_smaller.jpeg</image>
            <link>https://www.computerweekly.com/news/366645498/Tesco-VMware-migration-shows-backup-incompatibilities</link>
            <pubDate>Tue, 07 Jul 2026 05:30:00 GMT</pubDate>
            <title>Tesco VMware migration shows backup incompatibilities</title>
        </item>
        <item>
            <body>&lt;p&gt;&lt;a href="https://www.carnivalcorp.com/" target="_blank" rel="noopener"&gt;Carnival Corporation&lt;/a&gt;, the world’s largest cruise ship operator, has confirmed an extensive data breach in the wake of an April 2026 system compromise claimed by &lt;a href="https://www.computerweekly.com/news/366639851/Salesforce-tracks-possible-ShinyHunters-campaign-targeting-its-users" target="_blank" rel="noopener"&gt;the now-infamous ShinyHunters cyber gang&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;As is typical of incidents attributed to ShinyHunters, the attack appears to have stemmed from inside Carnival’s &lt;a href="https://www.techtarget.com/searchsecurity/definition/supply-chain-attack" target="_blank" rel="noopener"&gt;supply chain&lt;/a&gt;, involving a successful phishing attempt against a third-party account with access to the victims’ systems.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://haveibeenpwned.com/breach/Carnival" target="_blank" rel="noopener"&gt;According to HaveIBeenPwned&lt;/a&gt;, this enabled the hackers to steal almost millions of data records linked to holidaymakers who had voyaged with Carnival’s Holland America brand, including names, dates of birth, gender and loyalty programme status. Carnival has now added contact details and driving licence and passport data to this list. Almost six million individuals are &lt;a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/d6729ef2-7bb3-42d3-abdd-99a1dd8f2415.html" target="_blank" rel="noopener"&gt;thought to be affected&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.carnivalcorp.com/wp-content/uploads/2026/05/Website-Notice-Substitute-Notice-05.27.26.pdf" target="_blank" rel="noopener"&gt;In a disclosure notice&lt;/a&gt;, the company claimed: “Carnival Corporation values the trust you place in us, and we take the privacy and security of your information very seriously … We deeply regret this incident and any concern it may cause, and have sent notification letters to individuals whose data was impacted.”&lt;/p&gt; 
&lt;p&gt;Serial cyber attack victim Carnival suffered three incidents – a data breach and two distinct ransomware attacks – &lt;a href="https://www.computerweekly.com/news/252487779/Carnival-cruise-lines-hit-by-ransomware-customer-data-stolen" target="_blank" rel="noopener"&gt;in quick succession in 2020&lt;/a&gt;, followed by &lt;a href="https://www.computerweekly.com/news/252502659/Carnival-Cruises-hit-by-fourth-cyber-incident-in-a-year" target="_blank" rel="noopener"&gt;a fourth cyber breach in early 2021&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;“In addition to the comprehensive security measures our company had in place prior to the incident, we have taken steps to further safeguard our systems, including enhancing our security and monitoring controls,” said Carnival, which has also committed to offering affected US residents two years of free credit monitoring services.&lt;/p&gt; 
&lt;p&gt;“Our company will continue to advance our IT security and data privacy controls to stay ahead of an ever-evolving threat landscape,” the firm added.&lt;/p&gt; 
&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;Read more about ShinyHunters&lt;/h3&gt; 
  &lt;ul class="default-list"&gt; 
   &lt;li&gt;The notorious ShinyHunters hacking collective menaces video game publisher Rockstar and says it will leak data &lt;a href="https://www.computerweekly.com/news/366641486/Grand-Theft-Auto-publisher-Rockstar-hit-by-hackers-again" target="_blank" rel="noopener"&gt;on 14 April&lt;/a&gt;.&lt;/li&gt; 
   &lt;li&gt;The ShinyHunters hacking collective that caused chaos in 2025 is ramping up a new voice phishing campaign, with several potential victims &lt;a href="https://www.computerweekly.com/news/366637762/Wave-of-ShinyHunters-vishing-attacks-spreading-fast" target="_blank" rel="noopener"&gt;already identified&lt;/a&gt;.&lt;/li&gt; 
   &lt;li&gt;ReliaQuest researchers present new evidence that firms up a potential link, or outright partnership, between the ShinyHunters &lt;a href="https://www.computerweekly.com/news/366629157/Researchers-firm-up-ShinyHunters-Scattered-Spider-link" target="_blank" rel="noopener"&gt;and Scattered Spider cyber gangs&lt;/a&gt;.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;Muhammad Yahya Patel, virtual chief cyber security officer (vCISO) and cyber security advisor for EMEA at&amp;nbsp;&lt;a href="https://www.huntress.com/" target="_blank" rel="noopener"&gt;Huntress&lt;/a&gt;, said the pattern of a ShinyHunters breach should feel uncomfortably familiar by now.&lt;/p&gt; 
&lt;p&gt;“Nearly six million people; one social engineering technique,” he said. “That’s the Carnival breach in its simplest form … ShinyHunters didn’t need a zero-day or a sophisticated exploit to breach the world’s largest cruise operator. Their playbook is well-documented: voice phishing to extract single sign on (SSO) credentials and multi-factor authentication (MFA) codes from employees by impersonating IT staff, followed by systematic access to connected SaaS [software as a service] environments to exfiltrate data at scale. The same technique. The same result. A different logo on the breach notification letter.”&lt;/p&gt; 
&lt;p&gt;The hospitality and travel industry is acutely vulnerable to cyber attacks thanks to high levels of staff turnover, geographically dispersed operations, heavy reliance on customer-facing systems, and a need to move fast to get things done. Add to this the vast amount of valuable customer data – a “ready-made targeting kit”, noted Patel – that organisations like Carnival hold, and it is easy to see how such breaches occur.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://redflags.io/" target="_blank" rel="noopener"&gt;Redflags&lt;/a&gt; CEO and co-founder Tim Ward said the latest Carnival incident showed that many companies are not yet considering the need to address supply chain threats from the inside out.&lt;/p&gt; 
&lt;p&gt;“Organisations need to start thinking seriously about … how to meet people where they actually are: inside their workflows, at the point of risk, with guidance and support that helps them make the right call in real time,” he said.&lt;/p&gt; 
&lt;p&gt;“Security needs to be something that works with people, not something done to them once a quarter in a tick-box exercise. Until we shift from compliance-driven awareness to genuinely embedding security into the moments that matter, social engineering will keep being the easiest door into even the largest organisations in the world.”&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Next steps"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Next steps&lt;/h2&gt;
 &lt;p&gt;Huntress’ Patel laid out the next steps for security leaders. “First, your help desk verification process is a primary attack surface right now,” he said. “If employees can be persuaded to hand over MFA codes by a confident caller, your entire identity security investment is undermined at the human layer.&lt;/p&gt;
 &lt;p&gt;“Second, ShinyHunters uses SSO access as a gateway to every connected SaaS application behind it,” said Patel. “Audit your OAuth tokens, review third-party SaaS access, and monitor for unusual activity in connected platforms.&lt;/p&gt;
 &lt;p&gt;“Third, the question is no longer whether you’ll be targeted using these techniques,” he added. “It’s about whether your people would recognise the call, whether your processes make compliance hard, and whether your detection catches what follows.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;“If any of those answers are uncertain, then you need to address them now,” said Patel.&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Travel company Carnival Corporation confirms the extent of an April 2026 supply chain breach that was claimed by ShinyHunters</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/article/cruise-ship-ocean-liner-adobe.jpg</image>
            <link>https://www.computerweekly.com/news/366643559/Carnival-cruise-line-confirmed-as-latest-ShinyHunters-victim</link>
            <pubDate>Thu, 28 May 2026 11:45:00 GMT</pubDate>
            <title>Carnival cruise line confirmed as latest ShinyHunters victim</title>
        </item>
        <item>
            <body>&lt;p&gt;Sustainability and strategy don’t always seem like natural bedfellows in a profit-driven world, but Simon Ninan, global head of strategy at &lt;a href="https://www.computerweekly.com/feature/Hitachi-Vantara-VSP-One-leads-revamped-storage-portfolio"&gt;Hitachi Vantara&lt;/a&gt;, wants to make it a reality, finding fresh approaches that deliver for customers, products, profit and the planet together.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;He says that if you want to see something better tomorrow, you have to start today. And for Ninan, it’s about finding a way through conflicting requirements. His core strategy team aims to combine knowledge, experience and ideas so that “one plus one equals five” and solves sustainability and &lt;a href="https://www.computerweekly.com/ezine/Computer-Weekly/Viewing-business-through-a-sustainability-lens"&gt;business&lt;/a&gt; challenges together.&lt;/p&gt; 
&lt;p&gt;“I grew up in Bangalore, India,” he says. “Bangalore has changed a lot. It used to be known as green – now there’s so much traffic, a lot of the greenness is gone. It’s a shame.”&lt;/p&gt; 
&lt;p&gt;In India, there’s still “incredibly intense” competition for resources as the country races to catch up, but in a “fair” way. Ideas around balancing those issues are often inculcated as you grow up, says Ninan.&lt;/p&gt; 
&lt;p&gt;Similarly, it seemed to him that the longevity of companies and the “hardiness or value” embedded in their vision can be deeply connected.&lt;/p&gt; 
&lt;p&gt;Comparisons with the US, where he arrived after studying computer science and engineering, were stark. Growth delivered clear benefits to the population, but at the same time, he saw “a land of excess”, where resources were often wasted.&lt;/p&gt; 
&lt;p&gt;“I have continued consistently to think about how a little can potentially go a long way. How can we drive better decisions, and avoid innovation for innovation’s sake, technology for technology’s sake?” he says. “It’s about fusing business and technology. And there’s opportunity in that.”&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Long-term vision shapes sustainability strategy"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Long-term vision shapes sustainability strategy&lt;/h2&gt;
 &lt;p&gt;Ninan joined Hitachi Vantara in 2019, following seven years as an executive at Japan-headquartered parent Hitachi, and before that at Monitor Deloitte.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;At the board and corporate levels, Hitachi has a culture of going beyond short-term strategic planning.&lt;/p&gt;
 &lt;blockquote&gt; 
  &lt;div class="imagecaption alignLeft"&gt;
   &lt;img src="https://cdn.ttgtmedia.com/rms/computerweekly/Simon-Ninan-Hitachi-Vantara-140x180px.jpg" alt="Photo of Simon Ninan, global head of strategy at Hitachi Vantara"&gt;
  &lt;/div&gt; 
  &lt;p&gt;&lt;span style="font-size: 14pt;"&gt;&lt;strong&gt;&lt;span style="color: #34495e;"&gt;“I have continued to think about how a little can potentially go a long way. How can we drive better decisions, and avoid innovation for innovation’s sake, technology for technology’s sake? It’s about fusing business and technology. And there’s opportunity in that”&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt; 
  &lt;p&gt;&lt;em&gt;&lt;span style="color: #34495e;"&gt;Simon Ninan, Hitachi Vantara&lt;/span&gt;&lt;/em&gt;&lt;/p&gt; 
 &lt;/blockquote&gt;
 &lt;p&gt;That begins by asking how the world might look 30, 50 or even 70 years from today, and planning for “mega-trends”, such as in terms of productivity and artificial intelligence (AI), socio-politics and climate change. The strategic time frame is the next two generations at minimum, including innovating around products and solutions that benefit society at large.&lt;/p&gt;
 &lt;p&gt;That long-term focus is “very interesting and unique”, says Ninan.&lt;/p&gt;
 &lt;p&gt;“We also talk about ageing demographics, or changing demographics. Emerging markets, availability of resources, productivity, the digital divide,” Ninan says. “Big hurdles that society will face. Then, working backward as it were, Hitachi asks what we can do today.”&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Japanese principles guide collaborative approach"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Japanese principles guide collaborative approach&lt;/h2&gt;
