Service 4 of 7

Infrastructure
independently assessed

We assess independently which infrastructure fits your goals: your own data centre, a European or international cloud, or a hybrid model. The yardsticks are cost, risk, operations and data sovereignty.

Three stacked platforms of bronze and smoked glass with a warm core of light, as an image of sovereign infrastructure
3D visualisation: AI-generated

What it is about

The right infrastructure, measured against your criteria

Own data centre, cloud or both: infrastructure decisions often bind a company for many years. Yet they are frequently made under time pressure, for example before a contract renewal or after a security incident, and on the basis of vendor offers.

We assess your options independently. Before we compare offers, we agree the criteria with you: total cost over the full term, risks, operating effort, dependence on individual providers and the question of who can access your data. Every option is measured against the same yardsticks.

Data sovereignty calls for an honest assessment. Providers subject to US law can be compelled to hand over data under the CLOUD Act and FISA Section 702, even when the servers are located in Europe. That does not rule such offers out, but it belongs in the assessment. We treat “Your data stays your data.” as a criterion to be tested.

We also look at the infrastructure from a security perspective: identities and access, network segmentation, backup and recovery. The outcome is a reasoned recommendation with a roadmap that you can defend in front of shareholders, auditors and clients.

Bronze vault with a slightly open door and warm light inside
3D visualisation: AI-generated

What you gain

A decision for years, on a solid basis

  1. A recommendation you can defend

    All options are measured against the same criteria, which you agree with us in advance. The recommendation stands up to questions from shareholders, auditors and customers.

  2. Cost over the full term

    We include operations, licences, migration and a possible exit, not just the entry cost. You see what an option really costs over the contract term.

  3. Knowing who can access your data

    You learn which data is located where and which jurisdiction applies there. For sovereignty-critical data we do not recommend US hyperscalers.

  4. Independent of vendors

    We are not tied to any provider. The recommendation follows solely from the result of the analysis.

What we analyse

The view of the whole

  • Data centre, network and workplaces
  • Cloud and SaaS
  • Identity and access, network segmentation, backup and recovery
  • Service providers and operational responsibility
  • Dependencies and ability to switch

What you receive

Results that belong to you

  • A current-state review of your infrastructure
  • A comparison of options against criteria agreed in advance
  • A recommendation with rationale and roadmap

How we work

Four steps, each with a result

  1. Step 1

    Record the current state

    We capture data centre, cloud services, network, workplaces and the contracts behind them.

  2. Step 2

    Agree the criteria

    You decide with us what counts and how much, before any offer is on the table.

  3. Step 3

    Compare the options

    We assess data centre, European and international cloud as well as hybrid models against the same yardsticks.

  4. Step 4

    Justify the recommendation

    You receive a recommendation with rationale, risks and roadmap.

From practice

The contract is expiring, the offer is already on the table

The data centre contract expires in a year, and a provider has already submitted a cloud offer. Before any negotiation, we agree the criteria with the managing directors and assess three paths: renew, move to a European cloud or build a hybrid model. Management decides on the basis of a comparison that discloses cost, risk and data access, and goes into the negotiation with clear requirements.

A typical scenario as we encounter it in engagements, not a single client case.

Three platforms side by side, of glass, bronze and both, like three options to choose from
3D visualisation: AI-generated

When it pays off

Typical occasions

  • Before contract renewals or a cloud decision

  • After a security incident

  • When clients demand evidence

How it fits your path. Understand with a focus on BISA 1, then Architect and Transform. Penetration tests are separate services. It always starts with a free 45-minute initial call.

How the five phases fit together

Questions and answers

What managing directors ask about it

Is a US cloud with a data centre in Europe sovereign?

Not entirely. Providers subject to US law can be compelled to hand over data under the CLOUD Act and FISA Section 702, regardless of where the servers are located. We state this difference openly and assess all options against the same yardsticks.

As of October 2026, not legal advice

How does the assessment stay independent?

You agree the criteria with us before we compare options. Every assessment is documented so that you can follow it.

Why SIMO

Advisory that is on your side

  • Independent

    We are not tied to any vendor. Our recommendation follows the outcome of the engagement.

  • Eye to eye

    Thomas Wassum and Andreas O. Schwan lead every engagement personally as managing partners.

  • Results-driven

    Every phase delivers a result that stands on its own. No lock-in, no obligation to continue.

  • Sovereign

    “Your data stays your data.” For sovereignty-critical data we do not recommend US hyperscalers.

Your next step

45 minutes, and you will know whether it fits.

The initial call is free of charge and without obligation. You speak directly with one of the two managing partners.

Book an initial call

Or place yourself first: four-step self-check

Prefer to call? +49 6021 625 63 40

Note: the 3D visualisations on this page were created with AI.