Master Contract Review and Negotiation for Software Agreements

  • Buy Link or Shortcode: {j2store}170|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Vendor Management
  • Parent Category Link: /vendor-management
  • Internal stakeholders usually have different – and often conflicting – needs and expectations that require careful facilitation and management.
  • Vendors have well-honed negotiating strategies. Without understanding your own position and leverage points, it’s difficult to withstand their persuasive – and sometimes pushy – tactics.
  • Software – and software licensing – is constantly changing, making it difficult to acquire and retain subject matter expertise.

Our Advice

Critical Insight

  • Conservatively, it’s possible to save 5% of the overall IT budget through comprehensive software contract review.
  • Focus on the terms and conditions, not just the price.
  • Learning to negotiate is crucial.

Impact and Result

  • Look at your contract holistically to find cost savings.
  • Guide communication between vendors and your organization for the duration of contract negotiations.
  • Redline the terms and conditions of your software contract.
  • Prioritize crucial terms and conditions to negotiate.

Master Contract Review and Negotiation for Software Agreements Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out how to redline and negotiate your software agreement, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Gather requirements

Build and manage your stakeholder team, then document your business use case.

  • Master Contract Review and Negotiation for Software Agreements – Phase 1: Gather Requirements
  • RASCI Chart
  • Vendor Communication Management Plan
  • Software Business Use Case Template
  • SaaS TCO Calculator

2. Redline contract

Redline your proposed software contract.

  • Master Contract Review and Negotiation for Software Agreements – Phase 2: Redline Contract
  • Software Terms & Conditions Evaluation Tool
  • Software Buyer's Checklist

3. Negotiate contract

Create a thorough negotiation plan.

  • Master Contract Review and Negotiation for Software Agreements – Phase 3: Negotiate Contract
  • Controlled Vendor Communications Letter
  • Key Vendor Fiscal Year End Calendar
  • Contract Negotiation Tactics Playbook
[infographic]

Workshop: Master Contract Review and Negotiation for Software Agreements

Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

1 Collect and Review Data

The Purpose

Assemble documentation.

Key Benefits Achieved

Understand current position before going forward.

Activities

1.1 Assemble existing contracts.

1.2 Document their strategic and tactical objectives.

1.3 Identify current status of the vendor relationship and any historical context.

1.4 Clarify goals for ideal future state.

Outputs

Business Use Case

2 Define Business Use Case and Build Stakeholder Team

The Purpose

Define business use case and build stakeholder team.

Key Benefits Achieved

Create business use case to document functional and nonfunctional requirements.

Build internal cross-functional stakeholder team to negotiate contract.

Activities

2.1 Establish negotiation team and define roles.

2.2 Write communication plan.

2.3 Complete business use case.

Outputs

RASCI Chart

Vendor Communication Management Plan

SaaS TCO Calculator

Software Business Use Case

3 Redline Contract

The Purpose

Examine terms and conditions and prioritize for negotiation.

Key Benefits Achieved

Discover cost savings.

Improve agreement terms.

Prioritize terms for negotiation.

Activities

3.1 Review general terms and conditions.

3.2 Review license- and application-specific terms and conditions.

3.3 Match to business and technical requirements.

3.4 Redline agreement.

Outputs

Software Terms & Conditions Evaluation Tool

Software Buyer’s Checklist

4 Build Negotiation Strategy

The Purpose

Create a negotiation strategy.

Key Benefits Achieved

Establish controlled communication.

Choose negotiation tactics.

Plot negotiation timeline.

Activities

4.1 Review vendor- and application-specific negotiation tactics.

4.2 Build negotiation strategy.

Outputs

Contract Negotiation Tactics Playbook

Controlled Vendor Communications Letter

Key Vendor Fiscal Year End Calendar

Minimize the Damage of IT Cost Cuts

  • Buy Link or Shortcode: {j2store}53|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Cost & Budget Management
  • Parent Category Link: /cost-and-budget-management
  • Average growth rates for Opex and Capex budgets are expected to continue to decline over the next fiscal year.
  • Common “quick-win” cost-cutting initiatives are not enough to satisfy the organization’s mandate.
  • Cost-cutting initiatives often take longer than expected, failing to provide cost savings before the organization’s deadline.
  • Cost-optimization projects often have unanticipated consequences that offset potential cost savings and result in business dissatisfaction.

Our Advice

Critical Insight

  • IT costs affect the entire business, not just IT. For this reason, IT must work with the business collaboratively to convey the full implications of IT cost cuts.
  • Avoid making all your cuts at once; phase your cuts by taking into account the magnitude and urgency of your cuts and avoid unintended consequences.
  • Don’t be afraid to completely cut a service if it should not be delivered in the first place.

Impact and Result

  • Take a value-based approach to cost optimization.
  • Reduce IT spend while continuing to deliver the most important services.
  • Involve the business in the cost-cutting process.
  • Develop a plan for cost cutting that avoids unintended interruptions to the business.

Minimize the Damage of IT Cost Cuts Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out why you should take a value-based approach to cutting IT costs, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Understand the mandate and take immediate action

Determine your approach for cutting costs.

  • Minimize the Damage of IT Cost Cuts – Phase 1: Understand the Mandate and Take Immediate Action
  • Cost-Cutting Plan
  • Cost-Cutting Planning Tool

2. Select cost-cutting initiatives

Identify the cost-cutting initiatives and design your roadmap.

  • Minimize the Damage of IT Cost Cuts – Phase 2: Select Cost-Cutting Initiatives

3. Get approval for your cost-cutting plan and adopt change management best practices

Communicate your roadmap to the business and attain approval.

  • Minimize the Damage of IT Cost Cuts – Phase 3: Get Approval for Your Cost-Cutting Plan and Adopt Change Management Best Practices
  • IT Personnel Engagement Plan
  • Stakeholder Communication Planning Tool
[infographic]

Workshop: Minimize the Damage of IT Cost Cuts

Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

1 Understand the Mandate and Take Immediate Action

The Purpose

Determine your cost-optimization stance.

Build momentum with quick wins.

Key Benefits Achieved

Understand the internal and external drivers behind your cost-cutting mandate and the types of initiatives that align with it.

Activities

1.1 Develop SMART project metrics.

1.2 Dissect the mandate.

1.3 Identify your cost-cutting stance.

1.4 Select and implement quick wins.

1.5 Plan to report progress to Finance.

Outputs

Project metrics and mandate documentation

List of quick-win initiatives

2 Select Cost-Cutting Initiatives

The Purpose

Create the plan for your cost-cutting initiatives.

Key Benefits Achieved

Choose the correct initiatives for your roadmap.

Create a sensible and intelligent roadmap for the cost-cutting initiatives.

Activities

2.1 Identify cost-cutting initiatives.

2.2 Select initiatives.

2.3 Build a roadmap.

Outputs

High-level cost-cutting initiatives

Cost-cutting roadmap

3 Get Approval for Your Cost-Cutting Plan and Adopt Change Management Best Practices

The Purpose

Finalize the cost-cutting plan and present it to the business.

Key Benefits Achieved

Attain engagement with key stakeholders.

Activities

3.1 Customize your cost-cutting plan.

3.2 Create stakeholder engagement plans.

3.3 Monitor cost savings.

Outputs

Cost-cutting plan

Stakeholder engagement plan

Cost-monitoring plan

Review Your Application Strategy

  • Buy Link or Shortcode: {j2store}82|cart{/j2store}
  • member rating overall impact: 10.0/10 Overall Impact
  • member rating average dollars saved: $12,599 Average $ Saved
  • member rating average days saved: 2 Average Days Saved
  • Parent Category Name: Architecture & Strategy
  • Parent Category Link: /architecture-and-strategy
  • Over 80% of CXOs experience frustration with IT’s failure to deliver business value.
  • Sixty percent of CEOs believe that improvement is required around IT’s understanding of business goals.
  • Sixty percent of IT professionals know there is an opportunity to run applications more efficiently, eliminating wasteful or low-value activities.

Our Advice

Critical Insight

  • Organizations need to better align their application strategy with their business strategy as they proceed through tactical initiatives.
  • Application strategies provide guidance on how they will help the organization survive and thrive.

Impact and Result

Aligning your business with applications through your strategy will not only increase business satisfaction but also help to ensure you’re delivering applications that enable the organization’s goals.

Review Your Application Strategy Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out why you should have an application strategy and why you should use Info-Tech’s approach to review it. Learn how we can support you in completing this strategy and review.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Review your strategy

This review guide provides organizations with a detailed assessment of their application strategy, ensuring that the applications enable the business strategy so that the organization can be more effective.The assessment provides criteria and exercises to provide actionable outcomes.

  • Application Strategy Assessment Tool
  • Application Strategy Action Plan Report Template
  • Application Strategy Sample Action Plan Report
[infographic]

2021 Q3 Research Highlights

  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: The Briefs
  • Parent Category Link: /the-briefs
Our research team is a prolific bunch! Every quarter we produce lots of research to help you get the most value out of your organization. This PDF contains a selection of our most compelling research from the third quarter of 2021.

Switching Software Vendors Overwhelmingly Drives Increased Satisfaction

  • Buy Link or Shortcode: {j2store}612|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Selection & Implementation
  • Parent Category Link: /selection-and-implementation

Organizations risk being locked in a circular trap of inertia from auto-renewing their software. With inertia comes complacency, leading to a decrease in overall satisfaction. Indeed, organizations are uniformly choosing to renew their software – even if they don’t like the vendor!

Our Advice

Critical Insight

Renewal is an opportunity cost. Switching poorly performing software substantially drives increased satisfaction, and it potentially lowers vendor costs in the process. To realize maximum gains, it’s essential to have a repeatable process in place.

Impact and Result

Realize the benefits of switching by using Info-Tech’s five action steps to optimize your vendor switching processes:

  1. Identify switch opportunities.
  2. Evaluate your software.
  3. Build the business case.
  4. Optimize selection method.
  5. Plan implementation.

Switching Software Vendors Overwhelmingly Drives Increased Satisfaction Research & Tools

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Why you should consider switching software vendors

Use this outline of key statistics to help make the business case for switching poorly performing software.

  • Switching Existing Software Vendors Overwhelmingly Drives Increased Satisfaction Storyboard

2. How to optimize your software vendor switching process

Optimize your software vendor switching processes with five action steps.

[infographic]

Service Management

  • Buy Link or Shortcode: {j2store}46|cart{/j2store}
  • Related Products: {j2store}46|crosssells{/j2store}
  • Parent Category Name: Service Planning and Architecture
  • Parent Category Link: /service-planning-and-architecture

The challenge

  • We have holistic practices, but inconsistent adoption leads to chaotic service delivery and low customer satisfaction.
  • You may have designed your IT services with little structure, formalization, or standardization.
  • That makes the management of these services more difficult and also leads to low business satisfaction.

Continue reading

Identify Opportunities to Mature the Security Architecture

  • Buy Link or Shortcode: {j2store}385|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Secure Cloud & Network Architecture
  • Parent Category Link: /secure-cloud-network-architecture
  • Organizations do not have a solid grasp on the complexity of their infrastructure and are unaware of the overall risk to their infrastructure posed by inadequate security.
  • Organizations do not understand how to properly create and deliver value propositions of technical security solutions.

Our Advice

Critical Insight

  • The security architecture is a living, breathing thing based on the risk profile of your organization.
  • Compliance and risk mitigation create an intertwined relationship between the business and your security architecture. The security architecture roadmap must be regularly assessed and continuously maintained to ensure security controls align with organizational objectives.

Impact and Result

  • A right-sized security architecture can be created by assessing the complexity of the IT department, the operations currently underway for security, and the perceived value of a security architecture within the organization. This will bring about a deeper understanding of the organizational infrastructure.
  • Developing a security architecture should also result in a list of opportunities (i.e. initiatives) that an organization can integrate into a roadmap. These initiatives will seek to improve security operations and strengthen the IT department’s understanding of security’s role within the organization.
  • A better understanding of the infrastructure will help to save time on determining the correct technologies required from vendors and therefore cut down on the amount of vendor noise.
  • Creating a defensible roadmap will assist with justifying future security spend.

Identify Opportunities to Mature the Security Architecture Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out why you should develop a right-sized security architecture, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Identify the organization’s ideal security architecture

Complete three unique assessments to define the ideal security architecture maturity for your organization.

  • Identify Opportunities to Mature the Security Architecture – Phase 1: Identify the Organization's Ideal Security Architecture
  • Security Architecture Recommendation Tool
  • None

2. Create a security program roadmap

Use the results of the assessments from Phase 1 of this research to create a roadmap for improving the security program.

  • Identify Opportunities to Mature the Security Architecture – Phase 2: Create a Security Program Roadmap
[infographic]

Become a Transformational CIO

  • Buy Link or Shortcode: {j2store}86|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Innovation
  • Parent Category Link: /innovation
  • Business transformations are happening, but CIOs are often involved only when it comes time to implement change. This makes it difficult for the CIO to be perceived as an organizational leader.
  • CIOs find it difficult to juggle operational activities, strategic initiatives, and involvement in business transformation.
  • CIOs don’t always have the IT organization structured and mobilized in a manner that facilitates the identification of transformation opportunities, and the planning for and the implementation of organization-wide change.

Our Advice

Critical Insight

  • Don’t take an ad hoc approach to transformation.
  • You’re not in it alone.
  • Your legacy matters

Impact and Result

  • Elevate your stature as a business leader.
  • Empower the IT organization to act with a business mind first, and technology second.
  • Create a high-powered IT organization that is focused on driving lasting change, improving client experiences, and encouraging collaboration across the entire enterprise.
  • Generate opportunities for organizational growth, as manifested through revenue growth, profit growth, new market entry, new product development, etc.

Become a Transformational CIO Research & Tools

Start here – read the Executive Brief

Read our Executive Brief to find out why you should undergo an evolution in your role as a business leader, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Are you ready to lead transformation?

Determine whether you are ready to focus your attention on evolving your role.

  • Become a Transformational CIO – Phase 1: Are You Ready to Lead Transformation?

2. Build business partnerships

Create a plan to establish key business partnerships and position IT as a co-leader of transformation.

  • Become a Transformational CIO – Phase 2: Build Business Partnerships
  • Partnership Strategy Template

3. Develop the capability to transform

Mobilize the IT organization and prepare for the new mandate.

  • Become a Transformational CIO – Phase 3: Develop the Capability to Transform
  • Transformation Capability Assessment

4. Shift IT’s focus to the customer

Align IT with the business through a direct, concentrated focus on the customer.

  • Become a Transformational CIO – Phase 4: Shift IT’s Focus to the Customer
  • Transformational CIO Value Stream Map Template
  • Transformational CIO Business Capability Map Template

5. Adopt a transformational approach to leadership

Determine the key behaviors necessary for transformation success and delegate effectively to make room for new responsibilities.

  • Become a Transformational CIO – Phase 5: Adopt a Transformational Approach to Leadership
  • Office of the CIO Template

6. Sustain the transformational capability

Track the key success metrics that will help you manage transformation effectively.

  • Become a Transformational CIO – Phase 6: Sustain the Transformational Capability
  • Transformation Dashboard
[infographic]

Workshop: Become a Transformational CIO

Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

1 Determine Readiness to Become a Transformational CIO

The Purpose

Understand stakeholder and executive perception of the CIO’s performance and leadership.

Determine whether the CIO is ready to lead transformation.

Key Benefits Achieved

Decision to evolve role or address areas of improvement as a pre-requisite to becoming a transformational CIO.

Activities

1.1 Select data collection techniques.

1.2 Conduct diagnostic programs.

1.3 Review results and define readiness.

Outputs

Select stakeholder and executive perception of the CIO

Decision as to whether to proceed with the role evolution

2 Build Business Partnerships

The Purpose

Identify potential business partners and create a plan to establish key partnerships.

Key Benefits Achieved

An actionable set of initiatives that will help the CIO create valuable partnerships with internal or external business stakeholders.

Activities

2.1 Identify potential business partners.

2.2 Evaluate and prioritize list of potential partners.

2.3 Create a plan to establish the target partnerships.

Outputs

Partnership strategy

3 Establish IT’s Ability to Transform

The Purpose

Make the case and plan for the development of key capabilities that will enable the IT organization to handle transformation.

Key Benefits Achieved

A maturity assessment of critical capabilities.

A plan to address maturity gaps in preparation for a transformational mandate.

Activities

3.1 Define transformation as a capability.

3.2 Assess the current and target transformation capability maturity.

3.3 Develop a roadmap to address gaps.

Outputs

Transformation capability assessment

Roadmap to develop the transformation capability

4 Shift IT’s Focus to the Customer

The Purpose

Gain an understanding of the end customer of the organization.

Key Benefits Achieved

A change in IT mindset away from a focus on operational activities or internal customers to external customers.

A clear understanding of how the organization creates and delivers value to customers.

Opportunities for business transformation.

Activities

4.1 Analyze value streams that impact the customer.

4.2 Map business capabilities to value streams.

Outputs

Value stream maps

Business capability map

5 Establish Transformation Leadership and Sustain the Capability

The Purpose

Establish a formal process for empowering employees and developing new leaders.

Create a culture of continuous improvement and a long-term focus.

Key Benefits Achieved

Increased ability to sustain momentum that is inherent to business transformations.

Better strategic workforce planning and a clearer career path for individuals in IT.

A system to measure IT’s contribution to business transformation.

Activities

5.1 Set the structure for the office of the CIO.

5.2 Assess current leadership skills and needs.

5.3 Spread a culture of self-discovery.

5.4 Maintain the transformation capability.

Outputs

OCIO structure document

Transformational leadership dashboard

Improve Email Security

  • Buy Link or Shortcode: {j2store}272|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Secure Cloud & Network Architecture
  • Parent Category Link: /secure-cloud-network-architecture

As the sophistication of malicious attacks increases, it has become more difficult to ensure applications such as email software are properly protected and secured. The increase in usage and traffic of email exacerbates the security risks to the organization.

Our Advice

Critical Insight

Email has changed. Your email security needs to evolve as well to ensure you are protecting your organization’s communication.

Impact and Result

  • Gain an understanding of the importance of email security and steps to secure your corporate email.
  • Develop holistic guidelines on implementing best practices to modernize your organization’s email security.

Improve Email Security Research & Tools

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Improve Email Security Storyboard – A guide to best practices for improving an organization’s email security.

This research provides guidelines to assist organizations in identifying controls to secure their emails along with recommendations on the most common and effective controls to secure and protect corporate emails.

  • Improve Email Security Storyboard

2. Email Security Checklist – A checklist tool that enables organizations to monitor their progress in implementing controls to improve their email security.

This checklist of common email security categories and their associated controls helps ensure organizations are following best practices.

  • Email Security Checklist
[infographic]

Further reading

Improve Email Security

Follow the latest best practices for email security to mitigate evolving threats.

Analyst Perspective

Protecting your organization’s digital assets begins with securing your email communication.

As organizations increasingly rely on email communication for day-to-day business operations, threat actors are exploiting the increased traction to develop and implement more sophisticated email-based attacks. Furthermore, the lack of investment in measures, tools, and technologies for an organization’s email security exacerbates the vulnerabilities at hand.

Effective use of security procedures and techniques can mitigate and minimize email-based threats have been shown to reduce the ability of these attacks to infiltrate the email inbox. These guidelines and best practices will help your organization conduct due diligence to protect the contents of the email, its transit, and its arrival to the authorized recipient.

Ahmad Jowhar, Research Specialist, Security & Privacy

Ahmad Jowhar
Research Specialist, Security & Privacy
Info-Tech Research Group

Executive Summary

Your Challenge Common Obstacles Info-Tech’s Approach
  • As malicious attacks get increasingly sophisticated, it has become more difficult to ensure applications such as email software are properly protected and secured.
  • The increased usage and traffic of emails, as well as their contents, exacerbates security risks to the organization.
  • Given the variety of email security controls, it can be complicated to identify the most important techniques for improving your organization’s email security.
  • Understand the importance of implementing email security for your organization.
  • Develop a holistic guideline for implementing best practices to secure your organization’s emails.

Info-Tech Insight
Email has changed. Your email security must evolve to ensure the safety of your organization’s communication.

Your Challenge

As a security leader, you need to modernize your email security services so you can protect business communications and prevent security incidents.

  • Various factors must be considered when deciding how best to safeguard your organization’s communication chain. This includes the frequency of email traffic and the contents of emails.
  • The increased number of email-based cyberattacks reveals the sophistication of threat actors in leveraging an organization’s lack of email security to infiltrate their business.
  • As organizations continue to rely heavily on email communication, email-based threats will become increasingly prevalent.

75% of organizations have experienced an increase in email-based threats.

97% of security breaches are due to phishing attacks.

82% of companies reported a higher volume of email in 2022.

Source: Mimecast, 2023.

Modern email security controls framework for security leaders

Email has changed. Your email security must evolve to ensure the safety of your organization’s communication.

Modern email security controls framework for security leaders

Understand the best practices in securing your organization’s emails

Enhance your security posture by modernizing your email security
Email has changed. Your email security must evolve to ensure the safety of your organization’s communication.

Deploy an added layer of defense by preventing the contents of your email from being intercepted.

Encrypting your email communication will provide an additional layer of protection which only allows authorized users to read the email.

Leverage triple-threat authentication controls to strengthen your email security.

Leveraging SPF, DKIM, and DMARC enables you to have the proper authentication controls in place, ensuring that only legitimate users are part of the email communication.

Protect the contents of your email through data classification and data loss prevention.

Having tools and technologies in place to ensure that data is classified and backed up will enable better storage, analysis, and processing of the email.

Implement email policies for a holistic email security protection.

Policies ensure acceptable standards are in place to protect the organization’s assets, including the creation, attachment, sending, and receiving of emails.

User awareness and training
Training employees on protecting their corporate emails adds an extra layer of defense by ensuring end users are aware of various email-based threats and can confidently safeguard their organizations from attacks.

Email encryption

Deploy an added layer of defense by preventing the contents of your email from being intercepted.

  • Protecting your organization’s emails begins by ensuring only the appropriate recipients can receive and read the email’s contents.
  • This process includes encrypting the email’s contents to protect sensitive information from being read by unauthorized recipients.
  • This protects the contents even if the email is intercepted by anyone besides the intended recipient.
  • Other benefits of email encryption include:
    • Reducing any risks associated with regulatory violations.
    • Enabling business to confidently communicate sensitive information via email.
    • Ensuring protective measures taken to prevent data loss and corporate policy violations.

Along with the increased use of emails, organizations are seeing an increase in the number of attacks orchestrating from emails. This has resulted in 74% of organizations seeing an increase in email-based threats.

Source: Mimecast, 2023.

Info-Tech Insight
Encrypting your email communication will provide an additional layer of protection which only allows authorized users to read the email.

Implementing email encryption

Leverage these protocols and tools to help encrypt your email.

  • The most common email encryption protocols and tools include:
    • Transport Layer Security (TLS): A cryptographic protocol designed to securely deliver data via the internet, which prevents third parties from intercepting and accessing the data.
    • Secure/Multipurpose Internet Mail Extension (S/MIME): A protocol for sending digitally signed and encrypted messages by leveraging public key encryption to provide at-rest and in-transit data protection.
    • Secure Email Gateway: An email security solution that inspects emails for malicious content prior to it reaching the corporate system. The solution is positioned between the public internet and corporate email servers. An email gateway solution would be provided by a third-party vendor and can be implemented on-premises, through the cloud, or hybrid.
  • Email encryption policies can also be implemented to ensure processes are in place when sending sensitive information through emails.
  • Email encryption ensures end-to-end privacy for your email and is especially important when the email requires strict content privacy.

Email authentication

Three authentication controls your organization should leverage to stay secure.

  • Along with content encryption, it’s important to authenticate both the sender and recipient of an email to ensure that only legitimate users are able to send and receive it.
  • Implementing email authentication techniques prevents unsolicited email (e.g. spam) from entering your mailbox.
  • This also prevents unauthorized users from sending email on your organization’s behalf.
  • Having these standards in place would safeguard your organization from spam, spoofing, and phishing attacks.
  • The three authentication controls include:
    • Sender Policy Framework (SPF): Email validation control that verifies that the incoming email is from an authorized list of IP addresses provided by the sender’s domain administrator.
    • DomainKeys Identified Mail (DKIM): Enables recipients to verify that an email from a specific domain was authorized by the domain’s owner. This is conducted through cryptographic authentication by adding a digital signature to the message headers of outbound emails.
    • Domain Message Authentication Reporting & Conformance (DMARC): Provides domain-level protection of email channel by publishing DMARC records in the organization’s domain name system (DNS) and creates policies which prompts actions to take if an email fails authentication.

Although these authentication controls are available for organizations to leverage, the adoption rate remains low. 73% of survey respondents indicated they didn’t deploy email authentication controls within their organization.

Source: Mimecast, 2023.

Email authentication controls

All three authentication controls should be implemented to effectively secure your organization’s email. They ensure the emails you send and receive are securely authorized and legitimate.

SPF DKIM DMARC

Creating an SPF record identifies which IP addresses are allowed to send emails from your domain. Steps to implement SPF include the following:

  1. Create an SPF record by identifying the IP addresses that are authorized to send emails.
  2. Publish your SPF record into your DNS by creating a TXT record on your domain.

Implementing DKIM helps prevent attackers from sending emails that pretend to come from your domain. Steps to implement DKIM include the following:

  1. Identify and enable domains you wish to configure DKIM to create DKIM keys.
  2. Copy the canonical names (CNAMEs) that are provided.
  3. Publish the CNAME records to your DNS service provider.

Setting up DMARC ensures emails are validated and defines actions to take if an email fails authentication. These include:

  • None: Message is delivered to recipient and a DMARC report is sent to domain owner.
  • Quarantine: Message moved to quarantine folder and recipient is notified.
  • Reject: Message is not delivered to the recipient.
  • Steps to implement DMARC include:
  1. Create a DMARC record by including your organization’s email domain and IP addresses.
  2. Form a DMARC TXT record for your domain to include policies and publish it to your DNS.

For more information:

Data classification

Ensure sensitive data is securely processed, analyzed, and stored.

  • Besides authenticating the legitimacy of an email and its traffic to the recipient, it’s important to have procedures in place to protect the contents of an email.
  • Data classification is found not only in databases and spreadsheets, but also in the email messages being communicated. Examples of data most commonly included in emails:
    • Personal identifiable information (PII): social security number, financial account number, passcodes/passwords
  • Applying data classification to your email can help identify the sensitivity of the information it contains. This ensures any critical data within an email message is securely processed and protected against unauthorized use, theft, and loss.
  • Emails can be classified based on various sensitivity levels. such as:
    • Top secret, public, confidential, internal

Discover and Classify Your Data

Leverage this Info-Tech blueprint for guidelines on implementing a data classification program for your organization.

Info-Tech Insight
Having tools and technologies in place to ensure that data is classified and backed up will enable better storage, analysis, and processing of the email.

Data loss prevention (DLP)

Protect your data from being lost/stolen.

  • Protecting an email’s contents through data classification is only one approach for improving email security. Having a data loss prevention solution would further increase security by minimizing the threat of sensitive information leaving your organization’s email network.
  • Examples of tools embedded in DLP solutions that help monitor an organization's email communication:
    • Monitoring data sent and received from emails: This ensures the data within an email communication is protected with the necessary encryption based on its sensitivity.
    • Detecting suspicious email activity: This includes analyzing users’ email behavior regarding email attachments and identifying irregular behaviors.
    • Flagging or blocking email activities which may lead to data loss: This prevents highly sensitive data from being communicated via email and reduces the risk of information being intercepted.
  • The types of DLP technologies that can be leveraged include:
    • Rule-based: Data that has been tagged by admins as sensitive can be blocklisted, which would flag and/or block data from being sent via email.
    • Machine learning: Data on users’ email behavior is collected, processed, and trained to understand the employee’s normal email behavior and detect/flag suspicious activities.
  • Implementing DLP solutions would complement your data classification techniques by ensuring proper measures are in place to secure your organization’s assets through policies, technology, and tools.

48% of employees have accidently attached the wrong file to an email.

39% of respondents have accidently sent emails that contained security information such as passwords and passcodes.

Source: Tessian, 2021.

User awareness & training

A strong security awareness & training program is an important element of strengthening your email security.

  • Having all these tools and techniques in place to improve your email security will not be effective unless you also improve your employees’ awareness.
  • Employees should participate in email security training, especially since the majority utilize this channel of communication for day-to-day operations.
  • User awareness and training should go beyond phishing campaigns and should highlight the various types of email-based threats, the characteristics of these threats, and what procedures they can follow to minimize these threats.
  • 95% of data breaches are caused by human error. It can take nine months to discover and contain them, and they are expected to cost $8 trillion this year (Mimecast, 2023).
  • Investments in employee awareness and training would mitigate these risks by ensuring employees recognize and report suspicious emails, remain mindful of what type of data to share via email, and improve their overall understanding of the importance of email security.

Develop a Security Awareness and Training Program That Empowers End Users

Leverage this Info-Tech blueprint for assistance on creating various user training materials and empower your employees to become a main line of defense for your organization.

64% of organizations conduct formal training sessions (in-person or computer-based).

74% of organizations only focus on providing phishing-based training.

Source: Proofpoint, 2021.

Examples of email-based threats

Phishing
Email sent by threat actors designed to manipulate end user into providing sensitive information by posing as a trustworthy source

Business Email Compromise
Attackers trick a user into sending money or providing confidential information

Spam
Users receive unsolicited email, usually in bulk, some of which contains malware

Spear Phishing
A type of phishing attack where the email is sent to specific and targeted emails within the organization

Whaling
A type of phishing attack similar to spear phishing, but targeting senior executives within the organization

Password/Email Exposure
Employees use organizational email accounts and passwords to sign up for social media, leaving them susceptible to email and/or password exposure in a social media breach

Email policies

Having policies in place will enable these controls to be implemented.

Developing security policies that are reasonable, auditable, enforceable, and measurable ensures proper procedures are followed and necessary measures are implemented to protect the organization. Policies relating to email security can be categorized into two groups:

  • User policy: Policies employees must adhere to when using their corporate email. Examples:
    • User acceptance of technology: Acknowledgment of legitimate and restrictive actions when using corporate email
    • Security awareness and training: Acknowledging completion of email security training
  • Administrator-set policy: Policies that are implemented by IT and/or security admins. Examples:
    • Email backup: Policy on how long emails should be archived and processes for disposing of them
    • Log retention: Policy on how to retain, process, and analyze logs created from email servers
    • Throttling: Policies that limit the number of emails sent by a sender and the number of recipients per email and per day depending on the employee’s grouping

Develop and Deploy Security Policies

Leverage this Info-Tech blueprint for assistance on developing and deploying actionable policies and creating an overall policy management lifecycle to keep your policies current, effective, and compliant.

Info-Tech Insight
Policies ensure acceptable standards are in place to protect the organization’s assets, including the creation, attachment, sending, and receiving of emails.

Email security technologies & tools (SoftwareReviews)

SoftwareReviews, a division of Info-Tech Research Group, provides enterprise software reviews to help organizations make more efficient decisions during the software selection process. Reviews are provided by authenticated IT professionals who have leveraged the software and provide unbiased insights on different vendors and their products.

Learn from the collective knowledge of real IT professionals.

  • Know the products and features available.
  • Explore modules and detailed feature-level data.
  • Quickly understand the market.

Evaluate market leaders through vendor rankings and awards.

  • Convince stakeholders with professional reports.
  • Avoid pitfalls with unfiltered data from real users.
  • Choose software with confidence.

Cut through misleading marketing material.

  • Negotiate contracts based on data.
  • Know what to expect before you sign.
  • Effectively manage the vendor.

Email security technologies & tools

Leverage these tools for an enhanced email security solution.

Email Security Checklist

Follow these guidelines to ensure you are implementing best practices for securing your organization’s emails.

  • The Email Security Checklist is a tool to assess the current and future state of your organization’s email security and provides a holistic understanding on monitoring your progress within each category and associated controls.
  • The status column allows you to select the feature’s current implementation status, which includes the following options:
    • Enabled: The feature is deployed within the organization’s network.
    • Implemented: The feature is implemented within the organization’s network, but not yet deployed.
    • Not implemented: The feature has not been enabled or implemented.
  • Comments can be added for each feature to provide details such as indicating the progress on enabling/implementing a feature and why certain features are not yet implemented.

Email Security Checklist

Download the Email Security Checklist tool

Related Info-Tech Research

Discover and Classify Your Data
Leverage this Info-Tech blueprint for guidelines on implementing a data classification program for your organization.

Develop a Security Awareness and Training Program That Empowers End Users
Leverage this Info-Tech blueprint for assistance on creating various user training materials and empower your employees to become a main line of defense for your organization.

Develop and Deploy Security Policies
Leverage this Info-Tech blueprint for assistance on developing and deploying actionable policies and creating an overall policy management lifecycle to keep your policies current, effective, and compliant.

Bibliography

“10 Best Practices for Email Security in 2022.” TitanFile, 22 Sept. 2022. Web.

“2021 State of the Phish.” Proofpoint, 2021. Web.

Ahmad, Summra. “11 Email Security Best Practices You Shouldn't Miss (2023).” Mailmunch, 9 Mar. 2023. Web.

“Blumira's State of Detection and Response.” Blumira, 18 Jan. 2023. Web.

Clay, Jon. “Email Security Best Practices for Phishing Prevention.” Trend Micro, 17 Nov. 2022. Web.

Crane, Casey. “6 Email Security Best Practices to Keep Your Business Safe in 2019.” Hashed Out by The SSL Store™, 7 Aug. 2019. Web.

Hateb, Seif. “Basic Email Security Guide.” Twilio Blog, Twilio, 5 Dec. 2022. Web.

“How DMARC Advances Email Security.” CIS, 9 July 2021. Web.

Pal, Suryanarayan. “10 Email Security Best Practices You Should Know in 2023.” Mailmodo, 9 Feb. 2023. Web.

Pitchkites, Max. “Email Security: A Guide to Keeping Your Inbox Safe in 2023.” Cloudwards, 9 Dec. 2022. Web.

Rudra, Ahona. “Corporate Email Security Checklist.” PowerDMARC, 4 July 2022. Web.

“Sender Policy Framework.” Mimecast, n.d. Web.

Shea, Sharon, and Peter Loshin. “Top 15 Email Security Best Practices for 2023: TechTarget.” TechTarget, 14 Dec. 2022. Web.

“The Email Security Checklist: Upguard.” UpGuard, 16 Feb. 2022. Web.

“The State of Email Security 2023.” Mimecast, 2023. Web.

Wetherald, Harry. “New Product - Stop Employees Emailing the Wrong Attachments.” Tessian, 16 Sept. 2021. Web.

“What Is DMARC? - Record, Verification & More: Proofpoint Us.” Proofpoint, 9 Mar. 2023. Web.

“What Is Email Security? - Defining Security of Email: Proofpoint Us.” Proofpoint, 3 Mar.2023. Web.

Wilton, Laird. “How to Secure Email in Your Business with an Email Security Policy.” Carbide, 31 Jan. 2022. Web.

2021 CIO Priorities Report

  • Buy Link or Shortcode: {j2store}83|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: IT Strategy
  • Parent Category Link: /it-strategy
  • It is a new year, but the challenges of 2020 remain: COVID-19 infection rates continue to climb, governments continue to enforce lockdown measures, we continue to find ourselves in the worst economic crisis since the Great Depression, and civil unrest grows in many democratic societies.
  • At the start of 2020, no business leader predicted the disruption that was to come. This left IT in a reactive but critical role as the health crisis hit. It was core to delivering the organization’s products and services, as it drove the radical shift to work-from-home.
  • For the year ahead, IT will continue to serve a critical function in uncertain times. However, unlike last year, CIOs can better prepare for 2021. That said, in the face of the uncertainty and volatility of the year ahead, what they need to prepare for is still largely undefined.
  • But despite the lack of confidence on knowing specifically what is to come, most business leaders will admit they need to get ready for it. This year’s priority report will help.

Our Advice

Critical Insight

  • “Resilience” is the theme for this year’s CIO Priorities Report. In this context, resilience is about building up the capacity and the capabilities to effectively respond to emergent and unforeseen needs.
  • Early in 2021 is a good time to develop resilience in several different areas. As we explore in this year’s Report, CIOs can best facilitate enterprise resilience through strategic financial planning, proactive risk management, effective organizational change management and capacity planning, as well as through remaining tuned into emergent technologies to capitalize on innovations to help weather the uncertainty of the year ahead.

Impact and Result

  • Use Info-Tech’s 2021 CIO Priorities Report to prepare for the uncertainty of the year ahead. Across our five priorities we provide five avenues through which CIOs can demonstrate resilient planning, enabling the organization as a whole to better confront what’s coming in 2021.
  • Each of our priorities is backed up by a “call to action” that will help CIOs start to immediately implement the right drivers of resilience for their organization.
  • By building up resilience across our five key areas, CIOs will not only be able to better prepare for the year to come, but also strengthen business relations and staff morale in difficult times.

2021 CIO Priorities Report Research & Tools

Read the 2021 CIO Priorities Report

Use Info-Tech’s 2021 CIO Priorities Report to prepare for the uncertainty of the year ahead. Across our five priorities we provide five avenues through which CIOs can demonstrate resilient planning, enabling the organization as a whole to better confront what’s coming in 2021.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Create an appropriate budget reserve

Identifying and planning sources of financial contingency will help ensure CIOs can meet unforeseen and emergent operational and business needs throughout the year.

  • 2021 CIO Priorities Report: Priority 1 – Create an Appropriate Budget Reserve

2. Refocus IT risk planning

The start of 2021 is a time to refocus and redouble IT risk management and business continuity planning to bring it up to the standards of our “new normal.” Indeed, if last year taught us anything, it’s that no “black swan” should be off the table in terms of scenarios or possibilities for business disruption.

  • 2021 CIO Priorities Report: Priority 2 – Refocus IT Risk Planning

3. Strengthen organizational change management capabilities

At its heart, resilience is having the capacity to deal with unexpected change. Organizational change management can help build up this capacity, providing the ability to strategically plot known changes while leaving some capacity to absorb the unknowns as they present themselves.

  • 2021 CIO Priorities Report: Priority 3 – Strengthen Organizational Change Management Capabilities

4. Establish capacity awareness

Capacity awareness facilitates resilience by providing capital in the form of resource data. With this data, CIOs can make better decisions on what can be approved and when it can be scheduled for.

  • 2021 CIO Priorities Report: Priority 4 – Establish Capacity Awareness

5. Keep emerging technologies in view

Having an up-to-date view of emerging technologies will enable the resilient CIO to capitalize on and deploy leading-edge innovations as the business requires.

  • 2021 CIO Priorities Report: Priority 5 – Keep Emerging Technologies in View
[infographic]

Ensure Cloud Security in IaaS, PaaS, and SaaS Environments

  • Buy Link or Shortcode: {j2store}386|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Secure Cloud & Network Architecture
  • Parent Category Link: /secure-cloud-network-architecture
  • Security remains a large impediment to realizing cloud benefits. Numerous concerns still exist around the ability for data privacy, confidentiality, and integrity to be maintained in a cloud environment.
  • Even if adoption is agreed upon, it becomes hard to evaluate vendors that have strong security offerings and even harder to utilize security controls that are internally deployed in the cloud environment.

Our Advice

Critical Insight

  • The cloud can be secure despite unique security threats.
  • Securing a cloud environment is a balancing act of who is responsible for meeting specific security requirements.
  • Most security challenges and concerns can be minimized through our structured process (CAGI) of selecting a trusted cloud security provider (CSP) partner.

Impact and Result

  • The business is adopting a cloud environment and it must be secured, which includes:
    • Ensuring business data cannot be leaked or stolen.
    • Maintaining privacy of data and other information.
    • Securing the network connection points.
  • Determine your balancing act between yourself and your CSP; through contractual and configuration requirements, determine what security requirements your CSP can meet and cover the rest through internal deployment.
  • This blueprint and associated tools are scalable for all types of organizations within various industry sectors.

Ensure Cloud Security in IaaS, PaaS, and SaaS Environments Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out why you should prioritize security in the cloud, review Info-Tech’s methodology, and understand the ways we can support you in completing this project.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Determine your cloud risk profile

Determine your organization’s rationale for cloud adoption and what that means for your security obligations.

  • Ensure Cloud Security in IaaS, PaaS, and SaaS Environments – Phase 1: Determine Your Cloud Risk Profile
  • Secure Cloud Usage Policy

2. Identify your cloud security requirements

Use the Cloud Security CAGI Tool to perform four unique assessments that will be used to identify secure cloud vendors.

  • Ensure Cloud Security in IaaS, PaaS, and SaaS Environments – Phase 2: Identify Your Cloud Security Requirements
  • Cloud Security CAGI Tool

3. Evaluate vendors from a security perspective

Learn how to assess and communicate with cloud vendors with security in mind.

  • Ensure Cloud Security in IaaS, PaaS, and SaaS Environments – Phase 3: Evaluate Vendors From a Security Perspective
  • IaaS and PaaS Service Level Agreement Template
  • SaaS Service Level Agreement Template
  • Cloud Security Communication Deck

4. Implement your secure cloud program

Turn your security requirements into specific tasks and develop your implementation roadmap.

  • Ensure Cloud Security in IaaS, PaaS, and SaaS Environments – Phase 4: Implement Your Secure Cloud Program
  • Cloud Security Roadmap Tool

5. Build a cloud security governance program

Build the organizational structure of your cloud security governance program.

  • Ensure Cloud Security in IaaS, PaaS, and SaaS Environments – Phase 5: Build a Cloud Security Governance Program
  • Cloud Security Governance Program Template
[infographic]

Considerations for a Hub and Spoke Model When Deploying Infrastructure in the Cloud

  • Buy Link or Shortcode: {j2store}472|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Cloud Strategy
  • Parent Category Link: /cloud-strategy
  • The organization is planning to move resources to cloud or devise a networking strategy for their existing cloud infrastructure to harness value from cloud.
  • The right topology needs to be selected to deploy network level isolation, design the cloud for management efficiencies and provide access to shared services on cloud.
  • A perennial challenge for infrastructure on cloud is planning for governance vs flexibility which is often overlooked.

Our Advice

Critical Insight

Don’t wait until the necessity arises to evaluate your networking in the cloud. Get ahead of the curve and choose the topology that optimizes benefits and supports organizational needs in the present and the future.

Impact and Result

  • Define organizational needs and understand the pros and cons of cloud network topologies to strategize for the networking design.
  • Consider the layered complexities of addressing the governance vs. flexibility spectrum for your domains when designing your networks.

Considerations for a Hub and Spoke Model When Deploying Infrastructure in the Cloud Research & Tools

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Considerations for a Hub and Spoke Model When Deploying Infrastructure in the Cloud Deck – A document to guide you through designing your network in the cloud.

What cloud networking topology should you use? How do you provide access to shared resources in the cloud or hybrid infrastructure? What sits in the hub and what sits in the spoke?

  • Considerations for a Hub and Spoke Model When Deploying Infrastructure in the Cloud Storyboard
[infographic]

Further reading

Considerations for a Hub and Spoke Model When Deploying Infrastructure in the Cloud

Don't revolve around a legacy design; choose a network design that evolves with the organization.

Analyst Perspective

Cloud adoption among organizations increases gradually across both the number of services used and the amount those services are used. However, network builders tend to overlook the vulnerabilities of network topologies, which leads to complications down the road, especially since the structures of cloud network topologies are not all of the same quality. A network design that suits current needs may not be the best solution for the future state of the organization.

Even if on-prem network strategies were retained for ease of migration, it is important to evaluate and identify the cloud network topology that can not only elevate the performance of your infrastructure in the cloud, but also that can make it easier to manage and provision resources.

An "as the need arises" strategy will not work efficiently since changing network designs will change the way data travels within your network, which will then need to be adopted to existing application architectures. This becomes more complicated as the number of services hosted in the cloud grows.

Keep a network strategy in place early on and start designing your infrastructure accordingly. This gives you more control over your networks and eliminates the need for huge changes to your infrastructure down the road.

This is a picture of Nitin Mukesh

Nitin Mukesh
Senior Research Analyst, Infrastructure and Operations
Info-Tech Research Group

Executive Summary

Your Challenge

The organization is planning to move resources to the cloud or devise a networking strategy for their existing cloud infrastructure to harness value from the cloud.

The right topology needs to be selected to deploy network level isolation, design the cloud for management efficiencies, and provide access to shared services in the cloud.

A perennial challenge for infrastructure in the cloud is planning for governance vs. flexibility, which is often overlooked.

Common Obstacles

The choice of migration method may result in retaining existing networking patterns and only making changes when the need arises.

Networking in the cloud is still new, and organizations new to the cloud may not be aware of the cloud network designs they can consider for their business needs.

Info-Tech's Approach

Define organizational needs and understand the pros and cons of cloud network topologies to strategize for the networking design.

Consider the layered complexities of addressing the governance vs. flexibility spectrum for your domains when designing your networks.

Insight Summary

Don't wait until the necessity arises to evaluate your networking in the cloud. Get ahead of the curve and choose the topology that optimizes benefits and supports organizational needs in the present and future.

Your challenge

Selecting the right topology: Many organizations migrate to the cloud retaining a mesh networking topology from their on-prem design, or they choose to implement the mesh design leveraging peering technologies in the cloud without a strategy in place for when business needs change. While there may be many network topologies for on-prem infrastructure, the network design team may not be aware of the best approach in cloud platforms for their requirements, or a cloud networking strategy may even go overlooked during the migration.

Finding the right cloud networking infrastructure for:

  • Management efficiencies
  • Network-level isolation of resources
  • Access to shared services

Deciding between governance and flexibility in networking design: In the hub and spoke model, if a domain is in the hub, the greater the governance over it, and if it sits in the spoke, the higher the flexibility. Having a strategy for the most important domains is key. For example, some security belongs in the hub and some security belongs in the spoke. The tradeoff here is if it sits completely in the spoke, you give it a lot of freedom, but it becomes harder to standardize across the organization.

Mesh network topology

A mesh is a design where virtual private clouds (VPCs) are connected to each other individually creating a mesh network. The network traffic is fast and can be redirected since the nodes in the network are interconnected. There is no hierarchical relationship between the networks, and any two networks can connect with each other directly.

In the cloud, this design can be implemented by setting up peering connections between any two VPCs. These VPCs can also be set up to communicate with each other internally through the cloud service provider's network without having to route the traffic via the internet.

While this topology offers high redundancy, the number of connections grows tremendously as more networks are added, making it harder to scale a network using a mesh topology.

Mesh Network on AWS

This is an image of a Mesh Network on AWS

Source: AWS, 2018

Constraints

The disadvantages of peering VPCs into a mesh quickly arise with:

  • Transitive connections: Transitive connections are not supported in the cloud, unlike with on-prem networking. This means that if there are two networks that need to communicate, a single peering link can be set up between them. However, if there are more than two networks and they all need to communicate, they should all be connected to each other with separate individual connections.
  • Cost of operation: The lack of transitive routing requires many connections to be set up, which adds up to a more expensive topology to operate as the number of networks grows. Cloud providers also usually limit the number of peering networks that can be set up, and this limit can be hit with as few as 100 networks.
  • Management: Mesh tends to be very complicated to set up, owing to the large number of different peering links that need to be established. While this may be manageable for small organizations with small operations, for larger organizations with robust cybersecurity practices that require multiple VPCs to be deployed and interconnected for communications, mesh opens you up to multiple points of failure.
  • Redundancy: With multiple points of failure already being a major drawback of this design, you also cannot have more than one peered connection between any two networks at the same time. This makes designing your networking systems for redundancy that much more challenging.
Number of virtual networks 10 20 50 100
Peering links required
[(n-1)*n]/2
45 190 1225 4950

Proportional relationship of virtual networks to required peering links in a mesh topology

Case study

INDUSTRY: Blockchain
SOURCE: Microsoft

An organization with four members wants to deploy a blockchain in the cloud, with each member running their own virtual network. With only four members on the team, a mesh network can be created in the cloud with each of their networks being connected to each other, adding up to a total of 12 peering connections (four members with three connections each). While the members may all be using different cloud accounts, setting up connections between them will still be possible.

The organization wants to expand to 15 members within the next year, with each new member being connected with their separate virtual networks. Once grown, the organization will have a total of 210 peering connections since each of the virtual networks will then need 14 peering connections. While this may still be possible to deploy, the number of connections makes it harder to manage and would be that much more difficult to deploy if the organization grows to even 30 or 40 members. The new scale of virtual connections calls for an alternative networking strategy that cloud providers offer – the hub and spoke topology.

This is an image of the connections involved in a mesh network with four participants.

Source: Microsoft, 2017

Hub and spoke network topology

In hub and spoke network design, each network is connected to a central network that facilitates intercommunication between the networks. The central network, also called the hub, can be used by multiple workloads/servers/services for hosting services and for managing external connectivity. Other networks connected to the hub through network peering are called spokes and host workloads.

Communications between the workloads/servers/services on spokes pass in or out of the hub where they are inspected and routed. The spokes can also be centrally managed from the hub with IT rules and processes.

A hub and spoke design enable a larger number of virtual networks to be interconnected as each network only needs one peered connection (to the hub) to be able to communicate with any other network in the system.

Hub and Spoke Network on AWS

This is an image of the Hub and Spoke Network on AWS

What hub and spoke networks do better

  1. Ease of connectivity: Hub and spoke decreases the liabilities of scale that come from a growing business by providing a consistent connection that can be scaled easily. As more networks are added to an organization, each will only need to be connected once – to the hub. The number of connections is considerably lower than in a mesh topology and makes it easier to maintain and manage.
  2. Business agility and scalability: It is easier to increase the number of networks than in mesh, making it easier to grow your business into new channels with less time, investment, and risk.
  3. Data collection: With a hub and spoke design, all data flows through the hub – depending on the design, this includes all ingress and egress to and from the system. This makes it an excellent central network to collect all business data.
  4. Network-level isolation: Hub and spoke enables separation of workloads and tiers into different networks. This is particularly useful to ensure an issue affecting a network or a workload does not affect the rest.
  5. Network changes: Changes to a separated network are much easier to carry out knowing the changes made will not affect all the other connected networks. This reduces work-hours significantly when systems or applications need to be altered.
  6. Compliance: Compliance requirements such as SOC 1 and SOC 2 require separate environments for production, development, and testing, which can be done in a hub and spoke model without having to re-create security controls for all networks.

Hub and spoke constraints

While there are plenty of benefits to using this topology, there are still a few notable disadvantages with the design.

Point-to-point peering

The total number of total peered connections required might be lower than mesh, but the cost of running independent projects is cheaper on mesh as point-to-point data transfers are cheaper.

Global access speeds with a monolithic design

With global organizations, implementing a single monolithic hub network for network ingress and egress will slow down access to cloud services that users will require. A distributed network will ramp up the speeds for its users to access these services.

Costs for a resilient design

Connectivity between the spokes can fail if the hub site dies or faces major disruptions. While there are redundancy plans for cloud networks, it will be an additional cost to plan and build an environment for it.

Leverage the hub and spoke strategy for:

Providing access to shared services: Hub and spoke can be used to give workloads that are deployed on different networks access to shared services by placing the shared service in the hub. For example, DNS servers can be placed in the hub network, and production or host networks can be connected to the hub to access it, or if the central network is set up to host Active Directory services, then servers in other networks can act as spokes and have full access to the central VPC to send requests. This is also a great way to separate workloads that do not need to communicate with each other but all need access to the same services.

Adding new locations: An expanding organization that needs to add additional global or domestic locations can leverage hub and spoke to connect new network locations to the main system without the need for multiple connections.

Cost savings: Apart from having fewer connections than mesh that can save costs in the cloud, hub and spoke can also be used to centralize services such as DNS and NAT to be managed in one location rather than having to individually deploy in each network. This can bring down management efforts and costs considerably.

Centralized security: Enterprises can deploy a center of excellence on the hub for security, and the spokes connected to it can leverage a higher level of security and increase resilience. It will also be easier to control and manage network policies and networking resources from the hub.

Network management: Since each spoke is peered only once to the hub, detecting connectivity problems or other network issues is made simpler in hub and spoke than on mesh. A network manager deployed on the cloud can give access to network problems faster than on other topologies.

Hub and spoke – mesh hybrid

The advantages of using a hub and spoke model far exceed those of using a mesh topology in the cloud and go to show why most organizations ultimately end up using the hub and spoke as their networking strategy.

However, organizations, especially large ones, are complex entities, and choosing only one model may not serve all business needs. In such cases, a hybrid approach may be the best strategy. The following slides will demonstrate the advantages and use cases for mesh, however limited they might be.

Where it can be useful:

An organization can have multiple network topologies where system X is a mesh and system Y is a hub and spoke. A shared system Z can be a part of both systems depending on the needs.

An organization can have multiple networks interconnected in a mesh and some of the networks in the mesh can be a hub for a hub-spoke network. For example, a business unit that works on data analysis can deploy their services in a spoke that is connected to a central hub that can host shared services such as Active Directory or NAT. The central hub can then be connected to a regional on-prem network where data and other shared services can be hosted.

Hub and spoke – mesh hybrid network on AWS

This is an image of the Hub and spoke – mesh hybrid network on AWS

Why mesh can still be useful

Benefits Of Mesh

Use Cases For Mesh

Security: Setting up a peering connection between two VPCs comes with the benefit of improving security since the connection can be private between the networks and can isolate public traffic from the internet. The traffic between the networks never has to leave the cloud provider's network, which helps reduce a class of risks.

Reduced network costs: Since the peered networks communicate internally through the cloud's internal networks, the data transfer costs are typically cheaper than over the public internet.

Communication speed: Improved network latency is a key benefit from using mesh because the peered traffic does not have to go over the public internet but rather the internal network. The network traffic between the connections can also be quickly redirected as needed.

Higher flexibility for backend services: Mesh networks can be desirable for back-end services if egress traffic needs to be blocked to the public internet from the deployed services/servers. This also helps avoid having to set up public IP or network address translation (NAT) configurations.

Connecting two or more networks for full access to resources: For example, consider an organization that has separate networks for each department, which don't all need to communicate with each other. Here, a peering network can be set up only between the networks that need to communicate with full or partial access to each other such as finance to HR or accounting to IT.

Specific security or compliance need: Mesh or VPC peering can also come in handy to serve specific security needs or logging needs that require using a network to connect to other networks directly and in private. For example, global organizations that face regulatory requirements of storing or transferring data domestically with private connections.

Systems with very few networks that do not need internet access: Workloads deployed in networks that need to communicate with each other but do not require internet access or network address translation (NAT) can be connected using mesh especially when there are security reasons to keep them from being connected to the main system, e.g. backend services such as testing environments, labs, or sandboxes can leverage this design.

Designing for governance vs. flexibility in hub and spoke

Governance and flexibility in managing resources in the cloud are inversely proportional: The higher the governance, the less freedom you have to innovate.

The complexities of designing an organization's networks grow with the organization as it becomes global and takes on more services and lines of business. Organizations that choose to deploy the hub and spoke model face a dilemma in choosing between governance and flexibility for their networks. Organizations need to find that sweet spot to find the right balance between how much they want to govern their systems, mainly for security- and cost-monitoring, and how much flexibility they want to provide for innovation and other operations, since the two usually tend to have an inverse relationship.

This decision in hub and spoke usually means that the domains chosen for higher governance must be placed in the hub network, and the domains that need more flexibility in a spoke. The key variables in the following slide will help determine the placement of the domain and will depend entirely on the organization's context.

The two networking patterns in the cloud have layered complexities that need to be systematically addressed.

Designing for governance vs. flexibility in hub and spoke

If a network has more flexibility in all or most of these domains, it may be a good candidate for a spoke-heavy design; otherwise, it may be better designed in a hub-centric pattern.

  • Function: The function the domain network is assigned to and the autonomy the function needs to be successful. For example, software R&D usually requires high flexibility to be successful.
  • Regulations: The extent of independence from both internal and external regulatory constraints the domain has. For example, a treasury reporting domain typically has high internal and external regulations to adhere to.
  • Human resources: The freedom a domain has to hire and manage its resources to perform its function. For example, production facilities in a huge organization have the freedom to manage their own resources.
  • Operations: The freedom a domain has to control its operations and manage its own spending to perform its functions. For example, governments usually have different departments and agencies, each with its own budget to perform its functions.
  • Technology: The independence and the ability a domain has to manage its selection and implementation of technology resources in the cloud. For example, you may not want a software testing team to have complete autonomy to deploy resources.

Optimal placement of services between the hub and spoke

Shared services and vendor management

Resources that are shared between multiple projects or departments or even by the entire organization should be hosted on the hub network to simplify sharing these services. For example, e-learning applications that may be used by multiple business units to train their teams, Active Directory accessed by most teams, or even SAAS platforms such as O365 and Salesforce can leverage buying power and drive down the costs for the organization. Shared services should also be standardized across the organization and for that, it needs to have high governance.

Services that are an individual need for a network and have no preexisting relationship with other networks or buying power and scale can be hosted in a spoke network. For example, specialized accounting software used exclusively by the accounting team or design software used by a single team. Although the services are still a part of the wider network, it helps separate duties from the shared services network and provides flexibility to the teams to customize and manage their services to suit their individual needs.

Network egress and interaction

Network connections, be they in the cloud or hybrid-cloud, are used by everyone to either connect to the internet, access cloud services, or access the organization's data center. Since this is a shared service, a centralized networking account must be placed in the hub for greater governance. Interactions between the spokes in a hub and spoke model happens through the hub, and providing internet access to the spokes through the hub can help leverage cost benefits in the cloud. The network account will perform routing duties between the spokes, on-prem assets, and egress out to the internet.

For example, NAT gateways in the cloud that are managed services are usually charged by the hour, and deploying NAT on each spoke can be harder to manage and expensive to maintain. A NAT gateway deployed in a central networking hub can be accessed by all spokes, so centralizing it is a great option.

Note that, in some cases, when using edge locations for data transfers, it may be cost effective to deploy a NAT in the spoke, but such cases usually do not apply to most organizational units.

A centralized network hub can also be useful to configure network policies and network resources while organizational departments can configure non-network resources, which helps separate responsibilities for all the spokes in the system. For example, subnets and routes can be controlled from the central network hub to ensure standardized network policies across the network.

Security

While there needs to be security in the hub and the spokes individually, finding the balance of operation can make the systems more robust. Hub and spoke design can be an effective tool for security when a principal security hub is hosted in the hub network. The central security hub can collect data from the spokes as well as non-spoke sources such as regulatory bodies and threat intelligence providers, and then share the information with the spokes.

Threat information sharing is a major benefit of using this design, and the hub can take actions to analyze and enrich the data before sharing it with spokes. Shared services such as threat intelligence platforms (TIP) can also benefit from being centralized when stationed in the hub. A collective defense approach between the hub and spoke can be very successful in addressing sophisticated threats.

Compliance and regulatory requirements such as HIPAA can also be placed in the hub, and the spokes connected to it can make use of it instead of having to deploy it in each spoke individually.

Cloud metering

The governance vs. flexibility paradigm usually decides the placement of cloud metering, i.e. if the organization wants higher control over cloud costs, it should be in the central hub, whereas if it prioritizes innovation, the spokes should be allowed to control it. Regardless of the placement of the domain, the costs can be monitored from the central hub using cloud-native monitoring tools such as Azure Monitor or any third-party software deployed in the hub.

For ease of governance and since resources are usually shared at a project level, most cloud service providers suggest that an individual metering service be placed in the spokes. The centralized billing system of the organization, however, can make use of scale and reserved instances to drive down the costs that the spokes can take advantage of. For example, billing and access control resources are placed in the lower levels in GCP to enable users to set up projects and perform their tasks. These billing systems in the lower levels are then controlled by a centralized billing system to decide who pays for the resources provisioned.

Don't get stuck with your on-prem network design. Design for the cloud.

  1. Peering VPCs into a mesh design can be an easy way to get onto the cloud, but it should not be your networking strategy for the long run.
  2. Hub and spoke network design offers more benefits than any other network strategy to be adopted only when the need arises. Plan for the design early on and keep a strategy in place to deploy it as early as possible.
  3. Hybrid of mesh and hub and spoke will be very useful in connecting multiple large networks especially when they need to access the same resources without having to route the traffic over the internet.
  4. Governance vs. flexibility should be a key consideration when designing for hub and spoke to leverage the best out of your infrastructure.
  5. Distribute domains across the hub or spokes to leverage costs, security, data collection, and economies of scale, and to foster secure interactions between networks.

Cloud network design strategy

This is an image of the framework for developing a Cloud Network Design Strategy.

Bibliography

Borschel, Brett. "Azure Hub Spoke Virtual Network Design Best Practices." Acendri Solutions, 13 Jan. 2022. Web.
Singh, Garvit. "Amazon Virtual Private Cloud Connectivity Options." AWS, January 2018. Web.
"What Is the Hub and Spoke Information Sharing Model?" Cyware, 16 Aug. 2021. Web.
Youseff, Lamia. "Mesh and Hub-and-Spoke Networks on Azure." Microsoft, Dec. 2017. Web.

Architect Your Big Data Environment

  • Buy Link or Shortcode: {j2store}202|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Big Data
  • Parent Category Link: /big-data
  • Organizations may understand the transformative potential of a big data initiative, but they struggle to make the transition from the awareness of its importance to identifying a concrete use case for a pilot project.
  • The big data ecosystem is crowded and confusing, and a lack of understanding of it may cause paralysis for organizations.

Our Advice

Critical Insight

  • Don’t panic, and make use of the resources you already have. The skills, tools, and infrastructure for big data can break any budget quickly, but before making rash decisions, start with the resources you have in-house.
  • Big data as a service (BDaaS) is making big waves. BDaaS removes many of the hurdles associated with implementing a big data strategy and vastly lowers the barrier of entry.

Impact and Result

  • Follow Info-Tech’s methodology for understanding the types of modern approaches to big data tools, and then determining which approach style makes the most sense for your organization.
  • Based on your big data use case, create a plan for getting started with big data tools that takes into account the backing of the use case, the organization’s priorities, and resourcing available.
  • Put a repeatable framework in place for creating a comprehensive big data tool environment that will help you decide on the necessary tools to help you realize the value from your big data use case and scale for the future.

Architect Your Big Data Environment Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out why you should find your optimal approach to big data tools, review Info-Tech’s methodology, and understand the ways we can support you in completing this project.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Plant the foundations of your big data tool architecture

Identify your big data use case and your current data-related capabilities.

  • Architect Your Big Data Environment – Phase 1: Plant the Foundations of Your Big Data Tool Architecture
  • Big Data Execution Plan Presentation
  • Big Data Architecture Planning Tool

2. Weigh your big data architecture decision criteria

Determine your capacity for big data tools, as well as the level of customizability and security needed for your solution to help justify your implementation style decision.

  • Architect Your Big Data Environment – Phase 2: Weigh Your Big Data Architecture Decision Criteria

3. Determine your approach to implementing big data tools

Analyze the three big data implementation styles, select your approach, and complete the execution plan for your big data initiative.

  • Architect Your Big Data Environment – Phase 3: Determine Your Approach To Implementing Big Data Tools
[infographic]

Prepare for the Upgrade to Windows 11

  • Buy Link or Shortcode: {j2store}166|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: End-User Computing Devices
  • Parent Category Link: /end-user-computing-devices
  • Windows 10 is going EOL in 2025.That is closer than you think.
  • Many of your endpoints are not eligible for the Windows 11 upgrade. You can’t afford to replace all your endpoints this year. How do you manage this Microsoft initiated catastrophe?
  • You want to stay close to the leading edge of technology and services, but how do you do that while keeping your spending in check and within budget?

Our Advice

Critical Insight

Windows 11 is a step forward in security, which is one of the primary reasons for the release of the new operating system. Windows 11 comes with a list of hardware requirements that enable the use of tools and features that, when combined, will reduce malware infections.

Impact and Result

Windows 11 hardware requirements will result in devices that are not eligible for the upgrade. Companies will be left to spend money on replacement devices. Following the Info-Tech guidance will help clients properly budget for hardware replacements before Windows 10 is no longer supported by Microsoft. Eligible devices can be upgraded, but Info-Tech guidance can help clients properly plan the upgrade using the upgrade ring approach.

Prepare for the Upgrade to Windows 11 Research & Tools

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Prepare for the Upgrade to Windows 11 Deck – A look into some of the pros and cons of Microsoft’s latest desktop operating system, along with guidance on moving forward with this inevitable upgrade.

Discover the reason for the release of Windows 11, what you require to be eligible for the upgrade, what features were added or updated, and what features were removed. Our guidance will assist you with a planned and controlled rollout of the Windows 11 upgrade. We also provide guidance on how to approach a device refresh plan if some devices are not eligible for Windows 11. The upgrade is inevitable, but you have time, and you have options.

  • Prepare for the Upgrade to Windows 11 Storyboard

2. What Are My Options If My Devices Cannot Upgrade to Windows 11? – Build a Windows 11 Device Replacement budget with our Hardware Asset Management Budgeting Tool.

This tool will help you budget for a hardware asset refresh and to adjust the budget as necessary to accommodate any unexpected changes. The tool can easily be modified to assist in developing and justifying the budget for hardware assets for a Windows 11 project. Follow the instructions on each tab and feel free to play with the HAM budgeting tool to fit your needs.

  • HAM Budgeting Tool
[infographic]

Further reading

Prepare for the Upgrade to Windows 11

The upgrade is inevitable, but you have time, and you have options.

Analyst Perspective

Upgrading to Windows 11 is easy, and while it should be properly investigated and planned, it should absolutely be an activity you undertake.

“You hear that Mr. Anderson? That is the sound of inevitability.” ("The Matrix Quotes" )

The fictitious Agent Smith uttered those words to Keanu Reeves’ character, Neo, in The Matrix in 1999, and while Agent Smith was using them in a very sinister and figurative context, the words could just as easily be applied to the concept of upgrading to the Windows 11 operating system from Microsoft in 2022.

There have been two common, recurring themes in the media since late 2019. One is the global pandemic and the other is cyber-related crime. Microsoft is not in a position to make an impact on a novel coronavirus, but it does have the global market reach to influence end-user technology and it appears that it has done just that. Windows 11 is a step forward in endpoint security and functionality. It also solidifies the foundation for future innovations in end-user operating systems and how they are delivered. Windows-as-a-Service (WAAS) is the way forward for Microsoft. Windows 10 is living on borrowed time, with a defined end of support date of October 14, 2025. Upgrading to Windows 11 is easy, and while it should be properly investigated and planned, it should absolutely be an activity you undertake.

It is inevitable!

P.J. Ryan

Research Director, Infrastructure & Operations

Info-Tech Research Group

Executive Summary

Your Challenge

  • Windows 10 is going EOL in 2025. That is closer than you think.
  • Many of your endpoints are not eligible for the Windows 11 upgrade. You can’t afford to replace all your endpoints this year. How do you manage this Microsoft-initiated catastrophe?
  • You want to stay close to the leading edge of technology and services, but how do you do that while keeping your spending in check and within budget?

Common Obstacles

  • The difference between Windows 10 and Windows 11 is not clear. Windows 11 looks like Windows 10 with some minor changes, mostly cosmetic. Many online users don’t see the need. Why upgrade? What are the benefits?
  • The cost of upgrading devices just to be eligible for Windows 11 is high.
  • Your end users don’t like change. This is not going to go over well!

Info-Tech's Approach

  • Spend wisely. Space out your endpoint replacements and upgrades over several years. You do not have to upgrade everything right away.
  • Be patient. Windows 11 contained some bugs when it was initially released. Microsoft fixed most of the issues through monthly quality updates, but you should ensure that you are comfortable with the current level of functionality before you upgrade.
  • Use the upgrade ring approach. Test your applications with a small group first, and then stage the rollout to increasingly larger groups over time.

Info-Tech Insight

There is a lot of talk about Windows 11, but this is only an operating system upgrade, and it is not a major one. Understand what is new, what is added, and what is missing. Check your devices to determine how many are eligible and ineligible. Many organizations will have to spend capital on endpoint upgrades. Solid asset management practices will help.

Insight summary

Windows 11 is a step forward in security, which is one of the primary reasons for the release of the new operating system.

Windows 11 comes with a list of hardware requirements that enable the use of tools and features that, when combined, will reduce malware infections.

The hardware requirements for Windows 11 enable security features such as password-less logon, disk encryption, increased startup protection with secure boot, and virtualization-based security.

Many organizations will have to spend capital on endpoint upgrades.

Microsoft now insists that modern hardware is required for Windows 11 for not only security but also for improved stability. That same hardware requirement will mean that many devices that are only three or four years old (as well as older ones) may not be eligible for Windows 11.

Windows 11 is a virtualization challenge for some providers.

The hardware requirements for physical devices are also required for virtual devices. The TPM module appears to be the biggest challenge. Oracle VirtualBox and Citrix Hypervisor as well as AWS and Google are unable to support Windows 11 virtual devices as of the time of writing.

Windows 10 will be supported by Microsoft until October 2025.

That will remove some of the pressure felt due to the ineligibility of many devices and the need to refresh them. Take your time and plan it out, keeping within budget constraints. Use the upgrade ring approach for systems that are eligible for the Windows 11 upgrade.

New look and feel, and a center screen taskbar.

Corners are rounded, some controls look a little different, but overall Windows 11 is not a dramatic shift from Windows 10. It is easier to navigate and find features. Oh, and yes, the taskbar (and start button) is shifted to the center of the screen, but you can move them back to the left if desired.

The education industry gets extra attention with the release of Windows 11.

Windows 11 comes with multiple subscription-based education offerings, but it also now includes a new lightweight SE edition that is intended for the K-8 age group. Microsoft also released a Windows 11 Education SE specific laptop, at a very attractive price point. Other manufacturers also offer Windows 11 SE focused devices.

Why Windows 11?

Windows 10 was supposed to be the final desktop OS from Microsoft, wasn’t it?

Maybe. It depends who you ask.

Jerry Nixon, a Microsoft developer evangelist, gained notoriety when he uttered these words while at a Microsoft presentation as part of Microsoft Ignite in 2015: “Right now we’re releasing Windows 10, and because Windows 10 is the last version of Windows, we’re all still working on Windows 10,” (Hachman). Microsoft never officially made that statement. Interestingly enough, it never denied the comments made by Jerry Nixon either.

Perhaps Microsoft released a new operating system as a financial grab, a way to make significant revenue?

Nope.

Windows 11 is a free upgrade or is included with any new computer purchase.

Market share challenges?

Doubtful.

It’s true that Microsoft's market share of desktop operating systems is dropping while Apple OS X and Google Chrome OS are rising.

In fact, Microsoft has relinquished over 13% of the market share since 2012 and Apple has almost doubled its market share. BUT:

Microsoft is still holding 75.12% of the market while Apple is in the number 2 spot with 14.93% (gs.statcounter.com).

The market share is worth noting for Microsoft but it hardly warrants a new operating system.

New look and feel?

Unlikely

New start button and taskbar orientation, new search window, rounded corners, new visual look on some controls like the volume bar, new startup sound, new Windows logo, – all minor changes. Updates could achieve the same result.

Security?

Likely the main reason.

Windows 11 comes with a list of hardware requirements that enable the use of tools and features that, when combined, will reduce malware infections.

The hardware requirements for Windows 11 enable security features such as password-less logon, disk encryption, increased startup protection with secure boot, and virtualization-based security.

The features are available on all Windows 11 physical devices, due to the common hardware requirements.

Windows 11 hardware-based security

These hardware options and features were available in Windows 10 but not enforced. With Windows 11, they are no longer optional. Below is a description and explanation of the main features.

Feature What it is How it works
TPM 2.0 (Trusted Platform Module) Chip TPM is a chip on the motherboard of the computer. It is used to store encryption keys, certificates, and passwords. TPM does this securely with tamper-proof prevention. It can also generate encryption keys and it includes its own unique encryption key that cannot be altered (helpdeskgeek.com). You do not need to enter your password once you setup Windows Hello, so the password is no longer easy to capture and steal. It is set up on a device per device basis, meaning if you go to a different device to sign in, your Windows Hello authentication will not follow you and you must set up your Hello pin or facial recognition again on that particular device. TPM (Trusted Platform Module) can store the credentials used by Windows Hello and encrypt them on the module.
Windows Hello Windows Hello is an alternative to using a password for authentication. Users can use a pin, a fingerprint, or facial recognition to authenticate.
Device Encryption Device encryption is only on when your device is off. It scrambles the data on your disk to make it unreadable unless you have the key to unscramble it. If your endpoint is stolen, the contents of the hard drive will remain encrypted and cannot be accessed by anyone unless they can properly authenticate on the device and allow the system to unscramble the encrypted data.
UEFI Secure Boot Capable UEFI is an acronym for Unified Extensible Firmware Interface. It is an interface between the operating system and the computer firmware. Secure Boot, as part of the firmware interface, ensures that only unchangeable and approved software and drivers are loaded at startup and not any malware that may have infiltrated the system (Lumunge). UEFI, with Secure Boot, references a database containing keys and signatures of drivers and runtime code that is approved as well as forbidden. It will not let the system boot up unless the signature of the driver or run-time code that is trying to execute is approved. This UEFI Secure boot recognition process continues until control is handed over to the operating system.
Virtualization Based Security (VBS) and Hypervisor-Protected Code Integrity (HVCI) VBS is security based on virtualization capabilities. It uses the virtualization features of the Windows operating system, specifically the Hyper-V hypervisor, to create and isolate a small chunk of memory that is isolated from the operating system. HVCI checks the integrity of code for violations. The Code Integrity check happens in the isolated virtual area of memory protected by the hypervisor, hence the acronym HVCI (Hypervisor Protected Code Integrity) (Murtaza). In the secure, isolated region of memory created by VBS with the hypervisor, Windows will run checks on the integrity of the code that runs various processes. The isolation protects the stored item from tampering by malware and similar threats. If they run incident free, they are released to the operating system and can run in the standard memory space. If issues are detected, the code will not be released, nor will it run in the standard memory space of the operating system, and damage or compromise will be prevented.

How do all the hardware-based security features work?

This scenario explains how a standard boot up and login should happen.

You turn on your computer. Secure Boot authorizes the processes and UEFI hands over control to the operating system. Windows Hello works with TPM and uses a pin to authenticate the user and the operating systems gives you access to the Windows environment.

Now imagine the same process with various compromised scenarios.

You turn on your computer. Secure Boot does not recognize the signature presented to it by the second process in the boot sequence. You will be presented with a “Secure Boot Violation” message and an option to reboot. Your computer remains protected.

You boot up and get past the secure boot process and UEFI passes control over to the Windows 11 operating system. Windows Hello asks for your pin, but you cannot remember the pin and incorrectly enter it three times before admitting temporary defeat. Windows Hello did not find a matching pin on the TPM and will not let you proceed. You cannot log in but in the eyes of the operating system, it has prevented an unauthorized login attempt.

You power up your computer, log in without issue, and go about your morning routine of checking email, etc. You are not aware that malware has infiltrated your system and modified a page in system memory to run code and access the operating system kernel. VBS and HVCI check the integrity of that code and detect that it is malicious. The code remains isolated and prevented from running, protecting your system.

TPM, Hello, UEFI with Secure Boot, VBS and HVCI all work together like a well-oiled machine.

“Microsoft's rationale for Windows 11's strict official support requirements – including Secure Boot, a TPM 2.0 module, and virtualization support – has always been centered on security rather than raw performance.” – Andrew Cunningham, arstechnica.com

“Windows 11 raises the bar for security by requiring hardware that can enable protections like Windows Hello, Device Encryption, virtualization-based security (VBS), hypervisor-protected code integrity (HVCI), and Secure Boot. These features in combination have been shown to reduce malware by 60% on tested devices.” – Steven J. Vaughan-Nichols, Computerworld

Can any device upgrade to Windows 11?

In addition to the security-related hardware requirements listed previously, which may exclude some devices from Windows 11 eligibility, Windows 11 also has a minimum requirement for other hardware components.

Windows 7 and Windows 10 were publicized as being backward compatible and almost any hardware would be able to run those operating systems. That changed with Windows 11. Microsoft now insists that modern hardware is required for Windows 11 for not only security but also improved stability.

Software Requirement

You must be running Windows 10 version 2004 or greater to be eligible for a Windows 11 upgrade (“Windows 11 Requirements”).

Complete hardware requirements for Windows 11

  • 1 GHz (or faster) compatible 64-bit processor with two or more cores
  • 4 GB RAM
  • 64 GB or more of storage space
  • Compatible with DirectX 12 or later with WDDM 2.0 driver
    • DirectX connects the hardware in your computer with Windows. It allows software to display graphics using the video card or play audio, as long as that software is DirectX compatible. Windows 11 requires version 12 (“What are DirectX 12 compatible graphics”).
    • WDDM is an acronym for Windows Display Driver Model. WDDM is the architecture for the graphics driver for Windows (“Windows Display Driver Model”).
    • Version 2.0 of WDDM is required for Windows 11.
  • 720p display greater than 9" diagonally with 8 bits per color channel
  • UEFI Secure Boot capable
  • TPM 2.0 chip
  • (“Windows 11 Requirements”)

Windows 11 may challenge your virtual environment

When Windows 11 was initially released, some IT administrators experienced issues when trying to install or upgrade to Windows 11 in the virtual world.

The Challenge

The issues appeared to be centered around the Windows 11 hardware requirements, which must be detected by the Windows 11 pre-install check before the operating system will install.

The TPM 2.0 chip requirement was indeed a challenge and not offered as a configuration option with Citrix Hypervisor, the free VMware Workstation Player or Oracle VM VirtualBox when Windows 11 was released in October 2021, although it is on the roadmap for Oracle and Citrix Hypervisor. VMware provides alternative products to the free Workstation Player that do support a virtual TPM. Oracle and Citrix reported that the feature would be available in the future and Windows 11 would work on their platforms.

Short-Term Solutions

VMware and Microsoft users can add a vTPM hardware type when configuring a virtual Windows 11 machine. Microsoft Azure does offer Windows 11 as an option as a virtual desktop. Citrix Desktop-As-A-Service (DAAS) will connect to Azure, AWS, or Google Cloud and is only limited by the features of the hosting cloud service provider.

Additional Insight

According to Microsoft, any VM running Windows 11 must meet the following requirements (“Virtual Machine Support”):

  • It must be a generation 2 VM, and upgrading a generation 1 VM to Windows 11 (in-place) is not possible
  • 64 GB of storage or greater
  • Secure Boot capable with the virtual TPM enabled
  • 4 GB of memory or greater
  • 2 or more virtual processors
  • The CPU of the physical computer that is hosting the VM must meet the Windows 11 (“Windows Processor Requirements”)

What’s new or updated in Windows 11?

The following two slides highlight some of the new and updated features in Windows 11.

Security

The most important change with Windows 11 is what you cannot see – the security. Windows 11 adds requirements and controls to make the user and device more secure, as described in previous slides.

Taskbar

The most prominent change in relation to the look and feel of Windows 11 is the shifting of the taskbar (and Start button) to the center of the screen. Some users may find this more convenient but if you do not and prefer the taskbar and start button back on the left of your screen, you can change it in taskbar settings.

Updated Apps

Paint, Photos, Notepad, Media Player, Mail, and other standard Windows apps have been updated with a new look and in some cases minor enhancements.

User Interface

The first change users will notice after logging in to Windows 11 is the new user interface – the look and feel. You may not notice the additional colors added to the Windows palette, but you may have thought that the startup sound was different, and the logo also looks different. You would be correct. Other look-and-feel items that changed include the rounded corners on windows, slightly different icons, new wallpapers, and controls for volume and brightness are now a slide bar. File explorer and the settings app also have a new look.

Microsoft Teams

Microsoft Teams is now installed on the taskbar by default. Note that this is for a personal Microsoft account only. Teams for Work or School will have to be installed separately if you are using a work or school account.

What’s new or updated in Windows 11?

Snap Layouts

Snap layouts have been enhanced and snap group functionality has been added. This will allow you to quickly snap one window to the side of the screen and open other Windows in the other side. This feature can be accessed by dragging the window you wish to snap to the left or right edge of the screen. The window should then automatically resize to occupy that half of the screen and allow you to select other Windows that are already open to occupy the remaining space on the screen. You can also hover your mouse over the maximize button in the upper right-hand corner of the window. A small screen with multiple snap layouts will appear for your selection. Multiple snapped Windows can be saved as a “Snap Group” that will open together if one of the group windows are snapped in the future.

Widgets

Widgets are expanding. Microsoft started the re-introduction of widgets in Windows 10, specifically focusing on the weather. Widgets now include other services such as news, sports, stock prices, and others.

Android Apps

Android apps can now run in Windows 11. You will have to use the Amazon store to access and install Android apps, but if it is available in the Amazon store, you can install it on Windows 11.

Docking

Docking has improved with Windows 11. Windows knows when you are docked and will minimize apps when you undock so they are not lost. They will appear automatically when you dock again.

This is not intended to be an inclusive list but does cover some of the more prominent features.

What’s missing from Windows 11?

The following features are no longer found in Windows 11:

  • Backward compatibility
    • The introduction of the hardware requirements for Windows 11 removed the backward compatibility (from a hardware perspective) that made the transition from previous versions of Windows to their successor less of a hardware concern. If a computer could run Windows 7, then it could also run Windows 10. That does not automatically mean it can also run Windows 11.
  • Internet Explorer
    • Internet Explorer is no longer installed by default in Windows 11. Microsoft Edge is now the default browser for Windows. Other browsers can also be installed if preferred.
  • Tablet mode
    • Windows 11 does not have a "tablet" mode, but the operating system will maximize the active window and add more space between icons to make selecting them easier if the 2-in-1 hardware detects that you wish to use the device as a tablet (keyboard detached or device opened up beyond 180 degrees, etc.).
  • Semi-annual updates
    • It may take six months or more to realize that semi-annual feature updates are missing. Microsoft moved to an annual feature update schema but continued with monthly quality updates with Windows 11.
  • Specific apps
    • Several applications have been removed (but can be manually added from the Microsoft Store by the user). They include:
      • OneNote for Windows 10
      • 3D Viewer
      • Paint 3D
      • Skype
  • Cortana (by default)
    • Cortana is missing from Windows 11. It is installed but not enabled by default. Users can turn it on if desired.

Microsoft included a complete list of features that have been removed or deprecated with Windows 11, which can be found here Windows 11 Specs and System Requirements.

Windows 11 editions

  • Windows 11 is offered in several editions:
    • Windows 11 Home
    • Windows 11 Pro
    • Windows 11 Pro for Workstations
    • Windows 11 Enterprise Windows 11 for Education
    • Windows 11 SE for Education
  • Windows 11 hardware requirements and security features are common throughout all editions.
  • The new look and feel along with all the features mentioned previously are common to all editions as well.
  • Windows Home
    • Standard offering for home users
  • Pro versus Pro for Workstations
    • Windows 11 Pro and Pro for Workstations are both well suited for the business environment with available features such as support for Active Directory or Azure Active Directory, Windows Autopilot, OneDrive for Business, etc.
    • Windows Pro for Workstations is designed for increased demands on the hardware with the higher memory limits (2 TB vs. 6 TB) and processor count (2 CPU vs. 4 CPU).
    • Windows Pro for Workstations also features Resilient File System, Persistent Memory, and SMB Direct. Neither of these features are available in the Windows 11 Pro edition.
    • Windows 11 Pro and Pro for Workstations are both very business focused, although Pro may also be a common choice for non-business users (Home and Education).
  • Enterprise Offerings
    • Enterprise licenses are subscription based and are part of the Microsoft 365 suite of offerings.
    • Windows 11 Enterprise is Windows 11 Pro with some additional addons and functionality in areas such as device management, collaboration, and security services.
    • The level of the Microsoft 365 Enterprise subscription (E3 or E5) would dictate the additional features and functionality, such as the complete Microsoft Defender for Endpoint suite or the Microsoft phone system and Audio Conferencing, which are only available with the E5 subscription.

Windows 11 Education Editions

With the release of a laptop targeted specifically at the education market, Microsoft must be taking notice of the Google Chrome educational market penetration, especially with headlines like these.

“40 Million Chromebooks in Use in Education” (Thurrott)

“The Unprecedented Growth of the Chromebook Education Market Share” (Carklin)

“Chromebooks Gain Market Share as Education Goes Online” (Hruska)

“Chromebooks Gain Share of Education Market Despite Shortages” (Mandaro)

“Chromebook sales skyrocketed in Q3 2020 with online education fueling demand” (Duke)

  • Education licenses are subscription based and are part of the Microsoft 365 suite of offerings. Educational pricing is one benefit of the Microsoft 365 Education model.
  • Windows 11 Education is Windows 11 Pro with some additional addons and functionality similar to the Enterprise offerings for Windows 11 in areas such as device management, collaboration, and security services. Windows 11 Education also adds some education specific settings such as Classroom Tools, which allow institutions to add new students and their devices to their own environment with fewer issues, and includes OneNote Class Notebook, Set Up School PCs app, and Take a Test app.
  • The level of the Microsoft 365 Education subscription (A3 or A5) would dictate the additional features and functionality, such as the complete Microsoft Defender for Endpoint suite or the Microsoft phone system and Audio Conferencing, which are only available with the A5 subscription.
  • Windows 11 SE for Education:
    • A cloud-first edition of Windows 11 specifically designed for the K-8 education market.
    • Windows 11 SE is a light version of Windows 11 that is designed to run on entry-level devices with better performance and security on that hardware.
    • Windows 11 SE requires Intune for Education and only IT admins can install applications.
  • Microsoft and others have come out with Windows SE specific devices at a low price point.
    • The Microsoft Surface Laptop SE comes pre-loaded with Windows 11 SE and can be purchased for US$249.00.
    • Dell, Asus, Acer, Lenovo, and others also offer Windows 11 SE specific devices (“Devices for Education”).

Initial Reactions

Below you can find some actual initial reactions to Windows 11.

Initial reactions are mixed, as is to be expected with any new release of an operating system. The look and feel is new, but it is not a huge departure from the Windows 10 look and feel. Some new features are well received such as the snap feature.

The shift of the taskbar (and start button) is the most popular topic of discussion online when it comes to Windows 11 reactions. Some love it and some do not. The best part about the shift of the taskbar is that you can adjust it in settings and move it back to its original location.

The best thing about reactions is that they garner attention, and thanks in part to all the online reactions and comments, Microsoft is continually improving Windows 11 through quality updates and annual feature releases.

“My 91-year-old Mum has found it easy!” Binns, Paul ITRG

“It mostly looks quite nice and runs well.” Jmbpiano, Reddit user

“It makes me feel more like a Mac user.” Chang, Ben Info-Tech

“At its core, Windows 11 appears to be just Windows 10 with a fresh coat of paint splashed all over it.” Rouse, Rick RicksDailyTips.com

“Love that I can snap between different page orientations.” Roberts, Jeremy Info-Tech

“I finally feel like Microsoft is back on track again.” Jawed, Usama Neowin

“A few of the things that seemed like issues at first have either turned out not to be or have been fixed with patches.” Jmbpiano, Reddit user

“The new interface is genuinely intuitive, well-designed, and colorful.” House, Brett AnandTech

“No issues. Have it out on about 50 stations.” Sandrews1313, Reddit User

“The most striking change is to the Start menu.” Grabham, Dan pocket-lint.com

How do I upgrade to Windows 11?

The process is very similar to applying updates in Windows 10.

  • Windows 11 is offered as an upgrade through the standard Windows 10 update procedure. Windows Update will notify you when the Windows 11 upgrade is ready (assuming your device is eligible for Windows 11).
    • Allow the update (upgrade in this case) to proceed, reboot, and your endpoint will come back to life with Windows 11 installed and ready for you.
  • A fresh install can be delivered by downloading the required Windows 11 installation media from the Microsoft Software Download site for Windows 11.
  • Business users can control the timing and schedule of the Windows 11 rollout to corporate endpoints using Microsoft solutions such as WSUS, Configuration Manager, Intune and Endpoint Manager, or by using other endpoint management solutions.
  • WSUS and Configuration Manager will have to sync the product category for Windows 11 to manage the deployment.
  • Windows Update for Business policies will have to use the target version capability rather than using the feature update referrals alone.
  • Organizations using Intune and a Microsoft 365 E3 license will be able to use the Feature Update Deployments page to select Windows 11.
  • Other modern endpoint management solutions may also allow for a controlled deployment.

Info-Tech Insight

The upgrade itself may be a simple process but be prepared for the end-user reactions that will follow. Some will love it but others will despise it. It is not an optional upgrade in the long run, so everyone will have to learn to accept it.

When can I upgrade to Windows 11?

You can upgrade right now BUT there is no need to rush. Windows 11 was released in October 2021 but that doesn’t mean you have to upgrade everyone right away. Plan this out.

  • Build deployment rings into your Windows 11 upgrade approach: This approach, also referred to as Canary Releases or deployment rings, allows you to ensure that IT can support users if there's a major problem with the upgrade. Instead of disrupting all end users, you are only disrupting a portion of end users.
    • Deploy the initial update to your test environment.
    • After testing is successful or changes have been made, deploy Windows 11 to your pilot group of users.
    • After the pilot group gives you the thumbs up, deploy to the rest of production in phases. Phases are sometimes by office/location, sometimes by department, sometimes by persona (i.e. defer people that don't handle updates well), and usually by a combination of these factors.
    • Increase the size of each ring as you progress.
  • Always back up your data before any upgrade.

Deployment Ring Example

Pilot Ring - Individuals from all departments - 10 users

Ring #1 - Dev, Finance - 20 Users

Ring #2 - Research - 100 Users

Ring #3 - Sales, IT, Marketing - 500 Users

Upgrade your eligible devices and users to Windows 11

Build Windows 11 Deployment Rings

Instructions:

  1. Identify who will be in the pilot group. Use individuals instead of user groups.
  2. Identify how many standard rings you need. This number will be based on the total number of employees per office.
  3. Map groups to rings. Define which user groups will be in each ring.
  4. Allow some time to elapse between upgrades. Allow the first group to work with Windows 11 and identify any potential issues that may arise before upgrading the next group.
  5. Track and communicate. Record all information into a spreadsheet like the one on the right. This will aid in communication and tracking.
Ring Department or Group Total Users Delay Time Before Next Group
Pilot Ring Individuals from all departments 10 Three weeks
Ring 1 Dev Finance 20 Two weeks
Ring 2 Research 100 One week
Ring 3 Sales, IT Marketing 500 N/A

What are my options if my devices cannot upgrade to Windows 11?

Don’t rush out to replace all the ineligible endpoint devices. You have some time to plan this out. Windows 10 will be available and supported by Microsoft until October 2025.

Use asset management strategies and budget techniques in your Windows 11 upgrade approach:

  • Start with current inventory and determine which devices will not be eligible for upgrade to Windows 11.
  • Prioritize the devices for replacement, taking device age, the role of the user the device supports, and delivery times for remote users into consideration.
  • Take this opportunity to review overall device offerings and end-user compute strategy. This will help decide which devices to offer going forward while improving end-user satisfaction.
  • Determine the cost for replacement devices:
    • Compare vendor offerings using an RFP process.
  • Use the hardware asset management planning spreadsheet on the next slide to budget for the replacements over the coming months leading up to October 2025.

Leverage Info-Tech research to improve your end-user computing strategy and hardware asset management processes:

New to End User Computing Strategies? Start with Modernize and Transform Your End-User Computing Strategy.

New to IT asset management? Use Info-Tech’s Implement Hardware Asset Management blueprint.

Use Info-Tech’s HAM Budgeting Tool to plan your hardware asset budget

Build a Windows 11 Device Replacement Budget

The link below will open up a hardware asset management (HAM) budgeting tool. This tool can easily be modified to assist in developing and justifying the budget for hardware assets for the Windows 11 project. The tool will allow you to budget for hardware asset refresh and to adjust the budget as needed to accommodate any changes. Follow the instructions on each tab to complete the tool.

A sample of a possible Windows 11 budgeting spreadsheet is shown on the right, but feel free to play with the HAM budgeting tool to fit your needs.

HAM Budgeting Tool

Windows 11 Replacement Schedule
2022 2023 2024 2025
Department Total to replace Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Q4 Q1 Q2 Q3 Left to allocate
Finance 120 20 20 20 10 10 20 20 0
HR 28 15 13 0
IT 30 15 15 0
Research 58 8 15 5 20 5 5 0
Planning 80 10 15 15 10 15 15 0
Other 160 5 30 5 15 15 30 30 30 0
Totals 476 35 38 35 35 35 35 38 35 50 35 35 35 35 0

Related Info-Tech Research

Modernize and Transform Your End-User Computing Strategy

This project helps support the workforce of the future by answering the following questions: What types of computing devices, provisioning models, and operating systems should be offered to end users? How will IT support devices? What are the policies and governance surrounding how devices are used? What actions are we taking and when? How do end-user devices support larger corporate priorities and strategies?

Implement Hardware Asset Management

This project will help you analyze the current state of your HAM program, define assets that will need to be managed, and build and involve the ITAM team from the beginning to help embed the change. It will also help you define standard policies, processes, and procedures for each stage of the hardware asset lifecycle, from procurement through to disposal.

Bibliography

aczechowski, et al. “Windows 11 Requirements.” Microsoft, 3 June 2022. Accessed 13 June 2022.

Binns, Paul. Personal interview. 07 June 2022.

Butler, Sydney. “What Is Trusted Platform Module (TPM) and How Does It Work?” Help Desk Geek, 5 August 2021. Accessed 18 May 2022.

Carklin, Nicolette. “The Unprecedented Growth of the Chromebook Education Market Share.” Parallels International GmbH, 26 October 2021. Accessed 19 May 2022.

Chang, Ben. Personal interview. 26 May 2022.

Cunningham, Andrew. “Why Windows 11 has such strict hardware requirements, according to Microsoft.” Ars Technica, 27 August 2021. Accessed 19 May 2022.

Dealnd-Han, et al. “Windows Processor Requirements.” Microsoft, 9 May 2022. Accessed 18 May 2022.

“Desktop Operating Systems Market Share Worldwide.” Statcounter Globalstats, June 2021–June 2022. Accessed 17 May 2022.

“Devices for education.” Microsoft, 2022. Accessed 13 June 2022.

Duke, Kent. “Chromebook sales skyrocketed in Q3 2020 with online education fueling demand.” Android Police, 16 November 2020. Accessed 18 May 2022.

Grabham, Dan. “Windows 11 first impressions: Our initial thoughts on using Microsoft's new OS.” Pocket-Lint, 24 June 2021. Accessed 3 June 2022.

Hachman, Mark. “Why is there a Windows 11 if Windows 10 is the last Windows?” PCWorld, 18 June 2021. Accessed 17 May 2022.

Howse, Brett. “What to Expect with Windows 11: A Day One Hands-On.” Anandtech, 16 November 2020. Accessed 3 June 2022.

Hruska, Joel. “Chromebooks Gain Market Share as Education Goes Online.” Extremetech, 26 October 2020. Accessed 19 May 2022.

Jawed, Usama. “I am finally excited about Windows 11 again.” Neowin, 26 February 2022. Accessed 3 June 2022.

Jmbpiano. “Windows 11 - What are our initial thoughts and feelings?” Reddit, 22 November 2021. Accessed 3 June 2022.

Lumunge, Erick. “UEFI and Legacy boot.” OpenGenus, n.d. Accessed 18 May 2022.

Bibliography

Mandaro, Laura. “Chromebooks Gain Share of Education Market Despite Shortages.” The Information, 9 September 2020. Accessed 19 May 2022.

Murtaza, Fawad. “What Is Virtualization Based Security in Windows?” Valnet Inc, 24 October 2021. Accessed 17 May 2022.

Roberts, Jeremy. Personal interview. 27 May 2022.

Rouse, Rick. “My initial thoughts about Windows 11 (likes and dislikes).” RicksDailyTips.com, 5 September 2021. Accessed 3 June 2022.

Sandrews1313. “Windows 11 - What are our initial thoughts and feelings?” Reddit, 22 November 2021. Accessed 3 June 2022.

“The Matrix Quotes." Quotes.net, n.d. Accessed 18 May 2022.

Thurrott, Paul.” Google: 40 Million Chromebooks in Use in Education.” Thurrott, 21 January 2020. Accessed 18 May 2022.

Vaughan-Nichols, Steven J. “The real reason for Windows 11.” Computerworld, 6 July 2021, Accessed 19 May 2022.

“Virtual Machine Support.” Microsoft,3 June 2022. Accessed 13 June 2022.

“What are DirectX 12 compatible graphics and WDDM 2.x.” Wisecleaner, 20 August 2021. Accessed 19 May 2022.

“Windows 11 Specs and System Requirements.” Microsoft, 2022. Accessed 13 June 2022.

“Windows Display Driver Model.” MiniTool, n.d. Accessed 13 June 2022.

Implement Your Negotiation Strategy More Effectively

  • Buy Link or Shortcode: {j2store}225|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Vendor Management
  • Parent Category Link: /vendor-management
  • Forty-eight percent of CIOs believe their budgets are inadequate.
  • CIOs and IT departments are getting more involved with negotiations to reduce costs and risk.
  • Not all negotiators are created equal, and the gap between a skilled negotiator and an average negotiator is not always easy to identify objectively.
  • Skilled negotiators are in short supply.

Our Advice

Critical Insight

  • Preparation is critical for the success of your negotiation, but you cannot prepare for every eventuality.
  • Communication is the heart and soul of negotiations, but what is being “said” is only part of the picture.
  • Skilled negotiators separate themselves based on skillsets, and outcomes alone may not provide an accurate assessment of a negotiator.

Impact and Result

Addressing and managing critical negotiation elements helps:

  • Improve negotiation skills.
  • Implement your negotiation strategy more effectively.
  • Improve negotiation results.

Implement Your Negotiation Strategy More Effectively Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out why you should create and follow a scalable process for preparing to negotiate with vendors, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. During

Throughout this phase, ten essential negotiation elements are identified and reviewed.

  • Implement Your Negotiation Strategy More Effectively – Phase 1: During
  • During Negotiations Tool
[infographic]

Workshop: Implement Your Negotiation Strategy More Effectively

Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

1 12 Steps to Better Negotiation Preparation

The Purpose

Improve negotiation skills and outcomes.

Understand how to use the Info-Tech During Negotiations Tool.

Key Benefits Achieved

A better understanding of the subtleties of the negotiation process and an identification of where the negotiation strategy can go awry.

The During Negotiation Tool will be reviewed and configured for the customer’s environment (as applicable).

Activities

1.1 Manage six key items during the negotiation process.

1.2 Set the right tone and environment for the negotiation.

1.3 Focus on improving three categories of intangibles.

1.4 Improve communication skills to improve negotiation skills.

1.5 Customize your negotiation approach to interact with different personality traits and styles.

1.6 Maximize the value of your discussions by focusing on seven components.

1.7 Understand the value of impasses and deadlocks and how to work through them.

1.8 Use concessions as part of your negotiation strategy.

1.9 Identify and defeat common vendor negotiation ploys.

1.10 Review progress and determine next steps.

Outputs

Sample negotiation ground rules

Sample vendor negotiation ploys

Sample discussion questions and evaluation matrix

Maximize the Benefits from Enterprise Applications with a Center of Excellence

  • Buy Link or Shortcode: {j2store}367|cart{/j2store}
  • member rating overall impact: 10.0/10 Overall Impact
  • member rating average dollars saved: $129,465 Average $ Saved
  • member rating average days saved: 12 Average Days Saved
  • Parent Category Name: Optimization
  • Parent Category Link: /optimization
  • Processes pertaining to managing the application are inconsistent and do not drive excellence.
  • There is a lack of interdepartmental collaboration between different teams pertaining to the application.
  • There are no formalized roles and responsibilities for governance and support around enterprise applications.

Our Advice

Critical Insight

  • Scale the Center of Excellence (CoE) based on business needs. There is flexibility in how extensively the CoE methodology is applied and rigidity in how consistently it should be used.
  • The CoE is a refinery. It takes raw inputs from the business and produces an enhanced product, removing waste and isolating it from re-entering day-to-day operations.
  • Excellence is about people as much as it is about process. Documented best practices should include competencies, key resources, and identified champions to advocate the CoE practice.

Impact and Result

  • Formalize roles and responsibilities for all application initiatives.
  • Develop a standard process of governance and oversight surrounding the application.
  • Develop a comprehensive support network that consists of IT, the business, and external stakeholders to address issues and problem areas surrounding the application.

Maximize the Benefits from Enterprise Applications with a Center of Excellence Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out why you should establish a Center of Excellence for your enterprise application, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Create a vision for the CoE

Understand the importance of developing an enterprise application CoE, define its scope, and identify key stakeholders.

  • Maximize the Benefits from Enterprise Applications with a Center of Excellence – Phase 1: Create a Vision for the Center of Excellence
  • Enterprise Application Center of Excellence Project Charter

2. Design the CoE future state

Gather high-level requirements to determine the ideal future state.

  • Maximize the Benefits from Enterprise Applications with a Center of Excellence – Phase 2: Design the Center of Excellence Future State
  • Center of Excellence Refinery Model Template

3. Develop a CoE roadmap

Assess the required capabilities to reach the ideal state CoE.

  • Maximize the Benefits from Enterprise Applications with a Center of Excellence – Phase 3: Develop a Center of Excellence Roadmap
  • Center of Excellence Exceptions Report
  • Track and Measure Benefits Tool
  • Enterprise Application Center of Excellence Stakeholder Presentation Template
[infographic]

Workshop: Maximize the Benefits from Enterprise Applications with a Center of Excellence

Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

1 Create a Vision for the CoE

The Purpose

Understand the importance of developing a CoE for enterprise applications.

Determine how to best align the CoE mandate with business objectives.

Complete a CoE project charter to gain buy-in, build a project team, and track project success. 

Key Benefits Achieved

Key stakeholders identified.

Project team created with defined roles and responsibilities.

Project charter finalized to gain buy-in.

Activities

1.1 Evaluate business needs and priorities.

1.2 Identify key stakeholders and the project team.

1.3 Align CoE with business priorities.

1.4 Map current state CoE.

Outputs

Project vision

Defined roles and responsibilities

Strategic alignment of CoE and the business

CoE current state schematic

2 Design the CoE Future State

The Purpose

Gain a thorough understanding of pains related to the lack of application governance.

Identify and recycle existing CoE practices.

Visualize the CoE enhancement process.

Visualize your ideal state CoE. 

Key Benefits Achieved

Requirements to strengthen the case for the enterprise application CoE.

CoE value-add refinery.

Future potential of the CoE.

Activities

2.1 Gather requirements.

2.2 Map the CoE enhancement process.

2.3 Sketch future state CoE.

Outputs

Classified pains, opportunities, and existing practices

CoE refinery model

Future state CoE sketch

3 Develop a CoE Roadmap

The Purpose

Assess required capabilities and resourcing.

List and prioritize CoE initiatives.

Track and monitor CoE performance. 

Key Benefits Achieved

Next steps for the enterprise application CoE.

CoE resourcing plan.

CoE benefits realization tracking.

Activities

3.1 Build CoE capabilities.

3.2 Identify risks and mitigation efforts.

3.3 Prioritize and track CoE initiatives.

3.4 Finalize stakeholder presentation.

Outputs

CoE potential capabilities

Risk management plan

CoE initiatives roadmap

CoE stakeholder presentation

Go the Extra Mile With Blockchain

  • Buy Link or Shortcode: {j2store}130|cart{/j2store}
  • member rating overall impact: N/A
  • member rating average dollars saved: N/A
  • member rating average days saved: N/A
  • Parent Category Name: Data Management
  • Parent Category Link: /data-management
  • The transportation and logistics industry is facing a set of inherent flaws, such as high processing fees, fraudulent information, and lack of transparency, that blockchain is set to transform and alleviate.
  • Many companies have FOMO (fear of missing out), causing them to rush toward blockchain adoption without first identifying the optimal use case.

Our Advice

Critical Insight

  • Understand how blockchain can alleviate your pain points before rushing to adopt the technology. You have been hearing about blockchain for some time now and are feeling pressured to adopt it. Moreover, the series of issues hindering the transportation and logistics industry, such as the lack of transparency, poor cash flow management, and high processing fees, are frustrating business leaders and thereby adding additional pressure on CIOs to adopt the technology. While blockchain is complex, you should focus on its key features of transparency, integrity, efficiency, and security to identify how it can help your organization.
  • Ensure your use case is actually useful and can be valuable to your organization by selecting a business idea that is viable, feasible, and desirable. Applying design thinking tactics to your evaluation process provides a practical approach that will help you avoid wasting resources (both time and money) and hurting IT’s image in the eyes of the business. While it is easy to get excited and invest in a new technology to help maintain your image as a thought leader, you must ensure that your use case is fully developed prior to doing so.

Impact and Result

  • Understand blockchain’s transformative potential for the transportation and logistics industry by breaking down how its key benefits can alleviate inherent industry flaws.
  • Identify business processes and stakeholders that could benefit from blockchain.
  • Build and evaluate an inventory of use cases to determine where blockchain could have the greatest impact on your organization.
  • Articulate the value and organizational fit of your proposed use case to the business to gain their buy-in and support.

Go the Extra Mile With Blockchain Research & Tools

Start here – read the Executive Brief

Read our concise Executive Brief to find out why your organization should care about blockchain’s transformative potential for the transportation and logistics industry and how Info-Tech will support you as you identify and build your blockchain use case.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Evaluate why blockchain can disrupt the transportation and logistics industry

Analyze the four key benefits of blockchain as they relate to the transportation and logistics industry to understand how the technology can resolve issues being experienced by industry incumbents.

  • Go the Extra Mile With Blockchain – Phase 1: Evaluate Why Blockchain Can Disrupt the Transportation and Logistics Industry
  • Blockchain Glossary

2. Build and evaluate an inventory of use cases

Brainstorm a set of blockchain use cases for your organization and apply design thinking tactics to evaluate and select the optimal one to pitch to your executives for prototyping.

  • Go the Extra Mile With Blockchain – Phase 2: Build and Evaluate an Inventory of Use Cases
  • Blockchain Use Case Evaluation Tool
  • Prototype One Pager
[infographic]

Build a Value Measurement Framework

  • Buy Link or Shortcode: {j2store}182|cart{/j2store}
  • member rating overall impact: 9.2/10 Overall Impact
  • member rating average dollars saved: $82,374 Average $ Saved
  • member rating average days saved: 35 Average Days Saved
  • Parent Category Name: Architecture & Strategy
  • Parent Category Link: /architecture-and-strategy
  • Rapid changes in today’s market require rapid, value-based decisions, and organizations that lack a shared definition of value fail to maintain their competitive advantage.
  • Different parts of an organization have different value drivers that must be given balanced consideration.
  • Focusing solely on revenue ignores the full extent of value creation in your organization and does not necessarily result in the right outcomes.

Our Advice

Critical Insight

  • Business is the authority on business value. While IT can identify some sources of value, business stakeholders must participate in the creation of a definition that is meaningful to the whole organization.
  • It’s about more than profit. Organizations must have a definition that encompasses all of the sources of value or they risk making short-term decisions with long-term negative impacts.
  • Technology creates business value. Treating IT as a cost center makes for short-sighted decisions in a world where every business process is enabled by technology.

Impact and Result

  • Standardize your definition of business value. Work with your business partners to define the different sources of business value that are created through technology-enabled products and services.
  • Weigh your value drivers. Ensure that business and IT understand the relative weight and priority of the different sources of business value you have identified.
  • Use a balanced scorecard to understand value. Use the different value drivers to understand and prioritize different products, applications, projects, initiatives, and enhancements.

Build a Value Measurement Framework Research & Tools

Start here – read the Executive Brief

Read this Executive Brief to understand why building a consistent and aligned framework to measure the value of your products and services is vital for setting priorities and getting the business on board.

Besides the small introduction, subscribers and consulting clients within this management domain have access to:

1. Define your value drivers

This phase will help you define and weigh value drivers based on overarching organizational priorities and goals.

  • Build a Value Measurement Framework – Phase 1: Define Your Value Drivers
  • Value Calculator

2. Measure value

This phase will help you analyze the value sources of your products and services and their alignment to value drivers to produce a value score that you can use for prioritization.

  • Build a Value Measurement Framework – Phase 2: Measure Value
[infographic]

Further reading

Build a Value Measurement Framework

Focus product delivery on business value–driven outcomes.

ANALYST PERSPECTIVE

"A meaningful measurable definition of value is the key to effectively managing the intake, prioritization, and delivery of technology-enabled products and services."

Cole Cioran,

Senior Director, Research – Application Development and Portfolio Management

Info-Tech Research Group

Our understanding of the problem

This Research Is Designed For:

  • CIOs who need to understand the value IT creates
  • Application leaders who need to make good decisions on what work to prioritize and deliver
  • Application and project portfolio managers who need to ensure the portfolio creates business value
  • Product owners who are accountable for delivering value

This Research Will Help You:

  • Define quality in your organization’s context from both business and IT perspectives.
  • Define a repeatable process to understand the value of a product, application, project, initiative, or enhancement.
  • Define value sources and metrics.
  • Create a tool to make it easier to balance different sources of value.

This Research Will Also Assist:

  • Product and application delivery teams who want to make better decisions about what they deliver
  • Business analysts who need to make better decisions about how to prioritize their requirements

This Research Will Help Them:

  • Create a meaningful relationship with business partners around what creates value for the organization.
  • Enable better understanding of your customers and their needs.

Executive summary

Situation

  • Measuring the business value provided by IT is critical for improving the relationship between business and IT.
  • Rapid changes in today’s market require rapid, value-based decisions.
  • Every organization has unique drivers that make it difficult to see the benefits based on time and impact approaches to prioritization.

Complication

  • An organization’s lack of a shared definition of value leads to politics and decision making that does not have a firm, quantitative basis.
  • Different parts of an organization have different value drivers that must be given balanced consideration.
  • Focusing solely on revenue does not necessarily result in the right outcomes.

Resolution

  • Standardize your definition of business value. Work with your business partners to define the different sources of business value that are created through technology-enabled products and services.
  • Weigh your value drivers. Ensure business and IT understand the relative weight and priority of the different sources of business value you have identified.
  • Use a balanced scorecard to understand value. Use the different value drivers to understand and prioritize different products, applications, projects, initiatives, and enhancements.

Info-Tech Insight

  1. Business is the authority on business value. While IT can identify some sources of value, business stakeholders must participate in the creation of a definition that is meaningful to the whole organization.
  2. It’s about more than profit. Organizations must have a definition that encompasses all of the sources of value, or they risk making short-term decisions with long-term negative impacts.
  3. Technology creates business value. Treating IT as a cost center makes for short-sighted decisions in a world where every business process is enabled by technology.

Software is not currently creating the right outcomes

Software products are taking more and more out of IT budgets.

38% of spend on IT employees goes to software roles.

Source: Info-Tech’s Staffing Survey

18% of opex is spent on software licenses.

Source: SoftwareReviews.com

33% of capex is spent on new software.

However, the reception and value of software products do not justify the money invested.

Only 34% of software is rated as both important and effective by users.

Source: Info-Tech’s CIO Business Vision

IT benchmarks do not help or matter to the business. Focus on the metrics that represent business outcomes.

A pie chart is shown as an example to show how benchmarks do not help the business.

IT departments have a tendency to measure only their own role-based activities and deliverables, which only prove useful for selling practice improvement services. Technology doesn’t exist for technology's sake. It’s in place to generate specific outcomes. IT and the business need to be aligned toward a common goal of enabling business outcomes, and that’s the important measurement.

"In today’s connected world, IT and business must not speak different languages. "

– Cognizant, 2017

CxOs stress the importance of value as the most critical area for IT to improve reporting

A bar graph is shown to demonstrate the CxOs importance of value. Business value metrics are 32% of significant improvement necessary, and 51% where some improvement is necessary.

N=469 CxOs from Info-Tech’s CEO/CIO Alignment Diagnostic

Key stakeholders want to know how you and your products or services help them realize their goals.

While the basics of value are clear, few take the time to reach a common definition and means to measure and apply value

Often, IT misses the opportunity to become a strategic partner because it doesn’t understand how to communicate and measure its value to the business.

"Price is what you pay. Value is what you get."

– Warren Buffett

Being able to understand the value context will allow IT to articulate where IT spend supports business value and how it enables business goal achievement.

Value is...

Derived from business context

  • What is our business context?
  • Enabled through governance and strategy

  • Who sees the strategy through?
  • The underlying context for decision making

  • How is value applied to support decisions?
  • A measure of achievement

  • How do I measure?
  • Determine your business context by assessing the goals and defining the unique value drivers in your organization

    Competent organizations know that value cannot always be represented by revenue or reduced expenses. However, it is not always apparent how to envision the full spectrum of sources of value. Dissecting value by the benefit type and the value source’s orientation allows you to see the many ways in which a product or service brings value to the organization.

    A business value matrix is shown. It shows the relationship between reading customers, increase revenue, reduce costs, and enhance services.

    Financial Benefits vs. Improved Capabilities

    Financial Benefits refers to the degree to which the value source can be measured through monetary metrics and is often quite tangible. Human Benefits refers to how a product or service can deliver value through a user’s experience.

    Inward vs. Outward Orientation

    Inward refers to value sources that have an internal impact and improve your organization’s effectiveness and efficiency in performing its operations.Outward refers to value sources that come from your interaction with external factors, such as the market or your customers.

    Increase Revenue

    Reduce Costs

    Enhance Services

    Reach Customers

    Product or service functions that are specifically related to the impact on your organization’s ability to generate revenue.

    Reduction of overhead. They typically are less related to broad strategic vision or goals and more simply limit expenses that would occur had the product or service not been put in place.

    Functions that enable business capabilities that improve the organization’s ability to perform its internal operations.

    Application functions that enable and improve the interaction with customers or produce market information and insights.

    See your strategy through by involving both IT and the business

    Buy-in for your IT strategy comes from the ability to showcase value. IT needs to ensure it has an aligned understanding of what is valuable to the organization.

    Business value needs to first be established by the business. After that, IT can build a partnership with the business to determine what that value means in the context of IT products and services.

    The Business

    What the Business and IT have in common

    IT

    Keepers of the organization’s mission, vision, and value statements that define IT success. The business maintains the overall ownership and evaluation of the products along with those most familiar with the capabilities or processes enabled by technology.

    Business Value of Products and Services

    Technical subject matter experts of the products and services they deliver and maintain. Each IT function works together to ensure quality products and services are delivered up to stakeholder expectations.

    Measure your product or services with Info-Tech’s Value Measurement Framework (VMF) and value scores

    The VMF provides a consistent and less subjective approach to generating a value score for an application, product, service, or individual feature, by using business-defined value drivers and product-specific value metrics.

    Info-Tech's Value Measurement Framework is shown.

    A consistent set of established value drivers, sources, and metrics gives more accurate comparisons of relative value

    Value Drivers

    Value Sources

    Value Fulfillment Metrics

    Broad categories of values, weighed and prioritized based on overarching goals

    Instances of created value expressed as a “business outcome” of a particular function

    Units of measurement and estimated targets linked to a value source

    Reach Customers

    Customer Satisfaction

    Net Promoter Score

    Customer Loyalty

    # of Repeat Visits

    Create Revenue Streams

    Data Monetization

    Dollars Derived From Data Sales

    Leads Generation

    Leads Conversation Rate

    Operational Efficiency

    Operational Efficiency

    Number of Interactions

    Workflow Management

    Cycle Time

    Adhere to regulations & compliance

    Number of Policy Exceptions

    A balanced and weighted scorecard allows you to measure the various ways products generate value to the business

    The Info-Tech approach to measuring value applies the balanced value scorecard approach.

    Importance of value source

    X

    Impact of value source

    = Value Score

    Which is based on…

    Which is based on…

    Alignment to value driver

    Realistic targets for the KPI

    Which is weighed by…

    Which is estimated by…

    A 1-5 scale of the relative importance of the value driver to the organization

    A 1-5 scale of the application or feature’s ability to fulfill that value source

    +

    Importance of Value Source

    X

    Impact of Value Source

    +

    Importance of Value Source

    +

    Impact of Value Source

    +

    Importance of Value Source

    +

    Impact of Value Source

    +

    Importance of Value Source

    +

    Impact of Value Source

    =

    Balanced Business Value Score

    Value Score1 + VS2 + … + VSN = Overall Balance Value Score

    Value scores help support decisions. This blueprint looks specifically at four use cases for value scores.

    A value score is an input to the following activities:

    1. Prioritize Your Product Backlog
    2. Estimate the relative value of different product backlog items (i.e. epics, features, etc.) to ensure the highest value items are completed first.

      This blueprint can be used as an input into Info-Tech’s Build a Better Backlog.

    3. Prioritize Your Project Backlog
    4. Estimate the relative value of proposed new applications or major changes or enhancements to existing applications to ensure the right projects are selected and completed first.

      This blueprint can be used as an input into Info-Tech’s Optimize Project Intake, Approval, and Prioritization.

    5. Rationalize Your Applications
    6. Gauge the relative value from the current use of your applications to support strategic decision making such as retirement, consolidation, and further investments.

      This blueprint can be used as an input into Info-Tech’s Visualize Your Application Portfolio Strategy With a Business Value-Driven Roadmap.

    7. Categorize Application Tiers
    8. Gauge the relative value of your existing applications to distinguish your most to least important systems and build tailored support structures that limit the downtime of key value sources.

      This blueprint can be used as an input into Info-Tech’s Streamline Application Maintenance.

    The priorities, metrics, and a common understanding of value in your VMF carry over to many other Info-Tech blueprints

    Transition to Product Delivery

    Build a Product Roadmap

    Modernize Your SDLC

    Build a Strong Foundation for Quality

    Implement Agile Practices That Work

    Use Info-Tech’s Value Calculator

    The Value Calculator facilitates the activities surrounding defining and measuring the business value of your products and services.

    Use this tool to:

    • Weigh the importance of each Value Driver based on established organizational priorities.
    • Create a repository for Value Sources to provide consistency throughout each measurement.
    • Produce an Overall Balanced Value Score for a specific item.

    Info-Tech Deliverable

    A screenshot of Info-Tech's Value Calculator is shown.

    Populate the Value Calculator as you complete the activities and steps on the following slides.

    Limitations of the Value Measurement Framework

    "All models are wrong, but some are useful."

    – George E.P. Box, 1979

    Value is tricky: Value can be intangible, ambiguous, and cause all sorts of confusion, with the multiple, and often conflicting, priorities any organization is sure to have. You won’t likely come to a unified understanding of value or an agreement on whether one thing is more valuable than something else. However, this doesn’t mean you shouldn’t try. The VMF provides a means to organize various priorities in a meaningful way and to assess the relative value of a product or service to guide managers and decision makers on the right track and keep alignment with the rest of the organization.

    Relative value vs. ROI: This assessment produces a score to determine the value of a product or service relative to other products or services. Its primary function is to prioritize similar items (projects, epics, requirements, etc.) as opposed to producing a monetary value that can directly justify cost and make the case for a positive ROI.

    Apply caution with metrics: We live in a metric-crazed era, where everything is believed to be measurable. While there is little debate over recent advances in data, analytics, and our ability to trace business activity, some goals are still quite intangible, and managers stumble trying to link these goals to a quantifiable data source.

    In applying the VMF Info-Tech urges you to remember that metrics are not a magical solution. They should be treated as a tool in your toolbox and are sometimes no more than a rough gauge of performance. Carefully assign metrics to your products and services and do not disregard the informed subjective perspective when SMART metrics are unavailable.

    "One of the deadly diseases of management is running a company on visible figures alone."

    – William Edwards Deming, 1982

    Info-Tech’s Build a Value Measurement Framework glossary of terms

    This blueprint discusses value in a variety of ways. Use our glossary of terms to understand our specific focus.

    Value Measurement Framework (VMF)

    A method of measuring relative value for a product or service, or the various components within a product or service, through the use of metrics and weighted organizational priorities.

    Value Driver

    A board organizational goal that acts as a category for many value sources.

    Value Source

    A specific business goal or outcome that business and product or service capabilities are designed to fulfill.

    Value Fulfillment

    The degree to which a product or service impacts a business outcome, ideally linked to a metric.

    Value Score

    A measurement of the value fulfillment factored by the weight of the corresponding value driver.

    Overall Balanced Value Score

    The combined value scores of all value sources linked to a product or service.

    Relative Value

    A comparison of value between two similar items (i.e. applications to applications, projects to projects, feature to feature).

    Info-Tech offers various levels of support to best suit your needs

    DIY Toolkit

    “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

    Guided Implementation

    “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

    Workshop

    “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

    Consulting

    “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

    Diagnostics and consistent frameworks used throughout all four options

    Build a Value Measurement Framework – project overview

    1. Define Your Value Drivers

    2. Measure Value

    Best-Practice Toolkit

    1.1 Identify your business value authorities.

    2.1 Define your value drivers.

    2.2 Weigh your value drivers.

    • Identify your product or service SMEs.
    • List your products or services items and components.
    • Identify your value sources.
    • Align to a value driver.
    • Assign metrics and gauge value fulfillment.

    Guided Implementations

    Identify the stakeholders who should be the authority on business value.

    Identify, define, and weigh the value drivers that will be used in your VMF and all proceeding value measurements.

    Identify the stakeholders who are the subject matter experts for your products or services.

    Measure the value of your products and services with value sources, fulfillment, and drivers.

    Outcome:

    • Value drivers and weights

    Outcome:

    • An initial list of reusable value sources and metrics
    • Value scores for your products or services

    Phase 1

    Define Your Value Drivers

    First determine your value drivers and add them to your VMF

    One of the main aspects of the VMF is to apply consistent and business-aligned weights to the products or services you will evaluate.

    This is why we establish your value drivers first:

    • Get the right executive-level “value authorities” to establish the overarching weights.
    • Build these into the backbone of the VMF to consistently apply to all your future measurements.
    An image of the Value Measure Framework is shown.

    Step 1.1: Identify Value Authorities

    Phase 1

    1.1: Identify Value Authorities

    1.2: Define Value Drivers

    Phase 2

    2.1: Identify Product or Service SMEs

    2.2: Measure Value

    This step will walk you through the following activities:

    • Identify your authorities on business value.

    This step involves the following participants:

    • Owners of your value measurement framework

    Outcomes of this step

    • Your list of targeted individuals to include in Step 2.1

    Business value is best defined and measured by the combined effort and perspective of both IT and the business

    Buy-in for your IT strategy comes from the ability to showcase value. IT needs to ensure it has an aligned understanding of what is valuable to the organization. First, priorities need to be established by the business. Second, IT can build a partnership with the business to determine what that value means in the context of IT products and services.

    The Business

    What the Business and IT have in common

    IT

    Keepers of the organization’s mission, vision, and value statements that define IT success. The business maintains the overall ownership and evaluation of the products along with those most familiar with the capabilities or processes enabled by technology.

    Business Value of Products and Services

    Technical subject matter experts of the products and services they deliver and maintain. Each IT function works together to ensure quality products and services are delivered up to stakeholder expectations.

    Engage key stakeholders to reach a consensus on organizational priorities and value drivers

    Engage these key players to create your value drivers:

    CEO: Who better holds the vision or mandate of the organization than its leader? Ideally, they are front and center for this discussion.

    CIO: IT must ensure that technical/practical considerations are taken into account when determining value.

    CFO: The CFO or designated representative will ensure that estimated costs and benefits can be used to manage the budgets.

    VPs: Application delivery and mgmt. is designed to generate value for the business. Senior management from business units must help define what that value is.

    Evaluators (PMO, PO, APM, etc.): Those primarily responsible for applying the VMF should be present and active in identifying and carefully defining your organization’s value drivers.

    Steering Committee: This established body, responsible for the strategic direction of the organization, is really the primary audience.

    Identify your authorities of business value to identify, define, and weigh value drivers

    1.1 Estimated Time: 15 minutes

    The objective of this exercise is to identify key business stakeholders involved in strategic decision making at an organizational level.

    1. Review your organization’s governance structure and any related materials.
    2. Identify your key business stakeholders. These individuals are the critical business strategic partners.
      1. Target those who represent the business at an organizational level and often comprise the organization’s governing bodies.
      2. Prioritize a product backlog – include product owners and product managers who are in tune with the specific value drivers of the product in question.

    INFO-TECH TIP

    If your organization does not have a formal governance structure, your stakeholders would be the key players in devising business strategy. For example:

    • CEO
    • CFO
    • BRMs
    • VPs

    Leverage your organizational chart, governing charter, and senior management knowledge to better identify key stakeholders.

    INPUT

    • Key decision maker roles

    OUTPUT

    • Targeted individuals to define and weigh value drivers

    Materials

    • N/A

    Participants

    • Owner of the value measurement framework

    Step 1.2: Define Value Drivers

    Phase 1

    1.1: Identify Value Authorities

    1.2: Define Value Drivers

    Phase 2

    2.1: Identify Product or Service SMEs

    2.2: Measure Value

    This step will walk you through the following activities:

    • Define your value drivers.
    • Weigh your value drivers.

    This step involves the following participants:

    • Owners of your value measurement framework
    • Authorities of business value

    Outcomes of this step

    • A list of your defined and weighted value drivers

    Value is based on business needs and vision

    Value is subjective. It is defined through the organization’s past achievement and its future objectives.

    Purpose & Mission

    Past Achievement & Current State

    Vision & Future State

    Culture & Leadership

    There must be a consensus view of what is valuable within the organization, and these values need to be shared across the enterprise. Instead of maintaining siloed views and fighting for priorities, all departments must have the same value and purpose in mind. These factors – purpose and mission, past achievement and current state, vision and future state, and culture and leadership – impact what is valuable to the organization.

    Value derives from the mission and vision of an organization; therefore, value is unique to each organization

    Business value represents what the business needs to do to achieve its target state. Establishing the mission and vision helps identify that target state.

    Mission

    Vision

    Business Value

    Why does the company exist?

    • Specify the company’s purpose, or reason for being, and use it to guide each day’s activities and decisions.

    What does the organization see itself becoming?

    • Identify the desired future state of the organization. The vision articulates the role the organization strives to play and the way it wants to be perceived by the customer.
    • State the ends, rather than the means, to get to the future state.

    What critical factors fulfill the mission and vision?

    • Articulate the important capabilities the business should have in order to achieve its objectives. All business activities must enable business value.
    • Communicate the means to achieve the mission and vision.

    Understand the many types of value your products or services produce

    Competent organizations know that value cannot always be represented by revenue or reduced expenses. However, it is not always apparent how to envision the full spectrum of value sources. Dissecting value by the benefit type and the value source’s orientation allows you to see the many ways in which a product or service brings value to the organization.

    A business value matrix is shown. It shows the relationship between reading customers, increase revenue, reduce costs, and enhance services.

    Financial Benefits vs. Improved Capabilities

    Financial Benefits refers to the degree to which the value source can be measured through monetary metrics and is often quite tangible. Human Benefits refers to how a product or service can deliver value through a user’s experience.

    Inward vs. Outward Orientation

    Inward refers to value sources that have an internal impact and improve your organization’s effectiveness and efficiency in performing its operations. Outward refers to value sources that come from your interaction with external factors, such as the market or your customers.

    Increase Revenue

    Reduce Costs

    Enhance Services

    Reach Customers

    Product or service functions that are specifically related to the impact on your organization’s ability to generate revenue.

    Reduction of overhead. They typically are less related to broad strategic vision or goals and more simply limit expenses that would occur had the product or service not been put in place.

    Functions that enable business capabilities that improve the organization’s ability to perform its internal operations.

    Application functions that enable and improve the interaction with customers or produce market information and insights.

    Expand past Info-Tech’s high-level value quadrants and identify the value drivers specific to your organization

    Different industries have a wide range of value drivers. Consider the difference between public and private entities with respect to generating revenue or reaching their customers or other external stakeholders. Even organizations in the same industry may have different values. For example, a mature, well-established manufacturer may view reputation and innovation as its highest-priority values, whereas a struggling manufacturer will see revenue or market share growth as its main drivers.

    Value Drivers

    Increase Revenue

    Reduce Costs

    Enhance Services

    Reach Customers

    • Revenue growth
    • Data monetization
    • Cost optimization
    • Labor reduction
    • Collaboration
    • Risk and compliance
    • Customer experience
    • Trust and reputation

    You do not need to dissect each quadrant into an exhaustive list of value drivers. Info-Tech recommends defining distinct value drivers only for the areas you’ve identified as critical to your organization’s core goals and objectives.

    Understand value drivers that enable revenue growth

    Direct Revenue

    This value driver is the ability of a product or service to directly produce revenue through core revenue streams.

    Can be derived from:

    • Creating revenue
    • Improving the revenue generation of an existing service
    • Preventing the loss of a revenue stream

    Be aware of the differences between your products and services that enable a revenue source and those that facilitate the flow of capital.

    Funding

    This value driver is the ability of a product or service to enable other types of funding unrelated to core revenue streams.

    Can be derived from:

    • Tax revenue
    • Fees, fines, and ticketing programs
    • Participating in government subsidy or grant programs

    Be aware of the difference between your products and services that enable a revenue source and those that facilitate the flow of capital.

    Scale & Growth

    In essence, this driver can be viewed as the potential for growth in market share or new developing revenue sources.

    Does the product or service:

    • Increase your market share
    • Help you maintain your market share

    Be cautious of which items you identify here, as many innovative activities may have some potential to generate future revenue. Stick to those with a strong connection to future revenue and don’t qualify for other value driver categories.

    Monetization of Assets

    This value driver is the ability of your products and services to generate additional assets.

    Can be derived from:

    • Sale of data
    • Sale of market or customer reports or analysis
    • Sale of IP

    This value source is often overlooked. If given the right attention, it can lead to a big win for IT’s role in the business.

    Understand value drivers that reduce costs

    Cost Reduction

    A cost reduction is a “hard” cost saving that is reflected as a tangible decrease to the bottom line.

    This can be derived from reduction of expenses such as:

    • Salaries and wages
    • Hardware/software maintenance
    • Infrastructure

    Cost reduction plays a critical role in an application’s ability to increase efficiency.

    Cost Avoidance

    A cost avoidance is a “soft” cost saving, typically achieved by preventing a cost from occurring in the first place (i.e. risk mitigation). Cost avoidance indirectly impacts the bottom line.

    This can be derived from prevention of expenses by:

    • Mitigating a business outage
    • Mitigating another risk event
    • Delaying a price increase

    Understand the value drivers that enhance your services

    Enable Core Operations

    Some applications are in place to facilitate and support the structure of the organization. These vary depending on the capabilities of your organization but should be assessed in relation to the organization’s culture and structure.

    • Enables a foundational capability
    • Enables a niche capability

    This example is intentionally broad, as “core operations” should be further dissected to define different capabilities with ranging priority.

    Compliance

    A product or service may be required in order to meet a regulatory requirement. In these cases, you need to be aware of the organizational risk of NOT implementing or maintaining a service in relation to those risks.

    In this case, the product or service is required in order to:

    • Prevent fines
    • Allow the organization to operate within a specific jurisdiction
    • Remediate audit gaps
    • Provide information required to validate compliance

    Internal Improvement

    An application’s ability to create value outside of its core operations and facilitate the transfer of information, insights, and knowledge.

    Value can be derived by:

    • Data analytics
    • Collaboration
    • Knowledge transfer
    • Organizational learning

    Innovation

    Innovation is typically an ill-defined value driver, as it refers to the ability of your products and services to explore new value streams.

    Consider:

    • Exploration into new markets and products
    • New methods of organizing resources and processes

    Innovation is one of the more divisive value drivers, as some organizations will strive to be cutting edge and others will want no part in taking such risks.

    Understand business value drivers that connect the business to your customers

    Policy

    Products and services can also be assessed in relation to whether they enable and support policies of the organization. Policies identify and reinforce required processes, organizational culture, and core values.

    Policy value can be derived from:

    • The service or initiative will produce outcomes in line with our core organizational values.
    • Products that enable sustainability and corporate social responsibility

    Experience

    Applications are often designed to improve the interaction between customer and product. This value type is most closely linked to product quality and user experience. Customers, in this sense, can also include any stakeholders who consume core offerings.

    Customer experience value can be derived from:

    • Improving customer satisfaction
    • Ease of use
    • Resolving a customer issue or identified pain point
    • Providing a competitive advantage for your customers

    Customer Information

    Understanding demand and customer trends is a core driver for all organizations. Data provided through understanding the ways, times, and reasons that consumers use your services is a key driver for growth and stability.

    Customer information value can be achieved when an app:

    • Addresses strategic opportunities or threats identified through analyzing trends
    • Prevents failures due to lack of capacity to meet demand
    • Connects resources to external sources to enable learning and growth within the organization

    Trust & Reputation

    Products and services are designed to enable goals of digital ethics and are highly linked to your organization’s brand strategy.

    Trust and reputation can also be described as:

    • Customer loyalty and sustainability
    • Customer privacy and digital ethics

    Prioritizing this value source is critical, as traditional priorities can often come at the expense of trust and reputation.

    Define your value drivers

    1.2 Estimated Time: 1.5 hours

    The objective of this exercise is to establish a common understanding of the different values of the organization.

    1. Place your business value authorities at the center of this exercise.
    2. Collect all the documents your organization has on the mission and vision, strategy, governance, and target state, which may be defined by enterprise architecture.
    3. Identify the company mission and vision. Simply transfer the information from the mission and vision document into the appropriate spaces in the business value statement.
    4. Determine the organization’s business value drivers. Use the mission and vision, as well as the information from the collected documents, to formulate your own idea of business values.
    5. Use value driver template on the next slide to define the value driver, including:
    • Value Driver Name
    • Description
    • Related Business Capabilities – If available, review business architecture materials, such as business capability maps.
    • Established KPI and Targets – If available, include any organization-wide established KPIs related to your value driver. These KPIs will likely be used or influence the metrics eventually assigned to your applications.

    INPUT

    • Mission, vision, value statements

    OUTPUT

    • List and description of value drivers

    Materials

    • Whiteboard
    • Markers

    Participants

    • Business value authorities
    • Owner of value measurement framework

    Example Value Driver

    Value Driver Name

    Reach Customers

    Value Driver Description

    Our organization’s ability to provide quality products and experience to our core customers

    Value Driver Weight

    10/10

    Related Business Capabilities

    • Customer Services
    • Marketing
      • Customer Segmentation
      • Customer Journey Mapping
    • Product Delivery
      • User Experience Design
      • User Acceptance Testing

    Key Business Outcomes, KPIs, and Targets

    • Improved Customer Satisfaction
      • Net Promotor Score: 80%
    • Improved Loyalty
      • Repeat Sales: 30%
      • Customer Retention: 25%
      • Customer Lifetime Value: $2,500
    • Improved Interaction
      • Repeat Visits: 50%
      • Account Conversation Rates: 40%

    Weigh your value drivers

    1.3 Estimated Time: 30 minutes

    The objective of this exercise is to prioritize your value drivers based on their relative importance to the business.

    1. Again, place the business value authorities at the center of this exercise.
    2. In order to determine priority, divide 100% among your value drivers, allocating a percentage to each based on its relative importance to the organization.
    3. Normalize those percentages on to a scale of 1 to 10, which will act as the weights for your value drivers.

    INPUT

    • Mission, vision, value statements

    OUTPUT

    • Weights for value drivers

    Materials

    • Whiteboard
    • Markers

    Participants

    • Business value authorities
    • Owner of value measurement framework

    Weigh your value drivers

    1.3 Estimated Time: 30 minutes

    Value Driver

    Percentage Allocation

    1 to 10 Weight

    Revenue and other funding

    24%

    9

    Cost reduction

    8%

    3

    Compliance

    5%

    2

    Customer value

    30%

    10

    Operations

    13%

    7

    Innovation

    5%

    2

    Sustainability and social responsibility

    2%

    1

    Internal learning and development

    3%

    1

    Future growth

    10%

    5

    Total

    100%

    Carry results over to the Value Calculator

    1.3

    Document results of this activity in the “Value Drivers” tab of the Value Calculator.

    A screenshot of Info-Tech's Value Calculator is shown.

    List your value drivers.

    Define or describe your value drivers.

    Use this tool to create a repository for value sources to reuse and maintain consistency across your measurements.

    Enter the weight of each value driver in terms of importance to the organization.

    Phase 2

    Measure Value

    Step 2.1: Identify Product or Service SMEs

    Phase 1

    1.1: Identify Value Authorities

    1.2: Define Value Drivers

    Phase 2

    2.1: Identify Product or Service SMEs

    2.2: Measure Value

    This step will walk you through the following activities:

    • Identify your product or service SMEs.
    • List your product or services items and components.

    This step involves the following participants:

    • Owners of your value measurement framework
    • Product or service SMEs

    Outcomes of this step

    • Your list of targeted individuals to include in Step 2.2

    Identify the products and services you are evaluating and break down their various components for the VMF

    In order to get a full evaluation of a product or service you need to understand its multiple facets, functions, features capabilities, requirements, or any language you use to describe its various components.

    An image of the value measure framework is shown.

    Decompose a product or service:

    • Get the right subject matter experts in place who know the business and technical aspects of the product or service.
    • Decompose the product or service to capture all necessary components.

    Before beginning, consider how your use case will impact your value measurement approach

    This table looks at how the different use cases of the VMF call for variations of this analysis, is directed at different roles, and relies on participation from different subject matter experts to provide business context.

    Use Case (uses of the VMF applied in this blueprint)

    Value (current vs. future value)

    Item (the singular entity you are producing a value score for)

    Components (the various facets of that entity that need to be considered)

    Scope (# of systems undergoing analysis)

    Evaluator (typical role responsible for applying the VMF)

    Cadence (when and why do you apply the VMF)

    Information Sources (what documents, tools, etc., do you need to leverage)

    SMEs (who needs to participate to define and measure value)

    1. Prioritize Your Product Backlog

    You are estimating future value of proposed changes to an application.

    Product backlog items (epic, feature, etc.) in your product backlog

    • Features
    • User stories
    • Enablers

    A product

    Product owner

    Continuously apply the VMF to prioritize new and changing product backlog items.

    • Epic hypothesis, documentation
    • Lean business case

    Product manager

    ????

    2. Prioritize Your Project Backlog

    Proposed projects in your project backlog

    • Benefits
    • Outcomes
    • Requirements

    Multiple existing and/or new applications

    Project portfolio manager

    Apply the VMF during your project intake process as new projects are proposed.

    • Completed project request forms
    • Completed business case forms
    • Project charters
    • Business requirements documents

    Project manager

    Product owners

    Business analysts

    3. Application Rationalization

    You are measuring current value of existing applications and their features.

    An application in your portfolio

    The uses of the application (features, function, capabilities)

    A subset of applications or the full portfolio

    Application portfolio manager

    During an application rationalization initiative:

    • Iteratively collect information and perform value measurements.
    • Structure your iterations based on functional areas to target the specific SMEs who can speak to a particular subset of applications.
    • Business capability maps

    Business process owners

    Business unit representatives

    Business architects

    Application architects

    Application SMEs

    4. Application Categorization

    The full portfolio

    Application maintenance or operations manager

    • SLAs
    • Business capability maps

    Identify your product or service SMEs

    2.1 Estimated Time: 15 minutes

    The objective of this exercise is to identify specific business stakeholders who can speak to the business outcomes of your applications at a functional level.

    1. Review your related materials that reference the stakeholders for the scoped products and services (i.e. capability maps, org charts, stakeholder maps).
    2. Identify your specific business stakeholders and application SMEs. These individuals represent the business at a functional level and are in tune with the business outcomes of their operations and the applications that support their operations.
      1. Use Case 1 – Product Owner, Product Manager
      2. Use Case 2 – Project Portfolio Manager, Project Manager, Product Owners, Business Process Owners, Appropriate Business Unit Representatives
      3. Use Case 3 – Application Portfolio Manager, Product Owners, Business Analysts, Application SMEs, Business Process Owners, Appropriate Business Unit Representatives
      4. Use Case 4 – Application Maintenance Manager, Operations Managers, Application Portfolio Manager, Product Owners, Application SMEs, Business Process Owners, Appropriate Business Unit Representatives

    INPUT

    • Specific product or service knowledge

    OUTPUT

    • Targeted individuals to measure specific products or services

    Materials

    • Whiteboard
    • Markers

    Participants

    • Owner of value measurement framework

    Use Case 1: Collect and review all of the product backlog items

    Prioritizing your product backlog (epics, features, etc.) requires a consistent method of measuring the value of your product backlog items (PBIs) to continuously compare their value relative to one another. This should be treated as an ongoing initiative as new items are added and existing items change, but an initial introduction of the VMF will require you to collect and analyze all of the items in your backlog.

    Regardless of producing a value score for an epic, feature, or user story, your focus should be on identifying their various value sources. Review your product’s artifact documentation, toolsets, or other information sources to extract the business outcomes, impact, benefits, KPIs, or any other description of a value source.

    High

    Epics

    Carefully valuated with input from multiple stakeholders, using metrics and consistent scoring

    Level of valuation effort per PBI

    User Stories

    Collaboratively valuated by the product owner and teams based on alignment and traceability to corresponding epic or feature

    Low

    Raw Ideas

    Intuitively valuated by the product owner based on alignment to product vision and organization value drivers

    What’s in your backlog?

    You may need to create standards for defining and measuring your different PBIs. Traceability can be critical here, as defined business outcomes for features or user stories may be documented at an epic level.

    Additional Research

    Build a Better Backlog helps you define and organize your product backlog items.

    Use Case 2: Review the scope and requirements of the project to determine all of the business outcomes

    Depending on where your project is in your intake process, there should be some degree of stated business outcomes or benefits. This may be a less refined description in the form of a project request or business case document, or it could be more defined in a project charter, business requirements document/toolset, or work breakdown structure (WBS). Regardless of the information source, to make proper use of the VMF you need a clear understanding of the various business outcomes to establish the new or improved value sources for the proposed project.

    Project

    User Requirements

    Business Requirements

    System Requirements

    1

    1

    1

    2

    2

    2

    3

    3

    4

    Set Metrics Early

    Good project intake documentation begins the discussion of KPIs early on. This alerts teams to the intended value and gives your PMO the ability to integrate it into the workload of other proposed or approved projects.

    Additional Research

    Optimize Project Intake, Approval, and Prioritization provides templates to define proposed project benefits and outcomes.

    Use Cases 3 & 4: Ensure you’ve listed all of each application’s uses (functions, features, capabilities, etc.) and user groups

    An application can enable multiple capabilities, perform a variety of functions, and have a range of different user groups. Therefore, a single application can produce multiple value sources, which range in type, impact, and significance to the business’ overarching priorities. In order to effectively measure the overall value of an application you need to determine all of the ways in which that application is used and apply a business-downward view of your applications.

    Business Capability

    • Sub-capability
    • Process
    • Task

    Application

    • Module
    • Feature
    • Function

    Aim for Business Use

    Simply listing the business capabilities of an app can be too high level. Regardless of your organization’s terminology, you need to establish all of the different uses and users of an application to properly measure all of the facets of its value.

    Additional Research

    Discover Your Applications helps you identify and define the business use and features of your applications.

    List your product or services items and components

    2.2 Estimated Time: 15 minutes

    The objective of this exercise is to produce a list of the different items that you are scoring and ensure you have considered all relevant components.

    1. List each item you intend to produce a value score for:
      1. Use Case 1 – This may be the epics in your product backlog.
      2. Use Case 2 – This may be the projects in your project backlog.
      3. Use Cases 3 & 4 – This may be the applications in your portfolio. For this approach Info-Tech strongly recommends iteratively assessing the portfolio to produce a list of a subset of applications.
    2. For each item list its various components:
      1. Use Case 1 – This may be the features or user stories of an epic.
      2. Use Case 2 – This may be the business requirements of a project.
      3. Use Cases 3 & 4 – This may be the modules, features, functions, capabilities, or subsystems of an application.

