<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Service-Management | Marcel Wiedemeier</title>
    <link>https://marcelwiedemeier.com/tags/service-management/</link>
      <atom:link href="https://marcelwiedemeier.com/tags/service-management/index.xml" rel="self" type="application/rss+xml" />
    <description>Service-Management</description>
    <generator>Wowchemy (https://wowchemy.com)</generator><language>en-US</language><copyright>© 2023</copyright><lastBuildDate>Sat, 05 May 2018 12:00:00 +0200</lastBuildDate>
    <image>
      <url>https://marcelwiedemeier.com/media/icon_hu_99437298ac1eb4c9.png</url>
      <title>Service-Management</title>
      <link>https://marcelwiedemeier.com/tags/service-management/</link>
    </image>
    
    <item>
      <title>Shift Left in IT Operations: Integrating Security and Quality into Front-Line Triage</title>
      <link>https://marcelwiedemeier.com/post/shift-left-security/</link>
      <pubDate>Sat, 05 May 2018 12:00:00 +0200</pubDate>
      <guid>https://marcelwiedemeier.com/post/shift-left-security/</guid>
      <description>&lt;p&gt;In traditional enterprise IT support models, incidents and security alerts follow a sluggish escalation hierarchy: Tier 1 logs the ticket, Tier 2 investigates basic diagnostics, and Tier 3 engineering specialists are finally paged to perform root-cause analysis and remediation. This reactive pipeline is slow, expensive, and fundamentally ill-suited for modern cybersecurity, where every minute an active vulnerability or misconfiguration persists increases breach exposure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Shift Left&lt;/strong&gt; is a strategic service transformation that pushes knowledge, diagnostic automation, and security remediation as close to the initial point of contact as possible.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Traditional Support (Escalation Bottleneck)
[User / Alert] ---&amp;gt; [Tier 1: Triage] ---&amp;gt; [Tier 2: Diagnostic] ---&amp;gt; [Tier 3: Engineer / SecOps Fix]
                     (Hours/Days)           (Days/Weeks)              (Costly, Strained Resource)

