
Digital Sovereignty Under Pressure at the International Criminal Court
The incident in which the International Criminal Court (ICC) temporarily lost access to its email environment touches upon a fundamental governance theme: digital … Read more
The incident in which the International Criminal Court (International Criminal Court, ICC) temporarily lost access to its email environment touches upon a fundamental governance theme: digital sovereignty. The Court, based in The Hague, is an independent international tribunal that prosecutes serious crimes such as genocide and war crimes. Precisely such an organization must be able to operate autonomously at all times, without interference from states or commercial parties. The fact that access to an essential communication tool could be restricted by an external supplier caused a stir internationally. The incident illustrates that digital dependencies are not neutral and that sovereignty in the digital world extends beyond flags, treaties, and jurisdiction.
What Happened: Email Access as a Means of Power
The core of the incident was that the ICC procured its email service from a commercial cloud provider, in this case Microsoft. Due to geopolitical tensions and legal pressure from the United States, the service came under pressure, causing the Court to (temporarily) lose access to its email. For an organization like the ICC, email is not a supporting tool but a primary infrastructure for communication with states, lawyers, and researchers. For non-technical readers, it is important to see this clearly: this was not a technical malfunction, but a governance and legal issue in which a supplier effectively gained influence over the operational continuity of an international organization.
Sovereignty in the Digital Supply Chain
Traditionally, sovereignty is seen as control over territory and legislation. In the digital reality, this shifts to control over data, systems, and access. When core processes run on platforms subject to foreign law, a new dependency arises. The ICC incident shows that even organizations with an international mandate are vulnerable to decisions by external parties that fall outside their sphere of influence. This is a typical supply chain risk: it's not the organization itself that fails, but a link in the chain becomes a power factor. For executives, this is an uncomfortable realization, as these risks are often implicit and only become visible when things go wrong.
The Role of Legislation and Geopolitics
What makes this incident extra complex is the intertwining of technology and geopolitics. American technology companies fall under US legislation and can therefore be confronted with sanctions, export restrictions, or political pressure. This directly impacts customers worldwide. For the ICC, which must be independent of individual states, this is problematic. However, the same dynamic applies in a milder form to European governments, regulators, and semi-public organizations. The question is not whether suppliers are reliable, but under what legislation they operate and what obligations they may be subjected to. Digital sovereignty therefore also means understanding which external forces can influence your digital infrastructure.
Governance Lessons: Email is Not a Commodity
An important lesson from this incident is that some digital services are too quickly seen as a “commodity”. Email, cloud storage, and collaboration platforms seem generic and replaceable, but in reality, they are deeply intertwined with primary processes. For executives, this means that supplier choices are strategic, even when it comes to seemingly standard services. The question “what happens if the supplier pulls the plug tomorrow?” is not a doomsday scenario, but a legitimate governance question. For CISOs and CIOs, the task here is to make these dependencies explicit and translate them into risks for continuity, reputation, and autonomy.
Sovereignty is Not an All-or-Nothing Choice
The ICC incident also shows that digital sovereignty is not a black-and-white concept. Operating completely independently is not realistic for most organizations. The challenge lies in consciously choosing where dependency is acceptable and where it is not. This requires differentiation: which systems are critical for mission and mandate, and which are supporting? For critical systems, stricter requirements, alternatives, or exit scenarios can be chosen. This is not an argument against cloud usage, but for conscious governance. Sovereignty is not about rejecting technology, but about maintaining control.
Relevance for Dutch Organizations
Although the ICC has a unique international position, the lessons are highly relevant for Dutch governments and medium-sized organizations. They also use foreign cloud providers for core processes. The incident makes it clear that digital dependencies require executive ownership. Especially in sectors where confidentiality, continuity, and independence are crucial, sovereignty must be an explicit part of risk management. Positively, these types of incidents deepen the conversation. They help executives to see digital supply chain risk not just as a security issue, but as a strategic theme that touches upon autonomy and trust.
Conclusion: Sovereignty Begins with Insight
The temporary denial of email access at the International Criminal Court is not a technical incident, but a governance wake-up call. It shows that digital sovereignty is vulnerable when core processes depend on external parties under foreign law. For boards and CISOs, the most important lesson is that insight into digital dependencies is a prerequisite for autonomy. Those who understand where the levers are and who can pull them can make better choices. In a world where digitalization and geopolitics are increasingly intertwined, this is not a luxury, but a necessity.