Why lock-in became the hidden cost of public cloud
Ask any business owner who migrated to a hyperscaler five years ago what they expected, and you will hear a familiar answer: lower costs, less hardware to worry about, someone else handling the 3 a.m. failures. Ask them what actually happened, and the story gets more complicated. A private cloud built on open technology is now emerging as the serious public cloud alternative for SMEs that want predictability back, and managed Proxmox platforms hosted in Italian data centres show what that looks like in practice.
The problem is rarely the compute itself. It is everything wrapped around it: proprietary managed services, region-specific networking constructs, identity systems that assume you will never leave, and egress fees that turn “moving your data out” into a budget line nobody approved. Each of these is convenient on day one and expensive on day one thousand.
Flexera’s State of the Cloud reporting has consistently found that organisations overspend their public cloud budgets by around 30 percent, and a similar share of cloud spend is wasted outright. For a 60-person manufacturing firm or a professional services practice, that is not an accounting footnote. It is a hire you did not make.
What lock-in actually costs a mid-sized business
Lock-in shows up in four places. The first is commercial: you lose the ability to negotiate, because the alternative involves a migration project you cannot staff. The second is architectural: your applications get rewritten around a vendor’s proprietary queue, database, or serverless runtime, and that code has no life outside it.
The third is operational. Your team builds expertise in one console, one CLI, one permissions model, and that knowledge does not transfer. The fourth is legal, and it has become the most urgent of the four for European companies.
Sovereignty stopped being a theoretical concern
For years, data sovereignty was a topic for legal departments and public sector tenders. That changed with the Schrems II ruling, the introduction of the EU-US Data Privacy Framework, and the steady tightening of sector-specific rules. Today a European SMB signing a contract with a large enterprise client or a public administration is routinely asked where its data physically sits and which jurisdiction governs the entity holding it.
Sovereign cloud requirements are no longer only a UK or German preoccupation. The EU Data Act, applicable since September 2025, directly addresses switching between cloud providers: it requires providers to remove contractual, commercial, and technical obstacles to migration, and it phases out egress charges for switching. That is a regulatory acknowledgement that lock-in was a real market failure, not a complaint from disgruntled CTOs.
NIS2 pushes in the same direction from the security side. If your organisation falls into scope, or supplies someone who does, you need demonstrable control over your infrastructure, your backups, and your incident response. “The provider handles it” is not an answer an auditor accepts. We cover the practical compliance implications in our cybersecurity services overview.
The supply chain angle
There is a second-order effect that catches smaller companies off guard. Large clients increasingly cascade their own compliance obligations down to suppliers through contractual clauses. A 40-person software house that sells to a bank or a healthcare group will be asked to document its hosting arrangements, its backup immutability, and its ability to restore service within a stated window.
A private cloud for business answers these questions cleanly. You know the data centre. You know the jurisdiction. You know who has physical access and who holds the encryption keys.
What a managed Proxmox private cloud actually offers
Proxmox Virtual Environment has quietly become one of the most credible virtualisation platforms available, and its rise accelerated sharply after Broadcom’s acquisition of VMware reshaped licensing for smaller customers. Many SMBs found their virtualisation costs multiplying without any change in what they were running. That prompted a serious reassessment.
A managed Proxmox private cloud combines three things that used to be mutually exclusive. You get open source technology with no per-socket licensing surprises, dedicated resources rather than noisy shared tenancy, and a provider who handles patching, monitoring, and hardware lifecycle so your internal team is not on call for firmware.
Operational autonomy, not operational abandonment
The distinction that matters is between managed and opaque. A well-designed private cloud gives you full administrative visibility: you can see your virtual machines, your storage allocation, your network topology, and your backup jobs. You can provision and destroy resources yourself when a project demands it.
What you outsource is the layer below: the hypervisor cluster, the SAN, the redundant power, the cross-site replication. That is the layer where economies of scale genuinely exist and where a 10-person IT department cannot realistically compete with a specialist.
Immutable backups as the actual safety net
Ransomware economics changed the moment attackers started targeting backup repositories first. If your backups can be deleted or encrypted by a compromised administrator account, they are not backups. They are a comfort blanket.
Immutable backup storage, where written data physically cannot be modified or deleted for a defined retention period, is the single most valuable feature in a modern infrastructure contract. Combined with geographic separation (data written in Milan, replicated to Rome, or equivalent paired sites), it turns a catastrophic event into a recovery exercise with a known duration. European recovery timelines for firms without immutable copies routinely stretch past three weeks; with them, the conversation is usually about hours.
Is a private cloud right for your business?
Not every workload belongs in a private cloud, and any provider who says otherwise is selling rather than advising. Here is a practical way to think about it.
Strong candidates
Predictable, always-on workloads are the clearest fit. ERP systems, line-of-business databases, file servers, terminal servers, and internal applications that run 24 hours a day cost significantly less on dedicated infrastructure than on metered public cloud, because you are not paying a premium for elasticity you never use.
Workloads with regulatory constraints are the second category: health records, financial data, legal case files, industrial designs, anything where the jurisdiction question has a contractual answer. Data-heavy workloads are the third, since egress fees punish anything that moves large volumes in and out regularly.
Where public cloud still wins
Genuinely spiky workloads, seasonal e-commerce peaks, batch analytics, development environments spun up and torn down weekly, remain a good match for on-demand pricing. Global content delivery is another. So are specialised managed services, from machine learning pipelines to niche databases, where building the equivalent yourself makes no commercial sense.
The realistic answer for most European SMBs is hybrid: a private cloud core for the systems that run the business, with selective public cloud use where elasticity or a specific service genuinely earns its cost. The key is that you choose, rather than having the choice made for you by an architecture you cannot unwind.
Practical steps before you commit
Start with an honest inventory. List every workload, its actual resource consumption (not its provisioned size), its uptime requirement, and its data classification. Most companies discover that 20 to 30 percent of their cloud instances are oversized or idle, which distorts every cost comparison they have made.
Then model three years, not twelve months. Public cloud pricing looks favourable in year one and less so once you include egress, support tiers, reserved instance commitments, and the internal time spent on cost governance. Private cloud has a flatter, more predictable curve, which is easier to budget against.
Ask three specific questions of any provider: where are the data centres and under whose jurisdiction does the operating entity fall, are backups immutable and what is the guaranteed retention, and what exactly does an exit look like in technical and commercial terms. A provider confident in their platform will answer all three without hesitation.
Finally, check the exit path before you need it. A private cloud built on Proxmox stores virtual machines in standard, portable formats. If the relationship does not work out, your workloads move. That single property is the difference between being a customer and being a captive, and it is worth more than any feature comparison table. If you want to talk through how this maps to your own infrastructure, our team is available through our services page or directly via contact.