What should be assessed before rebuilding a slow, insecure on-premises system in the cloud?
Measure the performance and security causes before selecting a migration route. Moving the same legacy system into cloud infrastructure does not automatically make it faster or safer. On-premises hardware and old architecture may contribute, but slow queries, network distance, storage, data growth, and access mistakes may be the real causes. Wavesteam baselines user latency, service and database limits, assets, vulnerabilities, and access before recommending rehost, re-platform, refactor, rebuild, or SaaS replacement.
Microsoft's Cloud Adoption Framework migration strategies distinguishes retain, retire, rehost, re-platform, refactor, rebuild, and replace. It is vendor methodology rather than a neutral purchase conclusion, but the classification avoids treating cloud as one lift-and-shift action.
When comparing platform capabilities, constraints, and switching costs, also compare When should a business use low-code instead of custom development? and How can a project control cost across iOS, Android, and a WeChat mini-program?; the linked guidance adds context that should be considered in the same decision.
| Route | Suitable evidence | It can improve | It does not automatically fix |
|---|---|---|---|
| Rehost | System runs; data center exit or infrastructure refresh is primary | Hardware, location, some availability | Slow code, old permissions, maintainability |
| Re-platform | Database, storage, or release can move to managed services | Some operations and platform capability | Core model and deep coupling |
| Local refactor | Bottleneck is concentrated and boundary known | Target performance, scale, security | Other legacy risk |
| Rebuild | Core model is unfit and migration value is proven | Process, data, architecture | Hidden rules, migration, adoption |
| SaaS replacement | Process is standard and product meets control needs | Transfers much operation to supplier | Export, configuration, lock-in |
Profile tables and files, growth, nulls, duplicates, encoding, keys, sensitivity, retention, and downstream consumers. Decide full migration, cleaned migration, read-only archive, or lawful deletion. Rehearse conversion and record duration, counts, amounts, hashes, restart, and rollback rather than checking a few visible rows.
Measure real RTT, bandwidth, and loss from offices, factories, and mobile users to candidate regions before choosing public internet, VPN, dedicated connection, edge cache, or hybrid. Cloud farther from users can be slower. Preserve enterprise directory integration and least privilege for people, services, and operators; protect admin access and audit production action. Do not expose databases publicly by default.
Use NIST CSF 2.0 to organize governance, identification, protection, detection, response, and recovery. Supplier responsibility for physical facilities does not remove client responsibility for identity, configuration, data, application flaws, and incidents. A WAF does not repair every injection, authorization, or business-logic defect.
Set backup RPO/RTO, encryption, isolation, and retention and prove restoration. Multiple availability zones do not automatically equal disaster recovery. Monitor user tasks, application, database, queue, network, and cloud configuration with an on-call owner. FinOps forecasting supports rolling cost projections from usage, planned change, and pricing rather than one instance's first-month price.
Choose cutover from write consistency and allowed downtime. Read-first and dual-write are not universally safe. Options include one cut, module/region/user waves, change-data capture, or short parallel operation. Each states source of truth, freeze, reconciliation, rollback trigger, and treatment of data written after rollback.
Acceptance compares the same user tasks before and after for P95/P99, success, error, resources, and cost; tests peak, access, vulnerabilities, logs, recovery, and cutover; and reconciles migrated counts, money, and relationships. Revoke legacy writes and retire assets only after cloud evidence is stable and the rollback window closes.
Wavesteam delivers the baseline, route decision, target architecture, mapping, migration and validation, threat and access model, cost scenarios, cutover and rollback, and runbook. Duration follows system, data, interfaces, and downtime rather than a generic three-to-six-month promise.