Foundry4

Cloud and infrastructure 8 min read

Hybrid stopped being the thing you settled for

Every customer that told the CMA it would not move its public cloud workloads elsewhere was already running a hybrid estate. That is a destination, not a waypoint.

One sentence in the Competition and Markets Authority’s cloud investigation settles an argument the industry has been having for fifteen years, and it was written to make a completely different point.

The inquiry group was deciding whether on-premises infrastructure competes with public cloud, which matters because if it does, the market is bigger and the finding against the hyperscalers is weaker. AWS argued that customers run hybrid estates and therefore treat the two as substitutes. The CMA disagreed, and explained why in the final decision report published on 31 July 2025: parallel use of two products is ambiguous evidence, because it is equally consistent with the two being complements rather than alternatives. Then the observation that gives this article its argument. Every customer that told the regulator it would not move its public cloud workloads to a non-public-cloud environment was itself running a hybrid environment.

Those customers are not in transition. They have arrived. They run two kinds of infrastructure permanently, deliberately, and for reasons they can articulate, and they have no intention of collapsing the estate onto either side.

The transitional reading was always a sales position

For most of the last decade hybrid has been described as a stage. The story ran that an organisation begins on-premises, adopts cloud for new work, tolerates a period of running both, and eventually retires the old estate. Hybrid was the awkward middle, the tax you paid for having existed before 2010.

That story is useful to whoever is selling the destination, and it survives partly because it is convenient for the buyer too. A programme framed as a migration has an end date, a budget with a shape, and a moment at which somebody can be congratulated. A programme framed as running two environments permanently has none of those things, and it obliges the organisation to keep funding a capability its transformation narrative has already declared obsolete. The reason so many British estates contain a neglected on-premises tier is not that anybody decided to neglect it. It is that the plan of record said it was leaving.

The evidence collected by a regulator with statutory information-gathering powers does not support that plan. The customers the CMA questioned, selected at random rather than volunteered by a supplier, described a placement logic rather than a migration timetable. One said public cloud offers unparalleled ability to provision infrastructure at scale, in multiple geographies, with the latest functionality, and that it uses non-public-cloud environments precisely where public cloud cannot meet its requirements, naming latency and operational risk. Another said it moves workloads to public cloud only where technical benefits such as scalability, elasticity and resiliency can actually be achieved, and is guided by the specifics of each workload. A third, running legacy applications on-premises, said it would take significant effort to construct a stack with the security and observability capabilities of virtual machines and would still miss much of the public cloud proposition.

Read those as a set. None describes a plan to finish. Each describes a rule for deciding where a given workload goes, which is a different kind of document and a considerably more useful one.

Britain’s most cloud-committed buyer wrote the exception into the policy

The clearest evidence that hybrid is structural rather than residual is that the organisation most publicly committed to public cloud in this country has an on-premises route built into its own mandate.

The government cloud first policy, introduced in 2013 and last updated on 19 June 2023, requires public sector organisations to default to public cloud and to use other solutions only where that is not possible. It is mandatory for central government. It also states in the same breath that public cloud is not always achievable and that community, hybrid or private deployment models are acceptable in specific circumstances, provided the decision is documented and value for money demonstrated. Where hosting genuinely has to sit on physical estate, the policy directs organisations to Crown Hosting.

A mandate with a documented exception route and a named supplier for the exception is not a mandate to eliminate the alternative. It is a governance procedure for choosing between two permanent options, and it has been operating that way for over a decade.

The exit case that turned out to be a hybrid case

The most cited departure from public cloud in the industry describes itself, in a document filed with a securities regulator, as a hybrid estate.

Dropbox moved the vast majority of user data onto custom-built hardware in co-location facilities it leases and operates, completing in the fourth quarter of 2016. Its registration statement then explains the resulting architecture. More than 90% of user data sits on that infrastructure, in facilities in California, Texas and Virginia, and the company also uses Amazon Web Services for the remainder of storage needs and to help deliver its services, with AWS datacentres in the United States and Europe allowing it to localise where content is stored.

The residual 10% is doing specific work. It carries the regional footprint that would otherwise require Dropbox to build and staff datacentres in jurisdictions where it has no other reason to be. That is the shape hybrid takes when it is designed rather than inherited: the bulk of predictable, high-volume, well-understood load on owned capacity, and rented capacity for the parts where somebody else’s global estate is genuinely cheaper than your own.

Regulation has now made the second venue a board matter

Until recently a UK organisation could treat its placement policy as an engineering preference. In financial services that stopped being true this summer.

The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority published a joint policy statement on 12 November 2024, numbered PS16/24 by the PRA and PS24/16 by the FCA, creating an oversight regime for critical third parties, with designation reserved to HM Treasury on the statutory test that failure or disruption at the provider could threaten the stability of, or confidence in, the UK financial system. At publication nothing had been designated. On 10 July 2026 the Treasury named the first four, all of them cloud and technology providers, with regulatory oversight beginning on 13 July 2026: Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL and Oracle Corporation UK Limited.

The most consequential line in the policy statement is the one firms are most likely to misread. The regulators state that designation does not mean a third party is inherently more resilient or better suited to provide a service than an undesignated provider offering the same thing, and that firms remain accountable and responsible for managing the risks in any arrangement they hold with a designated provider. The regime imposes duties on the supplier. It transfers none of the buyer’s responsibility.

For an infrastructure lead that reframes the second environment. Keeping a workload somewhere other than the primary provider stops being a nostalgic preference for owning hardware and becomes part of an answer a firm has to give about how it would keep operating through a supplier event it cannot control. Four named companies now carry a formal designation acknowledging that their failure is a systemic question. Nobody who runs on them can treat single-provider concentration as a purely commercial choice.

What a real hybrid position writes down

The useful distinction is not between organisations that are hybrid and organisations that are not, since almost every large British organisation is. It is between those whose hybrid estate is the residue of decisions nobody recorded and those who can produce the rule.

The placement rule itself, in writing, at workload granularity. Which characteristics send a workload to rented capacity and which keep it on owned capacity. Latency, data residency, licence economics, peak-to-trough ratio and blast radius are the ones that recur in the evidence above, and any organisation can name its own. What matters is that the rule exists before the next architecture argument rather than being reconstructed afterwards to justify whichever way it went.

Where the identity boundary sits, which is the dependency most often missed. The CMA heard extensive evidence that customers running Active Directory on-premises and a cloud identity service alongside it end up dependent on both, that the cloud service is not a replacement for the on-premises one, and that some functionality does not exist on the cloud side, which leaves organisations with legacy Microsoft workloads effectively committed to running the pair. Identity is where hybrid stops being a diagram and becomes an operational constraint with a licence attached.

The direction data is travelling, since gravity is not symmetric. Egress charges make it cheaper to move a workload towards its data than to move data towards a workload, which quietly decides architecture years after anyone remembers choosing.

And who pays for the second venue. A capability that exists to absorb a failure produces no visible return in any month where nothing fails, which makes it the first line cut in a cost review and the reason the cut is regretted. Naming an owner and a budget for it is the difference between a hybrid estate and a single-provider estate with some old servers in it.

There is a diagnostic worth running against any of this, and it takes an afternoon. Pick three workloads currently sitting on rented infrastructure and ask the person who owns each one why it is there. If the answer is a property of the workload, the estate has a rule. If the answer is that everything went there in 2019, it has a history. Both are common. Only one of them survives the next time a regulator, a licence renewal or an electricity connection changes the arithmetic underneath it.

The economics that produce these decisions run through consumption billing and licence terms as much as through architecture, and that half is set out in what metered pricing does to a renewal. Whether moving workloads back off public cloud has ever been shown to pay is examined at who actually moved back, and what it saved them, and the rest of this section sits under cloud and infrastructure.

Sources

  1. Competition and Markets Authority, cloud services market investigation, final decision report, 31 July 2025 assets.publishing.service.gov.uk
  2. GOV.UK, government cloud first policy, updated 19 June 2023 gov.uk
  3. Bank of England, PRA and FCA, PRA PS16/24 and FCA PS24/16, operational resilience: critical third parties to the UK financial sector, 12 November 2024 bankofengland.co.uk
  4. HM Treasury, UK financial system strengthened with new safeguards for major technology providers, 10 July 2026 gov.uk
  5. Dropbox, Inc., Form S-1 registration statement, filed 23 February 2018 sec.gov