Saturday, 29 October 2016

Platform Schizophrenia

This year I became aware that there are two definitions to Digital Platforms. Whilst I had been meandering around in IT Space thinking that digital platform meant services like AWS and Azure, our friends in Marketing Space had decided that digital market places were Digital Platforms. So to them ComparetheMarket.com, Deliveroo.com and Uber.com are platforms. 

Anyway moving on from this diversion, it has for some time been a surprise to me that amazon has dominated IT thoughtspace and the market for PaaS based Digital Platforms, whilst belatedly Microsoft pushed into the market with Azure. 

In recent projects I have been involved with both AWS and Azure as well as all sort of fun with the OSS tools which are available on them. To traditionalists coming across the database as a service offerings available is quite amazing. I was also blown away when a Solution Architect who had no experience of Neural Networks was able within 2 weeks to knock up a fully working and trained prototype of a Machine Learning application on Azure.

So it has become increasingly interesting to see that Google, one of the most born in the cloud companies going, has recently started promoting its services. One has to ask why did they wait so long, especially as they have always made much of the fact that their products are all architected around a SOA concept and the ability to expose themselves as services, both internally and externally.

Oracle and IBM have also appeared actively in the market place this year promoting their own special blends. 

The thing about this is that they all have really good stories to tell. You will note that I am not stating any preferences, as to be honest, anything I say about them today will already be wrong tomorrow as this is an ever faster moving situation. Today's facts will be obsolete tomorrow.

So what does it all mean to the average business trying to go Digital?

Firstly, the means are there. You have to be comfortable with the fact that terms and conditions are what they are. You need to examine the pricing and understand how this would play out in some key real world applications. However there is plenty available to "Free Your business from the Tyranny of Infrastructure" and Focus on Value. If you choose reasonable sensibly, you will be able to scale costs with business activity and exploit platforms which support Agile and DevOps so you can move quickly and lightly in the pursuit of opportunities. All the major vendors are investing significantly in security and if you dig deeper, most offer localisation options if data cannot move outside certain jurisdictions. Additionally there are industry certification schemes which many providers are signed up to. So a lot of inhibitors have been addressed.

The key issue is going to be how much do you insulate yourself from the risk that you may need to change platform provider. Business Performance, Legislation, Pricing etc. will change with time. So you may need an exit plan. Therefore, some thought needs to be given to insulating yourself from future supply threats. Where your application is going in for short term gains, e.g. a new financial instrument which will only be around for a a few months or perhaps a couple of years, this is not a problem. But if you are locking yourself into a platforms specific machine learning solution for years, you may need to think how you would deal with problems if the platform vendor ceases training.

In the end, however, we have always faced these problems. Finding a totally vendor agnostic solution has always been too complicated and too costly. So its time to get comfortable with not being in total control. The System of Systems concept of de-optimising components to integrate and optimise the overall performance of the Big System applies. You just need to understand your risk appetitie, your risks, how you want treat them, what you will accept, what you need to insure against and get on with it. The risks of not doing so are far greater.








Friday, 7 October 2016

Cyber, Robots, Digital, Oktoberfest, Gosling and Demming - all in one week

This week was eventful. It started with the announcement that the UK's National Cyber Security Centre had at last opened its doors, see: http://bit.ly/2dpPZJH. This was long announced and is an essential plank in safeguarding the UK's Digital Infrastructure and Capability. My concern is the glacial pace at which progress has been made here and the comparatively small amounts of funding that the Government has assigned to fund it.

Then someone posed a picture of a man shaking hands with a robot at AT Kearney's Digital Business Forum with the caption "Next gen employee greets legacy employee". This displayed typical 1930s thinking about the value of people drawing from the legacy of the original R.U.R. play Rossumovi UniverzálnĂ­ Roboti (Rossum’s Universal Robots) written by the Czech writer Karel Capek in 1920. In the play, a factory owner attempts to replace his high versatile human workers with mechanical machines, totally undervaluing the creativity and inspiration that people bring to the workplace. Digital models are largely about delivering this value not implementing mindless mechanisation. So perhaps the caption should have been about valuable human talent supplanting inappropriate technology.

