Owning and operating physical hardware exposes organisations to supply chain risk, rising costs, and mounting operational burden. Here is why regulated organisations are shifting the model.
The 2021-22 global chip shortage was a sharp reminder of something that had been quietly true for years: organisations that depend on physical hardware are exposed to risks that sit entirely outside their control. Factory shutdowns, geopolitical tensions affecting supply chains, extreme weather disrupting fabrication plants. None of these were predictable, and all of them cascaded into delayed procurement, cost increases, and constrained IT programmes.
For regulated organisations running critical infrastructure, hardware dependency creates a specific set of problems that go beyond procurement complexity. Understanding them is useful context for any organisation evaluating how its network and security estate should be owned and operated.
Hardware procurement has long lead times in the best of conditions. Chips can take months from order to delivery. Specialist networking and security appliances require configuration, testing, and integration before they are operational. In a stable supply environment, this is manageable. When supply chains tighten, whether due to geopolitical disruption, manufacturing constraints, or sudden spikes in demand, organisations that depend on hardware find their infrastructure programmes stall at the point they can least afford it.
For regulated organisations, this is particularly acute. A delayed firewall refresh is not just an operational inconvenience. It can become a compliance risk: out-of-support hardware, extended vulnerability windows, and evidence gaps that auditors will ask about.
Hardware is typically treated as capital expenditure: a known cost, approved once, depreciated over time. In practice, the total cost of owned hardware is considerably less predictable. Prices fluctuate with supply and demand. Refresh cycles arrive faster than anticipated as vendor support windows shorten. Spares and replacements carry their own lead times and costs.
Operating costs add further unpredictability. Hardware requires rack space, power, cooling, maintenance contracts, and the engineering time to configure, patch, and manage it. For organisations running estates across multiple sites, these costs multiply at each location.
Owned hardware requires ongoing management that is easy to underestimate at procurement time. Firmware needs patching. Configurations drift. Rules accumulate without clear ownership. The person who originally set the system up leaves, and their replacement inherits an environment that is underdocumented and harder to evidence than anyone would like.
For regulated organisations, this accumulation creates a specific problem at audit time. Assessors examining a firewall estate under DSPT, CAF, or NIS2 expect to see change records, patch logs, and evidence of active governance. An estate running without a managed service behind it rarely produces that evidence cleanly.
Moving from owned hardware to a managed service transfers the supply chain and operational risk to a provider whose model is built around absorbing it. Cloud-delivered security and connectivity services, of the kind that make up a SASE architecture, remove the hardware layer from the customer’s estate entirely. Policy and capability are delivered through the platform; the infrastructure underneath is the provider’s responsibility to scale, maintain, and keep current.
For regulated organisations, this model has a further advantage: the evidence that auditors expect, change records, patch logs, configuration history, posture reporting, is generated as a by-product of the service rather than assembled by the customer’s team before each assessment cycle.
The chip shortage was a specific event. The argument for reducing hardware dependency is structural, and it applies regardless of what the supply chain is doing in any given year.
Cloud Gateway delivers connectivity and security as a managed service, with no hardware for the customer to procure, operate, or evidence. For more on how the platform works, see our platform page.