    Item

    Components

    Add Customer Portal (Epic)

    User story #1: As a sales team member I need to process customer info.

    User story #2: As a customer I want access to…

    Transition to the Cloud (Project)

    Requirement #1: Build Checkout Cart

    NFR – Build integration with data store

    CRM (Application)

    Order Processing (module), Returns & Claims (module), Analytics & Reporting (Feature)

    INPUT

    • Product or service knowledge

    OUTPUT

    • Detailed list of items and components

    Materials

    • Whiteboard
    • Markers

    Participants

    • Owner of value measurement framework
    • Product or service SMEs

    Use Cases 3 & 4: Create a functional view of your applications (optional)

    2.3 Estimated Time: 1 hour

    The objective of this exercise is to establish the different use cases of an application.

    1. Recall the functional requirements and business capabilities for your applications.
    2. List the various actors who will be interacting with your applications and list the consumers who will be receiving the information from the applications.
    3. Based on your functional requirements, list the use cases that the actors will perform to deliver the necessary information to consumers. Each use case serves as a core function of the application. See the diagram below for an example.
    4. Sometimes several use cases are completed before information is sent to consumers. Use arrows to demonstrate the flow of information from one use case to another.

    Example: Ordering Products Online

    Actors

    Order Customer

    Order Online

    Search Products

    Consumers

    Submit Delivery Information

    Order Customer

    Pay Order

    Bank

    INPUT

    • Product or service knowledge

    OUTPUT

    • Product or service function

    Materials

    • Whiteboard
    • Markers

    Participants

    • Application architect
    • Enterprise architect
    • Business and IT stakeholders
    • Business analyst
    • Development teams

    Use Cases 3 & 4: Create a functional view of your applications (optional) (cont’d.)

    2.3 Estimated Time: 1 hour

    5. Align your application’s use cases to the appropriate business capabilities and stakeholder objectives.

    Example:

    Stakeholder Objective: Automate Client Creation Processes

    Business Capability: Account Management

    Function: Create Client Profile

    Function: Search Client Profiles

    Business Capability: Sales Transaction Management

    Function: Order Online

    Function: Search Products Function: Search Products

    Function: Submit Delivery Information

    Function: Pay Order

    Step 2.2: Measure Value

    Phase 1

    1.1: Identify Value Authorities

    1.2: Define Value Drivers

    Phase 2

    2.1: Identify Product or Service SMEs

    2.2: Measure Value

    This step will walk you through the following activities:

    • Identify your value sources.
    • Align to a value driver.
    • Assign metrics and gauge value fulfillment.

    This step involves the following participants:

    • Owners of your value measurement framework
    • Product or service SMEs

    Outcomes of this step

    • An initial list of reusable value sources and metrics
    • Value scores for your products or services

    Use your VMF and a repeatable process to produce value scores for all of your items

    With your products or services broken down, you can then determine a list of value sources, as well as their alignment to a value driver and a gauge of their value fulfillment, which in turn indicate the importance and impact of a value source respectively.

    A image of the value measure framework is shown.

    Lastly, we produce a value score for all items:

    • Determine business outcomes and value sources.
    • Align to the appropriate value driver.
    • Use metrics as the gauge of value fulfillment.
    • Collect your score.
    • Repeat.

    The business outcome is the impact the product or service has on the intended business activity

    Business outcomes are the business-oriented results produced by organization’s capabilities and the applications that support those capabilities. The value source is, in essence, “How does the application impact the outcome?” and this can be either qualitative or quantitative.

    Quantitative

    Qualitative

    Key Words

    Examples

    Key Words

    Examples

    Faster, cheaper

    Deliver faster

    Better

    Better user experience

    More, less

    More registrations per week

    Private

    Enhanced privacy

    Increase, decrease

    Decrease clerical errors

    Easier

    Easier to input data

    Can, cannot

    Can access their own records

    Improved

    Improved screen flow

    Do not have to

    Do not have to print form

    Enjoyable

    Enjoyable user experience

    Compliant

    Complies with regulation 12

    Transparent

    Transparent progress

    Consistent

    Standardized information gathered

    Richer

    Richer data availability

    Adapted from Agile Coach Journal.

    Measure value – Identify your value sources

    2.4 Estimated Time: 30 minutes

    The objective of this exercise is to establish the different value sources of a product or service.

    1. List the items you are producing an overall balance value score for. These can be products, services, projects, applications, product backlog items, epics, etc.
    2. For each item, list its various business outcomes in the form of a description that includes:
      1. The item being measured
      2. Business capability or activity
      3. How the item impacts said capability or activity

    Consider applying the user story format for future value sources or a variation for current value sources.

    As a (user), I want to (activity) so that I get (impact)

    INPUT

    • Product or service knowledge
    • Business process knowledge

    OUTPUT

    • List of value sources

    Materials

    • Whiteboard
    • Markers

    Participants

    • Owner of value measurement framework
    • Product or service SMEs

    Measure value – Align to a value driver

    2.5 Estimated Time: 30 minutes

    The objective of this exercise is to determine the value driver for each value source.

    1. Align each value source to a value driver. Choose between options A and B.
      1. Using a whiteboard, draw out a 2 x 2 business value matrix or an adapted version based on your own organizational value drivers. Place each value source in the appropriate quadrant.
        1. Increase Revenue
        2. Reduce Costs
        3. Enhance Services
        4. Reach Customers
      2. Using a whiteboard or large sticky pads, create a section for each value driver. Place each value source with the appropriate value driver.

    INPUT

    • Product or service knowledge
    • Business process knowledge

    OUTPUT

    • Value driver weight

    Materials

    • Whiteboard
    • Markers

    Participants

    • Owner of value measurement framework
    • Product or service SMEs

    Brainstorm the different sources of business value (cont’d.)

    2.5

    Example:

    An example of activity 2.5 is shown.

    Carry results over to the Value Calculator

    2.5

    Document results of this activity in the Value Calculator in the Item {#} tab.

    A screenshot of the Value Calculator is shown.

    List your Value Sources

    Your Value Driver weights will auto-populate

    Aim, but do not reach, for SMART metrics

    Creating meaningful metrics

    S pecific

    M easureable

    A chievable

    R ealisitic

    T ime-based

    Follow the SMART framework when adding metrics to the VMF.

    The intention of SMART goals and metrics is to make sure you have chosen a gauge that will:

    • Reflect the actual business outcome or value source you are measuring.
    • Ensure all relevant stakeholders understand the goals or value you are driving towards.
    • Ensure you actually have the means to capture the performance.

    Info-Tech Insight

    Metrics are NOT a magical solution. They should be treated as a tool in your toolbox and are sometimes no more than a rough gauge of performance. Carefully assign metrics to your products and services and do not disregard the informed subjective perspective when SMART metrics are unavailable.

    Info-Tech Best Practice

    One last critical consideration here is the degree of effort required to collect the metric compared to the value of the analysis you are performing. Assessing whether or not to invest in a project should apply the rigor of carefully selecting and measuring value. However, performing a rationalization of the full app portfolio will likely lead to analysis paralysis. Taking an informed subjective perspective may be the better route.

    Measure value – Assign metrics and gauge value fulfillment

    2.6 30-60 minutes

    The objective of this exercise is to determine an appropriate metric for each value source.

    1. For each value source assign a metric that will be the unit of measurement to gauge the value fulfilment of the application.
    2. Review the product or services performance with the metric
      1. Use case 1&2 (Proposed Applications and/or Features) - You will need to estimate the degree of impact the product or services will have on your selected metric.
      2. Use case 3&4 (Existing Applications and/or Features) – You can review historically how the product or service has performed with your selected metric
    3. Determine a value fulfillment on a scale of 1 – 10.
    4. 10 = The product or service far exceeds expectations and targets on the metric.

      5 = the product or service meets expectations on this metric.

      1 = the product or service underperforms on this metric.

    INPUT

    • Product or service knowledge
    • Business process knowledge

    OUTPUT

    • Value driver weight

    Materials

    • Whiteboard
    • Markers

    Participants

    • Owner of value measurement framework
    • Product or service SMEs

    Carry results over to the Value Calculator

    2.6

    Document results of this activity in the Value Calculator in the Item {#} tab.

    A screenshot of Info-Tech's Value Calculator is shown.

    Assign Metrics.

    Consider using current or estimated performance and targets.

    Assess the impact on the value source with the value fulfillment.

    Collect your Overall Balanced Value Score

    Appendix

    Bibliography

    Brown, Alex. “Calculating Business Value.” Agile 2014 Orlando – July 13, 2014. Scrum Inc. 2014. Web. 20 Nov. 2017.

    Brown, Roger. “Defining Business Value.” Scrum Gathering San Diego 2017. Agile Coach Journal. Web.

    Curtis, Bill. “The Business Value of Application Internal Quality.” CAST. 6 April 2009. Web. 20 Nov. 2017.

    Fleet, Neville, Joan Lasselle, and Paul Zimmerman. “Using a Balance Scorecard to Measure the Productivity and Value of Technical Documentation Organizations.” CIDM. April 2008. Web. 20 Nov. 2017.

    Harris, Michael. “Measuring the Business Value of IT.” David Consulting Group. 20 Nov. 2017.

    Intrafocus. “What is a Balanced Scorecard?” Intrafocus. Web. 20 Nov. 2017

    Kerzner, Harold. Project Management: A Systems Approach to Planning, Scheduling, and Controlling. 12th ed., Wiley, 2017.

    Lankhorst, Marc., et al. “Architecture-Based IT Valuation.” Via Nova Architectura. 31 March 2010. Web. 20 Nov. 2017.

    Rachlin, Sue, and John Marshall. “Value Measuring Methodology.” Federal CIO Council, Best Practices Committee. October 2002. Web. April 2019.

    Thiagarajan, Srinivasan. “Bridging the Gap: Enabling IT to Deliver Better Business Outcomes.” Cognizant. July 2017. Web. April 2019.

    Create a Work-From-Anywhere Strategy

    • Buy Link or Shortcode: {j2store}323|cart{/j2store}
    • member rating overall impact: 9.0/10 Overall Impact
    • member rating average dollars saved: 33 Average Days Saved
    • member rating average days saved: After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve.
    • Parent Category Name: IT Strategy
    • Parent Category Link: /it-strategy

    Work-from-anywhere isn’t going anywhere. During the initial rush to remote work, tech debt was highlighted and the business lost faith in IT. IT now needs to:

    • Rebuild trust with the CXO.
    • Identify gaps created from the COVID-19 rush to remote work.
    • Identify how IT can better support remote workers.

    IT went through an initial crunch to enable remote work. It’s time to be proactive and learn from our mistakes.

    Our Advice

    Critical Insight

    • It’s not about embracing the new normal; it’s about resiliency and long-term success. Your strategy needs to not only provide short-term operational value but also make the organization more resilient for the unknown risks of tomorrow.
    • The nature of work has fundamentally changed. IT departments must ensure service continuity, not for how the company worked in 2019, but for how the company is working now and will be working tomorrow.
    • Ensure short-term survival. Don’t focus on becoming an innovator until you are no longer stuck in firefighting.
    • Aim for near-term innovation. Once you’re a trusted operator, become a business partner by helping the business better adapt business processes and operations to work-from-anywhere.

    Impact and Result

    Follow these steps to build a work-from-anywhere strategy that resonates with the business:

    • Identify a vision that aligns with business goals.
    • Design the work-from-anywhere value proposition for critical business roles.
    • Benchmark your current maturity.
    • Build a roadmap for bridging the gap.

    Benefit employees’ remote working experience while ensuring that IT heads in a strategic direction.

    Create a Work-From-Anywhere Strategy Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to find out why you should create a work-from-anywhere strategy, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Define a target state

    Identify a vision that aligns with business goals, not for how the company worked in 2019, but for how the company is working now and will be working tomorrow.

    • Work-From-Anywhere Strategy Template
    • Work-From-Anywhere Value Proposition Template

    2. Analyze current fitness

    Don’t focus on becoming an innovator until you are no longer stuck in firefighting mode.

    3. Build a roadmap for improving enterprise apps

    Use these blueprints to improve your enterprise app capabilities for work-from-anywhere.

    • Microsoft Teams Cookbook – Sections 1-2
    • Rationalize Your Collaboration Tools – Phases 1-3
    • Adapt Your Customer Experience Strategy to Successfully Weather COVID-19 Storyboard
    • The Rapid Application Selection Framework Deck

    4. Build a roadmap for improving strategy, people & leadership

    Use these blueprints to improve IT’s strategy, people & leadership capabilities for work-from-anywhere.

    • Define Your Digital Business Strategy – Phases 1-4
    • Training Deck: Equip Managers to Effectively Manage Virtual Teams
    • Sustain Work-From-Home in the New Normal Storyboard
    • Develop a Targeted Flexible Work Program for IT – Phases 1-3
    • Maintain Employee Engagement During the COVID-19 Pandemic Storyboard
    • Adapt Your Onboarding Process to a Virtual Environment Storyboard
    • Manage Poor Performance While Working From Home Storyboard
    • The Essential COVID-19 Childcare Policy for Every Organization, Yesterday Storyboard

    5. Build a roadmap for improving infrastructure & operations

    Use these blueprints to improve infrastructure & operations capabilities for work-from-anywhere.

    • Stabilize Infrastructure & Operations During Work-From-Anywhere – Phases 1-3
    • Responsibly Resume IT Operations in the Office – Phases 1-5
    • Execute an Emergency Remote Work Plan Storyboard
    • Build a Digital Workspace Strategy – Phases 1-3

    6. Build a roadmap for improving IT security & compliance capabilities

    Use these blueprints to improve IT security & compliance capabilities for work-from-anywhere.

    • Cybersecurity Priorities in Times of Pandemic Storyboard
    • Reinforce End-User Security Awareness During Your COVID-19 Response Storyboard

    Infographic

    Workshop: Create a Work-From-Anywhere Strategy

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Define a Target State

    The Purpose

    Define the direction of your work-from-anywhere strategy and roadmap.

    Key Benefits Achieved

    Base your decisions on senior leadership and user needs.

    Activities

    1.1 Identify drivers, benefits, and challenges.

    1.2 Perform a goals cascade to align benefits to business needs.

    1.3 Define a vision and success metrics.

    1.4 Define the value IT brings to work-from-anywhere.

    Outputs

    Desired benefits for work-from-anywhere

    Vision statement

    Mission statement

    Success metrics

    Value propositions for in-scope user groups

    2 Review In-Scope Capabilities

    The Purpose

    Focus on value. Ensure that major applications and IT capabilities will relieve employees’ pains and provide them with gains.

    Key Benefits Achieved

    Learn from past mistakes and successes.

    Increase adoption of resulting initiatives.

    Activities

    2.1 Review work-from-anywhere framework and identify capability gaps.

    2.2 Review diagnostic results to identify satisfaction gaps.

    2.3 Record improvement opportunities for each capability.

    2.4 Identify deliverables and opportunities to provide value for each.

    2.5 Identify constraints faced by each capability.

    Outputs

    SWOT assessment of work-from-anywhere capabilities

    Projects and initiatives to improve capabilities

    Deliverables and opportunities to provide value for each capability

    Constraints with each capability

    3 Build the Roadmap

    The Purpose

    Build a short-term plan that allows you to iterate on your existing strengths and provide early value to your users.

    Key Benefits Achieved

    Provide early value to address operational pain points.

    Build a plan to provide near-term innovation and business value.

    Activities

    3.1 Organize initiatives into phases.

    3.2 Identify tasks for short-term initiatives.

    3.3 Estimate effort with Scrum Poker.

    3.4 Build a timeline and tie phases to desired business benefits.

    Outputs

    Prioritized list of initiatives and phases

    Profiles for short-term initiatives

    2020 Applications Priorities Report

    • Buy Link or Shortcode: {j2store}159|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Optimization
    • Parent Category Link: /optimization
    • Although IT may have time to look at trends, it does not have the capacity to analyze the trends and turn them into initiatives.
    • IT does not have time to parse trends for initiatives that are relevant to them.
    • The business complains that if IT does not pursue trends the organization will get left behind by cutting-edge competitors. At the same time, when IT pursues trends, the business feels that IT is unable to deal with the basic issues.

    Our Advice

    Critical Insight

    • Take advantage of a trend by first understanding why it is happening and how it is actionable. Build momentum now. Breaking a trend into bite-sized initiatives and building them into your IT foundations enables the organization to maintain pace with competitors and make the technological leap.
    • The concepts of shadow IT and governance are critical. As it becomes easier for the business to purchase its own applications, it will be essential for IT to embrace this form of user empowerment. With a diminished focus on vendor selection, IT will drive the most value by directing its energy toward data and integration governance.

    Impact and Result

    • Determine how to explore, adopt, and optimize the technology and practice initiatives in this report by understanding which core objective(s) each initiative serves:
      • Optimize the effectiveness of the IT organization.
      • Boost the productivity of the enterprise.
      • Enable business growth through technology.

    2020 Applications Priorities Report Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief for a summary of the priorities and themes that an IT organization should focus on this year.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Read the 2020 Applications Priorities Report

    Use Info-Tech's 2020 Applications Priorities Report to learn about the five initiatives that IT should prioritize for the coming year.

    • 2020 Applications Priorities Report Storyboard
    [infographic]

    Manage the Active Directory in the Service Desk

    • Buy Link or Shortcode: {j2store}489|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Service Desk
    • Parent Category Link: /service-desk
    • Actively maintaining the Active Directory is a difficult task that only gets more difficult with issues like stale accounts and privilege creep.
    • Adding permissions without removing them in lateral transfers creates access issues, especially when regulatory requirements like HIPAA require tight controls.
    • With the importance of maintaining and granting permissions within the Active Directory, organizations are hesitant to grant domain admin access to Tier 1 of the service desk. However, inundating Tier 2 analysts with requests to grant permissions takes away project time.

    Our Advice

    Critical Insight

    • Do not treat the Active Directory like a black box. Strive for accurate data and be proactive by managing your monitoring and audit schedules.
    • Catch outage problems before they happen by splitting monitoring tasks between daily, weekly, and monthly routines.
    • Shift left to save resourcing by employing workflow automation or scripted authorization for Tier 1 technicians.
    • Design actionable metrics to monitor and manage your Active Directory.

    Impact and Result

    • Consistent and right-sized monitoring and updating of the Active Directory is key to clean data.
    • Split monitoring activities between daily, weekly, and monthly checklists to raise efficiency.
    • If need be, shift-left strategies can be implemented for identity and access management by scripting the process so that it can be done by Tier 1 technicians.

    Manage the Active Directory in the Service Desk Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to find out why you should manage your Active Directory in the service desk, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Maintain your Active Directory with clean data

    Building and maintaining your Active Directory does not have to be difficult. Standardized organization and monitoring with the proper metrics help you keep your data accurate and up to date.

    • Active Directory Standard Operating Procedure
    • Active Directory Metrics Tool

    2. Structure your service desk Active Directory processes

    Build a comprehensive Active Directory workflow library for service desk technicians to follow.

    • Active Directory Process Workflows (Visio)
    • Active Directory Process Workflows (PDF)
    [infographic]

    Streamline Your Workforce During a Pandemic

    • Buy Link or Shortcode: {j2store}515|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Lead
    • Parent Category Link: /lead

    Reduced infection rates in compromised areas are providing hope that these difficult times will pass. However, organizations are facing harsh realities in real time. With significant reductions in revenue, employers are facing pressure to quickly implement cost-cutting strategies, resulting in mass layoffs of valuable employees.

    Our Advice

    Critical Insight

    Employees are an organization’s greatest asset. When faced with cost-cutting pressures, look for redeployment opportunities that use talent as a resource to get through hard times before resorting to difficult layoff decisions.

    Impact and Result

    Make the most of your workforce in this unprecedented situation by following McLean & Company’s process to initiate redeployment efforts and reduce costs. If all else fails, follow our guidance on planning for layoffs and considerations when doing so.

    Streamline Your Workforce During a Pandemic Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Meet with leadership

    Set a strategy with senior leadership, brainstorm underused and understaffed employee segments and departments, then determine an approach to redeployments and layoffs.

    • Streamline Your Workforce During a Pandemic Storyboard
    • Redeployment and Layoff Strategy Workbook

    2. Plan individual and department redeployment

    Collect key information, prepare and redeploy, and roll up information across the organization.

    • Short-Term Survival Segment Evaluation Tool
    • Skills Inventory for Redeployment Tool
    • Redeployment Action and Communication Plan
    • Crisis Communication Guide for HR
    • Crisis Communication Guide for Leaders
    • Leadership Crisis Communication Guide Template
    • 3i's of Engaging Management – Manager Guide
    • Feedback and Coaching Guide for Managers
    • Redeployment Communication Roll-up Template

    3. Plan individual and department layoffs

    Plan for layoffs, execute on the layoff plan, and communicate to employees.

    • Employee Departure Checklist Tool
    • 10 Communication Best Practices in the Face of Crisis
    • Termination Logistics Tool
    • Termination Costing Tool
    • COVID-19: Employee-Facing Frequently Asked Questions Template
    • COVID-19: Employee-Facing Frequently Asked Questions
    • Standard Internal Communications Plan

    4. Monitor and manage departmental effectiveness

    Monitor departmental performance, review organizational performance, and determine next steps.

    • HR Metrics Library
    • Standard HR Scorecard
    [infographic]

    Develop a Master Data Management Practice and Platform

    • Buy Link or Shortcode: {j2store}401|cart{/j2store}
    • member rating overall impact: 9.3/10 Overall Impact
    • member rating average dollars saved: $27,416 Average $ Saved
    • member rating average days saved: 15 Average Days Saved
    • Parent Category Name: Data Management
    • Parent Category Link: /data-management
    • The volume of enterprise data is growing rapidly and comes from a wide variety of internal and external data sources (e.g. ERP, CRM). When data is located in different systems and applications, coupled with degradation and proliferation, this can lead to inaccurate, inconsistent, and redundant data being shared across departments within an organization.
    • Data kept in separate soiled sources can result in poor stakeholder decision making and inefficient business processes. Some common master data problems include:
      • The lack of a clean customer list results in poor customer service.
      • Hindering good analytics and business predictions, such as incorrect supply chain decisions when having duplicate product and vendor data between plants.
      • Creating cross-group consolidated reports from inconsistent local data that require too much manual effort and resources.

    Our Advice

    Critical Insight

    • Everybody has master data (e.g. customer, product) but not master data problems (e.g. duplicate customers and products). MDM is complex in practice and requires investments in data governance, data architecture, and data strategy. Identifying business outcomes based on quality master data is essential before you pull the trigger on an MDM solution.

    Impact and Result

    This blueprint can help you:

    • Build a list of business-aligned data initiatives and capabilities that address master data problem and realize business strategic objectives.
    • Design a master data management practice based on the required business and data process.
    • Design a master data management platform based on MDM implementation style and prioritized technical capabilities.

    Develop a Master Data Management Practice and Platform Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Develop a Master Data Management Practice and Platform Deck – A clear blueprint that provides a step-by-step approach to aid in the development of your MDM practice and platform.

    This blueprint will help you achieve a single view of your most important data assets by following our two-phase methodology:

  • Build a vision for MDM
  • Build an MDM practice and platform
    • Develop a Master Data Management Practice and Platform – Phases 1-2

    2. Master Data Management Readiness Assessment Tool – A tool to help you make the decision to stop the MDM project now or to continue the path to MDM.

    This tool will help you determine if your organization has a master data problem and if an MDM project should be undertaken.

    • Master Data Management Readiness Assessment Tool

    3. Master Data Management Business Needs Assessment Tool – A tool to help you identify and document the various data sources in the organization and determine which data should be classified as master data.

    The tool will help you identify the sources of data within the business unit and use the typical properties of master data to determine which data should be classified as master data.

    • Master Data Management Business Needs Assessment Tool

    4. Master Data Management Business Case Presentation Template – A template to communicate MDM basics, benefits, and approaches to obtain business buy-in for the MDM project.

    The template will help you communicate your organization's specific pains surrounding poor management of master data and identify and communicate the benefits of effective MDM. Communicate Info-Tech's approach for creating an effective MDM practice and platform.

    • Master Data Management Business Case Presentation Template

    5. Master Data Management Project Charter Template – A template to centralize the critical information regarding to objectives, staffing, timeline, and expected outcome of the project.

    The project charter will help you document the project sponsor of the project. Identify purpose, goals, and objectives. Identify the project risks. Build a cross-functional project team and assign responsibilities. Define project team expectations and meeting frequency. Develop a timeline for the project with key milestones. Identify metrics for tracking success. Receive approval for the project.

    • Master Data Management Project Charter Template

    6. Master Data Management Architecture Design Template – An architecture design template to effectively document the movement of data aligned with the business process across the organization.

    This template will assist you:

  • Document the current state and achieve a common understanding of the business process and movement of data across the company.
  • Identify the source of master data and what other systems will contribute to the MDM system.
  • Document the target architectural state of the organization.
    • Master Data Management Architecture Design Template

    7. Master Data Management Practice Pattern Template – Pre-built practice patterns to effectively define the key services and outputs that must be delivered by establishing core capabilities, accountabilities, roles, and governance for the practice.

    The master data management practice pattern describes the core capabilities, accountabilities, processes, essential roles, and the elements that provide oversight or governance of the practice, all of which are required to deliver on high value services and deliverables or output for the organization.

    • Master Data Management Practice Pattern Template

    8. Master Data Management Platform Template – A pre-built platform template to illustrate the organization’s data environment with MDM and the value MDM brings to the organization.

    This template will assist you:

  • Establish an understanding of where MDM fits in an organization’s overall data environment.
  • Determine the technical capabilities that is required based on organization’s data needs for your MDM implementation.
    • Master Data Management Platform Template

    Infographic

    Workshop: Develop a Master Data Management Practice and Platform

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Develop a Vision for the MDM Project

    The Purpose

    Identification of MDM and why it is important.

    Differentiate between reference data and master data.

    Discuss and understand the key challenges and pains felt by the business and IT with respect to master data, and identify the opportunities MDM can provide to the business.

    Key Benefits Achieved

    Identification of what is and is not master data.

    Understand the value of MDM and how it can help the organization better monetize its data.

    Knowledge of how master data can benefit both IT and the business.

    Activities

    1.1 Establish business context for master data management.

    1.2 Assess the value, benefits, challenges, and opportunities associated with MDM.

    1.3 Develop the vision, purpose, and scope of master data management for the business.

    1.4 Identify MDM enablers.

    1.5 Interview business stakeholders.

    Outputs

    High-level data requirements

    Identification of business priorities

    Project vision and scope

    2 Document the Current State

    The Purpose

    Recognize business drivers for MDM.

    Determine where master data lives and how this data moves within the organization.

    Key Benefits Achieved

    Streamline business process, map the movement of data, and achieve a common understanding across the company.

    Identify the source of master data and what other systems will contribute to the MDM system.

    Activities

    2.1 Evaluate the risks and value of critical data.

    2.2 Map and understand the flow of data within the business.

    2.3 Identify master data sources and users.

    2.4 Document the current architectural state of the organization.

    Outputs

    Data flow diagram with identified master data sources and users

    Business data glossary

    Documented current data state.

    3 Document the Target State

    The Purpose

    Document the target data state of the organization surrounding MDM.

    Identify key initiatives and metrics.

    Key Benefits Achieved

    Recognition of four MDM implementation styles.

    Identification of key initiatives and success metrics.

    Activities

    3.1 Document the target architectural state of the organization.

    3.2 Develop alignment of initiatives to strategies.

    3.3 Consolidate master data management initiatives and strategies.

    3.4 Develop a project timeline and define key success measures.

    Outputs

    Documented target state surrounding MDM.

    Data and master data management alignment and strategies

    4 Develop an MDM Practice and Platform

    The Purpose

    Get a clear picture of what the organization wants to get out of MDM.

    Identify master data management capabilities, accountabilities, process, roles, and governance.

    Key Benefits Achieved

    Prioritized master data management capabilities, accountabilities, process, roles, and governance.

    Activities

    4.1 Identify master data management capabilities, roles, process, and governance.

    4.2 Build a master data management practice and platform.

    Outputs

    Master Data Management Practice and Platform

    Further reading

    Develop a Master Data Management Practice and Platform

    Are you sure you have a master data problem?

    Analyst Perspective

    The most crucial and shared data assets inside the firm must serve as the foundation for the data maturing process. This is commonly linked to your master data (such as customers, products, employees, and locations). Every organization has master data, but not every organization has a master data problem.

    Don't waste time or resources before determining the source of your master data problem. Master data issues are rooted in the business practices of your organization (such as mergers and acquisitions and federated multi-geographic operations). To address this issue, you will require a master data management (MDM) solution and the necessary architecture, governance, and support from very senior champions to ensure the long-term success of your MDM initiative. Approaching MDM with a clear blueprint that provides a step-by-step approach will aid in the development of your MDM practice and platform.

    Ruyi Sun

    Ruyi Sun
    Research Specialist
    Data & Analytics Practice
    Info-Tech Research Group

    Rajesh Parab

    Rajesh Parab
    Research Director
    Data & Analytics Practice
    Info-Tech Research Group

    Executive Summary

    Your Challenge

    Common Obstacles

    Info-Tech’s Approach

    Your organization is experiencing data challenges, including:

    • Too much data volume, variety, and velocity, from more and more sources.
    • Duplicate and disorganized data across multiple systems and applications.
    • Master data is pervasive throughout the business and is often created and captured in highly disparate sources that often are not easily shared across business units and applications.

    MDM is useful in situations such as a business undergoing a merger or acquisition, where a unique set of master data needs to be created to act as a single source of truth. However, having a unified view of the definitions and systems of record for the most critical data in your organization can be difficult to achieve. An organization might experience some pain points:

    • Failure to identify master data problem and organization’s data needs.
    • Conflicting viewpoints and definitions of data assets across business units.
    • Recognize common business operating models or strategies with master data problems.
    • Identify the organization’s problem and needs out of its master data and align to strategic business needs.
    • Define the architecture, governance, and support.
    • Create a practice and platform for the organization’s MDM program.

    Info-Tech Insight

    Everybody has master data (e.g. customer, product) but not a master data problem (e.g. duplicate customers and products). MDM is complex in practice and requires investments in data governance, data architecture, and data strategy. Identifying business outcomes based on quality master data is essential before you pull the trigger on an MDM solution.

    What is master data and master data management?

    • Master data domains include the most important data assets of an organization. For this data to be used across an enterprise in consistent and value-added ways, the data must be properly managed. Some common master data entities include customer, product, and employees.
    • Master data management (MDM) is the control over master data values to enable consistent, shared, contextual use across systems, of the most accurate, timely, and relevant version of truth about essential business entities (DAMA DMBOK).
    • The fundamental objective of MDM is to enable the business to see one view of critical data elements across the organization.
    • MDM systems will detect and declare relationships between data, resolve duplicate records, and make data available to the people, processes, and applications that need it. The end goal of an MDM implementation is to make sure your investment in MDM technology delivers the promised business results. By supplementing the technology with rules, guidelines, and standards around enterprise data you will ensure data continues to be synchronized across data sources on an ongoing basis.

    The image contains a screenshot of Info-Tech's Data Management Framework.

    Info-Tech’s Data Management Framework Adapted from DAMA-DMBOK and Advanced Knowledge Innovations Global Solutions. See Create a Data Management Roadmap blueprint for more information.

    Why manage master data?

    Master data drives practical insights that arise from key aspects of the business.

    Customer Intimacy

    Innovation Leadership

    Risk Management

    Operational Excellence

    Improve marketing and the customer experience by using the right data from the system of record to analyze complete customer views of transactions, sentiments, and interactions.

    Gain insights on your products, services, usage trends, industry directions, and competitor results, and use these data artifacts to support decisions on innovations, new products, services, and pricing.

    Maintain more transparent and accurate records and ensure that appropriate rules are followed to support audit, compliance, regulatory, and legal requirements. Monitor data usage to avoid fraud.

    Make sure the right solution is delivered rapidly and consistently to the right parties for the right price and cost structure. Automate processes by using the right data to drive process improvements.

    85% of customers expect consistent interactions across departments (Salesforce, 2022).

    Top-decile economic performers are 20% more likely to have a common source of data that serves as the single source of truth across the organization compared to their peers (McKinsey & Company, 2021).

    Only 6% of board members believe they are effective in managing risk (McKinsey & Company, 2018).

    32% of sales and marketing teams consider data inconsistency across platforms as their biggest challenge (Dun & Bradstreet, 2022).

    Your Challenge

    Modern organizations have unprecedented data challenges.

    • The volume of enterprise data is growing rapidly and comes from a wide variety of internal and external data sources (e.g. ERP, CRM). When data is located in different systems and applications, coupled with degradation and proliferation, this can lead to inaccurate, inconsistent, and redundant data being shared across departments within an organization.
    • For example, customer information may not be identical in the customer service system, shipping system, and marketing management platform because of manual errors or different name usage (e.g. GE or General Electric) when input by different business units.
    • Data kept in separate soiled sources can also result in poor stakeholder decision making and inefficient business processes. Some issues include:
      • The lack of clean customer list results in poor customer service.
      • Hindering good analytics and business predictions, such as incorrect supply chain decision when having duplicate product and vendor data between plants.
      • Creating cross-group consolidated reports from duplicate and inconsistent local data requires too much manual effort and resources.

    On average, 25 different data sources are used for generating customer insights and engagement.

    On average, 16 different technology applications are used to leverage customer data.

    Source: Deloitte Digital, 2020

    Common Obstacles

    Finding a single source of truth throughout the organization can be difficult.

    Changes in business process often come with challenges for CIOs and IT leaders. From an IT perspective, there are several common business operating models that can result in multiple sets of master data being created and held in various locations. Some examples could be:

    • Integrate systems following corporate mergers and acquisitions
    • Enterprise with multi-product line
    • Multinational company or multi-geographic operations with various ERP systems
    • Digital transformation projects such as omnichannel

    In such situations, implementing an MDM solution helps achieve harmonization and synchronization of master data and provide a single, reliable, and precise view of the organization. However, MDM is a complex system that requires more than just a technical solution. An organization might experience the following pain points:

    • Failure to identify master data problem and organization’s data needs.
    • Conflicting viewpoints and definitions of data assets that should reside in MDM across business units.

    Building a successful MDM initiative can be a large undertaking that takes some preparation before starting. Understanding the fundamental roles that data governance, data architecture, and data strategy play in MDM is essential before the implementation.

    “Only 3 in 10 of respondents are completely confident in their company's ability to deliver a consistent omnichannel experience.”

    Source: Dun & Bradstreet, 2022

    The image contains an Info-Tech Thought Model of the Develop a Master Data Management Practice & Platform.

    Insight summary

    Overarching insight

    Everybody has master data (e.g. customer, product) but not a master data problem (e.g. duplicate customers and products). MDM is complex in practice and requires investments in data governance, data architecture, and data strategy. Figuring out what the organization needs out of its master data is essential before you pull the trigger on an MDM solution.

    Phase 1 insight

    A master data management solution will assist you in solving master data challenges if your organization is large or complex, such as a multinational corporation or a company with multiple product lines, with frequent mergers and acquisitions, or adopting a digital transformation strategy such as omnichannel.

    Organizations often have trouble getting started because of the difficulty of agreeing on the definition of master data within the enterprise. Reference data is an easy place to find that common ground.

    While the organization may have data that fits into more than one master data domain, it does not necessarily need to be mastered. Determine what master data entities your organization needs.

    Although it is easy to get distracted by the technical aspects of the MDM project – such as extraction and consolidation rules – the true goal of MDM is to make sure that the consumers of master data (such as business units, sales) have access to consistent, relevant, and trusted shared data.

    Phase 2 insight

    An organization with activities such as mergers and acquisitions or multi-ERP systems poses a significant master data challenge. Prioritize your master data practice based on your organization’s ability to locate and maintain a single source of master data.

    Leverage modern capabilities such as artificial intelligence or machine learning to support large and complex MDM deployments.

    Blueprint Overview

    1. Build a Vision for MDM

    2. Build an MDM Practice and Platform

    Phase Steps

    1. Assess Your Master Data Problem
    2. Identify Your Master Data Domains
    3. Create a Strategic Vision
    1. Document Your Organization’s Current Data State
    2. Document Your Organization’s Target Data State
    3. Formulate an Actionable MDM Practice and Platform

    Phase Participants

    CIO, CDO, or IT Executive

    Head of the Information Management Practice

    Business Domain Representatives

    Enterprise Architecture Domain Architects

    Information Management MDM Experts

    Data Stewards or Data Owners

    Phase Outcomes

    This step identifies the essential concepts around MDM, including its definitions, your readiness, and prioritized master data domains. This will ensure the MDM initiatives are aligned to business goals and objectives.

    To begin addressing the MDM project, you must understand your current and target data state in terms of data architecture and data governance surrounding your MDM strategy. With all these considerations in mind, design your organizational MDM practice and platform.

    Blueprint deliverables

    Each step of this blueprint is accompanied by supporting deliverables to help you accomplish your goals:

    1. MDM Readiness Assessment ToolThe image contains a screenshot of the MDM Readiness Assessment Tool. 2. Business Needs Assessment Tool The image contains a screenshot of the Business Needs Assessment Tool.
    3. Business Case Presentation Template The image contains a screenshot of the Business Case Presentation Template. 4. Project Charter Template The image contains a screenshot of the Project Charter Template.
    5. Architecture Design Template The image contains a screenshot of the Architecture Design Template.

    Key deliverable:

    6. MDM Practice Pattern Template

    7. MDM Platform Template

    Define the intentional relationships between the business and the master data through a well-thought-out master data platform and practice.

    The image contains a screenshot to demonstrate the intentional relationships between the business and the master data.

    Measure the value of this blueprint

    Refine the metrics for the overall Master Data Management Practice and Platform.

    In phase 1 of this blueprint, we will help you establish the business context and master data needs.

    In phase 2, we will help you document the current and target state of your organization and develop a practice and platform so that master data is well managed to deliver on those defined metrics.

    Sample Metrics

    Method of Calculation

    Master Data Sharing Availability and Utilization

    # of Business Lines That Use Master Data

    Master Data Sharing Volume

    # of Master Entities

    # of Key Elements, e.g. # of Customers With Many Addresses

    Master Data Quality and Compliance

    # of Duplicate Master Data Records

    Identified Sources That Contribute to Master Data Quality Issues

    # of Master Data Quality Issues Discovered or Resolved

    # of Non-Compliance Issues

    Master Data Standardization/Governance

    # of Definitions for Each Master Entity

    # of Roles (e.g. Data Stewards) Defined and Created

    Trust and Satisfaction

    Trust Indicator, e.g. Confidence Indicator of Golden Record

    Info-Tech offers various levels of support to best suit your needs

    DIY Toolkit

    “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

    Guided Implementation

    “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

    Workshop

    “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

    Consulting

    “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

    Diagnostics and consistent frameworks used throughout all four options

    Guided Implementation

    What does a typical GI on this topic look like?

    Phase 1 Phase 2

    Call #1: Identify master data problem and assess your organizational readiness for MDM.

    Call #2: Define master data domains and priorities.

    Call #3: Determine business requirements for MDM.

    Call #4: Develop a strategic vision for the MDM project.

    Call #5: Map and understand the flow of data within the business.

    Call #6: Document current architectural state.

    Call #7: Discover the MDM implementation styles of MDM and document target architectural state.

    Call #8: Create MDM data practice and platform.

    Call #9: Summarize results and plan next steps.

    A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

    A typical GI is 8 to 12 calls over the course of 4 to 6 months.

    Workshop Overview

    Contact your account representative for more information.
    workshops@infotech.com 1-888-670-8889

    Day 1 Day 2 Day 3 Day 4 Day 5

    Develop a Vision for the MDM Project

    Document the
    Current State

    Document the
    Target State

    Develop a MDM Practice and Platform

    Next Steps and
    Wrap-Up (offsite)

    Activities

    • Establish business context for master data management.
    • Assess the readiness, value, benefits, challenges, and opportunities associated with MDM.
    • Develop the vision, purpose, and scope of master data management for the business.
    • Identify master data management enablers.
    • Interview business stakeholders.
    • Evaluate the risks and value of critical data.
    • Map and understand the flow of data within the business.
    • Identify master data sources and users.
    • Document the current architectural state of the organization
    • Document the target data state of the organization.
    • Develop alignment of initiatives to strategies.
    • Consolidate master data management initiatives and strategies.
    • Develop a project timeline and define key success measures.
    • Identify master data management capabilities, roles, process, and governance.
    • Build a master data management practice and platform.
    • Complete in-progress deliverables from previous four days.
    • Set up review time for workshop deliverables and to discuss next steps.

    Deliverables

    1. High-level data requirements
    2. Identification of business priorities
    3. Project vision and scope
    1. Data flow diagram with identified master data sources and users
    2. Business data glossary
    3. Documented current data state
    1. Documented target state surrounding MDM
    2. Data and master data management alignment and strategies
    1. Master Data Management Practice and Platform
    1. Master Data Management Strategy for continued success

    Phase 1: Build a Vision for MDM

    Develop a Master Data Management Practice and Platform

    Step 1.1

    Assess Your Master Data Problem

    Objectives

    1. Build a solid foundation of knowledge surrounding MDM.

    2. Recognize MDM problems that the organization faces in the areas of mergers and acquisitions, omnichannel, multi-product line, and multi-ERP setups.

    This step involves the following participants:

    CIO, CDO, or IT Executive

    Head of Information Management

    Outcomes of this step

    An understanding of master data, MDM, and the prerequisites necessary to create an MDM program.

    Determine if there is a need for MDM in the organization.

    Understand your data – it’s not all transactional

    Info-Tech analyzes the value of data through the lenses of its four distinct classes: Master, Transactional, Operational, and Reference.

    Master

    Transactional

    Operational

    Reference

    • Addresses critical business entities that fall into four broad groupings: party (customers, suppliers); product (products, policies); location (physical spaces and segmentations); and financial (contracts, transactions).
    • This data is typically critical to the organization, less volatile, and more complex in nature; it contains many data elements and is used across systems.
    • Transactional data refers to data generated when dealing with external parties, such as clients and suppliers.
    • Transactional data may be needed on a per-use basis or through several activities.
    • The data can also be accessed in real-time if needed.
    • Operational data refers to data that is used to support internal business activities, processes, or workflows.
    • This data is generated during a one-time activity or multiple times through a data hub or orchestration layer.
    • Depending on the need for speed, there can be a real-time aspect to the situation.
    • Examples: scheduling service data or performance data.
    • Reference data refers to simple lists of data that are typically static and help categorize other data using code tables.
    • Examples: list of countries or states, postal codes, general ledger chart of accounts, currencies, or product code.

    Recognize the fundamental prerequisites for MDM before diving into more specific readiness requirements

    Organizational buy-in

    • Ensure there is someone actively invested and involved in the progress of the project. Having senior management support, especially in the form of an executive sponsor or champion, is necessary to approve MDM budgets and resourcing.
    • MDM changes business processes and practices that affect many departments, groups, and people – this type of change may be disruptive so sponsorship from the top ensures your project will keep moving forward even during difficulties.
    • Consider developing a cross-functional master data team involving stakeholders from management, IT, and the business units. This group can ensure that the MDM initiative is aligned with and supports larger organizational needs and everyone understands their role.

    Understanding the existing data environment

    • Knowing the state of an organization’s data architecture, and which data sources are linked to critical business processes, is essential before starting an MDM project.
    • Identify the areas of data pain within your organization and establish the root cause. Determine what impact this is having on the business.

    Before starting to look at technology solutions, make sure you have organizational buy-in and an understanding of the existing data environment. These two prerequisites are the foundation for MDM success.

    Master data management provides opportunities to use data for analytical and operational purposes with greater accuracy

    MDM can be approached in two ways: analytical and operational.

    Think of it in the context of your own organization:

    • How will MDM improve the ability for accurate data to be shared across business processes (Operational MDM)?
    • How will MDM improve the quality of reports for management reporting and executive decision making (Analytical MDM)?

    An investment in MDM will improve the opportunities for using the organization’s most valuable data assets, including opportunities like:

    • Data is more easily shared across the organization’s environment with greater accuracy and trust.
    • Multiple instances of the same data are consistent.
    • MDM enables the ability to find the right data more quickly.

    9.5% of revenue was at risk when bad experiences were offered to customers.

    Source: Qualtrics XM Institute, 2022

    Master data management drives better customer experience

    85% In a survey of nearly 17,000 consumers and business buyers, 85% of customers expect consistent interactions across departments.

    Source: Salesforce, 2022

    Yet, 60% of customer say it generally feels like sales, service, and marketing teams do not share information.

    Source: Salesforce, 2022

    What is a business without the customer? Positive customer service experience drives customer retention, satisfaction, and revenue growth, and ultimately, determines the success of the organization. Effective MDM can improve customer experiences by providing consistent interactions and the ability to meet customer expectations.

    61% of customers say they would switch to a competitor after just one bad customer service experience.

    Source: Zendesk, 2022

    Common business operating models or strategies with master data problems

    Mergers and acquisitions (M&A)

    M&A involves activities related to the consolidation of two companies. From IT’s perspective, whether the organization maintains different IT systems and applications in parallel or undergoes data integration process, it is common to have multiple instances of the same customer or product entity across different systems between companies, leading to incomplete, duplicate, and conflicting data sets. The organization may face challenges in both operational and analytical aspects. For many, the objective is to create a list of master data to have a single view of the organization.

    Multiple-instance ERP or multinational organizations

    Multiple-instance ERP solutions are commonly used by businesses that operate globally to accommodate each country’s needs or financial systems (Brightwork Research). With MDM, having a single source of truth could be a great advantage in certain business units to collaborate globally, such as sharing inventory coding systems to allow common identity and productive resource allocation and shared customer information for analytical purposes.

    Common business operating models or strategies with master data problems (cont.)

    Multiple product lines of business

    An example for firms that sells multiple product lines could be Nike’s multiple product lines including footwear, clothing, and equipment. Keeping track of many product lines is a constant challenge for organizations in terms of inventory management, vendor database, and a tracking system. The ability to track and maintain your product data accurately and consistently is crucial for a successful supply chain (whether in a warehouse, distribution center, or retail office), which leads to improved customer satisfaction and increased sales.

    Info-Tech Insight
    A master data management solution will assist you in solving master data challenges if your organization is large or complex such as a multinational corporation or a company with multiple product lines, frequent mergers and acquisitions, or adopting a digital transformation strategy such as omnichannel.

    Omni-channel

    In e-commerce and retail industry, omnichannel means a business strategy that offers seamless shopping experiences across all channels, such as in-store, mobile, and online (Oracle). This also means the company needs to provide consistent information on orders, inventory, pricing, and promotions to customers and keep the customer records up to date. The challenges of omnichannel include having to synchronize data across channels and systems such as ERP, CRM, and social media. MDM becomes a solution for the success of an omnichannel strategy that refers to the same source of truth across business functions and channels.

    Assess business model using Info-Tech’s MDM Readiness Assessment Tool

    30 Minutes

    • The MDM Readiness Assessment Tool will help you make the decision to stop the MDM project now or to continue on the path to MDM.
    • Not all organizations need MDM. Don’t waste precious IT time and resources if your organization does not have a master data problem.

    The image contains screenshots of the MDM Readiness Assessment Tool.

    Download the MDM Readiness Assessment Tool

    Input Output
    • List of key MDM decision points
    • MDM readiness
    Materials Participants
    • Master Data Management Readiness Assessment Tool
    • Head of Information Management
    • CIO, CDO, or IT Executive

    Step 1.2

    Identify the Master Data Domains

    Objectives

    Determine which data domain contains the most critical master data in the organization for an MDM strategy.

    This step involves the following participants:

    Business Domain Representatives

    Data Stewards or Data Owners

    Information Management Team

    Outcomes of this step

    Determine the ideal data domain target for the organization based on where the business is experiencing the largest pains related to master data and where it will see the most benefit from MDM.

    Reference data makes tackling master data easier

    Reference data serves as a great starting place for an MDM project.

    • Reference data is the simple lists of data that are typically static and help categorize other data using code tables. Examples include lists of countries or states, postal codes, general ledger charts of accounts, currencies, or product codes.
    • Loading information into the warehouse or an MDM hub usually requires reconciling reference data from multiple sources. By getting reference data in order first, MDM will be easier to implement.
    • Reference data also requires a relatively small investment with good returns so the value of the project can easily be demonstrated to stakeholders.
    • One example of how reference data makes master data easier to tackle is a master list of an organization’s customers that needs an attribute of an address. By maintaining a list of postal codes or cities as reference data, this is made much easier to manage than simply allowing free text.

    Info-Tech Insight

    Organizations often have trouble getting started because of the difficulty of agreeing on the definition of master data within the enterprise. Reference data is an easy place to find that common ground.

    There are several key considerations when defining which data is master data in the organization

    A successful implementation of MDM depends on the careful selection of the data element to be mastered. As departments often have different interests, establishing a standard set of data elements can lead to a lot of discussion. When selecting what data should be considered master data, consider the following:

    • Complexity. As the number of elements in a set increases, the likelihood that the data is master data also increases.
    • Volatility. Master data tends to be less volatile. The more volatile data is, the more likely it is transactional data.
    • Risk. The more likely data may have a risk associated with it, the more likely it should be managed with MDM.
    • Value. The more valuable a data set is to the organization, the greater the chance it is master data.
    • Sharing. If the data set is used in multiple systems, it likely should be managed with an MDM system.

    Begin by documenting the existing data sources within the organization.

    Use Info-Tech’s Master Data Management Business Needs Assessment Tool to determine master data sources.

    Info-Tech Insight

    While the organization may have data that fits into more than one master data domain, it does not necessarily need to be mastered. Determine what master data entities your organization needs.

    Master data also fall into these four areas

    More perspectives to consider and define which data is your master data.

    Internally Created Entities

    Externally Created Entities

    Large Non-Recurring Transactions

    Categories/Relationships/ Hierarchies/Aggregational Patterns

    • Business objects and concepts at the core of organizational activities that are created and maintained only by this organization.
    • Examples: customers, suppliers, products, projects
    • Business objects and concepts at the core of organizational activities that are created outside of this organization, but it keeps its own master list of these entities with additional attributions.
    • Examples: equipment, materials, industry classifications
    • Factual records reflecting the organization’s activities.
    • Examples: large purchases, large sales, measuring equipment data, student academic performance
    • Lateral and hierarchical relationships across master entities.
    • Organization-wide standards for data / information organization and aggregation.
    • Examples: classifications of equipment and materials, legal relationships across legal entities, sales regions or sub-regions

    Master data types can be divided into four main domains

    Parties

    • Data about individuals, organizations, and the roles they play in business relationships.
    • In the commercial world this means customer, employee, vendor, partner, and competitor data.

    Product

    • Can focus on organization's internal products or services or the entire industry, including competitor products and services.
    • May include information about part/ingredient usage, versions, patch fixes, pricing, and bundles.

    Financial

    • Data about business units, cost centers, profit centers, general ledger accounts, budgets, projections, and projects
    • Typically, ERP systems serve as the central hub for this.

    Locations

    • Often seen as the domain that encompasses other domains. Typically includes geopolitical data such as sales territories.
    • Provides ability to track and share reference information about different geographies and create hierarchical relationships based on information.

    Single Domain vs. Multi-Domain

    • By focusing on a single master data domain, organizations can start with smaller, more manageable steps, rather than trying to tackle everything at once.
    • MDM solutions can be domain-specific or be designed to support multiple domains.
    • Multi-domain MDM is a solution that manages multiple types of master data in one repository. By implementing multi-domain from the beginning, an organization is better able to support growth across all dimensions and business units.

    Use Info-Tech’s Master Data Management Business Needs Assessment Tool to determine master data priorities

    2 hours

    Use the Master Data Management Business Needs Assessment Tool to assist you in determining the master data domains present in your organization and the suggested domain(s) for your MDM solution.

    The image contains screenshots of the Master Data Management Business Needs Assessment Tool.

    Download the MDM Business Needs Assessment Tool

    Input Output
    • Current data sources within the organization
    • Business requirements of master data
    • Prioritized list of master data domains
    • Project scope
    Materials Participants
    • Master Data Management Business Needs Assessment Tool
    • Data Stewards or Data Custodians
    • Information Management Team

    Step 1.3

    Create a Strategic Vision for Your MDM Program

    Objectives

    1. Understand the true goal of MDM – ensuring that the needs of the master data users in the organization are fulfilled.

    2. Create a plan to obtain organizational buy-in for the MDM initiative.

    3. Organize and officialize your project by documenting key metrics, responsibilities, and goals for MDM.

    This step involves the following participants:

    CEO, CDO, or CIO

    Business Domain Representatives

    Information Management Team

    Outcomes of this step

    Obtain business buy-in and direction for the MDM initiative.

    Create the critical foundation plans that will guide you in evaluating, planning, and implementing your immediate and long-term MDM goals.

    MDM is not just IT’s responsibility

    Make sure the whole organization is involved throughout the project.

    • Master data is created for the organization as a whole, so get business input to ensure IT decisions fit with corporate goals and objectives.
    • The ownership of master data is the responsibility of the business. IT is responsible for the MDM project’s technology, support, platforms, and infrastructure; however, the ownership of business rules and standards reside with the business.
    • MDM requires IT and the business to form a partnership. While IT is responsible for the technical component, the business will be key in identifying master data.
    • MDM belongs to the entire organization – not a specific department – and should be created with the needs of the whole organization in mind. As such, MDM needs to be aligned with company’s overall data strategy. Data strategy planning involves identifying and translating business objectives and capability goals into strategies for improving data usage by the business and enhancing the capabilities of MDM.

    Keep the priorities of the users of master data at the forefront of your MDM initiative.

    • To fully satisfy the needs of the users of master data, you have to know how the data is consumed. Information managers and architects must work with business teams to determine how organizational objectives are achieved by using master data.
    • Steps to understanding the users of master data and their needs:
    1. Identify and document the users of master data – some examples include business units such as marketing, sales, and innovation teams.
    2. Interview those identified to understand how their strategic goals can be enabled by MDM. Determine their needs and expectations.
    3. Determine how changes to the master data management strategy will bring about improvements to information sharing and increase the value of this critical asset.

    Info-Tech Insight

    Although it is easy to get distracted by the technical aspects of the MDM project – such as extraction and consolidation rules – the true goal of MDM is to make sure that the consumers of master data (such as business units, sales reps) have access to consistent, relevant, and trusted shared data.

    Interview business stakeholders to understand how IT’s implementation of MDM will enable better business decisions

    1 hours

    Instructions

    1. Identify which members of the business you would like to interview to gather an understanding of their current data issues and desired data usage. (Recommendation: Gather a diverse set of individuals to help build a broader and more holistic knowledge of data consumption wants or requirements.)
    2. Prepare your interview questions.
    3. Interview the identified members of the business.
    4. Debrief and document results.

    Tactical Tips

    • Include members of your team to help heighten their knowledge of the business.
    • Identify a team member to operate as the formal scribe.
    • Keep the discussion as free flowing as possible; it will likely enable the business to share more. Don’t get defensive – one of the goals of the interviews is to open communication lines and identify opportunities for change, not create tension between IT and the business.
    Input Output
    • Current master data pain points and issues
    • Desired master data usage
    • Prioritized list of master data management enablers
    • Understanding of organizational strategic plan
    Materials Participants
    • Interview questions
    • Whiteboard/flip charts
    • Information Management Team
    • Business Line Representatives

    Info-Tech Insight

    Prevent the interviews from being just a venue for the business to complain about data by opening the discussion of having them share current concerns and then focus the second half on what they would like to do with data and how they see master data assets supporting their strategic plans.

    Ensure buy-in for the MDM project by aligning the MDM vision and the drivers of the organization

    MDM exists to enable the success of the organization as a whole, not just as a technology venture. To be successful in the MDM initiative, IT must understand how MDM will help the critical aspects of the business. Likewise, the business must understand why it is important to them to ensure long-term support of the project.

    The image contains a screenshot example of the text above.

    “If an organization only wants to look at MDM as a tech project, it will likely be a failure. It takes a very strong business and IT partnership to make it happen.”

    – Julie Hunt, Software Industry Analyst, Hub Designs Magazine

    Use Info-Tech’s Master Data Management Business Case Presentation Template to help secure business buy-in

    1-2 hours

    The image contains screenshots of the Master Data Management Business Case Presentation Template.

    Objectives

    • This presentation should be used to help obtain momentum for the ongoing master data management initiative and continued IT- business collaboration.
    • Master data management and the state of processes around data can be a sensitive business topic. To overcome issues of resistance from the operational or strategic levels, create a well-crafted business case.
    Input Output
    • Business requirements
    • Goals of MDM
    • Pain points of inadequate MDM
    • Awareness built for MDM project
    • Target data domains
    • Project scope
    Materials Participants
    • Master Data Management Business Case Presentation Template
    • Data Stewards or Data Custodians
    • CEO, CDO, or CIO
    • Information Management Team

    Download the MDM Business Case Presentation Template

    Use Info-Tech’s project charter to support your team in organizing their master data management plans

    Use this master document to centralize the critical information regarding the objectives, staffing, timeline, budget, and expected outcome of the project.

    1. MDM Vision and Mission

    Overview

    Define the value proposition behind addressing master data strategies and developing the organization's master data management practice.

    Consider

    Why is this project critical for the business?

    Why should this project be done now, instead of delayed further down the road?

    2. Goals or Objectives

    Overview

    Your goals and objectives should be practical and measurable. Goals and objectives should be mapped back to the reasons for MDM that we identified in the Executive Brief.

    Example Objectives

    Align the organization’s IT and business capabilities in MDM to the requirements of the organization’s business processes and the data that supports it.

    3. Expected Outcomes

    Overview

    Master data management as a concept can change based on the organization and with definitions and expectations varying heavily for individuals. Ensure alignment at the outset of the project by outlining and attaining agreement on the expectations and expected outcomes (deliverables) of the project.

    Recommended Outcomes

    Outline of an action plan

    Documented data strategies

    4. Outline of Action Plan

    Overview

    Document the plans for your project in the associated sections of the project charter to align with the outcomes and deliverables associated with the project. Use the sample material in the charter and the “Develop Your Timeline for the MDM Project” section to support developing your project plans.

    Recommended Project Scope

    Align master data MDM plan with the business.

    Document current and future architectural state of MDM.

    Download the MDM Project Charter Template

    5. Identify the Resourcing Requirements

    Overview

    Create a project team that has representation of both IT and the business (this will help improve alignment and downstream implementation planning).

    Business Roles to Engage

    Data owners (for subject area data)

    Data stewards who are custodians of business data (related to subject areas evaluated)

    Data scientists or other power users who are heavy consumers of data

    IT Roles to Engage

    Data architect(s)

    Any data management professionals who are involved in modeling data, managing data assets, or supporting the systems in which the data resides.

    Database administrators or data warehousing architects with a deep knowledge of data operations.

    Individuals responsible for data governance.

    Phase 2: Build the MDM Practice and Platform

    Develop a Master Data Management Practice and Platform

    Step 2.1

    Document the Current Data State

    Objectives

    1. Understand roles that data strategy, data governance, and data architecture play in MDM.

    2. Document the organization’s current data state for MDM.

    This step involves the following participants:

    Data Stewards or Data Custodians

    Data or Enterprise Architect

    Information Management Team

    Outcomes of this step

    Document the organization’s current data state, understanding the business processes and movement of data across the company.

    Effective data governance will create the necessary roles and rules within the organization to support MDM

    • A major success factor for MDM falls under data governance. If you don’t establish data governance early on, be prepared to face major obstacles throughout your project. Governance includes data definitions, data standards, access rights, and quality rules and ensures that MDM continues to offer value.
    • Data governance involves an organizational committee or structure that defines the rules of how data is used and managed – rules around its quality, processes to remediate data errors, data sharing, managing data changes, and compliance with internal and external regulations.
    • What is required for governance of master data? Defined roles, including data stewards and data owners, that will be responsible for creating the definitions relevant to master data assets.

    The image contains a screenshot of the Data Governance Key to Data Enablement.

    For more information, see Info-Tech Research Group’s Establish Data Governance blueprint.

    Ensure MDM success by defining roles that represent the essential high-level aspects of MDM

    Regardless of the maturity of the organization or the type of MDM project being undertaken, all three representatives must be present and independent. Effective communication between them is also necessary.

    Technology Representative

    Governance Representative

    Business Representative

    Role ensures:

    • MDM technology requirements are defined.
    • MDM support is provided.
    • Infrastructure to support MDM is present.

    Role ensures:

    • MDM roles and responsibilities are clearly defined.
    • MDM standards are adhered to.

    Role ensures:

    • MDM business requirements are defined.
    • MDM business matching rules are defined.

    The following roles need to be created and maintained for effective MDM:

    Data Owners are accountable for:

    • Data created and consumed.
    • Ensuring adequate data risk management is in place.

    Data Stewards are responsible for:

    • The daily and routine care of all aspects of data systems.
    • Supporting the user community.
    • Collecting, collating, and evaluating issues and problems with data.
    • Managing standard business definitions and metadata for critical data elements.

    Another crucial aspect of implementing MDM governance is defining match rules for master data

    • Matching, merging, and linking data from multiple systems about the same item, person, group, etc. attempts to remove redundancy, improve data quality, and provide information that is more comprehensive.
    • Matching is performed by applying inference rules. Data cleansing tools and MDM applications often include matching engines used to match data.
      • Engines are dependent on clearly defined matching rules, including the acceptability of matches at different confidence levels.
    • Despite best efforts, match decisions sometimes prove to be incorrect. It is essential to maintain the history of matches so that matches can be undone when they are discovered to be incorrect.
    • Artificial intelligence (AI) for match and merge is also an option, where the AI engine can automatically identify duplicate master data records to create a golden record.

    Match-Merge Rules vs. Match-Link Rules

    Match-Merge Rules

    • Match records and merge the data from these records into a single, unified, reconciled, and comprehensive record. If rules apply across data sources, create a single unique and comprehensive record in each database.
    • Complex due to the need to identify so many possible circumstances, with different levels of confidence and trust placed on data values in different fields from different sources.
    • Challenges include the operational complexity of reconciling the data and the cost of reversing the operation if there is a false merge.

    Match-Link Rules

    • Identify and cross-reference records that appear to relate to a master record without updating the content of the cross-referenced record.
    • Easier to implement and much easier to reverse.
    • Simple operation; acts on the cross-reference table and not the individual fields of the merged master data record, even though it may be more difficult to present comprehensive information from multiple records.

    Data architecture will assist in producing an effective data integration model for the technology underlying MDM

    Data quality is directly impacted by architecture.

    • With an MDM architecture, access, replication, and flow of data are controlled, which increases data quality and consistency.
    • Without an MDM architecture, master data occurs in application silos. This can cause redundant and inconsistent data.

    Before designing the MDM architecture, consider:

    • How the business is going to use the master data.
    • Architectural style (this is often dependent on the existing IT architecture, but generally, organizations starting with MDM find a hub architecture easiest to work with).
    • Where master data is entered, updated, and stored.
    • Whether transactions should be processed as batch or real-time.
    • What systems will contribute to the MDM system.
    • Implementation style. This will help ensure the necessary applications have access to the master data.

    “Having an architectural oversight and reference model is a very important step before implementing the MDM solutions.”

    – Selwyn Samuel, Director of Enterprise Architecture

    Document the organization’s data architecture to generate an accurate picture of the current data state

    2-3 hours

    Populate the template with your current organization's data components and the business flow that forms the architecture.

    Think about the source of master data and what other systems will contribute to the MDM system.

    The image contains a screenshot of the MDM Architecture Design Template.

    Input Output
    • Business process streamline
    • Current data state
    Materials Participants
    • MDM Architecture Design Template ArchiMate file
    • Enterprise Architect
    • Data Architect

    Download the MDM Architecture Design Template ArchiMate file

    Step 2.2

    Document the Target Data State

    Objectives

    1. Understand four implementation styles for MDM deployments.

    2. Document target MDM implementation systems.

    This step involves the following participants:

    Data Stewards or Data Custodians

    Data or Enterprise Architect

    Information Management Team

    Outcomes of this step

    Document the organization’s target architectural state surrounding MDM, identifying the specific MDM implementation style.

    How the organization’s data flows through IT systems is a convenient way to define your MDM state

    Understanding the data sources present in the organization and how the business organizes and uses this data is critical to implementing a successful MDM strategy.

    Operational MDM

    • As you manage data in an operational MDM system, the data gets integrated back into the systems that were the source of the data in the first place. The “best records” are created from a combination of data elements from systems that create relevant data (e.g. billing system, call center, reservation system) and then the data is sent back to the systems to update it to the best record. This includes both batch and real-time processing data.

    Analytical MDM

    • Generates “best records” the same way that operational MDM does. However, the data doesn’t go back to the systems that generated the data but rather to a repository for analytics, decision management, or reporting system purposes.

    Discovery of master data is the same for both approaches, but the end use is very different.

    The approaches are often combined by technologically mature organizations, but analytical MDM is generally more expensive due to increased complexity.

    Central to an MDM program is the implementation of an architectural framework

    Info-Tech Research Group’s Reference MDM Architecture uses a top-down approach.

    A top-down approach shows the interdependent relationship between layers – one layer of functionality uses services provided by the layers below, and in turn, provides services to the layers above.

    The image contains a screenshot of the Architectural Framework.

    Info-Tech Research Group’s Reference MDM Architecture can meet the unique needs of different organizations

    The image contains a screenshot of Info-Tech Research Group's Reference MDM Architecture.

    The MDM service layers that make up the hub are:

    • Virtual Registry. The virtual registry is used to create a virtual view of the master data (this layer is not necessary for every MDM implementation).
    • Interface Services. The interface services work directly with the transport method (e.g. Web Service, Pub/Sub, Batch/FTP).
    • Rules Management. The rules management layer manages business rules and match rules set by the organization.
    • Lifecycle Management. This layer is responsible for managing the master data lifecycle. This includes maintaining relationships across domains, modeling classification and hierarchies within the domains, helping with master data quality through profiling rules, deduplicating and merging data to create golden records, keeping authoring logs, etc.
    • Base Services. The base services are responsible for managing all data (master, history, metadata, and reference) in the MDM hub.
    • Security. Security is the base layer and is responsible for protecting all layers of the MDM hub.

    An important architectural decision concerns where master data should live

    All MDM architectures will contain a system of entry, a system of record, and in most cases, a system of reference. Collectively, these systems identify where master data is authored and updated and which databases will serve as the authoritative source of master data records.

    System of Entry (SOE)

    System of Record (SOR)

    System of Reference (SORf)

    Any system that creates master data. It is the point in the IT architecture where one or more types of master data are entered. For example, an enterprise resource planning (ERP) application is used as a system of entry for information about business entities like products (product master data) and suppliers (supplier master data).

    The system designated as the authoritative data source for enterprise data. The true system of record is the system responsible for authoring and updating master data and this is normally the SOE. An ideal MDM system would contain and manage a single, up-to-date copy of all master data. This database would provide timely and accurate business information to be used by the relevant applications. In these cases, one or more SOE applications (e.g. customer relationship management or CRM) will be declared the SOR for certain types of data. The SOR can be made up of multiple physical subsystems.

    A replica of master data that can be synchronized with the SOR(s). It is updated regularly to resolve discrepancies between data sets, but will not always be completely up to date. Changes in the SOR are typically batched and then transmitted to the SORf. When a SORf is implemented, it acts as the authoritative source of enterprise data, given that it is updated and managed relative to the SOR. The SORf can only be used as a read-only source for data consumers.

    Central to an MDM program is the implementation of an architectural framework

    These styles are complementary and see increasing functionality; however, organizations do not need to start with consolidation.

    Consolidation

    Registry

    Coexistence

    Transactional

    What It Means

    The MDM is a system of reference (application systems serve as the systems of record). Data is created and stored in the applications and sent (generally in batch mode) to a centralized MDM system.

    The MDM is a system of reference. Master data is created and stored in the

    application systems, but key master data identifiers are linked with the MDM system, which allows a view of master data records to be assembled.

    The MDM is a system of reference. Master data is created and stored in application systems; however, an authoritative record of master data is also created (through matching) and stored in the MDM system.

    The MDM is a genuine source of record. All master data records are centrally authored and materialized in the MDM system.

    Use Case

    This style is ideal for:

    • Organizations that want to have access to master data for reporting.
    • Organizations that do not need real-time access to master data.

    This style is ideal for:

    • A view of key master data identifiers.
    • Near real-time master data reference.
    • Organizations that need access to key master data for operational systems.
    • Organizations facing strict data replication regulations.

    This style is ideal for:

    • A complete view of each master data entity.
    • Deployment of workflows for collaborative authoring.
    • A central reference system for master data.

    This style is ideal for:

    • Organizations that want true master data management.
    • Organizations that need complete, accurate, and consistent master data at all times.
    • Transactional access to master data records.
    • Tight control over master data.

    Method of Use

    Analytical

    Operational

    Analytical, operational, or collaborative

    Analytical, operational, or collaborative

    Consolidation implementation style

    Master data is created and stored in application systems and then placed in a centralized MDM hub that can be used for reference and reporting.

    The image contains a screenshot of the architectural framework and MDM hub.

    Advantages

    • Prepares master data for enterprise data warehouse and reporting by matching/merging.
    • Can serve as a basis for coexistence or transactional MDM.

    Disadvantages

    • Does not provide real-time reference because updates are sent to the MDM system in batch mode.
    • New data requirements will need to be managed at the system of entry.

    Registry implementation style

    Master data is created and stored in applications. Key identifiers are then linked to the MDM system and used as reference for operational systems.

    The image contains a screenshot of the architectural framework with a focus on registry implementation style.

    Advantages

    • Quick to deploy.
    • Can get a complete view of key master data identifiers when needed.
    • Data is always current since it is accessed from the source systems.

    Disadvantages

    • Depends on clean data at the source system level.
    • Can be complex to manage.
    • Except for the identifiers persisting in the MDM system, all master data records remain in the applications, which means there is not a complete view of all master data records.

    Coexistence implementation style

    Master data is created and stored in existing systems and then synced with the MDM system to create an authoritative record of master data.

    The image contains a screenshot of the architectural framework with a focus on the coexistence implementation style.

    Advantages

    • Easier to deploy workflows for collaborative authoring.
    • Creates a complete view for each master data record.
    • Increased master data quality.
    • Allows for data harmonization across systems.
    • Provides organizations with a central reference system.

    Disadvantages

    • Master data is altered in both the MDM system and source systems. Data may not be up to date until synchronization takes place.
    • Higher deployment costs because all master data records must be harmonized.

    Transactional implementation style

    All master data records are materialized in the MDM system, which provides the organization with a single, complete source of master data at all times.

    The image contains a screenshot of the architectural framework with a focus on the transactional implementation style.

    Advantages

    • Functions as a system of record, providing complete, consistent, accurate, and up-to-date data.
    • Provides a single location for updating and managing master data.

    Disadvantages

    • The implementation of this style may require changes to existing systems and business processes.
    • This implementation style comes with increased cost and complexity.

    All organizations are different; identify the architecture and implementation needs of your organization

    Architecture is not static – it must be able to adapt to changing business needs.

    • The implementation style an organization chooses is dependent on organizational factors such as the purpose of MDM and method of use.
    • Some master data domains may require that you start with one implementation style and later graduate to another style while retaining the existing data model, metadata, and matching rules. Select a starting implementation style that will best suit the organization.
    • Organizations with multi-domain master data may have to use multiple implementation styles. For example, data domain X may require the use of a registry implementation, while domain Y requires a coexistence implementation.

    Document your target data state surrounding MDM

    2-3 hours

    Populate the template with your target organization’s data architecture.

    Highlight new capabilities and components that MDM introduced based on MDM implementation style.

    The image contains a screenshot of the MDM Architecture Design Template.

    Input Output
    • Business process streamline
    • MDM architectural framework
    • Target data state
    Materials Participants
    • MDM Architecture Design Template ArchiMate File
    • Enterprise Architect
    • Data Architect
    • Head of Data

    Step 2.3

    Develop MDM Practice and Platform

    Objectives

    1. Review Info-Tech’s practice pattern and design your master data management practice.

    2. Design your master data management platform.

    3. Consider next steps for the MDM project.

    This step involves the following participants:

    Data Stewards or Data Custodians

    Data or Enterprise Architect

    Information Management Team

    Outcomes of this step

    Define the key services and outputs that must be delivered by establishing core capabilities, accountabilities, roles, and governance for the practice and platform.

    What does a master data management practice pattern look like?

    The master data management practice pattern describes the core capabilities, accountabilities, processes, and essential roles and the elements that provide oversight or governance of the practice, all of which are required to deliver on high-value services and deliverables or output for the organization.

    The image contains a screenshot to demonstrate the intentional relationships between the business and the master data.

    Download the Master Data Management Practice Pattern Template ArchiMate File

    Master data management data practice setup

    • Define the practice lead’s accountabilities and responsibilities.
    • Assign the practice lead.
    • Design the practice, defining the details of the practice (including the core capabilities, accountabilities, processes, and essential roles; the elements that provide oversight or governance of the practice; and the practice’s services and deliverables or output for the organization).
    • Define services and accountabilities:
    1. Define deployment and engagement model
    2. Define practice governance and metrics
    3. Define processes and deliverables
    4. Summarize capabilities
    5. Use activity slide to assign the skills to the role

    General approach to setting up data practices

    Guidelines for designing and establishing your various data practices.

    Understand master data management practice pattern

    A master data management practice pattern includes key services and outputs that must be delivered by establishing core capabilities, accountabilities, roles, and governance for the practice.

    Assumption:

    The accountabilities and responsibilities for the master data management practice have been established and assigned to a practice lead.

    1. Download and review Master Data Management Practice Pattern (Level 1 – Master Data Management Practice Pattern).
    2. Review and update master data management processes for your organization.

    Download the Master Data Management Practice Pattern Template ArchiMate File

    Info-Tech Insight

    An organization with heavy merger and acquisition activity poses a significant master data challenge. Prioritize your master data practice based on your organization’s ability to locate and maintain a single source of master data.

    The image contains a screenshot of the Master Data Management Process.

    Initiate your one-time master data management practice setup

    1. Ensure data governance committees are established.
    2. Align master data management working group responsibilities with data governance committee.
    3. Download and review Master Data Management Practice Pattern Setup (Level 1 – Master Data Management Practice Setup).
    4. Start establishing your master data practice:
    5. 4.1 Define services and accountabilities

      4.2 Define processes and deliverables by stakeholder

      4.3 Design practice operating model

      4.4 Perform skills inventory and design roles

      4.5 Determine practice governance and metrics

      4.6 Summarize practice capabilities

    6. Define key master data management deliverable and processes.

    The image contains a screenshot of the Process Template MDM Conflict Resolution.

    Download and Update:

    Process Template: MDM Conflict Resolution

    MDM operating model

    The operating model is a visualization of how MDM commonly operates and the value it brings to the organization. It illustrates the master data flow, which works from left to right, from source system to consumption layer. Another important component of the model is the business data glossary, which is part of your data governance plan, to define terminology and master data’s key characteristics across business units.

    The image contains a screenshot of the MDM Operating Model.

    Choosing the appropriate technology capabilities

    An MDM platform should include certain core technical capabilities:

    • Master data hub: Functions as a system of reference, providing an authoritative source of data in read-only format to systems downstream.
    • Data modeling: Ability to model complex relationships between internal application sources and other parties.
    • Workflow management: Ability to support flexible and comprehensive workflow-based capabilities.
    • Relationship and hierarchies: Ability to determine relationships and identify hierarchies within the same domain or across different domains of master data.
    • Information quality: Ability to profile, cleanse, match, link, identify, and reconcile master data in different data sources to create and maintain the “golden record.”
    • Loading, integration, synchronization: Ability to load data quality tools and integrate so there is a bidirectional flow of data. Enable data migration and updates that prevent duplicates within the incoming data and data found in the hub.
    • Security: Ability to control access of MDM and the ability to report on activities. Ability to configure and manage different rules and visibilities.
    • Ease of use: Including different user interfaces for technical and business roles.
    • Scalability and high performance/high availability: Ability to expand or shrink depending on the business needs and maintain a high service level.

    Other requirements may include:

    • MDM solution that can handle multiple domains on a single set of technology and hardware.
    • Offers a broad set of data integration connectors out of the box.
    • Offers flexible deployments (on-premises, cloud, as-a-service).
    • Supports all architectural implementation styles: registry, consolidation, coexistence, and transactional.
    • Data governance tools: workflow and business process management (BPM) functionality to link data governance with operational MDM.
    • Uses AI to automate MDM processes.

    Info-Tech Research Group’s MDM platform

    The image contains a screenshot of Info-Tech's MDM Platform.

    Info-Tech Research Group’s MDM platform summarizes an organization’s data environment and the technical capabilities that should be taken into consideration for your organization's MDM implementation.

    Design your master data management platform

    2-3 hours

    Instructions

    Download the Master Data Management Platform Template.

    The platform is not static. Adapt the template to your own needs based on your target data state, required technical capabilities, and business use cases.

    The image contains a screenshot of Info-Tech's MDM Platform.

    Input Output
    • Technology capabilities
    • Target data state
    • Master Data Management Platform
    Materials Participants
    • Master Data Management Platform Template
    • Data Architect
    • Enterprise Architect
    • Head of Data

    Download the MDM Platform Template

    Next steps for the MDM project

    There are several deployment options for MDM platforms; pick the one best suited to the organization’s business needs:

    On-Premises Solutions

    Cloud Solutions

    Hybrid Solutions

    Embrace the technology

    MDM has traditionally been an on-premises initiative. On-premises solutions have typically had different instances for various divisions. On-premises solutions offer interoperability and consistency.

    Many IT teams of larger companies prefer an on-premises implementation. They want to purchase a perpetual MDM software license, install it on hardware systems, configure and test the MDM software, and maintain it on an ongoing basis.

    Cloud MDM solutions can be application-specific or platform-specific, which involves using a software platform or web-based portal interface to connect internal and external data. Cloud is seen as a more cost-effective MDM solution as it doesn’t require a large IT staff to configure the system and can be paid for through a monthly subscription. Because many organizations are averse to storing their master data outside of their firewalls, some cloud MDM solutions manage the data where it resides (either software as a service or on-premises), rather than maintaining it in the cloud.

    MDM system resides both on premises and in the cloud. As many organizations have some applications on premises and others in the cloud, having a hybrid MDM solution is a realistic option for many. MDM can be leveraged from either on-premises or in the cloud solutions, depending on the current needs of the organization.

    • Vendor-supplied MDM solutions often provide complete technical functionality in the package and various deployment options.
    • Consider leverage Info-Tech’s SoftwareReviews to accelerate and improve your software selection process.

    Capitalizing on trends in the MDM technology space would increase your competitive edge

    AI improves master data management.

    • With MDM technology improving every year, there are a greater number of options to choose from than ever before. AI is one of the hottest trends in MDM.
    • By using machine learning (ML) techniques, AI can automate many activities surrounding MDM to ease manual processes and improve accuracy, such as automating master data profiling, managing workflow, identifying duplication, and suggesting match and merge proposals.
    • Some other powerful applications include product categorization and hierarchical management. The product is assigned to the correct level of the category hierarchy based on the probability that a block of words in a product title or description belongs to product categories (Informatica, 2021).

    Info-Tech Insight

    Leverage modern capabilities such as AI and ML to support large and complex MDM deployments.

    The image contains a screenshot of the AI Activities in MDM.

    Informatica, 2021

    Related Info-Tech Research

    Build Your Data Quality Program

    • Data needs to be good, but truly spectacular data may go unnoticed. Provide the right level of data quality, with the appropriate effort, for the correct usage. This blueprint will help you determine what “the right level of data quality” means and create a plan to achieve that goal for the business.

    Build a Data Architecture Roadmap

    • Optimizing data architecture requires a plan, not just a data model.

    Create a Data Management Roadmap

    • Streamline your data management program with our simplified framework.

    Related Info-Tech Research

    Build a Robust and Comprehensive Data Strategy

    • Formulate a data strategy that stitches all of the pieces together to better position you to unlock the value in your data.

    Build Your Data Practice and Platform

    • The true value of data comes from defining intentional relationships between the business and the data through a well-thought-out data platform and practice.

    Establish Data Governance

    • Establish data trust and accountability with strong governance.

    Research Authors and Contributors

    Authors:

    Name

    Position

    Company

    Ruyi Sun

    Research Specialist, Data & Analytics

    Info-Tech Research Group

    Rajesh Parab

    Research Director, Data & Analytics

    Info-Tech Research Group

    Contributors:

    Name

    Position

    Company

    Selwyn Samuel

    Director of Enterprise Architecture

    Furniture manufacturer

    Julie Hunt

    Consultant and Author

    Hub Designs Magazine and Julie Hunt Consulting

    David Loshin

    President

    Knowledge Integrity Inc.

    Igor Ikonnikov

    Principal Advisory Director

    Info-Tech Research Group

    Irina Sedenko

    Advisory Director

    Info-Tech Research Group

    Anu Ganesh

    Principal Research Director

    Info-Tech Research Group

    Wayne Cain

    Principal Advisory Director

    Info-Tech Research Group

    Reddy Doddipalli

    Senior Workshop Director

    Info-Tech Research Group

    Imad Jawadi

    Senior Manager, Consulting

    Info-Tech Research Group

    Andy Neill

    Associate Vice President

    Info-Tech Research Group

    Steve Wills

    Practice Lead

    Info-Tech Research Group

    Bibliography

    “DAMA Guide to the Data Management Body of Knowledge (DAMA-DMBOK Guide).” First Edition. DAMA International. 2009. Digital. April 2014.
    “State of the Connected Customer, Fifth Edition.” Salesforce, 2022. Accessed Jan. 2023.
    “The new digital edge: Rethinking strategy for the postpandemic era.” McKinsey & Company, 26 May. 2021. Assessed Dec. 2022.
    “Value and resilience through better risk management.” Mckinsey & Company, 1 Oct. 2018. Assessed Dec. 2022.
    “Plotting a course through turbulent times (9TH ANNUAL B2B SALES & MARKETING DATA REPORT)” Dun & Bradstreet, 2022. Assessed Jan. 2023.
    ““How to Win on Customer Experience.”, Deloitte Digital, 2020. Assessed Dec. 2022.
    “CX Trends 2022.”, Zendesk, 2022. Assessed Jan. 2023
    .”Global consumer trends to watch out for in 2023.” Qualtrics XM Institute, 8 Nov. 2022. Assessed Dec. 2022
    “How to Understand Single Versus Multiple Software Instances.” Brightwork Research & Analysis, 24 Mar. 2021. Assessed Dec. 2022
    “What is omnichannel?” Oracle. Assessed Dec. 2022
    “How AI Improves Master Data Management (MDM).” Informatica, 30 May. 2021. Assessed Dec. 2022

    Data Architecture

    • Buy Link or Shortcode: {j2store}17|cart{/j2store}
    • Related Products: {j2store}17|crosssells{/j2store}
    • member rating overall impact: 9.5/10
    • member rating average dollars saved: $30,159
    • member rating average days saved: 5
    • Parent Category Name: Data and Business Intelligence
    • Parent Category Link: /data-and-business-intelligence
    Enable the business to achieve operational excellence, client intimacy, and product leadership with an innovative, agile, and fit-for-purpose data architecture practice

    Implement Infrastructure Shared Services

    • Buy Link or Shortcode: {j2store}456|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Operations Management
    • Parent Category Link: /i-and-o-process-management
    • Organizations have service duplications for unique needs. These duplications increase business expenditure.
    • Lack of collaboration between business units to share their services increases business cost and reduces business units’ faith to implement shared services.
    • Transitioning infrastructure to shared services is challenging for many organizations. It requires an accurate planning and efficient communication between participating business units.

    Our Advice

    Critical Insight

    • Identify your current process, tool, and people capabilities before implementing shared services. Understand the financial compensations prior to implementation and assess if your organization is ready for transitioning to shared services model.
    • Do not implement shared services when the nature of the services differs greatly between business units.

    Impact and Result

    • Understand benefits of shared services for the business and determine whether transitioning to shared services would benefit the organization.
    • Identify the best implementation plan based on goals, needs, and services.
    • Build a shared-services process to manage the plan and ensure its success.

    Implement Infrastructure Shared Services Research & Tools

    Start here – Read the Executive Brief

    Read our concise Executive Brief to find out why you should implement shared services, review Info-Tech’s methodology, and understand the ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Conduct gap analysis

    Identify benefits of shared services to your organization and define implementation challenges.

    • Implement Infrastructure Shared Services – Phase 1: Conduct Gap Analysis
    • Shared Services Implementation Executive Presentation
    • Shared Services Implementation Business Case Template
    • Shared Services Implementation Assessment Tool

    2. Choose the right path

    Identify your process and staff capabilities and discover which services will be transitioned to shared services plan. It will also help you to figure out the best model to choose.

    • Implement Infrastructure Shared Services – Phase 2: Choose the Right Path
    • Sample Enterprise Services

    3. Plan the transition

    Discuss an actionable plan to implement shared services to track the project. Walk through a communication plan to document the goals, progress, and expectations with customer stakeholders.

    • Implement Infrastructure Shared Services – Phase 3: Plan the Transition
    • Shared Services Implementation Roadmap Tool
    • Shared Services Implementation Customer Communication Plan
    [infographic]

    Workshop: Implement Infrastructure Shared Services

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Identify Challenges

    The Purpose

    Establish the need for change.

    Key Benefits Achieved

    Set a clear understanding about benefits of shared services to your organization.

    Activities

    1.1 Identify your organization’s main drivers for using a shared services model.

    1.2 Define if it is beneficial to implement shared services.

    Outputs

    Shared services mission

    Shared services goals

    2 Assess Your Capabilities

    The Purpose

    Become aware of challenges to implement shared services and your capabilities for such transition.

    Key Benefits Achieved

    Discover the primary challenges for transitioning to shared services, eliminate resistance factors, and identify your business potentials for implementation.

    Activities

    2.1 Identify your organization’s resistance to implement shared services.

    2.2 Assess process and people capabilities.

    Outputs

    Shared Services Business Case

    Shared Services Assessment

    3 Define the Model

    The Purpose

    Determine the shared services model.

    Key Benefits Achieved

    Identify the core services to be shared and the best model that fits your organization.

    Activities

    3.1 Define core services that will be moved to shared services.

    3.2 Assess different models of shared services and pick the one that satisfies your goals and needs.

    Outputs

    List of services to be transferred to shared services

    Shared services model

    4 Implement and Communicate

    The Purpose

    Define and communicate the tasks to be delivered.

    Key Benefits Achieved

    Confidently approach key stakeholders to make the project a reality.

    Activities

    4.1 Define the roadmap for implementing shared services.

    4.2 Make a plan to communicate changes.

    Outputs

    List of initiatives to reach the target state, strategy risks, and their timelines

    Draft of a communication plan

    Achieve IT Spend & Staffing Transparency

    • IT spend has increased in volume and complexity, but how IT spend decisions are made has not kept pace.
    • In most organizations, technology has evolved faster than the business’ understanding of what it is, how it works, and what it can do for them.
    • How traditional financial accounting methods are applied to IT expenditure don’t align well to modern IT realities.
    • IT is often directed to make cuts when cost optimization and targeted investment are what’s really needed to sustain and grow the organization in the long term.

    Our Advice

    Critical Insight

    • Meaningful conversations about IT spend don’t happen nearly as frequently as they should. When they do happen, they are often inhibited by a lack of IT financial management (ITFM) maturity combined with the absence of a shared vocabulary between IT, the CFO, and other business function leaders.
    • Supporting data about actual technology spend taking place that would inform decision making is often scattered and incomplete.
    • Creating transparency in your IT financial data is essential to powering collaborative and informed technology spend decisions.

    Impact and Result

    • Understand the uses and benefits of making your IT spend more transparent.
    • Discover and organize your IT financial data.
    • Map your organization’s total technology spend against four IT stakeholder views: CFO, CIO, CXO, and CEO.
    • Gain vocabulary and facts that will help you tell the true story of IT spend.

    Members may also be interested in Info-Tech's IT Spend & Staffing Benchmarking Service.

    Achieve IT Spend & Staffing Transparency Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Achieve IT Spend & Staffing Transparency Deck – A detailed, do-it-yourself framework and process for clearly mapping your organization’s total technology spend.

    This deck mirrors Info-Tech’s own internal methods for delivering its IT Spend & Staffing Benchmarking Service in a do-it-yourself format. Based on Info-Tech’s proven ITFM Cost Model, it includes an IT spend mapping readiness assessment, expert advice for sourcing and organizing your financial data, a methodology for mapping IT staff and vendor spend according to four key stakeholder views (CFO, CIO, CXO, and CEO), and guidance on how to analyze and share your results.

    • Achieve IT Spend & Staffing Transparency Storyboard

    2. IT Spend & Staffing Transparency Workbook – A structured Excel tool that allows you to allocate your IT spend across four key stakeholder views and generate high-impact visualizations.

    This workbook offers a step-by-step approach for mapping and visualizing your organization’s true IT spend.

    • IT Spend & Staffing Transparency Workbook

    3. IT Spend & Staffing Transparency Executive Presentation Template – A PowerPoint template that helps you summarize and showcase key results from your IT spend transparency exercise.

    This presentation template offers a recommended structure for introducing key executive stakeholders to your organization’s true IT spending behavior and IT financial management as a whole.

    • IT Spend & Staffing Transparency Executive Presentation Template

    Infographic

    Further reading

    Achieve IT Spend & Staffing Transparency

    Lay a foundation for meaningful conversations with the business.

    Analyst Perspective

    Take the first step in your IT spend journey.

    Talking about money is hard. Talking to the CEO, CFO, and other business leaders about money is even harder, especially if IT is seen as just a cost center, is not understood by stakeholders, or is simply taken for granted. In times of economic hardship, already lean IT operations are tasked with becoming even leaner.

    When there's little fat to trim, making IT spend decisions without understanding the spend's origin, location, extent, and purpose can lead to mistakes that weaken, not strengthen, the organization.

    The first step in optimizing IT spend decisions is setting a baseline. This means having a comprehensive and transparent view of all technology spend, organization-wide. This baseline is the only way to have meaningful, data-driven conversations with stakeholders and approvers around what IT delivers to the business and the implications of making changes to IT funding.

    Before stepping forward in your IT financial management journey, know exactly where you're standing today.

    Jennifer Perrier, Principal Research Director, ITFM Practice

    Jennifer Perrier
    Principal Research Director, ITFM Practice
    Info-Tech Research Group

    Executive Summary

    Your Challenge Common Obstacles Info-Tech's Approach
    IT spend has increased in volume and complexity, but how IT spend decisions are made has not kept pace:
    • Technology has evolved faster than the business' understanding of what it is, how it works, and what it can do for them.
    • How traditional financial accounting methods are applied doesn't align well to modern IT realities.
    • IT is directed to make cuts when cost optimization and targeted investment are what's really needed to sustain and grow the organization in the long-term.
    Meaningful conversations about IT spend don't happen nearly as much as they should. This is often due to:
    • A lack of maturity in how ITFM (IT financial management) is executed within IT and across the organization as a whole.
    • The absence of a shared vocabulary between IT, the CFO, and other business function leaders.
    • Scattered and incomplete data about the actual technology spend taking place in the organization.
    Lay a foundation for meaningful conversations and informed decision-making around IT spend.
    • Understand the uses and benefits of making your IT spend more transparent.
    • Discover and organize your IT financial data.
    • Map your organization's total technology spend against four IT stakeholder views: CFO, CIO, CXO, and CEO.
    • Gain both vocabulary and facts that will help you tell the true story of IT spend.

    Info-Tech Insight
    Create transparency in your IT financial data to power both collaborative and informed technology spend decisions.

    IT spend has grown alongside IT complexity

    IT spend has grown alongside IT complexity

    Growth creates change ... and challenges

    IT has become more integral to business operations and achievement of strategic goals, driving complexity in how IT funds are allocated and managed.

    How IT funds are spent has changed
    Value demonstration is two-pronged. The first is return on performance investment, focused on formal and objective goals, metrics, and KPIs. The second is stakeholder satisfaction, a more subjective measure driven by IT-business alignment and relationship. IT leaders must do both well to prove and promote IT's value.
    Funding decision cadence has sped up
    Many organizations have moved from three- to five-year strategic planning cycles to one-year planning horizons or less, most noticeably since the 2008/2009 recession. Not only has the pace of technological change accelerated, but so too has volatility in the broader business and economic environments, forcing rapid response.
    Justification rigor around IT spend has increased
    The need for formal business cases, proposals, and participation in formal governance processes has increased, as has demand for financial transparency. With many IT departments still reporting into the CFO, there's no getting around it - today's IT leaders need to possess financial management savvy.
    Clearly showing business value has become priority
    IT spend has moved from the purchase of discrete hardware and software tools traditionally associated with IT to the need to address larger-scale issues around interoperability, integration, and virtualized cloud solutions. Today's focus is more on big-picture architecture than on day-to-day operations.

    ITFM capabilities haven't grown with IT spend

    IT still needs to prove itself.

    Increased integration with the core business has made it a priority for the head of IT to be well-versed in business language and practice, specifically in the areas of measurement and financial management.

    However, IT staff across all industries aren't very confident in how well IT is doing in managing its finances via three core processes:

    • Accounting of costs and budgets.
    • Optimizing costs to gain the best return on investment.
    • Demonstrating IT's value to the business.

    Recent data from 4,137 respondents to Info-Tech's IT Management & Governance Diagnostic shows that while most IT staff feel that these three financial management processes are important, notably fewer feel that IT management is effective at executing them.

    IT leadership's capabilities around fundamental cost data capture appear to be lagging, not to mention the essential value-added capabilities around optimizing costs and showing how IT contributes to business value.

    Graph of Cost and Budget Management

    Graph of Cost Optimization

    Questions for support transition

    Source: IT Management & Governance Diagnostic, Info-Tech Research Group, 2022.

    Take the perspective of key IT stakeholders as a first step in ITFM capability improvement

    Other business unit leaders need to deliver on their own specific and unique accountabilities. Create true IT spend transparency by accounting for these multiple perspectives.

    Exactly how is IT spending all that money we give them?
    Many IT costs, like back-end infrastructure and apps maintenance, can be invisible to the business.

    Why doesn't my department get more support from IT?
    Some business needs won't align with spend priorities, while others seem to take more than their fair share.

    Does the amount we spend on each IT service make sense?
    IT will get little done or fall short of meeting service level requirements without appropriate funding.

    I know what IT costs us, but what is it really worth?
    Questions about value arise as IT investment and spend increase. How to answer these questions is critical.

    At the end of the day, telling IT's spend story to the business is a significant challenge if you don't understand your audience, have a shared vocabulary, or use a repeatable framework.

    Mapping your IT spend against a reusable framework helps generate transparency

    A framework makes transparency possible by simplifying methods, creating common language, and reducing noise.

    However, the best methodological framework won't work if the materials and information plugged into it are weak. With IT spend, the materials and information are your staff and your vendor financial data. To achieve true transparency, inputs must have the following three characteristics:

    Availability Reliability Usability
    The data and information are up-to-date and accessible when needed. The data and information are accurate, complete, and verifiable. The data and information are clearly defined, consistently and predictably organized, consumable, and meaningful for decision-making.

    A framework is an organizing principle. When it comes to better understanding your IT spend, the things being organized by a framework are your method and your data.

    If your IT spend information is transparent, you have an excellent foundation for having the right conversations with the right people in order to make strategically impactful decisions.

    Info-Tech's approach enables meaningful dialogue with stakeholders about IT spend

    View of meaningful dialogue with stakeholders about IT spend

    Investing time in preparing and mapping your IT spend data enables better IT governance

    While other IT spend transparency methods exist, Info-Tech's is designed to be straightforward and tactical.

    Info-Tech method for IT spend transparency

    Put your data to work instead of being put to work by your data.

    Introducing Info-Tech's methodology for creating transparency on technology spend

    1. Know your objectives 2. Gather required data 3. Map your IT staff spend 4. Map your IT vendor spend 5. Identify implications for IT
    Phase Steps
    1. Review your business context
    2. Set IT staff and vendor spend transparency objectives
    3. Assess effort and readiness
    1. Collect IT staff spend data
    2. Collect IT vendor spend data
    3. Define industry-specific CXO Business View categories
    1. Categorize IT staff spend in each of the four views
    2. Validate
    1. Categorize IT vendor spend in each of the four views
    2. Validate
    1. Analyze your findings
    2. Craft your key messages
    3. Create an executive presentation
    Phase Outcomes Goals and scope for your IT spend and staffing transparency effort. Information and data required to perform the IT staff and vendor spend transparency initiative. A mapping of the allocation of IT staff spend across the four views of the Info-Tech ITFM Cost Model. A mapping of the allocation of IT vendor spend across the four views of the Info-Tech ITFM Cost Model. An analysis of your results and a presentation to aid your communication of findings with stakeholders.

    Insight Summary

    Overarching insight
    Take the perspective of key stakeholders and lay out your organization's complete IT spend footprint in terms they understand to enable meaningful conversations and start evolving your IT financial management capability.

    Phase 1 insight
    Your IT spend transparency efforts are only useful if you actually do something with the outcomes of those efforts. Be clear about where you want your IT transparency journey to take you.

    Phase 2 insight
    Your IT spend transparency efforts are only as good as the quality of your inputs. Take the time to properly source, clean, and organize your data.

    Phase 3 insight
    Map your IT staff spend data first. It involves work but is relatively straightforward. Practice your mapping approach here and carry forward your lessons learned.

    Phase 4 insight
    The importance of good, usable data will become apparent when mapping your IT vendor spend. Apply consistent and meaningful vendor labels to enable true aggregation and insight.

    Phase 5 insight
    Communicating your final IT spend transparency mapping with executive stakeholders is your opportunity to debut IT financial management as not just an IT issue but an organization-wide concern.

    Blueprint deliverables

    Each step of this blueprint is accompanied by supporting deliverables to help you accomplish your goals.

    Use this tool in Phases 1-4

    IT Spend & Staffing Transparency Workbook

    Input your IT staff and vendor spend data to generate visual outputs for analysis and presentation in your communications.

    Key deliverable:

    IT Spend & Staffing Transparency Executive Presentation

    Create a showcase for your newly-transparent IT staff and vendor spend data and present it to key business stakeholders.

    Use this tool in Phase 5

    IT and business blueprint benefits

    IT Benefits Business Benefits
    • Gain insight into exactly where you're spending IT funds on hardware, software, service providers, and the workforce.
    • Understand how much it's costing IT to deliver specific IT services.
    • Illustrate differences in business consumption of IT spend.
    • Learn the ratio of spend allocated to innovation vs. growth vs. keeping the lights on (KTLO).
    • Develop a series of core IT spend metrics including IT spend as a percent of revenue, IT spend per organization employee, and IT spend per IT staff member.
    • Create a complete IT spend baseline to serve as a foundation for future benchmarking, cost optimization, and other forms of IT financial analysis.
    • Understand the relative allocation of IT spend across capital vs. operational expenditure.
    • See the degree to which IT differentially supports and enables organizational goals, strategies, and functions.
    • Have better data for informing the organization's IT spend allocation and prioritization decisions.
    • Gain better visibility into real-life IT spending behaviors, cadences, and patterns.
    • Identify potential areas of spend waste as well as underinvestment.
    • Understand the true value that IT brings to the business.

    Measure the value of this blueprint

    You will know that your IT spend and staffing transparency effort is succeeding when:

    • Your understanding of where technology funds are really being allocated is comprehensive.
    • You're having active and meaningful dialogue with key stakeholders about IT spend issues.
    • IT spend transparency is a permanent part of your IT financial management toolkit.

    In phase 1 of this blueprint, we will help you identify initiatives where you can leverage the outcomes of your IT spend and staffing transparency effort.

    In phases 2, 3, and 4, we will guide you through the process of mapping your IT staff and vendor spend data so you can generate your own IT spend metrics based on reliable sources and verifiable facts.

    Win #1: Knowing how to reliably source the financial data you need to make decisions.

    Win #2: Getting your IT spend data in an organized format that you can actually analyze.

    Win #3: Having a framework that puts IT spend in a language stakeholders understand.

    Win #4: Gaining a practical starting point to mature ITFM practices like cost optimization.

    Info-Tech offers various levels of support to best suit your needs

    DIY Toolkit Guided Implementation Workshop Consulting
    "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful." "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track." "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place." "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

    Diagnostics and consistent frameworks are used throughout all four options.

    Guided Implementation

    Info-Tech recommends the following calls in your Guided Implementation.

    Phase 1: Know your objectives Phase 2: Gather required data Phase 3: Map your IT staff spend Phase 4: Map your IT vendor spend Phase 5: Identify implications for IT
    Call #1: Discuss your IT spend and staffing transparency objectives and readiness. Call #2: Review spend and staffing data sources and identify data organization and cleanup needs. Call #3: Review your mapped IT staff spend and resolve lingering challenges. Call #4: Review your mapped IT vendor spend and resolve lingering challenges. Call #5: Analyze your mapping outputs for opportunities and devise next steps.

    A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

    A typical GI is between four to six calls over the course of two to three months.

    Want even more help with your IT spend transparency effort?

    Let us fast-track your IT spend journey.

    The path to IT financial management maturity starts with knowing exactly where your money is going. To streamline this effort, Info-Tech offers an IT Spend & Staffing Benchmarking service that provides full transparency into where your money is going without any heavy lifting on your part.

    This unique service features:

    • A client-proven approach to meet your IT spend transparency goals.
    • Vendor and staff spend mapping that reveals business consumption of IT.
    • Industry benchmarking to compare your spending and staffing to that of your peers.
    • Results in a fraction of the time with much less effort than going it alone.
    • Expert review of results and ongoing discussions with Info-Tech analysts.

    If you'd like Info-Tech to pave the way to IT spend transparency, contact your account manager for more information - we're happy to talk anytime.

    Phase 1

    Know Your Objectives

    This phase will walk you through the following activities:

    • Establish IT spend and staffing transparency uses and objectives
    • Assess your readiness to tackle IT spend and staffing transparency

    This phase involves the following participants:

    • Head of IT
    • IT financial lead
    • Other members of IT management

    Phase 1: Know your objectives

    Envision what transparency can do.

    You're at the very beginning of your IT spend transparency journey. In this phase you will:

    • Set your objectives for making your IT spend and staffing transparent.
    • Assess your readiness to tackle the exercise and gauge how much work you'll need to do in order to do it well.

    "I've heard this a lot lately from clients: 'I've got my hands on this data, but it's not structured in a way that will allow me to make any decisions about it. I have these journal entries and they have some accounting codes, GL descriptors, cost objects, and some vendors, but it's not enough detail to make any decisions about my services, my applications, my asset spend.'"
    - Angie Reynolds, Principal Research Director, ITFM Practice, Info-Tech Research Group

    Transparency positively enables both business outcomes and the practice of business ethics

    However, transparency's real superpower is in how it provides fact-based context.

    • More accurate and relevant data for decision-making.
    • Better managed and more impactful financial outcomes.
    • Increased inclusion of people in the decisions that affect them.
    • Clearer accountabilities for organizational efficiency and effectiveness goals.
    • Concrete proof that business priorities and decisions are being acted on and implemented.
    • Greater trust and respect between IT and the business.
    • Demonstration of integrity in how funds are being used.

    IT spend transparency efforts are only useful if you actually do something with the outputs

    Identify in advance how you plan to leverage IT spend transparency outcomes.

    CFO expense view

    • Demonstrate actual IT costs at the right level of granularity.
    • Update/change the categories finance uses to track IT spend.
    • Adjust the expected CapEx/OpEx ratio.

    CXO business view

    • Calculate consumption of IT resources by department.
    • Implement a showback/chargeback mechanism.
    • Change the funding conversation about proposed IT projects.

    CIO service view

    • Calculate the total cost to deliver a specific IT service.
    • Adjust the IT service spend-to-value ratio as per business priorities.
    • Rightsize IT service levels to reflect true value to the business.

    CEO innovation view

    • Formalize the organization's position on use of cloud/outsourcing.
    • Reduce the portion of spend dedicated to "keeping the lights on."
    • Develop a plan for boosting commitment to innovation investment.

    When determining your end objectives, think about the real questions IT is being asked by the business and how IT spend transparency will help you answer them.

    CFO: Financial accounting perspective

    IT spend used to be looked at from a strictly financial accounting perspective - this is the view of the CFO and the finance department. Their question, "exactly how is IT spending all that money we give them," is really about how money is distributed across different asset classes. This question breaks down into other questions that IT leaders needs to ask themselves in order to provide answers:

    • How should I classify my IT costs? What are the standard categories you need to have that are meaningful to folks crunching the corporate numbers? If you're too detailed, it won't make sense to them. If you pick outmoded categories, you'll have to adjust in the future as IT evolves, which makes tracking year-over-year spend patterns harder.
    • What information should I include in my plans and reports? This is about two things. One is about communicating with the finance department in language that reduces back-and-forth and eliminates misinterpretation. The other is about aligning with the categories the finance department uses to track financial data in the general ledger.
    • How do I justify current spend? This is about clarity and transparency. Specifically itemizing spend into categories that are meaningful for your audience does a lot of justification work for you since you don't have to re-explain what everything means.
    • How do I justify a budget increase? In a declining economy, this question may not be appropriate. However, establishing a baseline puts you in a better position to discuss spend requirements based on past performance and to focus the conversation.

    Exactly how is IT spending all that money we give them?

    Example
    Asset Class % IT Spend
    Workforce 42.72%
    Software - Cloud 9.26%
    Software - On Prem 13.61%
    Hardware - Cloud 0.59%
    Hardware - On Prem 15.68%
    Contract Services 18.14%
    Info-Tech IT Spend & Staffing Studies, 2022.

    CIO: IT operations management perspective

    As the CIO role was adopted, IT spend was viewed from the IT operations management perspective. Optimizing the IT delivery model is a critical step to reducing time to provision services. For the IT leader, the questions they need to ask themselves are:

    • What's the impact of cloud adoption on speed of delivery? Leveraging a SaaS solution can reduce time to deployment as well as increase your ability to scale; however, integration with other functionality will still be a challenge that will incur costs.
    • Where can I improve spend efficiency? This is about optimizing spend in your IT delivery model. What service levels does the business require and what's the most cost-effective way to meet those levels without incurring significant technical debt?
    • Is my support model optimized? By reviewing where support staff are focused and which services are using most of your resources, you can investigate underlying drivers of your staffing requirements. If staff costs in support of a business function are high, perhaps the portfolio of applications needs to be reviewed.
    • How does our spend compare to others? Benchmarking against peers is a useful input, but reflects common practice, not best practice. For example, if you need to invest in IT security, your entire industry is lagging on this front, and you happen to be doing slightly better than most, then bringing forth this benchmark won't help you make the case. Starting with year-over-year internal benchmarking is essential - establish your categories, establish your baseline, and track it consistently.

    Does the amount we spend on each IT service make sense?

    Example
    Service Area % IT Spend
    App Development 9.06%
    App Maintenance 30.36%
    Hosting/Network 25.39%
    End User 18.59%
    Data & BI 3.58%
    Security & Risk 5.21%
    IT Management 7.82%
    Info-Tech IT Spend & Staffing Studies, 2022.

    CXO: Business unit perspective

    As business requests have increased, so too has the importance of the business unit perspective. Each business function has a unique mandate to fulfill in the organization and also competes with other business functions for IT resources. By understanding business consumption of IT, organizations can bring transparency and drive a different dialog with their business partners. Every IT leader should find out the answers to these questions:

    • Which business units consume the most IT resources? By understanding consumption of IT by business function, IT organizations can clearly articulate which business units are getting the highest share of IT resources. This will bring much needed clarity when it comes to IT spend prioritization and investment.
    • Which business units are underserved by IT? By providing full transparency into where all IT spend is consumed, organizations can determine if certain business functions may need increased attention in an upcoming budget cycle. Knowing which levers to pull is critical in aligning IT activities with delivering business value.
    • How do I best communicate spend data internally? Different audiences need information presented to them differently. This is not just about the language - it's also about the frequency, format, and channel you use. Ask your audiences directly what methods of communication stand the best chance of you being seen and heard.
    • Where do I need better business sponsorship for IT projects? If a lot of IT spend is going toward one or two business units, the leaders of those units need to be active sponsors of IT projects and associated spend that will benefit all users.

    Why doesn't my business unit get more support from IT?

    Example
    Business Function % IT Spend
    HR Department 6.16%
    Finance Department 15.15%
    IT Department 10.69%
    Business Function 1 23.80%
    Business Function 2 10.20%
    Business Function 3 6.80%
    Business Function 4 27.20%
    Source: Info-Tech IT Spend & Staffing Studies, 2022.

    CEO: Strategic vs. operations perspective

    With a business view now available, evaluating IT spend from a strategic standpoint is critical. Simply put, how much is being spent keeping the lights on (KTLO) in the organization versus supporting business or organizational growth versus net-new business innovations? This view is not about what IT costs but rather how it is being prioritized to drive revenue, operating margin, or market share. Here are the questions IT leaders should be asking themselves along with the organization's executive leadership and the CEO:

    • Why is KTLO spend so high? This question is a good gauge of where the line is drawn between operations and strategy. Many IT departments want to reduce time spent on maintenance and redeploy resource investment toward strategic projects. This reallocation must include retiring or eliminating technologies to free up funds.
    • What should our operational spend priorities be? Maintenance and basic operations aren't going anywhere. The issue is what is necessary and what could be done more wisely. Are you throwing good money after bad on a high-maintenance legacy system?
    • Which projects and investments should we prioritize? The answer to this question should tightly align with business strategic goals and account for the lion's share of growth and innovation spend.
    • Are we spending enough on innovative initiatives? This is the ultimate dialogue between business partners, the CEO, and IT that needs to take place, yet often doesn't.

    I know what IT costs us, but what is it really worth?

    Example
    Focus Area % IT Spend
    KTLO 89.16%
    Grow 7.18%
    Innovate 3.66%
    Info-Tech IT Spend Studies, 2022.

    Be clear about where you want your IT spend transparency journey to take you in real life

    Transparent IT spend data will allow you to have conversations you couldn't have before. Consider this example of how telling an IT spend story could evolve.

    I want to ...
    Analyze the impact of the cloud on IT operating expenditure to update finance's expectations of a realistic IT CapEx/OpEx ratio now and into the future.

    To address the problem of ...

    • Many of our key software vendors have eliminated on-premises products and only offer software as an OpEx service.
    • Assumptions that modern IT solutions are largely on-premises and can be treated as capitalizable assets are out-of-date and don't reflect IT financial realities.

    And will use transparency to ...

    • Provide the CFO with specific, accurate, and annotated OpEx by product/service and vendor for all cloud-based and on-premises solutions.
    • Facilitate a realistic calculation of CapEx/OpEx distribution based on actuals, as well as let us develop defendable projections of OpEx into the future based on typical annual service fee increases and anticipated growth in the number of users/licenses.

    1.1 Establish ITFM objectives that leverage IT spend transparency

    Duration: One hour

    1. Consider the problems or issues commonly voiced by the business about IT, as well as your own ongoing challenges in communicating with stakeholders. Document these problems/issues as questions or statements as spoken by a person. To help structure your brainstorming, consider these general process domains and examples:
      1. Spend tracking and reporting. E.g. Why is IT's OpEx so high? We need you to increase IT's percentage of CapEx.
      2. Service levels and business continuity. E.g. Why do we need to hire more service desk staff? There are more of them in IT than any other role.
      3. Project and operations resourcing. E.g. Why can't IT just buy this new app we want? It's not very expensive.
      4. Strategy and innovation. E.g. Did output increase or decrease last quarter per input unit? IT should be able to run those reports for us.
    2. For each problem/issue noted, identify:
      1. The source(s) of the question/concern (e.g. CEO, CFO, CXO, CIO).
      2. The financial process involved (e.g. accurate costing, verification of costs, building a business case to invest).
    3. For each problem/issue, identify a broader project-style initiative where having transparent IT spend data is a valuable input. One initiative may apply to multiple problems/issues. For each initiative:
      1. Give it a working title.
      2. State the goal for the initiative with reference to ITFM aspirations.
      3. Identify key stakeholders (these will likely overlap with the problem/issue source).
      4. Set general time frames for resolution.

    Document your outputs on the slide immediately following the instruction slides for this exercise. Examples are included.

    1.1 Establish ITFM objectives that leverage IT spend transparency

    Input Output
    • Organizational knowledge
    • List of the potential uses and objectives of transparent IT spend and staffing data
    Materials Participants
    • Whiteboard/flip charts
    • Head of IT
    • IT financial lead

    ITFM initiatives that leverage transparency

    Problem/Issue Statement Source/ Stakeholder Associated ITFM Process Potential Initiative Initiative Goal Time Frame
    "Why is IT's OpEx so high? We need you to increase IT's percentage of CapEx." CFO IT spend categorization and reporting. Analyze the impact of the cloud on IT operating expenditure. To update finance's expectations of a realistic IT CapEx/OpEx ratio. <12 months
    "Why do we need to hire more service desk staff? There are more of them in IT than any other role." CFO, VP of HR Business case for hiring IT staff. Document ongoing IT support requirements for proposed ERP platform migration project. To ensure sufficient resources for an anticipated increase in service desk tickets due to implementation of a new ERP system. 1-3 months
    "Why can't IT just buy this new app we want? It's not very expensive." CEO, all CXOs/VPs Total cost of technology ownership. Develop a mechanism to review the lifecycle impact on IT of proposed technology purchases. To determine if functionality of new tool already exists in the org. and the total cost of ownership of a new app. <6 months
    "Did output increase or decrease last quarter per input unit? IT should be able to run those reports for us." CEO, CFO, VP of Production IT service costing. Develop an organizational business intelligence strategy. To create a comprehensive plan for evolving BI capability in the organization and transferring report development to users. Select a department for pilot. <12 months

    Your organization's governance culture will affect how you approach transparency

    Know your governance culture Lower Governance
    • Few regulations.
    • Financial reporting is largely internal.
    • Change is frequent and rapid.
    • Informal or nonexistent mechanisms and structures.
    • Data sharing behavior driven by competitive concerns.
    Higher Governance
    • Many regulations.
    • Stringent and regular external reporting requirements.
    • Change is limited and/or slow.
    • Defined and established mechanisms and structures.
    • Data sharing behavior driven by regulatory concerns.
    Determine impact on opportunities How does your governance culture impact IT spend transparency opportunities?
    Resistance to formality and bureaucracy Resistance to change and uncertainty
    Set expectations and approach You have plenty of room to implement transparency rigor within the confines of IT, but getting others to give you the time and attention you want will be a challenge. One-on-one, informal relationship building to create goodwill and dialogue is needed before putting forth recommendations or numbers. Many existing procedures must be accommodated and respected. While you can benefit by working with preexisting mechanisms and touchpoints, expect any changes you want to make to things like IT cost categories or CapEx/OpEx ratios to require a lot of time, meetings, and case-making.

    IT's current maturity around ITFM practice will also affect your approach to transparency

    Know your ITFM maturity level Lower ITFM Maturity
    • No/few formal policies, standards, or procedures exist.
    • There is little/no formal education or experience within IT around budget, costing, charging, or accounting practices.
    • Financial reporting is sporadic and inconsistent in its contents.
    • Business cases are rarely used in decision-making.
    • Financial data is neither reliable nor readily available.
    Higher ITFM Maturity
    • Formal policies, standards, and procedures are enforced organization-wide for all financial management activities.
    • Formally-trained accountants are embedded within IT.
    • Financial reporting is regular, scheduled, and defined.
    • Business cases are leveraged in most decision-making activities.
    • Financial data is governed, centralized, and current.
    Determine stakeholders' financial literacy How does your degree of ITFM maturity impact IT spend transparency opportunities?
    Improve your own financial literacy first Determine stakeholders' financial literacy
    Set expectations and approach Brush up on core financial management and accounting concepts before taking the discussion beyond IT's walls. Do start mapping your costs, but just know how to communicate what the data is saying before sharing it. Not everyone will be at your level, familiar with ITFM language and concepts, or focused on the same things you are. Gauge where your audience is at so you can prepare for meaningful dialogue.

    1.2 Assess your readiness to tackle IT spend transparency

    Duration: One hour

    Note: This assessment is general in nature. It's intended to help you identify and prepare for potential challenges in your IT spend and staffing transparency effort.

    1. Rate your agreement with the "Data & Information" and "Experience, Expertise, & Support" statements listed on the slide immediately following the two instruction slides for this exercise. For each statement, indicate the extent to which you agree or disagree, where:
      1. 1 = Strongly disagree
      2. 2 = Disagree
      3. 3 = Neither agree nor disagree
      4. 4 = Agree
      5. 5 = Strongly agree
    2. Add up your numerical scores for all statements, where the highest possible score is 65.
    3. Assess your general readiness against the following guidelines:
      1. 50-65: Ready. The transparency exercise will involve work, but should be straightforward since you have the data, skills, tools, processes, and support to do it.
      2. 40-49: Ready, with caveats. The transparency exercise is doable but will require some preparatory legwork and investigation on your part around data sourcing, organization, and interpretation.
      3. 30-39: Challenged. The transparency exercise will present some obstacles. Expect to encounter data gaps, inconsistencies, errors, roadblocks, and frustrations that will need to be resolved.
      4. Less than 30: Not ready. You don't have the data, skills, tools, processes, and/or support to do the data transparency exercise. Take time to develop a stronger foundation of financial literacy and governance before tackling it.

    Document your outputs on the slide immediately following the two instruction slides for this exercise.

    1.2 Assess your readiness to tackle IT spend transparency

    InputOutput
    • Organizational knowledge
    • Estimation of IT spend and staffing transparency effort
    MaterialsParticipants
    • Whiteboard/flip charts
    • Head of IT
    • IT financial lead

    IT spend transparency readiness assessment

    Data & Information
    Statement Rating
    We know how to access all IT department spend records.
    We know how to access all non-IT-department technology spend records.
    We know how to access all IT vendor/contractor agreements.
    We know how to access data about our IT staff costs and allocation, such as organizational charts and salaries/benefits.
    Our financial and staffing data is up-to-date.
    Our financial and staffing data are labeled, described, and organized so that we know what they're referring to.
    Our financial and staffing data are in a format that we can easily manipulate (e.g. export, copy and paste, perform calculations).
    Experience, Expertise, & Support
    Statement Rating
    We have sufficient expertise within the IT department to navigate and accurately interpret financial records.
    We have reasonable access to expertise/resources in our finance department to support us in an IT spend transparency exercise.
    We can allocate sufficient time (about 40 hours) and resources in the near term to do an IT spend transparency exercise.
    We have current accountabilities to track and internally report financial information to others on at least a monthly basis.
    There are existing financial policies, procedures, and standards in the organization with which we must closely adhere and comply.
    We have had the experience of participating in, or responding to the results of, an internal or external audit.

    Rating scale:
    1 = Strongly Disagree; 2 = Disagree; 3 = Neither agree nor disagree; 4 = Agree; 5 = Strongly agree
    Assessment scale:
    Less than 30 = Not ready; 30-39 = Challenged; 40-49 = Ready with caveats; 50-65 = Ready

    Take a closer look at the statements you rated 1, 2, or 3. These will be areas of challenge no matter what your total score on the assessment scale.

    Phase 1: Know your objectives

    Achievement summary

    You've now completed the first two steps on your IT spend transparency journey. You have:

    • Set your objectives for making your IT spend and staffing transparent.
    • Assessed your readiness to tackle the exercise and know how much work you'll need to do in order to do it well.

    "Mapping to a transparency model is labor intensive. You can do it once and never revisit it again, but we would never advise that. What it does is play well into an IT financial management maturity roadmap."
    - Monica Braun, Research Director, ITFM Practice, Info-Tech Research Group

    Phase 2

    Gather Required Data

    This phase will walk you through the following activities:

    • Gather, clean, and organize your data
    • Build your industry-specific business views

    This phase involves the following participants:

    • Head of IT
    • IT financial lead
    • Other members of IT management

    Phase 2: Gather required data

    Finish your preparation.

    You're now ready to do the final preparation for your IT spend and staffing transparency journey. In this phase you will:

    • Gather your IT spend and staffing data and information.
    • Clean and organize your data to streamline mapping.
    • Identify your baseline data points.

    "Some feel like they don't have all the data, so they give up. Don't. Every data point counts."
    - Rex Ding, Research Specialist, ITFM Practice, Info-Tech Research Group

    Your IT spend transparency efforts are only as good as the quality of your inputs

    Aim for a comprehensive, complete, and accurate set of data and information.

    Diagram of comprehensive, complete, and accurate set of data and information

    Start by understanding what's included in technology spend

    Info-Tech's ITFM Technology Inventory

    In scope:

    • All network, telecom, and data center equipment.
    • All end-user productivity software and devices (e.g. laptops, peripheral devices, cell phones).
    • Information security.
    • All acquisition, development, maintenance, and management of business and operations software.
    • All systems used for the storage and management of business assets, data, records, and information.
    • All managed IT services.
    • Third-party consulting services.
    • All identifiable spend from the business for the above.

    Expand your thinking: Total tech spend goes beyond what's under IT's operational umbrella

    "Technology" means all technology in the organization regardless of where it lives, who bought it, who owns it, who runs it, or who uses it.

    IT may have low or no visibility into technologies that exist in the broader business environment beyond IT. Accept that you won't gain 100% visibility right now. However, do get started and be persistent.

    Where to look for non-IT technology ...

    • Highly specialized business functions - niche tools that are probably used by only a few people.
    • Power users and the "underserved" - cloud-based workflow, communication, and productivity tools they got on their own.
    • Operational technology - network-connected industrial, building, or physical security sensors and control systems.
    • Recently acquired/merged entities - inherited software.

    Who might get you what you need ...

    • Business unit and team leaders - identification of what they use and copies of their spend records and/or contracts.
    • Finance - a report of the "software" expenditure category to spot unrecognized technologies and their owners.
    • Vendors - copies of contracts if not forthcoming internally.
    • Your service desk - informal knowledge gained about unknown technologies at play in the course of doing their job.

    The IT spend and staffing transparency exercise is an opportunity to kick-start a technology discovery process that will give you and the business a true picture of your technology profile, use, and spend.

    Seek out data at the right level of granularity with the right supporting information

    Key data and information to seek out:

    • Credits applied to appropriate debits that show net expense, or detailed descriptions of credits with no matching debit.
    • Cash-based accounting (not accrual accounting). If accrual, will need to determine how to simplify the data for your uses.
    • Vendor names, asset classes, descriptors, and departments.
    • A total spend amount (CapEx + OpEx) that:
      • Aligns with the spend period.
      • Passes your gut check for total IT spend.
      • Includes annual amounts for multi-year contracts (e.g. one year of a three-year Microsoft enterprise agreement).
      • Includes technology spend from the business (e.g. OT that IT supports).
    • Insights on large projects.
    • Consolidated recurring payments, salaries and benefits, and other small expenses.

    Look for these data descriptors in your files:

    • Cost center/accounting unit
    • Cost center/department description
    • GL ACCT
    • CL account description
    • Activity description
    • Status
    • Program/business function/project description
    • Accounting period
    • Transaction amount
    • Vendor/vendor name
    • Product/product name

    Avoid data that's hard to use or problematic as it will slow you down and bring limited benefits

    Spend data that's out of scope:

    • Depreciation/amortization.
    • Gain or loss of asset write-off.
    • Physical security (e.g. key cards, cameras, motion sensors, floodlights).
    • Printer consumables costs.
    • Heating and cooling costs (for data centers).

    Challenging data formats:

    • Large raw data files with limited or no descriptors.
    • Major accounts (hardware and software) combined in the same line item.
    • Line items (especially software) with no vendor reference information.
    • PDF files or screenshots that you can't extract data from readily. Use Excel or CSV files whenever possible.

    Getting at the data you need can be easy or hard – it all depends

    This is where your governance culture and ITFM maturity start to come into play.

    Data source Potential data and information What to expect
    IT Current/past budget, vendor agreements, IT project records, discretionary spend, number of IT employees. The rigor of your ITFM practice and centralization of data and documents will affect how straightforward this is.
    Finance General ledger, cash and income statements, contractor payments and other accounts payable, general revenue. Secure their expertise early. Let them know what you're trying to do and what you need. They may be willing to prepare data for you in the format you need and help you decipher records.
    Purchasing List of vendors/suppliers, vendor agreements, purchase invoices. Purchasing often has more descriptive information about vendors than finance. They can also point you to tech spend in other departments that you didn't know about.
    Human Resources Organizational chart, staff salaries and benefits, number of employees overall and by department. Data about benefits costs is something you're not likely to have, and there's only one place you can reliably get it.
    Other Business Units Non-IT technology spend vendor agreements and purchase invoices, number of department employees. Other departments may be tracking spend in an entirely different way than you. Be prepared to dig and reconcile.

    There may be some data or information you can't get without a Herculean effort. Don't worry about it too much - these items are usually relatively minor and won't significantly affect the overall picture.

    Commit to finding out what you don't know

    Many IT leaders don't have visibility into other departments' technology spend. In some cases, the fact that spend is even happening may be a complete surprise.

    Near-term visibility fix ...

    • Ask your finance department for a report on all technology-related spend categories. "Software" is a broad category that finance departments tend to track. Scan the report for items that don't look familiar and confirm the originating department or approver.
    • Check in with the procurement office. See what technology-related contracts they have on record and which departments "own" them. Get copies of those contracts if possible.
    • Contact individual department heads or technology spend approvers. Devise your contact shortlist based on what you already know or learned from finance and procurement. Position your outreach as a discovery process that supports your transparency effort. Avoid coming across as though you're judging their spend or planning to take over their technologies.

    Long-term visibility fix ...

    • Develop your relationships with other business unit leaders. This will help open the lines of communication permanently.
    • Establish a cross-functional central technology office or group. The main task of this unit is to set and manage technology standards organization-wide, including standards for tracking and documenting technology costs and asset lifecycle factors.
    • Ensure IT is formally involved in all technology spend proposals and plans. This gives IT the opportunity to assess them for security compliance, IT network/system interoperability, manageability, and IT support requirements prior to purchase.
    • Ensure IT is notified of all technology financial transactions. This includes contracts, invoices, and payments for all one-time purchases, subscription fees, and maintenance costs.

    Finally, note any potential anomalies in the IT spend period you're looking at

    No two years have the exact same spend patterns. One-time spend for a big capital project, for example, can dramatically alter your overall spend landscape.

    Look for the following anomalies:

    • New or ongoing capital implementations or projects that span more than one fiscal year.
    • Completed projects that have recently transitioned, or are transitioning, from CapEx (decreasing) to OpEx (increasing).
    • A major internal reorganization or merger, acquisition, or divestiture event.
    • Crises, disasters, or other rare emergencies.
    • Changes in IT funding sources (e.g. new or expiring grants).

    These anomalies often explain why IT spend is unusually high in certain areas. There's often a good business reason.

    In many cases, doing a separate spend transparency exercise for these anomalous projects or events can isolate their costs from other spend so their true nature and impact can be better understood.

    2.1 Gather your input data and information

    Duration: Variable

    1. Develop a complete list of the spending and staffing data and information you need to complete the transparency mapping exercise. For each required item, note the following:
      1. Description of data needed (i.e. type, timeframe, and format).
      2. Ideal timeframe or deadline for receipt.
      3. Probable source(s) and contact(s).
      4. Additional facilitation/support required.
      5. Person on your transparency team responsible for obtaining it.
    2. Set up a data and information repository to store all files as soon as they're received. Ideally, you'll want all data/information files to be in an electronic format so that everything can be stored in one place. Avoid paper documents if possible.
    3. Conduct your outreach to obtain the input data and information on your list. This could include delegating it to a subordinate, sending emails, making phone calls, booking meetings, and so on.
    4. Review the data and information received to confirm that it's the right type of data, at the correct level of granularity, for the right timeframe, in a usable format, and is generally accurate.
    5. Enter documentation about your data and information sources in tab "1. Data & Information Sources" in the IT Spend & Staffing Transparency Workbook to reflect what you needed and where you got it in order to make the discovery process easier in the future.
    6. In the same tab in the IT Spend & Staffing Transparency Workbook, document any significant events that occurred that directly or indirectly impacted the selected year's spend values. These could include mergers/acquisitions/divestitures, major reorganizations or changes in leadership, significant shifts in product offerings or strategic direction, large capital projects, legal/regulatory changes, natural disasters, or changes in the economy.

    Download the IT Spend & Staffing Transparency Workbook

    2.1 Gather your input data and information

    InputOutput
    • Knowledge of potential data and information sources
    • List of data and information required to complete the IT spend and staffing transparency exercise
    MaterialsParticipants
    • Whiteboard/flip charts
    • Head of IT
    • IT financial lead

    Tidy up your data before beginning any spend mapping

    Most organizations aren't immaculate in their tech spend documentation and tracking practices. This creates data rife with gaps that lives in hard-to-use formats.

    The more preparation you do to approach the "good data" intersection point in the diagram below, the easier your mapping effort will be and the more useful and insightful your final findings.

    Venn diagram of good data

    Make your data "un-unique" to reduce the number of line items and make it manageable

    There's a good chance that the IT spend data you've received is in the form of tens of thousands of unique line items. Use the checklist below to help you roll it up.

    Warning: Never overwrite your original data. Insert new columns/rows and put your alternate information in these instead.

    Step 1: Standardize vendor names

    • Start with known large vendors.
    • Select a standard name for the vendor.
    • Brainstorm possible variations on the vendor name, including abbreviations and shortforms.
    • Search for the vendor in your data and document the new standardized vendor name in the appropriate row.
    • Repeat the above for all vendors.
    • Sort the new vendor name column from A-Z. Look for instances where names remain unique or are missing entirely. Reconcile if needed and fill in missing data.

    Step 2: Consolidate vendor spend

    • Sort the new vendor name column from A-Z. Start with vendors that have the most line items.
    • Add together related spend items from a given vendor. Create a new row for the consolidated spend item and flag it as consolidated. Keep the following item types in separate rows:
      • Hardware vs. software spend for the same vendor.
      • Cloud vs. on-premises spend for the same vendor.
    • Repeat the above for all vendors.
    • Consider breaking out separate rows for overly consolidated line items that contain too many different types of IT spend.

    2.2 Clean and organize your data

    Duration: Variable

    1. Check to ensure that you have all data and information required to conduct the IT spend transparency exercise.
    2. Conduct an initial scan to assess the data's current state of hygiene and overall usability. Flag anything of concern and follow up with the data/information provider to fix or reconcile any issues.
    3. Normalize your data to make it easier to work with. This includes selecting data format standards and changing anything that doesn't conform to those standards. This includes items such as date conventions, currencies, and so on.
    4. Standardize product and vendor naming/references throughout to enable searching, sorting, and grouping. For example, Microsoft Office may be variably referred to as "Microsoft", "Office", "Office 365", and "Office365" throughout your data. Pick one descriptor for the product/vendor and replace all related references with that descriptor.
    5. Consolidate and aggregate your data. Ideally, the data you received from your sources has already been simplified; however, you may need to further organize it to reduce the number of individual line items to a more manageable number. The transparency exercise uses relatively high-level categories, so combine data sets and aggregate where feasible without losing appropriate granularity.
    6. Archive any original copies of files that have been modified or replaced with consolidated/aggregated versions for future reference if needed.

    2.2 Clean and organize your data

    InputOutput
    • Data and information files
    • A normalized set of data and information for completing the IT spend and staffing transparency exercise
    MaterialsParticipants
    • Whiteboard/flip charts
    • Head of IT
    • IT financial lead

    Select IT spend "buckets" for the CXO Business View as your final preparatory step

    Every organization has both industry-agnostic and industry-specific lines of business that are the direct beneficiaries of IT spend.

    Common shared business functions:

    • Human resources.
    • Finance and accounting.
    • Sales/customer service.
    • Marketing and advertising.
    • Legal services and regulatory compliance.
    • Information technology.

    It may seem odd to see IT on the business functions list since the purpose of this exercise is to map IT spend. For business view purposes, IT spend refers to what IT spends on itself to support its own internal operations.

    Examples of industry-specific functions:

    • Manufacturing: Product research and development; production operations; supply chain management.
    • Retail banking: Core banking services; loan, mortgage and credit services; investment and wealth management services.
    • Hospitals: Patient intake and admissions; patient diagnosis; patient treatment; patient recovery and ongoing care.
    • Insurance: Actuarial analysis; policy creation; underwriting; claims processing.

    See the Appendix of this blueprint for definitions of shared business functions plus sample industry-specific business view categories.

    Define your CXO Business View categories to set yourself up well for future ITFM analyses

    The CXO Business View buckets you set up today are tools you can and should reuse in your overall approach to ITFM governance. Spend some time to get them right.

    Stay high-level

    Getting too granular invites administrative headaches and overhead. Keep things high-level and general:

    • Limit the number of direct stakeholders represented: This will reduce communication overhead and ensure you're dealing only with people who have real decision-making authority.
    • Look to your org. chart: Note the departments or business units listed across the top of the chart that have one executive or top-ranking senior manager accountable for them. These business units often translate as-is into a tidy CXO Business View category.

    Limit your number of buckets

    Tracking IT spend across more than 8-10 shared and industry-specific business categories is impractical.

    • Simplify your options: Too many buckets gets confusing and invites time-wasting doubt.
    • Reduce future rework: Business structures will change, which means recategorizing spend data. Using a forklift is a lot easier than using tweezers.
    • Stick to major business units: Create separate "Business Other" and "Industry Other" catch-all categories to track IT spend for smaller functions that fall outside of major business unit structures.

    Stay high-level with the CXO Business View

    Be clear on what's in and what's out of your categories to keep everyone on the same page

    Clear lines of demarcation between CXO Business View categories reduce confusion, doubt, and wheel-reinvention when deciding where to allocate IT spend.

    Ensure clear boundaries

    Mutual exclusivity is key when defining categories in any taxonomical structure.

    • Avoid overlaps: Each high-level business function category should have few or no core function or process overlaps with another business function category. Aim for clear vertical separation.
    • Be encompassing: When defining a category, list all the business capabilities and sub-functions included in that category. For example, if defining the finance and accounting function, remember to specify its less obvious accountabilities, like enterprise asset management if appropriate.

    Identify exclusions

    Listing what's out can be just as informative and clarifying as listing what's in.

    • Beware odd bedfellows: Minor business groups are often tucked under a bigger organizational entity even though the two use different processes and technologies. Separate them if appropriate and state this exclusion in the bigger entity's definition.
    • Draw a line: If a process crosses business function categories, state which sub-steps are out of scope.
    • Document your decisions: This helps ensure you allocate IT spend the same way every time.

    Clear lines of demarcation between CXO Business View categories

    2.3 Build your industry-specific business views

    Duration: Two hours

    1. Confirm your list of high-level shared business services (human resources, finance and accounting, etc.) as provided in Info-Tech's IT Spend & Staffing Transparency Workbook. Rename them if needed to match the nomenclature used in your organization.
    2. Set and define your additional list of high-level, industry-specific business categories that are unique to or define your industry. See the slides immediately following this exercise for tips on developing these categories, as well as the appendix of this blueprint for some examples of industry-specific categories and definitions.
    3. Create "Business Other" and "Industry Other" categories to capture minor groups and activities supported by IT that fall beyond the major shared and industry-specific business functions you've shortlisted. Briefly note the business groups/activities that fall under these categories.
    4. Edit/enter your shared and industry-specific business function categories and their definitions on tab "2. Business View Definitions" in the IT Spend & Staffing Transparency Workbook.

    Download the IT Spend & Staffing Transparency Workbook

    2.3 Build your industry-specific business views

    InputOutput
    • Knowledge about your organization's structure and business functions/units
    • A list of major shared business functions and industry-specific business functions/capabilities that are defining of your industry
    MaterialsParticipants
    • Whiteboard/flip charts
    • Head of IT
    • IT financial lead

    Lock in key pieces of baseline data

    Calculating core IT spend metrics relies on a few key numbers. Settle these first based on known data before diving into detailed mapping.

    These baseline data will allow you to calculate high-level metrics like IT spend as a percent of revenue and year-over-year percent change in IT spend, as well as more granular metrics like IT staff spend per employee for a specific IT service.

    Baseline data checklist

    • IT spend analysis period (date range).
    • Currency used.
    • Organizational revenue.
    • Organizational OpEx.
    • Total current year IT spend.
    • Total current year IT CapEx and IT OpEx.
    • Total previous-year IT spend.
    • Total projected next-year IT spend.
    • Number of organizational employees.
    • Number of IT employees.

    You may have discovered some things you didn't know about during the mapping process. Revisit your baseline data when your mapping is complete and make adjustments where needed.

    2.4 Enter your baseline data

    Duration: One hour

    1. Navigate to tab "3. Baseline Data" in the IT Spend & Staffing Transparency Workbook. Using the data you've gathered, enter the following information to set your baseline data for future calculations:
      1. Your IT spend analysis date range. This can be concrete dates, a fiscal year abbreviation, etc.
      2. The currency you will be using throughout the workbook. It's important that all monetary values entered are in the same currency.
      3. Your organization's total revenue and total operating expenditure (OpEx) for the spend analysis data range you've specified. Revenue includes all sources of funding/income.
      4. Your total IT OpEx and total IT capital expenditure (CapEx). The workbook will add your OpEx and CapEx values for you to arrive at a total IT spend value.
      5. Total IT spend for the year prior to the current IT spend analysis date range, as well as anticipated total IT spend for the year following.
      6. Total IT staff spend (salaries, benefits, training, travel, and fees for employees and contractors in a staff augmentation role) for the spend analysis date range.
      7. The total number of organizational employees and total number of IT employees. These are typically full-time equivalent (FTE) values and include contractors in a staff augmentation role.
    2. Make note of any issues that have influenced the values you entered.

    Download the IT Spend & Staffing Transparency Workbook

    2.4 Enter your baseline data

    InputOutput
    • Cleaned and organized spend and staffing data and information
    • Finalized baseline data for deriving spend metrics
    MaterialsParticipants
    • IT Spend & Staffing Transparency Workbook
    • Head of IT
    • IT financial lead

    Phase 2: Gather required data

    Achievement summary

    You've now completed all preparation steps for your IT spend transparency journey. You have:

    • Gathered your IT spend and staffing data and information.
    • Cleaned and organized your data to streamline mapping.
    • Identified your baseline data points.

    "As an IT person, you're not speaking the same language at all as the accounting department. There's almost always a session of education that's required first."
    - Angie Reynolds, Principal Research Director, ITFM Practice, Info-Tech Research Group

    Phase 3

    Map Your IT Staff Spend

    This phase will walk you through the following activities:

    • Mapping your IT staff spend across the four views of the ITFM Cost Model
    • Validating your mapping

    This phase involves the following participants:

    • Head of IT
    • IT financial lead
    • Other members of IT management

    Phase 3: Map your IT staff spend

    Allocate your workforce costs across the four views.

    Now it's time to tackle the first part of your hands-on spend mapping effort, namely IT staff spend. In this phase you will:

    • Allocate your IT staff spend across the four views of the ITFM Cost Model.
    • Validate your mapping to ensure that it's accurate and complete.

    "We're working towards the truth. We know the answer, but it's how to get it. Take Data & BI. For some organizations, four FTEs is too many. Are these people really doing Data & BI? Look at the big picture and see if something's missing."
    - Rex Ding, Research Specialist, ITFM Practice, Info-Tech Research Group

    Staffing costs comprise a significant percent of OpEx

    Staffing is the first thing that comes to mind when it comes to spend. Intentionally bring it out of the shadows to promote constructive conversations.

    • Total staffing costs stand out from other IT spend line items. This is because they're comparatively large, often comprising 30-50% of total IT costs.
    • Standing out comes at a price. Staff costs are where business leadership looks first if they want cuts. If IT leadership doesn't bring forward ways to cut staffing costs as part of a broader cost-cutting mandate, it will be seen as ignorant of business priorities at best and outright insubordinate at worst.
    • Staffing costs as a percentage of total costs vary between IT functions. On the business side, there's a lack of understanding about what functions IT staff serve and support and the real-world costs of obtaining (and keeping) needed IT skills. For example, IT security staffing costs as a percentage of that service's total OpEx will likely be higher than service desk staff given the scarcity and higher market value of the former. Trimming 20% of IT staffing costs from the IT security function has much different implications than cutting 20% of service desk staffing costs.

    Staffing spend transparency can do a lot to change the conversation from one where the business thinks that IT management is just being self-protecting to one where they know that IT management is actually protecting the business.

    Demonstrating the legitimate reasons behind IT staff spend is critical in both rationalizing past and current spend decisions as well as informing future decisions.

    Info-Tech recommends that you map your IT staffing costs before all other IT costs

    Mapping your IT staffing spend first is a good idea because:

    • Staffing costs are usually documented more clearly, simply, and accurately than other IT costs.
    • Gathering all your IT staffing data is usually a one-stop shop (i.e. the HR department).
    • The comparative straightforwardness of mapping staff costs compared to other IT costs gives you the opportunity to:
      • Get familiar with the ITFM Cost Model views and categories.
      • Get the hang of the hands-on mapping process.
      • Determine the kinds of speed bumps and questions you'll encounter down the road when you tackle the more complicated mappings.

    "Some companies will say software developer. Others say application development specialist or engineer. What are these things? You have to have conversations ..."
    - Rex Ding, Research Specialist, ITFM Practice, Info-Tech Research Group

    Understand the CFO Expense View: "Workforce" categories defined

    For the staffing spend mapping exercise, we're defining the Workforce category here and will offer Vendor category definitions in the vendor spend mapping exercise later.

    Workforce: The total costs of employing labor in the IT organization. This includes all salary/wages, benefits, travel/training, dues and memberships, and contractor pay. Managed services expenses associated with an external service provider should be excluded from Workforce and included in Contract Services.

    Employee: A person employed by the IT organization on a permanent full-time or part-time basis. Costs include salary, benefits, training, travel and expenses, and professional dues and memberships. These relationships are managed under human resources and the bulk of spend transactions via payroll processes.

    Contractor: A person serving in a non-permanent staff augmentation role. These relationships are typically managed under procurement or finance and spend transactions handled via invoicing and accounts payable processes. Labor costs associated with an external service provider are excluded.

    CFO Expense View

    Mapping your IT staff across the CFO Expense View is relatively cut-and-dried

    The CFO Expense View is the most straightforward in terms of mapping IT staffing costs as it's made up of only two main categories: Workforce and Vendor.

    In the CFO Expense View, all IT spend on staffing is allocated to the Workforce bucket under either Employee or Contractor.

    What constitutes a Contractor can be confusing given increased use of long-term labor augmentation strategies, so being absolutely clear about this is imperative. For spend mapping purposes:

    • Any staff members under independent contract where individuals are paid directly by your organization as opposed to indirectly via a service provider (e.g. staffing firm) are considered Workforce > Contractor.
    • Any circumstances where you pay a third-party organization for labor is slotted under Vendor > Contract Services.

    CFO Expense View

    Understand the CIO Service View: Categories defined

    We've provided definitions for the major categories that require clarification.

    Applications Development: Purchase/development, testing, and deployment of application projects. Includes internally developed or packaged solutions.

    Applications Maintenance: Software maintenance fees or maintaining current application functionality along with minor enhancements.

    Hosting & Networks: Compute, storage, and network functionality for running/hosting applications and providing communications/connectivity for the organization.

    End User: Procurement, provision, management, and maintenance (break/fix) of end-user devices (desktop, laptops, tablets, peripherals, and phones) as well as purchase/support and use of productivity software on these devices. The IT service desk is included here as well.

    PPM & Projects: People, processes, and technologies dedicated to the management of IT projects and the IT project portfolio as a whole.

    Data & BI: Strategy and oversight of the technology used to support data warehousing, business intelligence, and analytics.

    IT Management: Senior IT leadership, IT finance, IT strategy and governance, enterprise architecture, process management, vendor management, talent management, and program and portfolio management oversight.

    Security: Information security strategy and oversight, practices, procedures, compliance, and risk mitigation to protect and prevent unauthorized access to organizational data and technology assets.

    CIO Service View

    Mapping your IT staff across the CIO Service View is a slightly harder exercise

    The complexity of mapping staff across this view depends on how your IT department is organized and the degree of role specialization vs. generalization.

    The CIO Service View mirrors how many IT departments are organized into teams or work groups. However, some partial percentage-based allocations are probably required, especially for smaller IT units with more generalized, cross-functional roles. For example:

    • A systems administrator's costs may need to be allocated 80% to Hosting & Networks and 20% to Security.
    • An app development team lead may spend about 40% of their time doing hands-on Development work and the other 60% on project management (i.e. PPM & Projects).

    Info-Tech has found that allocating staffing costs for Data & BI raises the most doubts as it can be very entangled with Applications and other spend. Do the best you can.

    Understand the CXO Expense View: Categories defined

    Expand shared services and industry function categories as suits your organization.

    Industry Functions: As listed and defined by you for your specific industry.

    Human Resources: IT staff and specific application functionality in support of organizational human resource management.

    Finance & Accounting: IT staff and specific application functionality in support of corporate finance and accounting.

    Shared Services Other: IT staff and specific application functionality in support of all other shared enterprise functions.

    Information Technology: IT staff and specific application functionality in support of IT performing its own internal IT operations functions.

    Industry Other: IT staff and specific application functionality in support of all other industry-specific functions.

    CXO Expense View

    Mapping your IT staff across the CXO Business View warrants the most time

    This view is probably the most difficult as many IT department roles are set up according to lines of IT service, not lines of business. Prepare to do a little math.

    The CXO Expense View also requires percentage-based splitting of role spend, but to a greater extent.

    • Start by mapping staff cost allocations for those roles that are at, or close to, 100% dedicated to a specific business function (if any).
    • For IT roles that support organization-wide or multi-department functions, knowing the percent of employees that work in each relevant business unit and parceling IT staff spend by those same percentages may be easiest. For example, a general systems administrator's costs could be allocated as 4% to HR, 2% to finance, 25% to sales, 20% to production operations, and so on based on the percentage of employees in each of the supported business units.

    Take a minute to figure out how you plan to map IT's indirect CXO Business View costs

    Direct IT costs are those that are dedicated to a specific business unit or user group, such a marketing campaign management app, specialized devices used by a specific subset of workers in the field, or a business analyst embedded full-time in a sales organization.

    VS

    Indirect IT costs are pretty much everything else that's shared broadly across the organization and can't be tied to just one stakeholder or user group, such as network infrastructure, the service desk, and office productivity apps. These costs must be fairly and evenly distributed.

    No indirect mapping method is perfect, but here's a suggestion:

    • Take the respective headcount of all business functions sharing the IT resource/service in question.
    • Calculate each business function's staff as a percentage of all organizational staff.
    • Use this same percent of staff to calculate and allocate a business function's indirect staff and indirect vendor costs.

    "There is always a conversation about indirect allocations. There's never been an organization I've heard of or worked for which has been able to allocate every technology cost directly to a business consumption or business unit."
    Monica Braun, ITFM Research Director, Info-Tech Research Group

    Example:

    • A company of 560 employees has six HR staff (about 1.1% of total staff).
    • Network admin staffing costs $143,000, so $1,573 (1.1%) would be allocated to HR.
    • Internet services cost $40,000, so $440 (1.1%) would be allocated to HR.

    Some indirect costs are shared by multiple business functions, but not all. In these cases, exclude non-participating business functions from the total number of organizational employees and re-calculate a new percent of staff for each participating business function.

    Know where you're most likely to encounter direct vs. indirect IT staffing costs

    Info-Tech has found that direct vs. indirect staffing spend is more commonly found in some areas than others. Use this insight to focus your work.

    Direct IT staffing spend

    Definition: Individuals or teams whose total time is formally dedicated to the support of one business unit/function.

    • Data & BI (direct to one non-IT unit)
    • IT Management (direct to IT)
      • Service planning & Architecture
      • Strategy & Governance
      • Financial Management
      • People & Resources

    Hybrid IT staffing spend

    Definition: Teams with a percent of time or entire FTEs formally dedicated to one business unit/function while the remainder of the time or team is generalized.

    • Applications
      • Applications Development
      • Applications Maintenance
    • IT Management
      • PPM & Projects

    Indirect IT staffing spend

    Definition: Individuals or teams whose total time is generalized to the support of multiple or all business units or functions.

    • Infrastructure
      • Hosting & Networks
      • End Users
    • Security

    Indirect staff spend only comes into play in the CXO Business View. Thoroughly map the CIO Service View first and leverage its outcomes to inform your allocations to individual business and industry functions.

    Understand the CEO Innovation View: Categories defined

    Be particularly clear on your understanding of the difference between business growth and business innovation.

    Business Innovation: IT spend/ activities focused on the development of new business capability, new products and services, and/or introduction of existing products/ services into new markets. It does not include expansion or update of existing capabilities.

    Business Growth: IT spend/activities focused on the expansion, scaling, or modernization of an existing business capability, product/service, or market. This is specifically related to growth within a current market.

    Keep the Lights On: IT spend/activities focused on keeping the organization running on a day-to-day basis. This includes all activities used to ensure the smooth operation of business functions and overall business continuity.

    CEO Innovation View

    Important Note

    Info-Tech analysts often skip mapping staff for the CEO Innovation View when delivering the IT Spend & Staffing Benchmarking Service.

    This is because, for many organizations, either most IT staff spend is allocated to Keep the Lights On or any IT staff allocation to Business Growth and Business Innovation activities is untracked, undocumented, and difficult to parse out.

    Mapping your IT staff across the CEO Innovation View is largely straightforward

    Clear divisions between CapEx and OpEx can be your friend when it comes to mapping this view. Focus your efforts on parsing growth vs. innovation.

    • The majority of IT staff costs are OpEx: And the majority of OpEx will land in the Keep the Lights On category. This is a comparatively simple mapping exercise. Know in advance that this will be the largest of the three buckets in the CEO Innovation View by a very wide margin, so don't be surprised if over 90% of IT staffing costs end up here.
    • Most of the remaining IT staff costs will be tied to capital projects and investments: This means that they will land in either Business Growth or Business Innovation, with the majority typically sitting under Business Growth. Again, don't be surprised if the Business Innovation category holds less than 3% of total IT staffing spend.

    Take your IT staff spend mapping to the next level with detailed time and headcount data

    Overlay a broader assessment of your IT staff

    Info-Tech's IT Staffing Assessment diagnostic can expand your view of what's really happening on the staffing front.

    • Learn your true distribution of IT staff across the same IT services listed in the ITFM Cost Model's CIO Service View.
    • Get other metrics such as degrees of seniority, manager span of control, and IT staff perception of their effectiveness.

    Take action

    1. Set it up: Contact your Info-Tech Account Manager and sign your team up to take the diagnostic.
    2. Assess the findings: Review the output report, specifically how your staff says they spend their time versus what your organization chart's been telling you.
    3. Apply the percentages: Use the FTE allocation percentages in the output report to guide how you distribute your staff spend across the CIO Service View.
    4. Expand your analysis: Use your staff's feedback around perceived aids and obstacles to effectiveness in order to inform and defend your recommendations and decisions on how IT funds should be spent.

    Consider these final tips for mapping your IT staffing costs before diving in

    Mapping your IT staffing costs definitely requires some work. However, knowing the common stumbling blocks and being systematic will yield the best results.

    Approach: Be efficient to be effective

    Start with what you know best: Map the CFO Expense View first to plug in information you already have. Next, map the CIO Service View since it's most aligned to your organization chart.

    Keep a list of questions: You'll need to seek clarifications. Note your questions, but don't reach out until you've done a first pass at the mapping - don't annoy people with a barrage of questions.

    Delegate: Your managers and leads have a more accurate view of exactly what their staff do. Consider delegating the CIO Service View and CXO Business View to them or turn the mapping exercise into a series of collaborative leadership team activities.

    Biggest challenge: Role/title ambiguity

    • The Business Analyst role is often vague. These staffers are often jacks-of-all-trades in IT. You probably can't rely on a generic job description to figure out exactly which services and business functions BAs are spending their time on. Plan to ask a lot of questions.
    • Other role titles may be completely inaccurate. Is the word "system" referring to apps, infrastructure, or both? Is the user experience specialist actually a programmer? Is a manager really managing anything? Know your organization's tendencies around meaningful job titling and set your workload expectations accordingly.

    Key step - validate! If you see services or functions with low or no allocation, or something just doesn't look right, investigate. Someone's doing that work - take the time to figure out who.

    3.1 Map your IT staffing costs

    Duration: Variable

    1. Navigate to tab "4. Staff Spend Mapping" in the IT Spend & Staffing Transparency Workbook. On one row, enter the name of an individual or group to be mapped, their role/title (if an individual), and their total known cost as per your collected data.
    2. Under the CFO Expense View (columns F-G), enter the number of FTEs represented by the individual or group named and their status (i.e. Employee or Contractor).
    3. Under the CIO Service View (columns L-AF), allocate the individual or group's spend as a percentage across all service categories. If the allocation for a service is 0%, leave the cell blank.
    4. Under the CXO Business View (columns AI-BA), allocate the individual or group's spend as a percentage across all business function and industry-specific function categories. If the allocation for a function is 0%, leave the cell blank.
    5. Under the CEO Innovation View (columns BD-BH), allocate the individual or group's spend as a percentage across Business Innovation, Business Growth, and Keep the Lights On. If the allocation for an investment type is 0%, leave the cell blank.
    6. Repeat steps 2 to 5 for all other IT staff (as individuals or groups).
    7. Follow up on and resolve any additional inquiries you need to make based on questions that arose during the mapping process.
    8. Validate your mapping by:
      1. Identifying spend categories that have zero staff spend allocation. Additional percentage allocation splits for certain roles are probably required.
      2. Investigating spend categories that seem to have very high or very low spend allocations based on a gut check. Again, double-check your percentage allocation splits.
      3. Ensuring your amounts add up to your previously calculated total IT staff spend. A balance tracker is provided on tab "6. Tracker & General Outputs" of the IT Spend & Staffing Transparency Workbook.

    Download the IT Spend & Staffing Transparency Workbook

    3.1 Map your staffing costs

    Input Output
    • Cleaned and organized IT staffing data and information
    • Finalized mapping of IT staff spend across the four views of the ITFM Cost Model
    Materials Participants
    • IT Spend & Staffing Transparency Workbook
    • Head of IT
    • IT financial lead
    • Other IT management as required

    Phase 3: Map your IT staff spend

    Achievement summary

    You've now completed your IT staff spend mapping. You have:

    • Allocated your IT staff spend across the four views of the ITFM Cost Model.
    • Validated your mapping to ensure it's accurate and complete.

    "Some want to allocate everybody to IT, but that's not how we do it. [In one CXO Business View mapping], a client allocated all their sand network people to the IT department. At the end of the process, the IT department itself accounted for 20% of total IT spend. We went back and reallocated those indirect staff costs across the business."
    - Kennedy Confurius, Research Analyst, ITFM Practice, Info-Tech Research Group

    Phase 4

    Map Your IT Vendor Spend

    This phase will walk you through the following activities:

    • Mapping your IT vendor spend across the four views of the ITFM Cost Model
    • Validating your mapping

    This phase involves the following participants:

    • Head of IT
    • IT financial lead
    • Other members of IT management

    Phase 4: Map your IT vendor spend

    Allocate your vendor costs across the four views.

    Now you're ready to take on the second part of your spend mapping, namely IT vendor spend. In this phase you will:

    • Allocate your IT vendor spend across the four views of the ITFM Cost Model.
    • Validate your mapping to ensure it's accurate and complete.

    "[One CIO] said that all technology spend runs through their IT group. But they didn't have hardware in their financial data file - no cellphones or laptops, no network or server expenses. They thought they had everything, but they didn't know what they didn't have. Assume it's out there somewhere."
    - Kennedy Confurius, Research Analyst, ITFM Practice, Info-Tech Research Group

    Tackle the non-staff side of IT spend

    Info-Tech analysts find that mapping the IT vendor spend data is harder because the source data is often scattered and not meaningfully labeled.

    • Be patient and systematic. As with mapping your IT staff spend data, the more organized you are from the outset and the more thoroughly you've prepared your data, the more straightforward the exercise will be.
      • Did you "un-unique" your data? If not, do that now before attempting mapping.
    • Get comfortable with making some assumptions. You need to get through the exercise, so sometimes making a best guess and entering a value is better than diving down a rabbit hole. Your gut is probably right anyway. But only make assumptions around smaller line items that don't have a massive impact on your final numbers. Never assume anything when it comes to big-ticket items.
    • Curb your urge to fix. Some of your buckets will start to get big, while others will barely budge. This is normal ... and interesting! Resist the urge to "balance" staffing spend in a bucket by loading it with apps and hardware for fear that the staffing spend looks too high and will be questioned. This exercise is about how things are, not how they look.

    "A common financial data problem is no vendor names. I've noticed that, even if the vendor name is there, there are no descriptors. You cannot actually tell what type of service it is. Data security? Infrastructure? Networking? Ask yourself 'What did we purchase and what does it do?'"
    - Aman Kumari, Research Specialist, ITFM Practice, Info-Tech Research Group

    Understand the CFO Expense View: Vendor categories defined

    These are the final definitions for this view. See the previous section for CFO Expense View > Workforce definitions used in the IT staffing cost mapping exercise.

    Vendor: Provider of a good or service in exchange for payment.

    Hardware: Costs of procuring, maintaining, and managing all IT hardware, including end-user devices, data center and networking equipment, cabling, and hybrid appliances for both on-premises and cloud-based providers.

    Software: Costs for all software (applications, database, middleware, utilities, tools) used across the organization. This includes purchase, maintenance, and licensing costs.

    Contract Services: Costs for all third-party services including managed service providers, consultants, and advisory services.

    Cloud: Offsite hosting and delivery of an on-demand software or hardware computing function by a third-party provider, often on a subscription-type basis.

    On-Prem: On-site hosting and delivery of a software or hardware computing function, often requiring upfront purchase cost and subsequent maintenance costs.

    Managed Services: Costs for outsourcing the provision and maintenance of a technical process or function.

    Consulting & Advisory: Costs for the third-party provision of professional or technical advice and expertise.

    CFO Expense View

    Know if a technology is cloud-based or on-premises before mapping

    A technology may be one, the other, or both if multiple versions are in play. Financial records rarely indicate which, but on-premises vs. cloud matters in your planning.

    On-Premises

    • Check your CapEx. Any net-new purchases of software or hardware for the IT spend analysis year in question should appear on the CapEx side of the equation. After the first year of implementation/rollout, all ongoing maintenance and management costs should be found under OpEx.
    • Focus on real in-year costs.
      • Don't try to map depreciation or amortization associated with CapEX. Instead, map any upfront purchase costs that occurred in the relevant IT spend analysis year.
      • Map any OpEX costs incurred from maintenance and management. For multi-year maintenance contracts, apply the percentage of fees paid for the relevant year.

    Cloud

    • Check your OpEx. Cloud services are typically fee-based, which means the costs often come in the form of regularly timed bills akin to a subscription.
    • Differentiate new services from older ones. If the cloud service was initiated during the IT spend analysis year in question, there may be some one-time service setup and initiation fees that were legitimately slotted under CapEx. If the cloud service isn't new, then all costs should be OpEx.

    Vendors are increasingly "retiring" on-premises software products. This means an older version may be on-prem, a newer one cloud, and you may have both in play.

    Mapping built-in data, analytics, and security functions can raise doubts

    With so many apps focused on capturing, manipulating, and protecting data, built-in analytics, reporting, and security functions blur CIO Service View bucket boundaries.

    Applications vs. Data & BI

    • In recent years, much more powerful analysis and report-generation features have been added to core enterprise applications. If analytics and reporting functionality is an extended feature of a database-driven application, such as ERP or CRM, then map it to one of the Applications buckets.
    • If the sole purpose of the application is to store, manipulate, query, analyze, and/or visualize data, then log its costs under Data & BI. These would include technologies such as data warehouses, marts, cubes, and lakes; desktop data visualization tools; enterprise business intelligence platforms; and specialized reporting tools.

    Applications vs. Security

    • A similar conundrum exists for Security. So many tools today have built-in security functionality that cannot be unintegrated from the app they support. Don't even try to isolate native security functionality for spend mapping purposes - map it to Applications.
    • If the tool is a special-purpose, standalone security tool or security platform, then map it to Security. These tools usually sit within, and are used/managed by, IT. They include firewalls; antivirus/anti-malware; intrusion prevention, detection and response; access control and authentication; encryption; and penetration testing and vulnerability assessment.

    Putting spend in the right bucket does matter. However, if uncertainty persists, err on the side of consistency. For most organizations Applications Maintenance does end up being the biggest bucket.

    When mapping the CXO Business View, do the biggest vendors first

    Below is a suggested order of operations to clear through the majority of vendor spend as early as possible in the process.

    1 Sort high to low Sort your list of vendor spend from highest to lowest. Your top 20 vendors should constitute most of the spend.
    2 Map multi-department enterprise apps Flag your top apps vendors that have presence in most or all of your business units. Map these first. These tend to be enterprise-level business apps "owned" by core business functions but used broadly across the organization such as enterprise resource planning (ERP), customer relationship management (CRM), and people management systems.
    3 Map end-user spend Identify top vendors of general end-user technologies like office productivity apps, desktop hardware, and IT service desk tools. Allocate percentages according to your selected indirect spend mapping method.
    4 Map core infrastructure spend Map the behind-the-scenes network, telecom, and data center technologies that underpin IT, plus any infrastructure managed services. Again, apply your selected indirect spend mapping method.
    5 Map business-unit specific technologies This is the spend that's often incurred by just one department. This may also be technology spend that's out in the business, not in IT proper. Map it to the right business function or put it in Business Other or Industry Other if the business function doesn't have its own bucket.
    6 Map the miscellaneous Only smaller spend items likely remain at this point. When in doubt, map them to either Business Other or Industry Other.

    After mapping the CXO Business View, your Other buckets might be getting a bit big

    It's common for the Business Other and Industry Other categories to be quite large, and even the largest. This is okay, but plan to dig deeper and understand why.

    Remember "when in doubt, map to either the Business Other or Industry Other category"? Know what large Other buckets might really be telling you. After your first pass at mapping the CXO Business View, review Business Other and Industry Other if either is more than about 10% of your total spend.
    Diversification: Your organization has a wide array of business functions and/or associated staff that exist outside the core business and industry-specific categories selected. Are there minor business functions that can reasonably be included with the core categories identified? If not, don't force it. Better to keep your core buckets clean and uncomplicated.
    Non-core monolith: There's a significant technology installation outside the core that's associated with a comparatively minor business function. Is there a business function incurring substantial technology spend that should probably be broken out on its own and added to the core? If so, do it. Spend is unlikely to get smaller as the organization grows, so best to shine a light on it now.
    Shadow IT: There's significant technology spend in several areas of the organization that is unowned, unmanaged, or serving an unknown purpose as far as IT is concerned. Is a lot of the spend non-IT technology in the business? If yes, flag it and plan to learn more. It's likely that technologies living elsewhere in the organization will become IT concerns eventually. Better to be ready than to be surprised.

    As with staffing, CapEx vs. OpEx helps map the CEO Innovation View

    Mapping to this view was optional for IT staffing. For hard technology vendor spend, mapping this view is key. Use the guidance below to determine what goes where.

    Keep the Lights On
    Spend usually triggered by a service deck ticket or work order, not a formal project. Includes:

    • Daily maintenance and management.
    • Repair or upgrade of existing technology to preserve business function/continuity.
    • Purchase of "commodity" technology, such as standard-issue laptops and licenses for office productivity software.

    Business Growth
    Spend usually in the context of a formal project under a CapEx umbrella. Includes:

    • Technology spend that directly supports business expansion of an existing product or service and/or market.
    • Modernizing existing technology.
    • Extension of, or investment in, existing infrastructure to ensure reliability and availability in response to growth-driven scaling of headcount and utilization.

    Business Innovation
    Spend is always in the context of a formal project and should be 100% CapEx in the first year after purchase. Includes:

    • Technology spend that directly supports development and rollout of new products or service and/or entry into new markets.
    • Use of existing technology or investment in net-new technology in direct support of a new business initiative, direction, or requirement.

    In many organizations, most technology spend will be allocated to Keep the Lights On. This is normal but should generate conversations with the business about redirecting funds to growth and innovation.

    Remember these top tips when mapping your technology vendor spend

    The benefits of having tidy and organized data can't be overstated, as your source data will be in a more varied state for this phase of the mapping than with IT staffing data.

    Approach: Move from macro to micro

    • Start with the big enterprise apps: These will probably be in the top five of your vendor spend list and will likely have good info about how and by whom they're used. Get them out of the way.
    • Clear out shared technologies. This will feature infrastructure and operations plus office productivity and communications spend. Portioning spend by department headcount for the CXO Business View is the hardest part. Get this forklift task out of the way too.
    • Don't sweat the small stuff. Wasting hours chasing the details of a $500 line item isn't worth it when you have five-, six-, or even seven-figure line items to map.

    Biggest challenge: Poor vendor labeling

    • Vendor labels are often an inconsistent mess or missing entirely. Standardize and apply consistent vendor labels throughout your data so that you can aggregate your data into a workable form.
    • Spend transactions with the same vendor can be scattered all over the place in your general ledger. Take the time to "un-unique" your data to save yourself tremendous grief later on.
    • Start new go-forward labeling habits. Talk to finance about your new list of vendor naming standards and tagging spend as on-prem or cloud. Getting their cooperation with these are major wins.

    Key step - validate! If you see services or functions with low or no allocation, or something just doesn't look right, investigate. There's probably a technology out there in the business doing that work.

    4.1 Map your IT vendor spend

    Duration: Variable

    1. Navigate to tab "5. Vendor Spend Mapping" in the IT Spend & Staffing Transparency Workbook. On one row, enter a spend line item (vendor, product, etc.), a brief description, and the known amount of spend.
    2. Under the CFO Expense View (columns F-P), allocate the line item's spend as a percentage across all asset-class categories. If the allocation for a line item is 0%, leave the cell blank.
    3. Under the CIO Service View (columns S-AM), allocate the line item's spend as a percentage across all service categories. If the allocation for a service is 0%, leave the cell blank.
    4. Under the CXO Business View (columns AP-BH), allocate the line item's spend as a percentage across all business function and industry-specific function categories. If the allocation for a function is 0%, leave the cell blank.
    5. Under the CEO Innovation View (columns BK-BO), allocate the line item's spend as a percentage across Business Innovation, Business Growth, and Keep the Lights On. If the allocation for an investment type is 0%, leave the cell blank.
    6. Repeat steps 2-5 for all spend line items.
    7. Follow up on and resolve any additional inquiries you need to make based on questions that arose during the mapping process.
    8. Validate your mapping by:
      1. Ensuring your amounts add up to your previously calculated total IT vendor spend. A balance tracker is provided on tab "6. Tracker & General Outputs" of the IT Spend & Staffing Transparency Workbook.
      2. Identifying spend categories that have zero spend allocation. Additional percentage allocation splits for certain line items are probably required.
      3. Investigating spend categories that seem to have very high or very low spend allocations based on a gut check. Again, double-check your percentage allocation splits.

    Download the IT Spend & Staffing Transparency Workbook

    4.1 Map your IT vendor spend

    InputOutput
    • Cleaned and organized IT vendor spend data and information
    • Finalized mapping of IT vendor spend across the four views of the IT Cost Model
    MaterialsParticipants
    • IT Spend & Staffing Transparency Workbook
    • Head of IT
    • IT financial lead
    • Other IT management as required

    Phase 4: Map your IT vendor spend

    Achievement summary

    You've now completed your IT vendor spend mapping. You have:

    • Allocated your IT vendor spend across the four views of the ITFM Cost Model.
    • Validated your mapping to ensure it's accurate and complete.

    "A lot of organizations log their spending by vendor name with no description of the goods or services they actually purchased from the vendor. It could be hardware, software, consulting services ... anything. Having a clear understanding of what's really in there is an essential aspect of the spend conversation."
    - Rex Ding, Research Specialist, ITFM Practice, Info-Tech Research Group

    Phase 5

    Identify Implications for IT

    This phase will walk you through the following activities:

    • Analyzing the results of your IT staff and vendor spend mapping across the four views of the ITFM Cost Model
    • Preparing an executive presentation of your transparent IT spend

    This phase involves the following participants:

    • Head of IT
    • IT financial lead
    • Other members of IT management

    Phase 5: Identify implications for IT

    Analyze and communicate.

    You're now nearing the end of the first leg in your IT spend transparency journey. In this phase you will:

    • Analyze the results of your IT spend mapping process.
    • Revisit your transparency objectives.
    • Prepare an executive presentation so you can share findings with other leaders in your organization.

    "Don't plug in numbers just to make yourself look good or please someone else. The only way to improve is to look at real life."
    - Monica Braun, Research Director, ITFM Practice, Info-Tech Research Group

    You've mapped your IT spend data. Now what?

    With mapped data in hand, now you can start to tell IT's spend story with stakeholders in the business.

    Mapping your IT spend is a lot of work, but what you've achieved is impressive (applause!) as well as essential for growing your ITFM maturity. Now put your hard work to work.

    • Consider benchmarking. While not covered in-depth here, benchmarking against yourself in a year-over-year approach as well as against external industry peers are very useful exercises in your technology spend analysis.
    • Review your numbers and graphs. Your IT Spend & Staffing Transparency Workbook contains a series of data visualizations that will help you see the big picture as well as relationships between spend categories.
    • Note the very big numbers, the very small numbers, and the things that just look odd. You'll want to investigate and understand these further.
    • Prepare to communicate. Facilitating conversations with stakeholders in the business is the immediate objective of the IT spend and staffing transparency exercise. Decide where and with whom you want to start dialogue.

    The slides that follow show sample data summaries and visualizations generated in the IT Spend & Staffing Transparency Workbook. We'll take a look at the metrics, tables, and graphs you now have available to you post-mapping and how you can potentially use them in conversations with different IT stakeholders.

    Evaluate how you might use benchmarks before diving into your analysis

    Benchmarking can be a useful input for contextualizing and interpreting your IT spend data. It's not essential at this point but should be part of your ITFM toolkit.

    There are two basic types of benchmarking ...

    Internal: Capturing a current-state set of data about an in-house operation to serve as a baseline. Over time, snapshots of the same data are taken and compared to the baseline to track and assess changes. Common uses for internal benchmarking include:

    • Assessing the impact of a project or initiative.
    • Measuring year-over-year performance.

    External: Seeking out aggregated, current-state data about a peer-group operation to assess your own relative status or performance on the same operation. Common uses for external benchmarking include:

    • Understanding common practices in the industry.
    • Strategic and operational visioning, planning, and goal-setting.
    • Putting together a business case for change or investment.

    Both types of benchmarking benefit from some formality and rigor. Info-Tech can help you stand up an ITFM benchmarking approach as well as connect you with actual IT spend peer benchmarks via our IT Spend & Staffing Benchmarking service.

    5.1 Analyze the results of your IT spend mapping

    Duration: Variable

    1. Review the guidance slides that follow the two instruction slides for this exercise to provide yourself with a grounding on how to interpret and analyze your mapped IT staff and vendor spend data.
    2. Systematically review the data tables and graphs on the "Outputs" tabs 6 through 10 in the IT Spend & Staffing Transparency Workbook. There are several approaches you can take - use the one that works best for you. For example:
      1. Review each view in its entirety, one at a time.
      2. Review all workforce spend collectively across all four views, followed by all vendor spend across all four views (or vice versa).
    3. Make note of any spend values that are comparatively high or low or strike you as odd or worth further investigation.
    4. Craft a series of spend-related questions you want to answer for yourself and your stakeholders using the data.
      1. For example, you need to cut costs and apps maintenance is high. Your question could be, "Can we cut costs on applications maintenance staffing?"
      2. Alternatively, you can develop a series of statements (research hypotheses) that you seek to prove true or false with the data. This approach is useful for testing assumptions you've been making. For example, "We can cut spending on applications maintenance staff. True or false?"
    5. Use the template provided on tab "11. Data Analysis" in the IT Spend & Staffing Transparency Workbook to document your findings and conclusions, along with the data that supports them.

    Download the IT Spend & Staffing Transparency Workbook

    5.1 Analyze the results of your IT spend mapping

    InputOutput
    • Tabular and graphical data outputs
    • Conclusions and potential actions about IT staff and vendor spend
    MaterialsParticipants
    • IT Spend & Staffing Transparency Workbook
    • Head of IT
    • IT financial lead
    • Other IT management as required

    High-level findings: Use these IT spend metrics to review and set big picture goals

    Think of these metrics as key anchors in your long-term strategic planning efforts.

    Use IT spend metrics to review and set big goals

    It's common for the business to want a sacrifice in IT OpEx in favor of CapEx

    CapEx and OpEx approval mechanisms are often entirely separate. Different tax treatment for CapEx means that it's usually preferred by the business over OpEx.

    OpEx is often seen as a sunk cost (i.e. an IT problem).

    • Barring a major decision or event, OpEx on an individual item will generally trend upward over time, often by a few percent every year, in lockstep with inflation and growth in organizational headcount.
    • A good portion of OpEx, however, is necessary for basic business continuity.

    CapEx is usually seen as investment (i.e. a business growth opportunity).

    • CapEx behaves quite differently than OpEx. On-the-books capitalized spend on an individual asset tends to trend downward over time due to depreciation or amortization.
    • CapEx only tends to go up when a net-new capital project is initiated, and organizations often have more control over if, when, and how this spend happens.

    Break down the OpEx/CapEx wall. Reference OpEx whenever you talk about CapEx. The best way to do this is via Total Cost of Ownership (TCO).

    • Present data on long-term OpEx projections whenever a new capital project is proposed and ensure ongoing maintenance funds are secured.
    • Educate your CFO about the impact of the cloud on OpEx. See if internal OpEx/CapEx ratio expectations can be adjusted to reflect this reality.

    Spend by asset class offers the CFO a visual illustration of where the money's really gone

    The major spend categories should look very familiar to your CFO. It's the minor sub-categories that sit underneath where you ultimately want to drive the conversation.

    Traditional categories don't reflect IT reality anymore.

    • Most finance departments have "software" accounts that contain apples and oranges, plus other dissimilar fruit.
    • Software isn't just software anymore. Now it's on-premises (CapEx) or cloud (OpEx). The same distinction applies to traditional hardware due to the advent of managed services.
    • The basic categories traditionally used to tag IT spend are out of date. This makes it hard for IT to have meaningful conversations with the CFO since they're not working from the same glossary.

    "Software (on-premises)" and "hardware (cloud)" are more meaningful descriptors than "software" and "hardware." Shift the dialogue.

    Start the migration from major categories to minor categories.

    • Still give the CFO the traditional major categories they're looking for but start including minor category breakdowns into your communications. Most importantly, have a meeting to explain what these minor categories are and why they're important to managing IT effectively.
    • Next, see if the CFO can formally split on-premises vs. cloud software on the books as a first step in making IT spend tracking more meaningful.

    Employees vs. contractors warrants a specific conversation, plus a change in mindset

    IT leaders often find it easier to get approval for contracted labor than to hire a permanent employee. However, the true value proposition for contractors does vary.

    The decision to go with permanent employees or contractors depends on your ultimate goals.

    • Contractors tend to be less expensive and provide more flexibility when adjusting to changing business needs. However, contractors may be less dedicated and take their skills and knowledge with them when they leave.
    • Permanent employees bring additional costs like benefits and training. Plus, letting them go is a lot more complicated. However, they can also bring real value in a way a contractor can't when it comes to sustaining long-term strategic growth. They're assets in themselves.

    Far too often, labor-sourcing decisions are driven by controlling near-term costs instead of generating and sustaining long-term value.

    Introduce the cost-to-value ratio to your workforce spend conversations.

    • Your mapped data will allow you to talk about comparative headcount and spend. This is a financial conversation devoid of context.
    • Go beyond. Show how workforce spend has allowed stated goals to be achieved while controlling for costs. This is the true definition of value.

    CFO Expense View: Shift the ITFM conversation

    Now that you've mapped your IT spend data to the CFO Expense View, there are some questions you're better equipped to answer, namely:

    • How should I classify my IT costs?
    • What information should I include in my plans and reports?
    • How do I justify current spend?
    • How do I justify a budget increase?

    You now have:

    • A starting point for educating the CFO about IT spend realities.
    • A foundation for creating a shared glossary of terms that works for both IT and the finance department and facilitates more meaningful conversations.
    • Proof that there are major areas of IT spend, such as cloud software, that are distinctive and probably warrant their own financial category in the general ledger.
    • A transparent record of IT spend that shows that you understand and care about financial issues, fostering the goodwill and trust that facilitates investment in IT.
    • A starting point to change the ITFM conversation with the CFO from one focused on cost to one focused on value.

    Exactly how is IT spending all that money we give them?

    Exactly like this ...

    Chart of the CFO Expense View

    The CIO Service View aligns with how IT organizes and manages itself – this is your view

    The data mapped here is a critical input for IT's service planning and management program and should be integrated into your IT performance measurement activities.

    Major service categories: These values give a high-level snapshot of your general IT service spend priorities. In most organizations, Applications dominates, making it a focus for cost optimization.

    Minor service categories: The level of granularity for these values prove more practical when measuring performance and making service management decisions - not too big, not too small. While not reflected in this example, application maintenance is usually the largest relative consumer of IT spend in most organizations.

    Data & BI and security: Isolating the exact spend for these services is challenging given that they're often entangled in applications and infrastructure spend respectively, and separate spend tracking for both is a comparatively recent practice.

    Table of CIO Service View

    Check the alignment of individual service spend against known business objectives

    Some IT services are taken for granted by the business, while others are virtually invisible. This lack of visibility often translates into funding misalignments.

    Is the amount of spend on a given service in parallel with the service's overall importance?

    • Though often unstated, ensuring continuity of basic business operations is always the top priority. This means business apps, core infrastructure, end users, and security need to be appropriately funded - these should collectively comprise the majority of IT service spend.
    • Strategy-supporting IT services, like data & BI, see high investment variability between organizations. If its strategic role/importance doesn't align with spend, flag it as an issue you'll need to reconcile with the business by increasing funding (important) or reducing service levels (unimportant).
    • The strategic importance of IT as a whole is often reflected in the spend on IT management services. If spend is low, IT's probably seen as a support function, not a strategic one.

    Identify the hot spots and pick your battles.

    • Spend levels are just approximate gauges of where and how the business is willing to spend its money. Start with this simple gut check.
    • Noting the areas of importance vs. spend misalignment will help you identify where negotiations with the business should probably happen.

    A mature IT cost optimization practice is often approached from the service perspective

    When optimizing IT costs, you have two OpEx levers to pull - vendor spend and staff spend. Isolating these two sources of IT service spend will help shortlist your options.

    It's all about how much room you have to move.

    • Any decision made about how a service is provisioned will push vendor and staff spend in clear, predictable, and often opposite directions (e.g. in-house and people-intensive services tend to see higher staff spend, while outsourced and tech-intensive services higher vendor spend).
    • Service levels required by the business should be the driving factor behind service design and spend decisions. High service spend may reflect priority but may also indicate it's over-built and is ripe for a cost-optimization treatment.
    • Service spend is a useful barometer for tracking the financial impact of any changes made to IT. Add simple unit-cost metrics like "service spend per organizational employee" and "service spend per FTE assigned to the service" to see if and how the dial has moved over time.

    Grow your IT service management practice.

    • The real power of the CIO Service View is laying the groundwork for next-level IT service management initiatives like developing a service catalog, negotiating service-level agreements, rolling out chargeback and showback mechanisms, and calculating IT's value to the business.
    • Use service spend as a common denominator for both your IT service management and IT performance management programs. Better yet, integrate the two programs to ensure a single version of the truth.

    CIO Service View: Optimize your cost-to-value ratio

    Now that you've mapped your IT spend data to the CIO Service View, there are some questions you're better equipped to answer, namely:

    • What's the impact of cloud adoption on speed of delivery?
    • Where can I improve spend efficiency?
    • Is my support model optimized?
    • How does our spend compare to others?

    You now have:

    • Data that shows the financial impact of change decisions on service costs.
    • Insight into the relationship between vendor spend and staff spend within a given IT service.
    • The information you need to start developing service unit costing mechanisms.
    • A tool for setting and right-sizing service-level agreements with the business.
    • A more focused starting point for investigating IT cost-optimization opportunities.
    • A baseline for benchmarking common IT services against your peers.

    Does the amount we spend on each IT service make sense?

    We have some good opportunities for optimization ...

    Chart of CIO Service View

    The CXO Business View will spur conversations that may have never happened before

    This view is a potential game changer as previously unknown technology spend is often revealed, triggering change in IT's relationship with business unit leaders.

    Table of CXO Business View

    The big beneficiaries of IT spend will leap out

    The CXO Business View mapping does have a "shock and awe" quality to it given large spend disparities. They may be totally legitimate, but they're still eye-catching.

    Share information, don't push recommendations.

    • Have a series of one-on-one meetings with business unit leaders to present these numbers.
      • Approach initial meetings as information-sharing sessions only. The data is probably new to them, and they'll need time to reflect and ask questions.
      • Bring a list of the big-ticket spend items for that business unit to focus the conversation.
    • Present these numbers at a broader leadership meeting.
      • It's critical for everyone to hear the same truth and learn about each other's technology needs and uses.
      • This is where recommendations for better aligning IT spend with business goals and cost-optimization strategies should surface. A group approach will bring technology haves and have-nots into the open, as well as provide a forum for collaborative solutioning.

    If possible, slice the numbers by business unit headcount.

    • IT spend per business unit employee is an attention-getting metric that can help gain entry to important conversations.
    • Comparing per-employee spend across different business functions is not necessarily an apples-to-apples comparison, as units like HR may have few employees but serve the entire organization. Bring up these kinds of differences to provide context and avoid misinterpretations.

    Questions will arise in how you calculated and allocated indirect IT spend

    IT spend for things like core infrastructure and end-user services must be distributed fairly across multiple or all business units. Be prepared to explain your methods.

    Be transparent in your transparency.

    • Distributing indirect spend is imprecise by nature. You can't account for every unique circumstance. However, you can devise a logic-driven, general approach that's defensible, fair, and works for most people most of the time.
    • Lay out your assumptions from the start. This is an important part of communicating transparently and can prevent unwanted descent into weedy rabbit holes.
      • List what you classified as indirect spend. Use the CFO Expense View and/or CIO Service View categories to aid your presentation of this information.
      • Point out known circumstances that didn't fit your general allocation method and how you handled them. Opting to ignore minor anomalies is reasonable but be sure to tell business unit leaders you did this and why.

    Use questions about indirect IT staff spend distribution to engage stakeholders.

    • As a percentage, the indirect IT staff spend allocation to a specific business unit may be higher than that for IT vendor spend since IT staff tend to operate more generally than the technologies they support.
    • Leverage any pushback about indirect spend as an opportunity to engage the broader business leadership group. Let them arrive at a consensus of how they want it done and confirm buy-in.

    CXO Business View: Bring the truth to light

    Now that you've mapped your IT spend data to the CXO Business View, there are some questions you're better equipped to answer, namely:

    • Which business units consume the most IT resources?
    • Which business units are underserved by IT?
    • How do I best communicate spend data internally?
    • Where do I need better business sponsorship for IT projects?

    You now have:

    • A reason-based accounting of direct and indirect amounts spent on IT vendors and staff in support of each major business unit.
    • Insight into the technology haves and have-nots in your organization and where opportunities to optimize costs may exist.
    • Attention-getting numbers that will help you engage business-unit leaders in meaningful conversations about their use of IT resources and the value they receive.
    • A mechanism to assess if a business unit's consumption of IT is appropriate and aligned with its purpose and mandate in the organization.
    • A list of previously unknown business-side technologies that IT will investigate further.

    Why doesn't my business unit get more support from IT?

    Let's look at how you compare to the other departments ...

    Chart of the CXO Business View

    From the CEO's high-level perspective, IT spend is a collection of distinct financial islands

    From IT's perspective, these islands are intimately connected, with events on one affecting what happens (or doesn't) on another. Focus on the bridges.

    Table of CEO High-level Perspective

    Focus more on unifying the view of technology spend than on the numbers

    When talking to the CEO, seek to build mutual understanding and encourage a holistic approach to the organization's technology spend.

    Use the numbers to get to the real issues.

    • Clarify with the CEO what business innovation, business growth, and KTLO means to them and the role each plays in the organization's strategic and operational plans.
    • Find out the role they think IT, and technology as a whole, has in realizing business plans. Only then can you look at the relative allocation of IT spend with them to see if the aspiration aligns with reality.
    • Eventually, you'll need to discuss expectations around who pays the bills for operationally supporting capital technology investments over the long-term (i.e. IT or the business units that actually want and use it). You'll have concrete examples of business projects that consumed IT operations resources without a corresponding increase in IT's OpEx budget.

    Focus your KTLO spend conversation on risk and trade-off.

    • Every strategic conversation needs to look at the impact on ongoing operations. Every discussion about CapEx needs to investigate the long-term repercussions for OpEx. Look at the whole tech spend picture.
    • Use risk to get KTLO/OpEx into the conversation. Be straightforward (i.e. "If we do/don't do this, then we can/can't do that"). Simply put, mitigating the risks that get in the way of having it all usually requires spending.

    CEO Innovation View: Learn what's really expected of IT

    Now that you've mapped your IT spend data to the CEO Innovation View, there are some questions you're better equipped to answer, namely:

    • Why is KTLO spend so high?
    • What should our operational spend priorities be?
    • Which projects and investments should we prioritize?
    • Are we spending enough on innovative initiatives?

    You now have:

    • A holistic, organization-wide view of total technology spend in support of different investment types, namely business innovation, business growth, and keeping things up and running.
    • Data-driven examples that prove the impact of near-term capital spend on long-term operational expenses and the intimate relationship between the two types of spend.
    • A way to measure the degree of alignment between the innovation and growth goals the organization has and how money is actually being spent to realize those goals.
    • A platform to discuss how technology investment decision-making and governance can work better to realize organizational mandates and goals.

    I know what IT costs us, but what is it really worth?

    Here's how tech spend directly supports business objectives ...

    Chart of CEO Innovation View

    Revisit your IT spend transparency objectives before crafting your executive presentation

    Go back to exercise 1.1 to remind yourself why you undertook this effort in the first place, clear your head of all that data, and refocus on the big picture.

    Review the real problems and issues you need to address and the key stakeholders.
    This will guide what data you focus on or showcase with other business leaders. For example, if IT OpEx is perceived as high, be prepared to examine the CapEx/OpEx ratio as well as cloud-related spend's impact on OpEx.

    Flag ITFM processes you'll develop as part of your ITFM maturity improvement plan.
    You won't become a TCO math expert overnight, but being able to communicate your awareness of and commitment to developing and applying ITFM capabilities helps build confidence in you and the information you're presenting.

    Use your first big presentation to debut ITFM.
    ITFM as a formal practice and the changes you hope to make may be a novel concept for your business peers. Use your newfound IT spend and staffing transparency to gently wade into the topic instead of going for the deep dive.

    Now it's time to present your transparent IT spend and staffing data to your executive

    Pull out of analysis mode. You're starting to tell the IT spend story, and this is just the first chapter. Introduce your cast of characters and pique your audience's interest.

    The goal of this first presentation is to showcase IT spend in general and make sure that everyone's getting the same information as everyone else.

    Go broad, not deep
    Defer any in-depth examinations until after you're sure you have everyone's attention. Only dive deep when you're ready to talk about specific plans via follow-up sessions.

    Focus on the CXO
    Given your audience, the CXO Business View may be the most interesting for them and will trigger the most questions and discussion. Plan to spend the largest chunk of your time here.

    Avoid judgment
    Let the numbers speak for themselves. Do point out what's high and what's low, but don't offer your opinion about whether it's good or bad. Let your audience draw their own conclusions.

    Ask for impressions
    Education and awareness are primary objectives. What comes up will give a good indication of what's known, what's news, who's interested, and where there's work to do.

    Pick a starting point
    Ask what they see as high-priority areas for both optimizing IT costs as well as improving the organization's approach to making IT spend decisions in general.

    What to include in your presentation ...

    • Purpose: Why you did the IT spend and staffing transparency exercise.
    • Method: The models and processes you used to map the data.
    • Data: Charts from the IT Spend & Staffing Transparency Workbook.
    • Feedback: Space for your audience to voice their thoughts.
    • Next steps: Discussion and summary of actions to come.

    5.2 Develop an executive presentation

    Duration: Two hours

    1. Download the IT Staff & Spend Executive Presentation Template.
    2. Copy and paste the IT spend output tables and graphs into the template. (Note: Pasting as an image will preserve formatting.)
    3. Incorporate observations and insights about your analysis of your IT spend metrics.
    4. Conduct an internal review of the final presentation to ensure it includes all the elements you need and is error free.
    5. Book time to make your presentation to the executive team. Plan time after the presentation to field questions, engage in follow-up information sessions, and act on feedback.

    Note: Refer to your organization's standards and norms for executive-level presentations and either adapt the Info-Tech template accordingly or use your own.

    Input Output
    • Tabular and graphical data outputs in the IT Spend & Staffing Transparency Workbook
    • Executive presentation summarizing your organization's actual IT spend
    Materials Participants
    • IT Spend & Staffing Transparency Workbook
    • IT Staff & Spend Executive Presentation Template
    • CIO/IT directors
    • IT financial lead
    • Other IT management

    Download the IT Spend & Staffing Transparency Executive Presentation TemplateTemplate

    Phase 5: Identify implications for IT

    Achievement summary

    You've done the hard part in starting your IT spend transparency journey. You have:

    • Analyzed the results of your IT spend mapping process.
    • Revisited your transparency objectives.
    • Prepared an executive presentation so you can share findings with other leaders in your organization.

    "Having internal conversations, especially if there is doubt, allows for accuracy and confidence in your model. I was showing someone the cost of a service he managed. He didn't believe the service was so expensive. We went through it: here are the people we allocated, the assets we allocated, and the software we allocated. It was right - that was the total cost. He was like, 'No way. Wow.' The costs were high, and the transparency is what allowed for a conversation on cost optimization."
    - Monica Braun, Research Director, ITFM Practice, Info-Tech Research Group

    Next Steps

    Achieve IT Spend & Staffing Transparency

    This final section will provide you with:

    • An overall summary of accomplishment
    • Recommended next steps
    • A list of contributors to this research
    • Some related Info-Tech resources to help you grow your ITFM practice

    Summary of Accomplishment

    Congratulations! You now have a fully transparent view of your IT spend.

    You've now mapped the entirety of technology spend in your organization. You've:

    1. Learned the key sources of spend data and information in your organization.
    2. Set some standards for data organization and labeling.
    3. Have a methodology for continuing to track and document spend in a transparent way.
    4. Crafted an executive presentation that's a first step in having more meaningful and constructive conversations about IT spend with your key stakeholders.

    What's next?

    With a reliable baseline, you can look forward to more informed and defensible IT budgeting and cost optimization. Use your newly-transparent IT spend as a foundation for improving your financial data hygiene in the near term and evolving your overall ITFM governance maturity in the long-term.

    If you would like additional support, have our analysts guide you through an Info-Tech full-service engagement or Guided Implementation.

    Contact your account representative for more information.

    1-888-670-8889

    Research Contributors and Experts

    Monica Braun, Research Director, ITFM Practice

    Monica Braun
    Research Director, ITFM Practice
    Info-Tech Research Group

    Dave Kish, Practice Lead, ITFM Practice

    Dave Kish
    Practice Lead, ITFM Practice
    Info-Tech Research Group

    Kennedy Confurius, Research Analyst, ITFM Practice

    Kennedy Confurius
    Research Analyst, ITFM Practice
    Info-Tech Research Group

    Aman Kumari, Research Specialist, ITFM Practice

    Aman Kumari
    Research Specialist, ITFM Practice
    Info-Tech Research Group

    Rex Ding, Research Specialist, ITFM Practice

    Rex Ding
    Research Specialist, ITFM Practice
    Info-Tech Research Group

    Angie Reynolds, Principal Research Director, ITFM Practice

    Angie Reynolds
    Principal Research Director, ITFM Practice
    Info-Tech Research Group

    Related Info-Tech Research

    Build Your IT Cost Optimization Roadmap

    • Cost optimization often doesn't go beyond the cutting part, but cutting costs isn't strategic - it's reactive and can easily result in mistakes.
    • True cost optimization is much more than this. Re-focus your efforts on optimizing your cost-to-value ratio and implementing a sustainable cost-optimization practice.

    Build an IT Budget

    • Budgetary approval is difficult because finance executives have a limited understanding of IT and use a different vocabulary.
    • Detailed budgets must be constructed in a way that is transparent but at a level of appropriate detail in order to limit complexity and confusion.

    Manage an IT Budget

    • No one likes to be over budget, but being under budget isn't necessarily good either.
    • Implement a budget management process that documents your planned budget and actual expenditures, tracks variances, and responds to those variances to stay on track.
    • Control for under- or overspending using Info Tech's budget management tool and tactics.

    APPENDIX

    Sample shared business services

    Sample industry-specific business services

    Sample shared business functions

    Business function Definition
    Human Resources The management of the recruitment, training, development, appraisal, compensation/reward, retention, and departure of employees in an organization. Does not include management of subcontractor or outsourced relationships.
    Finance and Accounting The management and analysis of an organization's revenue, funds, spend, investments, financial transactions, accounts, and financial statements. Often includes enterprise asset management.
    Procurement and Supplier Management Acquiring materials, goods, and services from an external party, including identifying potential suppliers/providers, managing tendering or bidding processes, negotiating terms and agreements, and managing the relationship with the vendor/provider.
    Information Technology The development, management, and optimization of information technology resources and systems over their lifecycle in support of an organization's work priorities and goals. Includes computer-based information and communication systems, but typically excludes industrial operational technologies.
    Legal Expertise in interpretation, implication, and application of legislation and regulation that affects the enterprise, including guidance and support in the areas of risk, contracting, compliance, ownership, and litigation.
    Regulatory Affairs and Compliance Management Identification, operationalization, monitoring, reporting, and enforcement of the standards, rules, codes, and laws that apply to an organization's operating environment and the products and services it offers.
    Sales Transactional provision of a product or service to a buyer at an agreed-upon price. Includes identifying and developing prospective buyers, presenting and explaining the product/service, overcoming prospect objections and concerns to purchase, negotiating terms, developing contracts, and billing or invoicing.
    Customer Service and Support A range of activities designed to optimize the customer experience with an organization and its products and services throughout the customer lifecycle with the goals of retaining the customer; encouraging additional spend or consumption; the customer positively influencing other potential customers; and minimizing financial and reputational business risks.
    Marketing and Advertising Understanding customer/prospect needs, developing strategies to meet those needs, and promotion of the organization's products/services to a target market via a range of channels to maximize revenue, membership, donations, and/or develop the organization's brand or reputation. Includes market research and analysis and promotion, campaign, and brand management.

    Sample industry-specific functions

    Supply chain and capital-intensive industries.

    Industry function Definition
    Product Innovation Research, design, development, and launch of new products, including the engineering of their underlying production processes.
    Product and Service Portfolio Management The management of an organization's collection of products and services, including management of the product/service roadmap; product/service portfolio and catalog; product/service quality and performance; and product/service pricing, bundling and markdown.
    Logistics and Supply Chain Management Sourcing raw materials or component parts needed and shipping of a finished product. Includes demand planning; procurement/supplier management; inventory management; yard management; allocation management; fulfillment and replenishment; and product distribution and delivery.
    Production Operations Manufacture, storage, and tracking of a product and ensuring product and production process quality. Includes operations management, materials management, quality/safety control, packaging management, and management of the tools, equipment, and technologies that support it.
    Architecture & Engineering The design and planning of structures or critical infrastructure systems according to scientific, functional, and aesthetic principles.
    Construction New construction, assembly, or alteration of buildings and critical infrastructure (e.g. transportation systems; telecommunications systems; utilities generation/transmission/distribution facilities and systems). Includes management of all construction project plans and the people, materials, and equipment required to execute.
    Real Estate Management Management of any residential, commercial, or industrial real estate holdings (land and buildings), including any financial dealings such as its purchase, sale, transfer, and rental as well as ongoing maintenance and repair of associated infrastructure and capital assets.

    Sample industry-specific functions

    Financial services and insurance industries.

    Industry function Definition
    Core Banking Services Includes ATM management; account management (opening, deposit/withdrawal, interest calculation, overdraft management, closing); payments processing; funds transfers; foreign currency exchange; cash management.
    Loan, Mortgage, and Credit Services Includes application, adjudication, and approval; facility; disbursement/card issuance; authorization management; merchant services; interest calculation; billing/payment; debt/collections management.
    Investment and Wealth Management Processes for the investment of premiums/monies received from policy holders/customers to generate wealth. Often two-pronged: internal investment to fund claim payout in the case of insurance, and customer-facing investment as a financial service (e.g. retirement planning/annuities). Includes product development and management, investment management, safety deposit box services, trust management services.
    Actuarial Analysis & Policy Creation Development of new policy products based on analysis of past losses and patterns, forecasts of financial risks, and assessment of potential profitability (i.e. actuarial science). These processes also include development of rate schedules (pricing) and the reserves that the insurer needs to have available for potential claim payouts.
    Underwriting & Policy Administration Processes for assessing risk of a potential policy holder; determining whether to insure them or not; setting the premiums the policy holder must pay; and administering the policy over the course of its lifecycle (including updates and billing).
    Claims Processing & Claims Management Processes for receiving, investigating, evaluating, approving/denying, and disbursing a claim payout. This process is unique to the insurance industry. In health insurance, ongoing case management processes need to be considered here whereby the insurer monitors and approves patient treatments over a long-term basis to ensure that the treatments are both necessary and beneficial.

    Sample industry-specific functions

    Healthcare industry

    Industry function Definition
    Patient Intake & Admissions Processes whereby key pieces of information about a patient are registered, updated, or confirmed with the healthcare provider in order to access healthcare services. Includes patient triage, intake management, and admissions management. These processes are generally administrative in nature.
    Patient Diagnosis A range of methods for determining the medical condition a patient has in order to provide appropriate care or treatment. Includes examination, consultation, testing, and diagnostic imaging.
    Patient Treatment The range of medical procedures, methods, and interventions to mitigate, relieve, or cure a patient's symptom, injury, disease, or other medical condition. Includes consultation and referral; treatment and care planning; medical procedure management; nursing and personal support; medicine management; trauma management; diet and nutrition management; and patient transportation.
    Patient Recovery & Ongoing Care Processes and methods for tracking the progress of a patient post-treatment; improving their health outcomes; restoring, maintaining, or improving their quality of life; and discharging or transferring them to other providers. Includes remote monitoring of vital parameters, physical therapy, post-trauma care, and a range of restorative and lifestyle modification programs.

    Sample industry-specific functions

    Gaming and hospitality industries

    Industry function Definition
    Accommodation Short-term lodging in hotel facilities. Includes management and maintenance of guest rooms and common spaces, amenities (e.g. swimming pool), and other related services (e.g. valet parking).
    Gaming Includes table wagering games and gambling activities such as slot machines or any other activity that includes on premises mobile casino gaming.
    Food & Beverage Services Food and beverages prepared, served, or available for sale by the hotel on the hotel premises via restaurants and bars and room service. Excludes catering (see Events Management) and management or operation of independent leased food and beverage establishments located on the hotel premises.
    Entertainment & Events Planning, coordination, and on-premises hosting of events including conferences, conventions, trade shows, parties, ceremonies and live entertainment, and other forms of recreation on the hotel premises. Includes all aspects of entertainment operations, facility management and catering for the event.

    Develop a Web Experience Management Strategy

    • Buy Link or Shortcode: {j2store}555|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Marketing Solutions
    • Parent Category Link: /marketing-solutions
    • Web Experience Management (WEM) solutions have emerged as applications that provide marketers and other customer experience professionals with a complete set of tools for web content management, delivery, campaign execution, and site analytics.
    • However, many organizations are unsure of how to leverage these new technologies to enhance their customer interaction strategy.

    Our Advice

    Critical Insight

    • WEM products are not a one-size-fits-all investment: unique evaluations and customization is required in order to deploy a solution that fits your organization.
    • WEM technology often complements core CRM and marketing management products – it does not supplant it, and must augment the rest of your customer experience management portfolio.
    • WEM provides benefits by giving web visitors a better experience – leveraging tools such as web analytics gives the customer a tailored experience. Marketing can then monitor their behavior and use this information to warm leads.

    Impact and Result

    • Deploy a WEM platform and execute initiatives that will strengthen the web-facing customer experience, improving customer satisfaction and unlocking new revenue opportunities.
    • Avoid making unnecessary new WEM investments.
    • Make informed decisions about the types of technologies and initiatives that are necessary to support WEM.

    Develop a Web Experience Management Strategy Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to find out why you should develop a WEM strategy, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Harness the value of web experience management

    Make the case for a web experience management suite and structure the WEM strategy project.

    • Develop a Web Experience Management Strategy Phase 1: Harness the Value of Web Experience Management
    • Web Experience Management Strategy Summary Template
    • WEM Project Charter Template

    2. Create the vision for web experience management

    Identify the target state WEM strategy, assess current state, and identify gaps.

    • Develop a Web Experience Management Strategy Phase 2: Create the Vision for Web Experience Management

    3. Execute initiatives for WEM deployment

    Build the WEM technology stack and create a web strategy initiatives roadmap.

    • Develop a Web Experience Management Strategy Phase 3: Execute Initiatives for WEM Deployment
    • Web Process Automation Investment Appropriateness Assessment Tool
    [infographic]

    Workshop: Develop a Web Experience Management Strategy

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Launch the WEM Selection Project

    The Purpose

    Discuss the general project overview for the WEM selection.

    Key Benefits Achieved

    Launch of your WEM selection project.

    Development of your organization’s WEM requirements. 

    Activities

    1.1 Facilitation of activities from the Launch the WEM Project and Collect Requirements phase, including project scoping and resource planning.

    1.2 Conduct overview of the WEM market landscape, trends, and vendors.

    1.3 Conduct process mapping for selected marketing processes.

    1.4 Interview business stakeholders.

    1.5 Prioritize WEM functional requirements.

    Outputs

    WEM Procurement Project Charter

    WEM Use-Case Fit Assessment

    2 Plan the Procurement and Implementation Process

    The Purpose

    Plan the procurement and the implementation of the WEM solution.

    Key Benefits Achieved

    Selection of a WEM solution.

    A plan for implementing the selected WEM solution. 

    Activities

    2.1 Complete marketing process mapping with business stakeholders.

    2.2 Interview IT staff and project team, identify technical requirements for the WEM suite, and document high-level solution requirements.

    2.3 Perform a use-case scenario assessment, review use-case scenario results, identify use-case alignment, and review the WEM Vendor Landscape vendor profiles and performance.

    2.4 Create a custom vendor shortlist and investigate additional vendors for exploration in the marketplace.

    2.5 Meet with project manager to discuss results and action items.

    Outputs

    Vendor Shortlist

    WEM RFP

    Vendor Evaluations

    Selection of a WEM Solution

    WEM projected work break-down

    Implementation plan

    Framework for WEM deployment and CRM/Marketing Management Suite Integration

    Application Portfolio Management

    • Buy Link or Shortcode: {j2store}28|cart{/j2store}
    • Related Products: {j2store}28|crosssells{/j2store}
    • member rating overall impact: 9.1/10
    • member rating average dollars saved: $81,275
    • member rating average days saved: 20
    • Parent Category Name: Applications
    • Parent Category Link: /applications

    The challenge

    • The chances are that you, too, have too many or far too many applications in your organization. You will not be alone. Almost 60% of companies report the same issue. 
    • That is due to poorly managed portfolios.
    • Your application managers now need to support too many non-critical applications, and they spend insufficient time on the vital applications.
    • You can rarely find the required pieces to rationalize your portfolio in one place. You will need to find the resources and build a team.
    • The lack of standard practices to define the value that each application in a portfolio provides to the company causes misalignments.

    Our advice

    Insight

    • There is no silver bullet solution. Going too rigid in your approach causes delays in value realization through application portfolio management. It may even prevent this altogether. Define flexible inputs to your portfolio and align closely with your business goals.

    Impact and results 

    • Define the outputs of your application rationalization effort, with clear roles and responsibilities.
    • Tailor the application rationalization framework (ARF) to your company's motivations, goals, and limitations.
    • Apply various application assessments to build a clear picture of your portfolio.
    • Build an application portfolio roadmap that shows your target state based on your rationalization decisions.

    The roadmap

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    Get started

    Our concise executive brief shows you why you should rationalize your application portfolio using a tailored framework for your company. We'll show you our methodology and the ways we can help you in handling this.

    Lay the foundations

    Define why you want to rationalize your application portfolio. Define the end state and scope. Build your action plan.

    • Build an Application Rationalization Framework – Phase 1: Lay Your Foundations (ppt)
    • Application Rationalization Tool (xls)

    Plan the application rationalization framework

    Understand what the core assessments are that you perform in these rationalizations. Define your framework and how rigorous you want to apply the reviews based on your business context.

    • Build an Application Rationalization Framework – Phase 2: Plan Your Application Rationalization Framework (ppt)

    Test and adapt your application rationalization framework (ARF)

    Our tool allows you to test the elements of your ARF. Then do a retrospective and adapt based on your experience and desired outcomes. 

    • Build an Application Rationalization Framework – Phase 3: Test and Adapt Your Application Rationalization Framework (ppt)
    • Application TCO Calculator (xls)
    • Value Calculator (xls)

    Initiate your roadmap

    Review your dispositions to ensure they align with your goals. 

    • Build an Application Rationalization Framework – Phase 4: Initiate Your Roadmap (ppt)
    • Disposition Prioritization Tool (xls)

     

    Make IT a Successful Partner in M&A Integration

    • Buy Link or Shortcode: {j2store}79|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: IT Strategy
    • Parent Category Link: /it-strategy
    • Many organizations forget the essential role IT plays during M&A integration. IT is often unaware of a merger or acquisition until the deal is announced, making it very difficult to adequately interpret business goals and appropriately assess the target organization.
    • IT-related integration activities are amongst the largest cost items in an M&A, yet these costs are often overlooked or underestimated during due diligence.
    • IT is expected to use the M&A team’s IT due diligence report and estimated IT integration budget, which may not have been generated appropriately.
    • IT involvement in integration is critical to providing a better view of risks, improving the ease of integration, and optimizing synergies.

    Our Advice

    Critical Insight

    • Anticipate that you are going to be under pressure. Fulfill short-term, tactical operational imperatives while simultaneously conducting discovery and designing the technology end-state.
    • To migrate risks and guide discovery, select a high-level IT integration posture that aligns with business objectives.

    Impact and Result

    • Once a deal has been announced, use this blueprint to set out immediately to understand business M&A goals and expected synergies.
    • Assemble an IT Integration Program to conduct discovery and begin designing the technology end-state, while simultaneously identifying and delivering operational imperatives and quick-wins as soon as possible.
    • Following discovery, use this blueprint to build initiatives and put together an IT integration budget. The IT Integration Program has an obligation to explain the IT cost implications of the M&A to the business.
    • Once you have a clear understanding of the cost of your IT integration, use this blueprint to build a long-term action plan to achieve the planned technology end-state that best supports the business capabilities of the organization.

    Make IT a Successful Partner in M&A Integration Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to find out why you should follow Info-Tech’s M&A IT integration methodology and understand the four ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Launch the project

    Define the business’s M&A goals, assemble an IT Integration Program, and select an IT integration posture that aligns with business M&A strategy.

    • Make IT a Successful Partner in M&A Integration – Phase 1: Launch the Project
    • IT Integration Charter

    2. Conduct discovery and design the technology end-state

    Refine the current state of each IT domain in both organizations, and then design the end-state of each domain.

    • Make IT a Successful Partner in M&A Integration – Phase 2: Conduct Discovery and Design the Technology End-State
    • IT Integration Roadmap Tool

    3. Initiate operational imperatives and quick-wins

    Generate tactical operational imperatives and quick-wins, and then develop an interim action plan to maintain business function and capture synergies.

    • Make IT a Successful Partner in M&A Integration – Phase 3: Initiate Operational Imperatives and Quick-Wins

    4. Develop an integration roadmap

    Generate initiatives and put together a long-term action plan to achieve the planned technology end-state.

    • Make IT a Successful Partner in M&A Integration – Phase 4: Develop an Integration Roadmap
    [infographic]

    Workshop: Make IT a Successful Partner in M&A Integration

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Launch the Project

    The Purpose

    Identification of staffing and skill set needed to manage the IT integration.

    Generation of an integration communication plan to highlight communication schedule during major integration events.

    Identification of business goals and objectives to select an IT Integration Posture that aligns with business strategy.

    Key Benefits Achieved

    Defined IT integration roles & responsibilities.

    Structured communication plan for key IT integration milestones.

    Creation of the IT Integration Program.

    Generation of an IT Integration Posture.

    Activities

    1.1 Define IT Integration Program responsibilities.

    1.2 Build an integration communication plan.

    1.3 Host interviews with senior management.

    1.4 Select a technology end-state and IT integration posture.

    Outputs

    Define IT Integration Program responsibilities and goals

    Structured communication plan

    Customized interview guide for each major stakeholder

    Selected technology end-state and IT integration posture

    2 Conduct Discovery and Design the Technology End-State

    The Purpose

    Identification of information sources to begin conducting discovery.

    Definition of scope of information that must be collected about target organization.

    Definition of scope of information that must be collected about your own organization.

    Refinement of the technology end-state for each IT domain of the new entity. 

    Key Benefits Achieved

    A collection of necessary information to design the technology end-state of each IT domain.

    Adequate information to make accurate cost estimates.

    A designed end-state for each IT domain.

    A collection of necessary, available information to make accurate cost estimates. 

    Activities

    2.1 Define discovery scope.

    2.2 Review the data room and conduct onsite discovery.

    2.3 Design the technology end-state for each IT domain.

    2.4 Select the integration strategy for each IT domain.

    Outputs

    Tone set for discovery

    Key information collected for each IT domain

    Refined end-state for each IT domain

    Refined integration strategy for each IT domain

    3 Initiate Tactical Initiatives and Develop an Integration Roadmap

    The Purpose

    Generation of tactical initiatives that are operationally imperative and will help build business credibility.

    Prioritization and execution of tactical initiatives.

    Confirmation of integration strategy for each IT domain and generation of initiatives to achieve technology end-states.

    Prioritization and execution of integration roadmap.

    Key Benefits Achieved

    Tactical initiatives generated and executed.

    Confirmed integration posture for each IT domain.

    Initiatives generated and executed upon to achieve the technology end-state of each IT domain. 

    Activities

    3.1 Build quick-win and operational imperatives.

    3.2 Build a tactical action plan and execute.

    3.3 Build initiatives to close gaps and redundancies.

    3.4 Finalize your roadmap and kick-start integration.

    Outputs

    Tactical roadmap to fulfill short-term M&A objectives and synergies

    Confirmed IT integration strategies

    Finalized integration roadmap

    Select a Security Outsourcing Partner

    • Buy Link or Shortcode: {j2store}246|cart{/j2store}
    • member rating overall impact: 8.8/10 Overall Impact
    • member rating average dollars saved: $13,739 Average $ Saved
    • member rating average days saved: 8 Average Days Saved
    • Parent Category Name: Security Processes & Operations
    • Parent Category Link: /security-processes-and-operations
    • Most organizations do not have a clear understanding of their current security posture, their security goals, and the specific security services they require. Without a clear understanding of their needs, organizations may struggle to identify a partner that can meet their requirements.
    • Breakdowns and lack of communication can be a significant obstacle, especially when clear lines of communication with partners, including regular check-ins, reporting, and incident response protocols, have not been clearly established.
    • Ensuring that security partners’ systems and processes integrate seamlessly with existing systems can be a challenge for most organizations in addition to making sure that security partners have the necessary access and permissions to perform their services effectively.
    • Adhering to security policies is rarely a priority to users as compliance often feels like an interference to daily workflow. For a lot of organizations, security policies are not having the desired effect.

    Our Advice

    Critical Insight

    • You can outsource your responsibilities but not your accountability.
    • Be aware that in most cases, the traditional approach is more profitable to MSSPs, and they may push you toward one, so make sure you get the service you want, not what they prescribe.

    Impact and Result

    • Determine which security responsibilities can be outsourced and which should be insourced and the right procedure to outsourcing to gain cost savings, improve resource allocation, and boost your overall security posture.

    Select a Security Outsourcing Partner Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Select a Security Outsourcing Partner Storyboard – A guide to help you determine your requirements and select and manage your security outsourcing partner.

    Our systematic approach will ensure that the correct procedure for selecting a security outsourcing partner is implemented. This blueprint will help you build and implement your security policy program by following our three-phase methodology: determine what to outsource, select the right MSSP, and manage your MSSP.

    • Select a Security Outsourcing Partner – Phases 1-3

    2. MSSP RFP Template – A customizable template to help you choose the right security service provider.

    This modifiable template is designed to introduce consistency and outline key requirements during the request for proposal phase of selecting an MSSP.

    • MSSP RFP Template

    Infographic

    Further reading

    Select a Security Outsourcing Partner

    Outsource the right functions to secure your business.

    Analyst Perspective

    Understanding your security needs and remaining accountable is the key to selecting the right partner.

    The need for specialized security services is fast becoming a necessity to most organizations. However, resource challenges will always mean that organizations will still have to take practical measures to ensure that the time, quality, and service that they require from outsourcing partners have been carefully crafted and packaged to elicit the right services that cover all their needs and requirements.

    Organizations must ensure that security partners are aligned not only with their needs and requirements, but also with the corporate culture. Rather than introducing hindrances to daily operations, security partners must support business goals and protect the organization’s interests at all times.

    And as always, outsource only your responsibilities and do not outsource your accountability, as that will cost you in the long run.

    Photo of Danny Hammond
    Danny Hammond
    Research Analyst
    Security, Risk, Privacy & Compliance Practice
    Info-Tech Research Group

    Executive Summary

    Your Challenge

    A lack of high-skill labor increases the cost of internal security, making outsourcing more appealing.

    A lack of time and resources prevents your organization from being able to enable security internally.

    Due to a lack of key information on the subject, you are unsure which functions should be outsourced versus which functions should remain in-house.

    Having 24/7/365 monitoring in-house is not feasible for most firms.

    There is difficulty measuring the effectiveness of managed security service providers (MSSPs).

    Common Obstacles

    InfoSec leaders will struggle to select the right outsourcing partner without knowing what the organization needs, such as:

    • How to start the process to select the right service provider that will cover your security needs. With so many service providers and technology tools in this field, who is the right partner?
    • Where to obtain guidance on externalization of resources or maintaining internal posture to enable to you confidently select an outsourcing partner.

    InfoSec leaders must understand the business environment and their own internal security needs before they can select an outsourcing partner that fits.

    Info-Tech’s Approach

    Info-Tech’s Select a Security Outsourcing Partner takes a multi-faceted approach to the problem that incorporates foundational technical elements, compliance considerations, and supporting processes:

    • Determine which security responsibilities can be insourced and which should be outsourced, and the right procedure to outsourcing in order to gain cost savings, improve resource allocation, and boost your overall security posture.
    • Understand the current landscape of MSSPs that are available today and the features they offer.
    • Highlight the future financial obligations of outsourcing vs. insourcing to explain which method is the most cost-effective.

    Info-Tech Insight

    Mitigate security risks by developing an end-to-end process that ensures you are outsourcing your responsibilities and not your accountability.

    Your Challenge

    This research is designed to help organizations select an effective security outsourcing partner.

    • A security outsourcing partner is a third-party service provider that offers security services on a contractual basis depending on client needs and requirements.
    • An effective outsourcing partner can help an organization improve its security posture by providing access to more specialized security experts, tools, and technologies.
    • One of the main challenges with selecting a security outsourcing partner is finding a partner that is a good fit for the organization's unique security needs and requirements.
    • Security outsourcing partners typically have access to sensitive information and systems, so proper controls and safeguards must be in place to protect all sensitive assets.
    • Without careful evaluation and due diligence to ensure that the partner is a good fit for the organization's security needs and requirements, it can be challenging to select an outsourcing partner.

    Outsourcing is effective, but only if done right

    • 83% of decision makers with in-house cybersecurity teams are considering outsourcing to an MSP (Syntax, 2021).
    • 77% of IT leaders said cyberattacks were more frequent (Syntax, 2021).
    • 51% of businesses suffered a data breach caused by a third party (Ponemon, 2021).

    Common Obstacles

    The problem with selecting an outsourcing partner isn’t a lack of qualified partners, it’s the lack of clarity about an organization's specific security needs.

    • Most organizations do not have a clear understanding of their current security posture, their security goals, and the specific security services they require. Without a clear understanding of their needs, organizations may struggle to identify a partner that can meet their requirements.
    • Breakdowns and lack of communication can be a significant obstacle, especially when clear lines of communication with partners, including regular check-ins, reporting, and incident response protocols, have not been clearly established.
    • Ensuring that security partner's systems and processes integrate seamlessly with existing systems can be a challenge for most organizations. This is in addition to making sure that security partners have the necessary access and permissions to perform their services effectively.
    • Adhering to security policies is rarely a priority to users, as compliance often feels like an interference to daily workflow. For a lot of organizations, security policies are not having the desired effect.

    A diagram that shows Average cost of a data breach from 2019 to 2022.
    Source: IBM, 2022 Cost of a Data Breach; N=537.


    Reaching an all-time high, the cost of a data breach averaged US$4.35 million in 2022. This figure represents a 2.6% increase from 2021, when the average cost of a breach was US$4.24 million. The average cost has climbed 12.7% since 2020.

    Info-Tech’s methodology for selecting a security outsourcing partner

    Determine your responsibilities

    Determine what responsibilities you can outsource to a service partner. Analyze which responsibilities you should outsource versus keep in-house? Do you require a service partner based on identified responsibilities?

    Scope your requirements

    Refine the list of role-based requirements, variables, and features you will require. Use a well-known list of critical security controls as a framework to determine these activities and send out RFPs to pick the best candidate for your organization.

    Manage your outsourcing program

    Adopt a program to manage your third-party service security outsourcing. Trust your managed security service providers (MSSP) but verify their results to ensure you get the service level you were promised.

    Select a Security Outsourcing Partner

    A diagram that shows your organization responsibilities & accountabilities, framework for selecting a security outsourcing partner, and benefits.

    Blueprint benefits

    IT/InfoSec Benefits

    Reduces complexity within the MSSP selection process by highlighting all the key steps to a successful selection program.

    Introduces a roadmap to clearly educate about the do’s and don’ts of MSSP selection.

    Reduces costs and efforts related to managing MSSPs and other security partners.

    Business Benefits

    Assists with selecting outsourcing partners that are essential to your organization’s objectives.

    Integrates outsourcing into corporate culture, leveraging organizational requirements while maximizing value of outsourcing.

    Reduces security outsourcing risk.

    Insight summary

    Overarching insight: You can outsource your responsibilities but not your accountability.

    Determine what to outsource: Assess your responsibilities to determine which ones you can outsource. It is vital that an understanding of how outsourcing will affect the organization, and what cost savings, if any, to expect from outsourcing is clear in order to generate a list of responsibilities that can/should be outsourced.

    Select the right partner: Create a list of variables to evaluate the MSSPs and determine which features are important to you. Evaluate all potential MSSPs and determine which one is right for your organization

    Manage your MSSP: Align the MSSP to your organization. Adopt a program to monitor the MSSP which includes a long-term strategy to manage the MSSP.

    Identifying security needs and requirements = Effective outsourcing program: Understanding your own security needs and requirements is key. Ensure your RFP covers the entire scope of your requirements; work with your identified partner on updates and adaptation, where necessary; and always monitor alignment to business objectives.

    Measure the value of this blueprint

    Phase

    Purpose

    Measured Value

    Determine what to outsource Understand the value in outsourcing and determining what responsibilities can be outsourced. Cost of determining what you can/should outsource:
    • 120 FTE hours at $90K per year = $5,400
    Cost of determining the savings from outsourcing vs. insourcing:
    • 120 FTE hours at $90K per year = $5,400
    Select the right partner Select an outsourcing partner that will have the right skill set and solution to identified requirements. Cost of ranking and selecting your MSSPs:
    • 160 FTE hours at $90K per year = $7,200
    Cost of creating and distributing RFPs:
    • 200 FTE hours at $90K per year = $9,000
    Manage your third-party service security outsourcing Use Info-Tech’s methodology and best practices to manage the MSSP to get the best value. Cost of creating and implementing a metrics program to manage the MSSP:
    • 80 FTE hours at $90K per year = $3,600

    After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve.

    Overall Impact: 8.9 /10

    Overall Average Cost Saved: $22,950

    Overall Average Days Saved: 9

    Info-Tech offers various levels of support to best suit your needs

    DIY Toolkit
    "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful."

    Guided Implementation
    "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track."

    Workshop
    "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place."

    Consulting
    "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

    Diagnostics and consistent frameworks are used throughout all four options.

    Create a Transparent and Defensible IT Budget

    • Buy Link or Shortcode: {j2store}291|cart{/j2store}
    • member rating overall impact: 9.3/10 Overall Impact
    • member rating average dollars saved: $29,682 Average $ Saved
    • member rating average days saved: 12 Average Days Saved
    • Parent Category Name: Cost & Budget Management
    • Parent Category Link: /cost-and-budget-management
    • IT struggles to gain budget approval year after year, largely driven by a few key factors:
      • For a long time, IT has been viewed as a cost center whose efficiency needs to be increasingly optimized over time. IT’s relationship to strategy is not yet understood or established in many organizations.
      • IT is one of the biggest areas of cost for many organizations. Often, executives don’t understand or even believe that all that IT spending is necessary to advance the organization’s objectives, let alone keep it up and running.

    Our Advice

    Critical Insight

    Internal and external obstacles beyond IT’s control make these challenges with gaining IT budget approval even harder to overcome:

    • Economic pressures can quickly drive IT’s budgetary focus from strategic back to tactical.
    • Corporate-driven categorizations of expenditure, plus disconnected approval mechanisms for capital vs. operational spend, hide key interdependencies and other aspects of IT’s financial reality.
    • Connecting the dots between IT activities and business benefits rarely forms a straight line.

    Impact and Result

    • CIOs need a straightforward way to create and present an approval-ready budget.
      • Info-Tech recognizes that connecting the dots to demonstrate value is key to budgetary approval.
      • Info-Tech also recognizes that key stakeholders require different perspectives on the IT budget.
      • This blueprint provides a framework, method, and templated exemplars for creating and presenting an IT budget to stakeholders that will speed up the approval process and ensure more of it is approved.

    Create a Transparent and Defensible IT Budget Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Create a Transparent and Defensible IT Budget Storyboard – A step-by-step guide to developing a proposed IT budget that’s sensitive to stakeholder perspectives and ready to approve.

    This deck applies Info-Tech’s proven ITFM Cost Model to the IT budgeting process and offers five phases that cover the purpose of your IT budget and what it means to your stakeholders, key budgeting resources, forecasting, selecting and fine-tuning your budget message, and delivering your IT budget executive presentation for approval.

    • Create a Transparent and Defensible IT Budget Storyboard

    2. IT Cost Forecasting and Budgeting Workbook – A structured Excel tool that allows you to forecast your IT budget for next fiscal year across four key stakeholder views, analyze it in the context of past expenditure, and generate high-impact visualizations.

    This Excel workbook offers a step-by-step approach for mapping your historical and forecasted IT expenditure and creating visualizations you can use to populate your IT budget executive presentation.

    • IT Cost Forecasting and Budgeting Workbook

    3. Sample: IT Cost Forecasting and Budgeting Workbook – A completed IT Cost Forecasting & Budgeting Workbook to review and use as an example.

    This sample workbook offers a completed example of the “IT Cost Forecasting and Budgeting Workbook” that accompanies the Create a Transparent & Defensible IT Budget blueprint.

    • Sample: IT Cost Forecasting and Budgeting Workbook

    4. IT Budget Executive Presentation – A PowerPoint template and full example for pulling together your proposed IT budget presentation.

    This presentation template offers a recommended structure for presenting your proposed IT budget for next fiscal year to your executive stakeholders for approval. 

    [infographic]

    Workshop: Create a Transparent and Defensible IT Budget

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Get into budget-starting position

    The Purpose

    Understand your IT budget in the context of your organization and key stakeholders, as well as gather your budgeting data and review previous years’ financial performance.

    Key Benefits Achieved

    Understand your organization’s budget process and culture.

    Understand your stakeholders’ priorities and perspectives regarding your IT budget.

    Gain insight into your historical IT expenditure.

    Set next fiscal year’s IT budget targets.

    Activities

    1.1 Review budget purpose. 

    1.2 Understand stakeholders and approvers.

    1.3 Gather your data.

    1.4 Map and review historical financial performance.

    1.5 Rationalize last year’s variances and set next year's budget targets.

    Outputs

    Budget process and culture assessment.

    Stakeholder alignment assessment and pre-selling strategy.

    Data prepared for next steps.

    Mapped historical expenditure.

    Next fiscal year’s budget targets.

    2 Forecast project CapEx

    The Purpose

    Develop a forecast of next fiscal year’s proposed capital IT expenditure driven by your organization’s strategic projects.

    Key Benefits Achieved

    Develop project CapEx forecast according to the four different stakeholder views of Info-Tech’s ITFM Cost Model.

    Ensure that no business projects that have IT implications (and their true costs) are missed.

    Activities

    2.1 Review the ITFM cost model

    2.2 List projects.

    2.3 Review project proposals and costs.

    2.4 Map and tally total project CapEx.

    2.5 Develop and/or confirm project-business alignment, ROI, and cost-benefit statements.

    Outputs

    Confirmed ITFM cost mdel.

    A list of projects.

    Confirmed list of project proposals and costs.

    Forecasted project-based capital expenditure mapped against the four views of the ITFM Cost Model.

    Projects financials in line.

    3 Forecast non-project CapEx and OpEx

    The Purpose

    Develop a forecast of next fiscal year’s proposed “business as usual” non-project capital and operating IT expenditure.

    Key Benefits Achieved

    Develop non-project CapEx and non-project OpEx forecasts according to the four different stakeholder views of Info-Tech’s ITFM Cost Model.

    Make “business as usual” costs fully transparent and rationalized.

    Activities

    3.1 Review non-project capital and costs. 

    3.2 Review non-project operations and costs.

    3.3 Map and tally total non-project CapEx and OpEx.

    3.4 Develop and/or confirm proposed expenditure rationales.

    Outputs

    Confirmation of non-project capital and costs.

    Confirmation of non-project operations and costs.

    Forecasted non-project-based capital expenditure and operating expenditure against the four views of the ITFM Cost Model.

    Proposed expenditure rationales.

    4 Finalize budget and develop presentation

    The Purpose

    Aggregate and sanity-check your forecasts, harden your rationales, and plan/develop the content for your IT budget executive presentation.

    Key Benefits Achieved

    Create a finalized proposed IT budget for next fiscal year that offers different views on your budget for different stakeholders.

    Select content for your IT budget executive presentation that will resonate with your stakeholders and streamline approval.

    Activities

    4.1 Aggregate forecast totals and sanity check.

    4.2 Generate graphical outputs and select content to include in presentation.

    4.3 Fine-tune rationales.

    4.4 Develop presentation and write commentary.

    Outputs

    Final proposed IT budget for next fiscal year.

    Graphic outputs selected for presentation.

    Rationales for budget.

    Content for IT Budget Executive Presentation.

    5 Next steps and wrap-up (offsite)

    The Purpose

    Finalize and polish the IT budget executive presentation.

    Key Benefits Achieved

    An approval-ready presentation that showcases your business-aligned proposed IT budget backed up with rigorous rationales.

    Activities

    5.1 Complete in-progress deliverables from previous four days.

    5.2 Set up review time for workshop deliverables and to discuss next steps.

    Outputs

    Completed IT Budget Executive Presentation.

    Review scheduled.

    Further reading

    Create a Transparent and Defensible IT Budget

    Build in approvability from the start.

    EXECUTIVE BRIEF

    Analyst Perspective

    A budget’s approvability is about transparency and rationale, not the size of the numbers.

    Jennifer Perrier.

    It’s that time of year again – budgeting. Most organizations invest a lot of time and effort in a capital project selection process, tack a few percentage points onto last year’s OpEx, do a round of trimming, and call it a day. However, if you want to improve IT financial transparency and get your business stakeholders and the CFO to see the true value of IT, you need to do more than this.

    Yourcrea IT budget is more than a once-a-year administrative exercise. It’s an opportunity to educate, create partnerships, eliminate nasty surprises, and build trust. The key to doing these things rests in offering a range of budget perspectives that engage and make sense to your stakeholders, as well as providing iron-clad rationales that tie directly to organizational objectives.

    The work of setting and managing a budget never stops – it’s a series of interactions, conversations, and decisions that happen throughout the year. If you take this approach to budgeting, you’ll greatly enhance your chances of creating and presenting a defensible annual budget that gets approved the first time around.

    Jennifer Perrier
    Principal Research Director
    IT Financial Management Practice
    Info-Tech Research Group

    Executive Summary

    Your Challenge

    Common Obstacles

    Info-Tech’s Approach

    IT struggles to gain budget approval year after year, largely driven by a few key factors:

    • For a long time, IT has been viewed as a cost center whose efficiency needs to be increasingly optimized over time. IT’s relationship to strategy is not yet understood or established in many organizations.
    • IT is one of the biggest areas of cost for many organizations. Often, executives don’t understand, or even believe, that all that IT spending is necessary to advance the organization’s objectives, let alone keep it running.

    Internal and external obstacles beyond IT’s control make these challenges even harder to overcome:

    • Economic pressures can quickly drive IT’s budgetary focus from strategic back to tactical.
    • Corporate-driven categorizations of expenditure, plus disconnected approval mechanisms for capital vs. operational spend, hide key interdependencies and other aspects of IT’s financial reality.
    • Connecting the dots between IT activities and business benefits rarely forms a straight line.

    CIOs need a straightforward way to create and present an approval-ready budget.

    • Info-Tech recognizes that connecting the dots to demonstrate value is key to budgetary approval.
    • Info-Tech also recognizes that key stakeholders require different perspectives on the IT budget.
    • This blueprint provides a framework, method, and templated exemplars for creating and presenting an IT budget to stakeholders. It will speed the approval process and ensure more of it is approved.

    Info-Tech Insight
    CIOs need a straightforward way to create and present an approval-ready IT budget that demonstrates the value IT is delivering to the business and speaks directly to different stakeholder priorities.

    IT struggles to get budgets approved due to low transparency and failure to engage

    Capability challenges

    Administrative challenges

    Operating challenges

    Visibility challenges

    Relationship challenges

    IT is seen as a cost center, not an enabler or driver of business strategy.

    IT leaders are not seen as business leaders.

    Economic pressures drive knee-jerk redirection of IT’s budgetary focus from strategic initiatives back to operational tactics.

    The vast majority of IT’s
    real-life expenditure is in the form of operating expenses i.e. keeping the lights on.

    Most business leaders don’t know how many IT resources their business units are really consuming.

    Other departments in the organization see IT as a competitor for funding, not a business partner.

    Lack of transparency

    IT and the business aren’t speaking the same language.

    IT leaders don’t have sufficient access to information about, or involvement in, business decisions and objectives.

    Outmoded finance department expenditure categorizations don’t accommodate IT’s real cost categories.

    IT absorbs unplanned spend because business leaders don’t realize or consider the impact of their decisions on IT.

    The business doesn’t understand what IT is, what it does, or what it can offer.

    IT and the business don’t have meaningful conversations about IT costs, opportunities, or investments.

    Defining and demonstrating the value of IT and its investments isn’t straightforward.

    IT leaders may not have the financial literacy or acumen needed to translate IT activities and needs into business terms.

    CapEx and OpEx approval and tracking mechanisms are handled separately when, in reality, they’re highly interdependent.

    IT activities usually have an indirect relationship with revenue, making value calculations more complicated.

    Much of IT, especially infrastructure, is invisible to the business and is only noticed if it’s not working.

    The relationship between IT spending and how it supports achievement of business objectives is not clear.

    Reflect on the numbers…

    The image contains a screenshot of five graphs. The graphs depict Cost and budget management, Cost optimization, Business value, perception of improvement, and intensity of business frustration.

    To move forward, first you need to get unstuck

    Today’s IT budgeting challenges have been growing for a long time. Overcoming these challenges means untangling yourself from the grip of the root causes.

    Principle 1:
    IT and the business are fighting diverging forces. Technology has changed monumentally, while financial management hasn’t changed much at all.

    Principle 2:
    Different stakeholders have different perspectives on your IT budget. Learn and acknowledge what’s important to them so that you can potentially deliver it.

    Principle 3:
    Connecting the dots to clearly demonstrate IT’s value to the organization is the key to budgetary approval. But those connected dots don’t always result in a straight line.

    The three principles above are all about IT’s changing relationship to the business. IT leaders need a systematic and repeatable approach to budgeting that addresses these principles by:

    • Clearly illustrating the alignment between the IT budget and business objectives.
    • Showing stakeholders the overall value that IT investment will bring them.
    • Demonstrating where IT is already realizing efficiencies and economies of scale.
    • Gaining consensus on the IT budget from all parties affected by it.

    “The culture of the organization will drive your success with IT financial management.”

    – Dave Kish, Practice Lead, IT Financial Management Practice, Info-Tech Research Group

    Info-Tech’s approach

    CIOs need a straightforward way to convince approval-granting CFOs, CEOs, boards, and committees to spend money on IT to advance the organization’s strategies.

    IT budget approval cycle

    The image contains a screenshot of the IT budget approval cycle.

    The Info-Tech difference:

    This blueprint provides a framework, method, and templated exemplars for building and presenting your IT budget to different stakeholders. These will speed the approval process and ensure that a higher percentage of your proposed spend is approved.

    Info-Tech’s methodology for how to create a transparent and defensible it budget

    1. Lay Your Foundation

    2. Get Into Budget-Starting Position

    3. Develop Your Forecasts

    4. Build Your Proposed Budget

    5. Create and Deliver Your Budget Presentation

    Phase steps

    1. Understand budget purpose
    2. Know your stakeholders
    3. Continuously pre-sell your budget
    1. Gather your data
    2. Review historical performance
    3. Set budget goals
    1. Develop alternate scenarios
    2. Develop project CapEx forecasts
    3. Develop non-project CapEx and OpEx forecasts
    1. Aggregate your forecasts
    2. Stress-test your forecasts
    3. Challenge and perfect your rationales
    1. Plan your presentation content
    2. Build your budget presentation
    3. Present, finalize, and submit your budget

    Phase outcomes

    An understanding of your stakeholders and what your IT budget means to them.

    Information and goals for planning next fiscal year’s IT budget.

    Completed forecasts for project and non-project CapEx and OpEx.

    A final IT budget for proposal including scenario-based alternatives.

    An IT budget presentation.

    Insight summary

    Overarching insight: Create a transparent and defensible IT budget

    CIOs need a straightforward way to create and present an approval-ready IT budget that demonstrates the value IT is delivering to the business and speaks directly to different stakeholder priorities.

    Phase 1 insight: Lay your foundation

    IT needs to step back and look at it’s budget-creation process by first understanding exactly what a budget is intended to do and learning what the IT budget means to IT’s various business stakeholders.

    Phase 2 Insight: Get into budget-starting position

    Presenting your proposed IT budget in the context of past IT expenditure demonstrates a pattern of spend behavior that is fundamental to next year’s expenditure rationale.

    Phase 3 insight: Develop your forecasts

    Forecasting costs according to a range of views, including CapEx vs. OpEx and project vs. non-project, and then positioning it according to different stakeholder perspectives, is key to creating a transparent budget.

    Phase 4 insight: Build your proposed budget

    Fine-tuning and hardening the rationales behind every aspect of your proposed budget is one of the most important steps for facilitating the budgetary approval process and increasing the amount of your budget that is ultimately approved.

    Phase 5 insight: Create and deliver your budget presentation

    Selecting the right content to present to your various stakeholders at the right level of granularity ensures that they see their priorities reflected in IT’s budget, driving their interest and engagement in IT financial concerns.

    Blueprint deliverables

    Each step of this blueprint is accompanied by supporting deliverables to help you accomplish your goals:

    IT Cost Forecasting and Budgeting Workbook

    This Excel tool allows you to capture and work through all elements of your IT forecasting from the perspective of multiple key stakeholders and generates compelling visuals to choose from to populate your final executive presentation.

    The image contains a screenshot of the IT Cost Forecasting and Budgeting Workbook.

    Also download this completed sample:

    Sample: IT Cost Forecasting and Budgeting Workbook

    Key deliverable

    IT Budget Executive Presentation Template

    Phase 5: Create a focused presentation for your proposed IT budget that will engage your audience and facilitate approval.

    The image contains a screenshot of the IT Budget Executive Presentation Template.

    Blueprint benefits

    IT benefits

    Business benefits

    • Improve IT’s overall financial management capability.
    • Streamline the administration of annual IT budget development.
    • Legitimize the true purpose and value of IT operations and associated expenditure.
    • Create visibility on the part of both IT and the business into IT’s mandate, what needs to be in place, and what it costs to fund it.
    • Foster better relationships with business stakeholders by demonstrating IT’s business and financial competency, working in partnership with business leaders on IT investment decisions, and building mutual trust.
    • Better understand the different types of expenditure occurring in IT, including project CapEx, non-project CapEx, and non-project OpEx.
    • Gain insight into the relationship between one-time CapEx on ongoing OpEx and its ramifications.
    • See business priorities and concerns clearly reflected in IT’s budget down to the business-unit level.
    • Receive thorough return on investment calculations and cost-benefit analyses for all aspects of IT expenditure.
    • Understand the direct relationship between IT expenditure and the depth, breadth, and quality of IT service delivery to the business.

    Measure the value of this blueprint

    Ease budgetary approval and improve its accuracy.

    Near-term goals

    • Percentage of budget approved: Target 95%
    • Percentage of IT-driven projects approved: Target 100%
    • Number of iterations/re-drafts required to proposed budget: One iteration

    Long-term goal

    • Variance in budget vs. actuals: Actuals less than budget and within 2%

    In Phases 1 and 2 of this blueprint, we will help you understand what your approvers are looking for and gather the right data and information.

    In Phase 3, we will help you forecast your IT costs it terms of four stakeholder views so you can craft a more meaningful IT budget narrative.

    In Phases 4 and 5, we will help you build a targeted presentation for your proposed IT budget.

    Value you will receive:

    1. Increased forecast accuracy through using a sound cost-forecasting methodology.
    2. Improved budget accuracy by applying more thorough and transparent techniques.
    3. Increased budget transparency and completeness by soliciting input earlier and validating budgeting information.
    4. Stronger alignment between IT and enterprise goals through building a better understanding of the business values and using language they understand.
    5. A more compelling budget presentation by offering targeted, engaging, and rationalized information.
    6. A faster budgeting rework process by addressing business stakeholder concerns the first time.

    An analogy…

    “A budget isn’t like a horse and cart – you can’t get in front of it or behind it like that. It’s more like a river…

    When developing an annual budget, you have a good idea of what the OpEx will be – last year’s with an annual bump. You know what that boat is like and if the river can handle it.

    But sometimes you want to float bigger boats, like capital projects. But these boats don’t start at the same place at the same time. Some are full of holes. And does your river even have the capacity to handle a boat of that size?

    Some organizations force project charters by a certain date and only these are included in the following year’s budget. The project doesn’t start until 8-12 months later and the charter goes stale. The river just can’t float all these boats! It’s a failed model. You have to have a great governance processes and clear prioritization so that you can dynamically approve and get boats on the river throughout the year.”

    – Mark Roman, Managing Partner, Executive Services,
    Info-Tech Research Group and Former Higher Education CIO

    Info-Tech offers various levels of support to best suit your needs

    DIY Toolkit

    “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

    Guided Implementation

    “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

    Workshop

    “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

    Consulting

    “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

    Diagnostics and consistent frameworks used throughout all four options

    Guided Implementation

    Phase 1: Lay Your Foundation

    Phase 2: Get Into Budget-Starting Position

    Phase 3: Develop Your Forecasts

    Phase 4: Build Your Proposed Budget

    Phase 5: Create and Deliver Your Budget Presentation

    Call #1: Discuss the IT budget, processes, and stakeholders in the context of your unique organization.

    Call #2: Review data requirements for transparent budgeting.

    Call #3: Set budget goals and process improvement metrics.

    Call #4: Review project CapEx forecasts.

    Call #5: Review non-project CapEx and OpEx forecasts.

    Call #6: Review proposed budget logic and rationales.

    Call #7: Identify presentation inclusions and exclusions.

    Call #8: Review final budget presentation.

    A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

    A typical GI is 8 to 12 calls over the course of 4 to 6 months.

    Workshop Overview

    Contact your account representative for more information.
    workshops@infotech.com 1-888-670-8889

    Day 1 Day 2 Day 3 Day 4 Day 5

    Get into budget-starting position

    Forecast project CapEx

    Forecast non-project CapEx and OpEx

    Finalize budget and develop presentation

    Next Steps and
    Wrap-Up (offsite)

    Activities

    1.1 Review budget purpose.

    1.2 Understand stakeholders and approvers.

    1.3 Gather your data.

    1.4 Map and review historical financial performance.

    1.5 Rationalize last year’s variances.

    1.5 Set next year’s budget targets.

    2.1 Review the ITFM Cost Model.

    2.2 List projects.

    2.3 Review project proposals and costs.

    2.4 Map and tally total project CapEx.

    2.5 Develop and/or confirm project-business alignment, ROI, and cost-benefit statements.

    3.1 Review non-project capital and costs.

    3.2 Review non-project operations and costs.

    3.3 Map and tally total non-project CapEx and OpEx.

    3.4 Develop and/or confirm proposed expenditure rationales.

    4.1 Aggregate forecast totals and sanity check.

    4.2 Generate graphical outputs and select content to include in presentation.

    4.3 Fine-tune rationales.

    4.4 Develop presentation and write commentary.

    5.1 Complete in-progress deliverables from previous four days.

    5.2 Set up review time for workshop deliverables and to discuss next steps.

    Deliverables

    1. Budget process and culture assessment.
    2. Stakeholder alignment assessment and pre-selling strategy.
    3. Mapped historical expenditure.
    4. Next fiscal year’s budget targets.
    1. Forecasted project-based capital expenditure mapped against the four views of the ITFM Cost Model.
    1. Forecasted non-project-based capital expenditure and operating expenditure against the four views of the ITFM Cost Model.
    1. Final proposed IT budget for next fiscal year.
    2. Plan and build content for IT Budget Executive Presentation.
    1. Completed IT Budget Executive Presentation.

    Phase 1

    Lay Your Foundation

    Lay Your
    Foundation

    Get Into Budget-Starting Position

    Develop Your
    Forecasts

    Build Your
    Proposed Budget

    Create and Deliver Your Presentation

    1.1 Understand what your budget is
    and does

    1.2 Know your stakeholders

    1.3 Continuously pre-sell your budget

    2.1 Assemble your resources

    2.2 Understand the four views of the ITFM Cost Model

    2.3 Review last year’s budget vs.
    actuals and five-year historical trends

    2.4 Set your high-level goals

    3.1 Develop assumptions and
    alternative scenarios

    3.2 Forecast your project CapEx

    3.3 Forecast your non-project CapEx and OpEx

    4.1 Aggregate your numbers

    4.2 Stress test your forecasts

    4.3 Challenge and perfect your
    rationales

    5.1 Plan your content

    5.2 Build your presentation

    5.3 Present to stakeholders

    5.4 Make final adjustments and submit your IT budget

    This phase will walk you through the following activities:

    • Seeing your budget as a living governance tool
    • Understanding the point of view of different stakeholders
    • Gaining tactics for setting future IT spend expectations

    This phase involves the following participants:

    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Lay Your Foundation

    Before starting any process, you need to understand exactly why you’re doing it.

    This phase is about understanding the what, why, and who of your IT budget.

    • Understand what your budget is and does. A budget isn’t just an annual administrative event – it’s an important governance tool. Understand exactly what a budget is and your budgetary accountabilities as an IT leader.
    • Know your stakeholders. The CFO, CEO, and CXOs in your organization have their own priorities, interests, and professional mandates. Get to know what their objectives are and what IT’s budget means to them.
    • Continuously pre-sell your budget. Identifying, creating, and capitalizing on opportunities to discuss your budget well in advance of its formal presentation will get influential stakeholders and approvers on side, foster collaborations, and avoid unpleasant surprises on all fronts.

    “IT finance is more than budgeting. It’s about building trust and credibility in where we’re spending money, how we’re spending money. It’s about relationships. It’s about financial responsibility, financial accountability. I rely on my entire leadership team to all understand what their spend is. We are a steward of other people’s money.”

    – Rick Hopfer, CIO, Hawaii Medical Service Association

    What does your budget actually do?

    A budget is not just a painful administrative exercise that you go through once a year.

    Most people know what a budget is, but it’s important to understand its true purpose and how it’s used in your organization before you engage in any activity or dialogue about it.

    In strictly objective terms:

    • A budget is a calculated estimate of income vs. expenditure for a period in the future, often one year. Basically, it’s an educated guess about how much money will come into a business entity or unit and how much money will go out of it.
    • A balanced budget is where income and expenditure amounts are equal.
    • The goal in most organizations is for the income component of the budget to match or exceed the expenditure component.
      If it doesn’t, this results in a deficit that may lead to debt.

    Simply put, a budget’s fundamental purpose is to plan and communicate how an organization will avoid deficit and debt and remain financially viable while meeting its various accountabilities and responsibilities to its internal and external stakeholders.

    “CFOs are not thinking that they want to shut down IT spend. Nobody wants to do that. I always looked at things in terms of revenue streams – where the cash inflow is coming from, where it’s going to, and if I can align my cash outflows to my revenue stream. Where I always got suspicious as a CFO is if somebody can’t articulate spending in terms of a revenue stream. I think that’s how most CFOs operate.”

    – Carol Carr, Technical Counselor,
    Info-Tech Research Group and Former CFO

    Put your IT budget in context

    Your IT budget is just one of several budgets across your organization that, when combined, create an organization-wide budget. In this context, IT’s in a tough spot.

    It’s a competition: The various units in your organization are competing for the biggest piece they can get of the limited projected income pie. It’s a zero-sum game. The organization’s strategic and operational priorities will determine how this projected income is divvied up.

    Direct-to-revenue units win: Business units that directly generate revenue often get bigger relative percentages of the organizational budget since they’re integral to bringing in the projected income part of the budget that allows the expenditure across all business units to happen in the first place.

    Indirect-to-revenue units lose: Unlike sales units, for example, IT’s relationship to projected income tends to be indirect, which means that IT must connect a lot more dots to illustrate its positive impact on projected income generation.

    In financial jargon, IT really is a cost center: This indirect relationship to revenue also explains why the focus of IT budget conversations is usually on the expenditure side of the equation, meaning it doesn’t have a clear positive impact on income.

    Contextual metrics like IT spend as a percentage of revenue, IT OpEx as a percentage of organizational OpEx, and IT spend per organizational employee are important baseline metrics to track around your budget, internally benchmark over time, and share, in order to illustrate exactly where IT fits into the broader organizational picture.

    Budgeting isn’t a once-a-year thing

    Yet, many organizations treat it like a “one and done” point of annual administration. This is a mistake that misses out on the real benefits of budgeting.

    Many organizations have an annual budgeting and planning event that takes place during the back half of the fiscal year. This is where all formal documentation around planned projects and proposed spend for the upcoming year is consolidated, culminating in final presentation, adjustment, and approval. It’s basically a consolidation and ranking of organization-wide priorities at the highest level.

    If things are running well, this culmination point in the overall budget development and management process is just a formality, not the beginning, middle, and end of the real work. Ideally:

    • Budgets are actually used: The whole organization uses budgets as tools to actively manage day-to-day operations and guide decision making throughout the year in alignment with priorities as opposed to something that’s put on a shelf or becomes obsolete within a few months.
    • Interdependencies are evident: No discrete area of spend focus is an island – it’s connected directly or indirectly with other areas of spend, both within IT and across the organization. For example, one server interacts with multiple business applications, IT and business processes, multiple IT staff, and even vendors or external managed service providers. Cost-related decisions about that one server – maintain, repurpose, consolidate, replace, discard – will drive other areas of spend up or down.
    • There are no surprises: While this does happen, your budget presentation isn’t a great time to bring up a new point of significant spend for the first time. The items in next year’s proposed budget should be priorities that are already known, vetted, supported, and funded.

    "A well developed and presented budget should be the numeric manifestation of your IT strategy that’s well communicated and understood by your peers. When done right, budgets should merely affirm what’s already been understood and should get approved with minimal pushback.“

    – Patrick Gray, TechRepublic, 2020

    Understand your budgetary responsibilities as the IT leader

    It’s in your job description. For some stakeholders, it’s the most important part of it.

    While not a contract per se, your IT budget is an objective and transparent statement made in good faith that shows:

    • You know what it takes to keep the organization viable.
    • You understand the organization’s accountabilities and responsibilities as well as those of its leaders.
    • You’re willing and able to do your part to meet these accountabilities and responsibilities.
    • You know what your part of this equation is, as well as what parts should and must be played by others.

    When it comes to your budget (and all things financial), your job is to be ethical, careful, and wise:

    1. Be honest. Business ethics matter.
    2. Be as accurate as possible. Your expenditure predictions won’t be perfect, but they need to be best-effort and defensible.
    3. Respect the other players. They have their own roles, motivations, and mandates. Accept and respect these by being a supporter of their success instead of an obstacle to them achieving it.
    4. Connect the dots to income. Always keep the demonstration of business value in your sights. Often, IT can’t draw a straight line to income, but demonstrating how IT expenditure supports and benefits future, current, and past (but still relevant) business goals and strategies, which in turn affect income, is the best course.
    5. Provide alternatives. There are only so many financial levers your organization can pull. An action on one lever will have wanted and unwanted consequences on another. Aim to put financial discussions in terms of risk-focused “what if” stories and let your business partners decide if those risks are satisfactory.

    Budgeting processes tend to be similar – it’s budgeting cultures that drive differences

    The basic rules of good budgeting are the same everywhere. Bad budgeting processes, however, are usually caused by cultural factors and can be changed.

    What’s the same everywhere…

    What’s unchangeable…

    What’s changeable…

    For right or wrong, most budgeting processes follow these general steps:

    There are usually only three things about an organization’s budgeting process that are untouchable and can’t be changed:

    Budgeting processes are rarely questioned. It never occurs to most people to challenge this system, even if it doesn’t work. Who wants to challenge the CFO? No one.

    Review your organization’s budgeting culture to discover the negotiable and non-negotiable constraints. Specifically, look at these potentially-negotiable factors if they’re obstacles to IT budgeting success:

    1. Capital project vetting and selection for the next fiscal year starts three-to-six months before the end of the current fiscal year.
    2. Operational expenditure, including salaries, is looked at later with much less formality and scrutiny with an aim to cut.
    3. Each business unit does a budget presentation and makes directed amendments (usually trimming).
    4. The approved budget numbers are plugged into a standard, sub-optimal budget template provided by Finance.
    1. The legal and regulatory mandates that govern financial funding, accounting, and reporting practices. These are often specific to industries and spend types.
    2. The accounting rules your organization follows, such as GAAP, or IFRS. These too may be legally mandated for government entities and publicly-traded companies.
    3. Hard limits on the projected available income the CFO has to distribute.
    • Timeframes and deadlines
    • Order of operations
    • Areas of focus (CapEx vs. OpEx)
    • Funding sources and ownership
    • Review/approval mechanisms
    • Templates and tools

    1.1 Review your budgeting process and culture

    1 hour

    1. Review the following components of your budget process using the questions provided for each as a guideline.
      1. Legal and regulatory mandates. What are the external rules that govern how we do financial tracking and reporting? How do they manifest in our processes?
      2. Accounting rules used. What rules does our finance department use and why? Do these rules allow for more meaningful representations of IT spend? Are there policies or practices in place that don’t appear to be backed by any external standards?
      3. Timeframes and deadlines. Are we starting the budgeting process too late? Do we have enough time to do proper due diligence? Will expenditures approved now be out of date when we go to execute? Are there mechanisms to update spend plans mid-cycle?
      4. Order of operations. What areas of spend do we always look at first, such as CapEx? Are there any benefits to changing the order in which we do things, such as examining OpEx first?
      5. Areas of focus. Is CapEx taking up most of our budgeting cycle time? Are we spending enough time examining OpEx? Is IT getting enough time from the CFO compared to other units?
      6. Funding sources and ownership. Is IT footing most of the technology bills? Are business unit leaders fronting any technology business case pitches? Is IT appropriately included in business case development? Is there any benefit to implementing show-back or charge-back?
      7. Review/approval mechanisms. Are strategies and priorities used to rank proposed spend clear and well communicated? Are spend approvers objective in their decision making? Do different approvers apply the same standards and tools?
      8. Templates and tools. Are the ones provided by Finance, the PMO, and other groups sufficient to document what we need to document? Are they accessible and easy to use? Are they automated and integrated so we only have to enter data once?
    2. On the slide following these activity instructions, rate how effective each of the above is on a scale of 1-10 (where 10 is very effective) in supporting the budgeting process. Note specific areas of challenge and opportunity for change.

    1.1 Review your budgeting process and culture

    Input Output Materials Participants
    • Organizational knowledge of typical budgeting processes
    • Copies of budgeting policies, procedures, and tools
    • Rated assessment of your organization’s budget process and culture, as well as major areas of challenge and opportunity for change
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Budget process and culture assessment

    Document the outcomes of your assessment. Examples are provided below.

    Budgeting area of assessment

    Rating

    1 = very ineffective

    10 = very effective

    Challenges

    Opportunities for change

    Legal and regulatory mandates

    7

    Significant regulation but compliance steps not clear or supported within departments.

    Create, communicate, and train management on compliance procedures and align the financial management tools accordingly.

    Accounting rules

    6

    IT not very familiar with them.

    Learn more about them and their provisions to see if IT spend can be better represented.

    Timeframes and deadlines

    5

    Finalize capital project plans for next fiscal four months before end of current fiscal.

    Explore flexible funding models that allow changes to budget closer to project execution.

    Order of operations

    3

    Setting CapEx before OpEx leads to paring of necessary OpEx based on CapEx commitments.

    Establish OpEx first as a baseline and then top up to target budget with CapEx.

    Areas of focus

    6

    Lack of focus on OpEx means incremental budgeting – we don’t know what’s in there.

    Perform zero-based budgeting on OpEx every few years to re-rationalize this spend.

    Funding sources and ownership

    4

    IT absorbing unplanned mid-cycle spend due to impact of unknown business actions.

    Implement a show-back mechanism to change behavior or as precursor to limited charge-back.

    Review/approval mechanisms

    8

    CFO is fair and objective with information presented but could demand more evidence.

    Improve business sponsorship/fronting of new initiative business cases and IT partnership.

    Templates and tools

    2

    Finance budget template largely irrelevant and unreflective of IT: only two relevant categories.

    Adjust account buckets over a period of time, starting with SW/HW and cloud breakouts.

    Receptive audiences make communication a lot easier

    To successfully communicate anything, you need to be heard and understood.

    The key to being heard and understood is first to hear and understand the perspective of the people with whom you’re trying to communicate – your stakeholders. This means asking some questions:

    • What context are they operating in?
    • What are their goals and responsibilities?
    • What are their pressures and stresses?
    • How do they deal with novelty and uncertainty?
    • How do they best take in information and learn?

    The next step of this blueprint shows the perspectives of IT’s key stakeholders and how they’re best able to absorb and accept the important information contained in your IT budget. You will:

    • Learn a process for discovering these stakeholders’ IT budget information needs within the context of your organization’s industry, goals, culture, organizational structure, personalities, opportunities, and constraints.
    • Document key objectives and messages when communicating with these various key stakeholders.

    There are certain principles, mandates, and priorities that drive your stakeholders; they’ll want to see these reflected in you, your work, and your budget.

    Your IT budget means different things to different stakeholders

    Info-Tech’s ITFM Cost Model lays out what matters most from various points of view.

    The image contains a screenshot of Info-Tech's ITFM Cost Model.

    The CFO: Understand their role

    The CFO is the first person that comes to mind in dealing with budgets. They’re personally and professionally on the line if anything runs amiss with the corporate purse.

    What are the CFO’s role and responsibilities?

    • Tracking cash flow and balancing income with expenditures.
    • Ensuring fiscal reporting and legal/regulatory compliance.
    • Working with the CEO to ensure financial-strategic alignment.
    • Working with business unit heads to set aligned budgets.
    • Seeing the big picture.

    What’s important to the CFO?

    • Costs
    • Benefits
    • Value
    • Analysis
    • Compliance
    • Risk Management
    • Strategic alignment
    • Control
    • Efficiency
    • Effectiveness
    • Reason
    • Rationale
    • Clarity
    • Objectivity
    • Return on investment

    “Often, the CFO sees IT requests as overhead rather than a need. And they hate increasing overhead.”

    – Larry Clark, Executive Counselor, Info-Tech Research Group and Former CIO

    The CFO carries big responsibilities focused on mitigating organizational risks. It’s not their job to be generous or flexible when so much is at stake. While the CEO appears higher on the organizational chart than the CFO, in many ways the CFO’s accountabilities and responsibilities are on par with, and in some cases greater than, those of the CEO.

    The CFO: What they want from the IT budget

    What they need should look familiar, so do your homework and be an open book.

    Your CFO’s IT budget to-do list:

    Remember to:

    • A review of the previous year financial performance. This demonstrates to the CFO your awareness, savvy, and overall competence in the financial management realm. This is also your opportunity to start laying out the real-life context within which IT has been operating. Information to show includes:
      • Budget vs. actuals, including an overview of factors that led to major variances.
      • Percentage difference in proposed budget versus previous year’s budget, and major contributing factors to those differences (i.e. unanticipated projects, changes, or events).
    • Presentation of information according to Finance’s existing categories. This makes it as easy as possible for them to plug your numbers into their system.
    • Separate views of overall workforce vs. overall vendor spending. This is a traditional view.
    • Separate views of capital expenditure (CapEx) and operating expenditure (OpEx). This also includes information on expected lifespan of proposed new capital assets to inform depreciation/amortization decisions.
    • Explanation of anticipated sources of funding. Specifically, indicate whether the funding required is a brand-new net increase or a reallocation from the existing pool.
    • Details (upon request). Have these available for every aspect of your proposed budget.
    • Avoid being flashy. Exclude proposed expenditures with a lot of bells and whistles that don’t directly tie to concrete business objectives.
    • Be a conservationist. Show how you plan to re-use or extend assets that you already have.
    • Act like a business leader. Demonstrate your understanding of near-term (12-month) realities, priorities, and goals.
    • Think like them. Present reliable and defensible calculations of benefits versus risks as well as projected ROI for major areas of new or different spending.

    The CFO: Budget challenges and opportunities

    Budget season is a great time to start changing the conversation and building trust.

    Potential challenges

    Low trust

    Poor financial literacy and historical sloppiness among business unit leaders means that a CFO may come into budget conversations with skepticism. This can put them on the offensive and put you on the defensive. You have to prove yourself.

    Competition

    You’re not the only department the CFO is dealing with. Everyone is competing for their piece of the pie, and some business unit leaders are persistent. A good CFO will stay out of the politics and not be swayed by sweet talk, but it can be an exhausting experience for them.

    Mismatched buckets

    IT’s spend classes and categories probably won’t match what’s in Finance’s budget template or general ledger. Annual budgeting isn’t the best time to bring this up. Respect Finance’s categories, but plan to tackle permanent changes at a less busy time.

    Potential opportunities

    Build confidence

    Engaging in the budgeting process is your best chance to demonstrate your knowledge about the business and your financial acumen. The more that the CFO sees that you get it and are taking it seriously, the more confidence and trust they’ll have in you.

    Educate

    The CFO will not know as much as you about the role technology could and should play in the organization. Introduce new language around technology focused on capabilities and benefits. This will start to shift the conversation away from costs and toward value.

    Initiate alignment

    An important governance objective is to change the way IT expenditure is categorized and tracked to better reveal and understand what’s really happening. This process should be done gradually over time, but definitely communicate what you want to do and why.

    The CXO: Understand their role

    CXOs are a diverse group who lead a range of business functions including admin, operations, HR, legal, production, sales and service, and marketing, to name a few.

    What are the CXO’s role and responsibilities?

    Like you, the CXO’s job is to help the organization realize its goals and objectives. How each CXO does this is specific to the domain they lead. Variations in roles and responsibilities typically revolve around:

    • Law and regulation. Some functions have compliance as a core mandate, including legal, HR, finance, and corporate risk groups.
    • Finance and efficiency. Other functions prioritize time, money, and process such as finance, sales, customer service, marketing, production, operations, and logistics units.
    • Quality. These functions prioritize consistency, reliability, relationship, and brand such as production, customer service, and marketing.

    What’s important to the CXO?

    • Staffing
    • Skills
    • Reporting
    • Funding
    • Planning
    • Performance
    • Predictability
    • Customers
    • Visibility
    • Inclusion
    • Collaboration
    • Reliability
    • Information
    • Knowledge
    • Acknowledgement

    Disagreement is common between business-function leaders – they have different primary focus areas, and conflict and misalignment are natural by-products of that fact. It’s also hard to make someone care as much about your priorities as you do. Focus your efforts on sharing and partnering, not converting.

    The CXO: What they want from the IT budget

    Focus on their unique part of the organization and show that you see them.

    Your CXO’s IT budget to-do list:

    Remember to:

    • A review of the previous year’s IT expenditure on the business function. This includes:
      • Budget vs. actuals (if available) for the business function, and overview of any situations or factors that led to major variances.
      • Percentage difference in proposed budget for that business function vs. the previous year’s spend, and major contributing factors to those differences, i.e. unanticipated projects, changes, or events.
      • Last year’s IT expenditure per business function employee vs. proposed IT expenditure per business function employee (if available). This is a good metric to use going forward as it’s a fair comparative internal benchmark.
    • Separate views of proposed IT workforce vs. proposed IT vendor spending for the business function. Do a specific breakout of proposed expenditure for the major applications that business unit explicitly uses.
    • Separate views of proposed IT capital expenditure (CapEx) and proposed IT operating expenditure (OpEx) for the business function. Show breakdowns for each capital project,
      as well as summaries for their core applications and portion of shared IT services.
    • Celebrate any collaborative wins from last year. You want to reinforce that working together is in both of your best interests and you’d like to keep it going.
    • Get to the apps fast. Apps are visible, concrete, and relatable – this is what the CXO cares about. Core IT infrastructure, on the other hand, is technobabble about something that’s invisible, boring, and disengaging for most CXOs.
    • Focus on the business function’s actual technology needs and consumption. Show them where they stand in relation to others. This will get their attention and serve as an opportunity to provide some education.

    The CXO: Budget challenges and opportunities

    Seek out your common ground and be the solution for their real problems.

    Potential challenges

    Different priorities

    Other business unit leaders will have bigger concerns than your IT budget. They have their own budget to figure out plus other in-flight issues. The head of sales, for instance, is going to be more concerned with hitting sales goals for this fiscal year than planning for next.

    Perceived irrelevance

    Some business unit leaders may be completely unaware of how they use IT, how much they use, and how they could use it more or differently to improve their performance. They may have a learning curve to tackle before they can start to see your relationship as collaborative.

    Bad track record

    If a business unit has had friction with IT in the past or has historically been underserved, they may be hesitant to let you in, may be married to their own solutions, or perhaps do not know how to express what they need.

    Potential opportunities

    Start collaborating

    You and other business unit leaders have a lot in common. You all share the objective of helping the organization succeed. Focus in on your shared concerns and how you can make progress on them together before digging into your unique challenges.

    Practice perspective taking

    Be genuinely curious about the business unit, how it works, and how they overcome obstacles. See the organization from their point of view. For now, keep your technologies completely out of the discussion – that will come later on.

    Build relationships

    You only need to solve one problem for a business unit to change how they think of you. Just one. Find that one thing that will make a real difference – ideally small but impactful – and work it into your budget.

    The CEO: Understand their role

    A CEO sets the tone for an organization, from its overall direction and priorities to its values and culture. What’s possible and what’s not is usually determined by them.

    What are the CEO’s role and responsibilities?

    • Assemble an effective team of executives and advisors.
    • Establish, communicate, and exemplify the organizations core values.
    • Study the ecosystem within which the organization exists.
    • Identify and evaluate opportunities.
    • Set long-term directions, priorities, goals, and strategies.
    • Ensure ongoing organizational performance, profitability, and growth.
    • Connect the inside organization to the outside world.
    • Make the big decisions no one else can make.

    What’s important to the CEO?

    • Strategy
    • Leadership
    • Vision
    • Values
    • Goals
    • Priorities
    • Performance
    • Metrics
    • Accountability
    • Stakeholders
    • Results
    • Insight
    • Growth
    • Cohesion
    • Context

    Unlike the CFO and CXOs, the CEO is responsible for seeing the big picture. That means they’re operating in the realm of big problems and big ideas – they need to stay out of the weeds. IT is just one piece of that big picture, and your problems and ideas are sometimes small in comparison. Use any time you get with them wisely.

    The CEO: What they want from the IT budget

    The CEO wants what the CFO wants, but at a higher level and with longer-term vision.

    Your CEO’s IT budget to-do list:

    Remember to:

    • A review of the previous year’s financial performance. In addition to last year’s budget vs. actuals vs. proposed budget and any rationales for variances, the CEO’s interest is in seeing numbers in terms of strategic delivery. Focus on performance against last year’s goals and concrete benefits realized.
    • A review of initiatives undertaken to optimize/reduce operating costs. Note overall gains with a specific look at initiatives that had a substantial positive financial impact.
    • A specific summary of the cost landscape for new strategic or capital projects. Ideally, these projects have already been committed to at the executive level. A more fine-tuned analysis of anticipated costs and variables may be required, including high-level projects with long-term impact on operational expenditure. Categorize these expenditures as investments in innovation, growth, or keeping the lights on.
    • Details (upon request). Have these available for every aspect of your proposed budget.
    • Be brief. Hopefully, the CEO is already well versed on the strategic spend plans. Stay high-level, reserve the deep dive for your documentation, and let the CEO decide if they want to hash anything out in more detail.
    • Be strategic. If you can’t tie it to a strategic objective, don’t showcase it.
    • Use performance language. This means citing goals, metrics, and progress made against them.
    • Ensure the CFO can translate. You may not get a direct audience with the CEO – the CFO may be your proxy for that. Ensure that everything is crystal clear so that the CFO can summarize your budget on your behalf.

    The CEO: Budget challenges and opportunities

    Strategically address the big issues, but don’t count on their direct assistance.

    Potential challenges

    Lack of interest

    Your CEO may just not be enthusiastic about technology. For them, IT is strictly a cost center operating on the margins. If they don’t have a strategic vision that includes technology, IT’s budget will always be about efficiency and cost control and not investment.

    Deep hierarchy

    The executive-level CIO role isn’t yet pervasive in every industry. There may be one or more non-IT senior management layers between IT and the office of the CEO, as well as other bureaucratic hurdles, which prohibit your direct access.

    Uncertainty

    What’s happening on the outside will affect what needs to be done on the inside. The CEO has to assess and respond quickly, changing priorities and plans in an instant. An indecisive CEO that’s built an inflexible organization will make it difficult to pivot as needed.

    Potential opportunities

    Grow competency

    Sometimes, IT just needs to wait it out. The biggest shifts in technology interest often come with an outright change in the organization’s leadership. In the meantime, fine-tune your operational excellence, brush up on business skills, and draft out your best ideas on paper.

    Build partnerships

    Other business-function executives may need to be IT’s voice. Investment proposals may be more compelling coming from them anyway. Behind-the-scenes partnerships and high-profile champions are something you want regardless of your degree of CEO access.

    Bake in resilience

    Regardless of who’s at the helm, systematic investment in agile and flexible solutions that can be readily scaled, decoupled, redeployed, or decommissioned is a good strategy. Use recent crises to help make the strategic case for a more resilient posture.

    What about the CIO view on the IT budget?

    IT leaders tend to approach budgeting from an IT services perspective. After all, that’s how their departments are typically organized.

    The CFO expense view, CXO business view, and CEO innovation view represent IT’s stakeholders. The CIO service view, however, represents you, the IT budget creator. This means that the CIO service view plays a slightly different role in developing your IT budget communications.

    An IT team effort…

    A logical starting point

    A supporting view

    Most budget drafts start with internal IT management discussion. These managers are differentially responsible for apps dev and maintenance, service desk and user support, networks and data center, security, data and analytics, and so forth.

    These common organizational units and their managers tend to represent discrete IT service verticals. This means the CIO service view is a natural structural starting point for your budget-building process. Stakeholder views of your budget will be derived from this first view.

    You probably don’t want to lead your budget presentation with IT’s perspective – it won’t make sense to your stakeholders. Instead, select certain impactful pieces of your view to drop in where they provide valued information and augment the IT budget story.

    Things to bring forward…

    Things to hold back…

    • All major application costs
    • Security/compliance costs
    • Strategic project costs
    • End-user support and enablement costs
    • Data and BI initiative costs
    • Minor applications costs
    • Day-to-day network and data center costs
    • Other infrastructure costs
    • IT management and administration costs

    1.2 Assess your stakeholders

    1 hour

    1. Use the “Stakeholder alignment assessment” template slide following this one to document the outcomes of this activity.
    2. As an IT management team, identify your key budget stakeholders and specifically those in an approval position.
    3. Use the information provided in this blueprint about various stakeholder responsibilities, areas of focus, and what’s typically important to them to determine each key stakeholder’s needs regarding the information contained in your IT budget. Note their stated needs, any idiosyncrasies, and IT’s current relationship status with the stakeholder (positive, neutral, or negative).
    4. Assess previous years’ IT budgets to determine how well they targeted each different stakeholder’s needs. Note any gaps or areas for future improvement.
    5. Develop a high-level list of items or elements to stop, start, or continue during your next budgeting cycle.
    Input Output
    • Organizational awareness of key stakeholders and budget approvers
    • Previous years’ budgets
    • Assessment of key stakeholder needs and a list of potential changes or additions to the IT budget/budget process
    Materials Participants
    • Whiteboard/flip charts
    • Stakeholder alignment assessment template (following slide)
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Stakeholder alignment assessment

    Document the outcomes of your assessment below. Examples are provided below.

    Stakeholder

    Relationship status

    Understanding of needs

    Budget changes/additions

    CFO

    Positive

    Wants at least 30% of budget to be CapEx. Needs more detail concerning benefits and tracking of realization.

    Do more detailed breakouts of CapEx vs. OpEx as 30% CapEx not realistic – pre-meet. Talk to Enterprise PMO about improving project benefits statement template.

    VP of Sales

    Negative

    Only concerned with hitting sales targets. Needs to respond/act quickly based on reliable data.

    Break out sales consumption of IT resources in detail focusing on CRM and SFA tool costs. Propose business intelligence enhancement project.

    Director of Marketing

    Neutral

    Multiple manual processes – would benefit from increased automation of campaign management and social media posting.

    Break out marketing consumption of IT resources and publicly share/compare to generate awareness/support for tech investment. Work together to build ROI statements

    [Name/Title]

    [Positive/Neutral/Negative]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Positive/Neutral/Negative]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Positive/Neutral/Negative]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Positive/Neutral/Negative]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Positive/Neutral/Negative]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Positive/Neutral/Negative]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Positive/Neutral/Negative]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Positive/Neutral/Negative]

    [Insert text]

    [Insert text]

    Set your IT budget pre-selling strategy

    Pre-selling is all about ongoing communication with your stakeholders. This is the most game-changing thing you can do to advance a proposed IT budget’s success.

    When IT works well, nobody notices. When it doesn’t, the persistent criticism about IT not delivering value will pop up, translating directly into less funding. Cut this off at the pass with an ongoing communications strategy based on facts, transparency, and perspective taking.

    1. Know your channels
    2. Identify all the communication channels you can leverage including meetings, committees, reporting cycles, and bulletins. Set up new channels if they don’t exist.

    3. Identify partners
    4. Nothing’s better than having a team of supporters when pitch day comes. Quietly get them on board early and be direct about the role each of you will play.

    5. Always be prepared
    6. Have information and materials about proposed initiatives at-the-ready. You never know when you’ll get your chance. But if your facts are still fuzzy, do more homework first.

    7. Don’t be annoying
    8. Talking about IT all the time will turn people off. Plan chats that don’t mention IT at all. Ask questions about their world and really listen. Empathy’s a powerful tool.

    9. Communicate IT initiatives at launch
    10. Describe what you will be doing and how it will benefit the business in language that makes sense to the beneficiaries of the initiative.

    11. Communicate IT successes
    12. Carry the same narrative forward through to the end and tell the whole story. Include comments from stakeholders and beneficiaries about the value they’re receiving.

    Pre-selling with partners

    The thing with pre-selling to partners is not to take a selling approach. Take a collaborative approach instead.

    A partner is an influencer, advocate, or beneficiary of the expenditure or investment you’re proposing. Partners can:

    • Advise you on real business impacts.
    • Voice their support for your funding request.
    • Present the initial business case for funding approval themselves.
    • Agree to fund all or part of an initiative from their own budget.

    When partners agree to pitch or fund an initiative, IT can lose control of it. Make sure you set specific expectations about what IT will help with or do on an ongoing basis, such as:

    • Calculating the upfront and ongoing technology maintenance/support costs of the initiative.
    • Leading the technology vetting and selection process, including negotiating with vendors, setting service-level agreements, and finalizing contracts.
    • Implementing selected technologies and training users.
    • Maintaining and managing the technology, including usage metering.
    • Making sure the bills get paid.

    A collaborative approach tends to result in a higher level of commitment than a selling approach.

    Put yourself in their shoes using their language. Asking “How will this affect you?” focuses on what’s in it for them.

    Example:

    CIO: “We’re thinking of investing in technology that marketing can use to automate posting content to social media. Is that something you could use?”

    CMO: “Yes, we currently pay two employees to post on Facebook and Twitter, so if it could make that more efficient, then there would be cost savings there.”

    Pre-selling with approvers

    The key here is to avoid surprises and ensure the big questions are answered well in advance of decision day.

    An approver is the CFO, CEO, board, council, or committee that formally commits funding support to a program or initiative. Approvers can:

    • Point out factors that could derail realization of intended benefits.
    • Know that a formal request is coming and factor it into their planning.
    • Connect your idea with others to create synergies and efficiencies.
    • Become active advocates.

    When approvers cool to an idea, it’s hard to warm them up again. Gradually socializing an idea well in advance of the formal pitch gives you the chance to isolate and address those cooling factors while they’re still minor. Things you can address if you get an early start with future approvers include:

    • Identify and prepare for administrative, regulatory, or bureaucratic hurdles.
    • Incorporate approvers’ insights about organizational realities and context.
    • Further reduce the technical jargon in your language.
    • Fine tune the relevance and specificity of your business benefits statements.
    • Get a better sense of the most compelling elements to focus on.

    Blindsiding approvers with a major request at a budget presentation could trigger an emotional response, not the rational and objective one you want.

    Make approvers part of the solution by soliciting their advice and setting their expectations well in advance.

    Example:

    CIO: “The underwriting team and I think there’s a way to cut new policyholder approval turnaround from 8 to 10 days down to 3 or 4 using an online intake form. Do you see any obstacles?”

    CFO: “How do the agents feel about it? They submit to underwriting differently and might not want to change. They’d all need to agree on it. Exactly how does this impact sales?”

    1.3 Set your budget pre-selling strategy

    1 hour

    1. Use the “Stakeholder pre-selling strategy” template slide following this instruction slide to document the outcomes of this activity.
    2. Carry forward your previously-generated stakeholder alignment assessment from Step 1.2. As a management team, discuss the following for each stakeholder:
      1. Forums and methods of contact and interaction.
      2. Frequency of interaction.
      3. Content or topics typically addressed during interactions.
    3. Discuss what the outcomes of an ideal interaction would look like with each stakeholder.
    4. List opportunities to change or improve the nature of interactions and specific actions you plan to take.
    InputOutput
    • Stakeholder Alignment Assessment (in-deck template)
    • Stakeholder Pre-selling Strategy
    MaterialsParticipants
    • Stakeholder Pre-selling Strategy (in-deck template)
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Stakeholder pre-selling strategy

    Document the outcomes of your discussion. Examples are provided below.

    Stakeholder

    Current interactions

    Opportunities and actions

    Forum

    Frequency

    Content

    CFO

    One-on-one meeting

    Monthly

    IT expenditure updates and tracking toward budgeted amount.

    Increase one-on-one meeting to weekly. Alternate focus – retrospective update one week, future-looking case development the next. Invite one business unit head to future-looking sessions to discuss their IT needs.

    VP of Sales

    Executive meeting

    Quarterly

    General business update - dominates.

    Set up bi-weekly one-on-one meeting – initially focus on what sales does/needs, not tech. Later, when the relationship has stabilized, bring data that shows Sales’ consumption of IT resources.

    Director of Marketing

    Executive meeting

    Quarterly

    General business update - quiet.

    Set up monthly one-on-one meeting. Temporarily embed BA to better discover/understand staff processes and needs.

    [Name/Title]

    [Insert text]

    [Insert text]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Insert text]

    [Insert text]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Insert text]

    [Insert text]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Insert text]

    [Insert text]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Insert text]

    [Insert text]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Insert text]

    [Insert text]

    [Insert text]

    [Insert text]

    [Name/Title]

    [Insert text]

    [Insert text]

    [Insert text]

    [Insert text]

    Phase recap: Lay your foundation

    Build in the elements from the start that you need to facilitate budgetary approval.

    You should now have a deeper understanding of the what, why, and who of your IT budget. These elements are foundational to streamlining the budget process, getting aligned with peers and the executive, and increasing your chances of winning budgetary approval in the end.

    In this phase, you have:

    • Reviewed what your budget is and does. Your budget is an important governance and communication tool that reflects organizational priorities and objectives and IT’s understanding of them.
    • Taken a closer look at your stakeholders. The CFO, CEO, and CXOs in your organization have accountabilities of their own to meet and need IT and its budget to help them succeed.
    • Developed a strategy for continuously pre-selling your budget. Identifying opportunities and approaches for building relationships, collaborating, and talking meaningfully about IT and IT expenditure throughout the year is one of the leading things you can do to get on the same page and pave the way for budget approval.

    “Many departments have mostly labor for their costs. They’re not buying a million and a half or two million dollars’ worth of software every year or fixing things that break. They don’t share IT’s operations mindset and I think they get frustrated.”

    – Matt Johnson, IT Director Governance and Business Solutions, Milwaukee County

    Phase 2

    Get Into Budget-Starting Position

    Lay Your
    Foundation

    Get Into Budget-Starting Position

    Develop Your
    Forecasts

    Build Your
    Proposed Budget

    Create and Deliver Your Presentation

    1.1 Understand what your budget is
    and does

    1.2 Know your stakeholders

    1.3 Continuously pre-sell your budget

    2.1 Assemble your resources

    2.2 Understand the four views of the ITFM Cost Model

    2.3 Review last year’s budget vs.
    actuals and five-year historical trends

    2.4 Set your high-level goals

    3.1 Develop assumptions and
    alternative scenarios

    3.2 Forecast your project CapEx

    3.3 Forecast your non-project CapEx and OpEx

    4.1 Aggregate your numbers

    4.2 Stress test your forecasts

    4.3 Challenge and perfect your
    rationales

    5.1 Plan your content

    5.2 Build your presentation

    5.3 Present to stakeholders

    5.4 Make final adjustments and submit your IT budget

    This phase will walk you through the following activities:

    • Putting together your budget team and gather your data.
    • Selecting which views of the ITFM Cost Model you’ll use.
    • Mapping and analyzing IT’s historical expenditure.
    • Setting goals and metrics for the next budgetary cycle.

    This phase involves the following participants:

    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Get into budget-starting position

    Now’s the time to pull together your budgeting resources and decision-making reference points.

    This phase is about clarifying your context and defining your boundaries.

    • Assemble your resources. This includes the people, data, and other information you’ll need to maximize insight into future spend requirements.
    • Understand the four views of the IT Cost Model. Firm up your understanding of the CFO expense view, CIO service view, CXO business view, and CEO innovation view and decide which ones you’ll use in your analysis and forecasting.
    • Review last year’s budget versus actuals. You need last year’s context to inform next year’s numbers as well as demonstrate any cost efficiencies you successfully executed.
    • Review five-year historical trends. This long-term context gives stakeholders and approvers important information about where IT fits into the business big picture and reminds them how you got to where you are today.
    • Set your high-level goals. You need to decide if you’re increasing, decreasing, or holding steady on your budget and whether you can realistically meet any mandates you’ve been handed on this front. Set a target as a reference point to guide your decisions and flag areas where you might need to have some tough conversations.

    “A lot of the preparation is education for our IT managers so that they understand what’s in their budgets and all the moving parts. They can actually help you keep it within bounds.”

    – Trisha Goya, Director, IT Governance & Administration, Hawaii Medical Service Association

    Gather your budget-building team

    In addition to your CFO, CXOs, and CEO, there are other people who will provide important information, insight, and skill in identifying IT budget priorities and costs.

    Role

    Skill set

    Responsibilities

    IT Finance Lead

    • Financial acumen, specifically with cost forecasting and budgeting.
    • Understanding of actual IT costs and service-based costing methods.

    IT finance personnel will guide the building of cost forecasting methodologies for operating and capital costs, help manage IT cash flows, help identify cost reduction options, and work directly with the finance department to ensure they get what they need.

    IT Domain Managers

    • Knowledge of services and their outputs.
    • Understanding of cost drivers for the services they manage.

    They will be active participants in budgeting for their specific domains, act as a second set of eyes, assist with and manage their domain budgets, and engage with stakeholders.

    Project Managers

    • Knowledge of project requirements.
    • Project budgeting.
    • Understanding of project IT-specific costs.

    Project managers will assist in capital and operational forecasting and will review project budgets to ensure accuracy. They will also assist in forecasting the operational impacts of capital projects.

    As the head of IT, your role is as the budgeting team lead. You understand both the business and IT strategies, and have relationships with key business partners. Your primary responsibilities are to guide and approve all budget components and act as a liaison between finance, business units, and IT.

    Set expectations with your budgeting team

    Be clear on your goals and ensure everyone has what they need to succeed.

    Your responsibilities and accountabilities.

    • Budget team lead.
    • Strategic direction.
    • Primary liaison with business stakeholders.
    • Pre-presentation approver and final decision maker.

    Goals and requirements.

    • Idea generation for investment and cost optimization.
    • Cost prioritization and rationale.
    • Skills requirements and sourcing options.
    • Risk assessment and operational impact.
    • Data format and level of granularity.

    Budgeting fundamentals.

    • Review of key finance concepts – CapEx, OpEx, cashflow, income, depreciation, etc.
    • What a budget is, and its component parts.
    • How the budget will be used by IT and the organization.
    • How to calculate cost forecasts.

    Their responsibilities and accountabilities.

    • Data/information collection.
    • Operational knowledge of their services, projects, and staff.
    • Cost forecast development for their respective domains/projects.
    • Review and sanity checking of their peers’ cost forecasts.

    Timeframes and deadlines.

    • Budgeting stages/phases and their deliverables.
    • Internal IT deadlines.
    • External business deadlines.
    • Goals and cadence of future working sessions and meetings.

    Available resources.

    • Internal and external sources of data and information.
    • Tools and templates for tracking information and performing calculations.
    • Individuals who can provide finance concept guidance and support.
    • Repositories for in-progress and final work.

    2.1 Brief and mobilize your IT budgeting team

    2 hours

    1. Download the IT Cost Forecasting and Budgeting Workbook
    2. Organize a meeting with your IT department management team, team leaders, and project managers.
    3. Review their general financial management accountabilities and responsibilities.
    4. Discuss the purpose and context of the budgeting exercise, different budget components, and the organization’s milestones/deadlines.
    5. Identify specific tasks and activities that each member of the team must complete in support of the budgeting exercise.
    6. Set up additional checkpoints, working sessions, or meetings that will take you through to final budget submission.
    7. Document your budget team members, responsibilities, deliverables, and due dates on the “Planning Variables” tab in the IT Cost Forecasting & Budgeting Workbook.

    Download the IT Cost Forecasting and Budgeting Workbook

    InputOutput
    • The organization’s budgeting process and procedures
    • Assignment of IT budgeting team responsibilities
    • A budgeting schedule
    MaterialsParticipants
    • IT Cost Forecasting and Budgeting Workbook
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Leverage the ITFM Cost Model

    Each of the four views breaks down IT costs into a different array of categories so you and your stakeholders can see expenditure in a way that’s meaningful for them.

    You may decide not to use all four views based on your goals, audience, and available time. However, let’s start with how you can use the first two views, the CFO expense view and the CIO service view.

    The image contains a screenshot of the CFO expense view.

    The CFO expense view is fairly traditional – workforce and vendor. However, Info-Tech’s approach breaks down the vendor software and hardware buckets into on-premises and cloud. Making this distinction is increasingly critical given key differences in CapEx vs. OpEx treatment.

    Forecasting this view is mandatory

    These two views provide information that will help you optimize IT costs. They’re designed to allow the CFO and CIO to find a common language that will allow them to collaboratively make decisions about managing IT expenditure effectively.

    The image contains a screenshot of the CIO service view.

    The CIO service view is your view, i.e. it’s how IT tends to organize and manage itself and is often the logical starting point for expenditure planning and analysis. Sub-categories in this view, such as security and data & BI, can also resonate strongly with business stakeholders and their priorities.

    Forecasting this view is recommended

    Extend your dialogue to the business

    Applying the business optimization views of the ITFM Cost Model can bring a level of sophistication to your IT cost analysis and forecasting efforts.

    Some views take a bit more work to map out, but they can be powerful tools for communicating the value of IT to the business. Let’s look at the last two views, the CXO business view and the CEO innovation view.

    The CXO business view looks at IT expenditure business unit by business unit so that each can understand their true consumption of IT resources. This view relies on having a fair and reliable cost allocation formula, such as one based on relative headcount, so it runs the risk of inaccuracy.

    Forecasting this view is recommended

    The image contains a screenshot of the CXO business view.

    These two views provide information that will help you optimize IT support to the business. These views also have a collaborative goal in mind, enabling IT to talk about IT spend in terms that will promote transparency and engage business stakeholders.

    The CEO innovation view is one of the hardest to analyze and forecast since a single spend item may apply to innovation, growth, and keeping the lights on. However, if you have an audience with the CEO and they want IT to play a more strategic or innovative role, then this view is worth mapping.

    Forecasting this view is optional

    The image contains a screenshot of the CEO innovation view.

    2.2 Select the ITFM Cost Model views you plan to complete based on your goals

    30 minutes

    The IT Cost Forecasting and Budgeting Workbook contains standalone sections for each view, as well as rows for each lowest-tier sub-category in a view, so each view can be analyzed and forecasted independently.

