SlideShare a Scribd company logo
1 of 32
© All rights reserved. Rob Livingstone Advisory Pty Ltd. Unauthorized redistribution prohibited without prior approval.
‘Navigating through the Cloud’ is a Trademark of Rob Livingstone Advisory Pty Ltd.




     The risks of a fractured
     Cloud strategy within the
     Australian Enterprise

     CSA – Sydney Meeting
     10th May 2012

      ROB LIVINGSTONE
      - PRINCIPAL, Rob Livingstone Advisory Pty Ltd, and
      - Fellow, University of Technology, Sydney



      navigatingthrougthecloud.com
Agenda

•   Scope
•   Theme
•   Systemic Risks vs. Technical Risks
•   Cloud Strategy? What Cloud Strategy?
•   Risks of a fractured Cloud strategy
•   From consumer to corporate – the leap of faith
•   Recognise the forces behind Cloud adoption
•   Orchestrating the Hybrid Cloud ecosystem
•   Some risk mitigation approaches


                                               navigatingthrougthecloud.com
Scope

                     HARDEST
         Major enterprise instances, with
        complexity, scale, risk, compliance,
           deep integration, long term

              Integration, enterprise
               governance needed

                   Commodity /
                   Stand-alone
                Cloud applications


                   EASIEST


                                               navigatingthrougthecloud.com
Theme

Key Variable #1: SIZE

How big is the target organisation?           A ‘no-brainer’
•  Sole trader
•  SME
•  Mid sized
•  Large
•  Very large                                Eyes wide open


Broadly speaking, what is the ease of adoption and suitability of Cloud for
these organisations?



                                                          navigatingthrougthecloud.com
Theme

Key Variable #2: COMPLEXITY

How complex is your organisation?                       A ‘no-brainer’
•  Simple – Can run it on a spreadsheet
•  Somewhat complex
•  Lots of moving parts
•  Very sophisticated structure, processes, etc
•  My head hurts thinking about it
                                                        Eyes wide open

Broadly speaking, what is the ease of adoption and suitability of Cloud for
these organisations?



                                                        navigatingthrougthecloud.com
Theme

Key Variable #3: FAULT TOLERANCE

How FAULT TOLERANT is your organisation?               A ‘no-brainer’
•  Pretty resilient – lots of workarounds
•  Would get by in the event of a major fault
•  Serious damage could result
•  Organisation’s viability would be threatened
•  High / extreme – people die, organisation           Eyes wide open
   ceases to exist, external liability, etc

Broadly speaking, what is the ease of adoption and suitability of Cloud for
these organisations?



                                                          navigatingthrougthecloud.com
Theme

The commercial imperative meets regulatory, security, privacy.




                                                navigatingthrougthecloud.com
Theme
Public Cloud : All You / Your Client have is a contract….




                                              navigatingthrougthecloud.com
Systemic Risks vs. Technical Risks

• Most large organisations are:
  – Complex systems

• Systemic Risks are inherent in Complex Systems
  – Systems that are complex (discrete or non-linear) rather than linear
  – Systems that are tightly coupled
  – Systems that are time-dependent
  – Systems that contain invariant processes (independent of change)
  – Systems that contain little slack…….
  …..are more prone to systemic failure, rather than component failure

• Technical Risks
  – Failures associated with discrete elements of the overall system

  ‘Normal Accidents: Living With High-Risk Technologies’. Charles Perrow, New York: Basic Books,
  Inc., 1984.
                                                                          navigatingthrougthecloud.com
Cloud Strategy? What Cloud Strategy?

• In, and of itself a ‘Cloud Strategy’ means little
• If there is a coherent……
   – Enterprise business strategy, supported by coherent..
   – Business Plans, of which a key component is the …
   – IT Business Plan, of which a key component may be …
   – A Cloud Strategy…
   … you minimise the risks of poorly defined /orphaned projects or
       fractured Cloud strategy

• Let’s explore some of the risks associated with a Fractured Cloud
  Strategy ….

                                                  navigatingthrougthecloud.com
Risks of a fractured Cloud Strategy

• Short term commercial imperatives trump all else
• Vendor predation
• Inappropriate reassignment of accountabilies from IT
• Dismembering of enterprise IT
• Federated Cloud solution selection without federating the risks
• Global Optimum vs. Local Optimum
• Increased TCO
• Inadequate procurement due diligence in key domains such as
  cost, legal, governance, compliance, security, etc…
• Suboptimal architecture
• Proliferation of data silos
• Heightened information security vulnerability
                                                  navigatingthrougthecloud.com
From Consumer to Corporate – a step
of faith for some?




     SMB      Mid Market   Big end of town



                                          navigatingthrougthecloud.com
Recognise the forces behind Cloud adoption

 •   Identify the origins of the change driver from
     Internally generated influences, which could
     include....
     o IT Department wanting to migrate to Cloud
     o Business demanding IT move to the Cloud
     o Compelling vendor offer (maybe yours?)
         generates the demand to shift to the Cloud
     o Need for an IT system – fast!
     o IT just not meeting the organisation’s needs
     o Perceived high comparative cost of internal IT
     o .... And so on ....


                                              navigatingthrougthecloud.com
Recognise the forces behind Cloud adoption

   Identify the origins of the change driver from External
   influences :
       o New legislation
       o Merger / Acquisition
       o Margin / Profit squeeze
       o Cut ‘Time to market’
       o Need to drive innovation
       o Mandate from overseas Headquarters
       o ... And so on .....




                                               navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

1. Key drivers of integration effort:
    • Number of systems to be connected




                                          navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

1. Key drivers of integration effort:
    • Number of systems to be connected
    • Who is in control – you or the Cloud vendor?
    • Degree and scope of Integration
    • Risk tolerance
    • IT Architectural considerations
    • Compliance, Regulatory and Audit load
    • Disaster Recovery implications (Logical and Physical)




                         X
                                               navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

1. Key drivers of integration effort:
    • Number of systems to be connected
    • Who is in control – you or the Cloud vendor?
    • Degree and scope of Integration
    • Risk tolerance
    • IT Architectural considerations
    • Compliance, Regulatory and Audit load
    • Disaster Recovery implications (Logical and Physical)
    • Size




                                               navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

1. Key drivers of integration effort:
    • Number of systems to be connected
    • Who is in control – you or the Cloud vendor?
    • Degree and scope of Integration
    • Risk tolerance
    • IT Architectural considerations
    • Compliance, Regulatory and Audit load
    • Disaster Recovery implications
    • Size
    • System volatility



                                               navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

1. Key drivers of integration effort:
    • Number of systems to be connected
    • Who is in control – you or the Cloud vendor?
    • Degree and scope of Integration
    • Risk tolerance
    • IT Architectural considerations
    • Compliance, Regulatory and Audit load
    • Disaster Recovery implications
    • Size
    • System volatility
    • Systemic complexity


                                               navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

1. Key drivers of integration effort:
    • Number of systems to be connected
    • Who is in control – you or the Cloud vendor?
    • Degree and scope of Integration
    • Risk tolerance
    • IT Architectural considerations
    • Compliance, Regulatory and Audit load
    • Disaster Recovery implications
    • Size
    • System volatility
    • Systemic complexity
    • Security and privacy

                                               navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

1. Key drivers of integration effort:
    • Number of systems to be connected
    • Who is in control – you or the Cloud vendor?
    • Degree and scope of Integration
    • Risk tolerance
    • IT Architectural considerations
    • Compliance, Regulatory and Audit load
    • Disaster Recovery implications
    • Size
    • System volatility
    • Systemic complexity
    • Security and privacy
    • Budgetary / cost
                                               navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem
1. Key drivers of integration effort:
    • Number of systems to be connected
    • Who is in control – you or the Cloud vendor?
    • Degree and scope of Integration
    • Risk tolerance          1 Yr      2 Yrs
    • IT Architectural considerations
    • Compliance, Regulatory and Audit load
               3 Yrs
    • Disaster Recovery implications
                          6 Mths
    • Size                                     5 Yrs
    • System volatility
    • Systemic complexity
    • Security and privacy
    • Budgetary / cost
    • Life expectancy of the system(s)
                                               navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

2. Blending legacy, on premise and other IT systems
• The cost of building the integration points may exceed the
    cost of your Cloud application
• What are the business requirements for:
    • Data integration
        Drives enterprise data matching
        Dashboards and ‘Business Intelligence’
        ...... And so on
    • Application integration
        Do you want to create an integrated user
          experience? – ie: Single screen rather than having a
          use a myriad of screens from different systems

                                                navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

3. Localised Clouds leading to federated IT / Cloud Silos
• Organisations with poor ITBusiness engagement and
    alignment facilitate the growth of local cloud applications
    that:
    • Meet a local business need
    • Are easily managed by the local ‘owner’




                                                  navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

4. Local optimum vs. Global optimum
•   What’s good for a local instance may be save time, cost, etc
•   Does this approach scale?
•   Factored in costs, effort and risks of Administering multiple systems?
•   Centralise Decentralise discussion starts all over again
•   Take an evolutionary approach?
•   Do you only mandate in the case of risk, privacy, security?




                                                           navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

5. Hybrid architectures including hybrid security model
• How do you manage security in a federated, distributed
    model?




                                             navigatingthrougthecloud.com
Orchestrating the Hybrid Cloud ecosystem

6. Potential points of conflicts with CSO / CFO / CIO /
   COO
   • Gain consensus from all stakeholders in your
     organisation on the settings for enterprise risk,
     governance including
   • Compliance, discovery, forensics, logging and fault
     finding challenges
7. Enterprise data warehousing and integration
   • Network speeds and related considerations
8. Enterprise data warehousing and ‘Big Data’
   • Quo Vadis?


                                               navigatingthrougthecloud.com
Some risk mitigation approaches

• Be crystal clear on the drivers behind Cloud for the
  organisation.
• Understand and accurately map the solution to the
  organisation’s legislative, regulatory and compliance
  environment
• Know the minimum privacy, security and data jurisdictional
  needs clearly.
• Map to the organisation’s potential client’s regulatory
  environments if needed
• Resolve integration complexities
   – Map cost exposures in cloud brokerage and integration
     environments

                                                  navigatingthrougthecloud.com
Some risk mitigation approaches
• Assess the volatility of your cloud provider’s ecosystem
    – What will your provider look like in 2 years time?
• Delivery through Service Value Chains means that the weakest
  link effect is to be recognised and managed
• Identify inconsistencies in Security, Privacy, Governance,
  Regulatory compliance through the Cloud provider’s chain
• Confirm executive accountabilies for risk!
Reshape the role of your IT Department
• Shift from a technology provider to a Services broker
• Differing skills mix for in-house IT
• Technology enabled business services is the direction to
  take for enterprise IT
                                                navigatingthrougthecloud.com
Some risk mitigation approaches
•   Perform your own due diligence, and seek absolutely
    independent, experienced, financially disinterested advice if
    needed
•   Stress test your business case by:
    – Conducting a sensitivity analysis for feasible business,
       legal and operational scenarios
    – Pricing in risk
    – Defining and costing your exit strategy for each stage of
       the life cycle in your Cloud
    – Defining the Cloud roles and accountabilities clearly. E.g.
       How do they compare to the roles defined in the NIST
       CCRA?




