“We should be multi-cloud” is one of those statements that sounds obviously prudent and is often wrong. The instinct is understandable — depending on a single cloud provider feels risky, and spreading across several feels safer. But multi-cloud carries real, ongoing costs in complexity, skills and efficiency, and single-cloud carries real concentration risk, and the right answer depends on which trade-off actually fits your firm. This is a board-level decision precisely because it is a genuine trade-off with no free option, and treating it as an obvious best practice in either direction is how firms end up with a strategy they did not really choose.
The trade-off, honestly
Single-cloud is simpler, cheaper to run, and lets you exploit one provider’s capabilities deeply — at the cost of concentration: your critical systems depend on one provider, and that dependency is exactly what regulators like those behind DORA now scrutinise. Multi-cloud reduces that concentration and preserves negotiating leverage — at the cost of complexity: you need skills across platforms, you cannot use each provider’s proprietary strengths as fully, integration is harder, and the operational overhead is real and permanent. Neither is safer in the abstract. Single-cloud trades resilience-through-diversity for efficiency; multi-cloud trades efficiency for reduced concentration. The question is which trade your firm should make, given your risk profile, your scale and your regulatory context.
Why “avoid lock-in” is not automatically the answer
The strongest argument for multi-cloud is avoiding lock-in, and it is a real consideration — but it is frequently overstated. Genuine multi-cloud, where workloads can move freely between providers, is expensive to build and maintain, and many “multi-cloud” strategies are really “different workloads on different clouds,” which spreads dependency without providing true portability. Meanwhile the complexity cost is paid every day, whether or not the lock-in risk ever materialises. For many firms, a well-managed single-cloud posture with a genuine, tested exit plan manages the concentration risk more cheaply than full multi-cloud manages it through duplication.
Free · 4 minutes
Do you actually know what you are running — and what it is about to cost you?
Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.
The board’s questions
- What is our real concentration risk, and does the regulator care? For a DORA-scope entity, single-provider dependency on a critical function is a supervisory question; that may tilt the trade-off toward diversification or a robust exit plan.
- Can we actually run multi-cloud well? The complexity requires skills and operational maturity; a multi-cloud strategy the firm cannot execute is worse than a single-cloud one it can.
- Do we want portability, or just spread? Be honest about whether you are buying true workload portability (expensive, rarely achieved) or just distributing dependency across providers.
- What is the tested exit? Often the real question behind “multi-cloud” is “could we leave if we had to?” — and a tested exit plan may answer it more cheaply than duplication.
Deciding it deliberately
Multi-cloud is not a best practice to adopt reflexively, and single-cloud is not a risk to avoid at all costs. Each is a deliberate position with real trade-offs, and the board’s job is to decide which trade fits the firm rather than drift into an accidental posture or follow a slogan. For many, a well-run single cloud with a genuine exit plan is the pragmatic answer; for some, the concentration risk or regulatory pressure justifies the cost of true multi-cloud. The discipline is making the choice consciously, sized to what the firm can execute and what its regulators expect — not treating either as the obviously safe option, because neither is.
Who this is for
This reading is for:
- Boards weighing a multi-cloud strategy against its cost
- CTOs pressed to “avoid lock-in” by going multi-cloud
- Risk leads assessing concentration against complexity
- Firms whose cloud strategy is drifting rather than decided
Sixteen Pillars helps boards make the multi-cloud-versus-single-cloud choice consciously – sized to what the firm can execute and what its regulators expect – rather than following a slogan. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Governance is what happens when nobody is watching.
Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming