Security & resilience

Cloud or Local: The Pros and Cyber Security Considerations

Yopla3 min read

Choosing where your systems run affects everyday work as well as security. It changes how colleagues access information, how you recover from disruption, and which responsibilities sit with your team or a provider.

Where should the work live?

Illustrative concept: Cloud / Local / Responsibility. Not a measured result.

Our original article compared cloud and local computing. The useful question is still practical: which arrangement fits this service, its information and the people who depend on it?

Start with the service you need to run

Before choosing an architecture, describe the work. Who needs access? From where? How long could the organisation manage without it? What information does it hold, and what would happen if that information were lost or exposed?

Then look at the team's capacity to operate it. Owning equipment gives you decisions to make and work to do. Outsourcing part of a service changes those responsibilities, but you still need to understand the arrangement.

Apply it to your work

Compare the service arrangement, not just its location

  1. Cloud service

    Check connectivity, supplier responsibilities, access and recovery.

  2. Local system

    Check equipment, updates, skills, access and recovery.

For either option: compare the whole cost and who owns each responsibility.

Illustrative comparison; security depends on the arrangement and how it is maintained.

What cloud services can offer

A suitable cloud service can make shared access easier and reduce the amount of infrastructure your organisation has to maintain. Depending on the service, the provider may manage hardware, operating systems, application updates or several of those layers.

The division matters. The NCSC's shared responsibility guidance explains that responsibilities vary with the service. Customers still need to choose a service that meets their security needs, configure it securely and decide what data to store in it.

For each option, ask what the provider manages and what remains yours. Make sure someone owns access reviews, account removal, configuration and incident coordination. A subscription does not answer those questions for you.

Where local systems may fit

Some workloads have specialist equipment, integration, performance or connectivity requirements that make a local component useful. Test those requirements rather than assuming that everything needs to move together.

Be equally clear about the operational work: maintenance, updates, physical protection, replacement equipment and recovery arrangements. Who will do it, and who can cover when they are unavailable?

Local storage alone is not proof that information is appropriately protected. Likewise, a cloud label does not establish that a service meets every requirement. Review the actual controls and contractual commitments for the information and activity involved.

Compare the whole arrangement

Use a short checklist for each candidate:

  • Access: how will people sign in, and how will unnecessary access be removed?
  • Responsibility: who manages each part of the service, including security updates?
  • Recovery: what can be restored, by whom, and how have you tested it?
  • Availability: what happens during an internet, supplier or local equipment outage?
  • Data: where is it stored, who can access it, and how can it be exported?
  • Cost: what will support, usage, migration and eventual replacement add to the headline price?

Avoid assuming that cloud always costs less, local always offers better control, or a hybrid arrangement automatically gives you the best of both. Each needs to be assessed against the same requirements.

Make the decision manageable

Start with one service. Document why the chosen arrangement fits, what the team is responsible for and how you will know it is working. Test the important failure scenarios before relying on it.

If you are weighing up a move, talk to Yopla about the work, information and dependencies that need to be understood first.

Originally published by Yopla in 2024. Refreshed for the current library.

All insights

We use analytics cookies to improve this site. Cookie policy