I want to start with something that will make a few cloud vendors wince. Every ransomware recovery I have personally worked on over the last several years had one thing in common: the clients who leaned hardest into a cloud-only strategy were the ones who hurt the most when the attack hit. Not because the cloud failed them in the way you would expect, but because they had quietly traded away options they did not know they would need.
The pitch for the last decade has been simple. Move everything to the cloud. Sunset your servers. Stop buying hardware. Let somebody else worry about patching, power, and cooling. And for a lot of workloads, that pitch holds up just fine. But “cloud-only” as a strategy, as the answer for every workload, every backup, every piece of infrastructure your business depends on, is a decision I watch burn businesses in real time.
In 2026, the smart posture is hybrid. Not because hybrid is trendy, but because the companies I see recover fastest and cleanest from major incidents are the ones who kept a physical foothold somewhere.
The Moment Cloud-Only Breaks: Ransomware
Let me tell you about an asphalt company here in our region. Good operation. They had done the “right” things on paper. Their backups were off site. They had a different account name for the offsite backup system. They even had dissimilar authentication on the offsite tunnel.
But they reused the same administrator password for that offsite backup account. The attackers got into the main environment, pulled credentials, enumerated account names, found one called “backup,” and tried every password they had harvested. One of them worked. They destroyed the offsite backups first, then kicked off encryption on the production network. That company could not recover. Their “offsite” copy was functionally the same network as far as the attacker was concerned.
This is the exact failure mode I see with pure cloud-only strategies. If your cloud backups sit on the same identity provider, the same admin credentials, or the same VPN tunnel as your production environment, you do not have a backup. You have a second copy of the blast radius. I covered this pattern in more detail in our piece on simple backup and recovery plans every small business needs, and the principle is simple: backups must be separated by network, by authentication, and by encryption keys. Not just by street address.
A cloud-only architecture quietly violates that rule all the time. Same M365 tenant. Same admin account. Same SSO. One compromised identity and the whole thing goes with it.
The Moment Cloud-Only Breaks: Recovery Hardware
Here is the scenario nobody warns you about. Your servers get encrypted. You have clean backups sitting in the cloud. You are feeling okay about it. Then your insurance company and their forensics team tell you something you did not expect: you cannot restore onto your existing hardware. Not yet. Maybe not for weeks.
Why? Because the original hardware is now evidence. The insurance company has to preserve the environment in its compromised state. There may still be active negotiations for decryption keys. Forensics needs to determine how the attacker got in, partly to close the hole and partly because the insurer is going to try to prove you did not follow your own policy so they can reduce the payout. Until all of that is resolved, those encrypted servers sit frozen.
So where do you restore to? “The cloud” is rarely the right answer for line-of-business systems that expect a specific network, specific latency, specific integrations. You need physical hardware, and you need it in days, not months.
This is why my company keeps over a hundred thousand dollars worth of servers racked and waiting as cold spares for our clients on agreement. They are not doing anything most of the time. That is the point. When a client has a major incident, we can put them on loaner hardware in hours. I have had clients live on those loaner servers for three months while they sourced and configured replacement infrastructure.
A cloud-only shop does not have that option. They have a cloud console, a credit card, and a lot of hope that somebody at the hyperscaler can spin up the exact environment they need before the lost-revenue meter eats them alive. I walked through the full cost picture of this scenario in what really happens when your business gets ransomware, and the loaner-hardware gap is one of the most underestimated line items.
The Moment Cloud-Only Breaks: Insurance and Forensics
There is a quieter failure mode that is worth naming. When your only copy of the business lives in a cloud tenant, and that tenant is the thing under investigation, forensics has a harder job. They cannot always image what they need. They cannot always preserve state the way they would with a physical box they can pull a drive out of.
I have watched insurance claims slow down for exactly this reason. The forensics team assigned to you, and remember, you do not get to pick them, they come off the insurer’s approved list, is going to work at their pace. If your evidence preservation story is “it is all in the cloud, go talk to Microsoft,” the clock keeps running. On one of my client engagements, three full days passed before recovery could even begin. At roughly a hundred thousand dollars a day in lost income, that is real money burning while the attorneys and forensics team assemble.
The Moment Cloud-Only Breaks: Connectivity
This one does not get talked about enough. When your internet goes down, your business goes down. If your file shares, your line-of-business app, your phones, your printing, and your authentication all live in the cloud, a fiber cut or an ISP outage turns your office into a coffee shop without wifi.
