For years, the security team’s job has been to defend against cyberattacks. New research from Proton suggests that job now needs to extend to a very different kind of threat: the risk that a foreign government orders a US technology provider to cut a business off entirely.
A study of 1,500 business decision-makers across the UK, France and Germany, commissioned by Proton and fielded by Toluna, found that 73.9% of respondents are at least somewhat concerned about a government-imposed “kill switch” cutting off access to their US technology providers. Critically, that figure is now statistically indistinguishable from concern about ransomware and cyberattacks, which stands at 74.9%. For security teams, the two threats are converging on the same risk register.
A single point of failure that security teams can’t patch
Unlike a conventional breach, a kill switch scenario cannot be defended against with endpoint protection or patch management. It is a jurisdictional risk baked into the vendor relationship itself. The study found that more than half of businesses (54.5%) could operate for a single business day or less before being forced to shut down entirely if they lost access to their cloud and digital services. That leaves security and continuity teams with almost no window to fail over before the business itself is at risk.
The financial exposure scales sharply with organisation size. Among large businesses, 44.8% expect to lose more than €50,000 from a single day of downtime, and 28.7%, more than one in four, expect losses to exceed €100,000.
Readiness lags behind awareness
Awareness of the risk has not translated into resilience. Only 44% of businesses surveyed have a continuity plan that is both documented and regularly tested against realistic scenarios; 36% have a plan that exists but is never tested, and 13% rely on something informal and undocumented. Despite this gap, 67.8% of businesses say they would switch providers if a kill switch blocked their access, meaning most organisations would be attempting an emergency migration under pressure, rather than executing a rehearsed plan.
Businesses have also invested unevenly across their stack. Email (33.6%) and cloud file storage (28.3%) attract the most continuity investment, but other commonly used services, from collaboration tools to identity and access management, lag well behind, leaving gaps that a determined adversary, or a single geopolitical decision, could exploit.
“The kill switch is no longer an abstract geopolitical concern but a business continuity crisis,” said Raphaël Auphan, Chief Operating Officer at Proton. “The study captures a clear shift in how European businesses perceive operational risk. The fact that concern about a government-imposed kill switch is virtually indistinguishable from concern about ransomware tells something significant: geopolitical risk applied to digital dependence is no longer a boardroom abstraction. It is joining the same threat register as criminal attacks, with the same sense of urgency and the same expectation that it could materialise without warning.”
Vendor diversification as a control
Proton, which recently launched a dedicated business continuity solution, argues that traditional secondary-vendor redundancy does not solve a jurisdictional problem: if the backup provider is also US-owned, it remains exposed to the same regulatory or executive action. Its approach instead pre-provisions dormant accounts on independent European infrastructure that can be activated the moment a primary provider becomes unavailable, giving security and IT teams a documented failover path that does not depend on the affected vendor.