                                                    navigatingthrougthecloud.com
Subscribe to my Podcast Channel – Interviews,
Discussions and independence + PDF Transcripts




                                          navigatingthrougthecloud.com
QUESTIONS / DISCUSSION

ROB LIVINGSTONE
- PRINCIPAL, Rob Livingstone Advisory Pty Ltd, and
- Fellow, University of Technology, Sydney
Rob Livingstone Advisory Pty Ltd
 ABN 41 146 643 165
W1:            www.rob-livingstone.com
W2:            www.navigatingthroughthecloud.com
E:             rob@rob-livingstone.com
P:             +61 2 8005 1972
P:             +1 609 843 0349
M:             +61 419 632 673
F:             +61 2 9879 5004
               rladvisory

© All rights reserved. Unauthorised redistribution not without prior approval
                                                                                navigatingthrougthecloud.com

More Related Content

What's hot

Why the systemic risks in Enterprise Cloud Computing could cripple your busin...
Why the systemic risks in Enterprise Cloud Computing could cripple your busin...Why the systemic risks in Enterprise Cloud Computing could cripple your busin...
Why the systemic risks in Enterprise Cloud Computing could cripple your busin...Livingstone Advisory
 
Cloud: Fuelling the crisis of confidence in corporate IT?
Cloud: Fuelling the crisis of confidence in corporate IT?Cloud: Fuelling the crisis of confidence in corporate IT?
Cloud: Fuelling the crisis of confidence in corporate IT?Livingstone Advisory
 
Career implications for the Business Analyst in the age of digital disruption
Career implications for the Business Analyst in the age of digital disruptionCareer implications for the Business Analyst in the age of digital disruption
Career implications for the Business Analyst in the age of digital disruptionLivingstone Advisory
 
Your Leadership Brand - The CIO as Business Strategist driving innovation. CI...
Your Leadership Brand - The CIO as Business Strategist driving innovation. CI...Your Leadership Brand - The CIO as Business Strategist driving innovation. CI...
Your Leadership Brand - The CIO as Business Strategist driving innovation. CI...Livingstone Advisory
 
Cloud Security Keynote: Cloud-Mobile Convergence: IT's Next Horizon, CISO's N...
Cloud Security Keynote: Cloud-Mobile Convergence: IT's Next Horizon, CISO's N...Cloud Security Keynote: Cloud-Mobile Convergence: IT's Next Horizon, CISO's N...
Cloud Security Keynote: Cloud-Mobile Convergence: IT's Next Horizon, CISO's N...Livingstone Advisory
 
Current enterprise information security measures continue to fail us. Why is ...
Current enterprise information security measures continue to fail us. Why is ...Current enterprise information security measures continue to fail us. Why is ...
Current enterprise information security measures continue to fail us. Why is ...Livingstone Advisory
 
Maximising the opportunities offered by emerging technologies within the chan...
Maximising the opportunities offered by emerging technologies within the chan...Maximising the opportunities offered by emerging technologies within the chan...
Maximising the opportunities offered by emerging technologies within the chan...Livingstone Advisory
 
Navigating the risks in implementing Hybrid Cloud, Agile and Project Manageme...
Navigating the risks in implementing Hybrid Cloud, Agile and Project Manageme...Navigating the risks in implementing Hybrid Cloud, Agile and Project Manageme...
Navigating the risks in implementing Hybrid Cloud, Agile and Project Manageme...Livingstone Advisory
 
Career resilience is the name of the game
Career resilience is the name of the gameCareer resilience is the name of the game
Career resilience is the name of the gameLivingstone Advisory
 
Future Tech: How should enterprise avoid the 'success trap' of the next big t...
Future Tech: How should enterprise avoid the 'success trap' of the next big t...Future Tech: How should enterprise avoid the 'success trap' of the next big t...
Future Tech: How should enterprise avoid the 'success trap' of the next big t...Livingstone Advisory
 
Rob livingstone CIO Strategy Summit - Park Hyatt Melbourne 17th feb 2012
Rob livingstone  CIO Strategy Summit - Park Hyatt Melbourne 17th feb 2012Rob livingstone  CIO Strategy Summit - Park Hyatt Melbourne 17th feb 2012
Rob livingstone CIO Strategy Summit - Park Hyatt Melbourne 17th feb 2012Livingstone Advisory
 
A future history of content management
A future history of content managementA future history of content management
A future history of content managementJohn Mancini
 
UU innovation masters november 2010
UU innovation masters november 2010UU innovation masters november 2010
UU innovation masters november 2010Tim Willoughby
 
Moving from Records to Engagement to Insight
Moving from Records to Engagement to InsightMoving from Records to Engagement to Insight
Moving from Records to Engagement to InsightJohn Mancini
 
20101116 deckers
20101116 deckers20101116 deckers
20101116 deckersCIONET
 
Wall street journal 22 sept 10 - perspectives on risk it
Wall street journal 22 sept 10  - perspectives on risk itWall street journal 22 sept 10  - perspectives on risk it
Wall street journal 22 sept 10 - perspectives on risk itMessiernl
 
Security Strategies for Success
Security Strategies for SuccessSecurity Strategies for Success
Security Strategies for SuccessCitrix
 
Business Cloud: The State of Play Shifts Rapidly
Business Cloud: The State of Play Shifts RapidlyBusiness Cloud: The State of Play Shifts Rapidly
Business Cloud: The State of Play Shifts RapidlyCapgemini
 
Everything You Need to Know About Enterprise IT in Three Slides
Everything You Need to Know About Enterprise IT in Three SlidesEverything You Need to Know About Enterprise IT in Three Slides
Everything You Need to Know About Enterprise IT in Three SlidesJohn Mancini
 

What's hot (20)

Why the systemic risks in Enterprise Cloud Computing could cripple your busin...
Why the systemic risks in Enterprise Cloud Computing could cripple your busin...Why the systemic risks in Enterprise Cloud Computing could cripple your busin...
Why the systemic risks in Enterprise Cloud Computing could cripple your busin...
 
Cloud: Fuelling the crisis of confidence in corporate IT?
Cloud: Fuelling the crisis of confidence in corporate IT?Cloud: Fuelling the crisis of confidence in corporate IT?
Cloud: Fuelling the crisis of confidence in corporate IT?
 
