Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - On-Premise Or In The Cloud? Choosing The Most Suitable Location For Applications In A Hybrid Environment
Articles

On-Premise Or In The Cloud? Choosing The Most Suitable Location For Applications In A Hybrid Environment

ISBuzz TeamBy ISBuzz TeamJuly 24, 2017Updated:July 24, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cloud App Data Loss Prevention
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Asher Benbenisty, Director of Product Marketing at AlgoSec examines current cloud adoption trends and how organizations can select the most suitable locations for their applications

 With cloud infrastructures expected to outstrip on-premise networks by 2020, many have anticipated that the move to the cloud would become a standardized, linear journey for enterprises.  Organizations would start by migrating specific business applications to the cloud, such as their email, before moving increasing amounts of their network infrastructure into virtualised environments and thus using a hybrid of on-premise and cloud networks.  Eventually, it was envisaged, their entire IT infrastructure would be run in the cloud, boosting efficiency, scalability, agility and flexibility.

On the surface, it may appear that this prediction is being realized; that organizations’ cloud adoption maturity has reached the point where a hybrid environment is no longer necessary, and their entire IT infrastructure can be migrated to the cloud.

However, the reality is starkly different.  Indeed, the evidence shows that the hybrid environment has not disappeared.

For example, while companies such as Dropbox, Groupon and Twitter all made strategic decisions from their inception to utilize only cloud infrastructures, they have ultimately found greater savings and benefits by combining both cloud and on-premise solutions, signalling that the hybrid environment will be here to stay for the foreseeable future.  As such, organizations will need to continue to maintain network security across both their cloud and on-premise infrastructures.

Understanding the best location for each application

So how should organizations approach managing the security of their increasingly hybrid environments?

A fundamental prerequisite to answering this question is to determine from the outset whether the security and compliance requirements for a given business application are better served in the cloud, or in an on-premise environment.  Here are four key pointers to help guide that decision.

Applications that store personal information data

Business applications that hold sensitive data, such as personal identifiable information for customers, are probably more suited for on-premise deployments.  In most instances, for personal information, there are many data privacy laws that govern where data can be stored when the information is collected, processed or communicated.   Over 80 countries and independent territories have adopted comprehensive data protection laws, so it is essential to check and verify what data the application processes, and what is allowed from a legal perspective before moving it to a cloud environment.

Applications subject to strict regulation

If the application, or the data it processes, is subject to regulatory oversight under compliance regimes such as HIPAA or PCI, then there is a clear need to understand the security compliance status of that application, and if moving it to the cloud will risk a compliance violation.  For example, HIPAA requires accountability practices on all Local Area Networks, Wide Area Networks, and for users accessing the network remotely through a Virtual Private Network (VPN).   If the application needs to be compliant with PCI, you will need to have a firewall at each Internet connection the application uses, and between any network demilitarized zone and the internal network zone.  Applications under this regulation, and others, are not ideal candidates for migration to the cloud.

Application already exposed to the internet

In contrast, if there are already parts of the application that are exposed to the internet, such as a web server, the application may well be suitable for migration to the cloud.  These applications should already have strong security implemented, and when moving the application to the cloud, this will ensure that the security of both the server and internal network is maintained.

 Network segmentation as an indicator

Finally, if you manage your network segmentation correctly, the servers and applications that reside in the least segregated zones may be suitable for migration to the cloud. For instance, the applications and servers that are in a zone with a single firewall are good candidates to be moved.  In contrast, those zones that are highly protected and reside behind multiple firewalls should stay in your own on-premise data center so they can be robustly secured.

With hybrid cloud environments here for the foreseeable future, the complexity of ensuring that security is maintained throughout every application migration will remain challenging. However, by identifying from the outset which applications are best suited for cloud deployments, and which should remain on-premise, organizations will be able to bring more clarity to their cloud security strategies – and improve their security posture in the process.

[su_box title=”About Asher Benbenisty” style=”noise” box_color=”#336588″][short_info id=’102951′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}