TechKnowSurge
VideoSecurityFree

Deployment Model Considerations

Choosing an infrastructure deployment model requires weighing cost, security, compliance, scalability, and organizational readiness across on-premises, cloud, and hybrid options. Each factor carries trade-offs that vary depending on business size, staff expertise, and data sensitivity.

Complete this video to capture a CTF flag worth 1 point.

About this video

No single infrastructure deployment model suits every organization, and the decision requires a structured analysis of multiple variables. Cost is rarely straightforward — managed cloud services shift capital expenditure to ongoing operational costs, and while renting infrastructure may appear more expensive over time, building and maintaining an on-premises data center can demand significant upfront investment. Licensing adds another layer of complexity, particularly for enterprise software like SQL Server, where on-premises licensing can be prohibitively expensive but cloud-based licensing through SaaS or PaaS arrangements may cost more in aggregate over time. Security considerations cut in both directions depending on organizational context. Self-managed infrastructure avoids the risks of shared environments, but organizations with small or non-specialized IT teams may actually achieve stronger security outcomes by leveraging cloud providers with dedicated security operations. Cloud deployments introduce specific concerns including data exposure, data remnants after deletion, insecure storage configurations, and reduced direct control over encryption keys — all of which require careful evaluation before committing to a cloud-based model. Beyond cost and security, compliance and regulatory requirements can significantly narrow the available options. Storing data with a third-party provider or in a colocation facility may conflict with industry-specific or regional data protection regulations. Geographic location also matters for both latency and data sovereignty reasons. Finally, internal organizational culture and executive attitudes toward cloud adoption can be a practical constraint — stakeholder alignment is a real factor in determining whether a technically sound deployment option is actually viable within a given business.

What you'll learn

What's covered

Deployment Model Considerations

Key terms

Cloud Computing
The delivery of computing services including servers, storage, and software over the internet on a pay-as-you-go basis.
Public Cloud
A cloud environment owned and operated by a third-party provider and shared among multiple customers.
Private Cloud
A cloud environment dedicated to a single organization, hosted on-premises or by a third party.
Infrastructure as a Service
IaaS
A cloud service model that provides virtualized computing infrastructure over the internet.
Platform as a Service
PaaS
A cloud service model that provides a platform for developing, running, and managing applications without managing infrastructure.
Software as a Service
SaaS
A cloud service model that delivers software applications over the internet on a subscription basis.
Scalability
The ability of a system to handle increased load by adding resources without degrading performance.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key to prevent unauthorized access.
Data Sovereignty
The concept that data is subject to the laws and regulations of the geographic region in which it originates or is collected.
Hybrid Deployment
An infrastructure model that combines on-premises resources with one or more cloud environments, allowing data and applications to be shared between them.

Topics

Cloud Computing Deployment Models Hybrid Cloud On Premises Infrastructure Data Sovereignty Cloud Security

Transcript

There are a lot of ways we can deploy our infrastructure, so which one do we choose? There are some considerations that go into which option we want to choose.

Choosing a deployment model

There are a lot of deployment models out there. I've given you some examples of where this might be used, but these are just examples. Bare metal, for instance, I put down as small business, but I can think of lots of situations where this would be part of a big business, that would want to have bare metal and install the operating system right onto that. So there are a lot of different variations of how we want to deploy things, or maybe it's a mix of all of this.

How do we decide which is the deployment model that we're going to use? There's a lot of considerations around that. Same thing when it comes to deploying in the cloud, whether we want to control most of it or we want to outsource some of it. We need to consider all of the variables involved with choosing the right solution for us. This is going to take quite a bit of exploration and looking into this.

  • We're going to look at the cost levels, depending on our size of business and what we can afford and these different deployment models.
  • We also need to consider security and data protection. What does that look like in each one of these scenarios? How secure is our data, and how secure are the options that we are considering putting it in?
  • We also need to look at availability and performance of each one of these options, and how easy it is to manage. Sometimes it's just easier to put it up in the cloud and have somebody else manage big aspects of it; otherwise, sometimes it's easier for us to manage that.
  • We need to consider the scalability of each of these options.
  • We need to consider regulations and compliance. If we put it up in the cloud or some sort of colocation, is that going to go against certain compliances, because we have to follow certain compliances?
  • And what about the location? Do we want it near our customers, near us, because of the delays that there could be? Do we want it overseas because it's cheaper over there? Or is there a concern around the data privacy and where we are storing that data?

So we need to have all of these considerations in mind when we're choosing where it is that we're going to deploy and how we're going to deploy our infrastructure.

Cost

If I'm considering costs, I could say that over here is more expensive, because I'm actually renting the equipment and I'm paying somebody else to manage that equipment, and they need to make money, they need to make a profit. So I'm actually going to pay more with these solutions over here, versus implementing it myself - I could actually pay less in the long run. Although then you consider, what if I have to build a whole new network, build all this infrastructure, build all this data center? That gets really expensive. So if I have to do that, then it's actually less expensive to put it up in the cloud and just have them manage all of that. So there's a lot of different scenarios.

Security

Think about the security as well. We can say that we can be more secure because it's not in a shared infrastructure, and when it's not in a shared infrastructure we have more control over it. So this is more secure, to control it ourselves. But let's say I'm really short on how many people I have to manage all of this, and they're not security professionals. Then it might be better - I might say it's more secure to put it up in the cloud and let somebody else take control of security, where they have teams of people that are making sure that this level down here is secure.

Because the cloud environment is a shared infrastructure, there are some security concerns about that. What about data exposure, or data leakage, or data remnants? That is, we've deleted the data but maybe the cloud provider doesn't delete it right away, so now there's some sort of data remnants with that. Or there are insecure storage resources out there, so if we don't manage things correctly, then that opens us up for security holes. So there's lots of different ways that we need to consider this cloud security and being in a shared infrastructure.

Licensing

There are also concerns around licensing. Let me give you an example. If I ran a SQL Server on premise, then that is going to be very expensive from a licensing perspective. SQL licensing can get very expensive. So I can move it into the cloud and avoid that upfront expense, so that could be a little bit cheaper, because now I'm paying for it over time, but I'm renting the license in that case. So if I'm renting the license and it's some sort of SaaS or PaaS, then what happens is that I'm probably going to pay more for that licensing. And then with infrastructure as a service, a lot of times I'm also purchasing the licensing for there. It just depends on what it is that I might be purchasing. Some of the licensing, like for instance SQL Server, I'd probably be purchasing the licensing in this environment, so that can get expensive upfront but maybe less expensive long term.

Encryption keys and adoption

We also have to consider encryption keys. When we start using these services over here, we're not in control of those encryption keys, or we're in less control of that. So how are those encryption keys protected in each one of these environments?

And your business might even be opposed to moving it into the cloud. There are boards of directors, there are CEOs, there are execs of the company, and depending on how they view the cloud, they may or may not think that it's a viable option, and they may have concerns about that. So we've got to think about the cloud service adoption, like within the company, how ready are they going to be to adopt these cloud services.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →