For a decade, “cloud first” was the standard answer to almost every IT question in the SME sector. The trend has now noticeably reversed: according to a Barclays CIO survey, at the end of 2024 86% of the IT decision-makers surveyed planned to move at least part of their public cloud workloads back to their own or private infrastructure[1]. The Flexera report confirms this: 21% of workloads have already been repatriated, and 70 to 80% of companies bring at least some data back from the public cloud every year[2]. The reason is rarely hostility towards the cloud, but a sober calculation of cost, security and control.

Short answer

Local IT infrastructure runs computing power and data within the company's own or a controlled environment. It is particularly attractive for predictable workloads, high control requirements or sensitive data. Cloud services remain the right choice where flexible scaling and ready-made platform features matter more. For many businesses, a deliberately separated hybrid architecture is the most robust solution.

Why local infrastructure is becoming attractive again

The best-known example is 37signals, the company behind Basecamp and HEY: moving away from AWS cut its annual cloud bill from US$3.2 million to US$1.3 million, with a one-off hardware investment of around US$700,000. Over five years, founder David Heinemeier Hansson calculates total savings of more than US$10 million[3]. This is an extreme example, but the underlying mechanism also applies to smaller businesses: cloud costs scale linearly with usage, whereas your own hardware pays for itself after a fixed period and is cheaper from then on.

A TCO analysis for stable, predictable workloads finds cumulative savings of more than US$3.4 million over five years compared with on-demand cloud pricing, with break-even reached after just under twelve months of use[4]. For a typical mid-sized company, the calculation is simpler: a server of your own costs €6,000 to €15,000 to purchase, plus running costs for power, cooling and maintenance, whereas comparable cloud storage starts at €5 to €15 per user per month. Break-even depends heavily on the usage profile, but with constant, predictable workloads it regularly shifts in favour of in-house operation[5].

Criterion Public cloud (full operation) Local infrastructure (in-house operation)
Cost profile Linear with usage, hard to plan as you grow Fixed costs after purchase, easy to plan
Data location Depends on the provider, often outside EU control Entirely on your own premises
US CLOUD Act risk Applies even to EU data centres of US providers Not applicable
Availability during provider outages Dependent on the hyperscaler In your own hands
Maintenance effort Largely eliminated Highly automatable today (RMM, monitoring)

Security: the underestimated cost factor

Bitkom's study “Wirtschaftsschutz 2025” (Economic Protection 2025) puts the total damage to German companies from theft, espionage and sabotage at €289.2 billion, of which €202.4 billion was caused by cyberattacks alone. 87% of the companies surveyed were affected[6]. Particularly alarming: 34% of companies were hit by ransomware in 2025, almost three times as many as in 2022 (12%). One in seven affected companies paid a ransom, in 4% of cases more than one million euros[6]. The 2025 situation report of Germany's Federal Office for Information Security (BSI) also shows that around 80% of reported attacks targeted small and medium-sized enterprises, with an average of 119 new vulnerabilities per day, 24% more than in the previous year[7].

The average total cost of a ransomware attack, including business interruption and recovery, is US$5.08 to 5.13 million[8]. On top of this comes the pure cost of downtime: according to an ITIC estimate, small businesses with fewer than 25 employees should expect costs of up to US$1,670 per minute of downtime, and as much as around US$53,000 per hour in the event of a cyberattack[9].

Important to know

Local infrastructure is not automatically more secure than the cloud. It does, however, shift responsibility and with it control: if you manage backups, patch management and network segmentation yourself, you are no longer dependent on the security architecture of a single cloud provider.

Cloud outages are no longer a theoretical risk

2025 clearly showed how vulnerable central cloud infrastructure can be: the Google Cloud outage in Frankfurt in October; the AWS outage on 20 October, which lasted around 15 hours and affected more than 1,000 companies; the Microsoft Azure outage on 29 October, which took down Outlook, Microsoft 365 and several airlines, among others; and the Cloudflare outage in November, which affected services including ChatGPT and Spotify[10]. Anyone who runs business-critical systems exclusively with a single hyperscaler takes on that provider's outage risk unfiltered.

Digital sovereignty has long been more than a buzzword

The market share of European cloud providers has fallen from 29% in 2017 to around 15% today[11]. At the same time, according to an industry survey, 60% of IT leaders in Western Europe want to expand their use of local providers, and 45% of EuroCloud members see “digital sovereignty” as the most important topic for 2026, ahead even of AI[12]. One reason for this is the US CLOUD Act: since 2018, US authorities have been able to access data held by US cloud providers, regardless of whether the server is located in Frankfurt or Dublin. An expert opinion for the German Federal Ministry of the Interior refutes the notion that standard contractual clauses effectively rule out this risk[13].

At regulatory level, the issue is coming under additional pressure: Germany's NIS2 Implementation Act (NIS-2-Umsetzungsgesetz) entered into force on 6 December 2025 and affects an estimated 30,000 companies in Germany, including parts of the SME sector in manufacturing, logistics, the food industry and digital infrastructure. Management bodies must approve the prescribed risk management measures and oversee their implementation. Personal liability does not arise automatically; it depends on responsibility, breach of duty, fault and the damage incurred[14].

Why in-house operation is easier today than it used to be

For a long time, the biggest objection to local infrastructure was the maintenance effort. This argument has lost considerable weight in recent years:

  1. Remote monitoring and management (RMM)In 2025, 60 to 63% of SMEs were already using RMM tools as a core component of their IT strategy. Patch management, monitoring and maintenance run automatically, without any need for a constant on-site presence.
  2. Mature virtualisationOpen-source platforms such as Proxmox turn a single server into a complete, manageable data centre in miniature, including snapshots, backups and live migration.
  3. Modern ransomware protectionThe 3-2-1-1-0 backup rule (three copies, two media types, one copy off-site, one immutable copy, zero errors in recovery tests) has become established as a robust standard and can be largely automated with today's tools.
  4. Energy-efficient, quiet hardwareModern mini PCs draw 10 to 20 watts at idle instead of the 80 to 200 watts of older servers, which means significantly lower annual electricity costs and no disruptive noise in the office.
  5. Local AI without a cloud subscriptionA mid-sized company with 200 employees can quickly pay around €1,200 a month for a standard AI API. A self-hosted server running an open language model costs a one-off €2,400 to €8,000, with comparable quality for many business tasks.

“Local infrastructure is no longer a step backwards; for many businesses it is the economically and legally cleaner solution, provided it is set up with the right structure.”

Abolish the cloud? That is not the point.

This is not about leaving the cloud entirely. Gartner expects around 90% of organisations to follow a hybrid approach by 2027[16]. The realistic strategy for SMEs is rarely “everything local” or “everything in the cloud”, but a deliberate decision for each workload: whatever needs to be highly available and elastically scalable stays in the cloud. Whatever is predictable, sensitive from a data protection perspective or permanently in operation is often cheaper, more secure and easier to control in-house.

How to make the switch in practice

The first step is an honest inventory: which systems currently run in the cloud, what do they really cost, including hidden ancillary costs, and which of them are suitable for in-house operation? This is followed by technical planning (hardware sizing, backup concept, network security) and a realistic maintenance plan that relies not on chance but on automation and clear responsibilities. If you approach this in a structured way, you gain both in the end: lower running costs and control over your own data.