Choosing between cloud and on-premise is a policy decision. You must justify it to customers, suppliers, regulators and insurers.
UK GDPR does not require customer data on your own servers. It requires proper security, processor terms and lawful safeguards for restricted transfers.
Cloud vs on-premise: which policy fits? There is no choice that is always safer. Select hosting by workload, controls and recovery needs.
Match each workload to its real risk
Classify each workload separately. Look at data sensitivity, local response needs, application age, recovery targets and your ability to run it safely.
For most UK SMEs, a hybrid approach is practical. Use Software as a Service for daily work. Use cloud hosting for systems that need off-site recovery. Keep on-premises infrastructure only where there is a tested local need. UK GDPR does not require customer data on your own server. It requires suitable security, a proper processor contract and lawful safeguards for restricted international transfers.
Score the system, not the supplier
A workload is one business system. It could be payroll, email, a stock database or a booking platform.
Score each workload from 1 to 5 against five tests. Require director approval where the score is high or personal data is involved.
A supplier name does not remove your duty to assess risk.
Set recovery targets before buying
Turn the assessment into a repeatable approval rule. Do not base it on a supplier preference.
Use weighted criteria in your workload risk assessment. Data sensitivity and regulatory exposure can each count for 30%.
Recovery targets can count for 20%. Latency, local-operation needs and internal operating capability can each count for 10%.
Do not grant automatic cloud approval to high-risk workloads.
A system with sensitive personal data needs closer review. The same applies where recovery is untested or no service owner is named.
Set clear thresholds for each score. Approve standard cloud use below an agreed risk score.
Require security and director sign-off for medium-risk workloads. Require a documented hybrid or on-premises exception for high-risk systems.
Record the score, evidence, approver and next review date. This keeps the decision defensible when the workload changes.
Cloud fits routine, recoverable SME work
Cloud suits collaboration and standard business software. It also suits disaster recovery where your firm controls accounts, permissions and settings.
Shared responsibility has a hard boundary
The shared responsibility model splits duties between you and the provider. The provider protects data centres and the core platform.
Your SME usually remains responsible for multi-factor authentication, access control and permissions. You also own backups, retention and incident response.
Cloud security still needs active management from your business.
Cloud backups need separate testing
💡
You might be interested
An encrypted external drive can hold an offline copy of key business data. It only helps when access is restricted and restoration has been tested.
- It stores a separate copy away from the main cloud account.
- Encryption helps protect data if the drive is lost or stolen.
- It supports a restoration test without relying on one supplier.
View options on Amazon →
Who protects what in a cloud service?
Provider
Data centre, hardware and core platform.
Your SME
Accounts, settings, data, backups and response.
Assess resilience and security as separate issues. Cloud hosting can add storage, processing power or user access quickly.
This can help during seasonal sales, rapid growth or disaster recovery. But a cloud-only design can still fail in daily work.
A site may lose internet access. A provider region may fail, or a critical integration may stop working.
For each important system, decide if staff can work safely offline. Also set connectivity backup needs.
Check whether the service can recover in another region. Check whether an independent backup can restore it.
On-premises systems can support local equipment during a broadband outage. They also need power protection, spare hardware, patching and off-site recovery.
Test the whole service, not only its primary data location.
Keep on-site only for a proven constraint
On-premises infrastructure can be justified for a clear constraint. The workload may need very low delay or depend on local equipment.
It may also be too old to move safely. A legacy system needs proof, not just habit.
Compare the full three-to-five-year cost
Compare costs across 3 to 5 years. Include migration, licences, connectivity, support, staff time and hardware renewal.
Include data egress, recovery tests and downtime too. Do not compare a cloud subscription with one server purchase alone.
| Workload | Usually suitable hosting | Decision test |
| Email and collaboration | SaaS cloud | MFA, export route and admin controls |
| Legacy line-of-business app | Hybrid or on-site exception | Patch plan, isolation and retirement date |
| Customer data recovery copy | Cloud plus separate backup | Restore test within agreed time |
| Machine-control database | Local or hybrid | Safe operation during internet failure |
Use exceptions with an expiry date
For UK GDPR compliance, record more than a supplier claim that data is secure. Identify whether your organisation is the controller.
Also identify whether the cloud supplier acts as a processor. Keep the processor contract with the workload record.
The contract should cover instructions, confidentiality and security measures. It should also cover rights requests, data return or deletion and sub-processors.
Check where primary data and backups are handled. Also check support access and telemetry, as these can involve other locations.
Restricted international transfers need a recorded transfer mechanism. Record any extra safeguards that apply.
Keep this evidence with the workload approval record. Review it when the supplier changes regions, adds a sub-processor or renews its terms.
An exception without a review date often becomes permanent by accident.
Avoid the insurance mistakes that raise risk
Cyber insurance does not make a weak configuration acceptable. Insurers commonly assess MFA, patching, access reviews and tested backups.
Write a one-page approval policy
Each workload must be approved as cloud, on-premises or hybrid. Use data sensitivity, latency, application age, recovery target and operating capability. Cloud services require MFA, least-privilege access and documented processor terms. They also require tested backups and an incident plan. On-premises exceptions require named ownership, patching and isolation where needed. They also need off-site backup and review at least every 12 months.
This choice matters less if your firm uses only standard SaaS applications. That is the case when you control no infrastructure. Focus on configuration, user accounts, supplier contracts and exportable data copies. Also plan how work continues during disruption. Critical health, financial or contract-regulated systems need a technical assessment. This article gives general information, not technology, legal or insurance advice.
A written rule can support an insurance renewal discussion. It also shows customers that your firm has considered each system's risk.
Your questions answered
Is cloud more secure than on-premise?
Cloud can be safer when you manage accounts, permissions, backups and settings properly. A badly configured cloud account can still expose data.
Does UK GDPR require data to stay in the UK?
UK GDPR does not require personal data on your own UK server. Check processor terms, data locations and safeguards for restricted transfers.
Will cloud hosting reduce cyber insurance premiums?
Cloud hosting alone does not guarantee lower premiums. Insurers also assess MFA, backups, patching, access controls and claims history.
Is SaaS enough for a small business?
SaaS is often enough for email, accounting and collaboration. You still need administrator control, supplier terms, exportable data and recovery arrangements.
When should an e-commerce firm keep systems on-site?
Keep systems on-site only where local speed or legacy dependency makes migration unsafe. Retain strong payment, access and recovery controls.
What is the biggest hidden cloud cost?
The largest hidden cost is often migration and support time. This includes data egress, training, specialist help, connectivity and downtime.
How often should a hybrid policy be reviewed?
Review a hybrid policy at least every 12 months. Also review it after major incidents, supplier changes or new sensitive-data workloads.
Put the policy in writing before renewal
A written hybrid policy shows each workload has a reasoned home. It also shows named ownership and minimum cyber security controls.
The essentials:- Choose hosting for each workload, not through one company-wide label.
- Cloud providers protect the platform. Your SME protects access, configuration, data and recovery.
- Compare three-to-five-year costs before approving a server or subscription. Include migration and interruption costs.
- Keep evidence of MFA, backup tests and access reviews. This helps insurers, customers and continuity planning.
Related sources
These articles can help you explore the topic in more depth: