Is the Cloud Really the Risk? Your Server Room Has a Public Address

Trustees, wealth managers and private banks often treat on-premises infrastructure as a security moat. Attackers see identity systems, exposed services and pathways into money.

The answer

Cloud and on-premises systems can both protect or expose private wealth. Physical ownership does not remove internet-facing services, vendor access, identity risk or the operational burden of patching and monitoring. The stronger model is the one that can explain and control every pathway, permission, alert and recovery step.

Picture the safest room in a wealth firm.

It sits behind a heavy door. Access requires a badge, perhaps a fingerprint. Cameras watch the corridor. Inside, steel cabinets hold servers owned by the firm, administered by people whose names appear on the payroll. A director can walk downstairs, place a hand on a rack and feel the low vibration of the machines.

That physical certainty is powerful. It also creates one of the most expensive illusions in modern finance.

A cable leaves the room.

The firm needs email, market data, payments, portfolio reporting, custodians, client portals, remote work, software updates and vendor support. Each requirement creates a route between the rack and the outside world. Firewalls sit on that boundary. Virtual private networks cross it. Microsoft Exchange, file-transfer systems, remote-management tools and web applications may face the public internet. Staff identities travel through it every day.

An attacker in another country sees none of the mahogany, steel or biometric locks. They see an IP address, a login page, an unpatched appliance, a reused password, an overprivileged service account or a contractor with remote access.

The cloud creates serious risk. So does a server room. Security depends on who can reach a system, what they can do after entry, how quickly defenders see them and whether the firm can recover before stolen information becomes leverage.

Location answers where the machines live. Architecture answers whether the business survives.

A public address behind a private door

Internet exposure has become a searchable property.

Criminal groups scan the internet continuously for vulnerable firewalls, virtual private networks, email servers and file-transfer products. Search engines built for infrastructure can identify software versions and open ports across millions of systems. CISA warns that misconfigured systems, default credentials and outdated software are routinely visible through internet-based discovery. A private server room can therefore advertise its weaknesses to the entire world.

The distance between discovery and intrusion keeps shrinking. Verizon’s 2026 Data Breach Investigations Report places vulnerability exploitation at the front of 31 percent of breaches. Third-party involvement appears in 48 percent, following a 60 percent rise. A firm can own every server in its estate and still inherit access paths through a software supplier, managed-service provider or remote-support account.

Microsoft Exchange supplied a brutal demonstration in 2021. Attackers exploited vulnerabilities in on-premises Exchange servers, installed web shells and created persistent access inside enterprise networks. CISA’s emergency directive described a path toward control of affected systems. One compromised email server could expose mailboxes, credentials, internal relationships and a platform for further movement.

MOVEit repeated the lesson at industrial scale. The Cl0p group exploited an internet-facing managed file-transfer product and accessed underlying databases. The product served exactly the purpose its owners bought it for: moving sensitive information between organisations. Its connection to the internet also gave criminals a route toward the data.

A wealth business contains unusually valuable connective tissue. One mailbox can reveal a client’s advisers, travel schedule, family disputes, banking relationships and pending transactions. One file-transfer system can hold passports, trust deeds, tax records and account instructions. One directory account can open doors across the firm. Criminals assemble those fragments into fraud, coercion and extortion.

Owning the hardware gives a firm authority over the machinery. That authority carries every operational burden: patching, hardening, logging, segmentation, backup integrity, privileged access, hardware lifecycle, incident response and continuous monitoring.

Cloud providers divide that burden with customers. An on-premises operator carries it alone.

What an on-premises attacker looks for

An on-premises estate usually exposes several of these routes:

  • Public-facing firewalls, VPN concentrators and remote desktop gateways
  • Email servers and web applications awaiting security updates
  • Vendor support tools with persistent or loosely controlled access
  • Shared administrator accounts and broad domain privileges
  • Legacy operating systems tied to specialist applications
  • Flat internal networks where one compromised machine can reach many others
  • Backup consoles joined to the same identity domain as production
  • Security alerts reviewed during business hours while intrusions run through the night
  • Remote staff connecting from unmanaged or weakly managed devices
  • Files copied into local shares with years of accumulated access permissions

Each route can be secured. Together, they demand a mature security operation and relentless maintenance.

ASIC’s case against FIIG Securities shows what operational failure can cost inside financial services. A cyberattack exposed roughly 385 gigabytes of confidential data connected to about 18,000 clients, including passports, driver licences, bank details and tax file numbers. The court found failures involving multifactor authentication for remote access, privileged controls, firewall management, patching, monitoring, staff training and incident-response testing. FIIG received a A$2.5 million penalty.

