Cost-Optimized Database Security Architectures for Multi-Cloud Environments: A Unified Pattern and Decision Model for Regulated Workloads
Abstract
Aim: This study aims to develop a provider-neutral security architecture and a quantitative decision model for evaluating alternative approaches to securing regulated database workloads across multiple public clouds. Methods: The study employs a model-driven comparative evaluation rather than an empirical research design. Three PCI DSS v4.0- and HIPAA-regulated workload profiles are evaluated across centralized, fragmented, and hybrid multi-cloud security architectures. The analysis integrates published cloud-service pricing, task-level estimates of operational effort, a five-theme compliance-coverage rubric, and sensitivity analysis covering variations in cost, labor rates, tooling requirements, log volumes, and data-residency assumptions. All inputs used in the worked example are reproduced in the study to facilitate transparency and replication. Results: The modeled results indicate that the centralized UMDSP architecture costs 20.7%–25.2% less annually than the fragmented architecture, with a 22.1% cost reduction in the worked example, while maintaining comparable overall compliance-control coverage. However, the centralized approach provides greater audit-evidence coverage, reaching 94% compared with 83% for the fragmented architecture. The cost advantage remains relatively stable under variations in log volume and labor rates but declines to approximately 12% - 18% under conservative assumptions concerning operational effort and tooling. The advantage also decreases when data-residency requirements necessitate duplicated regional analytics. The findings are based entirely on modeled scenarios and have not yet been validated through production deployments. Conclusion: The modeled cost advantage appears to arise primarily from reducing duplicated and inconsistent governance processes rather than from eliminating security controls. Recommendations: Organizations operating regulated database workloads across two or more public clouds should prioritize federated identity management, policy-as-code security baselines, centralized telemetry, and automated audit-evidence generation before expanding provider-specific security tooling.