No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

As SaaS Evolves, Hybrid Models Take Center Stage

Why 2025 could mark a turning point in how companies deploy cloud applications

by Jason Purviance
January 20, 2025
in Data Privacy
cloud over skyscraper

As companies wrestle with data privacy and compliance in the cloud era, hybrid SaaS deployments are emerging as a compelling solution. ModeOne CIO Jason Purviance examines the advantages and potential drawbacks of this approach, offering insights into what lies ahead for corporate data management. 

The decline of traditional on-premises data centers continues, with companies migrating to cloud infrastructures offered by providers like Amazon Web Services (AWS), Microsoft Azure and Google Cloud Platform (GCP). The Covid-19 pandemic further accelerated this trend, as remote work necessitated scalable and accessible cloud solutions. 

This migration is often driven by the desire for scalability, cost efficiency and the agility that cloud environments offer. The cloud offers flexible resource allocation, global accessibility and a pay-as-you-go model that aligns costs with actual usage.

The transition to cloud services has also funneled enterprises toward vendor-managed Software as a Service (SaaS) solutions. SaaS deployments offer ease of enrollment, reduced need for internal IT management and the promise of continuous updates without the overhead of manual installations. 

However, the shift to vendor-managed SaaS applications also raises a critical question: How can enterprises maintain control over their data? When they adopt vendor-managed SaaS applications, they may entrust sensitive data — including customer information, proprietary business data and regulated data like electronic protected health information (ePHI) — to third-party providers. 

This reliance raises concerns about data privacy, compliance with evolving regulations and exposure to potential security breaches. A hybrid approach is a potential solution for many companies, though it, too, isn’t without its drawbacks.

Reimagining SaaS deployment: A middle ground

Hybrid SaaS isn’t a new term or concept. Cloud providers offer marketplaces where software creators can publish their applications as deployable packages. These packages include all necessary components — compute resources, databases, networking configurations and security policies — required to run modern applications. Enterprises can deploy these applications within their own cloud environments, maintaining control over the underlying infrastructure and data.

Imagine, for example, deploying your company’s cloud CRM in your own corporate cloud, running the servers, with databases all set up from a single deployable package from a cloud marketplace, and with updates and enhancements arriving seamlessly from the marketplace on your schedule. All of your client records are stored in a database that you control and manage; you know who has access to it, but it’s in your cloud infrastructure. You still enjoy the benefits of not managing physical hardware or doing database updates, but you retain control, ensuring your data isn’t co-mingled with other tenants.

small child using computer
Data Privacy

The Digital Playground: Children’s Online Safety & Privacy Compliance

by Ryan Smyth, Marygrace Jay and Michael Spadea
December 17, 2024

Laws increasingly call on companies to specially protect kids’ data

Read moreDetails

Advantages of deploying hybrid SaaS in corporate cloud infrastructure

Enhanced data privacy and compliance

Data privacy has become a paramount concern for enterprises navigating the increasing complexity of data privacy regulations. With the proliferation of data breaches and the tightening of global data protection regulations like GDPR and CCPA, organizations are under immense pressure to safeguard sensitive information. Traditional SaaS models, while convenient, often require companies to relinquish control over their data to third-party vendors, potentially exposing them to compliance risks and unauthorized access. By adopting a hybrid approach and deploying SaaS applications within their own cloud infrastructure, enterprises can reclaim authority over their data. This not only ensures adherence to stringent data privacy laws and residency requirements but also reinforces customer trust by demonstrating a committed stance on data protection. 

Improved security posture

Managing the application infrastructure allows organizations to implement their security protocols, monitor for threats and quickly respond to incidents. It reduces reliance on third-party security measures, which may not align with the enterprise’s risk management strategies. While it may seem like a step back toward managing infrastructure, it’s highly likely that you are still doing that to some extent today.

Updates and maintenance

SaaS companies perform updates when it’s convenient for them, not always for the customer. Under the hybrid approach, enterprises can tailor the application’s update schedule to meet their needs, in alignment with their own maintenance windows and their training and release schedules.

Potential drawbacks of hybrid deployments

While the advantages of hybrid cloud implementations are many, decision-makers must consider downsides. Managing a hybrid cloud environment can be complex, requiring specific skillsets and roles suitable to managing a corporate cloud with both private and public cloud resources.