    1. Review Info-Tech’s ITFM Cost Model and the expenditure categories and sub-categories each view contains.
    2. Revisit your stakeholder analysis for the budgeting exercise. Plan to:
      1. Complete the CFO expense view regardless.
      2. Complete the CIO service view – consider doing this one first for forecasting purposes as it may be most familiar to you and serve as an easier entry point into the forecasting process.
      3. Complete the CXO business view – consider doing this only for select business units if you have the objective of enhancing awareness of their true consumption of IT resources or if you have (or plan to have) a show-back/chargeback mechanism.
      4. Complete the CEO innovation view only if your data allows it and there’s a compelling reason to discuss the strategic or innovative role of IT in the organization.
    Input Output
    • Stakeholder analysis
    • Info-Tech’s ITFM Cost Model
    • Decision on which views in the ITFM Cost Model you’ll use for historical expenditure analysis and forecasting purposes
    Materials Participants
    • Info-Tech’s ITFM Cost Model
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Gather your budget-building data

    Your data not only forms the content of your budget but also serves as the supporting evidence for the decisions you’ve made.

    Ensure you have the following data and information available to you and your budgeting team before diving in:

    Past data

    • Last fiscal year’s budget.
    • Actuals for the past five fiscal years.
    • Pre-set capital depreciation/amortization amounts to be applied to next fiscal year’s budget.

    Current data

    • Current-year IT positions and salaries.
    • Active vendor contracts with payment schedules and amounts (including active multi-year agreements).
    • Cost projections for remainder of any projects that are committed or in-progress, including projected OpEx for ongoing maintenance and support.

    Future data

    • Estimated market value for any IT positions to be filled next year (both backfill of current vacancies and proposed net-new positions).
    • Pricing data on proposed vendor purchases or contracts.
    • Cost estimates for any capital/strategic projects that are being proposed but not yet committed, including resulting maintenance/support OpEx.
    • Any known pending credits to be received or applied in the next fiscal year.

    If you’re just getting started building a repeatable budgeting process, treat it like any other project, complete with a formal plan/ charter and a central repository for all related data, information, and in-progress and final documents.

    Once you’ve identified a repeatable approach that works for you, transition the budgeting project to a regular operational process complete with policies, procedures, and tools.

    Review last year’s budget vs. actuals

    This is the starting point for building your high-level rationale around what you’re proposing for next fiscal year.

    But first, some quick definitions:

    • Budgeted: What you planned to spend when you started the fiscal year.
    • Actual: What you ended up spending in real life by the end of the fiscal year.
    • Variance: The difference between budgeted expenditure and actual expenditure.

    For last fiscal year, pinpoint the following metrics and information:

    Budgeted and actual IT expenditure overall and by major cost category.

    Categories will include workforce (employees/contractors) and vendors (hardware, software, contracted services) at a minimum.

    Actual IT expenditure as a percentage of organizational revenue.

    This is a widely-used benchmark that your CFO will expect to see.

    The known and likely drivers behind budgeted vs. actual variances.

    Your rationales will affect your perceived credibility. Be straightforward, avoid defending or making excuses, and just show the facts.

    Ask your CFO what they consider acceptable variance thresholds for different cost categories to guide your variance analysis, such as 1% for overall IT expenditure.

    Actual IT CapEx and OpEx.

    CapEx is often more variable than OpEx over time. Separate them so you can see the real trends for each. Consider:

    • Sub-dividing CapEx by strategic projects and non-strategic “business as usual” spend (e.g. laptops, network maintenance gear).
    • Showing overall CapEx and OpEx as percentages of their organization-wide counterparts if that information is available.

    Next, review your five-year historical expenditure trends

    The longer-term pattern of IT expenditure can help you craft a narrative about the overarching story of IT.

    For the previous five fiscal years, focus on the following:

    Actual IT expenditure as a percentage of organizational revenue.

    Again, for historical years 2-5, you can break this down into granular cost categories like workforce, software, and infrastructure like you did for last fiscal year. Avoid getting bogged down and focusing on the past – you ultimately want to redirect stakeholders to the future.

    Percentage expenditure increase/decrease year to year.

    You may choose to show overall IT expenditure amounts, breakdowns by CapEx and OpEx, as well as high-level cost categories.

    As you go back in time, some data may not be available to you, may be unreliable or incomplete, or employ the same cost categories you’re using today. Use your judgement on the level of granularity you want to and can apply when going back two to five years in the past.

    So, what’s the trend? Consider these questions:

    • Is the year-over-year trend on a steady trajectory or are there notable dips and spikes?
    • Are there any one-time capital projects that significantly inflated CapEx and overall spend in a given year or that forced maintenance-and support-oriented OpEx commitments in subsequent years?
    • Does there seem to be an overall change in the CapEx-to-OpEx ratio due to factors like increased use of cloud services, outsourcing, or contract-based staff?

    Take a close look at financial data showcasing the cost-control measures you’ve taken

    Your CFO will look for evidence that you’re gaining efficiencies by controlling costs, which is often a prerequisite for them approving any new funding requests.

    Your objective here is threefold:

    1. Demonstrate IT’s track record of fiscal responsibility and responsiveness to business priorities.
    2. Acknowledge and celebrate your IT-as-cost-center efficiency gains to clear the way for more strategic discussions.
    3. Identify areas where you can potentially source and reallocate recouped funds to bolster other initiatives or business cases for net-new spend.

    This step is about establishing credibility, demonstrating IT value, building trust, and showing the CFO you’re on their team.

    Do the following:

    • List any specific cost-control initiatives and their initial objectives and targets.
    • Identify any changes made to those targets and your approaches due to changing conditions, with rationales for the decisions made. For example:
      • Mid-year, the business decided to allow approximately half the workforce to work from home on a permanent basis.
      • As a result, remote-worker demand on the service desk remained high and actually increased in some areas. You were unable to reduce service desk staff headcount as originally planned.
      • You’re now exploring ways to streamline ticket intake and assignment to increase throughput and speed resolution.
    • Report on completed cost-control initiatives first, including targets, actuals, and related impacts. Include select feedback from business stakeholders and users about the impact of your cost-control measure on them.
    • For in-progress initiatives, report progress made to-date, benefits realized to date, and plans for continuation next fiscal year.

    “Eliminate the things you don’t need. People will give you what you need when you need it if you’re being responsible with what you already have.”

    – Angela Hintz, VP of PMO & Integrated Services,
    Blue Cross and Blue Shield of Louisiana

    2.3 Review your historical IT expenditure

    8 hours

    1. Download the IT Cost Forecasting and Budgeting Workbook.
    2. On Tab 1, “Historical Events & Projects,” note the cost-driving and cost-saving events that occurred last fiscal year that drove any variance between budgeted and actual expenditure. Describe the nature of their impact and current status (ongoing, resolved – temporary impact, or resolved – permanent impact).
    3. Also on Tab 1, “Historical Events & Projects”, summarize the work done on capital or strategic projects, expenditures, and status (in progress, deferred, canceled, or complete).
    4. On Tab 2, “Historical Expenditure”:
      1. Enter the budgeted and actuals data for last fiscal year in columns D-H for the views of the ITFM Cost Model you’re opted to do, i.e. CFO expense view, CIO service view, CXO business view, and CEO innovation view.
      2. Enter a brief rationale for any notable budgeted-versus-actuals variances or other interesting items in column K.
      3. Enter actuals data for the remaining past five fiscal years in columns L-O. Year-over-year comparative metrics will be calculated for you.
      4. Enter FTEs by business function in columns R-AA, rows 34-43.
        Expenditure per FTE and year-over year comparative metrics will be
        calculated for you.
    5. Using Tabs 2, “Historical Expenditure” and 3, “Historical Analysis”, review and analyze the resulting data sets and graphs to identify overall patterns, specifically notable increases or decreases in a particular category of expenditure or where rationales are repeated across categories or views (these are significant).
    6. Finally, flag any data points that help demonstrate achievement of, or progress toward, any cost-control measures you implemented.

    2.3 Review your historical IT expenditure

    InputOutputMaterialsParticipants
    • Budgeted data for the previous fiscal year and actuals data for the previous five fiscal years
    • Mapped budgeted for last fiscal year, mapped actuals for the past five fiscal years, and variance metrics and rationales
    • IT Cost Forecasting and Budgeting Workbook
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Pull historical trends into a present-day context when setting your high-level goals

    What’s happening to your organization and the ecosystem within which it’s operating right now? Review current business concerns, priorities, and strategies.

    Knowing what happened in the past can provide good insights and give you a chance to show stakeholders your money-management track record. However, what stakeholders really care about is “now” and “next”. For them, it’s all about current business context.

    Ask these questions about your current context to assess the relevance of your historical trend data:

    What’s the state of
    the economy and how is
    it affecting your organization?

    What are the
    organization’s stated
    strategic goals and objectives?

    What has the business
    explicitly communicated
    about finance-related targets?

    What’s the business
    executive’s attitude on
    budget increase requests?

    Some industries are very sensitive to economic cycles, causing wild budget fluctuations year to year. This uncertainty can reduce the volume of spend you automatically carry over one year to the next, making past spend patterns less relevant to your current budgeting effort.

    These can change year to year as well, and often manifest on the CapEx side in the form of strategic projects selected. Since this is so variable, using previous years’ CapEx to determine next fiscal’s CapEx isn’t always useful except in regard to multi-year, ongoing capital projects.

    Do your best to honor mandates. However, if cuts are suggested that could jeopardize core service delivery, tread cautiously, and pick your battles. You may be able to halt new capital spend to generate cuts, but these projects may get approved anyway, with IT expected to make cuts to OpEx.

    If the CFO and others rail against even the most necessary inflation-driven increases, you’ll need to take a conservative approach, focus on cost-saving initiatives, and plan to redirect last year’s expenditures instead of pursuing net-new spend.

    Set metrics and targets for some broader budget effectiveness improvement efforts

    Budget goalsetting isn’t limited to CapEx and OpEx targets. There are several effectiveness metrics to track overall improvement in your budgeting process.

    Step back and think about other budget and expenditure goals you have.
    Do you want to:

    • Better align the budget with organizational objectives?
    • Increase cost forecasting accuracy?
    • Increase budget transparency and completeness?
    • Improve the effectiveness of your budget presentation?
    • Reduce the amount of budget rework?
    • Increase the percentage of the budget that’s approved?
    • Reduce variance between what was budgeted and actuals?

    Establish appropriate metrics and targets that will allow you to define success, track progress, and communicate achievement on these higher-level goals.

    Check out some example metrics in the table below.

    Budgeting metric

    Improvement driver

    Current value

    Future target

    Percentage of spend directly tied to an organizational goal.

    Better alignment via increased communication and partnership with the business.

    72%

    90%

    Number of changes to budget prior to final acceptance.

    Better accuracy and transparency via use of zero-based budgeting and enhanced stakeholder views.

    8

    2

    Percentage variance between budgeted vs. actuals.

    Improved forecasting through better understanding of business plans and in-cycle show-back.

    +4%

    +/-2%

    Percentage of budget approved after first presentation.

    Improved business rationales and direct mapping of expenditure to org priorities.

    76%

    95%

    Percentage of IT-driven project budget approved.

    More rigor around benefits, ROI calculation, and quantifying value delivered.

    80%

    100%

    Set your high-level OpEx budget targets

    The high-level targets you set now don’t need to be perfect. Think of them as reference points or guardrails to sanity-check the cost forecasting exercise to come.

    First things first: Zero-based or incremental for OpEx?

    Set your OpEx targets

    Incremental budgeting is the addition of a few percentage onto next year’s budget, assuming the previous year’s OpEx is all re-occurring. The percentage often aligns with rates of inflation.

    • Most organizations take this approach because it’s faster and easier.
    • However, incremental budgeting is less accurate. Non-recurring items are often overlooked and get included in the forecast, resulting in budget bloat. Also, redundant or wasteful items can be entirely missed, undermining any cost optimization efforts.

    Zero-based budgeting involves rebuilding your budget from scratch, i.e. zero. It doesn’t assume that any of last year’s costs are recurring or consistent year to year.

    • This approach is harder because all relevant historical spend data needs to be collected and reviewed, which not only takes time but the data you need may be unlocatable.
    • Every item needs to be re-examined, re-justified, and tied to an asset, service, or project, which means it’s a far more comprehensive and accurate approach.

    Pick a range of percentage change based on your business context and past spend.

    • If economic prospects are negative, start with a 0-3% increase to balance inflation with potential cuts. Don’t set concrete reduction targets at this point, to avoid tunnel vision in the forecasting exercise.
    • If economic prospects are positive, target 3-5% increases for stable scenarios and 6-10% increases for growth scenarios.
    • If CapEx from previous-year projects is switching to steady-state OpEx, then account for these bumps in OpEx.
    • If the benefits from any previous-year efficiency measures will be realized next fiscal year, then account for these as OpEx reductions.

    If cost-cutting or optimization is a priority, then a zero-based approach is the right decision. If doing this every year is too onerous, plan to do it for your OpEx at least every few years to examine what’s actually in there, clean house, and re-set.

    Set your high-level CapEx budget targets

    A lot of IT CapEx is conceived in business projects, so your proposed expenditure here may not be up to you. Exercise as much influence as you can.

    First things first: Is it project CapEx, or “business as usual” CapEx?

    Project CapEx is tied to one-time strategic projects requiring investment in new assets.

    • This CapEx will probably be variable year to year, going up or down depending on the organization’s circumstances or goals.
    • This area of spend is driven largely by the business and not IT. Plan to set project CapEx targets in close partnership with the business and function as a steward of these funds instead of as an owner.

    User-driven “business as usual” CapEx manifests via changes (often increases) in organizational headcount due to growth.

    • Costs here focus on end-user hardware like desktops, laptops, and peripherals.
    • Any new capital software acquisitions you have planned will also be affected in terms of number of licenses required.
    • Get reliable estimates of department-by-department hiring plans for next fiscal year to better account for these in your budget.

    Network/data center-driven “business-as-usual” CapEx is about core infrastructure maintenance.

    • Costs here focus on the purchase of network and data center hardware and other equipment to maintain existing infrastructure services and performance.
    • Increased outsourcing often drives down this area of “business as usual” CapEx by reducing the purchase of new on-premises solutions and eliminating network and data center maintenance requirements.

    Unanticipated hiring and the need to buy end-user hardware is cited as a top cause of budget grief by IT leaders – get ahead of this. Project CapEx, however, is usually determined via business-based capital project approval mechanisms well in advance. And don’t forget to factor in pre-established capital asset depreciation amounts generated by all the above!

    2.4 Set your high-level IT budget targets and metrics

    8 hours

    1. Download the IT Cost Forecasting and Budgeting Workbook to document the outcomes of this activity.
    2. Review the context in which your organization is currently operating and expects to operate in the next fiscal year. Specifically, look at:
      1. The state of the economy.
      2. Stated goals, objectives, and targets.
      3. The executive’s point of view on budget increase requests.
      Document your factors, assessment, rationale, and considerations in the “Business Context Assessment” table on the “Planning Variables” tab in the IT Cost Forecasting and Budgeting Workbook.
    3. Based on the business context, anticipated flips of former CapEx to OpEx, and realization of previous years’ efficiency measures, set a general non-project OpEx target as a percentage increase or decrease for next fiscal year to serve as a guideline in the cost forecasting guideline. Document this in the “Budget Targets & Metrics” table on the “Planning Variables” tab in the IT Cost Forecasting and Budgeting Workbook. sed on known capital projects, changes in headcount, typical “business as usual” equipment expenditure, and pre-established capital asset depreciation amounts, set general project CapEx and non-project CapEx targets. Document these in the “Budget Targets & Metrics” table on the “Planning Variables” tab in the IT Cost Forecasting and Budgeting Workbook.
    4. Finally, set your overarching IT budget process success metrics. Also document these in the “Budget Targets & Metrics” table on the “Planning Variables” tab in the IT Cost Forecasting and Budgeting Workbook.

    Download the IT Cost Forecasting and Budgeting Workbook

    2.4 Set your high-level IT budget targets and metrics

    InputOutputMaterialsParticipants
    • Knowledge of current business context and probable context next fiscal year
    • Analysis of historical IT expenditure patterns
    • High-level project CapEx and non-project CapEx and OpEx targets for the next fiscal year
    • IT budget process success metrics
    • IT Cost Forecasting and Budgeting Workbook
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Phase recap: Get into budget-starting position

    Now you’re ready to do the deep dive into forecasting your IT budget for next year.

    In this phase, you clarified your business context and defined your budgetary goals, including:

    • Assembling your resources. You’ve built and organized your IT budgeting team, as well as gathered the data and information you’ll need to do your historical expenditure analysis and future forecasting
    • Understanding the four views of the IT Cost Model. You’ve become familiar with the four views of the model and have selected which ones you’ll map for historical analysis and forecasting purposes.
    • Reviewing last year’s budget versus actuals and five-year historical trends. You now have the critical rationale-building context to inform next year’s numbers and demonstrate any cost efficiencies you’ve successfully executed.
    • Setting your high-level goals. You’ve established high-level targets for project and non-project CapEx and OpEx, as well as set some IT budget process improvement goals.

    “We only have one dollar but five things. Help us understand how to spend that dollar.”

    – Trisha Goya, Director, IT Governance & Administration, Hawaii Medical Service Association

    Phase 3

    Develop Your Forecasts

    Lay Your
    Foundation

    Get Into Budget-Starting Position

    Develop Your
    Forecasts

    Build Your
    Proposed Budget

    Create and Deliver Your Presentation

    1.1 Understand what your budget is
    and does

    1.2 Know your stakeholders

    1.3 Continuously pre-sell your budget

    2.1 Assemble your resources

    2.2 Understand the four views of the ITFM Cost Model

    2.3 Review last year’s budget vs.
    actuals and five-year historical trends

    2.4 Set your high-level goals

    3.1 Develop assumptions and
    alternative scenarios

    3.2 Forecast your project CapEx

    3.3 Forecast your non-project CapEx and OpEx

    4.1 Aggregate your numbers

    4.2 Stress test your forecasts

    4.3 Challenge and perfect your
    rationales

    5.1 Plan your content

    5.2 Build your presentation

    5.3 Present to stakeholders

    5.4 Make final adjustments and submit your IT budget

    This phase will walk you through the following activities:

    • Documenting the assumptions behind your proposed budget and develop alternative scenarios.
    • Forecasting your project CapEx.
    • Forecasting your non-project CapEx and OpEx.

    This phase involves the following participants:

    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Develop your forecasts

    Start making some decisions.

    This phase focuses on putting real numbers on paper based on the research and data you’ve collected. Here, you will:

    • Develop assumptions and alternative scenarios. The assumptions you make are the logical foundation for your decisions, and your primary and alternative scenarios focus your thinking and demonstrate that you’ve thoroughly examined your organization’s current and future context.
    • Forecast your project CapEx costs. These costs are comprised of all the project-related capital expenditures for strategic or capital projects, including in-house labor.
    • Forecast your non-project CapEx and OpEx costs. These costs are the ongoing “business as usual” expenditures incurred via the day-to-day operations of IT and delivery of IT services.

    “Our April forecast is what really sets the bar for what our increase is going to be next fiscal year. We realized that we couldn’t change it later, so we needed to do more upfront to get that forecast right.

    If we know that IT projects have been delayed, if we know we pulled some things forward, if we know that a project isn’t starting until next year, let’s be really clear on those things so that we’re starting from a better forecast because that’s the basis of deciding two percent, three percent, whatever it’s going to be.”

    – Kristen Thurber, IT Director, Office of the CIO, Donaldson Company

    When pinning down assumptions, start with negotiable and non-negotiable constraints

    Assumptions are things you hold to be true. They may not actually be true, but they are your logical foundation and must be shared with stakeholders so they can follow your thinking.

    Start with understanding your constraints. These are either negotiable (adjustable) or non-negotiable (non-adjustable). However, what is non-negotiable for IT may be negotiable for the organization as a whole, such as its strategic objectives. Consider each of the constraints below, determine how it relates to IT expenditure options, and decide if it’s ultimately negotiable or non-negotiable.

    Organizational

    Legal and Regulatory

    IT/Other

    Example:
    • Strategic goals and priorities
    • Financial and market performance
    • Governance style and methods
    • Organizational policies
    • Organizational culture
    • Regulatory compliance and reporting
    • Data residency and privacy laws
    • Vendor contract terms and conditions
    • Health and safety
    • Compensation and collective bargaining
    • IT funding and fund allocation flexibility
    • Staff/skills availability and capacity
    • Business continuity and IT performance requirements
    • Time and timeframes
    You’re in year one of a three-year vendor contract. All contracts are negotiable, but this one isn’t for two years. This contact should be considered a non-negotiable for current budget-planning purposes.

    Identifying your negotiable and non-negotiable constraints is about knowing what levers you can pull. Government entities have more non-negotiable constraints than private companies, which means IT and the organization as a whole have fewer budgetary levers to pull and a lot less flexibility.

    An un-pullable lever and a pullable lever (and how much you can pull it) have one important thing in common – they are all fundamental assumptions that influence your decisions.

    Brainstorm your assumptions even further

    The tricky thing about assumptions is that they’re taken for granted – you don’t always realize you’ve made them. Consider these common assumptions and test them for validity.

    My current employees will still be here 18 months from now.

    My current vendors aren’t going to discontinue the products we have.

    My organization’s executive team will be the same 18 months from now. My current key vendors will be around for years to come.

    My organization’s departments, divisions, and general structure will be the same 18 months from now.

    IT has to be an innovation leader.

    We won’t be involved in any merger/acquisition activity next fiscal year.

    IT has always played the same role here and that won’t change.

    There won’t be a major natural disaster that takes us offline for days or even weeks.

    We must move everything we can to the cloud.

    We won’t be launching any new products or services next fiscal year.

    Most of our IT expenditure has to be CapEx, as usual.

    You won’t put some of these assumptions into your final budget presentation. It’s simply worthwhile knowing what they are so you can challenge them when forecasting.

    Based on your assumptions, define the primary scenario that will frame your budget

    Your primary scenario is the one you believe is most likely to happen and upon which you’ll build your IT cost forecasts.

    Now it’s time to outline your primary scenario.

    • A scenario is created by identifying the variable factors embedded in your assumptions and manipulating them across the range of possibilities. This manipulation of variables will result in different scenarios, some more likely or feasible than others.
    • Your primary scenario is the one you believe is the most feasible and/or likely to happen (i.e. most probable). This is based on:
      • Your understanding of past events and patterns.
      • Your understanding of your organization’s current context.
      • Your understanding of IT’s current context.
      • Your understanding of the organization’s objectives.
      • Your assessment of negotiable and non-negotiable constraints and other assumptions for both IT and the organization.

    A note on probability…

    • A non-negotiable constraint doesn’t have any variables to manipulate. It’s a 100% probability that must be rigidly accommodated and protected in your scenario. An example is a long-standing industry regulation that shows no signs of being updated or altered and must be complied with in its current state.
    • A negotiable constraint has many more variables in play. Your goal is to identify the different potential values of the variables and determine the degree of probability that one value is more likely to be true or feasible than another. An example is that you’re directed to cut costs, but the amount could be as little as 3% or as much as 20%.
    • And then there are the unknowns. These are circumstances, events, or initiatives that inevitably happen, but you can’t predict when, what, or how much. This is what contingency planning and insurance are for. Examples include a natural disaster, a pandemic, a supply chain crisis, or the CEO simply changing their mind. Its safe to assume something is going to happen, so if you’re able to establish a contingency fund or mechanisms that let you respond, then do it.

    What could or will be your organization’s new current state at the end of next fiscal year?

    Next, explore alternative scenarios, even those that may seem a bit outrageous

    Offering alternatives demonstrates that you weighed all the pertinent factors and that you’ve thought broadly about the organization’s future and how best to support it.

    Primary scenario approval can be helped by putting that scenario alongside alternatives that are less attractive due to their cost, priority, or feasibility. Alternative scenarios are created by manipulating or eliminating your negotiable constraints or treating specific unknowns as knowns. Here are some common alternative scenarios.

    The high-cost scenario: Assumes very positive economic prospects. Characterized by more of everything – people and skills, new or more sophisticated technologies, projects, growth, and innovation. Remember to consider the long-term impact on OpEx that higher capital spend may bring in subsequent years.

    Target 10-20% more expenditure than your primary scenario

    The low-cost scenario: Assumes negative economic prospects or cost-control objectives. Characterized by less of everything, specifically capital project investment, other CapEx, and OpEx. Must assume that business service-level expectations will be down-graded and other sacrifices will be made.

    Target 5-15% less expenditure than your primary scenario

    The dark horse scenario: This is a more radical proposition that challenges the status quo. For example, what would the budget look like if all data specialists in the organization were centralized under IT? What if IT ran the corporate PMO? What if the entire IT function was 100% outsourced?

    No specific target

    Case Study

    INDUSTRY: Manufacturing

    SOURCE: Anonymous

    A manufacturing IT Director gets budgetary approval by showing what the business would have to sacrifice to get the cheap option.

    Challenge

    Solution

    Results

    A manufacturing business had been cutting costs endlessly across the organization, but specifically in IT.

    IT was down to the bone. The IT Director had already been doing zero-based budgeting to rationalize all expenditure, stretching asset lifecycles as long as possible, and letting maintenance work slide.

    There were no obvious options left to reduce costs based on what the business wanted to do.

    The IT Director got creative. He put together three complete budgets:

    1. The budget he wanted.
    2. A budget where everything was entirely outsourced and there would be zero in-house IT staff.
    3. A budget that was not as extreme as the second one, but still tilted toward outsourcing.

    In the budget presentation, he led with the “super cheap” budget where IT was 100% outsourced.

    He proceeded to review the things they wouldn’t have under the extreme outsourced scenario, including the losses in service levels that would be necessary to make it happen.

    The executive was shocked by what the IT Director showed them.

    The executive immediately approved the IT Director’s preferred budget. He was able to defend the best budget for the business by showing them what they stood to lose.

    3.1 Document your assumptions and alternative scenarios

    2 hours

    1. Download the IT Cost Forecasting and Budgeting Workbook and document the outcomes of this activity on Tab 9, “Alternative Scenarios.”
    2. As a management team, identify and discuss your non-negotiable and negotiable constraints. Document these in rows 4 and 5 respectively in the Workbook.
    3. Brainstorm, list, and challenge any other assumptions being made by IT or the organization’s executive in terms of what can and cannot be done.
    4. Identify the most likely or feasible scenario (primary) and associated assumptions. You will base your initial forecasting on this scenario.
    5. Identify alternative scenarios. Document each scenario’s name, description, and key assumptions, and major opportunities in columns B-D on Tab 9, “Alternative Scenarios.” You will do any calculations for these scenarios after you have completed the forecast for your primary scenario.

    Download the IT Cost Forecasting and Budgeting Workbook

    InputOutput
    • Knowledge of organization’s context, culture, and operations
    • A list of assumptions that will form the logical foundation of your forecasting decisions
    • Identification of the primary budget scenario and alternatives
    MaterialsParticipants
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Before diving into actual forecasting, get clear on project and non-project CapEx and OpEx

    Traditional, binary “CapEx vs. OpEx” distinctions don’t seem adequate for showing where expenditure is really going. We’ve added a new facet to help further differentiate one-time project costs from recurring “business as usual” expenses.

    Project CapEx
    Includes all workforce and vendor costs associated with planning and execution of projects largely focused on the acquisition or creation of new capital assets.

    Non-project CapEx
    Includes “business as usual” capital asset acquisition in the interest of managing, maintaining, or supporting ongoing performance of existing infrastructure or services, such as replacement network equipment, end-user hardware (e.g. laptops), or disaster recovery/business continuity redundancies. Also includes ongoing asset depreciation amounts.

    Non-project OpEx
    Includes all recurring, non-CapEx “business as usual” costs such as labor compensation and training, cloud-based software fees, outsourcing costs, managed services fees, subscriptions, and other discretionary spend.

    Depreciation is technically CapEx. However, for practical purposes, most organizations list it under OpEx, which can cause it to get lost in the noise. Here, depreciation is under non-project CapEx to keep its true CapEx nature visible and in the company of other “business as usual” capital purchases that will ultimately join the depreciation ranks.

    Forecast your project CapEx costs

    This process can be simple as far as overall budget forecasting is concerned. If it isn’t simple now, plan to make it simpler next time around.

    What to expect…

    • Ideally, the costs for all projects should have been thoroughly estimated, reviewed, and accepted by a steering committee, your CFO, or other approving entity at the start of the budgeting season, and funding already committed to. In a nutshell, forecasting your project costs should already have been done and will only require plugging in those numbers.
    • If projects have yet to be pitched and rubber stamped, know that your work is cut out for you. Doing things in a rush or without proper due diligence will result in certain costs being missed. This means that you risk going far over budget in terms of actuals next year, or having to borrow from other areas in your budget to cover unplanned or underestimated project costs.

    Key forecasting principles…

    Develop rigorous business cases
    Secure funding approval well in advance
    Tie back costs benefitting business units
    Consider the longer-term OpEx impact

    For more information about putting together sound business cases for different projects and circumstances, see the following Info-Tech blueprints:

    Build a Comprehensive Business Case

    Fund Innovation with a Minimum Viable Business Case

    Reduce Time to Consensus with an Accelerated Business Case

    Apply these project CapEx forecasting tips

    A good project CapEx forecast requires steady legwork, not last-minute fast thinking.

    Tip #1: Don’t surprise your approvers. Springing a capital project on approvers at your formal presentation isn’t a good idea and stands a good chance of rejection, so do whatever you can to lock these costs down well in advance.

    Tip #2: Project costs should be entirely comprised of CapEx if possible. Keep in mind that some of these costs will convert to depreciated non-project CapEx and non-project OpEx as they transition from project costs to ongoing “business as usual” costs, usually in the fiscal year following the year of expenditure. Creating projections for the longer-term impacts of these project CapEx costs on future types of expenditure is a good idea. Remember that a one-time project is not the same thing as a one-time cost.

    Tip #3: Capitalize any employee labor costs on capital projects. This ensures the true costs of projects are not underestimated and that operational staff aren’t being used for free at the expense of their regular duties.

    Tip #4: Capitalizing cloud costs in year one of a formal implementation project is usually acceptable. It’s possible to continue treating cloud costs as CapEx with some vendors via something called reserved instances, but organizations report that this is a lot of work to set up. In the end, most capitalized cloud will convert into non-project OpEx in years two and beyond.

    Tip #5: Build in some leeway. By the time a project is initiated, circumstances may have changed dramatically from when it was first pitched and approved, including business priorities and needs, vendor pricing, and skillset availability. Your costing may become completely out of date. It’s a good practice to work within more general cost ranges than with specific numbers, to give you the flexibility to respond and adapt during actual execution.

    3.2 Forecast your project CapEx

    Time: Depends on size of project portfolio

    1. Download the IT Cost Forecasting and Budgeting Workbook and navigate to Tab 5, “Project CapEx Forecast”. Add more columns as required. Enter the following for all projects:
      • Row 5 – Its name and/or unique identifier.
      • Row 6 – Its known or estimated project start/end dates.
      • Row 7 – Its status (in proposal, committed, or in progress).
    2. Distribute each project’s costs across the categories listed for each view you’ve selected to map. Do not include any OpEx here – it will be mapped separately under non-project OpEx.
    3. Rationalize your values. A running per-project total for each view, as well as totals for all projects combined, are in rows 16, 28, 39, and 43. Ensure these totals match or are very close across all the views you are mapping. If they don’t match, review the views that are lower-end outliers as there’s a good chance something has been overlooked.

    Download the IT Cost Forecasting and Budgeting Workbook

    InputOutput
    • Project proposals and plans, including cost estimations
    • A project CapEx forecast for next fiscal year
    MaterialsParticipants
    • IT Cost Forecasting and Budgeting Workbook
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Forecast your non-project OpEx

    Most of your budget will be non-project OpEx, so plan to spend most of your forecasting effort here.

    What to expect…

    Central to the definition of OpEx is the fact that it’s ongoing. It rarely stops, and tends to steadily increase over time due to factors like inflation, rising vendor prices, growing organizational growth, increases in the salary expectations of employees, and other factors.

    The only certain ways to reduce OpEx are to convert it to capitalizable expenditure, decrease staffing costs, not pursue cloud technologies, or for the organization to simply not grow. For most organizations, none of these approaches are feasible. Smaller scale efficiencies and optimizations can keep OpEx from running amok, but they won’t change its overall upward trajectory over time. Expect it to increase.

    Key forecasting principles…

    Focus on optimization and efficiency.
    Aim for full spend transparency.
    Think about appropriate chargeback options.
    Give it the time it deserves.

    For more information about how to make the most out of your IT OpEx, see the following Info-Tech blueprints:

    Develop Your Cost Optimization Roadmap

    Achieve IT Spend & Staffing Transparency

    Discover the Hidden Costs of Outsourcing

    Apply these non-project OpEx forecasting tips

    A good forecast is in the details, so take a very close look to see what’s really there.

    Tip #1: Consider zero-based budgeting. You don’t have to do this every year, but re-rationalizing your OpEx every few years, or a just a segment of it on a rotational basis, will not only help you readily justify the expenditure but also find waste and inefficiencies you didn’t know existed.

    Tip #2: Capitalize your employee capital project work. While some organizations aren’t allowed to do this, others who can simply don’t bother. Unfortunately, this act can bloat the OpEx side of the equation substantially. Many regular employees spend a significant amount of their time working on capital projects, but this fact is invisible to the business. This is why the business keeps asking why it takes so many people to run IT.

    Tip #3: Break out your cloud vs. on-premises costs. Burying cloud apps costs in a generic software bucket works against any transparency ambitions you may have. If you have anything resembling a cloud strategy, you need to track, report, and plan for these costs separately in order to measure benefits realization. This goes for cloud infrastructure costs, too.

    Tip #4: Spend time on your CIO service view forecast. Completing this view counts as a first step toward service-based costing and is a good starting point for setting up an accurate service catalog. If looking for cost reductions, you’ll want to examine your forecasts in this view as there will likely be service-level reductions you’ll need to propose to hit your cost-cutting goals.

    Tip #5: Budget with consideration for chargeback. chargeback mechanisms for OpEx can be challenging to manage and have political repercussions, but they do shift accountability back to the business, guarantee that the IT bills get paid, and reduce IT’s OpEx burden. Selectively charging business units for applications that only they use may be a good entry point into chargeback. It may also be as far as you want to go with it. Doing the CXO business view forecast will provide insight into your opportunities here.

    Forecast your non-project CapEx

    These costs are often the smallest percentage of overall expenditure but one of the biggest sources of financial grief for IT.

    What to expect…

    • These costs can be hard to predict. Anticipating expenditure on end-user hardware such as laptops depends on knowing how many new staff will be hired by the organization next year. Predicting the need to buy networking hardware depends on knowing if, and when, a critical piece of equipment is going to spontaneously fail. You can never be completely sure.
    • IT often must reallocate funds from other areas of its budget to cover non-project CapEx costs. Unfortunately, keeping the network running and ensuring employees have access to that network is seen exclusively as an IT problem, not a business problem. Plan to change this mindset.

    Key forecasting principles…

    Discuss hiring plans with the business.
    Pay close attention to your asset lifecycles.
    Prepare to advise about depreciation schedules.
    Build in contingency for the unexpected.

    For more information about ensuring IT isn’t left in the lurch when it comes to non-project CapEx, see the following Info-Tech blueprints:

    Manage End-User Devices

    Develop an Availability and Capacity Management Plan

    Modernize the Network

    Apply these non-project CapEx forecasting tips

    A good forecast relies on your ability to accurately predict the future.

    Tip #1: Top up new hire estimations: Talk to every business unit leader about their concrete hiring plans, not their aspirations. Get a number, increase that number by 25% or 20 FTEs (whichever is less), and use this new number to calculate your end-user non-project CapEx.

    Tip #2: Make an arrangement for who’s paying for operational technology (OT) devices and equipment. OT involves specialized devices such as in-the-field sensors, scanners, meters, and other networkable equipment. Historically, operational units have handled this themselves, but this has created security problems and they still rely on IT for support. Sort the financials out now, including whose budget device and equipment purchases appear on, as well as what accommodations IT will need to make in its own budget to support them.

    Tip #3: Evaluate cloud infrastructure and managed services. These can dramatically reduce your non-project CapEx, particularly on the network and data center fronts. However, these solutions aren’t necessarily less expensive and will drive up OpEx, so tread cautiously.

    Tip #4: Definitely do an inventory. If you haven’t invested in IT asset management, put it on your project and budgetary agenda. You can’t manage what you don’t know you have, so asset discovery should be your first order of business. From there, start gathering asset lifecycle information and build in alerting to aid your spend planning.

    Tip #5: Think about retirement: What assets are nearing end of life or the end of their depreciation schedule? What impact is this having on non-project OpEx in terms of maintenance and support? Deciding to retire, replace, or extend an IT operational asset will change your non-project CapEx outlook and will affect costs in other areas.

    Tip #6: Create a contingency fund: You need one to deal with surprises and emergencies, so why wait?

    Document the organization’s projected FTEs by business function

    This data point is usually missing from IT’s budget forecasting data set. Try to get it.

    A powerful metric to share with business stakeholders is expenditure per employee or FTE. It’s powerful because:

    • It’s one of the few metrics that’s intuitively understood by most people
    • It can show changes in IT expenditure over time at both granular and general levels.

    This metric is one of the simplest to calculate. The challenge is in getting your hands on the data in the first place.

    • Most business unit leaders struggle to pin down this number in terms of actuals as they have difficulty determining what an FTE actually is. Does it include contract staff? Part-time staff? Seasonal workers? Volunteers and interns? And if the business unit has high turnover, this number can fluctuate significantly.
    • Encourage your business peers to produce a rational estimate. Unlike the headcount number you’re seeking to forecast for non-project capital expenditure for end-user hardware, this FTE number should strive to be more in the ballpark, as you’re not using it to ensure sufficient funds but comparatively track expenditure year to year.
    • Depending on your industry, employees or FTEs may not be the best measurement. Use what works best for you. Number of unique users is a common one. Other industry-specific examples include per student, per bed, per patient, per account, and per resident.

    Start to build in long-term and short-term forecasting into your budgeting process

    These are growing practices in mature IT organizations that afford significant flexibility.

    Short-term forecasting:

    Long-term forecasting:

    • At Donaldson Company, budgeting is a once-a-year event, but they’ve started formalizing a forecast review three times a year.
    • These mini-forecasts are not as full blown as the annual forecasting process. Rather, they look at specific parts of the budget and update it based on changing realities.

    “It’s a great step in the right direction. We look at
    the current, and then the future. What we’re really pushing is how to keep that outyear spend more in discussion. The biggest thing we’re trying to do when we approve projects is look at what does that approval do to outyear spend? Is it going to increase? Is it going to decrease? Will we be spending more on licensing? On people?”

    – Kristen Thurber, IT Director, Office of the CIO,
    Donaldson Company

    • In 2017, the Hawaii Medical Service Association accepted the fact that they were very challenged with legacy systems. They needed to modernize.
    • They created a multi-year strategic budget -- a five-year investment plan. This plan was a success. They were able to gain approval for a five-year horizon with variable allocations per year, as required.

    “This approach was much better. We now
    have a “guarantee” of funding for five years now – they’ve conceptually agreed. Now we don’t have
    to make that request for new money every time
    if we need more. We can vary the amount every
    year – it doesn’t have to be the same.”

    – Trisha Goya, Director, IT Governance & Administration,
    Hawaii Medical Service Association

    3.4 Forecast your non-project OpEx and CapEx

    Time: Depends on size of vendor portfolio and workforce

    1. Download the IT Cost Forecasting and Budgeting Workbook and navigate to Tab 4, “Business as Usual Forecast”. This tab assumes an incremental budgeting approach. Last year’s actuals have been carried forward for you to build upon.
    2. Enter expected percentage-based cost increases/decreases for next fiscal year for each of the following variables (columns E-I): inflation, vendor pricing, labor costs, service levels, and depreciation. Do this for all sub-categories for the ITFM cost model views you’ve opted to map. Provide rationales for your percentage values in column K.
    3. In columns M and N, enter the anticipated percentage allocation of cost to non-project CapEx versus non-project OpEx.
    4. In column O, rows 29-38, enter the projected FTEs for each business function (if available).
    5. If you choose, make longer-term, high-level forecasts for 2-3 years in the future in columns P-U. Performing longer-term forecasts for at least the CFO expense view categories is recommended.

    Download the IT Cost Forecasting and Budgeting Workbook

    Input Output
    • Last fiscal year’s actuals
    • Knowledge of likely inflation, vendor cost, and salary expectations for next fiscal year
    • Depreciation amounts
    • A non-project OpEx and CapEx forecast for next fiscal year
    Materials Participants
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Case Study

    INDUSTRY: Insurance

    SOURCE: Anonymous

    Challenge

    Solution

    Results

    In his first run at the annual budgeting process, a new CIO received delivery dates from Finance and spent the next three months building the budget for the next fiscal year.

    He discovered that the organization had been underinvesting in IT for a long time. There were platforms without support, no accounting for currency exchange rates on purchases, components that had not be upgraded in 16 years, big cybersecurity risks, and 20 critical incidences a month.

    In his budget, the CIO requested a 22-24% increase in IT expenditure to deal with the critical gaps, and provided a detailed defense of his proposal

    But the new CIO’s team and Finance were frustrated with him. He asked his IT finance leader why. She said she didn’t understand what his direction was and why the budgeting process was taking so long – his predecessor did the budget in only two days. He would add up the contracts, add 10% for inflation, and that’s it.

    Simply put, the organization hadn’t taken budgeting seriously. By doing it right, the new CIO had inadvertently challenged the status quo.

    The CIO ended up under-executing his first budget by 12% but is tracking closer to plan this year. Significantly, he’s been able cut critical incidences from 20 down to only 2-3 per month.

    Some friction persists with the CFO, who sees him as a “big spender,” but he believes that this friction has forced him to be even better.

    Phase recap: Develop your forecasts

    The hard math is done. Now it’s time to step back and craft your final proposed budget and its key messages.

    This phase focused on developing your forecasts and proposed budget for next fiscal year. It included:

    • Developing assumptions and alternative scenarios. These will showcase your understanding of business context as well as what’s most likely to happen (or should happen) next year.
    • Forecasting your project CapEx costs. If these costs weren’t laid out already in formal, approved project proposals or plans, now you know why it’s the better approach for developing a budget.
    • Forecasting your non-project CapEx and OpEx costs. Now you should have more clarity and transparency concerning where these costs are going and exactly why they need to go there.

    “Ninety percent of your projects will get started but a good 10% will never get off the ground because of capacity or the business changes their mind or other priorities are thrown in. There are always these sorts of challenges that come up.”

    – Theresa Hughes, Executive Counselor,
    Info-Tech Research Group
    and Former IT Executive

    Phase 4

    Build Your Proposed Budget

    Lay Your
    Foundation

    Get Into Budget-Starting Position

    Develop Your
    Forecasts

    Build Your
    Proposed Budget

    Create and Deliver Your Presentation

    1.1 Understand what your budget is
    and does

    1.2 Know your stakeholders

    1.3 Continuously pre-sell your budget

    2.1 Assemble your resources

    2.2 Understand the four views of the ITFM Cost Model

    2.3 Review last year’s budget vs.
    actuals and five-year historical trends

    2.4 Set your high-level goals

    3.1 Develop assumptions and
    alternative scenarios

    3.2 Forecast your project CapEx

    3.3 Forecast your non-project CapEx and OpEx

    4.1 Aggregate your numbers

    4.2 Stress test your forecasts

    4.3 Challenge and perfect your
    rationales

    5.1 Plan your content

    5.2 Build your presentation

    5.3 Present to stakeholders

    5.4 Make final adjustments and submit your IT budget

    This phase will walk you through the following activities:

    • Pulling your forecasts together into a comprehensive IT budget for next fiscal year.
    • Double checking your forecasts to ensure they’re accurate.
    • Fine tuning the rationales behind your proposals.

    This phase involves the following participants:

    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Build your proposed budget

    Triple check your numbers and put the finishing touches on your approval-winning rationales.

    This phase is where your analysis and decision making finally come together into a coherent budget proposal. Key steps include:

    • Aggregating your numbers. This step involves pulling together your project CapEx, non-project CapEx, and non-project OpEx forecasts into a comprehensive whole and sanity-checking your expenditure-type ratios.
    • Stress-testing your forecasts. Do some detailed checks to ensure everything’s accounted for and you haven’t overlooked any significant information or factors that could affect your forecasted costs.
    • Challenging and perfecting your rationales. Your ability to present hard evidence and rational explanations in support of your proposed budget is often the difference between a yes or a no. Look at your proposals from different stakeholder perspectives and ask yourself, “Would I say yes to this if I were them?”

    “We don’t buy servers and licenses because we want to. We buy them because we have to. IT doesn’t need those servers out at our data center provider, network connections, et cetera. Only a fraction of these costs are to support us in the IT department. IT doesn’t have control over these costs because we’re not the consumers.”

    – Matt Johnson, IT Director Governance and Business Solutions, Milwaukee County

    Great rationales do more than set you up for streamlined budgetary approval

    Rationales build credibility and trust in your business capabilities. They can also help stop the same conversations happening year after year.

    Any item in your proposed budget can send you down a rabbit hole if not thoroughly defensible.

    You probably won’t need to defend every item, but it’s best to be prepared to do so. Ask yourself:

    • What areas of spend does the CFO come back to year after year? Is it some aspect of OpEx, such as workforce costs or cloud software fees? Is it the relationship between proposed project spend and business benefits? Provide detailed and transparent rationales for these items to start re-directing long-term conversations to more strategic issues.
    • What areas of spend seem to be recurring points of conflict with business unit leaders? Is it surprise spend that comes from business decisions that didn’t include IT? Is it business-unit leaders railing against chargeback? Have frank, information-sharing conversations focused on business applications, service-level requirements, and true IT costs to support them.
    • What’s on the CEO’s mind? Are they focused on entering a new overseas market, which will require capital investment? Are they interested in the potential of a new technology because competitors are adopting it? It may not be the same focus as last year, so ensure you have fresh rationales that show how IT will help deliver on these business goals.

    “Budgets get out of control when one department fails to care for the implications of change within another department's budget. This wastes time, reduces accuracy and causes conflict.”

    – Tara Kinney, Atomic Revenue, LLC.

    Rationalizing costs depends on the intention of the spend

    Not all spending serves the same purpose. Some types require deeper or different justifications than others.

    For the business, there are two main purposes for spend:

    1. Spending that drives revenues or the customer experience. Think in terms of return on investment (ROI), i.e. when will the expenditure pay for itself via the revenue gains it helps create?
    2. Spending that mitigates and manages risk. Think in terms of cost-benefit, i.e. what are the costs of doing something versus doing nothing at all?
    Source: Kris Blackmon, NetSuite Brainyard.

    “Approval came down to ROI and the ability to show benefits realization for years one, two, and three through five.”

    – Duane Cooney, Executive Counselor, Info-Tech Research Group, and Former Healthcare CIO

    Regardless of its ultimate purpose, all expenditure needs statements of assumptions, obstacles, and likelihood of goals being realized behind it.

    • What are the assumptions that went into the calculation?
    • Is the spend new or a reallocation (and from where)?
    • What’s the likelihood of realizing returns or benefits?
    • What are potential obstacles to realizing returns or benefits?

    Rationales aren’t only for capital projects – they can and should be applied to all proposed OpEx and CapEx. Business project rationales tend to drive revenue and the customer experience, demanding ROI calculations. Internal IT-projects and non-project expenditure are often focused on mitigating and managing risk, requiring cost-benefit analysis.

    First, make sure your numbers add up

    There are a lot of numbers flying around during a budgeting process. Now’s the time to get out of the weeds, look at the big picture, and ensure everything lines up.

    Overall

    Non-Project OpEx

    Non-Project CapEx

    Project CapEx

    • Is your proposed budget consistent with previous IT expenditure patterns?
    • Did you account for major known anomalies or events?
    • Is your final total in line with your CFO’s communicated targets and expectations?
    • Are your alternative scenarios realistic and reflective of viable economic contexts that your organization could find itself in in the near term?
    • Are the OpEx-to-CapEx ratios sensible?
    • Does it pass your gut check?
    • Did you research and verify market rates for employees and skill sets?
    • Did you research and verify likely vendor pricing and potential increases?
    • Are cost categories with variances greater than +5% backed up by defensible IT hiring plans or documented operational growth or improvement initiatives?
    • Have you accounted for the absorption of previous capital project costs into day-to-day management, maintenance, and support operations?
    • Do you have accurate depreciation amounts and timeframes for their discontinuation?
    • Are any variances driven by confirmed business plans to increase headcount, necessitating purchase of end-user hardware and on-premises software licenses?
    • Are any variances due to net-new planned/contingency purchases or the retirement of depreciable on-premises equipment?
    • Is funding for all capital projects represented reliable, i.e. has it been approved?
    • Are all in-progress, proposed, or committed project CapEx costs backed up with reliable estimates and full project documentation?
    • Do capital project costs include the capitalizable costs of employees working on those projects, and were these amounts deducted from non-project OpEx?
    • Have you estimated the longer-term OpEx impact of your current capital projects?

    4.1 Aggregate your proposed budget numbers and stress test your forecasts

    2 hours

    1. Download the IT Cost Forecasting and Budgeting Workbook for this activity. If you have been using it thus far, the Workbook will have calculated your numbers for you across the four views of the ITFM Cost Model on Tab 7, “Proposed Budget”, including:
      1. Forecasted non-project OpEx, non-project CapEx (including depreciation values), project CapEx, and total values.
      2. Numerical and percentage variances from the previous year.
    2. Test and finalize your forecasts by applying the questions on the previous slide.
    3. Flag cost categories where large variances from the previous year or large numbers in general appear – you will need to ensure your rationales for these variances are rigorous in the next step.
    4. Make amendments if needed to Tabs 4, “Business as Usual Forecast” and 5, “Project CapEx Forecast” in the IT Cost Forecasting and Budgeting Workbook.

    Download the IT Cost Forecasting and Budgeting Workbook

    InputOutputMaterialsParticipants
    • Final drafts of all IT cost forecasts
    • A final proposed IT budget
    • IT Cost Forecasting and Budgeting Workbook
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Case Study

    INDUSTRY: Healthcare

    SOURCE: Anonymous

    Challenge

    Solution

    Results

    A senior nursing systems director needed the CIO’s help. She wanted to get a project off the ground, but it wasn’t getting priority or funding.

    Nurses were burning out. Many were staying one to two hours late per shift to catch up on patient notes. Their EHR platform had two problematic workflows, each taking up to about 15 minutes per nurse per patient to complete. These workflows were complex, of no value, and just not getting done. She needed a few million dollars to make the fix.

    The CIO worked with the director to do the math. In only a few hours, they realized that the savings from rewriting the workflows would allow them to hire over 500 full-time nurses.

    The benefits realized would not only help reduce nurse workload and generate savings, but also increase the amount of time spent with patients and number of patients seen overall. They redid the math several times to ensure they were right.

    The senior nursing systems director presented to her peers and leadership, and eventually to the Board of Directors. The Board immediately saw the benefits and promoted the project to first on the list ahead of all other projects.

    This collaborative approach to generating project benefits statements helped the CIO gain trust and pave the way for future budgets.

    The strength of your rationales will determine how readily your budget is approved

    When proposing expenditure, you need to thoroughly consider the organization’s goals, its governance culture, and the overall feasibility of what’s being asked.

    First, recall what budgets are really about.

    The completeness, accuracy, and granularity of your numbers and thorough ROI calculations for projects are essential. They will serve you well in getting the CFO’s attention. However, the numbers will only get you halfway there. Despite what some people think, the work in setting a budget is more about the what, how, and why – that is, the rationale – than about the how much.

    Next, revisit Phase 1 of this blueprint and review:

    • Your organization’s budgeting culture and processes.
    • The typical accountabilities, priorities, challenges, opportunities, and expectations associated with your CFO, CEO, and CXO IT budget stakeholders.
    • Your budgetary mandate as the head of IT.

    Then, look at each component of your proposed budget through each of these three rationale-building lenses.

    Business goals
    What are the organization’s strategic priorities?

    Governance culture
    How constrained is the decision-making process?

    Feasibility
    Can we make it happen?

    Linking proposed spend to strategic goals isn’t just for strategic project CapEx

    Tie in your “business as usual” non-project OpEx and CapEx, as well.

    Business goals

    What are the organization’s strategic priorities?

    Context

    This is all about external factors, namely the broader economic, political, and industry contexts in which the organization operates.

    Lifecycle position

    The stage the organization is at in terms of growth, stability, or decline will drive decisions, priorities, and the ability to spend or invest.

    Opportunities

    Context and lifecycle position determine opportunities, which are often defined in terms of potential cost savings
    or ROI.

    Tie every element in your proposed budget to an organizational goal.

    Non-project OpEx

    • Remember that OpEx is what comes from the realization of past strategic goals. If that past goal is still valid, then the OpEx that keeps that goal alive is, too.
    • Business viability and continuity are often unexpressed goals. OpEx directly supports these goals.
    • Periodically apply zero-based budgeting to OpEx to re-rationalize and identify waste.

    Non-project CapEx

    • Know the impact of any business growth goals on future headcount – this is essential to rationalize laptop/desktop and other end-user hardware spend.
    • Position infrastructure equipment spend in terms of having sufficient capacity to support growth goals as well as ensuring network/system reliability and continuity.
    • Leverage depreciation schedules as backup.

    Project CapEx

    • Challenge business-driven CapEx projects if they don’t directly support stated goals.
    • Ideally, the goal-supporting rationales for software, hardware, and workforce CapEx have been laid out in an already-approved project proposal. Refer to these plans.
    • If pitching a capital project at the last minute, especially an IT-driven one, expect a “no” regardless of how well it ties to goals.

    Your governance culture will determine what you need to show and when you show it

    The rigor of your rationales is entirely driven by “how things are done around here.”

    Governance Culture

    How rigorous/ constrained
    is decision-making?

    Risk tolerance

    This is the organization’s willingness to be flexible, take chances, make change, and innovate. It is often driven by legal and regulatory mandates.

    Control

    Control manifests in the number and nature of rules and how authority and accountability are centralized or distributed in the organization.

    Speed to action

    How quickly decisions are made and executed upon is determined by the amount of consultation and number of approval steps.

    Ensure all parts of your proposed budget align with what’s tolerated and allowed.

    Non-project OpEx

    • Don’t hide OpEx. If it’s a dirty word, put it front and center to start normalizing it.
    • As with business goals, position OpEx as necessary for business continuity and risk mitigation, as well as the thing that keeps long-term strategic goals alive.
    • Focus on efficiency and cost control, both in terms of past and future initiatives, regardless of the governance culture.

    Non-project CapEx

    • Treat non-project CapEx in the same way as you would non-project OpEx.
    • IT must make purchases quickly in this area of spend, but drawn-out procurement processes can make this impossible. Consider including a separate proposal to establish a policy that gives IT the control to make end-user and network/data center equipment purchases faster and easier.

    Project CapEx

    • If your organization is risk-averse, highly centralized, or slow to act, don’t expect IT to win approval for innovative capital projects. Let the business make any pitches and have IT serve in a supporting role.
    • Capital projects are often committed to 6-12 months in advance and can’t be completed within a fiscal year. Nudge the organization toward longer-term, flexible funding.

    No matter which way your goals and culture lean, ground all your rationales in reality

    Objective, unapologetic facts are your strongest rationale-building tool.

    Feasibility

    Can we do it, and what sacrifices will we have to make?

    Funding

    The ultimate determinant of feasibility is the availability, quantity, and reliability of funding next fiscal year and over the long term to support investment.

    Capabilities

    Success hinges on both the availability and accessibility of required skills and knowledge to execute on a spend plan in the required timeframe.

    Risk

    Risk is not just about obstacles to success and what could happen if you do something – it’s also about what could happen if you do nothing at all.

    Vet every part of your proposed budget to ensure what you’re asking for is both realistic and possible.

    Non-project OpEx

    • Point out your operational waste-reduction and efficiency-gaining efforts in hard, numerical terms.
    • Clearly demonstrate that OpEx cannot be reduced without sacrifices on the business side, specifically in terms of service levels.
    • Define OpEx impacts for all CapEx proposals to ensure funding commitments include long-term maintenance and support.

    Non-project CapEx

    • This is a common source of surprise budget overage, and IT often sacrifices parts of its OpEx budget to cover it. Shed light on this problem and define IT’s boundaries.
    • A core infrastructure equipment contingency fund and a policy mandating business units pay for unbudgeted end-user tech due to unplanned or uncommunicated headcount increases are worth pursuing.

    Project CapEx

    • Be sure IT is involved with every capital project proposal that has a technological implication (which is usually all of them).
    • Specifically, IT should take on responsibility for tech vendor evaluation and negotiation. Never leave this up to the business.
    • Ensure IT gains funding for supporting any technologies acquired via a capital planning process, including hiring if necessary.

    Double-check to ensure your bases are covered

    Detailed data and information checklist:

    • I have the following data and information for each item of proposed expenditure:
    • Sponsors, owners, and/or managers from IT and the business.
    • CapEx and OpEx costs broken down by workforce (employees/contract) and vendor (software, hardware, services) at a minimum for both last fiscal year (if continuing spend) and next fiscal year to demonstrate any changes.
    • Projected annual costs for the above, extending two to five years into the future, with dates when new spending will start, known depreciations will end, and CapEx will transition to OpEx.
    • Descriptions of any tradeoffs or potential obstacles.
    • Lifespan information for new, proposed assets informing depreciation scheduling.
    • Sources of funding (especially if new, transferred, or changed).
    • Copies of any research used to inform any of the above.

    High-level rationale checklist:

    • I have done the following thinking and analysis for each item of proposed expenditure:
    • Considered it in the context of my organization’s broader operating environment and the constraints and opportunities this creates.
    • Tied it – directly or indirectly – to the achievement or sustainment of current or past (but still relevant) organizational goals.
    • Understood my organization’s tolerances, how things get done, and whether I can win any battles that I need to fight given these realities.
    • Worked with business unit leaders to fully understand their plans and how IT can support them.
    • Obtained current, verifiable data and information and have a good idea if, when, and how this information may change next year.
    • Assessed benefits, risks, dependencies, and overall feasibility, as well as created ROI statements where needed.
    • Stuck to the facts and am confident they can speak for themselves.

    For more on creating detailed business cases for projects and investments, see Info-Tech’s comprehensive blueprint, Build a Comprehensive Business Case.

    4.2 Challenge and perfect your rationales

    2 hours

    1. Based on your analysis in Phase 1, review your organization’s current and near-term business goals (context, lifecycle position, opportunities), governance culture (risk tolerance, control, speed to action), and feasibility (funding, capabilities, risk) to understand what’s possible, what’s not, and your general boundaries.
    2. Review your proposed budget in its current form and flag items that may be difficult or impossible to sell, given the above.
    3. Systematically go through each item in you proposed budget and apply the detailed data and information and high-level rationale checklists on the previous slide to ensure you have considered it from every angle and have all the information you need to defend it.
    4. Track down any additional information needed to fill gaps and fine-tune your budget based on any discoveries, including eliminating or adding elements if needed.

    Download the IT Cost Forecasting and Budgeting Workbook

    InputOutput
    • Final drafts of all IT cost forecasts, including rationales
    • Fully rationalized proposed IT budget for next fiscal year
    MaterialsParticipants
    • IT Cost Forecasting and Budgeting Workbook
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Phase recap: Build your proposed budget

    You can officially say your proposed IT budget is done. Now for the communications part.

    This phase is where everything came together into a coherent budget proposal. You were able to:

    • Aggregate your numbers. This involved pulling for project and non-project CapEx and OpEx forecasts into a single proposed IT budget total.
    • Stress-test your forecasts. Here, you ensured that all your numbers were accurate and made sense.
    • Challenge and perfect your rationales. Finally, you made sure you have all your evidence in place and can defend every component in your proposed IT budget regardless of who’s looking at it.

    “Current OpEx is about supporting and aligning with past business strategies. That’s alignment. If the business wants to give up on those past business strategies, that’s up to them.”

    – Darin Stahl, Distinguished Analyst and Research Fellow, Info-Tech Research Group

    Phase 5

    Create and Deliver Your Presentation

    Lay Your
    Foundation

    Get Into Budget-Starting Position

    Develop Your
    Forecasts

    Build Your
    Proposed Budget

    Create and Deliver Your Presentation

    1.1 Understand what your budget is
    and does

    1.2 Know your stakeholders

    1.3 Continuously pre-sell your budget

    2.1 Assemble your resources

    2.2 Understand the four views of the ITFM Cost Model

    2.3 Review last year’s budget vs.
    actuals and five-year historical trends

    2.4 Set your high-level goals

    3.1 Develop assumptions and
    alternative scenarios

    3.2 Forecast your project CapEx

    3.3 Forecast your non-project CapEx and OpEx

    4.1 Aggregate your numbers

    4.2 Stress test your forecasts

    4.3 Challenge and perfect your
    rationales

    5.1 Plan your content

    5.2 Build your presentation

    5.3 Present to stakeholders

    5.4 Make final adjustments and submit your IT budget

    This phase will walk you through the following activities:

    • Planning the content you’ll include in your budget presentation.
    • Pulling together your formal presentation.
    • Presenting, finalizing, and submitting your budget.

    This phase involves the following participants:

    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Create and deliver your presentation

    Pull it all together into something you can show your approvers and stakeholders and win IT budgetary approval.

    This phase focuses on developing your final proposed budget presentation for delivery to your various stakeholders. Here you will:

    • Plan your final content. Decide the narrative you want to tell and select the visualizations and words you want to include in your presentation (or presentations) depending on the makeup of your target audience.
    • Build your presentation. Pull together all the key elements in a PowerPoint template in a way that best tells the IT budget story.
    • Present to stakeholders. Deliver your IT budgetary message.
    • Make final adjustments and submit your budget. Address any questions, make final changes, and deconstruct your budget into the account categories mandated by your Finance Department to plug into the budget template they’ve provided.

    “I could have put the numbers together in a week. The process of talking through what the divisions need and spending time with them is more time consuming than the budget itself.”

    – Jay Gnuse, IT Director, Chief Industries

    The content you select to present depends on your objectives and constraints

    Info-Tech classifies potential content according to three basic types: mandatory, recommended, and optional. What’s the difference?

    Mandatory: Just about every CFO or approving body will expect to see this information. Often high level in nature, it includes:

    • A review of last year’s performance.
    • A comparison of proposed budget totals to last year’s actuals.
    • A breakdown of CapEx vs. OpEx.
    • A breakdown of proposed expenditure according to traditional workforce and vendor costs.

    Recommended: This information builds on the mandatory elements, providing more depth and detail. Inclusion of recommended content depends on:

    • Availability of the information.
    • Relevance to a current strategic focus or overarching initiative in the organization.
    • Known business interest in the topic, or the topic’s ability to generate interest in IT budgetary concerns in general.

    Optional: This is very detailed information that provides alternative views and serves as reinforcement of your key messages. Consider including it if:

    • You need to bring fuller transparency to a murky IT spending situation.
    • Your audience is open to it, i.e. it wouldn’t be seen as irrelevant, wasting their time, or a cause of discord.
    • You have ample time during your presentation to dive into it.

    Deciding what to include or exclude depends 100% on your target audience. What will fulfill their basic information needs as well as increase their engagement in IT financial issues?

    Revisit your assumptions and alternative scenarios first

    These represent the contextual framework for your proposal and explain why you made the decisions you did.

    Stating your assumptions and presenting at least two alternative scenarios helps in the following ways:

    1. Identifies the factors you considered when setting budget targets and proposing specific expenditures, and shows that you know what the important factors are.
    2. Lays the logical foundation for all the rationales you will be presenting.
    3. Demonstrates that you’ve thought broadly about the future of the organization and how IT is best able to support that future organization regardless of its state and circumstances.

    Your assumptions and alternative scenarios may not appear back-to-back in your presentation, yet they’re intimately connected in that every unique scenario is based on adjustments to your core assumptions. These tweaks – and the resulting scenarios – reflect the different degrees of probability that a variable is likely to land on a certain value (i.e. an alternative assumption).

    Your primary scenario is the one you believe is most likely to happen and is represented by the complete budget you’re recommending and presenting.

    Target timeframe for presentation: 2 minutes

    Key objectives: Setting context, demonstrating breadth of thought.

    Potential content for section:

    • List of assumptions for the budget being presented (primary target scenario).
    • Two or more alternative scenarios.

    “Things get cut when the business
    doesn’t know what something is,
    doesn’t recognize it, doesn’t understand it. There needs to be an education.”

    – Angie Reynolds, Principal Research Director, ITFM Practice,
    Info-Tech Research Group,

    Select your assumptions and scenarios

    See Tabs “Planning Variables” and 9, “Alternative Scenarios” in your IT Cost Forecasting and Budgeting Workbook for these outputs.

    Core assumptions

    Primary target scenario

    Alternative scenarios

    Full alternative scenario budgets

    List

    Slide

    Slide

    Budget

    Mandatory: This is a listing of both internal and external factors that are most likely to affect the challenges and opportunities your organization will have and how it can and will operate. This includes negotiable and non-negotiable internal and external constraints, stated priorities, and the expression of known risk factors.

    Mandatory: Emanating from your core assumptions, this scenario is a high-level statement of goals, initial budget targets, and proposed budget based on your core assumptions.

    Recommended: Two alternatives are typical, with one higher spend and one lower spend than your target. The state of the economy and funding availability are the assumptions usually tweaked. More radical scenarios, like the cost and implications of completely outsourcing IT, can also be explored.

    Optional: This is a lot of work, but some IT leaders do it if an alternative scenario is a strong contender or is necessary to show that a proposed direction from the business is costly or not feasible.

    The image contains screenshots of tab Planning Variables and Alternative Scenarios.

    The first major section of your presentation will be a retrospective

    Plan to kick things off with a review of last year’s results, factors that affected what transpired, and longer-term historical IT expenditure trends.

    This retrospective on IT expenditure is important for three reasons:

    1. Clarifying definitions and the different categories of IT expenditure.
    2. Showing your stakeholders how, and how well you aligned IT expenditure with business objectives.
    3. Setting stakeholder expectations about what next year’s budget will look like based on past patterns.

    You probably won’t have a lot of time for this section, so everything you select to share should pack a punch and perform double duty by introducing concepts you’ll need your stakeholders to have internalized when you present next year’s budget details.

    Target timeframe for presentation: 7 minutes

    Key objectives: Definitions, alignment, expectations-setting.

    Potential content for section:

    • Last fiscal year budgeted vs. actuals
    • Expenditure by type
    • Major capital projects completed
    • Top vendor spend
    • Drivers of last year’s expenditures and efficiencies
    • Last fiscal year in in detail (expense view, service view, business view, innovation view)
    • Expenditure trends for the past five years

    “If they don’t know the consequences of their actions, how are they ever going to change their actions?”

    – Angela Hintz, VP of PMO & Integrated Services,
    Blue Cross and Blue Shield of Louisiana

    Start at the highest level

    See Tabs 1 “Historical Events & Projects,” 3 “Historical Analysis,” and 6 “Vendor Worksheet” in your IT Cost Forecasting and Budgeting Workbook for these outputs.

    Total budgeted vs. total actuals

    Graph

    Mandatory: Demonstrates the variance between what you budgeted for last year and what was actually spent. Explaining causes of variance is key.

    l actuals by expenditure type

    Graph

    Mandatory: Provides a comparative breakdown of last year’s expenditure by non-project OpEx, non-project CapEx, and project CapEx. This offers an opportunity to explain different types of IT expenditure and why they’re the relative size they are.

    Major capital projects completed

    List

    Mandatory: Illustrates progress made toward strategically important objectives.

    Top vendors

    List

    Recommended: A list of vendors that incurred the highest costs, including their relative portion of overall expenditure. These are usually business software vendors, i.e. tools your stakeholders use every day. The number of vendors shown is up to you.

    The image contains screenshots from Tabs 1, 3, and 6 of the IT Cost Forecasting and Budgeting Workbook.

    Describe drivers of costs and savings

    See Tab 1, “Historical Events & Projects” in your IT Cost Forecasting and Budgeting Workbook for these outputs.

    Cost drivers

    List

    Mandatory: A list of major events, circumstances, business decisions, or non-negotiable factors that necessitated expenditure. Be sure to focus on the unplanned or unexpected situations that caused upward variance.

    Savings drivers

    List

    Mandatory: A list of key initiatives pursued, or circumstances that resulted in efficiencies or savings. Include any deferred or canceled projects.

    The image contains screenshots from Tab 1 of the IT Cost Forecasting and Budgeting Workbook.

    Also calculate and list the magnitude of costs incurred or savings realized in hard financial terms so that the full impact of these events is truly understood by your stakeholders.

    “What is that ongoing cost?
    If we brought in a new platform, what
    does that do to our operating costs?”

    – Kristen Thurber, IT Director, Office of the CIO, Donaldson Company

    End with longer-term five-year trends

    See Tab 3 “Historical Analysis” in your IT Cost Forecasting and Budgeting Workbook for these outputs.

    IT actual expenditure
    year over year

    Graph

    Mandatory: This is crucial for showing overall IT expenditure patterns, particularly percentage changes up or down year to year, and what the drivers of those changes were.

    IT actuals as a % of organizational revenue

    Graph

    Mandatory: You need to set the stage for the proposed percentage of organizational revenue to come. The CFO will be looking for consistency and an overall decreasing pattern over time.

    IT expenditure per FTE year over year

    Graph

    Optional: This can be a powerful metric as it’s simple and easily to understand.

    The image contains screenshots from Tab 3 of the IT Cost Forecasting and Budgeting Workbook.

    The historical analysis you can do is endless. You can generate many more cuts of the data or go back even further – it’s up to you.

    Keep in mind that you won’t have a lot of time during your presentation, so stick to the high-level, high-impact graphs that demonstrate overarching trends or themes.

    Show different views of the details

    See Tab 3 “Historical Analysis” in your IT Cost Forecasting and Budgeting Workbook for these outputs.

    Budgeted vs. actuals CFO expense view

    Graph

    Mandatory: Showing different types of workforce expenditure compared to different types of vendor expenditure will be important to the CFO.

    Budgeted vs. actuals CIO services view

    Graph

    Optional: Showing the expenditure of some IT services will clarify the true total costs of delivering and supporting these services if misunderstandings exist.

    Budgeted vs. actuals CXO business view

    Graph

    Optional: A good way to show true consumption levels and the relative IT haves and have-nots. Potentially political, so consider sharing one-on-one with relevant business unit leaders instead of doing a big public reveal.

    Budgeted vs. actual CEO innovation view

    Graph

    Optional: Clarifies how much the organization is investing in innovation or growth versus keeping the lights on. Of most interest to the CEO and possibly the CFO, and good for starting conversations about how well funding is aligned with strategic directions.

    The image contains screenshots from Tab 3 of the IT Cost Forecasting and Budgeting Workbook.

    5.1a Select your retrospective content

    30 minutes

    1. Open your copy of the IT Cost Forecasting and Budgeting Workbook.
    2. From Tabs 1, “Historical Events & Projects, 3 “Historical Analysis”, and 6, “Vendor Worksheet,” select the visual outputs (graphs and lists) you plan to include in the retrospective section of your presentation. Consider the following when determining what to include or exclude:
      1. Fundamentals: Elements such as budgeted vs. actual, distribution across expenditure types, and drivers of variance are mandatory.
      2. Key clarifications: What expectations need to be set or common misunderstandings cleared up? Strategically insert visuals that introduce and explain important concepts early.
      3. Your time allowance. Plan for a maximum of seven minutes for every half hour of total presentation time.
    3. Note what you plan to include in your presentation and set aside.

    Download the IT Cost Forecasting and Budgeting Workbook

    InputOutput
    • Data and graphs from the completed IT Cost Forecasting and Budgeting Workbook
    • Selected content and visuals for the historical/ retrospective section of the IT Budget Executive Presentation
    MaterialsParticipants
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Next, transition from past expenditure to your proposal for the future

    Build a logical bridge between what happened in the past to what’s coming up next year using a comparative approach and feature major highlights.

    This transitional phase between the past and the future is important for the following reasons:

    1. It illustrates any consistent patterns of IT expenditure that may exist and be relevant in the near term.
    2. It sets the stage for explaining any deviations from historical patterns that you’re about to propose.
    3. It grounds proposed IT expenditure within the context of commitments made in previous years.

    Consider this the essential core of your presentation – this is the key message and what your audience came to hear.

    Target timeframe for presentation: 10 minutes

    Key objectives: Transition, reveal proposed budget.

    Potential content for section:

    • Last year’s actuals vs. next year’s proposed.
    • Next year’s proposed budget in context of the past five years’ year-over-year actuals.
    • Last year’s actual expenditure type distribution vs. next year’s proposed budget distribution.
    • Major projects to be started next year.

    “The companies...that invest the most in IT aren’t necessarily the best performers.
    On average, the most successful small and medium companies are more frugal when it comes to
    company spend on IT (as long as they do it judiciously).”

    – Source: Techvera, 2023

    Compare next year to last year

    See Tab 8, “Proposed Budget Analysis” in your IT Cost Forecasting and Budgeting Workbook for these outputs.

    Last year’s total actuals vs. next year’s total forecast

    Proposed budget in context: Year-over-year expenditure

    Last year’s actuals vs. next year’s proposed by expenditure type

    Last year’s expenditure per FTE vs. next year’s proposed

    Graph

    Graph

    Graph

    Graph

    Mandatory: This is the most important graph for connecting the past with the future and is also the first meaningful view your audience will have of your proposed budget for next year.

    Mandatory: Here, you will continue the long-term view introduced in your historical data by adding on next year’s projections to your existing five-year historical trend. The percentage change from last year to next year will be the focus.

    Recommended: A double-comparative breakdown of last year vs. next year by non-project OpEx, non-project CapEx, and project CapEx illustrates where major events, decisions, and changes are having their impact.

    Optional: This graph is particularly useful in demonstrating the success of cost-control if the actual proposed budget is higher that the previous year but the IT cost per employee has gone down.

    The image contains screenshots from Tab 8 of the IT Cost Forecasting and Budgeting Workbook.

    Select business projects to profile

    See Tab 5, “Project CapEx Forecast” in your IT Cost Forecasting and Budgeting Workbook for the data and information to create these outputs.

    Major project profile

    Slide

    Mandatory: Focus on projects for which funding is already committed and lean toward those that are strategic or clearly support business goal attainment. How many you profile is up to you, but three to five is suggested.

    Minor project overview

    List

    Optional: List other projects on IT’s agenda to communicate the scope of IT’s project-related responsibilities and required expenditure to be successful. Include in-progress projects that will be completed next year and net-new projects on the roster.

    The image contains screenshots from Tab 5 of the IT Cost Forecasting and Budgeting Workbook.

    You can’t profile every project on the list, but it’s important that your stakeholders see their priorities clearly reflected in your budget; projects are the best way to do this.

    If you’ve successfully pre-sold your budget and partnered with business-unit leaders to define IT initiatives, your stakeholders should already be very familiar with the project summaries you put in front of them in your presentation.

    5.1b Select your transitional past-to-future content

    30 minutes

    1. Open your copy of the IT Cost Forecasting and Budgeting Workbook.
    2. From Tabs 5, “Project CapEx Forecast” and 7, “Proposed Budget Analysis”, select the visual outputs (graphs and lists) you plan to include in the transitional section of your presentation. Consider the following when determining what to include or exclude:
      1. Shift from CapEx to OpEx: If this has been a point of contention or confusion with your CFO in the past, or if your organization has actively committed to greater cloud or outsourcing intensity, you’ll want to show this year-to-year shift in expenditure type.
      2. Strategic priorities: Profile major capital projects that reflect stakeholder priorities. If your audience is already very familiar with these projects, you may be able to skip detailed profiles and simply list them.
      3. Your time allowance. Plan for a maximum of 10 minutes for every half hour of total presentation time.
    3. Note what you plan to include in your presentation and set aside.

    Download the IT Cost Forecasting and Budgeting Workbook

    InputOutput
    • Data and graphs from the completed IT Cost Forecasting and Budgeting Workbook
    • Selected content and visuals for the past-to-future transitional section of the IT Budget Executive Presentation
    MaterialsParticipants
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Finally, carefully select detailed drill-downs that add clarity and depth to your proposed budget

    The graphs you select here will be specific to your audience and any particular message you need to send.

    This detailed phase of your presentation is important because it allows you to:

    1. Highlight specific areas of IT expenditure that often get buried under generalities.
    2. View your proposed budget from different perspectives that are most meaningful to your audience, such as traditional workforce vs. vendor allocations, expenditure by IT service, business-unit consumption, and the allocation of funds to innovation and growth versus daily IT operations.
    3. Get stakeholder attention. For example, laying out exactly how much money will be spent next year in support of the Sales Department compared to other units will get the VP of Sales’ attention…and everyone else’s, for that matter. This kind of transparency is invaluable for enabling meaningful conversations and thoughtful decision-making about IT spend.

    Target timeframe for presentation: 7 minutes, but this phase of the presentation may naturally segue into the final Q&A.

    Key objectives: Transparency, dialogue, buy-in.

    Potential content for section:

    • Allocation across workforce vs. vendors
    • Top vendors by expenditure
    • Allocation across on-premises vs. cloud
    • Allocation across core IT services
    • Allocation across core business units
    • Allocation across business focus area

    “A budget is a quantified version of
    your service-level agreements.”

    – Darin Stahl, Distinguished Analysis & Research Fellow,
    Info-Tech Research Group,

    Start with the expense view details

    See Tab 8, “Proposed Budget Analysis” in your IT Cost Forecasting and Budgeting Workbook for these outputs.

    Proposed budget: Workforce and vendors by expenditure type

    Graph

    Mandatory: This is the traditional CFO’s view, so definitely show it. The compelling twist here is showing it by expenditure type, i.e. non-project OpEx, non-project CapEx, and project CapEx.

    Proposed budget: Cloud vs. on-premises vendor expenditure

    Graph

    Optional: If this is a point of contention or if an active transition to cloud solutions is underway, then show it.

    Top vendors

    Graph

    Recommended: As with last year’s actuals, showing who the top vendors are slated to be next year speaks volumes to stakeholders about exactly where much of their money is going.

    If you have a diverse audience with diverse interests, be very selective – you don’t want to bore them with things they don’t care about.

    The image contains screenshots from Tab 8 of the IT Cost Forecasting and Budgeting Workbook.

    Offer choice details on the other views

    See Tab 8, “Proposed Budget Analysis” in your IT Cost Forecasting and Budgeting Workbook for these outputs.

    Proposed budget: IT services by expenditure type

    Graph

    Optional: Business unit leaders will be most interested in the application services. Proposed expenditure on security and data and BI services may be of particular interest given business priorities. Don’t linger on infrastructure spend unless chargeback is in play.

    Proposed budget: Business units by expenditure type

    Graph

    Optional: The purpose of this data is to show varying business units where they stand in terms of consumption. It may be more appropriate to show this graph in a one-on-one meeting or other context.

    Proposed budget: Business focus by expenditure type

    Graph

    Optional: The CEO will care most about this data. If they’re not in the room, then consider bypassing it and discuss it separately with the CFO.

    Inclusion of these graphs really depends on the makeup of your audience. It’s a good decision to show all of them to your CFO at some point before the formal presentation. Consider getting their advice on what to include and exclude.

    The image contains screenshots from Tab 8 of the IT Cost Forecasting and Budgeting Workbook.

    5.1c Select next year’s expenditure sub-category details

    30 minutes

    1. Open your copy of the IT Cost Forecasting and Budgeting Workbook.
    2. From Tab 8, “Proposed Budget Analysis,” select the visual outputs (graphs) you plan to include in the targeted expenditure sub-category details section of your presentation. Consider the following when determining what to include or exclude:
      1. The presence of important fence-sitters. If there are key individuals who require more convincing, this is where you show them the reality of what it costs to deliver their most business-critical IT services to them.
      2. The degree to which you’ve already gone over the numbers previously with your audience. Again, if you’ve done your pre-selling, this data may be old news and not worth going over again.
      3. Your time allowance. Plan for a maximum of seven minutes for every half hour of total presentation time.
    3. Note what you plan to include in your presentation and set aside.

    Download the IT Cost Forecasting and Budgeting Workbook

    InputOutput
    • Data and graphs from the completed IT Cost Forecasting and Budgeting Workbook
    • Selected content and visuals for the expenditure category details section of the IT Budget Executive Presentation
    MaterialsParticipants
    • Whiteboard/flip charts
    • Head of IT
    • IT Financial Lead
    • Other IT Management

    Finalize your line-up and put your selected content into a presentation template

    This step is about nailing down the horizontal logic of the story you want to tell. Start by ordering and loading the visualizations of your budget data.

    Download Info-Tech’s IT Budget Executive Presentation Template

    The image contains a screenshot of the IT Budget Executive Presentation Template.

    If you prefer, use your own internal presentation standard template instead and Info-Tech’s template as a structural guide.

    Regardless of the template you use, Info-Tech recommends the following structure:

    1. Summary: An overview of your decision-making assumptions, initial targets given the business context, and the total proposed IT budget amount.
    2. Retrospective: An overview of previous years’ performance, with a specific focus on last fiscal year.
    3. Proposed budget overview: A high-level view of the proposed budget for next fiscal year in the context of last year’s performance (i.e. the bridge from past to future), including alternative scenarios considered and capital projects on the roster.
    4. Proposed budget details by category: Detailed views of the proposed budget by expense type, IT service, business unit, and business focus category.
    5. Next steps: Include question-and-answer and itemization of your next actions through to submitting your final budget to the CFO.

    Draft the commentary that describes and highlights your data’s key messages

    This is where the rationales that you perfected earlier come into play.

    Leave the details for the speaker’s notes.
    Remember that this is an executive presentation. Use tags, pointers, and very brief sentences in the body of the presentation itself. Avoid walls of text. You want your audience to be listening to your words, not reading a slide.

    Speak to everything that represents an increase or decrease of more than 5% or that simply looks odd.
    Being transparent is essential. Don’t hide anything. Acknowledge the elephant in the room before your audience does to quickly stop suspicious or doubtful thoughts

    Identify causes and rationales.
    This is why your numbers are as they are. However, if you’re not 100% sure what all driving factors are, don’t make them up. Also, if the line between cause and effect isn’t straight, craft in advance a very simple way of explaining it that you can offer whenever needed.

    Be neutral and objective in your language.
    You need to park strong feelings at the door. You’re presenting rational facts and thoroughly vetted recommendations. The best defense is not to be defensive, or even offensive for that matter. You don’t need to argue, plead, or apologize – let your information speak for itself and allow the audience to arrive at their own logical conclusions.

    Re-emphasize your core themes to create connections.
    If a single strategic project is driving cost increases across multiple cost categories, point it out multiple times if needed to reinforce its importance. If an increase in one area is made possible by a significant offset in another, say so to demonstrate your ongoing commitment to efficiencies. If a single event from last year will continue having cost impacts on several IT services next year, spell this out.

    5.2 Develop an executive presentation

    Duration: 2 hours

    1. Download the IT Budget Executive Presentation PowerPoint template.
    2. Open your working version of the IT Cost Forecasting and Budgeting Workbook and copy and paste your selected graphs and tables into the template. Note: Pasting as an image will preserve graph formatting.
    3. Incorporate observations and insights about your proposed budget and other analysis into the template where indicated.
    4. Conduct an internal review of the final presentation to ensure it includes all the elements you need and is error-free.

    Note: Refer to your organization’s standards and norms for executive-level presentations and either adapt the Info-Tech template accordingly or use your own.

    Download the IT Budget Executive Presentation template

    Input Output
    • Tabular and graphical data outputs in the IT Cost Forecasting and Budgeting Workbook
    • Interpretive commentary based on your analysis
    • Executive presentation summarizing your proposed IT budget
    Materials Participants
    • IT Cost Forecasting and Budgeting Workbook
    • IT Budget Executive Presentation template
    • CIO/IT Directors
    • IT Financial Lead
    • Other IT Management

    Now it’s time to present your proposed IT budget for next fiscal year

    If you’ve done your homework and pre-sold your budget, the presentation itself should be a mere formality with no surprises for anyone, including you.

    Some final advice on presenting your proposed budget…

    Partner up

    If something big in your budget is an initiative that’s for a specific business unit, let that business unit’s leader be the face of it and have IT play the role of supporting partner.

    Use your champions

    Let your advocates know in advance that you’d appreciate hearing their voice during the presentation if you encounter any pushback, or just to reinforce your main messages.

    Focus on the CFO

    The CFO is the most important stakeholder in the room at the end of the day, even more than the CEO in some cases. Their interests should take priority if you’re pressed for time.

    Avoid judgment

    Let the numbers speak for themselves. Do point out highlights and areas of interest but hold off on offering emotion-driven opinions. Let your audience draw their own conclusions.

    Solicit questions

    You do want dialogue. However, keep your answers short and to the point. What does come up in discussion is a good indication of where you’ll need to spend more time in the future.

    The only other thing that can boost your chances is if you’re lucky enough to be scheduled to present between 10:00 and 11:00 on a Thursday morning when people are most agreeable. Beyond that, apply the standard rules of good presentations to optimize your success.

    Your presentation is done – now re-focus on budget finalization and submission

    This final stage tends to be very administrative. Follow the rules and get it done.

    • Incorporate feedback: Follow up on comments from your first presentation and reflect them in your budget if appropriate. This may include:
      • Having follow-up conversations with stakeholders.
      • Further clarifying the ROI projections or business benefits.
      • Adjusting proposed expenditure amounts based on new information or a shift in priorities.
      • Adding details or increasing granularity around specific issues of interest.
    • Trim: Almost every business unit leader will need to make cuts to their initial budget proposal. After all, the CFO has a finite pool of money to allocate. If all’s gone well, it may only be a few percent. Resurrect your less-costly alternative scenario and selectively apply the options you laid out there. Focus on downsizing or deferring capital projects if possible. If you must trim OpEx, remind the CFO about any service-level adjustments that will need to happen to make the less expensive alternatives work.
    • Re-present: It’s not unusual to have to present your budget one more time after you’ve made your adjustments. In some organizations, the first presentation is to an internal executive group while the second one is to a governing board. The same rules apply to this second presentation as to your first one.
    • Submit: Slot your final budget into the list of accounts prescribed in the budget template provided by Finance. These templates often don’t align with IT’s budget categories, but you’ll have to make do.

    Phase recap: Create and deliver your presentation

    You’ve reached the end of the budget creation and approval process. Now you can refocus on using your budget as a living governance tool.

    This phase focused on developing your final proposed budget presentation for delivery to your various stakeholders. Here, you:

    • Planned your final content. You selected the data and visuals to include and highlight.
    • Built your presentation. You pulled everything together into a PowerPoint template and crafted commentary to tell a cohesive IT budget story.
    • Presented to stakeholders. You delivered your proposed IT budget and solicited their comments and feedback.
    • Made final adjustments and submitted your budget. You applied final tweaks, deconstructed your budget to fit Finance’s template, and submitted it for entry into Finance’s system.

    “Everyone understands that there’s never enough money. The challenge is prioritizing the right work and funding it.”

    – Trisha Goya, Director, IT Governance & Administration, Hawaii Medical Service Association

    Next Steps

    “Keep that conversation going throughout the year so that at budgeting time no one is surprised…Make sure that you’re telling your story all year long and keep track of that story.”

    – Angela Hintz, VP of PMO & Integrated Services,
    Blue Cross and Blue Shield of Louisiana

    This final section will provide you with:

    • An overall summary of accomplishment.
    • Recommended next steps.
    • A list of contributors to this research.
    • Some related Info-Tech resources.

    Summary of Accomplishment

    You’ve successfully created a transparent IT budget and gotten it approved.

    By following the phases and steps in this blueprint, you have:

    1. Learned more about what an IT budget does and what it means to your key stakeholders.
    2. Assembled your budgeting team and critical data needed for forecasting and budgeting, as well as set expenditure goals for next fiscal year, and metrics for improving the budgeting process overall.
    3. Forecasted your project and non-project CapEx and OpEx for next fiscal year and beyond.
    4. Fine-tuned your proposed expenditure rationales.
    5. Crafted and delivered an executive presentation and got your budget approved.

    What’s next?

    Use your approved budget as an ongoing IT financial management governance tool and track your budget process improvement metrics.

    If you would like additional support, have our analysts guide you through an Info-Tech full-service engagement or Guided Implementation.

    Contact your account representative for more information.

    1-888-670-8889

    Research Contributors and Experts

    Monica Braun

    Research Director, ITFM Practice

    Info-Tech Research Group

    Carol Carr

    Technical Counselor (Finance)

    Info-Tech Research Group

    Larry Clark

    Executive Counselor

    Info-Tech Research Group

    Duane Cooney

    Executive Counselor

    Info-Tech Research Group

    Lynn Fyhrlund

    Former Chief Information Officer

    Milwaukee County

    Jay Gnuse

    Information Technology Director

    Chief Industries

    Trisha Goya

    Director, IS Client Services

    Hawaii Medical Service Association

    Angela Hintz

    VP of PMO & Integrated Services

    Blue Cross and Blue Shield of Louisiana

    Rick Hopfer

    Chief Information Officer

    Hawaii Medical Service Association

    Theresa Hughes

    Executive Counselor

    Info-Tech Research Group

    Research Contributors and Experts

    Dave Kish

    Practice Lead, IT Financial Management Practice

    Info-Tech Research Group

    Matt Johnson

    IT Director Governance and Business Solutions

    Milwaukee County

    Titus Moore

    Executive Counselor

    Info-Tech Research Group

    Angie Reynolds

    Principal Research Director, IT Financial Management Practice

    Info-Tech Research Group

    Mark Roman

    Managing Partner, Executive Services

    Info-Tech Research Group

    Darin Stahl

    Distinguished Analyst & Research Fellow

    Info-Tech Research Group

    Miguel Suarez

    Head of Technology

    Seguros Monterrey New York Life

    Kristen Thurber

    IT Director, Office of the CIO

    Donaldson Company

    Related Info-Tech Research & Services

    Achieve IT Spend & Staffing Transparency

    • IT spend has increased in volume and complexity, but how IT spend decisions are made has not kept pace.
    • Lay a foundation for meaningful conversations and informed decision making around IT spend by transparently mapping exactly where IT funds are really going.

    IT Spend & Staffing Benchmarking Service

    • Is a do-it-yourself approach to achieving spend transparency too onerous? Let Info-Tech do the heavy lifting for you.
    • Using Info-Tech’s ITFM Cost Model, our analysts will map your IT expenditure to four different stakeholder views – CFO Expense View, CIO Service View, CXO Business View, and CEO Innovation View – so that you clearly show where expenditure is going in terms that stakeholders can relate to and better demonstrate IT’s value to the business.
    • Get a full report that shows how your spend is allocated plus benchmarks that compare your results to those of your industry peers.

    Build Your IT Cost Optimization Roadmap

    • Cost optimization is usually thought about in terms of cuts, when it’s really about optimizing IT’s cost-to-value ratio.
    • Develop a cost-optimization strategy based on your organization’s circumstances and timeline focused on four key areas of IT expenditure: assets, vendors, projects, and workforce.

    Bibliography

    “How Much Should a Company Spend on IT?” Techvera, no date. Accessed 3 Mar. 2023.
    “State of the CIO Study 2023.” Foundry, 25 Jan. 2023. Accessed 3 Mar. 2023.
    Aberdeen Strategy & Research. “The State of IT 2023.” Spiceworks. Ziff Davis, 2022. Accessed 28 Feb. 2023.
    Ainsworth, Paul. “Responsibilities of the Modern CFO - A Function in Transition.” TopTal, LLC., no date. Accessed 15 Feb. 2023.
    Balasaygun, Kaitlin. “For the first time in a long time, CFOs can say no to tech spending.” CNBC CFO Council, 19 Jan. 2023. Accessed 17 Feb. 2023.
    Bashir, Ahmad. “Objectives of Capital Budgeting and factors affecting Capital Budget Decisions.” LinkedIn, 27 May 2017. Accessed 14 Apr. 2023.
    Blackmon, Kris. “Building a Data-Driven Budget Pitch the C-Suite Can't Refuse.” NetSuite Brainyard, 21 Sep. 2021. Accessed 17 Feb. 2023
    Butcher, Daniel. “CFO to CFO: Budgeting to Fund Strategic Plans.” Strategic Finance Magazine/Institute of Management Accountants, 1 Dec. 2021. Accessed 17 Feb. 2023
    Gray, Patrick. “IT Budgeting: A Cheat Sheet.” TechRepublic, 29 Jul. 2020. Accessed 28 Feb. 2023.
    Greenbaum, David. “Budget vs. Actuals: Budget Variance Analysis & Guide.” OnPlan, 15 Mar. 2022. Accessed 22 Mar. 2023.
    Huber, Michael and Joan Rundle. “How to Budget for IT Like a CFO.” Huber & Associates, no date. Accessed 15 Feb. 2023.
    Kinney, Tara. “Executing Your Department Budget Like a CFO.” Atomic Revenue, LLC., no date. Accessed 15 Feb. 2023.
    Lafley, A.G. “What Only the CFO Can Do.” Harvard Business Review, May 2009. Accessed 15 Mar. 2009.
    Moore, Peter D. “IN THE DIGITAL WORLD, IT should be run as a profit center, not a cost center.” Wild Oak Enterprise, 26 Feb. 2020. Accessed 3 Mar. 2023.
    Nordmeyer, Bille. “What Factors Are Going to Influence Your Budgeting Decisions?” bizfluent, 8 May 2019. Accessed 14 Apr. 2023
    Ryan, Vincent. “IT Spending and 2023 Budgets Under Close Scrutiny.” CFO, 5 Dec. 2022. Accessed 3 Mar. 2023.
    Stackpole, Beth. “State of the CIO, 2022: Focus turns to IT fundamentals.” CIO Magazine, 21 Mar. 2022. Accessed 3 Mar. 2023.

    Create a Game Plan to Implement Cloud Backup the Right Way

    • Buy Link or Shortcode: {j2store}469|cart{/j2store}
    • member rating overall impact: 7.0/10 Overall Impact
    • member rating average dollars saved: $2,000 Average $ Saved
    • member rating average days saved: 5 Average Days Saved
    • Parent Category Name: Storage & Backup Optimization
    • Parent Category Link: /storage-and-backup-optimization
    • Cloud adoption is frequently driven by hype rather than careful consideration of the best-fit solution.
    • IT is frequently rushed into cloud adoption without appropriate planning.
    • Organizations frequently lack appropriate strategies to deal with cloud-specific backup challenges.
    • Insufficient planning for cloud backup can exacerbate problems rather than solving them, leading to poor estimates of the cost and effort involved, budget overruns, and failure to meet requirements.

    Our Advice

    Critical Insight

    • The cloud isn’t a magic bullet, but it tends to deliver the most value to organizations with specific use cases – frequently smaller organizations who are looking to avoid the cost of building or upgrading a data center.
    • Cloud backup does not necessarily reduce backup costs so much as it moves them around. Cloud backup distributes costs over a longer term. Organizations need to compare the difference in CAPEX and OPEX to determine if making the move makes financial sense.
    • The cloud can deliver a great deal of value for organizations who are looking to reduce the operational effort demanded by an existing tape library for second- or third-tier backups.
    • Data security risks in some cases may be overstated, depending on what on-premises security is available. However, targeting backup to the cloud introduces other risks that need to be considered before implementation is given the green light.

    Impact and Result

    • Understand if cloud backup is the right solution for actual organizational needs.
    • Make an informed decision about targeting backup to the cloud by considering the big picture TCO and effort level involved in adoption.
    • Have a ready strategy to mitigate the most common challenges with cloud adoption projects.
    • Develop a roadmap that lays out the required step-by-step to implement cloud backup.

    Create a Game Plan to Implement Cloud Backup the Right Way Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Understand the benefits and risks of targeting backups to the cloud

    Build a plan to mitigate the risks associated with backing data up in the cloud.

    • Storyboard: Create a Game Plan to Implement Cloud Backup the Right Way

    2. Determine if the cloud can meet the organization's data requirements

    Assess if the cloud is a good fit for your organization’s backup data.

    • Cloud Backup Implementation Game Plan Tool

    3. Mitigate the Challenges of Backing Up to the Cloud

    Build a cloud challenge contingency plan.

    4. Build a Cloud Backup Implementation Roadmap

    Perform a gap analysis to determine cloud backup implementation initiatives.

    Infographic

    Workshop: Create a Game Plan to Implement Cloud Backup the Right Way

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Evaluate the business case for targeting backup at the cloud

    The Purpose

    Understand how cloud backup will affect backup and recovery processes

    Determine backup and recovery objectives

    Assess the value proposition of cloud backup

    Key Benefits Achieved

    A high-level understanding of the benefits of moving to cloud backup

    A best-fit analysis of cloud backup in comparison to organizational needs

    Activities

    1.1 Document stakeholder goals for cloud backup

    1.2 Document present backup processes

    1.3 Document ideal backup processes

    1.4 Review typical benefits of cloud backup

    Outputs

    Documented stakeholder goals

    Current backup process diagrams

    Ideal backup process diagram

    2 Identify candidate data sets and assess opportunities and readiness

    The Purpose

    Identify candidate data sets for cloud-based backup

    Determine RPOs and RTOs for candidate data sets

    Identify potential value specific to each data set for targeting backup at the cloud

    Evaluate organizational readiness for targeting backup at the cloud

    Key Benefits Achieved

    Documented recovery objectives

    Recommendations for cloud backup based on actual organizational needs and readiness

    Activities

    2.1 Document candidate data sets

    2.2 Determine recovery point and recovery time objectives for candidate data sets

    2.3 Identify potential value of cloud-based backup for candidate data sets

    2.4 Discuss the risk and value of cloud-based backup versus an on-premises solution

    2.5 Evaluate organizational readiness for cloud backup

    2.6 Identify data sets to move to the cloud

    Outputs

    Validated list of candidate data sets

    Specific RPOs and RTOs for core data sets

    An assessment of the value of cloud backup for data sets

    A tool-based recommendation for moving backups to the cloud

    3 Mitigate the challenges of backing up to the cloud

    The Purpose

    Understand different cloud provider models and their specific risks

    Identification of how cloud backup will affect IT infrastructure and personnel

    Strategize ways to mitigate the most common challenges of implementing cloud backup

    Understand the client/vendor relationship in cloud backup

    Understand the affect of cloud backup on data security

    Key Benefits Achieved

    Verified best-fit cloud provider model for organizational needs

    Verified strategy for meeting the most common challenges for cloud-based backup

    A strong understanding of how cloud backup will change IT

    Strategies for approaching vendors to ensure a strong footing in negotiations and clear expectations for the client/vendor relationship

    Activities

    3.1 Discuss the impact of cloud backup on infrastructure and IT environment

    3.2 Create a cloud backup risk contingency plan

    3.3 Document compliance and security regulations

    3.4 Identify client and vendor responsibilities for cloud backup

    3.5 Discuss and document the impact of cloud backup on IT roles and responsibilities

    3.6 Compile a list of implementation intiatives

    3.7 Evaluate the financial case for cloud backup

    Outputs

    Cloud risk assessment

    Documented contingency strategies for probabe risks

    Negotiation strategies for dealing with vendors

    A committed go/no-go decision on the value of cloud backup weighted against the effort of implementation

    4 Build a cloud backup implementation roadmap

    The Purpose

    Create a road map for implementing cloud backup

    Key Benefits Achieved

    Determine any remaining gaps between the present state and the ideal state for cloud backup

    Understand the steps and time frame for implementing cloud backup

    Allocate roles and responsibilities for the implementation intitiative

    A validated implementation road map

    Activities

    4.1 Perform a gap analysis to generate a list of implementation intiatives

    4.2 Prioritize cloud backup initiatives

    4.3 Assess risks and dependencies for critical implementation initiatives

    4.4 Assign ownership over implementation tasks

    4.5 Determine road map time frame and structure

    4.6 Populate the roadmap with cloud backup initiatives

    Outputs

    A validated gap analysis

    A prioritized list of cloud backup initiatives

    Documented dependencies and risks associated with implementation tasks

    A roadmap for targeting backups at the cloud

    Assess Your Readiness to Implement UCaaS

    • Buy Link or Shortcode: {j2store}305|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Voice & Video Management
    • Parent Category Link: /voice-video-management
    • Employees no longer work in the office all the time and have adopted a hybrid or remote policy.
    • Security is on your mind when it comes to the risks associated with data and voice across the internet.
    • You are unaware of the technology used by other departments, such as sales and marketing.

    Our Advice

    Critical Insight

    • The importance of doing your due diligence and building out requirements is paramount to deciding on what UCaaS solution works for you. Even if you decide not to pursue this cloud-based service, at least you have done your homework.
    • There are five reasons you should migrate to UCaaS: flexibility & scalability, productivity, enhanced security, business continuity, and cost savings. Challenge your selection with these criteria at your foundation and you cannot go wrong.

    Impact and Result

    With features such as messaging, collaboration tools, and video conferencing, UCaaS enables users to be more effective regardless of location and device. This can lead to quicker decision making and reduce communication delays.

    Assess Your Readiness to Implement UCaaS Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Assess Your Readiness to Implement UCaaS Storyboard – Research that reviews the business drivers to move to a UCaaS solution.

    In addition to examining the benefits of UCaaS, this deck covers how to drive toward an RFP and convince the C-suite to champion your UCaaS strategy.

    • Assess Your Readiness to Implement UCaaS Storyboard

    2. UCaaS Readiness Questionnaire – Three sets of questions to help determine your organization's readiness to move to a UCaaS platform.

    This questionnaire is a starting point. Sections include: 1) Current State Questionnaire, 2) IT Infrastructure Readiness Questionnaire, and 3) UCaaS Vendor Questionnaire. These questions can also be added to an RFP for UCaaS vendors you may want to work with.

    • UCaaS Readiness Questionnaire
    [infographic]

    Further reading

    Assess Your Readiness to Implement UCaaS

    Unified communication as a service (UCaaS) is already here. Find the right solution for your organization, whether it is Teams Phone or another solution.

    Analyst Perspective

    UCaaS is the solution to the hybrid and remote working world

    Hybrid/remote work is a reality and there is little evidence to prove otherwise despite efforts to return employees to the office. A 2023 survey from Zippia says 74% of US companies are planning to or have implemented hybrid work policies. Given the reality of the new ways people work, there’s a genuine need for a UCaaS solution.

    The days of on-premises private branch exchange (PBX) and legacy voice over internet protocol (VoIP) solutions are numbered, and organizations are examining alternative solutions to redundant desk phones. The stalwarts of voice solutions, Cisco and Avaya, have seen the writing on the wall for some time: the new norm must be a cloud-based solution that integrates via API with content resource management (CRM), email, chat, and collaboration tools.

    Besides remaining agile when accommodating different work locations, it’s advantageous to be able to quickly scale and meet the needs of organizations and their employees. New technology is moving at such a pace that utilizing a UCaaS service is truly beneficial, especially given its AI, analytics, and mobile capabilities. Being held back by an on-premises solution that is capitalized over several years is not a wise option.

    Photo of John Donovan
    John Donovan
    Principle Research Director, I&O Practice
    Info-Tech Research Group

    Insight Summary

    Improved integration and communication in a hybrid world
    Unified communication as a service (UCaaS) integrates several tools into one platform to provide seamless voice, video, chat, collaboration, sharing and much more. The ability to work from anywhere and the ability to use application programming interfaces (APIs) to integrate content resource management (CRM) and other productivity tools into a unified environment is a key component of employee productivity, whether at the office or remote, or even on mobile devices.

    Simplify your maintenance, management, and support
    Communication and voice using a cloud provisioner has many benefits and makes life easier for your IT staff. No more ongoing maintenance, upgrades, patching and managing servers or private branch exchanges (PBXs). UCaaS is easy to deploy, and due to its scalability and flexibility, users can easily be added or removed. Now businesses can retire their legacy technical debt of voice hardware and old desk phones that clutter the office.

    Oversight on security
    The utilization of a software as a service (SaaS) platform in UCaaS form does by design risk data breaches, phishing, and third-party malware. Fortunately, you can safeguard your organization’s security by ensuring the vendor you choose features SOC2 certification, taking care of encryption, firewalls, two-factor authentication and security incident handling, and disaster recovery. The big players in the UCaaS world have these features.

    Executive Summary

    Your Challenge

    So, your legacy PBX is ready to be replaced. It has no support or maintenance contract, and you face a critical decision. You could face these challenges:

    • Employees no longer work in the office all the time and have adopted a hybrid or remote policy
    • Security risks associated with data and voice across the internet
    • Limited awareness of the technology used by some departments, such as sales and marketing

    Common Obstacles

    Businesses may worry about several obstacles when it’s time to choose a voice and collaboration solution. For example:

    • Concern over internet connectivity or disruptions
    • Uncertainty integrating systems with the platform
    • Unsure whether employees will embrace new tools/workflows that completely change how they work, collaborate, and communicate
    • Failure to perform due diligence when trying to choose the right solution for an organization

    Info-Tech’s Approach

    It’s critically important to perform due diligence and build out requirements when deciding what UCaaS solution works for you. Even if you decide not to pursue this cloud-based service, at least you will:

    • Determine your business case
    • Evaluate your roadmap for unified communication
    • Ask all the right questions to determine suitability

    In this advisory deck, you will see a set of questions you must ask including whether Teams is suitable for your business.

    Info-Tech Insight

    Determine your communication and collaboration needs. Evaluate your current use of voice, video, chat, collaboration, sharing, and mobility whether for the office or remote work. Evaluate your security and regulatory requirements and needs. Determine the integration requirements when evaluating top vendors.

    The evolution of unified communication

    How we moved from fax machines and desk phones to an integrated set of tools on one platform in the cloud

    A diagram that shows the evolution of unified communication from 1980s to 2020s.

    Business drivers for moving to UCaaS

    What organizations look to gain or save by moving to UCaaS solutions

    Flexibility and scalability
    Ability to add/remove users and services as appropriate for changing business needs, allowing for quick adaptation to changing markets.

    Productivity
    Offering features like messaging, collaboration tools, and video conferencing enables users to be more effective regardless of location and device. May lead to quicker decision making and reduced communication delays.

    Cost savings
    Eliminating the need for on-premises hardware and software, reducing maintenance and support costs. Predictable monthly billing.

    Business continuity
    Reducing risks of disruption or disaster. Allowing users to work from anywhere when the physical office is unavailable. Additional features can include disaster recovery and backup services.

    Enhanced security
    UCaaS providers usually offer advanced security and compliance features including encryption, firewall, intrusion detection, and certifications like HIPAA and SOC 2.

    KPIs to demonstrate success

    What key metrics should businesses measure to demonstrate a successful UCaaS project?
    What improvements are needed?
    What can be optimized?

    KPI Measurement
    User adoption rate
    • % of employees utilizing UCaaS solutions
    • # of users who completed UCaaS training/onboarding
    • # of calls or messages sent per user
    Call quality and reliability
    • % of calls with good to excellent quality
    • # of dropped calls or call disruption
    • Mean opinion score (MOS) for video and voice quality
    Cost savings
    • TCO for UCaaS compared to previous solution
    • Cost per month for UCaaS
    • Reduced hardware/maintenance and communication costs
    Improved productivity
    • Time saved with streamlined comms workflows
    • # of successful collaborative projects or meetings
    • Improved speed and quality for customer service or support
    Customer satisfaction
    • Net promoter score or CSAT
    • Positive customer reviews
    • Time-to-resolution of customer issues
    Scalability
    • Ability to add/remove/change user features as needed
    • Time to deploy new UCaaS features
    • Scalability of network to support increased UCaaS usage

    What are the surveys telling us?

    Different organizations adopt UCaaS solutions for different reasons

    95%

    Collaboration: No Jitter’s study on team collaboration found that 95% of survey respondents think collaborative communication apps are a necessary component of a successful communications strategy.
    Source: No Jitter, 2018.

    95%

    Security: When deploying remote communication solutions, 95% of businesses say they want to use VPN connections to keep data private.
    Source: Mitel, 2018.

    31%

    Flexibility: While there are numerous advantages to cloud-based communications, 31% of companies intend to use UCaaS to eliminate technical debt from legacy systems and processes.
    Source: Freshworks, 2019.

    UCaaS adoption

    While many organizations are widely adopting UCaaS, they still have data security concerns

    UCaaS deployments are growing

    UCaaS is growing at a rate that shows the market for UC is moving toward cloud-based voice and collaboration solutions at a rate of 29% year over year.

    Source: Synergy Research Group, 2017.

    Security is still a big concern

    While it’s increasingly popular to adopt cloud-based unified communication solutions, 70% of those companies are still concerned about their data security.

    Source: Masergy, 2022.


    Concerns around security range from encrypting conversations to controlling who has access to what data in the organization’s network to how video is managed on emerging video communications platforms.

    Info-Tech Insight

    Ensure you maintain a robust security posture with your data regardless of where it is being stored. Security breaches can happen at any location.

    UCaaS vs. on-premises UC

    A diagram that shows UCaaS benefits

    Main benefits of UCaaS

    • Rapid deployment: Cloud hosting provides the ability to deploy quickly.
    • Ease of management: It’s no longer necessary for companies to manage communications across multiple platforms and devices.
    • Better connection: The communication flow across teams and with customers is faster and easier with phone, messaging, audio and video conferencing available in one place.
    • Scalability: Since UCaaS is an on-demand service, companies can scale their communication needs to what’s immediately required at an affordable price.

    Info-Tech Insight

    There are five reasons you should migrate to UCaaS. They are advanced technology, easily scalable, cost efficiencies, highly available, and security. There are always outliers, but these five criteria are a reliable foundation when assessing a vendor/product.

    UCaaS architecture

    The 6 primary elements of UCaaS

    Unified communications as a service (UCaaS) is a cloud-based subscription service primarily for communication tools such as voice, video, messaging, collaboration, content sharing, and other cloud services over the internet. It uses VoIP to process calls.

    The popularity of UCaaS is increasing with the recent trend of users working remotely full or part-time and requiring collaboration tools for their work.

    • The main benefit to businesses is the ability to remove on-premises hardware and reduce technical debt.
    • Additionally, it removes the need for expensive up-front capital costs and reduces communications costs.
    • From a productivity perspective, delivering these services under one platform/service increases effective collaboration and allows instant communication regardless of device or location.

    A diagram that shows protocols

    Features available to UCaaS/UC

    Must-haves vs. nice-to-haves

    A diagram that shows Must-haves vs. nice-to-haves UC features

    Info-Tech Insight

    Decide what matters most to the organization when choosing the UC platform and applications. Divide criteria into must-have vs. nice-to-have categories.

    Security and UCaaS

    • Maintain company integrity
    • Enhance data security
    • Regulatory compliance
    • Reduce risk of fraud
    • Protect data for multiple devices

    What are the concerns? What is at risk?

    • DDoS attacks: Enterprise transactions are paralyzed by flooding of data across the network preventing access
    • Phishing: Users are tricked into clicking a URL and sharing an organization’s sensitive data
    • Ransomware: Malicious attack preventing the business from accessing data and demanding a ransom for access
    • Third-party malware: Software infected with a virus, trojan horse, worms, spyware, or even ransomware with malicious intent

    Security solutions in UCaaS

    End-to-end encryption is critical

    SRTP

    • Secure real-time protocol is a cryptographic protocol used to secure voice & video calls over IP networks
    • SRTP provides encryption, message authentication, and integrity protection for voice and data packets. Using advanced encryption standard (AES) reduces chance of DDoS attacks

    TLS

    • Transport layer security (TLS) is a cryptographic protocol that secures data in transit over the internet, protecting from interception and tampering

    VPNs and firewalls

    • Virtual private networks (VPNs) are used to secure and encrypt connections between remote devices and the network. UCaaS providers can use VPN to secure access from remote locations
    • Firewalls are your primary line of defense against unauthorized traffic entering or leaving the network

    SIP

    • Session initiated protocol (SIP) over TLS is used to initiate and terminate video and voice calls over the internet. UCaaS providers often use SIP over TLS to encrypt and secure SIP messages

    SSH

    • Secure shell (SSH) is a cryptographic network protocol used to secure remote access and communications over the network. SSH is often used by UCaaS providers to secure remote management and configuration of systems

    Info-Tech Insight

    Encryption is a must for securing data and voice packets across the internet. These packets can be vulnerable to eavesdropping techniques and local area network (LAN) breaches. This risk must be mitigated from end to end.

    UCaaS

    Seven vendors competing with Microsoft’s integrated suite of collaboration tools

    Zoom

    A logo of Zoom
    Best for large meetings and webinars

    Key features:

    • Virtual meetings up to 300 users, up to 1,000 with enterprise version
    • Team chat
    • Digital whiteboard
    • Phone

    RingCentral

    A logo of RingCentral
    Best for project management collaboration tools

    Key features:

    • Video conferencing up to 200 users
    • Chat
    • Voice calls
    • Video polls and captioning
    • Digital whiteboard

    Nextiva

    A logo of Nextiva
    Best for CRM support, best-in-class functionality and features

    Key features:

    • Single dashboard
    • Chat
    • Cospace collaboration tool
    • Templates
    • Voice and call pop

    GoTo Connect

    A logo of GoTo Connect
    Best for integration with other business apps

    Key features:

    • Video conferencing up to 250 participants
    • Meeting transcripts
    • Dial plan

    Dialpad

    A logo of Dialpad
    Best for small companies under 15 users

    Key features:

    • Video meetings up to 15 participants
    • AI transcripts with call summary
    • Call controls share screen, switch between devices
    • Channel conversations with calendar app

    WebEx

    A logo of WebEx
    Only vendor offering real-time translation & closed captioning

    Key features:

    • Video meetings up to 200 participants
    • Calling features with noise removal, call recording, and transcripts
    • Live polling and Q&A

    Google Workspace

    A logo of Google Workspace
    Best for whole team collaboration for docs and slides

    Key features:

    • Google meet video
    • Collaboration on docs, sheets, and slides
    • Google chat and spaces
    • Calendars with sync updates with Gmail and auto-reminders

    Avaya and Cisco

    The major players in the VoIP on-premises PBX world have moved to a cloud experience to compete with Microsoft and other UCaaS players

    Avaya offers the OneCloud UC platform. It is one of the last UC vendors to offer on-premises solutions. In a market which is moving to the cloud at a serious pace, Avaya retains a 14% share. It made a strategic partnership with RingCentral in 2019 and in February 2021 they formed a joint venture which is now called Avaya Cloud Office, a UCaaS solution that integrates Avaya’s communication and collaboration solution with the RingCentral cloud platform.

    With around 33% of the UC market, Cisco also has a selection of UC products and services for on-premises deployment and the cloud, including WebEx Calling, Jabber, Unity Connections for voice messaging, and Single Number Reach for extensive telephony features.

    Both vendors support on-premises and cloud-based solutions for UC.

    Services provided by Avaya and Cisco in the UCaaS space

    A logo of Avaya Cloud Office
    Avaya Cloud Office

    • Voice calling: Cloud-based phone system over the internet with call forwarding, call transfer, voice mail, and more
    • Video conferencing: Virtual meetings for real-time collaboration, screen sharing, virtual backgrounds, video layout, meeting recording, whiteboarding and annotation, and virtual waiting room
    • Messaging: A feature that allows users to send and receive instant messages and SMS text messaging on the same platform
    • Collaboration: Work together on documents and projects in real time. File sharing and task management
    • Contact center: Manage customer interactions across voice, email, chat, and social media
    • Mobile app: Allows users to access communication and collaboration features on smartphones and tablets

    A logo of Cisco WebEx
    Cisco WebEx

    • Voice calling: Cisco WebEx calling provides cloud-based phone system over the internet including call forwarding, transfer, and voice mail
    • Video conferencing: Features include virtual meeting and real-time collaboration, screen sharing, and virtual backgrounds and layouts, highly scalable to large audiences
    • Messaging: Features include chat and SMS
    • Collaboration: Allows users to work together on docs and projects in real time, including file sharing and task management
    • Contact center: Multiple contact center solutions offered for small, medium, and large enterprises
    • Mobile app: Software clients for Jabber on cellphones
    • Artificial intelligence: Business insights, automatic transcripts, notes, and highlights to capture the meeting

    Service desk and contact center cloud options

    INDUSTRY: All industries
    SOURCE: Software reviews

    What vendors offer and what they don’t

    RingCentral integrates with some popular contact centers such as Five 9, Talkdesk and Sharpen. They also have a built-in contact center solution that can be integrated with their messaging and video conferencing tools.

    GoToConnect integrates with several leading customer service providers including Zendesk and Salesforce Service Cloud They also offer a built-in contact center solution with advanced call routing and management features.

    WebEx integrates with a variety of contact center and customer service platforms including Five9, Genesys, and ServiceNow.

    Dialpad integrates with contact center platforms such as Talkdesk and ServiceNow as well as CRM tools such as Salesforce and HubSpot.

    Google Workspace integrates with third-party contact center platforms through their Google Cloud Contact Center AI offering.

    SoftwareReviews

    A diagram that shows some top cloud options in Software reviews

    UCaaS comparison table

    A diagram of a UCaaS comparison table
    * Some reported issues around sound and voice quality may be due to network
    **Limited to certain plans

    Differences between UCaaS and CPaaS

    UCaaS

    CPaaS

    Defined

    Unified communication as a service – a cloud-based platform providing a suite of tools like voice, video messaging, file sharing & contact center.

    Communication platform as a service – a cloud-based platform allowing developers to use APIs to integrate real-time communications into their own applications.

    Functionality

    Designed for end users accessing a suite of tools for communication and collaboration through a unified platform.

    Designed for developers to create and integrate comms features into their own applications.

    Use cases

    Replace aging on-premises PBX systems with consolidated voice and collaboration services.

    Embedded communications capabilities into existing applications through SDKs, Java, and .NET libraries.

    Cost

    Often has a higher cost depending on services provided which can be quite comprehensive.

    Can be more cost effective than UCaaS if the business only requires a few communication features Integrated into their apps.

    Customization

    Offers less customization as it provides a predefined suite of tools that are rarely customized.

    Highly flexible and customizable so developers can build and integrate to fit unique use cases.

    Vendors

    Zoom, MS Teams, Cisco WebEx, RingCentral 8x8, GoTo Meeting, Slack, Avaya & many more.

    Twilio, Vonage, Pivo, MessageBird, Nexmo, SignalWire, CloudTalk, Avaya OneCloud, Telnyx, Voximplant, and others.

    Microsoft Teams Phone

    UCaaS for Microsoft 365

    Consider your approach to the telephony question. Microsoft incorporates telephony functionality with their broader collaboration suite. Other providers do the opposite.

    Microsoft’s voice solution

    These options allow you to plan for an all-cloud solution, connect to your own carrier, or use a combination of all cloud with a third-party carrier. Caveat: Calling plans must be available in your country or region.

    How do you connect with the public switched telephone network (PSTN)?

    Microsoft has three options for connecting the phone system to the PSTN:

    Calling Plan

    • Uses Microsoft's phone system and adds a domestic and international calling plan, which enables worldwide calling but depends on your chosen license
    • Since PSTN Calling Plan operates out of Microsoft 365, you are not required to deploy/maintain on-premises hardware
    • Customers can connect a supported session border controller (SBC) via direct routing if it’s necessary to operate with third-party PBX analog devices or other voice solutions supported by the SBC
    • You can assign your phone numbers directly in the Teams Admin Center

    This plan will work for you if:

    • There is a calling plan available in your region
    • You don’t need to maintain your PSTN carrier
    • You want to use Microsoft's managed PSTN
    • No SBC is necessary in your organization
    • Teams provides all the features your business needs

    Operator Connect

    • Leverage existing contracts or find a new operator from a selection of participating operators
    • Operator-managed infrastructure, your operator manages PSTN calling services and SBC
    • Faster, easier deployment, quickly connect to your operator and assign phone numbers directly from Teams Admin Center
    • Enhanced support and reliability, operators provide technical support and shared service level agreements
    • Customers can connect a supported SBC via Direct Routing for interoperability with third-party PBXs, analog devices, and other third-party voice solution equipment supported by SBC

    This plan will work for you if:

    • There is no calling plan available in your region
    • Your preferred carrier participates in the Microsoft operator connect plan
    • You are looking to get a new operator that enables calling in Teams

    Direct Routing

    • Connect your own supported SBC to Microsoft Phone System directly without needing additional on-premises software
    • Use virtually any voice solution carrier with Microsoft Phone System
    • Can be configured and managed by customers or by your carrier or partner (ask if your carrier or partner provides this option)
    • Configure interoperability between your voice solution equipment (e.g., a third-party PBX and analog devices) and Microsoft Phone System
    • Assign phone numbers directly from Teams Admin Center

    This plan will work for you if:

    • You want to use Teams with Phone System
    • You need to retain your current PSTN carrier
    • You want to mix routing – some calls are going via Calling Plans, some via your carrier
    • You need to interoperate with third-party PBXs and/or equipment such as overhead pagers, analog devices
    • Teams has all the features that your organization requires


    For more information, go to Microsoft Teams call flows.

    Teams phone architecture

    Microsoft offers three options that can be deployed based on several factors and questions you must answer.

    Microsoft Teams phone considerations when connecting to a PSTN

    • Do you want to move on-premises users to the cloud?
    • Is Microsoft's PSTN Calling Plan available in your region?
    • Is your preferred operator a participant in the Microsoft Operator Connect Program?
    • Do you want or need to keep your current voice carrier (e.g., does an existing contract require you to do so)?
    • Do you have an existing on-premises legacy PBX that you want or need to keep?
    • Does your current legacy PBX offer unique business-critical features?
    • Do all/any of your users require features not currently offered in Phone System?

    1. Phone System with Calling Plan

    All in the cloud for Teams users
    A diagram that shows Phone System with Calling Plan.

    Infrastructure requirements:

    Requires uninterrupted connection with Microsoft 365 Yes
    Available worldwide* No
    Requires deploying and maintaining a supported session border controller (SBC) No
    Requires contract with third-party carrier No

    *List of countries where calling plans are available: aka.ms/callingplans

    2. Phone System with own carrier via operator connect

    Phone system in the cloud; connectivity to on-premises voice network for Teams users
    A diagram that shows Phone System with own carrier via operator connect

    Infrastructure requirements:

    Requires uninterrupted connection with Microsoft 365 Yes
    Available worldwide* No
    Requires deploying and maintaining a supported session border controller (SBC) No
    Requires contract with third-party carrier Yes

    *List of countries where Operator Connect is available: aka.ms/operatorconnect

    3. Phone System with own carrier via Direct Routing

    Phone system in the cloud; connectivity to on-premises voice network for Teams users
    A diagram that shows Phone System with own carrier via Direct Routing

    Infrastructure requirements:

    Requires uninterrupted connection with Microsoft 365 Yes
    Available worldwide Yes
    Requires deploying and maintaining a supported session border controller (SBC) Yes
    Requires contract with third-party carrier* Yes

    *Unless deployed as an option to provide connection to third-party PBX, analog devices, or other voice equipment for users who are on Phone System with Calling Plans


    A Metrigy study found that 70% of organizations adopting MS Teams are using direct routing to connect to the PSTN
    Note: Complex organizations with varying needs can adopt all three options simultaneously.

    Avoid overpurchasing Microsoft telephony

    Microsoft telephony products on a page

    A diagram that shows Microsoft telephony products

    Pros:

    • The complete package: sole-sourcing your environment for simpler management
    • Users familiar with Microsoft will only have one place to go for telephony
    • You can bring your own provider and manage your own routing, giving you more choice
    • This can keep costs down as you do not have to pay for calling plan services
    • You can choose your own third-party solution while still taking advantage of the integrations that make Microsoft so attractive as a vendor

    Cons:

    • The most expensive option of the three
    • Less control and limited features compared to other pure-play telephony vendors
    • This service requires expertise in managing telephony infrastructure
    • Avoiding the cloud may introduce technical debt in the long term
    • You will have to manage integrations and deal with limited feature functionality (e.g. you may be able to receive inbound calls but not make outbound calls)

    Why does it matter?

    Phone System is Microsoft’s answer to the premises-based private branch exchange (PBX) functionality that has traditionally required a large capital expenditure. The cloud-based Phone System, offered with Microsoft’s highest tier of Microsoft/Office 365 licensing, allows Skype/Teams customers access to the following features (among others):

    • PSTN telephony (inbound and outbound)
    • Auto attendants (a menu system for callers to navigate your company directory)
    • Call forwarding, voice mail, and transferring
    • Caller ID
    • Shared lines
    • Common area phones

    Phone System, especially the Teams version, is a fully-featured telephony solution that integrates natively with a popular productivity solution. Phone System is worth exploring because many organizations already have Teams licenses.

    Key insights

    1. Don’t pay twice for the same service (unless you must). If you already have M/O365 E5 customer, Teams telephony can be a great way to save money and streamline your environment.
    2. Consider your approach to the telephony question. Microsoft incorporates telephony functionality into a broader collaboration suite. Other providers do the opposite. This reflects their relative strengths.
    3. Teams is a platform. You can use it as a front end for other telephone services. This might make sense if you have a preferred cloud PBX provider.

    Sources

    “Plan your Teams voice solution,” Microsoft, 2022.

    “Microsoft Calling Plans for Teams,” Microsoft, 2023.

    “Plan Direct Routing,” Microsoft, 2023.

    “Cisco vs. Microsoft Cloud Calling—Discussing the Options,” UC Today, 2022.

    “Microsoft Teams Phone Systems: 5 Deployment Options in 2020,” AeroCom, 2020.

    Contact Center and Teams integration

    Three Teams integration options

    If you want to use a certified and direct routing solution for Teams Phone, use the Connect model.

    If you want to use Azure bots and the Microsoft Graph Communication APIs that enable solution providers to create the Teams app, use the Extend model.

    If you want to use the SDK that enables solution providers to embed native Teams experiences in their App, use the Power model (under development).

    The Connect model features

    The Extend model features

    The Power model features (TBD)

    Office 365 authN for agents to connect to their MS tenant from their integrated CCaaS client

    Team graph APIs and Cloud Communication APIs for integration with Teams

    Goal: One app, one screen contact center experience

    Use Teams to see when agents are available

    Teams-based app for agent experience Chat and collaboration experience integrated with the Teams Client

    Goal: Adapt using software development kits (SDKs)

    Transfers and groups call support for Teams

    Teams as the primary calling endpoint for the agent

    Goal: One dashboard experience

    Teams Graph APIs and Cloud communication APIs for integration with Teams

    Teams' client calling for the all the call controls. Preserve performance & quality of Teams client experience

    Multi-tenant SIP trunking to support several customers on solution provider’s SBC

    Agent experience apps for both Teams web and mobile client

    Solution providers to use Microsoft certified session border controller (SBC)

    Analytics workflow management role-based experience for agents in the CaaS app in Teams

    Teams phone network assessment

    Useful tools for Microsoft network testing and Microsoft Teams site assessment

    Plan network basics

    • Does your network infrastructure have enough capacity? Consider switch ports, wireless access points, and other coverage.
    • If you use VLANs and DHCP, are your scopes sized accordingly?
    • Evaluate and test network paths from where devices are deployed to Microsoft 365.
    • Open the required firewall ports and URLs for Microsoft 365 as per guidance.
    • Review and test E911 requirements and configuration for location accuracy and compliance.
    • Avoid using a proxy server and optimize media paths for reliability and quality.

    What internet speed do I need for Teams calls?

    • Microsoft Teams uses about 1.2 Mbps for HD video calling (720p), 1.5 Mbps for 1080p, 500 kbps for standard quality video (360p). Group video requires about 1 Mbps, HD group video uses about 2 Mbps.

    Key physical considerations

    • Power: Do you have enough electrical outlets? If the device needs an external power source, how close can you position it to an outlet?
    • Device placement: Where will your device be located? Review desk stands, wall mounts, and other accessories from the original equipment manufacturer (OEM).
    • Security: Does your device need to be locked in certain spaces?
    • Accessibility: Does the device meet the accessibility requirements of its primary user? Consider where it's placed, wire length, and handset or headset usability.

    Prepare your organization's network for Microsoft Teams

    Plan your Teams voice solution

    Check your internet connection for Teams Phone System

    Teams Phone Mobile

    UCaaS Activity

    Questions that must be addressed by your business and the vendor. Site surveys and questionnaires for your assessment

    Activity: Questionnaire

    Input: Evaluate your current state, Network readiness
    Output: Decisions on readiness, Gaps in infrastructure readiness, Develop a project plan
    Materials: UCaaS Readiness Questionnaire
    Participants: Infrastructure Manager, Project Manager, Network Engineer, Voice Engineer

    As a group, read through the questions on Tabs 1 and 2 of the UCaaS Readiness Questionnaire workbook. The answers to the questions will determine if you have gaps to fill when determining your readiness to move forward on a UCaaS solution.

    You may produce additional questions during the session that pertain to your specific business and situation. Please add them to the questionnaire as needed.

    Record your answers to determine next steps and readiness.

    When assessing potential vendors, use Tab 3 to determine suitability for your organization and requirements. This section may be left to a later date when building a request for proposal (RFP).

    Call #1: Review client advisory deck and next steps.

    Call #2: Assess readiness from answers to the Tab 1 questions.

    Download the UCaaS Readiness Questionnaire here

    Critical Path – Teams with Phone System Deployment

    A diagram that shows Critical Path – Teams with Phone System Deployment

    Example Ltd.’s Communications Guide

    A diagram that shows Example Ltd.’s Communications Guide

    [Insert Organization Name]’s Communications Guide

    A diagram that shows [Insert Organization Name]’s Communications Guide

    Related Info-Tech Research

    Photo of Modernize Communications and Collaboration Infrastructure

    Modernize Communications and Collaboration Infrastructure

    Organizations are losing productivity from managing the limitations of yesterday’s technology. The business is changing and the current communications solution no longer adequately connects end users. A new communications and collaboration infrastructure is due to replace or update the legacy infrastructure in place today.

    Photo of Establish a Communication and Collaboration System Strategy

    Establish a Communication and Collaboration System Strategy

    Communication and collaboration portfolios are overburdened with redundant and overlapping services. Between Office 365, Slack, Jabber, and WebEx, IT is supporting a collection of redundant apps. This redundancy takes a toll on IT, and on the user.

    Photo of Implement a Transformative IVR Experience That Empowers Your Customers

    Implement a Transformative IVR Experience That Empowers Your Customers

    Learn the strategies that will allow you to develop an effective interactive voice response (IVR) framework that supports self-service and improves the customer experience.

    Bibliography

    “8 Security Considerations for UCaaS.” Tech Guidance, Feb. 2022. Accessed March 2023.

    “2022 UCaaS & CCaaS market trends snapshot.” Masergy, 2022. Web.

    “All-in-one cloud communications.” Avaya, 2023. Accessed April 2023. Web.

    Carter, Rebekah. “UC Case Study in Focus: Microsoft Teams and GroupM.” UC Today, 9 May 2022. Accessed Feb. 2023.

    “Cisco Unified Communications Manager Cloud (Cisco UCM Cloud) Data Sheet.” Cisco, 15 Sept. 2021. Accessed Jan. 2023.

    “Cloud Adoption as Viewed by European Companies: Assessing the Impact on Public, Hybrid and Private Cloud Communications.” Mitel, 2018. Web.

    De Guzman, Marianne. “Unified Communications Security: The Importance of UCaaS Encryption.” Fit Small Business, 13 Dec. 2022. Accessed March 2023.

    “Evolution of Unified Communications.” TrueConf, n.d. Accessed March 2023. Web.

    Froehlich, Andrew. “Choose between Microsoft Teams vs. Zoom for conference needs.” TechTarget, 7 May 2021. Accessed March 2023.

    Gerwig, Kate. “UCaaS explained: Guide to unified communications as a service.” TechTarget, 29 March 2022. Accessed Jan. 2023.

    Irei, Alissa. “Emerging UCaaS trends include workflow integrations and AI.” TechTarget, 21 Feb 2020. Accessed Feb. 2023.

    Kuch, Mike. “What Is Unified Communications as a Service (UCaaS)?” Avaya, 27 Dec. 2022. Accessed Jan. 2023.

    Lazar, Irwin. “UC vendors extend mobile telephony capabilities.” TechTarget, 10 Feb. 2023. Accessed Mar 2023.

    McCain, Abby. "30 Essential Hybrid Work Statistics [2023]: The Future of Work." Zippia, 20 Feb. 2023. Accessed Mar 2023.

    “Meet the modern CIO: What CEOs expect from their IT leaders.” Freshworks, 2019. Web.

    “A New Era of Workplace Communications: Will You Lead or Be Left Behind.” No Jitter, 2018. Web.

    Plumley, Mike, et al. “Microsoft Teams IT architecture and voice solutions posters.’” Microsoft Teams, Microsoft, 14 Feb. 2023. Accessed March 2023.

    Rowe, Carolyn, et al. “Plan your Teams voice solution” Microsoft Learn, Microsoft, 1 Oct. 2022.

    Rowe, Carolyn, et al. “Microsoft Calling Plans for Teams.” Microsoft Learn, Microsoft, 23 May 2023.

    Rowe, Carolyn, et al. “Plan Direct Routing.” Microsoft Learn, Microsoft, 20 Feb. 2023.

    Scott, Rob. “Cisco vs. Microsoft Cloud Calling—Discussing the Options,” UC Today, 21 April 2022.

    Smith, Mike. “Microsoft Teams Phone Systems: 5 Deployment Options in 2020.” YouTube, uploaded by AeroCom Inc, 23 Oct. 2020.

    “UCaaS - Getting Started With Unified Communications As A Service.” Cloudscape, 10 Nov. 2022. Accessed March 2023.

    “UCaaS Market Accelerating 29% per year; RingCentral, 8x8, Mitel, BroadSoft and Vonage Lead.” Synergy Research Group, 16 Oct. 2017. Web.

    “UCaaS Statistics – The Future of Remote Work.” UC Today, 21 April 2022. Accessed Feb. 2023.

    “Workplace Collaboration: 2021-22.” Metrigy, 27 Jan. 2021. Web.

    Understand the Difference Between Backups and Archives

    • Buy Link or Shortcode: {j2store}506|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Storage & Backup Optimization
    • Parent Category Link: /storage-and-backup-optimization
    • You don’t understand the difference between a backup and an archive or when to use one or the other.
    • Data is not constant. It is ever-changing and growing. How do you protect it?
    • You just replaced an application that was in use since day one, and even though you have a fully functional replacement, you would like to archive that original application just in case.
    • You want to save money, so you use your backup solution to archive data, but you know that is not ideal. What is the correct solution?

    Our Advice

    Critical Insight

    Keep in mind that backups are for recovery while archives are for discovery. Backups and archives are often confused but understanding the differences can result in significant savings of time and money. Backing up and archiving may be considered IT tasks, but recovery and discovery are capabilities the business wants and is willing to pay for.

    Impact and Result

    Archives and backups are not the same, and there is a use case for each. Sometimes minor adjustments may be required to make the use case work. Understanding the basics of backups and archives can lead to significant savings at a monetary and effort level.

    Understand the Difference Between Backups and Archives Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Understand the Difference Between Backups and Archives

    What is the difference between a backup and a data archive? When should I use one over the other? They are not the same and confusing the two concepts could be expensive.

    • Understand the Difference Between Backups and Archives Storyboard
    [infographic]

    Further reading

    Understand the Difference Between Backups and Archives

    They are not the same, and confusing the two concepts could be expensive

    Analyst Perspective

    Backups and archives are not interchangeable, but they can complement each other.

    Photo of P.J. Ryan, Research Director, Infrastructure & Operations, Info-Tech Research Group.

    Backups and archives are two very different operations that are quite often confused or misplaced. IT and business leaders are tasked with protecting corporate data from a variety of threats. They also must conform to industry, geographical, and legal compliance regulations. Backup solutions keep the data safe from destruction. If you have a backup, why do you also need an archive? Archive solutions hold data for a long period of time and can be searched. If you have an archive, why do you also need a backup solution? Backups and archives used to be the same. Remember when you would keep the DAT tape in the same room as the argon gas fire suppression system for seven years? Now that's just not feasible. Some situations require a creative approach or a combination of backups and archives.

    Understand the difference between archives and backups and you will understand why the two solutions are necessary and beneficial to the business.

    P.J. Ryan
    Research Director, Infrastructure & Operations
    Info-Tech Research Group

    Executive Summary

    Your Challenge
    • You don’t understand the difference between a backup and an archive or when to use one over the other.
    • Data is not constant. It is ever-changing and growing. How do you protect it?
    • You just replaced an application that had been in use since day one, and even though you have a fully functional replacement, you would like to archive that original application just in case.
    • You want to save money, so you use your backup solution to archive data, but you know that is not ideal. What is the correct solution?
    Common Obstacles
    • Storage costs can be expensive, as can some backup and archiving solutions.
    • Unclear requirements definition to decide between backups or archives.
    • Historically, people referred to archiving as tossing something into a box and storing it away indefinitely. Data archiving has a different meaning.
    • Executives want retired applications preserved but do not provide reasons or requirements.
    Info-Tech’s Approach
    • Spend wisely. Why spend money on an archive solution when a backup will suffice? Don’t leave money on the table.
    • Be creative and assess each backup or archive situation carefully. A custom solution may be required.
    • Backup your production data for the purpose of restoring it and adhere to the 3-2-1 rule of backups (Naviko.com).
    • Archive your older data to an alternate storge platform to save space, allow for searchability, and provide retention parameters.

    Info-Tech Insight

    Keep in mind that backups are for recovery while archives are for discovery. Backups and archives are often confused but understanding the differences can result in significant savings of time and money. Backing up and archiving may be considered IT tasks but recovery and discovery are capabilities the business wants and is willing to pay for.

    Archive

    What it IS

    A data archive is an alternate location for your older, infrequently accessed production data. It is indexed and searchable based on keywords. Archives are deleted after a specified period based on your retention policy or compliance directives.

    What it IS NOT

    Archives are not an emergency copy of your production data. They are not any type of copy of your production data. Archives will not help you if you lose your data or accidentally delete a file. Archives are not multiple copies of production data from various recovery points.

    Why use it

    Archives move older data to an alternate location. This frees up storage space for your current data. Archives are indexed and can be searched for historical purposes, compliance reasons, or in the event of a legal matter where specific data must be provided to a legal team.

    Tips & Tricks – Archiving

    • Archiving will move older data to an alternate location. This will free up storage space in the production environment.
    • Archiving solutions index the data to allow for easier searchability. This will aid in common business searches as well as assist with any potential legal searches.
    • Archiving allows companies to hold onto data for historical purposes as well as for specific retention periods in compliance with industry and regional regulations such as SOX, GDPR, FISMA, as well as others (msp360.com).

    Backup

    What it IS

    A backup is a copy of your data from a specific day and time. It is primarily used for recovery or restoration if something happens to the production copy of data. The restore will return the file or folder to the state it was in at the time of the backup.

    Backups occur frequently to ensure the most recent version of data is copied to a safe location.

    A typical backup plan makes a copy of the data every day, once a week, and once a month. The data is stored on tapes, disk, or using cloud storage.

    What it IS NOT

    Backups are not designed for searching or discovery. If you backup your email and must go to that backup in search of all email pertaining to a specific topic, you must restore the full backup and then search for that specific topic or sender. If you kept all the monthly backups for seven years, that will mean repeating that process 84 times to have a conclusive search, assuming you have adequate storage space to restore the email database 84 times.

    Backups do not free up space.

    Why use it

    Backups protect your data in the event of disaster, deletion, or accidental damage. A good backup strategy will include multiple backups on different media and offsite storage of at least one copy.

    Tips & Tricks – Backups

    • Production data should be backed up on a regular basis, ideally once a day or more frequently if possible.
    • Backups are intended to restore data when it gets deleted, over-written, or otherwise compromised. Most restore requests are from the last 24 to 48 hours, so it may be advantageous to keep a backup readily available on disk for a quick restore when needed.
    • Some vendors and industry subject matter experts advocate the use of a 3-2-1 rule when it comes to backups:
      • Keep three copies of your production data
      • In at least two separate locations (some advocate two different formats), and
      • One copy should be offsite (nakivo.com)

    Cold Storage

    • Cold storage refers to a storage option offered by some cloud vendors. In the context of the discussion between backups and archives, it can be an option for a dedicated backup solution for a specific period. Cost is low and the data is protected from destruction.
    • If an app has been replaced and all data transferred to the replacement solution but for some reason the company wishes to hold onto the data, you want a backup, not an archive. Extract the data, convert it into MongoDB or a similar solution, and drop it into cheap cloud storage (cold storage) for less than $5 per TB/month.

    Case Study

    Understanding the difference between archives and backups could save you a lot of time and money

    INDUSTRY: Manufacturing | SOURCE: Info-Tech Research

    Understanding the difference between an archive and a backup was the first step in solving their challenge.

    A leading manufacturing company found themselves in a position where they had to decide between archiving or doing nothing.

    The company had completed several acquisitions and ended up with multiple legacy applications that had been merged or migrated into replacement solutions. These legacy applications were very important to the original companies and although the data they held had been migrated to a replacement solution, executives felt they should hold onto these applications for a period of time, just in case.

    Some of the larger applications were archived using a modern archiving solution, but when it came to the smaller applications, the cost to add them to the archiving solution greatly exceeded the cost to just keep them running and maintain the associated infrastructure.

    A research advisor from Info-Tech Research Group joined a call with the manufacturing company and discussed their situation. The difference between archives and backups was explained and through the course of the conversation it was discovered that the solution was a modified backup. The application data had already been preserved through the migration, so data could be accessed in the production environment. The requirement to keep the legacy application up and running was not necessary but in compliance with the request to keep the information, the data could be exported from the legacy application into a non-sequential database, compressed, and stored in cloud-based cold storage for less than five dollars per terabyte per month. The manufacturing company’s staff realized that they could apply this same approach to several of their legacy applications and save tens of thousands of dollars in the process.

    Understand the Difference Between Backups and Archives

    Backups

    Backups are for recovery. A backup is a snapshot copy of production data at a specific point in time. If the production data is lost, destroyed, or somehow compromised, the data can be restored from the backup.

    Archives

    Archives are for discovery. It is production data that is moved to an alternate location to free up storage space, allow the data to be searchable, and still hold onto the data for historical or compliance purposes.

    Info-Tech Insight

    Archives and backups are not the same, and there is a use case for each. Sometimes minor adjustments may be required to make the use case work. Understanding the basics of backups and archives can lead to significant savings at a monetary and effort level.

    Additional Guidance

    Production data should be backed up.

    The specific backup solution is up to the business.

    Production data that is not frequently accessed should be archived.

    The specific solution to perform and manage the archiving of the data is up to the business

    • Archived data should also be backed up at least once.
    If the app has been replaced and all data transferred, you want a backup not an archive if you want to keep the data.
    • Short term – fence it off.
    • Long term – extract into Mongo then drop it into cheap cloud storage.

    Case Study

    Using tape backups as an archive solution could result in an expensive discovery and retrieval exercise.

    INDUSTRY: Healthcare | SOURCE: Zasio Enterprises Inc.

    “Do not commingle archive data with backup or disaster recovery tapes.”

    A court case in the United States District Court for the District of Nevada involving Guardiola and Renown Health in 2015 is a good example of why using a backup solution to solve an archiving challenge is a bad idea.

    Renown Health used a retention policy that declared any email older than six months of age as inactive and moved that email to a backup tape. Renown Health was ordered by the court to produce emails from a period of time in the past. Renown estimated that it would cost at least $248,000 to produce those emails, based on the effort involved to restore data from each tape and search for the email in question. Renown Health argued that this long and expensive process would result in undue costs.

    The court reviewed the situation and ruled against Renown Health and ordered them to comply with the request (Zasio.com).

    A proper archiving solution would have provided a quick and low-cost method to retrieve the emails in question.

