devsecfinops

No one wants to end up with an unexpected $50,000 invoice on their desk after a Cloud migration project. After all, isn’t the move to the Cloud supposed to save you money? Unfortunately, this scenario isn’t uncommon among enterprises that move from the on-premises environment they are used to into a Cloud environment.

Organizations running their systems in a data center are typically concerned with network and infrastructure issues such as heating and cooling. The overwhelming focus is on hardware. In this traditional environment, there is typically a set group of people worrying about the financial and security aspects, allowing the technical infrastructure people to go about their jobs, so long as they operate within those constraints.

When moving to the Cloud it is an alarming misconception that the business can carry this same infrastructure perspective into the Cloud, treating it as just another data center, which it simply isn’t. The ability to spin things up at speed creates a great opportunity for innovation through agility, but the cost and security challenges without having the appropriate controls in place as well.

This means a huge degree of education for the team operating in the Cloud. The ability to do things easier and faster requires a new set of skills, known as DevSecFinOps.

Financial awareness may be the last thing on the mind of the tech team but it is frankly no longer an option when operating in the Cloud. Rather than be daunting, there should be three core areas of focus:

  • DevOps (Development and Operations): As we have discussed, do not think of the Cloud as another data center or that you can simply lift and shift and get the most out of a move to Cloud. Any company taking this journey should keep in mind the benefits of optimizing and evolving beyond their current ways of working. The key difference is the digitization of infrastructure and the immediacy of the resulting servers or services.
  • FinOps (Finance): Building awareness of cost in all actions will empower the IT teams to cover all the bases when undertaking IT improvements. This also demands a level of governance and control around the approval of the spend incurred by seemingly innocuous actions. The challenge is to create a light touch approval process that keeps things moving, rather than a cumbersome ITIL process intended to limit change.
  • SecOps (Security): Like finance, there are security implications to most actions. Cloud providers have tried to shield customers from the most serious implications of their actions, but it still requires a significant amount of customer knowledge to keep their organizations safe.
  • The latter two are usually less of a concern when operating in an on-premises environment. But, in many cases, the internal resources within the enterprise do not have the experience and expertise around how things work in the Cloud. This can lead to mistakes, brought about simply by failing to take advantage of discount programs or utilizing alerts and notifications in case things are trending in the wrong direction. This can result in surprises and overspending simply by not understanding the implications of their actions. This is where DevOps takes center stage.
  • When the CFO asks why they must spend $50,000 more than planned, the infrastructure team will say they have just been doing what they’re accustomed to, without an understanding of the implications.
  • This scenario is typical of a major IT transformation project carried out to meet short-term objectives. Too often, simply ‘getting to the Cloud’ is the end of the journey. Instead, organizations should look beyond the migration phase and concentrate far more effort on how they ‘operate’ on the Cloud. At a practical level, notifications, reports and budgeting tools help monitor spend, along with training to understand how to work in the Cloud and pick up on anomalies.
  • Armed with the right mindset and an understanding of the financial and security implications of their actions, the technical team will be able to leverage the benefits of the Cloud and deliver truly game-changing innovation for the business.

Published: CloudTech

Related Content