Digital sovereignty: how Sopra Steria and VMRay are supporting a major French industrial company
Solution selection has historically been guided by two rationales: the highest-performing and the least expensive option. However, more and more organisations are having to rethink how they operate their critical infrastructure and protect their sensitive data. Decision-making criteria now take a new dimension into account: technological autonomy, namely data hosting and dependency chains.
This paradigm shift is taking place in a tense geopolitical context and amid rising security challenges. Cybersecurity plays a major role here: it is essential for both states and private companies, and is directly impacted by technological innovation. The European cybersecurity market is therefore estimated at €70–75 billion in 2025, representing around a quarter of the global market (European Cybersecurity Mapping, 2026). Gartner confirmed and expanded on these observations as early as 2024: “Between a threat level that never subsides, a massive migration to the cloud, and a persistent talent shortage, cybersecurity has become one of the top priorities for management teams.”
It is in this context that Sopra Steria and VMRay are supporting a major French industrial company in the selection and deployment of a 100% European solution dedicated to malware detection and analysis.
For this project, alignment with compliance and sovereignty requirements was a key criterion in successfully meeting the organisation’s needs. The objective was to reduce dependence on non-European solutions and secure the entire data hosting and processing framework. In addition to standing out clearly through its on-premise hosting capability, VMRay met the high standards of the functional specifications and offered the agility required to address the client’s industrialisation challenges.
A few key figures on this deployment:
- Around 1,000 analyses per month via API
- Around 100 user accounts covering a variety of profiles
Technological sovereignty: yes, but what exactly are we talking about?
The European Commission defines technological sovereignty as Europe’s ability to act independently in the digital world by developing and controlling key technologies, data and infrastructure, while reducing its dependence on third-country suppliers.
The topic has become mainstream: according to a 2025 Docaposte study, 68% of organisations consider sovereignty important or very important in terms of security, with public-sector players being the most likely to attach high importance to it (55%).
In practice, this independence operates on three levels: data — where it is stored, who processes it, and what contractual guarantees actually exist; technology — the level of dependence on non-European components or players subject to extraterritorial legislation; and legal frameworks — applicable law and exposure to disclosure obligations depending on the country.
These questions become particularly sensitive when tools handle suspicious samples, incident artefacts or indicators of compromise. For the most exposed sectors, the challenge is concrete: reducing dependencies and prioritising solutions that operate within a trusted European framework.
An agnostic partner: maintaining a holistic view to better meet organisations’ needs
Sopra Steria takes an agnostic position towards its cybersecurity partners.
“We are agnostic: our role is to propose the solution that meets our client’s needs, including both quality requirements and hosting constraints.” XXX Sopra Steria
This approach is based on business understanding and in-depth knowledge of technical prerequisites.
This neutrality makes it possible to rely on a selected ecosystem of European players — including VMRay, Sekoia, HarfangLab and Glimps — to offer organisations a sovereign European alternative across more than 30% of Sopra Steria’s cybersecurity offerings. In sensitive environments, hosting and compliance frameworks become necessary criteria, on a par with technical performance.
VMRay, or how to make modern malware talk
VMRay is a German company founded in 2013 that offers a sandboxing platform designed for investigation and enrichment. Its approach takes into account the evasion techniques used by a wide range of threats, including the most modern ones. The company is indirectly backed by Sopra Steria through its CVC investment in Brienne IV.[MC3]
Sandboxing consists of executing a suspicious digital item in a controlled environment in order to observe its behaviour and extract insights to better protect against it. The constraints surrounding this mechanism have evolved significantly in recent years. Modern malware actively seeks to detect and bypass sandboxes, using anti-VM techniques, timing attacks or environment checks. SOC teams, meanwhile, no longer have time to sift through lengthy reports: they need actionable results. Integration with existing tools — SIEM, SOAR, APIs and automation workflows — has become just as decisive.
Sovereignty as an architectural criterion, not a slogan
This project reflects a deeper trend: for European players operating in critical segments, sovereignty is becoming a structural requirement in specifications, on a par with performance, cost and ease of integration.
By combining Sopra Steria’s pragmatic, needs-driven integration approach with VMRay’s ability to provide the leading European alternative for sandboxing, it becomes possible to build cybersecurity systems that are robust, industrialised and sovereign.