
The conversations we have with organisations at the start of a cloud migration, or reconsidering one already underway, tend to land on two questions.
Why are the costs still climbing? And who’s actually accountable for where the data sits?
Cloud architecture matters more than cloud adoption. Getting the right workloads to the right cloud, governed, sovereign, and delivering measurable value, is where the real work is.
For over 20 years, Brennan has designed cloud environments for Australian businesses. Our approach starts with the workload and the business, before any server moves.
When cloud migrations go badly, they can usually be sheeted back to three predictable reasons:
Migrating because cloud is the default (rather than defining what value it's supposed to return) is not anchored in commercial logic. If you can't say what success looks like, you can't tell whether the migration worked.
Who actually owns cost and security after go-live? Without that ownership, costs blow out fast — anyone can spin up a dev resource, and no one notices it chewing dollars until the invoice lands.
The guardrail layer you set up before anything moves: identity, network, security baselines, patching policy. Skip it and you get what we've seen more than once: a server stood up with no security protocols, unpatched, quietly open to attack.

Cloud migrations go badly for a few predictable reasons, and they usually start before a single server moves.
Get those three right up front and most other problems don't get the chance to start.”
Cloud adoption being near-universal in Australia is indisputable.
Realising the value that justified the migration? That’s more contentious.
A finance team spins up an Azure subscription, an operations team adopts a SaaS platform hosted in Singapore, a third workload migrates with no clear ownership of what happens after go-live. Cloud sprawl is the result. Security gaps and spiralling costs follow.
A 2026 PwC Australia study1 found only 22% of CIOs feel fully confident their cloud provider demonstrates compliance across all relevant categories. It’s a striking number given that cloud migration has been underway in Australia for over a decade.
The gap between adoption and confidence is where risk lives.
1: SOURCE: PwC Australia, Global Digital Trust Insights 2026
The first question Brennan asks is not ‘when can we start the migration?’
An estate assessment precedes every migration project. It maps the current environment, surfaces risks (sprawl, security gaps, licensing waste, technical debt), and determines the right path for each workload.
The outcome is a clear cloud strategy and a prioritised business case, rather than a default to a single platform.
Brennan evaluates each workload against five paths. The right path depends on the workload’s strategic importance, technical debt, risk tolerance, and timeline. Brennan’s estate assessment produces a recommendation for each workload.
Some workloads don’t need to move anywhere. Migrations regularly surface applications nobody remembers commissioning. Decommissioning before migration reduces cost and risk without a single server move.
Move the workload to cloud infrastructure with minimal changes. Fast, lower-risk, appropriate for legacy systems where re-engineering isn’t justified. Rehosting doesn’t realise all cloud benefits, but it reduces on-premises dependency quickly.
A partial improvement: move to a managed cloud service (shifting a SQL Server instance to Azure SQL Managed Instance, for example) without a full rebuild. Some cloud efficiency gains, lower effort than full refactoring.
Redesign the application to use cloud-native capabilities: containers, microservices, serverless compute. Higher effort, greater return for strategic systems worth the investment.
Retire the existing application and build new on cloud-native architecture. Reserved for systems where the existing code is the obstacle.
A cloud strategy and a prioritised migration plan, costed and sequenced by business value and risk, not by what’s easiest to move first.
Each workload moves on its assessed path, with testing and validation gates before production cutover. Brennan’s project teams manage the migration and vendor coordination. The customer owns the business decisions. Brennan owns the delivery.
Brennan’s managed cloud services cover monitoring, cost management, governance, security, patching, and incident response. The environment is treated as a living system: governed, measured, and improved over time.
Ongoing cloud management sits within Brennan’s True Performance System: structured measurement, issue analysis, and a documented improvement program that runs continuously across every customer engagement.
Brennan holds Azure Expert MSP status, Microsoft’s highest accreditation for managed service providers in the Azure ecosystem.
Azure Expert MSP is not awarded on partnership tier alone. Microsoft assesses delivery quality, customer outcomes, technical depth, and operational processes. The accreditation is reviewed annually and can be revoked.
As of 2025, just 134 managed service providers globally and fewer than five Australian-based firms hold Azure Expert MSP status. Brennan is one.

