Cloud-first should not mean control-last

Why schools need to look beyond service descriptions when reviewing connectivity, filtering and resilience

Cloud-first has become the default direction for school IT, but it does not answer every infrastructure question.

Microsoft 365, Google Workspace, cloud storage, safeguarding platforms, VoIP, MIS access, remote support tools and online assessment all depend on reliable, secure internet access. For schools and trusts, cloud is already part of daily operation.

The internal network also plays a part, because wireless coverage, switching, VLANs and local network design all affect how reliably users reach those cloud services.

The useful question is what still needs to sit close to the school or trust to keep access to those services safe, resilient and controlled.

Cloud-based applications can make clear operational sense. They support easier access, regular updates, collaboration, remote working and reduced internal maintenance. But the infrastructure that protects access to those applications needs a different kind of scrutiny. Firewalling, failover, traffic visibility and filtering all form part of the control layer between the school and the services it depends on, but they do not all have to sit in the same place.

A school may use cloud applications across teaching, finance, communication and administration, while still choosing to keep some key controls close to the school network, and using client or cloud-based filtering where that is the better fit for managed devices.

Cloud-first should not mean control-last.

This article sets out the main considerations. A more detailed technical white paper is also available for schools and trusts that want to review the architecture in more depth.

What schools should check in hosted models

Hosted firewall and filtering models can look clean and modern.

There may be less equipment on site. Management may be centralised. The service may be easier to describe in procurement documents. The commercial model may also look simpler. In some cases, a hosted approach may be appropriate.

The important point is that schools and trusts should understand the architecture beneath the proposal.

A hosted model may route school traffic through a provider platform before it reaches the internet or cloud services. It may rely on shared infrastructure. A primary connection and a backup connection may still depend on the same central platform.

That distinction becomes important during an outage. If the main circuit fails, a backup connection may keep the school online. But if the dependency sits within the hosted platform itself, the second connection may not solve the problem. In a trust, the same issue may affect several schools at once.

This does not make hosted models automatically wrong. It means resilience needs to be examined beyond the headline promise.

A service can include two connections and still have shared dependencies elsewhere in the design. A proposal can describe a service as managed, resilient or cloud-hosted without making clear where the true points of control and failure sit.

For schools, this affects teaching continuity, safeguarding, support response, change control and the ability to diagnose faults during the school day.

Local control does not mean local burden

Any discussion of on-site infrastructure needs care.

For a small primary school, local control should not mean extra technical responsibility. Leaders do not want to manage firewall rules, investigate traffic logs or become network specialists. They want the service to work, stay safe and be supported by people who understand schools.

Control close to the school means the protection is enforced close to where it is needed. The service itself can still be fully managed by a specialist provider.

For a secondary school or trust with its own IT team, the same model can provide delegated access, better visibility, log review and the option to make agreed changes internally.

The service model should fit the school’s internal capability. Some schools want everything managed for them. Others want a co-managed model with more technical visibility. The underlying principle is the same: control should be available, accountable and close enough to the point of risk.

Why direct internet access and local firewall control still matter

A direct internet access model with local firewall control gives schools and trusts a different set of options.

Cloud services can still be reached efficiently, while firewalling, local network protection and relevant filtering controls are enforced at the school’s network edge. This gives more flexibility over connection type, carrier choice and backup design. It also makes it easier to distinguish between an internet fault, a firewall issue and a local network problem when cloud services appear unavailable.

Resilience is more than having a second line

A stronger design considers how the second connection behaves, whether it uses a different carrier or technology where available, whether both links can be used actively, whether critical services can be prioritised during an outage, and whether failover happens automatically.

That is a different conversation from simply saying “there is a backup connection”.

Local firewall control can also support visibility that may be harder to achieve if enforcement is handled away from the site. Depending on the configuration, this can include filtering by group, user, device or IP, HTTPS inspection, application control, intrusion prevention, remote access, site-to-site VPN and local management access.

For leadership teams, the practical test is simpler: can the school understand how it is protected, how failover works, how safeguarding controls are evidenced, and who takes ownership when something goes wrong?

Hybrid is often the stronger model for schools

For many schools and trusts, the strongest answer is not cloud-only or on-premise-only. It is hybrid.

That means using cloud services where they make sense, while keeping certain controls close to the school or trust where they improve resilience, visibility and accountability.

In practice, that may mean client or cloud-based filtering for managed school devices, alongside on-premise firewalling and network-level filtering for guest access, unmanaged devices, shared classroom technology and local network traffic.

Hybrid should not be understood as a halfway house. It is a design approach that places each control where it works best. For education, that means using cloud intelligently without giving up control where control is still needed.

What schools should ask before renewing or comparing quotes

When schools compare broadband, firewalling and filtering provision, it is natural to look first at price, bandwidth, contract length, support promises and headline features.

Those points are important, but they do not show the whole architecture.

Before renewing or comparing quotes, schools and trusts should ask:

  • How does school traffic reach the internet and cloud services?
  • Where do firewalling, filtering and monitoring controls sit?
  • Does filtering work across the right users, devices and locations?
  • Are primary and backup connections designed to reduce shared dependency?
  • What happens if the hosted platform has an issue?
  • Can internal network issues be distinguished quickly from internet, firewall or filtering faults?
  • Who owns the issue when connectivity, firewalling, filtering, LAN/WLAN or another third-party service is involved?

These questions are especially useful at renewal.

A school may be happy with its current provider. A trust may be comparing several proposals that appear similar on the surface. A lower-cost hosted option may look attractive if the only comparison is price, bandwidth and basic filtering.

But if the design introduces shared dependencies, limits visibility, restricts local control or makes failover harder to evidence, the comparison is incomplete.

The decision is not simply about buying internet access. It is about choosing the control layer between the school and the services it now depends on every day.

Why Wave9 takes a hybrid approach

Wave9 has chosen a hybrid, direct-internet-access approach because schools need more than generic connectivity.

Cloud services now sit at the centre of teaching, administration, communication and safeguarding, but the experience depends on the full path from device to cloud service. The infrastructure around those services has to protect access, keep essential services available, and allow issues to be understood and resolved quickly by people who know how schools and trusts operate.

That is why Wave9 places key controls close to the school where that improves resilience, visibility and accountability, while also using client, cloud and specialist filtering options where they are the better fit for the requirement.

This is not about keeping technology on site for the sake of it. It is about making sure the right controls sit in the right place.

If your school or trust is renewing broadband, firewalling or filtering provision, Wave9 can help review the architecture behind each proposal, so decisions are based on how the service will work in practice, not just price, bandwidth or feature lists.

For a deeper technical comparison, read Wave9’s companion white paper: Hybrid Infrastructure for School Connectivity.

Scroll to Top