Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Protecting Remote Laptops: Cloud-Managed Antivirus vs On-Prem Consoles

12 min read Updated October 4, 2026 Antivirus Comparisons

Fix it now

If your laptops rarely touch the office network, a cloud-managed console is the answer: the agent makes an outbound connection from wherever it is, and you publish nothing inbound. On-premises still wins for isolated networks and for custody requirements written into a contract. Check whether your product supports both before you decide.

  1. Choose cloud if staff work away from the office most of the week. Nothing of yours is exposed inbound and policy reaches a machine on hotel Wi-Fi as easily as one at a desk.
  2. Choose cloud if IT is one person. The console server is the machine that will not get patched, and you are the person who will not patch it.
  3. Choose on-premises if the network is deliberately isolated, or if a contract puts custody of security telemetry inside a boundary you control rather than a region you pick from a list.
  4. Choose a product that offers both if you are not sure. ESET states that its endpoints can be managed from a cloud-based or on-premises ESET PROTECT console; Bitdefender ships GravityZone on-premises as a self-configuring hardened Ubuntu virtual appliance.
  5. Skip Sophos if the answer has to be on-premises. Sophos describes Sophos Central as a single cloud-based console and publishes no on-premises alternative.
  6. Do not solve a remote-agent problem by publishing an on-premises console to the internet. That turns a management inconvenience into an attack surface you now have to defend.

Changing console model later is not free. Bitdefender supplies its on-premises to cloud migration patch only for environments with more than 20 managed endpoints; below that its documented answer is to reinstall and reconfigure every agent by hand.

If your estate is mostly remote, that is the decision made and you can stop here. Below is what each model actually costs to run, and the questions to get answered in writing before you sign.

Why it happens

An on-premises console expects either to reach its agents or to be reachable by them across a network you control. A laptop that lives on home broadband and hotel Wi-Fi breaks that assumption quietly rather than loudly. Policy changes queue. Detections arrive when the machine next comes home. The device list fills with entries last seen weeks ago, and nothing in the console tells you whether that means the laptop is switched off, the agent is broken, or the machine has been stolen.

Vendors do have answers, and they are real answers. On-premises deployments support relay, proxy or gateway components so agents can report without a full VPN, and split-tunnel VPN configurations can be shaped to let the agent through. Both work. Both are extra infrastructure that you now own, harden, patch and monitor, and each is a component that can stop working while everything around it still looks healthy.

A cloud console removes the problem instead of routing around it. The agent makes an outbound connection to the vendor’s service, which is permitted on essentially every network including the ones you do not control, and policy lands wherever the machine is. That single property is why most businesses with hybrid staff end up here, and it is a stronger argument than any feature comparison.

Your machines are mostly out of the building

You have this one if The console’s device list has entries that have not checked in for weeks, and you cannot tell which of them are a problem.

  1. Move to the cloud console for the product you already own if it has one. ESET publishes both models for ESET PROTECT; Bitdefender publishes both for GravityZone.
  2. Plan the move as a project, not an afternoon. Bitdefender’s documented migration path is a patch deployed to agents by GPO or another mass-deployment tool, and it is supplied only for environments with more than 20 managed endpoints.
  3. Below that threshold, Bitdefender’s own instruction is to reinstall and reconfigure the agents manually, so budget the hours before you commit to a date.

Whichever way you go, run a pilot group first and keep every machine protected by exactly one real-time product throughout.

A contract dictates where the data lives

You have this one if Somebody has written a clause about custody of security telemetry, and regional hosting is not what they meant.

  1. Read the clause before shortlisting anything. A requirement about geography is usually satisfiable by a cloud region; a requirement about custody usually is not.
  2. If it is custody, an on-premises console is the honest answer. Bitdefender delivers GravityZone on-premises as a Linux Ubuntu self-configuring hardened virtual appliance in OVA, XVA, VHD, OVF and RAW formats, with Control Center as the web console and an optional Security Server.
  3. Get the answer to where your tenancy is hosted, and for how long events are retained, in writing on the quote. Neither is published per tier in a form you can rely on.

Nobody is going to run the console server

You have this one if One person does IT alongside another job, and the last console upgrade was done by whoever left in 2023.

  1. Go cloud. The vendor patches the platform and carries its availability; you are left with policy work rather than plumbing.
  2. Accept the trade honestly: you give up control of the upgrade schedule, direct database access for custom reporting, and retention beyond what your tier allows.
  3. In a small estate the on-premises console is frequently the least well patched machine in the building, which makes the security comparison less flattering to it than it first sounds.

The weakness of the cloud model is not security, it is dependency and opacity. Their outage is your outage. Their upgrade schedule is your upgrade schedule. Retention is bounded by what you bought rather than by the disk you allocated, and custom reporting is limited to what the console and its API expose. None of that is fatal for most businesses, but all of it should be on the page before you sign, not discovered at the first incident.

