Developing a Cloud Strategy: A Guide for SMEs
A cloud strategy defines how a company uses cloud services securely, economically, and predictably. It defines goals, suitable cloud models, governance, security rules, cost control, and a roadmap for applications, data, and operational processes. It's crucial for SMEs because otherwise, cloud projects can quickly become fragmented decisions: individual SaaS solutions, isolated migrations, unclear responsibilities, and escalating operating costs.
Many companies are already using cloud services without a clear strategy. Microsoft 365 is in use, some applications run externally, backups are partially outsourced, and departments subscribe to additional tools. Without a shared vision, parallel environments emerge, comprised of on-premises, public cloud, SaaS, and local servers. This complicates security, cost control, compliance, and operations.
This guide shows how SMEs can develop a structured cloud strategy: from cloud readiness and vision to public, private, and hybrid cloud, to governance, security, TCO, FinOps, and a realistic roadmap. The goal is not cloud computing at any cost, but a strategy that fits the company, the IT landscape and the business requirements.
Table of contents
- What is a cloud strategy?
- Why is a cloud strategy important for SMEs?
- Assessing cloud readiness: Is your IT ready for the cloud?
- Public cloud, private cloud, or hybrid cloud?
- Cloud strategy vs. cloud migration
- Developing a cloud strategy: 7 steps to a roadmap
- Governance, security, and compliance in the cloud
- Managing cloud costs: TCO, FinOps, and budget traps
- Cloud strategy in practice: Workshop and target vision
- Checklist before cloud implementation
- Conclusion
- FAQ on cloud strategy
What is a cloud strategy?
Cloud computing means that IT resources such as storage, computing power, applications, and platform services are not exclusively operated on the company's own servers, but are provided via external data centers and cloud providers. Examples include SaaS solutions like Microsoft 365, public cloud services like Azure, and hybrid models combining on-premises IT and cloud services.
A cloud strategy describes how a company intends to use these cloud services strategically. It defines which applications and data are suitable for the cloud, which systems should remain on-premises, which security and compliance rules apply, and how costs, operations, and responsibilities are managed.
A good cloud strategy therefore not only answers the question of whether a company should use cloud services. It establishes clear decision criteria so that cloud projects can be implemented economically, securely, and transparently.
A typical cloud strategy includes:
- Target vision and business requirements
- Assessment of the existing IT landscape
- Cloud readiness of applications and data
- Decision between public, private, hybrid, or multi-cloud
- Security and governance rules
- Cost model including TCO and FinOps
- Migration sequence and roadmap
- Operating model with roles and responsibilities
- Backup, monitoring, compliance, and disaster recovery planning
A cloud strategy is therefore not just an IT document. It connects management, IT, data protection, business units, and controlling. Only when these perspectives are brought together can a cloud concept emerge that works in practice.
Why is a cloud strategy important for SMEs?
A cloud strategy is crucial for SMEs because cloud usage without clear guidelines can quickly become confusing, expensive, and risky. Many problems arise not from the cloud itself, but from a lack of planning: unclear responsibilities, incorrect workload selection, unchecked data flows, weak permissions, or insufficient cost control.
Cloud services can make companies significantly more agile. They enable faster deployment, better scalability, modern security features, and location-independent work. However, these advantages don't happen automatically. They must be secured through architecture, governance, and operations.
Typical goals of a cloud strategy include:
- Faster IT deployment
- Better support for growth and new locations
- Reduce hardware cycles
- Improve security and availability
- Smooth integration of Modern Workplace and Microsoft 365
- Improve backup and disaster recovery
- Modernize applications step by step
- Manage costs more transparently
- Provide verifiable documentation of compliance and data protection
Without a strategy, shadow IT, redundant systems, and increasing complexity often result. A department uses a SaaS tool, IT continues to operate local servers, data resides in multiple locations, and no one has a complete picture of access, costs, or responsibilities.
A good cloud strategy prevents exactly this. It ensures that cloud decisions are not made randomly, but according to clear criteria.

Check cloud readiness: Is your IT ready for the cloud?
Cloud readiness means that applications, data, identities, networks, and operational processes are assessed to ensure secure and predictable cloud usage. For SMEs, a massive transformation project is usually insufficient; instead, a structured inventory with clear criteria is sufficient.