 &lt;p&gt;Hitachi founder Namahei Odaira originally tied the company philosophy to the Japanese principles of “wa”, “makoto” and “kaitakusha-seishin”.&lt;/p&gt;
 &lt;p&gt;At Hitachi, the harmony-related concept of “wa” encourages respect for others’ opinions and promotes open, fair and impartial discussion. In sustainability, this translates into a highly collaborative, cross-functional approach that connects efforts across the full lifecycle of products and operations, and to ensure impacts are understood holistically, says Ninan.&lt;/p&gt;
 &lt;p&gt;“Makoto” is about sincerity – approaching issues with openness, honesty and respect, “in the spirit of true teamwork”.&lt;/p&gt;
 &lt;p&gt;“In &lt;a href="https://www.computerweekly.com/opinion/IT-Sustainability-Think-Tank-How-IT-sustainability-entered-the-mandate-era-during-2025"&gt;sustainability&lt;/a&gt;, this is reflected in transparency, proactive data collection and reporting, and a commitment to go beyond simply meeting requirements to delivering on the spirit of our goals,” says Ninan.&lt;/p&gt;
 &lt;p&gt;“Kaitakusha-seishin” may be best translated as “pioneering spirit”. Ninan says that at Hitachi, this emphasises a striving for leadership through pursuing new challenges and higher goals, but building on a commitment to innovation that goes beyond mere compliance, to driving positive impacts for society and the planet. That mission is now being extended to other parts of the world where Hitachi operates.&lt;/p&gt;
 &lt;p&gt;“I find that really powerful, because it says you can make trade-offs in your bottom line for a bigger goal,” he adds.&amp;nbsp;“It’s very ambitious. We have a double bottom line. Every company tries to make sure it delivers profit, but the double bottom line means it’s not just about the shareholders; it’s about the stakeholders and the value you’re delivering – your customers, your partners, your employees.”&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Tackling Scope 3 emissions in datacentres"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Tackling Scope 3 emissions in datacentres&lt;/h2&gt;
 &lt;p&gt;Today’s sustainability challenges for the team include weighing up the challenges and potential benefits of &lt;a href="https://www.computerweekly.com/feature/AI-drives-storage-array-makers-to-embrace-data-management"&gt;AI&lt;/a&gt; enablement, for example. Also, there’s a need to rethink the value of hybrid cloud data solutions versus the return on investment in data, says Ninan.&lt;/p&gt;
 &lt;p&gt;The most recent “major strategy refresh” with a medium- to long-term perspective at Hitachi Vantara was three years ago. It involved “extensive embedding” of Hitachi’s sustainability reporting into Hitachi Vantara, with Ninan as one of the executives presiding.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;That challenge had become “a huge proposition” with related opportunities around green IT and sustainability. Ninan had noticed that while Scope 1 and Scope 2 emissions were handled quite well, Scope 3 emissions accounting still needed work.&lt;/p&gt;
 &lt;p&gt;“It didn’t do a really good job of Scope 3. Yet &lt;a href="https://www.computerweekly.com/feature/Interview-CyrusOne-on-the-sustainable-innovation-that-drives-datacentre-business-outcomes"&gt;datacentres are a most impactful industry for global sustainability&lt;/a&gt;,” he says.&lt;/p&gt;
 &lt;p&gt;Sustainability is also important because so many datacentre projects are being cancelled. Ninan says that trend will increase, not least because &lt;a href="https://www.computerweekly.com/feature/Datacentre-developers-tout-benefits-to-local-communities-but-do-they-deliver"&gt;people often don’t want datacentres in their backyard&lt;/a&gt;, whether for environmental reasons or otherwise.&lt;/p&gt;
 &lt;p&gt;“They’re now leery about the effects of AI. They’ve also seen bills go up, and they worry about water resources,” he adds.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Cross-functional teams drive sustainability goals"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cross-functional teams drive sustainability goals&lt;/h2&gt;
 &lt;p&gt;Ninan’s team includes one other person, plus four entirely focused on product sustainability, helped by another &lt;a href="https://www.computerweekly.com/news/366638707/Interview-Sarwar-Khan-on-shaping-BTs-green-future-and-delivering-sustainability-at-scale"&gt;sustainability&lt;/a&gt; director and the sustainability lead analyst at Hitachi Digital, which is a centre of excellence shared across multiple Hitachi divisions.&lt;/p&gt;
 &lt;p&gt;Also, Ninan’s team works bi-weekly with people who have a 20% or so commitment to sustainability in addition to their day jobs in finance, HR, logistics, operations and the like. Formal executive committee governance meetings happen quarterly.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Hitatch Vantara has reported multiple &lt;a href="https://www.hitachivantara.com/content/dam/hvac/pdfs/analyst-content/helping-make-the-world-a-better-place-2024-sustainability-report.pdf"&gt;sustainability awards for its tech&lt;/a&gt;, including around AI, and high ratings from the likes of EnergyStar and EcoVadis. It launched a sustainability service level agreement (SLA) last year.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Hitachi Vantara’s &lt;a href="https://www.computerweekly.com/feature/An-action-plan-for-net-zero-compatible-with-budget-contraints"&gt;net-zero&lt;/a&gt; target is 2040, following the Science-based Targets Initiative (SBTi) – a “more aggressive” target than its parent’s 2050.&lt;/p&gt;
 &lt;p&gt;“And we have our state-of-the-art distribution centres, particularly one in the Netherlands, that have launched a whole bunch of new initiatives around logistics, distribution, biodiversity and so on,” he says.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Ninan points out that customers today are more often “buying outcomes”, rather than being 100% focused on product. And he suggests that if more tech companies don’t wake up, poor sustainability can and will hit profits – if it hasn’t already.&lt;/p&gt;
 &lt;p&gt;IT companies will lose customers and their credibility. In his view, &lt;a href="https://www.computerweekly.com/feature/Pure-AVK-self-powered-Dublin-datacentre-dodges-grid-constraints"&gt;datacentre&lt;/a&gt; operators could “make or break” sustainability goals, and it’s crucial for those in the industry to lead the way.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Which is also an opportunity, not just for marketing narratives or even benchmarking, but to drive innovation, he says.&lt;/p&gt;
 &lt;p&gt;So that’s what Ninan and his cross-functional team does – sponsoring and overseeing strategy and building sustainability together. Not least because it often takes people a long time to appreciate the importance of sustainability.&lt;/p&gt;
 &lt;p&gt;“I make a lot of noise about that,” he says. “I’ve had to become a real champion for sustainability.”&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="Bridging US and European sustainability narratives"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Bridging US and European sustainability narratives&lt;/h2&gt;
 &lt;p&gt;In the US, especially, narratives on sustainability can differ from those in many other regions and markets. In Europe, sustainability is seen as crucial simply because the planet depends on it.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    I’ve had to become a real champion for sustainability
   &lt;/figure&gt;
   &lt;figcaption&gt;
    &lt;strong&gt;Simon Ninan, Hitachi Vantara&lt;/strong&gt;
   &lt;/figcaption&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;However, US arguments typically must be formulated in dollars and cents. In the US, if you can’t make the economics work, if you can’t show how profits will be realised, it’s much more difficult to reach a consensus.&lt;/p&gt;
 &lt;p&gt;Europe sometimes creates burdensome regulations and reporting requirements in an effort to get everyone on board, but that’s seen as a necessary evil.&lt;/p&gt;
 &lt;p&gt;“You can’t have that ‘necessary evil’ conversation in the US. They say, ‘Tell me how it’s going to improve my revenue, and profits, and maybe then I’ll pay attention to it’,” says Ninan.&lt;/p&gt;
 &lt;p&gt;“Then, of course, you have changing political administrations – and you hear they want to deregulate, as a matter of national competitiveness and innovation, with greenness potentially coming in at some future date or time.”&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Making the business case for green technology"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Making the business case for green technology&lt;/h2&gt;
 &lt;p&gt;The challenge – and partly the fun – for Ninan and his team is to keep figuring out how to straddle the different &lt;a href="https://www.techtarget.com/sustainability/feature/How-to-lead-on-sustainability-in-the-rise-of-greenhushing"&gt;narratives&lt;/a&gt;, to explain how sustainability is good for businesses that are governed quarter to quarter by the markets. That includes via outreach, with public relations activities such as podcasts or thought leadership articles also a really interesting part of his job.&lt;/p&gt;
 &lt;p&gt;“That’s where I talk about Hitachi Vantara products a bit, and that datacentres are about 3% of greenhouse gas emissions globally, of power consumed, and how that’s multiplying with the AI and internet of things revolutions,” says Ninan.&lt;/p&gt;
 &lt;p&gt;Then his strategy might include pointing out projections for datacentre growth. If datacentre footprints triple in the next five years, as some estimates suggest, that will create problems for businesses.&lt;/p&gt;
 &lt;p&gt;Power grids can’t handle it. They’re not ready, and resources such as energy and water are lacking. Economies can’t currently sustain that sort of datacentre demand; investment is required to meet the “real value” proposition, which typically boils down to cost savings, he says.&lt;/p&gt;
 &lt;p&gt;“So, we explain that if you deploy our &lt;a href="https://www.techtarget.com/searchstorage/opinion/Hitachi-Vantara-expands-in-hybrid-and-multi-cloud-storage"&gt;storage&lt;/a&gt; and data solutions in datacentres, because of the proprietary technology, we can optimise how data is moved, stored and processed. We can reduce power consumption in datacentres by 30% to 60% compared to the average,” he says.&amp;nbsp;“Forget the cost of buying the bits. Sure, we’ll do a great job for you there, but we’ll save you longer-term costs.”&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more IT sustainability interviews&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/news/366638707/Interview-Sarwar-Khan-on-shaping-BTs-green-future-and-delivering-sustainability-at-scale"&gt;Sarwar Khan on shaping BT’s green future and delivering sustainability at scale&lt;/a&gt;: How the sustainability practice enables BT to move on ‘tough topic’ targets that increase innovation, efficiency and success across its product portfolio.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Interview-CyrusOne-on-the-sustainable-innovation-that-drives-datacentre-business-outcomes"&gt;CyrusOne on the sustainable innovation that drives datacentre business outcomes&lt;/a&gt;: Sustainability initiatives continue to drive competitive advantage in addition to cutting costs, reveals Kyle Myers of colocation giant CyrusOne.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>We talk to Hitachi Vantara’s Simon Ninan about how the company looks to the far horizon when trying to match business needs with those of society</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/HeroImages/IT-sustainability-interviews-hero.jpg</image>
            <link>https://www.computerweekly.com/news/366642586/Interview-Hitachi-Vantara-takes-long-view-on-business-and-sustainability</link>
            <pubDate>Tue, 12 May 2026 09:40:00 GMT</pubDate>
            <title>Interview: Hitachi Vantara takes long view on business and sustainability</title>
        </item>
        <item>
            <body>&lt;p&gt;Service provider Blackbox Hosting has consolidated storage from two full racks down to just 8U of rack space following migration to Everpure FlashArray hardware. The move has allowed the provider to deliver &lt;a href="https://www.computerweekly.com/feature/This-rise-of-the-splinternet-Data-sovereignty-risks-and-responses"&gt;“sovereign” cloud services&lt;/a&gt; with a 10:1 data reduction ratio and an 85% reduction in power utilisation.&lt;/p&gt; 
