A long comment I had to cut down in response to this post on Open Source. Highly recommended.
Cameron,
Very good run-down of 'Why FOSS" - standing on the Shoulders of Giants.
Where bugs become either a Shared problem or "Other People's", not a killing 'tarpit'.
Loved the Daniel Pink video:
we're not just about Survival and Profit at any cost.
Thirty Years in I.T. Theories, Ideas, Opinions.... Leveraging knowledge of the past to understand now. @SteveJCbr & stevej.cbr@gmail.com
Showing posts with label business benefits. Show all posts
Showing posts with label business benefits. Show all posts
2016/11/27
2013/01/26
Security: Computer Security for Business Continuity in Healthcare
If you run a Healthcare-realted Business, things changed in the last 6 months...
Ransomware is set to boom [0] and cyber-security is now part of our National Security Plan.
Businesses now have to secure their computers and data just as they secure their premises and goods.
It's not optional, fail to do so and you will go out of business, just when is the question.
Ask yourself this: "If my computers were destroyed, how long could I continue the business? At reduced capacity or at all?", then act accordingly.
i.e. Does anyone around the world see you as a high-value, exploitable target?
Especially those in low-income countries with employment problems: poverty corrupts, not just power or the love of money.
The Internet is defined by its explosive growth: A few For-Profit hackers have noticed Business Ransomware is an ideal way to monetise remote computer attacks & exploits.
The numbers of these attacks will now double every few months as word gets around, new "toolkits" are sold to them and they ramp up their activities.
Every business that can raise $5,000 and relies on its systems and data for daily operations is now in their sights. These people have no morals, ethics or compassion in their work: they want your money and don't care about the damage they cause or the impact of their actions. Appeals to them will fall on deaf ears. Neither believe that a single ransom payment will be the last you'll hear of them. Why would you trust the word of criminals who've already broken in and callously damaged your systems?
Ransomware is set to boom [0] and cyber-security is now part of our National Security Plan.
Businesses now have to secure their computers and data just as they secure their premises and goods.
It's not optional, fail to do so and you will go out of business, just when is the question.
Ask yourself this: "If my computers were destroyed, how long could I continue the business? At reduced capacity or at all?", then act accordingly.
i.e. Does anyone around the world see you as a high-value, exploitable target?
Especially those in low-income countries with employment problems: poverty corrupts, not just power or the love of money.
The Internet is defined by its explosive growth: A few For-Profit hackers have noticed Business Ransomware is an ideal way to monetise remote computer attacks & exploits.
The numbers of these attacks will now double every few months as word gets around, new "toolkits" are sold to them and they ramp up their activities.
Every business that can raise $5,000 and relies on its systems and data for daily operations is now in their sights. These people have no morals, ethics or compassion in their work: they want your money and don't care about the damage they cause or the impact of their actions. Appeals to them will fall on deaf ears. Neither believe that a single ransom payment will be the last you'll hear of them. Why would you trust the word of criminals who've already broken in and callously damaged your systems?
2012/10/05
Unringing the Bell: Impact of IT systems on Large Business Survival
I've posited that Telstra will be severely challenged within 15 years due to Structural Change within their Industry. They aren't fast or agile enough to adapt to the new world..
What are the factors that will prevent them from adapting? My top two:
Whilst "Management" and descriptions and theories about it has become an increasingly large field of study, we don't have a "Science of Management" with precisely defined and measurable terms.
This is crucially important when ownership (shareholders) and control (managers) is separated. The owners have no nuanced, standardised measures to evaluate the most critical part of the business: management. All we've got is the Accounting Standard Reports provided in Annual Reports. This is far from enough to make informed decisions on a business' future prospects.
I can't detail or quantify the many problems of Telstra's Management Culture, just waive my hands and say "it's the vibe". E.g. they not only don't do Customer Service well, they prioritise short-term cost-savings above good service and seem to go to great lengths to not resolve customer faults, at least in some areas.
Management is about doing what's important consistently well, doing what has to be done well enough and not doing at all the things that don't need to be done. [And avoiding entirely the things that should never be done.]
My Professional expertise is in IT Infrastructure. I hold a contrary view to the mainstream Management view of "IT is a Cost Centre". IT provides automated Business Processes, like employees directly responsible for all the Business Revenues: IT is a Profit Centre, not Cost Centre.
We've already seen businesses failure due to their failed I.T. systems: One.Tel is a shining example.
IT Infrastructure has, for the last two decades at least, constrained business mergers. If I recall correctly, the St. George-Westpac merger was cancelled twice due to "incompatible IT systems". Not sure how they solved that in the end.
Westpac itself is notorious for a decade long project, CS90, that was cancelled in December 1990. It was meant to be the ultimate Banking System (an 'ERP') that IBM would resell around the world for them. It was consuming 5-10% of Westpac's operational revenue.
The $10B Telstra "IT Transformation" under Greg Winn ran for around 5 years with the intention of reducing 1500 systems to 300. It failed to meet its targets and went live in 2009 with the 30% most valuable customers not migrated [from my Case Study evidence, now full of migration errors.]
The point: large businesses are inextricably intertwined with their IT Systems - they are part of the Business DNA and essential to the Business Differentiation: What we do differently that people value.
Too often IT Systems are allowed to "grow like topsy" and are never rationalised or reorganised, presumably because no immediate savings or value can be demonstrated, but mostly because nobody is responsible for everything and ensuring IT Systems are well maintained and suitable.
Leading to "Big Bang" projects like Telstra embracing of off-the-shelf ERP and CRM systems to resolve the mess. Inevitably they find that things are much more complex and intertwined than they knew, not the least because they have no correct, current System Maps and the whole was never designed or planned, it just happened. All of which suggests Management asleep at the wheel.
It will probably take Telstra 10 years to get staff trained, most, not all, data corrected in their new systems and workaround established to cater for what the new systems don't do.
But what will it be left with then? Will those systems be nimble, quick and responsive or big, cumbersome and so hard to change as to be effectively frozen?
Young, small companies start small and add functions as needed: the I.T. equivalent of "greenfields".
They don't carry of a legacy or mindset of "we have to cope with everyone and everything".
This is the commercial advantage small ISP's had over Telstra: no past, no baggage, just simple effective systems.
This will be the problem that Telstra will have to face again in 2020 as Retail Providers using the NBN challenge it. Telstra knows the pain, cost and delay in redoing their I.T. Systems, they won't be going there again anytime soon.
This is a generic and on-going challenge for all successful businesses, including those small, nimble Retail Providers: how to keep I.T. Systems from degrading into an unchangeable morass?
When Data hardens in Organisational Arteries and structures/processes ossify, a major Cardiac event will follow... More of the Same cannot fix the problems, radical rethinking is needed.
In an increasingly automated world, a problem looms for every large business: what happens to the IT Systems when you downsize?
You get to drag the big, bloated corpse of yesterdays organisation along with you. It never gets better with age...
It's easy to lay-off staff and "reorganise", but I've never heard of any organisation looking to make commensurate simplifications to their I.T. systems.
I suspect that Large Business who aren't consciously and deliberately cleaning-up and refreshing their I.T. Systems will ultimately fail due to the complexity, inflexibility and inadequacy of their Legacy Systems.
You can lay off Staff and cut whole Departments, but where do you start with the weeds that permeate your whole organisation and choke the life out of it?
Once built, it seems you can't "Unring the Bell" of legacy I.T. systems, you're stuck with them and they define what you can do, while smaller companies whizz past you on their way to Market Domination and being strangled by their Legacy systems.
Jerry Gregoire as CIO of Dell Computers in 1999 talked about how he tackled this problem - and won.
When he joined Dell, there was a massive ERP project underway, "One System To Rule Them All". It was late, over-budget and failing. His first action was to cancel the project and front the board...
Instead, he moved Dell to a new architecture dubbed "G2", based around a message broker.
It reduces the N*N-1 or N-factorial system interface problem to one...
All every system needs to interact with every other system is one 'message broker' interface.
It comes with a cost - you need infrastructure and rule sets to switch the messages. But at least that's a known, computable cost.
Dell Business Strategy Secrets
An ERP Package for You...and You...and You...and Even You
What are the factors that will prevent them from adapting? My top two:
- Management Culture
- IT Infrastructure
Whilst "Management" and descriptions and theories about it has become an increasingly large field of study, we don't have a "Science of Management" with precisely defined and measurable terms.
This is crucially important when ownership (shareholders) and control (managers) is separated. The owners have no nuanced, standardised measures to evaluate the most critical part of the business: management. All we've got is the Accounting Standard Reports provided in Annual Reports. This is far from enough to make informed decisions on a business' future prospects.
I can't detail or quantify the many problems of Telstra's Management Culture, just waive my hands and say "it's the vibe". E.g. they not only don't do Customer Service well, they prioritise short-term cost-savings above good service and seem to go to great lengths to not resolve customer faults, at least in some areas.
Management is about doing what's important consistently well, doing what has to be done well enough and not doing at all the things that don't need to be done. [And avoiding entirely the things that should never be done.]
My Professional expertise is in IT Infrastructure. I hold a contrary view to the mainstream Management view of "IT is a Cost Centre". IT provides automated Business Processes, like employees directly responsible for all the Business Revenues: IT is a Profit Centre, not Cost Centre.
We've already seen businesses failure due to their failed I.T. systems: One.Tel is a shining example.
IT Infrastructure has, for the last two decades at least, constrained business mergers. If I recall correctly, the St. George-Westpac merger was cancelled twice due to "incompatible IT systems". Not sure how they solved that in the end.
Westpac itself is notorious for a decade long project, CS90, that was cancelled in December 1990. It was meant to be the ultimate Banking System (an 'ERP') that IBM would resell around the world for them. It was consuming 5-10% of Westpac's operational revenue.
The $10B Telstra "IT Transformation" under Greg Winn ran for around 5 years with the intention of reducing 1500 systems to 300. It failed to meet its targets and went live in 2009 with the 30% most valuable customers not migrated [from my Case Study evidence, now full of migration errors.]
The point: large businesses are inextricably intertwined with their IT Systems - they are part of the Business DNA and essential to the Business Differentiation: What we do differently that people value.
Too often IT Systems are allowed to "grow like topsy" and are never rationalised or reorganised, presumably because no immediate savings or value can be demonstrated, but mostly because nobody is responsible for everything and ensuring IT Systems are well maintained and suitable.
Leading to "Big Bang" projects like Telstra embracing of off-the-shelf ERP and CRM systems to resolve the mess. Inevitably they find that things are much more complex and intertwined than they knew, not the least because they have no correct, current System Maps and the whole was never designed or planned, it just happened. All of which suggests Management asleep at the wheel.
It will probably take Telstra 10 years to get staff trained, most, not all, data corrected in their new systems and workaround established to cater for what the new systems don't do.
But what will it be left with then? Will those systems be nimble, quick and responsive or big, cumbersome and so hard to change as to be effectively frozen?
Young, small companies start small and add functions as needed: the I.T. equivalent of "greenfields".
They don't carry of a legacy or mindset of "we have to cope with everyone and everything".
This is the commercial advantage small ISP's had over Telstra: no past, no baggage, just simple effective systems.
This will be the problem that Telstra will have to face again in 2020 as Retail Providers using the NBN challenge it. Telstra knows the pain, cost and delay in redoing their I.T. Systems, they won't be going there again anytime soon.
This is a generic and on-going challenge for all successful businesses, including those small, nimble Retail Providers: how to keep I.T. Systems from degrading into an unchangeable morass?
When Data hardens in Organisational Arteries and structures/processes ossify, a major Cardiac event will follow... More of the Same cannot fix the problems, radical rethinking is needed.
In an increasingly automated world, a problem looms for every large business: what happens to the IT Systems when you downsize?
You get to drag the big, bloated corpse of yesterdays organisation along with you. It never gets better with age...
It's easy to lay-off staff and "reorganise", but I've never heard of any organisation looking to make commensurate simplifications to their I.T. systems.
I suspect that Large Business who aren't consciously and deliberately cleaning-up and refreshing their I.T. Systems will ultimately fail due to the complexity, inflexibility and inadequacy of their Legacy Systems.
You can lay off Staff and cut whole Departments, but where do you start with the weeds that permeate your whole organisation and choke the life out of it?
Once built, it seems you can't "Unring the Bell" of legacy I.T. systems, you're stuck with them and they define what you can do, while smaller companies whizz past you on their way to Market Domination and being strangled by their Legacy systems.
Jerry Gregoire as CIO of Dell Computers in 1999 talked about how he tackled this problem - and won.
When he joined Dell, there was a massive ERP project underway, "One System To Rule Them All". It was late, over-budget and failing. His first action was to cancel the project and front the board...
Instead, he moved Dell to a new architecture dubbed "G2", based around a message broker.
It reduces the N*N-1 or N-factorial system interface problem to one...
All every system needs to interact with every other system is one 'message broker' interface.
It comes with a cost - you need infrastructure and rule sets to switch the messages. But at least that's a known, computable cost.
Dell Business Strategy Secrets
An ERP Package for You...and You...and You...and Even You
2010/09/12
Business Metrics and "I.T. Event Horizons"
Is there any reason the "Public Service", as we call paid Government Administration in Australia, isn't the benchmark for good Management and Governance??
Summary: This piece proposes 5 simple metrics that reflect, but are not in themselves pay or performance measures for, management effectiveness and competence:
Summary: This piece proposes 5 simple metrics that reflect, but are not in themselves pay or performance measures for, management effectiveness and competence:
- Meeting efficiency and effectiveness,
- Time Planning/Use and Task Prioritisation,
- Typing Speed,
- Tool/I.T. Competence: speed and skill in basic PC, Office Tools and Internet tools and tasks, and
- E-mail use (sent, read, completed, in-progress, pending, never resolved, personal, social, other).
2010/02/27
ICT Productivity and the Failure of Australian Management
Prior Related Posts:
Quantifying the Business Benefits of I.T. Operations
The Triple Whammy - the true cost of I.T. Waste
Force Multipliers - Tools as Physical and Cognitive Amplifiers
I.T. in context
Alan Kohler and Robert Gottleibsen have been writing in "Business Spectator" about the relationship between jobs and Economic Productivity.
They note that the USA has improved productivity in the last year while in Australia it has declined (+4% and -3% respectively). My take on this is: a gross Failure of Australian Management.
There is solid research/evidence that "ICT" is the single largest contributor to both partial and multi-factor Productivity, and is expected to be so for the next 20 years. This is an big issue.
Quantifying the Business Benefits of I.T. Operations
The Triple Whammy - the true cost of I.T. Waste
Force Multipliers - Tools as Physical and Cognitive Amplifiers
I.T. in context
Alan Kohler and Robert Gottleibsen have been writing in "Business Spectator" about the relationship between jobs and Economic Productivity.
They note that the USA has improved productivity in the last year while in Australia it has declined (+4% and -3% respectively). My take on this is: a gross Failure of Australian Management.
There is solid research/evidence that "ICT" is the single largest contributor to both partial and multi-factor Productivity, and is expected to be so for the next 20 years. This is an big issue.
2008/11/29
Gershon Report - Review of Australian FedGovt ICT
The Gershon Review is good solid stuff that doesn't rock the boat, doesn't challenge current methods & thinking, nor show deep understanding of the field.
It has a major omission - it addresses ICT inputs only.
ICT is useful only in what it enables others to do or improve - measuring & improving ICT outputs is completely missing from 'Gershon'.
It doesn't examine the fundamentals of ICT work:
Gershon doesn't address outstanding issues of the IT Profession:
Aviation is controlled by ATSB (Australian Transport Safety Bureau, previously Bureau of Air Safety Investigation [BASI]) and CASA (Civil Aviation Safety Authority). The USA's FAI publishes hard data on all aspects of Aviation - and mostly they improve on every measure every year. This isn't just due to the march of technology - the figures for 'General Aviation' (as opposed to Regular Passenger Transport) plateaued decades ago... This is solid evidence that Aviation as a Profession takes itself seriously - and that commercial operators in one of the most competitive and cut-throat industries understand the commercial imperative of reducing Known Errors.
Aviation shows that profession wide attention to Learning and Improvement isn't just about Soft benefits, but translates into solid business fundamentals. You make more money if you don't repeat Know Errors/Mistakes.
ATSB investigates incidents and looks for Root Causes.
CASA takes these reports and turns them into enforceable guidelines - with direct penalties for individuals, groups and organisations. CASA is also responsible for the continual testing and certification of all licensed persons - pilots, Aircraft Engineers, ...
There are 4 specific areas Gershon could've included to cause real change in the IT Profession - to start the inculturation of Learning & Improvement and the flow-on business gains.
Federal Government accounts for 20% of total Australian IT expenditure. It is the single largest user and purchaser of IT - and uniquely positioned to redefine and change the entire IT profession in Australia.
The ACS describes Gerhon's recommendations as "all aimed at addressing the efficiency of ICT":
Nor does the idea of institutionalising the building/improving the Profession of IT and increasing the Capability/Performance of IT Professionals.
By the DCITA/DBCDE own reports, ICT contributes 75% of productivity improvements: ICT is still the single greatest point of leverage for organisations reducing costs and improving output.
Does getting IT right in Federal Government matter?