Career implications for the Business Analyst in the age of digital disruption
Career implications for the Business Analyst in the age of digital disruptionCareer implications for the Business Analyst in the age of digital disruption
Career implications for the Business Analyst in the age of digital disruption
 
Your Leadership Brand - The CIO as Business Strategist driving innovation. CI...
Your Leadership Brand - The CIO as Business Strategist driving innovation. CI...Your Leadership Brand - The CIO as Business Strategist driving innovation. CI...
Your Leadership Brand - The CIO as Business Strategist driving innovation. CI...
 
Cloud Security Keynote: Cloud-Mobile Convergence: IT's Next Horizon, CISO's N...
Cloud Security Keynote: Cloud-Mobile Convergence: IT's Next Horizon, CISO's N...Cloud Security Keynote: Cloud-Mobile Convergence: IT's Next Horizon, CISO's N...
Cloud Security Keynote: Cloud-Mobile Convergence: IT's Next Horizon, CISO's N...
 
Current enterprise information security measures continue to fail us. Why is ...
Current enterprise information security measures continue to fail us. Why is ...Current enterprise information security measures continue to fail us. Why is ...
Current enterprise information security measures continue to fail us. Why is ...
 
Maximising the opportunities offered by emerging technologies within the chan...
Maximising the opportunities offered by emerging technologies within the chan...Maximising the opportunities offered by emerging technologies within the chan...
Maximising the opportunities offered by emerging technologies within the chan...
 
Navigating the risks in implementing Hybrid Cloud, Agile and Project Manageme...
Navigating the risks in implementing Hybrid Cloud, Agile and Project Manageme...Navigating the risks in implementing Hybrid Cloud, Agile and Project Manageme...
Navigating the risks in implementing Hybrid Cloud, Agile and Project Manageme...
 
Career resilience is the name of the game
Career resilience is the name of the gameCareer resilience is the name of the game
Career resilience is the name of the game
 
Future Tech: How should enterprise avoid the 'success trap' of the next big t...
Future Tech: How should enterprise avoid the 'success trap' of the next big t...Future Tech: How should enterprise avoid the 'success trap' of the next big t...
Future Tech: How should enterprise avoid the 'success trap' of the next big t...
 
Thriving in the world of Big Data
Thriving in the world of Big DataThriving in the world of Big Data
Thriving in the world of Big Data
 
Rob livingstone CIO Strategy Summit - Park Hyatt Melbourne 17th feb 2012
Rob livingstone  CIO Strategy Summit - Park Hyatt Melbourne 17th feb 2012Rob livingstone  CIO Strategy Summit - Park Hyatt Melbourne 17th feb 2012
Rob livingstone CIO Strategy Summit - Park Hyatt Melbourne 17th feb 2012
 
A future history of content management
A future history of content managementA future history of content management
A future history of content management
 
UU innovation masters november 2010
UU innovation masters november 2010UU innovation masters november 2010
UU innovation masters november 2010
 
Moving from Records to Engagement to Insight
Moving from Records to Engagement to InsightMoving from Records to Engagement to Insight
Moving from Records to Engagement to Insight
 
20101116 deckers
20101116 deckers20101116 deckers
20101116 deckers
 
Wall street journal 22 sept 10 - perspectives on risk it
Wall street journal 22 sept 10  - perspectives on risk itWall street journal 22 sept 10  - perspectives on risk it
Wall street journal 22 sept 10 - perspectives on risk it
 
Security Strategies for Success
Security Strategies for SuccessSecurity Strategies for Success
Security Strategies for Success
 
Business Cloud: The State of Play Shifts Rapidly
Business Cloud: The State of Play Shifts RapidlyBusiness Cloud: The State of Play Shifts Rapidly
Business Cloud: The State of Play Shifts Rapidly
 
Everything You Need to Know About Enterprise IT in Three Slides
Everything You Need to Know About Enterprise IT in Three SlidesEverything You Need to Know About Enterprise IT in Three Slides
Everything You Need to Know About Enterprise IT in Three Slides
 

Similar to Rob Livingstone Advisory - The risks of a fractured cloud strategy within the australian enterprise - csa 10 may 2012 (c)

Map of the Cloud minefield - Banktech Sydney Summit 17 july 2012
Map of the Cloud minefield - Banktech Sydney Summit 17 july 2012 Map of the Cloud minefield - Banktech Sydney Summit 17 july 2012
Map of the Cloud minefield - Banktech Sydney Summit 17 july 2012 Livingstone Advisory
 
RightScale Webinar - Coping With Cloud Migration Challenges: Best Practices a...
RightScale Webinar - Coping With Cloud Migration Challenges: Best Practices a...RightScale Webinar - Coping With Cloud Migration Challenges: Best Practices a...
RightScale Webinar - Coping With Cloud Migration Challenges: Best Practices a...RightScale
 
Webinar compiled powerpoint
Webinar compiled powerpointWebinar compiled powerpoint
Webinar compiled powerpointCloudPassage
 
EMEA10: Trepidation in Moving to the Cloud
EMEA10: Trepidation in Moving to the CloudEMEA10: Trepidation in Moving to the Cloud
EMEA10: Trepidation in Moving to the CloudCompTIA UK
 
Bil Harmer - Myths of Cloud Security Debunked!
Bil Harmer - Myths of Cloud Security Debunked!Bil Harmer - Myths of Cloud Security Debunked!
Bil Harmer - Myths of Cloud Security Debunked!centralohioissa
 
UTSpeaks Public Lecture: Clearing up the Cloud -19th July 2011 - Rob Living...
UTSpeaks Public Lecture:  Clearing up the Cloud  -19th July 2011 - Rob Living...UTSpeaks Public Lecture:  Clearing up the Cloud  -19th July 2011 - Rob Living...
UTSpeaks Public Lecture: Clearing up the Cloud -19th July 2011 - Rob Living...Livingstone Advisory
 
110307 cloud security requirements gourley
110307 cloud security requirements gourley110307 cloud security requirements gourley
110307 cloud security requirements gourleyGovCloud Network
 