    Backups and archives are complementary to each other

    • Archives are still production data, but the data does not change. A backup is recommended for the archived data, but the frequency of the backups can be lowered.
    • Backups protect you if a disaster strikes by providing a copy of the production data that was compromised or damaged. Archives allow you to access older data that may have just been forgotten, not destroyed or compromised. Archives could also protect you in a legal court case by providing data that is older but may prove your argument in court.

    Archives and backups are not the same.

    Backups copy your data. Archives move your data. Backups facilitate recovery. Archives facilitate discovery.

    Archive Backup
    Definition Move rarely accessed (but still production) data to separate media. Store a copy of frequently used data on a separate media to ensure timely operational recovery.
    Use Case Legal discovery, primary storage reduction, compliance requirements, and audits. Accidental deletion and/or corruption of data, hardware/software failures.
    Method Disk, cloud storage, appliance. Disk, backup appliance, snapshots, cloud.
    Data Older, rarely accessed production data. Current production data.

    Is it a backup or archive?

    • You want to preserve older data for legal and compliance reasons, so you put extra effort into keeping your tape backups safe and secure for seven years. That’s a big mistake that may cost you time and money. You want an archive solution.
    • You replace your older application and migrate all data to the new system, but you want to hold onto the old data, just in case. That’s a backup, not an archive.
    • A long serving senior executive recently left the company. You want to preserve the contents of the executive's laptop in case it is needed in the future. That’s a backup.

    Considerations When Choosing Between Solutions

    1

    Backup or archive?

    2

    What are you protecting?

    3

    Why are you protecting data?

    4

    Solution

    Backup

    Backup and/or archive.
    Additional information required.
    Column 3 may help

    Archive

    Device

    Data

    Application

    Operational Environment

    Operational recovery

    Disaster recovery

    Just in case

    Production storage space reduction

    Retention and preservation

    Governance, risk & compliance

    Backup

    Archive

    Related Info-Tech Research

    Stock image of light grids and flares. Establish an Effective Data Protection Plan

    Give data the attention it deserves by building a strategy that goes beyond backup.

    Stock image of old fuse box switches. Modernize Enterprise Storage

    Current and emerging storage technologies are disrupting the status quo – prepare your infrastructure for the exponential rise in data and its storage requirements.

    Logo for 'Software Reviews' and their information on 'Compare and Evaluate: Data Archiving.'
    Sample of Info-Tech's 'Data Archiving Policy'. Data Archiving Policy

    Bibliography

    “Backup vs. archiving: Know the difference.” Open-E. Accessed 05 Mar 2022.Web.

    G, Denis. “How to build retention policy.” MSP360, Jan 3, 2020. Accessed 10 Mar 2022.

    Ipsen, Adam. “Archive vs Backup: What’s the Difference? A Definition Guide.” BackupAssist, 28 Mar 2017. Accessed 04 Mar 2022.

    Kang, Soo. “Mitigating the expense of E-discovery; Recognizing the difference between back-ups and archived data.” Zasio Enterprises, 08 Oct 2015. Accessed 3 Mar 2022.

    Mayer, Alex. “The 3-2-1 Backup Rule – An Efficient Data Protection Strategy.” Naviko. Accessed 12 Mar 2022.

    “What is Data-Archiving?” Proofpoint. Accessed 07 Mar 2022.

    Build a Strong Technology Foundation for Customer Experience Management

    • Buy Link or Shortcode: {j2store}526|cart{/j2store}
    • member rating overall impact: 8.6/10 Overall Impact
    • member rating average dollars saved: $340,152 Average $ Saved
    • member rating average days saved: 26 Average Days Saved
    • Parent Category Name: Customer Relationship Management
    • Parent Category Link: /customer-relationship-management
    • Technology is a fundamental enabler of an organization’s customer experience management (CXM) strategy. However, many IT departments fail to take a systematic approach when building a portfolio of applications for supporting marketing, sales, and customer service functions.
    • The result is a costly, ineffective, and piecemeal approach to CXM application deployment (including high-profile applications like CRM).

    Our Advice

    Critical Insight

    • IT must work in lockstep with their counterparts in marketing, sales, and customer service to define a unified vision and strategic requirements for enabling a strong CXM program.
    • To deploy applications that specifically align with the needs of the organization’s customers, IT leaders must work with the business to define and understand customer personas and common interaction scenarios. CXM applications are mission critical and failing to link them to customer needs can have a detrimental effect on customer satisfaction and ultimately, revenue.
    • IT must act as a valued partner to the business in creating a portfolio of CXM applications that are cost effective.
    • Organizations should create a repeatable framework for CXM application deployment that addresses critical issues, including the integration ecosystem, customer data quality, dashboards and analytics, and end-user adoption.

    Impact and Result

    • Establish strong application alignment to strategic requirements for CXM that is based on concrete customer personas.
    • Improve underlying business metrics across marketing, sales, and service, including customer acquisition, retention, and satisfaction metrics.
    • Better align IT with customer experience needs.

    Build a Strong Technology Foundation for Customer Experience Management Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to find out why you should build a strong technology foundation for CXM, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Drive value with CXM

    Understand the benefits of a robust CXM strategy.

    • Build a Strong Technology Foundation for Customer Experience Management – Phase 1: Drive Value with CXM
    • CXM Strategy Stakeholder Presentation Template
    • CXM Strategy Project Charter Template

    2. Create the framework

    Identify drivers and objectives for CXM using a persona-driven approach and deploy the right applications to meet those objectives.

    • Build a Strong Technology Foundation for Customer Experience Management – Phase 2: Create the Framework
    • CXM Business Process Shortlisting Tool
    • CXM Portfolio Designer

    3. Finalize the framework

    Complete the initiatives roadmap for CXM.

    • Build a Strong Technology Foundation for Customer Experience Management – Phase 3: Finalize the Framework
    [infographic]

    Workshop: Build a Strong Technology Foundation for Customer Experience Management

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Create the Vision for CXM Technology Enablement

    The Purpose

    Establish a consistent vision across IT, marketing, sales, and customer service for CXM technology enablement.

    Key Benefits Achieved

    A clear understanding of key business and technology drivers for CXM.

    Activities

    1.1 CXM fireside chat

    1.2 CXM business drivers

    1.3 CXM vision statement

    1.4 Project structure

    Outputs

    CXM vision statement

    CXM project charter

    2 Conduct the Environmental Scan and Internal Review

    The Purpose

    Create a set of strategic requirements for CXM based on a thorough external market scan and internal capabilities assessment.

    Key Benefits Achieved

    Well-defined technology requirements based on rigorous, multi-faceted analysis.

    Activities

    2.1 PEST analysis

    2.2 Competitive analysis

    2.3 Market and trend analysis

    2.4 SWOT analysis

    2.5 VRIO analysis

    2.6 Channel map

    Outputs

    Completed external analysis

    Strategic requirements (from external analysis)

    Completed internal review

    Channel interaction map

    3 Build Customer Personas and Scenarios

    The Purpose

    Augment strategic requirements through customer persona and scenario development.

    Key Benefits Achieved

    Functional requirements aligned to supporting steps in customer interaction scenarios.

    Activities

    3.1 Persona development

    3.2 Scenario development

    3.3 Requirements definition for CXM

    Outputs

    Personas and scenarios

    Strategic requirements (based on personas)

    4 Create the CXM Application Portfolio

    The Purpose

    Using the requirements identified in the preceding modules, build a future-state application inventory for CXM.

    Key Benefits Achieved

    A cohesive, rationalized portfolio of customer interaction applications that aligns with identified requirements and allows investment (or rationalization) decisions to be made.

    Activities

    4.1 Build business process maps

    4.2 Review application satisfaction

    4.3 Create the CXM application portfolio

    4.4 Prioritize applications

    Outputs

    Business process maps

    Application satisfaction diagnostic

    Prioritized CXM application portfolio

    5 Review Best Practices and Confirm Initiatives

    The Purpose

    Establish repeatable best practices for CXM applications in areas such as data management and end-user adoption.

    Key Benefits Achieved

    Best practices for rollout of new CXM applications.

    A prioritized initiatives roadmap.

    Activities

    5.1 Create data integration map

    5.2 Define adoption best practices

    5.3 Build initiatives roadmap

    5.4 Confirm initiatives roadmap

    Outputs

    Integration map for CXM

    End-user adoption plan

    Initiatives roadmap

    Further reading

    Build a Strong Technology Foundation for Customer Experience Management

    Design an end-to-end technology strategy to enhance marketing effectiveness, drive sales, and create compelling customer service experiences.

    ANALYST PERSPECTIVE

    Technology is the catalyst to create – and keep! – your customers.

    "Customers want to interact with your organization on their own terms, and in the channels of their choice (including social media, mobile applications, and connected devices). Regardless of your industry, your customers expect a frictionless experience across the customer lifecycle. They desire personalized and well-targeted marketing messages, straightforward transactions, and effortless service. Research shows that customers value – and will pay more for! – well-designed experiences.

    Strong technology enablement is critical for creating customer experiences that drive revenue. However, most organizations struggle with creating a cohesive technology strategy for customer experience management (CXM). IT leaders need to take a proactive approach to developing a strong portfolio of customer interaction applications that are in lockstep with the needs of their marketing, sales, and customer service teams. It is critical to incorporate the voice of the customer into this strategy.

    When developing a technology strategy for CXM, don’t just “pave the cow path,” but instead move the needle forward by providing capabilities for customer intelligence, omnichannel interactions, and predictive analytics. This blueprint will help you build an integrated CXM technology roadmap that drives top-line revenue while rationalizing application spend."

    Ben Dickie

    Research Director, Customer Experience Strategy

    Info-Tech Research Group

    Framing the CXM project

    This Research Is Designed For:

    • IT leaders who are responsible for crafting a technology strategy for customer experience management (CXM).
    • Applications managers who are involved with the selection and implementation of critical customer-centric applications, such as CRM platforms, marketing automation tools, customer intelligence suites, and customer service solutions.

    This Research Will Help You:

    • Clearly link your technology-enablement strategy for CXM to strategic business requirements and customer personas.
    • Build a rationalized portfolio of enterprise applications that will support customer interaction objectives.
    • Adopt standard operating procedures for CXM application deployment that address issues such as end-user adoption and data quality.

    This Research Will Also Assist:

    • Business leaders in marketing, sales, and customer service who want to deepen their understanding of CXM technologies, and apply best practices for using these technologies to drive competitive advantage.
    • Marketing, sales, and customer service managers involved with defining requirements and rolling out CXM applications.

    This Research Will Help Them:

    • Work hand-in-hand with counterparts in IT to deploy high-value business applications that will improve core customer-facing metrics.
    • Understand the changing CXM landscape and use the art of the possible to transform the internal technology ecosystem and drive meaningful customer experiences.

    Executive summary

    Situation

    • Customer expectations for personalization, channel preferences, and speed-to-resolution are at an all-time high.
    • Your customers are willing to pay more for high-value experiences, and having a strong customer CXM strategy is a proven path to creating sustainable value for the organization.

    Complication

    • Technology is a fundamental enabler of an organization’s CXM strategy. However, many IT departments fail to take a systematic approach to building a portfolio of applications to support Marketing, Sales, and Customer Service.
    • The result is a costly, ineffective, and piecemeal approach to CXM application deployment (including high profile applications like CRM).

    Resolution

    • IT must work in lockstep with their counterparts in marketing, sales, and customer service to define a unified vision, strategic requirements and roadmap for enabling strong customer experience capabilities.
    • In order to deploy applications that don’t simply follow previously established patterns but are aligned with the specific needs of the organization’s customers, IT leaders must work with the business to define and understand customer personas and common interaction scenarios. CXM applications are mission critical and failing to link them to customer needs can have a detrimental effect on customer satisfaction – and ultimately revenue.
    • IT must act as a valued partner to the business in creating a portfolio of CXM applications that are cost effective.
    • Organizations should create a repeatable framework for CXM application deployment that addresses critical issues, including the integration ecosystem, customer data quality, dashboards and analytics, and end-user adoption.

    Info-Tech Insight

    1. IT can’t hide behind the firewall. IT must understand the organization’s customers to properly support marketing, sales, and service efforts.
    2. IT – or Marketing – must not build the CXM strategy in a vacuum if they want to achieve a holistic, consistent, and seamless customer experience.
    3. IT must get ahead of shadow IT. To be seen as an innovator within the business, IT must be a leading enabler in building a rationalized and integrated CXM application portfolio.

    Guide to frequently used acronyms

    CXM - Customer Experience Management

    CX - Customer Experience

    CRM - Customer Relationship Management

    CSM - Customer Service Management

    MMS - Marketing Management System

    SMMP - Social Media Management Platform

    RFP - Request for Proposal

    SaaS - Software as a Service

    Customers’ expectations are on the rise: meet them!

    Today’s consumers expect speed, convenience, and tailored experiences at every stage of the customer lifecycle. Successful organizations strive to support these expectations.

    67% of end consumers will pay more for a world-class customer experience. 74% of business buyers will pay more for strong B2B experiences. (Salesforce, 2018)

    5 CORE CUSTOMER EXPECTATIONS

    1. More personalization
    2. More product options
    3. Constant contact
    4. Listen closely, respond quickly
    5. Give front-liners more control

    (Customer Experience Insight, 2016)

    Customers expect to interact with organizations through the channels of their choice. Now more than ever, you must enable your organization to provide tailored customer experiences.

    Realize measurable value by enabling CXM

    Providing a seamless customer experience increases the likelihood of cross-sell and up-sell opportunities and boosts customer loyalty and retention. IT can contribute to driving revenue and decreasing costs by providing the business with the right set of tools, applications, and technical support.

    Contribute to the bottom line

    Cross-sell, up-sell, and drive customer acquisition.

    67% of consumers are willing to pay more for an upgraded experience. (Salesforce, 2018)

    80%: The margin by which CX leaders outperformer laggards in the S&P 500.(Qualtrics, 2017)

    59% of customers say tailored engagement based on past interactions is very important to winning their business. (Salesforce, 2018)

    Enable cost savings

    Focus on customer retention as well as acquisition.

    It is 6-7x more costly to attract a new customer than it is to retain an existing customer. (Salesforce Blog, 2019)

    A 5% increase in customer retention has been found to increase profits by 25% to 95%. (Bain & Company, n.d.)

    Strategic CXM is gaining traction with your competition

    Organizations are prioritizing CXM capabilities (and associated technologies) as a strategic investment. Keep pace with the competition and gain a competitive advantage by creating a cohesive strategy that uses best practices to integrate marketing, sales, and customer support functions.

    87% of customers share great experiences they’ve had with a company. (Zendesk, n.d.)

    61% of organizations are investing in CXM. (CX Network, 2015)

    53% of organizations believe CXM provides a competitive advantage. (Harvard Business Review, 2014)

    Top Investment Priorities for Customer Experience

    1. Voice of the Customer
    2. Customer Insight Generation
    3. Customer Experience Governance
    4. Customer Journey Mapping
    5. Online Customer Experience
    6. Experience Personalization
    7. Emotional Engagement
    8. Multi-Channel Integration/Omnichannel
    9. Quality & Customer Satisfaction Management
    10. Customer/Channel Loyalty & Rewards Programs

    (CX Network 2015)

    Omnichannel is the way of the future: don’t be left behind

    Get ahead of the competition by doing omnichannel right. Devise a CXM strategy that allows you to create and maintain a consistent, seamless customer experience by optimizing operations within an omnichannel framework. Customers want to interact with you on their own terms, and it falls to IT to ensure that applications are in place to support and manage a wide range of interaction channels.

    Omnichannel is a “multi-channel approach to sales that seeks to provide the customer with a seamless transactional experience whether the customer is shopping online from a desktop or mobile device, by telephone, or in a bricks and mortar store.” (TechTarget, 2014)

    97% of companies say that they are investing in omnichannel. (Huffington Post, 2015)

    23% of companies are doing omnichannel well.

    CXM applications drive effective multi-channel customer interactions across marketing, sales, and customer service

    The success of your CXM strategy depends on the effective interaction of various marketing, sales, and customer support functions. To deliver on customer experience, organizations need to take a customer-centric approach to operations.

    From an application perspective, a CRM platform generally serves as the unifying repository of customer information, supported by adjacent solutions as warranted by your CXM objectives.

    CXM ECOSYSTEM

    Customer Relationship Management Platform

    • Web Experience Management Platform
    • E-Commerce & Point of Sale Solutions
    • Social Media Management Platform
    • Customer Intelligence Platform
    • Customer Service Management Tools
    • Marketing Management Suite

    Application spotlight: Customer experience platforms

    Description

    CXM solutions are a broad range of tools that provide comprehensive feature sets for supporting customer interaction processes. These suites supplant more basic applications for customer interaction management. Popular solutions that fall under the umbrella of CXM include CRM suites, marketing automation tools, and customer service applications.

    Features and Capabilities

    • Manage sales pipelines, provide quotes, and track client deliverables.
    • View all opportunities organized by their current stage in the sales process.
    • View all interactions that have occurred between employees and the customer, including purchase order history.
    • Manage outbound marketing campaigns via multiple channels (email, phone, social, mobile).
    • Build visual workflows with automated trigger points and business rules engine.
    • Generate in-depth customer insights, audience segmentation, predictive analytics, and contextual analytics.
    • Provide case management, ticketing, and escalation capabilities for customer service.

    Highlighted Vendors

    Microsoft Dynamics

    Adobe

    Marketo

    sprinklr

    Salesforce

    SugarCRM

    Application spotlight: Customer experience platforms

    Key Trends

    • CXM applications have decreased their focus on departmental silos to make it easier to share information across the organization as departments demand more data.
    • Vendors are developing deeper support of newer channels for customer interaction. This includes providing support for social media channels, native mobile applications, and SMS or text-based services like WhatsApp and Facebook Messenger.
    • Predictive campaigns and channel blending are becoming more feasible as vendors integrate machine learning and artificial intelligence into their applications.
    • Content blocks are being placed on top of scripting languages to allow for user-friendly interfaces. There is a focus on alleviating bottlenecks where content would have previously needed to go through a specialist.
    • Many vendors of CXM applications are placing increased emphasis on strong application integration both within and beyond their portfolios, with systems like ERP and order fulfillment.

    Link to Digital Strategy

    • For many organizations that are building out a digital strategy, improving customer experience is often a driving factor: CXM apps enable this goal.
    • As part of a digital strategy, create a comprehensive CXM application portfolio by leveraging both core CRM suites and point solutions.
    • Ensure that a point solution aligns with the digital strategy’s technology drivers and user personas.

    CXM KPIs

    Strong CXM applications can improve:

    • Lead Intake Volume
    • Lead Conversion Rate
    • Average Time to Resolution
    • First-Contact Resolution Rate
    • Customer Satisfaction Rate
    • Share-of-Mind
    • Share-of-Wallet
    • Customer Lifetime Value
    • Aggregate Reach/Impressions

    IT is critical to the success of your CXM strategy

    Technology is the key enabler of building strong customer experiences: IT must stand shoulder-to-shoulder with the business to develop a technology framework for CXM.

    Top 5 Challenges with CXM for Marketing

    1. Maximizing customer experience ROI
    2. Achieving a single view of the customer
    3. Building new customer experiences
    4. Cultivating a customer-focused culture
    5. Measuring CX investments to business outcomes

    Top 5 Obstacles to Enabling CXM for IT

    1. Systems integration
    2. Multichannel complexity
    3. Organizational structure
    4. Data-related issues
    5. Lack of strategy

    (Harvard Business Review, 2014)

    Only 19% of organizations have a customer experience team tasked with bridging gaps between departments. (Genesys, 2018)

    IT and Marketing can only tackle CXM with the full support of each other. The cooperation of the departments is crucial when trying to improve CXM technology capabilities and customer interaction and drive a strong revenue mandate.

    CXM failure: Blockbuster

    CASE STUDY

    Industry Entertainment

    Source Forbes, 2014

    Blockbuster

    As the leader of the video retail industry, Blockbuster had thousands of retail locations internationally and millions of customers. Blockbuster’s massive marketing budget and efficient operations allowed it to dominate the competition for years.

    Situation

    Trends in Blockbuster’s consumer market changed in terms of distribution channels and customer experience. As the digital age emerged and developed, consumers were looking for immediacy and convenience. This threatened Blockbuster’s traditional, brick-and-mortar B2C operating model.

    The Competition

    Netflix entered the video retail market, making itself accessible through non-traditional channels (direct mail, and eventually, the internet).

    Results

    Despite long-term relationships with customers and competitive standing in the market, Blockbuster’s inability to understand and respond to changing technology trends and customer demands led to its demise. The organization did not effectively leverage internal or external networks or technology to adapt to customer demands. Blockbuster went bankrupt in 2010.

    Customer Relationship Management

    • Web Experience Management Platform
    • E-Commerce & Point of Sale Solutions
    • Social Media Management
    • Customer Intelligence
    • Customer Service
    • Marketing Management

    Blockbuster did not leverage emerging technologies to effectively respond to trends in its consumer network. It did not optimize organizational effectiveness around customer experience.

    CXM success: Netflix

    CASE STUDY

    Industry Entertainment

    Source Forbes, 2014

    Netflix

    Beginning as a mail-out service, Netflix offered subscribers a catalog of videos to select from and have mailed to them directly. Customers no longer had to go to a retail store to rent a video. However, the lack of immediacy of direct mail as the distribution channel resulted in slow adoption.

    The Situation

    In response to the increasing presence of tech-savvy consumers on the internet, Netflix invested in developing its online platform as its primary distribution channel. The benefit of doing so was two-fold: passive brand advertising (by being present on the internet) and meeting customer demands for immediacy and convenience. Netflix also recognized the rising demand for personalized service and created an unprecedented, tailored customer experience.

    The Competition

    Blockbuster was the industry leader in video retail but was lagging in its response to industry, consumer, and technology trends around customer experience.

    Results

    Netflix’s disruptive innovation is built on the foundation of great CXM. Netflix is now a $28 billion company, which is tenfold what Blockbuster was worth.

    Customer Relationship Management Platform

    • Web Experience Management Platform
    • E-Commerce & Point of Sale Solutions
    • Social Media Management Platform
    • Customer Intelligence Platform
    • Customer Service Management Tools
    • Marketing Management Suite

    Netflix used disruptive technologies to innovatively build a customer experience that put it ahead of the long-time, video rental industry leader, Blockbuster.

    Leverage Info-Tech’s approach to succeed with CXM

    Creating an end-to-end technology-enablement strategy for CXM requires a concerted, dedicated effort: Info-Tech can help with our proven approach.

    Build the CXM Project Charter

    Conduct a Thorough Environmental Scan

    Build Customer Personas and Scenarios

    Draft Strategic CXM Requirements

    Build the CXM Application Portfolio

    Implement Operational Best Practices

    Why Info-Tech’s Approach?

    Info-Tech draws on best-practice research and the experiences of our global member base to develop a methodology for CXM that is driven by rigorous customer-centric analysis.

    Our approach uses a unique combination of techniques to ensure that your team has done its due diligence in crafting a forward-thinking technology-enablement strategy for CXM that creates measurable value.

    A global professional services firm drives measurable value for CXM by using persona design and scenario development

    CASE STUDY

    Industry Professionals Services

    Source Info-Tech Workshop

    The Situation

    A global professional services firm in the B2B space was experiencing a fragmented approach to customer engagement, particularly in the pre-sales funnel. Legacy applications weren’t keeping pace with an increased demand for lead evaluation and routing technology. Web experience management was also an area of significant concern, with a lack of ongoing customer engagement through the existing web portal.

    The Approach

    Working with a team of Info-Tech facilitators, the company was able to develop several internal and external customer personas. These personas formed the basis of strategic requirements for a new CXM application stack, which involved dedicated platforms for core CRM, lead automation, web content management, and site analytics.

    Results

    Customer “stickiness” metrics increased, and Sales reported significantly higher turnaround times in lead evaluations, resulting in improved rep productivity and faster cycle times.

    Components of a persona
    Name Name personas to reflect a key attribute such as the persona’s primary role or motivation.
    Demographic Include basic descriptors of the persona (e.g. age, geographic location, preferred language, education, job, employer, household income, etc.)
    Wants, needs, pain points Identify surface-level motivations for buying habits.
    Psychographic/behavioral traits Observe persona traits that are representative of the customers’ behaviors (e.g. attitudes, buying patterns, etc.).

    Follow Info-Tech’s approach to build your CXM foundation

    Create the Project Vision

    • Identify business and IT drivers
    • Outputs:
      • CXM Strategy Guiding Principles

    Structure the Project

    • Identify goals and objectives for CXM project
    • Form Project Team
    • Establish timeline
    • Obtain project sponsorship
    • Outputs:
      • CXM Strategy Project Charter

    Scan the External Environment

    • Create CXM operating model
    • Conduct external analysis
    • Create customer personas
    • Outputs:
      • CXM Operating Model
    • Conduct PEST analysis
    • Create persona scenarios
    • Outputs:
      • CXM Strategic Requirements

    Assess the Current State of CXM

    • Conduct SWOT analysis
    • Assess application usage and satisfaction
    • Conduct VRIO analysis
    • Outputs:
      • CXM Strategic Requirements

    Create an Application Portfolio

    • Map current processes
    • Assign business process owners
    • Create channel map
    • Build CXM application portfolio
    • Outputs:
      • CXM Application Portfolio Map

    Develop Deployment Best Practices

    • Develop CXM integration map
    • Create mitigation plan for poor data quality
    • Outputs:
      • Data Quality Preservation Map

    Create an Initiative Rollout Plan

    • Create risk management plan
    • Identify work initiative dependencies
    • Create roadmap
    • Outputs:
      • CXM Initiative Roadmap

    Confirm and Finalize the CXM Blueprint

    • Identify success metrics
    • Create stakeholder communication plan
    • Present CXM strategy to stakeholders
    • Outputs:
      • Stakeholder Presentation

    Info-Tech offers various levels of support to suit your needs

    DIY Toolkit

    “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

    Guided Implementation

    “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

    Workshop

    “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

    Consulting

    “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

    Diagnostics and consistent frameworks used throughout all four options

    Build a Strong Technology Foundation for CXM – project overview

    1. Drive Value With CXM 2. Create the Framework 3. Finalize the Framework
    Best-Practice Toolkit

    1.1 Create the Project Vision

    1.2 Structure the CXM Project

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Guided Implementations
    • Determine project vision for CXM.
    • Review CXM project charter.
    • Review environmental scan.
    • Review application portfolio for CXM.
    • Confirm deployment best practices.
    • Review initiatives rollout plan.
    • Confirm CXM roadmap.
    Onsite Workshop Module 1: Drive Measurable Value with a World-Class CXM Program Module 2: Create the Strategic Framework for CXM Module 3: Finalize the CXM Framework

    Phase 1 Outcome:

    • Completed drivers
    • Completed project charter

    Phase 2 Outcome:

    • Completed personas and scenarios
    • CXM application portfolio

    Phase 3 Outcome:

    • Strategic summary blueprint

    Workshop overview

    Contact your account representative or email Workshops@InfoTech.com for more information.

    Workshop Day 1 Workshop Day 2 Workshop Day 3 Workshop Day 4 Workshop Day 5
    Activities

    Create the Vision for CXM Enablement

    1.1 CXM Fireside Chat

    1.2 CXM Business Drivers

    1.3 CXM Vision Statement

    1.4 Project Structure

    Conduct the Environmental Scan and Internal Review

    2.1 PEST Analysis

    2.2 Competitive Analysis

    2.3 Market and Trend Analysis

    2.4 SWOT Analysis

    2.5 VRIO Analysis

    2.6 Channel Mapping

    Build Personas and Scenarios

    3.1 Persona Development

    3.2 Scenario Development

    3.3 Requirements Definition for CXM

    Create the CXM Application Portfolio

    4.1 Build Business Process Maps

    4.2 Review Application Satisfaction

    4.3 Create the CXM Application Portfolio

    4.4 Prioritize Applications

    Review Best Practices and Confirm Initiatives

    5.1 Create Data Integration Map

    5.2 Define Adoption Best Practices

    5.3 Build Initiatives Roadmap

    5.4 Confirm Initiatives Roadmap

    Deliverables
    1. CXM Vision Statement
    2. CXM Project Charter
    1. Completed External Analysis
    2. Completed Internal Review
    3. Channel Interaction Map
    4. Strategic Requirements (from External Analysis)
    1. Personas and Scenarios
    2. Strategic Requirements (based on personas)
    1. Business Process Maps
    2. Application Satisfaction Diagnostic
    3. Prioritized CXM Application Portfolio
    1. Integration Map for CXM
    2. End-User Adoption Plan
    3. Initiatives Roadmap

    Phase 1

    Drive Measurable Value With a World-Class CXM Program

    Build a Strong Technology Foundation for Customer Experience Management

    Phase 1 outline

    Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

    Complete these steps on your own, or call us to complete a guided implementation. A guided implementation is a series of 2-3 advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

    Guided Implementation 1: Drive Measurable Value With a World-Class CXM Program

    Proposed Time to Completion: 2 weeks

    Step 1.1: Create the Project Vision

    Start with an analyst kick-off call:

    • Review key drivers from a technology and business perspective for CXM
    • Discuss benefits of strong technology enablement for CXM

    Then complete these activities…

    • CXM Fireside Chat
    • CXM Business and Technology Driver Assessment
    • CXM Vision Statement

    With these tools & templates:

    • CXM Strategy Stakeholder Presentation Template

    Step 1.2: Structure the Project

    Review findings with analyst:

    • Assess the CXM vision statement for competitive differentiators
    • Determine current alignment disposition of IT with different business units

    Then complete these activities…

    • Team Composition and Responsibilities
    • Metrics Definition

    With these tools & templates:

    • CXM Strategy Project Charter Template

    Phase 1 Results & Insights:

    • Defined value of strong technology enablement for CXM
    • Completed CXM project charter

    Step 1.1: Create the Project Vision

    Phase 1

    1.1 Create the Project Vision

    1.2 Structure the Project

    Phase 2

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    Phase 3

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Activities:

    • Fireside Chat: Discuss past challenges and successes with CXM
    • Identify business and IT drivers to establish guiding principles for CXM

    Outcomes:

    • Business benefits of a rationalized technology strategy to support CXM
    • Shared lessons learned
    • Guiding principles for providing technology enablement for CXM

    Building a technology strategy to support customer experience isn’t an option – it’s a mission-critical activity

    • Customer-facing departments supply the lifeblood of a company: revenue. In today’s fast-paced and interconnected world, it’s becoming increasingly imperative to enable customer experience processes with a wide range of technologies, from lead automation to social relationship management. CXM is the holistic management of customer interaction processes across marketing, sales, and customer service to create valuable, mutually beneficial customer experiences. Technology is a critical building block for enabling CXM.
    • The parallel progress of technology and process improvement is essential to an efficient and effective CXM program. While many executives prefer to remain at the status quo, new technologies have caused major shifts in the CXM environment. If you stay with the status quo, you will fall behind the competition.
    • However, many IT departments are struggling to keep up with the pace of change and find themselves more of a firefighter than a strategic partner to marketing, sales, and service teams. This not only hurts the business, but it also tarnishes IT’s reputation.

    An aligned, optimized CX strategy is:

    Rapid: to intentionally and strategically respond to quickly-changing opportunities and issues.

    Outcome-based: to make key decisions based on strong business cases, data, and analytics in addition to intuition and judgment.

    Rigorous: to bring discipline and science to bear; to improve operations and results.

    Collaborative: to conduct activities in a broader ecosystem of partners, suppliers, vendors, co-developers, and even competitors.

    (The Wall Street Journal, 2013)

    Info-Tech Insight

    If IT fails to adequately support marketing, sales, and customer service teams, the organization’s revenue will be in direct jeopardy. As a result, CIOs and Applications Directors must work with their counterparts in these departments to craft a cohesive and comprehensive strategy for using technology to create meaningful (and profitable) customer experiences.

    Fireside Chat, Part 1: When was technology an impediment to customer experience at your organization?

    1.1.1 30 minutes

    Input

    • Past experiences of the team

    Output

    • Lessons learned

    Materials

    • Whiteboard
    • Markers

    Participants

    • Core Team

    Instructions

    1. Think about a time when technology was an impediment to a positive customer experience at your organization. Reflect on the following:
      • What frustrations did the application or the technology cause to your customers? What was their reaction?
      • How did IT (and the business) identify the challenge in the first place?
      • What steps were taken to mitigate the impact of the problem? Were these steps successful?
      • What were the key lessons learned as part of the challenge?

    Fireside Chat, Part 2: What customer success stories has your organization created by using new technologies?

    1.1.2 30 minutes

    Input

    • Past experiences of the team

    Output

    • Lessons learned

    Materials

    • Whiteboard
    • Markers

    Participants

    • Core Team

    Instructions

    1. Think about a time when your organization successfully leveraged a new application or new technology to enhance the experience it provided to customers. Reflect on this experience and consider:
      • What were the organizational drivers for rolling out the new application or solution?
      • What obstacles had to be overcome in order to successfully deploy the solution?
      • How did the application positively impact the customer experience? What metrics improved?
      • What were the key lessons learned as part of the deployment? If you had to do it all over again, what would you do differently?

    Develop a cohesive, consistent, and forward-looking roadmap that supports each stage of the customer lifecycle

    When creating your roadmap, consider the pitfalls you’ll likely encounter in building the IT strategy to provide technology enablement for customer experience.

    There’s no silver bullet for developing a strategy. You can encounter pitfalls at a myriad of different points including not involving the right stakeholders from the business, not staying abreast of recent trends in the external environment, and not aligning sales, marketing, and support initiatives with a focus on the delivery of value to prospects and customers.

    Common Pitfalls When Creating a Technology-Enablement Strategy for CXM

    Senior management is not involved in strategy development.

    Not paying attention to the “art of the possible.”

    “Paving the cow path” rather than focusing on revising core processes.

    Misalignment between objectives and financial/personnel resources.

    Inexperienced team on either the business or IT side.

    Not paying attention to the actions of competitors.

    Entrenched management preferences for legacy systems.

    Sales culture that downplays the potential value of technology or new applications.

    IT is only one or two degrees of separation from the end customer: so take a customer-centric approach

    IT →Marketing, Sales, and Service →External Customers

    Internal-Facing Applications

    • IT enables, supports, and maintains the applications used by the organization to market to, sell to, and service customers. IT provides the infrastructural and technical foundation to operate the function.

    Customer-Facing Applications

    • IT supports customer-facing interfaces and channels for customer interaction.
    • Channel examples include web pages, mobile device applications and optimization, and interactive voice response for callers.

    Info-Tech Insight

    IT often overlooks direct customer considerations when devising a technology strategy for CXM. Instead, IT leaders rely on other business stakeholders to simply pass on requirements. By sitting down with their counterparts in marketing and sales, and fully understanding business drivers and customer personas, IT will be much better positioned to roll out supporting applications that drive customer engagement.

    A well-aligned CXM strategy recognizes a clear delineation of responsibilities between IT, sales, marketing, and service

    • When thinking about CXM, IT must recognize that it is responsible for being a trusted partner for technology enablement. This means that IT has a duty to:
      • Develop an in-depth understanding of strategic business requirements for CXM. Base your understanding of these business requirements on a clear conception of the internal and external environment, customer personas, and business processes in marketing, sales, and customer service.
      • Assist with shortlisting and supporting different channels for customer interaction (including email, telephony, web presence, and social media).
      • Create a rationalized, cohesive application portfolio for CXM that blends different enabling technologies together to support strategic business requirements.
      • Provide support for vendor shortlisting, selection, and implementation of CXM applications.
      • Assist with end-user adoption of CXM applications (i.e. training and ongoing support).
      • Provide initiatives that assist with technical excellence for CXM (such as data quality, integration, analytics, and application maintenance).
    • The business (marketing, sales, customer service) owns the business requirements and must be responsible for setting top-level objectives for customer interaction (e.g. product and pricing decisions, marketing collateral, territory management, etc.). IT should not take over decisions on customer experience strategy. However, IT should be working in lockstep with its counterparts in the business to assist with understanding business requirements through a customer-facing lens. For example, persona development is best done in cross-functional teams between IT and Marketing.

    Activity: Identify the business drivers for CXM to establish the strategy’s guiding principles

    1.1.3 30 minutes

    Input

    • Business drivers for CXM

    Output

    • Guiding principles for CXM strategy

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Define the assumptions and business drivers that have an impact on technology enablement for CXM. What is driving the current marketing, sales, and service strategy on the business side?
    Business Driver Name Driver Assumptions, Capabilities, and Constraints Impact on CXM Strategy
    High degree of customer-centric solution selling A technically complex product means that solution selling approaches are employed – sales cycles are long. There is a strong need for applications and data quality processes that support longer-term customer relationships rather than transactional selling.
    High desire to increase scalability of sales processes Although sales cycles are long, the organization wishes to increase the effectiveness of rep time via marketing automation where possible. Sales is always looking for new ways to leverage their reps for face-to-face solution selling while leaving low-level tasks to automation. Marketing wants to support these tasks.
    Highly remote sales team and unusual hours are the norm Not based around core hours – significant overtime or remote working occurs frequently. Misalignment between IT working only core hours and after-hours teams leads to lag times that can delay work. Scheduling of preventative sales maintenance must typically be done on weekends rather than weekday evenings.

    Activity: Identify the IT drivers for CXM to establish the strategy’s guiding principles

    1.1.4 30 minutes

    Input

    • IT drivers for CXM

    Output

    • Guiding principles for CXM strategy

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Define the assumptions and IT drivers that have an impact on technology enablement for CXM. What is driving the current IT strategy for supporting marketing, sales, and service initiatives?
    IT Driver Name Driver Assumptions, Capabilities, and Constraints Impact on CXM Strategy
    Sales Application Procurement Methodology Strong preference for on-premise COTS deployments over homebrewed applications. IT may not be able to support cloud-based sales applications due to security requirements for on premise.
    Vendor Relations Minimal vendor relationships; SLAs not drafted internally but used as part of standard agreement. IT may want to investigate tightening up SLAs with vendors to ensure more timely support is available for their sales teams.
    Development Methodology Agile methodology employed, some pockets of Waterfall employed for large-scale deployments. Agile development means more perfective maintenance requests come in, but it leads to greater responsiveness for making urgent corrective changes to non-COTS products.
    Data Quality Approach IT sees as Sales’ responsibility IT is not standing as a strategic partner for helping to keep data clean, causing dissatisfaction from customer-facing departments.
    Staffing Availability Limited to 9–5 Execution of sales support takes place during core hours only, limiting response times and access for on-the-road sales personnel.

    Activity: Use IT and business drivers to create guiding principles for your CXM technology-enablement project

    1.1.5 30 minutes

    Input

    • Business drivers and IT drivers from 1.1.3 and 1.1.4

    Output

    • CXM mission statement

    Materials

    • Whiteboard
    • Markers

    Participants

    • Core Team

    Instructions

    1. Based on the IT and business drivers identified, craft guiding principles for CXM technology enablement. Keep guiding principles in mind throughout the project and ensure they support (or reconcile) the business and IT drivers.

    Guiding Principle Description
    Sales processes must be scalable. Our sales processes must be able to reach a high number of target customers in a short time without straining systems or personnel.
    Marketing processes must be high touch. Processes must be oriented to support technically sophisticated, solution-selling methodologies.

    2. Summarize the guiding principles above by creating a CXM mission statement. See below for an example.

    Example: CXM Mission Statement

    To ensure our marketing, sales and service team is equipped with tools that will allow them to reach out to a large volume of contacts while still providing a solution-selling approach. This will be done with secure, on-premise systems to safeguard customer data.

    Ensure that now is the right time to take a step back and develop the CXM strategy

    Determine if now is the right time to move forward with building (or overhauling) your technology-enablement strategy for CXM.

    Not all organizations will be able to proceed immediately to optimize their CXM technology enablement. Determine if the organizational willingness, backbone, and resources are present to commit to overhauling the existing strategy. If you’re not ready to proceed, consider waiting to begin this project until you can procure the right resources.

    Do not proceed if:

    • Your current strategy for supporting marketing, sales, and service is working well and IT is already viewed as a strategic partner by these groups. Your current strategy is well aligned with customer preferences.
    • The current strategy is not working well, but there is no consensus or support from senior management for improving it.
    • You cannot secure the resources or time to devote to thoroughly examining the current state and selecting improvement initiatives.
    • The strategy has been approved, but there is no budget in place to support it at this time.

    Proceed if:

    • Senior management has agreed that technology support for CXM should be improved.
    • Sub-divisions within IT, sales, marketing, and service are on the same page about the need to improve alignment.
    • You have an approximate budget to work with for the project and believe you can secure additional funding to execute at least some improvement initiatives.
    • You understand how improving CXM alignment will fit into the broader customer interaction ecosystem in your organization.

    If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

    Book a workshop with our Info-Tech analysts:

    • To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.
    • Info-Tech analysts will join you and your team onsite at your location or welcome you to Info-Tech’s historic Toronto office to participate in an innovative onsite workshop.
    • Contact your account manager (www.infotech.com/account), or email Workshops@InfoTech.com for more information.

    The following are sample activities that will be conducted by Info-Tech analysts with your team:

    1.1.3; 1.1.4; 1.1.5 - Identify business and IT drivers to create CXM guiding principles

    The facilitator will work with stakeholders from both the business and IT to identify implicit or explicit strategic drivers that will support (or pose constraints on) the technology-enablement framework for the CXM strategy. In doing so, guiding principles will be established for the project.

    Step 1.2: Structure the Project

    Phase 1

    1.1 Create the Project Vision

    1.2 Structure the Project

    Phase 2

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    Phase 3

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Activities:

    • Define the project purpose, objectives, and business metrics
    • Define the scope of the CXM strategy
    • Create the project team
    • Build a RACI chart
    • Develop a timeline with project milestones
    • Identify risks and create mitigation strategies
    • Complete the strategy project charter and obtain approval

    Outcomes:

    CXM Strategy Project Charter Template

    • Purpose, objectives, metrics
    • Scope
    • Project team & RACI
    • Timeline
    • Risks & mitigation strategies
    • Project sponsorship

    Use Info-Tech’s CXM Strategy Project Charter Template to outline critical components of the CXM project

    1.2.1 CXM Strategy Project Charter Template

    Having a project charter is the first step for any project: it specifies how the project will be resourced from a people, process, and technology perspective, and it clearly outlines major project milestones and timelines for strategy development. CXM technology enablement crosses many organizational boundaries, so a project charter is a very useful tool for ensuring everyone is on the same page.

    Sections of the document:

    1. Project Drivers, Rationale, and Context
    2. Project Objectives, Metrics, and Purpose
    3. Project Scope Definition
    4. Project Team Roles and Responsibilities (RACI)
    5. Project Timeline
    6. Risk Mitigation Strategy
    7. Project Metrics
    8. Project Review & Approvals

    INFO-TECH DELIVERABLE

    CXM Strategy Project Charter Template

    Populate the relevant sections of your project charter as you complete activities 1.2.2-1.2.8.

    Understand the roles necessary to complete your CXM technology-enablement strategy

    Understand the role of each player within your project structure. Look for listed participants on the activities slides to determine when each player should be involved.

    Title Role Within Project Structure
    Project Sponsor
    • Owns the project at the management/C-suite level
    • Responsible for breaking down barriers and ensuring alignment with organizational strategy
    • CIO, CMO, VP of Sales, VP of Customer Care, or similar
    Project Manager
    • The IT individual(s) that will oversee day-to-day project operations
    • Responsible for preparing and managing the project plan and monitoring the project team’s progress
    • Applications or other IT Manager, Business Analyst, Business Process Owner, or similar
    Business Lead
    • Works alongside the IT PM to ensure that the strategy is aligned with business needs
    • In this case, likely to be a marketing, sales, or customer service lead
    • Sales Director, Marketing Director, Customer Care Director, or similar
    Project Team
    • Comprised of individuals whose knowledge and skills are crucial to project success
    • Responsible for driving day-to-day activities, coordinating communication, and making process and design decisions. Can assist with persona and scenario development for CXM.
    • Project Manager, Business Lead, CRM Manager, Integration Manager, Application SMEs, Developers, Business Process Architects, and/or similar SMEs
    Steering Committee
    • Comprised of C-suite/management level individuals that act as the project’s decision makers
    • Responsible for validating goals and priorities, defining the project scope, enabling adequate resourcing, and managing change
    • Project Sponsor, Project Manager, Business Lead, CFO, Business Unit SMEs and similar

    Info-Tech Insight

    Do not limit project input or participation to the aforementioned roles. Include subject matter experts and internal stakeholders at particular stages within the project. Such inputs can be solicited on a one-off basis as needed. This ensures you take a holistic approach to creating your CXM technology-enablement strategy.

    Activity: Kick-off the CXM project by defining the project purpose, project objectives, and business metrics

    1.2.2 30 minutes

    Input

    • Activities 1.1.1 to 1.1.5

    Output

    • Drivers & rationale
    • Purpose statement
    • Business goals
    • Business metrics
    • CXM Strategy Project Charter Template, sections 1.0, 2.0, and 2.1

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Sponsor
    • Project Manager
    • Business Lead
    • Steering Committee

    Instructions

    Hold a meeting with IT, Marketing, Sales, Service, Operations, and any other impacted business stakeholders that have input into CXM to accomplish the following:

    1. Discuss the drivers and rationale behind embarking on a CXM strategy.
    2. Develop and concede on objectives for the CXM project, metrics that will gauge its success, and goals for each metric.
    3. Create a project purpose statement that is informed by decided-upon objectives and metrics from the steps above. When establishing a project purpose, ask the question, “what are we trying to accomplish?”
    • Example: Project Purpose Statement
      • The organization is creating a CXM strategy to gather high-level requirements from the business, IT, and Marketing, Sales, and Service, to ensure that the selection and deployment of the CXM meets the needs of the broader organization and provides the greatest return on investment.
  • Document your project drivers and rationale, purpose statement, project objectives, and business metrics in Info-Tech’s CXM Strategy Project Charter Template in sections 1.0 and 2.0.
  • Info-Tech Insight

    Going forward, set up a quarterly review process to understand changing needs. It is rare that organizations never change their marketing and sales strategy. This will change the way the CXM will be utilized.

    Establish baseline metrics for customer engagement

    In order to gauge the effectiveness of CXM technology enablement, establish core metrics:

    1. Marketing Metrics: pertaining to share of voice, share of wallet, market share, lead generation, etc.
    2. Sales Metrics: pertaining to overall revenue, average deal size, number of accounts, MCV, lead warmth, etc.
    3. Customer Service Metrics: pertaining to call volumes, average time to resolution, first contact resolution, customer satisfaction, etc.
    4. IT Metrics: pertaining to end-user satisfaction with CXM applications, number of tickets, contract value, etc.
    Metric Description Current Metric Future Goal
    Market Share 25% 35%
    Share of Voice (All Channels) 40% 50%
    Average Deal Size $10,500 $12,000
    Account Volume 1,400 1,800
    Average Time to Resolution 32 min 25 min
    First Contact Resolution 15% 35%
    Web Traffic per Month (Unique Visitors) 10,000 15,000
    End-User Satisfaction 62% 85%+
    Other metric
    Other metric
    Other metric

    Understand the importance of setting project expectations with a scope statement

    Be sure to understand what is in scope for a CXM strategy project. Prevent too wide of a scope to avoid scope creep – for example, we aren’t tackling ERP or BI under CXM.

    In Scope

    Establishing the parameters of the project in a scope statement helps define expectations and provides a baseline for resource allocation and planning. Future decisions about the strategic direction of CXM will be based on the scope statement.

    Scope Creep

    Well-executed requirements gathering will help you avoid expanding project parameters, drawing on your resources, and contributing to cost overruns and project delays. Avoid scope creep by gathering high-level requirements that lead to the selection of category-level application solutions (e.g. CRM, MMS, SMMP, etc.), rather than granular requirements that would lead to vendor application selection (e.g. Salesforce, Marketo, Hootsuite, etc.).

    Out of Scope

    Out-of-scope items should also be defined to alleviate ambiguity, reduce assumptions, and further clarify expectations for stakeholders. Out-of-scope items can be placed in a backlog for later consideration. For example, fulfilment and logistics management is out of scope as it pertains to CXM.

    In Scope
    Strategy
    High-Level CXM Application Requirements CXM Strategic Direction Category Level Application Solutions (e.g. CRM, MMS, etc.)
    Out of Scope
    Software Selection
    Vendor Application Review Vendor Application Selection Granular Application System Requirements

    Activity: Define the scope of the CXM strategy

    1.2.3 30 minutes

    Input

    • N/A

    Output

    • Project scope and parameters
    • CXM Strategy Project Charter Template, section 3.0

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Sponsor
    • Project Manager
    • Business Lead

    Instructions

    1. Formulate a scope statement. Decide which people, processes, and functions the CXM strategy will address. Generally, the aim of this project is to develop strategic requirements for the CXM application portfolio – not to select individual vendors.
    2. Document your scope statement in Info-Tech’s CXM Strategy Project Charter Template in section 3.0.

    To form your scope statement, ask the following questions:

    • What are the major coverage points?
    • Who will be using the systems?
    • How will different users interact with the systems?
    • What are the objectives that need to be addressed?
    • Where do we start?
    • Where do we draw the line?

    Identify the right stakeholders to include on your project team

    Consider the core team functions when composing the project team. Form a cross-functional team (i.e. across IT, Marketing, Sales, Service, Operations) to create a well-aligned CXM strategy.

    Required Skills/Knowledge Suggested Project Team Members
    IT
    • Application development
    • Enterprise integration
    • Business processes
    • Data management
    • CRM Application Manager
    • Business Process Manager
    • Integration Manager
    • Application Developer
    • Data Stewards
    Business
    • Understanding of the customer
    • Departmental processes
    • Sales Manager
    • Marketing Manager
    • Customer Service Manager
    Other
    • Operations
    • Administrative
    • Change management
    • Operations Manager
    • CFO
    • Change Management Manager

    Info-Tech Insight

    Don’t let your project team become too large when trying to include all relevant stakeholders. Carefully limiting the size of the project team will enable effective decision making while still including functional business units such as marketing, sales, service, and finance, as well as IT.

    Activity: Create the project team

    1.2.4 45 minutes

    Input

    • Scope Statement (output of Activity 1.2.3).

    Output

    • Project Team
    • CXM Strategy Project Charter Template, section 4.0

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Manager
    • Business Lead

    Instructions

    1. Review your scope statement. Have a discussion to generate a complete list of key stakeholders that are needed to achieve the scope of work.
    2. Using the previously generated list, identify a candidate for each role and determine their responsibilities and expected time commitment for the CXM strategy project.
    3. Document the project team in Info-Tech’s CXM Strategy Project Charter Template in section 4.0.

    Define project roles and responsibilities to improve progress tracking

    Build a list of the core CXM strategy team members, and then structure a RACI chart with the relevant categories and roles for the overall project.

    Responsible - Conducts work to achieve the task

    Accountable - Answerable for completeness of task

    Consulted - Provides input for the task

    Informed - Receives updates on the task

    Info-Tech Insight

    Avoid missed tasks between inter-functional communications by defining roles and responsibilities for the project as early as possible.

    Benefits of Assigning RACI Early:

    • Improve project quality by assigning the right people to the right tasks.
    • Improve chances of project task completion by assigning clear accountabilities.
    • Improve project buy-in by ensuring that stakeholders are kept informed of project progress, risks, and successes.

    Activity: Build a RACI chart

    1.2.5 30 minutes

    Input

    • Project Team (output of Activity 1.2.4)

    Output

    • RACI chart
    • CXM Strategy Project Charter Template, section 4.2

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Manager
    • Business Lead

    Instructions

    1. Identify the key stakeholder teams that should be involved in the CXM strategy project. You should have a cross-functional team that encompasses both IT (various units) and the business.
    2. Determine whether each stakeholder should be responsible, accountable, consulted, and/or informed with respect to each overarching project step.
    3. Confirm and communicate the results to relevant stakeholders and obtain their approval.
    4. Document the RACI chart in Info-Tech’s CXM Strategy Project Charter Template in section 4.2.
    Example: RACI Chart Project Sponsor (e.g. CMO) Project Manager (e.g. Applications Manager) Business Lead (e.g. Marketing Director) Steering Committee (e.g. PM, CMO, CFO…) Project Team (e.g. PM, BL, SMEs…)
    Assess Project Value I C A R C
    Conduct a Current State Assessment I I A C R
    Design Application Portfolio I C A R I
    Create CXM Roadmap R R A I I
    ... ... ... ... ... ...

    Activity: Develop a timeline in order to specify concrete project milestones

    1.2.6 30 minutes

    Input

    • N/A

    Output

    • Project timeline
    • CXM Strategy Project Charter Template, section 5.0

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Manager
    • Business Lead

    Instructions

    1. Assign responsibilities, accountabilities, and other project involvement to each project team role using a RACI chart. Remember to consider dependencies when creating the schedule and identifying appropriate subtasks.
    2. Document the timeline in Info-Tech’s CXM Strategy Project Charter Template in section 5.0.
    Key Activities Start Date End Date Target Status Resource(s)
    Structure the Project and Build the Project Team
    Articulate Business Objectives and Define Vision for Future State
    Document Current State and Assess Gaps
    Identify CXM Technology Solutions
    Build the Strategy for CXM
    Implement the Strategy

    Assess project-associated risk by understanding common barriers and enablers

    Common Internal Risk Factors

    Management Support Change Management IT Readiness
    Definition The degree of understanding and acceptance of CXM as a concept and necessary portfolio of technologies. The degree to which employees are ready to accept change and the organization is ready to manage it. The degree to which the organization is equipped with IT resources to handle new systems and processes.
    Assessment Outcomes
    • Is CXM enablement recognized as a top priority?
    • Will management commit time to the project?
    • Are employees resistant to change?
    • Is there an organizational awareness of the importance of customer experience?
    • Who are the owners of process and content?
    • Is there strong technical expertise?
    • Is there strong infrastructure?
    • What are the important integration points throughout the business?
    Risk
    • Low management buy-in
    • Lack of funding
    • Lack of resources
    • Low employee motivation
    • Lack of ownership
    • Low user adoption
    • Poor implementation
    • Reliance on consultants

    Activity: Identify the risks and create mitigation strategies

    1.2.7 45 minutes

    Input

    • N/A

    Output

    • Risk mitigation strategy
    • CXM Strategy Project Charter Template, section 6.0

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Manager
    • Business Lead
    • Project Team

    Instructions

    1. Brainstorm a list of possible risks that may impede the progress of your CXM project.
    2. Classify risks as strategy based (related to planning) or systems based (related to technology).
    3. Brainstorm mitigation strategies to overcome each risk.
    4. On a scale of 1 to 3, determine the impact of each risk on project success and the likelihood of each risk occurring.
    5. Document your findings in Info-Tech’s CXM Strategy Project Charter Template in section 6.0.

    Likelihood:

    1 - High/Needs Focus

    2 - Can Be Mitigated

    3 - Unlikely

    Impact

    1 - High Impact

    2 - Moderate Impact

    3 - Minimal Impact

    Example: Risk Register and Mitigation Tactics

    Risk Impact Likelihood Mitigation Effort
    Cost of time and implementation: designing a robust portfolio of CXM applications can be a time consuming task, representing a heavy investment for the organization 1 1
    • Have a clear strategic plan and a defined time frame
    • Know your end-user requirements
    • Put together an effective and diverse strategy project team
    Availability of resources: lack of in-house resources (e.g. infrastructure, CXM application developers) may result in the need to insource or outsource resources 1 2
    • Prepare a plan to insource talent by hiring or transferring talent from other departments – e.g. marketing and customer service

    Activity: Complete the project charter and obtain approval

    1.2.8 45 minutes

    Input

    • N/A

    Output

    • Project approval
    • CXM Strategy Project Charter Template, section 8.0

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Manager
    • Business Lead
    • Project Team

    Instructions

    Before beginning to develop the CXM strategy, validate the project charter and metrics with senior sponsors or stakeholders and receive their approval to proceed.

    1. Schedule a 30-60 minute meeting with senior stakeholders and conduct a live review of your CXM strategy project charter.
    2. Obtain stakeholder approval to ensure there are no miscommunications or misunderstandings around the scope of the work that needs to be done to reach a successful project outcome. Final sign-off should only take place when mutual consensus has been reached.
      • Obtaining approval should be an iterative process; if senior management has concerns over certain aspects of the plan, revise and review again.

    Info-Tech Insight

    In most circumstances, you should have your CXM strategy project charter validated with the following stakeholders:

    • Chief Information Officer
    • IT Applications Director
    • CFO or Comptroller (for budget approval)
    • Chief Marketing Office or Head of Marketing
    • Chief Revenue Officer or VP of Sales
    • VP Customer Service

    If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

    Book a workshop with our Info-Tech analysts:

    1.2.2 Define project purpose, objectives, and business metrics

    Through an in-depth discussion, an analyst will help you prioritize corporate objectives and organizational drivers to establish a distinct project purpose.

    1.2.3 Define the scope of the CXM strategy

    An analyst will facilitate a discussion to address critical questions to understand your distinct business needs. These questions include: What are the major coverage points? Who will be using the system?

    1.2.4; 1.2.5; 1.2.6 Create the CXM project team, build a RACI chart, and establish a timeline

    Our analysts will guide you through how to create a designated project team to ensure the success of your CXM strategy and suite selection initiative, including project milestones and team composition, as well as designated duties and responsibilities.

    Phase 2

    Create a Strategic Framework for CXM Technology Enablement

    Build a Strong Technology Foundation for Customer Experience Management

    Phase 2 outline: Steps 2.1 and 2.2

    Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

    Complete these steps on your own, or call us to complete a guided implementation. A guided implementation is a series of 2-3 advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

    Guided Implementation 2: Create a Strategic Framework for CXM Technology Enablement

    Proposed Time to Completion: 4 weeks

    Step 2.1: Scan the External Environment

    Start with an analyst kick-off call:

    • Discuss external drivers
    • Assess competitive environment
    • Review persona development
    • Review scenarios

    Then complete these activities…

    • Build the CXM operating model
    • Conduct a competitive analysis
    • Conduct a PEST analysis
    • Build personas and scenarios

    With these tools & templates:

    CXM Strategy Stakeholder Presentation Template

    Step 2.2: Assess the Current State for CRM

    Review findings with analyst:

    • Review SWOT analysis
    • Review VRIO analysis
    • Discuss strategic requirements for CXM

    Then complete these activities…

    • Conduct a SWOT analysis
    • Conduct a VRIO analysis
    • Inventory existing applications

    With these tools & templates:

    CXM Strategy Stakeholder Presentation Template

    Phase 2 outline: Steps 2.3 and 2.4

    Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

    Complete these steps on your own, or call us to complete a guided implementation. A guided implementation is a series of 2-3 advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

    Guided Implementation 2: Create a Strategic Framework for CXM Technology Enablement

    Proposed Time to Completion: 4 weeks

    Step 2.3: Create an Application Portfolio

    Start with an analyst kick-off call:

    • Discuss possible business process maps
    • Discuss strategic requirements
    • Review application portfolio results

    Then complete these activities…

    • Build business maps
    • Execute application mapping

    With these tools & templates:

    CXM Portfolio Designer

    CXM Strategy Stakeholder Presentation Template

    CXM Business Process Shortlisting Tool

    Step 2.4: Develop Deployment Best Practices

    Review findings with analyst:

    • Review possible integration maps
    • Discuss best practices for end-user adoption
    • Discuss best practices for customer data quality

    Then complete these activities…

    • Create CXM integration ecosystem
    • Develop adoption game plan
    • Create data quality standards

    With these tools & templates:

    CXM Strategy Stakeholder Presentation Template

    Phase 2 Results & Insights:

    • Application portfolio for CXM
    • Deployment best practices for areas such as integration, data quality, and end-user adoption

    Step 2.1: Scan the External Environment

    Phase 1

    1.1 Create the Project Vision

    1.2 Structure the Project

    Phase 2

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    Phase 3

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Activities:

    • Inventory CXM drivers and organizational objectives
    • Identify CXM challenges and pain points
    • Discuss opportunities and benefits
    • Align corporate and CXM strategies
    • Conduct a competitive analysis
    • Conduct a PEST analysis and extract strategic requirements
    • Build customer personas and extract strategic requirements

    Outcomes:

    • CXM operating model
      • Organizational drivers
      • Environmental factors
      • Barriers
      • Enablers
    • PEST analysis
    • External customer personas
    • Customer journey scenarios
    • Strategic requirements for CXM

    Develop a CXM technology operating model that takes stock of needs, drivers, barriers, and enablers

    Establish the drivers, enablers, and barriers to developing a CXM technology enablement strategy. In doing so, consider needs, environmental factors, organizational drivers, and technology drivers as inputs.

    CXM Strategy

    • Barriers
      • Lack of Resources
      • Cultural Mindset
      • Resistance to Change
      • Poor End-User Adoption
    • Enablers
      • Senior Management Support
      • Customer Data Quality
      • Current Technology Portfolio
    • Business Needs (What are your business drivers? What are current marketing, sales, and customer service pains?)
      • Acquisition Pipeline Management
      • Live Chat for Support
      • Social Media Analytics
      • Etc.
    • Organizational Goals
      • Increase Profitability
      • Enhance Customer Experience Consistency
      • Reduce Time-to-Resolution
      • Increase First Contact Resolution
      • Boost Share of Voice
    • Environmental Factors (What factors that affect your strategy are out of your control?)
      • Customer Buying Habits
      • Changing Technology Trends
      • Competitive Landscape
      • Regulatory Requirements
    • Technology Drivers (Why do you need a new system? What is the purpose for becoming an integrated organization?)
      • System Integration
      • Reporting Capabilities
      • Deployment Model

    Understand your needs, drivers, and organizational objectives for creating a CXM strategy

    Business Needs Organizational Drivers Technology Drivers Environmental Factors
    Definition A business need is a requirement associated with a particular business process (for example, Marketing needs customer insights from the website – the business need would therefore be web analytics capabilities). Organizational drivers can be thought of as business-level goals. These are tangible benefits the business can measure such as customer retention, operation excellence, and financial performance. Technology drivers are technological changes that have created the need for a new CXM enablement strategy. Many organizations turn to technology systems to help them obtain a competitive edge. External considerations are factors taking place outside of the organization that are impacting the way business is conducted inside the organization. These are often outside the control of the business.
    Examples
    • Web analytics
    • Live chat capabilities
    • Mobile self-service
    • Social media listening
    • Data quality
    • Customer satisfaction
    • Branding
    • Time-to-resolution
    • Deployment model (i.e. SaaS)
    • Integration
    • Reporting capabilities
    • Fragmented technologies
    • Economic factors
    • Customer preferences
    • Competitive influencers
    • Compliance regulations

    Info-Tech Insight

    A common organizational driver is to provide adequate technology enablement across multiple channels, resulting in a consistent customer experience. This driver is a result of external considerations. Many industries today are highly competitive and rapidly changing. To succeed under these pressures, you must have a rationalized portfolio of enterprise applications for customer interaction.

    Activity: Inventory and discuss CXM drivers and organizational objectives

    2.1.1 30 minutes

    Input

    • Business needs
    • Exercise 1.1.3
    • Exercise 1.1.4
    • Environmental factors

    Output

    • CXM operating model inputs
    • CXM Strategy Stakeholder Presentation

    Materials

    • Info-Tech examples
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Brainstorm the business needs, organizational drivers, technology drivers, and environmental factors that will inform the CXM strategy. Draw from exercises 1.1.3-1.1.5.
    2. Document your findings in the CXM operating model template. This can be found in the CXM Strategy Stakeholder Presentation Template.

    The image is a graphic, with a rectangle split into three sections in the centre. The three sections are: Barriers; CXM Strategy; Enablers. Around the centre are 4 more rectangles, labelled: Business Needs; Organizational Drivers; Technology Drivers; Environmental Factors. The outer rectangles are a slightly darker shade of grey than the others, highlighting them.

    Understand challenges and barriers to creating and executing the CXM technology-enablement strategy

    Take stock of internal challenges and barriers to effective CXM strategy execution.

    Example: Internal Challenges & Potential Barriers

    Understanding the Customer Change Management IT Readiness
    Definition The degree to which a holistic understanding of the customer can be created, including customer demographic and psychographics. The degree to which employees are ready to accept operational and cultural changes and the degree to which the organization is ready to manage it. The degree to which IT is ready to support new technologies and processes associated with a portfolio of CXM applications.
    Questions to Ask
    • As an organization, do we have a true understanding of our customers?
    • How might we achieve a complete understanding of the customer throughout different phases of the customer lifecycle?
    • Are employees resistant to change?
    • Are there enough resources to drive an CXM strategy?
    • To what degree is the existing organizational culture customer-centric?
    • Is there strong technical expertise?
    • Is there strong infrastructure?
    Implications
    • Uninformed creation of CXM strategic requirements
    • Inadequate understanding of customer needs and wants
    • User acceptance
    • Lack of ownership
    • Lack of accountability
    • Lack of sustainability
    • Poor implementation
    • Reliance on expensive external consultants
    • Lack of sustainability

    Activity: Identify CXM challenges and pain points

    2.1.2 30 minutes

    Input

    • Challenges
    • Pain points

    Output

    • CXM operating model barriers
    • CXM Strategy Stakeholder Presentation

    Materials

    • Info-Tech examples
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Brainstorm the challenges and pain points that may act as barriers to the successful planning and execution of a CXM strategy.
    2. Document your findings in the CXM operating model template. This can be found in the CXM Strategy Stakeholder Presentation Template.

    The image is the same graphic from a previous section. In this instance, the Barriers sections is highlighted.

    Identify opportunities that can enable CXM strategy execution

    Existing internal conditions, capabilities, and resources can create opportunities to enable the CXM strategy. These opportunities are critical to overcoming challenges and barriers.

    Example: Opportunities to Leverage for Strategy Enablement

    Management Buy-In Customer Data Quality Current Technology Portfolio
    Definition The degree to which upper management understands and is willing to enable a CXM project, complete with sponsorship, funding, and resource allocation. The degree to which customer data is accurate, consistent, complete, and reliable. Strong customer data quality is an opportunity – poor data quality is a barrier. The degree to which the existing portfolio of CXM-supporting enterprise applications can be leveraged to enable the CXM strategy.
    Questions to Ask
    • Is management informed of changing technology trends and the subsequent need for CXM?
    • Are adequate funding and resourcing available to support a CXM project, from strategy creation to implementation?
    • Are there any data quality issues?
    • Is there one source of truth for customer data?
    • Are there duplicate or incomplete sets of data?
    • Does a strong CRM backbone exist?
    • What marketing, sales, and customer service applications exist?
    • Are CXM-enabling applications rated highly on usage and performance?
    Implications
    • Need for CXM clearly demonstrated
    • Financial and logistical feasibility
    • Consolidated data quality governance initiatives
    • Informed decision making
    • Foundation for CXM technology enablement largely in place
    • Reduced investment of time and money needed

    Activity: Discuss opportunities and benefits

    2.1.3 30 minutes

    Input

    • Opportunities
    • Benefits

    Output

    • Completed CXM operating model
    • CXM Strategy Stakeholder Presentation

    Materials

    • Info-Tech examples
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Brainstorm opportunities that should be leveraged or benefits that should be realized to enable the successful planning and execution of a CXM strategy.
    2. Document your findings in the CXM operating model template. This can be found in the CXM Strategy Stakeholder Presentation Template.

    The image is the same graphic from earlier sections, this time with the Enablers section highlighted.

    Ensure that you align your CXM technology strategy to the broader corporate strategy

    A successful CXM strategy requires a comprehensive understanding of an organization’s overall corporate strategy and its effects on the interrelated departments of marketing, sales, and service, including subsequent technology implications. For example, a CXM strategy that emphasizes tools for omnichannel management and is at odds with a corporate strategy that focuses on only one or two channels will fail.

    Corporate Strategy

    • Conveys the current state of the organization and the path it wants to take.
    • Identifies future goals and business aspirations.
    • Communicates the initiatives that are critical for getting the organization from its current state to the future state.

    CXM Strategy

    • Communicates the company’s budget and spending on CXM applications and initiatives.
    • Identifies IT initiatives that will support the business and key CXM objectives, specific to marketing, sales, and service.
    • Outlines staffing and resourcing for CXM initiatives.

    Unified Strategy

    • The CXM implementation can be linked, with metrics, to the corporate strategy and ultimate business objectives.

    Info-Tech Insight

    Your organization’s corporate strategy is especially important in dictating the direction of the CXM strategy. Corporate strategies are often focused on customer-facing activity and will heavily influence the direction of marketing, sales, customer service, and consequentially, CXM. Corporate strategies will often dictate market targeting, sales tactics, service models, and more.

    Review sample organizational objectives to decipher how CXM technologies can support such objectives

    Identifying organizational objectives of high priority will assist in breaking down CXM objectives to better align with the overall corporate strategy and achieve buy-in from key stakeholders.

    Corporate Objectives Aligned CXM Technology Objectives
    Increase Revenue Enable lead scoring Deploy sales collateral management tools Improve average cost per lead via a marketing automation tool
    Enhance Market Share Enhance targeting effectiveness with a CRM Increase social media presence via an SMMP Architect customer intelligence analysis
    Improve Customer Satisfaction Reduce time-to-resolution via better routing Increase accessibility to customer service with live chat Improve first contact resolution with customer KB
    Increase Customer Retention Use a loyalty management application Improve channel options for existing customers Use customer analytics to drive targeted offers
    Create Customer-Centric Culture Ensure strong training and user adoption programs Use CRM to provide 360-degree view of all customer interaction Incorporate the voice of the customer into product development

    Activity: Review your corporate strategy and validate its alignment with the CXM operating model

    2.1.4 30 minutes

    Input

    • Corporate strategy
    • CXM operating model (completed in Activity 2.1.3)

    Output

    • Strategic alignment between the business and CXM strategies

    Materials

    • Info-Tech examples
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Brainstorm and create a list of organizational objectives at the corporate strategy level.
    2. Break down each organizational objective to identify how CXM may support it.
    3. Validate CXM goals and organizational objectives with your CXM operating model. Be sure to address the validity of each with the business needs, organizational drivers, technology drivers, and environmental factors identified as inputs to the operating model.

    Amazon leverages customer data to drive decision making around targeted offers and customer experience

    CASE STUDY

    Industry E-Commerce

    Source Pardot, 2012

    Situation

    Amazon.com, Inc. is an American electronic commerce and cloud computing company. It is the largest e-commerce retailer in the US.

    Amazon originated as an online book store, later diversifying to sell various forms of media, software, games, electronics, apparel, furniture, food, toys, and more.

    By taking a data-driven approach to marketing and sales, Amazon was able to understand its customers’ needs and wants, penetrate different product markets, and create a consistently personalized online-shopping customer experience that keeps customers coming back.

    Technology Strategy

    Use Browsing Data Effectively

    Amazon leverages marketing automation suites to view recent activities of prospects on its website. In doing so, a more complete view of the customer is achieved, including insights into purchasing interests and site navigation behaviors.

    Optimize Based on Interactions

    Using customer intelligence, Amazon surveys and studies standard engagement metrics like open rate, click-through rate, and unsubscribes to ensure the optimal degree of marketing is being targeted to existing and prospective customers, depending on level of engagement.

    Results

    Insights gained from having a complete understanding of the customer (from basic demographic characteristics provided in customer account profiles to observed psychographic behaviors captured by customer intelligence applications) are used to personalize Amazon’s sales and marketing approaches. This is represented through targeted suggestions in the “recommended for you” section of the browsing experience and tailored email marketing.

    It is this capability, partnered with the technological ability to observe and measure customer engagement, that allows Amazon to create individual customer experiences.

    Scan the external environment to understand your customers, competitors, and macroenvironmental trends

    Do not develop your CXM technology strategy in isolation. Work with Marketing to understand your STP strategy (segmentation, targeting, positioning): this will inform persona development and technology requirements downstream.

    Market Segmentation

    • Segment target market by demographic, geographic, psychographic, and behavioral characteristics
    • What does the competitive market look like?
    • Who are the key customer segments?
    • What segments are you going to target?

    Market Targeting

    • Evaluate potential and commercial attractiveness of each segment, considering the dynamics of the competition
    • How do you target your customers?
    • How should you target them in the future?
    • How do your products/services differ from the competition?

    Product Positioning

    • Develop detailed product positioning and marketing mixes for selected segments
    • What is the value of the product/service to each segment of the market?
    • How are you positioning your product/service in the market?

    Info-Tech Insight

    It is at this point that you should consider the need for and viability of an omnichannel approach to CXM. Through which channels do you target your customers? Are your customers present and active on a wide variety of channels? Consider how you can position your products, services, and brand through the use of omnichannel methodologies.

    Activity: Conduct a competitive analysis to understand where your market is going

    2.1.5 1 hour

    Input

    • Scan of competitive market
    • Existing customer STP strategy

    Output

    • Strategic CXM requirements
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team
    • Marketing SME

    Instructions

    1. Scan the market for direct and indirect competitors.
    2. Evaluate current and/or future segmentation, targeting, and positioning strategies by answering the following questions:
    • What does the competitive market look like?
    • Who are the key customer segments?
    • What segments are you going to target?
    • How do you target your customers?
    • How should you target them in the future?
    • How do your products/services differ from the competition?
    • What is the value of the product/service to each segment of the market?
    • How are you positioning your product/service in the market?
    • Other helpful questions include:
      • How formally do you target customers? (e.g. through direct contact vs. through passive brand marketing)
      • Does your organization use the shotgun or rifle approach to marketing?
        • Shotgun marketing: targets a broad segment of people, indirectly
        • Rifle marketing: targets smaller and more niche market segments using customer intelligence
  • For each point, identify CXM requirements.
  • Document your outputs in the CXM Strategy Stakeholder Presentation Template.
  • Activity: Conduct a competitive analysis (cont’d)

    2.1.5 30 minutes

    Input

    • Scan of competitive market

    Output

    • Competitive analysis
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team
    • Marketing SME (e.g. Market Research Stakeholders)

    Instructions

    1. List recent marketing technology and customer experience-related initiatives that your closest competitors have implemented.
    2. For each identified initiative, elaborate on what the competitive implications are for your organization.
    3. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Competitive Implications

    Competitor Organization Recent Initiative Associated Technology Direction of Impact Competitive Implication
    Organization X Multichannel E-Commerce Integration WEM – hybrid integration Positive
    • Up-to-date e-commerce capabilities
    • Automatic product updates via PCM
    Organization Y Web Social Analytics WEM Positive
    • Real-time analytics and customer insights
    • Allows for more targeted content toward the visitor or customer

    Conduct a PEST analysis to determine salient political, economic, social, and technological impacts for CXM

    A PEST analysis is a structured planning method that identifies external environmental factors that could influence the corporate and IT strategy.

    Political - Examine political factors, such as relevant data protection laws and government regulations.

    Economic - Examine economic factors, such as funding, cost of web access, and labor shortages for maintaining the site(s).

    Technological - Examine technological factors, such as new channels, networks, software and software frameworks, database technologies, wireless capabilities, and availability of software as a service.

    Social - Examine social factors, such as gender, race, age, income, and religion.

    Info-Tech Insight

    When looking at opportunities and threats, PEST analysis can help to ensure that you do not overlook external factors, such as technological changes in your industry. When conducting your PEST analysis specifically for CXM, pay particular attention to the rapid rate of change in the technology bucket. New channels and applications are constantly emerging and evolving, and seeing differential adoption by potential customers.

    Activity: Conduct and review the PEST analysis

    2.1.6 30 minutes

    Input

    • Political, economic, social, and technological factors related to CXM

    Output

    • Completed PEST analysis

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Identify your current strengths and weaknesses in managing the customer experience.
    2. Identify any opportunities to take advantage of and threats to mitigate.

    Example: PEST Analysis

    Political

    • Data privacy for PII
    • ADA legislation for accessible design

    Economic

    • Spending via online increasing
    • Focus on share of wallet

    Technological

    • Rise in mobile
    • Geo-location based services
    • Internet of Things
    • Omnichannel

    Social

    • Increased spending power by millennials
    • Changing channel preferences
    • Self-service models

    Activity: Translate your PEST analysis into a list of strategic CXM technology requirements to be addressed

    2.1.7 30 minutes

    Input

    • PEST Analysis conducted in Activity 2.1.6.

    Output

    • Strategic CXM requirements
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    For each PEST quadrant:

    1. Document the point and relate it to a goal.
    2. For each point, identify CXM requirements.
    3. Sort goals and requirements to eliminate duplicates.
    4. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Parsing Requirements from PEST Analysis

    Technological Trend: There has been a sharp increase in popularity of mobile self-service models for buying habits and customer service access.

    Goal: Streamline mobile application to be compatible with all mobile devices. Create consistent branding across all service delivery applications (e.g. website, etc.).

    Strategic Requirement: Develop a native mobile application while also ensuring that resources through our web presence are built with responsive design interface.

    IT must fully understand the voice of the customer: work with Marketing to develop customer personas

    Creating a customer-centric CXM technology strategy requires archetypal customer personas. Creating customer personas will enable you to talk concretely about them as consumers of your customer experience and allow you to build buyer scenarios around them.

    A persona (or archetypal user) is an invented person that represents a type of user in a particular use-case scenario. In this case, personas can be based on real customers.

    Components of a persona Example – Organization: Grocery Store
    Name Name personas to reflect a key attribute such as the persona’s primary role or motivation Brand Loyal Linda: A stay-at-home mother dedicated to maintaining and caring for a household of 5 people
    Demographic Include basic descriptors of the persona (e.g. age, geographic location, preferred language, education, job, employer, household income, etc.) Age: 42 years old Geographic location: London Suburbia Language: English Education: Post-secondary Job: Stay-at-home mother Annual Household Income: $100,000+
    Wants, needs, pain points Identify surface-level motivations for buying habits

    Wants: Local products Needs: Health products; child-safe products

    Pain points: Fragmented shopping experience

    Psychographic/behavioral traits Observe persona traits that are representative of the customers’ behaviors (e.g. attitudes, buying patterns, etc.)

    Psychographic: Detail-oriented, creature of habit

    Behavioral: Shops at large grocery store twice a week, visits farmers market on Saturdays, buys organic products online

    Activity: Build personas for your customers

    2.1.8 2 hours

    Input

    • Customer demographics and psychographics

    Output

    • List of prioritized customer personas
    • CXM Strategy Stakeholder Presentation

    Materials

    • Info-Tech examples
    • Whiteboard
    • Markers

    Participants

    Project Team

    Instructions

    1. In 2-4 groups, list all the customer personas that need to be built. In doing so, consider the people who interact with your organization most often.
    2. Build a demographic profile for each customer persona. Include information such as age, geographic location, occupation, annual income, etc.
    3. Augment the persona with a psychographic profile of each customer. Consider the goals and objectives of each customer persona and how these might inform buyer behaviors.
    4. Introduce your group’s personas to the entire group, in a round-robin fashion, as if you are introducing your persona at a party.
    5. Summarize the personas in a persona map. Rank your personas according to importance and remove any duplicates.

    Info-Tech Insight

    For CXM, persona building is typically used for understanding the external customer; however, if you need to gain a better understanding of the organization’s internal customers (those who will be interacting with CXM applications), personas can also be built for this purpose. Examples of useful internal personas are sales managers, brand managers, customer service directors, etc.

    Sample Persona Templates

    Fred, 40

    The Family Man

    Post-secondary educated, white-collar professional, three children

    Goals & Objectives

    • Maintain a stable secure lifestyle
    • Progress his career
    • Obtain a good future for his children

    Behaviors

    • Manages household and finances
    • Stays actively involved in children’s activities and education
    • Seeks potential career development
    • Uses a cellphone and email frequently
    • Sometimes follows friends Facebook pages

    Services of Interest

    • SFA, career counselling, job boards, day care, SHHS
    • Access to information via in-person, phone, online

    Traits

    General Literacy - High

    Digital Literacy - Mid-High

    Detail-Oriented - High

    Willing to Try New Things - Mid-High

    Motivated and Persistent - Mid-High

    Time Flexible - Mid-High

    Familiar With [Red.] - Mid

    Access to [Red.] Offices - High

    Access to Internet - High

    Ashley, 35

    The Tourist

    Single, college educated, planning vacation in [redacted], interested in [redacted] job opportunities

    Goals & Objectives

    • Relax after finishing a stressful job
    • Have adventures and try new things
    • Find a new job somewhere in Canada

    Behaviors

    • Collects information about things to do in [redacted]
    • Collects information about life in [redacted]
    • Investigates and follows up on potential job opportunities
    • Uses multiple social media to keep in touch with friends
    • Shops online frequently

    Services of Interest

    • SFA, job search, road conditions, ferry schedules, hospital, police station, DL requirements, vehicle rental
    • Access to information via in-person, phone, website, SMS, email, social media

    Traits

    General Literacy - Mid

    Digital Literacy - High

    Detail-Oriented - Mid

    Willing to Try New Things - High

    Motivated and Persistent - Mid

    Time Flexible - Mid-High

    Familiar With [Red.] - Low

    Access to [Red.] Offices - Low

    Access to Internet - High

    Bill, 25

    The Single Parent

    15-year resident of [redacted], high school education, waiter, recently divorced, two children

    Goals & Objectives

    • Improve his career options so he can support his family
    • Find an affordable place to live
    • Be a good parent
    • Work through remaining divorce issues

    Behaviors

    • Tries to get training or experience to improve his career
    • Stays actively involved in his children’s activities
    • Looks for resources and supports to resolve divorce issues
    • Has a cellphone and uses the internet occasionally

    Services of Interest

    • Child care, housing authority, legal aid, parenting resources
    • Access to information via in person, word-of mouth, online, phone, email

    Traits

    General Literacy - Mid

    Digital Literacy - Mid-Low

    Detail-Oriented - Mid-Low

    Willing to Try New Things - Mid

    Motivated and Persistent - High

    Time Flexible - Mid

    Familiar With [Red.] - Mid-High

    Access to [Red.] Offices - High

    Access to Internet - High

    Marie, 19

    The Regional Youth

    Single, [redacted] resident, high school graduate

    Goals & Objectives

    • Get a good job
    • Maintain ties to family and community

    Behaviors

    • Looking for work
    • Gathering information about long-term career choices
    • Trying to get the training or experience that can help her develop a career
    • Staying with her parents until she can get established
    • Has a new cellphone and is learning how to use it
    • Plays videogames and uses the internet at least weekly

    Services of Interest

    • Job search, career counselling
    • Access to information via in-person, online, phone, email, web applications

    Traits

    General Literacy - Mid

    Digital Literacy - Mid

    Detail-Oriented - Mid-Low

    Willing to Try New Things - Mid-High

    Motivated and Persistent - Mid-Low

    Time Flexible - High

    Familiar With [Red.] - Mid-Low

    Access to [Red.] Offices - Mid-Low

    Access to Internet - Mid

    Build key scenarios for each persona to extract strategic requirements for your CXM application portfolio

    A scenario is a story or narrative that helps explore the set of interactions that a customer has with an organization. Scenario mapping will help parse requirements used to design the CXM application portfolio.

    A Good Scenario…

    • Describes specific task(s) that need to be accomplished
    • Describes user goals and motivations
    • Describes interactions with a compelling but not overwhelming amount of detail
    • Can be rough, as long as it provokes ideas and discussion

    Scenarios Are Used To…

    • Provide a shared understanding about what a user might want to do, and how they might want to do it
    • Help construct the sequence of events that are necessary to address in your user interface(s)

    To Create Good Scenarios…

    • Keep scenarios high level, not granular in nature
    • Identify as many scenarios as possible. If you’re time constrained, try to develop 2-3 key scenarios per persona
    • Sketch each scenario out so that stakeholders understand the goal of the scenario

    Activity: Build scenarios for each persona and extract strategic requirements for the CXM strategy

    2.1.9 1.5 hours

    Input

    • Customer personas (output of Activity 2.1.5)

    Output

    • CX scenario maps
    • Strategic CXM requirements
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. For each customer persona created in Activity 2.1.5, build a scenario. Choose and differentiate scenarios based on the customer goal of each scenario (e.g. make online purchase, seek customer support, etc.).
    2. Think through the narrative of how a customer interacts with your organization, at all points throughout the scenario. List each step in the interaction in a sequential order to form a scenario journey.
    3. Examine each step in the scenario and brainstorm strategic requirements that will be needed to support the customer’s use of technology throughout the scenario.
    4. Repeat steps 1-3 for each persona. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Scenario Map

    Persona Name: Brand Loyal Linda

    Scenario Goal: File a complaint about in-store customer service

    Look up “[Store Name] customer service” on public web. →Reach customer support landing page. →Receive proactive notification prompt for online chat with CSR. →Initiate conversation: provide order #. →CSR receives order context and information. →Customer articulates problem, CSR consults knowledgebase. →Discount on next purchase offered. →Send email with discount code to Brand Loyal Linda.

    If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

    Book a workshop with our Info-Tech analysts:

    • To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.
    • Info-Tech analysts will join you and your team onsite at your location or welcome you to Info-Tech’s historic Toronto office to participate in an innovative onsite workshop.
    • Contact your account manager (www.infotech.com/account), or email Workshops@InfoTech.com for more information.

    The following are sample activities that will be conducted by Info-Tech analysts with your team:

    2.1.1; 2.1.2; 2.1.3; 2.1.4 - Create a CXM operating model

    An analyst will facilitate a discussion to identify what impacts your CXM strategy and how to align it to your corporate strategy. The discussion will take different perspectives into consideration and look at organizational drivers, external environmental factors, as well as internal barriers and enablers.

    2.1.5 Conduct a competitive analysis

    Calling on their depth of expertise in working with a broad spectrum of organizations, our facilitator will help you work through a structured, systematic evaluation of competitors’ actions when it comes to CXM.

    If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

    Book a workshop with our Info-Tech analysts:

    2.1.6; 2.1.7 - Conduct a PEST analysis

    The facilitator will use guided conversation to target each quadrant of the PEST analysis and help your organization fully enumerate political, economic, social, and technological trends that will influence your CXM strategy. Our analysts are deeply familiar with macroenvironmental trends and can provide expert advice in identifying areas of concern in the PEST and drawing strategic requirements as implications.

    2.1.8; 2.1.9 - Build customer personas and subsequent persona scenarios

    Drawing on the preceding exercises as inputs, the facilitator will help the team create and refine personas, create respective customer interaction scenarios, and parse strategic requirements to support your technology portfolio for CXM.

    Step 2.2: Assess the Current State of CXM

    Phase 1

    1.1 Create the Project Vision

    1.2 Structure the Project

    Phase 2

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    Phase 3

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Activities:

    • Conduct a SWOT analysis and extract strategic requirements
    • Inventory existing CXM applications and assess end-user usage and satisfaction
    • Conduct a VRIO analysis and extract strategic requirements

    Outcomes:

    • SWOT analysis
    • VRIO analysis
    • Current state application portfolio
    • Strategic requirements

    Conduct a SWOT analysis to prepare for creating your CXM strategy

    A SWOT analysis is a structured planning method that evaluates the strengths, weaknesses, opportunities, and threats involved in a project.

    Strengths - Strengths describe the positive attributes that are within your control and internal to your organization (i.e. what do you do better than anyone else?)

    Weaknesses - Weaknesses are internal aspects of your business that place you at a competitive disadvantage; think of what you need to enhance to compete with your top competitor.

    Opportunities - Opportunities are external factors the project can capitalize on. Think of them as factors that represent reasons your business is likely to prosper.

    Threats - Threats are external factors that could jeopardize the project. While you may not have control over these, you will benefit from having contingency plans to address them if they occur.

    Info-Tech Insight

    When evaluating weaknesses of your current CXM strategy, ensure that you’re taking into account not just existing applications and business processes, but also potential deficits in your organization’s channel strategy and go-to-market messaging.

    Activity: Conduct a SWOT analysis

    2.2.1 30 minutes

    Input

    • CXM strengths, weaknesses, opportunities, and threats

    Output

    • Completed SWOT analysis

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Identify your current strengths and weaknesses in managing the customer experience. Consider marketing, sales, and customer service aspects of the CX.
    2. Identify any opportunities to take advantage of and threats to mitigate.

    Example: SWOT Analysis

    Strengths

    • Strong customer service model via telephony

    Weaknesses

    • Customer service inaccessible in real-time through website or mobile application

    Opportunities

    • Leverage customer intelligence to measure ongoing customer satisfaction

    Threats

    • Lack of understanding of customer interaction platforms by staff could hinder adoption

    Activity: Translate your SWOT analysis into a list of requirements to be addressed

    2.2.2 30 minutes

    Input

    • SWOT Analysis conducted in Activity 2.2.1.

    Output

    • Strategic CXM requirements
    • CXM Stakeholder Presentation Template

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    For each SWOT quadrant:

    1. Document the point and relate it to a goal.
    2. For each point, identify CXM requirements.
    3. Sort goals and requirements to eliminate duplicates.
    4. Document your outputs in the CXM Stakeholder Presentation Template.

    Example: Parsing Requirements from SWOT Analysis

    Weakness: Customer service inaccessible in real-time through website or mobile application.

    Goal: Increase the ubiquity of access to customer service knowledgebase and agents through a web portal or mobile application.

    Strategic Requirement: Provide a live chat portal that matches the customer with the next available and qualified agent.

    Inventory your current CXM application portfolio

    Applications are the bedrock of technology enablement for CXM. Review your current application portfolio to identify what is working well and what isn’t.

    Understand Your CXM Application Portfolio With a Four-Step Approach

    Build the CXM Application Inventory →Assess Usage and Satisfaction →Map to Business Processes and Determine Dependencies →Determine Grow/Maintain/ Retire for Each Application

    When assessing the CXM applications portfolio, do not cast your net too narrowly; while CRM and MMS applications are often top of mind, applications for digital asset management and social media management are also instrumental for ensuring a well-integrated CX.

    Identify dependencies (either technical or licensing) between applications. This dependency tracing will come into play when deciding which applications should be grown (invested in), which applications should be maintained (held static), and which applications should be retired (divested).

    Info-Tech Insight

    Shadow IT is prominent here! When building your application inventory, ensure you involve Marketing, Sales, and Service to identify any “unofficial” SaaS applications that are being used for CXM. Many organizations fail to take a systematic view of their CXM application portfolio beyond maintaining a rough inventory. To assess the current state of alignment, you must build the application inventory and assess satisfaction metrics.

    Understand which of your organization’s existing enterprise applications enable CXM

    Review the major enterprise applications in your organization that enable CXM and align your requirements to these applications (net-new or existing). Identify points of integration to capture the big picture.

    The image shows a graphic titled Example: Integration of CRM, SMMP, and ERP. It is a flow chart, with icons defined by a legend on the right side of the image

    Info-Tech Insight

    When assessing the current application portfolio that supports CXM, the tendency will be to focus on the applications under the CXM umbrella, relating mostly to marketing, sales, and customer service. Be sure to include systems that act as input to, or benefit due to outputs from, CRM or similar applications. Examples of these systems are ERP systems, ECM (e.g. SharePoint) applications, and more.

    Assess CXM application usage and satisfaction

    Having a portfolio but no contextual data will not give you a full understanding of the current state. The next step is to thoroughly assess usage patterns as well as IT, management, and end-user satisfaction with each application.

    Example: Application Usage & Satisfaction Assessment

    Application Name Level of Usage IT Satisfaction Management Satisfaction End-User Satisfaction Potential Business Impact
    CRM (e.g. Salesforce) Medium High Medium Medium High
    CRM (e.g. Salesforce) Low Medium Medium High Medium
    ... ... ... ... ... ...

    Info-Tech Insight

    When evaluating satisfaction with any application, be sure to consult all stakeholders who come into contact with the application or depend on its output. Consider criteria such as ease of use, completeness of information, operational efficiency, data accuracy, etc.

    Use Info-Tech’s Application Portfolio Assessment to gather end-user feedback on existing CXM applications

    2.2.3 Application Portfolio Assessment: End-User Feedback

    Info-Tech’s Application Portfolio Assessment: End-User Feedback diagnostic is a low-effort, high-impact program that will give you detailed report cards on end-user satisfaction with an application. Use these insights to identify problems, develop action plans for improvement, and determine key participants.

    Application Portfolio Assessment: End-User Feedback is an 18-question survey that provides valuable insights on user satisfaction with an application by:

    • Performing a general assessment of the application portfolio that provides a full view of the effectiveness, criticality, and prevalence of all relevant applications.
    • Measuring individual application performance with open-ended user feedback surveys about the application, organized by department to simplify problem resolution.
    • Providing targeted department feedback to identify end-user satisfaction and focus improvements on the right group or line of business.

    INFO-TECH DIAGNOSTIC

    Activity: Inventory your CXM applications, and assess application usage and satisfaction

    2.2.4 1 hour

    Input

    • List of CXM applications

    Output

    • Complete inventory of CXM applications
    • CXM Stakeholder Presentation Template

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. List all existing applications that support the creation, management, and delivery of your customer experience.
    2. Identify which processes each application supports (e.g. content deployment, analytics, service delivery, etc.).
    3. Identify technical or licensing dependencies (e.g. data models).
    4. Assess the level of application usage by IT, management, and internal users (high/medium/low).
    5. Assess the satisfaction with and performance of each application according to IT, management, and internal users (high/medium/low). Use the Info-Tech Diagnostic to assist.

    Example: CXM Application Inventory

    Application Name Deployed Date Processes Supported Technical and Licensing Dependencies
    Salesforce June 2018 Customer relationship management XXX
    Hootsuite April 2019 Social media listening XXX
    ... ... ... ...

    Conduct a VRIO analysis to identify core competencies for CXM applications

    A VRIO analysis evaluates the ability of internal resources and capabilities to sustain a competitive advantage by evaluating dimensions of value, rarity, imitability, and organization. For critical applications like your CRM platform, use a VRIO analysis to determine their value.

    Is the resource or capability valuable in exploiting an opportunity or neutralizing a threat? Is the resource or capability rare in the sense that few of your competitors have a similar capability? Is the resource or capability costly to imitate or replicate? Is the organization organized enough to leverage and capture value from the resource or capability?
    NO COMPETITIVE DISADVANTAGE
    YES NO→ COMPETITIVE EQUALITY/PARITY
    YES YES NO→ TEMPORARY COMPETITIVE ADVANTAGE
    YES YES YES NO→ UNUSED COMPETITIVE ADVANTAGE
    YES YES YES YES LONG-TERM COMPETITIVE ADVANTAGE

    (Strategic Management Insight, 2013)

    Activity: Conduct a VRIO analysis on your existing application portfolio

    2.2.5 30 minutes

    Input

    • Inventory of existing CXM applications (output of Activity 2.2.4)

    Output

    • Completed VRIO analysis
    • Strategic CXM requirements
    • CXM Stakeholder Presentation Template

    Materials

    • VRIO Analysis model
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Evaluate each CXM application inventoried in Activity 2.2.4 by answering the four VRIO questions in sequential order. Do not proceed to the following question if “no” is answered at any point.
    2. Record the results. The state of your organization’s competitive advantage, based on each resource/capability, will be determined based on the number of questions with a “yes” answer. For example, if all four questions are answered positively, then your organization is considered to have a long-term competitive advantage.
    3. Document your outputs in the CXM Stakeholder Presentation Template.

    If you want additional support, have our analysts guide your through this phase as part of an Info-Tech workshop

    2.2.1; 2.2.2 Conduct a SWOT Analysis

    Our facilitator will use a small-team approach to delve deeply into each area, identifying enablers (strengths and opportunities) and challenges (weaknesses and threats) relating to the CXM strategy.

    2.2.3; 2.2.4 Inventory your CXM applications, and assess usage and satisfaction

    Working with your core team, the facilitator will assist with building a comprehensive inventory of CXM applications that are currently in use and with identifying adjacent systems that need to be identified for integration purposes. The facilitator will work to identify high and low performing applications and analyze this data with the team during the workshop exercise.

    2.2.5 Conduct a VRIO analysis

    The facilitator will take you through a VRIO analysis to identify which of your internal technological competencies ensure, or can be leveraged to ensure, your competitiveness in the CXM market.

    Step 2.3: Create an Application Portfolio

    Phase 1

    1.1 Create the Project Vision

    1.2 Structure the Project

    Phase 2

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    Phase 3

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Activities

    • Shortlist and prioritize business processes for improvement and reengineering
    • Map current CXM processes
    • Identify business process owners and assign job responsibilities
    • Identify user interaction channels to extract strategic requirements
    • Aggregate and develop strategic requirements
    • Determine gaps in current and future state processes
    • Build the CXM application portfolio

    Outcomes

    CXM application portfolio map

    • Shortlist of relevant business processes
    • Current state map
    • Business process ownership assignment
    • Channel map
    • Complete list of strategic requirements

    Understand business process mapping to draft strategy requirements for marketing, sales, and customer service

    The interaction between sales, marketing, and customer service is very process-centric. Rethink sales and customer-centric workflows and map the desired workflow, imbedding the improved/reengineered process into the requirements.

    Using BPM to Capture Strategic Requirements

    Business process modeling facilitates the collaboration between the business and IT, recording the sequence of events, tasks performed, who performed them, and the levels of interaction with the various supporting applications.

    By identifying the events and decision points in the process and overlaying the people that perform the functions, the data being interacted with, and the technologies that support them, organizations are better positioned to identify gaps that need to be bridged.

    Encourage the analysis by compiling an inventory of business processes that support customer-facing operations that are relevant to achieving the overall organizational strategies.

    Outcomes

    • Operational effectiveness
    • Identification, implementation, and maintenance of reusable enterprise applications
    • Identification of gaps that can be addressed by acquisition of additional applications or process improvement/ reengineering

    INFO-TECH OPPORTUNITY

    Refer to Info-Tech’s Create a Comprehensive BPM Strategy for Successful Process Automation blueprint for further assistance in taking a BPM approach to your sales-IT alignment.

    Leverage the APQC framework to help define your inventory of sales, marketing, and service processes

    APQC’s Process Classification Framework is a taxonomy of cross-functional business processes intended to allow the objective comparison of organizational performance within and among organizations.

    OPERATING PROCESSES
    1.0 Develop Vision and Strategy 2.0 Develop and Manage Products and Services 3.0 Market and Sell Products and Services 4.0 Deliver Products and Services 5.0 Manage Customer Service
    MANAGEMENT AND SUPPORT SERVICES
    6.0 Develop and Manage Human Capital
    7.0 Manage Information Technology
    8.0 Manage Financial Resources
    9.0 Acquire, Construct, and Manage Assets
    10.0 Manage Enterprise Risk, Compliance, and Resiliency
    11.0 Manage External Relationships
    12.0 Develop and Manage Business Capabilities

    (APQC, 2011)

    MORE ABOUT APQC

    • APQC serves as a high-level, industry-neutral enterprise model that allows organizations to see activities from a cross-industry process perspective.
    • Sales processes have been provided up to Level 3 of the APQC framework.
    • The APQC Framework can be accessed through APQC’s Process Classification Framework.
    • Note: The framework does not list all processes within a specific organization, nor are the processes that are listed in the framework present in every organization.

    Understand APQC’s “Market and Sell Products and Services” framework

    3.0 Market and Sell Products

    3.1 Understand markets, customers, and capabilities

    • 3.1.1 Perform customer and market intelligence analysis
    • 3.1.2 Evaluate and prioritize market opportunities

    3.2 Develop marketing strategy

    • 3.2.1 Define offering and customer value proposition
    • 3.2.2 Define pricing strategy to align to value proposition
    • 3.2.3 Define and manage channel strategy

    3.3 Develop sales strategy

    • 3.3.1 Develop sales forecast
    • 3.3.2 Develop sales partner/alliance relationships
    • 3.3.3 Establish overall sales budgets
    • 3.3.4 Establish sales goals and measures
    • 3.3.5 Establish customer management measures

    3.4 Develop and manage marketing plans

    • 3.4.1 Establish goals, objectives, and metrics by products by channels/segments
    • 3.4.2 Establish marketing budgets
    • 3.4.3 Develop and manage media
    • 3.4.4 Develop and manage pricing
    • 3.4.5 Develop and manage promotional activities
    • 3.4.6 Track customer management measures
    • 3.4.7 Develop and manage packaging strategy

    3.5 Develop and manage sales plans

    • 3.5.1 Generate leads
    • 3.5.2 Manage customers and accounts
    • 3.5.3 Manage customer sales
    • 3.5.4 Manage sales orders
    • 3.5.5 Manage sales force
    • 3.5.6 Manage sales partners and alliances

    Understand APQC’s “Manage Customer Service” framework

    5.0 Manage Customer Service

    5.1 Develop customer care/customer service strategy

    • 5.1.1 Develop customer service segmentation
      • 5.1.1.1 Analyze existing customers
      • 5.1.1.2 Analyze feedback of customer needs
    • 5.1.2 Define customer service policies and procedures
    • 5.1.3 Establish service levels for customers

    5.2 Plan and manage customer service operations

    • 5.2.1 Plan and manage customer service work force
      • 5.2.1.1 Forecast volume of customer service contacts
      • 5.2.1.2 Schedule customer service work force
      • 5.2.1.3 Track work force utilization
      • 5.2.1.4 Monitor and evaluate quality of customer interactions with customer service representatives

    5.2 Plan and 5.2.3.1 Receive customer complaints 5.2.3.2 Route customer complaints 5.2.3.3 Resolve customer complaints 5.2.3.4 Respond to customer complaints manage customer service operations

    • 5.2.2 Manage customer service requests/inquiries
      • 5.2.2.1 Receive customer requests/inquiries
      • 5.2.2.2 Route customer requests/inquiries
      • 5.2.2.3 Respond to customer requests/inquiries
    • 5.2.3 Manage customer complaints
      • 5.2.3.1 Receive customer complaints
      • 5.2.3.2 Route customer complaints
      • 5.2.3.3 Resolve customer complaints
      • 5.2.3.4 Respond to customer complaints

    Leverage the APQC framework to inventory processes

    The APQC framework provides levels 1 through 3 for the “Market and Sell Products and Services” framework. Level 4 processes and beyond will need to be defined by your organization as they are more granular (represent the task level) and are often industry-specific.

    Level 1 – Category - 1.0 Develop vision and strategy (10002)

    Represents the highest level of process in the enterprise, such as manage customer service, supply chain, financial organization, and human resources.

    Level 2 – Process Group - 1.1 Define the business concept and long-term vision (10014)

    Indicates the next level of processes and represents a group of processes. Examples include perform after sales repairs, procurement, accounts payable, recruit/source, and develop sales strategy.

    Level 3 – Process - 1.1.1 Assess the external environment (10017)

    A series of interrelated activities that convert input into results (outputs); processes consume resources and require standards for repeatable performance; and processes respond to control systems that direct quality, rate, and cost of performance.

    Level 4 – Activity - 1.1.1.1 Analyze and evaluate competition (10021)

    Indicates key events performed when executing a process. Examples of activities include receive customer requests, resolve customer complaints, and negotiate purchasing contracts.

    Level 5 – Task - 12.2.3.1.1 Identify project requirements and objectives (11117)

    Tasks represent the next level of hierarchical decomposition after activities. Tasks are generally much more fine grained and may vary widely across industries. Examples include create business case and obtain funding, and design recognition and reward approaches.

    Info-Tech Insight

    Define the Level 3 processes in the context of your organization. When creating a CXM strategy, concern yourself with the interrelatedness of processes across existing departmental silos (e.g. marketing, sales, customer service). Reserve the analysis of activities (Level 4) and tasks (Level 3) for granular work initiatives involved in the implementation of applications.

    Use Info-Tech’s CXM Business Process Shortlisting Tool to prioritize processes for improvement

    2.3.1 CXM Business Process Shortlisting Tool

    The CXM Business Process Shortlisting Tool can help you define which marketing, sales, and service processes you should focus on.

    Working in concert with stakeholders from the appropriate departments, complete the short questionnaire.

    Based on validated responses, the tool will highlight processes of strategic importance to your organization.

    These processes can then be mapped, with requirements extracted and used to build the CXM application portfolio.

    INFO-TECH DELIVERABLE

    The image shows a screenshot of the Prioritize Your Business Processes for Customer Experience Management document, with sample information filled in.

    Activity: Define your organization’s top-level processes for reengineering and improvement

    2.3.2 1 hour

    Input

    • Shortlist business processes relating to customer experience (output of Tool 2.3.1)

    Output

    • Prioritized list of top-level business processes by department

    Materials

    • APQC Framework
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Inventory all business processes relating to customer experience.
    2. Customize the impacted business units and factor weightings on the scorecard below to reflect the structure and priorities of your organization.
    3. Using the scorecard, identify all processes essential to your customer experience. The scorecard is designed to determine which processes to focus on and to help you understand the impact of the scrutinized process on the different customer-centric groups across the organization.

    The image shows a chart with the headings Factor, Check If Yes, repeated. The chart lists various factors, and the Check if Yes columns are left blank.

    This image shows a chart with the headings Factor, Weights, and Scores. It lists factors, and the rest of the chart is blank.

    Current legend for Weights and Scores

    F – Finance

    H – Human Resources

    I – IT

    L – Legal

    M – Marketing

    BU1 – Business Unit 1

    BU2 – Business Unit 2

    Activity: Map top-level business processes to extract strategic requirements for the CXM application portfolio

    2.3.3 45 minutes

    Input

    • Prioritized list of top-level business processes (output of Activity 2.3.2)

    Output

    • Current state process maps
    • CXM Strategy Stakeholder Presentation

    Materials

    • APQC Framework
    • Whiteboard
    • Markers
    • Sticky notes

    Participants

    • Project Team

    Instructions

    1. List all prioritized business processes, as identified in Activity 2.3.2. Map your processes in enough detail to capture all relevant activities and system touchpoints, using the legend included in the example. Focus on Level 3 processes, as explained in the APQC framework.
    2. Record all of the major process steps on sticky notes. Arrange the sticky notes in sequential order.
    3. On a set of different colored sticky notes, record all of the systems that enable the process. Map these system touchpoints to the process steps.
    4. Draw arrows in between the steps to represent manual entry or automation.
    5. Identify effectiveness and gaps in existing processes to determine process technology requirements.
    6. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    INFO-TECH OPPORTUNITY

    Refer to Info-Tech’s Create a Comprehensive BPM Strategy for Successful Process Automation blueprint for further assistance in taking a BPM approach to your sales-IT alignment.

    Info-Tech Insight

    Analysis of the current state is important in the context of gap analysis. It aids in understanding the discrepancies between your baseline and the future state vision, and ensures that these gaps are documented as part of the overall requirements.

    Example: map your current CXM processes to parse strategic requirements (customer acquisition)

    The image shows an example of a CXM process map, which is formatted as a flow chart, with a legend at the bottom.

    Activity: Extract requirements from your top-level business processes

    2.3.4 30 minutes

    Input

    • Current state process maps (output of Activity 2.3.3)

    Output

    • Requirements for future state mapping

    Materials

    • Info-Tech examples
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Discuss the current state of priority business processes, as mapped in Activity 2.3.3.
    2. Extract process requirements for business process improvement by asking the following questions:
    • What is the input?
    • What is the output?
    • What are the underlying risks and how can they be mitigated?
    • What conditions should be met to mitigate or eliminate each risk?
    • What are the improvement opportunities?
    • What conditions should be met to enable these opportunities?
    1. Break business requirements into functional and non-functional requirements, as outlined on this slide.

    Info-Tech Insight

    The business and IT should work together to evaluate the current state of business processes and the business requirements necessary to support these processes. Develop a full view of organizational needs while still obtaining the level of detail required to make informed decisions about technology.

    Establish process owners for each top-level process

    Identify the owners of the business processes being evaluated to extract requirements. Process owners will be able to inform business process improvement and assume accountability for reengineered or net-new processes going forward.

    Process Owner Responsibilities

    Process ownership ensures support, accountability, and governance for CXM and its supporting processes. Process owners must be able to negotiate with business users and other key stakeholders to drive efficiencies within their own process. The process owner must execute tactical process changes and continually optimize the process.

    Responsibilities include the following:

    • Inform business process improvement
    • Introduce KPIs and metrics
    • Monitor the success of the process
    • Present process findings to key stakeholders within the organization
    • Develop policies and procedures for the process
    • Implement new methods to manage the process

    Info-Tech Insight

    Identify the owners of existing processes early so you understand who needs to be involved in process improvement and reengineering. Once implemented, CXM applications are likely to undergo a series of changes. Unstructured data will multiply, the number of users may increase, administrators may change, and functionality could become obsolete. Should business processes be merged or drastically changed, process ownership can be reallocated during CXM implementation. Make sure you have the right roles in place to avoid inefficient processes and poor data quality.

    Use Info-Tech’s Process Owner Assignment Guide to aid you in choosing the right candidates

    2.3.5 Process Owner Assignment Guide

    The Process Owner Assignment Guide will ensure you are taking the appropriate steps to identify process owners for existing and net-new processes created within the scope of the CXM strategy.

    The steps in the document will help with important considerations such as key requirements and responsibilities.

    Sections of the document:

    1. Define responsibilities and level of commitment
    2. Define job requirements
    3. Receive referrals
    4. Hold formal interviews
    5. Determine performance metrics

    INFO-TECH DELIVERABLE

    Activity: Assign business process owners and identify job responsibilities

    2.3.6 30 minutes

    Input

    • Current state map (output of Activity 2.3.3)

    Output

    • Process owners assigned
    • CXM Strategy Stakeholder Presentation

    Materials

    Participants

    • Project Team

    Instructions

    1. Using Info-Tech’s Process Owner Assignment Guide, assign process owners for each process mapped out in Activity 2.3.3. To assist in doing so, answer the following questions
    • What is the level of commitment expected from each process owner?
    • How will the process owner role be tied to a formal performance appraisal?
    • What metrics can be assigned?
    • How much work will be required to train process owners?
    • Is there support staff available to assist process owners?
  • Document your outputs in the CXM Strategy Stakeholder Presentation Template.
  • Choose the channels that will make your target customers happy – and ensure they’re supported by CXM applications

    Traditional Channels

    Face-to-Face is efficient and has a positive personalized aspect that many customers desire, be it for sales or customer service.

    Telephony (or IVR) has been a mainstay of customer interaction for decades. While not fading, it must be used alongside newer channels.

    Postal used to be employed extensively for all domains, but is now used predominantly for e-commerce order fulfillment.

    Web 1.0 Channels

    Email is an asynchronous interaction channel still preferred by many customers. Email gives organizations flexibility with queuing.

    Live Chat is a way for clients to avoid long call center wait times and receive a solution from a quick chat with a service rep.

    Web Portals permit transactions for sales and customer service from a central interface. They are a must-have for any large company.

    Web 2.0 Channels

    Social Media consists of many individual services (like Facebook or Twitter). Social channels are exploding in consumer popularity.

    HTML5 Mobile Access allows customers to access resources from their personal device through its integrated web browser.

    Dedicated Mobile Apps allow customers to access resources through a dedicated mobile application (e.g. iOS, Android).

    Info-Tech Insight

    Your channel selections should be driven by customer personas and scenarios. For example, social media may be extensively employed by some persona types (i.e. Millennials) but see limited adoption in other demographics or use cases (i.e. B2B).

    Activity: Extract requirements from your channel map

    2.3.7 30 minutes

    Input

    • Current state process maps (output of Activity 2.3.3)

    Output

    • Channel map
    • CXM Strategy Stakeholder Presentation

    Materials

    • Info-Tech examples
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Inventory which customer channels are currently used by each department.
    2. Speak with the department heads for Marketing, Sales, and Customer Service and discuss future channel usage. Identify any channels that will be eliminated or added.
    3. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Business Unit Channel Use Survey

    Marketing Sales Customer Service
    Current Used? Future Use? Current Used? Future Use? Current Used? Future Use?
    Email Yes Yes No No No No
    Direct Mail Yes No No No No No
    Phone No No Yes Yes Yes Yes
    In-Person No No Yes Yes Yes No
    Website Yes Yes Yes Yes Yes Yes
    Social Channels No Yes Yes Yes No Yes

    Bring it together: amalgamate your strategic requirements for CXM technology enablement

    Discovering your organizational requirements is vital for choosing the right business-enabling initiative, technology, and success metrics. Sorting the requirements by marketing, sales, and service is a prudent mechanism for clarification.

    Strategic Requirements: Marketing

    Definition: High-level requirements that will support marketing functions within CXM.

    Examples

    • Develop a native mobile application while also ensuring that resources for your web presence are built with responsive design interface.
    • Consolidate workflows related to content creation to publish all brand marketing from one source of truth.
    • Augment traditional web content delivery by providing additional functionality such as omnichannel engagement, e-commerce, dynamic personalization, and social media functionality.

    Strategic Requirements: Sales

    Definition: High-level requirements that will support sales functions within CXM.

    Examples

    • Implement a system that reduces data errors and increases sales force efficiency by automating lead management workflows.
    • Achieve end-to-end visibility of the sales process by integrating the CRM, inventory, and order processing and shipping system.
    • Track sales force success by incorporating sales KPIs with real-time business intelligence feeds.

    Strategic Requirements: Customer Service

    Definition: High-level requirements that will support customer service functions within CXM.

    Examples

    • Provide a live chat portal that connects the customer, in real time, with the next available and qualified agent.
    • Bridge the gap between the source of truth for sales with customer service suites to ensure a consistent, end-to-end customer experience from acquisition to customer engagement and retention.
    • Use customer intelligence to track customer journeys in order to best understand and resolve customer complaints.

    Activity: Consolidate your strategic requirements for the CXM application portfolio

    2.3.8 30 minutes

    Input

    • Strategic CXM requirements (outputs of Activities 2.1.5, 2.1.6, and 2.2.2)

    Output

    • Aggregated strategic CXM requirements
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Aggregate strategic CXM requirements that have been gathered thus far in Activities 2.1.5, 2.1.6, and 2.2.2, 2.3.5, and 2.3.7.
    2. Identify and rectify any obvious gaps in the existing set of strategic CXM requirements. To do so, consider the overall corporate and CXM strategy: are there any objectives that have not been addressed in the requirements gathering process?
    3. De-duplicate the list. Prioritize the aggregated/augmented list of CXM requirements as “high/critical,” “medium/important,” or “low/desirable.” This will help manage the relative importance and urgency of different requirements to itemize respective initiatives, resources, and the time in which they need to be addressed. In completing the prioritization of requirements, consider the following:
    • Requirements prioritization must be completed in collaboration with all key stakeholders (across the business and IT). Stakeholders must ask themselves:
      • What are the consequences to the business objectives if this requirement is omitted?
      • Is there an existing system or manual process/workaround that could compensate for it?
      • What business risk is being introduced if a particular requirement cannot be implemented right away?
  • Document your outputs in the CXM Strategic Stakeholder Presentation Template.
  • Info-Tech Insight

    Strategic CXM requirements will be used to prioritize specific initiatives for CXM technology enablement and application rollout. Ensure that IT, the business, and executive management are all aligned on a consistent and agreed upon set of initiatives.

    Burberry digitizes the retail CX with real-time computing to bring consumers back to the physical storefront

    CASE STUDY

    Industry Consumer Goods, Clothing

    Source Retail Congress, 2017

    Burberry London

    Situation

    Internally, Burberry invested in organizational alignment and sales force brand engagement. The more the sales associate knew about the brand engagement and technology-enabled strategy, the better the store’s performance. Before the efforts went to building relationships with customers, Burberry built engagement with employees.

    Burberry embraced “omnichannel,” the hottest buzzword in retailing to provide consumers the most immersive and intuitive brand experience within the store.

    Technology Strategy

    RFID tags were attached to products to trigger interactive videos on the store’s screens in the common areas or in a fitting room. Consumers are to have instant access to relevant product combinations, ranging from craftsmanship information to catwalk looks. This is equivalent to the rich, immediate information consumers have grown to expect from the online shopping experience.

    Another layer of Burberry’s added capabilities includes in-memory-based analytics to gather and analyze data in real-time to better understand customers’ desires. Burberry builds customer profiles based on what items the shoppers try on from the RFID-tagged garments. Although this requires customer privacy consent, customers are willing to provide personal information to trusted brands.

    This program, called “Customer 360,” assisted sales associates in providing data-driven shopping experiences that invite customers to digitally share their buying history and preferences via their tablet devices. As the data is stored in Burberry’s customer data warehouse and accessed through an application such as CRM, it is able to arm sales associates with personal fashion advice on the spot.

    Lastly, the customer data warehouse/CRM application is linked to Burberry’s ERP system and other custom applications in a cloud environment to achieve real-time inventory visibility and fulfillment.

    Burberry digitizes the retail CX with real-time computing to bring consumers back to the physical storefront (cont'd)

    CASE STUDY

    Industry Consumer Goods, Clothing

    Source Retail Congress, 2017

    Burberry London

    Situation

    Internally, Burberry invested in organizational alignment and sales force brand engagement. The more the sales associate knew about the brand engagement and technology-enabled strategy, the better the store’s performance. Before the efforts went to building relationships with customers, Burberry built engagement with employees.

    Burberry embraced “omnichannel,” the hottest buzzword in retailing to provide consumers the most immersive and intuitive brand experience within the store.

    The Results

    Burberry achieved one of the most personalized retail shopping experiences. Immediate personal fashion advice using customer data is only one component of the experience. Not only are historic purchases and preference data analyzed, a customer’s social media posts and fashion industry trend data is proactively incorporated into the interactions between the sales associate and the customer.

    Burberry achieved CEO Angela Ahrendts’ vision of “Burberry World,” in which the brand experience is seamlessly integrated across channels, devices, retail locations, products, and services.

    The organizational alignment between Sales, Marketing, and IT empowered employees to bring the Burberry brand to life in unique ways that customers appreciated and were willing to advocate.

    Burberry is now one of the most beloved and valuable luxury brands in the world. The brand tripled sales in five years, became one of the leading voices on trends, fashion, music, and beauty while redefining what top-tier customer experience should be both digitally and physically.

    Leverage both core CRM suites and point solutions to create a comprehensive CXM application portfolio

    The debate between best-of-breed point solutions versus comprehensive CRM suites is ongoing. There is no single best answer. In most cases, an effective portfolio will include both types of solutions.

    • When the CRM market first evolved, vendors took a heavy “module-centric” approach – offering basic suites with the option to add a number of individual modules. Over time, vendors began to offer suites with a high degree of out-of-the-box functionality. The market has now witnessed the rise of powerful point solutions for the individual business domains.
    • Point solutions augment, rather than supplant, the functionality of a CRM suite in the mid-market to large enterprise context. Point solutions do not offer the necessary spectrum of functionality to take the place of a unified CRM suite.
    • Point solutions enhance aspects of CRM. For example, most CRM vendors have yet to provide truly impressive social media capabilities. An organization seeking to dominate the social space should consider purchasing a social media management platform to address this deficit in their CRM ecosystem.

    Customer Relationship Management (CRM)

    Social Media Management Platform (SMMP)

    Field Sales/Service Automation (FSA)

    Marketing Management Suites

    Sales Force Automation

    Email Marketing Tools

    Lead Management Automation (LMA)

    Customer Service Management Suites

    Customer Intelligence Systems

    Don’t adopt multiple point solutions without a genuine need: choose domains most in need of more functionality

    Some may find that the capabilities of a CRM suite are not enough to meet their specific requirements: supplementing a CRM suite with a targeted point solution can get the job done. A variety of CXM point solutions are designed to enhance your business processes and improve productivity.

    Sales

    Sales Force Automation: Automatically generates, qualifies, tracks, and contacts leads for sales representatives, minimizing time wasted on administrative duties.

    Field Sales: Allows field reps to go through the entire sales cycle (from quote to invoice) while offsite.

    Sales Compensation Management: Models, analyzes, and dispenses payouts to sales representatives.

    Marketing

    Social Media Management Platforms (SMMP): Manage and track multiple social media services, with extensive social data analysis and insight capabilities.

    Email Marketing Bureaus: Conduct email marketing campaigns and mine results to effectively target customers.

    Marketing Intelligence Systems: Perform in-depth searches on various data sources to create predictive models.

    Service

    Customer Service Management (CSM): Manages the customer support lifecycle with a comprehensive array of tools, usually above and beyond what’s in a CRM suite.

    Customer Service Knowledge Management (CSKM): Advanced knowledgebase and resolution tools.

    Field Service Automation (FSA): Manages customer support tickets, schedules work orders, tracks inventory and fleets, all on the go.

    Info-Tech Insight

    CRM and point solution integration is critical. A best-of-breed product that poorly integrates with your CRM suite compromises the value generated by the combined solution, such as a 360-degree customer view. Challenge point solution vendors to demonstrate integration capabilities with CRM packages.

    Refer to your use cases to decide whether to add a dedicated point solution alongside your CRM suite

    Know your end state and what kind of tool will get you there. Refer to your strategic requirements to evaluate CRM and point solution feature sets.

    Standalone CRM Suite

    Sales Conditions: Need selling and lead management capabilities for agents to perform the sales process, along with sales dashboards and statistics.

    Marketing or Communication Conditions: Need basic campaign management and ability to refresh contact records with information from social networks.

    Member Service Conditions: Need to keep basic customer records with multiple fields per record and basic channels such as email and telephony.

    Add a Best-of-Breed or Point Solution

    Environmental Conditions: An extensive customer base with many different interactions per customer along with industry specific or “niche” needs. Point solutions will benefit firms with deep needs in specific feature areas (e.g. social media or field service).

    Sales Conditions: Lengthy sales process and account management requirements for assessing and managing opportunities – in a technically complex sales process.

    Marketing Conditions: Need social media functionality for monitoring and social property management.

    Customer Service Conditions: Need complex multi-channel service processes and/or need for best-of-breed knowledgebase and service content management.

    Info-Tech Insight

    The volume and complexity of both customers and interactions have a direct effect on when to employ just a CRM suite and when to supplement with a point solution. Check to see if your CRM suite can perform a specific business requirement before deciding to evaluate potential point solutions.

    Use Info-Tech’s CXM Portfolio Designer to create an inventory of high-value customer interaction applications

    2.3.9 CXM Portfolio Designer

    The CXM Portfolio Designer features a set of questions geared toward understanding your needs for marketing, sales, and customer service enablement.

    These results are scored and used to suggest a comprehensive solution-level set of enterprise applications for CXM that can drive your application portfolio and help you make investment decisions in different areas such as CRM, marketing management, and customer intelligence.

    Sections of the tool:

    1. Introduction
    2. Customer Experience Management Questionnaire
    3. Business Unit Recommendations
    4. Enterprise-Level Recommendations

    INFO-TECH DELIVERABLE

    Understand the art of the possible and how emerging trends will affect your application portfolio (1)

    Cloud

    • The emergence and maturation of cloud technologies has broken down the barriers of software adoption.
    • Cloud has enabled easy-to-implement distributed sales centers for enterprises with global or highly fragmented workforces.
    • Cloud offers the agility, scalability, and flexibility needed to accommodate dynamic, evolving customer requirements while minimizing resourcing strain on IT and sales organizations.
    • It is now easier for small to medium enterprises to acquire and implement advanced sales capabilities to compete against larger competitors in a business environment where the need for business agility is key.
    • Although cost and resource reduction is a prominent view of the impact of cloud computing, it is also seen as an agile way to innovate and deliver a product/service experience that customers are looking for – the key to competitive differentiation.

    Mobile

    • Smartphones and other mobile devices were adopted faster than the worldwide web in the late 1990s, and the business and sales implications of widespread adoption cannot be ignored – mobile is changing how businesses operate.
      • Accenture’s Mobility Research Report states that 87% of companies in the study have been guided by a formal mobility strategy – either one that spans the enterprise or for specific business functions.
    • Mobile is now the first point of interaction with businesses. With this trend, gaining visibility into customer insights with mobile analytics is a top priority for organizations.
    • Enterprises need to develop and optimize mobile experiences for internal salespeople and customers alike as part of their sales strategy – use mobile to enable a competitive, differentiated sales force.
    • The use of mobile platforms by sales managers is becoming a norm. Sales enablement suites should support real-time performance metrics on mobile dashboards.

    Understand the art of the possible and how emerging trends will affect your application portfolio (2)

    Social

    • The rise of social networking brought customers together. Customers are now conversing with each other over a wide range of community channels that businesses neither own nor control.
      • The Power Shift: The use of social channels empowered customers to engage in real-time, unstructured conversations for the purpose of product/service evaluations. Those who are active in social environments come to wield considerable influence over the buying decisions of other prospects and customers.
    • Organizations need to identify the influencers and strategically engage them as well as developing an active presence in social communities that lead to sales.
    • Social media does have an impact on sales, both B2C and B2B. A study conducted in 2012 by Social Centered Selling states that 72.6% of sales people using social media as part of their sales process outperformed their peers and exceeded their quota 23% more often (see charts at right).

    The image shows two bar graphs, the one on top titled Achieving Quota: 2010-2012 and the one below titled Exceeding Quota: 2010-2012.

    (Social Centered Learning, n.d.)

    Understand the art of the possible and how emerging trends will affect your application portfolio (3)

    Internet of Things

    • Definition: The Internet of Things (IoT) is the network of physical objects accessed through the internet. These objects contain embedded technology to interact with internal states or the external environment.
    • Why is this interesting?
      • IoT will make it possible for everybody and everything to be connected at all times, processing information in real time. The result will be new ways of making business and sales decisions supported by the availability of information.
      • With ubiquitous connectivity, the current product design-centric view of consumers is changing to one of experience design that aims to characterize the customer relationship with a series of integrated interaction touchpoints.
      • The above change contributes to the shift in focus from experience and will mean further acceleration of the convergence of customer-centric business functions. IoT will blur the lines between marketing, sales, and customer service.
      • Products or systems linked to products are capable of self-operating, learning, updating, and correcting by analyzing real-time data.
      • Take for example, an inventory scale in a large warehouse connected to the company’s supply chain management (SCM) system. When a certain inventory weight threshold is reached due to outgoing shipments, the scale automatically sends out a purchase requisition to restock inventory levels to meet upcoming demand.
    • The IoT will eventually begin to transform existing business processes and force organizations to fundamentally rethink how they produce, operate, and service their customers.

    The image shows a graphic titled The Connected Life by 2020, and shows a number of statistics on use of connected devices over time.

    For categories covered by existing applications, determine the disposition for each app: grow it or cut it loose

    Use the two-by-two matrix below to structure your optimal CXM application portfolio. For more help, refer to Info-Tech’s blueprint, Use Agile Application Rationalization Instead of Going Big Bang.

    1

    0

    Richness of Functionality

    INTEGRATE RETAIN
    1
    REPLACE REPLACE OR ENHANCE

    0

    Degree of Integration

    Integrate: The application is functionally rich, so spend time and effort integrating it with other modules by building or enhancing interfaces.

    Retain: The application satisfies both functionality and integration requirements, so it should be considered for retention.

    Replace/Enhance: The module offers poor functionality but is well integrated with other modules. If enhancing for functionality is easy (e.g. through configuration or custom development), consider enhancement or replace it.

    Replace: The application neither offers the functionality sought nor is it integrated with other modules, and thus should be considered for replacement.

    Activity: Brainstorm the art of the possible, and build and finalize the CXM application portfolio

    2.3.10 1-2 hours

    Input

    • Process gaps identified (output of Activity 2.3.9)

    Output

    • CXM application portfolio
    • CXM Strategy Stakeholder Presentation

    Materials

    Participants

    • Project Team

    Instructions

    1. Review the complete list of strategic requirements identified in the preceding exercises, as well as business process maps.
    2. Identify which application would link to which process (e.g. customer acquisition, customer service resolution, etc.).
    3. Use Info-Tech’s CXM Portfolio Designer to create an inventory of high-value customer interaction applications.
    4. Define rationalization and investment areas.
    5. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Brainstorming the Art of the Possible

    Application Gap Satisfied Related Process Number of Linked Requirements Do we have the system? Priority
    LMA
    • Lead Generation
    • Social Lead Management
    • CRM Integration
    Sales 8 No Business Critical
    Customer Intelligence
    • Web Analytics
    • Customer Journey Tracking
    Customer Service 6 Yes Business Enabling
    ... ... ... ... ... ...

    Use Info-Tech’s comprehensive reports to make granular vendor selection decisions

    Now that you have developed the CXM application portfolio and identified areas of new investment, you’re well positioned to execute specific vendor selection projects. After you have built out your initiatives roadmap in phase 3, the following reports provide in-depth vendor reviews, feature guides, and tools and templates to assist with selection and implementation.

    Info-Tech Insight

    Not all applications are created equally well for each use case. The vendor reports help you make informed procurement decisions by segmenting vendor capabilities among major use cases. The strategic requirements identified as part of this project should be used to select the use case that best fits your needs.

    If you want additional support, have our analyst guide you through this phase as part of an Info-Tech workshop

    Book a workshop with our Info-Tech analysts:

    2.3.2; 2.3.3 Shortlist and map the key top-level business processes

    Based on experience working with organizations in similar verticals, the facilitator will help your team map out key sample workflows for marketing, sales, and customer service.

    2.3.6 Create your strategic requirements for CXM

    Drawing on the preceding exercises, the facilitator will work with the team to create a comprehensive list of strategic requirements that will be used to drive technology decisions and roadmap initiatives.

    2.3.10 Create and finalize the CXM application portfolio

    Using the strategic requirements gathered through internal, external, and technology analysis up to this point, a facilitator will assist you in assembling a categorical technology application portfolio to support CXM.

    Step 2.4: Develop Deployment Best Practices

    Phase 1

    1.1 Create the Project Vision

    1.2 Structure the Project

    Phase 2

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    Phase 3

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Activities:

    • Develop a CXM integration map
    • Develop a mitigation plan for poor quality customer data
    • Create a framework for end-user adoption of CXM applications

    Outcomes:

    • CXM application portfolio integration map
    • Data quality preservation plan
    • End-user adoption plan

    Develop an integration map to specify which applications will interface with each other

    Integration is paramount: your CXM application portfolio must work as a unified face to the customer. Create an integration map to reflect a system of record and the exchange of data.

    • CRM
      • ERP
      • Telephony Systems (IVR, CTI)
      • Directory Services
      • Email
      • Content Management
      • Point Solutions (SMMP, MMS)

    The points of integration that you’ll need to establish must be based on the objectives and requirements that have informed the creation of the CXM application portfolio. For instance, achieving improved customer insights would necessitate a well-integrated portfolio with customer interaction point solutions, business intelligence tools, and customer data warehouses in order to draw the information necessary to build insight. To increase customer engagement, channel integration is a must (i.e. with robust links to unified communications solutions, email, and VoIP telephony systems).

    Info-Tech Insight

    If the CXM application portfolio is fragmented, it will be nearly impossible to build a cohesive view of the customer and deliver a consistent customer experience. Points of integration (POIs) are the junctions between the applications that make up the CXM portfolio. They are essential to creating value, particularly in customer insight-focused and omnichannel-focused deployments. Be sure to include enterprise applications that are not included in the CXM application portfolio. Popular systems to consider for POIs include billing, directory services, content management, and collaboration tools.

    After identifying points of integration, profile them by business significance, complexity, and investment required

    • After enumerating points of integration between the CRM platform and other CXM applications and data sources, profile them by business significance and complexity required to determine a rank-ordering of priorities.
    • Points of integration that are of high business significance with low complexity are your must do’s – these are your quick wins that deliver maximum value without too much cost. This is typically the case when integrating a vendor-to-vendor solution with available native connectors.
    • On the opposite end of the spectrum are your POIs that will require extensive work to deliver but offer negligible value. These are your should not do’s – typically, these are niche requests for integration that will only benefit the workflows of a small (and low priority) group of end users. Only accommodate them if you have slack time and budget built into your implementation timeline.

    The image shows a square matrix with Point of Integration Value Matrix in the centre. On the X-axis is Business Significance, and on the Y-axis is POI complexity. In the upper left quadrant is Should Not Do, upper right is Should Do, lower left is Could Do, and lower right is Must do.

    "Find the absolute minimum number of ‘quick wins’ – the POIs you need from day one that are necessary to keep end users happy and deliver value." – Maria Cindric, Australian Catholic University Source: Interview

    Activity: Develop a CXM application integration map

    2.4.1 1 hour

    Input

    • CXM application portfolio (output of Activity 2.3.10)

    Output

    • CXM application portfolio integration map
    • CXM Strategy Stakeholder Presentation

    Materials

    • Sticky notes
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. On sticky notes, record the list of applications that comprise the CXM application portfolio (built in Activity 2.3.10) and all other relevant applications. Post the sticky notes on a whiteboard so you can visualize the portfolio.
    2. Discuss the key objectives and requirements that will drive the integration design of the CXM application portfolio.
    3. As deemed necessary by step 2, rearrange the sticky notes and draw connecting arrows between applications to reflect their integration. Allow the point of the arrow to indicate direction of data exchanges.
    4. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Mapping the Integration of CXM Applications

    The image shows several yellow rectangles with text in them, connected by arrows.

    Plug the hole and bail the boat – plan to be preventative and corrective with customer data quality initiatives

    Data quality is king: if your customer data is garbage in, it will be garbage out. Enable strategic CXM decision making with effective planning of data quality initiatives.

    Identify and Eliminate Dead Weight

    Poor data can originate in the firm’s system of record, which is typically the CRM system. Custom queries, stored procedures, or profiling tools can be used to assess the key problem areas.

    Loose rules in the CRM system lead to records of no significant value in the database. Those rules need to be fixed, but if changes are made before the data is fixed, users could encounter database or application errors, which will reduce user confidence in the system.

    • Conduct a data flow analysis: map the path that data takes through the organization.
    • Use a mass cleanup to identify and destroy dead weight data. Merge duplicates either manually or with the aid of software tools. Delete incomplete data, taking care to reassign related data.
    • COTS packages typically allow power users to merge records without creating orphaned records in related tables, but custom-built applications typically require IT expertise.

    Create and Enforce Standards & Policies

    Now that the data has been cleaned, protect the system from relapsing.

    Work with business users to find out what types of data require validation and which fields should have changes audited. Whenever possible, implement drop-down lists to standardize values and make programming changes to ensure that truncation ceases.

    • Truncated data is usually caused by mismatches in data structures during either one-time data loads or ongoing data integrations.
    • Don’t go overboard on assigning required fields – users will just put key data in note fields.
    • Discourage the use of unstructured note fields: the data is effectively lost unless it gets subpoenaed.
    • To specify policies, use Info-Tech’s Master Data Record Tool.

    Profile your customer and sales-related data

    Applications are a critical component of how IT supports Sales, but IT also needs to help Sales keep its data current and accurate. Conducting a sales data audit is critical to ensure Sales has the right information at the right time.

    Info-Tech Insight

    Data is king. More than ever, having accurate data is essential for your organization to win in hyper-competitive marketplaces. Prudent current state analysis looks at both the overall data model and data architecture, as well as assessing data quality within critical sales-related repositories. As the amount of customer data grows exponentially due to the rise of mobility and the Internet of Things, you must have a forward-looking data model and data marts/customer data warehouse to support sales-relevant decisions.

    • A current state analysis for sales data follows a multi-step process:
      • Determine the location of all sales-relevant and customer data – the sales data inventory. Data can reside in applications, warehouses, and documents (e.g. Excel and Access files) – be sure to take a holistic approach.
    • For each data source, assess data quality across the following categories:
      • Completeness
      • Currency (Relevancy)
      • Correctness
      • Duplication
    • After assessing data quality, determine which repositories need the most attention by IT and Sales. We will look at opportunities for data consolidation later in the blueprint.

    INFO-TECH OPPORTUNITY

    Refer to Info-Tech’s Develop a Master Data Management Strategy and Roadmap blueprint for further reference and assistance in data management for your sales-IT alignment.

    Activity: Develop a mitigation plan for poor quality customer data

    2.4.2 30 minutes

    Input

    • List of departments involved in maintenance of CXM data

    Output

    • Data quality preservation plan
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Inventory a list of departments that will be interacting directly with CXM data.
    2. Identify data quality cleansing and preservation initiatives, such as those in previous examples.
    3. Assign accountability to an individual in the department as a data steward. When deciding on a data steward, consider the following:
    • Data stewards are designated full-time employees who serve as the go-to resource for all issues pertaining to data quality, including keeping a particular data silo clean and free of errors.
    • Data stewards are typically mid-level managers in the business (not IT), preferably with an interest in improving data quality and a relatively high degree of tech-savviness.
    • Data stewards can sometimes be created as a new role with a dedicated FTE, but this is not usually cost effective for small and mid-sized firms.
    • Instead, diffuse the steward role across several existing positions, including one for CRM and other marketing, sales, and service applications.
  • Document your outputs in the CXM Strategy Stakeholder Presentation Template.
  • Example: Data Steward Structure

    Department A

    • Data Steward (CRM)
    • Data Steward (ERP)

    Department B

    • Data Steward (All)

    Department C

    • Data Steward (All)

    Determine if a customer data warehouse will add value to your CXM technology-enablement strategy

    A customer data warehouse (CDW) “is a subject-oriented, integrated, time-variant, non-volatile collection of data used to support the strategic decision-making process across marketing, sales, and service. It is the central point of data integration for customer intelligence and is the source of data for the data marts, delivering a common view of customer data” (Corporate Information Factory, n.d.).

    Analogy

    CDWs are like a buffet. All the food items are in the buffet. Likewise, your corporate data sources are centralized into one repository. There are so many food items in a buffet that you may need to organize them into separate food stations (data marts) for easier access.

    Examples/Use Cases

    • Time series analyses with historical data
    • Enterprise level, common view analyses
    • Integrated, comprehensive customer profiles
    • One-stop repository of all corporate information

    Pros

    • Top-down architectural planning
    • Subject areas are integrated
    • Time-variant, changes to the data are tracked
    • Non-volatile, data is never over-written or deleted

    Cons

    • A massive amount of corporate information
    • Slower delivery
    • Changes are harder to make
    • Data format is not very business friendly

    Activity: Assess the need for a customer data warehouse

    2.4.3. 30 minutes

    Input

    • List of data sources
    • Data inflows and outflows

    Output

    • Data quality preservation plan
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Create a shortlist of customer data sources.
    2. Profile the integration points that are necessary to support inflows and outflows of customer data.
    3. Ask the following questions around the need for a CDW based on these data sources and points of integration:
    • What is the volume of customer information that needs to be stored? The greater the capacity, the more likely that you should build a dedicated CDW.
    • How complex is the data? The more complex the data, the greater the need for a CDW.
    • How often will data interchange happen between various applications and data sources? The greater and more frequent the interchange, the greater the need for a CDW.
    • What are your organizational capabilities for building a CDW? Do you have the resources in-house to create a CDW at this time?
  • Document your outputs in the CXM Strategy Stakeholder Presentation Template.
  • INFO-TECH OPPORTUNITY

    Refer to Info-Tech’s Build an Agile Data Warehouse blueprint for more information on building a centralized and integrated data warehouse.

    Create a plan for end-user training on new (or refocused) CXM applications and data quality processes

    All training modules will be different, but some will have overlapping areas of interest.

    – Assign Project Evangelists – Analytics Training – Mobile Training

    Application Training

    • Customer Service - Assign Project Evangelists – Analytics Training – Mobile Training
      • Focus training on:
        • What to do with inbound tickets.
        • Routing and escalation features.
        • How to use knowledge management features effectively.
        • Call center capabilities.
    • Sales – Assign Project Evangelists – Analytics Training – Mobile Training
      • Focus training on:
        • Recording of opportunities, leads, and deals.
        • How to maximize sales with sales support decision tree.
    • Marketing - Assign Project Evangelists – Analytics Training
      • Focus training on:
        • Campaign management features.
        • Social media monitoring and engagement capabilities.
    • IT
      • Focus training on:
        • Familiarization with the software.
        • Software integration with other enterprise applications.
        • The technical support needed to maintain the system in the future.

    Info-Tech Insight

    Train customers too. Keep the customer-facing sales portals simple and intuitive, have clear explanations/instructions under important functions (e.g. brief directions on how to initiate service inquiries), and provide examples of proper uses (e.g. effective searches). Make sure customers are aware of escalation options available to them if self-service falls short.

    Ensure adoption with a formal communication process to keep departments apprised of new application rollouts

    The team leading the rollout of new initiatives (be they applications, new governance structures, or data quality procedures) should establish a communication process to ensure management and users are well informed.

    CXM-related department groups or designated trainers should take the lead and implement a process for:

    • Scheduling application platform/process rollout/kick-off meetings.
    • Soliciting preliminary input from the attending groups to develop further training plans.
    • Establishing communication paths and the key communication agents from each department who are responsible for keeping lines open moving forward.

    The overall objective for inter-departmental kick-off meetings is to confirm that all parties agree on certain key points and understand alignment rationale and new sales app or process functionality.

    The kick-off process will significantly improve internal communications by inviting all affected internal IT groups, including business units, to work together to address significant issues before the application process is formally activated.

    The kick-off meeting(s) should encompass:

    • Target business-user requirements
    • The high-level application overview
    • Tangible business benefits of alignment
    • Special consideration needs
    • Other IT department needs
    • Target quality of service (QoS) metrics

    Info-Tech Insight

    Determine who in each department will send out a message about initiative implementation, the tone of the message, the medium, and the delivery date.

    Construct a formal communication plan to engage stakeholders through structured channels

    Tangible Elements of a Communications Plan

    • Stakeholder Group Name
    • Stakeholder Description
    • Message
    • Concerns Relative to Application Maintenance
    • Communication Medium
    • Role Responsible for Communication
    • Frequency
    • Start and End Date

    Intangible Elements of a Communications Plan

    • Establish biweekly meetings with representatives from sales functional groups, who are tasked with reporting on:
      • Benefits of revised processes
      • Metrics of success
      • Resource restructuring
    • Establish a monthly interdepartmental meeting, where all representatives from sales and IT leadership discuss pressing bug fixes and minor process improvements.
    • Create a webinar series, complete with Q&A, so that stakeholders can reference these changes at their leisure.

    Info-Tech Insight

    Every piece of information that you give to a stakeholder that is not directly relevant to their interests is a distraction from your core message. Always remember to tailor the message, medium, and timing accordingly.

    Carry the CXM value forward with linkage and relationships between sales, marketing, service, and IT

    Once the sales-IT alignment committees have been formed, create organizational cadence through a variety of formal and informal gatherings between the two business functions.

    • Organizations typically fall in one of three maturity stages: isolation, collaboration, or synergy. Strive to achieve business-technology synergy at the operational level.
    • Although collaboration cannot be mandated, it can be facilitated. Start with a simple gauge of the two functions’ satisfaction with each other, and determine where and how inter-functional communication and synergy can be constructed.

    Isolation

    The image shows four shapes, with the words IT, Sales, Customer Service, and Marketing in them.

    • Point solutions are implemented on an ad-hoc basis by individual departments for specific projects.
    • Internal IT is rarely involved in these projects from beginning to end.

    Collaboration

    The image features that same four shapes and text from the previous image, but this time they are connected by dotted lines.

    • There is a formal cross-departmental effort to integrate some point solutions.
    • Internal IT gets involved to integrate systems and then support system interactions.

    Synergy

    The image features the same shapes and text from previous instances, except the shapes are now connect by solid lines and the entire image is surrounded by dotted lines.

    • Cross-functional, business technology teams are established to work on IT-enabled revenue generation initiatives.
    • Team members are collocated if possible.

    If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

    Book a workshop with our Info-Tech analysts:

    2.4.1 Develop a CXM application integration map

    Using the inventory of existing CXM-supporting applications and the newly formed CXM application portfolio as inputs, your facilitator will assist you in creating an integration map of applications to establish a system of record and flow of data.

    2.4.2 Develop a mitigation plan for poor quality customer data

    Our facilitator will educate your stakeholders on the importance of quality data and guide you through the creation of a mitigation plan for data preservation.

    2.4.3 Assess the need for a customer data warehouse

    Addressing important factors such as data volume, complexity, and flow, a facilitator will help you assess whether or not a customer data warehouse for CXM is the right fit for your organization.