Absolutely.
Gershon delivers 'more of the same' and could conceivably achieve its targets of 5% & 10% cost improvement
It has a major omission - it addresses ICT inputs only.
ICT is useful only in what it enables others to do or improve - measuring & improving ICT outputs is completely missing from 'Gershon'.
It doesn't examine the fundamentals of ICT work:
- What is that we do?
How is Computing/IT special or different to anything else? - Why do we do it?
Who benefits from our outputs and How?
- Computing is a "Cognitive Amplifier" allowing tasks to be done {Cheaper, Better, Quicker, More/Bigger}.
- IT is done for a Business Benefit.
Like Marketing, defining how outputs & outcomes are measured and assessed - both in the macro and micro - is one of the most important initial tasks.
Gershon doesn't address outstanding issues of the IT Profession:
- improving individual, organisational and general professional competence and performance.
- Reducing preventable failures, incompetence/ignorance and under-performance.
- Deliberate, directed & focussed effort is required to institute and maintain real Improvement of the Profession. (vs 'profession-al improvement' of practitioners)
- Are there any new ways to stuff things up?
- Is it "efficient, effective, ethical" to allow known Errors, Mistakes, Failures to recur without consequences? [see FMAA s44]
Aviation is controlled by ATSB (Australian Transport Safety Bureau, previously Bureau of Air Safety Investigation [BASI]) and CASA (Civil Aviation Safety Authority). The USA's FAI publishes hard data on all aspects of Aviation - and mostly they improve on every measure every year. This isn't just due to the march of technology - the figures for 'General Aviation' (as opposed to Regular Passenger Transport) plateaued decades ago... This is solid evidence that Aviation as a Profession takes itself seriously - and that commercial operators in one of the most competitive and cut-throat industries understand the commercial imperative of reducing Known Errors.
Aviation shows that profession wide attention to Learning and Improvement isn't just about Soft benefits, but translates into solid business fundamentals. You make more money if you don't repeat Know Errors/Mistakes.
ATSB investigates incidents and looks for Root Causes.
CASA takes these reports and turns them into enforceable guidelines - with direct penalties for individuals, groups and organisations. CASA is also responsible for the continual testing and certification of all licensed persons - pilots, Aircraft Engineers, ...
There are 4 specific areas Gershon could've included to cause real change in the IT Profession - to start the inculturation of Learning & Improvement and the flow-on business gains.
Federal Government accounts for 20% of total Australian IT expenditure. It is the single largest user and purchaser of IT - and uniquely positioned to redefine and change the entire IT profession in Australia.
- Lessons Learned - Root Cause Analysis of Failures/Problems
Dept. Finance 'Gateway Review Process' on Projects.
Needs equivalent of CASA - inspection and enforcement of standards plus penalties/sanctions - Not just reviews and suggested guidelines.
Not just ICT staff, not just FedGovt but their suppliers/vendors/contractors as well.
Without real & timely (personal and organisational) consequences, nothing changes. - Standish 'Chaos Report' equivalent - real stats on IT Projects.
Without solid numbers, nothing can change. - Operational Reviews.
How well does an IT organisation do its work?
Critical Self-assessment isn't possible - exactly the reason work needs to be cross-checked for errors/mistakes/omissions/defects.
C.f. Military Operational Readiness Reviews - done by specialist, impartial experts. - Individual Capability Assessment - equivalent of on-going Pilot etc recertification.
- Research: Quantifying & standardising metrics and models for "Effectiveness".
DCITA/DBCDE on macro-economic results.
The ACS describes Gerhon's recommendations as "all aimed at addressing the efficiency of ICT":
- governance,
- capability,
- ICT spending,
- skills,
- data centres
- sustainable ICT
Nor does the idea of institutionalising the building/improving the Profession of IT and increasing the Capability/Performance of IT Professionals.
By the DCITA/DBCDE own reports, ICT contributes 75% of productivity improvements: ICT is still the single greatest point of leverage for organisations reducing costs and improving output.
Does getting IT right in Federal Government matter?
Absolutely.
Gershon delivers 'more of the same' and could conceivably achieve its targets of 5% & 10% cost improvement
2008/05/28
I.T. Strategic Planning Failures
Sue Bushell asked on "LinkedIn": What are the most common failures in strategic IT planning and how are these best avoided? What best practices in strategic planning are most effective?
My answer:
1. There are no I.T. projects - only Business Projects.
Hence changing the premise of your question:
What are the most common business process failures around I.T. solutions?
[A: Make the business run the project and take the rap if it fails.]
2. I.T. is an Industry, not a Profession.
Proof: Professions Learn: repeating Known and avoidable Errors/Mistakes isn't consequence free, as it is within I.T.
3. The complete lack of History in I.T. - both on macro and micro scales.
4. The fundamental reason IT is used: It's a "cognitive amplifier".
Computing amplifies the effort and output of people, providing results 'Cheaper, Better, Faster'.
On the micro scale, no organisation I've heard of measures this. It's quantitative and should be calculable by any half-reasonable Management Accountant.
On the macro scale, the 'Profession' doesn't have or publish benchmarks on results (i.e. from across many organisations).
5. The 'Profession' doesn't even have a taxonomy of jobs and tasks, let alone any consistent method for evaluating and reporting the competence of, and skill level of, practitioners.
6. The almost complete disconnect between research results and practice. Enough said.
7. [Added]. The general capability of the Profession in general and young I.T. practitioners has declined greatly.
Proof: The increasing number of failed projects attempting to replace 'Legacy Systems'.
E.g. The failed A$200M Federal Government ADCNET project. I worked on the original IBM mainframe system, then found myself 15 years later sitting in the same awful basement not 50 feet away, coding it's replacement. The IBM system took 30-35 man-years (in structured assembler), just the second phase of the ADCNET system had a team of 70 for 1-2 years - and was abandoned. The best description of it is the Federal Court Judgment:
GEC Marconi Systems Pty Limited v BHP Information Technology Pty Limited
Federal Court of Australia
12 February 2003 and 14 July 2003
[2003] FCA 50; [2003] FCA 688
8. [Added] Creating Software is a performance discipline.
You have to both know the theory and be able to create good software.
Who are the Great Heros of Open Source? The guys that demonstrate they can code well.
Like Music, Surgery and Architecture, software requires head and hands to do it well.
9. [Added] Design is Everything.
This is what the Bell Labs Computing Research guys understood and what Microsoft doesn't. They invented the most cloned Operating System in the world - Unix, and then went onto build Plan 9, it's replacement 20 years later - with around 20 man-years. It was created portable and scalable, running on 6 different platforms from day 1. Of course it was incredibly small and blindingly fast. Time has shown it was robust and secure as well.
Not an accident that 15 years later Microsoft spent around 25,000 man-years on 'Longhorn', and then threw it all away! (The infamous 'Longhorn Reset' on 23-Sept-2005 by Jim Allchin)
Then spent the same again to create 'Vista' afresh from the 'Windows Server 2003' codebase.
How could Microsoft not understand what was well known 15 years prior, especially as Microsoft ported Unix to Intel in 1985?
There's more, but that will do for now.
"I.T. Governance" may be part of the Solution, but standards like AS8015 are primarily aimed at allocating blame or pushing all responsibility for failure onto I.T. and abnegating from I.T. any successes.
The 'root cause' of all I.T. failures is trivial to identify, but probably exceedingly hard to fix. These days, almost no projects should fail due to technology limitations - only practitioner and management failures.
The 'root cause' is: Business Management.
Yes, there are many problems with I.T. practitioners, but think about it...
Around 1950, Commercial Computing was born.
Some projects worked, in fact succeeded brilliantly: Man went to the moon on the back of that work just 2 decades later.
And then we have the majority or 'ordinary' projects that fail to deliver, are abandoned or under-deliver...
The first time 'management' commissioned a bunch of 'Bright Young Things' to build The Very Best Computer System Ever, they would naturally believe the nerds and their self-confidence.
After that effort failed, what would the rational approach be to the next project?
Not the usual, "do whatever you want and we'll see", but "you didn't do so well last time, how about we try smaller pieces or doing it differently?"
And when lining up for the third go-round, you'd think competent business managers (the ones writing the cheques) would put the brakes on and say "you haven't shown you can deliver results, we have to manage you closely for your own sakes."
"Fool me once, shame on you. Fool me twice, shame on me."
And who's the cause on the third, fifth, hundredth or thousandth repetition?
The people who keep paying for the same 'ol, same 'ol.
My answer:
1. There are no I.T. projects - only Business Projects.
Hence changing the premise of your question:
What are the most common business process failures around I.T. solutions?
[A: Make the business run the project and take the rap if it fails.]