Top Trends and Challenges in the Cloud
Top Trends and Challenges in the CloudTop Trends and Challenges in the Cloud
Top Trends and Challenges in the CloudPrecisely
 
VMworld 2013: How to make most out of your Hybrid Cloud
VMworld 2013: How to make most out of your Hybrid Cloud VMworld 2013: How to make most out of your Hybrid Cloud
VMworld 2013: How to make most out of your Hybrid Cloud VMworld
 
May 2013 Federal Cloud Computing Summit Keynote by David Cearly
May 2013 Federal Cloud Computing Summit Keynote by David CearlyMay 2013 Federal Cloud Computing Summit Keynote by David Cearly
May 2013 Federal Cloud Computing Summit Keynote by David CearlyTim Harvey
 
Considering The Cloud? Thinking Beyond The Readme File
Considering The Cloud? Thinking Beyond The Readme FileConsidering The Cloud? Thinking Beyond The Readme File
Considering The Cloud? Thinking Beyond The Readme FileBill Malchisky Jr.
 
The most trusted, proven enterprise-class Cloud:Closer than you think
The most trusted, proven enterprise-class Cloud:Closer than you think The most trusted, proven enterprise-class Cloud:Closer than you think
The most trusted, proven enterprise-class Cloud:Closer than you think Uni Systems S.M.S.A.
 
MBT Webinar: Does the security of your business data keep you up at night?
MBT Webinar: Does the security of your business data keep you up at night? MBT Webinar: Does the security of your business data keep you up at night?
MBT Webinar: Does the security of your business data keep you up at night? Jorge García
 
Moving Enterprise Applications to the Cloud
Moving Enterprise Applications to the CloudMoving Enterprise Applications to the Cloud
Moving Enterprise Applications to the CloudVISI
 
Security & Compliance in the Cloud [2019]
Security & Compliance in the Cloud [2019]Security & Compliance in the Cloud [2019]
Security & Compliance in the Cloud [2019]Tudor Damian
 
Single Realm Multi-Cloud Security Management with Palo Alto Networks
Single Realm Multi-Cloud Security Management with Palo Alto NetworksSingle Realm Multi-Cloud Security Management with Palo Alto Networks
Single Realm Multi-Cloud Security Management with Palo Alto Networks2nd Watch
 

Similar to Rob Livingstone Advisory - The risks of a fractured cloud strategy within the australian enterprise - csa 10 may 2012 (c) (20)

Map of the Cloud minefield - Banktech Sydney Summit 17 july 2012
Map of the Cloud minefield - Banktech Sydney Summit 17 july 2012 Map of the Cloud minefield - Banktech Sydney Summit 17 july 2012
Map of the Cloud minefield - Banktech Sydney Summit 17 july 2012
 
RightScale Webinar - Coping With Cloud Migration Challenges: Best Practices a...
RightScale Webinar - Coping With Cloud Migration Challenges: Best Practices a...RightScale Webinar - Coping With Cloud Migration Challenges: Best Practices a...
RightScale Webinar - Coping With Cloud Migration Challenges: Best Practices a...
 
Webinar compiled powerpoint
Webinar compiled powerpointWebinar compiled powerpoint
Webinar compiled powerpoint
 
EMEA10: Trepidation in Moving to the Cloud
EMEA10: Trepidation in Moving to the CloudEMEA10: Trepidation in Moving to the Cloud
EMEA10: Trepidation in Moving to the Cloud
 
Bil Harmer - Myths of Cloud Security Debunked!
Bil Harmer - Myths of Cloud Security Debunked!Bil Harmer - Myths of Cloud Security Debunked!
Bil Harmer - Myths of Cloud Security Debunked!
 
UTSpeaks Public Lecture: Clearing up the Cloud -19th July 2011 - Rob Living...
UTSpeaks Public Lecture:  Clearing up the Cloud  -19th July 2011 - Rob Living...UTSpeaks Public Lecture:  Clearing up the Cloud  -19th July 2011 - Rob Living...
UTSpeaks Public Lecture: Clearing up the Cloud -19th July 2011 - Rob Living...
 
GRC Dynamics in Securing Cloud
GRC Dynamics in Securing CloudGRC Dynamics in Securing Cloud
GRC Dynamics in Securing Cloud
 
110307 cloud security requirements gourley
110307 cloud security requirements gourley110307 cloud security requirements gourley
110307 cloud security requirements gourley
 
Is it an internal affair
Is it an internal affairIs it an internal affair
Is it an internal affair
 
Top Trends and Challenges in the Cloud
Top Trends and Challenges in the CloudTop Trends and Challenges in the Cloud
Top Trends and Challenges in the Cloud
 
VMworld 2013: How to make most out of your Hybrid Cloud
VMworld 2013: How to make most out of your Hybrid Cloud VMworld 2013: How to make most out of your Hybrid Cloud
VMworld 2013: How to make most out of your Hybrid Cloud
 
May 2013 Federal Cloud Computing Summit Keynote by David Cearly
May 2013 Federal Cloud Computing Summit Keynote by David CearlyMay 2013 Federal Cloud Computing Summit Keynote by David Cearly
May 2013 Federal Cloud Computing Summit Keynote by David Cearly
 
Considering The Cloud? Thinking Beyond The Readme File
Considering The Cloud? Thinking Beyond The Readme FileConsidering The Cloud? Thinking Beyond The Readme File
Considering The Cloud? Thinking Beyond The Readme File
 
The most trusted, proven enterprise-class Cloud:Closer than you think
The most trusted, proven enterprise-class Cloud:Closer than you think The most trusted, proven enterprise-class Cloud:Closer than you think
The most trusted, proven enterprise-class Cloud:Closer than you think
 
Cloud security ppt
Cloud security pptCloud security ppt
Cloud security ppt
 
MBT Webinar: Does the security of your business data keep you up at night?
MBT Webinar: Does the security of your business data keep you up at night? MBT Webinar: Does the security of your business data keep you up at night?
MBT Webinar: Does the security of your business data keep you up at night?
 
