State of the Industry: Cloud vs. On-Premise
Never thought we’d hear support for moving off the cloud and back on-premise but the subject has surfaced a lot lately and it’s important to understand why. In this article, we’ll explore some of the factors that are driving the shift in strategy and some ways to decide which way you should go:
Cost realization: Cloud economics often fell short of projections due to egress fees, security tooling costs, and the inability to fully decommission legacy data centers.
Security and control: Some agencies prefer direct physical and administrative control that exists with on-premise infrastructure, especially for intelligence, defense, and law enforcement workloads with elevated supply chain and insider threat concerns.
Data sovereignty: Classified and sensitive compartmented information often can’t leave government-controlled facilities, and managing hybrid classified/unclassified cloud environments proved more complex than expected.
Vendor lock-in: Agencies that adopted proprietary cloud services found migration and (in most cases, necessary) multi-cloud strategies costly and technically challenging.
Performance and latency: Tactical edge and real-time processing applications often can’t tolerate the network dependencies that cloud introduces.
In our work at Andrew Morgan, we’re seeing a clear pattern emerge. Both current and prospective client organizations aren’t abandoning cloud rather they’re optimizing their approach. The typical pattern involves hybrid architectures that keep variable, development, and collaborative workloads in the cloud while bringing predictable, sensitive, or cost-heavy operations back on-premise. This represents a maturing cloud strategy, a healthy correction based on our real operational experience rather than a wholesale shift in philosophy. Below are a few stats regarding the subject:
- “86% of CIOs planned to move some public cloud workloads back to private cloud or on-premises” [Barclays CIO Survey Q4 2024]
- “About 80% of respondents expected to see some level of repatriation of compute and storage resources in the next 12 months” [IDC June 2024 Report: “Assessing the Scale of Workload Repatriation”]
- “Only about 8% of organizations are moving their ENTIRE workloads off the cloud” [IDC October 2024 Survey]
Most organizations are landing on hybrid approaches enabling portability, maintaining scalable architectures in the cloud, and developing suitable workloads in the cloud while repatriating stable, sensitive, or cost-inefficient ones. We see this as a bit of correction as opposed to a full shift. Teams must remain focused on the realities of their workloads by adopting the following practices for determining their path to success:
Workload characteristics matter most: Favor cloud for variable, unpredictable, high intensity (AI), or rapidly evolving applications. Favor on-premise for steady-state systems running at consistent capacity.
True cost modeling requires rigor: Model total cost of ownership over 5-7 years including egress, security tooling, training, and on-premise refresh cycles in addition tocompute, egress, and storage.
Data sensitivity and compliance requirements should drive placement: Map each workload to its classification and regulatory requirements, then align with acceptable hosting environments using a clear decision matrix.
Evaluate mission criticality and resilience needs independently: Consider whether disconnected operations, geographic redundancy, or independence from commercial networks matters more for each system.
Consider your workforce realistically: Match infrastructure decisions to your actual ability to recruit, retain, afford, and train the talent needed to operate it effectively.
Adopt a workload decision framework: Score individual applications against weighted criteria rather than making blanket organizational commitments to either model.
Pilot and measure before committing: Run instrumented pilots to gather real cost and performance data rather than relying on vendor projections or theoretical models.
Contact Andrew Morgan to discuss an architecture that supports the freedom to select the most secure, flexible, and cost effective platform while maintaining the responsiveness and preventing vendor lock-in.


