ema-logo-secondary-c

Cybersecurity Awesomeness Podcast Recap - Episode 113: On Premise vs. Cloud vs. SaaS

Jun 23, 2025 8:48:17 AM

Welcome to the recap of the Enterprise Management Associates (EMA) Cybersecurity Awesomeness (CSA) Podcast. Hosted by Chris Steffen, Vice President of Research and Ken Buckler, Research Director at EMA, the CSA Podcast covers a wide range of cybersecurity topics, from cyber workforce talent shortages to cyber threat intelligence, to current events in technology and security. This short, laidback podcast is for listeners of all skill levels and backgrounds.

In today's rapidly evolving IT landscape, the decision on whether to keep workloads on-premises or move them to the cloud has sparked renewed debate among IT practitioners and decision-makers. The latest episode of the Cybersecurity Awesomeness Podcast addresses this very topic, featuring host Chris Steffen and guest Ken Buckler as they explore the complexities surrounding this critical conversation. As enterprises navigate the maze of technological options available, from on-premises setups to various cloud models—including hybrid systems and SaaS applications—understanding the implications for security and operational efficiency becomes paramount.

Traditionally, organizations moved from an on-premises approach to leveraging hosted solutions and eventually to embracing the cloud. Perceived cost efficiencies, agility in deployments, and the allure of enhanced collaboration tools largely drove this transition. However, the ground is shifting once again, suggesting that a significant percentage of organizations are reassessing their strategies. As Steffen and Buckler share, terms like "repatriation" have emerged—representing a return to on-premises environments for certain workloads. This shift can often be attributed to compliance requirements, security concerns, the desire for greater control over sensitive data, and other factors.

As they discuss the recent trends in the industry, Ken notes an interesting uptick in Google search patterns around on-prem hosting, reflecting an increasing curiosity about reverting to traditional infrastructure. The statistics suggest that a year-on-year shift is indeed occurring; many organizations now find themselves adopting a more balanced hybrid approach between on-prem and cloud-based solutions. In a world where regulatory scrutiny is relentless, a heightened focus on data location, protection, and reliability led enterprises to reconsider the suitability of their cloud deployments.

The podcast delves into essential best practices for identifying which workloads may be better suited to cloud versus on-premises settings. For instance, workloads with stringent security and compliance demands—such as those handled within financial institutions—may necessitate a return to local infrastructure. Steffen shares insights from his extensive experience in managing sensitive environments, noting that traditional on-prem setups can often harbor levels of reliability and uptime that cloud providers might not guarantee. As the two hosts dive deeper, they address the complexities of cloud security, often viewed as a more daunting challenge than anticipated.

Furthermore, the podcast discusses the role of SaaS applications as a middle-ground option. Buckler points out that SaaS solutions can alleviate the burdens of managing infrastructure while still delivering secure and efficient services for routine tasks. However, he also cautions that organizations must remain vigilant, as cloud misconfigurations can lead to significant security breaches—a reminder that the human element in cloud security should never be underestimated.

As our digital landscape continues to evolve, the conversation around the relevance of on-premises versus cloud solutions is sure to continue. For IT practitioners and decision-makers, understanding the nuances behind these choices is crucial for shaping an effective technology strategy that aligns with organizational goals and regulatory landscapes.

To dive deeper into these pressing issues and gain further insights from Chris Steffen and Ken Buckler, we invite you to listen to the full episode of the Cybersecurity Awesomeness Podcast. Your feedback and thoughts are vital to continue the conversation, so don’t hesitate to reach out. For more resources and expert analysis, visit us at www.enterprisemanagement.com. Engage with this evolving topic and empower your organization to make informed decisions in the realm of cybersecurity and IT strategy.

 

Chris Steffen & Ken Buckler

Written by Chris Steffen & Ken Buckler

Christopher Steffen, CISSP, CISA, is the vice president of research at EMA, covering information security, risk, and compliance management. Before EMA, he served as the CIO for a financial services firm, focusing on FedRAMP compliance and security. He has also served in executive and leadership roles in numerous industry verticals. Steffen has presented at numerous industry conferences and has been interviewed by multiple online and print media sources. Steffen holds over a dozen technical certifications, including CISSP and CISA.

Kenneth Buckler, CASP, is a research director of information security/risk and compliance management for Enterprise Management Associates, a leading industry analyst and consulting firm that provides deep insight across the full spectrum of IT and data management technologies. Before EMA, he supported a Federal agency’s Enterprise Visibility program, providing security insights and compliance trending for the agency’s national network of computers and devices. He has also served in technical hands-on roles across multiple agencies in the Federal cyber security space and has published three Cyber Security books. Ken holds multiple technical certifications, including CompTIA’s Advanced Security Practitioner (CASP) certification.

  • There are no suggestions because the search field is empty.

Lists by Topic

see all

Posts by Topic

see all

Recent Posts