Eyes Wide Shut: Cybersecurity Smoke & Mirrors...
Eyes Wide Shut: Cybersecurity Smoke & Mirrors...Eyes Wide Shut: Cybersecurity Smoke & Mirrors...
Eyes Wide Shut: Cybersecurity Smoke & Mirrors...
 
Moving Enterprise Applications to the Cloud
Moving Enterprise Applications to the CloudMoving Enterprise Applications to the Cloud
Moving Enterprise Applications to the Cloud
 
Security & Compliance in the Cloud [2019]
Security & Compliance in the Cloud [2019]Security & Compliance in the Cloud [2019]
Security & Compliance in the Cloud [2019]
 
Single Realm Multi-Cloud Security Management with Palo Alto Networks
Single Realm Multi-Cloud Security Management with Palo Alto NetworksSingle Realm Multi-Cloud Security Management with Palo Alto Networks
Single Realm Multi-Cloud Security Management with Palo Alto Networks
 

More from Livingstone Advisory

How to setup and lead digital transformation capability (CIOs perspectives)
How to setup and lead digital transformation capability (CIOs perspectives)How to setup and lead digital transformation capability (CIOs perspectives)
How to setup and lead digital transformation capability (CIOs perspectives)Livingstone Advisory
 
Best practices to mitigate data breach risk
Best practices to mitigate data breach riskBest practices to mitigate data breach risk
Best practices to mitigate data breach riskLivingstone Advisory
 
Influence, Power, Integrity and your career in IT
Influence, Power, Integrity and your career in ITInfluence, Power, Integrity and your career in IT
Influence, Power, Integrity and your career in ITLivingstone Advisory
 
Exposing the systemic risks in enterprise cloud computing
Exposing the systemic risks in enterprise cloud computingExposing the systemic risks in enterprise cloud computing
Exposing the systemic risks in enterprise cloud computingLivingstone Advisory
 
Rob livingstone Canberra Cloud Security Conference Nov 2011
Rob livingstone Canberra Cloud Security Conference Nov 2011 Rob livingstone Canberra Cloud Security Conference Nov 2011
Rob livingstone Canberra Cloud Security Conference Nov 2011 Livingstone Advisory
 
Rob livingstone - Australian Payroll Association's Annual Conference May 2011
Rob livingstone  - Australian Payroll Association's Annual Conference May 2011Rob livingstone  - Australian Payroll Association's Annual Conference May 2011
Rob livingstone - Australian Payroll Association's Annual Conference May 2011Livingstone Advisory
 
Australian Not-for-Profit CIO Forum March 2011 - Rob Livingstone
Australian Not-for-Profit CIO Forum March 2011 - Rob LivingstoneAustralian Not-for-Profit CIO Forum March 2011 - Rob Livingstone
Australian Not-for-Profit CIO Forum March 2011 - Rob LivingstoneLivingstone Advisory
 
Navigating through the cloud SPUSC 2011 -Rob Livingstone Keynote
Navigating through the cloud   SPUSC 2011 -Rob Livingstone KeynoteNavigating through the cloud   SPUSC 2011 -Rob Livingstone Keynote
Navigating through the cloud SPUSC 2011 -Rob Livingstone KeynoteLivingstone Advisory
 

More from Livingstone Advisory (8)

How to setup and lead digital transformation capability (CIOs perspectives)
How to setup and lead digital transformation capability (CIOs perspectives)How to setup and lead digital transformation capability (CIOs perspectives)
How to setup and lead digital transformation capability (CIOs perspectives)
 
Best practices to mitigate data breach risk
Best practices to mitigate data breach riskBest practices to mitigate data breach risk
Best practices to mitigate data breach risk
 
Influence, Power, Integrity and your career in IT
Influence, Power, Integrity and your career in ITInfluence, Power, Integrity and your career in IT
Influence, Power, Integrity and your career in IT
 
Exposing the systemic risks in enterprise cloud computing
Exposing the systemic risks in enterprise cloud computingExposing the systemic risks in enterprise cloud computing
Exposing the systemic risks in enterprise cloud computing
 
Rob livingstone Canberra Cloud Security Conference Nov 2011
Rob livingstone Canberra Cloud Security Conference Nov 2011 Rob livingstone Canberra Cloud Security Conference Nov 2011
Rob livingstone Canberra Cloud Security Conference Nov 2011
 
Rob livingstone - Australian Payroll Association's Annual Conference May 2011
Rob livingstone  - Australian Payroll Association's Annual Conference May 2011Rob livingstone  - Australian Payroll Association's Annual Conference May 2011
Rob livingstone - Australian Payroll Association's Annual Conference May 2011
 
Australian Not-for-Profit CIO Forum March 2011 - Rob Livingstone
Australian Not-for-Profit CIO Forum March 2011 - Rob LivingstoneAustralian Not-for-Profit CIO Forum March 2011 - Rob Livingstone
Australian Not-for-Profit CIO Forum March 2011 - Rob Livingstone
 
Navigating through the cloud SPUSC 2011 -Rob Livingstone Keynote
Navigating through the cloud   SPUSC 2011 -Rob Livingstone KeynoteNavigating through the cloud   SPUSC 2011 -Rob Livingstone Keynote
Navigating through the cloud SPUSC 2011 -Rob Livingstone Keynote
 

Recently uploaded

From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsMiki Katsuragi
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfRankYa
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 

Recently uploaded (20)

From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering TipsVertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Search Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdfSearch Engine Optimization SEO PDF for 2024.pdf
Search Engine Optimization SEO PDF for 2024.pdf
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 

Rob Livingstone Advisory - The risks of a fractured cloud strategy within the australian enterprise - csa 10 may 2012 (c)