Full reference

The two models on the dimensions that actually decide it

Dimension Cloud-managed console On-premises console
How remote agents report Outbound connection to the vendor’s service, from any network VPN, or a relay component you publish and maintain
What you expose inbound Nothing Either nothing plus a VPN dependency, or a published service to defend
Who patches the management platform The vendor, on their schedule You, on yours
Availability The vendor’s responsibility; their outage is your outage Yours, including the database backup nobody has tested
Where event data sits The vendor’s region, chosen from their list Your storage, entirely under your control
Event retention Bounded by the tier you bought Bounded by the disk you allocate
Custom reporting Whatever the console and its API expose Direct database access if you want it
Upgrade timing The vendor decides when features change You decide, and you carry the risk of deferring
Isolated or offline sites Not workable The only option that works
Ongoing effort Policy work A recurring share of an administrator’s time

Which products give you the choice

This matters more than it looks, because it decides whether a change of mind later is a setting or a migration. ESET states that all its endpoints, including mobiles, can be managed from its cloud-based or on-premises unified management console, ESET PROTECT – one licence, two console models. Bitdefender publishes both for GravityZone, with the on-premises option delivered as a hardened Ubuntu virtual appliance you host. Sophos describes Sophos Central as a single cloud-based console, and publishes no on-premises equivalent, so a Sophos decision is a cloud decision.

Do not assume every vendor still offers both. Console models get consolidated, and the safest check is the vendor’s current product page rather than a comparison table or a quote from two years ago.

What moving between models actually costs

Bitdefender is unusually specific here and it is worth reading before you assume a migration is a repoint. Its documented route from an on-premises console to the cloud console uses a patch that runs silently and can be deployed by Group Policy or any other tool for mass deployment of executable files – but Bitdefender supplies that patch only for network environments with more than 20 managed endpoints. In all other cases, its instruction is to manually reinstall and reconfigure the security agents. A twelve-machine business therefore has twelve manual reinstalls in front of it, not a checkbox.

Treat that as the shape of the problem generally rather than a Bitdefender quirk. The safe assumption for any vendor is that a console change touches every endpoint, and the safe question to ask before you buy is: what exactly happens to an existing agent when we move, and is there a supported path for an estate of our size?

The questions to get answered in writing

  • Which region will our tenancy be hosted in, and can that be stated on the contract rather than in an email?
  • How long is detection history retained at the tier we are buying, and what does it cost to retain it longer?
  • What is the supported migration path from the console model we are choosing to the other one, for an estate of our size?
  • If the management plane is unavailable, what continues to work on the endpoint and what stops?
  • What can we export, in what format, and how long do we keep access to it after the subscription ends?

Which model, by situation

  • Staff working from home most of the week, or no office network worth the name: cloud, without hesitation.
  • A single site of desktops on your own LAN, with an administrator who already runs servers: on-premises remains reasonable, and cloud would still be less work.
  • A written requirement about custody of security data: on-premises, or a cloud arrangement that satisfies the requirement in the contract rather than in conversation.
  • An isolated production or industrial network: on-premises is the only workable answer.
  • A one-person IT function of any kind: cloud, because the console server is the thing that will not get patched.
  • An estate you expect to restructure within the year: pick a product that publishes both models, so the decision stays reversible.

What the comparison is not about

Two things get argued about here that should not decide it. The first is detection: the agent is the same agent in both models, and no vendor publishes a claim that one console detects more than the other. The second is the licence line on the quote. The real cost difference between the models is the server, its storage, its backup and the hours somebody spends on it, and none of those appear on a licence quote at all. Work out the second number before comparing the first.

When a licence is the actual fix

ESET PROTECT Entry is a sensible place to land while this decision is still open, because the licence does not force it: ESET publishes the same estate as manageable from a cloud-based or on-premises ESET PROTECT console, so choosing one now does not lock you out of the other. Arco supplies the licences and sizes them per device. Tell us how many of your machines are actually in the building on a normal Tuesday and we will tell you which console model fits, rather than defaulting to whichever is easier to invoice. If your machines are mostly remote, expect us to point at the cloud console and say why.

Questions people ask about this

Is cloud management less secure than keeping the console in-house?

It changes the risk rather than adding to it. You depend on the vendor for the availability and integrity of the management plane; in exchange you expose nothing inbound and stop maintaining a server whose patch level is your problem. In small estates the on-premises console is often the least well patched machine in the building, which makes the comparison less flattering to it than it sounds.

Where does our endpoint data physically sit in a cloud console?

In the region the vendor hosts your tenancy in. The major vendors offer a choice, but the specific region and the retention period are commercial facts about your tenancy rather than published product facts, so get both in writing on the quote if they matter to your contracts. Do not accept a verbal assurance and do not rely on an article for it.

Does the cloud console cost more?

That is the wrong comparison. Whatever the licence lines say, the on-premises model also costs you a server, its storage, its backup, and the hours somebody spends keeping it available – none of which appear on a licence quote. Add those to the on-premises side before you compare, and price the two totals rather than the two per-device lines.

Can we move from on-premises to cloud without redeploying every agent?

Not reliably, and Bitdefender is the vendor that publishes the detail. Its migration patch is supplied only for environments with more than 20 managed endpoints and is deployed to the agents by GPO or a similar tool; below that size its documented instruction is to reinstall and reconfigure each agent manually. Confirm the path for your specific product, version and estate size before you commit to a date.

Which vendors let us change our minds later?

ESET and Bitdefender both publish cloud and on-premises console models for their business products, so the choice stays open in principle even though the move itself is work. Sophos Central is published as a cloud-based console with no on-premises equivalent, so a Sophos deployment is a cloud deployment. Check the current product page rather than a quote, because console models get consolidated.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Renew or Switch Antivirus? How to Judge Your Vendor at Renewal Time Review Free vs Paid Antivirus: What the Free Tier Quietly Leaves Out Review Best Antivirus for a Family of Five Devices: Cover Without Overbuying Review Ransomware Protection Compared: Which Antivirus Can Actually Roll Back?
โ† Back to Knowledge Base