Who cloud migration is for
Cloud migration services for SMEs are for businesses still relying on a server in the office, or on hosting nobody is really looking after. The warning signs are familiar:
- the office server is old, out of warranty or running an operating system that no longer receives security updates;
- staff can reach files or the main business application only from the office, or through a remote connection that keeps dropping;
- backups go to a drive beside the server, and no one has tried restoring from it;
- a website or application sits on a cheap shared host with no monitoring, and you hear about outages from customers;
- an insurer, auditor or large customer has started asking where your data is stored and who can access it.
We plan the move, carry it out with as little disruption as the work allows, and can run the hosting afterwards. For the wider question of which systems to keep, replace or retire, see IT consulting.
Problems a cloud migration solves
A well-planned move deals with risks that build up quietly around an office server:
- One ageing machine whose failure would stop the whole office
- Work that halts when the office loses power or its internet connection
- A fire, flood or theft that would take the server and its backup drive together
- Shared logins, and former staff who can still sign in
- Security updates skipped because nobody is responsible for them
- Hosting accounts and bills held in a former supplier's name
What is included
Audit and migration plan
An inventory of servers, applications, data and who uses them, with the order of the move and a way back if a step fails.
Platform set-up
Accounts created in your business name on Google Cloud, AWS or Azure, with networks, permissions and a chosen data region. Billing goes to you directly, so no supplier holds the environment.
Moving applications and data
Files, databases, websites and business applications transferred, tested and switched over at a time that suits your staff. Email and shared files can move to Microsoft 365 or Google Workspace under the same plan.
Access and security
Multi-factor authentication, single sign-on where it fits, permissions limited to what each role needs, and encryption in transit and at rest.
Backups and recovery
Automatic backups kept apart from the live system, with restore tests and a written recovery procedure.
Monitoring and cost control
Alerts for outages, failed backups and unusual activity, plus budgets and reports so the cloud bill holds no surprises.
What you hold at the end
- Cloud accounts in your business name, with you as the owner
- An architecture diagram and a plain-English description of what runs where
- Set-up files and scripts for the environment, in a repository you control
- An access register: who can sign in to what, and at which level
- A backup schedule and the results of a restore test
- A recovery runbook: the steps to bring systems back after a failure
- Monitoring dashboards and alert contacts
- A cost report showing what each system costs to run, with budget alerts set
- A record of how the old server and its drives were wiped or retired
- A handover session for your staff or your IT provider
Technologies we use and why
Where we can, we recommend one platform per business: one bill and one set of permissions to manage.
Google Cloud
Google's cloud platform. A good fit for web applications, databases and reporting, with regions in Sydney and Melbourne. Its managed services leave no operating system for you to patch.
AWS
Amazon Web Services offers a very wide range of hosting services, with regions in Sydney and Melbourne.
Microsoft Azure
Microsoft's cloud. Often the natural choice for businesses moving Windows servers and Microsoft-based applications, because staff keep signing in with the Microsoft accounts they already use.
Docker
Packages an application with everything it needs, so it runs the same way on any of the three platforms and you are not locked to one.
Terraform
Describes the hosting set-up in code, so it is documented, repeatable and can be rebuilt after a failure.
MFA, SSO and encryption
Multi-factor authentication adds a second proof at sign-in, single sign-on gives staff one managed login, and encryption keeps data unreadable without the key.
How we deliver a migration
| Stage | What happens |
|---|---|
| 1. Discovery call | A free conversation about what you run today, where it lives and what worries you about it. Nothing is changed at this point. |
| 2. Plan and quote | We audit the current set-up and give you a written migration plan, a recommended platform and a fixed or staged quote. |
| 3. Build and test | The new environment is built alongside the old one. We migrate in stages, starting with the lowest-risk system, and demonstrate each one working before moving on. |
| 4. Launch and train | Cut-over happens at an agreed quiet time, with the old system kept until you are satisfied. Staff are shown how to sign in and where things now live. |
| 5. Ongoing support | On a monthly plan we monitor the environment, apply updates, check backups by restoring them and review costs and access. |
Engagement options
| Option | Suits | How it works |
|---|---|---|
| Fixed quote | A defined move, such as one office server or one application | After the audit we agree a written price for the migration, including testing and cut-over. |
| Staged pricing | Several systems, or a move spread across sites | Each system or site is its own stage with its own quote, so you can pause between stages. |
| Monthly plan | Hosting we look after for you | Monitoring, updates, backup checks, cost reviews and support for the hosted environment. |
Usage charges from the cloud provider are separate from our fees and depend on what you run.
