Short answer: some of them are.
The longer answer is worse, and it is the one worth your time. Most of them never have to lie, because the arrangement does it for them. They are paid by the vendors whose products they recommend, at rates that move with which product you take and how much of it gets consumed, and nobody is obliged to mention a word of it. Put a business in that position for thirty years and dishonesty becomes unnecessary. The shortlist writes itself.
From where you sit, on the receiving end of the invoice, a lie and a rigged process cost exactly the same.
This part is the selling: who pays the person advising you, what never reaches the shortlist, why the better answer is the one they will not offer, and what you are quietly renting. Part two is what gets built once the paperwork is signed and who else can reach it. Part three is who carries it when the thing falls over, and what leaving costs. Some of it I have watched happen. The rest is on the public record with a regulator’s name on it, and every claim here carries a link.
None of it needs you to be technical. You only have to ask.
The Easy Fix Is The Tell
Take a common one. A home worker cannot get their laptop to hold a VPN tunnel back to the office. The provider looks at it and comes back with something for the customer to change at the home end. Not at their end. At the home end.
The tunnel is L2TP over IPsec onto a Cisco Meraki MX, and what is actually wrong is NAT traversal. The client is still negotiating on UDP 500 rather than moving to UDP 4500, because NAT-T was never configured at the office end. RFC 3947 is blunt about it: once a NAT is detected, the initiator “MUST set both UDP source and destination ports to 4500”. It never does. The tunnel dies in the NAT. Every time.
The answer is sat on their own firewall, switched off. The same MX runs AnyConnect, which “will attempt to connect using both TLS, and DTLS (Datagram TLS) over TCP and UDP 443 respectively”. Ordinary TLS on an ordinary port. A NAT understands that perfectly — there is nothing to traverse and nothing to configure — and it would work the afternoon somebody enabled it.
Nobody takes a packet capture. Nobody checks which port the client is actually talking on. Those are the first two things you do, and they would end it in a minute.
Now a second one from the same provider, and there is no network anywhere in it. A label printer, and a shipping label that has to come out in the right format. That is the whole of the request. It is also the only thing a label printer does.
The answer that came back was that it is not possible.
It was an option in the print driver. A box, in a settings dialogue, on software they administer, and the whole job was ticking it and running a test print. Nobody had to buy anything. Nobody had to design anything. They would not tick it.
Notice that “not possible” is an answer with no measurement anywhere in it, and it is the one answer that closes a ticket without anybody having to do owt. It also gets harder to walk back the longer it stands, because going to look now means admitting there was something to look at.
That is the shape to watch for, and it is the same shape twice. The fault is free to fix, the fix is sat inside kit the provider already owns and is already being paid to run, and what comes back instead is either an instruction to change something at the customer’s end or a flat statement that the thing cannot be done. When the cheap answer gets waved away without a measurement, you are not being given a diagnosis. You are being managed.
An engineer who has found the fault tells you what the fault is. Somebody who has not found it tells you it cannot be done, or tells you what to buy.
Who Pays Your Adviser
Start with the money, because everything else follows it.
When your MSP recommends a hyperscaler, they are not neutral. Microsoft’s own billing documentation describes partner earned credit — a credit applied against the charges on your Azure consumption, earned by the partner who holds admin rights to manage it. Your bill goes up, they get a slice. Sat alongside it are reseller margins, volume tiers, certification rebates, market development funds and quarterly targets, across every vendor in the stack, not just that one.
None of this is secret, and none of it is against any rule. It is published, it is normal, and it is how the channel has worked for thirty years.
Here is the bit that ought to bother you. Nobody has to tell you about any of it — not the rate, not the targets, not the credit. The person recommending the product is paid by the company that makes the product, at a rate that depends on which product they talk you into and on how much of it you then go on to consume, and there is no obligation anywhere to put a word of that in the proposal you are reading.
Another industry looked at exactly this arrangement and banned it. Under the FCA’s rules a financial adviser must “only be remunerated for the personal recommendation … by adviser charges” and must “not solicit or accept … any other commissions, remuneration or benefit”. You pay your adviser. The product provider does not. That rule exists because the regulator worked out something obvious. You cannot tell advice from selling when the seller is paid by the manufacturer.
IT never had that reckoning. The CMA has been through the cloud market and looked hard at committed spend, egress and switching, but nobody has yet looked at the layer in the middle. The outfit sat between you and the vendor, holding both a duty to you and a target from them.
Worth calling the thing by its name, as well.
An incentive is a payment from one party to shape a decision that a different party is relying on. That is the mechanism, whatever the programme is called on the vendor’s website. The vendor pays, the customer relies, and the recommendation moves.
It is coercive at the MSP’s end too, which is the half nobody looks at. Miss the tier and you do not simply forgo a bonus. Your buy price goes up on everything you sell for the next twelve months. So the pressure is not “sell this and get a treat”. It is “sell this or your whole business gets dearer”. Nobody in that position is choosing freely, and it was never designed to feel like a choice.
English law already knows the shape of this. The Bribery Act 2010 needs no public official anywhere near it — section 3 covers “any activity connected with a business”, and it bites where the person performing that activity is expected to do so “in good faith”, or “impartially”, or is “in a position of trust”. Read those three conditions. Then read the proposal on your desk.
I am not accusing anybody’s account manager of an offence. What is going on is duller than that and harder to fix. The arrangement sits a hair on the right side of the line, and the only thing holding it there is that nobody has ever established that an MSP owes you impartiality in the first place. Financial advice established it, and the commission stopped. Nobody has established it here, so it has not.
Call an incentive a mild form of corruption and people bristle. Put the payment, the target and the shortlist on the same page, then ask what else to call it.
The Small Supplier Never Gets Named
The list of suppliers you were shown is not the list of suppliers that exist. It is the list your MSP already has an account with.
To get onto that list a vendor needs a partner programme. Tiers, accreditation, rebates, deal registration, a distributor willing to carry the line. That is a machine. Running it costs money that has nothing whatsoever to do with how good the product is. There are plenty of small outfits in this country building better kit and better software than the badge on your proposal, and they will never appear on it, because they have twelve staff and no channel team.
Watch what the machine does to the recommendation.
Deal registration ties your MSP to a vendor before anybody has spoken to you about requirements. They log the opportunity, they get a better buy price and protection from another partner quoting you the same thing, and from that moment there is a reason to steer the design towards that vendor which has nowt to do with your business.
Tiers do the rest. Gold, platinum, whatever it is called this year, the status runs on annual volume, and it sets their discount on everything else they sell all year. Your project can be the thing that gets them over the line. You will not be told that.
Then the distributor decides what is left. An MSP buys through a distie, the distie carries the lines it holds agreements on, and a vendor that is not on the price list may as well not exist.
What that costs you is not abstract. A smaller supplier will usually put you on the phone to the people who wrote the software rather than a first-line script, will change something because you asked them to, and is still answerable to you next year because you are a real part of their revenue instead of a rounding error. None of that fits in a comparison matrix, and none of it pays anybody a rebate.
So ask what it would take to get one of those smaller outfits onto the shortlist. The answer tells you who the shortlist was drawn up for.
And The Mandate Comes From One Country
Look at the badges on the proposal. The hypervisor, the cloud, the network kit, the firewall, the office suite, the CRM, the backup target, the monitoring. Nearly all of them American.
None of that is a verdict on quality. It is what happens when the route to market is a channel programme, because the companies big enough to run one of those at global scale sit in one country. So the targets your MSP is carrying, the rebates that shape your shortlist and the tier that sets their margin are all written in the United States.
Which makes it worth knowing how that country currently treats the rules on winning business abroad.
On 10 February 2025 the President signed an executive order titled “Pausing Foreign Corrupt Practices Act Enforcement to Further American Economic and National Security”. It instructed the Attorney General, for 180 days, to “cease initiation of any new FCPA investigations or enforcement actions”, on the stated reasoning that enforcement against American businesses “for routine business practices in other nations” harms American competitiveness.
The FCPA prosecutes bribing foreign officials. That is the practice being described.
What followed is on the record. New Department of Justice guidelines on 9 June 2025 narrowed enforcement to cases touching cartels, direct harm to American companies or national security. Across 2025 the Securities and Exchange Commission brought no civil FCPA actions at all and disbanded its FCPA unit, while the Department of Justice closed roughly half of its active investigations. It did not turn up to the OECD Working Group on Bribery’s March 2025 meeting either.
Same statute, different direction. It took $772 million off a French engineering company in 2014, and it is the reason the French state commissioned a report on whether American extraterritorial law works as a commercial weapon. I went through that in how far one country’s law reaches. So the law reaches across borders for foreign firms and is stood down for domestic ones, by the government of the country your entire product list comes from.
Do not expect the UK to cover the gap either. The law here is not the weak part — the Bribery Act 2010 goes further than the American statute in places, and section 7 makes it an offence for a commercial organisation to fail to prevent bribery by anyone acting on its behalf. Strict, broad, and on the books for fifteen years.
The weak part is that enforcement at this size only ever works as a joint operation. Airbus is the largest bribery settlement this country has been part of, and Airbus’s own announcement sets out the shape of it: EUR 3,598 million in penalties on 31 January 2020, going EUR 2,083 million to the French Parquet National Financier, EUR 984 million to the Serious Fraud Office, EUR 526 million to the Department of Justice and EUR 9 million to the State Department, with the SFO and the PNF running it as a joint investigation team. The money crosses several countries and so does the evidence, and no single agency can compel the lot on its own. It needs everybody to turn up.
Note the date on that. January 2020 sits inside the first Trump administration, and the Department of Justice of the day was happy enough to take its EUR 526 million share of it. The pause came five years later, from the same president in his second term. This is not a difference between administrations. It is a decision taken in 2025.
One of them has stopped turning up, and it runs deeper than an empty chair. A prosecutor that is not opening cases is not producing anything to share. No subpoenas, no document productions, no cooperating defendants, no witnesses put under pressure — the evidence that made Airbus possible existed because somebody went out and got it. Close half a docket and bring no new actions, and there is nothing sat in the pot for anybody else to draw on. This is not a country declining to hand things over. It is a country that no longer has anything to hand over.
It shuts the other door as well. Airbus’s own announcement puts the outcome down to “reporting, cooperation and new compliance standards” at the company. Firms come forward because of what happens to them if they do not. Remove what happens to them, and the self-reports that start most of these cases stop arriving. In London as much as in Washington.
The Bribery Act does not get any weaker when that happens. It just loses the supply of evidence that made it usable on precisely the cases it was written for.
Eighteen months of that, and it has not moved a single shortlist in this industry. Nobody has it in a risk register, nobody asks it on a procurement form, and nobody selling you a five-year subscription has mentioned it.
The Training Budget Went First
There is a second reason the product keeps winning, and it is less cynical than the first. A lot of the people selling to you could not do the other thing.
Employer training investment in this country has been falling for twenty years. The Learning and Work Institute’s read of the 2024 Employer Skills Survey puts it at 36% less per employee in real terms than in 2005 — GBP 1,700 against GBP 2,634. Since the 2022 survey alone it is down another 13%. The apprenticeship levy arrived in 2017 to reverse exactly this, and spend per employee including the levy has fallen 23% since.
Then look at which sectors cut hardest between 2022 and 2024. Public administration at 50%, financial services at 47%, and information and communications at 30%. That last one is ours. Nearly a third gone in two years, from the industry that changes fastest.
Meanwhile the thing being defended grew. I counted the published vulnerabilities either side of a decade straight out of the National Vulnerability Database: 6,595 CVEs published in 2015, and 49,972 in 2025. Seven and a half times as many in ten years, against a training budget that went down by a third. Those two lines are heading in opposite directions and they have been for years.
The controls that would show up the difference are not in place either. The government’s own Cyber Security Breaches Survey 2025/2026 puts two-factor authentication at 47% of businesses — the same control the five-eyes agencies named for MSP accounts in 2022, and the same one the ICO fined Advanced over. The same survey has formal cyber security policies down from 59% to 52% in a year, and business continuity plans covering cyber security down from 53% to 44%. Not holding steady. Falling.
And then put a cloud tenancy underneath the lot. A small business does not administer its own. The MSP holds the global admin, builds the identity model, sets the conditional access, decides which storage is public and which is not, and owns the console. That is precisely what it was hired for. So when a tenancy ends up misconfigured, the hands on it were the contractor’s. Not a customer clicking the wrong box.
The blast radius changed as well. A server misconfigured in 2005 reached about as far as the wire it was plugged into. A tenancy misconfigured today is on the internet the second it is saved, it is the same tenancy for every system that business runs, and the credential that administers it sits with somebody they have never met, at a company they are not allowed to audit.
The security agencies of five countries wrote an advisory about this in 2022, and the very first action on their list concerns the accounts a provider uses to get into your systems. They put it first because that is the way in.
Then there is what this industry calls training. A vendor certification is product training. It teaches you where the buttons are in one company’s console and what that company has decided to call its features, it is written and priced by the company whose products it covers, and holding enough of them is a condition of the partner tier that sets the margin. It is a sales channel wearing a mortarboard.
Knowing a console is not knowing how the thing works. An engineer with five certifications may never have read an RFC, never taken a packet capture, and never once worked out why something failed from first principles. Put that person in front of a tunnel that will not come up and the honest answer is not available to them. Blaming the IPv6 on the customer’s home network is.
So the two halves meet. They are paid to sell a product, and more and more the product is the only answer they have got. A customer paying for expertise ends up with neither.
Nobody Wrote Down What You Needed
Ask to see your requirements. Not the proposal, not the quote, not the architecture diagram with your logo on it. The requirements.
A proper capture is boring and it is not short. What does the service have to do, and for whom. How many people, from where, on what. What is the busiest hour and what is the growth over three years. How long can it be down before it costs real money, and how much data can you afford to lose. What must never leave the country, and under whose law. What has to survive a fire in one building. What are you contractually on the hook for to your own customers. What is the budget, capital and revenue, split out. What do you already own that still has life in it. Who keeps it running afterwards, and what do they already know how to run.
That is a morning’s work with the right people in the room — and it should end in a document you sign off before anybody draws a single box.
If nobody asked you most of that, you have not been given a design. You have been given the thing they already sell, with your company name on the cover.
Watch for the tell in the other direction as well. If the sizing exercise happened in the first meeting, before anybody looked at what your load actually is, then the numbers came from a template rather than from your estate, and real sizing needs data. Somebody looking at what your kit is actually doing now, for long enough to see a month-end and a quarter close.
One Option Is Not A Choice
A design is a set of choices with the reasoning attached. Which means options, and costs on all of them, not just the one they want you to take.
You should get the do-nothing, priced, including what it costs you when it breaks. You should get the cheapest thing that meets the requirements. You should get the recommendation, and you should get the one that is over-specified for you, so you can see where the line is. Each one with what it costs to buy, what it costs to run for five years, what it does not do — and what you would have to do next if you outgrew it.
And crucially, you should get the list of what was ruled out and why. That is the part that shows somebody actually thought.
If you received exactly one answer, and that answer happens to be the vendor they are certified in and the licensing model that pays monthly, you did not get a design. You got a quote wearing a design’s clothes. Nothing more.
There is a simple question that flushes this out, and I would ask it in the room. What else did you consider, and what did it cost? Somebody who did the work has the numbers to hand and rather enjoys being asked. Somebody who did not will tell you the alternatives are not supported, not enterprise-grade, or not something they would put their name to. None of those is a number.
Open Source Never Makes The List
It is not that they hate it. There is no margin on it, no rebate against it, no certification to sell and no quarterly target that it moves.
The objection is always the same, and it is the one claim in this post that is flatly untrue — “it is not supported”. All of it is supported, commercially, with a contract and an SLA and somebody to ring — Proxmox sell subscriptions per socket, and Red Hat, SUSE and Canonical sell support for the stack. You are choosing who supports it rather than choosing whether it is supported at all. What you stop paying for is the right to use software you already have.
Then there is the kit already on the floor. It gets missed entirely. At my last employer I built a private cloud out of decommissioned HPC nodes — Proxmox, Ceph and a full chain of Ansible on top — and ended up with 7 servers, 480 cores, 15 TiB of RAM and 1.8 PiB of storage, on no budget and with three people. An MSP quoting that same requirement would have costed new hardware and a subscription — there is nothing in it for them in kit you have already bought and paid for.
The other half of this is the kit already sat on your floor, and it is the half that never gets costed at all. A server does not stop working on the day its support contract runs out. “End of support” is a date the vendor chose, not a measurement anybody took of the hardware, and a box with five good years left in it is worth more to you than to anybody selling its replacement. Open source is what lets you keep using it, because the licence does not care how old the CPU is or whether the badge on the front is still in warranty.
That is the bit that pays nobody. There is no rebate on hardware you already own, no tier credit for a machine that stays where it is, and no renewal on a licence nobody had to buy. As such it does not get proposed, and the phrase reached for instead is “end of life”, which sounds like engineering and is a sales date.
Ask for the open source option to be costed properly, support included, alongside the others — and ask for the version that reuses what you have got, priced against the version that does not. Not to be talked out of the commercial one. To see the gap, so the decision is yours.
What The Alternative Actually Looks Like
There is a supported open source answer to nearly everything on a proposal, and it is worth starting with the part that costs you most, because it is never the servers.
The per-seat software. This is where the recurring money is, and where an alternative is never mentioned. Office suite: LibreOffice, ONLYOFFICE, or Collabora Online, which sells supported deployments and gives you the browser-based editing people think only comes from one place. Mail, calendars and shared contacts: grommunio speaks MAPI, so Outlook connects to it like it would to Exchange, and it is sold with support; SOGo and mailcow cover the same ground differently. Files, sharing and the bits people actually use a cloud drive for: Nextcloud, with an enterprise contract behind it. Chat and meetings, which is the Teams half: Mattermost and Rocket.Chat are the closest like-for-like, both self-hostable with support to buy, and Zulip is Apache-licensed and threads properly. Matrix with Element, Nextcloud Talk and Jitsi cover the rest. And the SharePoint half — intranet, document libraries, team sites — is XWiki, BookStack, OpenProject, Seafile and Nextcloud between them.
The business applications. ERP: Odoo Community, ERPNext, Dolibarr. CRM: SuiteCRM, which the company behind it sells support for, or EspoCRM. Accounting: GnuCash, or the ledger built into Dolibarr and ERPNext. Document management: Paperless-ngx. Reporting: Metabase. Service desk and asset tracking, which your MSP is charging you for as a product: GLPI and Zammad.
Identity and secrets, which everything else hangs off. Keycloak, FreeIPA, or Samba as a domain controller. For passwords, Bitwarden can be self-hosted, Vaultwarden is a lightweight AGPL server that speaks to the same clients, and Passbolt and KeePassXC cover the same job differently. This is a per-user monthly line on most proposals.
Device management, which is the Intune line on your bill. Fleet does inventory, policy and enrolment across the platforms an estate actually contains, built on osquery. MicroMDM handles Apple enrolment, Headwind handles Android, and Ansible, Puppet or Salt do the configuration underneath any of it. For the remote-access half — the thing a later section of this post is entirely about — MeshCentral is Apache-licensed and RustDesk is AGPL, and both run on a server you own. Which means the answer to “which remote tool is on my machines, and who can log into the console” can be one you host and patch yourself, rather than one you find out about afterwards.
And the updating itself is no longer the dark art it gets sold as. Even on the Fisher-Price OS (Windows), application updates now run through winget, which is MIT-licensed, against a community manifest repository under the same licence; Chocolatey and Scoop have been doing the same job for longer, and every Unix has had it since the nineties. So when patch management turns up on a proposal as a premium managed line, look at what is actually being sold. The mechanism is free and shipped by the platform vendor, and setting it up is an afternoon. After that it is a scheduled task. A cron entry, or whatever the console calls one, running on a machine that was already there. You are paying a monthly fee for a job that runs itself.
The answer to that is supposed to be that you are paying for somebody to watch the result and act when it fails, and that would be worth the money. So look at the evidence for the watching. At Capita the alert was raised in ten minutes and acted on the best part of three days later, against a one-hour target, by a team the regulator found understaffed. Out on the internet there are firewalls still carrying vulnerabilities that went into the exploited catalogue years after a fix shipped. The watching is the part that would justify the invoice, and it is the part with the least evidence of happening.
The phone system, which is one of the oldest per-extension monthly lines there is. Asterisk has been doing this for twenty-five years, FreePBX puts a web interface on top of it, FreeSWITCH is the other engine, and Kamailio and OpenSIPS handle SIP routing at carrier scale. If you want it packaged rather than assembled, Wazo, FusionPBX and Issabel all ship it built.
It is also worth remembering what happened to the proprietary one most providers propose. In March 2023 CISA published an alert stating that “3CXDesktopApp — a voice and video conferencing app — was trojanized, potentially leading to multi-staged attacks against users employing the vulnerable app”. Nobody had to find a vulnerability and exploit it. It arrived as the vendor’s own signed application through the vendor’s own update channel, onto every desk a partner had rolled it out to.
Adobe, which is a per-seat subscription like everything else. Most businesses are not paying for a creative suite at all. They are paying for Acrobat and for signatures. Stirling PDF is a self-hosted toolkit doing the merging, splitting, redaction, OCR and form filling that Acrobat Pro gets bought for, and Okular or LibreOffice Draw cover the rest. For signing, Documenso and DocuSeal are both AGPL and both self-hostable — and a per-envelope charge for signing a document is about as clean an example as this post has of metering something your own server would do for nothing. Where there really is a design team: GIMP and Krita for images, Inkscape for vector, Scribus for layout, darktable and RawTherapee for photography, Kdenlive for video, Blender for 3D and compositing, Audacity and Ardour for audio.
Video, which is worth a paragraph of its own. Cameras get sold as a managed product with a licence per channel and a recorder you are not allowed inside. Frigate is MIT-licensed and does object detection locally on hardware you own; ZoneMinder has been GPL for twenty years. For conferencing, Jitsi and BigBlueButton. And remember which product it was that Cisco paid $8.6 million and another $6 million to settle over, a couple of sections down from here. Video surveillance software, sold to government bodies. The premium camera stack does not come with safety attached.
Storage and filesystems, and note that nobody ever offers you a choice here at all. OpenZFS for checksummed storage with snapshots and send/receive, Btrfs, XFS, CephFS. The filesystem under your data is an engineering decision with real consequences for how much of it you get back after a bad day, and it usually arrives as whatever the appliance shipped with.
The infrastructure, last, because it is the cheapest part of the bill. Hypervisor and cluster: Proxmox VE. Storage: Ceph, which will happily run on the disks you already own instead of a new array. Firewall and routing: nftables, OPNsense. VPN: WireGuard or strongSwan. For the mesh overlay everybody now sells, it is worth getting the picture right. Tailscale’s clients are open source and its own hosted coordination server is not — the company states that it “remains proprietary as part of our managed service”. But there is an open coordination server, and it is a serious one: Headscale is BSD-licensed, “an open source, self-hosted implementation of the Tailscale control server”, and Tailscale employs its head maintainer while saying it “does not set Headscale’s product direction”. So the whole thing can be run on your own kit. NetBird and Nebula are the other routes. Load balancing: HAProxy and keepalived. Monitoring: Prometheus, Grafana, Zabbix. Backup: Proxmox Backup Server, Bareos, restic. Config management: Ansible. And for the integration work that gets quoted either as bespoke development or as a per-run cloud automation subscription, Node-RED is Apache-licensed, runs on a box you own, and does not bill you per execution.
Three places where I will not pretend the swap is clean. First, Teams and SharePoint. The destination is not the problem, whatever you get told — the products above are mature and businesses run on them. The migration is the problem: years of accumulated sites, permission inheritance nobody ever documented, Power Automate flows somebody built and then left, and co-authoring behaviour staff expect without being able to name it. That is real work, and it should be costed as real work rather than waved away in either direction. Though notice what you stop carrying as well. Those flows and those sites are business processes running in somebody else’s datacentre, on a platform you cannot restart. When they stop, you do not fix them. You wait, and you tell your own customers you are waiting. And UK accounting has a hard edge: VAT has to be filed through software HMRC recognises, and HMRC publishes the list. The open source routes to Making Tax Digital exist — GnuCash has a community bridge, ERPNext has a UK VAT module — but they are community-maintained rather than a product with a support contract behind them. That is a real limitation and it belongs in the comparison. Third, a working design agency lives or dies on file interchange, and clients who send you a .psd and expect one back are a real problem rather than a matter of principle. For everybody else, who needs to fill in a PDF and get it signed, there is no swap to make at all. It is just stopping paying.
Why The Better Business Never Gets Sold
So why is none of it offered? Because it would be better business for them, not worse, which makes the refusal more interesting rather than less.
There are two ways to make money out of a customer. Resell a licence, and the margin is set by somebody else, capped by them, repriced by them at renewal, and paid whether you did any work that month or not. Deploy and run an open stack, and the margin is your own labour at your own rate, with nobody taking a cut on the way through and no vendor able to change the number next April. The second is worth more per customer, and it builds something. An engineer who can run Ceph, or stand up a mail server that Outlook talks to, is worth more next year than they are this year. Somebody who has only ever driven a console is worth exactly the same next year, and only for as long as that console exists.
It is also harder, and that is the whole of it. It has to be earned again every month. It needs engineers rather than administrators, and engineers are expensive, take years to grow, and can walk out and set up on their own. A licence never leaves.
That is a commitment, and commitment is the thing being avoided. Reselling asks nothing of anybody. Pick a vendor this year, pick a different one next year, and when it falls over it was never your design in the first place. Running the stack yourself means choosing it, learning it properly, and standing behind it in front of a customer at two in the morning. One of those needs you to know something. The other needs a portal login.
It also breaks the arithmetic the model runs on. A managed service is priced on leverage — as many customers as possible per engineer, junior staff working down runbooks, escalation only when the runbook runs out. That works because the job has been reduced to steps. Put in a stack that somebody has to actually understand and the ratio collapses, the wage bill climbs, and the business finds itself depending on people who could leave and take customers with them.
So the question underneath the shortlist was never which product is better. It is whether a firm is willing to be the sort that employs people who know things.
Which is where the training figure from earlier comes back round. A sector that has cut its spend on skills by 30% in two years cannot sell skill, so it sells licences. Selling licences means it never has to acquire the skill, so the training stays cut, and next year there is even less it can offer. That is a loop, and it only turns one way.
