Sovereign Cloud Risk Assessment

Sovereign Cloud Risk Assessment

Know what stops, what degrades, and what survives if your access to your current cloud provider is disrupted. In 10 weeks, you leave with a tested disruption scenario and a board-ready decision

Book your assessment
The Problem

Built on major cloud providers, but never tested for losing them?

Most of your estate probably runs on the public cloud, because that was the right call. If that access were disrupted by sanctions, export controls, or a jurisdictional action, could you show the board what stops, what degrades, and what survives?

The SOLUTION

An assessment scoped to your business

We focus on the critical functions that carry your business, then stress-test them against a real scenario. You'll be able to show the board exactly what stops, what degrades, and what survives.

Blast radius

How much of the business stops if this function goes down?

Regulatory pressure

Does it sit inside NIS2, DORA, or another binding deadline?

Recovery complexity

How many handoffs, owners, and external parties does recovery need?

Dependency breadth

Is it a hub for identity, data, or integration across the estate?

Four reasons teams bring this to Redeploy

A live stress test

We run your recovery runbook against a real loss of public cloud access and measure what actually recovers.

A board-ready decision

You leave with three costed options, accept, hedge, or act, ready to put in front of the board.

Independent by design

We have no cloud to sell, so the challenge to your estate stays genuinely neutral.

We build what you decide

The same team can stand up the continuity capability or the sovereign landing zone, and run it.

A critical payment flow, proven against losing public cloud access

A Nordic transport and logistics operator ran a critical payment flow on a public cloud, untested against losing that access, with downtime costing six figures an hour. Our Sovereign Cloud Risk Assessment mapped it, wrote the runbook, and proved it in a live exercise, cutting recovery time by almost a third.

0

%

faster recovery

The process

4 phases, 4 artefacts, 10 weeks

Each phase produces one artefact you keep. Together, they take you from an unmapped estate to a board-ready decision.

01 · Preparation

We interview function owners, sketch the architecture, and agree on the scenario and scope. You get a dependency map of the estate.

Artefact: Dependency map.

02 · Runbook

We write the recovery procedure with roles, prioritised functions, and an RTO and RPO target per function.

Artefact: Recovery runbook.

03 · Exercise

We run the runbook against the scenario in a tabletop or live exercise, measure the recovery time, and capture where it broke.

Artefact: Exercise report.

04 · Retrospective

We turn the findings into a prioritised backlog and a board-ready options paper.

Artefact: Prioritised backlog.

A Nordic partner that can also build what you decide

Redeploy is a cloud, data, and AI partner founded in 2015, a Microsoft Solutions Partner, and AWS Advanced Tier certified. We hold no sovereign-cloud product, so the challenge stays independent, and the same team can build and run whatever you decide next.

Frequently Asked Questions

Is this about leaving the major cloud providers?

No. The goal is resilience, and you keep the major cloud providers where they serve you. We size the dependency and prove what recovers; then you decide which workloads justify a move and which stay exactly where they are.

Does sovereign cloud just cost more?

Often, yes, sovereign options are perceived as more expensive, and sovereignty rarely justifies a switch on its own. That is exactly why this is a tiering exercise. The assessment tells you which workloads justify the premium and which do not, so you spend only where the exposure warrants it.

How long does it take?

10 weeks, fixed scope. The milestones are kickoff, scenario locked, exercise executed, and final presentation. It is designed to reach a board decision within a quarter.

What do we get at the end?

You get a board-ready options paper that sets out accept, hedge, and act, each with its cost and residual risk. It is backed by the artefacts from the engagement: a dependency map, a recovery runbook, an exercise report, a prioritised backlog, and a risk register.

What do you need from us?

An empowered sponsor at the CIO or CISO level, a function owner per pilot, a decision-maker for group management, and access to architecture, contracts, and BC/DR plans. The week-zero kickoff names every owner.

Is this just a DORA or NIS2 compliance exercise?

It produces the evidence a regulator or auditor asks for, but it is broader than compliance. It tests operational continuity under a loss of public cloud access.

Do you push us toward a European provider?

No. We are independent and have no cloud to sell. When leaving a workload where it is happens to be the right call, that is what we recommend, and the exercise gives you the evidence to defend the choice.

What happens after the assessment?

You choose one of three postures. Accept the exposure, hedge it by standing up continuity capability, or act by moving the critical estate to a sovereign landing zone. If you act, the same team can build it and operate it under a 24/7 managed service.