2. I.T. is an Industry, not a Profession.
Proof: Professions Learn: repeating Known and avoidable Errors/Mistakes isn't consequence free, as it is within I.T.
3. The complete lack of History in I.T. - both on macro and micro scales.
- Show me any large organisation that can even list all its current projects, which is a necessary starting point for:
- Formal "Lessons Learned" from projects and operations - known problems are avoided, known effective practices are used.
- Jerry Weinberg wrote definitive works on Software Quality Management and 35 years ago proved that focusing on Quality results in better code, written far faster & cheaper. And it is much more reliably and consistently produced!
- Jim Johnson of Standish Group, nearly 15 years ago started definitive research on what proportion of IT Business Projects fail and the causes of failure. This work is fundamental to advancing the Profession - but nobody else studies this field so his results can't be verified or refuted. Nor have organisations or practitioners, by-and-large, acted on this knowledge. People do argue that his results are suspect because other single-shot reports don't agree. But nothing happens to resolve this fundamental issue!
- Software ReUse is notable in how little it is practiced. Can it be possible that nearly ever problem is completely new? Not in my experience.
4. The fundamental reason IT is used: It's a "cognitive amplifier".
Computing amplifies the effort and output of people, providing results 'Cheaper, Better, Faster'.
On the micro scale, no organisation I've heard of measures this. It's quantitative and should be calculable by any half-reasonable Management Accountant.
On the macro scale, the 'Profession' doesn't have or publish benchmarks on results (i.e. from across many organisations).
5. The 'Profession' doesn't even have a taxonomy of jobs and tasks, let alone any consistent method for evaluating and reporting the competence of, and skill level of, practitioners.
- In a construction project you wouldn't specify "10 vehicles needed", you say "6 5-tonne trucks, 2 utes, a 20-tonne tip-truck and a bobcat".
- If the profession can't distinguish between the speciality, competence and skill levels of its practitioners, how can the business folk?
- If project plans don't identify the necessary the precise skills needed - implying some way to assess and rate the 'degree of difficulty' of individual tasks/components - then the right 'resources' can't be applied.
6. The almost complete disconnect between research results and practice. Enough said.
7. [Added]. The general capability of the Profession in general and young I.T. practitioners has declined greatly.
Proof: The increasing number of failed projects attempting to replace 'Legacy Systems'.
E.g. The failed A$200M Federal Government ADCNET project. I worked on the original IBM mainframe system, then found myself 15 years later sitting in the same awful basement not 50 feet away, coding it's replacement. The IBM system took 30-35 man-years (in structured assembler), just the second phase of the ADCNET system had a team of 70 for 1-2 years - and was abandoned. The best description of it is the Federal Court Judgment:
GEC Marconi Systems Pty Limited v BHP Information Technology Pty Limited
Federal Court of Australia
12 February 2003 and 14 July 2003
[2003] FCA 50; [2003] FCA 688
8. [Added] Creating Software is a performance discipline.
You have to both know the theory and be able to create good software.
Who are the Great Heros of Open Source? The guys that demonstrate they can code well.
Like Music, Surgery and Architecture, software requires head and hands to do it well.
9. [Added] Design is Everything.
This is what the Bell Labs Computing Research guys understood and what Microsoft doesn't. They invented the most cloned Operating System in the world - Unix, and then went onto build Plan 9, it's replacement 20 years later - with around 20 man-years. It was created portable and scalable, running on 6 different platforms from day 1. Of course it was incredibly small and blindingly fast. Time has shown it was robust and secure as well.
Not an accident that 15 years later Microsoft spent around 25,000 man-years on 'Longhorn', and then threw it all away! (The infamous 'Longhorn Reset' on 23-Sept-2005 by Jim Allchin)
Then spent the same again to create 'Vista' afresh from the 'Windows Server 2003' codebase.
How could Microsoft not understand what was well known 15 years prior, especially as Microsoft ported Unix to Intel in 1985?
There's more, but that will do for now.
"I.T. Governance" may be part of the Solution, but standards like AS8015 are primarily aimed at allocating blame or pushing all responsibility for failure onto I.T. and abnegating from I.T. any successes.
The 'root cause' of all I.T. failures is trivial to identify, but probably exceedingly hard to fix. These days, almost no projects should fail due to technology limitations - only practitioner and management failures.
The 'root cause' is: Business Management.
Yes, there are many problems with I.T. practitioners, but think about it...
Around 1950, Commercial Computing was born.
Some projects worked, in fact succeeded brilliantly: Man went to the moon on the back of that work just 2 decades later.
And then we have the majority or 'ordinary' projects that fail to deliver, are abandoned or under-deliver...
The first time 'management' commissioned a bunch of 'Bright Young Things' to build The Very Best Computer System Ever, they would naturally believe the nerds and their self-confidence.
After that effort failed, what would the rational approach be to the next project?
Not the usual, "do whatever you want and we'll see", but "you didn't do so well last time, how about we try smaller pieces or doing it differently?"
And when lining up for the third go-round, you'd think competent business managers (the ones writing the cheques) would put the brakes on and say "you haven't shown you can deliver results, we have to manage you closely for your own sakes."
"Fool me once, shame on you. Fool me twice, shame on me."
And who's the cause on the third, fifth, hundredth or thousandth repetition?
The people who keep paying for the same 'ol, same 'ol.
2008/02/08
The Open Source Business Model
This post by Dana Blankenhorn on ZDnet is the best answer I've seen to the question "Why Open Source?".
He says 'plumbing', I'd say '(Unix|Open Source) is the Universal Glue'.
And the on-going Open Source Business Model is "support" for those that need/want 'certainty'.
Which if you are the CIO (read: 'my arse is on the line') for somewhere with a high dependence on I.T., is only Good Governance (or "common sense"). You can't make key staff stay, nor mandate they never get sick or burn-out and "go sit on a beach" - and after '9/11', all Business Continuity plans have to account for covering people as well as systems and networks.
That's it - Business I.T. is all about the Data (or "all about XXX, stupid" to be Clintonesque).
Open Source tools are usually about manipulating data or providing services - like Apache, e-mail, DNS, firewalls and IDS, ...
Open Source is here to stay: use it, don't deny or fight it.
This Business Model, 'support for essential tools', is robust and on-going.
Whatever systems you use in the Data Center, you'll always have the need to provide many services and interface disparate systems and data formats.
The model also applies to embedded 'Appliances' and dedicated devices, like firewalls - or commercial web-hosting services. They are based in whole or part on Open Source.
You'll note this model has very limited application to the client-side - the 'Desktop' or End-User compute platform.
"Free Software" from GNU et al is about an ideological stance and subsumes all other goals to this.
"Open Source" is pragmatic and about getting on with the job. It makes sense for large vendors, like IBM and HP, to support it. Customers can feel confident and secure - because the source and tool-chain are freely available from multiple sites, they cannot be held to ransom or 'orphaned' by unpredictable events or capricious decisions.
"Open Source" starts from the premise that "IT is done for a Business Benefit" - that you build software, systems and services for the use of others, not your own amusement and benefit.
Business supporting software has to meet Professional standards/criteria - good design, clear documentation, reliability, robustness and very few errors/defects - with the unstated driver of Continuous Improvement.
Never new features for their own sake or to create 'forced upgrades', always making the code more stable, usable and useful.
Commercial considerations, by definition, are always subsidiary to technical. If the user community doesn't like changes - they aren't forced to upgrade and in an extreme case, can 'fork' the code, internally or publicly: just do it how they want.
He says 'plumbing', I'd say '(Unix|Open Source) is the Universal Glue'.
And the on-going Open Source Business Model is "support" for those that need/want 'certainty'.
Which if you are the CIO (read: 'my arse is on the line') for somewhere with a high dependence on I.T., is only Good Governance (or "common sense"). You can't make key staff stay, nor mandate they never get sick or burn-out and "go sit on a beach" - and after '9/11', all Business Continuity plans have to account for covering people as well as systems and networks.
That's it - Business I.T. is all about the Data (or "all about XXX, stupid" to be Clintonesque).
Open Source tools are usually about manipulating data or providing services - like Apache, e-mail, DNS, firewalls and IDS, ...
Open Source is here to stay: use it, don't deny or fight it.
This Business Model, 'support for essential tools', is robust and on-going.
Whatever systems you use in the Data Center, you'll always have the need to provide many services and interface disparate systems and data formats.
The model also applies to embedded 'Appliances' and dedicated devices, like firewalls - or commercial web-hosting services. They are based in whole or part on Open Source.
You'll note this model has very limited application to the client-side - the 'Desktop' or End-User compute platform.
"Free Software" from GNU et al is about an ideological stance and subsumes all other goals to this.