Before companies decide on migration, providers, or specific cloud services, they should understand their current IT landscape. It's crucial not only to identify existing systems but also to understand their dependencies and the requirements for security, availability, and data protection.
Key questions regarding cloud readiness include:
- What applications are in place?
- What data is processed?
- Who is responsible for the business and technical aspects?
- What interfaces and dependencies exist?
- Which systems are business-critical?
- What are the availability and recovery requirements?
- Which data may be stored where?
- What identity and authorization concepts are in place?
- What backup and restore processes are in place?
- What are the current operating costs?
The assessment of applications is particularly important. Not every application automatically belongs in the cloud. Some systems benefit greatly from cloud services, while others are better off remaining local or hybrid due to latency, specialized hardware, regulatory requirements, or integration problems.
Assess the cloud fit of applications
Cloud fit describes how well an application is suited for the cloud. This involves not only technical feasibility, but also benefits, risks, costs, and operational aspects.
Typical evaluation criteria include:
| Criteria | Importance for cloud strategy |
|---|---|
| Business criticality | How much does operation depend on the application? |
| Data criticality | Are sensitive or personal data processed? |
| Integrations | Which interfaces, databases or legacy systems are connected? |
| latency | Are there requirements for very fast local response times? |
| Degree of modernization | Is the application cloud-ready, container-ready, or severely outdated? |
| Operating costs | Are there high maintenance costs or hardware expenses? |
| Availability | What RTO and RPO targets must be met? |
| Compliance | Are there any requirements regarding data location, storage, or auditing? |
A good initial target is applications with manageable dependencies and recognizable benefits. Highly critical core systems should only be migrated once governance, monitoring, backup, and operational processes are reliably in place.
Public cloud, private cloud or hybrid cloud?
A cloud strategy must define which cloud model best suits the company. The most important models are public cloud, private cloud, and hybrid cloud. For many SMEs, a hybrid model is the most realistic option because existing systems are not immediately replaced, and certain applications remain on-premises.
For strategic guidance on cloud usage, interoperability, and data sovereignty, companies can also consider the European Commission's cloud strategy.
Public Cloud
Public cloud means using cloud services from providers like Microsoft Azure, AWS, or Google Cloud. Businesses benefit from scalability, managed services, rapid deployment, and usage-based billing.
Public cloud is particularly well-suited for:
- Web applications
- Development and test environments
- Data analytics
- Scalable workloads
- Backup and disaster recovery scenarios
- Modern platform services
- Microsoft 365-related services
The biggest risks usually lie not with the provider, but with misconfigurations, unclear permissions, uncontrolled costs, or a lack of governance.
Private Cloud
A private cloud describes a cloud-like environment operated exclusively for a single company. This can be in the company's own data center or with a service provider. It offers greater control but usually requires more in-house management and clear capacity planning.
A private cloud is a good choice when there are specific requirements regarding control, integration, data storage, or existing infrastructure. If existing virtualization environments are to be continued or modernized, a Proxmox or hybrid architecture can also be part of the cloud strategy. However, it is not automatically cheaper or more secure. Standardization, monitoring, backups, and clear operational processes are still essential.
Hybrid Cloud
Hybrid cloud combines on-premises IT, private cloud, public cloud, and SaaS services. For SMEs, this is often the most realistic target scenario because existing systems, Microsoft 365, on-premises applications, and cloud services are operated together.
Hybrid cloud makes sense when:
- certain applications must remain on-premises
- Microsoft 365 is already in use
- individual workloads should be moved to the public cloud
- cloud-based backup or disaster recovery is needed
- better support for on-site and remote work
- modernization should be phased
The challenge lies in the complexity. Identities, networking, monitoring, backup, security, and operations must function across multiple environments.
Multi-cloud: useful or too complex?
Multi-cloud means using multiple public cloud providers in parallel. This can be beneficial if there are clear reasons: specific services, regulatory requirements, redundancy, or exit strategies. However, for many SMEs, multi-cloud primarily increases complexity.
Multiple providers mean multiple security models, billing logics, tools, roles, and operational processes. Therefore, multi-cloud should only be chosen if the benefits justify the additional complexity.