    Phase 3

    Finalize the CXM Framework

    Build a Strong Technology Foundation for Customer Experience Management

    Phase 3 outline

    Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

    Complete these steps on your own, or call us to complete a guided implementation. A guided implementation is a series of 2-3 advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

    Guided Implementation 3: Finalize the CXM Framework

    Proposed Time to Completion: 1 week

    Step 3.1: Create an Initiative Rollout Plan

    Start with an analyst kick-off call:

    • Discuss strategic requirements and the associated application portfolio that has been proposed.

    Then complete these activities…

    • Initiatives prioritization

    With these tools & templates:

    • CXM Strategy Stakeholder Presentation Template

    Step 3.2: Confirm and Finalize the CXM Blueprint

    Review findings with analyst:

    • Discuss roadmap and next steps in terms of rationalizing and implementing specific technology-centric initiatives or rollouts.

    Then complete these activities…

    • Confirm stakeholder strategy presentation

    With these tools & templates:

    • CXM Strategy Stakeholder Presentation Template

    Phase 3 Results & Insights:

    • Initiatives roadmap

    Step 3.1: Create an Initiative Rollout Plan

    Phase 1

    1.1 Create the Project Vision

    1.2 Structure the Project

    Phase 2

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    Phase 3

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Activities:

    • Create a risk management plan
    • Brainstorm initiatives for CXM roadmap
    • Identify dependencies and enabling projects for your CXM roadmap
    • Complete the CXM roadmap

    Outcomes:

    • Risk management plan
    • CXM roadmap
      • Quick-win initiatives

    A CXM technology-enablement roadmap will provide smooth and timely implementation of your apps/initiatives

    Creating a comprehensive CXM strategy roadmap reduces the risk of rework, misallocation of resources, and project delays or abandonment.

    • People
    • Processes
    • Technology
    • Timeline
    • Tasks
    • Budget

    Benefits of a Roadmap

    1. Prioritize execution of initiatives in alignment with business, IT, and needs.
    2. Create clearly defined roles and responsibilities for IT and business stakeholders.
    3. Establish clear timelines for rollout of initiatives.
    4. Identify key functional areas and processes.
    5. Highlight dependencies and prerequisites for successful deployment.
    6. Reduce the risk of rework due to poor execution.

    Implement planning and controls for project execution

    Risk Management

    • Track risks associated with your CXM project.
    • Assign owners and create plans for resolving open risks.
    • Identify risks associated with related projects.
    • Create a plan for effectively communicating project risks.

    Change Management

    • Brainstorm a high-level training plan for various users of the CXM.
    • Create a communication plan to notify stakeholders and impacted users about the tool and how it will alter their workday and performance of role activities.
    • Establish a formal change management process that is flexible enough to meet the demands for change.

    Project Management

    • Conduct a post-mortem to evaluate the completion of the CXM strategy.
    • Design the project management process to be adaptive in nature.
    • Communication is key to project success, whether it is to external stakeholders or internal project team members..
    • Review the project’s performance against metrics and expectations.

    INFO-TECH OPPORTUNITIES

    Optimize the Change Management Process

    You need to design a process that is flexible enough to meet demand for change and strict enough to protect the live environment from change-related incidents.

    Create Project Management Success

    Investing time up front to plan the project and implementing best practices during project execution to ensure the project is delivered with the planned outcome and quality is critical to project success.

    Activity: Create a risk management plan

    3.1.1 45 minutes

    Input

    • Inventory of risks

    Output

    • Risk management plan
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Create a list of possible risks that may hamper the progress of your CXM project.
    2. Classify risks as strategy-based, related to planning, or systems-based, related to technology.
    3. Brainstorm mitigation strategies to overcome each listed risk.
    4. On a score of 1 to 3, determine the impact of each risk on the success of the project.
    5. On a score of 1 to 3, determine the likelihood of the occurrence for each risk.
    6. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Constructing a Risk Management Plan

    Risk Impact Likelihood Mitigation Effort
    Strategy Risks Project over budget
    • Detailed project plan
    • Pricing guarantees
    Inadequate content governance
    System Risks Integration with additional systems
    • Develop integration plan and begin testing integration methods early in the project
    .... ... ... ...

    Likelihood

    1 – High/ Needs Focus

    2 – Can Be Mitigated

    3 - Unlikely

    Impact

    1 - High Risk

    2 - Moderate Risk

    3 - Minimal Risk

    Prepare contingency plans to minimize time spent handling unexpected risks

    Understanding technical and strategic risks can help you establish contingency measures to reduce the likelihood that risks will occur. Devise mitigation strategies to help offset the impact of risks if contingency measures are not enough.

    Remember

    The biggest sources of risk in a CXM strategy are lack of planning, poorly defined requirements, and lack of governance.

    Apply the following mitigation tips to avoid pitfalls and delays.

    Risk Mitigation Tips

    • Upfront planning
    • Realistic timelines
    • Resource support
    • Change management
    • Executive sponsorship
    • Sufficient funding
    • Expectation setting
    1. Project Starts
    • Expectations are high
  • Project Workload Increases
    • Expectations are high
  • Pit of Despair
    • Why are we doing this?
  • Project Nears Close
    • Benefits are being realized
  • Implementation is Completed
    • Learning curve dip
  • Standardization & Optimization
    • Benefits are high
  • Identify factors to complete your CXM initiatives roadmap

    Completion of initiatives for your CXM project will be contingent upon multiple variables.

    Defining Dependencies

    Initiative complexity will define the need for enabling projects. Create a process to define dependencies:

    1. Enabling projects: complex prerequisites.
    2. Preceding tasks: direct and simplified assignments.

    Establishing a Timeline

    • Assign realistic timelines for each initiative to ensure smooth progress.
    • Use milestones and stage gates to track the progress of your initiatives and tasks.

    Defining Importance

    • Based on requirements gathering, identify the importance of each initiative to your marketing department.
    • Each initiative can be ranked high, medium, or low.

    Assigning Ownership

    • Owners are responsible for on-time completion of their assigned initiatives.
    • Populate a RACI chart to ensure coverage of all initiatives.

    Complex....Initiative

    • Enabling Project
      • Preceding Task
      • Preceding Task
    • Enabling Project
      • Preceding Task
      • Preceding Task

    Simple....Initiative

    • Preceding Task
    • Preceding Task
    • Preceding Task

    Activity: Brainstorm CXM application initiatives for implementation in alignment with business needs

    3.1.2 45 minutes

    Input

    • Inventory of CXM initiatives

    Output

    • Prioritized and quick-win initiatives
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. As a team, identify and list CXM initiatives that need to be addressed.
    2. Plot the initiatives on the complexity-value matrix to determine priority.
    3. Identify quick wins: initiatives that can realize quick benefits with little effort.
    4. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Importance-Capability Matrix

    The image shows a matrix, with Initiative Complexity on the X-axis, and Business Value on the Y-axis. There are circle of different sizes in the matrix.

    Pinpoint quick wins: high importance, low effort initiatives.

    The size of each plotted initiative must indicate the effort or the complexity and time required to complete.
    Top Right Quadrant Strategic Projects
    Top Left Quadrant Quick Wins
    Bottom Right Quadrant Risky Bets
    Bottom Left Quadrant Discretionary Projects

    Activity: Identify any dependencies or enabling projects for your CXM roadmap

    3.1.3 1 hour

    Input

    • Implementation initiatives
    • Dependencies

    Output

    • CXM project dependencies

    Materials

    • Sticky notes
    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Using sticky notes and a whiteboard, have each team member rank the compiled initiatives in terms of priority.
    2. Determine preceding tasks or enabling projects that each initiative is dependent upon.
    3. Determine realistic timelines to complete each quick win, enabling project, and long-term initiative.
    4. Assign an owner for each initiative.

    Example: Project Dependencies

    Initiative: Omnichannel E-Commerce

    Dependency: WEM Suite Deployment; CRM Suite Deployment; Order Fulfillment Capabilities

    Activity: Complete the implementation roadmap

    3.1.4 30 minutes

    Input

    • Implementation initiatives
    • Dependencies

    Output

    • CXM Roadmap
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Establish time frames to highlight enabling projects, quick wins, and long-term initiatives.
    2. Indicate the importance of each initiative as high, medium, or low based on the output in Activity 3.1.2.
    3. Assign each initiative to a member of the project team. Each owner will be responsible for the execution of a given initiative as planned.
    4. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Example: Importance-Capability Matrix

    Importance Initiative Owner Completion Date
    Example Projects High Gather business requirements. Project Manager MM/DD/YYYY
    Quick Wins
    Long Term Medium Implement e-commerce across all sites. CFO & Web Manager MM/DD/YYYY

    Importance

    • High
    • Medium
    • Low

    If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

    Book a workshop with our Info-Tech analysts:

    • To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.
    • Info-Tech analysts will join you and your team onsite at your location or welcome you to Info-Tech’s historic Toronto office to participate in an innovative onsite workshop.
    • Contact your account manager (www.infotech.com/account), or email Workshops@InfoTech.com for more information.

    The following are sample activities that will be conducted by Info-Tech analysts with your team:

    3.1.1 Create a risk management plan

    Based on the workshop exercises, the facilitator will work with the core team to design a priority-based risk mitigation plan that enumerates the most salient risks to the CXM project and addresses them.

    3.1.2; 3.1.3; 3.1.4 Identify initiative dependencies and create the CXM roadmap

    After identifying dependencies, our facilitators will work with your IT SMEs and business stakeholders to create a comprehensive roadmap, outlining the initiatives needed to carry out your CXM strategy roadmap.

    Step 3.2: Confirm and Finalize the CXM Blueprint

    Phase 1

    1.1 Create the Project Vision

    1.2 Structure the Project

    Phase 2

    2.1 Scan the External Environment

    2.2 Assess the Current State of CXM

    2.3 Create an Application Portfolio

    2.4 Develop Deployment Best Practices

    Phase 3

    3.1 Create an Initiative Rollout Plan

    3.2 Confirm and Finalize the CXM Blueprint

    Activities:

    • Identify success metrics
    • Create a stakeholder power map
    • Create a stakeholder communication plan
    • Complete and present CXM strategy stakeholder presentation

    Outcomes:

    • Stakeholder communication plan
    • CXM strategy stakeholder presentation

    Ensure that your CXM applications are improving the performance of targeted processes by establishing metrics

    Key Performance Indicators (KPIs)

    Key performance indicators (KPIs) are quantifiable measures that demonstrate the effectiveness of a process and its ability to meet business objectives.

    Questions to Ask

    1. What outputs of the process can be used to measure success?
    2. How do you measure process efficiency and effectiveness?

    Creating KPIs

    Specific

    Measurable

    Achievable

    Realistic

    Time-bound

    Follow the SMART methodology when developing KPIs for each process.

    Adhering to this methodology is a key component of the Lean management methodology. This framework will help you avoid establishing general metrics that aren’t relevant.

    Info-Tech Insight

    Metrics are essential to your ability to measure and communicate the success of the CXM strategy to the business. Speak the same language as the business and choose metrics that relate to marketing, sales, and customer service objectives.

    Activity: Identify metrics to communicate process success

    3.2.1 1 hour

    Input

    • Key organizational objectives

    Output

    • Strategic business metrics
    • CXM Strategy Stakeholder Presentation

    Materials

    • Whiteboard
    • Markers

    Participants

    • Project Team

    Instructions

    1. Recap the major functions that CXM will focus on (e.g. marketing, sales, customer service, web experience management, social media management, etc.)
    2. Identify business metrics that reflect organizational objectives for each function.
    3. Establish goals for each metric (as exemplified below).
    4. Document your outputs in the CXM Strategy Stakeholder Presentation Template.
    5. Communicate the chosen metrics and the respective goals to stakeholders.

    Example: Metrics for Marketing, Sales, and Customer Service Functions

    Metric Example
    Marketing Customer acquisition cost X% decrease in costs relating to advertising spend
    Ratio of lifetime customer value X% decrease in customer churn
    Marketing originated customer % X% increase in % of customer acquisition driven by marketing
    Sales Conversion rate X% increase conversion of lead to sale
    Lead response time X% decrease in response time per lead
    Opportunity-to-win ratio X% increase in monthly/annual opportunity-to-win ratio
    Customer Service First response time X% decreased time it takes for customer to receive first response
    Time-to-resolution X% decrease of average time-to-resolution
    Customer satisfaction X% improvement of customer satisfaction ratings on immediate feedback survey

    Use Info-Tech’s Stakeholder Power Map Template to identify stakeholders crucial to CXM application rollouts

    3.2.2 Stakeholder Power Map Template

    Use this template and its power map to help visualize the importance of various stakeholders and their concerns. Prioritize your time according to the most powerful and most impacted stakeholders.

    Answer questions about each stakeholder:

    • Power: How much influence does the stakeholder have? Enough to drive the project forward or into the ground?
    • Involvement: How interested is the stakeholder? How involved is the stakeholder in the project already?
    • Impact: To what degree will the stakeholder be impacted? Will this significantly change how they do their job?
    • Support: Is the stakeholder a supporter of the project? Neutral? A resistor?

    Focus on key players: relevant stakeholders who have high power, should have high involvement, and are highly impacted.

    INFO-TECH DELIVERABLE

    Stakeholder Power Map Template

    Use Info-Tech’s Stakeholder Communication Planning Template to document initiatives and track communication

    3.2.3 Stakeholder Communication Planning Template

    Use the Stakeholder Communication Planning Template to document your list of initiative stakeholders so you can track them and plan communication throughout the initiative.

    Track the communication methods needed to convey information regarding CXM initiatives. Communicate how a specific initiative will impact the way employees work and the work they do.

    Sections of the document:

    1. Document the Stakeholder Power Map (output of Tool 3.2.2).
    2. Complete the Communicate Management Plan to aid in the planning and tracking of communication and training.

    INFO-TECH DELIVERABLE

    Activity: Create a stakeholder power map and communication plan

    3.2.4 1 hour

    Input

    • Stakeholder power map

    Output

    • Stakeholder communication plan
    • CXM Strategy Stakeholder Presentation

    Materials

    • Info-Tech’s Stakeholder Communication Planning Template
    • Info-Tech’s Stakeholder Power Map Template

    Participants

    • Project Team

    Instructions

    1. Using Info-Tech’s Stakeholder Power Map Template, identify key stakeholders for ensuring the success of the CXM strategy (Tool 3.2.2).
    2. Using Info-Tech’s Stakeholder Communication Plan Template, construct a communication plan to communicate and track CXM initiatives with all CXM stakeholders (Tool 3.2.3).
    3. Document your outputs in the CXM Strategy Stakeholder Presentation Template.

    Use Info-Tech’s CXM Strategy Stakeholder Presentation Template to sell your CXM strategy to the business

    3.2.5 CXM Strategy Stakeholder Presentation Template

    Complete the presentation template as indicated when you see the green icon throughout this deck. Include the outputs of all activities that are marked with this icon.

    Info-Tech has designed the CXM Strategy Stakeholder Presentation Template to capture the most critical aspects of the CXM strategy. Customize it to best convey your message to project stakeholders and to suit your organization.

    The presentation should be no longer than one hour. However, additional slides can be added at the discretion of the presenter. Make sure there is adequate time for a question and answer period.

    INFO-TECH DELIVERABLE

    After the presentation, email the deck to stakeholders to ensure they have it available for their own reference.

    Activity: Determine the measured value received from the project

    3.2.6 30 minutes

    Input

    • Project Metrics

    Output

    • Measured Value Calculation

    Materials

    • Workbook

    Participants

    • Project Team

    Instructions

    1. Review project metrics identified in phase 1 and associated benchmarks.
    2. After executing the CXM project, compare metrics that were identified in the benchmarks with the revised and assess the delta.
    3. Calculate the percentage change and quantify dollar impact (i.e. as a result of increased customer acquisition or retention).

    If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

    Book a workshop with our Info-Tech analysts:

    • To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.
    • Info-Tech analysts will join you and your team onsite at your location or welcome you to Info-Tech’s historic Toronto office to participate in an innovative onsite workshop.
    • Contact your account manager (www.infotech.com/account), or email Workshops@InfoTech.com for more information.

    The following are sample activities that will be conducted by Info-Tech analysts with your team:

    3.2.4 Create a stakeholder power map and communication plan

    An analyst will walk the project team through the creation of a communication plan, inclusive of project metrics and their respective goals. If you are planning a variety of CXM initiatives, track how the change will be communicated and to whom. Determine the employees who will be impacted by the change.

    Insight breakdown

    Insight 1

    • IT must work in lockstep with Marketing, Sales, and Customer Service to develop a comprehensive technology-enablement strategy for CXM.
    • As IT works with its stakeholders in the business, it must endeavor to capture and use the voice of the customer in driving strategic requirements for CXM portfolio design.
    • IT must consider the external environment, customer personas, and internal processes as it designs strategic requirements to build the CXM application portfolio.

    Insight 2

    • The cloud is bringing significant disruption to the CXM space: to maintain relevancy, IT must become deeply involved in ensuring alignment between vendor capabilities and strategic requirements.
    • IT must serve as a trusted advisor on technical implementation challenges related to CXM, such as data quality, integration, and end-user training and adoption.
    • IT is responsible for technology enablement and is an indispensable partner in this regard; however, the business must ultimately own the objectives and communication strategy for customer engagement.

    Insight 3

    • When crafting a portfolio for CXM, be aware of the art of the possible: capabilities are rapidly merging and evolving to support new interaction channels. Social, mobile, and IoT are disrupting the customer experience landscape.
    • Big data and analytics-driven decision making is another significant area of value. IT must allow for true customer intelligence by providing an integration framework across customer-facing applications.

    Summary of accomplishment

    Knowledge Gained

    • Voice of the Customer for CXM Portfolio Design
    • Understanding of Strategic Requirements for CXM
    • Customer Personas and Scenarios
    • Environmental Scan
    • Deployment Considerations
    • Initiatives Roadmap Considerations

    Processes Optimized

    • CXM Technology Portfolio Design
    • Customer Data Quality Processes
    • CXM Integrations

    Deliverables Completed

    • Strategic Summary for CXM
    • CXM Project Charter
    • Customer Personas
    • External and Competitive Analysis
    • CXM Application Portfolio

    Bibliography

    Accenture Digital. “Growing the Digital Business: Accenture Mobility Research 2015.” Accenture. 2015. Web.

    Afshar, Vala. “50 Important Customer Experience Stats for Business Leaders.” Huffington Post. 15 Oct. 2015. Web.

    APQC. “Marketing and Sales Definitions and Key Measures.” APQC’s Process Classification Framework, Version 1.0.0. APQC. Mar. 2011. Web.

    CX Network. “The Evolution of Customer Experience in 2015.” Customer Experience Network. 2015. Web.

    Genesys. “State of Customer Experience Research”. Genesys. 2018. Web.

    Harvard Business Review and SAS. “Lessons From the Leading Edge of Customer Experience Management.” Harvard Business School Publishing. 2014. Web.

    Help Scout. “75 Customer Service Facts, Quotes & Statistics.” Help Scout. n.d. Web.

    Inmon Consulting Services. “Corporate Information Factory (CIF) Overview.” Corporate Information Factory. n.d. Web

    Jurevicius, Ovidijus. “VRIO Framework.” Strategic Management Insight. 21 Oct. 2013. Web.

    Keenan, Jim, and Barbara Giamanco. “Social Media and Sales Quota.” A Sales Guy Consulting and Social Centered Selling. n.d. Web.

    Malik, Om. “Internet of Things Will Have 24 Billion Devices by 2020.” Gigaom. 13 Oct. 2011. Web.

    McGovern, Michele. “Customers Want More: 5 New Expectations You Must Meet Now.” Customer Experience Insight. 30 July 2015. Web.

    McGinnis, Devon. “40 Customer Service Statistics to Move Your Business Forward.” Salesforce Blog. 1 May 2019. Web.

    Bibliography

    Reichheld, Fred. “Prescription for Cutting Costs”. Bain & Company. n.d. Web.

    Retail Congress Asia Pacific. “SAP – Burberry Makes Shopping Personal.” Retail Congress Asia Pacific. 2017. Web.

    Rouse, Margaret. “Omnichannel Definition.” TechTarget. Feb. 2014. Web.

    Salesforce Research. “Customer Expectations Hit All-Time High.” Salesforce Research. 2018. Web.

    Satell, Greg. “A Look Back at Why Blockbuster Really Failed and Why It Didn’t Have To.” Forbes. 5 Sept. 2014. Web.

    Social Centered Learning. “Social Media and Sales Quota: The Impact of Social Media on Sales Quota and Corporate Review.” Social Centered Learning. n.d. Web.

    Varner, Scott. “Economic Impact of Experience Management”. Qualtrics/Forrester. 16 Aug. 2017. Web.

    Wesson, Matt. “How to Use Your Customer Data Like Amazon.” Salesforce Pardot Blog. 27 Aug. 2012. Web.

    Winterberry Group. “Taking Cues From the Customer: ‘Omnichannel’ and the Drive For Audience Engagement.” Winterberry Group LLC. June 2013. Web.

    Wollan, Robert, and Saideep Raj. “How CIOs Can Support a More Agile Sales Organization.” The Wall Street Journal: The CIO Report. 25 July 2013. Web.

    Zendesk. “The Impact of Customer Service on Customer Lifetime Value 2013.” Z Library. n.d. Web.

    Explore the Secrets of SAP Software Contracts to Optimize Spend and Reduce Compliance Risk

    • Buy Link or Shortcode: {j2store}140|cart{/j2store}
    • member rating overall impact: 9.8/10 Overall Impact
    • member rating average dollars saved: $73,994 Average $ Saved
    • member rating average days saved: 9 Average Days Saved
    • Parent Category Name: Licensing
    • Parent Category Link: /licensing
    • SAP has strict audit practices, which, in combination with 50+ types of user classifications and manual accounting for some licenses, make maintaining compliance difficult.
    • Mapping and matching SAP products to the environment can be highly complex, leading to overspending and an inability to reduce spend later.
    • Beware of indirect access to SAP applications from third-party applications (e.g. Salesforce).
    • Products that have been acquired by SAP may have altered licensing terms that are innocuously referred to in support renewal documents.

    Our Advice

    Critical Insight

    • Focus on needs first. Conduct a thorough requirements assessment and document the results. Well-documented license needs will be your core asset in navigating SAP licensing and negotiating your agreement.
    • Examine indirect access possibilities. Understanding how in-house or third-party applications may be accessing the SAP software is critical.
    • Know whats in the contract. Each customer agreement is different and there may be terms that are beneficial. Older agreements may provide both benefits and challenges when evaluating your SAP license position.

    Impact and Result

    • Conduct an analysis to remove inactive and duplicate users as multiple logins may exist and could end up costing the organization license fees when audited.
    • Adopt a cyclical approach to reviewing your SAP licensing and create a reference document to track your software needs, planned licensing, and purchase negotiation points.
    • Learn the “SAP way” of conducting business, which includes a best-in-class sales structure, unique contracts and license use policies, and a hyper-aggressive compliance function. Conducting business with SAP is not typical compared to other vendors, and you will need different tools to emerge successfully from a commercial transaction.
    • Manage SAP support and maintenance spend and policies. Once an agreement has been signed, it can be very difficult to decrease spend, as SAP will reprice products if support is dropped.

    Explore the Secrets of SAP Software Contracts to Optimize Spend and Reduce Compliance Risk Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to find out why you need to understand and document your SAP licensing strategy, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Establish licensing requirements

    Begin your proactive SAP licensing journey by understanding which information to gather and assessing the current state and gaps.

    • Explore the Secrets of SAP Software Contracts to Optimize Spend and Reduce Compliance Risk – Phase 1: Establish Licensing Requirements
    • SAP License Summary and Analysis Tool

    2. Evaluate licensing options

    Review current licensing models and determine which licensing models will most appropriately fit your environment.

    • Explore the Secrets of SAP Software Contracts to Optimize Spend and Reduce Compliance Risk – Phase 2: Evaluate Licensing Options

    3. Evaluate agreement options

    Review SAP’s contract types and assess which best fit the organization’s licensing needs.

    • Explore the Secrets of SAP Software Contracts to Optimize Spend and Reduce Compliance Risk – Phase 3: Evaluate Agreement Options

    4. Purchase and manage licenses

    Conduct negotiations, purchase licensing, and finalize a licensing management strategy.

    • Explore the Secrets of SAP Software Contracts to Optimize Spend and Reduce Compliance Risk – Phase 4: Purchase and Manage Licenses
    [infographic]

    Plan Your Digital Transformation on a Page

    • Buy Link or Shortcode: {j2store}81|cart{/j2store}
    • member rating overall impact: 8.0/10 Overall Impact
    • member rating average dollars saved: $34,649 Average $ Saved
    • member rating average days saved: 20 Average Days Saved
    • Parent Category Name: IT Strategy
    • Parent Category Link: /it-strategy
    • Digital investments often under deliver on expectations of return, and there is no cohesive approach to managing the flow of capital into digital.
    • The focus of the business has historically been to survive technological disruption rather than to thrive in it.
    • Strategy is based mostly on opinion rather than an objective analysis of the outcomes customers want from the organization.
    • Digital is considered a buzzword – nobody has a clear understanding of what it is and what it means in the organization’s context.

    Our Advice

    Critical Insight

    • The purpose of going digital is getting one step closer to the customer. The mark of a digital organization lies in how they answer the question, “How does what we’re doing contribute to what the customer wants from us?”
    • The goal of digital strategy is digital enablement. An organization that is digitally enabled no longer needs a digital strategy, it’s just “the strategy.”

    Impact and Result

    • Focus strategy making on delivering the digital outcomes that customers want.
      • Leverage the talent, expertise, and perspectives within the organization to build a customer-centric digital strategy.
    • Design a balanced digital strategy that creates value across the five digital value pools:
      • Digital marketing, digital channels, digital products, digital supporting capabilities, and business model innovation.
    • Ask how disruption can be leveraged, or even become the disruptor.
      • Manage disruption through quick-win approaches and empowering staff to innovate.
    • Use a Digital Strategy-on-a-Page to spark the digital transformation.
      • Drive awareness and alignment on the digital vision and spark your organization’s imagination around digital.

    Plan Your Digital Transformation on a Page Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to understand how digital disruption is driving the need for transformation, and how Info-Tech’s methodology can help.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Scope the digital transformation

    Learn how to apply the Digital Value Pools thought model and scope strategy around them.

    • Plan Your Digital Transformation on a Page – Phase 1: Scope the Digital Transformation

    2. Design the digital future state vision

    Identify business imperatives, define digital outcomes, and define the strategy’s guiding principles.

    • Plan Your Digital Transformation on a Page – Phase 2: Design the Digital Future State Vision
    • Digital Strategy on a Page

    3. Define the digital roadmap

    Define, prioritize, and roadmap digital initiatives and plan contingencies.

    • Plan Your Digital Transformation on a Page – Phase 3: Define the Digital Roadmap

    4. Sustain digital transformation

    Create, polish, and socialize the Digital Strategy-on-a-Page.

    • Plan Your Digital Transformation on a Page – Phase 4: Sustain Digital Transformation
    [infographic]

    Workshop: Plan Your Digital Transformation on a Page

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Scope the Digital Transformation

    The Purpose

    Identify the need for and use of digital strategy and determine a realistic scope for the digital strategy.

    Key Benefits Achieved

    The digital strategy project is planned and scoped around a subset of the five digital value pools.

    Activities

    1.1 Introduction to digital strategy.

    1.2 Establish motivation for digital.

    1.3 Discuss in-flight digital investments.

    1.4 Define the scope of digital.

    1.5 Identify stakeholders.

    1.6 Perform discovery interviews.

    1.7 Select two value pools to focus day 2, 3, and 4 activities.

    Outputs

    Business model canvas

    Stakeholder power map

    Discovery interview results

    Two value pools for focus throughout the workshop

    2 Design the Digital Future State Vision

    The Purpose

    Create guiding principles to help define future digital initiatives. Generate the target state with the help of strategic goals.

    Key Benefits Achieved

    Establish the basis for planning out the initiatives needed to achieve the target state from the current state.

    Activities

    2.1 Identify digital imperatives.

    2.2 Define key digital outcomes.

    2.3 Create a digital investment thesis.

    2.4 Define digital guiding principles.

    Outputs

    Corporate strategy analysis, PESTLE analysis, documented operational pain points (value streams)

    Customer needs assessment (journey maps)

    Digital investment thesis

    Digital guiding principles

    3 Define the Digital Roadmap

    The Purpose

    Understand the gap between the current and target state. Create transition options and assessment against qualitative and quantitative metrics to generate a list of initiatives the organization will pursue to reach the target state. Build a roadmap to plan out when each transition initiative will be implemented.

    Key Benefits Achieved

    Finalize the initiatives the organization will use to achieve the target digital state. Create a roadmap to plan out the timing of each initiative and generate an easy-to-present document for digital strategy approval.

    Activities

    3.1 Identify initiatives to achieve digital outcomes.

    3.2 Align in-flight initiatives to digital initiatives.

    3.3 Prioritize digital initiatives.

    3.4 Document architecturally significant requirements for high-priority initiatives.

    Outputs

    Digital outcomes and KPIs

    Investment/value pool matrix

    Digital initiative prioritization

    Architecturally significant requirements for high-priority initiatives

    4 Define the Digital Roadmap

    The Purpose

    Plan your approach to socializing the digital strategy to help facilitate the cultural changes necessary for digital transformation.

    Key Benefits Achieved

    Plant the seed of digital and innovation to start making digital a part of the organization’s DNA.

    Activities

    4.1 Review and refine Digital Strategy on a Page.

    4.2 Assess company culture.

    4.3 Define high-level cultural changes needed for successful transformation.

    4.4 Define the role of the digital transformation team.

    4.5 Establish digital transformation team membership and desired outcomes.

    Outputs

    Digital Strategy on a Page

    Strategyzer Culture Map

    Digital transformation team charter

    Leverage Web Analytics to Reinforce Your Web Experience Management Strategy

    • Buy Link or Shortcode: {j2store}563|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Marketing Solutions
    • Parent Category Link: /marketing-solutions
    • Organizations are unaware of the capabilities of web analytics tools and unsure how to leverage these new technologies to enhance their web experience.
    • Traditional solutions offer only information and data about the activity on the website. It is difficult for organizations to understand the customer motivations and behavioral patterns using the data.
    • In addition, there is an overwhelming number of vendors offering various solutions. Understanding which solution best fits your business needs is crucial to avoid overspending.

    Our Advice

    Critical Insight

    • Understanding organizational goals and business objectives is essential in effectively leveraging web analytics.
    • It is easy to get lost in a sea of expensive web analytical tools. Choosing tools that align with the business objectives will keep the costs of customer acquisition and retention to a minimum.
    • Beyond selection and implementation, leveraging web analytic tools requires commitment from the organization to continuously monitor key KPIs to ensure good customer web experience.

    Impact and Result

    • Understand what web analytic tools are and some key trends in the market space. Learn about top advanced analytic tools that help understand user behavior.
    • Discover top vendors in the market space and some of the top-level features they offer.
    • Understand how to use the metrics to gather critical insights about the website’s use and key initiatives for successful implementation.

    Leverage Web Analytics to Reinforce Your Web Experience Management Strategy Research & Tools

    Leverage Web Analytics to Reinforce Your Web Experience Management Strategy Storyboard – A deck outlining the importance of web analytic tools and how they can be leveraged to meet your business needs.

    This research offers insight into web analytic tools, key trends in the market space, and an introduction to advanced web analytics techniques. Follow our five-step initiative to successfully select and implement web analytics tools and identify which baseline metrics to measure and continuously monitor for best results.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    • Leverage Web Analytics to Reinforce Your Web Experience Management Strategy Storyboard
    [infographic]

    Further reading

    Leverage Web Analytics to Reinforce Your Web Experience Management Strategy

    Web analytics tools are the gateway to understanding customer behavior.

    EXECUTIVE BRIEF

    Analyst Perspective

    In today’s world, users want to consume concise content and information quickly. Websites have a limited time to prove their usefulness to a new user. Content needs to be as few clicks away from the user as possible. Analyzing user behavior using advanced analytics techniques can help website designers better understand their audience.

    Organizations need to implement sophisticated analytics tools to track user data from their website. However, simply extracting data is not enough to understand the user motivation. A successful implementation of a web analytics tool will comprise both understanding what a customer does on the website and why the customer does what they do.

    This research will introduce some fundamental and advanced analytics tools and provide insight into some of the vendors in the market space.

    Photo of Sai Krishna Rajaramagopalan, Research Specialist, Applications − Enterprise Applications, Info-Tech Research Group. Sai Krishna Rajaramagopalan
    Research Specialist, Applications − Enterprise Applications
    Info-Tech Research Group

    Executive Summary

    Your Challenge
    • Web analytics solutions have emerged as applications that provide extensive information and data about users visiting your webpage. However, many organizations are unaware of the capabilities of these tools and unsure how to leverage these new technologies to enhance user experience.
    Common Obstacles
    • Traditional solutions offer information and data about customers’ activity on the website but no insight into their motivations and behavioral patterns.
    • In addition, an overwhelming number of vendors are offering various solutions. Understanding which solution best fits your business needs is crucial to avoid overspending.
    Info-Tech’s Approach
    • This research is aimed to help you understand what web analytic tools are and some key trends in the market space. Learn about top advanced analytic tools that help you understand user behavior. Discover top vendors in the market space and some of the high-level features offered.
    • This research also explains techniques and metrics to gather critical insights about your website’s use and will aid in understanding users’ motivations and patterns and better predict their behavior on the website.

    Info-Tech Insight

    It is easy to get lost in a sea of expensive web analytics tools. Choose tools that align with your business objectives to keep the costs of customer acquisition and retention to a minimum.

    Ensure the success of your web analytics programs by following five simple steps

    1. ORGANIZATIONAL GOALS

    The first key step in implementing and succeeding with web analytics tools is to set clearly defined organizational goals, e.g. improving product sales.

    3. KPI METRICS

    Define key performance indicators (KPIs) that help track the organization’s performance, e.g. number of page visits, conversion rates, bounce rates.

    5. REVIEW

    Continuous improvement is essential to succeed in understanding customers. The world is a dynamic place, and you must constantly revise your organizational goals, business objectives, and KPIs to remain competitive.

    Centerpiece representing the five surrounding steps.

    2. BUSINESS OBJECTIVES

    The next step is to lay out business objectives that help to achieve the organization’s goals, e.g. to increase customer leads, increase customer transactions, increase web traffic.

    4. APPLICATION SELECTION

    Understand the web analytics tool space and which combination of tools and vendors best fits the organization’s goals.

    Web Analytics Introduction

    Understand traditional and advanced tools and their capabilities.

    Understanding web analytics

    • Web analytics is the branch of analytics that deals with the collection, reporting, and analysis of data generated by users visiting and interacting with a website.
    • The purpose of web analytics is to measure user behavior, optimize the website’s user experience and flow, and gain insights that help meet business objectives like increasing conversions and sales.
    • Web analytics allows you to see how your website is performing and how people are acting while on your website. What’s important is what you can do with this knowledge.
    • Data collected through web analytics may include traffic sources, referring sites, page views, paths taken, and conversion rates. The compiled data often forms a part of customer relationship management analytics to facilitate and streamline better business decisions.
    • Having strong web analytics is important in understanding customer behavior and fine-tuning marketing and product development approaches accordingly.
    Example of a web analytics dashboard.

    Why you should leverage web analytics

    Leveraging web analytics allows organizations to better understand their customers and achieve their business goals.

    The global web analytics market size is projected to reach US$5,156.3 million by 2026, from US$2,564 million in 2019, at a CAGR of 10.4% during 2021-2026. (Source: 360 Research Reports, 2021) Of the top 1 million websites with the highest traffic, there are over 3 million analytics technologies used. Google Analytics has the highest market share, with 50.3%. (Source: “Top 1 Million Sites,” BuiltWith, 2022)
    Of the 200 million active websites, 57.3% employ some form of web analytics tool. This trend is expected to grow as more sophisticated tools are readily available at a cheaper cost. (Source: “On the Entire Internet,” BuiltWith, 2022; Siteefy, 2022) A three-month study by Contentsquare showed a 6.9% increase in traffic, 11.8% increase in page views, 12.4% increase in transactions, and 3.6% increase in conversion rates through leveraging web analytics. (Source: Mordor Intelligence, 2022)

    Case Study

    Logo for Ryanair.
    INDUSTRY
    Aviation
    SOURCE
    AT Internet
    Web analytics

    Ryanair is a low-fare airline in Europe that receives nearly all of its bookings via its website. Unhappy with its current web analytics platform, which was difficult to understand and use, Ryanair was looking for a solution that could adapt to its requirements and provide continuous support and long-term collaboration.

    Ryanair chose AT Internet for its intuitive user interface that could effectively and easily manage all the online activity. AT was the ideal partner to work closely with the airline to strengthen strategic decision making over the long term, increase conversions in an increasingly competitive market, and increase transactions on the website.

    Results

    By using AT Internet Web Analytics to improve email campaigns and understand the behavior of website visitors, Ryanair was able to triple click-through rates, increase visitor traffic by 16%, and decrease bounce rate by 18%.

    Arrows denoting increases or decreases in certain metrics: '3x increase in click-through rates', '16% increase in visitor traffic', '18% decrease in bounce rate'.

    Use traditional web analytics tools to understand your consumer

    What does the customer do?
    • Traditional web analytics allows organizations to understand what is happening on their website and what customers are doing. These tools deliver hard data to measure the performance of a website. Some of the data measured through traditional web analytics are:
    • Visit count: The number of visits received by a webpage.
    • Bounce rate: The percentage of visitors that leave the website after only viewing the first page compared to total visitors.
    • Referrer: The previous website that sent the user traffic to a specific website.
    • CTA clicks: The number of times a user clicks on a call to action (CTA) button.
    • Conversion rate: Proportion of users that reach the final outcome of the website.
    Example of a traditional web analytics dashboard.

    Use advanced web analytics techniques to understand your consumer

    Why does the customer do what they do?
    • Traditional web analytic tools fail to explain the motivation of users. Advanced analytic techniques help organizations understand user behavior and measure user satisfaction. The techniques help answer questions like: Why did a user come to a webpage? Why did they leave? Did they find what they were looking for? Some of the advanced tools include:
    • Heatmapping: A visual representation of where the users click, scroll, and move on a webpage.
    • Recordings: A recording of the mouse movement and clicks for the entire duration of a user’s visit.
    • Feedback forms and surveys: Voice of the customer tools allowing users to give direct feedback about websites.
    • Funnel exploration: The ability to visualize the steps users take to complete tasks on your site or app.
    Example of an advanced web analytics dashboard.

    Apply industry-leading techniques to leverage web analytics

    Heatmapping
    • Heatmaps are used to visualize where users move their mouse, click, and scroll in a webpage.
    • Website heatmaps use a warm-to-cold color scheme to indicate user activity, with the warmest color indicating the highest visitor engagement and the coolest indicating the lowest visitor engagement.
    • Organizations can use this tool to evaluate the elements of the website that attract users and identify which sections require improvement to increase user engagement.
    • Website designers can make changes and compare the difference in user interaction to measure the effectiveness of the changes.
    • Scrollmaps help designers understand what the most popular scroll-depth of your webpage is – and that’s usually a prime spot for an important call to action.
    Example of a website with heatmapping overlaid.
    (Source: An example of a heatmap layered with a scrollmap from Crazy Egg, 2020)

    Apply industry-leading techniques to leverage web analytics

    Funneling

    • Funnels are graphical representations of a customer’s journey while navigating through the website.
    • Funnels help organizations identify which webpage users land on and where users drop off.
    • Organizations can capture every user step to find the unique challenges between entry and completion. Identifying what friction stands between browsing product grids and completing a transaction allows web designers to then eliminate it.
    • Designers can use A/B testing to experiment with different design philosophies to compare conversion statistics.
    • Funneling can be expanded to cross-channel analytics by incorporating referral data, cookies, and social media analytics.
    Example of a bar chart created through funneling.

    Apply industry-leading techniques to leverage web analytics

    Session recordings

    • Session recordings are playbacks of users’ interaction with the website on a single session. User interaction can vary between mouse clicks, keyboard input, and mouse scroll.
    • Recordings help organizations understand user motivation and help identify why users undertake certain tasks or actions on the webpage.
    • Playbacks can also be used to see if users are confused anywhere between the landing page and final transaction phase. This way, playbacks further help ensure visitors complete the funneling seamlessly.
    Example of a session recording featuring a line created by the mouse's journey.

    Apply industry-leading techniques to leverage web analytics

    Feedback and microsurveys

    • Feedback can be received directly from end users to help organizations improve the website.
    • Receiving feedback from users can be difficult, since not every user is willing to spend time to submit constructive and detailed feedback. Microsurveys are an excellent alternative.
    • Users can submit short feedback forms consisting of a single line or emojis or thumbs up or down.
    • Users can directly highlight sections of the page about which to submit feedback. This allows designers to quickly pinpoint areas for improvement. Additionally, web designers can play back recordings when feedback is submitted to get a clear idea about the challenges users face.
    Example of a website with a microsurvey in the corner.

    Market Overview

    Choose vendors and tools that best match your business needs.

    Top-level traditional features

    Feature Name

    Description

    Visitor Count Tracking Counts the number of visits received by a website or webpage.
    Geographic Analytics Uses location information to enable the organization to provide location-based services for various demographics.
    Conversion Tracking Measures the proportion of users that complete a certain task compared to total number of users.
    Device and Browser Analytics Captures and summarizes device and browser information.
    Bounce and Exit Tracking Calculates exit rate and bounce rate on a webpage.
    CTA Tracking Measures the number of times users click on a call to action (CTA) button.
    Audience Demographics Captures, analyzes, and displays customer demographic/firmographic data from different channels.
    Aggregate Traffic Reporting Works backward from a conversion or other key event to analyze the differences, trends, or patterns in the paths users took to get there.
    Social Media Analytics Captures information on social signals from popular services (Twitter, Facebook, LinkedIn, etc.).

    Top-level advanced features

    Feature Name

    Description

    HeatmappingShows where users have clicked on a page and how far they have scrolled down a page or displays the results of eye-tracking tests through the graphical representation of heatmaps.
    Funnel ExplorationVisualizes the steps users take to complete tasks on your site or app.
    A/B TestingEnables you to test the success of various website features.
    Customer Journey ModellingEffectively models and displays customer behaviors or journeys through multiple channels and touchpoints.
    Audience SegmentationCreates and analyzes discrete customer audience segments based on user-defined criteria or variables.
    Feedback and SurveysEnables users to give feedback and share their satisfaction and experience with website designers.
    Paid Search IntegrationIntegrates with popular search advertising services (i.e. AdWords) and can make predictive recommendations around areas like keywords.
    Search Engine OptimizationProvides targeted recommendations for improving and optimizing a page for organic search rankings (i.e. via A/B testing or multivariate testing).
    Session RecordingRecords playbacks of users scrolling, moving, u-turning, and rage clicking on your site.

    Evaluate software category leaders using SoftwareReviews’ vendor rankings and awards

    Logo for SoftwareReviews.
    Sample of SoftwareReviews' The Data Quadrant. The Data Quadrant is a thorough evaluation and ranking of all software in an individual category to compare platforms across multiple dimensions.

    Vendors are ranked by their Composite Score, based on individual feature evaluations, user satisfaction rankings, vendor capability comparisons, and likeliness to recommend the platform.

    Sample of SoftwareReviews' The Emotional Footprint. The Emotional Footprint is a powerful indicator of overall user sentiment toward the relationship with the vendor, capturing data across five dimensions.

    Vendors are ranked by their Customer Experience (CX) Score, which combines the overall Emotional Footprint rating with a measure of the value delivered by the solution.

    Speak with category experts to dive deeper into the vendor landscape

    Logo for SoftwareReviews.
    Fact-based reviews of business software from IT professionals. Top-tier data quality backed by a rigorous quality assurance process. CLICK HERE to ACCESS

    Comprehensive software reviews
    to make better IT decisions

    We collect and analyze the most detailed reviews on enterprise software from real users to give you an unprecedented view into the product and vendor before you buy.

    Product and category reports with state-of-the-art data visualization. User-experience insight that reveals the intangibles of working with a vendor.

    SoftwareReviews is powered by Info-Tech

    Technology coverage is a priority for Info-Tech and SoftwareReviews provides the most comprehensive unbiased data on today’s technology. Combined with the insight of our expert analysts, our members receive unparalleled support in their buying journey.

    Top vendors in the web analytics space

    Logo for Google Analytics. Google Analytics provides comprehensive traditional analytics tools, free of charge, to understand the customer journey and improve marketing ROI. Twenty-four percent of all web analytical tools used on the internet are provided by Google analytics.
    Logo for Hotjar. Hotjar is a behavior analytics and product experience insights service that helps you empathize with and understand your users through their feedback via tools like heatmaps, session recordings, and surveys. Hotjar complements the data and insights you get from traditional web analytics tools like Google Analytics.
    Logo for Crazy Egg. Crazy Egg is a website analytics tool that helps you optimize your site to make it more user-friendly, more engaging, and more conversion-oriented. It does this through heatmaps and A/B testing, which allow you to see how people are interacting with your site.
    Logo for Amplitude Analytics. Amplitude Analytics provides intelligent insight into customer behavior. It offers basic functionalities like measuring conversion rate and engagement metrics and also provides more advanced tools like customer journey maps and predictive analytics capabilities through AI.

    Case Study

    Logo for Miller & Smith.
    INDUSTRY
    Real Estate
    SOURCE
    Crazy Egg

    Heatmaps and playback recordings

    Challenge

    Miller & Smith had just redesigned their website, but the organization wanted to make sure it was user-friendly as well as visually appealing. They needed an analytics platform that could provide information about where visitors were coming from and measure the effectiveness of the marketing campaigns.

    Solution

    Miller & Smith turned to Crazy Egg to obtain visual insights and track user behavior. They used heatmaps and playback recordings to see user activity within webpages and pinpoint any issues with user interface. In just a few weeks, Miller & Smith gained valuable data to work with: the session recordings helped them understand how users were navigating the site, and the heatmaps allowed them to see where users were clicking – and what they were skipping.

    Results

    Detailed reports generated by the solution allowed Miller & Smith team to convince key stakeholders and implement the changes easily. They were able to pinpoint what changes needed to be made and why these changes would improve their experience.

    Within few weeks, the bounce rate improved by 7.5% and goal conversion increased by 8.5% over a similar period the previous year.

    Operationalizing Web Analytics Tools

    Execute initiatives for successful implementation.

    Ensure success of your web analytics programs by following five simple steps

    1. ORGANIZATIONAL GOALS

    The first key step in implementing and succeeding with web analytics tools is to set clearly defined organizational goals, e.g. improving product sales.

    3. KPI METRICS

    Define key performance indicators (KPIs) that help track the organization’s performance, e.g. number of page visits, conversion rates, bounce rates.

    5. REVIEW

    Continuous improvement is essential to succeed in understanding customers. The world is a dynamic place, and you must constantly revise your organizational goals, business objectives, and KPIs to remain competitive.

    Centerpiece representing the five surrounding steps.

    2. BUSINESS OBJECTIVES

    The next step is to lay out business objectives that help to achieve the organization’s goals, e.g. to increase customer leads, increase customer transactions, increase web traffic.

    4. APPLICATION SELECTION

    Understand the web analytics tool space and which combination of tools and vendors best fits the organization’s goals.

    1.1 Understand your organization’s goals

    30 minutes

    Output: Organization’s goal list

    Materials: Whiteboard, Markers

    Participants: Core project team

    1. Identify the key organizational goals for both the short term and the long term.
    2. Arrange the goals in descending order of priority.

    Example table of goals ranked by priority and labeled short or long term.

    1.2 Align business objectives with organizational goals

    30 minutes

    Output: Business objectives

    Materials: Whiteboard, Markers

    Participants: Core project team

    1. Identify the key business objectives that help attain organization goals.
    2. Match each business objective with the corresponding organizational goals it helps achieve.
    3. Arrange the objectives in descending order of priority.

    Example table of business objectives ranked by priority and which organization goal they're linked to.

    Establish baseline metrics

    Baseline metrics will be improved through:

    1. Efficiently using website elements and CTA button placement
    2. Reducing friction between the landing page and end point
    3. Leveraging direct feedback from users to continuously improve customer experience

    1.3 Establish baseline metrics that you intend to improve via your web analytics tools

    30 minutes

    Example table with metrics, each with a current state and goal state.

    Accelerate your software selection project

    Vendor selection projects often demand extensive and unnecessary documentation.

    Software Selection Insight

    Balance the effort-to-information ratio required for a business impact assessment to keep stakeholders engaged. Use documentation that captures the key data points and critical requirements without taking days to complete. Stakeholders are more receptive to formal selection processes that are friction free.

    The Software Selection Workbook

    Work through the straightforward templates that tie to each phase of the Rapid Application Selection Framework, from assessing the business impact to requirements gathering.

    Sample of the Software Selection Workbook deliverable.

    The Vendor Evaluation Workbook

    Consolidate the vendor evaluation process into a single document. Easily compare vendors as you narrow the field to finalists.

    Sample of the Vendor Evaluation Workbook deliverable.

    The Guide to Software Selection: A Business Stakeholder Manual

    Quickly explain the Rapid Application Selection Framework to your team while also highlighting its benefits to stakeholders.

    Sample of the Guide to Software Selection: A Business Stakeholder Manual deliverable.

    Revisit the metrics you identified and revise your goals

    Track the post-deployment results, compare the metrics, and set new targets for the next fiscal year.

    Example table of 'Baseline Website Performance Metrics' with the column 'Revised Target' highlighted.

    Related Info-Tech Research

    Stock image of two people going over a contract. Modernize Your Corporate Website to Drive Business Value

    Drive higher user satisfaction and value through UX-driven websites.

    Stock image of a person using the cloud on their smartphone. Select and Implement a Web Experience Management Solution

    Your website is your company’s face to the world: select a best-of-breed platform to ensure you make a rock-star impression with your prospects and customers!

    Stock image of people studying analytics. Create an Effective Web Redesign Strategy

    Ninety percent of web redesign projects, executed without an effective strategy, fail to accomplish their goals.

    Bibliography

    "11 Essential Website Data Factors and What They Mean." CivicPlus, n.d. Accessed 26 July 2022.

    “Analytics Usage Distribution in the Top 1 Million Sites.” BuiltWith, 1 Nov. 2022. Accessed 26 July 2022.

    "Analytics Usage Distribution on the Entire Internet." BuiltWith, 1 Nov. 2022. Accessed 26 July 2022.

    Bell, Erica. “How Miller and Smith Used Crazy Egg to Create an Actionable Plan to Improve Website Usability.” Crazy Egg, n.d. Accessed 26 July 2022.

    Brannon, Jordan. "User Behavior Analytics | Enhance The Customer Journey." Coalition Technologies, 8 Nov 2021. Accessed 26 July 2022.

    Cardona, Mercedes. "7 Consumer Trends That Will Define The Digital Economy In 2021." Adobe Blog, 7 Dec 2020. Accessed 26 July 2022.

    “The Finer Points.“ Analytics Features. Google Marketing Platform, 2022. Accessed 26 July 2022.

    Fitzgerald, Anna. "A Beginner’s Guide to Web Analytics." HubSpot, 21 Sept 2022. Accessed 26 July 2022.

    "Form Abandonment: How to Avoid It and Increase Your Conversion Rates." Fullstory Blog, 7 April 2022. Accessed 26 July 2022.

    Fries, Dan. "Plug Sales Funnel Gaps by Identifying and Tracking Micro-Conversions." Clicky Blog, 9 Dec 2019. Accessed 7 July 2022.

    "Funnel Metrics in Saas: What to Track and How to Improve Them?" Userpilot Blog, 23 May 2022. Accessed 26 July 2022.

    Garg, Neha. "Digital Experimentation: 3 Key Steps to Building a Culture of Testing." Contentsquare, 21 June 2021. Accessed 26 July 2022.

    “Global Web Analytics Market Size, Status and Forecast 2021-2027.” 360 Research Reports, 25 Jan. 2021. Web.

    Hamilton, Stephanie. "5 Components of Successful Web Analytics." The Daily Egg, 2011. Accessed 26 July 2022.

    "Hammond, Patrick. "Step-by-Step Guide to Cohort Analysis & Reducing Churn Rate." Amplitude, 15 July 2022. Accessed 26 July 2022.

    Hawes, Carry. "What Is Session Replay? Discover User Pain Points With Session Recordings." Dynatrace, 20 Dec 2021. Accessed 26 July 2022.

    Huss, Nick. “How Many Websites Are There in the World?” Siteefy, 8 Oct. 2022. Web.

    Nelson, Hunter. "Establish Web Analytics and Conversion Tracking Foundations Using the Google Marketing Platform.” Tortoise & Hare Software, 29 Oct 2022. Accessed 26 July 2022.

    "Product Analytics Vs Product Experience Insights: What’s the Difference?" Hotjar, 14 Sept 2021. Accessed 26 July 2022.

    “Record and watch everything your visitors do." Inspectlet, n.d. Accessed 26 July 2022.

    “Ryanair: Using Web Analytics to Manage the Site’s Performance More Effectively and Improve Profitability." AT Internet, 1 April 2020. Accessed 26 July 2022.

    Sibor, Vojtech. "Introducing Cross-Platform Analytics.” Smartlook Blog, 5 Nov 2022. Accessed 26 July 2022.

    "Visualize Visitor Journeys Through Funnels.” VWO, n.d. Accessed 26 July 2022.

    "Web Analytics Market Share – Growth, Trends, COVID-19 Impact, and Forecasts (2022-2027)." Mordor Intelligence, 2022. Accessed 26 July 2022.

    “What is the Best Heatmap Tool for Real Results?” Crazy Egg, 27 April 2020. Web.

    "What Is Visitor Behavior Analysis?" VWO, 2022. Accessed 26 July 2022.

    Zheng, Jack G., and Svetlana Peltsverger. “Web Analytics Overview.” IGI Global, 2015. Accessed 26 July 2022.

    Mitigate the Risk of Cloud Downtime and Data Loss

    • Buy Link or Shortcode: {j2store}412|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: DR and Business Continuity
    • Parent Category Link: /business-continuity
    • Senior leadership is asking difficult questions about the organization’s dependency on third-party cloud services and the risk that poses.
    • IT leaders have limited control over third-party incidents and that includes cloud services. Yet they are on the hot seat when cloud services go down.
    • While vendors have swooped in to provide resilience options for the more-common SaaS solutions, it is not the case for all cloud services.

    Our Advice

    Critical Insight

    • No control over the software does not mean no recovery options. Solutions range from designing an IT workaround using alternate technologies to pre-defined third-party service continuity options (e.g. see options for O365) to business workarounds.
    • Even where there is limited control, you can at least define an incident response plan to streamline notification, assessment, and implementation of workarounds. Leadership wants more options than simply waiting for the service to come back online.
    • At a minimum, IT’s responsibility is to identify and communicate risk to senior leadership. That starts with a vendor review to identify SLA issues and overall resilience gaps.

    Impact and Result

    • Follow a structured process to assess cloud resilience risk.
    • Identify opportunities to mitigate risk – at the very least, ensure critical data is protected.
    • Summarize cloud services risk, mitigation options, and incident response for senior leadership.

    Mitigate the Risk of Cloud Downtime and Data Loss Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Mitigate the Risk of Cloud Downtime and Data Loss – Step-by-step guide to assess risk, identify risk mitigation options, and create an incident response plan.

    Even where there is limited control, you can define an incident response plan to streamline notification, assessment, and implementation of workarounds.

    • Mitigate the Risk of Cloud Downtime and Data Loss Storyboard

    2. Cloud Services Incident Risk and Mitigation Review – Review your key cloud vendors’ SLAs, incident preparedness, and data protection strategy.

    At a minimum, IT’s responsibility is to identify and communicate risk to senior leadership. That starts with a vendor review to identify SLA and overall resilience gaps.

    • Cloud Services Incident Risk and Mitigation Review Tool

    3. SaaS Incident Response Workflows – Use these examples to guide your efforts to create cloud incident response workflows.

    The examples illustrate different approaches to incident response depending on the criticality of the service and options available.

    • SaaS Incident Response Workflows (Visio)
    • SaaS Incident Response Workflows (PDF)

    4. Cloud Services Resilience Summary – Use this template to capture your results.

    Summarize cloud services risk, mitigation options, and incident response for senior leadership.

    • Cloud Services Resilience Summary
    [infographic]

    Further reading

    Mitigate the Risk of Cloud Downtime and Data Loss

    Resilience and disaster recovery in an increasingly Cloudy and SaaSy world.

    Analyst Perspective

    If you think cloud means you don’t need a response plan, then get your resume ready.

    Frank Trovato

    Most organizations are now recognizing that they can’t ignore the risk of a cloud outage or data loss, and the challenge is “what can I do about it?” since there is limited control.

    If you still think “it’s in the cloud, so I don’t need to worry about it,” then get your resume ready. When O365 goes down, your executives are calling IT, not Microsoft, for an answer of what’s being done and what can they do in the meantime to get the business up and running again.

    The key is to recognize what you can control and what actions you can take to evaluate and mitigate risk. At a minimum, you can ensure senior leadership is aware of the risk and define a plan for how you will respond to an incident, even if that is limited to monitoring and communicating status.

    Often you can do more, including defining IT workarounds, backing up your SaaS data for additional protection, and using business process workarounds to bridge the gap, as illustrated in the case studies in this blueprint.

    Frank Trovato
    Research Director, Infrastructure & Operations

    Info-Tech Research Group

    Use this blueprint to expand your DRP and BCP to account for cloud services

    As more applications are migrated to cloud-based services, disaster recovery (DR) and business continuity plans (BCP) must include an understanding of cloud risks and actions to mitigate those risks. This includes evaluating vendor and service reliability and resilience, security measures, data protection capabilities, and technology and business workarounds if there is a cloud outage or incident.

    Use the risk assessments and cloud service incident response plans developed through this blueprint to supplement your DRP and BCP as well as further inform your crisis management plans (e.g. account for cloud risks in your crisis communication planning).

    Overall Business Continuity Plan

    IT Disaster Recovery Plan

    A plan to restore IT application and infrastructure services following a disruption.

    Info-Tech’s Disaster Recovery Planning blueprint provides a methodology for creating the IT DRP. Leverage this blueprint to validate and provide inputs for your IT DRP.

    BCP for Each Business Unit

    A set of plans to resume business processes for each business unit.

    Info-Tech’s Develop a Business Continuity Plan blueprint provides a methodology for creating business unit BCPs as part of an overall BCP for the organization.

    Crisis Management Plan

    A plan to manage a wide range of crises, from health and safety incidents to business disruptions to reputational damage.

    Info-Tech’s Implement Crisis Management Best Practices blueprint provides a framework for planning a response to any crisis, from health and safety incidents to reputational damage.

    Executive Summary

    Your Challenge

    Common Obstacles

    Info-Tech’s Approach

    • Senior leadership is asking difficult questions about the organization’s dependency on third-party cloud services and the risk that poses.
    • Migrating to cloud services transfers much of the responsibility for day-to-day platform maintenance but not accountability for resilience.
    • IT leaders are often responsible for not just the organization’s IT DRP but also BCP and other elements of overall resilience. Cloud risk adds another element IT leaders need to consider.
    • IT leaders have limited control over third-party incidents and that includes cloud services. With SaaS services in particular, recovery or continuity options may be limited.
    • While vendors have swooped in to provide resilience options for the more common SaaS solutions, that is not the case for all cloud services.
    • Part of the solution is defining business process workarounds and that depends on cooperation from business leaders.
    • At a minimum, IT’s responsibility is to identify and communicate risk to senior leadership. That starts with a vendor review to identify SLA and overall resilience gaps.
    • Adapt how you approach downtime and data loss risk, particularly for SaaS solutions where there is limited or no control over the system.
    • Even where there is limited control, you can define an incident response plan to streamline notification, assessment, and implementation of workarounds. Leadership wants more options than simply waiting for the service to come back online.

    Info-Tech Insight

    Asking vendors about their DRP, BCP, and overall resilience has become commonplace. Expect your vendors to provide answers so you can assess risk. Furthermore, your vendor may have additional offerings to increase resilience or recommendations for third parties who can further assist your goals of improving cloud service resilience.

    Key deliverable

    Cloud Services Resilience Summary

    Provide leadership with a summary of cloud risk, downtime workarounds implemented, and additional data protection.

    The image contains a screenshot of the Cloud Services Resilience Summary.

    Additional tools and templates in this blueprint

    Cloud Services Incident Risk and Mitigation Review Tool

    Use this tool to gather vendor input, evaluate vendor SLAs and overall resilience, and track your own risk mitigation efforts.

    The image contains a screenshot of the Cloud Services Incident Risk and Mitigation Review Tool.

    SaaS Incident Response Workflows

    Use the examples in this document as a model to develop your own incident response workflows for cloud outages or data loss.

    The image contains a screenshot of the SaaS Incident Response Workflows.

    This blueprint will step you through the following actions to evaluate and mitigate cloud services risk

    1. Assess your cloud risk
    • Review your cloud services to determine potential impact of downtime/data loss, vendor SLA gaps, and vendor’s current resilience.
  • Identify options to mitigate risk
    • Explore your cloud vendor’s resilience offerings, third-party solutions, DIY recovery options, and business workarounds.
  • Create an incident response plan
    • Document your cloud risk mitigation strategy and incident response plan, which might include a failover strategy, data protection, and/or business continuity.

    Cloud Risk Mitigation

    Identify options to mitigate risk

    Create an incident response plan

    Assess risk

    Phase 1: Assess your cloud risk

    Phase 1

    Phase 2

    Phase 3

    Assess your cloud risk

    Identify options to mitigate risk

    Create an incident response plan

    Cloud does not guarantee uptime

    Public cloud services (e.g. Azure, GCP, AWS) and popular SaaS solutions experience downtime every year.

    A few cloud outage examples:

    • Microsoft Azure AD outage, March 15, 2022:
      Many users could not log into O365, Dynamics, or the Azure Portal.
      Cause: software change.
    • Three AWS outages in December 2021: December 7 (Netflix and others impacted), December 15 (Duo, Zoom, Slack, others), December 20 (Slack, Epic Games, others). Cause: network issues, power outage.
    • Salesforce outage, May 12, 2022: Users could not access the Lightning platform. Cause: expired certificate.

    Cloud availability

    • Migrating to cloud services can improve availability, as they typically offer more resilience than most organizations can afford to implement themselves.
    • However, having multiple data centers, zones, and regions doesn’t prevent all outages, as we see every year with even the largest cloud vendors.

    DR challenges for IaaS, PaaS, and cloud-native

    While there are limits to what you control, often traditional “failover” DR strategy can apply.

    High-level challenges and resilience options:

    • IaaS: No control over the hardware, but you can failover to another region. This is fairly similar to traditional DR.
    • PaaS: No control over the software platform (e.g. SQL server as a service), but you can back up your data and explore vendor options to replicate your environment.
    • Cloud-native applications: As with PaaS, you can back up your data and explore vendor options to replicate your environment.

    Plan for resilience

    • Include DR requirements when designing cloud service implementation. For example, for IaaS solutions, identify what data would need to be replicated and what services may need to be “always on” (e.g. database services where high-availability is demanded).
    • Similarly, for PaaS and cloud-native solutions, consult your vendor regarding options to build in resilience options (e.g. ability to failover to another environment).

    DR challenges for SaaS solutions

    SaaS is the biggest challenge because you have no control over any part of the base application stack.

    High-level challenges and resilience options:

    • No control over the hardware (or the facility, maintenance processes, and so on).
    • No control over the base application (control is limited to configuration settings and add-on customizations or integrations).
    • Options to back up your data will depend on the service.

    Note: The rest of this blueprint is focused primarily on SaaS resilience due to the challenges listed here. For other cloud services, leverage traditional DR strategies and vendor management to mitigate risk (as summarized on the previous slides).

    Focus on what you can control

    • For SaaS solutions in particular, you must toss out traditional DR. If Salesforce has an outage, you won’t be involved in recovering the system.
    • Instead, DR for SaaS needs to focus on improving resilience where you do have control and implementing business workarounds to bridge the gap.

    Evaluate your cloud services to clarify your specific risks

    Time and money is limited, so focus first on cloud services that are most critical and evaluate the vendors’ SLA and existing resilience capabilities.

    The activities on the next two slides will evaluate risk through two approaches:

    Activity 1: Estimate potential impact of downtime and data loss to quantify the risk and determine which cloud services are most critical and need to be prioritized. This is done through a business impact analysis that assesses:

    • Impact on revenue or costs (if applicable).
    • Impact on reputation (e.g. customer impact).
    • Impact on regulatory compliance and health and safety (if applicable).

    Activity 2: Review the vendor to identify risks and gaps. Specifically, evaluate the following:

    • Incident Management SLAs (e.g. does the SLA include RTO/RPO commitments? Do they meet your requirements?)
    • Incident Response Preparedness (e.g. does the vendor have a DRP, BCP, and security incident response plan?)
    • Data Protection (e.g. does their backup strategy and data security meet your standards?)

    Activity 1: Quantify potential impact and prioritize cloud services using a business impact analysis (BIA)

    1-3 hours

    1. Download the latest version of our DRP BIA: DRP Business Impact Analysis Tool. The tool includes instructions.
    2. Include the cloud services you want to assess in the list of applications/systems (see the tool excerpt below), and follow the BIA methodology outlined in the Create a Right-Sized Disaster Recovery Plan blueprint.
    3. Use the results to quantify potential impact and prioritize your efforts on the most-critical cloud services.

    The image contains a screenshot of the DRP Business Impact Analysis Tool.

    Materials
    • DRP BIA Tool
    Participants
    • Core group of IT management and staff who can provide a well-rounded perspective on potential impact. They will create the first draft of the BIA.
    • Review the draft BIA with relevant business leaders to refine and validate the results.

    Activity 2: Review your key cloud vendors’ SLAs, incident preparedness, and data protection strategy

    1-3 hours

    Use the Cloud Services Incident Risk and Mitigation Review Tool as follows:

    1. Send the Vendor Questionnaire tab to your cloud vendors to gather input, and review your existing agreements.
    2. Copy the vendor responses into the tool (see the instructions in the tool) and evaluate. See the example excerpt below.
    3. Identify action items to clarify gaps or address risks. Some action items might not be defined yet and will need to wait until you have had a chance to further explore risk mitigation options.

    The image contains a screenshot of the Cloud Services Incident Risk and Mitigation Review Tool.

    Materials
    • Cloud Services Incident Risk and Mitigation Review Tool
    Participants
    • Core group of IT management and staff tasked with evaluating and improving cloud services’ resilience.

    Phase 2: Identify options to mitigate risk

    Phase 1

    Phase 2

    Phase 3

    Assess your cloud risk

    Identify options to mitigate risk

    Create an incident response plan

    Consult your vendor to identify options to improve resilience, as a starting point

    Your vendor might also be able to suggest third parties that offer additional support, backup, or service continuity options.

    • The Vendor Questionnaire tab in the Cloud Services Incident Risk and Mitigation Review Tool includes a section at the bottom where your vendor can name additional options to improve resilience (e.g. premium support packages, potentially their own DR services).
    • If your vendor has not completed that part of the questionnaire, meet with them to discuss this. Asking service vendors about resilience has become commonplace, so they should be prepared to answer questions about their own offerings and potentially can name trusted third-party vendors who can further assist you.
    • Leverage Info-Tech’s advisory services to evaluate options outlined by your vendor and potential third-party options (e.g. enterprise backup solutions that support backing up SaaS data).

    Some SaaS solutions have plenty of resilience options; others not so much

    • The pervasiveness of O365 has led vendors to close the service continuity gap, with options to send and receive email during an outage and back up your data.
    • With many SaaS solutions, there isn’t going to be a third-party service continuity option, but you might still be able to at least back up your data and implement business process workarounds to close the service gap.

    Example SaaS risk and mitigation: O365

    Risk

    • Several outages every year (e.g. MS Teams July 20, 2022).
    • SLA exceptions include “Scheduled Downtime,” which can occur with just five days’ notice.
    • The Recycling Bin is your data backup, depending on your setup.

    Options to mitigate risk (not an exhaustive list):

    • Third-party solutions for email service continuity.
    • Several backup vendors (e.g. Veeam, Rubrik) can protect most of your O365 suite.
    • Business continuity workarounds leveraging synced OneDrive, SharePoint, and Outlook (access to calendar invites).

    Example SaaS risk and mitigation: Salesforce

    Risk

    • Downtime has been infrequent, but Salesforce did have a major outage in May 2021 (DNS issue) and May 2022 (expired certificate).
    • At the time of this writing, the Main Services Agreement does not commit to a specific uptime value and specifies the usual exclusions.
    • Similarly, there are limited commitments regarding data protection.

    Options to mitigate risk (not an exhaustive list):

    • Salesforce provides a backup and restore service offering.
    • In addition, some third-party vendors support backing up Salesforce data for additional protection against data corruption or data loss.
    • Business continuity workarounds can further reduce the impact of downtime (e.g. record updates in MS Word and leverage Outlook for contact info until Salesforce is recovered).

    Establish a baseline standard for risk mitigation, regardless of cloud service

    At a minimum, set a goal to review vendor risk at least annually, define standard processes for monitoring outages, and review options to back up your SaaS data.

    Example baseline standard for cloud risk mitigation

    • Review vendor risk at least annually. This includes reviewing SLAs, vendor’s incident preparedness (e.g. do they have a current DRP, BCP, and Security IRP?), and the vendor’s data protection strategy.
    • Incident response plans must include, at a minimum, steps to monitor vendor outage and communicate status to relevant stakeholders. Where possible, business process workarounds are defined to bridge the service gap.
    • For critical data (based on your BIA and an evaluation of risk), maintain your own backups of SaaS data for additional protection.

    Embed risk mitigation standards into existing IT operations

    • Include specific SLA requirements, including incident management processes, in your RFP process and annual vendor review.
    • Define cloud incident response in your incident management procedures.
    • Include cloud data considerations in your backup strategy reviews.

    Phase 3: Create an incident response plan

    Phase 1

    Phase 2

    Phase 3

    Assess your cloud risk

    Identify options to mitigate risk

    Create an incident response plan

    Activity 1: Review the example incident response workflows and case studies as a starting point

    1-3 hours

    1. Review the SaaS Incident Response Workflows examples. The examples illustrate different approaches to incident response depending on the criticality of the service and options available.
    2. Review the case studies on the next few slides, which further illustrate the resilience and incident response solutions implemented.
    3. Note the key elements:
    • Detection
    • Assessment
    • Monitoring status / contacting the vendor
    • Communication with key stakeholders
    • Invoking workarounds, if applicable

    Example SaaS Incident Response Workflow Excerpt

    The image contains a screenshot of an example of the SaaS Incident Response Workflow Excerpt.
    Materials
    • SaaS Incident Response Workflows examples
    Participants
    • Core group of IT management and staff tasked with evaluating and improving cloud services’ resilience.
    • Relevant business process owners to provide input and define business workarounds, where applicable.

    Case Study 1: Recovery plan for critical fundraising event

    If either critical SaaS dependency fails, the following plan is executed:

    1. Donors are redirected to a predefined alternate donation page hosted by a different service. The alternate page connects to the backup payment processing service (with predefined integrations).
    2. Marketing communications support the redirect.
    3. While the backup solution doesn’t gather as much data, the payment details provide enough information to follow up with donors where necessary.

    Criticality justified a failover option

    The Annual Day of Giving generates over 50% of fundraising for the year. It’s critically dependent on two SaaS solutions that host the donation page and payment processing.

    To mitigate the risk, the organization implemented the ability to failover to an alternate “environment” – much like a traditional DR solution – supported by workarounds to manage data collection.

    Case Study 2: Protecting customer data

    Daily exports from a SaaS-hosted donations site reduce potential data loss:

    1. Daily exports to a CRM support donor profile updates and follow-ups (tax receipts, thank-you letters, etc.).
    2. The exports also mitigate the risk of data loss due to an incident with the SaaS-hosted donation site.
    3. This company is exploring more-frequent exports to further reduce the risk of data loss.

    Protecting your data gives you options

    For critical data, do you want to rely solely on the vendor’s default backup strategy?

    If your SaaS vendor is hit by ransomware or if their backup frequency doesn’t meet your needs, having your own data backup gives you options.

    It can also support business process workarounds that need to access that data while waiting for SaaS recovery.

    Case Study 3: Recovery plan for payroll

    To enable a more accurate payroll workaround, the following is done:

    1. After each payroll run, export the payroll data from the SaaS solution to a secure location.
    2. If there is a SaaS outage when payroll must be submitted, the exported data can be modified and converted to an ACH file.
    3. The ACH file is submitted to the bank, which has preapproved this workaround.

    BCP can bridge the gap

    When leadership looks to IT to mitigate cloud risk, include BCP in the discussion.

    Payroll is a good example where the best recovery option might be a business continuity workaround.

    IT often still has a role in business continuity workarounds, as in this case study: specifically, providing a solution to modify and convert the payroll data to an ACH file.

    Activity 2: Run tabletop planning exercises as a starting point to build your incident response plan

    1-3 hours

    1. Follow the tabletop planning instructions provided in the Create a Right-Sized Disaster Recovery Plan blueprint.
    2. Run the exercise for each cloud service. Keep the scenario generic at first (e.g. cloud service is down with no reported root cause) so you can focus on your response. Capture response steps and gaps.
    3. Add complexity in subsequent exercises (e.g. data loss plus downtime), and use that to expand and refine the workflow as needed.
    4. Use the resulting workflows as the core piece of your incident response plan.
    5. Supplement the workflow with relevant checklists or procedures. At this point you can choose to incorporate this into your DRP or BCP or maintain these documents as supplements to those plans.
      See the DRP Case Study and BCP Case Study for an example of DRP-BCP documentation.

    Example tabletop planning results excerpt with gaps identified

    The image contains an example tabletop planning results excerpt with gaps identified.

    Materials
    • SaaS Incident Response Workflows examples
    Participants
    • Core group of IT management and staff tasked with evaluating and improving cloud services’ resilience.
    • Review results with relevant business process owners to provide input and define business workarounds where applicable.

    Activity 3: Summarize cloud services resilience to inform senior leadership of current risks and mitigation efforts

    1-3 hours

    1. Use the Cloud Services Resilience Summary example as a template to capture the following:
    • The results of your vendor review (i.e. incident management SLAs, incident response preparedness, data protections strategy).
    • The current state of your downtime workarounds and additional data loss protection.
    • Your baseline standard for cloud services risk mitigation.
    • Summary of resilience, risks, workarounds, and data loss protection for each individual cloud service that you have reviewed.
  • Present the results to senior leadership to:
    • Highlight risks to inform business decisions to mitigate or accept those risks.
    • Summarize actions already taken to mitigate risks.
    • Communicate next steps (e.g. action items to address remaining risks).

    Cloud Services Resilience Summary – Table of Contents

    The image contains a screenshot of Cloud Services Resilience Summary – Table of Contents.
    Materials
    • Cloud Services Resilience Summary
    Participants
    • Core group of IT management and staff tasked with evaluating and improving cloud services’ resilience.
    • Review results with relevant business process owners to provide input and define business workarounds where applicable.

    Summary: For cloud services, after evaluating risk, IT must adapt how they approach risk mitigation

    1. Identify failover options where possible
    • A failover strategy is possible for many cloud services (e.g. IaaS replication to another region, or failing over SaaS to an alternate solution as in case study 1).
  • At least protect your data
    • Explore supplementary backup options to protect against ransomware, data corruption, or data loss and support business continuity workarounds (see case study 2).
  • Leverage BCP to close the gap
    • This doesn’t absolve IT of its role in mitigating cloud incident risk, but business process workarounds can bridge the gap where IT options are limited (see case study 3).

    Related Info-Tech Research

    IT DRP Maturity Assessment

    Get an objective assessment of your DRP program and recommendations for improvement.

    Create a Right-Sized Disaster Recovery Plan

    Close the gap between your DR capabilities and service continuity requirements.

    Develop a Business Continuity Plan

    Streamline the traditional approach to make BCP development manageable and repeatable.

    Implement Crisis Management Best Practices

    Don’t be another example of what not to do. Implement an effective crisis response plan to minimize the impact on business continuity, reputation, and profitability.

    Map Your Business Architecture to Define Your Strategy

    • Buy Link or Shortcode: {j2store}579|cart{/j2store}
    • member rating overall impact: 9.4/10 Overall Impact
    • member rating average dollars saved: $357,799 Average $ Saved
    • member rating average days saved: 30 Average Days Saved
    • Parent Category Name: Strategy & Operating Model
    • Parent Category Link: /strategy-and-operating-model
    • Organizations need to innovate rapidly to respond to the changing forces in their industry, but their IT initiatives often fail to deliver meaningful outcomes.
    • Planners face challenges in understanding the relationships between the important customer-focused innovations they’re trying to introduce and the resources (capabilities) that make them possible, including applications, human resources, information, and processes. For example, are we risking the success of a new service offering by underpinning it with a legacy or manual solution?

    Our Advice

    Critical Insight

    Successful execution of business strategy requires planning that:

    1. Accurately reflects organizational capabilities.
    2. Is traceable so all levels can understand how decisions are made.
    3. Makes efficient use of organizational resources.

    To accomplish this, the business architect must engage stakeholders, model the business, and drive planning with business architecture.

    • Business architecture is often regarded as an IT function when its role and tools should be fixtures within the business planning and innovation practice.
    • Any size of organization – from start-ups to global enterprises -- can benefit from using a common language and modeling rigor to identify the opportunities that will produce the greatest impact and value.
    • You don’t need sophisticated modeling software to build an effective business architecture knowledgebase. In fact, the best format for engaging business stakeholders is intuitive visuals using business language.

    Impact and Result

    • Execute more quickly on innovation and transformation initiatives.
    • More effectively target investments in resources and IT according to what goals and requirements are most important.
    • Identify problematic areas (e.g. legacy applications, manual processes) that hinder the business strategy and create inefficiencies in our information technology operation.

    Map Your Business Architecture to Define Your Strategy Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Map Your Business Architecture Deck – A step-by-step document that walks you through how to properly engage business and IT in applying a common language and process rigor to build key capabilities required to achieve innovation and growth goals.

    Build a structured, repeatable framework for both IT and business stakeholders to appraise the activities that deliver value to consumers; and assess the readiness of their capabilities to enable them.

    • Map Your Business Architecture to Define Your Strategy – Phases 1-3

    2. Stakeholder Engagement Strategy Template – A best-of-breed template to help you build a clear, concise, and compelling strategy document for identifying and engaging stakeholders.

    This template helps you ensure that your business architecture practice receives the resources, visibility, and support it needs to be successful, by helping you develop a strategy to engage the key stakeholders involved.

    • Stakeholder Engagement Strategy Template

    3. Value Stream Map Template – A template to walk through the value streams that are tied to your strategic goals.

    Record the complete value stream and decompose it into stages. Add a description of the expected outcome of the value stream and metrics for each stage.

    • Value Stream Map Template

    4. Value Stream Capability Mapping Template – A template to define capabilities and align them to selected value streams.

    Build a business capability model for the organization and map capabilities to the selected value stream.

    • Value Stream – Capability Mapping Template
    [infographic]

    Workshop: Map Your Business Architecture to Define Your Strategy

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Discover the Business Context

    The Purpose

    Identify and consult stakeholders to discover the business goals and value proposition for the customer.

    Key Benefits Achieved

    Engage stakeholders and SMEs in describing the business and its priorities and culture.

    Identify focus for the areas we will analyze and work on.

    Activities

    1.1 Select key stakeholders

    1.2 Plan for engaging stakeholders

    1.3 Gather business goals and priorities

    Outputs

    Stakeholder roles

    Engagement plan

    Business strategy, value proposition

    2 Define Value Streams

    The Purpose

    Describe the main value-adding activities of the business from the consumer’s point of view, e.g. provide product or service.

    Key Benefits Achieved

    Shared understanding of why we build resources and do what we do.

    Starting point for analyzing resources and investing in innovation.

    Activities

    2.1 Define or update value streams

    2.2 Decompose selected value stream(s) into value stages and identify problematic areas and opportunities

    Outputs

    Value streams for the enterprise

    Value stages breakdown for selected value stream(s)

    3 Build Business Capability Map

    The Purpose

    Describe all the capabilities that make up an organization and enable the important customer-facing activities in the value streams.

    Key Benefits Achieved

    Basis for understanding what resources the organization has and their ability to support its growth and success.

    Activities

    3.1 Define and describe all business capabilities (Level 1)

    3.2 Decompose and analyze capabilities for a selected priority value stream.

    Outputs

    Business Capability Map (Level 1)

    Business Capabilities Level 2 for selected value stream

    4 Develop a Roadmap

    The Purpose

    Use the Business Capability Map to identify key capabilities (e.g. cost advantage creator), and look more closely at what applications or information or business processes are doing to support or hinder that critical capability.

    Key Benefits Achieved

    Basis for developing a roadmap of IT initiatives, focused on key business capabilities and business priorities.

    Activities

    4.1 Identify key capabilities (cost advantage creators, competitive advantage creators)

    4.2 Assess capabilities with the perspective of how well applications, business processes, or information support the capability and identify gaps

    4.3 Apply analysis tool to rank initiatives

    Outputs

    Business Capability Map with key capabilities: cost advantage creators and competitive advantage creators

    Assessment of applications or business processes or information for key capabilities

    Roadmap of IT initiatives

    Further reading

    Map Your Business Architecture to Define Your Strategy

    Plan your organization’s capabilities for best impact and value.

    Info-Tech Research Group

    Info-Tech is a provider of best-practice IT research advisory services that make every IT leader’s job easier.

    35,000 members sharing best practices you can leverage Millions spent developing tools and templates annually Leverage direct access to over 100 analysts as an extension of your team Use our massive database of benchmarks and vendor assessments Get up to speed in a fraction of the time

    Analyst perspective

    Know your organization’s capabilities to build a digital and customer-driven culture.

    Business architecture provides a holistic and unified view of:

    • All the organization’s activities that provide value to their clients (value streams).
    • The resources that make them possible and effective (capabilities, i.e. its employees, software, processes, information).
    • How they inter-relate, i.e. depend on and impact each other to help deliver value.

    Without a business architecture it is difficult to see the connections between the business’s activities for the customer and the IT resources supporting them – to demonstrate that what we do in IT is customer-driven.

    As a map of your business, the business architecture is an essential input to the digital strategy:

    • Develop a plan to transform the business by investing in the most important capabilities.
    • Ensure project initiatives are aligned with business goals as they evolve.
    • Respond more quickly to customer requirements and to disruptions in the industry by streamlining operations and information sharing across the enterprise.

    Crystal Singh, Research Director, Data and Analytics

    Crystal Singh
    Research Director, Data and Analytics
    Info-Tech Research Group

    Andrea Malick, Research Director, Data and Analytics

    Andrea Malick
    Research Director, Data and Analytics
    Info-Tech Research Group

    Executive summary

    Your Challenge Common Obstacles Info-Tech’s Approach

    Organizations need to innovate rapidly to respond to ever-changing forces and demands in their industry. But they often fail to deliver meaningful outcomes from their IT initiatives within a reasonable time.

    Successful companies are transforming, i.e. adopting fluid strategies that direct their resources to customer-driven initiatives and execute more quickly on those initiatives. In a responsive and digital organization, strategies, capabilities, information, people, and technology are all aligned, so work and investment are consistently allocated to deliver maximum value.

    You don’t have a complete reference map of your organization’s capabilities on which to base strategic decisions.

    You don’t know how to prioritize and identify the capabilities that are essential for achieving the organization’s customer-driven objectives.

    You don’t have a shared enterprise vision, where everyone understands how the organization delivers value and to whom.

    Begin important business decisions with a map of your organization – a business reference architecture. Model the business in the form of architectural blueprints.

    Engage your stakeholders. Recognize the opportunity for mapping work, and identify and engage the right stakeholders.

    Drive business architecture forward to promote real value to the organization. Assess your current projects to determine if you are investing in the right capabilities. Conduct business capability assessments to identify opportunities and prioritize projects.

    Info-Tech Insight
    Business architecture is the set of strategic planning techniques that connects organization strategy to execution in a manner that is accurate and traceable and promotes the efficient use of organizational resources.

    Blueprint activities summary

    Phase Purpose Activity Outcome
    1. Business context:
    Identify organization goals, industry drivers, and regulatory requirements in consultation with business stakeholders.
    Identify forces within and outside the organization to consider when planning the focus and timing of digital growth, through conducting interviews and surveys and reviewing existing strategies. Business value canvas, business strategy on a page, customer journey
    2. Customer activities (value stream):
    What is the customer doing? What is our reason for being as a company? What products and services are we trying to deliver?
    Define or update value streams, e.g. purchase product from supplier, customer order, and deliver product to customer. Value streams enterprise-wide (there may be more than one set of value streams, e.g. a medical school and community clinic)
    Prioritize value streams:
    Select key value streams for deeper analysis and focus.
    Assess value streams. Priority value streams
    Value stages:
    Break down the selected value stream into its stages.
    Define stages for selected value streams. Selected value stream stages
    3. Business capability map, level 1 enterprise:
    What resources and capabilities at a high level do we have to support the value streams?
    Define or update the business capabilities that align with and support the value streams. Business capability map, enterprise-wide capabilities level 1
    Business capability map, level 2 for selected area:
    List resources and capabilities that we have at a more detailed level.
    Define or update business capabilities for selected value stream to level 2. Business capability map, selected value stream, capability level 2
    Heatmap Business Capability Map: Flag focus areas in supporting technology, applications, data and information.

    Info-Tech’s workshop methodology

    Day 1: Discover Business Context Day 2: Define Value Streams Day 3: Build Business Capability Map Day 4: Roadmap Business Architecture
    Phase Steps

    1.1 Collect corporate goals and strategies

    1.2 Identify stakeholders

    2.1 Build or update value streams

    2.2 Decompose selected value stream into value stages and analyze for opportunities

    3.1 Update business capabilities to level 1 for enterprise

    3.2 For selected value streams, break down level 1 to level 2

    3.3 Use business architecture to heatmap focus areas: technology, information, and processes

    3.4 Build roadmap of future business architecture initiatives

    Phase Outcomes
    • Organizational context and goals
    • Business strategy on a page, customer journey map, business model canvas
    • Roles and responsibilities
    • Value stream map and definitions
    • Selected value stream(s) decomposed into value stages
    • Enterprise business capabilities map to level 1
    • Business architecture to level 2 for prioritized value stream
    • Heatmap business architecture
    • Business architecture roadmap, select additional initiatives

    Key concepts for this blueprint

    INDUSTRY VALUE CHAIN DIGITAL TRANSFORMATION BUSINESS ARCHITECTURE
    A high-level analysis of how the industry creates value for the consumer as an overall end-to-end process. The adoption of digital technologies to innovate and re-invent existing business, talent ,and operating models to drive growth, business value, and improved customer experience. A holistic, multidimensional business view of capabilities, end-to-end value, and operating model in relation to the business strategy.
    INDUSTRY VALUE STREAM STRATEGIC OBJECTIVES CAPABILITY ASSESSMENTS
    A set of activities, tasks, and processes undertaken by a business or a business unit across the entire end-to-end business function to realize value. A set of standard objectives that most industry players will feature in their corporate plans. A heat-mapping effort to analyze the maturity and priority of each capability relative to the strategic priorities that they serve.

    Info-Tech’s approach

    1 Understand the business context and drivers
    Deepen your understanding of the organization’s priorities by gathering business strategies and goals. Talking to key stakeholders will allow you to get a holistic view of the business strategy and forces shaping the strategy, e.g. economy, workforce, and compliance.
    2 Define value streams; understand the value you provide
    Work with senior leadership to understand your customers’ experience with you and the ways your industry provides value to them.
    Assess the value streams for areas to explore and focus on.
    3 Customize the industry business architecture; develop business capability map
    Work with business architects and enterprise architects to customize Info-Tech’s business architecture for your industry as an enterprise-wide map of the organization and its capabilities.
    Extend the business capability map to more detail (Level 2) for the value stream stages you select to focus on.

    Business architecture is a planning function that connects strategy to execution

    Business architecture provides a framework that connects business strategy and IT strategy to project execution through a set of models that provide clarity and actionable insights. How well do you know your business?

    Business architecture is:

    • Inter-disciplinary: Business architecture is a core planning activity that supports all important decisions in the organization, for example, organizational resources planning. It’s not just about IT.
    • Foundational: The best way to answer the question, “Where do we start?” or “Where is our investment best directed?”, comes from knowing your organization, what its core functions and capabilities are (i.e. what’s important to us as an organization), and where there is work to do.
    • Connecting: Digital transformation and modernization cannot work with siloes. Connecting siloes means first knowing the organization and its functions and recognizing where the siloes are not communicating.

    Business architecture must be branded as a front-end planning function to be appropriately embedded in the organization’s planning process.

    Brand business architecture as an early planning pre-requisite on the basis of maintaining clarity of communication and spreading an accurate awareness of how strategic decisions are being made.

    As an organization moves from strategy toward execution, it is often unclear as to exactly how decisions pertaining to execution are being made, why priority is given to certain areas, and how the planning function operates.

    The business architect’s primary role is to model this process and document it.

    In doing so, the business architect creates a unified view as to how strategy connects to execution so it is clearly understood by all levels of the organization.

    Business architecture is part of the enterprise architecture framework

    Business Architecture
    Business strategy map Business model canvas Value streams
    Business capability map Business process flows Service portfolio
    Data Architecture Application Architecture Infrastructure Architecture
    Conceptual data model Application portfolio catalog Technology standards catalog
    Logical data model Application capability map Technology landscape
    Physical data model Application communication model Environments location model
    Data flow diagram Interface catalog Platform decomposition diagram
    Data lifecycle diagram Application use-case diagram Network computing / hardware diagram
    Security Architecture
    Enterprise security model Data security model Application security model

    Business architecture is a set of shared and practical views of the enterprise

    The key characteristic of the business architecture is that it represents real-world aspects of a business, along with how they interact.

    Many different views of an organization are typically developed. Each view is a diagram that illustrates a way of understanding the enterprise by highlighting specific information about it:

    • Business strategy view captures the tactical and strategic goals that drive an organization forward.
    • Business capabilities view describes the primary business functions of an enterprise and the pieces of the organization that perform those functions.
    • Value stream view defines the end-to-end set of activities that deliver value to external and internal stakeholders.
    • Business knowledge view establishes the shared semantics (e.g. customer, order, and supplier) within an organization and relationships between those semantics (e.g. customer name, order date, supplier name) – an information map.
    • Organizational view captures the relationships among roles, capabilities, and business units, the decomposition of those business units into subunits, and the internal or external management of those units.

    Business architect connects all the pieces

    The business owns the strategy and operating model; the business architect connects all the pieces together.

    R Business Architect (Responsible)
    A Business Unit Leads (Accountable)
    C Subject Matter Experts (Consulted)
    – Business Lines, Operations, Data, Technology Systems & Infrastructure Leads
    I Business Operators (Informed)
    – Process, Data, Technology Systems & Infrastructure

    Choose a key business challenge to address with business architecture

     Choose a key business challenge to address with business architecture

    Picking the right project is critical to setting the tone for business architecture work in the organization.

    Best practices for business architecture success

    Consider these best practices to maintain a high level of engagement from key stakeholders throughout the process of establishing or applying business architecture.

    Balance short-term cost savings with long-term benefits

    Participate in project governance to facilitate compliance

    Create a center of excellence to foster dialogue

    Identify strategic business objectives

    Value streams: Understand how you deliver value today

    It is important to understand the different value-generating activities that deliver an outcome for and from your customers.

    We do this by looking at value streams, which refer to the specific set of activities an industry player undertakes to create and capture value for and from the end consumer (and so the question to ask is, how do you make money as an organization?).

    Our approach helps you to strengthen and transform those value streams that generate the most value for your organization.

    Understand how you deliver value today

    An organization can have more than one set of streams.
    For example, an enterprise can provide both retail shopping and financial services, such as credit cards.

    Define the organization’s value streams

    • Value streams connect business goals to the organization’s value realization activities. They enable an organization to create and capture value in the market place by engaging in a set of interconnected activities. Those activities are dependent on the specific industry segment an organization operates within. Value streams can extend beyond the organization into the supporting ecosystem, whereas business processes are contained within and the organization has complete control over them.
    • There are two types of value streams: core value streams and support value streams. Core value streams are mostly externally facing: they deliver value to either an external or internal customer and they tie to the customer perspective of the strategy map. Support value streams are internally facing and provide the foundational support for an organization to operate.
    • An effective method for ensuring all value streams have been considered is to understand that there can be different end-value receivers. Info-Tech recommends identifying and organizing the value streams with customers and partners as end-value receivers.

    Example: Value stream descriptions for the retail industry

    Value Streams Create or Purchase the Product Manage Inventory Distribute Product Sell Product, Make Product Available to Customers
    • Product is developed before company sells it.
    • Make these products by obtaining raw materials from external suppliers or using their own resources.
    • Retailers purchase the products they are going to sell to customers from manufacturers or wholesale distributors.
    • Retailer success depends on its ability to source products that customers want and are willing to buy.
    • Inventory products are tracked as they arrive in the warehouse, counted, stored, and prepared for delivery.
    • Estimate the value of your inventory using retail inventory management software.
    • Optimizing distribution activities is an important capability for retailers. The right inventory needs to be at a particular store in the right quantities exactly when it is needed. This helps to maximize sales and minimize how much cash is held up in inventory.
    • Proper supply chain management can not only reduce costs for retailers but drive revenues by enhancing shopping experiences.
    • Once produced, retailers need to sell the products. This is done through many channels including physical stores, online, the mail, or catalogs.
    • After the sale, retailers typically have to deliver the product, provide customer care, and manage complaints.
    • Retailers can use loyalty programs, pricing, and promotions to foster repeat business.

    Value streams describe your core business

    Value streams describe your core business

    Value streams – the activities we do to provide value to customers – require business capabilities.

    Value streams are broken down further into value stages, for example, the Sell Product value stream has value stages Evaluate Options, Place Order, and Make Payment.

    Think of value streams as the core operations: the reason for your organization’s being. A professional consulting organization may have a legal team but it does not brand itself as a law firm. A core value stream is providing research products and services; a business capability that supports it is legal counsel.

    Decompose the value stream into stages

    The stages of a value stream are usually action-oriented statements or verbs that make up the individual steps involved throughout the scope of the value stream, e.g. Place Order or Make Payment.

    Each value stream should have a trigger or starting point and an end result for a client or receiver.

    Decompose the value stream into stages

    There should be measurable value or benefits at each stage. These are key performance indicators (KPIs). Spot problem areas in the stream.

    Value streams usually fall into one of these categories:

    1. Fulfillment of products and services
    2. Manufacturing
    3. Software products
    4. Supporting value streams (procurement of supplies, product planning)

    Value streams need capabilities

    • Value streams connect business goals to the organization’s value realization activities. They enable an organization to create and capture value in the market place by engaging in a set of interconnected activities.
    • There are two types of value streams: core value streams and support value streams. Core value streams are mostly externally facing: they deliver value to either an external or internal customer and they tie to the customer perspective of the strategy map. Support value streams are internally facing and provide the foundational support for an organization to operate.
    • There can be different end-value receivers. Info-Tech recommends identifying and organizing the value streams with customers and partners as end-value receivers.

    Value streams need business capabilities

    Business capabilities are built up to allow the business to perform the activities that bring value to customers. Map capabilities to the value-add activities in the value stream. Business capabilities lie at the top layer of the business architecture:

    • They are the most stable reference for planning organizations.
    • They make strategy more tangible.
    • If properly defined, they can help overcome organizational silos.

    Value streams need business capabilities

    Example business capability map – Higher Education

    A business capability map can be thought of as a visual representation of your organization’s business capabilities and represents a view of what your data program must support.

    Validate your business capability map with the right stakeholders, including your executive team, business unit leaders, and/or other key stakeholders.

    Example business capability map for: Higher Education

    Example business capability map for Higher Education

    Example business capability map – Local Government

    Validate your business capability map with the right stakeholders, including your executive team, business unit leaders, and/or other key stakeholders.

    A business capability map can be thought of as a visual representation of your organization’s business capabilities and represents a view of what your data program must support.

    Example business capability map for: Local Government

    Example business capability map for Local Government

    Value streams need business capabilities

    Value streams – the activities we do to provide value to customers – require business capabilities. Value streams are broken down further into value stages.

    Business capabilities are built up to allow the business to perform the activities that bring value to customers. Map capabilities to the activities in the value stage to spot opportunities and problems in delivering services and value.

    Business processes fulfill capabilities. They are a step-by-step description of who is performing what to achieve a goal. Capabilities consist of networks of processes and the resources – people, technology, materials – to execute them.

    Capability = Processes + Software, Infrastructure + People

    Prioritize a value stream and identify its supporting capabilities

    Prioritize your improvement objectives and business goals and identify a value stream to transform.

    Align the business objectives of your organization to your value streams (the critical actions that take place within your organization to add value to a customer).

    Prioritize a value stream to transform based on the number of priorities aligned to a value stream, and/or the business value (e.g. revenue, EBITDA earnings, competitive differentiation, or cost efficiency).

    Decompose the selected value stream into value stages.

    Align capabilities level 1 and 2 to value stages. One capability may support several value stages in the stream.

    Build a business architecture for the prioritized value stream with a map of business capabilities up to level 2.

    NOTE: We can’t map all capabilities all at once: business architecture is an ongoing practice; select key mapping initiatives each year based on business goals.

    Prioritize a value stream and identify its supporting capabilities

    Map business capabilities to Level 2

     Map business capabilities to Level 2

    Map capabilities to value stage

    Map capabilities to value stage

    Business value realization

    Business value defines the success criteria of an organization as manifested through organizational goals and outcomes, and it is interpreted from four perspectives:

    • Profit generation: The revenue generated from a business capability with a product that is enabled with modern technologies.
    • Cost reduction: The cost reduction when performing business capabilities with a product that is enabled with modern technologies.
    • Service enablement: The productivity and efficiency gains of internal business operations from products and capabilities enhanced with modern technologies.
    • Customer and market reach: The improved reach and insights of the business in existing or new markets.

    Business Value Matrix

    Value, goals, and outcomes cannot be achieved without business capabilities

    Break down your business goals into strategic and achievable initiatives focused on specific value streams and business capabilities.

    Business goals and outcomes

    Accelerate the process with an industry business architecture

    It’s never a good idea to start with a blank page.

    The business capability map available from Info-Tech and with industry standard models can be used as an accelerator. Assemble the relevant stakeholders – business unit leads and product/service owners – and modify the business capability map to suit your organization’s context.

    Acceleration path: Customize generic capability maps with the assistance of our industry analysts.

    Accelerate the process with an industry business architecture

    Identify goals and drivers

    Consider organizational goals and industry forces when planning.

    Business context Define value streams Build business capability map
    1.1 Select key stakeholders
    1.2 Collect and understand corporate goals
    2.1 Update or define value streams
    2.2 Decompose and analyze selected value stream
    3.1 Build level 1 capability map
    3.2 Build level 2 capability map
    3.3 Heatmap capability map
    3.4 Roadmap

    Use inputs from business goals and strategies to understand priorities.

    It is not necessary to have a comprehensive business strategy document to start – with key stakeholders, the business architect should be able to gather a one-page business value canvas or customer journey.

    Determine how the organization creates value

    Begin the process by identifying and locating the business mission and vision statements.

    What is business context?

    “The business context encompasses an understanding of the factors impacting the business from various perspectives, including how decisions are made and what the business is ultimately trying to achieve. The business context is used by IT to identify key implications for the execution of its strategic initiatives.”

    Source: Businesswire, 2018

    Identify the key stakeholders who can help you promote the value of business architecture

    First, as the CIO, you must engage executive stakeholders and secure their support.
    Focus on key players who have high power and high interest in business architecture.

    Engage the stakeholders who are impacted the most and have the power to impede the success of business architecture.

    For example, if the CFO – who has the power to block funding – is disengaged, business architecture will be put at risk.

    Use Info-Tech’s Stakeholder Power Map Template to help prioritize time spent with stakeholders.

    Sample power map

    Identify the key stakeholders concerned with the business architecture project

    A business architecture project may involve the following stakeholders:

    Business architecture project stakeholders

    You must identify who the stakeholders are for your business architecture work.

    Think about:

    • Who are the decision makers and key influencers?
    • Who will impact the business architecture work? Who will the work impact?
    • Who has vested interest in the success or failure of the practice?
    • Who has the skills and competencies necessary to help us be successful?

    Avoid these common mistakes:

    • Don’t focus on the organizational structure and hierarchy. Often stakeholder groups don’t fit the traditional structure.
    • Don’t ignore subject-matter experts on either the business or IT side. You will need to consider both.

    1.1 Identify and assemble key stakeholders

    1-3 hours

    Build an accurate depiction of the business.

    1. It is important to make sure the right stakeholders participate in this exercise. The exercise of identifying capabilities for an organization is very introspective and requires deep analysis.
    2. Consider:
      1. Who are the decision makers and key influencers?
      2. Who will impact the business capability work? Who has a vested interest in the success or failure of the outcome?
      3. Who has the skills and competencies necessary to help you be successful?
    3. Avoid:
      1. Don’t focus on the organizational structure and hierarchy. Often stakeholder groups don’t fit the traditional structure.
      2. Don’t ignore subject matter experts on either the business or IT side. You will need to consider both.
    Input Output
    • List of who is accountable for key business areas and decisions
    • Organizational chart
    • List of who has decision-making authority
    • A list of the key stakeholders
    Materials Participants
    • Whiteboard/Flip Charts
    • Modeling software (e.g. Visio, ArchiMate)
    • Business capability map industry models
    • CIO
    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • Departmental Executives & Senior Managers

    Conduct interviews with the business to gather intelligence for strategy

    Talking to key stakeholders will allow you to get a holistic view of the business strategy.

    Stakeholder interviews provide holistic view of business strategy

    Build a strategy on a page through executive interviews and document reviews

    Understanding the business mandate and priorities ensures alignment across the enterprise.

    A business strategy must articulate the long-term destination the business is moving into. This illustration shapes all the strategies and activities in every other part of the business, including what IT capabilities and resources are required to support business goals. Ultimately, the benefits of a well-defined business strategy increase as the organization scales and as business units or functions are better equipped to align the strategic planning process in a manner that reflects the complexity of the organization.

    Using the Business Strategy on a Page canvas, consider the questions in each bucket to elicit the overall strategic context of the organization and uncover the right information to build your digital strategy. Interview key executives including your CEO, CIO, CMO, COO, CFO, and CRO, and review documents from your board or overall organizational strategy to uncover insights.

    Info-Tech Insight
    A well-articulated and clear business strategy helps different functional and business units work together and ensures that individual decisions support the overall direction of the business.

    Focus on business value and establish a common goal

    Business architecture is a strategic planning function and the focus must be on delivering business value.

    Examples business objectives:

    • Digitally transform the business, redefining its customer interactions.
    • Identify the root cause for escalating customer complaints and eroding satisfaction.
    • Identify reuse opportunities to increase operational efficiency.
    • Identify capabilities to efficiently leverage suppliers to handle demand fluctuations.

    Info-Tech Insight
    CIOs are ideally positioned to be the sponsors of business architecture given that their current top priorities are digital transformation, innovation catalyzation, and business alignment.

    1.2 Collect and understand business objectives

    1-3 hours

    Having a clear understanding of the business is crucial to executing on the strategic IT initiatives.

    1. Discover the strategic CIO initiatives your organization will pursue:
    • Schedule interviews.
    • Use the CIO Business Vision diagnostic or Business Context Discovery Tool.
  • Document the business goals.
  • Update and finalize business goals.
  • InputOutput
    • Existing business goals and strategies
    • Existing IT strategies
    • Interview findings
    • Diagnostic results
    • List of business goals
    • Strategy on a page
    • Business model canvas
    • Customer journey
    MaterialsParticipants
    • CIO Business Vision diagnostic
    • Interview questionnaire
    • CIO
    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • Departmental Executives & Senior Managers

    CIO Business Vision Diagnostic

    CEO

    Vision

    Where do you want to go?
    What is the problem your organization is addressing?

    Mission/Mandate

    What do you do?
    How do you do?
    Whom do you do it for?

    Value Streams

    Why are you in business? What do you do?
    What products and services do you provide?
    Where has your business seen persistent demand?

    Key Products & Services

    What are your top three to five products and services?

    Key Customer Segments

    Who are you trying to serve or target?
    What are the customer segments that decide your value proposition?

    Value Proposition

    What is the value you deliver to your customers?

    Future Value Proposition

    What is your value proposition in three to five years’ time?

    Digital Experience Aspirations

    How can you create a more effective value stream?
    For example, greater value to customers or better supplier relationships.

    Business Resilience Aspirations

    How can you reduce business risks?
    For example, compliance, operational, security, or reputational.

    Sustainability (or ESG) Aspirations

    How can you deliver ESG and sustainability goals?

    Interview the following executives for each business goal area.

    CEO
    CRO
    COO

    Core Business Goals

    What are the core business goals to meet business objectives?

    Top Priorities & Initiatives

    What are the top initiatives and priorities over the planning horizon?

    Performance Insights/Metrics

    What do we need to achieve?
    How can the success be measured?

    CMO
    COO
    CFO

    Shared Business Goals

    What are the shared (operational) business goals to meet business objectives?

    Top Priorities & Initiatives

    What are the top initiatives and priorities over the planning horizon?

    Performance Insights/Metrics

    What do we need to achieve?
    How can the success be measured?

    CFO
    CIO
    COO
    CHRO

    Enabling Business Goals

    What are the enabling (supporting/enterprise) business goals to meet business objectives?

    Top Priorities & Initiatives

    What are the top initiatives and priorities over the planning horizon?

    Performance Insights/Metrics

    What do we need to achieve?
    How can the success be measured?

    Craft a strategy to increase stakeholder support and participation

    The BA practice’s supporters are potential champions who will help you market the value of BA; engage with them first to create positive momentum. Map out the concerns of each group of stakeholders so you can develop marketing tactics and communications vehicles to address them.

    Example Communication Strategy

    Stakeholder Concerns Tactics to Address Concerns Communication Vehicles Frequency
    Supporters
    (High Priority)
    • Build ability to execute BA techniques
    • Build executive support
    • Build understanding of how they can contribute to the success of the BA practice
    • Communicate the secured executive support
    • Help them apply BA techniques in their projects
    • Show examples of BA work (case studies)
    • Personalized meetings and interviews
    • Department/functional meetings
    • Communities of practice or centers of excellent (education and case studies)
    Bi-Monthly
    Indifferent
    (Medium Priority)
    • Build awareness and/or confidence
    • Feel like BA has nothing to do with them
    • Show quick wins and case studies
    • Centers of excellence (education and case studies
    • Use the support of the champions
    Quarterly
    Resistors
    (Medium Priority)
    • BA will cause delays
    • BA will step in their territory
    • BA’s scope is too broad
    • Lack of understanding
    • Prove the value of BA – case studies and metrics
    • Educate how BA complements their work
    • Educate them on the changes resulting from the BA practice’s work, and involve them in crafting the process
    • Individual meetings and interviews
    • Political jockeying
    • Use the support of the champions
    Tailored to individual groups

    1.3 Craft a strategy to increase stakeholder support and participation

    1-2 hours

    Now that you have organized and categorized your stakeholders based on their power, influence, interest, and knowledge of business architecture, it is time to brainstorm how you are going to gain their support and participation.

    Think about the following:

    • What are your stakeholders’ concerns?
    • How can you address them?
    • How will you deliver the message?
    • How often will you deliver the message?

    Avoid these common mistakes:

    • Your communication strategy development should be an iterative process. Do not assume to know the absolute best way to get through to every resistor right away. Instead, engage with your supporters for their input on how to communicate to resistors and repeat the process for indifferent stakeholders as well.
    Input Output
  • Stakeholder Engagement Map
    • Stakeholder Communications Strategy
    Materials Participants
    • Stakeholder Engagement Strategy Template
    • A computer
    • A whiteboard and markers CIO
    • Business Architect
    • IT Department Leads

    Download the Stakeholder Engagement Strategy Template for this project.

    Engaging the right stakeholders

    CASE STUDY

    Industry
    Financial - Banking

    Source
    Anonymous

    Situation Complication Result

    To achieve success with the business architecture initiative, the bank’s CIO needed to put together a plan to engage the right stakeholders in the process.

    Without the right stakeholders, the initiative would suffer from inadequate information and thus would run the risk of delivering an ineffective solution.

    The bank’s culture was resistant to change and each business unit had its own understanding of the business strategy. This was a big part of the problem that led to decreasing customer satisfaction.

    The CIO needed a unified vision for the business architecture practice involving people, process, and technology that all stakeholders could support.

    Starting with enlisting executive support in the form of a business sponsor, the CIO identified the rest of the key stakeholders, in this case, the business unit heads, who were necessary to engage for the initiative.

    Once identified, the CIO promoted the benefits of business architecture to each of the business unit heads while taking stock of their individual needs.

    1.4 Develop a plan to engage key stakeholders

    1 hour

    Using your stakeholder power map as a starting point, focus on the three most important quadrants: those that contain stakeholders you must keep informed, those to keep satisfied, and the key players.

    Plot the stakeholders from those quadrants on a stakeholder engagement map.

    Think about the following:

    • Who are your resistors? These individuals will actively detract from project’s success if you don’t address their concerns.
    • Who is indifferent? These individuals need to be educated more on the benefits of business architecture to have an opinion either way.
    • Who are your supporters? These individuals will support you and spread your message if you equip them to do so.

    Avoid these common mistakes:

    • Do not jump to addressing resistor concerns first. Instead, equip your supporters with the info they need to help your cause and gain positive momentum before approaching resistors.
    InputOutput
    • Stakeholder Engagement Map
    • Stakeholder Communications Strategy
    MaterialsParticipants
    • Stakeholder Engagement Strategy Template
    • A computer
    • A whiteboard and markers
    • CIO
    • Business Architect
    • IT Department Leads

    Download the Stakeholder Engagement Strategy Template for this project.

    1.5 Craft a strategy to increase stakeholder support and participation

    1-2 hours

    Now that you have organized and categorized your stakeholders based on their power, influence, interest, and knowledge of business architecture, it is time to brainstorm how you are going to gain their support and participation.

    Think about the following:

    • What are your stakeholders’ concerns?
    • How can you address them?
    • How will you deliver the message?
    • How often will you deliver the message?

    Avoid these common mistakes:

    • Your communication strategy development should be an iterative process. Do not assume to know the absolute best way to get through to every resistor right away. Instead, engage with your supporters for their input on how to communicate to resistors and repeat the process for indifferent stakeholders as well.
    InputOutput
    • Stakeholder Engagement Map
    • Stakeholder Communications Strategy
    MaterialsParticipants
    • Stakeholder Engagement Strategy Template
    • A computer
    • A whiteboard and markers
    • CIO
    • Business Architect
    • IT Department Leads

    Download the Stakeholder Engagement Strategy Template for this project.

    Define value streams

    Identify the core activities your organization does to provide value to your customers.

    Business context Define value streams Build business capability map

    1.1 Select key stakeholders
    1.2 Collect and understand corporate goals

    2.1 Update or define value streams
    2.2 Decompose and analyze selected value stream

    3.1 Build Level 1 capability map
    3.2 Build Level 2 capability map
    3.3 Heatmap capability map
    3.4 Roadmap

    This phase will walk you through the following activities:

    • Note: It is recommended that you gather and leverage relevant industry standard business architecture models you may have available to you. Example: Info-Tech Industry Business Architecture, BIZBOK, APQC.
    • Defining or updating the organization’s value streams.
    • Selecting priority value streams for deeper analysis.

    This phase involves the following participants:

    • Business Architect, Enterprise Architect
    • Relevant Business Stakeholder(s): Business Unit Leads, Departmental Executives, Senior Mangers, Business Analysts

    Define the organization’s value streams

    • Value streams connect business goals to the organization’s value realization activities. They enable an organization to create and capture value in the marketplace by engaging in a set of interconnected activities. Those activities are dependent on the specific industry segment an organization operates within. Value streams can extend beyond the organization into the supporting ecosystem, whereas business processes are contained within and the organization has complete control over them.
    • There are two types of value streams: core value streams and support value streams. Core value streams are mostly externally facing: they deliver value to either an external or internal customer and they tie to the customer perspective of the strategy map. Support value streams are internally facing and provide the foundational support for an organization to operate.
    • An effective method for ensuring all value streams have been considered is to understand that there can be different end-value receivers. Info-Tech recommends identifying and organizing the value streams with customers and partners as end-value receivers.

    Connect business goals to value streams

    Example strategy map and value stream

    Identifying value streams

    Value streams connect business goals to organization’s value realization activities. They enable an organization to create and capture value in the market place by engaging in a set of interconnected activities.

    There are several key questions to ask when endeavoring to identify value streams.

    Key Questions
    • Who are your customers?
    • What are the benefits we deliver to them?
    • How do we deliver those benefits?
    • How does the customer receive the benefits?

    Example: Value stream descriptions for the retail industry

    Value StreamsCreate or Purchase ProductManage InventoryDistribute ProductSell Product
    • Retailers need to purchase the products they are going to sell to customers from manufacturers or wholesale distributors.
    • A retailer’s success depends on its ability to source products that customers want and are willing to buy.
    • In addition, they need to purchase the right amount and assortment of products based on anticipated demand.
    • The right inventory needs to be at a particular store in the right quantities exactly when it is needed. This helps to maximize sales and minimize how much cash is held up in inventory.
    • Inventory management includes tracking, ordering, and stocking products, e.g. raw materials, finished products, buffer inventory.
    • Optimizing distribution activities is important for retailers.
    • Proper supply chain management can not only reduce costs for retailers but also drive revenues by enhancing shopping experiences.
    • Distribution includes transportation, packaging and delivery.
    • As business becomes global, it is important to ensure the whole distribution channel is effective.
    • Once produced, retailers need to sell the products. This is done through many channels including physical stores, online, the mail, or catalogs.
    • After the sale, retailers typically have to deliver the product, provide customer care, and manage complaints.
    • Retailers can use loyalty programs, pricing, and promotions to foster repeat business.

    Value streams describe your core business

    Value streams – the activities we do to provide value to customers – require business capabilities.

    Value streams are broken down further into value stages, for example, Sell Product value stream has value stages Evaluate Options, Place Order, and Make Payment.

    Think of value streams as the core operations, the reason for our organization’s being. A professional consulting organization may have a legal team but it does not brand itself as a law firm. A core value stream is providing research products and services – a business capability that supports it is legal counsel.

    2.1 Define value streams

    1-3 hours

    Unify the organization’s perspective on how it creates value.

    1. Write a short description of the value stream that includes a statement about the value provided and a clear start and end for the value stream. Validate the accuracy of the descriptions with your key stakeholders.
    2. Consider:
      1. How does the organization deliver those benefits?
      2. How does the customer receive the benefits?
      3. What is the scope of your value stream? What will trigger the stream to start and what will the final value be?
    3. Avoid: Don’t start with a blank page. Use Info-Tech’s business architecture models for sample value streams.
    Input Output
    • Business strategy or goals
    • Financial statements
    • Info-Tech’s industry-specific business architecture
    • List of organizational specific value streams
    • Detailed value stream definition(s)
    Materials Participants
    • Whiteboard / Kanban Board
    • Reference Architecture Template – See your Account Representative for details
    • Other industry standard reference architecture models: BIZBOK, APQC, etc.
    • Info-Tech Archi Models
    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • CIO
    • Departmental Executives & Senior Managers

    See your Info-Tech Account Representative for access to the Reference Architecture Template

    Decompose the value stream into stages

    The stages of a value stream are usually action-oriented statements or verbs that make up the individual steps involved throughout the scope of the value stream, e.g. Place Order or Make Payment.

    Each value stream should have a trigger or starting point and an end result for a client or receiver.

    Decompose the value stream into stages

    There should be measurable value or benefits at each stage.
    These are key performance indicators (KPIs).
    Spot problem areas in the stream.

    Value streams usually fall into one of these categories:

    1. Fulfillment of products and services
    2. Manufacturing
    3. Software products
    4. Supporting value streams (procurement of supplies, product planning)

    Value stream and value stages examples

    Customer Acquisitions
    Identify Prospects > Contact Prospects > Verify Interests

    Sell Product
    Identify Options > Evaluate Options > Negotiate Price and Delivery Date > Place Order > Get Invoice > Make Payment

    Product Delivery
    Confirm Order > Plan Load > Receive Warehouse > Fill Order > Ship Order > Deliver Order > Invoice Customer

    Product Financing
    Initiate Loan Application > Decide on Application > Submit Documents > Review & Satisfy T&C > Finalize Documents > Conduct Funding > Conduct Funding Audits

    Product Release
    Ideate > Design > Build > Release

    Sell Product is a value stream, made up of value stages Identify options, Evaluate options, and so on.

    2.2 Decompose selected value streams

    1-3 hours

    Once we have a good understanding of our value streams, we need to decide which ones to focus on for deeper analysis and modeling, e.g. extend the business architecture to more detailed level 2 capabilities.

    Organization has goals and delivers products or services.

    1. Identify which value propositions are most important, e.g. be more productive or manage money more simply.
    2. Identify the value stream(s) that create the value proposition.
    3. Break the selected value stream into value stages.
    4. Analyze value stages for opportunities.

    Practical Guide to Agile Strategy Execution

    InputOutput
    • Value stream maps and definitions
    • Business goals, business model canvas, customer journey (value proposition) Selected value streams decomposed into value stages
    • Analysis of selected value streams for opportunities
    • Value stream map
    MaterialsParticipants
    • Whiteboard / Kanban Board
    • Reference Architecture Template – See your Account Representative for details
    • Other industry standard reference architecture models: BIZBOK, APQC, etc.
    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • CIO
    • Departmental Executives & Senior Managers

    Build your value stream one layer at a time to ensure clarity and comprehensiveness

    The first step of creating a value stream is defining it.

    • In this step, you create the parameters around the value stream and document them in a list format.
    • This allows you to know where each value stream starts and ends and the unique value it provides.

    The second step is the value stream mapping.

    • The majority of the mapping is done here where you break down your value stream into each of its component stages.
    • Analysis of these stages allows for a deeper understanding of the value stream.
    • The mapping layer connects the value stream to organizational capabilities.

    Define the value streams that are tied to your strategic goals and document them in a list

    Title

    • Create a title for your value stream that indicates the value it achieves.
    • Ensure your title is clear and will be understood the same way across the organization.
    • The common naming convention for value streams is to use nouns, e.g. product purchase.

    Scope

    • Determine the scope of your value stream by defining the trigger to start the value stream and final value delivered to end the value stream.
    • Be precise with your trigger to ensure you do not mistakenly include actions that would not trigger your value stream.
    • A useful tip is creating a decision tree and outlining the path that results in your trigger.

    Objectives

    • Determine the objectives of the value stream by highlighting the outcome it delivers.
    • Identify the desired outcomes of the value stream from the perspective of your organization.

    Example Value Streams List

    Title Scope Objectives
    Sell Product From option identification to payment Revenue Growth

    Create a value stream map

    A Decompose the Value Stream Into Stages B Add the Customer Perspective
    • Determine the different stages that comprise the value stream.
    • Place the stages in the correct order.
    • Outline the likely sentiment and meaningful needs of the customer at each value stage.
    C Add the Expected Outcome D Define the Entry and Exit Criteria
    • Define the desired outcome of each stage from the perspective of the organization.
    • Define both the entry and exit criteria for each stage.
    • Note that the entry criteria of the first stage is what triggers the value stream.
    E Outline the Metrics F Assess the Stages
    • For each stage of the value stream, outline the metrics the organization can use to identify its ability to attain the desired outcome.
    • Assess how well each stage of the value stream is performing against its target metrics and use this as the basis to drill down into how/where improvements can be made.

    Decompose the value stream into its value stages

    The first step in creating a value stream map is breaking it up into its component stages.

    The stages of a value stream are usually action-oriented statements or verbs that make up the individual steps involved throughout the scope of the value stream.

    Illustration of decomposing value stream into its value stages

    The Benefit
    Segmenting your value stream into individual stages will give you a better understanding of the steps involved in creating value.

    Connect the stages of the value stream to a specific customer perspective

    Example of a sell product value stream

    The Benefit
    Adding the customer’s perspective will inform you of their priorities at each stage of the value stream.

    Connect the stages of the value stream to a desired outcome

    Example of a sell product value stream

    The Benefit
    Understanding the organization’s desired outcome at each stage of the value stream will help set objectives and establish metrics.

    Define the entry and exit criteria of each stage

    Example of entry and exit criteria for each stage

    The Benefit
    Establishing the entry and exit criteria for each stage will help you understand how the customer experience flows from one end of the stream to the other.

    Outline the key metric(s) for each stage

    Outline the key metrics for each stage

    The Benefit
    Setting metrics for each stage will facilitate the tracking of success and inform the business architecture practitioner of where investments should be made.

    Example value stream map: Sell Product

    Assess the stages of your value stream map to determine which capabilities to examine further

    To determine which specific business capabilities you should seek to assess and potentially refine, you must review performance toward target metrics at each stage of the value stream.

    Stages that are not performing to their targets should be examined further by assessing the capabilities that enable them.

    Value Stage Metric Description Metric Target Current Measure Meets Objective?
    Evaluate Options Number of Product Demonstrations 12,000/month 9,000/month No
    Identify Options Google Searches 100K/month 100K/month Yes
    Identify Options Product Mentions 1M/month 1M/month Yes
    Website Traffic (Hits)
    Average Deal Size
    Number of Deals
    Time to Complete an Order
    Percentage of Invoices Without Error
    Average Time to Acquire Payment in Full

    Determine the business capabilities that support the value stage corresponding with the failing metric

    Sell Product

    Identify Options > Evaluate Options > Negotiate Price and Delivery Date > Place Order > Get Invoice > Make Payment

    The value stage(s) that doesn’t meet its objective metrics should be examined further.

    • This is done through business capability mapping and assessment.
    • Starting at the highest level (level 0) view of a business, the business architecture practitioner must drill down into the lower level capabilities that support the specific value stage to diagnose/improve an issue.

    Info-Tech Insight
    In the absence of tangible metrics, you will have to make a qualitative judgement about which stage(s) of the value stream warrant further examination for problems and opportunities.

    Build business capability map

    Align supporting capabilities to priority activities.

    Business context Define value streams Build business capability map
    1.1 Select key stakeholders
    1.2 Collect and understand corporate goals
    2.1 Update or define value streams
    2.2 Decompose and analyze selected value stream
    3.1 Build Level 1 capability map
    3.2 Build Level 2 capability map
    3.3 Heatmap capability map
    3.4 Roadmap

    This step will walk you through the following activities:

    • Determine which business capabilities support value streams
    • Accelerate the process with an industry reference architecture
    • Validate the business capability map
    • Establish level 2 capability

    This step involves the following participants:

    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • CIO
    • Departmental Executives & Senior Managers

    Outcomes of this step

  • A validated level 1 business capability map
  • Level 2 capabilities for selected value stream(s)
  • Heatmapped business capability map
  • Business architecture initiatives roadmap
  • Develop a business capability map – level 1

    • Business architecture consists of a set of techniques to create multiple views of an organization; the primary view is known as a business capability map.
    • A business capability defines what a business does to enable value creation and achieve outcomes, rather than how. Business capabilities are business terms defined using descriptive nouns such as “Marketing” or “Research and Development.” They represent stable business functions, are unique and independent of each other, and typically will have a defined business outcome. Business capabilities should not be defined as organizational units and are typically longer lasting than organizational structures.
    • A business capability mapping process should begin at the highest-level view of an organization, the level 1, which presents the entire business on a page.
    • An effective method of organizing business capabilities is to split them into logical groupings or categories. At the highest level, capabilities are either “core” (customer-facing functions) or “enabling” (supporting functions).
    • As a best practice, Info-Tech recommends dividing business capabilities into the categories illustrated to the right.

    The Business Capability Map is the primary visual representation of the organization’s key abilities or services that are delivered to stakeholders. This model forms the basis of strategic planning discussions.

    Example of a business capability map

    Example business capability map – Higher Education

    A business capability map can be thought of as a visual representation of your organization’s business capabilities and represents a view of what your data program must support.

    Validate your business capability map with the right stakeholders, including your executive team, business unit leaders, and/or other key stakeholders.

    Example business capability map for: Higher Education

    Example business capability map for higher education

    Example business capability map – Local Government

    A business capability map can be thought of as a visual representation of your organization’s business capabilities and represents a view of what your data program must support.

    Validate your business capability map with the right stakeholders, including your executive team, business unit leaders, and/or other key stakeholders.

    Example business capability map for: Local Government

    Example business capability map for local government

    Map capabilities to value stage

    Example of a value stage

    Source: Lambert, “Practical Guide to Agile Strategy Execution”

    3.1 Build level 1 business capability map

    1-3 hours

    1. Analyze the value streams to identify and describe the organization’s capabilities that support them. This stage requires a good understanding of the business and will be a critical foundation for the business capability map. Use the reference business architecture’s business capability map for your industry for examples of level 1 and 2 business capabilities and the capability map template to work in.
    2. Avoid:
      1. Don’t repeat capabilities. Capabilities are typically mutually exclusive activities.
      2. Don’t include temporary initiatives. Capabilities should be stable over time. The people, processes, and technologies that support capabilities will change continuously.

    Ensure you engage with the right stakeholders:

    Don’t waste your efforts building an inaccurate depiction of the business: The exercise of identifying capabilities for an organization is very introspective and requires deep analysis.

    It is challenging to develop a common language that everyone will understand and be able to apply. Invest in the time to ensure the right stakeholders are brought into the fold and bring their business area expertise and understanding to the table.

    InputOutput
    • Existing business capability maps
    • Value stream map
    • Info-Tech’s industry-specific business architecture
    • Level 1 business capability map for enterprise
    MaterialsParticipants
    • Whiteboard
    • Reference Architecture Template – See your Account Representative for details
    • Other industry standard reference architecture models: BIZBOK, APQC, etc.
    • Archi Models
    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • CIO
    • Departmental Executives & Senior Managers

    Prioritize one value stream and build a business architecture to level 2 capabilities

    Prioritize your innovation objectives and business goals, and identify a value stream to transform.

    Align the innovation goals and business objectives of your organization to your value streams (the critical actions that take place within your organization to add value to a customer).
    Prioritize a value stream to transform based on the number of priorities aligned to a value stream and/or the business value (e.g. revenue, EBITDA earnings, competitive differentiation, or cost efficiency).
    Working alongside a business or enterprise architect, build a reference architecture for the prioritized value stream up to level 2.

    Example of a value stream to business architecture level 2 capabilities

    Info-Tech Insight
    To produce maximum impact, focus on value streams that provide two-thirds of your enterprise value (EBITDA earnings).

    From level 1 to level 2 business capabilities

    Example moving from level 1 to level 2 business capabilities

    3.2 Build level 2 business capability map

    1-3 hours

    It is only at level 2 and further that we can pinpoint the business capabilities – the exact resources, whether applications or data or processes – that we need to focus on to realize improvements in the organization’s performance and customer experience.

    1. Gather industry reference models and any existing business capability maps.
    2. For the selected value stream, further break down its level 1 business capabilities into level 2 capabilities.
    3. You can often represent the business capabilities on a single page, providing a holistic visual for decision makers.
    4. Use meaningful names for business capabilities so that planners, stakeholders, and subject matter experts can easily search the map.
    InputOutput
    • Existing business capability maps
    • Value stream map
    • Info-Tech’s industry-specific business architecture
    • Level 1 business capability map
    • Level 2 Business Capability Map for selected Value Stream
    MaterialsParticipants
    • Whiteboard
    • Reference Architecture Template – See your Account Representative for details.
    • Other industry standard reference architecture models: BIZBOK, APQC, etc.
    • Archi Models
    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • CIO
    • Departmental Executives & Senior Managers

    Download: See your Account Representative for access to Info-Tech’s Reference Architecture Template

    3.3 Heatmap business capability map

    1-3 hours

    Determine the organization’s key capabilities.

    1. Determine cost advantage creators. If your organization has a cost advantage over competitors, the capabilities that enable it should be identified and prioritized. Highlight these capabilities and prioritize the programs that support them.
    2. Determine competitive advantage creators. If your organization does not have a cost advantage over competitors, determine if it can deliver differentiated end-customer experiences. Once you have identified the competitive advantages, understand which capabilities enable them. These capabilities are critical to the success of the organization and should be highly supported.
    3. Define key future state capabilities. In addition to the current and competitive advantage creators, the organization may have the intention to enhance new capabilities. Discuss and select the capabilities that will help drive the attainment of future goals.
    4. Assess how well information, applications, and processes support capabilities.
    InputOutput
    • Business capability map
    • Cost advantage creators
    • Competitive advantage creators
    • IT and business assessments
    • Key business capabilities
    • Business process review
    • Information assessment
    • Application assessment
    • List of IT implications
    MaterialsParticipants
    • Whiteboard
    • Reference Architecture Template – See your Account Representative for details.
    • Other industry standard reference architecture models: BIZBOK, APQC, etc.
    • Archi Models
    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • CIO
    • Departmental Executives & Senior Managers

    Download: See your Account Representative for access to Info-Tech’s Reference Architecture Template

    Business capability map: Education

    Illustrative example of a business capability map for education

    Define key capabilities

    Illustrative example of Define key capabilities

    Note: Illustrative Example

    Business process review

    Illustrative example of a business process review

    Note: Illustrative Example

    Information assessment

     Illustrative example of an Information assessment

    Note: Illustrative Example

    Application assessment

     Illustrative example of an Application assessment

    Note: Illustrative Example

    MoSCoW analysis for business capabilities

     Illustrative example of a MoSCoW analysis for business capabilities

    Note: Illustrative Example

    Ranked list of IT implications

    MoSCoW Rank IT Implication Value Stream Impacted Comments/Actions
    M [Implication] [Value Stream]
    M [Implication] [Value Stream]
    M [Implication] [Value Stream]
    S [Implication] [Value Stream]
    S [Implication] [Value Stream]
    S [Implication] [Value Stream]
    C [Implication] [Value Stream]
    C [Implication] [Value Stream]
    C [Implication] [Value Stream]
    W [Implication] [Value Stream]
    W [Implication] [Value Stream]
    W [Implication] [Value Stream]

    3.4 Roadmap business architecture initiatives

    1-3 hours

    Unify the organization’s perspective on how it creates value.

    1. Write a short description of the value stream that includes a statement about the value provided and a clear start and end for the value stream. Validate the accuracy of the descriptions with your key stakeholders.
    2. Consider:
      1. How does the organization deliver those benefits?
      2. How does the customer receive the benefits?
      3. What is the scope of your value stream? What will trigger the stream to start and what will the final value be?
    3. Don’t start with a blank page. Use Info-Tech’s business architecture models for sample value streams.
    InputOutput
    • Existing business capability maps
    • Value stream map
    • Info-Tech’s industry-specific business architecture
    • Level 1 business capability map
    • Heatmapped business capability map
    MaterialsParticipants
    • Whiteboard
    • Reference Architecture Template – See your Account Representative for details.
    • Other industry standard reference architecture models: BIZBOK, APQC, etc.
    • Archi Models
    • Enterprise/Business Architect
    • Business Analysts
    • Business Unit Leads
    • CIO
    • Departmental Executives & Senior Managers

    Download: See your Account Representative for access to Info-Tech’s Reference Architecture Template

    Example: Business architecture deliverables

    Enterprise Architecture Domain Architectural View Selection
    Business Architecture Business strategy map Required
    Business Architecture Business model canvas Optional
    Business Architecture Value streams Required
    Business Architecture Business capability map Not Used
    Business Architecture Business process flows
    Business Architecture Service portfolio
    Data Architecture Conceptual data model
    Data Architecture Logical data model
    Data Architecture Physical data model
    Data Architecture Data flow diagram
    Data Architecture Data lineage diagram

    Tools and templates to compile and communicate your business architecture work

    The Industry Business Reference Architecture Template for your industry is a place for you to collect all of the activity outputs and outcomes you’ve completed for use in next-steps.

    Download the Industry Business Reference Architecture Template for your industry

    Info-Tech offers various levels of support to best suit your needs

    DIY Toolkit Guided Implementation Workshop Consulting
    "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful." "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track." "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place." "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

    Diagnostics and consistent frameworks are used throughout all four options

    Research Contributors and Experts

    Name Role Organization
    Ibrahim Abdel-Kader Research Analyst, Data & Analytics Info-Tech Research Group
    Ben Abrishami-Shirazi Technical Counselor, Enterprise Architecture Info-Tech Research Group
    Andrew Bailey Consulting, Manager Info-Tech Research Group
    Dana Dahar Research & Advisory Director, CIO / Digital Business Strategy Info-Tech Research Group
    Larry Fretz VP Info-Tech Research Group
    Shibly Hamidur Enterprise Architect Toronto Transit Commission (TTC)
    Rahul Jaiswal Principal Research Director, Industry Info-Tech Research Group
    John Kemp Executive Counselor, Executive Services Info-Tech Research Group
    Gerald Khoury Senior Executive Advisor Info-Tech Research Group
    Igor Ikonnikov Principal Advisory Director, Data & Analytics Info-Tech Research Group
    Daniel Lambert VP Benchmark Consulting
    Milena Litoiu Principal Research Director, Enterprise Architecture Info-Tech Research Group
    Andy Neill AVP Data & Analytics, Chief Enterprise Architect Info-Tech Research Group
    Rajesh Parab Research Director, Data & Analytics Info-Tech Research Group
    Rick Pittman VP, Research Info-Tech Research Group
    Irina Sedenko Research Director, Data & Analytics Info-Tech Research Group

    Bibliography

    Andriole, Steve. “Why No One Understands Enterprise Architecture & Why Technology Abstractions Always Fail.” Forbes, 18 September 2020. Web.

    “APQC Process Classification Framework (PCF) – Retail.” American Productivity & Quality Center, 9 January 2019. Web.

    Brose, Cari. “Who’s on First? Architecture Roles and Responsibilities in SAFe.” Business Architecture Guild, 9 March 2017. Web.

    Burlton, Roger, Jim Ryne, and Daniel St. George. “Value Streams and Business Processes: The Business Architecture Perspective.” Business Architecture Guild, December 2019. Web.

    “Business Architecture: An overview of the business architecture professional.” Capstera, 5 January 2022. Web.

    Business Architecture Guild. “What is Business Architecture?” Business Analyst Mentor, 18 November 2022. Web.

    “Business Architecture Overview.” The Business Architecture Working Group of the Object Management Group (OMG), n.d. Web.

    “Delivering on your strategic vision.” The Business Architecture Guild, n.d. Web.

    Ecker, Grant. “Deploying business architecture.” LinkedIn, 11 November 2021. (Presentation)

    IRIS. “Retail Business Architecture Framework and Examples.” IRIS Business Architect, n.d. Web.

    IRIS. “What Is Business Architecture?” IRIS Business Architect, 8 May 2014. Web.

    IRIS. “Your Enterprise Architecture Practice Maturity 2021 Assessment.” IRIS Business Architect, 17 May 2021. Web.

    Khuen, Whynde. “How Business Architecture Breaks Down and Bridges Silos.” Biz Arch Mastery, January 2020. Web.

    Lambert, Daniel. “Practical Guide to Agile Strategy Execution.” 18 February 2020.

    Lankhorst, Marc, and Bernd Ihnen. “Mapping the BIZBOK Metamodel to the ArchiMate Language.” Bizzdesign, 2 September 2021. Web.

    Ramias, Alan, and Andrew Spanyi, “Demystifying the Relationship Between Processes and Capabilities: A Modest Proposal.” BPTrends, 2 February 2015. Web.

    Newman, Daniel. “NRF 2022: 4 Key Trends From This Year’s Big Show.” Forbes, 20 January 2022. Web.

    Research and Markets. “Define the Business Context Needed to Complete Strategic IT Initiatives: 2018 Blueprint.” Business Wire, 1 February 2018. Web.

    Sabanoglu, Tugba. “Retail market worldwide - Statistics & Facts.” Statista, 21 April 2022. Web.

    Spacey, John. “Capability vs Process.” Simplicable, 18 November 2016. Web.

    “The Definitive Guide to Business Capabilities.” LeanIX, n.d. Web.

    TOGAF 9. Version 9.1. The Open Group, 2011. Web.

    “What is Business Architecture?” STA Group, 2017. PDF.

    Whittie, Ralph. “The Business Architecture, Value Streams and Value Chains.” BA Institute, n.d. Web.

    Modernize Your Applications

    • Buy Link or Shortcode: {j2store}178|cart{/j2store}
    • member rating overall impact: 10.0/10 Overall Impact
    • member rating average dollars saved: After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve.
    • member rating average days saved: Read what our members are saying
    • Parent Category Name: Architecture & Strategy
    • Parent Category Link: /architecture-and-strategy
    • Application modernization is essential to stay competitive and productive in today’s digital environment. Your stakeholders have outlined their digital business goals that IT is expected to meet.
    • Your application portfolio cannot sufficiently support the flexibility and efficiency the business needs because of legacy challenges.
    • Your teams do not have a framework to illustrate, communicate, and justify the modernization effort and organizational changes in the language your stakeholders understand.

    Our Advice

    Critical Insight

    • Build your digital applications around continuous modernization. End-user needs, technology, business direction, and regulations rapidly change in today’s competitive and fast-paced industry. This reality will quickly turn your modern applications into shelfware. Build continuous modernization at the center of your digital application vision to keep up with evolving business, end-user, and IT needs.
    • Application modernization is organizational change management. If you build and modernize it, they may not come. The crux of successful application modernization is centered on the strategic, well-informed, and onboarded adoption of changes in key business areas, capabilities, and processes. Organizational change management must be front and center so that applications are fit for purpose and are something that end users want and need to use.
    • Business-IT collaboration is not optional. Application modernization will not be successful if your lines of business (LOBs) and IT are not working together. IT must empathize how LOBs operate and proactively support the underlying operational systems. LOBs must be accountable for all products leveraging modern technologies and be able to rationalize the technical feasibility of their digital application vision.

    Impact and Result

    • Establish the digital application vision. Gain a grounded understanding of the digital application construct and prioritize these attributes against your digital business goals.
    • Define your modernization approach. Obtain a thorough view of your business and technical complexities, risks, and impacts. Employ the right modernization techniques based on your organization’s change tolerance.
    • Build your roadmap. Clarify the organizational changes needed to support modernization and adoption of your digital applications.

    Modernize Your Applications Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to find out why you should strategically modernize your applications, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Set your vision

    Describe your application vision and set the right modernization expectations with your stakeholders.

    • Modernize Your Applications – Phase 1: Set Your Vision

    2. Identify your modernization opportunities

    Focus your modernization efforts on the business opportunities that your stakeholders care about.

    • Modernize Your Applications – Phase 2: Identify Your Modernization Opportunities

    3. Plan your modernization

    Describe your modernization initiatives and build your modernization tactical roadmap.

    • Modernize Your Applications – Phase 3: Plan Your Modernization
    [infographic]

    Workshop: Modernize Your Applications

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Set Your Vision

    The Purpose

    Discuss the goals of your application modernization initiatives

    Define your digital application vision and priorities

    List your modernization principles

    Key Benefits Achieved

    Clear application modernization objectives and high priority value items

    Your digital application vision and attributes

    Key principles that will guide your application modernization initiatives

    Activities

    1.1 State Your Objectives

    1.2 Characterize Your Digital Application

    1.3 Define Your Modernization Principles

    Outputs

    Application modernization objectives

    Digital application vision and attributes definitions

    List of application modernization principles and guidelines

    2 Identify Your Modernization Opportunities

    The Purpose

    Identify the value streams and business capabilities that will benefit the most from application modernization

    Conduct a change tolerance assessment

    Build your modernization strategic roadmap

    Key Benefits Achieved

    Understanding of the value delivery improvements modernization can bring

    Recognizing the flexibility and tolerance of your organization to adopt changes

    Select an approach that best fits your organization’s goals and capacity

    Activities

    2.1 Identify the Opportunities

    2.2 Define Your Modernization Approach

    Outputs

    Value streams and business capabilities that are ideal modernization opportunities

    Your modernization strategic roadmap based on your change tolerance and modernization approach

    3 Plan Your Modernization

    The Purpose

    Identify the most appropriate modernization technique and the scope of changes to implement your techniques

    Develop an actionable tactical roadmap to complete your modernization initiatives

    Key Benefits Achieved

    Clear understanding of what must be changed to the organization and application considering your change tolerance

    An achievable modernization plan

    Activities

    3.1 Shortlist Your Modernization Techniques

    3.2 Roadmap Your Modernization Initiatives

    Outputs

    Scope of your application modernization initiatives

    Your modernization tactical roadmap

    AI Trends 2023

    • Buy Link or Shortcode: {j2store}207|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Business Intelligence Strategy
    • Parent Category Link: /business-intelligence-strategy

    As AI technologies are constantly evolving, organizations are looking for AI trends and research developments to understand the future applications of AI in their industries.

    Our Advice

    Critical Insight

    • Understanding trends and the focus of current and future AI research helps to define how AI will drive an organization’s new strategic opportunities.
    • Understanding the potential application of AI and its promise can help plan the future investments in AI-powered technologies and systems.

    Impact and Result

    Understanding AI trends and developments enables an organization’s competitive advantage.

    AI Trends 2023 Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. AI Trends 2023 – An overview of trends that will continue to drive AI innovation.

    • AI Trends Report 2023
    [infographic]

    Further reading

    AI Trends Report 2023

    The eight trends:

    1. Design for AI
    2. Event-Based Insights
    3. Synthetic Data
    4. Edge AI
    5. AI in Science and Engineering
    6. AI Reasoning
    7. Digital Twin
    8. Combinatorial Optimization
    Challenges that slowed the adoption of AI

    To overcome the challenges, enterprises adopted different strategies

    Data Readiness

    • Lack of unified systems and unified data
    • Data quality issues
    • Lack of the right data required for machine learning
    • Improve data management capabilities, including data governance and data initiatives
    • Create data catalogs
    • Document data and information architecture
    • Solve data-related problems including data quality, privacy, and ethics

    ML Operations Capabilities

    • Lack of tools, technologies, and methodologies to operationalize models created by data scientists
    • Increase availability of cloud platforms, tools, and capabilities
    • Develop and grow machine learning operations (MLOps) tools, platforms, and methodologies to enable model operationalizing and monitoring in production

    Understanding of AI Role and Its Business Value

    • Lack of understanding of AI use cases – how AI/ML can be applied to solve specific business problems
    • Lack of understanding how to define the business value of AI investments
    • Identify AI C-suite toolkits (for example, Empowering AI Leadership from the World Economic Forum, 2022)
    • Document industry use cases
    • Use frameworks and tools to define business value for AI investments

    Design for AI

    Sustainable AI system design needs to consider several aspects: the business application of the system, data, software and hardware, governance, privacy, and security.

    It is important to define from the beginning how AI will be used by and for the application to clearly articulate business value, manage expectations, and set goals for the implementation.

    Design for AI will change how we store and manage data and how we approach the use of data for development and operation of AI systems.

    An AI system design approach should cover all stages of AI lifecycle, from design to maintenance. It should also support and enable iterative development of an AI system.

    To take advantage of different tools and technologies for AI system development, deployment, and monitoring, the design of an AI system should consider software and hardware needs and design for seamless and efficient integrations of all components of the system and with other existing systems within the enterprise.

