The federal government is currently testing whether it can do without Microsoft. But the underlying question applies to every company.

The Trigger: A “Kill Switch” That Nobody Wants


This week, Daniel Markwalder, the Federal Council’s delegate for digital transformation, explained candidly in an SRF interview why the federal administration has reached a point that many companies have yet to face: It is testing the switch to open-source alternatives to Microsoft with 3,000 employees. The reason is not primarily cost savings or a matter of principle, but a very concrete risk that Markwalder calls the “kill switch”: Access to the administration’s own data could be blocked, for technical or political reasons.

Why This Is More Than Just a Microsoft Issue

What applies to the federal government essentially applies to any company that works with ChatGPT, Microsoft 365, Salesforce, or Google Workspace on a daily basis. Microsoft is merely the most prominent example here—not the actual issue.

The real question is: Who truly has legal, technical, and operational control over our most important data?

Could you answer this question for your company off the top of your head, in five minutes?

Lively Discussions at the tfz Network Breakfast

This is exactly where things got interesting last Friday at our tfz Network Breakfast. We had expected to discuss a technical and legal topic. Instead, it turned into one of the liveliest discussions we’ve ever had in this group.

In practice, opinions and attitudes on the subject vary widely: Some see no immediate risk as long as the server is located in Europe. Others have realized that this very assumption is the problem. After all, the physical location of the server is not legally decisive. What matters is which jurisdiction the provider is subject to.

The Technical Perspective: Not All Cloud Services Are Created Equal

Gerald Dürr (Safe Swiss Cloud) explained how risk varies depending on the service model: IaaS, SaaS, and AI services are governed by entirely different rules. His key message: Regardless of a company’s size, it’s worth actually reading your contract terms—not just accepting them.

The Legal Perspective: Responsibility Cannot Be Outsourced

 

Nicole Beranek Zanon (HÄRTING Attorneys at Law) made it clear that data sovereignty is not a one-time decision, but rather a matter of ongoing governance: Before a SaaS or AI tool is approved, the data class, the actual data path, and effective controls must align.


Furthermore, responsibility always remains with the company itself, regardless of how many providers are involved.

What Is Technically Possible

Technically speaking, there is actually more leeway than many SMEs assume. Open-source operating systems like Linux, for example, offer extensive options for self-management: from complete transparency of network traffic to the isolation of individual applications in containers, all the way to strong, system-integrated encryption.

This does not automatically make open-source solutions the only correct answer, but it does make them one of several viable options, alongside Swiss cloud providers or carefully crafted contracts with existing providers.

Conclusion: It’s Not an All-or-Nothing Situation

The good news remains: Digital sovereignty is not an all-or-nothing decision, nor is it a luxury reserved for large corporations or the federal government. It begins with a willingness to take an honest look at one’s own starting point.