Somebody in your business has said "we should just move everything to the cloud" in the last two years, and somebody else has said "I want our data in this building". Both of them meant it, and both of them were arguing from instinct rather than a number. The frustrating part is that the honest answer is knowable — it is a spreadsheet, not a philosophy — and almost nobody builds it before deciding.

Cloud is not automatically cheaper. On-premise is not automatically safer. What separates a good decision from an expensive one is knowing which costs each option hides, and being honest about which of your reasons for keeping the servers in the building are real.

We have written the plain-language comparison of cloud, on-premise and hybrid before. This piece goes at the money and at the motives: what each option actually costs over five years, and why, despite a decade of "the data centre is dead", a very large share of South African businesses still have a server humming in a back room — and why some of them are right to.

What you are really comparing

On-premise is a capital purchase with an operating tail. You spend a lump sum, then you spend smaller amounts forever on power, cooling, maintenance and the person who looks after it. Cloud is pure operating expense: nothing up front, a bill every month that never ends and rarely goes down on its own.

That difference matters beyond accounting. Capital spend is approved once, scrutinised hard, and then forgotten. Operating spend is approved once, scrutinised never, and grows quietly. A server you over-specified costs you once. A cloud environment you over-specified costs you every month until someone notices — and in most businesses, nobody is paid to notice.

The honest cost of on-premise

The quote from the hardware supplier is the smallest part of the number. A fair on-premise total includes all of this:

  • The hardware, and its replacement. Servers, storage, switches, the rack. Budget a refresh at four to five years, because that is when support contracts end and failure rates climb.
  • Licences. The operating system, the hypervisor, the database, the backup software, the antivirus, the monitoring agent. This is routinely half again on top of the hardware.
  • Power, and power you can rely on. A UPS sized for a clean shutdown is the minimum. If the business has to keep trading through an outage, that becomes an inverter or generator, and both have running and replacement costs of their own — see what it actually takes to keep working through an outage.
  • Cooling and space. A cupboard with a domestic air conditioner is what most small businesses have, and it is also why most small businesses have had a heat-related failure.
  • Backups, stored somewhere else. A backup on a drive next to the server is not a backup. Off-site copies cost money whether you ship tapes or pay for cloud storage.
  • Somebody's time. Patching, monitoring, capacity, the 2am call. Whether that is a salary, a share of one, or a support contract, it is real, recurring and usually left out of the comparison entirely.
  • Connectivity and security. Firewall, remote access, and a line good enough that people outside the building can reach the thing you just bought.

The honest cost of cloud

The published instance price is, similarly, the smallest part. What lands on the invoice:

  • Compute, and compute you forgot to switch off. Test environments left running over a weekend are the single most common line item nobody can explain.
  • Storage, and its backups and snapshots. Snapshots are cheap individually and expensive in aggregate, because nothing deletes them unless you build the thing that does.
  • Data transfer out. Getting data in is usually free. Getting it out is not. For reporting, media, or a nightly extract into another system, this can quietly become one of your largest lines.
  • Licensing, again. Running commercial software in the cloud often costs more per core than running it on hardware you own, and vendor licensing terms for "hosted" use are frequently a surprise.
  • Support. The free support tier means a web form. A response time you can rely on is a paid plan, typically a percentage of spend.
  • The exchange rate. Most of the big providers bill in dollars. Your revenue is in rands. That is a cost line you do not control and cannot forecast.
A cloud bill is not a price, it is a meter. The discipline it demands — sizing, switching things off, reviewing the invoice monthly — is exactly the discipline that most businesses moved to the cloud hoping to avoid.

Where the maths actually flips

There is a shape to this, and it is reliable enough to plan around.

Cloud wins when demand is uneven or unknown. A seasonal retailer, a new product with no traffic history, a project that might be cancelled in six months, a workload that runs hard for four hours a day. Paying only for what you use beats owning a machine that idles for twenty hours.

On-premise wins when demand is flat and known. A database that has served the same forty users for six years, doing the same work every day, has no elasticity to buy. You are renting flexibility you will never use. Over a five-year horizon, owning the hardware frequently comes out cheaper, sometimes dramatically so.