&lt;p&gt;Blackbox Hosting evolved over 14 years from a single rack to supporting more than 1,500 virtual machines (VMs), and has datacentre capacity at Canary Wharf with a secondary site in Slough.&lt;/p&gt; 
&lt;p&gt;The company operates a fully managed, sovereign (see box) model for major software suppliers including Iris Software Group, which supports payroll and financial management for approximately 60% of UK academies.&lt;/p&gt; 
&lt;p&gt;Blackbox previously relied on HPE 3PAR 8400 &lt;a href="https://www.computerweekly.com/resources/Flash-storage-and-solid-state-drives-SSDs"&gt;all-flash arrays&lt;/a&gt;. However, as the hardware approached end-of-life, the company faced mounting challenges.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;“Support renewal costs were significant, and we had issues with HPE support,” said Matthew Burden, CEO at Blackbox Hosting. “We had a power supply failure in a&amp;nbsp;&lt;a href="https://www.computerweekly.com/feature/Disaster-recovery-As-a-service-vs-on-premise"&gt;DR site&lt;/a&gt;, and despite a four-hour SLA [service-level agreement], it took nearly two weeks to replace. They also began charging for firmware updates that were previously included.”&lt;/p&gt; 
&lt;p&gt;The 3PAR environment was cumbersome, said Burden, and required two full racks of hardware to manage the company’s near-petabyte scale.&lt;/p&gt; 
&lt;p&gt;When it looked for a more performant and dense alternative, Blackbox turned to Pure Storage, which recently rebranded as Everpure.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="High density; ‘one-second’ RPO"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;High density; ‘one-second’ RPO&lt;/h2&gt;
 &lt;p&gt;Blackbox has deployed a range of Pure Storage FlashArray models across its two datacentres to support its active-passive high-availability design.&lt;/p&gt;
 &lt;p&gt;The deployment includes two FlashArray//X50 R3s, two X50 R4s, and two FlashArray//C20 units for file clusters.&lt;/p&gt;
 &lt;p&gt;The hardware supports predominantly Hyper-V and VMware VMs, running 90% Windows-based workloads, primarily SQL Server, plus Linux servers.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more about data storage&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Storage-explained-Consumption-models-of-storage-procurement"&gt;Storage explained: Consumption models of storage procurement&lt;/a&gt;. We look at consumption models of storage purchasing and how cloud operating models have made them mainstream and supplanted the traditional three-year lift-and-shift datacentre refresh.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Auditing-classifying-and-building-a-data-sovereignty-strategy"&gt;Auditing, classifying and building a data sovereignty strategy&lt;/a&gt;. We look at data sovereignty – what it is and how to build a data sovereignty strategy around data auditing.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
 &lt;p&gt;The transition from 3PAR to Pure has seen a dramatic consolidation of physical space. “We went from two entire racks filled with disks to two 4U boxes,” said Burden. “Our total provisioned storage is 998TB and we get a total reduction of 10:1. 3PAR had deduplication, but not compression on SSDs.”&lt;/p&gt;
 &lt;p&gt;Beyond space savings, the disaster recovery (DR) capabilities have seen a massive upgrade. Previously, the company’s &lt;a href="https://www.computerweekly.com/feature/Define-RPO-and-RTO-tiers-for-storage-and-data-protection-strategy"&gt;recovery point objective&lt;/a&gt; (RPO) was limited to 15 minutes. “With Pure Storage, it is one second,” said Durden. “We replicate all 1,500 VMs to our backup datacentre. For a customer with 1,000 VMs, we can spin those up for quarterly testing and they are only one second out from live data.”&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Performance and sustainability"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Performance and sustainability&lt;/h2&gt;
 &lt;p&gt;The shift to non-volatile memory express-based flash has also provided a significant boost to the provider’s green credentials. Sustainability reports generated via Pure’s Evergreen dashboard show an 85% saving in power utilisation compared with the legacy HPE environment.&lt;/p&gt;
 &lt;p&gt;For the end users – which include major corporate energy, finance and transport organisations – the benefit is felt in application speed. “We’ve had clients with huge databases that were always slow with previous providers,” said Justin Field, commercial director at Blackbox. “They can pull data significantly faster now, which is a big play for us when competing against hyperscalers.”&lt;/p&gt;
 &lt;p&gt;Burden also highlighted the “zero-touch” operational simplicity of the new arrays. “The older arrays were very cumbersome; you had to know exactly what you were doing,” he said. “The Pure web interface is very simple, which makes the operational side much easier. Plus, with Evergreen, we don’t have to pull arrays out for upgrades. We can just put in new controllers as scale increases.”&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Sovereign cloud: A selling point&lt;/h3&gt; 
   &lt;p&gt;While hyperscalers like Amazon Web Services and Azure dominate the global market, Blackbox Hosting is attempting to carve out a niche as a UK-based sovereign cloud provider. For Blackbox, data sovereignty is defined by 100% UK ownership, UK-based staff, and physical data residency within UK borders (Telehouse South and Virtus Slough).&lt;/p&gt; 
   &lt;p&gt;“People are scratching their heads over the US Cloud Act and how it affects them and their customers,” said commercial director Justin Field. “It’s leading to a lot more kind of engagement with people that probably always just opted for that public cloud.&lt;/p&gt; 
   &lt;p&gt;“We’re not a worldwide provider, but we offer sovereignty to businesses within the UK,” he added.&lt;/p&gt; 
   &lt;p&gt;But in theory, if any data in transit is handled by any of the US companies, then it’s not sovereign. Does this affect Blackbox? For example, where Everpure has access to storage performance data via its Evergreen-as-a-service dashboard or its Pure1 telemetry?&amp;nbsp;&lt;/p&gt; 
   &lt;p&gt;“Our storage and all of our hardware is 100% owned,” said Field. “All of our infrastructure is owned and managed by us. We don’t rely on outside support for our services. It’s all 100% UK staff. Everpure doesn’t process any data.”&lt;/p&gt; 
   &lt;p&gt;This “sovereign” status is increasingly seen as vital for Blackbox’s clients in the UK legal, financial and educational sectors.&lt;/p&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>UK-based IaaS ‘sovereign’ provider, with multiple public sector-facing clients, replaced end-of-life 3PAR arrays with FlashArray storage that saw it reduce power consumption by 85%</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/article/light-bulb-energy-powercut-idea-adobe.jpg</image>
            <link>https://www.computerweekly.com/news/366641940/Blackbox-replaces-two-racks-of-HPE-storage-with-8U-of-Everpure</link>
            <pubDate>Wed, 22 Apr 2026 04:00:00 GMT</pubDate>
            <title>Blackbox replaces two racks of HPE storage with 8U of Everpure</title>
        </item>
        <item>
            <body>&lt;p&gt;Cloud backup has made it possible for organizations of any size to improve their data protection. At the same time, traditional local backup still has its place in the storage world. The decision to use one or the other -- or, in some instances, both -- comes down to an organization's specific needs.&lt;/p&gt; 
&lt;p&gt;In the cloud backup vs. local backup debate, both options have their advantages and disadvantages.&lt;/p&gt; 
&lt;p&gt;Cloud-based workloads have seen a huge surge in popularity. Not only are established vendors adding more cloud capabilities, but new cloud storage and backup vendors are appearing. The simplicity and scale of cloud computing can provide a backup solution for organizations that need protection.&lt;/p&gt; 
&lt;p&gt;However, local backup providers are not sitting still. Disk speeds continue to get faster, and tape storage capacities are growing. In addition, if an organization has used local backup for a long time, it can be a burden to move to the cloud. IT and executives should ask several questions about such a move, including whether the move makes sense operationally and financially, and whether they should consider a partial migration and keep some local backup.&lt;/p&gt; 
&lt;p&gt;Many organizations, especially enterprises, have a&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/tip/Hybrid-backups-reap-benefits-of-cloud-and-local-backup"&gt;mix of cloud and local backup&lt;/a&gt;. Both have pros and cons. For example, local file backup can be quicker for recovery purposes, but the cloud provides that off-site location in the event of a primary data center disaster. Local backup typically requires more in-house management and staff time.&lt;/p&gt; 
&lt;p&gt;To decide which method is best for your organization, weigh the pros and cons of cloud and local backups and how they match with your existing infrastructure.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Cloud backup basics"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Cloud backup basics&lt;/h2&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchdatabackup/definition/cloud-backup"&gt;Cloud backup&lt;/a&gt;&amp;nbsp;involves copying data over a network to an off-site storage server, typically hosted by a service provider. The cloud backup vendor charges the customer based on elements such as capacity, bandwidth, number of users and data egress.&lt;/p&gt;
 &lt;p&gt;Cloud data backup options include&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/answer/What-are-some-public-cloud-backup-options-for-better-data-protection"&gt;backing up directly to a public cloud&lt;/a&gt;&amp;nbsp;such as AWS, Google or Microsoft Azure, or backing up to a service provider's private cloud.&amp;nbsp;The newer&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/definition/cloud-to-cloud-backup"&gt;cloud-to-cloud backup&lt;/a&gt;&amp;nbsp;involves backing up data that originates in the cloud -- in SaaS applications, such as Salesforce and Microsoft 365 -- to another cloud.&lt;/p&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/Lc-hY-uHgUU?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://www.computerweekly.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Understanding local backup"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Understanding local backup&lt;/h2&gt;
 &lt;p&gt;Local backups are a longstanding form of&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/tip/The-pros-and-cons-of-on-site-backup"&gt;backing up data at an organization's primary site&lt;/a&gt;. Organizations typically use disk-based hardware for this backup. Backup software manages the copying of data to the hardware. Sometimes that software is integrated with the hardware, or it runs separately. Data reduction features, such as deduplication, decrease the amount of data backed up on the disk.&lt;/p&gt;
 &lt;p&gt;Tape was the more common traditional backup medium before disk took over in the early 2000s. In the&amp;nbsp;tape backup process, an organization moves data to a tape cartridge that resides in a library. Organizations &lt;a href="https://www.techtarget.com/searchdatabackup/tip/Storage-media-showdown-The-benefits-of-tape-vs-disk-backup"&gt;still use tape&lt;/a&gt; today, typically for immutable offline protection against ransomware and other cyber attacks, or for long-term archiving. LTO-10, the latest version of the Linear Tape-Open format, offers 75 TB of compressed capacity per cartridge.&lt;/p&gt;
 &lt;p&gt;A new twist to the cloud backup vs. local backup story involves backing up SaaS data to a local device. In this case, data originating in the cloud -- such as Microsoft 365 emails -- is backed up to local storage.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://www.computerweekly.com/rms/onlineimages/cloud_backup-cloud_vs_local_comparison.png"&gt;
  &lt;img data-src="https://www.computerweekly.com/rms/onlineimages/cloud_backup-cloud_vs_local_comparison_mobile.png" class="lazy" data-srcset="https://www.computerweekly.com/rms/onlineimages/cloud_backup-cloud_vs_local_comparison_mobile.png 960w,https://www.computerweekly.com/rms/onlineimages/cloud_backup-cloud_vs_local_comparison.png 1280w" alt="Chart of cloud backup and local backup considerations" height="532" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;It's important to consider the many elements of cloud backup vs. local backup for your organization's data protection.
