IMHO if you're doing anything financial and don't own the bare metal hardware that the hypervisor runs on and 100% control physical access to it, and run your own network gear (right up to your border with transit providers), you're doing something fundamentally wrong.