Back to blog
Cloud & Backup·

Hybrid Cloud Strategy for Indian Businesses: Where Each Workload Belongs

IT technicians configuring network rack and firewall in an Indian office server room for a hybrid cloud deployment

The ₹18 lakh question that started this

In March 2025 a 140-person logistics company in Peenya asked us to move everything to the cloud. Everything. Their CFO had read that data centres were dead, and their IT lead had been given a number: ₹18 lakh a year in projected savings across two years. We modelled it against what they actually ran — a 6-year-old Dell PowerEdge R640 pair, a Synology RS3621xs+ NAS, a FortiGate 100F, and a Tally server that three finance staff hit continuously from 9am to 7pm. The number flipped. It was not ₹18 lakh saved, it was ₹11-14 lakh added per year, before they accounted for the ERP rewrite. We kept roughly 70% on-premise and moved the rest. That is what a hybrid cloud strategy actually looks like for most Indian businesses between 20 and 500 staff: a deliberate split, not a wholesale migration.

This article is for the IT manager or ops head who has been asked to produce a cloud strategy and suspects the honest answer is "it depends". It does depend, but on a small number of specific variables. We will go through them with real 2026 prices, named hardware, a failure story with a rupee figure attached, and the parts where our own managed services approach is the wrong fit.

What "hybrid" actually means in an Indian mid-market context

Hybrid cloud has been mangled by vendor marketing into something close to meaningless. For our purposes, it is this: some workloads run on hardware you own or lease in a facility you control, and some run on public cloud infrastructure you rent, and the two estates talk to each other over a network you have designed for that purpose. That is it. There may be a private cloud layer (VMware vSphere 8, Proxmox VE 8, or Azure Stack HCI) sitting on top of the on-prem hardware. There may not.

The three reasons a mid-market Indian firm ends up hybrid rather than fully one or the other:

Latency that public cloud cannot fix from Mumbai or Hyderabad. A Mumbai region round trip to a Bangalore office is 18-30ms on a good day, and considerably worse when an ISP has a routing incident. For line-of-business software doing thousands of small database transactions per hour, that delay compounds into visible user pain. Tally Prime, busy accounting, and most older ERP installations fall into this bucket.

Data residency and regulatory pull. DPDP Act 2023 obligations, RBI storage directions for payment data, and CERT-In's 6-hour incident reporting requirement all nudge certain datasets toward infrastructure you can point at. Not everything. But some things.

Sunk cost that has not yet been amortised. A server bought in 2023 has a 5-7 year useful life. Ripping it out in 2026 to "go cloud" writes off three years of depreciation and replaces it with an opex line. Sometimes that is the right call. Often it is not.

The workloads that stay on-prem, and why

Not every on-prem workload is on-prem for a good reason. We regularly find things staying on local metal purely out of inertia. But there are categories where on-prem is genuinely the better call, and we would push back on a migration:

WorkloadTypical sizeWhy on-prem winsCloud cost if migrated (2026)
Tally Prime / Busy accounting (multi-user)5-40 concurrent usersConstant small transactions; latency above ~10ms is visible to finance staff during month-end close₹18,000-₹35,000/month for equivalent compute + SQL licensing + egress
Manufacturing ERP with shop-floor terminals20-200 devicesShop floor LAN latency, unreliable Wi-Fi in plant areas, integrations with legacy serial/PLC systems₹40,000-₹90,000/month plus integration rework
CCTV NVR storage16-128 cameras24×7 high-bitrate write traffic; cloud egress and storage costs escalate fast₹60,000-₹3,00,000/month depending on retention
CAD / design file servers10-60 engineersLarge file reads (200MB-2GB per open); cloud file sync is unusable for SolidWorks/Revit workflows₹50,000-₹1,50,000/month plus per-seat sync licences
Voice / SIP PBX trunks50-400 extensionsJitter and packet loss are audible; local breakout mattersMarginal savings, real quality risk
Backup repository (first copy)VariesRestore speed over LAN vs WAN; egress charges on full restoresEgress alone can hit ₹80,000+ per full DR test

The workloads that should move, and the ones that surprise people

Email and collaboration moved years ago and nobody argues. Microsoft 365 Business Standard is ₹1,050 per user per month plus GST on the annual commitment in 2026, and running Exchange 2019 on-prem to match that feature set costs more than the licence once you count patching, DAG design, and a second server for redundancy. Just move it.

Where it gets interesting is the middle tier:

  • CRM and support ticketing: move. These are bursty, user-facing, and benefit from the vendor's own uptime engineering. Zoho CRM Plus at ₹1,500/user/month and Freshdesk Pro at ~₹1,300/agent/month are better than anything you will run yourself for under ₹10 lakh.
  • Dev/test environments: move. Spin up, tear down. On-prem dev boxes sit idle 80% of the time and still consume power and licensing.
  • Web front ends and API gateways: move, unless you have a specific reason not to. Azure App Service or a small AWS ECS footprint handles this at ₹6,000-₹25,000/month for typical mid-market loads.
  • Data warehouse / analytics: split. A nightly ETL that pulls 50GB from on-prem ERP into a cloud warehouse (Snowflake, BigQuery, or Microsoft Fabric) works fine. Real-time analytics on on-prem transaction data does not work without expensive private connectivity.
  • Domain controllers: controversial. We keep at least one on-prem DC in almost every deployment because an office that loses internet should still let people log in. Azure AD Connect syncs the identities. People argue about this; we do not move the last DC.

The connectivity layer is where hybrid strategies actually fail

Every hybrid strategy document we have seen underestimates connectivity. Cloud architects in Bangalore offices design beautiful multi-region architectures and then discover that the Jayanagar branch has a 40Mbps VDSL line with a 3-hour MTTR from the local ISP.

Here is what actually works in 2026 across Indian offices:

Primary links

  • ACT Fibernet Enterprise: available in most Bangalore commercial areas; 200Mbps symmetrical around ₹14,000-₹22,000/month with 99.5% SLA. Good enough for a 100-person office where cloud is the destination for email and CRM, not for ERP.
  • Airtel IQ / Airtel Business Internet: ₹18,000-₹35,000/month for 200-500Mbps in metro areas; better routes to Azure and AWS Mumbai than most local ISPs because Airtel peers directly.
  • Jio Business Fiber: ₹10,000-₹19,000/month for similar speeds; pricing aggressive, routing less consistent, support experience varies by circle.
  • Tata Tele Business: enterprise-grade, ₹35,000-₹80,000/month for 500Mbps+, with real SLAs and dedicated account management. Where we deploy when an ERP depends on the link.

The MPLS-vs-SD-WAN-vs-IPsec decision

For multi-branch Indian firms, MPLS is largely dead. Not because it is bad, but because the pricing has not come down while SD-WAN and IPsec have gotten better. A 20Mbps MPLS circuit between Bangalore and Chennai still runs ₹28,000-₹45,000/month. Two 200Mbps internet circuits at each site plus a FortiGate 100F running SD-WAN at each end — capex around ₹1.8-2.4 lakh per site, opex ₹28,000-₹44,000/month for both links — beats it on every metric except consistency, and consistency is only critical if you are running real-time voice between sites.

We generally deploy FortiGate 90G at branch sites under 50 users, FortiGate 100F or 200G at larger sites, and run FortiManager for centralised policy. The FortiGate 90G at ₹95,000-₹1,10,000 (2026 pricing, with 3-year UTP bundle) handles 200Mbps of inspected throughput comfortably. If you are doing full TLS inspection on top, size up to the 200G.

The failure story

In September 2024 monsoon season, a 90-person pharmaceutical distribution client in south Bangalore had a cabling incident. Their primary ACT link was on an aerial drop from a pole to a second-floor window, a routing choice made in 2019 because it was cheaper than trenching. During a three-day rain spell, water ingress into a joint box took the link down. Their failover should have been an Airtel circuit on a separate physical route. It was not — both cables ran along the same pole path, twenty metres apart. Both went down within four hours of each other.

The failure ran Monday through Wednesday. Their order desk could not process purchase orders because the ERP front end was cloud-hosted at the time. Forty-three orders delayed. Two hospital customers moved one-off emergency orders to a competitor. The measured cost, once their finance team reconciled it, was ₹6.8 lakh in lost margin plus an estimated ₹1.2 lakh in expedited logistics to recover some of it. The fix cost ₹92,000: two genuinely separate paths (one fibre, one a Jio fixed-wireless backup), a FortiGate 90G with proper SD-WAN failover rules tested quarterly, and ₹8,000 of outdoor-rated cable conduit. The cabling cost less than 2% of the loss.

If you take one thing from this article: your internet redundancy is only redundancy if the two paths are physically separate. Verify with your provider that they do not share a duct or pole run. Ask for it in writing.

Identity federation: the piece everyone postpones

Hybrid identity is where most mid-market deployments quietly become a security problem. The pattern we see: Exchange on-prem still running for some legacy reason, Microsoft 365 in the cloud, a Synology for file shares with local AD accounts, and a few SaaS apps with their own passwords. Users have four credentials. Nobody knows who has access to what. An auditor asks for an access review and the answer takes three weeks.

The right answer, in order of preference:

  1. Microsoft Entra ID Connect (formerly Azure AD Connect) in hybrid mode with Password Hash Sync. On-prem AD remains authoritative for on-prem resources. Cloud resources trust Entra ID. One password. This is what we deploy in 80% of our managed services engagements and it works.
  2. Entra ID with Pass-through Authentication if compliance requires passwords to never leave on-prem. More moving parts, more to break, and the benefit is mostly theoretical for a 200-person firm.
  3. Federated with AD FS. Do not. AD FS 2016 and 2019 have had a steady drip of vulnerabilities, Microsoft has been signalling its sunset for years, and the operational overhead of an AD FS farm for a firm under 500 people is unjustifiable.

For SaaS apps beyond Microsoft, deploy SAML SSO through Entra ID where possible. Zoho, Freshworks, Slack, Atlassian, and most others support it. If an app does not, and it is used by more than 10 people, push back on the vendor.

MFA and conditional access without breaking workflows

Every hybrid identity project runs into the same objection: "our finance team cannot do MFA every time they open Tally". Correct, and they should not have to. Split your policy:

  • On-prem resources behind the firewall: no MFA required, network location is the signal.
  • Cloud apps from managed office devices: MFA every 30 days, device compliance required.
  • Cloud apps from personal devices or outside India: MFA every session, no persistent tokens.
  • Admin roles: phishing-resistant MFA (FIDO2 keys or Windows Hello for Business), every session.

We deploy YubiKey 5 NFC keys at ₹4,500-₹6,000 each for admins. Ten keys is ₹50,000 and it removes the single most exploited attack vector we see. If you have a Microsoft 365 Business Premium licence (₹1,750/user/month in 2026), you have the conditional access features already; you just have to configure them.

The honest TCO model, with 2026 numbers

Here is a fully worked example. 150 users, two offices (Bangalore HQ, Chennai branch), mixed workload. This is close to the median profile of firms that ask us for this analysis.

Option A: Fully on-prem, no cloud

ItemCapexAnnual opex5-year TCO
2× Dell PowerEdge R760 (16-core Xeon Silver, 256GB RAM)₹9,20,000₹9,20,000
VMware vSphere Essentials Plus (3 hosts, 96 cores)₹2,60,000₹13,00,000
Microsoft Windows Server Datacenter (2×16-core, via CSP)₹9,80,000₹49,00,000
Storage: Synology RS3621xs+ with 12×8TB enterprise drives₹4,60,000₹40,000₹6,60,000
Exchange Server 2019 (2 servers, licences + CALs)₹3,40,000₹1,20,000₹9,40,000
Backup: Veeam + secondary NAS + offsite copy₹3,80,000₹90,000₹8,30,000
Power, cooling, racks, UPS (server room)₹2,20,000₹2,40,000₹14,20,000
IT staff time (0.5 FTE loaded)₹4,80,000₹24,00,000
Total₹23,20,000₹22,10,000₹1,33,70,000

That exchange figure is real and uncomfortable. Exchange Server 2019 extended support ends October 2025; if you are still on it in 2026 you are paying for Extended Security Updates at roughly ₹80,000-₹1,20,000 per server per year. If you are considering Exchange SE on-prem to replace it, that will be a very different animal to price and the numbers rarely favour it below 500 mailboxes.

Option B: Fully cloud

ItemCapexAnnual opex5-year TCO
Microsoft 365 Business Premium (150 users)₹31,50,000₹1,57,50,000
Azure compute for ERP front end + backend (B-series + SQL MI)₹18,60,000₹93,00,000
Azure Storage (5TB hot, 20TB cool)₹3,80,000₹19,00,000
Cloud backup (Veeam for Azure + secondary region)₹2,40,000₹12,00,000
Network egress (estimated, 2TB/month)₹2,60,000₹13,00,000
ExpressRoute connection (10Mbps, 2 sites)₹40,000₹3,60,000₹18,40,000
IT staff time (0.3 FTE)₹2,90,000₹14,50,000
Legacy system workarounds (added per above)₹4,20,000₹21,00,000
Total₹40,000₹69,60,000₹3,47,90,000

The Azure line items are conservative and they will grow. Cloud compute costs climb with data volume and usage patterns; nobody we work with has ever seen a 5-year Azure bill come in where the initial estimate was.

Option C: Hybrid (what we actually recommend here)

ItemCapexAnnual opex5-year TCO
2× Dell PowerEdge R660xs (ERP, Tally, DCs, file services)₹6,80,000₹6,80,000
Shared storage: Synology RS2423+ with expansion₹3,20,000₹30,000₹4,70,000
Microsoft 365 Business Standard + Business Premium for 30 users₹22,40,000₹1,12,00,000
Backup: Veeam B&R v12 to local NAS + Azure Blob immutable₹1,60,000₹1,10,000₹7,10,000
Azure compute for CRM, web front end, dev/test₹5,40,000₹27,00,000
Azure Blob storage (archive tier, 15TB)₹60,000₹3,00,000
Network: 2× internet (ACT + Airtel), FortiGate 90G × 2₹2,10,000₹7,20,000₹38,10,000
Power, cooling, smaller UPS₹1,10,000₹1,80,000₹10,10,000
Entra ID Connect, MFA, SSO rollout₹80,000₹80,000
IT staff time (0.6 FTE — hybrid is more complex to run)₹5,80,000₹29,00,000
Total₹15,60,000₹44,60,000₹2,38,00,000

Five-year saving versus fully cloud: roughly ₹1.09 crore. Ten years out, as the on-prem hardware refreshes twice, the gap narrows considerably — maybe ₹30-50 lakh in favour of hybrid at the 10-year mark. If your firm plans a full exit from capital equipment by 2030, cloud is defensible. If not, hybrid wins on cost in almost every scenario we have modelled.

Note the honest detail: hybrid costs more IT staff time than either extreme. You are running two environments. Anyone who tells you hybrid is easier to operate than pure on-prem or pure cloud is selling something.

Where this analysis does not apply

We would be doing you a disservice if we pretended hybrid was always right. Cases where we tell clients to go straight to cloud and stay there:

  • Under 30 employees with no legacy server applications. If your entire workload is email, file sharing, and a SaaS CRM, there is nothing to hybridise. Buy Microsoft 365 Business Premium and a good NAS for local file speed if needed, and be done.
  • Startups planning to raise capital. Investors expect cloud-native architecture. On-prem gear looks like legacy debt on the balance sheet. Cloud costs twice as much and is the right answer anyway for the audience.
  • Firms with no server room and no physical security. If your "server room" is a cupboard next to the pantry, with no access control and no UPS, everything should move to cloud until you can fix that. A ₹3 lakh server in an unsecured room is a liability.
  • Businesses operating across more than five states with rapid site turnover. Maintaining hardware in an office you may close in 18 months is not worth it. Cloud scales down for free.
  • Anything where the data is genuinely cloud-only by regulation or partner requirement. Some SaaS ecosystems just do not accept on-prem integrations any more.

There is one more honest caveat. Hybrid requires network engineering we can deliver but not every IT provider can. If your current IT support cannot describe the difference between a FortiGate SD-WAN rule and a static route, they will not run a hybrid estate. Get that capability in place before you build one.

The Microsoft 365 and Azure licensing traps

Aggressively relevant, because this is where most hybrid TCO models go wrong.

Microsoft 365 Business Premium: ₹1,750/user/month, maximum 300 users. Above 300, you move to Enterprise E3 at ₹2,750/user/month or E5 at ₹4,700/user/month. There is no gentle transition; the cliff is real and it arrives faster than anyone expects. Plan the licence tier by headcount five years out, not today.

Windows Server licensing through CSP: the Datacenter edition allows unlimited Windows VMs on a licensed host, which is why it appears in the on-prem option above. Standard edition allows only two. If you plan to run more than four or five VMs on a host, Datacenter is cheaper over five years, but the upfront line item looks large. Do not let procurement talk you into Standard to save money at year one.

Azure Hybrid Benefit: if you have Windows Server Datacenter with Software Assurance, you can bring that licence to Azure and pay only compute. Saves roughly 40% on Windows Server VMs in Azure. It is real and underused by Indian mid-market firms because nobody tells them.

Reserved Instances and Savings Plans: a 3-year Reserved Instance on Azure SQL Managed Instance saves 38-45% versus pay-as-you-go. If your Azure spend is stable, buy them. We see clients paying on-demand rates for workloads that have not changed shape in two years.

Backup architecture in a hybrid estate

Backup is where hybrid gets genuinely better than either pure model, and where poor design quietly wastes money.

The pattern we deploy:

  • Veeam Backup & Replication v12 at the on-prem site, backing up VMware VMs to a Synology RS2423+ with 22TB usable. Fast restores over LAN, near-instant VM recovery.
  • Veeam Agent for Microsoft Windows on physical servers, same repository.
  • Veeam Backup for Microsoft 365 (separate product, ₹350-₹550 per user per year depending on volume) backing up Exchange Online, SharePoint, and OneDrive. Yes, you need this. Microsoft's shared responsibility model means they do not back up your data in a restorable way — they replicate it, which protects against hardware failure and not against a user deleting a folder they have also deleted from the recycle bin.
  • Azure Blob storage with immutable container as the offsite target. 3-2-1 rule still applies. Immutable means even an attacker with admin credentials cannot delete the backups for the retention period, typically 30 days hot for quick recovery and 12 months archive.

Cost profile: 12TB of Azure Blob archive tier at 2026 rates, ₹0.85/GB/month, is around ₹1,05,000/year. Compare that to a monthly tape rotation or a courier to a Chennai facility, and it is not close.

One practical point: test your restores. We do full restore drills at least twice a year at every managed client. A restore that has never been tested is a hypothesis, not a backup.

GST treatment and procurement details that affect the math

Cloud services from Microsoft, Amazon, and Google billed through Indian entities attract 18% GST, creditable if you are GST-registered. This makes cloud opex effectively 18% cheaper for a GST-registered firm than the headline price suggests. Capex on servers and networking also attracts 18% GST, also creditable. In practice, the GST treatment is neutral for both options if you are registered; if you are not registered (some partnerships and smaller proprietorships), cloud is 18% more expensive than the sticker price and this shifts the calculation.

Input tax credit on the opex heavy cloud model is smoother than chasing credit on large capex purchases. Some finance teams prefer it for cash flow. Legitimate consideration, not typically decisive.

On import: servers bought from Dell or HPE India are domestically supplied and GST applies locally. Do not get talked into importing to save 3-4% — customs, duty, BIS compliance, warranty region issues, and the risk of grey-market firmware all eat the difference and then some.

A practical sequencing plan

If you are starting from an all-on-prem or all-cloud position and want to get to a sensible hybrid state, this is the order we use, and roughly what it costs.

Month 1-2: Assessment. Inventory every workload. Measure actual usage (not just CPU allocation — measure real transaction rates and IOPS with something like SolarWinds or PRTG for two weeks). Confirm network paths. Cost the target state. Typical fee: ₹1,50,000-₹3,50,000 for a firm of 100-300 people depending on complexity. We do this as the first milestone of most managed services engagements.

Month 2-3: Identity. Roll out Entra ID Connect, Password Hash Sync, MFA for admins, SSO for the top 5 SaaS apps. This makes every subsequent step easier. Budget ₹80,000-₹1,80,000 in professional services plus Microsoft licensing.

