Service 4 of 7
Infrastructure
independently assessed
We assess independently which infrastructure fits your goals: your own data centre, a European or international cloud, or a hybrid model. The yardsticks are cost, risk, operations and data sovereignty.

What it is about
The right infrastructure, measured against your criteria
Own data centre, cloud or both: infrastructure decisions often bind a company for many years. Yet they are frequently made under time pressure, for example before a contract renewal or after a security incident, and on the basis of vendor offers.
We assess your options independently. Before we compare offers, we agree the criteria with you: total cost over the full term, risks, operating effort, dependence on individual providers and the question of who can access your data. Every option is measured against the same yardsticks.
Data sovereignty calls for an honest assessment. Providers subject to US law can be compelled to hand over data under the CLOUD Act and FISA Section 702, even when the servers are located in Europe. That does not rule such offers out, but it belongs in the assessment. We treat “Your data stays your data.” as a criterion to be tested.
We also look at the infrastructure from a security perspective: identities and access, network segmentation, backup and recovery. The outcome is a reasoned recommendation with a roadmap that you can defend in front of shareholders, auditors and clients.

What you gain
A decision for years, on a solid basis
A recommendation you can defend
All options are measured against the same criteria, which you agree with us in advance. The recommendation stands up to questions from shareholders, auditors and customers.
Cost over the full term
We include operations, licences, migration and a possible exit, not just the entry cost. You see what an option really costs over the contract term.
Knowing who can access your data
You learn which data is located where and which jurisdiction applies there. For sovereignty-critical data we do not recommend US hyperscalers.
Independent of vendors
We are not tied to any provider. The recommendation follows solely from the result of the analysis.
What we analyse
The view of the whole
- Data centre, network and workplaces
- Cloud and SaaS
- Identity and access, network segmentation, backup and recovery
- Service providers and operational responsibility
- Dependencies and ability to switch
What you receive
Results that belong to you
- A current-state review of your infrastructure
- A comparison of options against criteria agreed in advance
- A recommendation with rationale and roadmap
How we work
Four steps, each with a result
- Step 1
Record the current state
We capture data centre, cloud services, network, workplaces and the contracts behind them.
- Step 2
Agree the criteria
You decide with us what counts and how much, before any offer is on the table.
- Step 3
Compare the options
We assess data centre, European and international cloud as well as hybrid models against the same yardsticks.
- Step 4
Justify the recommendation
You receive a recommendation with rationale, risks and roadmap.
From practice
The contract is expiring, the offer is already on the table
The data centre contract expires in a year, and a provider has already submitted a cloud offer. Before any negotiation, we agree the criteria with the managing directors and assess three paths: renew, move to a European cloud or build a hybrid model. Management decides on the basis of a comparison that discloses cost, risk and data access, and goes into the negotiation with clear requirements.
A typical scenario as we encounter it in engagements, not a single client case.

When it pays off
Typical occasions
Before contract renewals or a cloud decision
After a security incident
When clients demand evidence
How it fits your path. Understand with a focus on BISA 1, then Architect and Transform. Penetration tests are separate services. It always starts with a free 45-minute initial call.
Questions and answers
What managing directors ask about it
Is a US cloud with a data centre in Europe sovereign?
Not entirely. Providers subject to US law can be compelled to hand over data under the CLOUD Act and FISA Section 702, regardless of where the servers are located. We state this difference openly and assess all options against the same yardsticks.
As of October 2026, not legal advice
How does the assessment stay independent?
You agree the criteria with us before we compare options. Every assessment is documented so that you can follow it.
Why SIMO
Advisory that is on your side
Independent
We are not tied to any vendor. Our recommendation follows the outcome of the engagement.
Eye to eye
Thomas Wassum and Andreas O. Schwan lead every engagement personally as managing partners.
Results-driven
Every phase delivers a result that stands on its own. No lock-in, no obligation to continue.
Sovereign
“Your data stays your data.” For sovereignty-critical data we do not recommend US hyperscalers.
Your next step
45 minutes, and you will know whether it fits.
The initial call is free of charge and without obligation. You speak directly with one of the two managing partners.
Or place yourself first: four-step self-check
Prefer to call? +49 6021 625 63 40
Note: the 3D visualisations on this page were created with AI.