Cloud Services for Enterprise: The Strategic Migration Guide
Cloud migration is not a single event — it is a multi-year programme of portfolio modernisation. Most organisations discover this the hard way after a "lift and shift" migration that delivers cloud billing without cloud benefits. Understanding the full strategic scope from the start is what separates organisations that realise cloud's compounding returns from those that end up cloud-washed on-premises infrastructure at higher cost.
Why Cloud Migrations Go Wrong
Discovery failures. The most common cause of cloud migration delays and incidents is undiscovered application dependencies — application A calls application B's database directly, a batch job runs on a server also serving another purpose, a legacy integration has no documentation. Revino's migration methodology begins with automated dependency mapping, not assumptions.
Treating cloud as a cheaper data centre. Lifting and shifting on-premises virtual machines to cloud IaaS is the worst of both worlds: you pay cloud variable pricing without getting cloud-native benefits. The real value of cloud — auto-scaling, managed databases, serverless functions, MLaaS, global edge delivery — requires re-architecture, not just migration.
FinOps neglect. Organisations routinely discover they are spending 40–60% more than necessary because of over-provisioned instances, unused resources, data transfer costs between regions and availability zones, and absence of Reserved Instance planning. FinOps governance must be implemented before migration, not after the first large cloud bill.
Security as an afterthought. Lifting a VM to cloud with the same security controls as the data centre ignores the fundamentally different threat model: public cloud surfaces are different from private networks, IAM roles replace network-based access control, and cloud-native security services (AWS GuardDuty, Azure Defender, GCP Security Command Center) need configuration to provide value.
The 6Rs Migration Framework in Practice
Rehost (lift-and-shift): Move the application to cloud IaaS without changing it. Fastest to execute, captures 15–25% of potential cloud benefit. Appropriate for time-sensitive migrations and applications planned for retirement within 3 years.
Replatform (lift-tinker-and-shift): Make targeted cloud optimisations without changing the core architecture — migrate from self-managed database to RDS, move to Elastic Beanstalk for application hosting, adopt S3 for object storage. Captures 40–55% of potential benefit. The sweet spot for most commercial applications.
Repurchase: Move from on-premises software to SaaS — replace self-managed CRM with Salesforce, self-managed email with Google Workspace, self-managed HR with Workday. Eliminates infrastructure management entirely for the replaced systems.
Refactor/Re-architect: Decompose the application into cloud-native microservices, adopt serverless where appropriate, implement auto-scaling, and leverage managed cloud AI/ML services. Captures 80–95% of potential cloud benefit. Appropriate for core business applications with 5+ year lifespans.
Retire: Eliminate applications that are no longer needed. Discovery consistently surfaces 10–15% of the application portfolio as retirement candidates — removing them reduces migration cost and ongoing operational complexity.
Retain: Keep on-premises where cloud migration does not deliver positive ROI within 3 years — typically mainframe workloads, latency-sensitive edge applications, or applications in countries without appropriate cloud data residency.
APRA CPS 234 Cloud Compliance for Global Financial Institutions
Global Prudential Regulation Authority's CPS 234 creates specific obligations for financial institutions using cloud infrastructure. Revino's Global cloud practice builds CPS 234 compliance into the architecture:
Information asset classification. Every data element must be classified and the cloud provider's handling of each classification documented to APRA's standard.
Security control equivalence. The bank must demonstrate that cloud security controls are equivalent to or stronger than on-premises controls — requiring formal assessment and documentation.
Data residency. Critical financial data must remain in Global regions (Sydney for AWS, Global East/Southeast for Azure, Global-southeast1 for GCP) with explicit controls preventing cross-border transfer.
Oversight and review rights. The contract with the cloud provider must provide the bank and APRA with review rights — and Revino's vendor management framework ensures these are negotiated into every cloud agreement.
Incident notification. Cloud security incidents must be reported to APRA within required timeframes — requiring automated incident detection, classification, and escalation workflows.