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Advantages and disadvantages of cloud backup"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Advantages and disadvantages of cloud backup&lt;/h2&gt;
 &lt;p&gt;Overall, cloud backup provides an additional layer of protection with minimal burden on staff. Although cloud backup is a popular mode of data protection with many advantages, pay attention to the disadvantages to make sure your organization is covered. Some areas of advantage can be considered disadvantageous in different situations.&lt;/p&gt;
 &lt;p&gt;The&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/tip/The-pros-and-cons-of-cloud-backup-technologies"&gt;advantages of cloud backup&lt;/a&gt;&amp;nbsp;include the following:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Low entry costs.&lt;/b&gt;&amp;nbsp;Backing up to the cloud, especially in the beginning, is a cheap form of data protection. Although local backup storage devices could run in the thousands of dollars, the cost in money and time to set up a cloud backup account is minimal. Cloud backup is especially attractive to an organization that doesn't have the funds or resources for a separate disaster recovery site.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Wide-ranging accessibility.&lt;/b&gt;&amp;nbsp;A cloud backup is accessible from any internet-connected device, which is especially handy when an organization's primary site is down. Accessing a small amount of data is a quick process.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;An array of security features.&lt;/b&gt;&amp;nbsp;Cloud backup products offer a range of features to keep data safe.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Easy scalability.&lt;/b&gt;&amp;nbsp;&lt;a href="https://www.techtarget.com/searchstorage/tip/Cloud-storage-advantages-Solving-five-common-IT-problems"&gt;Cloud storage is essentially unlimited&lt;/a&gt;. Organizations can add cloud backup capacity with just a couple of clicks. In contrast, local backup requires acquiring and setting up another physical piece of hardware.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Easy management.&lt;/b&gt;&amp;nbsp;Cloud backup management generally takes less time and effort than local data backup, depending on the organization's needs and requests. Organizations just need to make sure they are OK with leaving management of the storage hardware in the hands of a service provider.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Simple disaster recovery.&lt;/b&gt;&amp;nbsp;If there's a failure or data loss event at a primary site, organizations can easily fail over to cloud-based disaster recovery as a service (&lt;a href="https://www.techtarget.com/searchdisasterrecovery/definition/disaster-recovery-as-a-service-DRaaS"&gt;DRaaS&lt;/a&gt;). This option provides disaster recovery to businesses that couldn't previously afford it.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The following are some&amp;nbsp;potential downsides&amp;nbsp;of cloud backup:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Cost accumulations.&lt;/b&gt;&amp;nbsp;Although a small amount of data is cheap, a lot of data stored over a long period of time steadily increases costs. A company must pay for its data backup storage every month. It's critical to keep a close eye on cloud backup expenses.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Latency.&lt;/b&gt;&amp;nbsp;The cloud can cause latency, especially if many users are trying to access the same data or cloud, or if an organization is trying to get a large volume of data out of the cloud.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Security issues.&lt;/b&gt;&amp;nbsp;Some organizations are still worried about the&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/answer/Whats-the-best-method-for-protecting-data-in-the-cloud"&gt;safety of keeping data in the cloud&lt;/a&gt;. Confirm that a cloud backup product has the necessary security elements, such as end-to-end encryption. In addition, just because a backup is in the cloud, that doesn't mean it's safe from cyber attacks, so be wary of a false sense of security.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Slow, costly restores.&lt;/b&gt;&amp;nbsp;Although DRaaS is fast and efficient, actually restoring data from the cloud can be a time-consuming and costly process, especially when it involves large volumes. Data egress fees can quickly make restorations expensive.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Advantages and disadvantages of local backup"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Advantages and disadvantages of local backup&lt;/h2&gt;
 &lt;p&gt;Organizations must consider their data protection needs when comparing cloud and local backup options. While the cloud is a popular option and offers benefits, local backups might be a better choice for some organizations. The benefits of local backup include the following:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;On-site accessibility.&lt;/b&gt;&amp;nbsp;It doesn't get much more accessible than having the backup data at your primary site. Disk-based backups in particular are typically continuous throughout the day, so a user can go back to a specific point in time.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Speed.&lt;/b&gt;&amp;nbsp;On-site disk is fast for backup and recovery operations.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Security control.&lt;/b&gt;&amp;nbsp;An organization has more control over local backup than data that's in the hands of a cloud provider.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The following are some drawbacks of local backup:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;High initial cost.&lt;/b&gt;&amp;nbsp;In comparing cloud backup vs. local backup, the expense of on-site hardware is generally far more than preparing for a cloud-based platform. Disks are expensive, so adding them can make a significant&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/tip/How-to-craft-a-strong-and-cost-effective-data-backup-budget"&gt;dent in the budget&lt;/a&gt;. In addition, the lifespan and durability of disk&amp;nbsp;&lt;a target="_blank" href="https://www.enterprisestorageforum.com/hardware/life-expectancy-of-a-drive/" rel="noopener"&gt;requires replacement from time to time&lt;/a&gt;&amp;nbsp;as well as routine maintenance.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Scalability difficulties.&lt;/b&gt;&amp;nbsp;With local backup, the process of adding space is more labor-intensive because the organization needs to acquire the additional storage and install it. Physically storing more data backups is more of a burden than just adding storage space in the cloud.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;High maintenance.&lt;/b&gt;&amp;nbsp;Local backup requires dedicated staff to maintain and manage it. When an organization uses cloud computing, IT staff is freed up to focus on other important tasks besides backup maintenance.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Cybersecurity issues.&lt;/b&gt;&amp;nbsp;If a cyber attack hits the primary data center, an organization should&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/feature/How-does-off-site-backup-stack-up-against-cloud-backup"&gt;use an off-site backup&lt;/a&gt;&amp;nbsp;-- whether it be on tape or in the cloud -- to make sure the restore is clean.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Disaster recovery issues.&lt;/b&gt;&amp;nbsp;If there's a disaster at the primary site, a local backup will not be helpful. However, if your organization has moved tapes off-site, those backups are valuable for disaster recovery.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Bottom line: Which should you choose?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Bottom line: Which should you choose?&lt;/h2&gt;
 &lt;p&gt;When your organization analyzes cloud backup vs. local backup, consider all these positives and negatives and address the specific needs of the business.&lt;/p&gt;
 &lt;p&gt;Cloud backup clearly continues to gain traction in the market, and there are many options for businesses of any size. There are numerous reported cases of businesses ditching their legacy data backup platforms for a cloud-based product. However, the opposite is also true: Some organizations are choosing to &lt;a href="https://www.techtarget.com/searchdatabackup/tip/Is-cloud-backup-repatriation-right-for-your-organization"&gt;repatriate cloud backups&lt;/a&gt; back on-site.&lt;/p&gt;
 &lt;p&gt;Though not to the extent of&amp;nbsp;&lt;a href="https://www.techtarget.com/searchdatabackup/feature/Top-20-cloud-backup-services-for-2019"&gt;cloud backup products&lt;/a&gt;, local backup options are evolving as well. If you need a certain size of hardware for your data center, you can probably find it.&lt;/p&gt;
 &lt;p&gt;In many cases, and if the budget and resources are adequate, a hybrid backup approach is appropriate. This combination of cloud and local backup provides strong data protection. &amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Make sure you carefully assess your organization's backup and recovery needs, research potential products and make a careful, informed decision about your backup platform. This includes consideration of data retention and recovery needs. The survival of your business could depend on it.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Paul Crocetti is editorial director of Informa TechTarget's Infrastructure sites, which include SearchStorage, SearchDataCenter and SearchITOperations. Since starting at then-TechTarget in 2015, he has also served as editor on the SearchStorage, SearchDataBackup and SearchDisasterRecovery sites.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Stephen J. Bigelow, senior technology editor at TechTarget, has more than 30 years of technical writing experience in the PC and technology industry.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Cloud vs. local backup is an important discussion for IT leaders today. The cloud backup market is soaring, but traditional local backups also have much to offer.</description>
            <image>https://cdn.ttgtmedia.com/visuals/searchVMware/cloud/vmware_article_004.jpg</image>
            <link>https://www.techtarget.com/data-technologies/feature/Cloud-vs-local-backup-Which-is-right-for-your-organization</link>
            <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
            <title>Cloud vs. local backup: Which is right for your organization?</title>
        </item>
        <item>
            <body>&lt;p&gt;Executive leaders should treat compliance as an integral part of organizational strategic planning rather than the cost of doing business.&lt;/p&gt; 
&lt;p&gt;Organizations can face major penalties if they don't comply with laws and regulations that protect customer data, like GDPR and HIPAA. Additionally, customers can lose confidence in an organization if their personal information is not protected properly.&lt;/p&gt; 
&lt;p&gt;A significant number of &lt;a href="https://www.techtarget.com/searchcustomerexperience/tip/How-to-improve-the-contact-center-experience-for-customers"&gt;customer interactions occur in the contact center&lt;/a&gt;. Therefore, contact center leaders need to comply&amp;nbsp;with regulatory requirements and smart business practices to protect customers' rights. A combination of following legislative rules and thoughtful internal practices -- such as call monitoring -- can protect sensitive customer data while improving the customer experience.&lt;/p&gt; 
&lt;p&gt;Establishing and following a contact center compliance checklist provides a strong foundation of good practices that lead to successful compliance.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is contact center compliance and why is it important?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is contact center compliance and why is it important?&lt;/h2&gt;
 &lt;p&gt;Contact center compliance is critical. A failure, such as a data breach, can have significant negative effects on a customer's life and devastate an organization's brand image and reputation. Customers don't want to buy services from organizations that can't&amp;nbsp;protect their personal information from bad actors. And, if there's a security incident, organizations don't want to pay fines and penalties to regulatory agencies.&lt;/p&gt;
 &lt;p&gt;Compliance requires participation from every individual in an organization. Contact center managers shouldn't assume that documented processes always work or that agents always follow proper procedures. &lt;a href="https://www.techtarget.com/searchcustomerexperience/tip/Best-practices-for-call-center-monitoring"&gt;Ongoing monitoring and reporting must be in place&lt;/a&gt; to ensure things are working properly. Additionally, all employees must keep their eyes and ears open. Controls must be in place, and if something does not seem right, they must raise the issue with the appropriate individual.&lt;/p&gt;
 &lt;p&gt;Before the COVID-19 pandemic, most contact centers were on-premises, which, in many ways, made compliance easier to implement and monitor. For example, employees had to swipe their key cards to enter the contact center. Compliance became more of a challenge when contact centers began to operate remotely, so checklists can help contact center managers follow proper guidelines.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Contact center compliance checklist"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Contact center compliance checklist&lt;/h2&gt;
 &lt;p&gt;Organizations can't achieve compliance with a single tool or process. Compliance requires a multifaceted approach that integrates technology, processes and procedures.&lt;/p&gt;
 &lt;p&gt;The following contact center compliance checklist can serve as a starting point for contact center managers as they seek to comply with internal and external requirements.&lt;/p&gt;
 &lt;h3&gt;1. Secure the network&lt;/h3&gt;
 &lt;p&gt;Organizations should use network&amp;nbsp;&lt;a href="https://www.techtarget.com/searchsecurity/definition/access-control"&gt;access control&lt;/a&gt;&amp;nbsp;to limit who can physically and logically access system hardware and software. Physical security protects the physical components of a network, such as devices, modems or routers, from physical harm. Logical security uses passwords and system permissions to protect a network's software and data from unauthorized individuals.&lt;/p&gt;
 &lt;h3&gt;2. Lock down workstations&lt;/h3&gt;
 &lt;p&gt;For remote workers, organizations must ensure workstation equipment adheres to pre-defined specifications or that the organization provides the proper tools.&lt;/p&gt;
 &lt;p&gt;Physical workstation audits enable an organization to inspect both on-site and remote employees' work environments and ensure they support basic controls and meet compliance requirements. As physical visits to employees' remote workstations aren't always feasible, supervisors can use video conferencing to perform high-level audits. Beware: A video conferencing audit is limited in its scope and timing.&lt;/p&gt;
 &lt;h3&gt;3. Authenticate customers&lt;/h3&gt;
 &lt;p&gt;Customer authentication is a process where individuals prove they are who they claim to be. In some cases, single-factor authentication, where customers provide a single piece of information to confirm their identity, can suffice. However, many organizations have adopted&amp;nbsp;&lt;a href="https://www.techtarget.com/searchsecurity/definition/multifactor-authentication-MFA"&gt;multifactor authentication&lt;/a&gt;, which asks customers to provide distinct pieces of information -- such as a password and a code sent to a mobile device -- to confirm their identity. Additionally, some companies are using voice and&amp;nbsp;&lt;a href="https://www.techtarget.com/searchenterpriseai/definition/facial-recognition"&gt;facial recognition&lt;/a&gt;&amp;nbsp;technologies to authenticate customers.&lt;/p&gt;
 &lt;h3&gt;4. Record customer conversations&lt;/h3&gt;
 &lt;p&gt;Call recording lets organizations&amp;nbsp;review telephone conversations&amp;nbsp;between customers and agents. Managers can review recordings through a QA program and AI tools to determine if agents fulfilled external requirements, such as appropriate disclosures and authentication processes. Managers can also review recordings to determine if an agent fulfilled internal requirements, such as providing a customer with accurate information or following the correct internal procedures.&lt;/p&gt;
 &lt;h3&gt;5. Provide mandatory disclosures&lt;/h3&gt;
 &lt;p&gt;Contact center agents must provide mandatory disclosures, which are legal statements to explain specific processes, rules and options to callers. For example, if a contact center in the U.S. wants to record a customer call, it must be disclosed to the caller, and consent must be provided, which is passive consent in most cases. Regulations require mandatory disclosures when agents record customer calls, perform collection functions or make financial transactions.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://www.computerweekly.com/rms/onlineimages/call_center_compliance_checklist-f.png"&gt;
  &lt;img data-src="https://www.computerweekly.com/rms/onlineimages/call_center_compliance_checklist-f_mobile.png" class="lazy" data-srcset="https://www.computerweekly.com/rms/onlineimages/call_center_compliance_checklist-f_mobile.png 960w,https://www.computerweekly.com/rms/onlineimages/call_center_compliance_checklist-f.png 1280w" alt="Contact center compliance checklist image" height="266" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;This compliance checklist can help contact centers adhere to important standards and regulations.