The rest is incentive, and we have been through it already. The vendor pays a rebate on the licence and nothing at all on the labour. The salesperson is compensated on product. And when a hyperscaler has an outage it is the hyperscaler’s fault, while a cluster you built yourself is yours — so reselling buys somebody a place to put the blame. That is worth real money to a business that would rather not be accountable.
None of that makes it the right answer for you. It just explains why the comparison never gets written.
The IPv4 Tax
This one is the cleanest example in the whole post, because you can put a price on both sides.
They will build you an IPv4-only service. Then they will sell you the public addresses you need to reach it, per address, per month, forever. Ask for another and there is a form, a justification and a line on the renewal.
Meanwhile IPv6 costs nothing extra. The allocation comes with the registry membership you are already paying for, and RIPE’s 2026 charging scheme is a flat EUR 1,800 per LIR account whatever you hold. RIPE-690 says an end site gets a /48 or a /56. There is no per-address meter on the v6 side. There is nothing to meter.
The numbers on the other side are public too. AWS charges $0.005 per hour for every public IPv4 address, attached or not, which is about $43.80 a year each. On the transfer market the average price in the first half of 2026 was $20.04 per address, with the going lease rate about $0.59 per address per month. So an address is worth roughly twenty dollars to buy outright, and rents wholesale for about seven a year — and it is being resold to you as a scarce resource. A monthly line on your bill and a form to fill in when you want another.
The scarcity is real. The reason you are still paying for it is not. Dual-stacking a service is an afternoon’s work, and it turns a recurring charge into a one-off change request, which is precisely why it never gets proposed.
If you want the full picture of who in this country has actually bothered, I counted the lot: We Never Ran Out of Addresses. We Ran Out of Effort.
Cloud By Default, When Everything You Have Is On Site
Think about where the work actually happens. A manufacturing site. A car mechanic. A catering business.
Every user is in the building. Every bit of data is made in the building — the machines, the tills, the job cards, the stock, the CAD, the CNC programs, the orders coming over the counter. Everything that consumes that data is in the building as well. No second site, no field force, no customers hitting a web front end, and no month where the load doubles.
Put the application in somebody else’s datacentre and every one of those bytes now leaves the premises and comes straight back. Same users. Same data. Same processing. Plus a WAN in the middle of it, a monthly bill, and a dependency on a line you do not own.
Nothing cloud is genuinely good at applies here. Elastic scale is for load that moves, and a shop floor running two shifts does not move. Global reach is for users who are somewhere else, and yours are stood at the machine. Somebody else’s building is a real answer for disaster recovery, but disaster recovery is a backup target, not the place you run the line from.
What it does buy you is a new way to stop. On prem a dead broadband line is an inconvenience, and the work carries on until somebody fixes it. In the cloud it is a stoppage — the line goes, the garage cannot pull up a job, the kitchen cannot take an order, production stands there, and you are waiting on somebody else’s engineer against an SLA you never negotiated.
And your broadband is only half of it. The other half is theirs, and it goes down too. AWS’s own post-event summary for October 2025 describes a disruption in its primary Northern Virginia region running from 11:48 PM on 19 October to 2:20 PM on 20 October — the better part of fifteen hours — where customers and other AWS services “were unable to establish new connections”. The cause, in their words, was “a latent defect within the service’s automated DNS management system”. Nine days later Azure Front Door took Microsoft 365, Outlook and the Azure portal down with it for most of a working day. Microsoft keeps a running history of these, and it is not a short document.
Downtime is not the whole of it either. The other thing sold on the front of the proposal was capacity on demand, and that has a documented failure mode of its own. Microsoft publishes a page titled “Troubleshooting Azure VM allocation failures”. AWS publishes “How do I troubleshoot InsufficientInstanceCapacity errors when I start or launch an EC2 instance?”. Read those titles again. Both vendors maintain standing documentation for the case where you ask for a machine and there is not one — no fault, no outage, just nothing spare in that region today. On top of that sit quotas, set per subscription, which is a second way to be told no.
So the elastic scale on the proposal carries a caveat the proposal does not. Elastic within whatever is spare, in that region, on the day you ask. And providers keep signing customers into constrained regions regardless, because a signature counts this quarter and a capacity check does not. You find out at deployment, which is the worst moment available — after the migration is committed, after the on-premises kit has gone, and after the fallback was torn down to pay for the move.
Read what all of that means for the garage and the kitchen. On your own kit, an outage is somebody you can ring, or a machine somebody can walk over to and restart. In somebody else’s cloud there is no lever at all. You cannot escalate it, you cannot prioritise your own recovery, and neither can the provider you are paying. They are refreshing the same status page as everybody else. What you bought as resilience turns out to be a dependency you share with several million other customers, and on the day it fails your position is the same as theirs.
