The Challenge: Meeting New Mandates with Existing Infrastructure
Between November 2021 and early 2022, three major legislative and executive actions landed on Federal IT desks: the $1.2 trillion infrastructure bill, the American Rescue Plan, and the cybersecurity executive order. Each introduced new programs, mandates, and deadlines.
Instead of celebration, these actions triggered a wave of panicked messages and emergency architecture reviews. Security teams and compliance officers faced a harsh reality: their current infrastructure couldn't scale fast enough to meet these mandates, and their siloed cloud environments weren't solving the problem.
These questions emerged in government IT channels, compliance office hours, and vendor briefings. They're real questions from teams trying to determine if hybrid cloud is a strategic move or just another costly distraction.
Q1: "We already moved some stuff to the cloud. Why are people saying we still need hybrid?"
You likely created cloud silos instead of a cohesive cloud architecture.
During the pandemic, agencies rushed applications to the cloud to support remote work. But instead of building a flexible, interconnected environment, many teams just replicated their on-prem approach in a different location. You had an application on a physical rack before; now it's isolated in a cloud tenant.
That's not hybrid. It's just on-prem with a different landlord.
Hybrid cloud means a flexible architecture that lets workloads move between on-prem and cloud environments based on security requirements, performance needs, and cost. It allows your infrastructure to scale when the American Rescue Plan requires processing millions of new applications and segregates sensitive data when Committee on National Security Systems Instruction No. 1253 or the DoD Cloud Computing Security Requirements Guide demands it.
If you can't spin up new capacity in hours instead of months, you don't have hybrid. You've got cloud sprawl.
Q2: "The infrastructure bill has cybersecurity funding. Does that mean we need to rethink our security architecture?"
Yes, and not just because there's money available.
The cybersecurity executive order calls for removing barriers to threat information sharing and implementing stronger cybersecurity standards across federal systems. If you're running a monolithic on-prem environment or isolated cloud instances, you can't meet those requirements effectively.
Hybrid cloud provides a modular architecture that's harder to compromise in a single attack. You can segment workloads by Impact Level, apply NIST SP 800-53 Rev 5 controls at the appropriate baseline (Low, Moderate, High), and implement continuous monitoring without rebuilding your entire stack every time a new Security Technical Implementation Guide drops.
The infrastructure bill's funding isn't just for buying new tools. It's for building an architecture that can support the enhanced security posture the executive order requires. That means hybrid infrastructure with proper Identity, Credential, and Access Management across environments, audit logging that works regardless of where the workload lives, and the ability to apply Two-Layer Encryption or Type 1 Encryption when handling National Security Systems data.
Q3: "We moved too fast during COVID and now everything's a mess. How do we fix this without starting over?"
You don't need to rip and replace. You need a migration roadmap that prioritizes based on compliance risk and operational impact.
Start by categorizing your current workloads:
- Which applications handle Controlled Unclassified Information and need to meet NIST SP 800-171 Rev 2 requirements?
- Which systems support programs created by recent legislation and need to scale rapidly?
- Which legacy applications can't move to cloud due to ITAR restrictions or classified information requirements?
Then build your hybrid architecture in phases. Maybe 20 percent of your infrastructure moves to a true hybrid model first (the high-impact, high-visibility programs that the infrastructure bill or American Rescue Plan created). That gives you immediate operational wins while you plan the harder migrations.
Don't try to force every application into the same model. Some workloads belong on-prem in a FIPS 140-2 validated environment. Some belong in FedRAMP Moderate cloud services. Some need GCC High because they're handling DoD data. Hybrid means you've got the architecture to support all three without creating security gaps or compliance failures.
Q4: "Our leadership keeps saying 'culture shift.' What does that actually mean for my team?"
It means your team needs to stop thinking about individual servers and start thinking about service delivery.
In the old model, you provisioned a server for an application. That server had a physical location, a fixed capacity, and a specific security boundary. Your team managed that server, and when a new mandate came down, you ordered more hardware and waited.
In a hybrid model, you're managing services across multiple environments. When the American Rescue Plan requires you to stand up a new citizen portal in weeks instead of months, you're not ordering racks. You're spinning up capacity in the environment that meets your security and compliance requirements, applying the appropriate controls from your System Security Plan, and delivering the service.
That's the culture shift: moving from "we manage servers" to "we deliver secure, compliant services wherever they need to run."
For compliance officers, it means your control implementation documentation needs to work across environments. Your Shared Responsibility Model with your cloud provider needs to be clear about who owns which controls. Your continuous monitoring program needs to work whether the system is on-prem or in cloud.
Q5: "How do we know if a workload should be on-prem, in cloud, or actually needs hybrid?"
Use your compliance requirements and operational characteristics as decision criteria.
Keep it on-prem if:
- It processes classified information that requires Commercial Solutions for Classified or National Industrial Security Program controls
- It needs hardware-based Type 1 Encryption that isn't available in your cloud environment
- It's a legacy system with hard dependencies that can't be refactored
Move it to cloud if:
- It needs rapid scaling (like programs created by recent legislation)
- It's a new application without legacy dependencies
- It fits cleanly into a FedRAMP authorized service offering and doesn't need on-prem integration
Build it hybrid if:
- It needs to burst capacity for peak demand but maintain steady-state on-prem
- It processes both CUI Basic and unclassified data with different security requirements
- It needs to share data with external partners while keeping sensitive processing internal
The infrastructure bill and American Rescue Plan created dozens of programs that fit that third category. They need to scale quickly, handle sensitive citizen data, and integrate with existing agency systems. That's a hybrid workload.
Q6: "What's the biggest mistake agencies are making right now?"
Treating hybrid cloud as a technology project instead of a compliance and operational strategy.
Teams are buying hybrid cloud platforms and then wondering why they're not seeing the benefits. That's because they haven't changed how they architect solutions, apply security controls, or think about service delivery.
The infrastructure bill gave you funding. The cybersecurity executive order gave you mandates. The American Rescue Plan gave you urgent program deadlines. Hybrid cloud is how you meet all three simultaneously, but only if you're using it to enable a new operating model, not just to host the same old applications in a fancier environment.
Next Steps: Building Your Hybrid Strategy
Your agency's Risk Management Framework process should already be evaluating system categorization and control selection. Use that process to assess which systems are candidates for hybrid architecture.
Review your cloud service providers' Customer Responsibility Matrix documentation to understand exactly which NIST SP 800-53 controls you still own in a hybrid model. If you're handling DoD data, cross-reference the DoD Cloud Computing Security Requirements Guide to ensure your hybrid architecture can meet the appropriate Impact Level.
Consult your 3PAO or Independent Assessor before migrating critical systems. They'll help determine whether your hybrid architecture actually closes compliance gaps or creates new ones.



