Resources 8 min read

Data Center Hosting and Colocation for Public Agencies

Every workload sits on-premise, in a rack you rent, on a leased server or in public cloud. How a public agency decides which, and what the decision should leave behind.

IT professionals collaborate at a workstation reviewing 3D data center and network analytics dashboards on dual monitors.

Every workload an agency runs sits in one of four places. It is on a machine in a building you control, in a rack you rent, on a server somebody else owns and leases to you, or in public cloud. Most agencies are in three of the four simultaneously and did not plan it that way.

This is a guide to making that placement deliberate, because the cost of getting it wrong is rarely a bill. It is a system that cannot be recovered, an audit finding, or a five year commitment to the wrong shape.

The four places, and what each is really for

On-premise means a room you control in a building you occupy. Its real advantage is proximity: a system that has to keep working when the connection to the outside world does not, or hardware that something physical depends on, belongs near the thing it serves. Its real cost is that you are operating a small facility, and facilities are unforgiving. Power, cooling, physical access and somebody to respond at night are not optional just because the room is small.

Colocation moves the room and keeps the machines. You still own, patch and replace the equipment; somebody else guarantees the conditions it runs in. It suits equipment with life left in it and workloads that must stay on hardware you govern. Colocation, and what it does not include, is worth reading before you specify one.

Dedicated hosting moves the machine as well. The provider owns the server and rents it monthly, so hardware failure, warranty and replacement stop being yours. It converts a capital purchase into an operating line and removes an asset from the register, which is sometimes the entire reason to do it.

Public cloud is a different proposition again, and the one most often chosen for the wrong reason. It is genuinely superior where demand varies, where an application was designed to scale horizontally, or where a managed service replaces work your team is doing by hand. It is frequently worse where demand is flat and predictable, because you are paying for elasticity you never use.

Why the placement decision is worth running properly

The common failure is not choosing badly. It is never choosing at all: systems accumulate wherever they were first installed, and a decade later the estate reflects a series of individual decisions nobody would defend as a whole.

Three things follow from that, and each of them costs real money. Duplication, where the same capability runs twice because two teams solved the same problem in different places. Hidden concentration, where a continuity plan names two sites and both depend on one room. And drift out of compliance, where a system that once held nothing sensitive now holds a great deal and nobody revisited where it lives.

There is a specific trap for federally funded equipment. Property standards at 2 CFR 200.313 require a non-Federal entity to maintain property records, take a physical inventory at least once every two years, reconcile it, and keep a control system that guards against loss, damage and theft. Those duties follow the equipment. Housing a federally funded server in somebody else's building does not transfer any of them, and a facility that cannot tell you where a specific asset is, by tag, is a facility that has made your inventory harder rather than easier.

How the assessment actually works

An honest placement review takes a fortnight of somebody's attention and answers four questions per system rather than one about the estate.

What does it need to be near? Very few things genuinely need to be near anything. The ones that do, usually a control system, a building system or an instrument, are the ones that stay on-premise, and identifying them early stops the rest of the conversation being hypothetical.

What does its demand curve look like? Flat and predictable points toward owned or leased hardware. Spiky, seasonal or growing fast points toward cloud. Most public sector workloads are flatter than people expect, which is why colocation and dedicated hosting remain reasonable answers long after they stopped being fashionable.

What is the recovery requirement? Not the aspiration, the requirement: how long the organization can be without it, and how much data it can afford to lose. That answer determines whether a second site is needed at all, and if it is, how far away and how warm.

What conditions attach to it? Funding source, data classification, licensing terms and any residency condition. These are the ones that override every other answer, and they are the ones most often discovered late.

Run those four questions across the estate and the placement usually settles itself. What you end up with is rarely all of one thing. A common result for a mid-sized agency is a small on-premise footprint for what must be local, a rack for the systems with hardware life left in them and a recovery copy in it, and public cloud for anything genuinely elastic or already delivered as a service.

What a mixed estate looks like in practice

It is easier to see the decision working through a concrete shape than through principles, so here is a common one for a mid-sized agency with a few hundred staff and a converted server room.

The student or case management system is the reason the room exists. It is licensed per server, the vendor supports only on-premise or hosted deployment, and demand is flat during the working day. It moves to a rack, unchanged, because nothing about it wants to be elastic and its licence would punish the attempt.

The public website and any forms go to public cloud or a managed platform, because demand genuinely spikes, because a content platform is delivered as a service by everybody now, and because the security burden of running one yourself is disproportionate.

The building systems, access control, cameras and anything on a controller, stay on-premise. They have to work when the connection does not, and moving them buys nothing.

The recovery copy goes somewhere that is not the main site, which the rack now provides for free, since the equipment is already in a different city from the offices.

What makes that estate defensible is not that it uses four models. It is that somebody can say, per system, why it is where it is. An estate that grew rather than being placed looks superficially similar and cannot answer the question.

Two cautions about that shape. It is more suppliers, not fewer, and somebody has to hold the relationships and the renewal dates. And the boundaries between the four are where failures hide, because each supplier can reasonably say the problem is on the other side of a boundary they do not control. Agencies that run mixed estates well write down, per system, who is accountable when it is broken, before anything breaks. It takes an afternoon and it settles an argument that otherwise happens during an incident.

What good looks like afterwards

A placement decision that has been made properly leaves three artifacts, and if they do not exist the decision has not really been made.

A written inventory of systems with their placement and the reason for it, which is the document that stops the same argument recurring annually. A recovery statement naming, per system, where the copy is and how long restoration takes. And a review date, because the answers change when hardware ages out or a funding source changes.

None of that requires a consultant, though an outside reading is useful precisely because it has no history with the estate. What it does require is that somebody is accountable for the whole picture rather than for individual systems.

Buying it once the decision is made

Space, leased servers and the professional work to move equipment are all available to public agencies through an awarded cooperative contract, which means the placement decision does not have to wait on a solicitation. How to purchase IT services through a TIPS contract sets out the sequence, and how to specify a hosting or colocation requirement covers what to put in the order itself.

LABUSA operates a carrier-neutral Houston facility with continuous monitoring and SSAE 18 SOC 1 and SOC 2 reporting, and supports public, on-premise and hybrid environments rather than pushing every workload toward one of them. The published scope, ceilings and ordering steps are on the awarded vehicle for hosting and colocation, and the contract itself is listed with TIPS.

If you want a second opinion on where a particular system should live, tell us what it is and what it depends on.

About LABUSA

LAB Information Technology Incorporated (LABUSA) is a trusted provider of managed IT solutions, empowering organizations with secure, efficient, and scalable technologies. With expertise spanning cybersecurity, cloud services, enterprise software, and data management, LABUSA helps clients modernize operations, strengthen compliance, and optimize performance. Our customer-focused approach ensures tailored solutions that align with organizational goals while maintaining the highest standards of reliability and security. Headquartered in Houston, Texas, LABUSA serves government agencies, corporations, and nonprofits across the United States and internationally.