So why is it always the recommendation? Because a capital purchase pays your MSP once. A subscription pays them every month, at a percentage, with a credit from the vendor on top. Migrating you also moves the hardware off their plate, which is the part of the service they find hardest to staff. Three reasons pointing the same way, none of them yours.
Then there is where your data ends up. Under 18 U.S.C. § 2713, added by the CLOUD Act, a US provider must produce data in its “possession, custody, or control” when properly served, “regardless of whether such communication, record, or other information is located within or outside of the United States”. So “it is in the UK region” is a true answer to a question you did not ask. The region tells you where the disk is. The statute follows who owns the company.
Nobody put that to you as a decision. It arrived as an assumption, inside a proposal, written by somebody who gets paid more when you say yes.
I have written about that dependency at length in what renting your technology costs.
All Of That Happened Before Anything Was Built
Notice when it takes place, the whole of it. Before a machine is racked, before anybody has logged into anything, in meetings and on spreadsheets you were mostly not in. The rebate, the requirements nobody captured, the single option, the missing open source line, the addresses you will now rent for the life of the contract, the datacentre nobody in the building needed — none of it is technical, and all of it is settled in the first fortnight.
Which is why it is worth your attention even if you have never opened a switch. It is also why it is so hard to unpick afterwards. Everything downstream inherits that fortnight. The estate gets built the way the shortlist said it would. The tooling turns up because it is what the provider already owns and already knows. The keys end up wherever their process puts them. And the contract signed at the end of it decides, years ahead of time, who is carrying the loss on the morning something stops.
So part two is what actually got built: the box they will not be talked out of, the perimeter kit with the worst record on the exploited list, the basics that were the thing you bought, and the tooling that reaches every machine you own from a console you have never seen. Two of the failures in it have a regulator’s finding attached. None of them happened to a customer. They happened to a provider, and the customers were downstream.
Sources
Retrieved 28 August 2026.
How the money works.
- Microsoft Partner Center billing documentation — partner earned credit applied against charges on customer Azure consumption.
- FCA Handbook, COBS 6.1A — adviser charging: the rule that a firm must only be paid for a recommendation by the client, and must not accept commission from the product provider.
- CMA cloud services market investigation — the UK competition regulator’s work on the cloud market.
Addresses.
- RIPE NCC charging scheme 2026 — EUR 1,800 per LIR account, flat.
- RIPE-690 — /48 or /56 to an end site, October 2017.
- AWS public IPv4 charge — $0.005 per address per hour, from February 2024.
- IPv4 transfer market, first half of 2026 — average $20.04 per address, lease rate about $0.59 per address per month, summarising CircleID’s analysis of publicly priced transactions.
The VPN.
- Cisco Meraki’s AnyConnect troubleshooting guide — TLS and DTLS on 443, with no NAT problem to solve.
- RFC 3947 and RFC 3948 — NAT traversal for IPsec, and the move to UDP 4500.
Support you can actually buy.
- Proxmox VE subscriptions — one example of commercial support for open source infrastructure.
Training and skills.
- Learning and Work Institute, 24 December 2025 — employer training investment down 36% per employee in real terms since 2005, and down 30% in information and communications between 2022 and 2024, on the 2024 Employer Skills Survey.
- National Vulnerability Database — CVE publication counts by year, summed per quarter: 6,595 in 2015 against 49,972 in 2025.
- Cyber Security Breaches Survey 2025/2026 — two-factor authentication at 47% of businesses, formal policies down to 52%, continuity plans covering cyber down to 44%.
- CISA alert, 30 March 2023 — the trojanised 3CX desktop application.
Law and policy.
- Executive order, 10 February 2025 — pausing Foreign Corrupt Practices Act enforcement, in the administration’s own words.
- Just Security, on the year that followed — the June 2025 enforcement guidelines, the SEC’s disbanded FCPA unit, and the closed investigations.
- Bribery Act 2010 and section 7 — the UK statute, and the corporate failure-to-prevent offence.
- Airbus, 31 January 2020 — the company’s own account of the tripartite settlement and how the penalties split between the PNF, the SFO, the DoJ and the DoS.
Jurisdiction.
- 18 U.S.C. § 2713 — the CLOUD Act provision: disclosure regardless of where the data is stored.
When the platform stops.
- AWS post-event summary, October 2025 — the DynamoDB and DNS disruption in us-east-1, in Amazon’s own words.
- Azure status history — Microsoft’s own running record of its incidents.