cloud computing, or cloud computing, is the delivery of IT resources (servers, storage, databases, networking and software) over the internet, on demand and paid for according to use. Instead of buying and maintaining equipment, the company rents capacity from a provider such as AWS, Microsoft Azure or Google Cloud, scales up or down when needed and pays only for what it consumes.
This guide explains how that works underneath, which types exist, what the LGPD requires, which disadvantages no one mentions and how to choose the provider. It was written by people who design and operate cloud environments for midsize and large companies in Brazil, with no product catalog in the middle.
Key points
- Cloud computing has five characteristics defined by NIST: on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.
- There are four deployment models (public, private, hybrid, multicloud) and four service models (IaaS, PaaS, SaaS, serverless). The difference is who manages each layer.
- AWS, Azure and Google Cloud have physical regions in São Paulo, which resolves latency and data residency for the LGPD.
- The advantages are real, but each one comes with a condition. Without the condition, the benefit does not appear.
- Gartner projects growth of 14.2% in global IT spending in 2026, driven by AI, cloud and data center.
What is cloud computing?
Cloud computing is a model for delivering computing resources over the internet, in which the provider maintains the infrastructure and the client consumes capacity on demand, billed by usage.
According to NIST, a service is only cloud computing if it has five characteristics:
- On-demand self-service. The client provisions a server, storage or database on their own, without opening a ticket.
- Broad network access. Everything is accessed through standard protocols, from any device.
- Resource pooling. The provider serves several clients with the same physical infrastructure, isolating each one logically.
- Rapid elasticity. Capacity grows and shrinks in minutes, sometimes automatically.
- Measured service. Consumption is metered and billed granularly.
What is the main characteristic of cloud computing? It is measured elasticity. You use what you need, pay for what you used and give it back when you no longer need it. An in-house data center, however modern, does not do that.
How does cloud computing work?
It works through virtualization at industrial scale. The provider builds data centers with tens of thousands of physical servers and uses virtualization software to slice each machine into virtual machines, containers or functions. When you request a server in the console, the system allocates a slice of that capacity in seconds.
Regions and availability zones. Each provider divides the world into regions, and each region has two or more independent data centers. If one goes down, the other takes over. In Brazil, AWS (sa-east-1), Azure (Brazil South) and Google Cloud (southamerica-east1) operate regions in São Paulo.
Shared responsibility. The provider is responsible for physical security, network, hardware and hypervisor. The client is responsible for identity, access, configuration, data and application. Most cloud incidents happen on the client's side, not the provider's.
Usage-based billing. Every resource has a meter. A server is billed per hour running, storage per GB per month, outbound traffic per GB transferred. The invoice is the sum of hundreds of meters, and that is why it rises without anyone noticing.
What are the types of cloud computing?
Deployment models
| Model | What is it | Suited to | Main risk |
|---|---|---|---|
| Public cloud | Provider infrastructure, shared | Most workloads: ERP, websites, data, DR | Variable cost without governance |
| Private Cloud | Dedicated infrastructure | Data under strict regulation, critical latency | High fixed cost, limited elasticity |
| Hybrid Cloud | Private and public integrated | On-premises legacy with new workloads in the cloud | Network and identity complexity |
| Multicloud | Two or more public providers | Avoiding lock-in, using the best of each | Doubling skills and tooling |
In practice, most midsize Brazilian companies operate a hybrid model even without calling it that: point of sale and the shop floor stay local; ERP, data and disaster recovery go to the public cloud.
Service models: IaaS, PaaS, SaaS and serverless
The simplest way to understand it is to ask who manages each layer.
| Layer | On-premises | IaaS | PaaS | SaaS |
|---|---|---|---|---|
| Application | You | You | You | Provider |
| Data | You | You | You | Provider |
| Runtime and middleware | You | You | Provider | Provider |
| Operating system | You | You | Provider | Provider |
| Virtualization | You | Provider | Provider | Provider |
| Servers, storage, network | You | Provider | Provider | Provider |
| Examples | In-house data center | VMs on Azure or AWS | App Service, managed database | Microsoft 365, Salesforce |
IaaS is the closest to what the infrastructure team already knows, and it is the natural path for migrating existing servers. PaaS delivers the platform ready to use: you push the code and the provider is responsible for the operating system, patching and scaling. SaaS is software by subscription. Serverless runs functions triggered by events and charges per execution, which suits integrations, not everything.
Who are the providers and which cloud is the most used?
The global market is led by AWS, Microsoft Azure and Google Cloud, in that order. Oracle and IBM follow, with strength in specific niches.
The useful question is not which is the largest, but which fits what you already have:
- Azure tends to win in companies that already use Microsoft 365 and Active Directory, because identity, licensing and support consolidate into a single contract.
- AWS usually fits better with Linux workloads, software engineering and startups, with the broadest catalog.
- Google Cloud stands out in data, analytics and machine learning.
- Oracle Cloud makes sense when the main workload is an Oracle database and the license already exists.
If your ERP and your directory are Microsoft, the decision is half made. If not, run the assessment before choosing.
What are the advantages?
Each one comes with a condition. Without it, the benefit does not appear.
- Low upfront cost. No servers are purchased. Condition: consumption governance, otherwise the monthly cost exceeds that of the hardware.
- Elasticity. Black Friday and month-end close are absorbed without buying for the worst day. Condition: the application has to know how to scale.
- Availability. Multiple zones, automatic backup and disaster recovery with a few clicks. Condition: configuring it, because nothing comes switched on by default.
- Speed. A new environment in minutes, not in weeks of procurement.
- Baseline security. Certifications and monitoring at a scale no midsize company reaches on its own. Condition: the client's side remains the client's responsibility.
