<?xml version="1.0" encoding="utf-8" standalone="yes" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Strategy | Marcel Wiedemeier</title>
    <link>https://marcelwiedemeier.com/tags/strategy/</link>
      <atom:link href="https://marcelwiedemeier.com/tags/strategy/index.xml" rel="self" type="application/rss+xml" />
    <description>Strategy</description>
    <generator>Wowchemy (https://wowchemy.com)</generator><language>en-US</language><copyright>© 2023</copyright><lastBuildDate>Mon, 25 Apr 2022 21:35:40 +0200</lastBuildDate>
    <image>
      <url>https://marcelwiedemeier.com/media/icon_hu_99437298ac1eb4c9.png</url>
      <title>Strategy</title>
      <link>https://marcelwiedemeier.com/tags/strategy/</link>
    </image>
    
    <item>
      <title>New work and SaaS</title>
      <link>https://marcelwiedemeier.com/post/newwork/</link>
      <pubDate>Mon, 25 Apr 2022 21:35:40 +0200</pubDate>
      <guid>https://marcelwiedemeier.com/post/newwork/</guid>
      <description>&lt;h1 id=&#34;the-challenge&#34;&gt;The challenge&lt;/h1&gt;
&lt;p&gt;Transparency is one of the key elements creating self-managed teams and enabling people to make informed decisions in progressive organisations.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Every single activity we conduct at work — recruiting, sales, accounting — is dependent on
information processing and knowledge transfer. If we can tap into our collective
intelligence, we can accomplish amazing things. And so it’s somewhat surprising how little
time we spend on our information architecture — our approach to discovering, storing, and
sharing what we know.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;em&gt;(Source: [Dignan, Aaron. Brave New Work (pp. 129-130). Penguin Books Ltd. Kindle Edition.] (&lt;a href=&#34;https://lesen.amazon.de/kp/embed?asin=B07D93TF33&amp;amp;preview=newtab&amp;amp;linkCode=kpe&amp;amp;ref_=cm_sw_r_kb_dp_A9VHX4ENJTZRAG4SYYKM%29%29&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://lesen.amazon.de/kp/embed?asin=B07D93TF33&amp;preview=newtab&amp;linkCode=kpe&amp;ref_=cm_sw_r_kb_dp_A9VHX4ENJTZRAG4SYYKM))&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;However, many SaaS subscriptions and on-prem software packages are licensed by the number of users. In order to save money, organisations are thus limiting the number of users and subscriptions to the minimum required. This creates information silos that are addressed in several ways:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;One way is exporting the data into some kind of data lake or repository where it can be added to reports and dashboards. As these data exports can become large, they are often scheduled to load once daily - slowing down data updates into a 24h pattern. Having data copied into another system just to make it viewable is an overhead. As the exported data cannot be edited, data quality is not improved.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Another way is creating gateway users that retrieve and update records on behalf of other users that don&amp;rsquo;t have direct access. This creates information asymmetry, frustration and slows down the whole organisation.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Probably the worst option is to simply share login credentials across multiple people. This is not only a usability nightmare, but also unethical and generally a bad security practice.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;None of these practices address the issue at hand, which is that additional users only incur marginal cost; the main cost are usually to be found in customer acquisition, infrastructure (transfer, storage and processing of data), support and development.&lt;/p&gt;
&lt;p&gt;In addition, many tools that help organize work benefit from a network effect: Their value increases as more parts of an organization start using them (including customers and providers).&lt;/p&gt;
&lt;h1 id=&#34;the-solution&#34;&gt;The solution&lt;/h1&gt;
&lt;p&gt;My suggestion is for software providers and SaaS vendors to allow  unlimited - at least read only - accounts to be created so progressive organisations can create the required transparency without incurring prohibitive cost. This would also enable organisations to grant access to customers and providers - creating an interesting cross-selling opportunity.&lt;/p&gt;
&lt;p&gt;There is also mounting evidence that traditional per user pricing models (which are not coupled to actual cost) are detrimental to the actual growth of subscriptions.&lt;/p&gt;
&lt;h1 id=&#34;my-suggestion&#34;&gt;My suggestion&lt;/h1&gt;
&lt;p&gt;Organizations need to prioritize their organisational goals over technology decisions and make this transparent to providers. This may be uncomfortable, but I regard it as necessary to grow as an organization. SaaS providers need to understand that holding customers hostage using arbitrary limits is not only alienating, but fundamentally hurts both in the long term.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>To cloud or not to cloud</title>
      <link>https://marcelwiedemeier.com/post/cloud/</link>
      <pubDate>Wed, 16 Jan 2019 21:35:40 +0200</pubDate>
      <guid>https://marcelwiedemeier.com/post/cloud/</guid>