A hybrid posture gives you something important: the ability to keep working on the local network for at least some core functions when the pipe to the outside world is down. That is not a theoretical benefit. I have seen businesses lose full days because a single carrier had an outage and they had no local fallback for anything.
What Hybrid Actually Looks Like for a 10 to 100 Person Business
When I say “hybrid,” I am not talking about running a private data center in your closet. For a business in the 10 to 100 employee range, hybrid is pragmatic, not grand.
A realistic hybrid footprint usually looks like this:
- Cloud for productivity and collaboration. Email, calendars, shared documents, video meetings. M365 or Google Workspace is the right tool here. Do not fight it.
- Cloud for SaaS line-of-business apps. If your CRM, your accounting, or your PM tool is already SaaS, leave it there. You are renting the expertise of the vendor.
- On-prem or colo for core servers that are latency sensitive or expensive to re-platform. File servers with heavy daily use, specialty apps, industry software that was not designed for the cloud, and anything doing large-scale data processing.
- On-prem, air-gapped or near-air-gapped backup appliance. Separate network segment. Separate admin credentials. Separate encryption keys. Immutable snapshots where possible.
- A second backup copy in the cloud, in a separate tenant. Not the same M365 tenant that runs your email. A dedicated backup tenant or a third-party cloud backup service with its own identity stack.
- Cold spare hardware access. Either your own, or through a managed provider. You want a path to physical servers in hours, not weeks.
That is it. That is the whole model. It is not exotic. It is not expensive compared to a real incident. And it survives failure modes that pure cloud simply cannot.
A Decision Framework: What Goes Where
When I sit down with a client to decide where a workload should live, I ask four questions.
1. How bad is it if this goes offline for a day because the internet is down? If the answer is “catastrophic,” that workload wants a local copy or a local fallback. Phones, point of sale, and core file access often fall here.
2. How predictable is the load? Steady, predictable load favors on-prem or colo over time. The capital investment pays back. Spiky, unpredictable load favors the cloud where you only pay for what you use. This is where the OpEx versus CapEx math actually matters, and where I see a lot of businesses get it backwards.
3. How much data moves in and out? Cloud egress fees are the silent killer. If the workload chews through large volumes of data every day, running it on-prem and keeping the cloud for archive or burst is almost always cheaper.
4. What does my recovery path look like if this is compromised? If the honest answer is “I would have to rebuild this from scratch on hardware I do not own,” you need to fix that before you need to fix that.
The Cost Reality Nobody Talks About
Cloud-only is sold as cheaper. For the first year or two, for a lot of workloads, it genuinely is. But as you scale, the picture changes. Storage grows. Egress grows. Licensing tiers ratchet up. Seats multiply. And because everything is OpEx, the spend is easy to ignore until it is not.
I wrote more about this drift in managing cloud waste as you scale, but the short version is this: the companies I see overspending the most are the pure cloud shops who never revisit the decision. They spun up resources in year one, added more in year two, and by year four they are paying for zombie storage, over-provisioned VMs, and premium tiers on services the team barely uses.
A hybrid strategy forces you to have the conversation. When you have a real on-prem footprint, you know what it costs. When you also have cloud spend, you have a natural comparison point. You catch waste faster because you can see it.
The Counterargument I Hear Most
“But Brian, on-prem means I have to manage servers again.” Yes. Or your managed provider does. That is a real cost and a real consideration, but it is not the cost people imagine. A modern hybrid setup for a small-to-midsize business might be two or three physical boxes, a backup appliance, and a UPS. That is not a data center. That is a rack in a closet that a competent provider checks on remotely and visits a few times a year.
Compare that to rebuilding your entire business from scratch in the cloud after an incident, and the math stops being close.
The 2026 Call
If you are making infrastructure decisions right now for the next two or three years, do not let anybody sell you a pure cloud-only story without walking you through the ransomware recovery path, the insurance forensics path, the connectivity outage path, and the five-year cost curve. If the person pitching you cannot answer those four questions with specifics, they are selling you a product, not a strategy.
Hybrid is not a hedge. It is not a compromise. It is the posture that keeps you operating when the thing you did not plan for happens. And in my experience, the thing you did not plan for always happens.
Want Us to Map This for Your Business?
If you are in the Tulsa area and you want a real look at what belongs in the cloud, what belongs on-prem, and where your current setup has hidden single points of failure, reach out. We will walk your environment with you, show you exactly where a cloud-only posture has you exposed, and put together a hybrid roadmap that fits the size and budget of your business. No pressure, no scare tactics, just the honest picture.

Brian Largent
Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)