The case matters because each missing control sounds ordinary. Criminal campaigns thrive on ordinary gaps stacked together.

A delayed patch opens the edge. Weak remote authentication admits a user. Broad privilege expands access. Thin monitoring gives the intruder time. Fragile response plans turn hours into days. Sensitive records leave the network while the server rack continues blinking peacefully downstairs.

What a cloud attacker looks for

Cloud systems shift the terrain toward identity and configuration.

An attacker may pursue:

  • Stolen usernames, passwords, session cookies and authentication tokens
  • Accounts lacking phishing-resistant multifactor authentication
  • Dormant contractor identities and unmonitored service accounts
  • Excessive permissions across cloud resources
  • OAuth applications able to read mail or files
  • Secrets embedded in scripts, repositories and deployment pipelines
  • Storage exposed through public links or permissive policies
  • Absent network allowlists and device restrictions
  • Weak recovery procedures for account resets
  • Logs that exist yet receive little attention
  • SaaS applications connected to the firm’s central identity provider

Mandiant’s investigation into data theft from Snowflake customer instances offers a precise example. The campaign used credentials stolen from customer environments. Mandiant and Snowflake notified about 165 potentially exposed organisations. Impacted accounts lacked multifactor authentication, some credentials remained valid for years, and affected instances lacked network allowlists. Mandiant found evidence that at least 79.7 percent of accounts used by the threat actor had prior credential exposure.

The servers lived inside a major cloud platform. Customer identity controls decided who entered.

Microsoft disclosed another identity-led intrusion after Midnight Blizzard compromised a legacy, non-production test tenant account through password spraying. That account lacked multifactor authentication. The actor abused OAuth applications and elevated permissions to reach corporate email. A neglected identity at the edge of an environment became a route toward valuable communications.

Cloud services create concentration risk, provider dependency and powerful control planes. A stolen administrator identity can alter infrastructure at speed. A configuration mistake can expose a vast dataset. A compromised software supplier can touch many customers. Outages can affect entire regions. Legal jurisdiction and data residency can complicate sensitive estates.

Cloud also supplies capabilities few private organisations can reproduce economically: global infrastructure teams, managed security services, automated patching for provider-controlled layers, resilient storage, detailed activity logs, rapid deployment of controls and geographic redundancy.

The customer still owns critical decisions. NCSC’s shared-responsibility guidance makes this division explicit. Responsibility changes across infrastructure, platform and software services. Identity, information, access policy and safe configuration remain central customer concerns.

Cloud security succeeds through disciplined use of those capabilities. A default deployment deserves zero confidence.

One criminal journey, two sets of scenery

Cloud and on-premises attacks often converge after the first step.

First comes entry. An exposed VPN appliance may provide it. A stolen cloud credential may do the same.

Next comes privilege. In a local network, the attacker hunts domain administrators and service accounts. In cloud environments, they pursue roles, tokens, OAuth grants and identity-provider access.

Then comes expansion. Local attackers move across endpoints, servers and shared drives. Cloud attackers enumerate tenants, storage, mail, applications and connected services.

Collection follows. Both environments contain correspondence, legal structures, identification documents, transaction records and operational intelligence.

Finally, the attacker converts access into money or pressure. They steal funds, intercept payments, sell access, leak records, encrypt systems, threaten clients or combine several tactics at once.

Attackers choose the cheapest reliable route. A supplier may provide it. A personal laptop may provide it. A forgotten test tenant may provide it. A firewall awaiting a patch may provide it. Physical ownership changes the scenery while the criminal objective remains fixed.

Air gaps change the geometry

True isolation can reduce remote attack paths dramatically.

An isolated system has no routine internet connection, no remote administration, tightly controlled data transfer, purpose-built hardware and severe operational restrictions. Some national-security, industrial and vault-like environments use variants of this model.

Trustees, private banks and wealth managers usually run a connected business. Staff communicate with clients. Teams exchange files with lawyers, accountants and custodians. Systems receive market data and software updates. Remote support keeps specialist applications alive. Payment and reporting workflows cross organisational boundaries.

Each connection brings the external world back into the estate.

Isolation also carries its own attack paths through removable media, supply chains, maintenance laptops, insiders and compromised updates. It demands specialised engineering and operational discipline. A rack in an office basement with an internet line and a vendor VPN occupies a very different category.

Calling that rack “private” describes its address and ownership. It says little about its exposure.

