Orphaned Access: The Silent Cybersecurity Gap
Benedikt Langer
5 Min. Read Time Service accounts, API keys, and AI agents often outnumber human accounts. Many of these ...
4 min. read
More and more companies are moving workloads back from the public cloud into their own data centers or private cloud environments. The trend is called cloud repatriation and runs counter to the previous cloud-first mantra. For CIOs, this is not a step backward but a sign of strategic maturity: those who understand which workloads belong where can optimize costs, compliance and control at the same time.
Cloud-first was the paradigm of the past decade. Companies migrated workloads to the public cloud on a massive scale, driven by the promise of flexibility, scalability and the desire not to have to deal with hardware. But after years of use, the downsides are becoming clear: costs that rise unchecked. Vendor lock-in that makes switching difficult. Compliance requirements that are hard to reconcile with US-controlled hyperscalers.
In one study, IDC found that 71 percent of companies have already moved workloads back from the public cloud. The reasons vary: cost optimization comes first, followed by data sovereignty and performance requirements. Especially in the DACH region, the regulatory landscape is playing an increasingly important role: NIS2, DORA and the EU AI Act impose requirements for data control that cannot be met with certain cloud configurations.
The most prominent case is 37signals, the company behind Basecamp and HEY. Founder David Heinemeier Hansson documented the move from AWS to owned hardware and reported projected savings of 7 million dollars over five years. The case cannot be transferred one-to-one to Germany’s Mittelstand, but it illustrates the principle: from a certain scale and level of workload predictability onward, owned infrastructure is more economical than renting cloud capacity.
“The decision to bring workloads back from the public cloud is, in most cases, a cost decision. Companies with predictable workloads can save 30 to 50 percent on their own infrastructure.”
IDG/Supermicro Cloud Survey (2024)
Driver 1: Cost transparency after years of cloud use. Many companies only calculated the actual total cost of ownership after several years of cloud use. Egress costs, storage costs, premium support, and the effort required for cloud architects add up. According to Flexera, average cloud waste is 29 percent. For predictable workloads with stable load, owned infrastructure is often 30 to 50 percent cheaper than the equivalent cloud configuration. The break-even point depends on size, but is typically around 100 to 200 virtual machines or an equivalent container load.
Driver 2: Regulatory requirements for data sovereignty. The EU Data Act, NIS2, and the EU AI Act are tightening the requirements for control over data. The US CLOUD Act allows US authorities to access data held by US companies, regardless of where the servers are located. An EU data center operated by AWS or Microsoft does not automatically protect against this access. For sensitive data in regulated industries, this can mean: sovereign cloud or owned infrastructure, tertium non datur.
Driver 3: Performance and latency. Certain workloads benefit from physical proximity to the data source. Industrial IoT applications, real-time analytics in manufacturing, and certain AI inference workloads require latencies below 10 milliseconds, which cloud architectures cannot always guarantee. Edge computing and on-premises infrastructure offer advantages here that cannot be achieved with cloud solutions.
Cloud repatriation does not mean that all workloads come back. CIOs need a nuanced framework that assesses each workload individually. The decision depends on four factors: cost, compliance, performance, and scalability.
Sources: IDC 2025, Flexera State of Cloud 2026, 37signals Blog
Cloud remains the right choice for: AI training with GPU bursts, global applications with variable traffic, disaster recovery and backup, development and test environments, SaaS applications with an established ecosystem. Here, the benefits of scalability and flexibility outweigh the cost premium.
Repatriation pays off for: Stable production workloads with predictable load, databases with high I/O requirements, sensitive data subject to regulatory requirements in DACH, legacy applications that would have to be rebuilt cloud-natively, HPC workloads with constant GPU utilization above 70 percent. These workloads benefit from lower unit costs and full data control.
The hybrid approach as the best path: Most companies will end up with a hybrid model. Regulatory-critical and cost-intensive workloads on owned or sovereign infrastructure, variable and global workloads in the public cloud. The challenge lies not in the decision, but in execution: network connectivity, data synchronization, and unified management across both worlds require investments in platform engineering and multi-cloud expertise.
The biggest challenge is communication. “We are moving back from the cloud” sounds like a step backward. CIOs need to position the message as strategic maturity: “We are optimizing our IT architecture based on four years of cloud experience. Workloads that are more expensive in the cloud than on our own infrastructure and do not use any cloud-specific advantages are being brought back. That saves X euros per year with the same or better compliance.”
The business case must be specific: a TCO comparison per workload over 3 to 5 years, compliance improvements through data sovereignty, performance gains for latency-sensitive applications, and avoided risks through reduced vendor lock-in. With these figures, cloud repatriation becomes the logical consequence of a data-driven decision, not an admission of a failed strategy.
Cloud repatriation refers to moving workloads from the public cloud back into an organization’s own data centers, private cloud environments, or colocation sites. The trend is driven by cost optimization, regulatory requirements, and performance considerations.
Stable production workloads with predictable load, databases with high I/O requirements, regulatory-sensitive data, and legacy applications benefit the most. The break-even point is typically around 100 to 200 virtual machines or an equivalent container load.
Depending on the workload profile, companies report cost savings of 30 to 50 percent for predictable workloads. The most prominent example is 37signals, with projected savings of 7 million dollars over five years. Actual savings depend on the specific workload structure.
No. Repatriation is not an anti-cloud statement, but a sign of strategic maturity. Most companies end up with a hybrid model: regulatory-critical and cost-intensive workloads on their own infrastructure, variable and global workloads in the public cloud.
The biggest risks are the initial investment required for owned infrastructure, the need for specialist staff to operate it, and the complexity of a hybrid architecture. CIOs should start with a TCO analysis covering at least three years before making the decision.
Title image source: Brett Sayles / Pexels