HYBRID CLOUD ARCHITECTURE FOR SECURE DATA STORAGE AND HIGH-AVAILABILITY ACCESS IN SAUDI ENTERPRISES
DOI:
https://doi.org/10.18623/rvd.v23.7024Keywords:
Hybrid Cloud, Secure Storage, High Availability, Saudi Enterprises, Data Sovereignty, Zero Trust, Distributed StorageAbstract
Saudi enterprises are modernizing critical information systems while facing strict expectations for data protection, continuous availability and accountable cloud governance. Hybrid cloud architecture has become a pragmatic design pattern because it allows sensitive databases, regulated records and latency-sensitive services to remain under direct enterprise control while elastic public-cloud services support analytics, disaster recovery, software delivery and burst capacity. This review paper synthesises recent work from 2020 to 2025 on hybrid cloud security, private cloud platforms, high-availability storage, cloud threat management and Saudi regulatory alignment. The paper develops an integrated review framework and proposes a reference architecture that combines data classification, encrypted storage, zero-trust access, distributed storage, active-active service routing, immutable backup and continuous observability. The findings indicate that Saudi enterprises should treat hybrid cloud as a governed operating model rather than a simple mixture of local and public infrastructure. Secure storage depends on policy-driven data placement, key sovereignty, identity federation, segmentation and auditable transfer controls. High availability depends on removing single points of failure across proxy, control, data, compute, network and storage layers, with routine failover testing and business-aligned recovery objectives. The review contributes a structured control matrix and implementation roadmap for Saudi enterprises that need scalable digital platforms without weakening confidentiality, integrity or service continuity.
References
[1] Zhao, L., Hu, G., & Xu, Y. (2024). Educational resource private cloud platform based on OpenStack. Computers, 13, 241. https://doi.org/10.3390/computers13090241
[2] Dawood, M., Tu, S., Xiao, C., Alasmary, H., Waqas, M., & Rehman, S. U. (2023). Cyberattacks and security of cloud computing: A complete guideline. Symmetry, 15, 1981. https://doi.org/10.3390/sym15111981
[3] Alwakeel, A. M. (2025). Adaptive edge-fog healthcare networks: A novel framework for emergency response management. Journal of Cloud Computing, 14, 48. https://doi.org/10.1186/s13677-025-00784-3
[4] Yigit, Y., Ferrag, M. A., Ghanem, M. C., Sarker, I. H., Maglaras, L. A., et al. (2025). Generative AI and LLMs for critical infrastructure protection: Evaluation benchmarks, agentic AI, challenges, and opportunities. Sensors, 25, 1666. https://doi.org/10.3390/s25061666
[5] Abdulsalam, Y. S., & Hedabou, M. (2022). Security and privacy in cloud computing: Technical review. Future Internet, 14, 11. https://doi.org/10.3390/fi14010011
[6] Alharbe, N., Aljohani, A., Rakrouki, M. A., & Khayyat, M. (2023). An access control model based on system security risk for dynamic sensitive data storage in the cloud. Applied Sciences, 13, 3187. https://doi.org/10.3390/app13053187
[7] Razaque, A., Frej, M. B. H., Alotaibi, B., & Alotaibi, M. (2021). Privacy preservation models for third-party auditor over cloud computing: A survey. Electronics, 10, 2721. https://doi.org/10.3390/electronics10212721
[8] Soveizi, N., Turkmen, F., & Karastoyanova, D. (2023). Security and privacy concerns in cloud-based scientific and business workflows: A review. ACM Computing Surveys, 55, 1–38.
[9] Babaei, A., Kebria, P. M., Dalvand, M. M., & Nahavandi, S. (2023). A review of machine learning-based security in cloud computing. IEEE Access, 11, 105043–105078.
[10] National Cybersecurity Authority. (2024). Cloud cybersecurity controls (CCC-2:2024). NCA.
[11] Saudi Data and AI Authority. (2024). Guide to the Saudi Personal Data Protection Law for controllers and processors. SDAIA.
[12] Communications, Space and Technology Commission. (2024). Cloud computing services regulatory framework. CST.
[13] National Institute of Standards and Technology. (2024). The NIST cybersecurity framework 2.0. NIST.
[14] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). NIST.
[15] Joint Task Force. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53 Rev. 5). NIST.
[16] International Organization for Standardization. (2022). ISO/IEC 27001:2022 information security, cybersecurity and privacy protection — Information security management systems. ISO.
[17] International Organization for Standardization. (2022). ISO/IEC 27002:2022 information security, cybersecurity and privacy protection — Information security controls. ISO.
[18] Cloud Security Alliance. (2021). Cloud controls matrix version 4.0. CSA.
[19] Cloud Security Alliance. (2024). Security guidance for critical areas of focus in cloud computing, version 5. CSA.
[20] Amazon Web Services. (2024). AWS well-architected framework: Reliability pillar. AWS.
[21] Microsoft. (2024). Azure well-architected framework: Reliability. Microsoft.
[22] Google Cloud. (2024). Architecture framework: Reliability. Google.
[23] European Union Agency for Cybersecurity. (2024). ENISA threat landscape 2024. ENISA.
[24] IBM Security. (2024). Cost of a data breach report 2024. IBM.
[25] Verizon. (2024). 2024 data breach investigations report. Verizon Business.
[26] Depoutovitch, A., Chen, C., Chen, J., Larson, P., Lin, S., et al. (2024). Taurus database: How to be fast, available, and frugal in the cloud. Proceedings of the VLDB Endowment, 17, 4701–4714.
[27] Hewage, T. B., Ilager, S., Rodriguez, M. A., & Buyya, R. (2025). Carbon-aware real-time workload management in clouds using renewables-driven cores. Future Generation Computer Systems, 162, 107452.
[28] Zhang, J., Chen, A., & Zhang, P. (2023). Provably secure data access control protocol for cloud computing. Symmetry, 15, 2111. https://doi.org/10.3390/sym15122111
[29] Yan, L., Ge, L., Wang, Z., Zhang, G., Xu, J., & Hu, Z. (2023). Access control scheme based on blockchain and attribute-based searchable encryption in cloud environment. Journal of Cloud Computing, 12, 61. https://doi.org/10.1186/s13677-023-00444-4
[30] Gupta, R., Saxena, D., & Singh, A. K. (2021). Data security and privacy in cloud computing: Concepts and emerging trends. IEEE Access, 9, 165273–165295.
Downloads
Published
How to Cite
Issue
Section
License
I (we) submit this article which is original and unpublished, of my (our) own authorship, to the evaluation of the Veredas do Direito Journal, and agree that the related copyrights will become exclusive property of the Journal, being prohibited any partial or total copy in any other part or other printed or online communication vehicle dissociated from the Veredas do Direito Journal, without the necessary and prior authorization that should be requested in writing to Editor in Chief. I (we) also declare that there is no conflict of interest between the articles theme, the author (s) and enterprises, institutions or individuals.
I (we) recognize that the Veredas do Direito Journal is licensed under a CREATIVE COMMONS LICENSE.
Licença Creative Commons Attribution 3.0