    AI in Science and Engineering

    AI helps sequence genomes to identify variants in a person’s DNA that indicate genetic disorders. It allows researchers to model and calculate complicated physics processes, to forecast the genesis of the universe’s structure, and to understand planet ecosystem to help advance the climate research. AI drives advances in drug discovery and can assist with molecule synthesis and molecular property identification.

    AI finds application in all areas of science and engineering. The role of AI in science will grow and allow scientists to innovate faster.

    AI will further contribute to scientific understanding by assisting scientists in deriving new insights, generating new ideas and connections, generalizing scientific concepts, and transferring them between areas of scientific research.

    Using synthetic data and combining physical and machine learning models and other advances of AI/ML – such as graphs, use of unstructured data (language models), and computer vision – will accelerate the use of AI in science and engineering.

    Event- and Scenario-Driven AI

    AI-driven signal-gathering systems analyze a continuous stream of data to generate insights and predictions that enable strategic decision modeling and scenario planning by providing understanding of how and what areas of business might be impacted by certain events.

    AI enables the scenario-based approach to drive insights through pattern identification in addition to familiar pattern recognition, helping to understand how events are related.

    A system with anticipatory capabilities requires an event-driven architecture that enables gathering and analyzing different types of data (text, video, images) across multiple channels (social media, transactional systems, news feeds, etc.) for event-driven and event-sequencing modeling.

    ML simulation-based training of the model using advanced techniques under the umbrella of Reinforcement Learning in conjunction with statistically robust Bayesian probabilistic framework will aid in setting up future trends in AI.

    AI Reasoning

    Most of the applications of machine learning and AI today is about predicting future behaviors based on historical data and past behaviors. We can predict what product the customer would most likely buy or the price of a house when it goes on sale.

    Most of the current algorithms use the correlation between different parameters to make a prediction, for example, the correlation between the event and the outcome can look like “When X occurs, we can predict that Y will occur.” This, however, does not translate into “Y occurred because of X.”

    The development of a causal AI that uses causal inference to reason and identify the root cause and the causal relationships between variables without mistaking correlation and causation is still in its early stages but rapidly evolving.

    Some of the algorithms that the researchers are working with are casual graph models and algorithms that are at the intersection of causal inference with decision making and reinforcement learning (Causal Artificial Intelligence Lab, 2022).

    Synthetic Data

    Synthetic data is artificially generated data that mimics the structure of real-life data. It should also have the same mathematical and statistical properties as the real-world data that it is created to replicate.

    Synthetic data is used to train machine learning models when there is not enough real data or the existing data does not meet specific needs. It allows users to remove contextual bias from data sets containing personal data, prevent privacy concerns, and ensure compliance with privacy laws and regulations.

    Another application of synthetic data is solving data-sharing challenges.

    Researchers learned that quite often synthetic data sets outperform real-world data. Recently, a team of researchers at MIT built a synthetic data set of 150,000 video clips capturing human actions and used that data set to train the model. The researchers found that “the synthetically trained models performed even better than models trained on real data for videos that have fewer background objects” (MIT News Office, 2022).

    Today, synthetic data is used in language systems, in training self-driving cars, in improving fraud detection, and in clinical research, just to name a few examples.

    Synthetic data opens the doors for innovation across all industries and applications of AI by enabling access to data for any scenario and technology and business needs.

    Digital Twins

    Digital twins (DT) are virtual replicas of physical objects, devices, people, places, processes, and systems. In Manufacturing, almost every product and manufacturing process can have a complete digital replica of itself thanks to IoT, streaming data, and cheap cloud storage.

    All this data has allowed for complex simulations of, for example, how a piece of equipment will perform over time to predict future failures before they happen, reducing costly maintenance and extending equipment lifetime.

    In addition to predictive maintenance, DT and AI technologies have enabled organizations to design and digitally test complex equipment such as aircraft engines, trains, offshore oil platforms, and wind turbines before physically manufacturing them. This helps to improve product and process quality, manufacturing efficiency, and costs. DT technology also finds applications in architecture, construction, energy, infrastructure industries, and even retail.

    Digital twins combined with the metaverse provide a collaborative and interactive environment with immersive experience and real-time physics capabilities (as an example, Siemens presented an Immersive Digital Twin of a Plant at the Collision 2022 conference).

    Future trends include enabling autonomous behavior of a DT. An advanced DT can replicate itself as it moves into several devices, hence requiring the autonomous property. Such autonomous behavior of the DT will in turn influence the growth and further advancement of AI.

    Edge AI

    A simple definition for edge AI: A combination of edge computing and artificial intelligence, it enables the deployment of AI applications in devices of the physical world, in the field, where the data is located, such as IoT devices, devices on the manufacturing floor, healthcare devices, or a self-driving car.

    Edge AI integrates AI into edge computing devices for quicker and improved data processing and smart automation.

    The main benefits of edge AI include:

    • Real-time data processing capabilities to reduce latency and enable near real-time analytics and insights.
    • Reduced cost and bandwidth requirements as there is no need to transfer data to the cloud for computing.
    • Increased data security as the data is processed locally, on the device, reducing the risk of loss of sensitive data.
    • Improved automation by training machines to perform automated tasks.

    Edge AI is already used in a variety of applications and use cases including computer vision, geospatial intelligence, object detection, drones, and health monitoring devices.

    Combinatorial Optimization

    “Combinatorial optimization is a subfield of mathematical optimization that consists of finding an optimal object from a finite set of objects” (Wikipedia, retrieved December 2022).

    Applications of combinatorial optimization include:

    • Supply chain optimization
    • Scheduling and logistics, for example, vehicle routing where the trucks are making stops for pickup and deliveries
    • Operations optimization

    Classical combinatorial optimization (CO) techniques were widely used in operations research and played a major role in earlier developments of AI.

    The introduction of deep learning algorithms in recent years allowed researchers to combine neural network and conventional optimization algorithms; for example, incorporating neural combinatorial optimization algorithms in the conventional optimization framework. Researchers confirmed that certain combinations of these frameworks and algorithms can provide significant performance improvements.

    The research in this space continues and we look forward to learning how machine learning and AI (backtracking algorithms, reinforcement learning, deep learning, graph attention networks, and others) will be used for solving challenging combinatorial and decision-making problems.

    References

    “AI Can Power Scenario Planning for Real-Time Strategic Insights.” The Wall Street Journal, CFO Journal, content by Deloitte, 7 June 2021. Accessed 11 Dec. 2022.
    Ali Fdal, Omar. “Synthetic Data: 4 Use Cases in Modern Enterprises.” DATAVERSITY, 5 May 2022. Accessed
    11 Dec. 2022.
    Andrews, Gerard. “What Is Synthetic Data?” NVIDIA, 8 June 2021. Accessed 11 Dec. 2022.
    Bareinboim, Elias. “Causal Reinforcement Learning.” Causal AI, 2020. Accessed 11 Dec. 2022.
    Bengio, Yoshua, Andrea Lodi, and Antoine Prouvost. “Machine learning for combinatorial optimization: A methodological tour d’horizon.” European Journal of Operational Research, vol. 290, no. 2, 2021, pp. 405-421, https://doi.org/10.1016/j.ejor.2020.07.063. Accessed 11 Dec. 2022.
    Benjamins, Richard. “Four design principles for developing sustainable AI applications.” Telefónica S.A., 10 Sept. 2018. Accessed on 11 Dec. 2022.
    Blades, Robin. “AI Generates Hypotheses Human Scientists Have Not Thought Of.” Scientific American, 28 October 2021. Accessed 11 Dec. 2022.
    “Combinatorial Optimization.” Wikipedia article, Accessed 11 Dec. 2022.
    Cronholm, Stefan, and Hannes Göbel. “Design Principles for Human-Centred Artificial Intelligence.” University of Borås, Sweden, 11 Aug. 2022. Accessed on 11 Dec. 2022
    Devaux, Elise. “Types of synthetic data and 4 real-life examples.” Statice, 29 May 2022. Accessed 11 Dec. 2022.
    Emmental, Russell. “A Guide to Causal AI.” ITBriefcase, 30 March 2022. Accessed 11 Dec. 2022.
    “Empowering AI Leadership: AI C-Suite Toolkit.” World Economic Forum, 12 Jan. 2022. Accessed 11 Dec 2022.
    Falk, Dan. “How Artificial Intelligence Is Changing Science.” Quanta Magazine, 11 March 2019. Accessed 11 Dec. 2022.
    Fritschle, Matthew J. “The Principles of Designing AI for Humans.” Aumcore, 17 Aug. 2018. Accessed 8 Dec. 2022.
    Garmendia, Andoni I., et al. Neural Combinatorial Optimization: a New Player in the Field.” IEEE, arXiv:2205.01356v1, 3 May 2022. Accessed 11 Dec. 2022.
    Gülen, Kerem. “AI Is Revolutionizing Every Field and Science is no Exception.” Dataconomy Media GmbH, 9 Nov. 9, 2022. Accessed 11 Dec. 2022
    Krenn, Mario, et al. “On scientific understanding with artificial intelligence.” Nature Reviews Physics, vol. 4, 11 Oct. 2022, pp. 761–769. https://doi.org/10.1038/s42254-022-00518-3. Accessed 11 Dec. 2022.
    Laboratory for Information and Decision Systems. “The real promise of synthetic data.” MIT News, 16 Oct. 2020. Accessed 11 Dec. 2022.
    Lecca, Paola. “Machine Learning for Causal Inference in Biological Networks: Perspectives of This Challenge.” Frontiers, 22 Sept. 2021. Accessed 11 Dec. 2022. Mirabella, Lucia. “Digital Twin x Metaverse: real and virtual made easy.” Siemens presentation at Collision 2022 conference, Toronto, Ontario. Accessed 11 Dec. 2022. Mitchum, Rob, and Louise Lerner. “How AI could change science.” University of Chicago News, 1 Oct. 2019. Accessed 11 Dec. 2022.
    Okeke, Franklin. “The benefits of edge AI.” TechRepublic, 22 Sept. 2022, Accessed 11 Dec. 2022.
    Perlmutter, Nathan. “Machine Learning and Combinatorial Optimization Problems.” Crater Labs, 31 July 31, 2019. Accessed 11 Dec. 2022.
    Sampson, Ovetta. “Design Principles for a New AI World.” UX Magazine, 6 Jan. 2022. Accessed 11 Dec. 2022.
    Sgaier, Sema K., Vincent Huang, and Grace Charles. “The Case for Causal AI.” Stanford Social Innovation Review, Summer 2020. Accessed 11 Dec. 2022.
    “Synthetic Data.” Wikipedia article, Accessed 11 Dec. 2022.
    Take, Marius, et al. “Software Design Patterns for AI-Systems.” EMISA Workshop 2021, CEUR-WS.org, Proceedings 30. Accessed 11 Dec. 2022.
    Toews, Rob. “Synthetic Data Is About To Transform Artificial Intelligence.” Forbes, 12 June 2022. Accessed
    11 Dec. 2022.
    Zewe, Adam. “In machine learning, synthetic data can offer real performance improvements.” MIT News Office, 3 Nov. 2022. Accessed 11 Dec. 2022.
    Zhang, Junzhe, and Elias Bareinboim. “Can Humans Be out of the Loop?” Technical Report, Department of Computer Science, Columbia University, NY, June 2022. Accessed 11 Dec. 2022.

    Contributors

    Irina Sedenko Anu Ganesh Amir Feizpour David Glazer Delina Ivanova

    Irina Sedenko

    Advisory Director

    Info-Tech

    Anu Ganesh

    Technical Counselor

    Info-Tech

    Amir Feizpour

    Co-Founder & CEO

    Aggregate Intellect Inc.

    David Glazer

    VP of Analytics

    Kroll

    Delina Ivanova

    Associate Director, Data & Analytics

    HelloFresh

    Usman Lakhani

    DevOps

    WeCloudData

    Digital Data Ethics

    • Download01-Title: Tech Trend Update: If Digital Ethics Then Data Equity
    • Download-01: Visit Link
    • member rating overall impact: 9/10
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Innovation
    • Parent Category Link: /innovation

    In the past two years, we've seen that we need quick technology solutions for acute issues. We quickly moved to homeworking and then to a hybrid form. We promptly moved many of our offline habits online.

    That necessitated a boost in data collection from us towards our customers and employees, and business partners.
    Are you sure how to approach this structurally? What is the right thing to do?

    Impact and Results

    • When you partner with another company, set clear expectations
    • When you are building your custom solution, invite constructive criticism
    • When you present yourself as the authority, consider the most vulnerable in the relationship

    innovation

    Manage End-User Devices

    • Buy Link or Shortcode: {j2store}307|cart{/j2store}
    • member rating overall impact: 10.0/10 Overall Impact
    • member rating average dollars saved: $45,499 Average $ Saved
    • member rating average days saved: 10 Average Days Saved
    • Parent Category Name: End-User Computing Devices
    • Parent Category Link: /end-user-computing-devices
    • Desktop and mobile device management teams use separate tools and different processes.
    • People at all levels of IT are involved in device management.
    • Vendors are pushing unified endpoint management (UEM) products, and teams struggling with device management are hoping that UEM is their savior.
    • The number and variety of devices will only increase with the continued advance of mobility and emergence of the Internet of Things (IoT).

    Our Advice

    Critical Insight

    • Many problems can be solved by fixing roles, responsibilities, and process. Standardize so you can optimize.
    • UEM is not a silver bullet. Your current solution can image computers in less than 4 hours if you use lean images.
    • Done with, not done to. Getting input from the business will improve adoption, avoid frustration, and save everyone time.

    Impact and Result

    • Define the benefits that you want to achieve and optimize based on those benefits.
    • Take an evolutionary, rather than revolutionary, approach to merging end-user support teams. Process and tool unity comes first.
    • Define the roles and responsibilities involved in end-user device management, and create a training plan to ensure everyone can execute their responsibilities.
    • Stop using device management practices from the era of Windows XP. Create a plan for lean images and app packages.

    Manage End-User Devices Research & Tools

    Start here – read the Executive Brief

    Read our concise Executive Brief to find out why you should optimize end-user device management, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Identify the business and IT benefits of optimizing endpoint management

    Get your desktop and mobile device support teams out of firefighting mode by identifying the real problem.

    • Manage End-User Devices – Phase 1: Identify the Business and IT Benefits
    • End-User Device Management Standard Operating Procedure
    • End-User Device Management Executive Presentation

    2. Improve supporting teams and processes

    Improve the day-to-day operations of your desktop and mobile device support teams through role definition, training, and process standardization.

    • Manage End-User Devices – Phase 2: Improve Supporting Teams and Processes
    • End-User Device Management Workflow Library (Visio)
    • End-User Device Management Workflow Library (PDF)

    3. Improve supporting technologies

    Stop using management tools and techniques from the Windows XP era. Save yourself, and your technicians, from needless pain.

    • Manage End-User Devices – Phase 3: Improve Supporting Technologies
    [infographic]

    Workshop: Manage End-User Devices

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Identify the Business and IT Benefits of Optimizing End-User Device Management

    The Purpose

    Identify how unified endpoint management (UEM) can improve the lives of the end user and of IT.

    Key Benefits Achieved

    Cutting through the vendor hype and aligning with business needs.

    Activities

    1.1 Identify benefits you can provide to stakeholders.

    1.2 Identify business and IT goals in order to prioritize benefits.

    1.3 Identify how to achieve benefits.

    1.4 Define goals based on desired benefits.

    Outputs

    Executive presentation

    2 Improve the Teams and Processes That Support End-User Device Management

    The Purpose

    Ensure that your teams have a consistent approach to end-user device management.

    Key Benefits Achieved

    Developed a standard approach to roles and responsibilities, to training, and to device management processes.

    Activities

    2.1 Align roles to your environment.

    2.2 Assign architect-, engineer-, and administrator-level responsibilities.

    2.3 Rationalize your responsibility matrix.

    2.4 Ensure you have the necessary skills.

    2.5 Define Tier 2 processes, including patch deployment, emergency patch deployment, device deployment, app deployment, and app packaging.

    Outputs

    List of roles involved in end-user device management

    Responsibility matrix for end-user device management

    End-user device management training plan

    End-user device management standard operating procedure

    Workflows and checklists of end-user device management processes

    3 Improve the Technologies That Support End-User Device Management

    The Purpose

    Modernize the toolset used by IT to manage end-user devices.

    Key Benefits Achieved

    Saving time and resources for many standard device management processes.

    Activities

    3.1 Define the core image for each device/OS.

    3.2 Define app packages.

    3.3 Gather action items for improving the support technologies.

    3.4 Create a roadmap for improving end-user device management.

    3.5 Create a communication plan for improving end-user device management.

    Outputs

    Core image outline

    Application package outline

    End-user device management roadmap

    End-user device management communication plan

    Manage Service Catalogs

    • Buy Link or Shortcode: {j2store}44|cart{/j2store}
    • Related Products: {j2store}44|crosssells{/j2store}
    • member rating overall impact: 9.0/10
    • member rating average dollars saved: $3,956
    • member rating average days saved: 24
    • Parent Category Name: Service Planning and Architecture
    • Parent Category Link: /service-planning-and-architecture

    The challenge

    • Your business users may not be aware of the full scope of your services.
    • Typically service information is written in technical jargon. For business users, this means that the information will be tough to understand.
    • Without a service catalog, you have no agreement o what is available, so business will assume that everything is.

    Our advice

    Insight

    • Define your services from a user's or customer perspective.
      • When your service catalog contains too much information that does not apply to most users, they will not use it.
    • Separate the line-of-business services from enterprise services. It simplifies your documentation process and makes the service catalog more comfortable to use.

    Impact and results 

    • Our approach helps you organize your service catalog in a business-friendly way while keeping it manageable for IT.
    • And manageable also means that your service catalog remains a living document. You can update your service records easily.
    • Your service catalog forms a visible bridge between IT and the business. Improve IT's perception by communicating the benefits of the service catalog.

    The roadmap

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    Get started

    Our concise executive brief shows you why building a service catalog is a good idea for your company. We'll show you our methodology and the ways we can help you in handling this.

    Minimize the risks from attrition through an effective knowledge transfer process.

    Launch the initiative

    Our launch phase will walk you through the charter template, build help a balanced team, create your change message and communication plan to obtain buy-in from all your organization's stakeholders.

    • Design & Build a User-Facing Service Catalog – Phase 1: Launch the Project (ppt)
    • Service Catalog Project Charter (doc)

    Identify and define the enterprise services

    Group enterprise services which you offer to everyone in the company, logically together.

    • Design & Build a User-Facing Service Catalog – Phase 2: Identify and Define Enterprise Services (ppt)
    • Sample Enterprise Services (ppt)

    Identify and define your line-of-business (LOB) services

    These services apply only to one business line. Other business users should not see them in the catalog.

    • Design & Build a User-Facing Service Catalog – Phase 3: Identify and Define Line of Business Services (ppt)
    • Sample LOB Services – Industry Specific (ppt)
    • Sample LOB Services – Functional Group (ppt)

    Complete your services definition chart

    Complete this chart to allow the business to pick what services to include in the service catalog. It also allows you to extend the catalog with technical services by including IT-facing services. Of course, separated-out only for IT.

    • Design & Build a User-Facing Service Catalog – Phase 4: Complete Service Definitions (ppt)
    • Services Definition Chart (xls)

    Manage Poor Performance While Working From Home

    • Buy Link or Shortcode: {j2store}599|cart{/j2store}
    • member rating overall impact: 9.0/10 Overall Impact
    • member rating average dollars saved: $1,600 Average $ Saved
    • member rating average days saved: 18 Average Days Saved
    • Parent Category Name: Manage & Coach
    • Parent Category Link: /manage-coach
    • For many, emergency WFH comes with several new challenges such as additional childcare responsibilities, sudden changes in role expectations, and negative impacts on wellbeing. These new challenges, coupled with previously existing ones, can result in poor performance. Owing to the lack of physical presence and cues, managers may struggle to identify that an employee’s performance is suffering. Even after identifying poor performance, it can be difficult to address remotely when such conversations would ideally be held in person.

    Our Advice

    Critical Insight

    • Poor performance must be managed, despite the pandemic. Evaluating root causes of performance issues is more important than ever now that personal factors such as lack of childcare and eldercare for those working from home are complicating the issue.

    Impact and Result

    • Organizations need to have a clear process for improving performance for employees working remotely during the COVID-19 pandemic. Provide managers with resources to help them identify performance issues and uncover their root causes as part of addressing overall performance. This will allow managers to connect employees with the required support while working with them to improve performance.

    Manage Poor Performance While Working From Home Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Follow the remote performance improvement process

    Determine how managers can identify poor performance remotely and help them navigate the performance improvement process while working from home.

    • Manage Poor Performance While Working From Home Storyboard
    • Manage Poor Performance While Working From Home: Manager Guide
    • Manage Poor Performance While Working From Home: Infographic

    2. Clarify roles and leverage resources

    Clarify roles and responsibilities in the performance improvement process and tailor relevant resources.

    • Wellness and Working From Home
    [infographic]

    Further reading

    Manage Poor Performance While Working From Home

    Assess and improve remote work performance with our ready-to-use tools.

    Executive Summary

    McLean & Company Insight

    Poor performance must be managed, despite the pandemic. Evaluating root causes of performance issues is more important than ever now that personal factors such as lack of childcare and eldercare for those working from home are complicating the issue.

    Situation

    COVID-19 has led to a sudden shift to working from home (WFH), resulting in a 72% decline in in-office work (Ranosa, 2020). While these uncertain times have disrupted traditional work routines, employee performance remains critical, as it plays a role in determining how organizations recover. Managers must not turn a blind eye to performance issues but rather must act quickly to support employees who may be struggling.

    Complication

    For many, emergency WFH comes with several new challenges such as additional childcare responsibilities, sudden changes in role expectations, and negative impacts on wellbeing. These new challenges, coupled with previously existing ones, can result in poor performance. Owing to the lack of physical presence and cues, managers may struggle to identify that an employee’s performance is suffering. Even after identifying poor performance, it can be difficult to address remotely when such conversations would ideally be held in person.

    Solution

    Organizations need to have a clear process for improving performance for employees working remotely during the COVID-19 pandemic. Provide managers with resources to help them identify performance issues and uncover their root causes as part of addressing overall performance. This will allow managers to connect employees with the required support while working with them to improve performance.

    Manage Poor Performance While Working From Home is made up of the following resources:

    1

    Identify

    2

    Initiate

    3

    Deploy

    4

    a) Follow Up
    b) Decide
    Storyboard

    This storyboard is organized by the four steps of the performance improvement process: identify, initiate, deploy, and follow up/decide. These will appear on the left-hand side of the slides as a roadmap.

    The focus is on how HR can design the process for managing poor performance remotely and support managers through it while emergency WFH measures are in place. Key responsibilities, email templates, and relevant resources are included at the end.

    Adapt the process as necessary for your organization.

    Manager Guide

    The manager guide contains detailed advice for managers on navigating the process and focuses on the content of remote performance discussions.

    It consists of the following sections:

    • Identifying poor performance.
    • Conducting performance improvement discussions.
    • Uncovering and addressing root causes of poor performance.
    Manager Infographic

    The manager infographic illustrates the high-level steps of the performance improvement process for managers in a visually appealing and easily digestible manner.

    This can be used to easily outline the process, providing managers with a resource to quickly reference as they navigate the process with their direct reports.

    In this blueprint, “WFH” and “remote working” are used interchangeably.

    This blueprint will not cover the performance management framework; it is solely focused on managing performance issues.

    For information on adjusting the regular performance management process during the pandemic, see Performance Management for Emergency Work-From-Home.

    Identify how low performance is normally addressed

    A process for performance improvement is not akin to outlining the steps of a performance improvement plan (PIP). The PIP is a development tool used within a larger process for performance improvement. Guidance on how to structure and use a PIP will be provided later in this blueprint.

    Evaluate how low performance is usually brought to the attention of HR in a non-remote situation:
    • Do managers approach HR for an employee transfer or PIP without having prior performance conversations with the employee?
    • Do managers come to HR when they need support in developing an employee in order to meet expectations?
    • Do managers proactively reach out to HR to discuss appropriate L&D for staff who are struggling?
    • Do some departments engage with the process while others do not?
    Poor performance does not signal the immediate need to terminate an employee. Instead, managers should focus on helping the struggling employee to develop so that they may succeed.
    Evaluate how poor performance is determined:
    • Do managers use performance data or concrete examples?
    • Is it based on a subjective assessment by the manager?
    Keep in mind that “poor performance” now might look different than it did before the pandemic. Employees must be aware of the current expectations placed on them before they can be labeled as underperforming – and the performance expectations must be assessed to ensure they are realistic.

    For information on adjusting performance expectations during the pandemic, see Performance Management for Emergency Work-From-Home.

    The process for non-union and union employees will likely differ. Make sure your process for unionized employees aligns with collective agreements.

    Determine how managers can identify poor performance of staff working remotely

    1

    Identify

    2

    Initiate

    3

    Deploy

    4

    a) Follow Up
    b) Decide
    Identify: Determine how managers can identify poor performance.
    In person, it can be easy to see when an employee is struggling by glancing over at their desk and observing body language. In a remote situation, this can be more difficult, as it is easy to put on a brave face for the half-hour to one-hour check-in. Advise managers on how important frequent one-one-ones and open communication are in helping identify issues when they arise rather than when it’s too late.

    Managers must clearly document and communicate instances where employees aren’t meeting role expectations or are showing other key signs that they are not performing at the level expected of them.

    What to look for:
    • PM data/performance-related assessments
    • Continual absences
    • Decreased quality or quantity of output
    • Frequent excuses (e.g. repeated internet outages)
    • Lack of effort or follow-through
    • Missed deadlines
    • Poor communication or lack of responsiveness
    • Failure to improve
    It’s crucial to acknowledge an employee might have an “off week” or need time to adjust to working from home, which can be addressed with performance management techniques. Managers should move into the process for performance improvement when:
    • Performance fluctuates frequently or significantly.
    • Performance has dropped for an extended period of time.
    • Expectations are consistently not being met.

    While it’s important for managers to keep an eye out for decreased performance, discourage them from over-monitoring employees, as this can lead to a damaging environment of distrust.

    Support managers in initiating performance conversations and uncovering root causes

    1

    Identify

    2

    Initiate

    3

    Deploy

    4

    a) Follow Up
    b) Decide
    Initiate: Require that managers have several conversations about low performance with the employee.
    Before using more formal measures, ensure managers take responsibility for connecting with the employee to have an initial performance conversation where they will make the performance issue known and try to diagnose the root cause of the issue.

    Coach managers to recognize behaviors associated with the following performance inhibitors:

    Personal Factors

    Personal factors, usually outside the workplace, can affect an employee’s performance.

    Lack of clarity

    Employees must be clear on performance expectations before they can be labeled as a poor performer.

    Low motivation

    Lack of motivation to complete work can impact the quality of output and/or amount of work an employee is completing.

    Inability

    Resourcing, technology, organizational change, or lack of skills to do the job can all result in the inability of an employee to perform at their best.

    Poor people skills

    Problematic people skills, externally with clients or internally with colleagues, can affect an employee’s performance or the team’s engagement.

    Personal factors are a common performance inhibitor due to emergency WFH measures. The decreased divide between work and home life and the additional stresses of the pandemic can bring up new cases of poor performance or exacerbate existing ones. Remind managers that all potential root causes should still be investigated rather than assuming personal factors are the problem and emphasize that there can be more than one cause.

    Ensure managers continue to conduct frequent performance conversations

    Once an informal conversation has been initiated, the manager should schedule frequent one-on-one performance conversations (above and beyond performance management check-ins).

    1

    Identify

    2

    Initiate

    3

    Deploy

    4

    a) Follow Up
    b) Decide
    Explain to managers the purpose of these discussions is to:
    • Continue to probe for root causes.
    • Reinforce role expectations and performance targets.
    • Follow up on any improvements.
    • Address the performance issue and share relevant resources (e.g. HR or employee assistance program [EAP]).
    Given these conversations will be remote, require managers to:
    • Use video whenever possible to read physical cues and body language.
    • Bookend the conversation. Starting each meeting by setting the context for the discussion and finishing with the employee reiterating the key takeaways back will ensure there are no misunderstandings.
    • Document the conversation and share with HR. This provides evidence of the conversations and helps hold managers accountable.
    What is HR’s role? HR should ensure that the manager has had multiple conversations with the employee before moving to the next step. Furthermore, HR is responsible for ensuring manages are equipped to have the conversations through coaching, role-playing, etc.

    For more information on the content of these conversations or for material to leverage for training purposes, see Manage Poor Performance While Working From Home: Manager Guide.

    McLean & Company Insight

    Managers are there to be coaches, not therapists. Uncovering the root cause of poor performance will allow managers to pinpoint supports needed, either within their expertise (e.g. coaching, training, providing flexible hours) or by directing the employee to proper external resources such as an EAP.

    Help managers use formal performance improvement tools with remote workers

    1

    Identify

    2

    Initiate

    3

    Deploy

    4

    a) Follow Up
    b) Decide
    Deploy: Use performance improvement tools.
    If initial performance conversations were unsuccessful and performance does not improve, refer managers to performance improvement tools:
    • Suggest any other available support and resources they have not yet recommended (e.g. EAP).
    • Explore options for co-creation of a development plan to increase employee buy-in. If the manager has been diligent about clarifying role expectations, invite the employee to put together their own action plan for meeting performance goals. This can then be reviewed and finalized with the manager.
    • Have the manager use a formal PIP for development and to get the employee back on track. Review the development plan or PIP with the manager before they share it with the employee to ensure it is clear and has time bound, realistic goals for improvement.
    Using a PIP solely to avoid legal trouble and terminate employees isn’t true to its intended purpose. This is what progressive discipline is for.In the case of significant behavior problems, like breaking company rules or safety violations, the manager will likely need to move to progressive discipline. HR should advise managers on the appropriate process.

    When does the issue warrant progressive discipline? If the action needs to stop immediately, (e.g. threatening or inappropriate behavior) and/or as outlined in the collective agreement.

    Clarify remote PIP stages and best practices

    1

    Identify

    2

    Initiate

    3

    Deploy

    4

    a) Follow Up
    b) Decide
    Sample Stages:
    1. Written PIP
    • HR reviews and signs off on PIP
    • Manager holds meeting to provide employee with PIP
    • Employee reviews the PIP
    • Manager and employee provide e-signatures
    • Signed PIP is given to HR
    2. Possible Extension
    3. Final Notice
    • Manager provides employee with final notice if there has been no improvement in agreed time frame
    • Copy of signed final notice letter given to HR

    Who is involved?

    The manager runs the meeting with the employee. HR should act as a support by:

    • Ensuring the PIP is clear, aligned with the performance issue, and focused on development, prior to the meeting.
    • Pointing to resources and making themselves available prior to, during, and after the meeting.
      • When should HR be involved? HR should be present in the meeting if the manager has requested it or if the employee has approached HR beforehand with concerns about the manager. Keep in mind that if the employee sees HR has been unexpectedly invited to the video call, it could add extra stress for them.
    • Reviewing documentation and ensuring expectations and the action plan are reasonable and realistic.

    Determine the length of the PIP

    • The length of the initial PIP will often depend on the complexity of the employee’s role and how long it will reasonably take to see improvements. The minimum (before a potential extension) should be 30-60 days.
    • Ensure the action plan takes sustainment into account. Employees must be able to demonstrate improvement and sustain improved performance in order to successfully complete a PIP.

    Timing of delivery

    Help the manager determine when the PIP meeting will occur (what day, time of day). Take into account the schedule of the employee they will be meeting with (e.g. avoid scheduling right before an important client call).

    1

    Identify

    2

    Initiate

    3

    Deploy

    4

    a) Follow Up
    b) Decide

    Follow up: If the process escalated to step 3 and is successful.

    What does success look like? Performance improvement must be sustained after the PIP is completed. It’s not enough to simply meet performance improvement goals and expectations; the employee must continue to perform.

    Have the manager schedule a final PIP review with the employee. Use video, as this enables the employee and manager to read body language and minimize miscommunication/misinterpretation.

    • If performance expectations have been met, instruct managers to document this in the PIP, inform the employee they are off the PIP, and provide it to HR.

    The manager should also continue check-ins with the employee to ensure sustainment and as part of continued performance management.

    • Set a specific timeline, e.g. every two weeks or every month. Choose a cadence that works best for the manager and employee.

    OR

    Decide: Determine action steps if the process is unsuccessful.

    If at the end of step 3 performance has not sufficiently improved, the organization (HR and the manager) should either determine if the employee could/should be temporarily redeployed while the emergency WFH is still in place, if a permanent transfer to a role that is a better fit is an option, or if the employee should be let go.

    See the Complete Manual for COVID-19 Layoffs blueprint for information on layoffs in remote environments.

    Managers, HR, and employees all have a role to play in performance improvement

    Managers
    • Identify the outcomes the organization is looking for and clearly outline and communicate the expectations for the employee’s performance.
    • Diagnose root cause(s) of the performance issue.
    • Support employee through frequent conversations and feedback.
    • Coach for improved performance.
    • Visibly recognize and broadcast employee achievements.
    Employees
    • Have open and honest conversations with their manager, acknowledge their accountability, and be receptive to feedback.
    • Set performance goals to meet expectations of the role.
    • Prepare for frequent check-ins regarding improvement.
    • Seek support from HR as required.
    HR
    • Provide managers with a process, training, and support to improve employee performance.
    • Coach managers to ensure employees have been made aware of their role expectations and current performance and given specific recommendations on how to improve.
    • Reinforce the process for improving employee performance to ensure that adequate coaching conversations have taken place before the formal PIP.
    • Coach employees on how to approach their manager to discuss challenges in meeting expectations.

    HR should conduct checkpoints with both managers and employees in cases where a formal PIP was initiated to ensure the process for performance improvement is being followed and to support both parties in improving performance.

    Email templates

    Use the templates found on the next slides to draft communications to employees who are underperforming while working from home.

    Customize all templates with relevant information and use them as a guide to further tailor your communication to a specific employee.

    Customization Recommendations

    Review all slides and adjust the language or content as needed to suit the needs of the employee, the complexity of their role, and the performance issue.

    • The pencil icon to the left denotes slides requiring customization of the text. Customize text in grey font and be sure to convert all font to black when you are done.

    Included Templates

    1. Performance Discussion Follow-Up
    2. PIP Cover Letter

    This template is not a substitute for legal advice. Ensure you consult with your legal counsel, labor relations representative, and union representative to align with collective agreements and relevant legislation.

    Sample Performance Discussion Follow-Up

    Hello [name],

    Thank you for the commitment and eagerness in our meeting yesterday.

    I wanted to recap the conversation and expectations for the month of [insert month].

    As discussed, you have been advised about your recent [behavior, performance, attendance, policy, etc.] where you have demonstrated [state specific issue with detail of behavior/performance of concern]. As per our conversation, we’ll be working on improvement in this area in order to meet expectations set out for our employees.

    It is expected that employees [state expectations]. Please do not hesitate to reach out to me if there is further clarification needed or you if you have any questions or concerns. The management team and I are committed to helping you achieve these goals.

    We will do a formal check-in on your progress every [insert day] from [insert time] to review your progress. I will also be available for daily check-ins to support you on the right track. Additionally, you can book me in for desk-side coaching outside of my regular desk-side check-ins. If there is anything else I can do to help support you in hitting these goals, please let me know. Other resources we discussed that may be helpful in meeting these objectives are [summarize available support and resources]. By working together through this process, I have no doubt that you can be successful. I am here to provide support and assist you through this.

    If you’re unable to show improvements set out in our discussion by [date], we will proceed to a formal performance measure that will include a performance improvement plan. Please let me know if you have any questions or concerns; I am here to help.

    Please acknowledge this email and let me know if you have any questions.

    Thank you,

    PIP Cover Letter

    Hello [name] ,

    This is to confirm our meeting on [date] in which we discussed your performance to date and areas that need improvement. Please find the attached performance improvement plan, which contains a detailed action plan that we have agreed upon to help you meet role expectations over the next [XX days]. The aim of this plan is to provide you with a detailed outline of our performance expectations and provide you the opportunity to improve your performance, with our support.

    We will check in every [XX days] to review your progress. At the end of the [XX]-day period, we will review your performance against the role expectations set out in this performance improvement plan. If you don’t meet the performance requirements in the time allotted, further action and consequences will follow.

    Should you have any questions about the performance improvement plan or the process outlined in this document, please do not hesitate to discuss them with me.

    [Employee name], it is my personal objective to help you be a fully productive member of our team. By working together through this performance improvement plan, I have no doubt that you can be successful. I am here to provide support and assist you through the process. At this time, I would also like to remind you about the [additional resources available at your organization, for example, employee assistance program or HR].

    Please acknowledge this email and let me know if you have any questions.

    Thank you,

    Prepare and customize manager guide and resources

    Sample of Manage Poor Performance While Working From Home: Manager Guide. Manage Poor Performance While Working From Home: Manager Guide

    This tool for managers provides advice on navigating the process and focuses on the content of remote performance discussions.

    Sample of Set Meaningful Employee Performance Measures. Set Meaningful Employee Performance Measures

    See this blueprint for information on setting holistic measures to inspire employee performance.

    Sample of Manage Poor Performance While Working From Home: Infographic. Manage Poor Performance While Working From Home: Infographic

    This tool illustrates the high-level steps of the performance improvement process.

    Sample of Wellness and Working From Home: Infographic. Wellness and Working From Home: Infographic

    This tool highlights tips to manage physical and mental health while working from home.

    Sample of Build a Better Manager: Team Essentials. Build a Better Manager: Team Essentials

    See this solution set for more information on kick-starting the effectiveness of first-time IT managers with essential management skills.

    Sample of Leverage Agile Goal Setting for Improved Employee Engagement & Performance. Leverage Agile Goal Setting for Improved Employee Engagement & Performance

    See this blueprint for information on dodging the micromanaging foul and scoring with agile short-term goal setting.

    Bibliography

    Arringdale, Chris. “6 Tips For Managers Trying to Overcome Performance Appraisal Anxiety.” TLNT. 18 September 2015. Accessed 2018.

    Borysenko, Karlyn. “What Was Management Thinking? The High Cost of Employee Turnover.” Talent Management and HR. 22 April 2015. Accessed 2018.

    Cook, Ian. “Curbing Employee Turnover Contagion in the Workplace.” Visier. 20 February 2018. Accessed 2018.

    Cornerstone OnDemand. Toxic Employees in the Workplace. Santa Monica, California: Cornerstone OnDemand, 2015. Web.

    Dewar, Carolyn and Reed Doucette. “6 elements to create a high-performing culture.” McKinsey & Company. 9 April 2018. Accessed 2018.

    Eagle Hill. Eagle Hill National Attrition Survey. Washington, D.C.: Eagle Hill, 2015. Web.

    ERC. “Performance Improvement Plan Checklist.” ERC. 21 June 2017. Accessed 2018.

    Foster, James. “The Impact of Managers on Workplace Engagement and Productivity.” Interact. 16 March 2017. Accessed 2018.

    Godwins Solicitors LLP. “Employment Tribunal Statistics for 2015/2016.” Godwins Solicitors LLP. 8 February 2017. Accessed 2018.

    Mankins, Michael. “How to Manage a Team of All-Stars.” Harvard Business Review. 6 June 2017. Accessed 2018.

    Maxfield, David, et al. The Value of Stress-Free Productivity. Provo, Utah: VitalSmarts, 2017. Web.

    Murphy, Mark. “Skip Your Low Performers When Starting Performance Appraisals.” Forbes. 21 January 2015. Accessed 2018.

    Quint. “Transforming into a High Performance Organization.” Quint Wellington Redwood. 16 November 2017. Accessed 2018.

    Ranosa, Rachel. "COVID -19: Canadian Productivity Booms Despite Social Distancing." Human Resources Director, 14 April 2020. Accessed 2020.

    Tactics to Retain IT Talent

    • Buy Link or Shortcode: {j2store}549|cart{/j2store}
    • member rating overall impact: N/A
    • member rating average dollars saved: N/A
    • member rating average days saved: N/A
    • Parent Category Name: Engage
    • Parent Category Link: /engage
    • Regrettable turnover is impacting organizational productivity and leading to significant costs associated with employee departures and the recruitment required to replace them.
    • Many organizations focus on increasing engagement to improve retention, but this approach doesn’t address the entire problem.

    Our Advice

    Critical Insight

    • Engagement surveys mask the volatility of the employee experience and hide the reason why individual employees leave. You must also talk to employees to understand the moments that matter and engage managers to understand turnover triggers.

    Impact and Result

    • Build the case for creating retention plans by leveraging employee data and feedback to identify the key reasons for turnover that need to be addressed.
    • Target employee segments and work with management to develop solutions to retain top talent.

    Tactics to Retain IT Talent Research & Tools

    Besides the small introduction, subscribers and consulting clients within this management domain have access to:

    1. Tactics to Retain IT Talent Storyboard – Use this storyboard to develop a targeted talent retention plan to retain top and core talent in the organization.

    Integrate data from exit surveys and interviews, engagement surveys, and stay interviews to understand the most commonly cited reasons for employee departure in order to select and prioritize tactics that improve retention. This blueprint will help you identify reasons for regrettable turnover, select solutions, and create an action plan.

    • Tactics to Retain IT Talent Storyboard

    2. Retention Plan Workbook – Capture key information in one place as you work through the process to assess and prioritize solutions.

    Use this tool to document and analyze turnover data to find suitable retention solutions.

    • Retention Plan Workbook

    3. Stay Interview Guide – Managers will use this guide to conduct regular stay interviews with employees to anticipate and address turnover triggers.

    The Stay Interview Guide helps managers conduct interviews with current employees, enabling the manager to understand the employee's current engagement level, satisfaction with current role and responsibilities, suggestions for potential improvements, and intent to stay with the organization.

    • Stay Interview Guide

    4. IT Retention Solutions Catalog – Use this catalog to select and prioritize retention solutions across the employee lifecycle.

    Review best-practice solutions to identify those that are most suitable to your organizational culture and employee needs. Use the IT Retention Solutions Catalog to explore a variety of methods to improve retention, understand their use cases, and determine stakeholder responsibilities.

    • IT Retention Solutions Catalog
    [infographic]

    Workshop: Tactics to Retain IT Talent

    Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

    1 Identify Reasons for Regrettable Turnover

    The Purpose

    Identify the main drivers of turnover at the organization.

    Key Benefits Achieved

    Find out what to explore during focus groups.

    Activities

    1.1 Review data to determine why employees join, stay, and leave.

    1.2 Identify common themes.

    1.3 Prepare for focus groups.

    Outputs

    List of common themes/pain points recorded in the Retention Plan Workbook.

    2 Conduct Focus Groups

    The Purpose

    Conduct focus groups to explore retention drivers.

    Key Benefits Achieved

    Explore identified themes.

    Activities

    2.1 Conduct four 1-hour focus groups with the employee segment(s) identified in the pre-workshop activities.

    2.2 Info-Tech facilitators independently analyze results of focus groups and group results by theme.

    Outputs

    Focus group feedback.

    Focus group feedback analyzed and organized by themes.

    3 Identify Needs and Retention Initiatives

    The Purpose

    Home in on employee needs that are a priority.

    Key Benefits Achieved

    A list of initiatives to address the identified needs

    Activities

    3.1 Create an empathy map to identify needs.

    3.2 Shortlist retention initiatives.

    Outputs

    Employee needs and shortlist of initiatives to address them.

    4 Prepare to Communicate and Launch

    The Purpose

    Prepare to launch your retention initiatives.

    Key Benefits Achieved

    A clear action plan for implementing your retention initiatives.

    Activities

    4.1 Select retention initiatives.

    4.2 Determine goals and metrics.

    4.3 Plan stakeholder communication.

    4.4 Build a high-level action plan.

    Outputs

    Finalized list of retention initiatives.

    Goals and associated metrics recorded in the Retention Plan Workbook.

    Further reading

    Tactics to Retain IT Talent

    Keep talent from walking out the door by discovering and addressing moments that matter and turnover triggers.

    Executive Summary

    Your Challenge

    Many organizations are facing an increase in voluntary turnover as low unemployment, a lack of skilled labor, and a rise in the number of vacant roles have given employees more employment choices.

    Common Obstacles

    Regrettable turnover is impacting organizational productivity and leading to significant costs associated with employee departures and the recruitment required to replace them.

    Many organizations tackle retention from an engagement perspective: Increase engagement to improve retention. This approach doesn't consider the whole problem.

    Info-Tech's Approach

    Build the case for creating retention plans by leveraging employee data and feedback to identify the key reasons for turnover that need to be addressed.

    Target employee segments and work with management to develop solutions to retain top talent.

    Info-Tech Insight

    Engagement surveys mask the volatility of the employee experience and hide the reason why individual employees leave. You must also talk to employees to understand the moments that matter and engage managers to understand turnover triggers.

    This research addresses regrettable turnover

    This is an image of a flow chart with three levels. The top level has only one box, labeled Turnover.  the Second level has 2 boxes, labeled Voluntary, and Involuntary.  The third level has two boxes under Voluntary, labeled Non-regrettable: The loss of employees that the organization did not wish to keep, e.g. low performers, and Regrettable:  The loss of employees that the organization wishes it could have kept.

    Low unemployment and rising voluntary turnover makes it critical to focus on retention

    As the economy continues to recover from the pandemic, unemployment continues to trend downward even with a looming recession. This leaves more job openings vacant, making it easier for employees to job hop.

    This image contains a graph of the US Employment rate between 2020 - 2022 from the US Bureau of Economic Analysis and Bureau of Labor Statistics (BLS), 2022, the percentage of individuals who change jobs every one to five years from 2022 Job Seeker Nation Study, Jobvite, 2022, and voluntary turnover rates from BLS, 2022

    With more employees voluntarily choosing to leave jobs, it is more important than ever for organizations to identify key employees they want to retain and put plans in place to keep them.

    Retention is a challenge for many organizations

    The number of HR professionals citing retention/turnover as a top workforce management challenge is increasing, and it is now the second highest recruiting priority ("2020 Recruiter Nation Survey," Jobvite, 2020).

    65% of employees believe they can find a better position elsewhere (Legaljobs, 2021). This is a challenge for organizations in that they need to find ways to ensure employees want to stay at the organization or they will lose them, which results in high turnover costs.

    Executives and IT are making retention and turnover – two sides of the same coin – a priority because they cost organizations money.

    • 87% of HR professionals cited retention/turnover as a critical and high priority for the next few years (TINYpulse, 2020).
    • $630B The cost of voluntary turnover in the US (Work Institute, 2020).
    • 66% of organizations consider employee retention to be important or very important to an organization (PayScale, 2019).

    Improving retention leads to broad-reaching organizational benefits

    Cost savings: the price of turnover as a percentage of salary

    • 33% Improving retention can result in significant cost savings. A recent study found turnover costs, on average, to be around a third of an employee's annual salary (SHRM, 2019).
    • 37.9% of employees leave their organization within the first year. Employees who leave within the first 90 days of being hired offer very little or no return on the investment made to hire them (Work Institute, 2020).

    Improved performance

    Employees with longer tenure have an increased understanding of an organization's policies and processes, which leads to increased productivity (Indeed, 2021).

    Prevents a ripple effect

    Turnover often ripples across a team or department, with employees following each other out of the organization (Mereo). Retaining even one individual can often have an impact across the organization.

    Transfer of knowledge

    Retaining key individuals allows them to pass it on to other employees through communities of practice, mentoring, or other knowledge-sharing activities.

    Info-Tech Insight

    Improving retention goes beyond cost savings: Employees who agree with the statement "I expect to be at this organization a year from now" are 71% more likely to put in extra hours and 32% more likely to accomplish more than what is expected of their role (McLean & Company Engagement Survey, 2021; N=77,170 and 97,326 respectively).

    However, the traditional engagement-focused approach to retention is not enough

    Employee engagement is a strong driver of retention, with only 25% of disengaged employees expecting to be at their organization a year from now compared to 92% of engaged employees (McLean & Company Engagement Survey, 2018-2021; N=117,307).

    Average employee Net Promoter Score (eNPS)

    This image contains a graph of the Average employee Net Promoter Score (eNPS)

    Individual employee Net Promoter Scores (eNPS)

    This image contains a graph of the Individual employee Net Promoter Scores (eNPS)

    However, engagement surveys mask the volatility of the employee experience and hide the reason why individual employees leave.

    This analysis of McLean & Company's engagement survey results shows that while an organization's average employee net promoter score (eNPS) stays relatively static, at an individual level there is a huge amount of volatility.

    This demonstrates the need for an approach that is more capable of responding to or identifying employees' in-the-moment needs, which an annual engagement survey doesn't support.

    Turnover triggers and moments that matter also have an impact on retention

    Retention needs to be monitored throughout the employee lifecycle. To address the variety of issues that can appear, consider three main paths to turnover:

    1. Employee engagement – areas of low engagement.
    2. Turnover triggers that can quickly lead to departures.
    3. Moments that matter in the employee experience (EX).

    Employee engagement

    Engagement drivers are strong predictors of turnover.

    Employees who are highly engaged are 3.6x more likely to believe they will be with the organization 12 months from now than disengaged employees (McLean & Company Engagement Survey, 2018-2021; N=117,307).

    Turnover triggers

    Turnover triggers are events that act as shocks or catalysts that quickly lead to an employee's departure.

    Turnover triggers are a cause for voluntary turnover more often than accumulated issues (Lee et al.).

    Moments that matter

    Employee experience is the employee's perception of the accumulation of moments that matter within their employee lifecycle.

    Retention rates increase from 21% to 44% when employees have positive experiences in the following categories: belonging, purpose, achievement, happiness, and vigor at work. (Workhuman, 2020).

    While managers do not directly impact turnover, they do influence the three main paths to turnover

    Research shows managers do not appear as one of the common reasons for employee turnover.

    Top five most common reasons employees leave an organization (McLean & Company, Exit Survey, 2018-2021; N=107 to 141 companies,14,870 to 19,431 responses).

    Turnover factorsRank
    Opportunities for career advancement1
    Satisfaction with my role and responsibilities2
    Base pay3
    Opportunities for career-related skill development4
    The degree to which my skills were used in my job5

    However, managers can still have a huge impact on the turnover of their team through each of the three main paths to turnover:

    Employee engagement

    Employees who believe their managers care about them as a person are 3.3x more likely to be engaged than those who do not (McLean & Company, 2021; N=105,186).

    Turnover triggers

    Managers who are involved with and aware of their staff can serve as an early warning system for triggers that lead to turnover too quickly to detect with data.

    Moments that matter

    Managers have a direct connection with each individual and can tailor the employee experience to meet the needs of the individuals who report to them.

    Gallup has found that 52% of exiting employees say their manager could have done something to prevent them from leaving (Gallup, 2019). Do not discount the power of managers in anticipating and preventing regrettable turnover.

    Addressing engagement, turnover triggers, and moments that matter is the key to retention

    This is an image of a flow chart with four levels. The top level has only one box, labeled Turnover.  the Second level has 2 boxes, labeled Voluntary, and Involuntary.  The third level has two boxes under Voluntary, labeled Non-regrettable, and Regrettable.  The fourth level has three boxes under Regrettable, labeled Employee Engagement, Turnover triggers, and Moments that matter

    Info-Tech Insight

    HR traditionally seeks to examine engagement levels when faced with retention challenges, but engagement is only a part of the full picture. You must also talk to employees to understand the moments that matter and engage managers to understand turnover triggers.

    Follow Info-Tech's two-step process to create a retention plan

    1. Identify Reasons for Regrettable Turnover

    2. Select Solutions and Create an Action Plan

    Step 1

    Identify Reasons for Regrettable Turnover

    After completing this step you will have:

    • Analyzed and documented why employees join, stay, and leave your organization.
    • Identified common themes and employee needs.
    • Conducted employee focus groups and prioritized employee needs.

    Step 1 focuses on analyzing existing data and validating it through focus groups

    Employee engagement

    Employee engagement and moments that matter are easily tracked by data. Validating employee feedback data by speaking and empathizing with employees helps to uncover moments that matter. This step focuses on analyzing existing data and validating it through focus groups.

    Engagement drivers such as compensation or working environment are strong predictors of turnover.
    Moments that matter
    Employee experience (EX) is the employee's perception of the accumulation of moments that matter with the organization.
    Turnover triggers
    Turnover triggers are events that act as shocks or catalysts that quickly lead to an employee's departure.

    Turnover triggers

    This step will not touch on turnover triggers. Instead, they will be discussed in step 2 in the context of the role of the manager in improving retention.

    Turnover triggers are events that act as shocks or catalysts that quickly lead to an employee's departure.

    Info-Tech Insight

    IT managers often have insights into where and why retention is an issue through their day-to-day work. Gathering detailed quantitative and qualitative data provides credibility to these insights and is key to building a business case for action. Keep an open mind and allow the data to inform your gut feeling, not the other way around.

    Gather data to better understand why employees join, stay, and leave

    Start to gather and examine additional data to accurately identify the reason(s) for high turnover. Begin to uncover the story behind why these employees join, stay, and leave your organization through themes and trends that emerge.

    Look for these icons throughout step 2.

    Join

    Why do candidates join your organization?

    Stay

    Why do employees stay with your organization?

    Leave

    Why do employees leave your organization?

    For more information on analysis, visualization, and storytelling with data, see Info-Tech's Start Making Data-Driven People Decisions blueprint.

    Employee feedback data to look at includes:

    Gather insights through:

    • Focus groups
    • Verbatim comments
    • Exit interviews
    • Using the employee value proposition (EVP) as a filter (does it resonate with the lived experience of employees?)

    Prepare to draw themes and trends from employee data throughout step 1.

    Uncover employee needs and reasons for turnover by analyzing employee feedback data.

    • Look for trends (e.g. new hires join for career opportunities and leave for the same reason, or most departments have strong work-life balance scores in engagement data).
    • Review if there are recurring issues being raised that may impact turnover.
    • Group feedback to highlight themes (e.g. lack of understanding of EVP).
    • Identify which key employee needs merit further investigation or information.

    This is an image showing how you can draw out themes and trends using employee data throughout step 1.

    Classify where key employee needs fall within the employee lifecycle diagram in tab 2 of the Retention Plan Workbook. This will be used in step 2 to pinpoint and prioritize solutions.

    Info-Tech Insight

    The employee lifecycle is a valuable way to analyze and organize engagement pain points, moments that matter, and turnover triggers. It ensures that you consider the entirety of an employee's tenure and the different factors that lead to turnover.

    Examine new hire data and begin to document emerging themes

    Join

    While conducting a high-level analysis of new hire data, look for these three key themes impacting retention:

    Issues or pain points that occurred during the hiring process.

    Reasons why employees joined your organization.

    The experience of their first 90 days. This can include their satisfaction with the onboarding process and their overall experience with the organization.

    Themes will help to identify areas of strength and weakness organization-wide and within key segments. Document in tab 3 of the Retention Plan Workbook.

    1. Start by isolating the top reasons employees joined your organization. Ask:
      • Do the reasons align with the benefits you associate with working at your organization?
      • How might this impact your EVP?
      • If you use a new hire survey, look at the results for the following questions:
      • For which of the following reasons did you apply to this organization?
      • For what reasons did you accept the job offer with this organization?
    2. then, examine other potential problem areas that may not be covered by your new hire survey, such as onboarding or the candidate experience during the hiring process.
      • If you conduct a new hire survey, look at the results in the following sections:
        • Candidate Experience
        • Acclimatization
        • Training and Development
        • Defining Performance Expectations

      Analyze engagement data to identify areas of strength that drive retention

      Employees who are engaged are 3.6x more likely to believe they will be with the organization 12 months from now (McLean & Company Engagement Survey, 2018-2021; N=117,307). Given the strength of this relationship, it is essential to identify areas of strength to maintain and leverage.

      1. Look at the highest-performing drivers in your organization's employee engagement survey and drivers that fall into the "leverage" and "maintain" quadrants of the priority matrix.
        • These drivers provide insight into what prompts broader groups of employees to stay.

      This is an image of a quadrant analysis, with the following quadrants in order from left to right, top to bottom.  Improve; Leverage; Evaluate; Maintain.

      1. Look into what efforts have been made to maintain programs, policies, and practices related to these drivers and ensure they are consistent across the entire organization.
      2. Document trends and themes related to engagement strengths in tab 2 of the Retention Plan Workbook.

      If you use Info-Tech's Engagement Survey, look in detail at what are classified as "Retention Drivers": total compensation, working environment, and work-life balance.

      Identify areas of weakness that drive turnover in your engagement data

      1. Look at the lowest-performing drivers in your organization's employee engagement survey and drivers that fall into the "improve" and "evaluate" quadrants of the priority matrix.
        • These drivers provide insight into what pushes employees to leave the organization.
      2. Delve into organizational efforts that have been made to address issues with the programs, policies, and practices related to these drivers. Are there any projects underway to improve them? What are the barriers preventing improvements?
      3. Document trends and themes related to engagement weaknesses in tab 2 of the Retention Plan Workbook.

      If you use a product other than Info-Tech's Engagement Survey, your results will look different. The key is to look at areas of weakness that emerge from the data.

      This is an image of a quadrant analysis, with the following quadrants in order from left to right, top to bottom.  Improve; Leverage; Evaluate; Maintain.

      If you use Info-Tech's Engagement Survey, look in detail at what are classified as "Retention Drivers": total compensation, working environment, and work-life balance.

      Mine exit surveys to develop an integrated, holistic understanding of why employees leave

      Conduct a high-level analysis of the data from your employee exit diagnostic. While analyzing this data, consider the following:

      • What are the trends and quantitative data about why employees leave your organization that may illuminate employee needs or issues at specific points throughout the employee lifecycle?
      • What are insights around your key segments? Data on key segments is easily sliced from exit survey results and can be used as a starting point for digging deeper into retention issues for specific groups.
      • Exit surveys are an excellent starting point. However, it is valuable to validate the data gathered from an exit survey using exit interviews.
      1. Isolate results for key segments of employees to target with retention initiatives (e.g. by age group or by department).
      2. Identify data trends or patterns over time; for example, that compensation factors have been increasing in importance.
      3. Document trends and themes taken from the exit survey results in tab 2 of the Retention Plan Workbook.

      If your organization conducts exit interviews, analyze the results alongside or in lieu of exit survey data.

      Compare new hire data with exit data to identify patterns and insights

      Determine if new hire expectations weren't met, prompting employees to leave your organization, to help identify where in the employee lifecycle issues driving turnover may be occurring.

      1. Look at your new hire data for the top reasons employees joined your organization.
        • McLean & Company's New Hire Survey database shows that the top three reasons candidates accept job offers on average are:
          1. Career opportunities
          2. Nature of the job
          3. Development opportunities
      2. Next, look at your exit data and the top reasons employees left your organization.
        1. McLean & Company's Exit Survey database shows that the top three reasons employees leave on average are:
          1. Opportunities for career advancement
          2. Base pay
          3. Satisfaction with my role and responsibilities
      3. Examine the results and ask:
        • Is there a link between why employees join and leave the organization?
        • Did they cite the same reasons for joining and for leaving?
        • What do the results say about what your employees do and do not value about working at your organization?
      4. Document the resulting insights in tab 2 of the Retention Plan Workbook.

      Example:

      A result where employees are leaving for the same reason they're joining the organization could signal a disconnect between your organization's employee value proposition and the lived experience.

      Revisit your employee value proposition to uncover misalignment

      Your employee value proposition (EVP), formal or informal, communicates the value your organization can offer to prospective employees.

      If your EVP is mismatched with the lived experience of your employees, new hires will be in for a surprise when they start their new job and find out it isn't what they were expecting.

      Forty-six percent of respondents who left a job within 90 days of starting cited a mismatch of expectations about their role ("Job Seeker Nation Study 2020," Jobvite, 2020).

      1. Use the EVP as a filter through which you look at all your employee feedback data. It will help identify misalignment between the promised and the lived experience.
      2. If you have EVP documentation, start there. If not, go to your careers page and put yourself in the shoes of a candidate. Ask what the four elements of an EVP look like for candidates:
        • Compensation and benefits
        • Day-to-day job elements
        • Working conditions
        • Organizational elements
      3. Next, compare this to your own day-to-day experiences. Does it differ drastically? Are there any contradictions with the lived experience at your organization? Are there misleading statements or promises?
      4. Document any insights or patterns you uncover in tab 2 of the Retention Plan Workbook.

      Conduct focus groups to examine themes

      Through focus groups, explore the themes you have uncovered with employees to discover employee needs that are not being met. Addressing these employee needs will be a key aspect of your retention plan.

      Identify employee groups who will participate in focus groups:

      • Incorporate diverse perspectives (e.g. employees, managers, supervisors).
      • Include employees from departments and demographics with strong and weak engagement for a full picture of how engagement impacts your employees.
      • Invite boomerang employees to learn why an individual might return to your organization after leaving.

      image contains two screenshots Mclean & Company's Standard Focus Group Guide.

      Customize Info-Tech's Standard Focus Group Guide based on the themes you have identified in tab 3 of the Retention Plan Workbook.

      The goal of the focus group is to learn from employees and use this information to design or modify a process, system, or other solution that impacts retention.

      Focus questions on the employees' personal experience from their perspective.

      Key things to remember:

      • It is vital for facilitators to be objective.
      • Keep an open mind; no feelings are wrong.
      • Beware of your own biases.
      • Be open and share the reason for conducting the focus groups.

      Info-Tech Insight

      Maintaining an open dialogue with employees will help flesh out the context behind the data you've gathered and allow you to keep in mind that retention is about people first and foremost.

      Empathize with employees to identify moments that matter

      Look for discrepancies between what employees are saying and doing.

      1. Say

      "What words or quotes did the employee use?"

      3.Think

      "What might the employee be thinking?"

      Record feelings and thoughts discussed, body language observed, tone of voice, and words used.

      Look for areas of negative emotion to determine the moments that matter that drive retention.

      2. Do

      "What actions or behavior did the employee demonstrate?"

      4. Feel

      "What might the employee be feeling?"

      Record them in tab 3 of the Retention Plan Workbook.

      5. Identify Needs

      "Needs are verbs (activities or desires), not nouns (solutions)"

      Synthesize focus group findings using Info-Tech's Empathy Map Template.

      6. Identify Insights

      "Ask yourself, why?"

      (Based on Stanford d.school Empathy Map Method)

      Distill employee needs into priority issues to address first

      Take employee needs revealed by your data and focus groups and prioritize three to five needs.

      Select a limited number of employee needs to develop solutions to ensure that the scope of the project is feasible and that the resources dedicated to this project are not stretched too thin. The remaining needs should not be ignored – act on them later.

      Share the needs you identify with stakeholders so they can support prioritization and so you can confirm their buy-in and approval where necessary.

      Ask yourself the following questions to determine your priority employee needs:

      • Which needs will have the greatest impact on turnover?
      • Which needs have the potential to be an easy fix or quick win?
      • Which themes or trends came up repeatedly in different data sources?
      • Which needs evoked particularly strong or negative emotions in the focus groups?

      This image contains screenshots of two table templates found in tab 5 of the Retention Plan Workbook

      In the Retention Plan Workbook, distill employee needs on tab 2 into three to five priorities on tab 5.

      Step 2

      Select Solutions and Create an Action Plan

      After completing this step, you will have:

      • Selected and prioritized solutions to address employee needs.
      • Created a plan to launch stay interviews.
      • Built an action plan to implement solutions.

      Select IT-owned solutions and implement people leader–driven initiatives

      Solutions

      First, select and prioritize solutions to address employee needs identified in the previous step. These solutions will address reasons for turnover that influence employee engagement and moments that matter.

      • Brainstorm solutions using the Retention Solutions Catalog as a starting point. Select a longlist of solutions to address your priority needs.
      • Prioritize the longlist of solutions into a manageable number to act on.

      People leaders

      Next, create a plan to launch stay interviews to increase managers' accountability in improving retention. Managers will be critical to solving issues stemming from turnover triggers.

      • Clarify the importance of harnessing the influence of people leaders in improving retention.
      • Discover what might cause individual employees to leave through stay interviews.
      • Increase trust in managers through training.

      Action plan

      Finally, create an action plan and present to senior leadership for approval.

      Look for these icons in the top right of slides in this step.

      Select solutions to employee needs, starting with the Retention Solutions Catalog

      Based on the priority needs you have identified, use the Retention Solutions Catalog to review best-practice solutions for pain points associated with each stage of the lifecycle.

      Use this tool as a starting point, adding to it and iterating based on your own experience and organizational culture and goals.

      This image contains three screenshots from Info-Tech's Retention Solutions Catalog.

      Use Info-Tech's Retention Solutions Catalog to start the brainstorming process and produce a shortlist of potential solutions that will be prioritized on the next slide.

      Info-Tech Insight

      Unless you have the good fortune of having only a few pain points, no single initiative will completely solve your retention issues. Combine one or two of these broad solutions with people-leader initiatives to ensure employee needs are addressed on an individual and an aggregate level.

      Prioritize solutions to be implemented

      Target efforts accordingly

      Quick wins are high-impact, low-effort initiatives that will build traction and credibility within the organization.

      Long-term initiatives require more time and need to be planned for accordingly but will still deliver a large impact. Review the planning horizon to determine how early these need to begin.

      Re-evaluate low-impact and low-effort initiatives and identify ones that either support other higher impact initiatives or have the highest impact to gain traction and credibility. Look for low-hanging fruit.

      Deprioritize initiatives that will take a high degree of effort to deliver lower-value results.

      When assessing the impact of potential solutions, consider:

      • How many critical segments or employees will this solution affect?
      • Is the employee need it addresses critical, or did the solution encompass several themes in the data you analyzed?
      • Will the success of this solution help build a case for further action?
      • Will the solution address multiple employee needs?

      Info-Tech Insight

      It's better to master a few initiatives than under-deliver on many. Start with a few solutions that will have a measurable impact to build the case for further action in the future.

      Solutions

      Low ImpactMedium ImpactLarge Impact
      Large EffortThis is an image of the used to help you prioritize solutions to be implemented.
      Medium Effort
      Low Effort

      Use tab 3 of the Retention Plan Workbook to prioritize your shortlist of solutions.

      Harness the influence of people leaders to improve employee retention

      Leaders at all levels have a huge impact on employees.

      Effective people leaders:

      • Manage work distribution.
      • Create a motivating work environment.
      • Provide development opportunities.
      • Ensure work is stimulating and challenging, but not overwhelming.
      • Provide clear, actionable feedback.
      • Recognize team member contributions.
      • Develop positive relationships with their teams.
      • Create a line of sight between what the employee is doing and what the organization's objectives are.

      Support leaders in recommitting to their role as people managers through Learning & Development initiatives with particular emphasis on coaching and building trust.

      For coaching training, see Info-Tech's Build a Better Manager: Team Essentials – Feedback and Coaching training deck.

      For more information on supporting managers to become better people leaders, see Info-Tech's Build a Better Manager: Manage Your People blueprint.

      "HR can't fix turnover. But leaders on the front line can."
      – Richard P. Finnegan, CEO, C-Suite Analytics

      Equip managers to conduct regular stay interviews to address turnover triggers

      Managers often have the most visibility into their employees' personal and work lives and have a key opportunity to anticipate and address turnover triggers.

      Stay interviews are an effective way of uncovering potential retention issues and allowing managers to act as an early warning system for turnover triggers.

      Examples of common turnover triggers and potential manager responses:

      • Moving, creating a long commute to the office.
        • Through stay interviews, a manager can learn that a long commute is an issue and can help find workarounds such as flexible/remote work options.
      • Not receiving an expected promotion.
        • A trusted manager can anticipate issues stemming from this, discuss why the decision was made, and plan development opportunities for future openings.

      Stay interview best practices

      1. Conducted by an employee's direct manager.
      2. Happen regularly as a part of an ongoing process.
      3. Based on the stay interview, managers produce a turnover forecast for each direct report.
        1. The method used by stay interview expert Richard P. Finnegan is simple: red for high risk, yellow for medium, and green for low.
      4. Provide managers with training and a rough script or list of questions to follow.
        1. Use and customize Info-Tech's Stay Interview Guide to provide a guide for managers on how to conduct a stay interview.
      5. Managers use the results to create an individualized retention action plan made up of concrete actions the manager and employee will take.

      Sources: Richard P. Finnegan, CEO, C-Suite Analytics; SHRM

      Build an action plan to implement the retention plan

      For each initiative identified, map out timelines and actions that need to be taken.

      When building actions and timelines:

      • Refer to the priority needs you identified in tab 4 of the Retention Plan Workbook and ensure they are addressed first.
      • Engage internal stakeholders who will be key to the development of the initiatives to ensure they have sufficient time to complete their deliverables.
        • For example, if you conduct manager training, Learning & Development needs to be involved in the development and launch of the program.
      • Include a date to revisit your baseline retention and engagement data in your project milestones.
      • Designate process owners for new processes such as stay interviews.

      Plan for stay interviews by determining:

      • Whether stay interviews will be a requirement for all employees.
      • How much flexibility managers will have with the process.
      • How you will communicate the stay interview approach to managers.
      • If manager training is required.
      • How managers should record stay interview data and how you will collect this data from them as a way to monitor retention issues.
        • For example, managers can share their turnover forecasts and action plans for each employee.

      Be clear about manager accountabilities for initiatives they will own, such as stay interviews. Plan to communicate the goals and timelines managers will be asked to meet, such as when they must conduct interviews or their responsibility to follow up on action items that come from interviews.

      Track project success to iterate and improve your solutions

      Analyze measurements

      • Regularly remeasure your engagement and retention levels to identify themes and trends that provide insights into program improvements.
      • For example, look at the difference in manager relationship score to see if training has had an impact, or look at changes in critical segment turnover to calculate cost savings.

      Revisit employee and manager feedback

      • After three to six months, conduct additional surveys or focus groups to determine the success of your initiatives and opportunities for improvement. Tweak the program, including stay interviews, based on manager and employee feedback.

      Iterate frequently

      • Revisit your initiatives every two or three years to determine if a refresh is necessary to meet changing organizational and employee needs and to update your goals and targets.

      Key insights

      Insight 1Insight 2Insight 3

      Retention and turnover are two sides of the same coin. You can't fix retention without first understanding turnover.

      Engagement surveys mask the volatility of the employee experience and hide the reason why individual employees leave. You must also talk to employees to understand the moments that matter and engage managers to understand turnover triggers.

      Improving retention isn't just about lowering turnover, it's about discovering what healthy retention looks like for your organization.

      Insight 4Insight 5Insight 6

      HR professionals often have insights into where and why retention is an issue. Gathering detailed employee feedback data through surveys and focus groups provides credibility to these insights and is key to building a case for action. Keep an open mind and allow the data to inform your gut feeling, not the other way around.

      Successful retention plans must be owned by both IT leaders and HR.

      IT leaders often have the most visibility into their employees' personal and work lives and have a key opportunity to anticipate and address turnover triggers.

      Stay interviews help managers anticipate potential retention issues on their teams.

      Workshop Overview

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      Info-Tech AnalystsPre-workPost-work
      Client Data Gathering and PlanningImplementation Supported Through Analyst Calls

      1.1 Discuss participants, logistics, overview of workshop activities

      1.2 Provide support to client for below activities through calls.

      2.1 Schedule follow-up calls to work through implementation of retention solutions based on identified needs.
      Client

      1.Gather results of engagement survey, new hire survey, exit survey, and any exit and stay interview feedback.

      2.Gather and analyze turnover data.

      3.Identify key employee segment(s) and identify and organize participants for focus groups.

      4.Complete cost of turnover analysis.

      5.Review turnover data and prioritize list of employee segments.

      1.Obtain senior leader approval to proceed with retention plan.

      2.Finalize and implement retention solutions.

      3.Prepare managers to conduct stay interviews.

      4.Communicate next steps to stakeholders.

      Workshop Overview

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      ActivitiesDay 1Day 2Day 3Day 4
      Assess Current StateConduct Focus GroupsIdentify Needs and Retention InitiativesPrepare to Communicate and Launch

      1.1 Review data to determine why employees join, stay, and leave.

      1.2 Identify common themes.

      1.3 Prepare for focus groups.

      2.1 Conduct four 1-hour focus groups with the employee segment(s) identified in the pre-workshop activities..

      2.2 Info-Tech facilitators independently analyze results of focus groups and group results by theme.

      3.1 Create an empathy map to identify needs

      3.2 Shortlist retention initiatives

      4.1 Select retention initiatives

      4.2 Determine goals and metrics

      4.3 Plan stakeholder communication4.4 Build a high-level action plan

      Deliverables

      1.List of common themes/pain points recorded in the Retention Plan Workbook

      2.Plan for focus groups documented in the Focus Group Guide

      1.Focus group feedback

      2.Focus group feedback analyzed and organized by themes

      1.Employee needs and shortlist of initiatives to address them1.Finalized list of retention initiatives

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

      Guided Implementation

      “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

      Workshop

      “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

      Consulting

      “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

      Diagnostics and consistent frameworks used throughout all four options

      Research Contributors and Experts

      Jeff Bonnell
      VP HR
      Info-Tech Research Group

      Phillip Kotanidis
      CHRO
      Michael Garron Hospital

      Michael McGuire
      Director, Organizational Development
      William Osler Health System

      Dr. Iris Ware
      Chief Learning Officer
      City of Detroit

      Richard P. Finnegan
      CEO
      C-Suite Analytics

      Dr. Thomas Lee
      Professor of Management
      University of Washington

      Jane Moughon
      Specialist in increasing profits, reducing turnover, and maximizing human potential in manufacturing companies

      Lisa Kaste
      Former HR Director
      Citco

      Piyush Mathur
      Head of Workforce Analytics
      Johnson & Johnson

      Gregory P. Smith
      CEO
      Chart Your Course

      Works Cited

      "17 Surprising Statistics about Employee Retention." TINYpulse, 8 Sept. 2020. Web.
      "2020 Job Seeker Nation Study." Jobvite, April 2020. Web.
      "2020 Recruiter Nation Survey." Jobvite, 2020. Web.
      "2020 Retention Report: Insights on 2019 Turnover Trends, Reasons, Costs, & Recommendations." Work Institute, 2020. Web.
      "25 Essential Productivity Statistics for 2021." TeamStage, 2021. Accessed 22 Jun. 2021.
      Agovino, Theresa. "To Have and to Hold." SHRM, 23 Feb. 2019. Web.
      "Civilian Unemployment Rate." Bureau of Labor Statistics, June 2020. Web.
      Foreman, Paul. "The domino effect of chief sales officer turnover on salespeople." Mereo, 19 July 2018. Web.
      "Gross Domestic Product." U.S. Bureau of Economic Analysis, 27 May 2021. Accessed 22 Jun. 2020.
      Kinne, Aaron. "Back to Basics: What is Employee Experience?" Workhuman, 27August 2020. Accessed 21 Jun. 2021.
      Lee, Thomas W, et al. "Managing employee retention and turnover with 21st century ideas." Organizational Dynamics, vol 47, no. 2, 2017, pp. 88-98. Web.
      Lee, Thomas W. and Terence R. Mitchell. "Control Turnover by Understanding its Causes." The Blackwell Handbook of Principles of Organizational Behaviour. 2017. Print.
      McFeely, Shane, and Ben Wigert. "This Fixable Problem Costs U.S. Businesses $1 Trillion." Gallup. 13 March 2019. Web.
      "Table 18. Annual Quit rates by Industry and Region Not Seasonally Adjusted." Bureau of Labor Statistics. June 2021. Web.
      "The 2019 Compensation Best Practices Report: Will They Stay or Will They Go? Employee Retention and Acquisition in an Uncertain Economy." PayScale. 2019. Web.
      Vuleta, Branka. "30 Troubling Employee Retention Statistics." Legaljobs. 1 Feb. 2021. Web.
      "What is a Tenured Employee? Top Benefits of Tenure and How to Stay Engaged as One." Indeed. 22 Feb. 2021. Accessed 22 Jun. 2021.

      Build a Security Metrics Program to Drive Maturity

      • Buy Link or Shortcode: {j2store}266|cart{/j2store}
      • member rating overall impact: 9.5/10 Overall Impact
      • member rating average dollars saved: $22,947 Average $ Saved
      • member rating average days saved: 8 Average Days Saved
      • Parent Category Name: Security Processes & Operations
      • Parent Category Link: /security-processes-and-operations
      • Many security leaders put off adding metrics to their program because they don't know where to start or how to assess what is worth measuring.
      • Sometimes, this uncertainty causes the belief that their security programs are not mature enough for metrics to be worthwhile.
      • Because metrics can become very technical and precise,it's easy to think that they're inherently complicated (not true).

      Our Advice

      Critical Insight

      • The best metrics are tied to goals.
      • Tying your metrics to goals ensures that you are collecting metrics for a specific purpose rather than just to watch the numbers change.

      Impact and Result

      • A metric, really, is just a measure of success against a given goal. Gradually, programs will achieve their goals and set new more specific goals, and with them come more-specific metrics.
      • It is not necessary to jump into highly technical metrics right away. A lot can be gained from metrics that track behaviors.
      • A metrics program can be very simple and still effectively demonstrate the value of security to the organization. The key is to link your metrics to the goals or objectives the security team is pursuing, even if they are simple implementation plans (e.g. percentage of departments that have received security training course).

      Build a Security Metrics Program to Drive Maturity Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should build a security metrics program, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Link security metrics to goals to boost maturity

      Develop goals and KPIs to measure your progress.

      • Build a Security Metrics Program to Drive Maturity – Phase 1: Link Security Metrics to Goals to Boost Maturity
      • Security Metrics Determination and Tracking Tool
      • KPI Development Worksheets

      2. Adapt your reporting strategy for various metric types

      Learn how to present different types of metrics.

      • Build a Security Metrics Program to Drive Maturity – Phase 2: Adapt Your Reporting Strategy for Various Metric Types
      • Security Metrics KPX Dashboard
      • Board-Level Security Metrics Presentation Template
      [infographic]

      Workshop: Build a Security Metrics Program to Drive Maturity

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Current State, Initiatives, and Goals

      The Purpose

      Create a prioritized list of goals to improve the security program’s current state.

      Key Benefits Achieved

      Insight into the current program and the direct it needs to head in.

      Activities

      1.1 Discuss current state and existing approach to metrics.

      1.2 Review contract metrics already in place (or available).

      1.3 Determine security areas that should be measured.

      1.4 Determine what stakeholders are involved.

      1.5 Review current initiatives to address those risks (security strategy, if in place).

      1.6 Begin developing SMART goals for your initiative roadmap.

      Outputs

      Gap analysis results

      SMART goals

      2 KPI Development

      The Purpose

      Develop unique KPIs to measure progress against your security goals.

      Key Benefits Achieved

      Learn how to develop KPIs

      Prioritized list of security goals

      Activities

      2.1 Continue SMART goal development.

      2.2 Sort goals into types.

      2.3 Rephrase goals as KPIs and list associated metric(s).

      2.4 Continue KPI development.

      Outputs

      KPI Evolution Worksheet

      3 Metrics Prioritization

      The Purpose

      Determine which metrics will be included in the initial program launch.

      Key Benefits Achieved

      A set of realistic and manageable goals-based metrics.

      Activities

      3.1 Lay out prioritization criteria.

      3.2 Determine priority metrics (implementation).

      3.3 Determine priority metrics (improvement & organizational trend).

      Outputs

      Prioritized metrics

      Tool for tracking and presentation

      4 Metrics Reporting

      The Purpose

      Strategize presentation based around metric type to indicate organization’s risk posture.

      Key Benefits Achieved

      Develop versatile reporting techniques

      Activities

      4.1 Review metric types and discuss reporting strategies for each.

      4.2 Develop a story about risk.

      4.3 Discuss the use of KPXs and how to scale for less mature programs.

      Outputs

      Key Performance Index Tool and presentation materials

      Further reading

      Build a Security Metrics Program to Drive Maturity

      Good metrics come from good goals.

      ANALYST PERSPECTIVE

      Metrics are a maturity driver.

      "Metrics programs tend to fall into two groups: non-existent and unhelpful.

      The reason so many security professionals struggle to develop a meaningful metrics program is because they are unsure of what to measure or why.

      The truth is, for metrics to be useful, they need to be tied to something you care about – a state you are trying to achieve. In other words, some kind of goal. Used this way, metrics act as the scoreboard, letting you know if you’re making progress towards your goals, and thus, boosting your overall maturity."

      Logan Rohde, Research Analyst, Security Practice Info-Tech Research Group

      Executive summary

      Situation

      • Many security leaders put off adding metrics to their program because they don't know where to start or how to assess what is worth measuring.

      Complication

      • Sometimes, this uncertainty causes the belief that their security programs are not mature enough for metrics to be worthwhile.
      • Because metrics can become very technical and precise, it's easy to think they're inherently complicated (not true).

      Resolution

      • A metric, really, is just a measure of success against a given goal. Gradually, programs will achieve their goals and set new, more specific goals, and with them comes more specific metrics.
      • It is not necessary to jump into highly technical metrics right away. A lot can be gained from metrics that track behaviors.
      • A metrics program can be very simple and still effectively demonstrate the value of security to the organization. The key is to link your metrics to the goals or objectives the security team is pursuing, even if they are simple implementation plans (e.g. percentage of departments that have received security training).

      Info-Tech Insight

      1. Metrics lead to maturity, not vice versa
        • Tracking metrics helps you assess progress and regress in your security program. This helps you quantify the maturity gains you’ve made and continue to make informed strategic decisions.
      2. The best metrics are tied to goals
        • Tying your metrics to goals ensures that you are collecting metrics for a specific purpose rather than just to watch the numbers change.

      Our understanding of the problem

      This Research is Designed For:

      • CISO

      This Research Will Help You:

      • Understand the value of metrics.
      • Right-size a metrics program based on your organization’s maturity and risk profile.
      • Tie metrics to goals to create meaningful KPIs.
      • Develop strategies to effectively communicate the right metrics to stakeholders.

      This Research Will Also Assist:

      • CIO
      • Security Manager
      • Business Professionals

      This Research Will Help Them:

      • Become informed on the metrics that matter to them.
      • Understand that investment in security is an investment in the business.
      • Feel confident in the progress of the organization’s security strategy.

      Info-Tech’s framework integrates several best practices to create a best-of-breed security framework

      Information Security Framework

      Governance

      • Context and Leadership
        • Information Security Charter
        • Information Security Organizational Structure
        • Culture and Awareness
      • Evaluation and Direction
        • Security Risk Management
        • Security Policies
        • Security Strategy and Communication
      • Compliance, Audit, and Review
        • Security Compliance Management
        • External Security Audit
        • Internal Security Audit
        • Management Review of Security

      Management

      • Prevention
        • Identity Security
          • Identity and Access Management
        • Data Security
          • Hardware Asset Management
          • Data Security & Privacy
        • Infrastructure Security
          • Network Security
          • Endpoint Security
          • Malicious Code
          • Application Security
          • Vulnerability Management
          • Cryptography Management
          • Physical Security
          • Cloud Security
        • HR Security
          • HR Security
        • Change and Support
          • Configuration and Change Management
          • Vendor Management
      • Detection
        • Security Threat Detection
        • Log and Event Management
      • Response and Recovery
        • Security Incident Management
        • Information Security in BCM
        • Security eDiscovery and Forensics
        • Backup and Recovery
      • Measurement
        • Metrics Program
        • Continuous Improvement

      Metrics help to improve security-business alignment

      While business leaders are now taking a greater interest in cybersecurity, alignment between the two groups still has room for improvement.

      Key statistics show that just...

      5% of public companies feel very confident that they are properly secured against a cyberattack.

      41% of boards take on cybersecurity directly rather than allocating it to another body (e.g. audit committee).

      19% of private companies do not discuss cybersecurity with the board.

      (ISACA, 2018)

      Info-Tech Insight

      Metrics help to level the playing field

      Poor alignment between security and the business often stems from difficulties with explaining how security objectives support business goals, which is ultimately a communication problem.

      However, metrics help to facilitate these conversations, as long as the metrics are expressed in practical, relatable terms.

      Security metrics benefit the business

      Executives get just as much out of management metrics as the people running them.

      1. Metrics assuage executives’ fears
        • Metrics help executives (and security leaders) feel more at ease with where the company is security-wise. Metrics help identify areas for improvement and gaps in the organization’s security posture that can be filled. A good metrics program will help identify deficiencies in most areas, even outside the security program, helping to identify what work needs to be done to reduce risk and increase the security posture of the organization.
      2. Metrics answer executives’ questions
        • Numbers either help ease confusion or signify other areas for improvement. Offering quantifiable evidence, in a language that the business can understand, offers better understanding and insight into the information security program. Metrics also help educate on types of threats, staff needed for security, and budget needs to decrease risk based on management’s threat tolerance. Metrics help make an organization more transparent, prepared, and knowledgeable.
      3. Metrics help to continually prove security’s worth
        • Traditionally, the security team has had to fight for a seat at the executive table, with little to no way to communicate with the business. However, the new trend is that the security team is now being invited before they have even asked to join. This trend allows the security team to better communicate on the organization’s security posture, describe threats and vulnerabilities, present a “plan of action,” and get a pulse on the organization’s risk tolerance.

      Common myths make security metrics seem challenging

      Security professionals have the perception that metrics programs are difficult to create. However, this attitude usually stems from one of the following myths. In reality, security metrics are much simpler than they seem at first, and they usually help resolve existing challenges rather than create new ones.

      Myth Truth
      1 There are certain metrics that are important to all organizations, based on maturity, industry, etc. Metrics are indications of change; for a metric to be useful it needs to be tied to a goal, which helps you understand the change you're seeing as either a positive or a negative. Industry and maturity have little bearing here.
      2 Metrics are only worthwhile once a certain maturity level is reached Metrics are a tool to help an organization along the maturity scale. Metrics help organizations measure progress of their goals by helping them see which tactics are and are not working.
      3 Security metrics should focus on specific, technical details (e.g. of systems) Metrics are usually a means of demonstrating, objectively, the state of a security program. That is, they are a means of communicating something. For this reason, it is better that metrics be phrased in easily digestible, non-technical terms (even if they are informed by technical security statistics).

      Tie your metrics to goals to make them worthwhile

      SMART metrics are really SMART goals.

      Specific

      Measurable

      Achievable

      Realistic

      Timebound

      Achievable: What is an achievable metric?

      When we say that a metric is “achievable,” we imply that it is tied to a goal of some kind – the thing we want to achieve.

      How do we set a goal?

      1. Determine what outcome you are trying to achieve.
        • This can be small or large (e.g. I want to determine what existing systems can provide metrics, or I want a 90% pass rate on our monthly phishing tests).
      2. Decide what indicates that you’ve achieved your goal.
        • At what point would you be satisfied with the progress made on the initiative(s) you’re working on? What conditions would indicate victory for you and allow you to move on to another goal?
      3. Develop a key performance indicator (KPI) to measure progress towards that goal.
        • Now that you’ve defined what you’re trying to achieve, find a way to indicate progress in relative or relational terms (e.g. percentage change from last quarter, percentage of implementation completed, ratio of programs in place to those still needing implementation).

      Info-Tech’s security metrics methodology is repeatable and iterative to help boost maturity

      Security Metric Lifecycle

      Start:

      Review current state and decide on priorities.

      Set a SMART goal for improvement.

      Develop an appropriate KPI.

      Use KPI to monitor program improvement.

      Present metrics to the board.

      Revise metrics if necessary.

      Metrics go hand in hand with your security strategy

      A security strategy is ultimately a large goal-setting exercise. You begin by determining your current maturity and how mature you need to be across all areas of information security, i.e. completing a gap analysis.

      As such, linking your metrics program to your security strategy is a great way to get your metrics program up and running – but it’s not the only way.

      Check out the following Info-Tech resource to get started today:

      Build an Information Security Strategy

      The value of security metrics goes beyond simply increasing security

      This blueprint applies to you whether you need to develop a metrics program from scratch or optimize and update your current strategy.

      Value of engaging in security metrics:

      • Increased visibility into your operations.
      • Improved accountability.
      • Better communication with executives as a result of having hard evidence of security performance.
      • Improved security posture through better understanding of what is working and what isn’t within the security program.

      Value of Info-Tech’s security metrics blueprint:

      • Doesn’t overwhelm you and allows you to focus on determining the metrics you need to worry about now without pressuring you to do it all at once.
      • Helps you develop a growth plan as your organization and metrics program mature, so you continue to optimize.
      • Creates effective communication. Prepares you to present the metrics that truly matter to executives rather than confusing them with unnecessary data. Pay attention to metric accuracy and reproducibility. No management wants inconsistent reporting.

      Impact

      Short term: Streamline your program. Based on your organization’s specific requirements and risk profile, figure out which metrics are best for now while also planning for future metrics as your organization matures.

      Long term: Once the program is in place, improvements will come with increased visibility into operations. Investments in security will be encouraged when more evidence is available to executives, contributing to overall improved security posture. Potential opportunities for eventual cost savings also exist as there is more informed security spending and fewer incidents.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

      Guided Implementation

      “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

      Workshop

      “We need to hit the ground running and get this project kicked-off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

      Consulting

      “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

      Diagnostics and consistent frameworks used throughout all four options

      Link Security Metrics to Goals to Boost Maturity – Project Overview

      1. Link Security Metrics to Goals to Boost Maturity 2. Adapt Your Reporting Strategy for Various Metric Types
      Best-Practice Toolkit

      1.1 Review current state and set your goals

      1.2 Develop KPIs and prioritize your goals

      1.3 Implement and monitor the KPI to track goal progress

      2.1 Review best practices for presenting metrics

      2.2 Strategize your presentation based on metric type

      2.3 Tailor presentation to your audience

      2.4 Use your metrics to create a story about risk

      2.5 Revise your metrics

      Guided Implementations
      • Call 1: Setting Goals
      • Call 2: KPI Development
      • Call 1: Best Practices and Reporting Strategy
      • Call 2: Build a Dashboard and Presentation Deck
      Onsite Workshop Module 1: Current State, Initiatives, Goals, and KPIs Module 2: Metrics Reporting

      Phase 1 Outcome:

      • KPI development and populated metrics tracking tool.

      Phase 2 Outcome:

      • Reporting strategy with dashboard and presentation deck.

      Workshop overview

      Contact your account representative or email Workshops@InfoTech.com for more information.

      Workshop Day 1 Workshop Day 2 Workshop Day 3 Workshop Day 4 Workshop Day 5
      Activities

      Current State, Initiatives, and Goals

      • Discuss current state and existing approach to metrics.
      • Review contract metrics already in place (or available).
      • Determine security areas that should be measured.
      • Determine which stakeholders are involved.
      • Review current initiatives to address those risks (security strategy, if in place).
      • Begin developing SMART goals for your initiative roadmap.

      KPI Development

      • Continue SMART goal development.
      • Sort goals into types.
      • Rephrase goals as KPIs and list associated metric(s).
      • Continue KPI development.

      Metrics Prioritization

      • Lay out prioritization criteria.
      • Determine priority metrics (implementation).
      • Determine priority metrics (improvement & organizational trend).

      Metrics Reporting

      • Review metric types and discuss reporting strategies for each.
      • Develop a story about risk.
      • Discuss the use of KPXs and how to scale for less mature programs.

      Offsite Finalization

      • Review and finalization of documents drafted during workshop.
      Deliverables
      1. Gap analysis results
      1. Completed KPI development templates
      1. Prioritized metrics and tool for tracking and presentation.
      1. Key Performance Index tool and presentation materials.
      1. Finalization of completed deliverables

      Phase 1

      Link Security Metrics to Goals to Boost Maturity


      Phase 1

      1.1 Review current state and set your goals

      1.2 Develop KPIs and prioritize your goals

      1.3 Implement and monitor KPIs

      This phase will walk you through the following activities:

      • Current state assessment
      • Setting SMART goals
      • KPI development
      • Goals prioritization
      • KPI implementation

      This phase involves the following participants:

      • Security Team

      Outcomes of this phase

      • Goals-based KPIs
      • Security Metrics Determination and Tracking Tool

      Phase 1 outline

      Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

      Complete these steps on your own or call us to complete a guided implementation. A guided implementation is a series of two to three advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

      Guided Implementation 1: Link Security Metrics to Goals to Boost Maturity

      Proposed Time to Completion: 2-4 weeks

      Step 1.1: Setting Goals

      Start with an analyst kick-off call:

      • Determine current and target maturity for various security programs.
      • Develop SMART Goals.

      Then complete these activities…

      • CMMI Assessment

      Step 1.2 – 1.3: KPI Development

      Review findings with analyst:

      • Prioritize goals
      • Develop KPIs to track progress on goals
      • Track associated metrics

      Then complete these activities…

      • KPI Development

      With these tools & templates:

      • KPI Development Worksheet
      • Security Metrics Determination and Tracking Tool

      Phase 1 Results & Insights:

      • Basic Metrics program

      1.1 Review current state and set your goals

      120 minutes

      Let’s put the security program under the microscope.

      Before program improvement can take place, it is necessary to look at where things are at presently (in terms of maturity) and where we need to get them to.

      In other words, we need to perform a security program gap analysis.

      Info-Tech Best Practice

      The most thorough way of performing this gap analysis is by completing Info-Tech’s Build an Information Security Strategy blueprint, as it will provide you with a prioritized list of initiatives to boost your security program maturity.

      Completing an abbreviated gap analysis...

      • Security Areas
      • Network Security
      • Endpoint Security
      • Vulnerability Management
      • Identity Access Management
      • Incident Management
      • Training & Awareness
      • Compliance, Audit, & Review
      • Risk Management
      • Business Alignment & Governance
      • Data Security
      1. Using the CMMI scale on the next slide, assess your maturity level across the security areas to the left, giving your program a score from 1-5. Record your assessment on a whiteboard.
      2. Zone in on your areas of greatest concern and choose 3 to 5 areas to prioritize for improvement.
      3. Set a SMART goal for improvement, using the criteria on goals slides.

      Use the CMMI scale to contextualize your current maturity

      Use the Capability Maturity Model Integration (CMMI) scale below to help you understand your current level of maturity across the various areas of your security program.

      1. Initial
        • Incident can be managed. Outcomes are unpredictable due to lack of a standard operating procedure.
      2. Repeatable
        • Process in place, but not formally implemented or consistently applied. Outcomes improve but still lack predictability.
      3. Defined
        • Process is formalized and consistently applied. Outcomes become more predictable, due to consistent handling procedure.
      4. Managed
        • Process shows signs of maturity and can be tracked via metrics. Moving towards a predictive approach to incident management.
      5. Optimizing
        • Process reaches a fully reliable level, though improvements still possible. Regularity allows for process to be automated.

      (Adapted from the “CMMI Institute Maturity Model”)

      Base your goals around the five types of metrics

      Choose goals that make sense – even if they seem simple.

      The most effective metrics programs are personalized to reflect the goals of the security team and the business they work for. Using goals-based metrics allows you to make incremental improvements that can be measured and reported on, which makes program maturation a natural process.

      Info-Tech Best Practice

      Before setting a SMART goal, take a moment to consider your maturity for each security area, and which metric type you need to collect first, before moving to more ambitious goals.

      Security Areas

      • Network Security
      • Endpoint Security
      • Vulnerability Management
      • Identity Access Management
      • Incident Management
      • Training & Awareness
      • Compliance, Audit & Review
      • Risk Management
      • Business Alignment & Governance
      • Data Security
      Metric Type Description
      Initial Probe Determines what can be known (i.e. what sources for metrics exist?).
      Baseline Testing Establishes organization’s normal state based on current metrics.
      Implementation Focuses on setting up a series of related processes to increase organizational security (i.e. roll out MFA).
      Improvement Sets a target to be met and then maintained based on organizational risk tolerance.
      Organizational Trends Culls together several metrics to track (sometimes predict) how various trends affect the organization’s overall security. Usually focuses on large-scale issues (e.g. likelihood of a data breach).

      Set SMART goals for your security program

      Specific

      Measurable

      Achievable

      Realistic

      Timebound

      Now that you have determined which security areas you’d like to improve, decide on a goal that meets the SMART criteria.

      Examples of possible goals for various maturity levels:

      1. Perform initial probe to determine number of systems capable of providing metrics by the end of the week.
      2. Take baseline measurements each month for three months to determine organization’s baseline state.
      3. Implement a vulnerability management program to improve baseline state by the end of the quarter.
      4. Improve deployment of critical patches by applying 90% of them within the set window by the end of the year.
      5. Demonstrate how vulnerability management affects broad organizational trends at quarterly report to senior leadership.

      Compare the bolded text in these examples with the metric types on the previous slide

      Record and assess your goals in the Security Metrics Determination and Tracking Tool

      1.1 Security Metrics Determination and Tracking Tool

      Use tab “2. Identify Security Goals” to document and assess your goals.

      To increase visibility into the cost, effort, and value of any given goal, assess them using the following criteria:

      • Initial Cost
      • Ongoing Cost
      • Initial Staffing
      • Ongoing Staffing
      • Alignment w/Business
      • Benefit

      Use the calculated Cost/Effort Rating, Benefit Rating, and Difference Score later in this project to help with goal prioritization.

      Info-Tech Best Practice

      If you have already completed a security strategy with Info-Tech resources, this work may likely have already been done. Consult your Information Security Program Gap Analysis Tool from the Build an Information Security Strategy research.

      1.2 Develop KPIs and prioritize your goals

      There are two paths to success.

      At this time, it is necessary to evaluate the priorities of your security program.

      Option 1: Progress to KPI Development

      • If you would like practice developing KPIs for multiple goals to get used to the process, move to KPI development and then assess which goals you can pursue now based on resources available, saving the rest for later.

      Option 2: Progress to Prioritization of Goals

      • If you are already comfortable with KPI development and do not wish to create extras for later use, then prioritize your goals first and then develop KPIs for them.

      Phase 1 Schematic

      • Gap Analysis
      • Set SMART Goals (You are here.)
        • Develop KPIs
      • Prioritize Goals
      • Implement KPI & Monitor
      • Phase 2

      Develop a key performance indicator (KPI)

      Find out if you’re meeting your goals.

      Terms like “key performance indicator” may make this development practice seem more complicated than it really is. A KPI is just a single metric used to measure success towards a goal. In relational terms (i.e. as a percentage, ratio, etc.) to give it context (e.g. % of improvement over last quarter).

      KPI development is about answering the question: what would indicate that I have achieved my goal?

      To develop a KPI follow these steps:

      1. Review the case study on the following slides to get a sense of how KPIs can start simple and general and get more specific and complex over time.
      2. Using the example to the right, sort your SMART goals from step 1.1 into the various metric types, then determine what success would look like for you. What outcome are you trying to achieve? How will you know when you’ve achieved it?
      3. Fill out the KPI Development Worksheets to create sample KPIs for each of the SMART goals you have created. Ensure that you complete the accompanying KPI Checklist.

      KPIs differ from goal to goal, but their forms follow certain trends

      Metric Type KPI Form
      Initial Probe Progress of probe (e.g. % of systems checked to see if they can supply metrics).
      Baseline Testing What current data shows (e.g. % of systems needing attention).
      Implementation Progress of the implementation (e.g. % of complete vulnerability management program implementation).
      Improvement The threshold or target to be achieved and maintained (e.g. % of incidents responded to within target window).
      Organizational Trends The interplay of several KPIs and how they affect the organization’s risk posture (e.g. assessing the likelihood for a data breach).

      Explore the five metric types

      1. Initial Probe

      Focused on determining how many sources for metrics exist.

      • Question: What am I capable of knowing?
      • Goal: To determine what level of insight we have into our security processes.
      • Possible KPI: % of systems for which metrics are available.
      • Decision: Do we have sufficient resources available to collect metrics?

      2. Baseline Testing

      Focused on gaining initial insights about the state of your security program (what are the measurements?).

      • Question: Does this data suggest areas for improvement?
      • Goal: To create a roadmap for improvement.
      • Possible KPI: % of systems that provide useful metrics to measure improvement.
      • Decision: Is it necessary to acquire tools to increase, enhance, or streamline the metrics-gathering process?

      Info-Tech Insight

      Don't lose hope if you lack resources to move beyond these initial steps. Even if you are struggling to pull data, you can still draw meaningful metrics. The percent or ratio of processes or systems you lack insight into can be very valuable, as it provides a basis to initiate a risk-based discussion with management about the organization's security blind spots.

      Explore the five metric types (cont’d)

      3. Program Implementation

      Focused on developing a basic program to establish basic maturity (e.g. implement an awareness and training program).

      • Question: What needs to be implemented to establish basic maturity?
      • Goal: To begin closing the gap between current and desired maturity.
      • Possible KPI: % of implementation completed.
      • Decision: Have we achieved a formalized and repeatable process?

      4. Improvement

      Focused on attaining operational targets to lower organizational risk.

      • Question: What other related activities could help to support this goal (e.g. regular training sessions)?
      • Goal: To have metrics operate above or below a certain threshold (e.g. lower phishing-test click rate to an average of 10% across the organization)
      • Possible KPI: Phishing click rate %
      • Decision: What other metrics should be tracked to provide insight into KPI fluctuations?

      Info-Tech Insight

      Don't overthink your KPI. In many cases it will simply be your goal rephrased to express a percentage or ratio. In others, like the example above, it makes sense for them to be identical.

      5. Organizational Impact

      Focused on studying several related KPIs (Key Performance Index, or KPX) in an attempt to predict risks.

      • Question: What risks does the organization need to address?
      • Goal: To provide high-level summaries of several metrics that suggest emerging or declining risks.
      • Possible KPI: Likelihood of a given risk (based on the trends of the KPX).
      • Decision: Accept the risk, transfer the risk, mitigate the risk?

      Case study: Healthcare example

      Let’s take a look at KPI development in action.

      Meet Maria, the new CISO at a large hospital that desperately needs security program improvements. Maria’s first move was to learn the true state of the organization’s security. She quickly learned that there was no metrics program in place and that her staff were unaware what, if any, sources were available to pull security metrics from.

      After completing her initial probe into available metrics and then investigating the baseline readings, she determined that her areas of greatest concern were around vulnerability and access management. But she also decided it was time to get a security training and awareness program up and running to help mitigate risks in other areas she can’t deal with right away.

      See examples of Maria’s KPI development on the next four slides...

      Info-Tech Insight

      There is very little variation in the kinds of goals people have around initial probes and baseline testing. Metrics in these areas are virtually always about determining what data sources are available to you and what that data actually shows. The real decisions start in determining what you want to do based on the measures you’re seeing.

      Metric development example: Vulnerability Management

      See examples of Maria’s KPI development on the next four slides...

      Implementation

      Goal: Implement vulnerability management program

      KPI: % increase of insight into existing vulnerabilities

      Associated Metric: # of vulnerability detection methods

      Improvement

      Goal: Improve deployment time for patches

      KPI: % of critical patches fully deployed within target window

      • Associated Metric 1: # of critical vulnerabilities not patched
      • Associated Metric 2: # of patches delayed due to lack of staff
      • Associated Metric X

      Metric development example: Identity Access Management

      Implementation

      Goal: Implement MFA for privileged accounts

      KPI: % of privileged accounts with MFA applied

      Associated Metric: # of privileged accounts

      Improvement

      Goal: Remove all unnecessary privileged accounts

      KPI: % of accounts with unnecessary privileges

      • Associated Metric 1: # of privileged accounts
      • Associated Metric 2: # of necessary privileged accounts
      • Associated Metric X

      Metric development example: Training and Awareness

      Implementation

      Goal: Implement training and awareness program

      KPI: % of organization trained

      Associated Metric: # of departments trained

      Improvement

      Goal: Improve time to report phishing

      KPI: % of phishing cases reported within target window

      • Associated Metric 1: # of phishing tests
      • Associated Metric 2: # of training sessions
      • Associated Metric X

      Metric development example: Key Performance Index

      Organizational Trends

      Goal: Predict Data Breach Likelihood

      • KPX 1: Insider Threat Potential
        • % of phishing cases reported within target window
          • Associated Metrics:
            • # of phishing tests
            • # of training sessions
        • % of critical patches fully deployed within target window
          • Associated Metrics:
            • # of critical vulnerabilities not patched
            • # of patches delayed due to lack of staff
        • % of accounts with unnecessary privileges
          • Associated Metrics:
            • # of privileged accounts
            • # of necessary privileged accounts
      • KPX 2: Data Leakage Issues
        • % of incidents related to unsecured databases
          • Associated Metrics:
            • # of unsecured databases
            • # of business-critical databases
        • % of misclassified data
          • Associated Metrics:
            • # of misclassified data reports
            • # of DLP false positives
        • % of incidents involving data-handling procedure violations.
          • Associated Metrics:
            • # of data processes with SOP
            • # of data processes without SOP
      • KPX 3: Endpoint Vulnerability Issues
        • % of unpatched critical systems
          • Associated Metrics:
            • # of unpatched systems
            • # of missed patches
        • % of incidents related to IoT
          • Associated Metrics:
            • # of IoT devices
            • # of IoT unsecure devices
        • % of incidents related to BYOD
          • Associated Metrics:
            • # of end users doing BYOD
            • # of BYOD incidents

      Develop Goals-Based KPIs

      1.2 120 minutes

      Materials

      • Info-Tech KPI Development Worksheets

      Participants

      • Security Team

      Output

      • List of KPIs for immediate and future use (can be used to populate Info-Tech’s KPI Development Tool).

      It’s your turn.

      Follow the example of the CISO in the previous slides and try developing KPIs for the SMART goals set in step 1.1.

      • To begin, decide if you are starting with implementation or improvement metrics.
      • Enter your goal in the space provided on the left-hand side and work towards the right, assigning a KPI to track progress towards your goal.
      • Use the associated metrics boxes to record what raw data will inform or influence your KPI.
        • Associated metrics are connected to the KPI box with a segmented line. This is because these associated metrics are not absolutely necessary to track progress towards your goal.
        • However, if a KPI starts trending in the wrong direction, these associated metrics would be used to determine where the problem has occurred.
      • If desired, bundle together several related KPIs to create a key performance index (KPX), which is used to forecast the likelihood of certain risks that would have a major business impact (e.g. potential for insider threat, or risk for a data breach).

      Record KPIs and assign them to goals in the Security Metrics Determination and Tracking Tool

      1.2 Security Metrics Determination and Tracking Tool

      Document KPI metadata in the tool and optionally assign them to a goal.

      Tab “3. Identify Goal KPIs” allows you to record each KPI and its accompanying metadata:

      • Source
      • Owner
      • Audience
      • KPI Target
      • Effort to Collect
      • Frequency of Collection
      • Comments

      Optionally, each KPI can be mapped to goals defined on tab “2. Identify Security Goals.”

      Info-Tech Best Practice

      Ensure your metadata is comprehensive, complete, and realistic. A different employee should be able to use only the information outlined in the metadata to continue collecting measurements for the program.

      Complete Info-Tech’s KPI Development Worksheets

      1.2 KPI Development Worksheet

      Use these worksheets to model the maturation of your metrics program.

      Follow the examples contained in this slide deck and practice creating KPIs for:

      • Implementation metrics
      • Improvement metrics
      • Organizational trends metrics

      As well as drafting associated metrics to inform the KPIs you create.

      Info-Tech Best Practice

      Keep your metrics program manageable. This exercise may produce more goals, metrics, and KPIs than you deal with all at once. But that doesn’t mean you can’t save some for future use.

      Build an effort map to prioritize your SMART goals

      1.2 120 minutes

      Materials

      • Whiteboard
      • Sticky notes
      • Laptop

      Participants

      • Security team
      • Other stakeholders

      Output

      • Prioritized list of SMART goals

      An effort map visualizes a cost and benefit analysis. It is a quadrant output that visually shows how your SMART goals were assessed. Use the calculated Cost/Effort Rating and Benefit Rating values from tab “2. Identify Security Goals” of the Security Metrics Determination and Tracking Tool to aid this exercise.

      Steps:

      1. Establish the axes and colors for your effort map:
        1. X-axis (horizontal) - Security benefit
        2. Y-axis (vertical) - Overall cost/effort
        3. Sticky color - Business alignment
      2. Create sticky notes for each SMART goal and place them onto the effort map based on your determined axes.
        • Goal # Example Security Goal - Benefit (1-12) - Cost (1-12)

      The image shows a matric with four quadrants. The X-axis is labelled Low Benefit on the left side and High benefit on the right side. The Y-axis is labelled Low cost at the top and High cost at the bottom. The top left quadrant is labelled Could Dos, the top right quadrant is labelled Must Dos, the lower left quadrant is labelled May Not Dos, and the lower right quadrant is Should Dos. On the right, there are three post-it style notes, the blue one labelled High Alignment, the yellow labelled Medium Alignment, and the pink labelled Low Alignment.

      1.3 Implement and monitor the KPI to track goal progress

      Let’s put your KPI into action!

      Now that you’ve developed KPIs to monitor progress on your goals, it’s time to use them to drive security program maturation by following these steps:

      1. Review the KPI Development Worksheets (completed in step 1.2) for your prioritized list of goals. Be sure that you are able to track all of the associated metrics you have identified.
      2. Track the KPI and associated metrics using Info-Tech’s KPI Development Tool (see following slide).
      3. Update the data as necessary according to your SMART criteria of your goal.

      A Word on Key Risk Indicators...

      The term key risk indicator (KRI) gets used in a few different ways. However, in most cases, KRIs are closely associated with KPIs.

      1. KPIs and KRIs are the same thing
        • A KPI, at its core, is really a measure of risk. Sometimes it is more effective to emphasize that risk rather than performance (i.e. the data shows you’re not meeting your goal).
      2. KRI is KPI going the wrong way
        • After achieving the desired threshold for an improvement goal, our new goal is usually to maintain such a state. When this balance is upset, it indicates that settled risk has once again become active.
      3. KRI as a predictor of emerging risks
        • When organizations reach a highly mature state, they often start assessing how events external to the organization can affect the optimal performance of the organization. They monitor such events or trends and try to predict when the organization is likely to face additional risks.

      Track KPIs in the Security Metrics Determination and Tracking Tool

      1.3 Security Metrics Determination and Tracking Tool

      Once a metric has been measured, you have the option of entering that data into tab “4. Track Metrics” of the Tool.

      Tracking metric data in Info-Tech's tool provides the following data visualizations:

      • Sparklines at the end of each row (on tab “4. Track Metrics”) for a quick sense of metric performance.
      • A metrics dashboard (on tab “5. Graphs”) with three graph options in two color variations for each metric tracked in the tool, and an overall metric program health gauge.

      Info-Tech Best Practice

      Be diligent about measuring and tracking your metrics. Record any potential measurement biases or comments on measurement values to ensure you have a comprehensive record for future use. In the tool, this can be done by adding a comment to a cell with a metric measurement.

      If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

      Book a workshop with our Info-Tech analysts:

      Workshops offer an easy way to accelerate your project. While onsite, our analysts will work with you and your team to facilitate the activities outlined in the blueprint.

      Getting key stakeholders together to formalize the program, while getting started on data discovery and classification, allows you to kickstart the overall program.

      In addition, leverage over-the-phone support through Guided Implementations included in advisory memberships to ensure the continuous improvement of the classification program even after the workshop.

      Logan Rohde

      Research Analyst – Security, Risk & Compliance Info-Tech Research Group

      Ian Mulholland

      Senior Research Analyst – Security, Risk & Compliance Info-Tech Research Group

      Call 1-888-670-8889 for more information.

      Phase 2

      Adapt Your Reporting Strategy for Various Metric Types


      Phase 2

      2.1 Review best practices for presenting metrics

      2.2 Strategize your presentation based on metric type

      2.3 Tailor your presentation to your audience

      2.4 Use your metrics to create a story about risk

      2.5 Revise Metrics

      This phase will walk you through the following activities:

      • Develop reporting strategy
      • Use metrics to create a story about risk
      • Metrics revision

      This phase involves the following participants:

      • Security Team

      Outcomes of this phase

      • Metrics Dashboard
      • Metrics Presentation Deck

      Phase 2 outline

      Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

      Complete these steps on your own or call us to complete a guided implementation. A guided implementation is a series of two to three advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

      Guided Implementation 2: Adapt Your Reporting Strategy for Various Metric Types

      Proposed Time to Completion: 2-4 weeks

      Step 2.1 – 2.3: Best Practices and Reporting Strategy

      Start with an analyst kick-off call:

      • Do’s and Don’ts of reporting metrics.
      • Strategize presentation based on metric type.

      Then complete these activities…

      • Strategy development for 3-5 metrics

      Step 2.4 – 2.5: Build a Dashboard and Presentation Deck

      Review findings with analyst:

      • Review strategies for reporting.
      • Compile a Key Performance Index.
      • Revise metrics.

      Then complete these activities…

      • Dashboard creation
      • Presentation development

      With these tools & templates:

      • Security Metrics Determination and Tracking Tool Template
      • Security Metrics KPX Dashboard Tool

      Phase 2 Results & Insights:

      • Completed reporting strategy with presentable dashboard

      2.1 Review best practices for presenting metrics

      Avoid technical details (i.e. raw data) by focusing on the KPI.

      • KPIs add context to understand the behavior and associated risks.

      Put things in terms of risk; it's the language you both understand.

      • This usually means explaining what will happen if not addressed and what you recommend.
      • There are always three options:
        • Address it completely
        • Address it partially
        • Do not address it (i.e. accept the risk)

      Explain why you’re monitoring metrics in terms of the goals you’re hoping to achieve.

      • This sets you up well to explain what you've been doing and why it's important for you to meet your goals.

      Choose between KPI or KRI as the presentation format.

      • Base your decision on whether you are trying to emphasize current success or risk.

      Match presentation with the audience.

      • Board presentations will be short; middle-management ones may be a bit longer.
      • Maximize your results by focusing on the minimum possible information to make sure you sufficiently get your point across.
      • With the board, plan on showing no more than three slides.

      Read between the lines.

      • It can be difficult to get time with the board, so you may find yourself in a trial and error position, so pay attention to cues or suggestions that indicate the board is interested in something.
      • If you can, make an ally to get the inside scoop on what the board cares about.

      Read the news if you’re stuck for content.

      • Board members are likely to have awareness (and interest) in large-scale risks like data breaches and ransomware.

      Present your metrics as a story.

      • Summarize how the security program looks to you and why the metrics lead you to see it this way.

      2.2 Strategize your presentation based on metric type (1 of 5)

      Metric Type: Initial Probe

      Scenario: Implementing your first metrics program.

      • All metrics programs start with determining what measurements you are capable of taking.

      Decisions: Do you have sufficient insight into the program? (i.e. do you need to acquire additional tools to collect metrics?)

      Strategy: If there are no barriers to this (e.g. budget), then focus your presentation on the fact that you are addressing the risk of not knowing what your organization's baseline state is and what potential issues exist but are unknown. This is likely the first phase of an improvement plan, so sketching the overall plan is a good idea too.

      • If budget is an issue, explain the risks associated with not knowing and what you would need to make it happen.

      Possible KPIs:

      • % of project complete.
      • % of systems that provide worthwhile metrics.

      Strategize your presentation based on metric type (2 of 5)

      Metric Type: Baseline Testing

      Scenario: You've taken the metrics to determine what your organization’s normal state is and you're now looking towards addressing your gaps or problem areas.

      Decisions: What needs to be prioritized first and why? Are additional resources required to make this happen?

      Strategy: Explain your impression of the organization's normal state and what you plan to do about it. In other words, what goals are you prioritizing and why? Be sure to note any challenges that may occur along the way (e.g. staffing).

      • If the board doesn't like to open their pocketbook, your best play is to explain what stands to happen (or is happening) if risks are not addressed.

      Possible KPIs:

      • % of goals complete.
      • % of metrics indicating urgent attention needed.

      Strategize your presentation based on metric type (3 of 5)

      Metric Type: Implementation

      Scenario: You are now implementing solutions to address your security priorities.

      Decisions: What, to you, would establish the basis of a program?

      Strategy: Focus on what you're doing to implement a certain security need, why, and what still needs to be done when you’re finished.

      • Example: To establish a training and awareness program, a good first step is to actually hold training sessions with each department. A single lecture is simple but something to build from. A good next step would be to hold regular training sessions or implement monthly phishing tests.

      Possible KPIs:

      • % of implementation complete (e.g. % of departments trained).

      Strategize your presentation based on metric type (4 of 5)

      Metric Type: Improvement

      Scenario: Now that a basic program has been established, you are looking to develop its maturity to boost overall performance (i.e. setting a new development goal).

      Decisions: What is a reasonable target, given the organization's risk tolerance and current state?

      Strategy: Explain that you're now working to tighten up the security program. Note that although things are improving, risk will always remain, so we need to keep it within a threshold that’s proportionate with our risk tolerance.

      • Example: Lower phishing-test click rate to 10% or less. Phishing will always be a risk, and just one slip up can have a huge effect on business (i.e. lost money).

      Possible KPIs:

      • % of staff passing the phishing test.
      • % of employees reporting phishing attempts within time window.

      Strategize your presentation based on metric type (5 of 5)

      Metric Type: Organizational Trends

      Scenario: You've reached a mature state and now how several KPIs being tracked. You begin to look at several KPIs together (i.e. a KPX) to assess the organization's exposure for certain broad risk trends.

      Decisions: Which KPIs can be used together to look at broader risks?

      Strategy: Focus on the overall likelihood of a certain risk and why you've chosen to assess it with your chosen KPIs. Spend some time discussing what factors affect the movement of these KPIs, demonstrating how smaller behaviors create a ripple effect that affects the organization’s exposure to large-scale risks.

      Possible KPX: Insider Threat Risk

      • % of phishing test failures.
      • % of critical patches missed.
      • % of accounts with unnecessary privileges.

      Change your strategy to address security challenges

      Even challenges can elicit useful metrics.

      Not every security program is capable of progressing smoothly through the various metric types. In some cases, it is impossible to move towards goals and metrics for implementation, improvement, or organizational trends because the security program lacks resources.

      Info-Tech Insight

      When your business is suffering from a lack of resources, acquiring these resources automatically becomes the goal that your metrics should be addressing. To do this, focus on what risks are being created because something is missing.

      When your security program is lacking a critical resource, such as staff or technology, your metrics should focus on what security processes are suffering due to this lack. In other words, what critical activities are not getting done?

      KPI Examples:

      • % of critical patches not deployed due to lack of staff.
      • % of budget shortfall to acquire vulnerability scanner.
      • % of systems with unknown risk due to lack of vulnerability scanner.

      2.3 Tailor presentation to your audience

      Metrics come in three forms...

      1. Raw Data

      • Taken from logs or reports, provides values but not context.
      • Useful for those with technical understanding of the organization’s security program.

      2. Management-Level

      • Raw data that has been contextualized and indicates performance of something (i.e. a KPI).
      • Useful for those with familiarity with the overall state of the security program but do not have a hands-on role.

      3. Board-Level

      • KPI with additional context indicating overall effect on the organization.
      • Useful for those removed from the security program but who need to understand the relationship between security, business goals, and cyber risk.

      For a metric to be useful it must...

      1. Be understood by the audience it’s being presented to.
        • Using the criteria on the left, choose which metric form is most appropriate.
      2. Indicate whether or not a certain target or goal is being met.
        • Don’t expect metrics to speak for themselves; explain what the indications and implications are.
      3. Drive some kind of behavioral or strategic change if that target or goal is not being met.
        • Metrics should either affirm that things are where you want them to be or compel you to take action to make an improvement. If not, it is not a worthwhile metric.

      As a general rule, security metrics should become decreasingly technical and increasingly behavior-based as they are presented up the organizational hierarchy.

      "The higher you travel up the corporate chain, the more challenging it becomes to create meaningful security metrics. Security metrics are intimately tied to their underlying technologies, but the last thing the CEO cares about is technical details." – Ben Rothke, Senior Information Security Specialist, Tapad.

      Plan for reporting success

      The future of your security program may depend on this presentation; make it count.

      Reporting metrics is not just another presentation. Rather, it is an opportunity to demonstrate and explain the value of security.

      It is also a chance to correct any misconceptions about what security does or how it works.

      Use the tips on the right to help make your presentation as relatable as possible.

      Info-Tech Insight

      There is a difference between data manipulation and strategic presentation: the goal is not to bend the truth, but to present it in a way that allows you to show the board what they need to see and to explain it in terms familiar to them.

      General Tips for a Successful Presentation

      Avoid jargon; speak in practical terms

      • The board won’t receive your message if they can’t understand you.
      • Explain things as simply as you can; they only need to know enough to make decisions about addressing cyber risk.

      Address compliance

      • Boards are often interested in compliance, so be prepared to talk about it, but clarify that it doesn't equal security.
      • Instead, use compliance as a bridge to discussing areas of the security program that need attention.

      Have solid answers

      • Try to avoid answering questions with the answer, “It depends.”
        • Depends on what?
        • Why?
        • What do you recommend?
      • The board is relying on you for guidance, so be prepared to clarify what the board is asking (you may have to read between the lines to do this).
      • Also address the pain points of board members and have answers to their questions about how to resolve them.

      2.4 Use your metrics to create a story about risk

      Become the narrator of your organization’s security program.

      Security is about managing risk. This is also its primary value to the organization. As such, risk should be the theme of the story you tell.

      "Build a cohesive story that people can understand . . . Raw metrics are valuable from an operations standpoint, but at the executive level, it's about a cohesive story that helps executives understand the value of the security program and keeps the company moving forward. "– Adam Ely, CSO and Co-Founder, Bluebox Security, qtd. by Tenable, 2016

      How to Develop Your Own Story...

      1. Review your security program goals and the metrics you’re using to track progress towards them. Then, decide which metrics best tell this story (i.e. what you’re doing and why).
        • Less is more when presenting metrics, so be realistic about how much your audience can digest in one sitting.
        • Three metrics is usually a safe number; choose the ones that are most representative of your goals.
      2. Explain why you chose the goals you did (i.e. what risks were you addressing?). Then, make an honest assessment of how the security program is doing as far as meeting those goals:
        • What’s going well?
        • What still needs improvement?
        • What about your metrics suggests this?
      3. Address how risks have changed and explain your new recommended course of action.
        • What risks were present when you started?
        • What risks remain despite your progress?
        • How do these risks affect the business operation and what can security do to help?

      Story arc for security metrics

      The following model encapsulates the basic trajectory of all story development.

      Use this model to help you put together your story about risk.

      Introduction: Overall assessment of security program.

      Initial Incident: Determination of the problems and associated risks.

      Rising Action: Creation of goals and metrics to measure progress.

      Climax: Major development indicated by metrics.

      Falling Action: New insights gained about organization’s risks.

      Resolution: Recommendations based on observations.

      Info-Tech Best Practice

      Follow this model to ensure that your metrics presentation follows a coherent storyline that explains how you assessed the problem, why you chose to address it the way you did, what you learned in doing so, and finally what should be done next to boost the security program’s maturity.

      Use a nesting-doll approach when presenting metrics

      Move from high-level to low-level to support your claims

      1. Avoid the temptation to emphasize technical details when presenting metrics. The importance of a metric should be clear from just its name.
      2. This does not mean that technical details should be disregarded entirely. Your digestible, high-level metrics should be a snapshot of what’s taking place on the security ground floor.
      3. With this in mind, we should think of our metrics like a nesting doll, with each metrics level being supported by the one beneath it.

      ...How do you know that?

      Board-Level KPI

      Mgmt.-Level KPI

      Raw Data

      Think of your lower-level metrics as evidence to back up the story you are telling.

      When you’re asked how you arrived at a given conclusion, you know it’s time to go down a level and to explain those results.

      Think of this like showing your work.

      Info-Tech Insight

      This approach is built into the KPX reporting format, but can be used for all metric types by drawing from your associated metrics and goals already achieved.

      Use one of Info-Tech’s dashboards to present your metrics

      2.4 Security Metrics Determination and Tracking Tool

      Choose the dashboard tool that makes the most sense for you.

      Info-Tech provides two options for metric dashboards to meet the varying needs of our members.

      If you’re just starting out, you’ll likely be inclined towards the dashboard within the Security Metrics Determination and Tracking Tool (seen here).

      The image shows a screenshot of the Security Metrics Determination and Tracking Tool.

      But if you’ve already got several KPIs to report on, you may prefer the Security Metrics KPX Dashboard Tool, featured on the following slides.

      Info-Tech Best Practice

      Not all graphs will be needed in all cases. When presenting, consider taking screenshots of the most relevant data and displaying them in Info-Tech’s Board-Level Security Metrics Presentation Template.

      Use one of Info-Tech’s dashboards to present your metrics

      2.4 Security Metrics KPX Dashboard

      Use Info-Tech’s Security Metrics KPX Dashboard to track and show your work.

      The image shows a screenshot of the Definitions section of the Security Metrics KPX Dashboard

      1. Start by customizing the definitions on tab 1 to match your organization’s understanding of high, medium, and low risk across the three impact areas (functional, informational, and recoverability).
      2. Next, enter up to 5 business goals that your security program supports.

      Use one of Info-Tech’s dashboards to present your metrics

      2.4 Security Metrics KPX Dashboard

      Use Info-Tech’s Security Metrics KPX Dashboard to track and show your work.

      The image shows a screenshot of tab 2 of the Security Metrics KPX Dashboard.

      1. On tab 2, enter the large-scale risk you are tracking
      2. Proceed by naming each of your KPXs after three broad risks that – to you – contribute to the large-scale risk.

      Use one of Info-Tech’s dashboards to present your metrics

      2.4 Security Metrics KPX Dashboard

      Use Info-Tech’s Security Metrics KPX Dashboard to track and show your work.

      The image is the same screenshot from the previous section, of tab 2 of the Security Metrics KPX Dashboard.

      1. Then, add up to five KPIs aimed at managing more granular risks that contribute to the broad risk.
      2. Assess the frequency and impact associated with these more granular risks to determine how likely it is to contribute to the broad risk the KPX is tracking.

      Use one of Info-Tech’s dashboards to present your metrics

      2.4 Security Metrics KPX Dashboard

      Use Info-Tech’s Security Metrics KPX Dashboard to track and show your work.

      The image is the same screenshot of tab 2 of the Security Metrics KPX Dashboard.

      1. Repeat as necessary for the other KPXs on tab 2.
      2. Repeat steps 3-7 for up to two more large-scale risks and associated KPXs on tabs 3 and 4.

      Use one of Info-Tech’s dashboards to present your metrics

      2.4 Security Metrics KPX Dashboard

      Use Info-Tech’s Security Metrics KPX Dashboard to track and show your work.

      The image shows a chart titled Business Alignment, with sample Business Goals and KPXs filled in.

      1. If desired, complete the Business Alignment evaluation (located to the right of KPX 2 on tabs 2-4) to demonstrate how well security is supporting business goals.

      "An important key to remember is to be consistent and stick to one framework once you've chosen it. As you meet with the same audiences repeatedly, having the same framework for reference will ensure that your communications become smoother over time." – Caroline Wong, Chief Strategy Officer, Cobalt.io

      Use one of Info-Tech’s dashboards to present your metrics

      2.4 Security Metrics KPX Dashboard

      Use Info-Tech’s Security Metrics KPX Dashboard to track and show your work.

      The image shows a screenshot of the dashboard on tab 5 of the Security Metrics KPX Dashboard.

      1. Use the dashboard on tab 5 to help you present your security metrics to senior leadership.

      Use one of Info-Tech’s dashboards to present your metrics

      2.4 Security Metrics KPX Dashboard

      Use Info-Tech’s Security Metrics KPX Dashboard to track and show your work.

      The image shows the same screenshot of Tab 2 of the Security Metrics KPX Dashboard that was shown in previous sections.

      Best Practice:

      This tool helps you convert your KPIs into the language of risk by assessing frequency and severity, which helps to make the risk relatable for senior leadership. However, it is still useful to track fluctuations in terms of percentage. To do this, track changes in the frequency, severity, and trend scores from quarter to quarter.

      Customize Info-Tech’s Security Metrics Presentation Template

      2.4 Board-Level Security Metrics Presentation Template

      Use the Board-Level Security Metrics Presentation Template deck to help structure and deliver your metrics presentation to the board.

      To make the dashboard slide, simply copy and paste the charts from the dashboard tool and arrange the images as needed.

      Adapt the status report and business alignment slides to reflect the story about risk that you are telling.

      2.5 Revise your metrics

      What's next?

      Now that you’ve made it through your metrics presentation, it’s important to reassess your goals with feedback from your audience in mind. Use the following workflow.

      The image shows a flowchart titled Metrics-Revision Workflow. The flowchart begins with the question Have you completed your goal? and then works through multiple potential answers.

      If you want additional support, have our analysts guide you through this phase as part of an Info-Tech workshop

      Book a workshop with our Info-Tech analysts:

      Workshops offer an easy way to accelerate your project. While onsite, our analysts will work with you and your team to facilitate the activities outlined in the blueprint.

      Getting key stakeholders together to formalize the program, while getting started on data discovery and classification, allows you to kickstart the overall program.

      In addition, leverage over-the-phone support through Guided Implementations included in advisory memberships to ensure the continuous improvement of the classification program even after the workshop.

      Logan Rohde

      Research Analyst – Security, Risk & Compliance Info-Tech Research Group

      Ian Mulholland

      Senior Research Analyst – Security, Risk & Compliance Info-Tech Research Group

      Call 1-888-670-8889 for more information.

      Insight breakdown

      Metrics lead to maturity, not vice versa.

      • Tracking metrics helps you assess progress and regress in your security program, which helps you quantify the maturity gains you’ve made.

      Don't lose hope if you lack resources to move beyond baseline testing.

      • Even if you are struggling to pull data, you can still draw meaningful metrics. The percent or ratio of processes or systems you lack insight into can be very valuable, as it provides a basis to initiate a risk-based discussion with management about the organization's security blind spots.

      The best metrics are tied to goals.

      • Tying your metrics to goals ensures that you are collecting metrics for a specific purpose rather than just to watch the numbers change.

      Summary of accomplishment

      Knowledge Gained

      • Current maturity assessment of security areas
      • Setting SMART goals
      • Metric types
      • KPI development
      • Goals prioritization
      • Reporting and revision strategies

      Processes Optimized

      • Metrics development
      • Metrics collection
      • Metrics reporting

      Deliverables Completed

      • KPI Development Worksheet
      • Security Metrics Determination and Tracking Tool
      • Security Metrics KPX Dashboard Tool
      • Board-Level Security Metrics Presentation Template

      Research contributors and experts

      Mike Creaney, Senior Security Engineer at Federal Home Loan Bank of Chicago

      Peter Chestna, Director, Enterprise Head of Application Security at BMO Financial Group

      Zane Lackey, Co-Founder / Chief Security Officer at Signal Sciences

      Ben Rothke, Senior Information Security Specialist at Tapad

      Caroline Wong, Chief Strategy Officer at Cobalt.io

      2 anonymous contributors

      Related Info-Tech research

      Build an Information Security Strategy

      Tailor best practices to effectively manage information security.

      Implement a Security Governance and Management Program

      Align security and business objectives to get the greatest benefit from both.

      Bibliography

      Capability Maturity Model Integration (CMMI). ISACA. Carnegie Mellon University.

      Ely, Adam. “Choose Security Metrics That Tell a Story.” Using Security Metrics to Drive Action: 33 Experts Share How to Communicate Security Program Effectiveness to Business Executives and the Board Eds. 2016. Web.

      https://www.ciosummits.com/Online_Assets_Tenable_eBook-_Using_Security_Metrics_to_Drive_Action.pdf

      ISACA. “Board Director Concerns about Cyber and Technology Risk.” CSX. 11 Sep. 2018. Web.

      Rothke, Ben. “CEOs Require Security Metrics with a High-Level Focus.” Using Security Metrics to Drive Action: 33 Experts Share How to Communicate Security Program Effectiveness to Business Executives and the Board Eds. 2016. Web.

      https://www.ciosummits.com/Online_Assets_Tenable_eBook-_Using_Security_Metrics_to_Drive_Action.pdf

      Wong, Caroline. Security Metrics: A Beginner’s Guide. McGraw Hill: New York, 2012.

      Secure Operations in High-Risk Jurisdictions

      • Buy Link or Shortcode: {j2store}369|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Security Strategy & Budgeting
      • Parent Category Link: /security-strategy-and-budgeting

      Business operations in high-risk areas of the world contend with complex threat environments and risk scenarios that often require a unique response. But traditional approaches to security strategy often miss these jurisdictional risks, leaving organizations vulnerable to threats that range from cybercrime and data breaches to fines and penalties.

      Security leaders need to identify high-risk jurisdictions, inventory critical assets, identify vulnerabilities, assess risks, and identify security controls necessary to mitigate those risks.

      Secure operations and protect critical assets in high-risk regions

      Across risks that include insider threats and commercial surveillance, the two greatest vulnerabilities that organizations face in high-risk parts of the world are travel and compliance. Organizations can make small adjustments to their security program to address these risks:

      1. Support high-risk travel: Put measures and guidelines in place to protect personnel, data, and devices before, during, and after employee travel.
      2. Mitigate compliance risk: Consider data residency requirements, data breach notification, cross-border data transfer, and third-party risks to support business growth.

      Using these two prevalent risk scenarios in high-risk jurisdictions as examples, this research walks you through the steps to analyze the threat landscape, assess security risks, and execute a response to mitigate them.

      Secure Operations in High-Risk Jurisdictions Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Secure Operations in High-Risk Jurisdictions – A step-by-step approach to mitigating jurisdictional security and privacy risks.

      Traditional approaches to security strategy often miss jurisdictional risks. Use this storyboard to make small adjustments to your security program to mitigate security risks in high-risk jurisdictions.

      • Secure Operations in High-Risk Jurisdictions – Phases 1-3

      2. Jurisdictional Risk Register and Heat Map Tool – A tool to inventory, assess, and treat jurisdictional risks.

      Use this tool to track jurisdictional risks, assess the exposure of critical assets, and identify mitigation controls. Use the geographic heatmap to communicate inherent jurisdictional risk with key stakeholders.

      • Jurisdictional Risk Register and Heat Map Tool

      3. Guidelines for Key Jurisdictional Risk Scenarios – Two structured templates to help you develop guidelines for two key jurisdictional risk scenarios: high-risk travel and compliance risk

      Use these two templates to develop help you develop your own guidelines for key jurisdictional risk scenarios. The guidelines address high-risk travel and compliance risk.

      • Digital Safety Guidelines for International Travel
      • Guidelines for Compliance With Local Security and Privacy Laws Template

      Infographic

      Workshop: Secure Operations in High-Risk Jurisdictions

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Identify Context for Risk Assessment

      The Purpose

      Assess business requirements and evaluate security pressures to set the context for the security risk assessment.

      Key Benefits Achieved

      Understand the goals of the organization in high-risk jurisdictions.

      Assess the threats to critical assets in these jurisdictions and capture stakeholder expectations for information security.

      Activities

      1.1 Determine assessment scope.

      1.2 Determine business goals.

      1.3 Determine compliance obligations.

      1.4 Determine risk appetite.

      1.5 Conduct pressure analysis.

      Outputs

      Business requirements

      Security pressure analysis

      2 Analyze Key Risk Scenarios for High-Risk Jurisdictions

      The Purpose

      Build key risk scenarios for high-risk jurisdictions.

      Key Benefits Achieved

      Identify critical assets in high-risk jurisdictions, their vulnerabilities to relevant threats, and the adverse impact should malicious agents exploit them.

      Assess risk exposure of critical assets in high-risk jurisdictions.

      Activities

      2.1 Identify critical assets.

      2.2 Identify threats.

      2.3 Assess risk likelihood.

      2.4 Assess risk impact.

      Outputs

      Key risk scenarios

      Jurisdictional risk exposure

      Jurisdictional Risk Register and Heat Map

      3 Build Risk Treatment Roadmap

      The Purpose

      Prioritize and treat jurisdictional risks to critical assets.

      Key Benefits Achieved

      Build an initiative roadmap to reduce residual risks in high-risk jurisdictions.

      Activities

      3.1 Identify and assess risk response.

      3.2 Assess residual risks.

      3.3 Identify security controls.

      3.4 Build initiative roadmap.

      Outputs

      Action plan to mitigate key risk scenarios

      Further reading

      Secure Operations in High-Risk Jurisdictions

      Assessments often omit jurisdictional risks. Are your assets exposed?

      EXECUTIVE BRIEF

      Analyst Perspective

      Operations in high-risk jurisdictions face unique security scenarios.

      The image contains a picture of Michel Hebert.

      Michel Hébert

      Research Director

      Security and Privacy

      Info-Tech Research Group


      The image contains a picture of Alan Tang.

      Alan Tang

      Principal Research Director

      Security and Privacy

      Info-Tech Research Group


      Traditional approaches to security strategies may miss key risk scenarios that critical assets face in high-risk jurisdictions. These include high-risk travel, heightened insider threats, advanced persistent threats, and complex compliance environments. Most organizations have security strategies and risk management practices in place, but securing global operations requires its own effort. Assess the security risk that global operations pose to critical assets. Consider the unique assets, threats, and vulnerabilities that come with operations in high-risk jurisdictions. Focus on the business activities you support and integrate your insights with existing risk management practices to ensure the controls you propose get the visibility they need. Your goal is to build a plan that mitigates the unique security risks that global operations pose and secures critical assets in high-risk areas. Don’t leave security to chance.

      Executive Summary

      Your Challenge

      • Security leaders who support operations in many countries struggle to mitigate security risks to critical assets. Operations in high-risk jurisdictions contend with complex threat environments and security risk scenarios that often require a unique response.
      • Security leaders need to identify critical assets, assess vulnerabilities, catalog threats, and identify the security controls necessary to mitigate related operational risks.

      Common Obstacles

      • Securing operations in high-risk jurisdictions requires additional due diligence. Each jurisdiction involves a different risk context, which complicates efforts to identify, assess, and mitigate security risks to critical assets.
      • Security leaders need to engage the organization with the right questions and identify high-risk vulnerabilities and security risk scenarios to help stakeholders make an informed decision about how to assess and treat the security risks they face in high-risk jurisdictions.

      Info-Tech’s Approach

      Info-Tech has developed an effective approach to protecting critical assets in high-risk jurisdictions.

      This approach includes tools for:

      • Evaluating the security context of your organization’s high-risk jurisdictions.
      • Identifying security risk scenarios unique to high-risk jurisdictions and assessing the exposure of critical assets.
      • Planning and executing a response.

      Info-Tech Insight

      Organizations with global operations must contend with a more diverse set of assets, threats, and vulnerabilities when they operate in high-risk jurisdictions. Security leaders need to take additional steps to secure operations and protect critical assets.

      Business operations in high-risk jurisdictions face a more complex security landscape

      Information security risks to business operations vary widely by region.

      The 2022 Allianz Risk Barometer surveyed 2,650 business risk specialists in 89 countries to identify the most important risks to operations. The report identified cybercrime, IT failures, outages, data breaches, fines, and penalties as the most important global business risks in 2022, but their results varied widely by region. The standout finding of the 2022 Allianz Risk Barometer is the return of security risks as the most important threat to business operations. Security risks will continue to be acute beyond 2022, especially in Africa, the Middle East, Europe, and the Asia-Pacific region, where they will dwarf risks of supply chain interruptions, natural catastrophe, and climate change.

      Global operations in high-risk jurisdictions contend with more diverse threats. These security risk scenarios are not captured in traditional security strategies.

      The image contains a picture of the world map that has certain areas of the map highlighted in various shades of blue based on higher security-related business risks.

      Figures represent the number of cybersecurity risks business risk specialists selected as a percentage of all business risks (Allianz, 2022). Higher scores indicate jurisdictions with higher security-related business risks. Jurisdictions without data are in grey.

      Different jurisdictions’ commitment to cybersecurity also varies widely, which increases security risks further

      The Global Cybersecurity Index (GCI) provides insight into the commitment of different countries to cybersecurity.

      The index assesses a country’s legal framework to identify basic requirements that public and private stakeholders must uphold and the legal instruments prohibiting harmful actions.

      The 2020 GCI results show overall improvement and strengthening of the cybersecurity agenda globally, but significant regional gaps persist. Of the 194 countries surveyed:

      • 33% had no data protection legislation.
      • 47% had no breach notification measures in place.
      • 50% had no legislation on the theft of personal information.
      • 19% still had no legislation on illegal access.

      Not every jurisdiction has the same commitment to cybersecurity. Protecting critical assets in high-risk jurisdictions requires additional due diligence.

      The image contains a picture of the world map that has certain areas of the map highlighted in various shades of blue based on scores in relation to the Global Security Index.

      The diagram sets out the score and rank for each country that took part in the Global Cybersecurity Index (ITU, 2021)

      Higher scores show jurisdictions with a lower rank on the CGI, which implies greater risk. Jurisdictions without data are in grey.

      Securing critical assets in high-risk jurisdictions requires additional effort

      Traditional approaches to security strategy may miss these key risk scenarios.

      As a result, security leaders who support operations in many countries need to take additional steps to mitigate security risks to critical assets.

      Guide stakeholders to make informed decisions about how to assess and treat the security risks and secure operations.

      • Engage the organization with the right questions.
      • Identify critical assets and assess vulnerabilities.
      • Catalogue threats and build risk scenarios.
      • Identify the security controls necessary to mitigate risks.

      Work with your organization to analyze the threat landscape, assess security risks unique to high-risk jurisdictions, and execute a response to mitigate them.

      This project blueprint works through this process using the two most prevalent risk scenarios in high-risk jurisdictions: high-risk travel and compliance risk.

      Key Risk Scenarios

      • High-Risk Travel
      • Compliance Risk
      • Insider Threat
      • Advanced Persistent Threat
      • Commercial Surveillance
      The image contains a screenshot of an Info-Tech thought model regarding secure global operations in high-risk jurisdictions.

      Travel risk is the first scenario we use as an example throughout the blueprint

      • This project blueprint outlines a process to identify, assess, and mitigate key risk scenarios in high-risk jurisdictions. We use two common key risk scenarios as examples throughout the deck to illustrate how you create and assess your own scenarios.
      • Supporting high-risk travel is the first scenario we will study in-depth as an example. Business growth, service delivery, and mergers and acquisitions can lead end users to travel to high-risk jurisdictions where staff, devices, and data are at risk.
      • Compromised or stolen devices can provide threat actors with access to data that could compromise the organization’s strategic, economic, or competitive advantage or expose the organization to regulatory risk.

      The project blueprint includes template guidance in Phase 3 to help you build and deploy your own travel guidelines to protect critical assets and support end users before they leave, during their trip, and when they return.

      Before you leave

      • Identify high-risk countries.
      • Enable controls.
      • Limit what you pack.

      During your trip

      • Assume you are monitored.
      • Limit access to systems.
      • Prevent theft.

      When you return

      • Change your password.
      • Restore your devices.

      Compliance risk is the second scenario we use as an example

      • Mitigating compliance risk is the second scenario we will study as an example in this blueprint. The legal and regulatory landscape is evolving rapidly to keep step with the pace of technological change. Security and privacy leaders are expected to mitigate the risk of noncompliance as the organization expands to new jurisdictions.
      • Later sections will show how to think through at least four compliance risks, including:
        • Cross-border data transfer
        • Third-party risk management
        • Data breach notification
        • Data residency

      The project blueprint includes template guidance in Phase 3 to help you deploy your own compliance governance controls as a risk mitigation measure.

      Secure Operations in High-Risk Jurisdictions: Info-Tech’s methodology

      1. Identify Context

      2. Assess Risks

      3. Execute Response

      Phase Steps

      1. Assess business requirements
      2. Evaluate security pressures
      1. Identify risks
      2. Assess risk exposure
      1. Treat security risks
      2. Build initiative roadmap

      Phase Outcomes

      • Internal security pressures that capture the governance, policies, practices, and risk tolerance of the organization
      • External security pressures that capture the expectations of customers, regulators, legislators, and business partners
      • A heatmap that captures not only the global exposure of your critical assets but also the business processes they support
      • A security risk register to allow for the easy transfer of critical assets’ global security risk data to your organization’s enterprise risk management practice
      • A roadmap of prioritized initiatives to apply relevant controls and secure global assets
      • A set of key risk indicators to monitor and report your progress

      Blueprint deliverables

      Each step of this blueprint is accompanied by supporting deliverables to help you accomplish your goals:

      Business Security Requirements

      Identify the context for the global security risk assessment, including risk appetite and risk tolerance.