What are the disadvantages and risks?
No one on the first page of Google talks about this.
- Variable cost. The invoice changes every month and, without governance, only goes up.
- Lock-in. The more managed services, the harder it is to change provider. That is not a reason not to use them; it is a reason to decide deliberately.
- Dependence on connectivity. If the link goes down, the operation stops. Redundancy stops being optional.
- Latency. An application that talks to the point of sale or to a factory machine in milliseconds may not tolerate the round trip to São Paulo.
- Compliance. Where the data sits and who accesses it becomes a contract clause, not an IT decision.
How much does cloud computing cost?
The cost has three parts: the provider's monthly consumption, the cost of migrating and the cost of operating afterward. Most estimates look only at the first and get it wrong.
Consumption is the sum of the meters: compute, storage, database, outbound traffic, licenses and backup. Three mechanisms reduce that bill consistently: reserved instances for predictable workloads, rightsizing (most migrated servers are oversized) and automatic shutdown of development environments outside business hours.
Go deeper: we break down the components of the bill and how to estimate them in Cloud migration cost, and the techniques for continuous reduction in FinOps in practice.
The cost no one mentions: taking data out of the cloud costs money; putting it in is free. An architecture with heavy exchange between cloud and on-premises discovers this on the invoice.
Is the cloud secure? The LGPD and data residency in Brazil
Yes, on the condition that the company does its part. The LGPD prohibits neither the cloud nor international transfer, but it requires a legal basis, a contract with the processor and measures proportionate to the risk.
Data residency. AWS, Azure and Google Cloud have regions in São Paulo. Keeping personal data in a Brazilian region removes the international transfer discussion and reduces latency.
Processor agreement. Under the LGPD, the provider is the processor and your company is the controller. The contract has to define what the provider does with the data, how long it keeps it and how it reports an incident.
Shared responsibility in practice. Encryption at rest and in transit, mandatory MFA, least privilege, access logging and immutable backup are client configurations. The provider offers the tool; switching it on is up to you.
How do you migrate to the cloud?
A well-executed migration has five stages: assessment (inventory, dependencies, TCO), landing zone design (network, identity, security, backup), migration waves (applications grouped by dependency), cutover with a tested rollback and stabilization with FinOps.
Skipping the first is the most expensive mistake. For a typical environment of 30 to 80 servers, the cycle takes three to six months.
Go deeper: the complete step by step, with timelines per phase and what goes into each wave, is in Cloud migration cost.
Examples by sector
Food retail. ERP, WMS and data platform in the cloud; point of sale and scales in the store. The cloud absorbs the Black Friday peak and the store keeps selling if the link goes down.
Manufacturing. MES and SCADA systems stay local because of latency; ERP, BI and disaster recovery go to the cloud. Sensors feed predictive maintenance models.
Healthcare. Medical records and imaging require data residency and an audit trail. The Brazilian region resolves the first; managed logs resolve the second.
Startups and software. They are born in the cloud, on PaaS and serverless, without ever buying a server.
Cloud computing trends in 2026
According to Gartner (July 2026), global IT spending is expected to grow 14.2% in the year, to US$ 6.37 trillion, concentrated in AI infrastructure, cloud and data center systems. Four movements explain that figure.
AI as a cloud workload. Training and running models requires GPUs at scale, and almost no one buys GPUs.
FinOps as a board-level discipline. Cloud cost has stopped being a subject for IT alone.
Sovereignty and data residency. Regulation and client pressure moving more workloads to local regions.
Edge computing. Processing data close to where it originates and sending only what is necessary to the cloud.
How to choose the right cloud computing solution
Ask five questions, in this order:
- What do we already have? Current identity, licensing and ERP weigh more than any price comparison.
- What has to stay local? Latency, regulation or specific hardware determine whether the model is hybrid.
- Who will operate it? An internal team, a partner or both. It changes total cost more than the choice of provider does.
- How will cost be controlled? Without someone accountable for FinOps, the invoice goes up.
- What is the exit plan? Knowing how to take data and applications out is the antidote to lock-in.
After that, a cloud computing assessment with numbers decides the rest.
Frequently asked questions
What is the main characteristic of cloud computing?
Measured elasticity: capacity grows and shrinks according to demand, and you pay only for what you use.
How does the cloud work in practice?
The provider maintains data centers with thousands of servers and uses virtualization to divide the capacity. You request a resource through the console or an API, it is created in seconds and billed by time or volume of use.
What are the types of cloud computing?
By deployment: public, private, hybrid and multicloud. By service: IaaS, PaaS, SaaS and serverless.
Which cloud is the most used?
AWS leads globally, followed by Microsoft Azure and Google Cloud. In Brazil, the choice is usually determined by what the company already uses.
Is cloud computing secure for personal data under the LGPD?
Yes, provided there is a processor agreement, a preference for Brazilian regions for sensitive data, and encryption, MFA and access control configured on the company's side.
Do I need to migrate everything to the cloud?
No. Most keep latency-critical systems local and migrate ERP, data, backup and disaster recovery.
Does serverless replace IaaS?
No. Serverless is ideal for integrations and event-driven processing. Traditional applications remain on IaaS or PaaS.
Conclusion
Cloud computing is the standard infrastructure model in 2026, but it is neither a binary nor an automatic decision. What separates a migration that reduces cost and risk from one that increases both is method: understanding the five attributes that define cloud, choosing based on what the company already has, treating security as shared responsibility, respecting the LGPD through residency and contract, and governing cost from the first month.
If your company is already on the cloud and the question has become how much the bill can come down, the cloud cost assessment measures six areas and estimates in money where the room is, with every percentage taken from the vendor’s official documentation.