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
 &lt;h3&gt;6. Adhere to local privacy legislation&lt;/h3&gt;
 &lt;p&gt;Organizations must adhere to various global and local legislation on customer privacy, depending on the geographic reach of the business. Due to legislation, organizations can't manage all customer information in the same way.&amp;nbsp;&lt;a href="https://www.techtarget.com/searchsecurity/tip/State-of-data-privacy-laws"&gt;Data privacy laws vary by country and region&lt;/a&gt;, so organizations must know where each customer resides before they transmit, process and store customer information.&lt;/p&gt;
 &lt;p&gt;Examples of location-based privacy legislation include the following:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;General Data Protection Regulation.&lt;/b&gt;&amp;nbsp;GDPR provides guidance on how organizations can collect and process personally identifiable information (PII) for individuals who live in the European Union.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;California Consumer Privacy Act.&amp;nbsp;&lt;/b&gt;CCPA provides guidance on how organizations can collect and process personal and household information for individuals who live in California.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Because privacy legislation is always evolving, organizations must be proactive to ensure they're up to date on laws affecting their contact center operations.&lt;/p&gt;
 &lt;h3&gt;7. Adhere to the Telephone Consumer Protection Act&lt;/h3&gt;
 &lt;p&gt;Organizations in the U.S. must adhere to the Telephone Consumer Protection Act, which sets rules for how an organization can use outbound calls for solicitation.&amp;nbsp;&lt;a target="_blank" href="https://www.fcc.gov/sites/default/files/tcpa-rules.pdf" rel="noopener"&gt;TCPA&lt;/a&gt;&amp;nbsp;regulations state that telemarketing contact centers cannot use predictive dialers to contact a wireless phone without prior consent from the customer. It also ensures telemarketers adhere to the National Do Not Call Registry and special regulations, which may include restricted calling hours in a particular geographic location after a natural disaster event.&lt;/p&gt;
 &lt;h3&gt;8. Manage sensitive information&lt;/h3&gt;
 &lt;p&gt;To comply with standards, such as the&amp;nbsp;&lt;a href="https://www.techtarget.com/searchsecurity/definition/PCI-DSS-Payment-Card-Industry-Data-Security-Standard"&gt;Payment Card Industry Data Security Standard&lt;/a&gt;&amp;nbsp;and HIPAA, organizations must&amp;nbsp;protect sensitive customer data&amp;nbsp;at rest and in motion. Sensitive information can include PII, credit card numbers or protected health information. To protect sensitive information, organizations should encrypt all data, minimize the amount of stored data and use automation, such as&amp;nbsp;&lt;a href="https://www.techtarget.com/searchcustomerexperience/definition/Interactive-Voice-Response-IVR"&gt;interactive voice response&lt;/a&gt;, to perform sensitive transactions.&lt;/p&gt;
 &lt;h3&gt;9. Provide ongoing training&lt;/h3&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchcustomerexperience/tip/Best-practices-for-call-center-agent-training-programs"&gt;Organizations should provide annual training&lt;/a&gt;&amp;nbsp;on proper compliance procedures and guidelines to all employees. All employees should be up to date on specific compliance rules and understand how they can protect their organization and its customers.&lt;/p&gt;
 &lt;h3&gt;10. Promote self-service&lt;/h3&gt;
 &lt;p&gt;Organizations should maximize &lt;a href="https://www.techtarget.com/whatis/definition/customer-self-service-CSS"&gt;customer self-service&lt;/a&gt; procedures through secured portals to limit the sharing of information with other individuals and reduce security risks.&lt;/p&gt;
 &lt;h3&gt;11. Test, monitor and act on a continuous basis&lt;/h3&gt;
 &lt;p&gt;Organizations can and should implement all the items on this checklist. However, business leaders shouldn't assume everything is working properly or that bad actors have not found ways to bypass established controls. Organizations should continually test and monitor the various compliance controls, whether through automated processes, such as reporting unauthorized attempts to access customer data, or human processes, like placing test calls.&lt;/p&gt;
 &lt;p&gt;When something doesn't seem right, organizations should analyze the issue and take action to ensure the controls in place are performing as expected.&lt;/p&gt;
 &lt;p&gt;A contact center compliance checklist can help organizations&amp;nbsp;&lt;a href="https://www.techtarget.com/searchcio/feature/9-common-risk-management-failures-and-how-to-avoid-them"&gt;avoid compliance failures&lt;/a&gt;. Contact center managers can use this checklist to evaluate their organization's current compliance protocols and ensure their teams follow proper guidelines.&lt;/p&gt;
&lt;/section&gt;                                
&lt;section class="section main-article-chapter" data-menu-title="Common contact center compliance issues and malpractices"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Common contact center compliance issues and malpractices&lt;/h2&gt;
 &lt;p&gt;If strong compliance controls and practices are not in place, the following negative events can occur:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;Calling customers who requested not to be called, which violates&amp;nbsp;&lt;a href="https://www.techtarget.com/searchcustomerexperience/definition/outbound-call"&gt;outbound calling&lt;/a&gt;&amp;nbsp;restrictions.&lt;/li&gt; 
  &lt;li&gt;Allowing PII to be stolen due to incorrectly accessing customer information.&lt;/li&gt; 
  &lt;li&gt;Improperly recording customer conversations by not adhering to call recording and consent rules.&lt;/li&gt; 
  &lt;li&gt;Providing incomplete information to customers by not adhering to scripting requirements.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;If these events occur, an organization can be liable for financial penalties, along with other legal consequences. Just as important is the potential for negative customer perception, which can lead to degraded customer loyalty and customer defections.&lt;/p&gt;
 &lt;p&gt;Leadership in all areas of an organization must keep in mind that a compliance checklist only provides a template of best practices. It must be more than a written document. The organization must translate the document into reality and embed it into the corporate culture by focusing on the following actions:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Invest in technology to support key items on the checklist.&lt;/li&gt; 
  &lt;li&gt;Promote accountability.&lt;/li&gt; 
  &lt;li&gt;Reward adherence to policies and address any gaps that arise.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;A contact center compliance checklist might not stop all unauthorized activities, but it's a solid start to implementing a strategy that adheres to legal, organizational and customer requirements.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Scott Sachs is president and founder of SJS Solutions, a consultancy that specializes in contact center strategy assessments and technology selection.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>A contact center compliance checklist can serve as a starting point for contact center managers as they seek to comply with internal and external regulations.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/check_g1268128622.jpg</image>
            <link>https://www.techtarget.com/enterprise-software/tip/Contact-center-compliance-checklist-for-modern-workforces</link>
            <pubDate>Thu, 02 Apr 2026 09:00:00 GMT</pubDate>
            <title>Contact center compliance checklist for modern workforces</title>
        </item>
        <item>
            <body>&lt;p&gt;After Google moved up its &lt;a href="https://www.computerweekly.com/news/366640650/Google-targets-2029-for-post-quantum-cyber-readiness" target="_blank" rel="noopener"&gt;quantum readiness timeline&lt;/a&gt; and revealed it was working on building &lt;a href="https://www.techtarget.com/searchsecurity/video/An-explanation-of-post-quantum-cryptography" target="_blank" rel="noopener"&gt;post-quantum cryptography&lt;/a&gt; (PQC) features into the next version of its Android mobile operating system, cyber experts have welcomed indications that the pace of travel towards effective, security-preserving PQC is speeding up, but also highlighted that the data security risks posed by quantum computers must be addressed today, not whenever the so-called Q-Day occurs.&lt;/p&gt; 
&lt;p&gt;Google’s target of migrating to PQC in 2029, three years from now, blasts past the migration schedules of others, including the US Commercial National Security Algorithms (CNSA) 2.0 &lt;a href="https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF" target="_blank" rel="noopener"&gt;migration schedule&lt;/a&gt;. &lt;a href="https://www.pingidentity.com/en.html" target="_blank" rel="noopener"&gt;Ping Identity&lt;/a&gt; head of privileged access management&amp;nbsp;engineering Suman Sharma said: “Google accelerating its timeline to 2029 underscores a growing realisation across the industry that the window to prepare for a post-quantum world is smaller than many anticipated.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;“We’re already in the midst of the largest overhaul of the internet’s encryption backbone in decades, with hybrid quantum-resistant standards rolling out across browsers and core infrastructure,” he said.&lt;/p&gt; 
&lt;p&gt;“High-security sectors are moving quickly toward fully quantum-safe deployments, yet much of the broader ecosystem is still operating in a transitional, hybrid state,” said Sharma. “This latest move reinforces that leading technology providers no longer see post-quantum security as a distant concern. It’s now an immediate priority, and the pace of adoption will only continue to accelerate.”&lt;/p&gt; 
&lt;p&gt;According to Mark Pecen, chair of the Technical Committee on Quantum Technologies at the &lt;a href="https://www.etsi.org/"&gt;European Telecommunications Standards Institute&lt;/a&gt; (ETSI), Google’s accelerated deadline reflects a shift from trying to predict Q-Day to preventative management of present-day risks.&lt;/p&gt; 
&lt;p&gt;“The real concern isn’t when quantum computers arrive, it’s that adversaries are already collecting encrypted data today to decrypt later,” said Pecen. “The existing public key cryptographic systems that protect our internet and wireless transactions, Rivest-Shamir-Adelman (RSA) and Elliptic Curve Cryptography (ECC) are aging cryptosystems, developed in the 1970s and 1980s respectively.&lt;/p&gt; 
&lt;p&gt;“These algorithms become weaker for every year that technology advances, so post-quantum cryptography is also being viewed as the next generation of data security.”&lt;/p&gt; 
&lt;div class="extra-info"&gt;
 &lt;div class="extra-info-inner"&gt;
  &lt;h3 class="splash-heading"&gt;Read more about quantum computing&lt;/h3&gt; 
  &lt;ul style="list-style-type: square;" class="default-list"&gt; 
   &lt;li&gt;We speak to Lucy Robson, a quantum algorithm scientist at Universal Quantum, about her work in helping to develop&amp;nbsp;&lt;a rel="noopener" target="_blank" href="https://www.computerweekly.com/podcast/Understanding-quantum-A-Computer-Weekly-Downtime-Upload-podcast"&gt;simulations for drug discovery&lt;/a&gt;.&lt;/li&gt; 
   &lt;li&gt;Japan and Singapore will work together to bridge the gap between quantum research and real-world commercialisation, marking Singapore’s first government-to-government pact&amp;nbsp;&lt;a rel="noopener" target="_blank" href="https://www.computerweekly.com/news/366637028/Singapore-and-Japan-team-up-on-quantum-computing"&gt;dedicated to the technology&lt;/a&gt;.&lt;/li&gt; 
   &lt;li&gt;Claims that quantum computing will destroy Bitcoin may be exaggerated,&amp;nbsp;&lt;a rel="noopener" target="_blank" href="https://www.computerweekly.com/opinion/Will-Quantum-Computing-Kill-Bitcoin"&gt;but Bitcoin will need to adapt&lt;/a&gt;.&lt;/li&gt; 
  &lt;/ul&gt;
 &lt;/div&gt;
&lt;/div&gt; 
&lt;p&gt;Additionally, newer and faster quantum decryption algorithms are already being developed, such as&amp;nbsp;Jesse-Victor-Gharabaghi (JVG) – &lt;a href="https://www.securityweek.com/quantum-decryption-of-rsa-is-much-closer-than-expected/" target="_blank" rel="noopener"&gt;which caused a stir in March 2026&lt;/a&gt; – as it appears to need vastly less quantum computational power (qubits) to break legacy algorithms.&lt;/p&gt; 
&lt;p&gt;Its creators say that given the right hardware, when Q-Day comes, JVG could break RSA in 11 hours.&lt;/p&gt; 
&lt;p&gt;“By moving earlier than government timelines, Google is effectively forcing the industry to treat post-quantum migration as an immediate operational priority rather than a future compliance exercise,” said Pecen.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Harvest now, decrypt later"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Harvest now, decrypt later&lt;/h2&gt;
 &lt;p&gt;At present, &lt;a href="https://globalriskinstitute.org/publication/quantum-threat-timeline-report-2025b/" target="_blank" rel="noopener"&gt;much of the concern&lt;/a&gt; stems from the demonstrable growth in so-called &lt;a href="https://www.techtarget.com/searchsecurity/feature/Cybersecurity-trends-to-watch" target="_blank" rel="noopener"&gt;harvest now, decrypt later&lt;/a&gt; (HNDL) cyber attacks in which threat actors exfiltrate encrypted data now and keep it in readiness for the moment present-day algorithms fail, and Simon Pamplin, chief technology officer at &lt;a href="https://certes.ai/" target="_blank" rel="noopener"&gt;Certes&lt;/a&gt; – a PQC specialist – said that for many organisations, the most dangerous moment in time is not the day quantum computers arrive, but rather right now.&lt;/p&gt;
 &lt;p&gt;“Adversaries are already running HNDL campaigns: exfiltrating encrypted data today with the intention of unlocking it once a cryptographically relevant quantum computer [CRQC] exists,” he said.&lt;/p&gt;
 &lt;p&gt;“If your organisation is still relying on RSA, TLS or standard PKI to protect sensitive data in transit, that data is already at risk, regardless of whether Q-Day lands in 2029 or 2035,” added Certes.&lt;/p&gt;
 &lt;p&gt;“With data flowing across legacy systems, multi-cloud environments, AI and the edge, the potential risk organisations face today is very real, and extremely serious if left unchecked.”&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Next steps"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Next steps&lt;/h2&gt;
 &lt;p&gt;Matt Campagna, who chairs ETSI’s Quantum-Safe Cryptography working group, said Google’s prioritisation of quantum-resistant digital signatures demonstrated important industry leadership in the field, and hailed significant progress in a field for which ETSI has been advocating for 13 years.&lt;/p&gt;
