Poland’s Defence Spending Must Be Matched by Digital Resilience

SECURITYPoland’s Defence Spending Must Be Matched by Digital Resilience
- Advertisement -Translation agency in Poland – professional language servicesTranslation agency in Poland – professional language services

Among all NATO members, Poland spent the most on defence in 2025—4.3% of GDP, or PLN 166.2 billion. [1] Most of these funds are allocated to the physical components of security, such as weapons, ammunition and military infrastructure. Yet an increasingly large part of modern defence depends on a less visible layer: data, command systems, analytics, cybersecurity and a country’s ability to maintain operational continuity in a digital environment.

“At this scale of investment, it matters not only what Poland invests in, but also how it builds its digital backbone: whether it remains under local jurisdiction, whether it enables independent operations in times of crisis, and whether it strengthens the domestic supplier ecosystem,” says Krzysztof Kaziów, Director of Customer Engineering for Central and Eastern Europe at Google Cloud.

A useful reference point is the recent example of Bulgaria. There, national systems integrator Information Services, working with Google Cloud and using EU funding, is implementing Cybershield—a national AI-based cyber defence shield. The programme is intended to connect 54 government institutions through a federated Security Operations Centre and improve the monitoring of, and response to, cyber threats. From Poland’s perspective, it shows how an EU member state can combine local expertise, European funding and the technologies of a global provider to build cyber-resilience capabilities.

In this context, the question of modernising Poland’s defence should not concern only which systems will be purchased, but also the architecture on which they will operate. As defence shifts towards a software-defined model, data—and the ability to analyse it rapidly, securely and at scale—becomes a strategic asset. The priority is therefore to design a digital backbone that is innovative, operationally resilient and embedded in clear legal and control frameworks.

Sovereignty Is a Choice, Not Isolation

Public debate often reduces the issue to a simple divide: global providers versus locally built solutions. However, the practice of allied countries points to a more nuanced approach. European military leaders, including Admiral Rob Bauer, Chair of the NATO Military Committee, [3] and General Carsten Breuer, Inspector General of the Bundeswehr, [4] have openly highlighted the risks of hasty decoupling from US technologies, which have long formed the software foundation of many military systems. The alternative is a “sovereign-by-design” model that combines access to advanced, scalable technologies with full operational and legal control on the part of the state.

“Digital sovereignty is not about isolating oneself from global innovation. It is about having a real choice and control over where data is processed, who has access to it and which law applies,” says Kaziów. “Moreover, the experience of conflicts in Ukraine and the Persian Gulf region clearly shows that domestic data centres are now priority targets because they are a critical element of national infrastructure. The answer is therefore not to confine everything within the borders of a single country, but to intelligently diversify architecture across the European Economic Area and even globally—while retaining full, independent control over the data itself.”

Digital Sovereignty in Practice

Today’s threat landscape is diverse and requires the creation of diversified digital environments. On the one hand, states face the risk of cyber operations, where air-gapped solutions—completely isolated from the internet—are particularly effective and provide the highest level of cybersecurity. On the other hand, there is also a kinetic risk: a physical attack on a single, centralised data centre could paralyse critical systems. Poland’s closest partners demonstrate that digital sovereignty is not a declaration, but the result of specific architectural choices—from the physical isolation of environments to the way data and supplier relationships are managed.

In the United Kingdom, the emphasis has been placed on full operational control. The Ministry of Defence’s contract with Google Cloud provides for the deployment of an air-gapped environment, physically disconnected from the internet and the public cloud. Data remains under national jurisdiction, while the system supports analytics, AI and the exchange of classified information with allies. At the same time, local capabilities and a domestic supplier ecosystem are being developed.

Germany, meanwhile, is focusing on diversification and architectural resilience. BWI, the Bundeswehr’s IT service provider, is building a private cloud in a multi-cloud model, using Google Cloud Air-Gapped installed in its own data centres. Environments are physically separated according to the sensitivity level of the data, while the lack of connections to external Google systems ensures full operational control and so-called platform survivability—the ability to maintain operations in complete isolation. This approach reduces dependence on a single partner and makes it possible to flexibly select technologies for specific applications.

NATO’s approach, in turn, focuses on interoperability and the practical use of data in operations. The deployment carried out by the NATO Communications and Information Agency at JATEC includes a fully isolated environment with AI tools for analytics and training, while maintaining strict rules on data residency and access control. It is an example of an architecture that combines a high level of security with effective cooperation among Allied countries.

The essence of this approach is clear: sovereignty is now built through architecture and the way it is designed—not through a simplistic choice between “local” and “global” solutions. It depends on real control over the deployment and operational use of technology.

“National security and digital security are now inseparable. A responsible sovereignty architecture relies on different players and complementary capabilities. The key is for the rules of the game to be transparent and independently verifiable, regardless of who provides the service,” says Kaziów.

Poland’s Moment

Poland is now at a point where architectural decisions will begin to translate directly into operational capabilities.

The logic of “local content”, which is becoming increasingly visible in Poland’s industrial policy, now also extends to the digital layer—from infrastructure to integration capabilities. It is not an alternative to global technologies, but rather a framework defining the conditions under which they are implemented.

By drawing on the experience of London, Berlin and Sofia, Poland has an opportunity to build a model that combines operational autonomy with advanced, scalable solutions. The success of this transformation, however, will depend not only on technology choices, but above all on building strong integration capabilities within the public sector and implementing transparent certification and independent audit processes.

In this model, cloud sovereignty—understood as genuine control over architecture rather than merely the location of servers—becomes one of the foundations of an effective defence transformation.

Sources

[1] https://www.pap.pl/en/news/poland-leads-nato-defence-spending-allies-boost-outlays-2025

[2] https://businessinsider.com.pl/gospodarka/kraj-nato-ue-buduje-tarcze-cybernetyczna-ai/3xd6p78

[3] https://www.nato.int/en/news-and-events/events/transcripts/2024/10/24/speech-by-the-chair-of-the-nato-military-committee-admiral-rob-bauer

[4] https://www.youtube.com/watch?v=LLBl-9IOwbk

Check out our other content
Related Articles
The Latest Articles