"Open Source" is pragmatic and about getting on with the job. It makes sense for large vendors, like IBM and HP, to support it. Customers can feel confident and secure - because the source and tool-chain are freely available from multiple sites, they cannot be held to ransom or 'orphaned' by unpredictable events or capricious decisions.
"Open Source" starts from the premise that "IT is done for a Business Benefit" - that you build software, systems and services for the use of others, not your own amusement and benefit.
Business supporting software has to meet Professional standards/criteria - good design, clear documentation, reliability, robustness and very few errors/defects - with the unstated driver of Continuous Improvement.
Never new features for their own sake or to create 'forced upgrades', always making the code more stable, usable and useful.
Commercial considerations, by definition, are always subsidiary to technical. If the user community doesn't like changes - they aren't forced to upgrade and in an extreme case, can 'fork' the code, internally or publicly: just do it how they want.
2007/12/29
IBM, Outsourcing and the IT Profession
This is a reaction to Robert X. Cringely's "Pulpit" of 28-Dec-2007:
Leaner and Meaner Still: IBM's U.S. operations continue to shrivel.
There are 3 parts to my comments:
They are interlinked. Lou Gertsner set IBM on the road on "Services" and away from Mainframes. It looked promising.
IT Services look very appealing on the Balance Sheet - nearly no investment (no tangible assets) and what seem to be good profits from turnover. The ROA and ROI (Return on Assets and Return on Investment) look great - until you take some other factors into account.
Quality is not 'gold-plating' - it is central to improving productivity, reducing waste and fulfilling customer expectations. These are the drivers for growth, profitability and sustainability - not penny-pinching and cost-cutting.
IT Services companies cannot, and will not, pursue Excellence & Quality if they are not driven to it.
It is only their Clients who can hold them accountable and force a change.
Concurrently, IT has to evolve from an Industry to a Profession so that managers can realistically evaluate the performances of different practitioners. It's not hard to win new business and make good profits if your employees are 10 times more productive than your competitions.
Answering the poll question: Will IBM survive?
Lou Gertsner turned IBM around, starting 1993.
It took an outsider to do it - and the board knew that.
His legacy, after leaving in 2002, should've been a company with a solid future. Five years on, it appears not so - that can only be "Corporate Culture".
IBM is far too important to be let fail and broken up in a firesale.
But we have a perfect model for the future of Cringely's "lumbering giant": Unisys.
In 1986, Numbers 2&3 in the market (Burroughs & Sperry Univac) combined and produced a dud. It's still alive, but failing. Because enough people use their mainframes (2200's and A-series), they can't be allowed to die. Slowly withering on the vine seems to be fine.
Fujitsu is the perfect vacuum-cleaner to buy the hardware business in the final break-up.
IBM GSA and the other 'Tier 1' outsourcers operate from the same playbook - a version of 'bait and switch'. Also known as "The Value Prevention Society".
I've worked with and for all the major outsourcers in Australia. They all bid low to win contracts and adopt a dual strategy of "controlling costs" and price gouging for "variations".
'Controlling costs' is reducing staff, replacing competent staff with 'cheap and cheerful' newbies, not performing maintenance and avoiding capital investment.
What's wrong with a 5-10 year-old system? Nothing if you don't have to suffer the performance and other problems!
They routinely ignore contract provisions - like scheduled roll-outs of new desktops, upgrades and system performance targets.
The problems are at least three-fold:
- inequality of parties (Outsourcer vs Client)
- internal 'manager' performance has no upside, only downside
- no impartial umpire and effective 'stick' to enforce system performance targets
Inequality
Every company that signs an IT Outsourcing agreement signs just one. The outsourcers has done this many, many times before.
Clients also don't factor in the increased staff and reporting costs - each side needs additional staff for 'contract management'.
The Client thinks it has stitched up an iron-clad contract and they forecast a bountiful harvest... Which doesn't happen.
Service degrades, minor works become hugely expensive, major works take forever and often don't get implemented.
The business people give-up and adapt around it.
In Australia, all the major EDS contracts let around 10 years ago are now being re-tendered - with EDS getting very little of the new work.
Are they the worst? Hard to say...
Aligning internal rewards with Client Needs
Outsourcer 'managers' can only be assessed on monetary performance. With fixed price contracts, base income is fixed.
If a manager reduces costs 5% one year, this becomes the expectation for every following year - it is not seen as a 'one-off'. Without significant staff training and capital expenditure, this quickly becomes impossible without sacrificing service quality. Commercial systems are quite reliable these days. For existing stable systems, 'Do nothing' is good for at least 3 years - then you are in deep trouble.
The only ways to increase profits are to reduce expenses or increase non-base income.
Every service request is deemed a 'change' and subject to the full, heavyweight, project evaluation methodology. No project, not even buying a simple standalone appliance, takes under 4 man-weeks ($20-50,000). For the client, this stifles change/innovation (or forces it underground) and these additional costs overshadow most systems costs.
Capital expenditures are worse. Payback has to be within 12-18 months - and it has to beat 'do nothing'.
Since the 2003 slowdown in Moores' Law for CPU speed, the problem has compounded.
Take a 5 year-old file server that is now close to saturated most of the day. It is not yet 'end of life' and maintenance costs still low.
Because file open/close, read/write performance is not specified and the system is "available" during work hours, the Client cannot complain.
The Operating System (O/S) may be old and need constant attention, updates and reboots - but they are part of the normal admin workload, so not an 'additional' cost. Salaried staff as 'professionals' must work any unpaid overtime that is demanded.
Any proposal to replace the server or upgrade it has to pass a simple, and reasonable, test:
'Do nothing' is the benchmark - for zero capital expenditure and a few extra unpaid admin hours, a service is provided that brings in the service full revenue - and will continue to do so. That's a very tough argument to beat.
Only when the client funds the replacement, hardware maintenance costs are high enough, an O/S upgrade is required for security or compatibility or qualified admin staff move on will the system be upgraded. And then it will begin the same inevitable slide into entropy and uselessness.
Finding solutions that benefit the customer and reduce operating expenses are career suicide for outsourcing staff in a culture focussed on increasing billables.
For example: a major Australian bank replaced all the local file servers with small Network Appliance NAS's. These are the most expensive product per Gb available. The outsourcer had charged ~$2,500/month to 'administer' these systems. The bank paid for the change in under a year, increased availability and performance and solving many other issues to boot.
If the client gives all its IT staff to the outsourcer, who is going to seek out, design and implement new cost saving technology/systems?
Not the outsourcer - it's not in the contract and not in its (short term) interests.
The client has no IT staff - so it cannot and doesn't happen.
Audits and an Impartial Umpire
Who reports to the Client on the performance of their systems?
Who has the training/qualifications to check and asses the metrics and reports?
Who maintains & audits the basis of payments - the asset register?
Only the Outsourcer.
What are the downsides to the Outsourcer of a major failure in Prime Time?
A small number of 'service credits'.
Meanwhile, the Client suffers real costs and potentially large losses.
The Client wears all the business and financial risk with only minor penalties to the Outsourcer.
We are yet to see a corporate collapse due to an outsourcers IT failures - but it is only a matter of time.
There is a clear conflict of interest, or an real Agency Theory problem.
The outsourcer is Judge, Jury and Executioner...
There is no way to hold them to account or dispute their figures.
The huge (100+:1) variability in individual competence and the inability to measure it is one of the worst problems in our industry.
IT is not a 'Profession'. It, like 'Management', fail a very simple test:
Mostly it is "fire/blame the innocent, promote the guilty". The exact inverse of what you'd want.
People may trump technology and process, but Politics trumps everything...
And our Professional Bodies don't help.
The only real research into the causes of Project Failure are by consultancies - who are driven by the ability to sell their products, not what will benefit the Profession.
The ACM, IEEE, IFIP and friends have abrogated their responsibilities. We on the firing line, get to suffer their inaction.
Managers have to go with what they can quantify and inspect. Good managers will see through the B/S - but mostly too little, too late. Mostly, office politics, influence and self-promotion rule.
The adversarial nature of Outsourcing and the seemingly universal decline in code and service Quality stems from this failure of IT as a Profession.
Steve Jenkin 29-December-2007
Leaner and Meaner Still: IBM's U.S. operations continue to shrivel.
There are 3 parts to my comments:
- Will IBM Survice?
- Outsourcing
- IT as a Profession
They are interlinked. Lou Gertsner set IBM on the road on "Services" and away from Mainframes. It looked promising.
IT Services look very appealing on the Balance Sheet - nearly no investment (no tangible assets) and what seem to be good profits from turnover. The ROA and ROI (Return on Assets and Return on Investment) look great - until you take some other factors into account.
- Barriers to Entry for competitors are low.