      <description>&lt;p&gt;The question of how to integrate cloud service providers as part of the IT strategy is one of the tougher questions IT leaders are currently facing. In this blog post, I&amp;rsquo;ll outline our thought process and the conclusion derived.&lt;/p&gt;
&lt;p&gt;For the sake of this blog post, we&amp;rsquo;ll peruse the definition of &amp;ldquo;cloud computing&amp;rdquo; by &lt;a href=&#34;http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;NIST&lt;/a&gt;:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&amp;ldquo;Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. This cloud model is composed of five essential characteristics, three service models, and four deployment models.&amp;rdquo;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;There are many factors to consider: Performance, availability, integrity, confidentiality, cost, compliance, data protection, and privacy. We do not know what services will be cloud-based, but we have to assume that – as services become commoditized – running systems on-premise will return diminishing results. As part of our Services Business Strategy, we identified cloud agnosticism as one of our strategic goals. What do we mean by this? Today, we buy a certain amount of capacity to run hosted solutions in a rented facility. By design, a part of this capacity sits idle in anticipation of additional demand by existing or new customers. Meanwhile, we’re running dev systems in Amazon Web Services (AWS EC2) where we pay by the hour. Additionally, we have old systems (that could be retired) still occupying space in our hosting infrastructure.&lt;/p&gt;
&lt;p&gt;This leads to a sub-optimal cost and capacity structure, amateurish depicted in the following picture.&lt;/p&gt;
&lt;p&gt;















&lt;figure  id=&#34;figure-public-cloud-adoption-model&#34;&gt;
  &lt;div class=&#34;d-flex justify-content-center&#34;&gt;
    &lt;div class=&#34;w-100&#34; &gt;&lt;img src=&#34;https://marcelwiedemeier.com/img/cloud2.png&#34; alt=&#34;alt text&#34; loading=&#34;lazy&#34; data-zoomable /&gt;&lt;/div&gt;
  &lt;/div&gt;&lt;figcaption&gt;
      Public Cloud Adoption Model
    &lt;/figcaption&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;h1 id=&#34;advantages-of-being-cloud-agnostic&#34;&gt;Advantages of being cloud agnostic&lt;/h1&gt;
&lt;p&gt;Our goal must be to maximize return on investment (ROI) on the hosting environment and to use public cloud providers as a buffer for peak demand. To achieve this, we need to make sure our services are cloud agnostic – so we can deploy them internally or to an external cloud without re-engineering. Adding cloud cost management will then allow us to broker the best price/performance ratio for us and our customers and whilst preventing vendor lock-in.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ve been asked if I believe we will still provide our own hosting infrastructure in the future: I&amp;rsquo;m absolutely convinced that providing full service including having our own infrastructure is not only a major differentiator to our competitors – but also a guarantee we&amp;rsquo;ll properly understand the caveats and dynamics of a cloud-based service delivery model. I&amp;rsquo;m also convinced public cloud providers will further lower their cost and a price/feature war will make them more attractive over time. However, vendors will also continue to differentiate their services and create lock-in models so we have to remain vigilant. Nonetheless, I see more opportunities than threats.&lt;/p&gt;
&lt;p&gt;Being cloud agnostic will allow us to leverage a unique proposition to broker the best solution for our customers while maximizing our return on investment in physical hardware and engineering. However, we have to solve the technical challenges to enable this flexibility. A strong collaboration between developers and engineers is fundamental to build the necessary abstraction, standardization, and automation to achieve our goal.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Shift Left in IT Operations: Integrating Security and Quality into Front-Line Triage</title>
      <link>https://marcelwiedemeier.com/post/shift-left-security/</link>
      <pubDate>Sat, 05 May 2018 12:00:00 +0200</pubDate>
      <guid>https://marcelwiedemeier.com/post/shift-left-security/</guid>
      <description>&lt;p&gt;In traditional enterprise IT support models, incidents and security alerts follow a sluggish escalation hierarchy: Tier 1 logs the ticket, Tier 2 investigates basic diagnostics, and Tier 3 engineering specialists are finally paged to perform root-cause analysis and remediation. This reactive pipeline is slow, expensive, and fundamentally ill-suited for modern cybersecurity, where every minute an active vulnerability or misconfiguration persists increases breach exposure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Shift Left&lt;/strong&gt; is a strategic service transformation that pushes knowledge, diagnostic automation, and security remediation as close to the initial point of contact as possible.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Traditional Support (Escalation Bottleneck)
[User / Alert] ---&amp;gt; [Tier 1: Triage] ---&amp;gt; [Tier 2: Diagnostic] ---&amp;gt; [Tier 3: Engineer / SecOps Fix]