When cloud earns the stronger security case

Cloud infrastructure can create a stronger security position when a firm:

  • Uses phishing-resistant multifactor authentication for every privileged and remote account
  • Applies least privilege and reviews access continuously
  • Restricts administration to managed devices and controlled networks
  • Separates production, administration and backup identities
  • Centralises logs and monitors them around the clock
  • Uses immutable backups with rehearsed restoration
  • Controls OAuth applications, tokens, secrets and service accounts
  • Maintains network allowlists and conditional-access policies
  • Assesses provider concentration, jurisdiction and exit plans
  • Understands every line of the shared-responsibility model

Those controls turn provider scale into an advantage.

When on-premises earns the stronger security case

On-premises infrastructure can create a stronger security position when a firm:

  • Limits internet-facing services to a tightly governed minimum
  • Patches exposed systems at the pace of active exploitation
  • Separates user, server, administrative and backup networks
  • Uses dedicated privileged workstations and individual administrator identities
  • Removes standing vendor access and approves each support session
  • Replaces end-of-life hardware and software before support expires
  • Monitors endpoints, identity, network traffic and data movement continuously
  • Protects backups through separate credentials and immutable copies
  • Tests incident containment and restoration under realistic pressure
  • Funds a specialist team capable of operating the full stack

Those controls turn physical authority into an advantage.

Twelve questions for a board that wants a real answer

A board can cut through the cloud debate with twelve questions:

  1. Which systems can be reached from the public internet today?
  2. Which identities can administer infrastructure, email, backups and client data?
  3. Which privileged accounts lack phishing-resistant multifactor authentication?
  4. Which suppliers retain remote access, and who reviews each connection?
  5. How quickly can the firm patch an internet-facing system under active attack?
  6. Can one stolen identity reach production systems and backups?
  7. Which legacy applications depend on unsupported software?
  8. Who watches security alerts overnight, on weekends and during holidays?
  9. How long would discovery take after a successful login from a hostile device?
  10. Can the firm restore critical operations from clean, isolated backups?
  11. Which client records could leave the environment before an alert fires?
  12. When did leaders last rehearse a live intrusion involving executives, advisers, counsel and clients?

Vague answers expose risk. Precise answers expose work.

The exercise also reveals a useful pattern. Weak on-premises environments tend to hide behind ownership. Weak cloud environments tend to hide behind the provider’s reputation. Strong environments can explain every important path, permission, alert and recovery step.

Security lives between the addresses

Boards often frame cloud migration as a choice between control and exposure. The real decision concerns where responsibility sits and whether the firm can execute it.

An on-premises system places enormous responsibility inside the organisation. A cloud service distributes responsibility across provider and customer. Either model can protect sensitive wealth. Either model can expose it. Architecture, identity and operations decide the result.

NIST’s zero-trust guidance removes network location as a source of implicit trust. Every user, device and connection must earn access according to policy. That principle fits a private bank, a family office, a trustee and a global cloud provider equally well.

The most dangerous sentence in this debate remains simple: “We own the servers, so we are secure.”

Ownership deserves pride. Security demands evidence.

Cloud and server room are addresses. The decisive territory lies in the permissions, pathways and response times between them.

Sources

  1. NIST: Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud EnvironmentsNIST

    Standard

  2. NIST: Zero Trust Architecture, SP 800-207NIST

    Standard

  3. Verizon: 2026 Data Breach Investigations ReportVerizon

    Industry guidance

  4. CISA: Exposure ReductionCISA

    Primary authority

  5. CISA: Emergency Directive and Alert on Microsoft ExchangeCISA

    Primary authority

  6. CISA: Cl0p Exploits MOVEit VulnerabilityCISA

    Primary authority

  7. Google Cloud and Mandiant: UNC5537 Snowflake Data Theft and ExtortionGoogle Cloud and Mandiant

    Industry guidance

  8. Microsoft Security: Midnight Blizzard Guidance for RespondersMicrosoft Security

    Industry guidance

  9. UK National Cyber Security Centre: Cloud Security Shared Responsibility ModelUK National Cyber Security Centre

    Primary authority

  10. ASIC: FIIG Securities ordered to pay A$2.5 million over cyber-security failuresASIC

    Regulator

Jonathan P. De Collibus

Jonathan co-founded Svperior in 2014 and leads its cyber practice. His work sits where adversarial pressure, technical architecture, and consequential decisions meet, with experience across clinical, financial, public-sector, and private-client systems where confidentiality, continuity, and technical correctness carry material consequences.

Cyber strategy / Adversarial assessment / Security architecture / Private systemsRead Jonathan's full biography

Need to apply this to a specific situation?

Send us the initial context. If the matter fits, we will respond directly.

Send private inquiry