Anyway, the highlight of this week was the IPexpo event in London. This had a wide array of suppliers and speakers. Notable about the event was the desire to celebrate Oktoberfest complete with free beer and people dressed in Bavarian costumes at 4:00 pm on the first day. Many of the suppliers were also offering beer at other parts of the day. It was a strange example of how modern "fun oriented" culture of digital start up companies is affecting the mainstream and making us weirdly 1960s and modern all at the same time.

James Gosling presented a captivating key note talk on liquid robots covering his current involvement with Marine UAVs used for data collation in remote seascapes and the IoT practices needed to make this work. The UAVs themselves are very cool, capturing wave energy and converting it into propulsion.  The techniques for transferring data from the middle of oceans, where there is very poor bandwidth available even from satellites, were also very interesting with the same data being transfered by differnt networks and routes to increase the reliability and speed of data transport from the UAVs to the place where it is analysed. The interesting point that he made was that Scalability is a relatively trivial issue for IoT. Security and reliable Availability are much more important.

Two other talks were really good. Mathew Skelton (skelton Thatcher Consulting) gave an illuminating talk on anti-patterns for continuous delivery (aka DevOps). He confirmed my viewpoint that typically you need roughly 1 operations person working continuously with each Product Team, to avoid the bottleneck that some traditional ITIL shops have introduced with undersized change management functions.

Derek Weeks also gave a well researched presentation on the use of Opensource software and how modern software product development practices have now become highly analagous with manufacturing and supply chain practices. He presented interesting statistics on how much open source code contains security and legacy debt bugs. His premise being that Deming's (the father of Quality Management) recommendations to reduce the number of suppliers and quality assure bought in products can raise productivity in the adoption and exploitation of Open Software.

Tuesday, 27 September 2016

GDPR Bricks and Mortar Defence or Digital Viking's Inspiration

GDPR - the General Data Protection Regulation - is the next wave of personal data privacy regulation from the EU and is expected to go live mid 2018, i.e. pre-Brexit. This generally tightens up privacy requirements in a number of areas and has been a theme of discussion at a number of Cyber Security events this year, including today's InfoSecurity Magazine event.

Anyone interested in "Things Digital" should ask themselves, will this act as a regulatory defensive wall for old fashioned Bricks and Mortar / Industrial Age companies to shelter behind, or is it a new discipline or challenge for digital Vikings to embrace?

A couple of today's speakers made some interesting observations and comments: 
  • GDPR means that you need to know the What, Where and Why of Personal Data, especially customer data;
  • Regulation should not drive data security, Security Should Drive Regulatory Compliance;
  • There is a strong case for Digital Companies to adopt Social Digital Responsibility as Part of their Brand.
In a way, it should be easier for purely Digital companies to do this, as they are mostly starting from scratch with few of the problems of IT Estate Sprawl that many established companies have, with legacy systems, infrastructure and the typical complications inherited from previous defunct strategies as well as mergers and acquisitions. 

Also, in a previous blog, I mentioned that many digital companies actually regard this data as part of their IPR. So addressing GDPR (& other jurisdictional requirements) should be core to their business activity. Although future approaches toward collection and explicit consent may have to be sharpened up to meet the new requirements.

The implication is that Digital company that plans and builds Privacy Protection in from Day 1, will actually be building its own competitive advantage over traditional companies who mainly will be playing catch up.

Friday, 23 September 2016

It's strategy Jim, but not as we know it ...

A friend of mine who was a leading light in the development of Information Strategy and Architecture practices in the 80s and 90s, retired a few years ago. The key driver being his disillusionment with organisations who said that there was no time for developing strategy.

In the time since then, Enterprise Architecture has enjoyed a considerable re-birth and growth, everything has gone digital and organisations have started to publish strategies which read more like marketing guff expounding bland benefits, than anything which informs the reader or directs action.

A couple of things have brought this to mind recently. the first was that I picked up a copy of Richard Rumelt's "Good Strategy Bad Strategy", in which he emphasises the need for a situation diagnosis of what is needed to succeed, proposing an integrated and coherent policy which addresses this, and a small set of supporting actions. This is a great read and worth while for anyone interested in Business Strategy.

