Geoffrey is CTO at a UK insurance broker. 12 years of legacy, three teams, two engineers maintaining the estate full-time. The DR plan hadn’t been rehearsed since 2019. A power event took the primary down for 6 hours and the warm DR didn’t come up cleanly.
On-premise to cloud migration that leaves the datacentre, not the data sovereignty.
We move UK enterprises and regulated teams off a datacentre or self-hosted estate onto AWS, Google Cloud, or Azure — data residency preserved, audit trail through cutover, the IAM + network baseline your auditor will sign.
You don’t need to leave on-premise. You need to leave the version that’s costing you growth.
AWS London, GCP london-1, Azure UK South. Your data stays UK, SCCs aren’t needed, the auditor is satisfied, and procurement gates clear. Datacentre running costs typically equal 2-3× cloud spend. Migration pays back in 18-30 months.
0
2-3×
0
Geoffrey runs 14 servers in a Slough datacentre. The refresh quote came in at £180K.
The FCA audit asked for a change-management evidence pack. The team had nothing version-controlled. The hardware refresh quote sat next to a deadline neither could move. He’d decided the migration was happening. He just needed it to land without taking the business down.
Eighteen-week migration to AWS London. Lift-and-shift first to land in eight weeks, then refactor: EC2 to ECS Fargate, RDS Multi-AZ, S3 + CloudFront, IAM + SSO, CloudTrail audit, Terraform everywhere. FCA evidence pack auto-generated. DR RTO went from 4 hours to 25 minutes.
Four phases
No mystery box. Each phase is fixed-scope, fixed-price, and ends with a written deliverable you can show your board. You decide whether to continue at every boundary.
Migration audit · 5 days, £8K
Two senior engineers read your estate, data, and infra. You get a 20-30 page audit pack: risk matrix, target architecture, data plan, rollback plan, fixed quote.
Plan + parallel build · 2-4 weeks
We build the cloud target in parallel while your on-premise system keeps running. Data dry-runs, rebuilt integrations, dual-write or shadow-read set up. No customer-facing change yet.
Cutover · 1-3 days, planned window
Often a weekend. We dual-run, shadow-read, then flip the canonical write path. Old system stays read-only for 60 days. Rollback is rehearsed and reversible.
Stabilise + decommission · 2-6 weeks
We monitor, fix what only production traffic surfaces, hand over to your team or our retainer, and decommission the old estate on a schedule you sign off.
The migration risk. How we close it before cutover.
We don’t pretend migrations are safe. We make each risk legible and mitigated, in writing, before a single line of production changes.
- 01
“Will our UK customer data still sit in the UK?”
UK / EU data residency, in-region backups. AWS London + Dublin, GCP london-1, Azure UK South + UK West. Data and backups stay in-region. SCCs not needed for UK customer data. Auditor and ICO defendable.
- 02
“Our partner connections and VPNs have to move too.”
Landing zone planned before apps move. AWS Direct Connect, Azure ExpressRoute, GCP Interconnect. We plan the network landing zone first, then migrate the applications onto it.
- 03
“We carry Cyber Essentials Plus, ISO 27001, and SOC 2.”
Controls inherited, evidence mapped. We map controls to AWS Config Rules + GuardDuty + Security Hub + Vanta evidence. Re-certification audit is ready, not a scramble.
- 04
“Some apps were never built to leave the rack.”
Lift-and-shift gotchas audited first. Hard-coded hostnames, /tmp dependencies, NFS shares, multicast networking break in cloud. We audit and remediate before lift, then refactor to cloud-native after stable.
- 05
“How much downtime does the database migration cost us?”
CDC replication, zero downtime for most engines. AWS DMS / Azure DMS / GCP DMS for database change data capture. Snowflake and BigQuery analytics warehouses migrated separately.
- 06
“Our DR plan hasn’t been tested in years.”
Backup and DR rehearsed, RTO + RPO documented. AWS Backup + cross-region replication. DR rehearsed in week 16 and every 6 months after. Untested DR is no DR.
- 07
“We’ve heard cloud bills run out of control.”
Reserved + savings plans + tagging. Pay-as-you-go without optimisation costs 2-3× what it should. Reserved and savings plans, spot for batch, and a tagging strategy from day one for cost allocation.
- 08
“Our team has never run a cloud estate.”
Internal team brought along, not left behind. We pair with your engineers, hand over Terraform and runbooks, and offer 3-6 months of retainer after cutover. Migrations fail when the internal team isn’t upskilled.
The cloud stack we migrate you onto.
We default to AWS and the MERN + Python ecosystem. We’re senior on GCP, Azure, Cloudflare, DigitalOcean, Vercel, and Fly.io where your team has constraints or a relationship.
The default target stack
AWS-defaultMigration-specific tooling
the move itselfInfra, observability, safety net
the day-2 layerSlough datacentre to AWS London,
insurance broker, in numbers
Eighteen-week migration. Lift-and-shift first to land safely in eight weeks, then refactor to ECS Fargate + RDS Multi-AZ + IAM + CloudTrail audit over ten weeks. Terraform everywhere. The FCA evidence pack auto-generates.
The move
Resilience
Track record
Two phases. Audit, then migration sprint.
Pick the shape that fits and Mohit will send your real number inside 24 hours.
5-day migration audit
Two senior engineers read your estate, data, and integrations. We map the migration, write the risk matrix, and quote the sprint.
- Fixed scope, fixed price
- 20-30 page audit pack
- Target architecture + rollback plan
- From £8,000 (GBP)
Cloud migration sprint
Parallel build, dry-run data migration, planned cutover, post-cutover stabilisation, decommission. Sprint length tracks estate size.
- 8-16 week sprint
- Lift first, refactor second
- 30-day walk-away both ways
- From £65,000 fixed (GBP)
Post-migration retainer
One senior engineer, one day a week, for 3-6 months. New surface area, performance work, integrations, and your team gets unblocked.
- Senior engineer, day a week
- Terraform + runbook handover
- 3-6 month term
- From £5,000 / month (GBP)
“We left the datacentre before the refresh quote and the FCA audit. Eighteen weeks later the estate was on AWS London, the evidence pack auto-generated, and DR recovery dropped from four hours to twenty-five minutes.”
— Geoffrey, CTO, UK insurance brokerWhat CTOs actually ask on the audit call
Direct answers, no marketing varnish.
AWS London is the most common choice for on-premise to cloud migration, with the most services available and the strongest UK partner network. GCP london-1 is close behind. Azure UK South / West sometimes wins on Microsoft-shop economics. We’ll recommend at audit and we’re senior on all three.
Both, in order. Lift first to land safely and de-risk the datacentre exit. Refactor second to capture the cost, reliability, and velocity benefits. Going straight to cloud-native usually fails on a tight datacentre exit deadline.
12-26 weeks is typical. Server count, database complexity, network complexity, and your compliance regime drive scope. Multi-region or multi-cloud takes longer. The 5-day audit gives you the real number for your estate, not a guess.
Yes, if it’s set up right from day one. IAM + SSO + audit log + Terraform + Config Rules + GuardDuty + Vanta / Drata gives you an evidence pack that’s ready. We’ve passed FCA, ISO 27001, SOC 2, Cyber Essentials Plus, and DSPT audits after migration.
Yes. Hybrid is normal during transition and sometimes long-term for licensing or latency reasons. AWS Outposts, Azure Arc, and GCP Anthos are all on the table. We’ll recommend hybrid where it earns its keep, not as a default.
For most database engines, close to none. We use AWS DMS / Azure DMS / GCP DMS change data capture to keep the old and new systems in sync, then flip the write path in a planned window. The old system stays read-only for 60 days as a parallel run.
The audit is fixed at £8K and ends with a fixed quote for the sprint, typically from £65K. Each phase is fixed-scope and fixed-price, and you decide whether to continue at every boundary. You’re never signing a blank day-rate cheque.
Every migration has two senior engineers paired. Every decision lands in an ADR the same day, and the whole estate is in Terraform, so context is in the repo, not in one person’s head. In seven years, two engineers have left mid-project and both handovers were inside 48 hours.

Inside the work.
A look at the kind of on premise to cloud migration surface we hand over — real screens, real data, documented and yours from day one.
Two senior engineers. 5 days.
Send a 5-line brief: current on-premise estate (traffic, data size, integrations), why you’re migrating, and the deadline you’re working to. Mohit replies inside 24 hours with availability and the next 5-day audit slot.
- < 24h
A personal reply.
Availability and your next 5-day audit slot. Straight to your inbox.
- Week 1
Migration audit begins.
Risk matrix, target architecture, data plan, rollback plan, fixed quote.
- Cutover
You leave the datacentre.
Planned window, rehearsed rollback, 60-day parallel run, auditor sign-off.