The return of on-premises cybersecurity solutions: a long-term trend?
On-premises?
The term « On-premises »refers to solutions hosted locally on the company’s own servers and operated by the company itself, as opposed to SaaS services, where the solutions are hosted on separate infrastructure and operated by the software provider. In the case of SaaS, it is the software provider’s responsibility to ensure the maintenance, operation and security of the systems that enable the applications to run.
The case for a return to on-premises solutions
Argument No. 1: «Since nobody can serve you better than yourself, let’s do it ourselves»
Companies wish to retain full control over their most sensitive data to avoid the risks of data breaches and regulatory non-compliance. In Europe, the proliferation of data regulations (NIS2, DORA, GDPR, CRA, AI Act, etc.) requires organisations to «control» their data and therefore to invest significant resources to ensure a high level of the so-called DICT (Availability, Integrity, Confidentiality and Traceability).
Argument No. 2: «There are some risks that simply cannot be delegated!»
By hosting cybersecurity solutions in-house, organisations believe they can better protect their assets against external threats. Reliance on SaaS service providers can lead to vulnerabilities, such as exposure to supply chain attacks via vulnerabilities in third-party software vendors. Adopting an on-premises solution enables organisations to control their risk of compromise.
Argument No. 3: «If there’s a glitch, at least we’ll know about it (in theory… normally…)»
Hosting solutions in-house offers a twofold benefit in terms of monitoring by the SOC: the organisation has control over both the operational infrastructure (the server layer) and the application’s behaviour (the software layer), and therefore has a broader scope for monitoring.
Argument No. 4: «We’ll end up doing something with it eventually, so we might as well have all the data to hand»
One of the major challenges facing SaaS solutions is the collection and management of logs. In the event of an incident, it can be more difficult to gain a comprehensive overview of events in a cloud environment. With an on-premises solution, the collection, archiving and analysis of logs are simplified, enabling a faster response and better traceability of attacks.
Argument No. 5: «The day we decide to stop, we’ll know exactly what we’re keeping»
Another major advantage of returning to on-premises solutions is the ability to better control data reversibility. If a company wishes to migrate to another service provider or change its infrastructure, managing data is much easier in-house than with SaaS solutions, where dependence on the provider can complicate the retrieval or transfer of data.
A step backwards?
The return to on-premises solutions also brings back into focus the drawbacks which, a few years ago, had accelerated the move in the opposite direction.
- Integration costs: the installation and maintenance of on-premises solutions require significant investment in hardware and qualified staff.
- Full responsibility: organisations are once again responsible for the proper management of their applications and for updating and securing their systems, with significantly more limited support from the software vendor.
- Complex updates: unlike SaaS solutions, which benefit from continuous and automatic updates, the on-premises model often requires the software vendor or provider to be granted temporary access in order to carry out updates. This can introduce latency and complexity, particularly in the case of urgent security updates.
Conclusion
The shift back to on-premises cybersecurity reflects a desire among organisations to strengthen their control over their data and infrastructure. Control over security, management of supply chain attack risks, ease of log collection and greater data reversibility are key elements of this trend. However, this approach presents challenges, particularly in terms of costs, update management and liability. It is therefore essential to carefully assess the specific needs of each organisation before deciding between an on-premises or cloud-based solution.