  • 1. © All rights reserved. Rob Livingstone Advisory Pty Ltd. Unauthorized redistribution prohibited without prior approval. ‘Navigating through the Cloud’ is a Trademark of Rob Livingstone Advisory Pty Ltd. The risks of a fractured Cloud strategy within the Australian Enterprise CSA – Sydney Meeting 10th May 2012 ROB LIVINGSTONE - PRINCIPAL, Rob Livingstone Advisory Pty Ltd, and - Fellow, University of Technology, Sydney navigatingthrougthecloud.com
  • 2. Agenda • Scope • Theme • Systemic Risks vs. Technical Risks • Cloud Strategy? What Cloud Strategy? • Risks of a fractured Cloud strategy • From consumer to corporate – the leap of faith • Recognise the forces behind Cloud adoption • Orchestrating the Hybrid Cloud ecosystem • Some risk mitigation approaches navigatingthrougthecloud.com
  • 3. Scope HARDEST Major enterprise instances, with complexity, scale, risk, compliance, deep integration, long term Integration, enterprise governance needed Commodity / Stand-alone Cloud applications EASIEST navigatingthrougthecloud.com
  • 4. Theme Key Variable #1: SIZE How big is the target organisation? A ‘no-brainer’ • Sole trader • SME • Mid sized • Large • Very large Eyes wide open Broadly speaking, what is the ease of adoption and suitability of Cloud for these organisations? navigatingthrougthecloud.com
  • 5. Theme Key Variable #2: COMPLEXITY How complex is your organisation? A ‘no-brainer’ • Simple – Can run it on a spreadsheet • Somewhat complex • Lots of moving parts • Very sophisticated structure, processes, etc • My head hurts thinking about it Eyes wide open Broadly speaking, what is the ease of adoption and suitability of Cloud for these organisations? navigatingthrougthecloud.com
  • 6. Theme Key Variable #3: FAULT TOLERANCE How FAULT TOLERANT is your organisation? A ‘no-brainer’ • Pretty resilient – lots of workarounds • Would get by in the event of a major fault • Serious damage could result • Organisation’s viability would be threatened • High / extreme – people die, organisation Eyes wide open ceases to exist, external liability, etc Broadly speaking, what is the ease of adoption and suitability of Cloud for these organisations? navigatingthrougthecloud.com
  • 7. Theme The commercial imperative meets regulatory, security, privacy. navigatingthrougthecloud.com
  • 8. Theme Public Cloud : All You / Your Client have is a contract…. navigatingthrougthecloud.com
  • 9. Systemic Risks vs. Technical Risks • Most large organisations are: – Complex systems • Systemic Risks are inherent in Complex Systems – Systems that are complex (discrete or non-linear) rather than linear – Systems that are tightly coupled – Systems that are time-dependent – Systems that contain invariant processes (independent of change) – Systems that contain little slack……. …..are more prone to systemic failure, rather than component failure • Technical Risks – Failures associated with discrete elements of the overall system ‘Normal Accidents: Living With High-Risk Technologies’. Charles Perrow, New York: Basic Books, Inc., 1984. navigatingthrougthecloud.com
  • 10. Cloud Strategy? What Cloud Strategy? • In, and of itself a ‘Cloud Strategy’ means little • If there is a coherent…… – Enterprise business strategy, supported by coherent.. – Business Plans, of which a key component is the … – IT Business Plan, of which a key component may be … – A Cloud Strategy… … you minimise the risks of poorly defined /orphaned projects or fractured Cloud strategy • Let’s explore some of the risks associated with a Fractured Cloud Strategy …. navigatingthrougthecloud.com
  • 11. Risks of a fractured Cloud Strategy • Short term commercial imperatives trump all else • Vendor predation • Inappropriate reassignment of accountabilies from IT • Dismembering of enterprise IT • Federated Cloud solution selection without federating the risks • Global Optimum vs. Local Optimum • Increased TCO • Inadequate procurement due diligence in key domains such as cost, legal, governance, compliance, security, etc… • Suboptimal architecture • Proliferation of data silos • Heightened information security vulnerability navigatingthrougthecloud.com
  • 12. From Consumer to Corporate – a step of faith for some? SMB  Mid Market Big end of town navigatingthrougthecloud.com
  • 13. Recognise the forces behind Cloud adoption • Identify the origins of the change driver from Internally generated influences, which could include.... o IT Department wanting to migrate to Cloud o Business demanding IT move to the Cloud o Compelling vendor offer (maybe yours?) generates the demand to shift to the Cloud o Need for an IT system – fast! o IT just not meeting the organisation’s needs o Perceived high comparative cost of internal IT o .... And so on .... navigatingthrougthecloud.com
  • 14. Recognise the forces behind Cloud adoption Identify the origins of the change driver from External influences : o New legislation o Merger / Acquisition o Margin / Profit squeeze o Cut ‘Time to market’ o Need to drive innovation o Mandate from overseas Headquarters o ... And so on ..... navigatingthrougthecloud.com
  • 15. Orchestrating the Hybrid Cloud ecosystem 1. Key drivers of integration effort: • Number of systems to be connected navigatingthrougthecloud.com
  • 16. Orchestrating the Hybrid Cloud ecosystem 1. Key drivers of integration effort: • Number of systems to be connected • Who is in control – you or the Cloud vendor? • Degree and scope of Integration • Risk tolerance • IT Architectural considerations • Compliance, Regulatory and Audit load • Disaster Recovery implications (Logical and Physical) X navigatingthrougthecloud.com
  • 17. Orchestrating the Hybrid Cloud ecosystem 1. Key drivers of integration effort: • Number of systems to be connected • Who is in control – you or the Cloud vendor? • Degree and scope of Integration • Risk tolerance • IT Architectural considerations • Compliance, Regulatory and Audit load • Disaster Recovery implications (Logical and Physical) • Size navigatingthrougthecloud.com
  • 18. Orchestrating the Hybrid Cloud ecosystem 1. Key drivers of integration effort: • Number of systems to be connected • Who is in control – you or the Cloud vendor? • Degree and scope of Integration • Risk tolerance • IT Architectural considerations • Compliance, Regulatory and Audit load • Disaster Recovery implications • Size • System volatility navigatingthrougthecloud.com