Yesterday, I went to very stimulating talk about post merger integration by Henry McNeill at the British Computer Society. Afterwards as we huddled around the wine and sandwiches, several key themes came out:

  • Many companies are still not aligning acquisition activity with business strategy;
  • There was violent agreement that clarity of the aims, target state and value proposition of an acquisition is imperative for successful integration;
  • Participation of IT from due diligence onwards, provides an ideal opportunity for IT to show how it can help the business articulate and deliver against a strategy for the exploitation of the newly acquired business. Sadly, many organisations are still bringing IT in on Day 1 after deal completion and missing opportunities to mitigate risks and address early integration opportunities quickly. Some still take years to work out what to do with them.
This brings me to the point of today's commentary. My experience has been that almost all business strategies are usually incomplete and fail to unify the senior management of the business. IT needs a coherent exposition of Strategy which identifies the "game changing" opportunities or risks in the business market place to be able to prioritise its investments, define what common capabilities are needed and to support effective innovation. Working with business leaders at C suite and direct report level to "elicit the real business strategy that they work to" and agree the opportunities is valuable to the business as a whole. It's often a great way to get everyone to understand each others problems and can help unify purpose.  However, its got to be continuous to support the ever shifting business environment as businesses go Digital and Agile. Strategy has to take a Fail Early, Refactor and Learn approach to continuously calibrate its diagnosis, unifying policy and action plan. There's a role for the CIO in this.


Friday, 19 August 2016

The Way of the Digital Leader

What Makes a Digital Leader Great? For many years now it has been clear that other C Suite and senior managers have been increasingly impatient with the efforts of the Information Function to deliver innovation. At the same time it is vitally important to deliver existing services robustly and drive down costs as globalisation and digital delivery increase competition and customer expectations.


In parallel there has been long been a strong movement to "Manage IT as a Business-within-a-Business" or what I call "The Business of IT" (TBIT). Recently this has morphed into a trend for describing the CIO's role as being the CEO of IT. This is important as one of the key roles of a CEO is to think and act in the 3 functional dimensions of his organisation: Control the Business, Do the Business and Support the Business. This is key to building an integrated senior management team which acts coherently with the same unity of purpose. Failure to achieve cohesion will undermine the success of any investment in IT systems, as the business will fail to exploit the potential value.

At the same time there are initiatives such the TBM Council's work on developing "Technology Business Management". This focuses on the conversations that the Information Function must have with other parts of its Business. Key to this is agreeing upon and demonstrating value and cost with transparency.

However for TBIT to be successful, the "Right Value" needs to be identified. Whilst the CIO cannot do this on his/her own, the CIO needs to be stongly plugged into the Business and its Market. Understanding of how the Business Operates, its strengths and weaknesses and the issues that it faces is a start. Understanding the trends within the market place and positioning of key competitors is another milestone. But overall, there needs to be understanding of the customer's needs, desires, frustrations and experience, as well as anticipation of how they may change. Lastly, there needs to be empathy which identifies who else deals with your customers, in a non competitive but complementary manner, and how they could collaborate with you to deliver more.

One more plank is widening the sources of innovation to exploit capability and knowledge that existing partners can bring to the Business and networking with other sources of ideas, e.g. former colleagues from the Business, analysts and academic thinkers.

If I put this together, the answer to the question may include a leader who:

- has good social skills (or at least works on them) and networks with key internal and external stakeholders,
- looks outward and understands the "big rules of the market place",
- builds an effective team which can deliver and gets on well with each other,
- works well with the rest of the C Suite and their teams,
- is lucky enough to work in a business with a healthy collaborative culture.

So just as digital enterprises are moving to understand each customer's individual needs better and make customer interaction more human, the digital leader needs to focus on empathy for success.





 


Tuesday, 16 August 2016

Are You Ready for Digital Disaster?

We all know that we should have a Disaster Recovery / Business Continuity Plan. Yet most of us have worked in businesses where this is a convenient afterthought. Even when businesses have them, active testing of them is often patchy at best. Many businesses aspire to do this at least once a year, fail to meet this target and even if they do, they then brush a lot of things under the carpet.

