

I ended up going with Crowdsec.
The setup was a bit of a challenge as I like to do it the RTFM way abd that there is a bunch of concepts to grasp before you really understand what you are doing, but since then it’s been working pretty great ! And it’s free (as in you are providing them with data on the occurence of threats etc, so you don’t pay)

In SOME cases, it is cheaper than on prem. If you need a lot of compute power occasionally, it can be cheaper. If you actually scale up and down according to the load (which a lot of companies do not do), it might be cheaper. But a large amount of companies don’t fall in those cases or don’t do it efficiently. Some spend in a year the same amount they would have paid for on prem servers they would have kept 5 years or more.
Cloud providers offer other things like multi regional redundancy, which can be hard to achieve for smaller businesses.