Alongside Azure Expert MSP, Brennan holds all six Microsoft Solutions Partner designations and eight Solutions Partner specialisations. These span Infrastructure Azure, Digital and App Innovation, Data and AI, Modern Work, Business Applications, and Security.
Brennan also holds Featured Fabric Partner status, the Microsoft designation for data analytics and AI workloads delivered through Microsoft Fabric.















In practice, this means direct access to Microsoft engineering support, preview features before general release, and a co-investment relationship in customer outcomes.
For organisations migrating complex Azure environments or running workloads the business depends on, the partner’s depth of relationship with Microsoft matters more than most procurement teams ask about.
Brennan is also an authorised AWS partner, supporting customers who run workloads across both platforms or who are evaluating their platform mix.
Data sovereignty has moved from government preoccupation to sector-wide concern.
The 2024 Privacy Act reforms introduced maximum penalties for serious privacy interference of $50 million, 3x the benefit obtained, or 30% of annual turnover, whichever is greatest.
The Security of Critical Infrastructure Act (SOCI) covers 11 sectors of the Australian economy, from health and financial services to energy and data storage. APRA CPS 234 requires financial services organisations to maintain information security commensurate with their cyber risk profile.
For a private hospital, a regional bank, or a utility with SOCI Act obligations, where data sits, and who can access it under which legal framework, is now a compliance question with a dollar figure attached.
Foreign governments can issue disclosure orders under their own legislation. The US CLOUD Act gives US federal agencies broad powers to access data held by US-headquartered companies, regardless of where that data is physically stored.
For Australian organisations handling health records or financial data, this is the live risk, and it sits above the question of which region the data centre is in.
Brennan designs cloud environments with clear answers to these questions. For organisations with sensitive workloads or regulatory obligations, that means Australian-hosted infrastructure, onshore teams, and architecture that keeps data within Australian legal jurisdiction.
Three things matter more than where the data centre sits: ownership, access, and the encryption keys.
The question is who operates the environment, and whose laws can compel them. A provider headquartered overseas can be reached under its home-country legislation regardless of where the data physically sits. An Australian-owned and operated provider answers to Australian law only: there's no foreign parent for another government to compel.
Access takes into account where the people with administrative rights sit, and under which jurisdiction they operate. Onshore data with offshore admin access isn't sovereign.
If you hold the encryption keys and the provider can't decrypt your data, even a lawful foreign disclosure order produces something unreadable. If the provider holds the keys, that protection doesn't exist.

Sovereignty often gets talked about as a hosting question: "is my data in an Australian data centre?"
For organisations with genuine sovereignty requirements, three things matter more: ownership, access, and keys.”
Some workloads belong in public cloud. Elastic demand, modern SaaS integrations, development and test environments, data analytics workloads. Microsoft and AWS have both invested heavily in Australian regional infrastructure. For the right workloads, public cloud is the right answer.
Other workloads don’t fit the public cloud model. Legacy applications with licensing constraints, latency-sensitive systems, workloads with strict data residency requirements, or systems tightly coupled to on-premises hardware often run better, or at lower cost, in a private or hybrid environment.
Brennan Private Cloud gives customers a private cloud operating model, with self-service provisioning, elastic capacity, and consumption-based billing, within a managed environment hosted in Australian data centres. It’s an option for organisations where public cloud doesn’t fit all workloads.
Governance is what holds a hybrid environment together. Without policy enforcement and automated guardrails, hybrid environments drift: workloads proliferate and costs climb.
Brennan’s governance work covers identity and access controls, cost oversight, configuration management, and the automated guardrails that surface issues before they become compliance events.

The benefits of choosing the right partner goes well beyond migration experience.
The real value is how your partner can support you once you're in the cloud: managed services, observability, financial control, modernisation.”
Most organisations evaluating cloud partners are doing so for the first time, or after a disappointing experience with a previous one. Eight questions cut through most of these conversations.
Lastly, as with every project, things don’t always go to plan. Finding a partner that is pragmatic, values relationships, and has skin in the game will mean that those difficult moments are navigated together as a team.
