
Defining architectural requirements for data protection in hybrid and multi-cloud landscapes
Enterprise environments are increasingly shifting towards hybrid and multi-cloud deployments, with 86% of enterprise cloud deployments being hybrid or multi-cloudsource[1]. This introduces new challenges for data protection, necessitating a careful definition of architectural requirements. Key metrics such as RTO (Recovery Time Objective) and RPO (Recovery Point Objective) are fundamental: RTO defines the maximum tolerable downtime for a service, while RPO specifies the maximum acceptable amount of data losssource[4]. Shorter RTO/RPO values typically incur higher costssource[4]. Furthermore, demands for data sovereignty and residency are growing, especially with regulations like the EU Data Act, which imposes strict rules on third-country government access requests for non-personal data stored in the EUsource[2].
Key data protection architectural patterns for hybrid and multi-cloud environments
Various architectural patterns are employed to ensure data resilience in hybrid and multi-cloud environments:
- Centralized cloud backup: This pattern involves consolidating backups from on-premises infrastructure and various cloud environments into a centralized cloud storage. This simplifies management and provides a single point of recovery.
- Cloud-native backup for cloud workloads: For applications running directly in the cloud (IaaS, PaaS, SaaS), native cloud backup services or third-party solutions integrated with cloud APIs are utilized.
- Disaster Recovery as a Service (DRaaS): DRaaS offers rapid disaster recovery by replicating data and applications to a cloud environment. This enables low RTO/RPO without significant capital expenditure on proprietary DR infrastructure.
- Cyber recovery 'clean rooms': In response to the rise of cyber threats like ransomware, architectures now incorporate the concept of 'clean rooms' for recovery. These are isolated environments where restored data and systems are validated for malware absence before returning to production. Immutable backups, stored on a WORM (Write Once, Read Many) principle, are critical for this, as they cannot be altered, deleted, or encrypted for a defined periodsource[3]. Cloud immutability provides the highest level of protection against cybercriminals, accidental errors, or deliberate interference, ensuring a clean copy for recoverysource[3].
Balancing cost, resilience, and compliance: Architectural trade-offs
The choice of data protection architecture always involves trade-offs. On one hand, the pursuit of high resilience (low RTO/RPO) and comprehensive cybersecurity (immutable copies, 'clean rooms') increases costs. On the other hand, cost optimization can lead to reduced protection levels. It is important to consider both CAPEX (capital expenditures) for on-premises solutions and OPEX (operational expenditures) for cloud services. Egress fees are a significant factor in multi-cloud environments, as cloud providers charge for every gigabyte transferred out of their network, which can account for 10-15% of total cloud costssource[2]. To ensure data sovereignty, especially in the context of the EU Data Act, it is necessary to select cloud regions that meet data residency requirements or utilize specialized cloud zones.
Tools and strategies for centralized data protection management and automation
Managing data protection in hybrid and multi-cloud environments is a complex task. Centralized backup and recovery management platforms enable unified processes, monitoring, and reporting across the entire infrastructure. Automation, implemented through APIs and Infrastructure as Code (IaC) tools, is key to efficiency. It allows for automated backup creation, integrity verification, recovery testing, and DR process orchestration. Integrating these solutions with existing monitoring and IT infrastructure management systems provides complete visibility and control.
Minimizing vendor lock-in and ensuring data portability
The risk of vendor lock-in is significant in cloud environments, arising from accumulated dependencies on proprietary services and APIs of a single cloud providersource[2]. This makes migration expensive and slow, creating security risks and limiting adaptabilitysource[2]. To minimize this risk, open standards and technologies should be used. Containerization with standard orchestration, such as Kubernetes, promotes application portability, allowing them to run on any cloud provider without code changes and reducing vendor lock-insource[2]. Using S3-compatible storage and hybrid cloud storage can also help abstract from a specific vendor, providing flexibility in choosing a platform for backup storage.
How to apply a checklist for data protection architecture assessment
To make an informed decision regarding data protection architecture in hybrid and multi-cloud environments, use the following checklist. For each potential architectural pattern or solution, evaluate it against the specified criteria, assigning scores or using qualitative assessments (e.g., 'low', 'medium', 'high'). This will help visualize trade-offs and select the solution that best meets your organization's unique needs.
| Criterion | Description |
|---|---|
| RTO/RPO targets (for different data criticality levels) | Does the solution meet the established RTO/RPO targets for different data categories (critical, important, non-critical)? |
| Workload coverage (on-premises, IaaS, PaaS, SaaS) | Does the solution provide protection for all types of workloads in your hybrid/multi-cloud environment? |
| Cyber recovery capabilities (immutable backups, 'clean rooms') | Does the solution support immutable backups and the ability to recover in isolated 'clean rooms' to protect against cyber threats? |
| Data sovereignty and residency requirements | Does the architecture comply with regulatory requirements for data storage and processing (e.g., EU Data Act, NIS2)? |
| Centralized management and automation features | How effectively does the solution allow for centralized management and automation of data protection processes? |
| Cost implications (CAPEX vs. OPEX, egress fees) | What are the total costs (CAPEX/OPEX) and the potential impact of egress fees on the budget? |
| Vendor lock-in and portability considerations | To what extent does the solution reduce vendor lock-in risk and ensure data portability between platforms? |
| Implementation and management complexity | What is the complexity of deploying, integrating, and managing the chosen solution daily? |
| Solution scalability | Can the solution scale to accommodate growing data volumes and workload counts? |
DMIG, as a leading technical B2B knowledge base, provides in-depth analysis of architectural solutions, enabling Ukrainian enterprises and public institutions actively integrating into the European digital space to effectively adapt their data protection strategies to the requirements of the EU Data Act, NIS2, and other regulatory norms, while ensuring a high level of cyber resilience in the face of growing threats.
The strategic choice of data protection architecture in hybrid and multi-cloud environments is not merely a technical task but a critical business decision. It requires continuous analysis of trade-offs between resilience, cost, and compliance, as well as a readiness to adapt to rapidly changing conditions.
Перелік джерел

Author
