Carla Petersen | F5 Channel Manager | Westcon-Comstor | mail me |
Hybrid IT and hybrid cloud are terms that we are continually confronted with. Still, when asked to explain what this translates to, there is often a pause in the room as people try and ascertain if it’s hybridity or multi-cloud, which we are referring to.
It’s almost as if the term multi-cloud has been used to get around the challenges of the hybrid model.
A hybrid infrastructure or cloud is an infrastructure or design comprising a mix of on-premises data centres and private and public clouds. Within this structure, a business can deploy applications, operating systems, or processes at any point that makes sense to the business.
Yes, the multi-cloud term has a place, as organisations operate in multiple clouds, but the term itself doesn’t speak to the complexities of hybrid IT.
For as long as the cloud has been here, IT has had one foot in the cloud and the other still in its own on-premises data centre. Add to this that their IT portfolio also spans myriad applications, systems, and solutions that are an established part of their IT portfolio. This often includes every generation of major app architectures, from monoliths to microservices, from client-server to mobile.
Distribution of apps
In the F5 State of Application Strategy 2023 report, the company asked respondents what the distribution of their enterprise application portfolio was.
The results stated that 15% of these apps were in the public cloud, 16% were served as a SaaS service, 17% were in an on-prem or private cloud, and 37% were in a traditional on-premises data centre.
When understanding where applications are distributed, it is essential to be specific about the on-premises environments they are hosted on as it offers a clear picture of the challenges that customers are facing. And if the above figures are to be analysed, it is clear that customers are still very much living in a hybrid state.
There is no doubt that there is a trend towards modern applications, but there is also still some caution being exercised as many IT professionals have emphatically stated that they won’t (in the immediate future) replace all traditional apps with modern ones. This then offers us the view that we can expect to live in a “hybrid IT” world for years to come.
The Implications for App and API Security
Now that we know that we are living in a hybrid world, we can assume that businesses’ application portfolios and operational environments are themselves hybrid. But this also highlights that this fact has a huge implication for application and API security.
Why? Remember that every application environment, just like containers, all have very specific use cases and needs for security. Not all of these can be met by traditional security offerings available on the market today.
It also suggests that the complexity of balancing on-premises and cloud environments for applications isn’t going to go away as businesses will battle to find security solutions that traverse core, cloud, and edge application workloads.
The bottom line? According to F5, hybrid IT does not imply hybrid security. What is inferred by hybrid security is a mix of app and API security services from multiple vendors that must all communicate and be interoperable.
What a lot of security companies are proposing as a solution is moving security “left” into the application lifecycle. On paper, this is the easiest way and the path of least resistance, but don’t forget that many of these apps and API security services aren’t compatible.
What next?
The complexity that cloud tools, cloud-native apps, APIs, and even SaaS solutions serve makes it nearly impossible for a business to consistently apply security across all applications.
How do we know this approach isn’t working? Because we have seen (first-hand) a massive increase in breaches over the past year, all of which are coming from cybercriminals attacking vulnerabilities and exploits in APIs.
So what is the solution? Well, it isn’t a patchwork approach to securing apps and APIs. We need to embrace the fact that IT will remain hybrid for years to come, so we need to look at how we can deploy application infrastructure platforms – not just to manage application complexity. But also to ensure enterprise (hybrid) application security.


