 &lt;p&gt;“Organisations operating information technology systems should take note,” he said. “Understanding local PQC migration timelines, as set by customers and regulators, is now essential. Businesses must develop their own PQC migration strategies and actively engage with vendors and suppliers to ensure alignment.”&lt;/p&gt;
 &lt;p&gt;Certes’ Pamplin echoed this sentiment. “Post-quantum migration is a multi-year project for most organisations, and with Gartner predicting a CRQC could arrive by 2029, the gap between where most businesses are and where they need to be is closing fast – and action should be taken today,” he said.&lt;/p&gt;
 &lt;p&gt;Some of the looming challenges that business tech leaders will soon need to face include legacy systems that may prove impossible to natively upgrade to PQC, multi-cloud environments causing issues due to inconsistent security models and data privacy policies, and gaps around the user and network edge.&lt;/p&gt;
 &lt;p&gt;Pamplin said: “Firms need to look at end-to-end PQC solutions that are able to protect data across any app, any infrastructure, anywhere. Specifically, solutions that enforce sovereign, crypto-agile PQC protection, where only the data owner controls the key, from server to edge, and ones where protection persists with the data, not infrastructure.&lt;/p&gt;
 &lt;p&gt;“Quantum readiness isn’t about predicting a date,” he said. “It’s about eliminating a long-term exposure before that date becomes irrelevant.”&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Google’s decision to move up its timeline for migration to post-quantum cryptography highlights that some of the cyber security risks posed by quantum computing are already reality</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/HeroImages/risk-Omid-studio-adobe.jpg</image>
            <link>https://www.computerweekly.com/news/366640684/Shrinking-PQC-timeline-highlights-immediate-risk-to-data-security</link>
            <pubDate>Tue, 31 Mar 2026 05:30:00 GMT</pubDate>
            <title>Shrinking PQC timeline highlights immediate risk to data security</title>
        </item>
        <item>
            <body>&lt;p&gt;Work to translate the &lt;a href="https://cfit.org.uk/" target="_blank" rel="noopener"&gt;Centre for Finance, Innovation and Technology’s&lt;/a&gt; (CFIT’s) Digital Company ID blueprint into practical, real-world deployments of reusable digital identities for UK businesses is bearing fruit as the project reaches its latest milestone.&lt;/p&gt; 
&lt;p&gt;The CFIT this week unveiled the outcomes of its &lt;a href="https://www.computerweekly.com/news/366620195/CFIT-publishes-blueprint-for-digital-company-business-IDs" target="_blank" rel="noopener"&gt;Digital Company ID Coalition&lt;/a&gt; at a showcase event at which three industry-led working groups, led by UK Finance, Smart Data and Technology Alliance, Select ID, A&amp;amp;O Shearman and Skadden – supported by the likes of&amp;nbsp;Yoti, OneID, Dun &amp;amp; Bradstreet, Alloy, Monzo, Lloyds Banking Group and Differential AI&lt;i&gt; – &lt;/i&gt;shared their work so far.&lt;/p&gt; 
&lt;p&gt;Almost &lt;a href="https://www.computerweekly.com/news/366616523/UK-economy-could-see-600m-boost-through-digital-IDs-for-businesses" target="_blank" rel="noopener"&gt;18 months on from the project's inception&lt;/a&gt;, the groups have now collectively delivered a series of priority use cases – focusing on financial services onboarding, supplier verification, marketplace identity and government identity; built a trust and governance framework allowing scalable adoption across sectors; conducted extensive analysis of the commercial models and market opportunity needed to support long-term implementation; and finally, and finally, reported back with a pathway to a live, interoperable prototype&amp;nbsp;demonstrating that Digital Company ID is indeed a feasible concept.&lt;/p&gt; 
&lt;p&gt;“Digital Company ID is a systemic challenge that no single organisation can solve alone. Through this coalition, CFIT has brought together deep technical expertise from across industry, government and technology to move from concept to practical delivery,” said CFIT CEO Anna Wallace.&lt;/p&gt; 
&lt;p&gt;“The foundations are now in place, and the focus rightly shifts to implementation - turning this collaborative work into real-world infrastructure that strengthens trust and reduces friction for businesses across the UK economy. I’m deeply proud of the progress we have made alongside our partners to make this happen,” she said.&lt;/p&gt; 
&lt;p&gt;CFIT said its coalition had proven that Digital Company ID has the potential to remake how UK organisations prove their identities online, reducing fraud, simplifying onboarding and enabling faster, more secure digital transactions.&lt;/p&gt; 
&lt;p&gt;Currently, businesses face “persistent inefficiencies” when it comes to proving their identity to access financial and other professional services, said CFIT. One of the biggest challenges they face is the requirement to repeatedly provide the same verification information to different institutions, which creates burdensome and unnecessary administrative work, slows access to services, and increases the cost of compliance. A unified digital ID standard may help alleviate this.&lt;/p&gt; 
&lt;p&gt;Industry and policymakers are already strongly aligned on the need for a trusted digital identity infrastructure for British businesses, the organisation added.&lt;/p&gt; 
&lt;p&gt;CFIT’s own data says that over 80% of SMEs in the country would actually be willing to pay for a Digital Company ID to support a wide range of applications, which includes fraud prevention, financial services onboarding, marketplace verification, and government reporting.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Next steps"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Next steps&lt;/h2&gt;
 &lt;p&gt;In the coming weeks, the project will move to the next phase in its development, with the &lt;a href="https://www.cityoflondon.gov.uk/about-us/about-the-city-of-london-corporation" target="_blank" rel="noopener"&gt;City of London Corporation&lt;/a&gt; taking responsibility for coordinating implementation that is expected to eventually lead to a market-led orchestration model – CFIT will maintain strategic oversight and offer advisory support in this process.&lt;/p&gt;
 &lt;p&gt;City&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;of London Corporation policy chairman Chris Hayward said: “Fraud is a global challenge and remains a principal threat to the integrity of financial markets. As a founder of CFIT, and through participation in these working groups, City of London Corporation supports CFIT's conclusion that verified, reusable company identity confronts this challenge directly.&lt;/p&gt;
 &lt;p&gt;“It improves security, while removing friction for legitimate businesses that create jobs and generate growth. City of London is committed to ensuring our financial centre remains the safest, most transparent, and most competitive in the world,” he said.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more about digital ID&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;Westminster's eight-week consultation aims to get the public’s view on how the proposed digital ID system would work, and contemplates introducing a universal unique identifier &lt;a href="https://www.computerweekly.com/news/366639956/Whitehall-launches-digital-ID-consultation" target="_blank" rel="noopener"&gt;linked to the ID&lt;/a&gt;.&lt;/li&gt; 
    &lt;li&gt;The UK government’s recently announced digital ID scheme aims to curb the prospect of work for undocumented migrants, along with claiming benefits for UK citizens and legal residents. &lt;a href="https://www.computerweekly.com/feature/Is-Digital-ID-worth-the-risk" target="_blank" rel="noopener"&gt;However, are the threats to our personal data worth the risk?&lt;/a&gt;&lt;/li&gt; 
    &lt;li&gt;The proposed national digital identity app will no longer be compulsory for conducting right-to-work checks, removing the most contentious &lt;a href="https://www.computerweekly.com/news/366637189/UK-government-backtracks-on-plans-for-mandatory-digital-ID" target="_blank" rel="noopener"&gt;and widely criticised element of the scheme&lt;/a&gt;.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>Industries and policymakers are strongly aligned on the need for digital company IDs for UK businesses, as progress is made towards the implementation of a practical standard</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/Hero%20Images/bank-online-banking-adobe.jpeg</image>
            <link>https://www.computerweekly.com/news/366640405/Digital-IDs-edge-closer-to-practical-reality-for-UK-businesses</link>
            <pubDate>Tue, 17 Mar 2026 15:36:00 GMT</pubDate>
            <title>Digital IDs edge closer to practical reality for UK businesses</title>
        </item>
        <item>
            <body>&lt;p&gt;NetApp has refreshed &lt;a href="https://www.computerweekly.com/news/366611834/NetApp-E-series-Not-part-of-the-big-message-but-here-to-stay-says-CEO"&gt;its E-Series line&lt;/a&gt; with two &lt;a href="https://www.computerweekly.com/resources/Flash-storage-and-solid-state-drives-SSDs"&gt;all-flash&lt;/a&gt; models – the EF50 and EF80 – aimed at artificial intelligence (AI) training, inferencing and high-performance computing (HPC) workloads.&lt;/p&gt; 
&lt;p&gt;The launch comes with a claimed performance boost of 2.5x for these E-Series arrays. E-Series has long been the speedy option in &lt;a href="https://www.computerweekly.com/feature/NetApp-Not-just-NAS-filers-and-a-comprehensive-cloud-strategy"&gt;NetApp’s portfolio&lt;/a&gt; for applications that require dedicated bandwidth rather than the advanced storage functionality of the Ontap-based FAS and AFF lines.&lt;/p&gt; 
&lt;p&gt;The new arrays are built to tackle the “data-starving” problem seen in GPU-heavy environments where storage I/O does not keep GPU utilisation at optimum levels. According to NetApp, the EF80 delivers more than 100GBps read throughput and 57GBps write throughput, and targets checkpoint writes during generative AI (GenAI) training, for example.&lt;/p&gt; 
&lt;p&gt;The 2.5x performance improvement over the previous generation is a significant jump from the existing EF models. In terms of density, NetApp packs 1.5 petabytes of storage into a 2U chassis, a move designed to curb the ever-growing power and cooling footprint in modern datacentres.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Targeting neoclouds"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Targeting neoclouds&lt;/h2&gt;
 &lt;p&gt;Sandeep Singh, senior vice-president and general manager for storage with NetApp, said: “We are delivering proven and affordable high-performance, extreme performance, for the most performance-intensive and demanding workloads.&lt;/p&gt;
 &lt;p&gt;“That includes &lt;a href="https://www.computerweekly.com/news/366611617/NetApp-maintains-push-to-data-management-for-AI"&gt;AI use cases&lt;/a&gt; inclusive of AI training, AI inferencing, HPC workloads and transactional database workloads, not only for the enterprises, but also for neoclouds, sovereign AI clouds and AI-powered manufacturing use cases.”&lt;/p&gt;
 &lt;p&gt;Singh said EF-Series is intended to serve as the high-speed “scratch space” in a tiered architecture, often paired with parallel file systems such as Lustre or BeeGFS. This allows the E-Series to act as a high-performance engine at the front end, while larger, more persistent data stores sit behind it.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="E-Series heritage"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;E-Series heritage&lt;/h2&gt;
 &lt;p&gt;The E-Series has occupied a unique space within NetApp. Its DNA doesn’t come from the company's famous WAFL-based filers, but from the 2011 acquisition of Engenio (from LSI). This gave NetApp a much-needed block-storage play and for workloads where the bells and whistles of Ontap were actually a hindrance.&lt;/p&gt;
 &lt;p&gt;E-Series has been a quiet workhorse, often found working with offerings from IBM, Dell, and Teradata. While NetApp’s primary AFF/FAS lines focus on unified storage with heavy data reduction, the E-Series has remained the go-to for dedicated, high-duty-cycle applications. Its SANtricity operating system favours raw performance and simplicity.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Powering the rack"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Powering the rack&lt;/h2&gt;
 &lt;p&gt;As the focus in the datacentre shifts from mere capacity to power draw, E-Series density is a primary defence. Singh noted that storage draw is a “small fraction” of what a rack of GPUs pulls. By feeding GPUs more efficiently and reducing idle time, the net effect is a more streamlined, if still power-hungry, AI infrastructure.&lt;/p&gt;
 &lt;p&gt;Singh said: “When you put it in the context of GPUs, these arrays enable the GPUs to not be sitting idle and starving. And to that part of it, if you can optimise it, you’re reducing wasted power and boosting utilisation of those GPUs. That also goes into the equation for customers.”&lt;/p&gt;
 &lt;p&gt;This release puts NetApp into tighter competition with the likes of Pure Storage and its FlashArray//XL, as well as Dell’s Project Lightning. While Pure focuses on a unified architecture, NetApp’s strategy remains “horses for courses”, using E-Series for raw throughput while keeping ONTAP for general-purpose enterprise data management.&amp;nbsp;&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more about NetApp storage&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/NetApp-Not-just-NAS-filers-and-a-comprehensive-cloud-strategy"&gt;NetApp: Not just NAS filers, and a comprehensive cloud strategy&lt;/a&gt;. NetApp market share has slipped, but it has built out storage across file, block and object, plus capex purchasing, Kubernetes storage management and hybrid cloud.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/news/366611834/NetApp-E-series-Not-part-of-the-big-message-but-here-to-stay-says-CEO"&gt;NetApp E-series: Not part of the big message, but here to stay, says CEO&lt;/a&gt;. We asked NetApp about its high-performance computing-focused E-series block storage arrays and found inconsistent messaging but ultimately a commitment from CEO George Kurian to retain it.&amp;nbsp;&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>High-performance non-ONTAP workhorse targets AI use cases and aims to ensure GPUs get fed optimally, with claimed 2.5x boost in performance over previous models</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/article/GPU-datacentre-2-adobe.jpg</image>
            <link>https://www.computerweekly.com/news/366640454/NetApp-targets-E-Series-at-AI-era-with-EF50-and-EF80</link>
            <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
            <title>NetApp targets E-Series at AI and neoclouds with EF50 and EF80</title>