EDS under Ross Perrot came from nowhere to define and dominate the field - so can the next giant in the field.
If your business model is "hire cattle and drive them till they drop" - you have no market differentiation.
Same cattle, same drivers, same pay - same 'ol, same 'ol... The cattle aren't loyal, motivated or engaged.
Writing new contracts is a matter of perception, influence and contacts.
There is so much feeling against IT Outsourcers in business at the moment, the first company to come along and tell a better story will take the field.
The change won't be overnight, but fast enough that the incumbents won't notice until too late.
- Whilst only tangible assets appear on the Balance Sheet, IT Services are driven by your Human Capital and some Intellectual Capital embodied in your processes, branding and IP, such as trademarks and patents.
What value is let in the offices when everybody has gone home? Very, very little.
What is the business risk of a large, sudden exodus of your staff? A competitor may deliberately poach enough to put you in trouble.
It's a failing of the Board not understand this and institute appropriate metrics, accounting and management rewards.
- Profit based on Operations turnover are very fragile/volatile.
Income and Expenses are very large numbers with a small difference. Expenses are mainly employees - which you may not be able to shed as quickly as service contracts expire.
Tendering for new contracts implies you have, or can quickly get, the resources to fulfill the contract. That's an extreme business risk.
The key figures-of-merit are Income/Employee and Profit/Employee.
We don't see those reported or obviously managed.
- IT Services work is Knowledge Work - it is mostly invisible and intangible.
Driving IT staff like unskilled labourers with threats/punishment to lift performance is anti-productive.
Unhappy staff withdraw and pushback. At best they aren't engaged or motivated. They 'do the minimum' - a grudging compliance.
They stop caring about their work, the customer and their employer. And if you are lucky, it stops there.
Hiring bright, capable people doing intangible work and treating them badly is not just a recipe for disaster, it is foolishness writ large.
- IT is a cognitive amplifier and this can be leveraged both within the business and internally in IT.
The only sustainable strategy to deliver improved profits is through investment. - Automating tasks.
Applying our own technology to our jobs to make tasks, not jobs, redundant.
Investing in tools and hardware to increase the both Quality of work
- Building Human Capital.
Investing in the people at the work-face to build their capability and performance.
The SEI's Barry Boehem created COCOMO - a quantitative model for estimating Software costs.
Experienced, competent practitioners not only produce better work, fewer defects, faster - they are cheaper.
- Actively reducing Errors.
Consciously reducing waste, rework and wrong work.
Quality is not about 'doing the minimum', it's a mindset where Errors are allowed, but their repetition is anathema.
High Quality performances are only achieved with deliberate, focussed intention. Not blaming and denial.
Quality Systems only goal is to make it difficult for good people to make mistakes.
Deming said it all with "Plan-Do-Check-Act", or in new-speak: "Preparation - Execution - Review & Evaluation - Improvement" - Learning is central to improving Quality, Performance, Security & Safety and Usability.
Learning systems, processes and procedures takes an investment of time, tools and technology.
Failing to build teams and their capability will decrease expenses in the short-run and will increase them in the long-run.
- Resiling from the classic adversarial stance of IT Outsourcing.
IT is a business enabler. It is now central to normal business operations. It is still where 80% of efficiency improvements arise.
Every act that hurts the client will turn-around and hurt the provider, but more.
The client is earning the income that pays for the IT.
More income, more IT, more outsourcing revenue and profits. A simple equation that seems lost on Outsourcing managers.
Outsourcing contracts need to align the internal management rewards with improving business outcomes for the Client.
What's anathema to current management - reducing Client costs - must be aggressively pursued to create a long-term Outsourcing business.
Quality is not 'gold-plating' - it is central to improving productivity, reducing waste and fulfilling customer expectations. These are the drivers for growth, profitability and sustainability - not penny-pinching and cost-cutting.
IT Services companies cannot, and will not, pursue Excellence & Quality if they are not driven to it.
It is only their Clients who can hold them accountable and force a change.
Concurrently, IT has to evolve from an Industry to a Profession so that managers can realistically evaluate the performances of different practitioners. It's not hard to win new business and make good profits if your employees are 10 times more productive than your competitions.
Will IBM Survive?
Answering the poll question: Will IBM survive?
Lou Gertsner turned IBM around, starting 1993.
It took an outsider to do it - and the board knew that.
His legacy, after leaving in 2002, should've been a company with a solid future. Five years on, it appears not so - that can only be "Corporate Culture".
IBM is far too important to be let fail and broken up in a firesale.
But we have a perfect model for the future of Cringely's "lumbering giant": Unisys.
In 1986, Numbers 2&3 in the market (Burroughs & Sperry Univac) combined and produced a dud. It's still alive, but failing. Because enough people use their mainframes (2200's and A-series), they can't be allowed to die. Slowly withering on the vine seems to be fine.
Fujitsu is the perfect vacuum-cleaner to buy the hardware business in the final break-up.
Outsourcing
IBM GSA and the other 'Tier 1' outsourcers operate from the same playbook - a version of 'bait and switch'. Also known as "The Value Prevention Society".
I've worked with and for all the major outsourcers in Australia. They all bid low to win contracts and adopt a dual strategy of "controlling costs" and price gouging for "variations".
'Controlling costs' is reducing staff, replacing competent staff with 'cheap and cheerful' newbies, not performing maintenance and avoiding capital investment.
What's wrong with a 5-10 year-old system? Nothing if you don't have to suffer the performance and other problems!
They routinely ignore contract provisions - like scheduled roll-outs of new desktops, upgrades and system performance targets.
The problems are at least three-fold:
- inequality of parties (Outsourcer vs Client)
- internal 'manager' performance has no upside, only downside
- no impartial umpire and effective 'stick' to enforce system performance targets
Inequality
Every company that signs an IT Outsourcing agreement signs just one. The outsourcers has done this many, many times before.
Clients also don't factor in the increased staff and reporting costs - each side needs additional staff for 'contract management'.
The Client thinks it has stitched up an iron-clad contract and they forecast a bountiful harvest... Which doesn't happen.
Service degrades, minor works become hugely expensive, major works take forever and often don't get implemented.
The business people give-up and adapt around it.
In Australia, all the major EDS contracts let around 10 years ago are now being re-tendered - with EDS getting very little of the new work.
Are they the worst? Hard to say...
Aligning internal rewards with Client Needs
Outsourcer 'managers' can only be assessed on monetary performance. With fixed price contracts, base income is fixed.
If a manager reduces costs 5% one year, this becomes the expectation for every following year - it is not seen as a 'one-off'. Without significant staff training and capital expenditure, this quickly becomes impossible without sacrificing service quality. Commercial systems are quite reliable these days. For existing stable systems, 'Do nothing' is good for at least 3 years - then you are in deep trouble.
The only ways to increase profits are to reduce expenses or increase non-base income.
Every service request is deemed a 'change' and subject to the full, heavyweight, project evaluation methodology. No project, not even buying a simple standalone appliance, takes under 4 man-weeks ($20-50,000). For the client, this stifles change/innovation (or forces it underground) and these additional costs overshadow most systems costs.
Capital expenditures are worse. Payback has to be within 12-18 months - and it has to beat 'do nothing'.
Since the 2003 slowdown in Moores' Law for CPU speed, the problem has compounded.
Take a 5 year-old file server that is now close to saturated most of the day. It is not yet 'end of life' and maintenance costs still low.
Because file open/close, read/write performance is not specified and the system is "available" during work hours, the Client cannot complain.
The Operating System (O/S) may be old and need constant attention, updates and reboots - but they are part of the normal admin workload, so not an 'additional' cost. Salaried staff as 'professionals' must work any unpaid overtime that is demanded.
Any proposal to replace the server or upgrade it has to pass a simple, and reasonable, test:
How much extra revenue will we make? How long will the payback period be?
'Do nothing' is the benchmark - for zero capital expenditure and a few extra unpaid admin hours, a service is provided that brings in the service full revenue - and will continue to do so. That's a very tough argument to beat.
Only when the client funds the replacement, hardware maintenance costs are high enough, an O/S upgrade is required for security or compatibility or qualified admin staff move on will the system be upgraded. And then it will begin the same inevitable slide into entropy and uselessness.
Finding solutions that benefit the customer and reduce operating expenses are career suicide for outsourcing staff in a culture focussed on increasing billables.
For example: a major Australian bank replaced all the local file servers with small Network Appliance NAS's. These are the most expensive product per Gb available. The outsourcer had charged ~$2,500/month to 'administer' these systems. The bank paid for the change in under a year, increased availability and performance and solving many other issues to boot.
If the client gives all its IT staff to the outsourcer, who is going to seek out, design and implement new cost saving technology/systems?