                     (Hours/Days)           (Days/Weeks)              (Costly, Strained Resource)

Shift Left Model (Immediate, Automated Resolution)
[User / Alert] ---&amp;gt; [Self-Service Automation / Tier 1 Armed with Runbooks] ===&amp;gt; [Instant Resolution]
                           |
                           +---&amp;gt; [Tier 3 Focuses on Automated Guardrails &amp;amp; Prevention]
&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;reversing-the-burden-of-proof-in-service-delivery&#34;&gt;Reversing the Burden of Proof in Service Delivery&lt;/h2&gt;
&lt;p&gt;At the heart of the Shift Left philosophy is an &lt;strong&gt;inversion of proof&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;In legacy models, the burden rests on the business customer to report when a service is degraded or non-compliant.&lt;/li&gt;
&lt;li&gt;Under Shift Left, the service organization continuously and proactively demonstrates that services meet changing security, compliance, and performance baselines before end users experience friction.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;core-operational-and-security-pillars&#34;&gt;Core Operational and Security Pillars&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Codified Security Runbooks&lt;/strong&gt;: Complex security assessments and standard remediations (e.g., certificate renewals, IAM permission adjustments, suspicious login quarantines) were packaged into automated scripts and clear decision trees for Level 1 support teams.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secure Offshore Operational Enablement&lt;/strong&gt;: Established vendor contracts, secure virtual desktop infrastructure (VDI), and rigorous data privacy boundaries to enable an offshore operations team in India to handle 24/7 front-line support safely without exposing core production secrets.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automated Baseline Verification&lt;/strong&gt;: Deployed continuous automated checks across servers and endpoints, reporting deviations from security baselines (unpatched packages, disabled firewalls, open ports) directly to Level 1 operators for rapid remediation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Knowledge Democratization &amp;amp; Self-Healing&lt;/strong&gt;: Built an interactive knowledge portal and automated self-healing scripts that resolve common user issues (such as password resets, token synchronization, and VPN re-authentication) instantly without human intervention.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&#34;strategic-outcomes&#34;&gt;Strategic Outcomes&lt;/h2&gt;
&lt;p&gt;By shifting resolution leftward, our organizations achieved dramatic improvements in agility and security posture:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Drastic Mean Time to Resolution (MTTR) Reduction&lt;/strong&gt;: Routine security requests and incident tickets that previously took 48+ hours were resolved in under 15 minutes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tier 3 Engineering Offload&lt;/strong&gt;: Freed senior architects and security engineers from repetitive firefighting, allowing them to focus on high-value architecture, threat modeling, and proactive defenses.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Elevated Customer Satisfaction&lt;/strong&gt;: Business units experienced transparent, predictable IT services with minimal operational friction.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Shift Left transforms IT service delivery from a reactive cost center into an agile, security-first organizational enabler.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Shift Left</title>
      <link>https://marcelwiedemeier.com/project/sl/</link>
      <pubDate>Tue, 01 May 2018 22:49:08 +0200</pubDate>
      <guid>https://marcelwiedemeier.com/project/sl/</guid>
      <description>&lt;p&gt;&amp;ldquo;Shift Left&amp;rdquo; is the concerted effort of an organization to increase customer satisfaction and productivity to ensure incidents and requests are handled according to business needs.&lt;/p&gt;
&lt;p&gt;Shift left means a changed service philosophy with the business need at its center. Ideally, this leads to an inversion of proof: No more has the customer to complain or proof something does not work, but the service provider has to continuously proof that the service meets (even changing) customer needs.&lt;/p&gt;
&lt;p&gt;Establish contracts, vendor relationship and processes to allow an IT organization gradually hand over activties to an offshore team in India.&lt;/p&gt;
&lt;p&gt;I even put a lame prezi together to illustrate this: &lt;a href=&#34;http://prezi.com/elvtwokfgkjx/?utm_campaign=share&amp;amp;utm_medium=copy&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;http://prezi.com/elvtwokfgkjx/?utm_campaign=share&amp;utm_medium=copy&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Strategy</title>
      <link>https://marcelwiedemeier.com/post/strategy/</link>
      <pubDate>Mon, 04 Dec 2017 21:35:40 +0200</pubDate>
      <guid>https://marcelwiedemeier.com/post/strategy/</guid>
      <description>&lt;p&gt;Edit 2023-01-08 - this blog post was initially published on
