By Ste Nadin - Chief Architect
May 14, 2026 4 Minute Read
As a global business, where do you run services and hold data?
Well, this used to be a relatively simple answer as it would probably have been wherever your data center was, or more recently the location of your cloud service. Today, the landscape is fractured and complex.
Three critical shifts have driven this complexity and forced a pause or even a reversal in the ‘cloud-first’ transformation:
This convergence of factors has led most enterprises to question their cloud journey. Many have paused their transformation, while some have fully reversed course, repatriating data and services back to local data centers, or moving toward complex multi-cloud and pinned multi-region strategies. The result? A fragmented enterprise hosting landscape that infrastructure, network, and data teams struggle to manage and secure.
Being able to secure data and services in each of these hosting locations has been available for some time, with different vendors offering specific solutions for cloud and / or on-premise solutions.
But do you want to manage a set of different security services for each of your hosting points separately?
As enterprise complexity grows, security teams must ensure that the same policies and capabilities are applied across all data center and cloud positions to maintain a consistent business security posture. Managing this across disparate tools inevitably increases your attack surface.
Crucially, managing policy via traditional cloud-controlled security systems often breaks sovereignty regulations. Storing and transmitting global policy from a cloud location back into geographically restricted data centers or geo-position clouds is a regulatory non-starter. Furthermore, if you rely on the cloud for policy enforcement and decision-making, the associated egress costs will quickly spiral out of control.
So, this leads us to the “hybrid solution.” An opportunity to bring full coverage from your traditional SSE capability across your entire landscape.
My personal view is hybrid in itself is muddying the water, in that this is potentially looking for product vendors to try and expand their traditional cloud services to on-premise or vice versa. But as discussed this could either break the regulations or not be cost effective.
There is also another problem in that not all of these hosting positions are the same and what you need to protect them can be very different and actually need deep experience in how this can be done.
Really we need to think about bringing this together to provide total protection across the enterprise landscape. This shifts the focus from protection at a technical level to achieving business level outcomes, while proving the additional capability that each of the hosting endpoints needs to ensure these outcomes can be met.
Putting all of these together really means you need to be looking for a solution that truly understands the real-world issues that enterprises face rather than a clean theoretical future that will never come.
At Skyhigh Security we have decades of experience of delivering both on-premise and cloud native solutions using rich functional policy. We are constantly driving forward providing options for where services need to operate, while providing license models that recognise your already invested networks.
If you want to find out more, come and have a conversation with us, and find out how we are approaching this to solve the real world enterprise level problems today.
About the Author

Ste is an Enterprise Architect, performing Chief Architect and CTO roles, with almost 30 years real world experience delivering critical operational systems. Believing in a business outcome first approach he has driven success across a number of highly regulated industry sectors. These have included national critical infrastructure, government, healthcare and security. He is recognized as a leading thinker in the industry performing the roles including that of president for SEMAT.inc working for a common understanding of driving best practice design and delivery.
Ste Nadin May 14, 2026
Sarang Warudkar and Stuart Bayliss April 30, 2026
Nick LeBrun April 23, 2026
Stuart Bayliss and Sarang Warudkar April 16, 2026
Thyaga Vasudevan April 3, 2026