Not the outsourcer - it's not in the contract and not in its (short term) interests.
The client has no IT staff - so it cannot and doesn't happen.
Audits and an Impartial Umpire
Who reports to the Client on the performance of their systems?
Who has the training/qualifications to check and asses the metrics and reports?
Who maintains & audits the basis of payments - the asset register?
Only the Outsourcer.
What are the downsides to the Outsourcer of a major failure in Prime Time?
A small number of 'service credits'.
Meanwhile, the Client suffers real costs and potentially large losses.
The Client wears all the business and financial risk with only minor penalties to the Outsourcer.
We are yet to see a corporate collapse due to an outsourcers IT failures - but it is only a matter of time.
There is a clear conflict of interest, or an real Agency Theory problem.
The outsourcer is Judge, Jury and Executioner...
There is no way to hold them to account or dispute their figures.
The Profession of IT
Contributors Michael Ellis, BJ, Kevin James, Richard Steven Hack,... started a thread about the 'value'/competency of individual IT practitioners.The huge (100+:1) variability in individual competence and the inability to measure it is one of the worst problems in our industry.
IT is not a 'Profession'. It, like 'Management', fail a very simple test:
What are the personal and organisational consequences of repeating, or allowing to be repeated, a known error, fault or failure??
[Do your mistakes have clear 'consequences' professionally?']
[Do your mistakes have clear 'consequences' professionally?']
Mostly it is "fire/blame the innocent, promote the guilty". The exact inverse of what you'd want.
People may trump technology and process, but Politics trumps everything...
And our Professional Bodies don't help.
The only real research into the causes of Project Failure are by consultancies - who are driven by the ability to sell their products, not what will benefit the Profession.
The ACM, IEEE, IFIP and friends have abrogated their responsibilities. We on the firing line, get to suffer their inaction.
Managers have to go with what they can quantify and inspect. Good managers will see through the B/S - but mostly too little, too late. Mostly, office politics, influence and self-promotion rule.
The adversarial nature of Outsourcing and the seemingly universal decline in code and service Quality stems from this failure of IT as a Profession.
Steve Jenkin 29-December-2007
2007/05/02
Defining I.T. Service Management
Objectives (The What)
Having begun around 1950, the world of Commercial I.T. is now mature in many ways. "Fields of Work" and professional taxonomies are starting to become standardised. Professional "Best Practices" are being documented and international standards agreed in some areas.
For the first time, audits of one of the most pragmatic I.T. disciplines, "Service Management", are possible with ISO 20,000. Business managers can now get an independent , objective opinion on the state of their I.T. operations - or of their outsourcers.
Being "documented common sense", ITIL and the related ISO 20,000 are good professional guides, but not underpinned by theory. Are there any gaps in the standard? How does Service Management interface with other IT Fields of Work? and What changes in those other disciplines are necessary to support the new audited practice?
Analysis of the full impact of I.T. Service Management, creation of a full taxonomy and definitions of "I.T. Maturity" are beyond the scope of a small "single researcher" project.
Approach (The How)
ITIL Version 2 and 3 and ISO 20,000, as published documents, form the basis of the project.Prior work in the field has yet to be identified. Secondary research will be the first step.
Each of the models will be codified and uniformly described, then a 3-way comparison performed. A Gap Analysis done of the 3 models, and a formal model built describing "I.T. Service Management" and its interfaces built and each of the existing approaches mapped to it.
Importance/Value (The Why)
The global economy, especially businesses in the "Western Industrialised World" are increasingly dependent on I.S./I.T. and their continued efficient operation. Corporate failures partially due to I.S./I.T. failure have occurred. Improving delivery of I.T. Services and the business management and use of them is important to reduce those failures in the future.The advent of ubiquitous and universal computing requires concomitant development of business management.
There assertions are considered axioms in this context:
- Organisations these days are dependent on their I.T. Operations.
- I.T. cuts across all segments of current organisations.
- I.T. defines the business processes and hence productivity of the whole organisation.
- What you don't measure you can't manage and improve.
- Improving the effectiveness of I.T. Operations requires auditable processes.
- Common I.T. Audit and Reporting Standards, like the Accounting Standards, are necessary to contrast and compare the efficiency and effectiveness of I.T. Operations across different organisations or different units within a single organisation.
For simple, repetitive cognitive tasks, computers are 1-5,000 times cheaper than people in western countries.
From this amplification effect, computers still provide the greatest single point of leverage for organisations. The underpin the requirement to "do more with the same", improving productivity and increasing profitability.
The few studies of "IT Efficiency" that are available show that IT effectiveness is highly variable and unrelated to expenditure.
The value-add to business of a complete I.T. Service Management model is two-fold:
- manage down the input costs of the I.T. infrastructure and Operations and,
- audit assurance for the board and management of the continued good performance of I.T. Operations.
[A 1990 HBS or MIT study into "White Collar Productivity" - reported a decrease in the first decade of PC's]
Previous Work (What else)
There is much opinion in the area, without substantive evidence: e.g. Nick Carr and "Does IT Matter?" The McKinsey report/book on European Manufacturers and their I.T. expenditure versus financial performance shows there is no co-relation between effort (expenditure) and effect (financial performance)."Commonsense" IT Practitioner approaches, SOX, ITIL and COBIT and others, do not address the measuring and managing of I.T. outputs and interfaces and their business effects, utiliation and effectiveness.
Jerrry Landsbaum's 1992 work included examples of their regular business reports - quantifiable and repeatable metrics of I.T. Operations phrased in business terms.
Hope to find (The Wherefore)
- Create a formal model for I.T. Operations and its performance within and across similar organisations.
- From the model, generate a standard set of I.T. performance metrics.
- Generate a set of useful I.T. Operations Business Impact metrics.
Report Outline
- Coded process models of ITIL version 2, 3 and ISO 20,000.
- 3-way comparison of ITIL version 2, 3 and ISO 20,000.
- Gap Analysis of ITIL version 2, 3 and ISO 20,000 models.
- Formal I.T. Service Management model.
- Common I.T. Service Management internal metrics and Business Impact
metrics flowing from the model. - Interfaces to other I.T. and business areas and changes necessary to support audits of I.T. Service Management.
- Further Work and Research Questions
Execution Phases
- Learn ITIL Version 2 - Service Managers Certificate course [complete]
- Learn ISO 20,000 - IT Consultants training [in process]
- Acquire and learn ITIL Version 3 [depends on OGC availability. mid/late 2007]
- Create/identify process codification.
- Codify ITIL version 2, 3 and ISO 20,000
- Compare and contrast coded descriptions. Report.
- Create/adapt process description calculus for formal model.
- Create formal I.T. Service Management model.
- Derive interfaces to business and other I.T. processes
- Derive internal metrics, role KPI's and business impact metrics
- Finalise report.
2007/03/20
Quantifying the Business Benefits of I.T. Operations
Objectives (The What)
That "I.T. is done for a Business Benefit" seems axiomatic.
But where's the evidence after 50-60 years of computing? It's not coming out our ears - just the reverse.
Businesses understand the importance of hard data and it's through analysis for marketing, but don't apply the same techniques or management principles to their I.T. Operations.
I'd like to model and quantify the Business Benefits of I.T. Operations across multiple organisations to provide baselines, benchmarks and trend analysis. The impact of all aspects of I.T. is beyond the scope of a single researcher project.
Approach (The How)
Data is fundamental input for analyses. Leveraging what's available means the outputs can be commercially reproduced and aer within the project budget (zero cost).
Three separate data streams will be mined:
- Historic "ITSM" tool data from multiple organisations.
- Detailed I.T. accounting information from selected organisations.
- Primary research in one organisation to collect and report "FTE equivalents provided" by I.T.
[FTE = Full Time Employee. Otherwise, "virtual employees". What head count and cost would be needed to provide similar services with 1965 technology.]
Importance/Value (The Why)
There propositions are to be tested:
- I.T. is done for a Business Benefit.
- Business Benefits, tangible or intangible, should be measurable.
- Organisations these days are dependent on their I.T. Operations.
- I.T. cuts acros all segments of current organisations.
- I.T. defines the business processes and hence productivity of the whole organisation.
- What you don't measure you can't manage and improvve.
- Improving the effectiveness of I.T. Operations requires reliable metrics.
- Commin I.T. Reporting Standards, like the Accounting Standards, are necessary to contrast and compare the efficiency and effectiveness of I.T. Operations across different organisations or different units within a single organisation.
I.T. is a cognitive amplifier, it delivers "cheaper, better, faster, more, all-the-same", through the embedding of finely detailed business processes into electronic (computing) systems.
For simple, repetitive cognitive tasks, computers are 1-5,000 times cheaper than people in western countries.
