Why XaaS could be detrimental to your business
Oh look, another IT acronym: what a shock. I swear, even with an entire career in the world of IT it never ceases to amaze me how many ridiculous acronyms seem to crop up daily. In this particular case, XaaS, meaning “anything as a service.” But what exactly does that mean? Anything? Really?
Now, it’s no shock that Software-as-a-Service (SaaS) is something that many have heard about ad nauseam for the past decade. It’s also something that many use daily. And like any good idea at the time, many ideas and business models have spun from it, including Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and more.
However, along with all this innovation and recurring revenue models comes an important question: How do these business models impact business every day?
Key Takeaways
- XaaS (“anything as a service”) has expanded well beyond the now-familiar SaaS model into more involved business infrastructure like IaaS and PaaS, each carrying significantly higher stakes when it comes to data control and security.
- Moving infrastructure to third-party cloud providers introduces risks beyond just external hackers, including the provider’s own legal terms and conditions, which determine exactly who has access to your data, from log files to metadata.
- Secret government subpoenas, such as those covered under the USA Patriot Act, can legally compel service providers to grant data access without ever being able to inform the business whose data is involved, a risk many companies don’t consider when moving to the cloud.
- A hybrid infrastructure model, keeping sensitive data under a company’s own direct control rather than fully outsourcing to third-party IaaS or PaaS providers, can significantly reduce exposure to both external breaches and provider-level legal vulnerabilities.
- Investing in the right on-premises equipment with a vendor who understands how to properly architect infrastructure gives businesses more control over their own security and data governance rather than being fully subject to a third party’s terms.
For any growing business, the challenges resulting from build or buy are continually present. From budgets to time, to staffing and support, these all play tremendous roles in determining the best course of action. However, there is far more to consider: the internet and being a slave to the worldwide web.
It’s easy to consider SaaS—today, it’s both benign and commonplace. But when it comes to far more involved business processes, both IaaS and PaaS need to be well vetted, thought through, and approached with a healthy amount of fear and paranoia.
Moving one’s infrastructure to the “cloud” comes with a host of issues—and security and privacy are at the top of the list of concerns. For most, the idea of the nefarious foreign hacker comes to mind—maybe they breach your provider’s security and leak your data to the world, or maybe they use it to extort you.
But that’s not the worst-case scenario (insert choking feeling here). You see, there is something far beyond that of nefarious hackers that needs to be considered, and that’s your service provider’s own legal terms and conditions and how they impact you and your business. It’s those T&Cs that determine who is permitted to have access to your data—from log files, to meta data, and more.
Then, of course, there is the Warrant Canary, a method by which a communications service provider aims to inform its users that the provider has not been served with a secret government subpoena. And whether or not that’s up-to-date can help or hinder you. In the United States, secret subpoenas, such as those covered under 18 U.S. Code § 2709(c) of the USA Patriot Act, provide criminal penalties for disclosing the existence of the warrant to any third party, including the service provider’s users.
Sound scary? Because loosely translated this means that your IaaS or PaaS could come back to bite you in the aSS.
So, what is the solution? I’m not saying that IaaS or PaaS is all inherently bad. It can help companies grow and succeed in an otherwise impossible climate. However, take this as a cautionary tale. Perhaps a hybrid model is best for many organizations, in that their data is kept under their own roof and not subject to third-party scenarios that mean their data is out of their control. If you invest in the right equipment with a vendor who knows how to architect the right type of infrastructure, the likelihood of being breached by bandits or bureaucrats can be greatly reduced.
And as a wise man once said, “Just because you’re paranoid doesn’t mean they aren’t after you.”
CONTACT INTELECA TODAY FOR MORE INFORMATION REGARDING IaaS AND PaaS
FAQs
What is the difference between SaaS, IaaS, and PaaS?
Software-as-a-Service (SaaS) delivers ready-to-use applications over the internet, something most businesses are already comfortable with. Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) go much further, handing over core computing infrastructure or development platforms to a third-party provider. While SaaS is generally low-risk and widely accepted, IaaS and PaaS require far more careful vetting since they involve placing significant business infrastructure and sensitive data in the hands of an outside vendor, along with all the legal and security implications that come with that arrangement.
What are the risks of moving business infrastructure to third-party cloud providers?
Beyond the commonly discussed risk of external hackers breaching a provider’s systems, businesses face a less obvious risk in the provider’s own legal terms and conditions, which determine exactly who can access company data, including log files and metadata. In the US, secret subpoenas issued under laws like the USA Patriot Act can legally compel a provider to grant government access to data without ever notifying the business involved. This creates a scenario where a company’s data could be accessed without their knowledge, a risk that exists entirely outside of traditional cybersecurity concerns.
Why might a hybrid infrastructure model be safer than full cloud outsourcing?
A hybrid model, where sensitive data and infrastructure remain under a business’s own direct control rather than being fully outsourced to a third-party IaaS or PaaS provider, significantly reduces exposure to both external security breaches and provider-level legal vulnerabilities like secret subpoenas. Building or maintaining owned infrastructure gives a business full control over layout, hardware, and security policy, though it does require more upfront investment and internal expertise. For teams weighing this tradeoff, understanding the cost, control, and expertise involved in owning versus leasing infrastructure is an important part of deciding which model fits a business’s specific risk tolerance and resources.
How can businesses reduce the security risks associated with cloud infrastructure?
Businesses can reduce risk by carefully vetting any IaaS or PaaS provider’s terms and conditions before committing, understanding exactly what access the provider and any government authority may have to company data, and considering a hybrid approach that keeps the most sensitive data under direct company control. Partnering with a vendor experienced in architecting secure infrastructure, whether hybrid or fully on-premises, helps businesses maintain stronger oversight of their own data rather than being entirely subject to a third party’s legal and security posture.