Partners who lead with migration timelines before understanding the environment are prioritising their own project schedule. An estate assessment should come first, even when it slows the start date.
A cloud migration is an ongoing engagement, not a project with an end date. Managed services, ongoing cost management, governance oversight, and capacity planning are the continuing work. Ask who’s accountable for what, and how performance is measured over time.
Azure Expert MSP and AWS partner tiers are meaningful credentials. Ask which accreditations the partner holds, and what those accreditations are assessed against.
Where does your data sit? In which legal jurisdiction? What happens if a foreign government issues a disclosure order? Clear answers to these questions before signing a contract are worth more than assurances after.
A migration without a business case is a project chasing a reason after the fact. A partner worth choosing helps build that case up front, tied to real numbers, before a single workload moves.
Managed services, cost visibility and security monitoring should be built into the contract before go-live. If a partner's engagement ends at cutover, ask who owns the environment from day two.
Azure Expert MSP status is reviewed annually and can be revoked, so a badge on a homepage doesn't confirm anything about today. Ask when it was last assessed, and whether it covers the specific service you're buying: migration, security, or ongoing management.
This is where the sovereignty question gets tested for real. If the provider holds the keys, a lawful order can compel them to decrypt your data regardless of where the servers sit. If you hold the keys, the same order produces nothing readable.
Every Brennan cloud engagement starts with an estate assessment.
Post-migration managed services, cost control, observability, and security oversight are built into the engagement from the outset, with clear accountability structures and monthly reporting.
Brennan holds Azure Expert MSP status, all six Microsoft Solutions Partner designations, and eight specialisations, the deepest Microsoft accreditation structure available to an Australian managed service provider.
On sovereignty: Brennan designs cloud environments with Australian-hosted infrastructure and onshore teams for organisations with specific regulatory requirements, with architecture that keeps data within Australian legal jurisdiction.
Brennan has been operating in Australian IT for over 20 years, with a cloud practice that has grown alongside the shift from cloud adoption to cloud maturity.
Cloud migration is the process of moving data, applications, and IT infrastructure from on-premises environments to cloud platforms, or from one cloud platform to another. A well-run migration starts with an estate assessment: mapping current systems, identifying which workloads benefit from migration, and determining the right path for each one (retire, rehost, replatform, refactor, or rebuild). Migration then runs in phases, with testing and validation at each stage. Managed services and governance keep the environment performing as intended after go-live.
Brennan manages cloud migrations across public cloud (Microsoft Azure, AWS), private cloud, and hybrid environments for Australian organisations.
Timelines depend on the scale of the environment, the complexity of workloads, and the chosen approach. A focused rehosting project for a simple, well-documented environment may run over several weeks. A large-scale migration involving refactoring and modernisation of complex systems typically takes months.
Brennan’s estate assessment produces a realistic timeline with phased milestones, based on the actual environment rather than a standard template
Hybrid cloud is an architecture that combines public cloud platforms (Azure, AWS), private cloud infrastructure, and often on-premises systems, managed as a connected environment with consistent governance across all of it.
It makes sense when different workloads have different requirements. Elastic, modern workloads often run well in public cloud. Latency-sensitive systems or workloads with strict data residency requirements may be better suited to private cloud or on-premises infrastructure. Hybrid architecture lets organisations place each workload where it performs best.
Brennan designs and manages hybrid cloud architectures for Australian organisations, with governance applied consistently across public, private, and on-premises environments.
Data sovereignty refers to the principle that data is subject to the laws of the country in which it is stored or processed. For Australian businesses, sovereignty concerns focus on two things: whether data is physically hosted in Australian facilities, and whether it is accessible to foreign governments under foreign legislation.
The US CLOUD Act gives US federal agencies broad powers that can compel US-headquartered companies to produce data, regardless of where that data is stored physically. For Australian organisations handling sensitive data, including patient records or financial data, this creates compliance and reputational risk that sits above the question of which data centre region is used.
Brennan designs cloud environments with clear sovereignty outcomes, including Australian-hosted infrastructure and onshore teams for organisations with specific regulatory requirements under the Privacy Act, SOCI Act, APRA CPS 234, or the My Health Record framework.
