Skip to content
Microsoft 365 & Cloud

Cloud or On-Premises: What Suits SMEs

Cloud or on-premises: six criteria, a decision matrix per workload and a four-step approach that help SMEs settle the server question on the facts.

Published on 4 min read

A server rack behind glass on the left, an open view through the glass front over the city on the right.

Cloud or on-premises is no longer a question of principle for most companies, but a question per workload. Email and collaboration run in the cloud in many businesses, while the ERP system, a file server holding design data or a specialist application with its database stay on the company’s own servers or in a data centre in Germany.

Six criteria per workload

The criteria apply to each individual workload, not to the company as a whole.

  • Load profile: Constant load around the clock favours own hardware that is fully used over its service life. Strongly fluctuating load, such as seasonal business or test environments, favours the cloud.
  • Data sovereignty and sector rules: Personal data, patient and client data and design documents are subject to legal or contractual requirements. Some demand storage in Germany or the EU, some rule out certain providers. These requirements often decide before any technical question.
  • Latency and connectivity: Applications with many small database calls are sensitive to latency. A site without a redundant line should not source business-critical systems exclusively from the cloud.
  • Available IT staff: Own servers require people who apply patches, check backups, replace hardware and can be reached when something fails. Without that capacity, the balance shifts towards the cloud or managed services.
  • Licensing models: Many vendors now offer their software only as a subscription or tie functions to the cloud version. The licensing model can be decisive, regardless of the technology.
  • Dependency and exit: Every decision needs a way back: in which format and with how much effort the data can be retrieved. This applies to cloud providers as much as to a specialist application with a proprietary database on your own server.

How mid-sized companies set themselves up

Most of the mid-sized companies we support run a hybrid model. Microsoft 365 handles email, calendars, Teams, SharePoint and the Office applications.

Specialist applications, ERP systems, file servers with large data volumes and applications with particular data sovereignty requirements run locally or in a German data centre. The foundation is almost always a virtualisation platform. At our customers we operate Citrix Hypervisor, VMware and Hyper-V, depending on history, licensing and high-availability requirements.

WorkloadDecisive criteriaUsual operating model
Email and collaborationUser numbers, mobile work, availabilityCloud (Microsoft 365)
FilesData volume, data sovereignty, external accessHybrid: SharePoint for team documents, local file server for large or sensitive holdings
ERPLicensing model, latency, interfacesLocal or data centre; increasingly cloud where the vendor dictates it
Specialist applicationSector rules, database access, vendor strategyMostly virtualised locally
BackupSeparation from production, recovery timeHybrid: local copy for fast recovery, second copy off site
Speech recognitionData protection, connectivity, user numbersLocal or cloud, depending on the sector

Security in both models

The cloud is not automatically more secure than your own server, and the reverse is equally true. The two models simply distribute responsibility differently.

In the cloud, shared responsibility applies. The provider secures the data centre, hardware and platform. Accounts, permissions, multi-factor authentication, sharing and the backup of your own data remain the company’s responsibility. A file deleted by mistake or encrypted by ransomware is not protected just because it sits in the cloud.

With on-premises operation, the entire responsibility sits in-house: patches for operating system, hypervisor and applications, firewall rules, physical access, backups following the 3-2-1 rule and regular restore tests. Anyone who cannot cover these duties with their own staff hands them to a service provider or moves the workload to the cloud.

A four-step approach

  1. Inventory: List all applications, servers and data holdings with user numbers, data volume, dependencies and licensing status.
  2. Assessment per workload: Check each workload against the six criteria and set an operating model. Sector rules and licensing models first, because they rule out options.
  3. Target picture and sequence: Which systems move first, which stay, which dependencies must be resolved beforehand. An ERP system whose vendor only offers the cloud move next year sets the timetable.
  4. Implementation in stages with a way back: Every migration with a test phase, acceptance and a documented rollback. Switch off the old environment only after successful operation.

Key points

  • The decision is made per workload, not for the company as a whole; sector rules and licensing models rule out options first.
  • Mid-sized companies mostly run hybrid: Microsoft 365 for collaboration, specialist applications and ERP virtualised locally.
  • In both models, security depends on accounts, permissions and backups, not on the location.

The combinations DEVACON operates are shown on the page Cloud, hybrid and on-premises.

Topics Cloud On-premises Hybrid Microsoft 365 Virtualisation

This article comes from the DEVACON blog and was editorially revised for the new website.