Cloud strategy vs. cloud migration
Cloud strategy and cloud migration are not the same. Cloud strategy defines goals, rules, priorities, and the target architecture. Cloud migration is the technical implementation of individual applications or data into this target architecture.
Many companies start migrations too quickly. This simply shifts existing problems to a new environment: oversized servers, unclear permissions, missing documentation, poor backup processes, or unnecessary costs.
Therefore, before a migration, existing systems should be reviewed as part of server maintenance to ensure that outdated servers, missing updates, and untested backups are not simply moved to the cloud.
A sensible sequence is:
- Clarify goals and requirements
- Evaluate the IT landscape
- Define the cloud model and target architecture
- Define governance and security principles
- Select a roadmap and pilot project
- Implement migrations in phases
- Ongoingly monitor operations, costs, and security
Overview of migration approaches
Depending on the application, there are different migration approaches:
| Approach | Meaning | Suitable for |
|---|---|---|
| Rehost | Postpone application almost unchanged | rapid data center replacement |
| Replatform | Utilize targeted platform improvements | Databases, web applications |
| Refactor | Technically modernize the application | long-term cloud-native use |
| Replace | Replace application with SaaS | Standard processes |
| Retire | Turn off the application | outdated or unnecessary systems |
| Retain | Keep the application local for now. | Legacy, specialized hardware, latency |
Lift-and-shift can be useful in the short term, but it is rarely a complete strategy. Without adapting to cloud operations, it often results in high costs and limited benefits.
Developing a cloud strategy: 7 steps to a roadmap
A cloud strategy can be developed in 7 steps. The goal is an actionable roadmap that integrates business objectives, technical requirements, security, costs, and operations.
Step 1: Goals
It all starts with clear business objectives. Cloud computing shouldn't be an end in itself. Define what specifically needs to be improved.
Possible goals include:
- Faster deployment of new systems
- Improved scalability
- Reduced hardware costs
- Higher availability
- Better support for remote work
- More secure Microsoft 365 integration
- Improved recoverability
- Transparent cost control
It's crucial to make goals measurable. Instead of "more flexibility," you need concrete key performance indicators (KPIs), such as shorter deployment times, defined RTO/RPO targets, or clear cost budgets.
Step 2: Define scope and principles
The scope defines which areas are considered first: specific locations, applications, data types, or business units. Cloud principles dictate the rules by which decisions are made.
Examples of cloud principles:
- Cloud only with clearly defined responsibilities
- No production workloads without monitoring and backup
- Multi-factor authentication (MFA) and least privilege as minimum standards
- Data classification before migration
- Cost centers and tagging are mandatory
- Standard services before custom solutions
Step 3: Assess the current landscape
Document applications, data, interfaces, user groups, operating costs, security requirements, and technical dependencies. This inventory forms the basis for prioritization and roadmap development.
Systems related to identities, files, email, ERP, databases, or backups are particularly important. Unexpected dependencies often arise in these areas during cloud projects.
Step 4: Develop the target architecture
The target architecture describes how cloud services will be used and connected in the future. It encompasses identity, network, security, logging, backup, monitoring, data storage, and operational boundaries.
For SMEs, a few clearly defined architectural building blocks are often sufficient:
- Identity model
- Network and access model
- Security baseline
- Backup and recovery concept
- Logging and monitoring
- Standard patterns for typical workloads
- Operational responsibilities
Step 5: Define the cloud model and provider criteria
Decide whether a public cloud, private cloud, hybrid cloud, or a combination of both is the right choice. Additionally, define your provider criteria.
Key criteria include:
- Data residency and contractual framework
- Integration with existing IT infrastructure
- Security and compliance features
- Support model
- Cost and billing logic
- Exit options
- Existing in-house expertise
- Compatibility with Microsoft 365 and existing systems
Step 6: Plan the roadmap in waves
The roadmap translates the strategy into concrete implementation steps. Instead of migrating everything at once, workloads should be prioritized in waves.
A sensible roadmap includes:
- Preparatory work for identity, network, and governance
- Pilot workload
- Migration waves
- Dependencies
- Effort estimation
- Responsibilities
- Security and backup requirements
- Cost assumptions
- Handover
The pilot should be manageable but demonstrate real value. It serves to test the technical foundations, processes, and cost model.