        </item>
        <item>
            <body>&lt;p&gt;Everpure has announced Evergreen One for AI, a performance-backed consumption model for artificial intelligence (AI) that extends to use of its &lt;a href="https://www.computerweekly.com/news/366620538/Pure-aims-at-AI-beyond-the-enterprise-with-FlashBlade-Exa"&gt;FlashBlade//Exa&lt;/a&gt; &lt;a href="https://www.computerweekly.com/resources/Flash-storage-and-solid-state-drives-SSDs"&gt;high-performance storage&lt;/a&gt;. Meanwhile, the company – &lt;a href="https://www.computerweekly.com/news/366639189/Pure-Storage-rebrands-to-Everpure-as-storage-makers-business-expands-focus-to-data-management"&gt;known as Pure Storage until recently&lt;/a&gt; – has announced the beta release of its Datastream automated AI pipeline appliance.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Evergreen One for AI differs from existing flexible capacity offers in the Everpure range by providing use of FlashBlade//Exa and service-level agreements (SLA) based on graphics processing unit (GPU) count. The aim here is to ensure that the storage environment provides the throughput to keep GPU resources fully utilised.&lt;/p&gt; 
&lt;p&gt;FlashBlade//Exa, Everpure’s highest-performance platform, was previously excluded from the &lt;a href="https://www.computerweekly.com/feature/Pures-storage-as-a-service-We-can-offer-what-others-cant"&gt;Evergreen One consumption model&lt;/a&gt;.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Exa aims at AI and high-performance computing (HPC) workloads that demand extremely high throughput, likely in customers between large enterprise users of AI and the hyperscalers.&lt;/p&gt; 
&lt;p&gt;At its launch, FlashBlade//Exa introduced an architecture to the Pure product line in which metadata and bulk storage are disaggregated with different hardware and protocols in use.&lt;/p&gt; 
&lt;p&gt;Kaycee Lai, vice-president for AI with Everpure, said Evergreen One for AI shifted the financial and operational risk away from the customer. “Specifically, we have an offering which we call Evergreen One for AI,” he said. “The big difference for AI is that we set the performance level of the offering based on the number of GPUs that you have … it is an SLA-backed performance guarantee.”&lt;/p&gt; 
&lt;p&gt;Evergreen One and Flex are Pure Storage’s pay-as-you-go procurement models, while Forever involves upfront purchase with built-in upgrades.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Automating the RAG pipeline"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Automating the RAG pipeline&lt;/h2&gt;
 &lt;p&gt;Everpure also announced the beta availability of Datastream. First previewed in late 2024, Datastream is a “single SKU” appliance that integrates Nvidia GPUs with Everpure storage. It is designed to tackle the “data readiness” challenge, said Lai. This refers to the oft-cited statistic that data teams spend 80% of their time preparing unstructured data for use.&lt;/p&gt;
 &lt;p&gt;The appliance automates the &lt;a href="https://www.computerweekly.com/feature/RAG-AI-Do-it-yourself-says-NYC-data-scientist"&gt;retrieval-augmented generation&lt;/a&gt; (RAG) pipeline, which includes ingest, curation and vectorisation of data. By providing an integrated hardware and software stack, Everpure aims to provide an “easy button” for enterprises building chatbots or autonomous agents, he said.&lt;/p&gt;
 &lt;p&gt;The software capability behind Datastream was built in-house, though it can connect to third-party data sources including Dell, HP and NetApp environments, as well as cloud-resident data. This flexibility allows the appliance to act as a central hub for AI readiness regardless of where the data lives.&lt;/p&gt;
 &lt;p&gt;“Today, people run RAG pipelines … they do the chunking, the embedding, the indexing to make sure that the data is going to be accurate and relevant so that chatbot agents can consume them in a specific format,” said Lai. “That takes up about 80% of most data teams’ time because there’s no standard tool.”&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Underpinning performance"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Underpinning performance&lt;/h2&gt;
 &lt;p&gt;To support these launches, Everpure revealed new benchmarks intended to validate its hardware under AI stress. In MLPerf 2.0 testing, the company claimed the top spot for checkpointing – a critical function for saving the state of a model during long training runs – reporting results up to two times better than competitors such as Huawei and Vast.&lt;/p&gt;
 &lt;p&gt;The company also cited Spec Storage AI image benchmarks, where it outperformed NetApp’s AFX platform by approximately 20%, he said.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more about storage and AI&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Storage-technology-explained-AI-and-the-data-storage-it-needs"&gt;Storage technology explained: AI and data storage&lt;/a&gt;: In this guide, we examine the data storage needs of artificial intelligence, the demands it places on data storage, the suitability of cloud and object storage for AI, and key AI storage products.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Storage-technology-explained-Vector-databases-at-the-core-of-AI"&gt;Storage technology explained: Vector databases at the core of AI&lt;/a&gt;: We look at the use of vector data in AI and how vector databases work, plus vector embedding, the challenges for storage of vector data and the key suppliers of vector database products.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>Nvidia GTC is the occasion for beta launch of its Datastream appliance that marries software to ingest and manage AI data pipelines with Everpure storage and GPU resources</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/Hero%20Images/Cambridge-1-GPU-CREDIT-NVIDIA-hero.jpg</image>
            <link>https://www.computerweekly.com/news/366640415/Everpures-Evergreen-One-for-AI-brings-Exa-flash-and-GPU-based-service-level-agreements</link>
            <pubDate>Mon, 16 Mar 2026 16:30:00 GMT</pubDate>
            <title>Everpure’s Evergreen One for AI brings Exa flash and GPU-based service-level agreements</title>
        </item>
        <item>
            <body>&lt;p&gt;&lt;a href="https://www.gov.uk/government/organisations/companies-house" target="_blank" rel="noopener"&gt;Companies House&lt;/a&gt;, the UK’s business registrar, has successfully rebooted its online WebFiling service after it emerged that a previously unknown cyber security issue exposed various data on companies and people associated with them to other logged-in users.&lt;/p&gt; 
&lt;p&gt;The flaw – which appears to have arisen during a WebFiling update last year – was never accessible to the general public and only logged-in users in possession of an authorised code could have exploited it. Companies House pulled WebFiling offline at lunchtime on Friday 13 March to investigate and remediate.&lt;/p&gt; 
&lt;p&gt;Companies House found the data exposed included dates of birth, residential addresses and company addresses. It also discovered that it may have been possible for people to make unauthorised actions – such as changing directors or even filing accounts.&lt;/p&gt; 
&lt;p&gt;It stressed that no credentials or data used for identity verification such as passport information, and neither could any existing filed documents have been altered.&lt;/p&gt; 
&lt;p&gt;Companies House chief executive Andy King said: “We are asking all companies to check their registered details and filing history to make sure everything appears correct. If a company has a concern, please&amp;nbsp;&lt;a href="https://www.gov.uk/government/organisations/companies-house/about/complaints-procedure" target="_blank" rel="noopener"&gt;raise a complaint&lt;/a&gt; and include evidence to describe the concern.&amp;nbsp;I recognise that this incident will have caused concern and inconvenience to many of the companies and individuals who rely on our services. I am sorry for that.&lt;/p&gt; 
&lt;p&gt;“Companies House takes its responsibility to protect the data entrusted to us extremely seriously. We have taken swift action to secure and restore our service, and are committed to doing everything in our power to support those affected and to making sure that our services continue to merit the trust placed in them,” said King.&lt;/p&gt; 
&lt;p&gt;The incident has been reported to both the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC). King said that the registrar was still actively analysing its data to try to identify any anomalies, adding: “If we find evidence that anyone has used this issue to access or change another company’s details without authorisation, we will take firm action.”&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Simple vulnerability"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Simple vulnerability&lt;/h2&gt;
 &lt;p&gt;The issue was first reported to Companies House by Dan Neidle, of non-profit thinktank &lt;a href="https://taxpolicy.org.uk/" target="_blank" rel="noopener"&gt;Tax Policy Associates&lt;/a&gt;, on behalf of John Hewitt, operations director at &lt;a href="https://ghostmail.co.uk/" target="_blank" rel="noopener"&gt;Ghost Mail&lt;/a&gt;, a provider of mailing address services.&lt;/p&gt;
 &lt;p&gt;Writing online, Neidle said the vulnerability was “incredibly simple” to exploit. All a logged-in user needed to do was click through the “file for another company” option – which would usually prompt for an authentication code to stop unauthorised access. However, if the logged-in user hit their backspace key a few times they would be sent back not to their own dashboard, but to the “target” company’s.&lt;/p&gt;
 &lt;p&gt;Neidle said that the two men were able to use the vulnerability to view the private dashboard of another individual – with permission from them – and to successfully modify his own registered address at Companies House. “I was incredulous at what John showed me,” he said.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Was the bug exploited?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Was the bug exploited?&lt;/h2&gt;
 &lt;p&gt;It is unclear if the bug was ever exploited, but in Companies House’s view it was also highly unlikely that any systematic access to company records or large-scale data exfiltration took place because any access that did occur would have been limited to individual company records, viewed one at a time, by a registered user.&lt;/p&gt;
 &lt;p&gt;Neidle noted that the flaw had been live and exploitable since October 2025, which meant there is a distinct policy that it was discovered by a threat actor. He said that if this had been the case, it was likely used “carefully, selectively and for profit” because broad exploitation would have been swiftly discovered.&lt;/p&gt;
 &lt;p&gt;William Wright, CEO of &lt;a href="https://www.cdsec.co.uk/" target="_blank" rel="noopener"&gt;Closed Door Security&lt;/a&gt;, said the ability to access and edit company details presented a huge amount of leeway for both explicit and subtle fraud, and had caused serious uncertainty around a system used by the vast majority of UK companies.&lt;/p&gt;
 &lt;p&gt;“Company directors and C-suite are already lucrative targets for phishing and fraudsters; these individuals typically have privileged access in company systems and are privy to sensitive and valuable information,” said Wright.&lt;/p&gt;
 &lt;p&gt;“Being able to acquire details like home addresses, etc. makes targeted attacks like spear phishing against these individuals far more viable and increases the potential for many other kinds of fraud and targeted harassment. This is to mention nothing of the GDPR implications were information to be exposed.&lt;/p&gt;
 &lt;p&gt;“That companies’ registration details could also be modified presents obvious problems. Companies can be penalised in various ways for providing inaccurate information when filing, and this can lead in some instances to serious accusations of fraud. The fact details could be modified by anyone without authorisation could raise serious problems for future investigations, especially if there’s any suspicion of tampering.”&lt;/p&gt;
 &lt;p&gt;Wright added that the length of time for which the flaw went undetected also raises more serious questions for Companies House as it suggests the body tasked with providing the public with an single, transparent source of accurate information on British businesses, lacked appropriate auditing, logging or testing procedures that might have spotted it sooner, and without outside help.&lt;/p&gt;
 &lt;p&gt;“If the government and Companies House's current security testing processes were fit for purpose, flaws like this should not have occurred,” said Wright. “Given that many companies are required by law to use these services, basic testing and data protection are absolutely critical, especially if the government wants to retain its credibility with the business community.”&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more about data breaches&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;Details of over 70 million customers of US sportswear giant Under Armour were leaked following a supposed ransomware attack &lt;a href="https://www.computerweekly.com/news/366637595/Sportswear-firm-Under-Armour-falls-victim-to-data-breach" target="_blank" rel="noopener"&gt;by the Everest gang&lt;/a&gt;.&lt;/li&gt; 
    &lt;li&gt;Synnovis, the pathology lab services provider hit by a Qilin ransomware attack in 2024, is notifying its NHS partners that their patient data was compromised, &lt;a href="https://www.computerweekly.com/news/366634454/Synnovis-to-notify-NHS-of-data-breach-after-nearly-18-months" target="_blank" rel="noopener"&gt;following a lengthy investigation&lt;/a&gt;.&lt;/li&gt; 
    &lt;li&gt;Many more data breaches at the MoD's Arap programme to relocate at-risk Afghan citizens to Britain have emerged &lt;a href="https://www.computerweekly.com/news/366629784/Scale-of-MoD-Afghan-data-breaches-widens-dramatically" target="_blank" rel="noopener"&gt;following an FoI request by BBC journalists.&lt;/a&gt;&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>Companies House was forced to pull its WebFiling service offline at the weekend after it emerged that a flawed update was putting data at risk of exposure</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/article/Data-breach-hacker-adobe.jpg</image>
            <link>https://www.computerweekly.com/news/366640295/Companies-House-restarts-online-services-following-cyber-breach</link>
            <pubDate>Mon, 16 Mar 2026 14:35:00 GMT</pubDate>
            <title>Companies House restarts online services following cyber breach</title>
        </item>
        <item>
            <body>&lt;p&gt;When US president Trump implemented sanctions against the &lt;a href="https://www.computerweekly.com/opinion/Microsofts-ICC-email-block-reignites-European-data-sovereignty-concerns"&gt;International Criminal Court (ICC)&lt;/a&gt; in February 2025, it wasn’t long before ICC chief prosecutor Karim Khan found himself locked out of his Microsoft 365 email account.&lt;/p&gt; 
