Pappe: Let me challenge you. In principle, you’re
right. Why should an off-premise service be different
from an on-premise service if the same rules, processes,
and policies are applied? Often you don’t know the
off-premise rules and policies, as well as you know your
own policies. Let’s take the example of the famous malicious
insider. On premise, hopefully you don’t have
shared privileged IDs, so if there’s a malicious insider,
you know who it is. Does your off-premise provider
follow the same rule set? If not, the probability that
they’ll catch a malicious insider is much lower.
Krebbers: I’m more careful of statements like on
premise is more secure than off premise.