The most secure cloud is the one the internet can't see.

Every breach post-mortem starts the same way: something was reachable that shouldn't have been. Here's what changes when your cloud comes from your network provider — and why your next firewall shouldn't be a box at all.

private by wire — encrypted in, invisible outside, no appliance to babysit

The problem isn't your firewall. It's your address.

Put a server on a public IP and the clock starts. Automated scanners sweep the entire IPv4 space continuously; anything you expose is catalogued within minutes and probed forever after. Most organisations respond by stacking defences in front of public addresses — appliances, rules, patches, renewals — and hoping the configuration never slips. That's not a security posture. That's a countdown.

The stronger move is simpler: don't be reachable at all.

What a network provider's private cloud makes possible

When your cloud provider is also your network provider, your infrastructure can live its entire life on private addressing. On ScaleSpace, your VMs, databases, and Kubernetes clusters run inside your VPC with no public IPs at all — unless you deliberately choose to publish something. There is nothing for a scanner to find, because from the internet's point of view, your estate does not exist.

How you reach it instead:

Security stops being a perimeter you defend and becomes a property of the network itself. Your infrastructure is completely private, all traffic is fully encrypted, and the attack surface the internet sees rounds to zero.

Coming soon: ScaleSpace Cloud Firewall

There's one piece of the old model left to retire: the proprietary hardware firewall — the FortiGate-class appliance in your rack, with its refresh cycles, per-box licences, and the quiet dread of a missed firmware advisory.

We're launching a fully managed cloud firewall that moves that entire function into the network layer, where it belongs:

For your team, infrastructure management gets radically simpler: one provider runs the line, the cloud, and the firewall on it — and you stop paying an appliance vendor for the privilege of doing their patching.

The takeaway

Choose infrastructure the internet can't see. Reach it over encrypted tunnels or your own private line. Let the firewall be a managed service in the network instead of a box in your rack. That's what a private cloud from a network provider means — and it's a level of quiet the public-cloud model can't offer.