  • 19. Orchestrating the Hybrid Cloud ecosystem 1. Key drivers of integration effort: • Number of systems to be connected • Who is in control – you or the Cloud vendor? • Degree and scope of Integration • Risk tolerance • IT Architectural considerations • Compliance, Regulatory and Audit load • Disaster Recovery implications • Size • System volatility • Systemic complexity navigatingthrougthecloud.com
  • 20. Orchestrating the Hybrid Cloud ecosystem 1. Key drivers of integration effort: • Number of systems to be connected • Who is in control – you or the Cloud vendor? • Degree and scope of Integration • Risk tolerance • IT Architectural considerations • Compliance, Regulatory and Audit load • Disaster Recovery implications • Size • System volatility • Systemic complexity • Security and privacy navigatingthrougthecloud.com
  • 21. Orchestrating the Hybrid Cloud ecosystem 1. Key drivers of integration effort: • Number of systems to be connected • Who is in control – you or the Cloud vendor? • Degree and scope of Integration • Risk tolerance • IT Architectural considerations • Compliance, Regulatory and Audit load • Disaster Recovery implications • Size • System volatility • Systemic complexity • Security and privacy • Budgetary / cost navigatingthrougthecloud.com
  • 22. Orchestrating the Hybrid Cloud ecosystem 1. Key drivers of integration effort: • Number of systems to be connected • Who is in control – you or the Cloud vendor? • Degree and scope of Integration • Risk tolerance 1 Yr 2 Yrs • IT Architectural considerations • Compliance, Regulatory and Audit load 3 Yrs • Disaster Recovery implications 6 Mths • Size 5 Yrs • System volatility • Systemic complexity • Security and privacy • Budgetary / cost • Life expectancy of the system(s) navigatingthrougthecloud.com
  • 23. Orchestrating the Hybrid Cloud ecosystem 2. Blending legacy, on premise and other IT systems • The cost of building the integration points may exceed the cost of your Cloud application • What are the business requirements for: • Data integration  Drives enterprise data matching  Dashboards and ‘Business Intelligence’  ...... And so on • Application integration  Do you want to create an integrated user experience? – ie: Single screen rather than having a use a myriad of screens from different systems navigatingthrougthecloud.com
  • 24. Orchestrating the Hybrid Cloud ecosystem 3. Localised Clouds leading to federated IT / Cloud Silos • Organisations with poor ITBusiness engagement and alignment facilitate the growth of local cloud applications that: • Meet a local business need • Are easily managed by the local ‘owner’ navigatingthrougthecloud.com
  • 25. Orchestrating the Hybrid Cloud ecosystem 4. Local optimum vs. Global optimum • What’s good for a local instance may be save time, cost, etc • Does this approach scale? • Factored in costs, effort and risks of Administering multiple systems? • Centralise Decentralise discussion starts all over again • Take an evolutionary approach? • Do you only mandate in the case of risk, privacy, security? navigatingthrougthecloud.com
  • 26. Orchestrating the Hybrid Cloud ecosystem 5. Hybrid architectures including hybrid security model • How do you manage security in a federated, distributed model? navigatingthrougthecloud.com
  • 27. Orchestrating the Hybrid Cloud ecosystem 6. Potential points of conflicts with CSO / CFO / CIO / COO • Gain consensus from all stakeholders in your organisation on the settings for enterprise risk, governance including • Compliance, discovery, forensics, logging and fault finding challenges 7. Enterprise data warehousing and integration • Network speeds and related considerations 8. Enterprise data warehousing and ‘Big Data’ • Quo Vadis? navigatingthrougthecloud.com
  • 28. Some risk mitigation approaches • Be crystal clear on the drivers behind Cloud for the organisation. • Understand and accurately map the solution to the organisation’s legislative, regulatory and compliance environment • Know the minimum privacy, security and data jurisdictional needs clearly. • Map to the organisation’s potential client’s regulatory environments if needed • Resolve integration complexities – Map cost exposures in cloud brokerage and integration environments navigatingthrougthecloud.com
  • 29. Some risk mitigation approaches • Assess the volatility of your cloud provider’s ecosystem – What will your provider look like in 2 years time? • Delivery through Service Value Chains means that the weakest link effect is to be recognised and managed • Identify inconsistencies in Security, Privacy, Governance, Regulatory compliance through the Cloud provider’s chain • Confirm executive accountabilies for risk! Reshape the role of your IT Department • Shift from a technology provider to a Services broker • Differing skills mix for in-house IT • Technology enabled business services is the direction to take for enterprise IT navigatingthrougthecloud.com
  • 30. Some risk mitigation approaches • Perform your own due diligence, and seek absolutely independent, experienced, financially disinterested advice if needed • Stress test your business case by: – Conducting a sensitivity analysis for feasible business, legal and operational scenarios – Pricing in risk – Defining and costing your exit strategy for each stage of the life cycle in your Cloud – Defining the Cloud roles and accountabilities clearly. E.g. How do they compare to the roles defined in the NIST CCRA? navigatingthrougthecloud.com
  • 31. Subscribe to my Podcast Channel – Interviews, Discussions and independence + PDF Transcripts navigatingthrougthecloud.com
  • 32. QUESTIONS / DISCUSSION ROB LIVINGSTONE - PRINCIPAL, Rob Livingstone Advisory Pty Ltd, and - Fellow, University of Technology, Sydney Rob Livingstone Advisory Pty Ltd ABN 41 146 643 165 W1: www.rob-livingstone.com W2: www.navigatingthroughthecloud.com E: rob@rob-livingstone.com P: +61 2 8005 1972 P: +1 609 843 0349 M: +61 419 632 673 F: +61 2 9879 5004 rladvisory © All rights reserved. Unauthorised redistribution not without prior approval navigatingthrougthecloud.com