Shift Left Model (Immediate, Automated Resolution)
[User / Alert] ---&amp;gt; [Self-Service Automation / Tier 1 Armed with Runbooks] ===&amp;gt; [Instant Resolution]
                           |
                           +---&amp;gt; [Tier 3 Focuses on Automated Guardrails &amp;amp; Prevention]
&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;reversing-the-burden-of-proof-in-service-delivery&#34;&gt;Reversing the Burden of Proof in Service Delivery&lt;/h2&gt;
&lt;p&gt;At the heart of the Shift Left philosophy is an &lt;strong&gt;inversion of proof&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;In legacy models, the burden rests on the business customer to report when a service is degraded or non-compliant.&lt;/li&gt;
&lt;li&gt;Under Shift Left, the service organization continuously and proactively demonstrates that services meet changing security, compliance, and performance baselines before end users experience friction.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;core-operational-and-security-pillars&#34;&gt;Core Operational and Security Pillars&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Codified Security Runbooks&lt;/strong&gt;: Complex security assessments and standard remediations (e.g., certificate renewals, IAM permission adjustments, suspicious login quarantines) were packaged into automated scripts and clear decision trees for Level 1 support teams.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secure Offshore Operational Enablement&lt;/strong&gt;: Established vendor contracts, secure virtual desktop infrastructure (VDI), and rigorous data privacy boundaries to enable an offshore operations team in India to handle 24/7 front-line support safely without exposing core production secrets.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automated Baseline Verification&lt;/strong&gt;: Deployed continuous automated checks across servers and endpoints, reporting deviations from security baselines (unpatched packages, disabled firewalls, open ports) directly to Level 1 operators for rapid remediation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Knowledge Democratization &amp;amp; Self-Healing&lt;/strong&gt;: Built an interactive knowledge portal and automated self-healing scripts that resolve common user issues (such as password resets, token synchronization, and VPN re-authentication) instantly without human intervention.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&#34;strategic-outcomes&#34;&gt;Strategic Outcomes&lt;/h2&gt;
&lt;p&gt;By shifting resolution leftward, our organizations achieved dramatic improvements in agility and security posture:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Drastic Mean Time to Resolution (MTTR) Reduction&lt;/strong&gt;: Routine security requests and incident tickets that previously took 48+ hours were resolved in under 15 minutes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tier 3 Engineering Offload&lt;/strong&gt;: Freed senior architects and security engineers from repetitive firefighting, allowing them to focus on high-value architecture, threat modeling, and proactive defenses.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Elevated Customer Satisfaction&lt;/strong&gt;: Business units experienced transparent, predictable IT services with minimal operational friction.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Shift Left transforms IT service delivery from a reactive cost center into an agile, security-first organizational enabler.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Strategy</title>
      <link>https://marcelwiedemeier.com/post/strategy/</link>
      <pubDate>Mon, 04 Dec 2017 21:35:40 +0200</pubDate>
      <guid>https://marcelwiedemeier.com/post/strategy/</guid>
      <description>&lt;p&gt;Edit 2023-01-08 - this blog post was initially published on
&lt;a href=&#34;https://www.unic.com/en/competencies/experts-blog/2017/effective-it-strategy&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://www.unic.com/en/competencies/experts-blog/2017/effective-it-strategy&lt;/a&gt; but deleted - I copied here for future reference:&lt;/p&gt;
&lt;p&gt;One of the key challenges in IT is that not every system is created equal. When developing services we try to harmonize the way we manage IT systems and the applications provided by them. However, we see an increasing tension between flexibility and reliability. Very generally we want agility when it comes to systems that allow us to work and collaborate in new ways. On the other hand, we could not get things done if all systems were in constant flux. So we aim for stability for systems that provide standardized services.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.gartner.com/en/documents/1488129#a1230436674&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Gartner!&lt;/a&gt; developed a classification system that might allow us to identify which application services require what type management to ensure agility and stability at the same time:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Systems of Record: usually found in business capabilities with a clear focus on standardization and / or operational efficiency; these are also often subject to regulatory / compliance requirements. Good examples are finance and HR Systems.&lt;/li&gt;
&lt;li&gt;Systems of Differentiation: typically related to applications that enable unique company processes or industry-specific capabilities; these sustain a company&amp;rsquo;s competitive advantage.&lt;/li&gt;
&lt;li&gt;Systems of Innovation: new applications that are built on an ad hoc basis to address emerging business requirements or opportunities; these involve an experimental environment for testing new ideas and identify the company&amp;rsquo;s next competitive advantage.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Applied to our world as a leading Swiss web agency, here&amp;rsquo;s where I would see our various capabilities:&lt;/p&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th style=&#34;text-align: left&#34;&gt;Pace&lt;/th&gt;
					&lt;th style=&#34;text-align: left&#34;&gt;Ideas&lt;/th&gt;
					&lt;th style=&#34;text-align: left&#34;&gt;Focus&lt;/th&gt;
					&lt;th style=&#34;text-align: left&#34;&gt;Example of Tools and Services&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Systems of Record&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Common Ideas&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Business capabilities with a clear focus on standardization and operational efficiency to ensure quality and compliance.&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;ERP, CRM, Email, Clients, VPN, Network&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Systems of Differentiation&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Better Ideas&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Enable unique company processes or industry-specific capabilities to sustain the company&amp;rsquo;s current competitive advantage.&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Asynchrounous collaboration, continouos integration, deployment&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Systems of Innovation&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;New Ideas&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Ideas or opportunities to identify the company&amp;rsquo;s next competitive advantage.&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Machine Learning, Blockchain&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;We have several examples of systems starting as a side project in innovation and then graduate to a system of differentiation.
Important to understand is that system of records done well, can be a differentiator. However, more often than not cost reduction is the main driver.
We can map business needs to pace layers by a simple guide:&lt;/p&gt;
&lt;p&gt;How does this help us in day-to-day activities? This strategy allows us to clearly determine how a specific system should be managed.
Our tasks are therefore outlined as follows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Optimise cost / performance for systems of record: Outsource, streamline, offshore maintenance (like we did with Email and are now doing with SharePoint). No custom development, at best configuration of commercial off-the-shelf systems. No in-house development.&lt;/li&gt;
&lt;li&gt;Find new current growing services that are easy to implement for us, but hard for competitors. These will be new systems of differentiation. Can be commercial or open-source systems; some customizations. Some in-house development to glue systems together.&lt;/li&gt;
&lt;li&gt;Establish service development to identify and develop systems of innovation and differentiation into systems of differentiation. Predominantly developed in-house. The reality of business applications will be an interconnected mesh of applications in different states of maturity. I&amp;rsquo;m convinced that successful businesses will be the ones who manage to differentiate services based on these pace layers.&lt;/li&gt;
&lt;/ol&gt;
</description>
    </item>
    
  </channel>
</rss>