&lt;p&gt;This sent digital sovereignty-shaped shock waves across Europe and raised fears that US &lt;a href="https://www.computerweekly.com/resources/Cloud-computing-services"&gt;cloud hyperscalers&lt;/a&gt; could wield a “kill switch” against customers that fall foul of US political imperatives. Many saw it as another example of the US’s “America First” policies hitting home, this time in the digital domain and against an organisation’s vital information infrastructure.&lt;/p&gt; 
&lt;p&gt;For the ICC, it pushed the organisation to migrate to German supplier ZenDiS’s openDesk, which provides office productivity tools based on open source, &lt;a href="https://www.computerweekly.com/news/366626126/UK-data-reforms-become-law"&gt;GDPR-compliant&lt;/a&gt; technology.&lt;/p&gt; 
&lt;p&gt;For many others in the UK and Europe, it pushed the question of digital sovereignty to the fore. In response to the ICC-Microsoft affair, for example, Dutch lawmakers petitioned their government to move to 30% Dutch or European cloud services by 2029.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;In this article, we look at data sovereignty in terms of the risks – political, legal and economic – with special reference to the massive &lt;a href="https://www.computerweekly.com/feature/Go-big-or-go-home-Should-UK-IT-buyers-favour-US-clouds-or-homegrown-providers"&gt;penetration of US hyperscalers in the UK&lt;/a&gt; and European markets. We also hear from voices concerned about US hyperscaler penetration into the public sector, vital services and the cloud economy, and reveal massive penetration of the UK public sector by the hyperscalers.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;This is the first article in a series, with the next looking more deeply at campaigner concerns and state-level responses around data sovereignty.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What is data/digital sovereignty?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What is data/digital sovereignty?&lt;/h2&gt;
 &lt;p&gt;To discuss &lt;a href="https://www.computerweekly.com/news/366637125/Campaigners-urge-UK-to-develop-digital-sovereignty-strategy"&gt;data sovereignty&lt;/a&gt; at all, we need to arrive at a working definition or a set of definitions. The idea of data sovereignty comes from the wider political notion of sovereignty as applied to states, where it means the solely held power to govern a country.&lt;/p&gt;
 &lt;p&gt;When it comes to data, we can extend that idea to mean complete control over data and applications to give us a concept of data sovereignty or digital sovereignty. That could apply to enterprises and their need to retain data in specific jurisdictions to meet legal and regulatory requirements.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="What are the risks to nation states around data sovereignty?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What are the risks to nation states around data sovereignty?&lt;/h2&gt;
 &lt;p&gt;The risks to nation states around data sovereignty fall under three main categories:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Risks of political interference from foreign states;&lt;/li&gt; 
  &lt;li&gt;Legal interference when the laws of one state affect data held in another;&lt;/li&gt; 
  &lt;li&gt;Issues of economic sovereignty, where the degree of foreign company control over data in an economy is considered a risk.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="The political risk and the hyperscaler ‘kill switch’"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The political risk and the hyperscaler ‘kill switch’&lt;/h2&gt;
 &lt;p&gt;The ICC-Microsoft affair shows that data sovereignty isn’t just theoretical. It’s a live risk, says Liberal Democrat spokesperson for science, innovation and technology, Tim Clement-Jones.&lt;/p&gt;
 &lt;p&gt;“If you see that kind of risk, where a hyperscaler like Microsoft can be pressured to withdraw a service, you have to look at the fact that we are so heavily embedded – we’ve got Microsoft, AWS and Google all over government,” he says. “Where are the alternative UK suppliers?”&lt;/p&gt;
 &lt;p&gt;US president Trump and his unpredictable and/or targeted decision-making have been a major driver around data sovereignty, not least because so much cloud capability deployed across the globe is US-owned, in particular by the three main hyperscalers – AWS, Microsoft and Google Cloud.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="The legal risk and ‘jurisdictional overreach’"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The legal risk and ‘jurisdictional overreach’&lt;/h2&gt;
 &lt;p&gt;Then there are concerns around legal interference. This is where the laws of one country apply to data held in systems that may also be subject to the laws of another. This is referred to as “jurisdictional overreach”.&lt;/p&gt;
 &lt;p&gt;Risks of that type around data sovereignty are exemplified by the US Cloud Act and Chinese National Intelligence Law (NIL), which both create situations where the laws of one country directly conflict with the laws of another, where the data is protected.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;The US Clarifying Lawful Overseas Use of Data (Cloud) Act was passed in 2018, and empowers US law enforcement agencies to compel US-based technology companies to provide data to them, wherever that data is stored, inside or outside the US.&amp;nbsp; That requirement directly affects privacy laws elsewhere, such as the EU’s GDPR, which prohibits transfer of data to a third country.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Meanwhile, the Chinese NIL mandates assistance and cooperation with Chinese state intelligence work and can apply to Chinese companies and citizens wherever they are. Like the US Cloud Act, GDPR makes it impossible to comply with this in Europe because the NIL might require a company to hand over data on customers in Europe, again contravening transfer of data overseas.&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="The economic risk: becoming a ‘digital colony’"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The economic risk: becoming a ‘digital colony’&lt;/h2&gt;
 &lt;p&gt;There’s a point where worries about foreign political interference and data sovereignty become entwined with issues of economic sovereignty.&amp;nbsp; The concern is that UK and European states don’t have the homegrown capacity to offer cloud and software services as the US giants do, and that is a risk to the economic wellbeing of those countries.&lt;/p&gt;
 &lt;p&gt;Axel Voss, German Christian Democrat MEP in the European Parliament, is a keen advocate of building increased European economic sovereignty in the digital realm, saying that he believes Europe risks becoming a digital colony of the US or China.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;“It shows up when Europe’s daily digital life and increasingly our critical infrastructure runs on non-European hardware, software, cloud services and platforms,” says Voss. “That means the next technological wave can be shaped by actors who don’t share our values or standards. That creates systemic risks for prosperity, privacy and security, and it can leave Europeans feeling that democratic institutions have ‘lost control’ over the digital environment.&lt;/p&gt;
 &lt;p&gt;“The biggest risks are strategic lock-in and unilateral dependencies. If core collaboration tools, identity, storage, cloud and AI are controlled elsewhere, Europe’s administrations and companies lose real freedom of choice and bargaining power.”&lt;/p&gt;
 &lt;p&gt;That dependency can sometimes come to light in shocking ways. Last year, it was revealed that Scottish police forces that use Microsoft 365 have no idea what country their data may be kept in – &lt;a href="https://www.computerweekly.com/news/366629871/Microsoft-refuses-to-divulge-data-flows-to-Police-Scotland"&gt;and Microsoft wouldn’t tell them&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;Clement-Jones says: “Their data can be held all over the world in any datacentre run by Microsoft. The first thing that comes into my mind is really, that’s crazy. How can they do that? How do they justify that? Surely an organisation like the police force is going to demand physical sovereignty.”&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="The scale of hyperscaler penetration: the UK public sector"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The scale of hyperscaler penetration: the UK public sector&amp;nbsp;&lt;/h2&gt;
 &lt;p&gt;US hyperscale cloud providers have near-universal penetration across the UK public sector and account for the majority of technology spending. In the financial year 2023/2024, 95% of central and local public sector organisations in the UK spent budget on hyperscale cloud services. When software services that run on hyperscale cloud – such as software as a service (SaaS) – are included, that share rises to 99%.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;This is the case for more than 1,100 public sector bodies, including government departments, councils, police forces and NHS organisations, according to data that comes from &lt;a href="https://www.computerweekly.com/news/366626559/Public-sector-spends-166bn-directly-with-tech-suppliers-every-year"&gt;analyst Tussell&lt;/a&gt;. The public sector procurement specialist publishes its Tech Titans list every year of the top 150 tech suppliers by spend received from the UK public sector, and breaks that down by department. In the financial year 2023/24, these companies were paid around £17.7bn of public sector budget, which was 84% of total spend.&lt;/p&gt;
 &lt;p&gt;In the data, it is possible to identify an actual hyperscaler in only one case – AWS is present under its own name. That's because for the most part, cloud provision comes via resellers of the three key US-owned public clouds, AWS, Microsoft Azure and Google Cloud, with Oracle and IBM also counted as hyperscalers for this analysis. Prominent cloud resellers to the UK public sector are Bytes, Capgemini and Softcat, but the list extends to around 30 such suppliers.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;We can verify suppliers as resellers of hyperscaler cloud provision because they publish information about their accreditations, such as AWS Premier Tier Services Partner, Azure Expert Managed Service Provider, or Google Cloud Premier Partner. That is not to say that they are solely providers of cloud connectivity, as they often provide consultancy too.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Out of the £17.7bn total Tech Titans spend, more than half – 55% or £9.9bn – was spent directly with hyperscale cloud providers or via cloud resellers of hyperscaler cloud in financial year (FY) 2023/2024. Beyond direct or reseller provision of hyperscale cloud connectivity, suppliers that offer services that use hyperscale cloud – e.g. SaaS – can also be identified, or at least ruled out as suppliers of cloud connectivity. Adding these to direct hyperscale and cloud resellers, they accounted for 86% of total Tech Titans spend, with £15.3bn going their way.&lt;/p&gt;
 &lt;p&gt;Out of 22 government departments in the data, 21 spent budget on hyperscale cloud in some form in that year, with 13 of them spending 50% or more of their tech budget on hyperscale cloud directly or via cloud resellers.&lt;/p&gt;
 &lt;p&gt;The top five public sector spenders on hyperscale cloud were: Ministry of Defence (£1.09bn), HM Revenue &amp;amp; Customs (£1.01bn), the Home Office (£775m), Department for Work and Pensions (£622m), and NHS England (£442m).&lt;/p&gt;
 &lt;p&gt;Out of 64 police forces and other police agencies in the data, 55 spent budget on hyperscale cloud, which rose to 59 if services that use hyperscale cloud were included. The Metropolitan Police spent £354m on hyperscale cloud.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Out of 271 NHS organisations in the data, 270 spent budget on hyperscale cloud in 2023/24.&lt;/p&gt;
&lt;/section&gt;          
&lt;section class="section main-article-chapter" data-menu-title="Conclusion: UK digital infrastructure dependent on foreign tech"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Conclusion: UK digital infrastructure dependent on foreign tech&lt;/h2&gt;
 &lt;p&gt;The Tussell/Computer Weekly data highlights how deeply embedded US cloud infrastructure has become across the UK public sector – a reality that complicates efforts by European policymakers to promote “sovereign cloud” alternatives.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;When nearly every government department and myriad local and other agencies relies on a handful of offshore entities, the line between supplied services and national sovereignty blurs. As some of the campaigners we spoke to warn, the risk is no longer just about where data sits, but whether a nation state has complete control – sovereignty – over its own critical functions.&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;To correct this situation potentially requires a radical shift in strategy. In the next feature in this series, we look at how governments and campaigners in the UK and Europe have responded.&amp;nbsp;&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Read more about data sovereignty&lt;/h3&gt; 
   &lt;ul class="default-list"&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Auditing-classifying-and-building-a-data-sovereignty-strategy"&gt;Auditing, classifying and building a data sovereignty strategy&lt;/a&gt;: We look at data sovereignty – what it is and how to build a data sovereignty strategy around data auditing.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.computerweekly.com/feature/Public-cloud-Data-sovereignty-and-data-security-in-the-UK"&gt;Public cloud: Data sovereignty and data security in the UK&lt;/a&gt;: We assess the impact of new regulations and government policy on the ability to use public cloud services.&lt;/li&gt; 
   &lt;/ul&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;</body>
            <description>We look at the political, legal and economic risks around data sovereignty, the fears for digital dependency and massive hyperscaler penetration in the UK public sector</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/Hero%20Images/passport-visa-fotolia.jpg</image>
            <link>https://www.computerweekly.com/feature/This-rise-of-the-splinternet-Data-sovereignty-risks-and-responses</link>
            <pubDate>Thu, 12 Mar 2026 08:17:00 GMT</pubDate>
            <title>The rise of the splinternet? Data sovereignty risks and responses</title>
        </item>
        <title>ComputerWeekly.com</title>
        <ttl>60</ttl>
        <webMaster>editor@computerweekly.com</webMaster>
    </channel>
</rss>