Cloud wins when you have nobody to run it. This is the argument that decides more cases than cost ever does. If there is no person whose job includes patching the server, the cloud is not cheaper — it is simply the only option that will still be working in three years.

Build the five-year number before you argue

One page, two columns, sixty months. On the left: hardware, licences, UPS or generator, cooling, backups, and a realistic share of someone's salary. On the right: compute, storage, egress, backup, support plan, and the licensing uplift, with a rand-dollar assumption written down. Add a refresh in year five to the left column. Most arguments end quietly once this page exists, and it takes an afternoon.

Why so many companies still keep data on premise

Cloud adoption is widespread, but the server room is not empty, and the reasons are more varied than "they haven't got around to it". Some of these are excellent reasons. Some are not, and it is worth being able to tell them apart.

The good reasons

  1. The system talks to hardware. Production lines, weighbridges, biometric readers, CCTV recorders, laboratory instruments, tills. These speak to a machine on the same network, in real time, and a round trip to another continent is not a design detail you can fix later.
  2. It has to keep working when the line goes down. If a fibre cut three streets away stops you from invoicing, dispatching or manufacturing, the case for keeping that system local is not nostalgia. Proper failover reduces the risk; it does not remove it.
  3. Data residency and contractual obligation. Some data has to stay in the country, either by regulation or because a customer's contract says so. Under POPIA, moving personal information across a border is allowed but conditional, and "the provider's default region is in Europe" is not an answer to an auditor.
  4. The data is enormous and moves constantly. Video, imaging, scanned documents, sensor histories. Data gravity is real: once a few terabytes live somewhere, everything that touches it wants to live there too, and egress charges punish the alternative.
  5. The hardware is already bought. A server in year two of a five-year life is a sunk cost that is still delivering. Migrating it to a monthly bill before it has finished earning its keep destroys money for no operational gain.
  6. Exit and control. Owning the platform means nobody can reprice it, deprecate it, or change its terms. That matters more to some boards than a modest saving, and it is a legitimate position — the flip side of vendor lock-in.

The weaker reasons, stated honestly

  • "It is more secure because I can see it." Physical proximity is not security. A patched cloud workload behind enforced multi-factor authentication is usually safer than an unpatched box under a desk with a port forwarded to the internet. The relevant question is who is doing the patching, not where the metal is.
  • "We have always run it here." Sometimes this is institutional caution wearing a technical costume. It is still worth respecting — but as a preference, not as an analysis.
  • "The ERP vendor doesn't support cloud." Often true a few years ago, and worth re-checking, because it quietly stops being true. It is also the single best question to put to a vendor before you renew.

The shape most businesses actually land on

Very few end up all one thing. The pattern that keeps repeating is unglamorous and sensible: email, documents, collaboration and reporting go to the cloud, because they benefit from scale and nobody wants to run a mail server. The line-of-business system that talks to machines or has to survive an outage stays local. Backups run in both directions, so the on-premise system has an off-site copy and the cloud data has a copy you control.

That is hybrid, and it earns its complexity only when the split is deliberate. Hybrid by design is resilience. Hybrid by accident — half a migration that stalled two years ago — is two environments to patch, two bills, two sets of credentials, and one failure nobody has traced. If you cannot say in a sentence why each system is where it is, you have the second kind.

How to run the decision

Do it per workload, not per company, and ask five questions of each system in turn:

  1. Does it have to keep working when the internet does not?
  2. Is its demand flat or spiky, and do we know which from evidence rather than assumption?
  3. Does its data have to stay in South Africa, by law or by contract?
  4. How much data leaves it every month, and what would that cost to move?
  5. Who patches it, and are they real, named and available — or hypothetical?

Then build the five-year page for the two or three systems where the answer is genuinely close. For everything else, those five questions will have decided it already. And whichever way each one lands, write down the reason next to it. In three years, when somebody asks again, that sentence is worth more than the spreadsheet — and if you have not also planned what happens the day the thing dies, neither location will save you.