From this ampflication effect, computers still provide the greatest single point of leverage for organisations. The underpin the requirement to "do more with the same", improving productivity and increasing profitability.
Subtle shifts in this whole-organisation amplification ratio (e.g. from 100:1 to 95:1 or 105:1) are impossible for isolated individuals to detect unaided. But they make very large differences to the 'global' organisation output and productivity.
In retail businesse, the gross margin is often around 2.5%. Reducing whole company productivity by 5% will destroy it's profitability, and without any metrics, will be impossible for any management team to identify and resolve.
The few studies of "IT Efficiency" that are available show that IT effectiveness is highly variable and unrelated to expenditure.
My proposition is that "intuitive management" of IT is stretched well beyond it's useful limits and needs to be replaced by evidence-based management.
The value-add to business is two-fold:
- manage downt he input costs of the I.t. infrastructure and,
- quantify the "cognitive amplifier" effects across the whole organisation to make informed decisions on optimum 'global' investment/expenditure on I.T. Operations.
[There's the 1990 HBS or MIT study into "White Collar Productivity" - reporting a decrease in the first decade of PC's]
Previous Work (What else)
There is a dearth of published material/research in this area.
The "State-of-Practice" is "NEVER DONE".
There is much opnion in the area, without substantive evidence: e.g. Nick Carr and "Does IT Matter?"
"Commonsense" IT Practitioner approaches, ITIL and COBIT (others?), do not address the measuring and managing of I.T. outputs and their business effects, ultilisation and effectiveness.
The McKinsey report/book on European Manufacturers and their I.T. expenditure versus financial performance shows there is no co-relation between effort (expenditure) and effect (financial peformance).
Jerrry Landsbaum's 1992 work included examples of their regular business reports - quantifiable and repeatable metrics of I.T. Operations phrased in business terms. This work seems entirely disregarded.
Hope to find (The Wherefore)
- Model I.T. Operations performance within and across similar organisations.
- generate tools usable within organisations to collect/report their own metrics.
- Define a set of useful I.T. Operations performance and Business Impact metrics.
- Model inputs to Business and Business Utilisation/Outcomes.
Report Outline
- Analyse ITSM tool data. Derive KPI's, Internal Baselines/Trends, Cross-section Benchmarks
- Annual I.T. Operations Report
- FTE Employee equivalents - Count and Cost
- Why IT Matters to the Business.
- Gaps in Service Management models - ITIL and COBIT
- Adding I.T. Operations to Management Theories.
- Advancing I.T. as a Profession
- Further Work and Research Questions
Execution Phases
2007/03/19
Controlling Waste in Government I.T. - An Immodest Proposal
The Standish Group has researched and released the CHAOS report since 1994. What's special about Yet Another Expensive Industry Report?
The fact that nobody else does it, they have 50,000 detailed case studies of I.T. projects, and their results are consistent year to year (but they would make it that way, wouldn't they?).
Do we believe their claims the US spends $250Bn/year on IT applications development? That $81Bn of that is on cancelled projects and anothe $59Bn on over-runs? Or that only 16.2% of projects finish on time and within 130% of budget? That "For every 100 projects that start, there are 94 restarts"?
To scale that back to Australia, about one fifteenth the size, there'd be A$21Bn/year on just applications development. Which doesn't gel with estimates from the ABS that the I.T. sector here is about A$20Bn in total. (The ABS only reports accurately the ICT sector - grossly inflated by 'Communications' i.e. phone et al.) If the Australian I.T. sector is 5% of GDP, it would be around $50Bn and employ 500,000 people. Not unbelievable.
Either the US does a lot more AppDev that us, they pay a lot more, the survey is wrong - or the ABS survery figures are out.
To cut through the questions, all that's needed is a 'scale factor' - to convert the numbers from Standish into believable figures for Australia. Taking the ABS survey figure as a lower bound and guessing that half I.T. budgets go on AppsDev, or $10Bn, then that's a scale factor of 25:1.
So the Waste in Australia on cancelled AppDev projects is at least $3.25Bn/yr. The ABS also state that 40% of I.T. expenditure is by Government - half by the Federal Govt. The Government is wasting $1.5Bn - $3Bn of public monies yearly.
The only reliable figure for 'waste' is cancelled projects. Standish do say 52.7% of projects will cost 189% of their original estimates. But that could just be deliberate low estimates, optimisum or ineptitude of the IT areas - which after 50+ years of commercial I.T. you'd have thought management might have recognised and addressed.
It's over 10 years since Standish started their CHAOS reports - so why hasn't any section of the Australian Government looked at the problem here? Some possibilities:
There is a tried, proven model for controlling 'waste' - and the government knows it well:
Aviation.
Two independent bodies are needed: An investigator and an enforcement/compliance agency.
In Aviation, they are "BASI (Bureau of Air Safety Investigation)" and "CASA (Civil Aviation Safety Authority)".
CASA creates real 'consequences' for people and organisations - negligence and incompetence are cause for temporary or permanent disbarment from the industry.
BASI looks to find the causes of 'incidents', how to avoid them in future and promulgates the information to everyone that should know.
For about $30M/year, roughly the budget of the ANAO, the Federal Government could start to define and address the problem of I.T. waste. This is an area where the Government can lead the Private Sector - the same companies and people contract for the public and private sector. The Government can be seen to be impartial and transparent, and their is no legal impediment for a government "right to practice" list.
Spending $30M to save $3,250M - that sound like a good deal to me. Why not to the Government?
The fact that nobody else does it, they have 50,000 detailed case studies of I.T. projects, and their results are consistent year to year (but they would make it that way, wouldn't they?).
Do we believe their claims the US spends $250Bn/year on IT applications development? That $81Bn of that is on cancelled projects and anothe $59Bn on over-runs? Or that only 16.2% of projects finish on time and within 130% of budget? That "For every 100 projects that start, there are 94 restarts"?
To scale that back to Australia, about one fifteenth the size, there'd be A$21Bn/year on just applications development. Which doesn't gel with estimates from the ABS that the I.T. sector here is about A$20Bn in total. (The ABS only reports accurately the ICT sector - grossly inflated by 'Communications' i.e. phone et al.) If the Australian I.T. sector is 5% of GDP, it would be around $50Bn and employ 500,000 people. Not unbelievable.
Either the US does a lot more AppDev that us, they pay a lot more, the survey is wrong - or the ABS survery figures are out.
To cut through the questions, all that's needed is a 'scale factor' - to convert the numbers from Standish into believable figures for Australia. Taking the ABS survey figure as a lower bound and guessing that half I.T. budgets go on AppsDev, or $10Bn, then that's a scale factor of 25:1.
So the Waste in Australia on cancelled AppDev projects is at least $3.25Bn/yr. The ABS also state that 40% of I.T. expenditure is by Government - half by the Federal Govt. The Government is wasting $1.5Bn - $3Bn of public monies yearly.
The only reliable figure for 'waste' is cancelled projects. Standish do say 52.7% of projects will cost 189% of their original estimates. But that could just be deliberate low estimates, optimisum or ineptitude of the IT areas - which after 50+ years of commercial I.T. you'd have thought management might have recognised and addressed.
It's over 10 years since Standish started their CHAOS reports - so why hasn't any section of the Australian Government looked at the problem here? Some possibilities:
- There is no problem here. [Nope, glorious failures like ADCNET abound]
- We don't have figures, so nothing could be wrong.
- It's too trivial a figure
- Nobody here knows the Standish work. [That's either negligence or incompetence.]
- It's nobody's job? How about:
- Australian Audit Office?
- Senate Estimates Committee and Expenditure Review Board?
- AGIMO, NOIE, GOI, ...
- FMA Act & Finance - "Efficient, Effective, Ethical expenditure of public monies"
- Department Heads [see FMAA]
- I.T. Heads
There is a tried, proven model for controlling 'waste' - and the government knows it well:
Aviation.
Two independent bodies are needed: An investigator and an enforcement/compliance agency.
In Aviation, they are "BASI (Bureau of Air Safety Investigation)" and "CASA (Civil Aviation Safety Authority)".
CASA creates real 'consequences' for people and organisations - negligence and incompetence are cause for temporary or permanent disbarment from the industry.
BASI looks to find the causes of 'incidents', how to avoid them in future and promulgates the information to everyone that should know.
For about $30M/year, roughly the budget of the ANAO, the Federal Government could start to define and address the problem of I.T. waste. This is an area where the Government can lead the Private Sector - the same companies and people contract for the public and private sector. The Government can be seen to be impartial and transparent, and their is no legal impediment for a government "right to practice" list.
Spending $30M to save $3,250M - that sound like a good deal to me. Why not to the Government?
Subscribe to:
Posts (Atom)