For many years the key concern has been a major fire, followed by lesser concerns about flooding, terrorist attacks and other major natural disasters. Statistics suggest, that in the UK the typical rate of major fires is around once per hundred years of a data centre's operations. This is actually a very high high rate. Although in actual practice the more frequent major incidents which disrupt operations tend to be caused by more mundane things such as loss of power from the grid, major network switch failures within the the data centre or loss of telecommunications coming into a data centre.

Many businesses have been content to make minimal investment in preparations and accept the risk. They have mostly got away with this despite urban myths about the high percentage of businesses, suffering major incidents, which go out of business. Though if you personally have ever lived through such an incident, you would not want to do so again.

This complacency is looking increasingly out of place as enterprises go digital. For one thing, operations become impossible to deliver with failure, for another the increasing frequency of "Cyber Attacks" means that the old cosy assumptions are no longer valid and not only may operations be disrupted but valuable information or IPR stolen and an enterprise's reputation destroyed along with customer confidence.

The increasing pace of change inherent with modern digital business, based on Agile and DevOps styles of continuous change, also mean that an annual test is laughable as recovery plans will never be up to date if annual refresh thinking continues to dominate. This will also exacerbated by use of multiple SaaS, PaaS and IaaS services. As although each one used may increase the theoretical resilience of the enterprise's systems, it also complicates the inter-dependencies between them.

Business and IT Management Teams need to actively engage in preparing for major disasters and incidents. This means several things need to be addressed:

- capturing all changes to the systems and process lanscape, especially adoption of SaaS services, so that current architecture is documented, understood, risk assessed and continuously revised in recovery plans;
- regular incremental testing of recovery plans to address changes to the systems landscape;
- conduct of scenario "war games" to evaluate responses to different types of threat, taking into account that under Murphy's Law key people may be unavailable when a major incident occurs;
- regular review of major 3rd party services that the enterprise relies upon for the suitability their response capabilities and likely behaviours;
- media training of all senior executives and managers who may be called upon to represent the enterprise in the event of an incident, taking into account that some of them may have been incapacitated by the incident or away from the business.

Not many of us work in enterprises where all this happens, but most of us need this now.

Monday, 8 August 2016

Death of the CIO

Over the last thirty years I have read the orbituaries of many IT professions.

I cannot count the number of times that I have read of the death of the programmer as some new type of tool was supposed to make everything so easy that programmers would soon die out. 4GLs (or Fourth Generation Languages were supposed to do it in the early eighties, Workflow in the nineties and more recently rules engines). Each time the promoted nemesis has turned out to be more difficult to use than its promoters sales pitches would have you believe. Each time some other technological progression or change has introduced new complexities which need detailed technical knowledge. Always there have been things that these tools can not do, requiring specialist programmers to address short commings.

Likewise, the analyst was supposed to be killed by RAD and then Agile developers, yet we need them even more than ever.

Architect, too have been in the line of fire. At the end of the nineties, as the first internet boom took hold, we were told that there was no time for strategy and we were advised to stop worrying about architecture. Then in the late noughties the current fad for enterprise architecture took off again. So it was not a surprise that I was invited to a debate about "Whether Agile is killing the Architect" a few months ago. Everything is cyclic and Agile only really works well when the overall architecture is pre-planned, unless of course the solution is so trivial that it does not matter.

So it is no surprise then that we often see pundits trying to stir the pot with assertions that the CIO will die out. The most recent justification being that Chief Marketting Officers have stolen the "Chief Digital Officer" crown.

Interestingly enough, a recent global survey run jointly by a well know recruitment agency in partnership with a big 4 consultancy, showed that there is a resurgence of CIO roles here with an increasing proportion of them taking on the role of Chief Digital Officer.

This is unsurprising really, given the range of skills needed to be an effective CIO. They are quite different to those required to be a Chief Marketing Officer and what we are really witnessing is the end of another fad, as the CIO's role adjusts to deal with the new opportunities and challenges involved to shifting to a digital business agenda.