Security and data handling
- Least privilege. Each person and each application receives only the permissions it needs. Administrator accounts are few, named and separate from everyday accounts.
- Sign-in. Multi-factor authentication on every account that can reach the cloud console, with no shared logins.
- Patching. Operating systems and applications are kept current, and we prefer managed services that the provider patches.
- Encryption and logging. Data is encrypted in transit and at rest, and activity logs record sign-ins and changes for later review.
- During the move. Data travels over encrypted connections, temporary copies are deleted afterwards, and old drives are wiped before disposal.
These controls line up with the Australian Signals Directorate's Essential Eight, which includes patching operating systems, multi-factor authentication, restricting administrative privileges and regular backups. Its maturity model asks organisations to plan for a target maturity level suitable for their environment. We can help you work towards a target; a formal assessment is a separate exercise.
On privacy, the OAIC's guidelines on Australian Privacy Principle 11 list third party providers, including cloud computing, among the areas where reasonable security steps are expected. Its guidelines on Principle 8 explain how the cross-border rules can apply when personal information is held by an overseas cloud provider. We record the region and the provider terms so your adviser has the facts.
Support after launch
Hosting needs a named person watching it. On a monthly plan we respond to monitoring alerts, apply updates, restore a backup as a test, review who has access when staff join or leave, and report on what the environment costs. If something fails we follow the recovery runbook and tell you in plain words what happened and what was done.
Contact us by email at hello@comingwave.com.au, by phone or through the enquiry form. We reply within one business day. If you would sooner run the environment yourselves, the handover documents are written for that.
Industries this suits
Professional services
Client files and practice software moved off the office server, so staff can work securely from home or a client's premises.
Retail and e-commerce
Hosting for online stores and stock systems that copes with sale periods without a permanently larger server.
Logistics and transport
One hosted system that depots, dispatchers and drivers all reach, in place of a server at head office.
Import and export
Shared documents and order systems available to staff and agents working in different countries and time zones.
Australian context: shared responsibility, data regions and backups
Shared responsibility. Moving to the cloud does not hand all security to the provider. AWS says it is responsible for protecting the infrastructure that runs its services, while the customer's responsibility depends on the services chosen. Microsoft says that for all cloud deployment types, you own your data and identities. Google Cloud says customers always remain responsible for their access policies and data. Your side of that line (accounts, permissions, configuration and backups) is the part we set up and can manage.
Australian data regions. All three providers publish regions in Australia. AWS lists Asia Pacific (Sydney) and Asia Pacific (Melbourne). Google Cloud lists Sydney and Melbourne. Azure lists Australia East in New South Wales, Australia Southeast in Victoria and Australia Central in Canberra. We choose a region with you and record it. The OAIC's guidance says a privacy policy should cover whether a business is likely to disclose personal information to overseas recipients, so knowing where your data sits helps you answer accurately.
Backups. The Small business cyber security handbook on cyber.gov.au lists this among its key actions: back up important business and customer information regularly, and test that you can restore it if needed. That is why a restore test is part of every migration we hand over.
Cloud migration and hosting questions
Will our business be offline during the migration?
We plan for the shortest interruption the work allows. The new environment is built and tested beside the old one, and the switch is made at a quiet time you agree to, with the old system kept ready in case we need to go back. You are told beforehand what will be unavailable and when.
Which is right for us: Google Cloud, AWS or Azure?
All three are sound. The choice usually follows what you already run: Microsoft-based servers often move most easily to Azure, while web applications and databases sit comfortably on Google Cloud or AWS. We recommend one in the written plan and explain why.
Will our data stay in Australia?
It can. Each provider has Australian regions, and we set your storage, databases and backups to the region you choose. Some provider services run globally, so the plan lists any that do.
Is the cloud cheaper than running our own server?
Not always. You stop buying and replacing hardware and pay for usage instead, which can creep up if nobody watches it. We set budgets and alerts so spending stays visible.
Who is responsible for backups once we are in the cloud?
You are, unless you arrange otherwise. Providers secure their infrastructure, but your data and its backups sit on your side of the shared responsibility model. On a monthly plan we run, check and test the backups for you, alongside the wider controls on our cyber security page.
Can you host and look after a website or application someone else built?
Yes. We review the code and current hosting, move it to an account in your name and take on monitoring, updates and backups. For day-to-day help with staff devices and accounts, see managed IT support.
What happens to the old server after the move?
It stays in place, switched off or read-only, until you are satisfied that everything has arrived. After that its drives are securely wiped and the hardware is recycled or reused, as agreed in the plan, and we record what was done.


