Government cloud gives agencies agility. What's the resilience plan for everything else?

As government agencies accelerate AI initiatives on commercial cloud, Everpure's APJ CTO Matthew Oostveen shares why resilience needs to be cloud-agnostic and a clear data strategy to innovate securely.

Ahead of the Pure Accelerate event in Singapore on September 8, Everpure's CTO for APJ, Matthew Oostveen, shares more on why resilience needs to be cloud-agnostic, and why the harder work starts with who controls the data underneath it. Image: Canva

Governments around the world are quickly moving onto commercial cloud to leverage new artificial intelligence (AI) capabilities, particularly in faster deployment and access to AI services that would take a long time to build in-house.

 

Agility tends to be the headline story.

 

But according to Matthew Oostveen, Chief Technology Officer for Asia Pacific & Japan at Everpure, agility was never the hard part.

 
Matthew Oostveen is the Chief Technology Officer for Asia Pacific & Japan at Everpure. Image: Everpure

What happens when something goes wrong is.


"The biggest risk isn't the cloud itself, it's the naive assumption that every workload belongs there," he says.

 

When agencies rush toward commercial cloud for quick AI wins without a clear data strategy, he says, agility quietly becomes a substitute for control.

 

Ahead of the Pure Accelerate event in Singapore on September 8, he shares more on why resilience needs to be cloud-agnostic, and why the harder work starts with who controls the data underneath it.

Agility isn't the same as control

 

The exposure isn't always obvious at the point of adoption, Oostveen says.

 

Foreign legislations create legal friction over who ultimately controls citizen data once it sits with a foreign-owned provider.

 

Feeding sensitive public sector data into public cloud AI engines without proper guardrails adds privacy risk that's hard to quantify.

 

His answer is adopting a hybrid approach: commercial cloud for public-facing innovation, sovereign control over the workloads and data that carry the most risk.

 

When asked what resilience means in practice, Oostveen says it "isn't about having a nice architecture diagram. It's about how many minutes it takes to restore trusted data and resume operations."

 

He was sharing this in the context when a major cloud provider suffers an outage or ransomware attack strike.

 

He points to three requirements for cloud-agnostic resilience:

 
  1. Data mobility, so workloads can shift between on-prem, colocation and hyperscalers without a rebuild;
  2. Independent control planes, so security and recovery still work even if a hyperscaler's own systems go down; and
  3. Aggressive recovery targets, replacing manual disaster recovery with automated failover to immutable data copies.
 

Without those three, he argues, an outage that halts services for 48 hours because the failover plan takes a week to execute isn't resilience. "You just have vendor lock-in."

 

The starkest risk, Oostveen says, is when an agency's entire AI stack sitting inside a single cloud.

 

A provider outage, a cyber incident, or a legal dispute could turn off public services instantly.

 

To test that, this means engineering real chaos rather than paper audits, he says.

 

"You pull the plug on that primary cloud provider during an unannounced live simulation and see what actually happens.

 

"Do your public services failover to an alternate environment in real time? How fast can you recover clean data to keep models running?"

Hybrid is the destination

 

A common assumption is that hybrid cloud is a stepping stone toward eventually running everything in the public cloud, which Oostveen disagrees.

 

Different workloads solve different problems, he says.

 

For example, a public-facing app and a classified national database have different requirements around sovereignty, latency, cost and control, and forcing both into the same environment doesn't make either of them work better.

 

He points to Singapore as an example of getting this right: matching deployment models to actual operational needs, rather than treating public cloud as a default mandate.

 

So which workloads should stay on-prem? Oostveen says this is asking where data legally must live, and who holds ultimate custody.

 

In Singapore, citizen's personally identifiable information (PII) cannot leave local shores, and national security data requires absolute operational sovereignty.

 

AI doesn't change that rule, he notes, but it just splits the execution. "You can tap the commercial cloud for heavy compute power or public-facing features, but the underlying sensitive data stays locked down locally behind strict guardrails," he adds.

 

This is why Everpure has built its architecture around data primacy.

 

"To keep governance consistent across split environments, agencies must deploy an independent control plane that sits above individual clouds.

 

"Access controls, encryption keys, and audit policies attach directly to the data itself, whether it rests on a local drive or in a commercial cloud bucket," he explains.

 

Handled this way, governance follows the data rather than the infrastructure underneath it, letting agencies enforce one consistent compliance standard across on-premises systems and commercial cloud alike.

The real scaling problem

 

Looking across the region, Oostveen argues that scaling government AI has stopped being a compute problem. "It's a trust and architecture challenge," he says, which aligns to the messaging in Singapore's Smart Nation 2.0 push.

 

His advice for agencies planning that next phase is to build real-time visibility into data pipelines, so no one loses track of what's feeding a model or where it sits.

 

Additionally, respect data gravity rather than dragging datasets into every new AI platform, as well as to keep control through encryption keys and access policies.

 

By pairing commercial cloud agility with strict data primacy, agencie can innovate at full speed without sacrificing public trust or national control.


 

Everpure will be unpacking these ideas further at Pure Accelerate Singapore on September 8,2026, at ParkRoyal Collection Marina Bay. You can find out more and register here.