Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»Business continuity»Breaking free from the pull of data gravity (Page 5)
Business continuity

Breaking free from the pull of data gravity

Terry Storrar explains what data gravity is, why it has developed, and why it can have an impact on business continuity provision.
September 29, 20254 Mins Read
A hand pointing at a button, choosing to act.

As data volumes and value grow, they attract accompanying applications, services, and infrastructure to optimise system performance. Over time, this process can take on its own momentum in a situation analogous to gravitational force, with components drawn together around a central data mass. However, as these systems increase in size and take on greater importance, they almost always become more costly to maintain or relocate.

This is the basis of the ‘data gravity’ concept, which, for many organizations, is having an adverse effect on their cloud strategies and adds more complexity to business continuity provision.

On the face of it, consolidating data, applications, and workflows under a single cloud provider is an attractive, straightforward option. Apply the data gravity arguments, however, and there is often a complex and expensive problem lurking in the background: migrating data to alternative cloud providers or repatriating it to on-premises infrastructure can be extremely costly, slow, and complicated.

Beyond the financial implications of egress fees, concentrating data in one place can also increase exposure to outages, service degradation, or pricing changes, while making it harder for organizations to adopt innovative services from other providers. Deterred by some or all of these issues, some organizations delay or cancel cloud transformation plans, falling into a classic vendor lock-in scenario.

Driven off course

Unfortunately, the consequences of cloud-based data gravity are not confined directly to IT. Agility, innovation, and competitiveness can all be compromised if cloud infrastructure becomes too rigid to support business objectives. For example, if migration plans are slowed or even abandoned due to the cost and complexity of moving data, key initiatives can lose momentum. In some cases, strategic projects are postponed at board level because data gravity has created fundamental barriers to change and, ironically, is acting as a brake on the very innovation that cloud adoption is intended to deliver.

These issues also apply to many organizations on their AI development and integration journeys. The explosive growth in AI workloads and rush to deploy has real potential to exacerbate cloud-based data gravity. On a basic level, AI data needs to be close to AI compute – a requirement that can reinforce lock-in. Training, fine-tuning, and model updates drive continuous demand for high-performance, low-latency datacentre services; and those organizations working with cloud providers on AI projects need to guard against data gravity issues.

The concentration of workloads within a single cloud environment also creates potential vulnerabilities. System outages, cyberattacks, or unexpected price hikes can cause major problems when business-critical data and applications are tied to a single provider. This has led many organizations to explore resilience strategies that build in redundancy, diversify providers, or establish alternative environments in which workloads can be redeployed if circumstances dictate. In this context, the objective is to mitigate the risks associated with over-reliance on the single provider model, which needs to be front of mind for those responsible for business continuity strategies.

Achieving escape velocity

So, for organizations concerned about their exposure to data gravity, what are the options? At the top of the list should be to work out what data exists within the organization, where it resides, how important it is, and how frequently it needs to be accessed. From there, leaders can decide which datasets are suitable for high-performance cloud environments, which can be tiered to lower-cost storage, which may need to remain on-premises, and which can be deleted. By segmenting data in this way, organizations create more flexibility in how it is managed, how backups are organized, and reduce the risk of everything being pulled into a single system.

This might mean using public cloud for scalability and innovation, private cloud for sensitive workloads, and on-premises systems for applications that require low latency or support legacy infrastructure. By matching environments to workload requirements in this way, organizations not only mitigate the effects of data gravity but also create a more resilient and adaptable foundation for future change.

In addition, utilising private networking, cloud exchanges, and open standards can reduce the cost and complexity of moving workloads between environments. Meanwhile, predictable pricing and clear governance frameworks limit the impact of egress fees. These measures also support compliance by ensuring that data can be stored and processed in line with local and regional requirements. Taken together, they provide organizations with greater freedom of choice, making it easier to manage the pull of data gravity without losing the efficiency and performance benefits of cloud adoption.

Building on this foundation, many IT teams are redefining their approach to the cloud. For each organization, a bespoke combination of public cloud, private cloud, and on-premises infrastructure can reintroduce the levels of flexibility and redundancy needed to address these challenges head-on.

The author

Terry Storrar, Managing Director, Leaseweb UK 

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleFrom threat to operational resilience: understanding and managing open source risks in your organizational software
Next Article Majority of cyber attacks are by hacktivists says ENISA Threat Landscape 2025 report

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A digital twin test bay showing a large screen displaying a virtual boiler model synchronised with the physical unit during operational testing.

International cyber agencies publish guidance for isolating critical infrastructure systems during times of crisis

July 29, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?