Security also remains a critical concern. Although keeping data in the customer-managed cloud while the application runs in a public cloud may solve many security concerns and issues, it may also introduce new security concerns. For example, hybrid models allow for greater control by keeping sensitive data in customer-controlled environments, but integration points like APIs and gateways can introduce vulnerabilities, and misconfigurations or inadequate monitoring can expose systems to breaches.

Hybrid clouds also require organizations to incur both the cost of the SaaS application itself (on-demand or other licensing/user fees) and the cost of maintaining their own cloud or on-premises environment to store the scoped data. For resource-constrained IT teams, maintaining a cloud or on-premises environment to host the scoped data may stretch resources or require additional hires. However, larger companies may already have an on-premises or cloud environment and would be able to absorb the overhead; for that reason, these organizations may be a better fit for the hybrid model.

In some circumstances, hybrid deployments simply aren’t appropriate. Some legacy applications, for instance, may require significant refactoring to function across multiple platforms. Industries with low sensitivity to data sovereignty or regulatory requirements may not benefit from the added complexity of a hybrid cloud; for them, simpler public cloud solutions might suffice.

Companies should look at their risk tolerance and their regulatory and compliance requirements to determine if a hybrid model provides enough benefits by mitigating risks, while at the same time considering any new risks that may be introduced. Hybrid clouds provide a compelling balance of control and scalability, but their suitability depends on specific organizational needs, workloads and capabilities.

Predictions for 2025 & beyond

Will more software vendors adapt by offering their applications through cloud marketplaces, providing deployment packages that enterprises can manage within their environments? Can we anticipate an increase in enterprises adopting this hybrid SaaS model? In spite of the potential drawbacks for at least some organizations, I think we can.

The evolution of the hybrid model blurs the lines between traditional SaaS and on-premises applications, fostering a new paradigm where control and convenience coexist and offering the distinct advantage of a symbiotic relationship. Vendors benefit from broader distribution and simplified update processes, while enterprises regain control over their data and compliance posture.

Embracing a balanced future

The journey from on-premises data centers to vendor-managed SaaS applications has been marked by trade-offs between control and convenience. The emergence of marketplaces and the hybrid cloud offers a middle ground between the hassles and costs of managing a physical data center and the risks of trusting a SaaS software company with your data. While traditional SaaS solutions are here to stay, companies that choose the hybrid option can enjoy all of the benefits of modern applications while maintaining sovereignty over their data.

In a world where data is their most critical asset and regulatory landscapes are constantly changing, organizations must prioritize control and security without hindering innovation. For many, the hybrid SaaS model represents a step toward a future in which enterprises are no longer forced to choose between agility and governance — why not have both?


Tags: Cloud ComplianceData Governance
Previous Post

What Corporate Leaders Can Expect From Trump on Executive Pay

Next Post

Digital Collaboration: Risk Assessment’s Next Chapter

Jason Purviance

Jason Purviance

Jason Purviance is chief information officer of ModeOne, a smartphone data discovery firm. He is a seasoned litigation professional who has spent the past 20 years in a variety of litigation technology roles, including litigation project management, evidence collections, processing, hosting, productions, IT and information security.

Related Posts

doj building sign with flags

‘Reasonable Steps’: What the DOJ Expects From Your Bulk Data Transfer Compliance Program

by Alexandra P. Moylan, Alisa L. Chestler and Michael J. Halaiko
May 5, 2025

Sample provisions offer blueprint for compliant data brokerage with foreign entities

data security program concept cameras

Your Sensitive Data Is Now a National Security Matter: The DOJ’s New Data Security Program

by Randall Cook, Vince Mekles and Rachel Woloszynski
April 29, 2025

90-day implementation window closing on regulations affecting companies with genomic, biometric, health and other personal information

Electronic Evidence Collection for eDiscovery and Compliance

Electronic Evidence Collection for eDiscovery and Compliance

by Corporate Compliance Insights
March 30, 2025

Are you prepared to manage modern data sources in your compliance program? Whitepaper Electronic Evidence Collection for eDiscovery and Compliance...

examining data on laptop screen

Privacy Rights Surge Forces Rethink of Data Management

by Gal Ringel
March 14, 2025

As global privacy regulations multiply, organizations face mounting pressure to efficiently respond to data subject requests amid complex data environments

Next Post
digital hands reaching out

Digital Collaboration: Risk Assessment’s Next Chapter

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights