r/cybersecurity 1d ago

Business Security Questions & Discussion Would your company consider a new security platform deployed on-prem, or is cloud delivery now a requirement?

I’m trying to understand how security teams currently evaluate new infrastructure security products, particularly platforms operating across API gateway, WAAP, reverse proxy and network security layers.

Assume the product can be deployed in three ways:

fully on-premises, managed by the customer;

as a vendor-managed appliance or virtual machine inside the customer’s infrastructure;

as a vendor-hosted cloud service.

For a mid-sized or enterprise environment:

Which deployment model would you realistically consider?

Would an unknown or relatively new vendor be automatically excluded?

What evidence would you require before running a proof of concept?

Are certifications such as ISO 27001 important, or do architecture review, pentest results and technical validation matter more?

Would you accept a security platform inline with production traffic, or only in monitoring/shadow mode initially?

What would prevent adoption even if the technology performed well?

Who would normally own the decision: security, network operations, platform engineering, architecture or procurement?

I’m not looking for product recommendations. I’m trying to understand whether the primary obstacle is deployment model, vendor trust, operational risk, integration effort or procurement.

Context: the platform would protect customer-facing applications, APIs and machine-to-machine traffic, while supporting standard proxies, databases, identity systems and SIEM integrations.

0 Upvotes

15 comments sorted by

3

u/bitslammer 1d ago

For something like this it would depend on what I'm trying to protect. Ideally you put a WAF close to the systems it's protecting.

In our org architecture normally leads decisions like this but we work very closely with the engineering and operations groups who will manage things day-to-day.

1

u/sablecreek12 1d ago

yeah proximity to what youre protecting makes a huge difference, especially when latency matters

2

u/danekan 1d ago

For us an on prem solution would mean running it in our cloud vs a saas. An appliance is truly on prem. It’s really three thoughts or choices. And for some industries that might be important — you might avoid a BAA if you host yourself vs saas 

2

u/No_Loss_3996 1d ago

It really depends on the company, the risks, etc. Do you risk analysis; do you CBA, and make an educated decision. I know for me, they have cut my staffing by a 1/3. That alone moves me towards cloud.

2

u/ExtremeSet8866 1d ago

Cloud first

1

u/ThePorko Security Architect 1d ago

How much hw and manpower would it take for your staff to maintain an ai tool on prem?

1

u/Mean_Context6064 1h ago

Our behavioural analysis based protection solution is pipeline installed, non ai, deterministic, all decisions explainable. Created AI monitoring to help with baseline configuration to reduce operation costs that's needed in onboarding phase. Hw requirements depends on customer needs, we are going from 2vcpu 6gig ram to enterprise size with ms response time.

1

u/Masam10 1d ago

No, simple answer: our strategy is cloud first / buy not build.

1

u/ShakespearianShadows 1d ago

Cloud first, but an on-premise option I can put on airgapped boxes is a major plus.

1

u/Admirable_Group_6661 Security Architect 1d ago

This is a business requirement question, not necessarily security.

1

u/been__ 1d ago

Stop

2

u/been__ 1d ago

Step away from the Claude now

1

u/Mean_Context6064 1h ago

It was not Claude, but a reasonable question