Azure Expert MSP is Microsoft’s highest accreditation for managed service providers delivering Azure services. Microsoft assesses delivery quality, customer outcomes, technical depth, and operational processes. The accreditation is reviewed annually and can be revoked.
Standard Microsoft partner status reflects a commercial relationship with Microsoft. Azure Expert MSP reflects assessed delivery capability at the highest level. Brennan holds Azure Expert MSP status alongside all six Microsoft Solutions Partner designations and eight Solutions Partner specialisations.
The right answer depends on the organisation’s existing technology investments, the applications being migrated, and the specific workloads involved.
Azure is the natural fit for organisations already running Microsoft 365, Windows Server, or other Microsoft workloads. Integration is tight, and the licensing economics are often favourable. Azure’s Australian regions (Australia East and Australia Southeast) are well-established, and Microsoft has committed ongoing investment in Australian infrastructure.
AWS has a larger global service catalogue and is often preferred for cloud-native development or organisations that need to run workloads across multiple providers. Brennan works with both platforms and recommends based on workload fit, not platform preference.
Cloud governance covers the policies and controls that keep a cloud environment secure and financially predictable. Without it, cloud environments drift: workloads proliferate and costs climb.
Brennan’s governance approach covers policy enforcement, cost visibility and alerting, identity and access management, configuration management, and automated guardrails that surface issues before they become incidents. For organisations with regulatory obligations, governance is also the mechanism for demonstrating compliance.
On cost: cloud environments routinely carry around 27% in unnecessary spend2 from over-provisioned resources, unused storage, and abandoned accounts. Brennan’s cost management work identifies and eliminates this as part of ongoing managed services.
2: SOURCE: Flexera, 2025 State of the Cloud Report. The 27% waste estimate is consistent across Flexera, Harness, and Datadog annual cloud studies (2023–25).
Several frameworks apply depending on the sector:
The Privacy Act 1988 (as amended) applies to most organisations handling personal information. The 2024 reforms substantially increased penalties for privacy breaches.
The Security of Critical Infrastructure Act covers 11 sectors including health, financial services, energy, and data storage. It requires risk management programs, incident reporting, and grants government intervention powers.
APRA CPS 234 applies to financial services entities regulated by APRA. It requires information security proportionate to the organisation’s cyber risk profile.
The My Health Record Act applies to healthcare providers handling digital health records.
The Information Security Manual (ISM) and Protective Security Policy Framework (PSPF) apply to government agencies and their service providers.
Brennan supports organisations across all these frameworks, aligning cloud design and managed services to the specific obligations that apply.
Yes. Brennan provides ongoing managed cloud services, including Azure-focused managed services, covering monitoring, cost management, governance, security, patching, and incident response.
A cloud environment that delivers value at go-live can drift over time: costs climb, configurations change, new workloads appear outside the original governance framework. Brennan’s managed services are designed to improve the environment continuously, not simply maintain it.
Brennan Private Cloud is a managed private cloud environment hosted in Australian data centres. It gives customers a cloud operating model (self-service provisioning, elastic capacity, consumption-based billing) within a private infrastructure environment, rather than shared public cloud.
It suits organisations where public cloud doesn’t fit all workloads: legacy systems, strict data residency requirements, or workloads where the economics of public cloud infrastructure don’t stack up. Brennan Private Cloud operates alongside public cloud platforms, with the same governance framework applied across the full environment.
Cloud backup creates protected copies of data and systems, stored separately from the production environment, allowing recovery after data loss, ransomware, hardware failure, or accidental deletion. Disaster recovery goes further: it covers the processes and infrastructure needed to restore full system operation after a significant incident.
The critical design decisions are Recovery Time Objective (RTO), meaning how quickly systems must be back online, and Recovery Point Objective (RPO), meaning how much data loss is acceptable. These define the architecture and cost of the recovery solution.
Brennan designs backup and disaster recovery solutions around specific RTO and RPO targets, aligned to the business priorities of each organisation. We run proactive restore testing as standard. Backup solutions that haven’t been tested are not recovery solutions