On-Premises vs. in the Cloud: Making the Switch

Nov 30, 2015 | Cloud

Shoretel

Featured article by Greg Keller, JumpCloud’s Chief Product Officer

The cloud. IT professionals hold differing opinions on it. Regardless of how they feel about it, the cloud is undeniably changing the way organizations operate and the trend is only gaining momentum. There is an appropriate amount of uncertainty as companies make the switch away from on-premises operations, especially by larger organizations that maintain the on-premises tradition in the supposed interest of keeping everything under their direct control. These same organizations often believe the many myths that surround the benefits of keeping everything on-premises. In this article, we’ll debunk some of those myths, including control, security, and cost-effectiveness.

One of the biggest concerns for organizations considering making the transition to the cloud is control. For companies that have largely managed ‘traditional’ on-premises software and infrastructure, there is a myth that cloud-based systems lack control the organization needs; for many companies, that’s a very scary thought. While there are some legitimate concerns with respect to control, they predominantly apply only to the largest organizations in the world.  For a company maintaining its own datacenter and server farm, there still is an ongoing cost center including time and effort to keep it operational. Ultimately, using the cloud the company can deeply control the various components. For some organizations that is critical, if not a mandate (think government or heavily regulated organizations).

Related to considerations of control, some organizations are still interested in building their own software solutions. While bespoke applications may continue to be required to solve edge-case needs and extremely proprietary business problems, SaaS vendors have largely eradicated this need. The advantages to “build vs SaaS” relate to control needs. For instance, IT organizations often cannot specify the exact hardware combinations needed for cloud servers. With SaaS-based applications, you’re at the mercy of the available APIs or what software is being used. Many cloud providers are deepening their levels of control, but it still isn’t complete. The good news is that for most organizations, cloud providers are working hard to give their customers deeper control over their platforms, allowing a much wider array of trusted, specified software components.

Security is perhaps the quickest justification for companies wanting to maintain on-premises infrastructure. The cloud has been notoriously targeted for a lack of security. Startups are building incredible applications but aren’t yet focused on protecting the holes left as a result of continuous deployment of features to customers. The thinking is that if the service and its underlying software, servers and infrastructure are directly accessed via the open Internet, they must be more vulnerable. Having infrastructure behind a personal firewall is better, right? The answer isn’t as clear cut as it might seem, and in many cases security is likely to be better in the cloud where it is supported by a trusted hosting provider who, in many cases, will be more adept at securing infrastructures than an organization.

Most cloud providers spend extensive amounts of time and resources securing their infrastructure, and are often forced into deeper practices for regulatory compliance needs. From the server security to data security to application level security, cloud providers are building layers of security that IT or development organizations oftentimes don’t have the time to develop. There’s more good news: Cloud providers have the benefit of amortizing the cost of their security program across all customers, and further they often have the advantage of being able to recruit topnotch security experts because of the increased challenges, resources and infrastructure available. Unless an organization can match the level of effort that a cloud provider can expend against the security problem, it’s best to stick with the cloud.

Finally, there’s the matter of cost: Are organizations better off financially owning their own infrastructure, or having it hosted or SaaS-based? The common thought process is that cloud infrastructure is less cost-effective than on-premises solutions. This is based on the historical thinking that a capital purchase can be amortized over a long period of time as servers and applications could be used over multiple years in the past. The challenge now is that with growing computer and application demands, IT organizations are upgrading their solutions faster than ever. When upgrades and the quest for additional functionality is factored in, the costs quickly escalate. IT organizations also need to factor in maintenance and management efforts, and production-level staffing needs to ensure uptime and availability.

Comparatively, cloud providers have complex monitoring systems and, arguably, some of the most sophisticated recovery, failover, elasticity, performance and availability mechanisms in place. Internal efforts to maintain this level of constant support are often cost or manpower prohibitive. There is also the literal ‘cost of money’ as a further argument for the benefits of cloud services. Paying-as-you-go versus paying up-front enables organizations to put that money to work rather than tie it up in infrastructure. If all costs are calculated, it is likely that cloud infrastructure will turn out to be more cost effective.

For IT organizations and their executives, the process of moving to the cloud can be challenging, but the outcome is worthwhile. There are a number of variables to consider. While control, security and costs are generally at the top of the list, each organization is different. Each scenario is unique, but there is a very strong case to move to the cloud that will only continue to get stronger.

Keller_Headshot

Greg is JumpCloud’s Chief Product Officer, overseeing the product management team, product vision and go-to-market execution for the company’s Directory-as-a-Service (DaaS) offering. The SaaS-based platform re-imagines Active Directory and LDAP for the cloud era, securely connecting and managing employees, their devices and IT applications.

Top 10 Cybersecurity Stories This Week: FBI Warns FortiBleed Is Locking Admins Out of Their Own Firewalls, Attackers Hijack Three Country-Code Domain Registries to Obtain 12 Google HTTPS Certificates, ShinyHunters Suspect Arrested in Jordan

Top 10 Cybersecurity Stories This Week: FBI Warns FortiBleed Is Locking Admins Out of Their Own Firewalls, Attackers Hijack Three Country-Code Domain Registries to Obtain 12 Google HTTPS Certificates, ShinyHunters Suspect Arrested in Jordan

October 9, 2026 | ITBriefcase.net Why it matters: The FBI and US Secret Service issued a joint advisory on October 6 confirming that the FortiBleed credential-harvesting campaign — which has compromised credentials for 86,644 Fortinet FortiGate firewalls and SSL VPN...

read more
Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more