# Cloud strategy for mid-sized companies: what belongs in the cloud and what does not

> Cloud decisions per system rather than across the board: cost over the term, operations and specialists, legal requirements, vendor dependency and a defined way back.

URL: https://techport.ai/en/it-beratung/architektur-und-anwendungen/cloud-strategie

---

1.  [IT Consulting](/en/it-beratung)/
2.  [Architecture and Applications](/en/it-beratung/architektur-und-anwendungen)/
3.  Settling the cloud question

[Architecture and Applications](/en/it-beratung/architektur-und-anwendungen)

# Settling the cloud question

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

The cloud debate in mid-sized companies is often conducted as a matter of belief. One side says everything belongs in the cloud because someone else then handles operations and updates. The other says the data has to stay in house. Both positions lead to poor decisions because both are blanket statements.

The useful question is not whether cloud, but which system and for what reason. For a standard system with fluctuating usage the answer differs from a production control system that has to keep running without an internet connection.

## How you notice it

*   There is a cloud strategy on paper but daily decisions do not follow it.
*   Monthly cloud costs rise without anyone being able to name the cause.
*   Customer questions about server location and access take weeks to answer.
*   Changing provider is considered impossible because nobody knows how the data would come out.

## Why this happens

Cloud decisions in the mid-market are usually not made as decisions but arise as side effects. A vendor moves its product to a subscription, a department books a service, a project needs an environment quickly. Two years later part of the landscape sits outside the company without anyone having a view of total cost, dependencies or contractual basis. A retrospective strategy then has to sort out a grown situation rather than set a direction.

## How we go about it

1.  **Define the criteria.** We define with you what future decisions will be based on: criticality for operations, requirements for availability and response times, type of data, contractual commitments to customers, specialists available in house, and total cost across the planned term.
2.  **Classify what exists.** We assess the current systems against those criteria and assign each a target state: in house, operated by a provider, consumed as a service, or to be retired. That produces a picture which shortens individual decisions later.
3.  **Review contracts and exit.** We review per service the server location, processing agreement, sub-processors, availability commitments, price adjustments and above all the release of your data at the end of the contract, including format and deadline.
4.  **Watch the cost continuously.** We set up simple cost monitoring showing consumption per service and per area, and define who reviews it. Consumption based billing without observation is the most reliable way to spend money unnoticed.

## What you gain

*   Decisions per system that are justified and repeatable.
*   Answers to customer questions about location and access without weeks of research.
*   Contracts that permit a change, and therefore a negotiating position.

## From our projects

The most common error in cloud calculations is comparing the wrong figures. The monthly invoice gets compared with the purchase price of a server, while your own operating effort, maintenance contracts, power, space and above all the working time for updates are left out. In the other direction, cloud calculations regularly omit the cost of data transfer, backup and the environments for testing and training. We therefore always calculate across the planned term and with both sides complete. In roughly half of the cases that calculation reverses the original assumption.

## Good to know

The EU Data Act, Regulation (EU) 2023/2854, has applied since 12 September 2025 and strengthens your position when changing provider. Cloud providers must enable the switch contractually and technically, with a notice period of no more than two months followed by a transition period of usually no more than thirty days. Charges for switching disappear entirely from 12 January 2027. When renewing contracts, check whether the switching provisions meet the current requirements, and have the export formats named specifically rather than merely the possibility of an export.

## Häufige Fragen

Does our data have to be held in Germany?

Legally only in a few cases. More often the requirement comes from customer contracts, from industry requirements or from your own risk decision. More important than location alone are the questions of who has access to the data, which law the provider and its parent company are subject to, and how access is logged.

What about dependency on a single provider?

It cannot be avoided entirely and should be limited deliberately. Three measures are practical: prefer common formats and interfaces, test the data export regularly rather than only agreeing it contractually, and know for the business critical systems what the alternative would be and what a change would cost.

## Let us talk about Settling the cloud question

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our software](/en/loesungen)

## Further reading

[Architecture and ApplicationsCleaning up the application landscapeWhich systems carry which process, where data originates, what is duplicated and what is being phased out. An overview that speeds up decisions instead of filling folders.](/en/it-beratung/architektur-und-anwendungen/anwendungslandschaft)[IT Governance and ComplianceImplementing data protection technicallyGDPR put into practice: technical and organisational measures, processor agreements, records, deletion concept, log data, third country transfers and handling data breaches.](/en/it-beratung/it-governance-und-recht/datenschutz-in-der-it)[Operations and SupportPlanning IT infrastructureInfrastructure that carries: plan capacity and replacement ahead, size network and sites, make dependencies visible, set maintenance windows and keep outages manageable.](/en/it-beratung/betrieb-und-support/it-infrastruktur)[KnowledgeIT regulatory radarWhat applies, what is coming, what to do now.](/en/it-beratung/regulatorik-radar)[KnowledgeIT metricsDefinitions and formulas read the same way across the company.](/en/it-beratung/kennzahlen)

Back to the field [Architecture and Applications](/en/it-beratung/architektur-und-anwendungen)

## Sources

*   [Regulation (EU) 2023/2854 (Data Act), EUR-Lex](https://eur-lex.europa.eu/eli/reg/2023/2854/oj)
*   [Article 28 GDPR, processor](https://gdpr-info.eu/art-28-gdpr/)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