Step 7: Define operations, KPIs and optimization
Cloud strategy doesn't end with migration. Ongoing operations are crucial. This includes monitoring, patch management, backups, incident response, cost reviews, and regular security audits.
Relevant KPIs include:
- Deployment time of new systems
- Cost variance against budget
- Number of critical security findings
- Backup and restore success rate
- RTO/RPO test results
- Availability of business-critical workloads
- Number of unresolved exceptions
Governance, security and compliance at the cloud
Governance, security, and compliance are central components of any cloud strategy. Without clear rules, misconfigurations, unnecessary costs, unclear access rights, and difficult-to-trace data flows can occur.
Cloud Governance
Cloud governance defines how cloud services are used, managed, and controlled. It encompasses roles, policies, approvals, technical guidelines, and regular reviews.
Key governance components include:
- Roles and responsibilities
- Landing zone or baseline architecture
- Naming and tagging standards
- Budget and cost rules
- Access concepts
- Security policies
- Approval processes
- Logging and reporting
- Exception documentation
Good governance isn't bureaucratic; it helps teams make informed decisions faster.
Cloud security
Cloud security is based on clear principles: strong identities, least privilege, encryption, monitoring, backup, and rapid incident response. It's particularly important not to view cloud security in isolation. It must work in conjunction with endpoint security, backup, and server operations.
Especially with Microsoft 365, it's crucial to verify that mailboxes, OneDrive, SharePoint, and Teams data can be restored independently.
Important security measures include:
- MFA for all relevant accounts
- Least Privilege
- Conditional Access
- Centralized logging
- Encryption
- Network segmentation
- Regular security reviews
- Backup and restore testing
- Incident response processes
- Monitoring of misconfigurations
Compliance and GPDR
For GDPR-relevant data, companies must clearly document which data is processed, where it is stored, who has access and which technical and organizational measures have been implemented.
Important points are:
- Roles as controller or processor
- Order processing contracts
- Data flows and data locations
- Deletion and retention periods
- Authorization concepts
- Encryption
- Logging
- Evidence of technical and organizational measures
- Audit of subcontractors
- possible data protection impact assessment
The Austrian Data Protection Authority and the Chamber of Commerce offer guidance on the GDPR, technical measures and documentation requirements.
Managing cloud costs: TCO, FinOps and budget traps
Cloud costs are controllable, but they behave differently than traditional IT investments. Instead of a one-time purchase, there are ongoing, usage-based costs. Without transparency, budgets can quickly be exceeded.
Calculate TCO realistically
TCO stands for Total Cost of Ownership. A realistic TCO analysis includes not only cloud resources, but also migration, operation, security, monitoring, backup, support, and training.
Typical cost categories include:
| Cost block | Examples |
|---|---|
| Cloud usage | Compute, Storage, Databases, Network, Support |
| Migration | Assessment, adaptation, testing, cutover, documentation |
| Security | Logging, monitoring, SIEM, key management, audits |
| Backup & Recovery | Backup storage, restore tests, DR scenarios |
| Operation | Administration, On-Call, Automation, Runbooks |
| training | Cloud skills, security, FinOps, operational processes |
Common budget traps
Typical cloud budget traps arise from:
- Oversized resources
- Unpowered test environments
- High data transfer costs
- Unclear licensing models
- Lack of tagging
- Shadow IT
- Duplicate operational phases
- Lack of cost accountability
- Insufficient automation
- Unplanned backup and restore testing
Many cost problems can be avoided if budgets, responsibilities, and regular reviews are part of the cloud strategy from the outset.
FinOps for SMEs
FinOps connects IT, controlling, and business departments. The goal is to make cloud costs transparent and actively manage them.
For SMEs, simple measures are often sufficient:
- Tagging by application, team, and cost center
- Budgets per department
- Cost alerts
- Monthly cost reviews
- Shutting down unused resources
- Limiting access rights for new resources
- Checking reservations for stable workloads
- Documenting and explaining deviations
FinOps is not just a controlling issue. It ensures that technical decisions and economic responsibility are aligned.

Cloud strategy in practice: Workshop and target vision
In practice, a cloud strategy workshop is often the fastest way to reach a shared vision. Crucially, the workshop must deliver concrete results and not just focus on general cloud benefits.