Month 3-5: Network. Separate physical paths. SD-WAN policy. Firewall rules audited. Documented. Budget ₹2,00,000-₹4,50,000 per site in capex and ₹25,000-₹60,000/month opex depending on link sizes.

Month 4-6: Move email and collaboration. If you have not already. This is the easy win and it unblocks the Exchange licensing conversation.

Month 5-9: Migrate the workloads that should move. Web front ends, dev/test, CRM if it is not already SaaS. Run in parallel for two weeks before cutting over. Have a rollback plan that is not "restore from backup" — that is not a rollback plan, that is a disaster recovery plan.

Month 8-12: Backup and DR. Now that the estate shape is known, build the backup architecture to match. Test restores. Document RTO and RPO for each workload. These should have been estimated earlier but they cannot be finalised until the architecture is settled.

Total capex for the full sequence at a 150-user firm: ₹10-15 lakh plus licensing. Total professional services: ₹8-14 lakh. Timeline: 12 months if you do not rush.

FAQ

Is hybrid cloud more expensive than pure cloud for an Indian SME?

Almost always, yes — over five years. Our worked model above shows roughly ₹1.09 crore saved versus a full-cloud approach for a 150-user firm. The gap narrows if you have no legacy server applications or plan to divest capital equipment, in which case cloud wins. It is workload-dependent, not a general rule.

How much bandwidth do I need for a hybrid cloud setup in Bangalore?

For 50-100 users with email, CRM, and a few SaaS apps in cloud: 200Mbps symmetrical with a secondary 100Mbps circuit of a different physical path. For 100-300 users: 500Mbps primary, 200Mbps secondary. Add 10-20% headroom over your peak measured usage. Do not count SD-WAN as a bandwidth saver — it is a failover and policy tool, not a compression tool in most deployments.

Can I keep Tally on-premise and still have a hybrid strategy?

Yes, and you probably should. Tally Prime is the archetypal workload that belongs on-prem because of its transaction pattern. Cloud-hosted Tally is possible via terminal services but every client we have seen do it reports slower month-end closes. Keep Tally on a dedicated VM on-prem with good local storage, back it up with Veeam, and treat the rest of the estate as hybrid.

What is the DPDP Act requirement for hybrid cloud data?

The DPDP Act 2023 requires that personal data of Indian data principals be processed with consent, with adequate security safeguards, and with breach notification to the Data Protection Board. It does not mandate Indian data residency for all categories. Certain data — payment data under RBI direction, some telecom and government data — has stricter residency rules. For most mid-market firms, keeping customer PII (names, phone numbers, addresses) either on-prem or in an Indian cloud region and documenting your protection measures is the pragmatic reading. Get a lawyer's opinion on your specific data categories; this is not legal advice.

How do I handle multi-cloud without making it worse?

Do not, unless you have a specific reason. Two clouds is twice the identity integration, twice the network paths, twice the egress cost modelling, and twice the skills requirement. A single primary cloud with an on-prem estate is hybrid. Two clouds plus on-prem is a complexity tax that fewer than 5% of Indian mid-market firms can justify.

What is a realistic timeline for moving to hybrid?

For a 150-user firm from an all-on-prem start: 10-14 months end to end if you do it properly. Compressing to six months is possible and we have done it, but it requires an internal IT team that can absorb the parallel work, and it usually means the backup architecture gets deferred. Deferring backup is how the failure stories start.

One concrete next step

Pick one workload and one number this week. Decide whether your finance ERP front end stays on-prem, based on the actual measured latency from your office to the closest cloud region it would run in. If you do not have the measurement, ask your network team or your ISP for a week of latency data — anything over 15ms p95 during business hours means the UI experience will be worse in cloud, and no amount of architecture elegance changes that. Bring that number to a conversation.

If you want a second opinion on the workload split, or you want the TCO model run on your actual environment rather than our median example, we are happy to do that. Our contact page is the fastest way in. Bring your last six months of Azure or AWS bills and your server refresh cycle; those two documents tell us 80% of the story before we log in.