&lt;a href=&#34;https://www.unic.com/en/competencies/experts-blog/2017/effective-it-strategy&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;https://www.unic.com/en/competencies/experts-blog/2017/effective-it-strategy&lt;/a&gt; but deleted - I copied here for future reference:&lt;/p&gt;
&lt;p&gt;One of the key challenges in IT is that not every system is created equal. When developing services we try to harmonize the way we manage IT systems and the applications provided by them. However, we see an increasing tension between flexibility and reliability. Very generally we want agility when it comes to systems that allow us to work and collaborate in new ways. On the other hand, we could not get things done if all systems were in constant flux. So we aim for stability for systems that provide standardized services.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.gartner.com/en/documents/1488129#a1230436674&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;Gartner!&lt;/a&gt; developed a classification system that might allow us to identify which application services require what type management to ensure agility and stability at the same time:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Systems of Record: usually found in business capabilities with a clear focus on standardization and / or operational efficiency; these are also often subject to regulatory / compliance requirements. Good examples are finance and HR Systems.&lt;/li&gt;
&lt;li&gt;Systems of Differentiation: typically related to applications that enable unique company processes or industry-specific capabilities; these sustain a company&amp;rsquo;s competitive advantage.&lt;/li&gt;
&lt;li&gt;Systems of Innovation: new applications that are built on an ad hoc basis to address emerging business requirements or opportunities; these involve an experimental environment for testing new ideas and identify the company&amp;rsquo;s next competitive advantage.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Applied to our world as a leading Swiss web agency, here&amp;rsquo;s where I would see our various capabilities:&lt;/p&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th style=&#34;text-align: left&#34;&gt;Pace&lt;/th&gt;
					&lt;th style=&#34;text-align: left&#34;&gt;Ideas&lt;/th&gt;
					&lt;th style=&#34;text-align: left&#34;&gt;Focus&lt;/th&gt;
					&lt;th style=&#34;text-align: left&#34;&gt;Example of Tools and Services&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Systems of Record&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Common Ideas&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Business capabilities with a clear focus on standardization and operational efficiency to ensure quality and compliance.&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;ERP, CRM, Email, Clients, VPN, Network&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Systems of Differentiation&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Better Ideas&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Enable unique company processes or industry-specific capabilities to sustain the company&amp;rsquo;s current competitive advantage.&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Asynchrounous collaboration, continouos integration, deployment&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Systems of Innovation&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;New Ideas&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Ideas or opportunities to identify the company&amp;rsquo;s next competitive advantage.&lt;/td&gt;
					&lt;td style=&#34;text-align: left&#34;&gt;Machine Learning, Blockchain&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;We have several examples of systems starting as a side project in innovation and then graduate to a system of differentiation.
Important to understand is that system of records done well, can be a differentiator. However, more often than not cost reduction is the main driver.
We can map business needs to pace layers by a simple guide:&lt;/p&gt;
&lt;p&gt;How does this help us in day-to-day activities? This strategy allows us to clearly determine how a specific system should be managed.
Our tasks are therefore outlined as follows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Optimise cost / performance for systems of record: Outsource, streamline, offshore maintenance (like we did with Email and are now doing with SharePoint). No custom development, at best configuration of commercial off-the-shelf systems. No in-house development.&lt;/li&gt;
&lt;li&gt;Find new current growing services that are easy to implement for us, but hard for competitors. These will be new systems of differentiation. Can be commercial or open-source systems; some customizations. Some in-house development to glue systems together.&lt;/li&gt;
&lt;li&gt;Establish service development to identify and develop systems of innovation and differentiation into systems of differentiation. Predominantly developed in-house. The reality of business applications will be an interconnected mesh of applications in different states of maturity. I&amp;rsquo;m convinced that successful businesses will be the ones who manage to differentiate services based on these pace layers.&lt;/li&gt;
&lt;/ol&gt;
</description>
    </item>
    
  </channel>
</rss>
