メインコンテンツへスキップ
ブログへ戻る 業界の視点

Work is Hybrid. Why Are You Paying Double for a Cloud Tax on the Office?

By Mike Smart - Director of Product Marketing

September 24, 2026 3 Minute Read

Let’s be honest about where workforce security (i.e. the SSE market) got off track. A few years ago, the default consensus was simple: move every application to the cloud, route every byte of user traffic through a vendor’s cloud PoP, and add Zero Trust as the icing on the cake. That was a rational strategy when the entire workforce went remote overnight.

The operating environment has fundamentally shifted.

Employees are back in physical offices. Workloads, sensitive data repositories, and increasingly, private AI infrastructure are being relocated back into private networks and local data centers. Gallup’s May 2026 Hybrid Work Indicator shows that 52% of U.S. employees with remote-capable jobs work in a hybrid arrangement and another 22% work on-site. In other words, nearly three-quarters spend at least some of their working time on-site. (Gallup, Hybrid Work Indicator, May 2026).

Critical applications, sensitive data repositories, and increasingly private AI infrastructure still span cloud, private networks, and local data centers. Organizations are doing this for very practical reasons: to drive cost savings, improve performance, and regain data privacy, sovereign control too.

Yet, many cloud-only security vendors are still asking enterprises to hairpin local office traffic out to a cloud PoP just to route it right back to these local applications, AI infrastructure or data stores.

Routing local traffic through the cloud forces you to pay premium cloud-inspection rates for data that never needed to leave your building. If your data and your AI workloads are local, your security enforcement should be local too.

Zero Trust is a policy principle, not a geographic ball and chain. True Zero Trust means applying the exact same enterprise-grade data protection, browser controls, and access policies consistently—whether a user is sitting at a desk in headquarters, working in a branch office, or logging in remotely. Security needs to adapt to your business architecture, not force your network to adapt to a vendor’s cloud.

This brings us to the elephant in the room: cost.

Enterprises are paying a cloud tax. Paying maximum cloud rates to inspect 100% of your traffic—even when workers are sitting inside your corporate network—is an obsolete billing model. You shouldn’t pay a highway toll for a road you aren’t driving on.

Fairness in security vendor pricing means location-aware, adaptable economics. When traffic stays on-premises, local enforcement engines should handle the load, eliminating unnecessary cloud security transit hops (i.e. “hairpinning”).The more local office traffic a company routes through a cloud security service for inspection, the more it pays cloud-delivery economics for traffic that could be enforced locally. If you don’t use your cloud service, you shouldn’t have to pay for it! – That operational efficiency should be passed directly back to you, offering a realistic path to cut Cloud Security OPEX as much as 50%.

It is time to stop accepting the false choice between modern Zero Trust and local control. You should be able to have your SSE cake and eat it, paying a fair price at the same time.

The implications reach beyond the network team.For the CISO, it means consistent Zero Trust and data protection across cloud and local environments; for the CIO, an architecture that fits the company’s applications, infrastructure, and workforce; and for the CFO, a way to reduce structural security cost without cutting capability.

Hear the CISO, CIO, and CFO perspectives in our upcoming webinar, where we compare cloud-only SSE, legacy dual-stack hybrid, and a unified Hybrid Mesh SSE approach—and how each affects operating expenses, security, operations, performance. Find out how Skyhigh Security’s Hybrid Mesh SSE is rewriting the rule book to enable you to Put Security Where Work Happens—And Pay Fairly For It!

著者について

Mike Smart

Director of Product Marketing

Mike is Director of Product Marketing at Skyhigh Security and brings 30 years of experience in the technology industry, with most of his career spent in product marketing at leading cybersecurity companies including ExtraHop, Cybereason, Forcepoint, Symantec and McAfee. At Cybereason, he received an MVP award for a sales program that helped accelerate pipeline generation and deal velocity.

ブログへ戻る

トレンドブログ

業界の視点

Work is Hybrid. Why Are You Paying Double for a Cloud Tax on the Office?

Mike Smart September 24, 2026

業界の視点

We Can’t Stop the AI Race. We Can Make It Safer and More Secure.

Thyaga Vasudevan September 15, 2026

業界の視点

AI Is Changing Your Data Risk. DSPM Puts You Back in Control.

Megha Shukla September 4, 2026

業界の視点

Why Customers Love Mowgli: The IKEA Effect in Cybersecurity

Thyaga Vasudevan August 13, 2026