A good cloud strategy workshop clarifies:
- business objectives
- current IT landscape
- cloud readiness
- risks and dependencies
- cloud model
- target architecture
- minimum security and governance standards
- cost assumptions
- pilot candidates
- roadmap and next steps
Typical deliverables include:
- vision and principles
- prioritized application portfolio
- cloud fit assessment
- roadmap in phases
- governance and security baseline
- high-level business case
- action plan
- responsibilities
FIGULI CONSULTING supports companies in developing a structured cloud strategy: from initial assessment and target architecture to roadmap, governance, cost control, security, and implementation preparation.
Checklist before cloud implementation
Before implementing cloud solutions, companies should clarify key questions. This checklist helps to identify typical gaps early on.
Strategy and goals
- Are business and IT goals clearly defined?
- Are there measurable success criteria?
- Is the scope of the first phase defined?
- Does management and IT share a common vision?
IT landscape and applications
- Is there an up-to-date application inventory?
- Are data, interfaces, and dependencies documented?
- Have critical applications been identified?
- Has the cloud fit been assessed?
Security and Compliance
- Is there an identity and authorization concept?
- Are multi-factor authentication (MFA) and least privilege implemented?
- Are data locations and data flows defined?
- Are GDPR requirements documented?
- Is there a backup and restore concept?
Costs and operation
- Is a total cost of ownership (TCO) analysis in place?
- Are budgets and cost owners defined?
- Are there tagging standards?
- Are monitoring, incident response, and handover procedures planned?
- Are internal skills and external support secured?
Short checklist to tick off
- Target vision and KPIs defined
- Applications and data inventoried
- Cloud fit assessed
- Cloud model selected
- Governance rules established
- Security baseline defined
- Backup and restore planned
- TCO and budgets calculated
- Roadmap created in phases
- Pilot selected
- Responsibilities clarified
Conclusion
A cloud strategy helps SMEs use cloud services securely, economically, and predictably. The key is not to move as many systems to the cloud as quickly as possible. What matters is a clear vision with suitable cloud models, a realistic roadmap, governance, security, compliance, and cost control.
For many companies, a hybrid approach makes sense: Microsoft 365 and selected cloud services are used, while certain applications remain on-premises or are modernized gradually. For this model to work, identity, network, monitoring, backup, security, and operations must be planned together.
If you lack the time, expertise, or overview internally, FIGULI CONSULTING can help you develop a structured cloud strategy and derive concrete next steps.
Discuss your cloud strategy with FIGULI
FAQ on Cloud Strategy
What is a cloud strategy?
A cloud strategy is a binding plan for the use of cloud services within a company. It defines goals, cloud models, target architecture, governance, security rules, cost control, responsibilities, and a roadmap for applications and data.
Why do SMEs need a cloud strategy?
SMEs need a cloud strategy because cloud usage without clear guidelines quickly leads to shadow IT, rising costs, security vulnerabilities, and unclear responsibilities. A strategy helps to use cloud services in a targeted, secure, and cost-effective manner.
What is included in a cloud strategy?
A cloud strategy includes a target vision, cloud readiness, application and data assessment, selection of the cloud model, governance, security, compliance, TCO, FinOps, a roadmap, an operating model, and responsibilities.
What is the difference between a cloud strategy and cloud migration?
The cloud strategy defines goals, rules, the target architecture, and the roadmap. Cloud migration is the technical implementation of individual applications or data in the cloud. Without a strategy, migration can lead to cost problems, security vulnerabilities, and inconsistent architectures.
What cloud models are there?
The most important cloud models are public cloud, private cloud, and hybrid cloud. Public cloud offers scalable services from large providers. Private cloud offers more control. Hybrid cloud combines on-premises IT, cloud services, and SaaS solutions.
Is hybrid cloud a good option for SMEs?
Hybrid cloud makes sense for many SMEs because existing applications don't need to be replaced immediately. On-premises systems, Microsoft 365, cloud services, and backup solutions can be combined. Unified identities, monitoring, security, and clear operational processes are crucial.
How do you realistically calculate cloud costs?
Cloud costs should be calculated using Total Cost of Ownership (TCO). This includes not only compute and storage but also migration, networking, licenses, security, monitoring, backup, operations, support, and training. Additionally, FinOps, tagging, budgets, and regular cost reviews are helpful.