      Jurisdictional Risk Register and Heatmap

      Identify critical global assets and the threats they face in high-risk jurisdictions and assess exposure.

      Mitigation Plan

      Roadmap of initiatives and security controls to mitigate global risks to critical assets. Tools and templates to address key security risk scenarios.

      Key deliverable:

      Jurisdictional Risk Register and Heatmap

      Use the Jurisdictional Risk Register and Heatmap Tool to capture information security risks to critical assets in high-risk jurisdictions. The tool generates a world chart that illustrates the risks global operations face to help you engage the business and execute a response.

      Blueprint benefits

      Protect critical assets in high-risk jurisdictions

      IT Benefits

      Assess and remediate information security risk to critical assets in high-risk jurisdictions.

      Easily integrate your risk assessment with enterprise risk assessments to improve communication with the business.

      Illustrate key information security risk scenarios to make the case for action in terms the business understands.

      Business Benefits

      Develop mitigation plans to protect staff, devices, and data in high-risk jurisdictions.

      Support business growth in high-risk jurisdictions without compromising critical assets.

      Mitigate compliance risk to protect your organization’s reputation, avoid fines, and ensure business continuity.

      Quantify the impact of securing global operations

      The tool included with this blueprint can help you measure the impact of implementing the research

      • Use the Jurisdictional Risk Register and Heatmap Tool to describe the key risk scenarios you face, assess their likelihood and impact, and estimate the cost of mitigating measures. Working through the project in this way will help you quantify the impact of securing global operations.
      The image contains a screenshot of Info-Tech's Jurisdictional Risk Register and Heatmap Tool. The image contains a screenshot of the High-Risk Travel Jurisdiction.

      Establish Baseline Metrics

      • Review existing information security and risk management metrics and the output of the tools included with the blueprint.
      • Identify metrics to measure the impact of your risk management efforts. Focus specifically on high-risk jurisdictions.
      • Compare your results with those in your overall security and risk management program.

      ID

      Metric

      Why is this metric valuable?

      How do I calculate it?

      1.

      Overall Exposure – High-Risk Jurisdictions

      Illustrates the overall exposure of critical assets in high-risk jurisdictions.

      Use the Jurisdictional Risk Register and Heatmap Tool. Calculate the impact times the probability rating for each risk. Take the average.

      2.

      # Risks Identified – High-Risk Jurisdictions

      Informs risk tolerance assessments.

      Use the Jurisdictional Risk Register and Heatmap Tool.

      3.

      # Risks Treated – High-Risk Jurisdictions

      Informs residual risk assessments.

      Use the Jurisdictional Risk Register and Heatmap Tool.

      4.

      Mitigation Cost – High-Risk Jurisdictions

      Informs cost-benefit analysis to determine program effectiveness.

      Use the Jurisdictional Risk Register and Heatmap Tool.

      5.

      # Security Incidents – High-Risk Jurisdictions

      Informs incident trend calculations to determine program effectiveness.

      Draw the information from your service desk or IT service management tool.

      6.

      Incident Remediation Cost – High-Risk Jurisdictions

      Informs cost-benefit analysis to determine program effectiveness.

      Estimate based on cost and effort, including direct and indirect cost such as business disruptions, administrative finds, reputational damage, etc.

      7.

      TRENDS: Program Effectiveness – High-Risk Jurisdictions

      # of security incidents over time. Remediation : Mitigation costs over time

      Calculate based on metrics 5 to 7.

      Info-Tech offers various levels of support to best suit your needs.

      DIY Toolkit

      "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful."

      Guided Implementation

      "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track."

      Workshop

      "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place."

      Consulting

      "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

      Diagnostics and consistent frameworks are used throughout all four options.

      Guided Implementation

      What does a typical GI on this topic look like?

      Phase 1

      Call #1: Scope project requirements, determine assessment scope, and discuss challenges.

      Phase 2

      Call #2: Conduct initial risk assessment and determine risk tolerance.

      Call #3: Evaluate security pressures in high-risk jurisdictions.

      Call #4: Identify risks in high-risk jurisdictions.

      Call #5: Assess risk exposure.

      Phase 3

      Call #6: Treat security risks in high-risk jurisdictions.

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization. A typical GI is between 8 to 12 calls over the course of 4 to 6 months.

      Workshop Overview

      Contact your account representative for more information. workshops@infotech.com 1-888-670-8889

      Days 1

      Days 2-3

      Day 4

      Day 5

      Identify Context

      Key Risk Scenarios

      Build Roadmap

      Next Steps and Wrap-Up (offsite)

      Activities

      1.1.1 Determine assessment scope.

      1.1.2 Determine business goals.

      1.1.3 Identify compliance obligations.

      1.2.1 Determine risk appetite.

      1.2.2 Conduct pressure analysis.

      2.1.1 Identify assets.

      2.1.2 Identify threats.

      2.2.1 Assess risk likelihood.

      2.2.2 Assess risk impact.

      3.1.1 Identify and assess risk response.

      3.1.2 Assess residual risks.

      3.2.1 Identify security controls.

      3.2.2 Build initiative roadmap.

      5.1 Complete in-progress deliverables from previous four days.

      5.2 Set up review time for workshop deliverables and to discuss next steps.

      Deliverables

      1. Business requirements for security risk assessment
      2. Identification of high-risk jurisdictions
      3. Security threat landscape for high-risk jurisdictions
      1. Inventory of relevant threats, critical assets, and their vulnerabilities
      2. Assessment of adverse effects should threat agents exploit vulnerabilities
      3. Risk register with key risk scenarios and heatmap of high-risk jurisdictions
      1. Action plan to mitigate key risk scenarios
      2. Investment and implementation roadmap
      1. Completed information security risk assessment for two key risk scenarios
      2. Risk mitigation roadmap

      No safe jurisdictions

      Stakeholders sometimes ask information security and privacy leaders to produce a list of safe jurisdictions from which to operate. We need to help them see that there are no safe jurisdictions, only relatively risky ones. As you build your security program, deepen the scope of your risk assessments to include risk scenarios critical assets face in different jurisdictions. These risks do not need to rule out operations, but they may require additional mitigation measures to keep staff, data, and devices safe and reduce potential reputational harms.

      Traditional approaches to security strategy often omit jurisdictional risks.

      Global operations must contend with a more complex security landscape. Secure critical assets in high-risk jurisdictions with a targeted risk assessment.

      The two greatest risks are high-risk travel and compliance risk.

      You can mitigate them with small adjustments to your security program.

      Support High-Risk Travel

      When securing travel to high-risk jurisdictions, you must consider personnel safety as well as data and device security. Put measures and guidelines in place to protect them before, during, and after travel.

      Mitigate Compliance Risk

      Think through data residency requirements, data breach notification, cross-border data transfer, and third-party risks to support business growth and mitigate compliance risks in high-risk jurisdictions to protect your organization’s reputation and avoid hefty fines or business disruptions.

      Phase 1

      Identify Context

      This phase will walk you through the following activities:

      • Assess business requirements to understand the goals of the organization’s global operations, as well as its risk governance, policies, and practices.
      • Evaluate jurisdictional security pressures to understand threats to critical assets and capture the expectations of external stakeholders, including customers, regulators, legislators, and business partners, and assess risk tolerance.

      This phase involves the following participants:

      • Business stakeholders
      • IT leadership
      • Security team
      • Risk and Compliance

      Step 1.1

      Assess Business Requirements

      Activities

      1.1.1 Determine assessment scope

      1.1.2 Identify enterprise goals in high-risk jurisdictions

      1.1.3 Identify compliance obligations

      This step involves the following participants:

      • Business stakeholders
      • IT leadership
      • Security team
      • Risk and Compliance

      Outcomes of this step

      • Assess business requirements to understand the goals of the organization’s global operations, as well as its risk governance, policies, and practices.

      Focus the risk assessment on high-risk jurisdictions

      Traditional approaches to information security strategy often miss threats to global operations

      • Successful security strategies are typically sensitive to risks to different IT systems and lines of business.
      • However, securing global operations requires additional focus on high-risk jurisdictions, considering what makes them unique.
      • This first phase of the project will help you evaluate the business context of operations in high-risk jurisdictions, including:
        • Enterprise and security goals.
        • Lines of business, physical locations, and IT systems that need additional oversight.
        • Unique compliance obligations.
        • Unique risks and security pressures.
        • Organizational risk tolerance in high-risk jurisdictions.

      Focus your risk assessment on the business activities security supports in high-risk jurisdictions and the unique threats they face to bridge gaps in your security strategy.

      Identify jurisdictions with higher inherent risks

      Your security strategy may not describe jurisdictional risk adequately.

      • Security strategies list lines of business, physical locations, and IT systems the organization needs to secure and those whose security will depend on a third-party. You can find additional guidance on fixing the scope and boundaries of a security strategy in Phase 1 of Build an Information Security Strategy.
      • However, security risks vary widely from one jurisdiction to another according to:
        • Active cyber threats.
        • Legal and regulatory frameworks.
        • Regional security and preparedness capabilities.
      • Your first task is to identify high-risk jurisdictions to target for additional oversight.

      Work closely with your enterprise risk management function.

      Enterprise risk management functions are often tasked with developing risk assessments from composite sources. Work closely with them to complete your own assessment.

      Countries at heightened risk of money laundering and terrorism financing are examples of high-risk jurisdictions. The Financial Action Task Force and the U.S. Treasury publish reports three times a year that identify Non-Cooperative Countries or Territories.

      Develop a robust jurisdictional assessment

      Design an intelligence collection strategy to inform your assessment

      Strategic Intelligence

      White papers, briefings, reports. Audience: C-Suite, board members

      Tactical Intelligence

      Internal reports, vendor reports. Audience: Security leaders

      Operational intelligence

      Indicators of compromise. Audience: IT Operations

      Operational intelligence focuses on machine-readable data used to block attacks, triage and validate alerts, and eliminate threats from the network. It becomes outdated in a matter of hours and is less useful for this exercise.

      Determine travel risks to bolster your assessments

      Not all locations and journeys will require the same security measures.

      • Travel risks vary significantly according to destination, the nature of the trip, and traveler profile.
      • Access to an up-to-date country risk rating system enables your organization and individual staff to quickly determine the overall level of risk in a specific country or location.
      • Based on this risk rating, you can specify what security measures are required prior to travel and what level of travel authorization is appropriate, in line with the organization's security policy or travel security procedures.
      • While some larger organizations can maintain their own country risk ratings, this requires significant capacity, particularly to obtain the necessary information to keep these regularly updated.
      • It may be more effective for your organization to make use of the travel risk ratings provided by an external security information provider, such as a company linked to your travel insurance or travel booking service, if available.
      • Alternatively, various open-source travel risk ratings are available via embassy travel sites or other website providers.

      Without a flexible system to account for the risk exposures of different jurisdictions, staff may perceive measures as a hindrance to operations.

      Develop a tiered risk rating

      The example below outlines potential risk indicators for high-risk travel.

      Rating

      Description

      Low

      Generally secure with adequate physical security. Low violent crime rates. Some civil unrest during significant events. Acts of terrorism rare. Risks associated with natural disasters limited and health threats mainly preventable.

      Moderate

      Periodic civil unrest. Antigovernment, insurgent, or extremist groups active with sporadic acts of terrorism. Staff at risk from common and violent crime. Transport and communications services are unreliable and safety records are poor. Jurisdiction prone to natural disasters or disease epidemics.

      High

      Regular periods of civil unrest, which may target foreigners. Antigovernment, insurgent, or extremist groups very active and threaten political or economic stability. Violent crime rates high, often targeting foreigners. Infrastructure and emergency services poor. May be regular disruption to transportation or communications services. Certain areas off-limits to foreigners. Jurisdictions experiencing natural disasters or epidemics are considered high risk.

      Extreme

      Undergoing active conflict or persistent civil unrest. Risk of being caught up in a violent incident or attack is very high. Authorities may have lost control of significant portions of the country. Lines between criminality and political and insurgent violence are blurred. Foreigners are likely to be denied access to parts of the country. Transportation and communication services are severely degraded or nonexistent. Violence presents a direct threat to staff security.

      Ratings are formulated by assessing several types of risk, including conflict, political/civil unrest, terrorism, crime, and health and infrastructure risks.

      1.1.1 Determine assessment scope

      1 – 2 hours

      1. As a group, brainstorm a list of high-risk jurisdictions to target for additional assessment. Write down as many items as possible to include in:
      • Lines of business
      • Physical locations
      • IT systems

      Pay close attention to elements of the assessment that are not in scope.

    • Discuss the response and the rationale for targeting each of them for additional risk assessments. Identify security-related concerns for different lines of business, locations, user groups, IT systems, and data.
    • Record your responses and your comments in the Information Security Requirements Gathering Tool.
    • Input

      Output

      • Corporate strategy
      • IT strategy
      • Security strategy
      • Relevant threat intelligence
      • A list of high-risk jurisdictions to focus your risk assessment

      Materials

      Participants

      • Laptop
      • Projector
      • Security team
      • IT leadership
      • Business stakeholders
      • Enterprise Risk Management
      • Compliance
      • Legal

      Download the Information Security Requirements Gathering Tool

      Position your efforts in a business context

      Securing critical assets in high-risk jurisdictions is a business imperative

      • Many companies relegate their information security strategies to their IT department. Aside from the strain the choice places on a department that already performs many different functions, it wrongly implies that mitigating information security risk is simply an IT problem.
      • Managing information security risks is a business problem. It requires that organizations identify their risk appetite, prioritize relevant threats, and define risk mitigation initiatives. Business leaders can only do these activities effectively in a context that recognizes the business and financial benefits of implementing protections.
      • This is notably true of businesses with operations in many different countries. Each jurisdiction has its own set of security risks the organization must account for, as well as unique local laws and regulations that affect business operations.
      • In high-risk jurisdictions, your efforts must consider the unique operational challenges your organization may not face in its home country. Your efforts to secure critical assets will be most successful if you describe key risk scenarios in terms of their impact on business goals.
      • You can find additional guidance on assessing the business context of a security strategy in Phase 1 of Build an Information Security Strategy.

      Do you understand the unique business context of operations in high-risk jurisdictions?

      1.1.2 Identify business goals

      Estimated Time: 1-2 hours

      1. As a group, brainstorm the primary and secondary business goals of the organization. Focus your assessment on operations in high-risk jurisdictions you identified in Exercise 1.1.1. Review:
      • Relevant corporate and IT strategies.
      • The business goal definitions and indicator metrics in tab 2, “Goals Definition,” of the Information Security Requirements Gathering Tool.
    • Limit business goals to no more than two primary goals and three secondary goals. This limitation will help you prioritize security initiatives at the end of the project.
    • For each business goal, identify up to two security alignment goals that will support business goals in high-risk jurisdictions.
    • Input

      Output

      • Corporate strategy
      • IT strategy
      • Security strategy
      • Your goals for the security risk assessment for high-risk jurisdictions

      Materials

      Participants

      • Laptop
      • Projector
      • Security team
      • IT leadership
      • Business stakeholders
      • Risk Management
      • Compliance
      • Legal

      Download the Information Security Requirements Gathering Tool

      Record business goals

      Capture the results in the Information Security Requirements Gathering Tool

      1. Record the primary and secondary business goals you identified in tab 3, “Goals Cascade,” of the Information Security Requirements Gathering Tool.
      2. Next, record the two security alignment goals you selected for each business goal based on the tool’s recommendations.
      3. Finally, review the graphic diagram that illustrates your goals on tab 6, “Results,” of the Information Security Requirements Gathering Tool.
      4. Revisit this exercise whenever operations expands to a new jurisdiction to capture how they contribute to the organization’s mission and vision and how the security program can support them.
      The image contains a screenshot of Tab 3, Goals Cascade.

      Tab 3, Goals Cascade

      The image contains a screenshot of Tab 6, Results.

      Tab 6, Results

      Analyze business goals

      Assess how operating in multiple jurisdictions adds nuance to your business goals

      • Security leaders need to understand the direction of the business to propose relevant security initiatives that support business goals in high-risk jurisdictions.
      • Operating in different jurisdictions carries its own degree of risk. The organization is subject not only to the information security risks and legal frameworks of its country of origin but also to those associated with international jurisdictions.
      • You need to understand where your organization operates and how these different jurisdictions contribute to your business goals to support their performance and protect the firm’s reputation.
      • This exercise will make an explicit link between security and privacy concerns in high-risk jurisdictions, what the business cares about, and what security is trying to accomplish.

      If the organization is considering a merger and acquisition project that will expand operations in jurisdictions with different travel risk profiles, the security organization needs to revise the security strategy to ensure the organization can support high-risk travel and mitigate risks to critical assets.

      Identify compliance obligations

      Data compliance obligations loom large in high-risk jurisdictions

      The image contains four hexagons, each with their own words. SOX, PCI DSS, HIPAA, HITECH.

      Security leaders are familiar with most conventional regulatory obligations that govern financial, personal, and healthcare data in North America and Europe.

      The image contains four hexagons, each with their own words. Residency, Cross-Border Transfer, Breach Notification, Third-Party Risk Mgmt.

      Data privacy concerns, nationalism, and the economic value of data are all driving jurisdictions to adopt data residency and data localization and to shut down the cross-border transfer of data.

      The next step requires you to consider the compliance obligations the organization needs to meet to support the business as it expands to other jurisdictions through natural growth, mergers, and acquisitions.

      1.1.3 Identify compliance obligations

      Estimated Time: 1-2 hours

      1. As a group, brainstorm compliance obligations in target jurisdictions. Focus your assessment on operations in high-risk jurisdictions.
      2. Include:

      • Laws
      • Governing regulations
      • Industry standards
      • Contractual agreements
    • Record your compliance obligations and comments on tab 4, “Compliance Obligations,” of the Information Security Requirements Gathering Tool.
    • If you need to take full stock of the laws and regulations in place in the jurisdictions where you operate that you are not familiar with, consider seeking local legal counsel to help you navigate this exercise.
    • Input

      Output

      • Legal and compliance frameworks in target jurisdictions
      • Mandatory and voluntary compliance obligations for target jurisdictions

      Materials

      Participants

      • Laptop
      • Projector
      • Security team
      • IT leadership
      • Business stakeholders
      • Risk Management
      • Compliance
      • Legal

      Download the Information Security Requirements Gathering Tool

      Step 1.2

      Evaluate Security Pressures

      Activities

      1.2.1 Conduct initial risk assessment

      1.2.2 Conduct pressure analysis

      1.2.3 Determine risk tolerance

      This step involves the following participants:

      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Outcomes of this step

      Identify threats to global assets and capture the security expectations of external stakeholders, including customers, regulators, legislators, and business partners, and determine risk tolerance.

      Evaluate security pressures to set the risk context

      Perform an initial assessment of high-risk jurisdictions to set the context.

      Assess:

      • The threat landscape.
      • The security pressures from key stakeholders.
      • The risk tolerance of your organization.

      You should be able to find the information in your existing security strategy. If you don’t have the information, work through the next three steps of the project blueprint.

      The image contains a diagram to demonstrate evaluating security pressures, as described in the text above.

      Some jurisdictions carry inherent risks

      • Jurisdictional risks stem from legal, regulatory, or political factors that exist in different countries or regions. They can also stem from unexpected legal changes in regions where critical assets have exposure. Understanding jurisdictional risks is critical because they can require additional security controls.
      • Jurisdictional risk tends to be higher in jurisdictions:
        • Where the organization:
          • Conducts high-value or high-volume financial transactions.
          • Supports and manages critical infrastructure.
          • Has high-cost data or data whose compromise could undermine competitive advantage.
          • Has a high percentage of part-time employees and contractors.
          • Experiences a high rate of employee turnover.
        • Where state actors:
          • Have a low commitment to cybersecurity, financial, and privacy legislation and regulation.
          • Support cybercrime organizations within their borders.

      Jurisdictional risk is often reduced to countries where money laundering and terrorist activities are high. In this blueprint, the term refers to the broader set of information security risks that arise when operating in a foreign country or jurisdiction.

      Five key risk scenarios are most prevalent

      Key Risk Scenarios

      • High-Risk Travel
      • Compliance Risk
      • Insider Threat
      • Advanced Persistent Threat
      • Commercial Surveillance

      Security leaders who support operations in many countries need to take additional steps to mitigate security risks to critical assets. The goal of the next two exercises is to analyze the threat landscape and security pressures unique to high-risk jurisdictions, which will inform the construction of key scenarios in Phase 2. These five scenarios are most prevalent in high-risk jurisdictions. Keep them in mind as you go through the exercises in this section.

      1.2.1 Assess jurisdictional risk

      1-3 hours

      1. As a group, review the questions on tab 2, “Risk Assessment,” of the Information Security Pressure Analysis Tool.
      2. Gather the required information from subject matter experts on the following risk elements with a focus on high-risk jurisdictions:
      3. Review each question in tab 2 of the Information Security Pressure Analysis Tool and select the most appropriate response.

      Input

      Output

      • Existing security strategy
      • List of organizational assets
      • Historical data on information security incidents
      • Completed risk assessment

      Materials

      Participants

      • Information Security Pressure Analysis Tool
      • Security team
      • IT leadership
      • Risk Management

      For more information on how to complete the risk assessment questionnaire, see Step 1.2.1 of Build an Information Security Strategy.

      1.2.2 Conduct pressure analysis

      1-3 hours

      1. As a group, review the questions on tab 3, “Pressure Analysis,” of the Information Security Pressure Analysis Tool.
      2. Gather the required information from subject matter experts on the following pressure elements with a focus on high-risk jurisdictions:
      • Compliance and oversight
      • Customer expectations
      • Business expectations
      • IT expectations
    • Review each question in the questionnaire and provide the most appropriate response using the drop-down list. It may be helpful to consult with the appropriate departments to obtain their perspectives.
    • For more information on how to complete the pressure analysis questionnaire, see Step 1.3 of Build an Information Security Strategy.

      Input

      Output

      • Information on various pressure elements within the organization
      • Existing security strategy
      • Completed pressure analysis

      Materials

      Participants

      • Information Security Pressure Analysis Tool
      • Security team
      • IT leadership
      • Business leaders
      • Compliance

      A low security pressure means that your stakeholders do not assign high importance to information security. You may need to engage stakeholders with the right key risk scenarios to illustrate jurisdictional risk and generate support for new security controls.

      Download the Information Security Pressure Analysis Tool

      Assess risk tolerance

      • Risk tolerance expresses the types and amount of risk the organization is willing to accept in pursuit of its goals.
      • These expectations can help you identify, manage, and report on key risk scenarios in high-risk jurisdictions.
      • For instance, an organization with a low risk tolerance will require a stronger information security program to minimize operational security risks.
      • It’s up to business leaders to determine the risks they are willing to accept. They may need guidance to understand how system-level risks affect the organization’s ability to pursue its goals.

      A formalized risk tolerance statement can help:

      • Support risk-based security decisions that align with business goals.
      • Provide a meaningful rationale for security initiatives.
      • Improve the transparency of investments in the organization’s security program.
      • Provide guidance for monitoring inherent risk and residual risk exposure.

      The role of security professionals is to identify and analyze key risk scenarios that may prevent the organization from reaching its goals.

      1.2.3 Determine risk tolerance

      1-3 hours

      1. As a group, review the questions on tab 4, “Risk Tolerance,” of the Information Security Pressure Analysis Tool.
      2. Gather the required information from subject matter experts on the following risk tolerance elements:
      • Recent IT problems, especially downtime and data recovery issues
      • Historical security incidents
    • Review any relevant documentation, including:
      • Existing security strategy
      • Business impact assessments
      • Service-level agreements

      For more information on how to complete the risk tolerance questionnaire, see Step 1.4 of Build an Information Security Strategy.

      Input

      Output

      • Existing security strategy
      • Data on recent IT problems and incidents
      • Business impact assessments
      • Completed risk tolerance statement

      Materials

      Participants

      • Information Security Pressure Analysis Tool
      • Security team
      • IT leadership
      • Risk Management

      Download the Information Security Pressure Analysis Tool

      Review the output of the results tab

      • The organizational risk assessment provides a high-level assessment of inherent risks in high-risk jurisdictions. Use the results to build and assess key risk scenarios in Phase 2.
      • Use the security pressure analysis to inform stakeholder management efforts. A low security pressure indicates that stakeholders do not yet grasp the impact of information security on organizational goals. You may need to communicate its importance before you discuss additional security controls.
      • Jurisdictions in which organizations have a low risk tolerance will require stronger information security controls to minimize operational risks.
      The image contains a screenshot of the organizational risk assessment. The image contains a screenshot of the security pressure analysis. The image contains a screenshot of the risk tolerance curve.

      Phase 2

      Assess Security Risks to Critical Assets

      This phase will walk you through the following activities:

      • Identify critical assets, their vulnerabilities to relevant threats, and the adverse impact a successful threat event would have on the organization.
      • Assess risk exposure of critical assets in high-risk jurisdictions for each risk scenario through an analysis of its likelihood and impact.

      This phase involves the following participants:

      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Step 2.1

      Identify Risks

      Activities

      2.1.1 Identify assets

      2.1.2 Identify threats

      This step involves the following participants:

      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Outcomes of this step

      • Define risk scenarios that identify critical assets, their vulnerabilities to relevant threats, and the adverse impact a successful threat event would have on the organization.

      This blueprint focuses on mitigating jurisdictional risks

      The image contains a screenshot of the IT Risk Management Framework. The framework includes: Risk Identification, Risk Assessment, Risk Response, and Risk Governance.

      For a deeper dive into building a risk management program, see Info-Tech’s core project blueprints on risk management:

      Build an IT Risk Management Program

      Combine Security Risk Management Components Into One Program

      Draft key risk scenarios to illustrate adverse events

      Risk scenarios help decision-makers understand how adverse events affect business goals.

      • Risk-scenario building is the process of identifying the critical factors that contribute to an adverse event and crafting a narrative that describes the circumstances and consequences if it were to happen.
      • Risk scenarios set up the risk analysis stage of the risk assessment process. They are narratives that describe in detail:
        • The asset at risk.
        • The threat that can act against the asset.
        • Their intent or motivation.
        • The circumstances and threat actor model associated with the threat event.
        • The potential effect on the organization.
        • When or how often the event might occur.

      Risk scenarios are further distilled into a single sentence or risk statement that communicates the essential elements from the scenario.

      Well-crafted risk scenarios have four components

      The second phase of the project will help you craft meaningful risk scenarios

      Threat

      Exploits an

      Asset

      Using a

      Method

      Creating an

      Effect

      An actor capable of harming an asset

      Anything of value that can be affected and results in loss

      Technique an actor uses to affect an asset

      How loss materializes

      Examples: Malicious or untrained employees, cybercriminal groups, malicious state actors

      Examples: Systems, regulated data, intellectual property, people

      Examples: Credential compromise, privilege escalation, data exfiltration

      Examples: Loss of data confidentiality, integrity, or availability; impact on staff health & safety

      Risk scenarios are concise, four to six sentence narratives that describe the core elements of forecasted adverse events. Use them to engage stakeholders with the right questions and guide them to make informed decisions about how to address and treat security risks in high-risk jurisdictions.

      The next slides review five key risk scenarios prevalent in high-risk jurisdictions. Use them as examples to develop your own.

      Travel to high-risk jurisdictions requires special measures to protect staff, devices, and data

      Governmental, academic, and commercial advisors compile lists of jurisdictions that pose greater travel risks annually.

      For instance, in the US, these lists might include countries that are:

      • Subjects of travel warnings by the US Department of State.
      • Identified as high risk by other US government sources such as:
        • The Department of the Treasury Office of Foreign Assets Control (OFAC).
        • The Federal Bureau of Investigation (FBI).
        • The Office of the Director of National Intelligence (ODNI).
      • Compiled from academic and commercial sources, such as Control Risks.

      When securing travel to high-risk jurisdictions, you must consider personnel safety as well as data and device security.

      The image contains a diagram to present high-risk jurisdictions.

      The diagram presents high-risk jurisdictions based on US governmental sources (2021) listed on this slide.

      High-risk travel

      Likelihood: Medium

      Impact: Medium

      Key Risk Scenario #1

      Malicious state actors, cybercriminals, and competitors can threaten staff, devices, and data during travel to high-risk jurisdictions. Device theft or compromise may occur while traveling through airports, accessing hotel computer and phone networks, or in internet cafés or other public areas. Threat actors can exploit data from compromised or stolen devices to undermine the organization’s strategic, economic, or competitive advantage. They can also infect compromised devices with malware that delivers malicious payloads once they reconnect with home networks.

      Threat Actor:

      • Malicious state actors
      • Cybercriminals
      • Competitors

      Assets:

      • Staff
      • IT systems
      • Sensitive data

      Effect:

      • Compromised staff health and safety
      • Loss of data
      • Lost of system integrity

      Methods:

      • Identify, steal, or target mobile devices.
      • Compromise network, wireless, or Bluetooth connections.
      • Leverage stolen devices as a means of infecting other networks.
      • Access devices to track user location.
      • Activate microphones on devices to collect information.
      • Intercept electronic communications users send from high-risk jurisdictions.

      The data compliance landscape is a jigsaw puzzle of data protection and data residency requirements

      Since the EU passed the GDPR in 2016, jurisdictions have turned to data regulations to protect citizen data

      Data privacy concerns, nationalism, and the economic value of data are all driving jurisdictions to adopt data residency, breach notification, and cross-border data transfer regulations. As 2021 wound down to a close, nearly all the world’s 30 largest economies had some form of data regulation in place. The regulatory landscape is shifting rapidly, which complicates operations as organizations grow into new markets or engage in merger and acquisition activities.

      Global operations require special attention to data-residency requirements, data breach notification requirements, and cross-border data transfer regulations to mitigate compliance risk.

      The image contains a diagram to demonstrate the data regulations placed in various places around the world.

      Compliance risk

      Likelihood: Medium

      Impact: High

      Key Risk Scenario #2

      Rapid changes in the privacy and security regulatory landscape threaten organizations’ ability to meet their compliance obligations from local legal and regulatory frameworks. Organizations risk reputational damage, administrative fines, criminal charges, and loss of market share. In extreme cases, organizations may lose their license to operate in high-risk jurisdictions. Shifts in the regulatory landscape can involve additional requirements for data residency, cross-border data transfer, data breach notification, and third-party risk management.

      Threat Actor:

      • Local, regional, and national state actors

      Asset:

      • Reputation, market share
      • License to operate

      Effect:

      • Administrative fines
      • Loss of reputation, brand trust, and consumer loyalty
      • Loss of market share
      • Suspension of business operations
      • Lawsuits due to collective actions and claims
      • Criminal charges

      Methods:

      • Shifts in the privacy and security regulatory landscape, including requirements for:
        • Data residency.
        • Cross-border data transfer.
        • Data breach notification.
        • Third-party security and privacy risk management.

      The incidence of insider threats varies widely by jurisdiction in unexpected ways

      On average, companies in North America, the Middle East, and Africa had the most insider incidents in 2021, while those in the Asia-Pacific region had the least.

      The Ponemon Institute set out to understand the financial consequences that result from insider threats and gain insight into how well organizations are mitigating these risks.

      In the context of this research, insider threat is defined as:

      • Employee or contractor negligence.
      • Criminal or malicious insider activities.
      • Credential theft (imposter risk).

      On average, the total cost to remediate insider threats in 2021 was US$15.4 million per incident.

      In all regions, employee or contractor negligence occurred most frequently. Organizations in North America and in the Middle East and Africa were most likely to experience insider threat incidents in 2021.

      the image contains a diagram of the world, with various places coloured in different shades of blue.

      The diagram represents the average number of insider incidents reported per organization in 2021. The results are analyzed in four regions (Ponemon Institute, 2022)

      Insider threat

      Likelihood: Low to Medium

      Impact: High

      Key Risk Scenario #3

      Malicious insiders, negligent employees, and credential thieves can exploit inside access to information systems to commit fraud, steal confidential or commercially valuable information, or sabotage computer systems. Insider threats are difficult to identify, especially when security is geared toward external threats. They are often familiar with the organization’s data and intellectual property as well as the methods in place to protect them. An insider may steal information for personal gain or install malicious software on information systems. They may also be legitimate users who make errors and disregard policies, which places the organization at risk.

      Threat Actor:

      • Malicious insiders
      • Negligent employees
      • Infiltrators

      Asset:

      • Sensitive data
      • Employee credentials
      • IT systems

      Effects:

      • Loss of system integrity
      • Loss of data confidentiality
      • Financial loss

      Methods:

      • Infiltrators may compromise credentials.
      • Malicious or negligent insiders may use corporate email to steal or share sensitive data, including:
        • Regulated data.
        • Intellectual property.
        • Critical business information.
      • Malicious agents may facilitate data exfiltration, as well as open-port and vulnerability scans.

      The risk of advanced persistent threats is more prevalent in Central and South America and the Asia-Pacific region

      Attacks from advanced persistent threat (APT) actors are more sophisticated than traditional ones.

      • More countries will use legal indictments as part of their cyber strategy. Exposing toolsets of APT groups carried out at the governmental level will drive more states to do the same.
      • Expect APTs to increasingly target network appliances like VPN gateways as organizations continue to sustain hybrid workforces.
      • The line between APTs and state-sanctioned ransomware groups is blurring. Expect cybercriminals to wield better tools, mount more targeted attacks, and use double-extortion tactics.
      • Expect more disruption and collateral damage from direct attacks on critical infrastructure.

      Top 10 Significant Threat Actors:

      • Lazarus
      • DeathStalker
      • CactusPete
      • IAmTheKing
      • TransparentTribe
      • StrongPity
      • Sofacy
      • CoughingDown
      • MuddyWater
      • SixLittleMonkeys

      Top 10 Targets:

      • Government
      • Banks
      • Financial Institutions
      • Diplomatic
      • Telecommunications
      • Educational
      • Defense
      • Energy
      • Military
      • IT Companies
      The image contains a world map coloured in various shades of blue.
      Top 12 countries targeted by APTs (Kaspersky, 2020)

      Track notable APTs to revise your list of high-risk jurisdictions and review the latest tactics and techniques

      Governmental advisors track notable APT actors that pose greater risks.

      The CISA Shields Up site, SANS Storm Center site, and MITRE ATT&CK group site provide helpful and timely information to understand APT risks in different jurisdictions.

      The following threat actors are currently associated with cyberattacks affiliated with the Russian government.

      Activity Group

      Risks

      APT28 (GRU)

      Known as Fancy Bear, this threat group has been tied to espionage since 2004. They compromised the Hillary Clinton campaign, amid other major events.

      APT29 (SVT)

      Tied to espionage since 2008. Reportedly compromised the Democratic National Committee in 2015. Cited in the 2021 SolarWinds compromise.

      Buhtrap/RTM Group

      Group focused on financial targets since 2014. Currently known to target Russian and Ukrainian banks.

      Gamaredon

      Operating in Crimea. Aligned with Russian interests. Has previously targeted Ukrainian government officials and organizations.

      DEV-0586

      Carried out wiper malware attacks on Ukrainian targets in January 2022.

      UNC1151

      Active since 2016. Linked to information operation campaigns and the distribution of anti-NATO material.

      Conti

      Most successful ransomware gang of 2021, with US$188M revenue. Supported Russian invasion of Ukraine, threatening attacks on allied critical infrastructure.

      Sources: MITRE ATT&CK; Security Boulevard, 2022; Reuters, 2022; The Verge, 2022

      Advanced persistent threat

      Likelihood: Low to Medium

      Impact: High

      Key Risk Scenario #4

      Advanced persistent threats are state actors or state-sponsored affiliates with the means to avoid detection by anti-malware software and intrusion detection systems. These highly-skilled and persistent malicious agents have significant resources with which to bypass traditional security controls, establish a foothold in the information technology infrastructure, and exfiltrate data undetected. APTs have the resources to adapt to a defender’s efforts to resist them over time. The loss of system integrity and data confidentiality over time can lead to financial losses, business continuity disruptions, and the destruction of critical infrastructure.

      Threat Actor:

      • State actors
      • State-sponsored affiliates

      Asset:

      • Sensitive data
      • IT systems
      • Critical infrastructure

      Effects:

      • Loss of system integrity
      • Loss of data confidentiality
      • Financial loss
      • Business continuity disruptions
      • Infrastructure destruction

      Methods:

      • Persistent, consistent attacks using the most advanced threats and tactics to bypass security defenses.
      • The goal of APTs is to maintain access to networks for prolonged periods without being detected.
      • The median dwell time differs widely between regions. FireEye reported the mean dwell time for 2018:
        • Americas: 71 days
        • Europe, Middle East, and Africa: 177 days
        • Asia-Pacific: 204 days
      Sources: Symantec, 2011; FireEye, 2019

      Threat agents have deployed invasive technology for commercial surveillance in at least 76 countries since 2015

      State actors and their affiliates purchased and used invasive spyware from companies in Europe, Israel, and the US.

      • “Customers are predominantly repressive regimes looking for new ways to control the flow of information and stifle dissent. Less than 10% of suspected customers are considered full democracies by the Economist Intelligence Unit.” (Top10VPN, 2021)
      • Companies based in economically developed and largely democratic states are profiting off the technology.
      • The findings demonstrate the need to consider geopolitical realities when assessing high-risk jurisdictions and to take meaningful action to increase layered defenses against invasive malware.
      • Spyware is having an increasingly well-known impact on civil society. For instance, since 2016, over 50,000 individual phone numbers have been identified as potential targets by NSO Group, the Israeli manufacturers of the notorious Pegasus Spyware. The target list contained the phone numbers of politicians, journalists, activists, doctors, and academics across the world.
      • The true number of those affected by spyware is almost impossible to determine given that many fall victim to the technology and do not notice.
      The image contains a map of the world with various countries highlighted in shades of blue.

      Countries where commercial surveillance tools have been deployed (“Global Spyware Market Index,” Top10VPN, 2021)

      The risks and effects of spyware vary greatly

      Spyware can steal mundane information, track a user’s every move, and everything in between.

      Adware

      Software applications that display advertisements while the program is running.

      Keyboard Loggers

      Applications that monitor and record keystrokes. Malicious agents use them to steal credentials and sensitive enterprise data.

      Trojans

      Applications that appear harmless but inflict damage or data loss to a system.

      Mobile Spyware

      Surveillance applications that infect mobile devices via SMS or MMS channels, though the most advanced can infect devices without user input.

      State actors and their affiliates use system monitors to track browsing habits, application usage, and keystrokes and capture information from devices’ GPS location data, microphone, and camera. The most advanced system monitor spyware, such as NSO Group’s Pegasus, can infect devices without user input and record conversations from end-to-end encrypted messaging systems.

      Commercial surveillance

      Likelihood: Low to Medium

      Impact: Medium

      Key Risk Scenario #5

      Malicious agents can deploy malware on end-user devices with commercial tools available off the shelf to secretly monitor the digital activity of users. Attacks exploit widespread vulnerabilities in telecommunications protocols. They occur through email and text phishing campaigns, malware embedded in untested applications, and sophisticated zero-click attacks that deliver payloads without requiring user interactions. Attacks target sensitive as well as mundane information. They can be used to track employee activities, investigate criminal activity, or steal credentials, credit card numbers, or other personally identifiable information.

      Threat Actor:

      • State actors
      • State-sponsored affiliates

      Asset:

      • Sensitive data
      • Staff health and safety
      • IT systems

      Effects:

      • Data breaches
      • Loss of data confidentiality
      • Increased risk to staff health and safety
      • Misuse of private data
      • Financial loss

      Methods:

      • Email and text phishing attacks that delivery malware payloads
      • Sideloading untested applications from a third-party source rather than an official retailer
      • Sophisticated zero-click attacks that deliver payloads without requiring user interaction

      Use the Jurisdictional Risk Register and Heatmap Tool

      The tool included with this blueprint can help you draft risk scenarios and risk statements in this section.

      The risk register will capture a list of critical assets and their vulnerabilities, the threats that endanger them, and the adverse effect your organization may face.

      The image includes two screenshots of the jurisdictional risk register and heatmap tool. The image contains a screenshot of the High-Risk Travel Jurisdiction.

      Download the Jurisdictional Risk Register and Heatmap Tool

      2.1.1 Identify assets

      1 – 2 hours

      1. As a group, consider critical or mission-essential functions in high-risk jurisdictions and the systems on which they depend. Brainstorm a list of the organization’s mission-supporting assets in high-risk jurisdictions. Consider:
      • Staff
      • Critical IT systems
      • Sensitive data
      • Critical operational processes
    • On a whiteboard, brainstorm the potential adverse effect of malicious agents in high-risk jurisdictions compromising critical assets. Consider the impact on:
      • Information systems.
      • Sensitive or regulated data.
      • Staff health and safety.
      • Critical operations and objectives.
      • Organizational finances.
      • Reputation and brand loyalty

      Threat

      Exploits an

      Asset

      Using a

      Method

      Creating an

      Effect

      Inputs for risk scenario identification

      Input

      Output

      • Corporate strategy
      • IT strategy
      • Security strategy
      • Business impact analyses
      • A list of the organization’s mission-supporting assets

      Materials

      Participants

      • Laptop
      • Projector
      • Whiteboard
      • Security team
      • IT leadership
      • System owner
      • Enterprise Risk Management

      Threat

      Exploits an

      Asset

      Using a

      Method

      Creating an

      Effect

      Inputs for risk scenario identification

      The image contains an example of the activity mentioned in the text above.

      Model threats to narrow the range of scenarios

      Motives and capabilities to perform attacks on critical assets vary across different threat actors.

      Category

      Actions

      Motivation

      Sophistication

      Nation-states

      Cyberespionage, cyberattacks

      Geopolitical

      High. Dedicated resources and personnel, extensive planning and coordination.

      Proxy organizations

      Espionage, destructive attacks

      Geopolitical, Ideological, Profit

      Moderate. Some planning and support functions and technical expertise.

      Cybercrime

      Theft, fraud, extortion

      Profit

      Moderate. Some planning and support functions and technical expertise.

      Hacktivists

      Disrupt operations, attack brands, release sensitive data

      Ideological

      Low. Rely on widely available tools that require little skill to deploy.

      Insiders

      Destruction or release of sensitive data, theft, exposure through negligence

      Incompetence, Discontent

      Internal access. Acting on their own or in concert with any of the above.

      • Criminals, hacktivists, and insiders vary in sophistication. Some criminal groups demonstrate a high degree of sophistication; however, a large cyber event that damages critical infrastructure does not align with their incentives to make money at minimal risk.
      • Proxy actors conduct offensive cyber operations on behalf of a beneficiary. They may be acting on behalf of a competitor, national government, or group of individuals.
      • Nation-states engage in long-term espionage and offensive cyber operations that support geopolitical and strategic policy objectives.

      2.1.2 Identify threats

      1 – 2 hours

      1. Review the outputs from activity 1.1.1 and activity 2.1.1.
      2. Identify threat agents that could undermine the security of critical assets in high-risk jurisdictions. Include internal and external actors.
      3. Assess their motives, means, and opportunities.
      • Which critical assets are most attractive? Why?
      • What paths and vulnerabilities can threat agents exploit to reach critical assets without going through a control?
      • How could they defeat existing controls? Draw on the MITRE framework to inform your analysis.
      • Once agents defeat a control, what further attack can they launch?

      Threat

      Exploits an

      Asset

      Using a

      Method

      Creating an

      Effect

      Inputs for risk scenario identification

      Input

      Output

      • Jurisdictional assessment from activity 1.1.1
      • Critical assets from activity 2.1.1
      • Potential vulnerabilities from:
        • Security control gap analysis
        • Security risk register
      • Threat intelligence
      • MITRE framework
      • A list of critical assets, threat agents, vulnerabilities, and potential attack vectors.

      Materials

      Participants

      • Laptop
      • Projector
      • Whiteboard
      • Security team
      • Infrastructure & Operations team
      • Enterprise Risk Management

      2.1.2 Identify threats (continued)

      1 – 2 hours

      1. On a whiteboard, brainstorm how threat agents will exploit vulnerabilities in critical assets to reach their goal. Redefine attack vectors to capture what could result from a successful initial attack.

      For example:

      • State actors and cybercriminals may steal or compromise end-user devices during travel to high-risk jurisdictions using malware they embed in airport charging stations, internet café networks, or hotel business centers.
      • Compromised devices may infect corporate networks and threaten sensitive data once they reconnect to them.

      Threat

      Exploits an

      Asset

      Using a

      Method

      Creating an

      Effect

      The image contains a screenshot of activity 2.1.2 as described in the text above.

      Bring together the critical risk elements into a single risk scenario

      Summarize the scenario further into a single risk statement

      Risk Scenario: High-Risk Travel

      State actors and cybercriminals can threaten staff, devices, and data during travel to high-risk jurisdictions. Device theft or compromise may occur while traveling through airports, accessing hotel computer and phone networks, or in internet cafés or other public areas. Threat actors can exploit data from compromised or stolen devices to undermine the organization’s strategic, economic, or competitive advantage. They can also infect compromised devices with malware that delivers malicious payloads once they reconnect with home networks.

      Risk Statement

      Cybercriminals compromise end-user devices during travel to high-risk jurisdictions, jeopardizing staff safety and leading to loss of sensitive data.

      Risk Scenario: Compliance Risk

      Rapid changes in the privacy and security regulatory landscape threaten an organization’s ability to meet its compliance obligations from local legal and regulatory frameworks. Organizations that fail to do so risk reputational damage, administrative fines, criminal charges, and loss of market share. In extreme cases, organizations may lose their license to operate in high-risk jurisdictions. Shifts in the regulatory landscape can involve additional requirements for data residency, cross-border data transfer, data breach notification, and third-party risk management.

      Risk Statement

      Rapid changes in the privacy and security regulations landscape threaten our ability to remain compliant, leading to reputational and financial loss.

      Fill out the Jurisdictional Risk Register and Heatmap Tool

      The tool is populated with data from two key risk scenarios: high-risk travel and compliance risk.

      The image includes two screenshots of the Jurisdictional Risk Register and Heatmap Tool.

      1. Label the risk in Tab 3, Column B.
      2. Record your risk scenario in Tab 3, Column C.
      3. Record your risk statement in Tab 3, Column D.
      4. Identify the applicable jurisdictions in Tab 3, Column E.
      5. You can further categorize the scenario as:
        • an enterprise risk (Column G).
        • an IT risk (Column H).

      Download the Jurisdictional Risk Register and Heatmap Tool

      Step 2.2

      Assess Risk Exposure

      Activities

      2.2.1 Identify existing controls

      2.2.2 Assess likelihood and impact

      This step involves the following participants:

      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Outcomes of this step

      • Assess risk exposure for each risk scenario through an analysis of its likelihood and impact.

      Brush up on risk assessment essentials

      The next step will help you prioritize IT risks based on severity.

      Likelihood of Occurrence X Likelihood of Impact = Risk Severity

      Likelihood of occurrence: How likely the risk is to occur.

      Likelihood of impact: The likely impact of a risk event.

      Risk severity: The significance of the risk.

      Evaluate risk severity against the risk tolerance thresholds and the cost of risk response.

      Identify existing controls before you proceed

      Existing controls will reduce the inherent likelihood and impact of the risk scenario you face.

      Existing controls were put in place to avoid, mitigate, or transfer key risks your organization faced in the past. Without considering existing controls, you run the risk of overestimating the likelihood and impact of the risk scenarios your organization faces in high-risk jurisdictions.

      For instance, the ability to remote-wipe corporate-owned devices will reduce the potential impact of a device lost or compromised during travel to high-risk jurisdictions.

      As you complete the risk assessment for each scenario, document existing controls that reduce their inherent likelihood and impact.

      2.2.1 Document existing controls

      6-10 hours

      1. Document the Risk Category and Existing Controls in the Jurisdictional Risk Register and Heatmap Tool.
        • Tactical controls apply to individual risks only. For instance, the ability to remote-wipe devices mitigates the impact of a device lost in a high-risk jurisdiction.
        • Strategic controls apply to multiple risks. For instance, deploying MFA for critical applications mitigates the likelihood that malicious actors can compromise a lost device and impedes their access in devices they do compromise.

      Input

      Output

      • Risk scenarios
      • Existing controls for risk scenarios

      Materials

      Participants

      • Jurisdictional Risk Register and Heatmap Tool
      • Laptop
      • Projector
      • Security team
      • IT leadership
      • Business stakeholders
      • Enterprise Risk Management

      Download the Jurisdictional Risk Register and Heatmap Tool.

      Assess the risk scenarios you identified in Phase 1

      The risk register is the central repository for risks in high-risk jurisdictions.

      • Use the second tab of the Jurisdictional Risk Register and Heatmap Tool to create likelihood, impact, and risk tolerance assessment scales to evaluate every risk event effectively.
      • Severity-level assessment is a “first pass” of your risk scenarios that will reveal your organization’s most severe risks in high-risk jurisdictions.
      • You can incorporate expected cost calculations into your evaluation to assess scenarios in greater detail.
      • Expected cost represents how much you would expect to pay in an average year for each risk event. Expected cost calculations can help compare IT risks to non-IT risks that may not use the same scales and communicate system-level risk to the business in a language they will understand.

      Expected cost calculations may not be practical. Determining robust likelihood and impact values to produce cost estimates can be challenging and time consuming. Use severity-level assessments as a first pass to make the case for risk mitigation measures and take your lead from stakeholders.

      The image contains two screenshots of the Jurisdictional Risk Register and Heatmap Tool.

      Use the Jurisdictional Risk Register and Heatmap Tool to capture and analyze your data.

      2.2.2 Assess likelihood and impact

      6-10 hours

      1. Assign each risk scenario a likelihood of occurrence and a likely impact level that represents the impact of the scenario on the whole organization considering existing controls. Record your results in Tab 3, column R and S, respectively.
      2. You can further dissect likelihood and impact into component parameters but focus first on total likelihood and impact to keep the task manageable.
      3. As you input the first few likelihood and impact values, compare them to one another to ensure consistency and accuracy. For instance, is a device lost in a high-risk jurisdiction truly more impactful than a device compromised with commercial surveillance software?
      4. The tool will calculate the probability of risk exposure based on the likelihood and consequence associated with the scenario. The results are published in Tab 3, Column T.

      Input

      Output

      • Risk scenarios
      • Assessed the likelihood of occurrence and impact for all identified risk events

      Materials

      Participants

      • Jurisdictional Risk Register and Heatmap Tool
      • Laptop
      • Projector
      • Security team
      • IT leadership
      • Business stakeholders
      • Enterprise Risk Management

      Download the Jurisdictional Risk Register and Heatmap Tool.

      Refine your risk assessment to justify your estimates

      Document the rationale behind each value and the level of consensus in group discussions.

      Stakeholders will likely ask you to explain some of the numbers you assigned to likelihood and impact assessments. Pointing to an assessment methodology will give your estimates greater credibility.

      • Assign one individual to take notes during the assessment exercise.
      • Have them document the main rationale behind each value and the level of consensus.

      The goal is to develop robust intersubjective estimates of the likelihood and impact of a risk scenario.

      We assigned a 50% likelihood rating to a risk scenario. Were we correct?

      Assess the truth of the following statements to test likelihood assessments. In this case, do these two statements seem true?

      • The risk event will likely occur once in the next two years, all things being equal.
      • In two nearly identical organizations, one out of two will experience the risk event this year.
      The image includes a screenshot of the High-Risk Travel Jurisdictions.

      Phase 3

      Execute Response

      This phase will walk you through the following activities:

      • Prioritize and treat global risks to critical assets based on their value and exposure.
      • Build an initiative roadmap that identifies and applies relevant controls to protect critical assets. Identify key risk indicators to monitor progress.

      This phase involves the following participants:

      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Step 3.1

      Treat Security Risks

      Activities

      3.1.1 Identify and assess risk response

      This step involves the following participants:

      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Outcomes of this step

      • Prioritize and treat global risks to critical assets based on their value and exposure.

      Analyze and select risk responses

      The next step will help you treat the risk scenarios you built in Phase 2.

      Identify

      Identify risk responses.

      Predict

      Predict the effectiveness of the risk response, if implemented, by estimating the residual likelihood and impact of the risk.

      Calculate

      The tool will calculate the residual severity of the risk after applying the risk response.

      The first part of the phase outlines project activities. The second part elaborates on high-risk travel and compliance risk, the two key risk scenarios we are following throughout the project. Use the Jurisdictional Risk Register and Heatmap Tool to capture your work.

      Analyze likelihood and impact to identify response

      The image contains a diagram of he risk response analysis. Risk Transfer and Risk Avoidance has the most likelihood, and Risk Acceptance and Risk Mitigation have the most impact. Risk Avoidance has the most likelihood and most impact in regards to risk response.

      3.1.1 Identify and assess risk response

      Complete the following steps for each risk scenario.

      1. Identify a risk response action that will help reduce the likelihood of occurrence or the impact if the scenario were to occur. Indicate the type of risk response (avoidance, mitigation, transfer, acceptance, or no risk exists).
      2. Assign each risk response action a residual likelihood level and a residual impact level. This is the same step you performed in Activity 2.2.2, but you are now are estimating the likelihood and impact of the risk event after you implemented the risk response action successfully. The Jurisdictional Risk Register and Heatmap Tool will generate a residual risk severity level for each risk event.
      3. Identify the potential Risk Action Owner (Project Manager) if the response is selected and turned into an IT project, and document this in the Jurisdictional Risk Register and Heatmap Tool .
      4. For each risk event, document risk response actions, residual likelihood and impact levels, and residual risk severity level.

      Input

      Output

      • Risk scenarios from Phase 2
      • Risk scenario mitigation plan

      Materials

      Participants

      • Whiteboard/flip charts
      • Jurisdictional Risk Register and Heatmap Tool
      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Download the Jurisdictional Risk Register and Heatmap Tool

      Step 3.2

      Mitigate Travel Risk

      Activities

      3.2.1 Develop a travel policy

      3.2.2 Develop travel procedures

      3.2.3 Design high-risk travel guidelines

      This step involves the following participants:

      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Outcomes of this step

      • Prioritize and treat global risks to critical assets based on their value and exposure.

      Identify controls to mitigate jurisdictional risk

      This section provides guidance on the most prevalent risk scenarios identified in Phase 2 and provides a more in-depth examination of the two most prevalent ones, high-risk travel and compliance risk. Determine the appropriate response to each risk scenario to keep global risks to critical assets aligned with the organization’s risk tolerance.

      Key Risk Scenarios

      • High-Risk Travel
      • Compliance Risk
      • Insider Threat
      • Advanced Persistent Threat
      • Commercial Surveillance

      Travel risk is a common concern in organizations with global operations

      • The security of staff, devices, and data is one of the biggest challenges facing organizations with a global footprint. Working and traveling in unpredictable environments will aways carry a degree of risk, but organizations can do much to develop a safer and more secure working environment.
      • Compromised or stolen devices can provide threat actors with access to data that could compromise the organization’s strategic, economic, or competitive advantage or expose the organization to regulatory risk.
      • For many organizations, security risk assessments, security plans, travel security procedures, security training, and incident reporting systems are a key part of their operating language.
      • The following section provides a simple structure to help organizations demystify travel in high-risk jurisdictions.

      The image contains a diagram to present high-risk jurisdictions.

      Before you leave

      • Identify high-risk countries.
      • Enable controls.
      • Limit what you pack.

      During your trip

      • Assume you are monitored.
      • Limit access to systems.
      • Prevent theft.

      When you return

      • Change your password.
      • Restore your devices.

      Case study

      Higher Education: Camosun College

      Interview: Evan Garland

      Frame additional security controls as a value-added service.

      Situation

      The director of the international department at Camosun College reached out to IT security for additional support. Department staff often traveled to hostile environments. They were concerned malicious agents would either steal end-user devices or compromise them and access sensitive data. The director asked IT security for options that would better protect traveling staff, their devices, and the information they contain.

      Challenges

      First, controls would need to admit both work and personal use of corporate devices. Staff relied exclusively on work devices for travel to mitigate the risk of personal device theft. Personal use of corporate devices during travel was common. Second, controls needed to strike the right balance between friction and effortless access. Traveling staff had only intermittent access to IT support. Restrictive controls could prevent them from accessing their devices and data altogether.

      Solution

      IT consulted staff to discuss light-touch solutions that would secure devices without introducing too much complexity or compromising functionality. They then planned security controls that involved user interaction and others that did not and identified training requirements.

      Results

      Controls with user interaction

      Controls without user interaction

      • Multifactor authentication for college systems and collaboration platforms
      • Password manager for both work and personal use for staff for stronger passwords and practices
      • Security awareness training to help traveling staff identify potential threats while traveling through airports or accessing public Wi-Fi.
      • Drive encryption and always-on VPN to protect data at rest and in transit
      • Increased setting for phishing and spam filtering for traveling staff email
      • Enhanced anti-malware/endpoint detection and response (EDR) solution for traveling laptops

      Build a program to mitigate travel risks

      There is no one-size-fits-all solution.

      The most effective solution will take advantage of existing risk management policies, processes, and procedures at your organization.

      • Develop a framework. Outline the organization’s approach to high-risk travel, including the policies, procedures, and mechanisms put in place to ensure safe travel to high-risk jurisdictions.
      • Draft a policy. Outline the organization’s risk attitude and key security principles and define roles and responsibilities. Include security responsibilities and obligations in job descriptions of staff members and senior managers.
      • Provide flexible options. Inherent travel risk will vary from one jurisdiction to another. You will likely not find an approach that works for every case. Establish locally relevant measures and plans in different security contexts and risk environments.
      • Look for quick wins. Identify measures or requirements that you can establish quickly but that can have a positive effect on the security of staff, data, and devices.
      • Monitor and review. Undertake periodic reviews of the organization’s security approach and management framework, as well as their implementation, to ensure the framework remains effective.

      3.2.1 Develop a travel policy

      1. Work with your business leaders to build a travel policy for high-risk jurisdictions. The policy should be a short and accessible document structured around four key sections:
        • A statement on the importance of staff security and safety, the scope of the policy, and who it applies to (staff, consultants, contractors, volunteers, visitors, accompanying dependants, etc.).
        • A principles section explaining the organization’s security culture, risk attitude, and the key principles that shape the organization’s approach to staff security and safety.
        • A responsibilities section setting out the organization’s security risk management structure and the roles and actions allocated to specific positions.
        • A minimal security requirements section establishing the specific security requirements that must be in place in all locations and specific locations.
      2. Common security principles include:
      • Shared responsibility – Managing risks to staff is a shared organizational responsibility.
      • Acknowledgment of risk – Managing security will not remove all risks. Staff need to appreciate, as part of their informed consent, that they are still exposed to risk.
      • Primacy of life – Staff safety is of the highest importance. Staff should never place themselves at excessive risk to meet program objectives or protect property.
      • Proportionate risk – Risks must be assessed to ensure they are proportionate to the benefits organizational activities provide and the ability to manage those risks.
      • Right to withdraw – Staff have the right to withdraw from or refuse to take up work in a particular area due to security concerns.
      • No right to remain – The organization has the right to suspend activities that it considers too dangerous.
    • Cross-reference the organization’s other governing policies that outline requirements related to security risk management, such as the health and safety policy, access control policy, and acceptable use of security assets.
    • Input

      Output

      • List of high-risk jurisdictions
      • Risk scenarios from Phase 2
      • Data inventory and data flows
      • Travel policy for high-risk jurisdictions

      Materials

      Participants

      • Whiteboard/flip charts
      • Jurisdictional Risk Register and Heatmap Tool
      • Security team
      • Legal team
      • IT leadership
      • Risk Management

      Develop security plans for high-risk travel

      Security plans advise staff on how to manage the risk identified in assessments.

      Security plans are key country documents that outline the security measures and procedures in place and the responsibilities and resources required to implement them. Security plans should be established in high-risk jurisdictions where your organization has a regular, significant presence. Security plans must remain relevant and accessible documents that address the specific risks that exist in that location, and, if appropriate, are specific about where the measures apply and who they apply to. Plans should be updated regularly, especially following significant incidents or changes in the operating environment or activities.

      Key Components

      Critical information – One-page summary of pertinent information for easy access and quick reference (e.g. curfew times, no-go areas, important contacts).

      Overview – Purpose and scope of the document, responsibilities for security plan, organization’s risk attitude, date of completion and review date, and a summary of the security strategy and policy.

      Current Context – Summary of current operating context and overall security situation; main risks to staff, assets, and operations; and existing threats and risk rating.

      Procedures – Simple security procedures that staff should adhere to in order to prevent incidents and how to respond should problems arise. Standard operating procedures (SOPs) should address key risks identified in the assessment.

      Security levels – The organization's security levels/phases, with situational indicators that reflect increasing risks to staff in that context and location and specific actions/measures required in response to increasing insecurity.

      Incident reporting – The procedures and responsibilities for reporting security-related incidents; for example, the type of incidents to be reported, the reporting structure, and the format for incident reporting.

      Determine travel risk

      Tailor your risk response to the security risk assessment you conducted in earlier stages of this project.

      Ratings are formulated by assessing several types of risk, including conflict, political/civil unrest, terrorism, crime, and health and infrastructure risks.

      Rating

      Description (Examples)

      Recommended Action

      Low

      Generally secure with adequate physical security. Low violent crime rates. Some civil unrest during significant events. Acts of terrorism rare. Risks associated with natural disasters limited and health threats mainly preventable.

      Basic personal security, travel, and health precautions required.

      Moderate

      Periodic civil unrest. Antigovernment, insurgent, or extremist groups active with sporadic acts of terrorism. Staff at risk from common and violent crime. Transport and communications services are unreliable and safety records are poor. Jurisdiction prone to natural disasters or disease epidemics.

      Increased vigilance and routine security procedures required.

      High

      Regular periods of civil unrest, which may target foreigners. Antigovernment, insurgent, or extremist groups very active and threaten political or economic stability. Violent crime rates high and targeting of foreigners is common. Infrastructure and emergency services poor. May be regular disruption to transportation or communications services. Certain areas off-limits to foreigners. Jurisdictions experiencing a natural disaster or a disease epidemic are considered high risk.

      High level of vigilance and effective, context-specific security precautions required.

      Extreme

      Undergoing active conflict or persistent civil unrest. Risk of being caught up in a violent incident or attack is very high. Civil authorities may have lost control of significant portions of the country. Lines between criminality and political and insurgent violence are blurred. Foreigners are likely to be denied access to significant parts of the country. Transportation and communication services are severely degraded or non-existent. Violence presents a direct threat to staff security.

      Stringent security precautions essential and may not be sufficient to prevent serious incidents.

      Program activities may be suspended and staff withdrawn at very short notice.

      3.2.2 Develop travel procedures

      1. Work with your business leaders to build travel procedures for high-risk jurisdictions. The procedures should be tailored to the risk assessment and address the risk scenarios identified in Phase 2.
      2. Use the categories outlined in the next two slides to structure the procedure. Address all types of travel, detail security measures, and outline what the organization expects of travelers before, during, and after their trip.
      3. Consider the implementation of special measures to limit the impact of a potential security event, including:
        • Information end-user device loaner programs.
        • Temporary travel service email accounts.
      4. Specify what happens when staff add personal travel to their work trip to cover issues such as insurance, check-in, actual travel times, etc.
      5. Discuss the rationale for each procedure. Ensure the components align with the policy statements outlined in the high-risk travel policy developed in the previous step.

      Input

      Output

      • List of high-risk jurisdictions
      • Risk scenarios from Phase 2
      • High-risk travel policy
      • Travel procedures for high-risk jurisdictions

      Materials

      Participants

      • Whiteboard/flip charts
      • Jurisdictional Risk Register and Heatmap Tool
      • Security team
      • Legal team
      • IT leadership
      • Risk Management

      Draft procedures to mitigate travel risks

      Address all types of travel, detail security measures, and outline what the organization expects of travelers before, during, and after their trip

      Introduction

      Clarifies who the procedures apply to. Highlights any differences in travel security requirements or support provided to staff, consultants, partners, and official visitors.

      Travel risk ratings

      Explains the travel or country risk rating system, how staff access the information, the different categories and indicators, and their implications.

      Roles and responsibilities

      Clarifies the responsibilities of travelers, their line managers or contact points, and senior management regarding travel security and how this changes for destinations with higher risk ratings.

      Travel authorization

      Stipulates who in the organization authorizes travel, the various compliance measures required, and how this changes for destinations with higher risk ratings.

      Travel risk assessment

      Explains when travel risk assessments are required, the template that should be used, and who approves the completed assessments.

      Travel security procedures should specify what happens when staff add personal travel to their work trip to cover issues such as insurance, check-in, actual travel times, etc.

      Pre-travel briefings

      Outlines the information that must be provided to travelers prior to departure, the type of briefing required and who provides it, and how these requirements change as risk ratings increase.

      Security training

      Explain security training required prior to travel. This may vary depending on the country’s risk rating. Includes information on training waiver system, including justifications and authorization.

      Traveler profile forms

      Travelers should complete a profile form, which includes personal details, emergency contacts, medical details, social media footprint, and proof-of-life questions (in contexts where there are abduction risks).

      Check-in protocol

      Specifies who travelers must maintain contact with while traveling and how often, as well as the escalation process in case of loss of contact. The frequency of check-ins should reflect the increase in the risk rating for the destination.

      Emergency procedures

      Outlines the organization's emergency procedures for security and medical emergencies.

      3.2.3 Design high-risk travel guidelines

      • Supplement the high-risk travel policies and procedures with guidelines to help international travelers stay safe.
      • The document is intended for an end-user audience and should reflect your organization’s policies and procedures for the use of information and information systems during international travel.
      • Use the Digital Safety Guidelines for International Travel template in concert with this blueprint to provide guidance on what end users can do to stay safe before they leave, during their trip, and when they return.
      • Consider integrating the guidelines into specialized security awareness training sessions that target end users who travel to high-risk jurisdictions.
      • The guidelines should supplement and align with existing technical controls.

      Input

      Output

      • List of high-risk jurisdictions
      • Risk scenarios from Phase 2
      • High-risk travel policy
      • High-risk travel procedure
      • Travel guidelines for high-risk jurisdictions

      Materials

      Participants

      • Whiteboard/flip charts
      • Jurisdictional Risk Register and Heatmap Tool
      • Security team
      • Legal team
      • IT leadership
      • Risk Management

      Download the Digital Safety Guidelines for International Travel template

      Step 3.3

      Mitigate Compliance Risk

      Activities

      3.3.1 Identify data localization obligations

      3.3.2 Integrate obligations into IT system design

      3.3.3 Document data processing activities

      3.3.4 Choose the right mechanism

      3.3.5 Implement the appropriate controls

      3.3.6 Identify data breach notification obligations

      3.3.7 Integrate data breach notification into incident response

      3.3.8 Identify vendor security and data protection requirements

      3.3.9 Build due diligence questionnaire

      3.3.10 Build appropriate data processing agreement

      This step involves the following participants:

      • Security team
      • Risk and Compliance
      • IT leadership (optional)

      Outcomes of this step

      • Prioritize and treat global risks to critical assets based on their value and exposure.

      Compliance risk is a prevalent risk in organizations with a global footprint

      • The legal and regulatory landscape is evolving rapidly to keep step with the pace of technological change. Security and privacy leaders are expected to mitigate the risk of noncompliance as the organization expands to new jurisdictions.
      • Organizations with a global footprint must stay abreast of local regulations and provide risk management guidance to business leaders to support global operations.
      • This sections describes four compliance risks in this context:
        • Cross-border data transfer
        • Third-party risk management
        • Data breach notification
        • Data residency

      Compliance with local obligations

      Likelihood: Medium to High

      Impact: High

      Data Residency

      Gap Controls

      • Identify and document the data localization obligations for the jurisdictions that the organization is operating in.
      • Design and implement IT systems that satisfy the data localization requirements.
      • Comply with data localization obligations within each jurisdiction.

      Heatmap of Global Data Residency Regulations

      The image contains a screenshot of a picture of a world map with various shades of blue to demonstrate the heatmap of global data residency regulations.
      Source: InCountry, 2021

      Examples of Data Residency Requirements

      Country

      Data Type

      Local Storage Requirements

      Australia

      Personal data – heath record

      My Health Records Act 2012

      China

      Personal information — critical information infrastructure operators

      Cybersecurity law

      Government cloud data

      Opinions of the Office of the Central Leading Group for Cyberspace Affairs on Strengthening Cybersecurity Administration of Cloud Computing Services for Communist Party and Government Agencies

      India

      Government email data

      The Public Records Act of 1993

      Indonesia

      Data held by electronic system operator for the public service

      Regulation 82 concerning “Electronic System and Transaction Operation”

      Germany

      Government cloud service data

      Criteria for the procurement and use of cloud services by the federal German administration

      Russia

      Personal data

      The amendments of Data Protection Act No. 152 FZ

      Vietnam

      Data held by internet service providers

      The Decree on Management, Provision, and Use of Internet Services and Information Content Online (Decree 72)

      US

      Government cloud service data

      Defense Federal Acquisition Regulation Supplement: Network Penetration Reporting and Contracting for Cloud Services (DFARS Case 2013-D018)

      3.3.1 Identify data localization obligations

      1-2 hours

      1. Work with your business leaders to identify and document the jurisdictions where your organization is operating in or providing services and products to consumers within.
      2. Work with your legal team to identify and document all relevant data localization obligations for the data your organization generates, collects, and processes in order to operate your business.
      3. Record your data localization obligations in the table below.

      Jurisdiction

      Relevant Regulations

      Local Storage Requirements

      Date Type

      Input

      Output

      • List of jurisdictions your organization is operating in
      • Relevant security and data protection regulations
      • Data inventory and data flows
      • Completed list of data localization obligations

      Materials

      Participants

      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Privacy team
      • Security team
      • Legal team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      3.3.2 Integrate obligations into your IT system design

      1-2 hours

      1. Work with your IT department to design the IT architecture and systems to satisfy the data localization requirements.
      2. The table below provides a checklist for integrating privacy considerations into your IT systems.

      Item

      Consideration

      Answer

      Supporting Document

      1

      Have you identified business services that process data that will be subject to localization requirements?

      2

      Have you identified IT systems associated with the business services mentioned above?

      3

      Have you established a data inventory (i.e. data types, business purposes) for the IT systems mentioned above?

      4

      Have you established a data flow diagram for the data identified above?

      5

      Have you identified the types of data that should be stored locally?

      6

      Have you confirmed whether a copy of the data locally stored will satisfy the obligations?

      7

      Have you confirmed whether an IT redesign is needed or whether modifications (e.g. adding a server) to the IT systems would satisfy the obligations?

      8

      Have you confirmed whether access from another jurisdiction is allowed?

      9

      Have you identified how long the data should be stored?

      Input

      Output

      • Data localization obligations
      • Business services that process data that will be subject to localization requirements
      • IT systems associated with business services
      • Data inventory and data flows
      • Completed checklist of localization obligations for IT system design

      Materials

      Participants

      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Privacy team
      • Security team
      • Legal team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      Compliance with local obligations

      Likelihood: Medium to High

      Impact: High

      Cross-Border Transfer

      Gap Controls

      • Know where you transfer your data.
      • Identify jurisdictions that your organization is operating in and that impose different requirements for the cross-border transfer of personal data.
      • Adopt and implement a proper cross-border data transfer mechanism in accordance with applicable privacy laws and regulations.
      • Re-evaluate at appropriate intervals.

      Which cross-border transfer mechanism should I choose?

      Transfer Mechanism

      Advantages

      Disadvantages

      Standard Contractual Clauses (SCC)

      • Easy to implement
      • No DPA (data processing agreement) approval
      • Not suitable for complex data transfers
      • Do not meet business agility
      • Needs legal solution

      Binding Corporate Rules (BCRs)

      • Meets business agility needs
      • Raises trust in the organization
      • Doubles as solution for art. 24/25 of the GDPR
      • Sets high compliance maturity level
      • Takes time to draft/implement
      • Requires DPA approval (scrutiny)
      • Requires culture of compliance
      • Approved by one "lead" authority and two other "co-lead“ authorities
      • Takes usually between six and nine months for the approval process only

      Code of Conduct

      • Raises trust in the sector
      • Self-regulation instead of law
      • No code of conduct approved yet
      • Takes time to draft/implement
      • Requires DPA approval and culture of compliance
      • Needs of organization may not be met

      Certification

      • Raises trust in the organization
      • No certification schemes available yet
      • Risk of compliance at minimum necessary
      • Requires audits

      Consent

      • Legal certainty
      • Transparent
      • Administrative burden
      • Some data subjects are incapable of consenting all or nothing

      3.3.3 Document data processing activities

      1-2 hours

      1. Identify and document the following information:
        • Name of business process
        • Purposes of processing
        • Lawful basis
        • Categories of data subjects and personal data
        • Data subject categories
        • Which system the data resides in
        • Recipient categories
        • Third country/international organization
        • Documents for appropriate safeguards for international transfer (adequacy, SCCs, BCRs, etc.)
        • Description of mitigating measures

      Input

      Output

      • Name of business process
      • Categories of personal data
      • Which system the data resides
      • Third country/international organization
      • Documents for appropriate safeguards for international transfer
      • Completed list of data processing activities

      Materials

      Participants

      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Privacy team
      • Security team
      • Legal team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      3.3.4 Choose the right mechanism

      1-2 hours

      1. Identify jurisdictions that your organization is operating in and that impose different requirements for the cross-border transfer of personal data. For example, the EU’s GDPR and China’s Personal Information Protection Law require proper cross-border transfer mechanisms before the data transfers. Your organization should decide which cross-border transfer mechanism is the best fit for your cross-border data transfer scenarios.
      2. Use the following table to identify and document the pros and cons of each data transfer mechanism and the final decision.

      Data Transfer Mechanism

      Pros

      Cons

      Final Decision

      SCC

      BCR

      Code of Conduct

      Certification

      Consent

      Input

      Output

      • List of relevant data transfer mechanisms
      • Assessment of the pros and cons of each mechanism
      • Final decision regarding which data transfer mechanism is the best fit for your organization

      Materials

      Participants

      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Privacy team
      • Security team
      • Legal team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      3.3.5 Implement the appropriate controls

      1-3 hours

      • One of the most common mechanisms is standard contractual clauses (SCCs).
      • Use Info-Tech’s Standard Contractual Clauses Template to facilitate your cross-border transfer activities.
      • Identify and check whether the following core components are covered in your SCC and record the results in the table below.
      # Core Components Status Note
      1 Purpose and scope
      2 Effect and invariability of the Clauses
      3 Description of the transfer(s)
      4 Data protection safeguards
      5 Purpose limitation
      6 Transparency
      7 Accuracy and data minimization
      8 Duration of processing and erasure or return of data
      9 Storage limitation
      10 Security of processing
      11 Sensitive data
      12 Onward transfers
      13 Processing under the authority of the data importer
      14 Documentation and compliance
      15 Use of subprocessors
      16 Data subject rights
      17 Redress
      18 Liability
      19 Local laws and practices affecting compliance with the Clauses
      20 Noncompliance with the Clauses and termination
      21 Description of data processing activities, such as list of parties, description of transfer, etc.
      22 Technical and organizational measures
      InputOutput
      • Description of the transfer(s)
      • Duration of processing and erasure or return of data
      • Onward transfers
      • Use of subprocessors
      • Etc.
      • Draft of the standard contractual clauses (SCC)
      MaterialsParticipants
      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Legal team
      • Privacy team
      • Security team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      Compliance with local obligations

      Likelihood: High

      Impact: Medium to High

      Data Breach

      Gap Controls

      • Identify jurisdictions that your organization is operating in and that impose different obligations for data breach reporting.
      • Document the notification obligations for various business scenarios, such as controller to DPA, controller to data subject, and processor to controller.
      • Integrate breach notification obligations into security incident response process.

      Examples of Data Breach Notification Obligations

      Location

      Regulation/ Standard

      Reporting Obligation

      EU

      GDPR

      72 hours

      China

      PIPL

      Immediately

      US

      HIPAA

      No later than 60 days

      Canada

      PIPEDA

      As soon as feasible

      Global

      PCI DSS

      • Visa – immediately after breach discovered
      • Mastercard – within 24 hours of discovering breach
      • American Express – immediately after breach discovered

      Summary of US State Data Breach Notification Statutes

      The image contains a graph to show the summary of the US State Data Breach Notification Statutes.

      Source: Davis Wright Tremaine

      3.3.6 Identify data breach notification obligations

      1-2 hours

      1. Identify jurisdictions that your organization is operating in and that impose different obligations for data breach reporting.
      2. Document the notification obligations for various business scenarios, such as controller to DPA, controller to data subject, and processor to controller.
      3. Record your data breach obligations in the table below.
      Region Regulation/Standard Reporting Obligation

      Input

      Output

      • List of regions and jurisdictions your business is operating in
      • List of relevant regulations and standards
      • Documentation of data breach reporting obligations in applicable jurisdictions

      Materials

      Participants

      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Legal team
      • Privacy team
      • Security team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      3.3.7 Integrate data breach notification into incident response

      1-2 hours

      • Integrate breach notification obligations into the security incident response process. Understand the security incident management framework.
      • All incident runbooks follow the same process: detection, analysis, containment, eradication, recovery, and post-incident activity.
      • The table below provides a basic checklist for you to consider when implementing your data breach and incident handling process.
      # Phase Considerations Status Notes
      1 Prepare Ensure the appropriate resources are available to best handle an incident.
      2 Detect Leverage monitoring controls to actively detect threats.
      3 Analyze Distill real events from false positives.
      4 Contain Isolate the threat before it can cause additional damage.
      5 Eradicate Eliminate the threat from your operating environment.
      6 Recover Restore impacted systems to a normal state of operations.
      7 Report Report data breaches to relevant regulators and data subjects if required.
      8 Post-Incident Activities Conduct a lessons-learned post-mortem analysis.
      InputOutput
      • Security and data protection incident response steps
      • Key considerations for integrating data breach notifications into incident response
      • Data breach notifications integrated into the incident response process
      MaterialsParticipants
      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Security team
      • Privacy team
      • Legal team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      Compliance with local obligations

      Likelihood: High

      Impact: Medium to High

      Third-Party Risk

      Gap Controls

      • Build an end-to-end third-party security and privacy risk management process.
      • Perform internal due diligence prior to selecting a service provider.
      • Stipulate the security and privacy protection obligations of the third party in a legally binding document such as contract or data processing agreement, etc.

      End-to-End Third-Party Security and Privacy Risk Management

      1. Pre-Contract
      • Due diligence check
    • Signing of Contract
      • Data processing agreement
    • Post-Contract
      • Continuous monitoring
      • Regular check or audit
    • Termination of Contract
      • Data deletion
      • Access deprovisioning

      Examples of Vendor Security Management Requirements

      Region

      Law/Standard

      Section

      EU

      General Data Protection Regulation (GDPR)

      Article 28 (1)

      Article 46 (1)

      US

      Health Insurance Portability and Accountability Act (HIPAA)

      §164.308(b)(1)

      US

      New York Department of Financial Services Cybersecurity Requirements

      500.11(a)

      Global

      ISO 27002:2013

      15.1.1

      15.1.2

      15.1.3

      15.2.1

      15.2.2

      US

      NIST 800-53

      SA-12

      SA-12 (2)

      US

      NIST Cybersecurity Framework

      ID-SC-1

      ID-SC-2

      ID-SC-3

      ID-SC-4

      Canada

      OSFI Cybersecurity Guidelines

      4.25

      4.26

      3.3.8 Identify vendor security and data protection requirements

      1-2 hours

      • Effective vendor security risk management is an end-to-end process that includes assessment, risk mitigation, and periodic reassessments.
      • An efficient and effective assessment process can only be achieved when all stakeholders are participating.
      • Identify and document your vendor security and data protection requirements in the table below.
      Region Law/Standard Section Requirements

      Input

      Output

      • List of regions and jurisdictions your business is operating in
      • List of relevant regulations and standards
      • Documentation of vendor security and data protection obligations in applicable jurisdictions

      Materials

      Participants

      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Legal team
      • Privacy team
      • Security team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      3.3.9 Build due diligence questionnaire

      1-2 hours

      Perform internal due diligence prior to selecting a service provider.

      1. Build and right-size your vendor security questionnaire by leveraging Info-Tech’s Vendor Security Questionnaire template.
      2. Document your vendor security questionnaire in the table below.
      # Question Vendor Request Vendor Comments
      1 Document Requests
      2 Asset Management
      3 Governance
      4 Supply Chain Risk Management
      5 Identify Management, Authentication, and Access Control
      InputOutput
      • List of regions and jurisdictions your business is operating in
      • List of relevant regulations and standards
      • Business security and data protection requirements and expectations
      • Draft of due diligence questionnaire
      MaterialsParticipants
      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Legal team
      • Privacy team
      • Security team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      3.3.10 Build appropriate data processing agreement

      1-2 hours

      1. Stipulate the security and privacy protection obligations of the third party in a legally binding document such as contract or data processing agreement, etc.
      2. Leverage Info-Tech’s Data Processing Agreement Template to put the language into your legally binding document.
      3. Use the table below to check whether core components of a typical DPA are covered in your document.
      # Core Components Status Note
      1 Processing of personal data
      2 Scope of application and responsibilities
      3 Processor's obligations
      4

      Controller's obligations

      5 Data subject requests
      6 Right to audit and inspection
      7 Subprocessing
      8 Data breach management
      9 Security controls
      10 Transfer of personal data
      11 Duty of confidentiality
      12 Compliance with applicable laws
      13 Service termination
      14 Liability and damages
      InputOutput
      • Processing of personal data
      • Processor’s obligations
      • Controller’s obligations
      • Subprocessing
      • Etc.
      • Draft of data processing agreement (DPA)
      MaterialsParticipants
      • Guidelines for Compliance With Local Security and Privacy Laws Template
      • Legal team
      • Privacy team
      • Security team
      • IT leadership
      • Risk Management

      Download the Guidelines for Compliance With Local Security and Privacy Laws Template

      Summary of Accomplishment

      Problem Solved

      By following Info-Tech’s methodology for securing global operations, you have:

      • Evaluated the security context of your organization’s global operations.
      • Identified security risks scenarios unique to high-risk jurisdictions and assessed the exposure of critical assets.
      • Planned and executed a response.

      You have gone through a deeper analysis of two key risk scenarios that affect global operations:

      • Travel to high-risk jurisdictions.
      • Compliance risk.

      If you would like additional support, have our analysts guide you through an Info-Tech workshop or Guided Implementation.

      Contact your account representative for more information.

      workshop@infotech.com

      1-888-670-8889

      Additional Support

      If you would like additional support, have our analysts guide you through other phases as part of an Info-Tech Workshop.

      The image contains a picture of Michel Hebert.

      Contact your account representative for more information.

      workshops@infotech.com 1-888-670-8889

      To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team. Info-Tech analysts will join you and your team at your location or welcome you to Info-Tech’s historic Toronto office to participate in an innovative onsite workshop.

      The following are sample activities that will be conducted by Info-Tech analysts with your team:

      The image contains a screenshot of High-Risk Travel Jurisdictions.

      Identify High-Risk Jurisdictions

      Develop requirements to identify high-risk jurisdictions.

      The image contains a screenshot of Build Risk Scenarios.

      Build Risk Scenarios

      Build risk scenarios to capture assets, vulnerabilities, threats, and the potential effect of a compromise.

      External Research Contributors

      Ken Muir

      CISO

      LMC Security

      Premchand Kurup

      CEO

      Paramount Computer Systems

      Preeti Dhawan

      Manager, Security Governance

      Payments Canada

      Scott Wiggins

      Information Risk and Governance

      CDPHP

      Fritz Y. Jean Louis

      CISO

      Globe and Mail

      Eric Gervais

      CIO

      Ovivo Water

      David Morrish

      CEO

      MBS Techservices

      Evan Garland

      Manager, IT Security

      Camosun College

      Jacopo Fumagalli

      CISO

      Axpo

      Dennis Leon

      Governance and Security Manager

      CPA Canada

      Tero Lehtinen

      CIO

      Planmeca Oy

      Related Info-Tech Research

      Build an IT Risk Management Program

      • Build a program to identify, evaluate, assess, and treat IT risks.
      • Monitor and communicate risks effectively to support business decision making.

      Combine Security Risk Management Components Into One Program

      • Develop a program focused on assessing and managing information system risks.
      • Build a governance structure that integrates security risks within the organization’s broader approach to risk management.

      Build an Information Security Strategy

      • Build a holistic, risk-aware strategy that aligns to business goals.
      • Develop a roadmap of prioritized initiatives to implement the strategy over 18 to 36 months.

      Bibliography

      2022 Cost of Insider Threats Global Report.” Ponemon Institute, NOVIPRO, 9 Feb. 2022. Accessed 25 May 22.

      “Allianz Risk Barometer 2022.” Allianz Global Corporate & Specialty, Jan. 2022. Accessed 25 May 22.

      Bickley, Shaun. “Security Risk Management: a basic guide for smaller NGOs”. European Interagency Security Forum (EISF), 2017. Web.

      “Biden Administration Warns against spyware targeting dissidents.” New York Times, 7 Jan 22. Accessed 20 Jan 2022.

      Boehm, Jim, et al. “The risk-based approach to cybersecurity.” McKinsey & Company, October 2019. Web.

      “Cost of a Data Breach Report 2021.” IBM Security, July 2021. Web.

      “Cyber Risk in Asia-Pacific: The Case for Greater Transparency.” Marsh & McLennan Companies, 2017. Web.

      “Cyber Risk Index.” NordVPN, 2020. Accessed 25 May 22

      Dawson, Maurice. “Applying a holistic cybersecurity framework for global IT organizations.” Business Information Review, vol. 35, no. 2, 2018, pp. 60-67.

      “Framework for improving critical infrastructure cybersecurity.” National Institute of Standards and Technology, 16 Apr 2018. Web.

      “Global Cybersecurity Index 2020.” International Telecommunication Union (ITU), 2021. Accessed 25 May 22.

      “Global Risk Survey 2022.” Control Risks, 2022. Accessed 25 May 22.

      “International Travel Guidance for Government Mobile Devices.” Federal Mobility Group (FMG), Aug. 2021. Accessed 18 Nov 2021.

      Kaffenberger, Lincoln, and Emanuel Kopp. “Cyber Risk Scenarios, the Financial System, and Systemic Risk Assessment.” Carnegie Endowment for International Peace, September 2019. Accessed 11 Jan 2022.

      Koehler, Thomas R. Understanding Cyber Risk. Routledge, 2018.

      Owens, Brian. “Cybersecurity for the travelling scientist.” Nature, vol. 548, 3 Aug 2017. Accessed 19 Jan. 2022.

      Parsons, Fintan J., et al. “Cybersecurity risks and recommendations for international travellers.” Journal of Travel Medicine, vol. 1, no. 4, 2021. Accessed 19 Jan 2022.

      Quinn, Stephen, et al. “Identifying and estimating cybersecurity risk for enterprise risk management.” National Institute of Standards and Technology (NIST), Interagency or Internal Report (IR) 8286A, Nov. 2021.

      Quinn, Stephen, et al. “Prioritizing cybersecurity risk for enterprise risk management.” NIST, IR 8286B, Sept. 2021.

      “Remaining cyber safe while travelling security recommendations.” Government of Canada, 27 April 2022. Accessed 31 Jan 2022.

      Stine, Kevin, et al. “Integrating cybersecurity and enterprise risk management.” NIST, IR 8286, Oct. 2020.

      Tammineedi, Rama. “Integrating KRIs and KPIs for effective technology risk management.” ISACA Journal, vol. 4, 1 July 2018.

      Tikk, Eneken, and Mika Kerttunen, editors. Routledge Handbook of International Cybersecurity. Routledge, 2020.

      Voo, Julia, et al. “National Cyber Power Index 2020.” Belfer Center for Science and International Affairs, Harvard Kennedy School, Sept. 2020. Web.

      Zhang, Fang. “Navigating cybersecurity risks in international trade.” Harvard Business Review, Dec 2021. Accessed 31 Jan 22.

      Appendix

      Insider Threat

      Key Risk Scenario

      Likelihood: Medium to High

      Impact: High

      Gap Controls

      The image contains a picture of the Gap Controls. The controls include: Policy and Awareness, Identification, Monitoring and Visibility, which leads to Cooperation.

      • Identification: Effective and efficient management of insider threats begins with a threat and risk assessment to establish which assets and which employees to consider, especially in jurisdictions associated with sensitive or critical data. You need to pay extra attention to employees who are working in satellite offices in jurisdictions with loose security and privacy laws.
      • Monitoring and Visibility: Organizations should monitor critical assets and groups with privileged access to defend against malicious behavior. Implement an insider threat management platform that provides your organization with the visibility and context into data movement, especially cross-border transfers that might cause security and privacy breaches.
      • Policy and Awareness Training: Insider threats will persist without appropriate action and culture change. Training and consistent communication of best practices will mitigate vulnerabilities to accidental or negligent attacks. Customized training materials using local languages and role-based case studies might be needed for employees in high-risk jurisdictions.
      • Cooperation: An effective insider threat management program should be built with cross-team functions such as Security, IT, Compliance and Legal, etc.

      For more holistic approach, you can leverage our Reduce and Manage Your Organization’s Insider Threat Risk blueprint.

      Info-Tech Insight

      You can’t just throw tools at a human problem. While organizations should monitor critical assets and groups with privileged access to defend against malicious behavior, good management and supervision can help detect attacks and prevent them from happening in the first place.

      Insider threats are not industry specific, but malicious insiders are

      Industry

      Actors

      Risks

      Tactics

      Motives

      State and Local Government

      • Full-time employees
      • Current employees
      • Privileged access to personally identifiable information, financial assets, and physical property
      • Abuse of privileged access
      • Received or transferred fraudulent funds
      • Financial gain
      • Recognition
      • Benefiting foreign entity

      Information Technology

      • Equal mix of former and current employees
      • Privileged access to networks or systems as well as data
      • Highly technical attacks
      • Received or transferred fraudulent funds
      • Revenge
      • Financial gain

      Healthcare

      • Majority were full-time and current employees
      • Privileged access to customer data with personally identifiable information, financial assets
      • Abuse of privileged access
      • Received or transferred fraudulent funds
      • Financial gain
      • Entitlement

      Finance and Insurance

      • Majority were full-time and current employees
      • Authorized users
      • Electronic financial assets
      • Privileged access to customer data
      • Created or used fraudulent accounts
      • Fraudulent purchases
      • Identity theft
      • Financial gain
      • Gambling addiction
      • Family pressures
      • Multiple motivations

      Source: Carnegie Mellon University Software Engineering Institute, 2019

      Advanced Persistent Threat

      Key Risk Scenario #4

      Likelihood: Medium to High

      Impact: High

      Gap Controls

      The image contains a screenshot of the Gap Controls listed: Prevent, Detect, Analyze, Respond.

      Prevent: Defense in depth is the best approach to protect against unknown and unpredictable attacks. Effective anti-malware, diligent patching and vulnerability management, and strong human-centric security are essential.

      Detect: There are two types of companies – those who have been breached and know it, and those who have been breached and don’t know it. Ensure that monitoring, logging, and event detection tools are in place and appropriate to your organizational needs.

      Analyze: Raw data without interpretation cannot improve security and is a waste of time, money, and effort. Establish a tiered operational process that not only enriches data but also provides visibility into your threat landscape.

      Respond: Organizations can’t rely on ad hoc response anymore – don’t wait until a state of panic. Formalize your response processes in a detailed incident runbook to reduce incident remediation time and effort.

      Best practices moving forward

      Defense in Depth

      Lock down your organization. Among other tactics, control administrative privileges, leverage threat intelligence, use IP whitelisting, adopt endpoint protection and two-factor authentication, and formalize incident response measures.

      Block Indicators

      Information alone is not actionable. A successful threat intelligence program contextualizes threat data, aligns intelligence with business objectives, and then builds processes to satisfy those objectives. Actively block indicators and act upon gathered intelligence.

      Drive Adoption

      Create organizational situational awareness around security initiatives to drive adoption of foundational security measures: network hardening, threat intelligence, red-teaming exercises, and zero-day mitigation, policies, and procedures.

      Supply Chain Security

      Security extends beyond your organization. Ensure your organization has a comprehensive view of your organizational threat landscape and a clear understanding of the security posture of any managed service providers in your supply chain.

      Awareness and Training

      Conduct security awareness and training. Teach end users how to recognize current cyberattacks before they fall victim – this is a mandatory first line of defense.

      Additional Resources

      Follow only official sources of information to help you assess risk

      The image contains an image highlighting a few additional resources.

      As misinformation is a major attack vector for malicious actors, follow only reliable sources for cyberalerts and actionable intelligence. Aggregate information from these reliable sources.

      Federal Cyber Agency Alerts

      Informational Resources

      Info-Tech Insight

      The CISA Shields Up site provides the latest cyber risk updates on the Russia-Ukraine conflict and should provide the most value in staying informed.

      Improve IT-Business Alignment Through an Internal SLA

      • Buy Link or Shortcode: {j2store}455|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Operations Management
      • Parent Category Link: /i-and-o-process-management
      • The business is rarely satisfied with IT service levels, yet there is no clear definition of what is acceptable.
      • Dissatisfaction with service levels is often based on perception. Your uptime might be four 9s, but the business only remembers the outages.
      • IT is left trying to hit a moving target with a limited budget and no agreement on where services levels need to improve.

      Our Advice

      Critical Insight

      • Business leaders have service level expectations regardless of whether there is a formal agreement. The SLA process enables IT to manage those expectations.
      • Track current service levels and report them in plain language (e.g. hours and minutes of downtime, not “how many 9s” which then need to be translated) to gain a clearer mutual understanding of current versus desired service levels.
      • Use past incidents to provide context (how much that hour of downtime actually impacted the business) in addition to a business impact analysis to define appropriate target service levels based on actual business need.

      Impact and Result

      Create an effective internal SLA by following a structured process to report current service levels and set realistic expectations with the business. This includes:

      • Defining the current achievable service level by establishing a metrics tracking and monitoring process.
      • Determining appropriate (not ideal) business needs.
      • Creating an SLA that clarifies expectations to reduce IT-business friction.

      Improve IT-Business Alignment Through an Internal SLA Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should create an internal SLA, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Scope the pilot project

      Establish the SLA pilot project and clearly document the problems and challenges that it will address.

      • Improve IT-Business Alignment Through an Internal SLA – Phase 1: Scope the Pilot Project
      • Internal SLA Process Flowcharts (PDF)
      • Internal SLA Process Flowcharts (Visio)
      • Build an Internal SLA Project Charter Template
      • Internal SLA Maturity Scorecard Tool

      2. Establish current service levels

      Expedite the SLA process by thoroughly, carefully, and clearly defining the current achievable service levels.

      • Improve IT-Business Alignment Through an Internal SLA – Phase 2: Determine Current Service Levels
      • Availability and Reliability SLA Metrics Tracking Template
      • Service Desk SLA Metrics Tracking Template
      • Service Catalog SLA Metrics Tracking Template

      3. Identify target service levels and create the SLA

      Create a living document that aligns business needs with IT targets by discovering the impact of your current service level offerings through a conversation with business peers.

      • Improve IT-Business Alignment Through an Internal SLA – Phase 3: Set Target Service Levels and Create the SLA
      • SLA Project Roadmap Tool
      • Availability Internal Service Level Agreement Template
      • Service Catalog Internal Service Level Agreement Template
      • Service Desk Internal Service Level Agreement Template
      • Internal SLA Executive Summary Presentation Template
      [infographic]

      Threat Preparedness Using MITRE ATT&CK®

      • Buy Link or Shortcode: {j2store}252|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Security Strategy & Budgeting
      • Parent Category Link: /security-strategy-and-budgeting
      • To effectively protect your business interests, you need to be able to address what the most pressing vulnerabilities in your network are. Which attack vectors should you model first? How do you adequately understand your threat vectors when attacks continually change and adapt?
      • Security can often be asked the world but given a minimal budget with which to accomplish it.
      • Security decisions are always under pressure from varying demands that pull even the most well-balanced security team in every direction.
      • Adequately modeling any and every possible scenario is ineffective and haphazard at best. Hoping that you have chosen the most pressing attack vectors to model will not work in the modern day of threat tactics.

      Our Advice

      Critical Insight

      • Precision is critical to being able to successfully defend against threats.
        • Traditional threat modeling such as STRIDE or PASTA is based on a spray-and-pray approach to identifying your next potential threat vector. Instead, take a structured risk-based approach to understanding both an attacker’s tactics and how they may be used against your enterprise. Threat preparedness requires precision, not guesswork.
      • Knowing is half the battle.
        • You may be doing better than you think. Undoubtedly, there is a large surface area to cover with threat modeling. By preparing beforehand, you can separate what’s important from what’s not and identify which attack vectors are the most pressing for your business.
      • Be realistic and measured.
        • Do not try to remediate everything. Some attack vectors and approaches are nearly impossible to account for. Take control of the areas that have reasonable mitigation methods and act on those.
      • Identify blind spots.
        • Understand what is out there and how other enterprises are being attacked and breached. See how you stack up to the myriad of attack tactics that have been used in real-life breaches and how prepared you are. Know what you’re ready for and what you’re not ready for.
      • Analyze the most pressing vectors.
        • Prioritize the attack vectors that are relevant to you. If an attack vector is an area of concern for your business, start there. Do not cover the entire tactics list if certain areas are not relevant.
      • Detection and mitigation lead to better remediation.
        • For each relevant tactic and techniques, there are actionable detection and mitigation methods to add to your list of remediation efforts.

      Impact and Result

      Using the MITRE ATT&CK® framework, Info-Tech’s approach helps you understand your preparedness and effective detection and mitigation actions.

      • Learn about potential attack vectors and the techniques that hostile actors will use to breach and maintain a presence on your network.
      • Analyze your current protocols versus the impact of an attack technique on your network.
      • Discover detection and mitigation actions.
      • Create a prioritized series of security considerations, with basic actionable remediation items. Plan your next threat model by knowing what you’re vulnerable to.
      • Ensure business data cannot be leaked or stolen.
      • Maintain privacy of data and other information.
      • Secure the network connection points.
      • Mitigate risks with the appropriate services.

      This blueprint and associated tool are scalable for all types of organizations within various industry sectors, allowing them to know what types of risk they are facing and what security services are recommended to mitigate those risks.

      Threat Preparedness Using MITRE ATT&CK® Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why threat preparedness is a crucial first step in defending your network against any attack type. Review Info-Tech’s methodology and understand the ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Attack tactics and techniques

      Review a breakdown of each of the various attack vectors and their techniques for additional context and insight into the most prevalent attack tactics.

      • Threat Preparedness Using MITRE ATT&CK® – Phase 1: Attack Tactics and Techniques

      2. Threat Preparedness Workbook mapping

      Map your current security protocols against the impacts of various techniques on your network to determine your risk preparedness.

      • Threat Preparedness Using MITRE ATT&CK® – Phase 2: Threat Preparedness Workbook Mapping
      • Enterprise Threat Preparedness Workbook

      3. Execute remediation and detective measures

      Use your prioritized attack vectors to plan your next threat modeling session with confidence that the most pressing security concerns are being addressed with substantive remediation actions.

      • Threat Preparedness Using MITRE ATT&CK® – Phase 3: Execute Remediation and Detective Measures
      [infographic]

      Exploit Disruptive Infrastructure Technology

      • Buy Link or Shortcode: {j2store}298|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Disruptive & Emerging Technologies
      • Parent Category Link: /disruptive-emerging-technologies
      • New technology can hit like a meteor. Not only disruptive to IT, technology provides opportunities for organization-wide advantage.
      • Your role is endangered. If you don’t prepare for the most disruptive technologies, you could be overshadowed. Don’t let the Chief Marketing Officer (CMO) set the technological innovation agenda
      • Predicting the future isn’t easy. Most IT leaders fail to realize how quickly technology increases in capability. Even for the tech savvy, predicting which specific technologies will become disruptive is difficult.
      • Communication is difficult when the sky is falling. Even forward-looking IT leaders struggle with convincing others to devote time and resources to monitoring technologies with a formal process.

      Our Advice

      Critical Insight

      • Establish the core working group, select a leader, and select a group of visionaries to help brainstorm emerging technologies.
      • Brainstorm about creating a better future, begin brainstorming an initial longlist.
      • Train the group to think like futurists.
      • Evaluate the shortlist.
      • Define your PoC list and schedule.
      • Finalize, present the plan to stakeholders and repeat.

      Impact and Result

      • Create a disruptive technology working group.
      • Produce a longlist of disruptive technologies.
      • Evaluate the longlist to produce a shortlist of disruptive technologies.
      • Develop a plan for a proof-of-concept project for each shortlisted technology.

      Exploit Disruptive Infrastructure Technology Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Exploit Disruptive Infrastructure Technology – A guide to help IT leaders make the most of disruptive impacts.

      As a CIO, there is a need to move beyond day-to-day technology management with an ever-increasing need to forecast technology impacts. Not just from a technical perspective but to map out the technical understandings aligned to potential business impacts and improvements. Technology transformation and innovation is moving more quickly than ever before and as an innovation champion, the CIO or CTO should have foresight in specific technologies with the understanding of how the company could be disrupted in the near future.

      • Exploit Disruptive Infrastructure Technology – Phases 1-3

      2. Disruptive Technology Exploitation Plan Template – A guide to develop the plan for exploiting disruptive technology.

      The Disruptive Technology Exploitation Plan Template acts as an implementation plan for developing a long-term strategy for monitoring and implementing disruptive technologies.

      • Disruptive Technology Exploitation Plan Template

      3. Disruptive Technology Look to the Past Tool – A tool to keep track of the missed technology disruption from previous opportunities.

      The Disruptive Technology Look to the Past Tool will assist you to collect reasonability test notes when evaluating potential disruptive technologies.

      • Disruptive Technology Look to the Past Tool

      4. Disruptive Technology Research Database Tool – A tool to keep track of the research conducted by members of the working group.

      The Disruptive Technology Research Database Tool will help you to keep track of the independent research that is conducted by members of the disruptive technology exploitation working group.

      • Disruptive Technology Research Database Tool

      5. Disruptive Technology Shortlisting Tool

      The Disruptive Technology Shortlisting Tool will help you to codify the results of the disruptive technology working group's longlist winnowing process.

      • Disruptive Technology Shortlisting Tool

      6. Disruptive Technology Value-Readiness and SWOT Analysis Tool – A tool to systematize notional evaluations of the value and readiness of potential disruptive technologies.

      The Disruptive Technology Value Readiness & SWOT Analysis Tool will assist you to systematize notional evaluations of the value and readiness of potential disruptive technologies.

      • Disruptive Technology Value-Readiness and SWOT Analysis Tool

      7. Proof of Concept Template – A handbook to serve as a reference when deciding how to proceed with your proposed solution.

      The Proof of Concept Template will guide you through the creation of a minimum-viable proof-of-concept project.

      • Proof of Concept Template

      8. Disruptive Technology Executive Presentation Template – A template to help you create a brief progress report presentation summarizing your project and program progress.

      The Disruptive Technology Executive Presentation Template will assist you to present an overview of the disruptive technology process, outlining the value to your company.

      • Disruptive Technology Executive Presentation Template

      Infographic

      Workshop: Exploit Disruptive Infrastructure Technology

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Pre-work: Establish the Disruptive Tech Process

      The Purpose

      Discuss the general overview of the disruptive technology exploitation process.

      Develop an initial disruptive technology exploitation plan.

      Key Benefits Achieved

      Stakeholders are on board, the project’s goals are outlined, and the working group is selected.

      Activities

      1.1 Get execs and stakeholders on board.

      1.2 Review the process of analyzing disruptive tech.

      1.3 Select members for the working group.

      1.4 Choose a schedule and time commitment.

      1.5 Select a group of visionaries.

      Outputs

      Initialized disruptive tech exploitation plan

      Meeting agenda, schedule, and participants

      2 Hold the Initial Meeting

      The Purpose

      Understand how disruption will affect the organization, and develop an initial list of technologies to explore.

      Key Benefits Achieved

      Knowledge of how to think like a futurist.

      Understanding of organizational processes vulnerable to disruption.

      Outline of potentially disruptive technologies.

      Activities

      2.1 Start the meeting with introductions.

      2.2 Train the group to think like futurists.

      2.3 Brainstorm about disruptive processes.

      2.4 Brainstorm a longlist.

      2.5 Research and brainstorm separate longlists.

      Outputs

      List of disruptive organizational processes

      Initial longlist of disruptive tech

      3 Create a Longlist and Assess Shortlist

      The Purpose

      Evaluate the specific value of longlisted technologies to the organization.

      Key Benefits Achieved

      Defined list of the disruptive technologies worth escalating to the proof of concept stage.

      Activities

      3.1 Converge the longlists developed by the team.

      3.2 Narrow the longlist to a shortlist.

      3.3 Assess readiness and value.

      3.4 Perform a SWOT analysis.

      Outputs

      Finalized longlist of disruptive tech

      Shortlist of disruptive tech

      Value-readiness analysis

      SWOT analysis

      Candidate(s) for proof of concept charter

      4 Create an Action Plan

      The Purpose

      Understand how the technologies in question will impact the organization.

      Key Benefits Achieved

      Understanding of the specific effects of the new technology on the business processes it is intended to disrupt.

      Business case for the proof-of-concept project.

      Activities

      4.1 Build a problem canvas.

      4.2 Identify affected business units.

      4.3 Outline and map the business processes likely to be disrupted.

      4.4 Map disrupted business processes.

      4.5 Recognize how the new technology will impact business processes.

      4.6 Make the case.

      Outputs

      Problem canvas

      Map of business processes: current state

      Map of disrupted business processes

      Business case for each technology

      Further reading

      Analyst Perspective

      The key is in anticipation.

      “We all encounter unexpected changes and our responses are often determined by how we perceive and understand those changes. We react according to the unexpected occurrence. Business organizations are no different.

      When a company faces a major technology disruption in its markets – one that could fundamentally change the business or impact its processes and technology – the way its management perceive and understand the disruption influences how they describe and plan for it. In other words, the way management sets the context of a disruption – the way they frame it – shapes the strategy they adopt. Technology leaders can vastly influence business strategy by adopting a proactive approach to understanding disruptive and innovative technologies by simply adopting a process to review and evaluate technology impacts to the company’s lines of business.”

      This is a picture of Troy Cheeseman

      Troy Cheeseman
      Practice Lead, Infrastructure & Operations Research
      Info-Tech Research Group

      Executive Summary

      Your Challenge

      • New technology can hit like a meteor. Not only disruptive to IT, technology provides opportunities for organization-wide advantage.
      • Your role is endangered. If you don’t prepare for the most disruptive technologies, you could be overshadowed. Don’t let the chief marketing officer (CMO) set the technological innovation agenda.

      Common Obstacles

      • Predicting the future isn’t easy. Most IT leaders fail to realize how quickly technology increases in capability. Even for the tech savvy, predicting which specific technologies will become disruptive is difficult.
      • Communication is difficult when the sky is falling. Even forward-looking IT leaders struggle with convincing others to devote time and resources to monitoring technologies with a formal process.

      Info-Tech’s Approach

      • Identify, resolve, and evaluate. Use an annual process as described in this blueprint: a formal evaluation of new technology that turns analysis into action.
      • Lead the analysis from IT. Establish a team to carry out the annual process as a cure for the causes of “airline magazine syndrome” and to prevent it from happening in the future.
      • Train your team on the patterns of progress, track technology over time in a central database, and read Info-Tech’s analysis of upcoming technology.
      • Create your KPIs. Establish your success indicators to create measurable value when presenting to your executive.
      • Produce a comprehensive proof-of-concept plan that will allow your company to minimize risk and maximize reward when engaging with new technology.

      Info-Tech Insight

      Proactively monitoring, evaluating, and exploiting disruptive tech isn’t optional.
      This will protect your role, IT’s role, and the future of the organization.

      A diverse working group maximizes the insight brought to bear.
      An IT background is not a prerequisite.

      The best technology is only the best when it brings immediate value.
      Good technology might not be ready; ready technology might not be good.

      Review

      We help IT leaders make the most of disruptive impacts.

      This research is designed for:

      Target Audience: CIO, CTO, Head of Infrastructure

      This research will help you:

      • Develop a process for anticipating, analyzing, and exploiting disruptive technology.
      • Communicate the business case for investing in disruptive technology.
      • Categorize emerging technologies to decide what to do with them.
      • Develop a plan for taking action to exploit the technology that will most affect your organization.

      Problem statement:

      As a CIO, there is a need to move beyond day-to-day technology management with an ever-increasing need to forecast technology impacts. Not just from a technical perspective but to map out the technical understandings aligned to potential business impacts and improvements. Technology transformation and innovation is moving more quickly than ever before and as an innovation champion, the CIO or CTO should have foresight in specific technologies with the understanding of how the company could be disrupted in the near future. Foresight + Current Technology + Business Understanding = Understanding the Business Disruption. This should be a repeatable process, not an exception or reactionary response.

      Insight Summary

      Establish the core working group, select a leader, and select a group of visionaries to help brainstorm emerging technologies.

      The right team matters. A core working group will keep focus through the process and a leader will keep everyone accountable. Visionaries are out-of-the-box thinkers and once they understand how to think like a "futurists," they will drive the longlist and shortlist actions.

      Train the group to think like futurists

      To keep up with exponential technology growth you need to take a multi-threaded approach.

      Brainstorm about creating a better future; begin brainstorming an initial longlist

      Establish the longlist. The longlist helps create a holistic view of most technologies that could impact the business. Assigning values and quadrant scoring will shortlist the options and focus your PoC option.

      Converge everyone’s longlists

      Long to short...that's the short of it. Using SWOT, value readiness, and quadrant mapping review sessions will focus the longlist, creating a shortlist of potential POC candidates to review and consider.

      Evaluate the shortlist

      There is no such thing as a risk-free endeavor. Use a systematic process to ensure that the risks your organization takes have the potential to produce significant rewards.

      Define your PoC list and schedule

      Don’t be afraid to fail! Inevitably, some proof-of-concept projects will not benefit the organization. The projects that are successful will more than cover the costs of the failed projects. Roll out small scale and minimize losses.

      Finalize, present the plan to stakeholders, and repeat!

      Don't forget the C-suite. Effectively communicate and present the working group’s finding with a well-defined and succinct presentation. Start the process again!

      This is a screenshot of the Thought map for Exploit disruptive infrastructure Technology.
      1. Identify
        • Establish the core working group and select a leader; select a group of visionaries
        • Train the group to think like futurists
        • Hold your initial meeting
      2. Resolve
      • Create and winnow a longlist
      • Assess and create the shortlist
    • Evaluate
      • Create process maps
      • Develop proof of concept charter
    • The Key Is in Anticipation!

      Use Info-Tech’s approach for analyzing disruptive technology in your own disruptive tech working group

      Phase 1: Identify Phase 2: Resolve Phase 3: Evaluate

      Phase Steps

      1. Establish the disruptive technology working group
      2. Think like a futurist (Training)
      3. Hold initial meeting or create an agenda for the meeting
      1. Create and winnow a longlist
      2. Assess shortlist
      1. Create process maps
      2. Develop proof of concept charter

      Phase Outcomes

      • Establish a team of subject matter experts that will evaluate new, emerging, and potentially disruptive technologies.
      • Establish a process for including visionaries from outside of the working group who will provide insight and direction.
      • Introduce the core working group members.
      • Gain a better understanding of how technology advances.
      • Brainstorm a list of organizational processes.
      • Brainstorm an initial longlist.
      • Finalized longlist
      • Finalized shortlist
      • Initial analysis of each technology on the shortlist
      • Finalized shortlist
      • Initial analysis of each technology on the shortlist
      • Business process maps before and after disruption
      • Proof of concept charter
      • Key performance indicators
      • Estimation of required resources
      • Executive presentation

      Four key challenges make it essential for you to become a champion for exploiting disruptive technology

      1. New technology can hit like a meteor. It doesn’t only disrupt IT; technology provides opportunities for organization-wide advantage.
      2. Your role is endangered. If you don’t prepare for the most disruptive technologies, you could be overshadowed. Don’t let the CMO rule technological innovation.
      3. Predicting the future isn’t easy. Most IT leaders fail to realize how quickly technology increases in capability. Even for the tech savvy, predicting which specific technologies will become disruptive is difficult.
      4. Communication is difficult when the sky is falling. Even forward-looking IT leaders struggle with convincing others to devote time and resources to monitoring emerging technologies with a formal process.

      “Look, you have never had this amount of opportunity for innovation. Don’t forget to capitalize on it. If you do not capitalize on it, you will go the way of the dinosaur.”
      – Dave Evans, Co-Founder and CTO, Stringify

      Technology can hit like a meteor

      “ By 2025:

      • 38.6 billion smart devices will be collecting, analyzing, and sharing data.
      • The web hosting services market is to reach $77.8 billion in 2025.
      • 70% of all tech spending is expected to go for cloud solutions.
      • There are 1.35 million tech startups.
      • Global AI market is expected to reach $89.8 billion.”

      – Nick Gabov

      IT Disruption

      Technology disrupts IT by:

      • Affecting the infrastructure and applications that IT needs to use internally.
      • Affecting the technology of end users that IT needs to support and deploy, especially for technologies with a consumer focus.
      • Allowing IT to run more efficiently and to increase the efficiency of other business units.
      • Example: The rise of the smartphone required many organizations to rethink endpoint devices.

      Business Disruption

      Technology disrupts the business by:

      • Affecting the viability of the business.
      • Affecting the business’ standing in relation to competitors that better deal with disruptive technology.
      • Affecting efficiency and business strategy. IT should have a role in technology-related business decisions.
      • Example: BlackBerry failed to anticipate the rise of the apps ecosystem. The company struggled as it was unable to react with competitive products.

      Senior IT leaders are expected to predict disruptions to IT and the business, while tending to today’s needs

      You are expected to be both a firefighter and a forecaster

      • Anticipating upcoming disruptions is part of your job, and you will be blamed if you fail to anticipate future business disruptions because you are focusing on the present.
      • However, keeping IT running smoothly is also part of your job, and you will be blamed if today’s IT environment breaks down because you are focusing on the future.

      You’re caught between the present and the future

      • You don’t have a process that anticipates future disruptions but runs alongside and integrates with operations in the present.
      • You can’t do it alone. Tending to both the present and the future will require a team that can help you keep the process running.

      Info-Tech Insight

      Be prepared when disruptions start coming down, even though it isn’t easy. Use this research to reduce the effort to a simple process that can be performed alongside everyday firefighting.

      Make disruptive tech analysis and exploitation part of your innovation agenda

      A scatter plot graph is depicted, plotting IT Innovative Leadership (X axis), and Satisfaction with IT(Y axis). IT innovative leadership explains 75% of variation in satisfaction with IT

      Organizations without high satisfaction with IT innovation leadership are only 20% likely to be highly satisfied with IT

      “You rarely see a real-world correlation of .86!”
      – Mike Battista, Staff Scientist, Cambridge Brain Sciences, PhD in Measurement

      There is a clear relationship between satisfaction with IT and the IT department’s innovation leadership.

      Prevent “airline magazine syndrome” by proactively analyzing disruptive technologies

      “The last thing the CIO needs is an executive saying ‘I don’t what it is or what it does…but I want two of them!”
      – Tim Lalonde

      Airline magazine syndrome happens to IT leaders caught between the business and IT. It usually occurs in this manner:

      1. While on a flight, a senior executive reads about an emerging technology that has exciting implications for the business in an airline magazine.
      2. The executive returns and approaches IT, demanding that action be taken to address the disruptive technology – and that it should have been (ideally) completed already.

      Without a Disruptive Technology Exploitation Plan:

      “I don’t know”

      With a Disruptive Technology Exploitation Plan:

      “Here in IT, we have already considered that technology and decided it was overhyped. Let me show you our analysis and invite you to join our working group.”

      OR

      “We have already considered that technology and have started testing it. Let me show you our testing lab and invite you to join our working group.”

      Info-Tech Insight

      Airline magazine syndrome is a symptom of a wider problem: poor CEO-CIO alignment. Solve this problem with improved communication and documentation. Info-Tech’s disruptive tech iterative process will make airline magazine syndrome a thing of the past!

      IT leaders who do not keep up with disruptive technology will find their roles diminished

      “Today’s CIO dominion is in a decaying orbit with CIOs in existential threat mode.”
      – Ken Magee

      Protect your role within IT

      • IT is threatened by disruptive technology:
        • Trends like cloud services, increased automation, and consumerization reduce the need for IT to be involved in every aspect of deploying and using technology.
        • In the long term, machines will replace even intellectually demanding IT jobs, such as infrastructure admin and high-level planning.
      • Protect your role in IT by:
        • Anticipating new technology that will disrupt the IT department and your place within it.
        • Defining new IT roles and responsibilities that accurately reflect the reality of technology today.
        • Having a process for the above that does not diminish your ability to keep up with everyday operations that remain a priority today.

      Protect your role against other departments

      • Your role in the business is threatened by disruptive technology:
        • The trends that make IT less involved with technology allow other executives – such as the CMO – to make IT investments.
        • As the CMO gains the power and data necessary to embrace new trends, the CIO and IT managers have less pull.
      • Protect your role in the business by:
        • Being the individual to consult about new technology. It isn’t just a power play; IT leaders should be the ones who know technology thoroughly.
        • Becoming an indispensable part of the entire business’ innovation strategy through proposing and executing a process for exploiting disruptive technology.

      IT leaders who do keep up have an opportunity to solidify their roles as experts and aggregators

      “The IT department plays a critical role in [innovation]. What they can do is identify a technology that potentially might introduce improvements to the organization, whether it be through efficiency, or through additional services to constituents.”
      – Michael Maguire, Management Consultant

      The contemporary CIO is a conductor, ensuring that IT works in harmony with the rest of the business.

      The new CIO is a conductor, not a musician. The CIO is taking on the role of a business engineer, working with other executives to enable business innovation.

      The new CIO is an expert and an aggregator. Conductor CIOs increasingly need to keep up on the latest technologies. They will rely on experts in each area and provide strategic synthesis to decide if, and how, developments are relevant in order to tune their IT infrastructure.

      The pace of technological advances makes progress difficult to predict

      “An analysis of the history of technology shows that technological change is exponential, contrary to the common-sense ‘intuitive linear’ view. So we won’t experience 100 years of progress in the 21st century – it will be more like 20,000 years of progress (at today’s rate).”
      – Ray Kurzweil

      Technology advances exponentially. Rather than improving by the same amount of capability each year, it multiplies in capability each year.

      Think like a futurist to anticipate technology before it goes mainstream.

      Exponential growth happens much faster than linear growth, especially when it hits the knee of the curve. Even those who acknowledge exponential growth underestimate how capabilities can improve.

      To predict new advances, turn innovation into a process

      “We spend 70 percent of our time on core search and ads. We spend 20 percent on adjacent businesses, ones related to the core businesses in some interesting way. Examples of that would be Google News, Google Earth, and Google Local. And then 10 percent of our time should be on things that are truly new.”
      – Eric Schmidt, Google

      • Don’t get caught in the trap of refining your core processes to the exclusion of innovation. You should always be looking for new processes to improve, new technology to pilot, and where possible, new businesses to get into.
      • Devote about 10% of your time and resources to exploring new technology: the potential rewards are huge.

      You and your team need to analyze technology every year to predict where it’s going.

      A bar graph is shown which depicts the proportion of technology use from 2018-2022. the included devices are: Tablets; PCs; TVs; Non-smartphones; Smartphones; M2M
      • Foundational technologies, such as computing power, storage, and networks, are improving exponentially.
      • Disruptive technologies are specific manifestations of foundational advancements. Advancements of greater magnitude give rise to more manifestations; therefore, there will be more disruptive technologies every year.
      • There is a lot of noise to cut through. Remember Google Glasses? As technology becomes ubiquitous and consumerization reigns, everybody is a technology expert. How do you decide which technologies to focus on?

      Protect IT and the business from disruption by implementing a simple, repeatable disruptive technology exploitation process

      “One of the most consistent patterns in business is the failure of leading companies to stay at the top of their industries when technologies or markets change […] Managers must beware of ignoring new technologies that can’t initially meet the needs of their mainstream customers.”
      – Joseph L. Bower and Clayton M. Christensen

      Challenge

      Solution

      New technology can hit like a meteor, but it doesn’t have to leave a crater:

      Use the annual process described in this blueprint to create a formal evaluation of new technology that turns analysis into action.

      Predicting the future isn’t easy, but it can be done:

      Lead the analysis from the office of the CIO. Establish a team to carry out the annual process as a cure for airline magazine syndrome.

      Your role is endangered, but you can survive:

      Train your team on the patterns of progress, track technology over time in a central database, and read Info-Tech’s analysis of upcoming technology.

      Communication is difficult when the sky is falling, so have a simple way to get the message across:

      Track metrics that communicate your progress, and summarize the results in a single, easy-to-read exploitation plan.

      Info-Tech Insight

      Use Info-Tech’s tools and templates, along with this storyboard, to walk you through creating and executing an exploitation process in six steps.

      Create measurable value by using Info-Tech’s process for evaluating the disruptive potential of technology

      This image contains a bar graph with the following Title: Which are the primary benefits you've either realized or expect to realize by deploying hyperconverged infrastructure in the near term.

      No business process is perfect.

      • Use Info-Tech’s Proof of Concept Template to create a disruptive technology proof of concept implementation plan.
      • Harness your company’s internal wisdom to systematically vet new technology. Engage only in calculated risk and maximize potential benefit.

      Info-Tech Insight

      Inevitably, some proof of concept projects will not benefit the organization. The projects that are successful will more than cover the costs of the failed projects. Roll out small scale and minimize losses.

      Establish your key performance indicators (KPIs)

      Key performance indicators allow for rigorous analysis, which generates insight into utilization by platform and consumption by business activity.

      • Brainstorm metrics that indicate when process improvement is actually taking place.
      • Have members of the group pitch KPIs; the facilitator should record each suggestion on a whiteboard.
      • Make sure to have everyone justify the inclusion of each metric: how does it relate to the improvement that the proof of concept project is intended to drive? How does it relate to the overall goals of the business?
      • Include a list of KPIs, along with a description and a target (ensuring that it aligns with SMART metrics).
      Key Performance Indicator Description Target Result

      Number of Longlist technologies

      Establish a range of Longlist technologies to evaluate 10-15
      Number of Shortlist technologies Establish a range of Shortlist technologies to evaluate 5-10
      number of "look to the past" likes/dislikes Minimum number of testing characteristics 6
      Number of POCs Total number of POCs Approved 3-5

      Communicate your plan with the Disruptive Technology Exploitation Plan Template

      Use the Disruptive Technology Exploitation Plan Template to summarize everything that the group does. Update the report continuously and use it to show others what is happening in the world of disruptive technology.

      Section Title Description
      1 Rationale and Summary of Exploitation Plan A summary of the current efforts that exist for exploring disruptive technology. A summary of the process for exploiting disruptive technology, the resources required, the team members, meeting schedules, and executive approval.
      2 Longlist of Potentially Disruptive Technologies A summary of the longlist of identified disruptive technologies that could affect the organization, shortened to six or less that have the largest potential impact based on Info-Tech’s Disruptive Technology Shortlisting Tool.
      3 Analysis of Shortlist Individually analyze each technology placed on the shortlist using Info-Tech’s Disruptive Technology Value-Readiness and SWOT Analysis Tool.
      4 Proof of Concept Plan Use the results from Section 3 to establish a plan for moving forward with the technologies on the shortlist. Determine the tasks required to implement the technologies and decide who will complete them and when.
      5 Hand-off Pass the project along to identified stakeholders with significant interest in its success. Continue to track metrics and prepare to repeat the disruptive technology exploitation process annually.

      Whether you need a process for exploiting disruptive technology, or an analysis of current trends, Info-Tech can help

      Two sets of research make up Info-Tech’s disruptive technology coverage:

      This image contains four screenshots from each of the following Info-Tech Blueprints: Exploit disruptive Infrastructure Technology; Infrastructure & operations priorities 2022

      This storyboard, and the associated tools and templates, will walk you through creating a disruptive technology working group of your own.

      Blueprint deliverables

      Each step of this blueprint is accompanied by supporting deliverables to help you accomplish your goals:

      Key deliverable:

      Disruptive Technology Exploitation Plan Template

      The Disruptive Technology Exploitation Plan Template acts as an implementation plan for developing a long-term strategy for monitoring and implementing disruptive technologies.

      Proof of Concept Template

      The Proof of Concept Template will guide you through the creation of a minimum-viable proof-of-concept project.

      Executive Presentation

      The Disruptive Technology Executive Presentation Template will assist you to present an overview of the disruptive technology process, outlining the value to your company.

      Disruptive Technology Value Readiness & SWOT Analysis Tool

      The Disruptive Technology Value Readiness & SWOT Analysis Tool will assist you to systematize notional evaluations of the value and readiness of potential disruptive technologies.

      Disruptive Technology Research Database Tool

      The Disruptive Technology Research Database Tool will help you to keep track of the independent research that is conducted by members of the disruptive technology exploitation working group.

      Disruptive Technology Shortlisting Tool

      The Disruptive Technology Shortlisting Tool will help you to codify the results of the disruptive technology working group's longlist winnowing process.

      Disruptive Technology Look to the Past Tool

      The Disruptive Technology Look to the Past Tool will assist you to collect reasonability test notes when evaluating potential disruptive technologies.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

      Guided Implementation

      “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

      Workshop

      “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

      Consulting

      “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

      Diagnostics and consistent frameworks used throughout all four options

      Guided Implementation

      What does a typical GI on this topic look like?

      Phase 1 Phase 2 Phase 3

      Call #1: Explore the need for a disruptive technology working group.

      Call #3: Review the agenda for the initial meeting.

      Call #5: Review how you’re brainstorming and your sources of information.

      Call #7: Review the final shortlist and assessment.

      Call #9: Review the progress of your team.

      Call #2: Review the team name, participants, and timeline.

      Call #4: Assess the results of the initial meeting.

      Call #6: Review the final longlist and begin narrowing it down.

      Call #8: Review the next steps.

      Call #10: Review the communication plan.

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

      A typical GI is 8 to 12 calls over the course of 4 to 6 months.

      Workshop Overview

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      Pre-Work Day 1 Day 2 Day 3 Day 4
      Establish the Disruptive Tech Process Hold Your Initial Meeting Create a Longlist and Assess Shortlist Create Process Maps Develop a Proof of Concept Charter

      Activities

      1.1.a Get executives and stakeholders on board.

      1.1.b Review the process of analyzing disruptive tech.

      1.1.c Select members for the working group.

      1.1.d Choose a schedule and time commitment.

      1.1.e Select a group of visionaries.

      1.2.a Start the meeting with introductions.

      1.2.b Train the group to think like futurists.

      1.2.c Brainstorm about disruptable processes.

      1.2.d Brainstorm a longlist.

      1.2.e Research and brainstorm separate longlists.

      2.1.a Converge the longlists developed by the team.

      2.2.b Narrow the longlist to a shortlist.

      2.2.c Assess readiness and value.

      2.2.d Perform a SWOT analysis.

      3.1.a Build a problem canvas.

      3.1.b Identify affected business units.

      3.1.c Outline and map the business processes likely to be disrupted.

      3.1.d Map disrupted business processes.

      3.1.e Recognize how the new technology will impact business processes.

      3.1.f Make the case.

      3.2.a Develop key performance indicators (KPIs).

      3.2.b Identify key success factors.

      3.2.c Outline project scope.

      3.2.d Identify responsible team.

      3.2.e Complete resource estimation.

      Deliverables

      1. Initialized Disruptive Tech Exploitation Plan
      1. List of Disruptable Organizational Processes
      2. Initial Longlist of Disruptive Tech
      1. Finalized Longlist of Disruptive Tech
      2. Shortlist of Disruptive Tech
      3. Value-Readiness Analysis
      4. SWOT Analysis
      5. Candidate(s) for Proof of Concept Charter
      1. Problem Canvas
      2. Map of Business Processes: Current State
      3. Map of Disrupted Business Processes
      4. Business Case for Each Technology
      1. Completed Proof of Concept Charter

      Exploit Disruptive Infrastructure Technology

      Disrupt or be disrupted.

      Identify

      Create your working group.

      PHASE 1

      Use Info-Tech’s approach for analyzing disruptive technology in your own disruptive tech working group

      1. Identify
        1. Establish the core working group and select a leader; select a group of visionaries
        2. Train the group to think like futurists
        3. Hold your initial meeting
      2. Resolve
        1. Create and winnow a longlist
        2. Assess and create the shortlist
      3. Evaluate
        1. Create process maps
        2. Develop proof of concept charter

      The Key Is in Anticipation!

      Phase 1: Identify

      Create your working group.

      Activities:

      Step 1.1: Establish the core working group and select a leader; select a group of visionaries
      Step 1.2: Train the group to think like futurists
      Step 1.3: Hold the initial meeting

      This step involves the following participants:

      IT Infrastructure Manager

      CIO or CTO

      Potential members and visionaries of the working group

      Outcomes of this step:

      • Establish a team of subject matter experts that will evaluate new, emerging, and potentially disruptive technologies.
      • Establish a process for including visionaries from outside of the working group who will provide insight and direction.
      • Introduce the core working group members.
      • Gain a better understanding of how technology advances.
      • Brainstorm a list of organizational processes.
      • Brainstorm an initial longlist.

      Step 1.1

      Establish the core working group and select a leader; select a group of visionaries.

      Activities:

      • Articulate the long- and short-term benefits and costs to the entire organization
      • Gain support by articulating the long- and short-term benefits and costs to the IT department
      • Gain commitment from key stakeholders and executives
      • Help stakeholders understand what goes into formally exploiting disruptive tech by reviewing this process
      • Establish the core working group and select a leader
      • Create a schedule with a time commitment appropriate to your organization’s size; it doesn’t need to take long
      • Select a group of visionaries external to IT to help the working group brainstorm disruptive technologies

      This step involves the following participants:

      • IT Infrastructure Manager
      • CIO or CTO
      • Potential members and visionaries of the working group

      Outcomes of this step

      • Establish a team of subject matter experts that will evaluate new, emerging, and potentially disruptive technologies.
      • Establish a process for including visionaries from outside of the working group that will provide insight and direction.

      1.1.A Articulate the long- and short-term benefits and costs to the entire organization

      A cost/benefit analysis will give stakeholders a picture of how disruptive technology could affect the business. Use the chart as a starting point and customize it based on your organization.

      Disruptive Technology Affects the Organization

      Benefits Costs

      Short Term

      • First-mover advantage from implementing new technology in the business before competitors – and before start-ups.
      • Better brand image as an organization focused on innovation.
      • Increased overall employee satisfaction by implementing new technology that increases employee capabilities or lowers effort.
      • Possibility of increased IT budget for integrating new technology.
      • Potential for employees to reject wide-scale use of unfamiliar technology.
      • Potential for technology to fail in the organization if it is not sufficiently tested.
      • Executive time required for making decisions about technology recommended by the team.

      Long Term

      • Increased internal business efficiencies from the integration of new technology (e.g. energy efficiency, fewer employees needed due to automation).
      • Better services or products for customers, resulting in increased long-term revenue.
      • Lowered costs of services or products and potential to grow market share.
      • Continued relevance of established organizations in a world changed by disruptive technologies.
      • Technology may not reach the capabilities initially expected, requiring waiting for increased value or readiness.
      • Potential for customers to reject new products resulting from technology.
      • Lack of focus on current core capabilities if technology is massively disruptive.

      1.1.B Gain support by articulating the long- and short-term benefits and costs to the IT department

      A cost/benefit analysis will give stakeholders a picture of how disruptive technology could affect the business. Use the chart as a starting point and customize it based on your organization.

      Disruptive Technology Affects IT

      BenefitsCosts

      Short Term

      • Perception of IT as a core component of business practices.
      • Increase IT’s capabilities to better serve employees (e.g. faster network speeds, better uptime, and storage and compute capacity that meet demands).
      • Cost for acquiring or implementing new technology and updating infrastructure to integrate with it.
      • Cost for training IT staff and end users on new IT technology and processes.
      • Minor costs for initial setup of disruptive technology exploitation process and time taken by members.

      Long Term

      • More efficient and powerful IT infrastructure that capitalizes on emerging trends at the right time.
      • Lower help desk load due to self-service and automation technology.
      • Increased satisfaction with IT due to implementation of improved enterprise technology and visible IT influence on improvements.
      • Increased end-user satisfaction with IT due to understanding and support of consumer technology that affects their lives.
      • New technology may result in lower need for specific IT roles. Cultural disruptions due to changing role of IT.
      • Perception of failure if technology is tested and never implemented.
      • Expectation that IT will continue to implement the newest technology available, even when it has been dismissed as not having value.

      1.1.C Gain commitment from key stakeholders and executives

      Gaining approval from executives and key stakeholders is the final obstacle. Ensure that you cover the following items to have the best chance for project approval.

      • Use a sample deck similar to this section for gaining buy-in, ensuring that you add/remove information to make it specific to your organization. Cover this section, including:
        • Who: Who will lead the team and who will be on it (working group)?
        • What: What resources will be required by the team (costs)?
        • Where/When: How often and where will the team meet (meeting schedule)?
        • Why: Why is there a need to exploit disruptive technology (benefits and examples)?
        • How: How is the team going to exploit disruptive technology (the process)?
      • Go through this blueprint prior to presenting the plan to stakeholders so that you have a strong understanding of the details behind each process and tool.
      • Frame the first iteration of the cycle as a pilot program. Use the completed results of the pilot to establish exploiting disruptive technology as a necessary company initiative.

      Insert the resources required by the disruptive tech exploitation team into Section 1.5 of the Disruptive Technology Exploitation Plan Template. Have executives sign-off on the project in Section 1.6.

      Disruption has undermined some of the most successful tech companies

      “The IT department plays a critical role in [innovation]. What they can do is identify a technology that potentially might introduce improvements to the organization, whether it be through efficiency or through additional services to constituents.”
      - Michael Maguire, Management Consultant

      VoIP’s transformative effects

      Disruptive technology:
      Voice over Internet Protocol (VoIP) is a modern means of making phone calls through the internet by sending voice packets using data, as opposed to the traditional circuit transmissions of the PSTN.

      Who won:
      Organizations that realized the cost savings that VoIP provided for businesses with a steady internet connection saved as much as 60% on telephony expenses. Even in the early stages, with a few more limitations, organizations were able to save a significant amount of money and the technology has continued to improve.

      Who lost?
      Telecom-related companies that failed to realize VoIP was a potential threat to their market, and organizations that lacked the ability to explore and implement the disruptive technology early.

      Digital photography — the new norm

      Disruptive technology:
      Digital photography refers to the storing of photographs in a digital format, as opposed to traditional photography, which exposes light to sensitive photographic film.

      Who won:
      Photography companies and new players that exploited the evolution of data storage and applied it to photography succeeded. Those that were able to balance providing traditional photography and exploiting and introducing digital photography, such as Nikon, left competitors behind. Smartphone manufacturers also benefited by integrating digital cameras.

      Who lost?
      Photography companies, such as Kodak, that failed to respond to the digital revolution found themselves outcompeted and insolvent.

      1.1.D Help stakeholders understand what goes into formally exploiting disruptive tech by reviewing this process

      There are five steps to formally exploiting disruptive technology, each with its own individual outputs and tools to take analysis to the next level.

      Step 1.2:
      Hold Initial Meeting

      Output:

      • Initial list of disruptable processes;
      • Initial longlist

      Step 2.1:

      Brainstorm Longlist

      Output:

      • Finalized longlist;
      • Shortlist

      Step 2.2:

      Assess Shortlist

      Output:

      • Final shortlist;
      • SWOT analysis;
      • Tech categorization

      Step 3.1:
      Create Process Maps

      Output:

      • Completed process maps

      Step 3.2:
      Develop a proof of concept charter

      Output:

      • Proof-of-concept template with KPIs

      Info-Tech Insight

      Before going to stakeholders, complete the entire blueprint to better understand the tools and outputs of the process.

      1.1.E Establish the core working group and select a leader

      • Selecting your core membership for the working group is a critical step to the group’s success. Ensure that you satisfy the following criteria:
        • This is a team of subject matter experts. They will be overseeing the learning and piloting of disruptive technologies. Their input will also be valuable for senior executives and for implementing these technologies.
        • Choose members that can take time away from firefighting tasks to dedicate time to meetings.
        • It may be necessary to reach outside of the organization now or in the future for expertise on certain technologies. Use Info-Tech as a source of information.
      Organization Size Working Group Size
      Small 02-Jan
      Medium 05-Mar
      Large 10-May
      • Once the team is established, you must decide who will lead the group. Ensure that you satisfy the following criteria:
        • A leader should be credible, creative, and savvy in both technology and business.
        • The leader should facilitate, acting as both an expert and an aggregator of the information gathered by the team.

      Choose a compelling name

      The working group needs a name. Be sure to select one with a positive connotation within your organization.

      Section 1.3 of the Disruptive Technology Exploitation Plan Template

      1.1.F Create a schedule with a time commitment appropriate to your organization’s size; it doesn’t need to take long

      Time the disruptive technology working group’s meetings to coincide and integrate with your organization’s strategic planning — at least annually.

      Size Meeting Frequency Time per Meeting Example Meeting Activities
      Small Annually One day A one-day meeting to run through phase 2 of the project (SWOT analysis and shortlist analysis).
      Medium Two days A two-day meeting to run through the project. The additional meeting involves phase 3 of this deck, developing a proof-of-concept plan.
      Large Two+ days Two meetings, each two days. Two days to create and winnow the longlist (phase 2), and two further days to develop a proof of concept plan.

      “Regardless of size, it’s incumbent upon every organization to have some familiarity of what’s happening over the next few years, [and to try] to anticipate what some of those trends may be. […] These trends are going to accelerate IT’s importance in terms of driving business strategy.”
      – Vern Brownell, CEO, D-Wave

      Section 1.4 of the Disruptive Technology Exploitation Plan Template

      1.1.G Select a group of visionaries external to IT to help the working group brainstorm disruptive technologies

      Selecting advisors for your group is an ongoing step, and the roster can change.

      Ensure that you satisfy the following criteria:

      • Look beyond IT to select a team representing several business units.
      • Check for self-professed “geeks” and fans of science fiction that may be happy to join.
      • Membership can be a reward for good performance.

      This group does not have to meet as regularly as the core working group. Input from external advisors can occur between meetings. You can also include them on every second or third iteration of the entire process.

      However, the more input you can get into the group, the more innovative it can become.

      “It is … important to develop design fictions based on engagement with directly or indirectly implicated publics and not to be designed by experts alone.”
      – Emmanuel Tsekleves, Senior Lecturer in Design Interactions, University of Lancaster

      Section 1.3 of the Disruptive Technology Exploitation Plan Template

      The following case study illustrates the innovative potential that is created when you include a diverse group of people

      INDUSTRY - Chip Manufacturing
      SOURCE - Clayton Christensen, Intel

      To achieve insight, you need to collaborate with people from outside of your department.

      Challenge

      • Headquartered in California, through the 1990s, Intel was the largest microprocessor chip manufacturer in the world, with revenue of $25 billion in 1997.
      • All was not perfect, however. Intel faced a challenge from Cyrix, a manufacturer of low-end chips. In 18 months, Cyrix’s share of the low-margin entry-level chip manufacturing business mushroomed from 10% to 70%.

      Solution

      • Troubled by the potential for significant disruption of the microprocessor market, Intel brought in external consultants to hold workshops to educate managers about disruptive innovation.
      • Managers would break into groups and discuss ways Intel could facilitate the disruption of its competitors. In one year, Intel hosted 18 workshops, and 2,000 managers went through the process.

      Results

      • Intel launched the Celeron chip to serve the lower end of the PC market and win market share back from Cyrix (which no longer exists as an independent company) and other competitors like AMD.
      • Within one year, Intel had captured 35% of the market.

      “[The models presented in the workshops] gave us a common language and a common way to frame the problem so that we could reach a consensus around a counterintuitive course of action.” – Andy Grove, then-CEO, Intel Corporation

      Phase 1: Identify

      Create your working group.

      Activities:

      Step 1.1: Establish the core working group and select a leader; select a group of visionaries
      Step 1.2: Train the group to think like futurists
      Step 1.3: Hold the initial meeting

      This step involves the following participants:

      • IT Infrastructure Manager
      • CIO or CTO
      • Potential members and visionaries of the working group

      Outcomes of this phase:

      • Establish a team of subject matter experts that will evaluate new, emerging, and potentially disruptive technologies.
      • Establish a process for including visionaries from outside of the working group who will provide insight and direction.
      • Introduce the core working group members.
      • Gain a better understanding of how technology advances.
      • Brainstorm a list of organizational processes.
      • Brainstorm an initial longlist.

      Step 1.2

      Train the group to think like futurists

      Activities:

      1. Look to the past to predict the future:
        • Step 1: Review the technology opportunities you missed
        • Step 2: Review and record what you liked about the tech
        • Step 3: Review and record your dislikes
        • Step 4: Record and test the reasonability
      2. Crash course on futurology principles
      3. Peek into the future

      This step involves the following participants:

      • IT Infrastructure Manager
      • CIO or CTO
      • Core working group members
      • Visionaries

      Outcomes of this step

      • Team members thinking like futurists
      • Better understanding of how technology advances
      • List of past examples and characteristics

      Info-Tech Insight

      Business buy-in is essential. Manage your business partners by providing a summary of the EDIT methodology and process. Validate the process value, which will allow you create a team of IT and business representatives.

      1.2 Train the group to think like futurists

      1 hour

      Ensure the team understands how technology advances and how they can identify patterns in upcoming technologies.

      1. Lead the group through a brainstorming session.
      2. Follow the next phases and steps.
      3. This session should be led by someone who can facilitate a thought-provoking discussion.
      4. This training deck finishes with a video.

      Input

      • Facilitated creativity
      • Training deck [following slides]

      Output

      • Inspiration
      • Anonymous ideas

      Materials

      • Futurist training “steps”
      • Pen and paper

      Participants

      • Core working group
      • Visionaries
      • Facilitator

      1.2.A Look to the past to predict the future

      30 minutes

      Step 1

      Step 2 Step 3 Step 4

      Review what you missed.

      What did you like?

      What did you dislike?

      Test the reasonability.

      Think about a time you missed a technical disruptive opportunity.

      Start with a list of technologies that changed your business and processes.

      Consider those specifically you could have identified with a repeatable process.

      What were the most impactful points about the technology?

      Define a list of “characteristics” you liked.

      Create a shortlist of items.

      Itemize the impact to process, people, and technology.

      Why did you pass on the tech?

      Define a list of “characteristics” you did not like.

      Create a shortlist of items.

      Itemize the impact to process, people, and technology.

      Avoid the “arm chair quarterback” view.

      Refer to the six positive and negative points.

      Check against your data points at the end of each phase.

      Record the list of missed opportunities

      Record 6 characteristics

      Record 6 characteristics

      Completed “Think like a Futurists” tool

      Use the Disruptive Technology Research Look to the Past Tool to record your output.

      Input

      • Facilitated creativity
      • Speaker’s notes

      Output

      • Inspiration
      • Anonymous ideas
      • Recorded missed opportunities
      • Recorded positive points
      • Recorded dislikes
      • Reasonability test list

      Materials

      • Futurist training “steps”
      • Pen and paper
      • “Look to the Past” tool

      Participants

      • Core working group
      • Visionaries
      • Facilitator

      Understand how the difference between linear and exponential growth will completely transform many organizations in the next decade

      “The last ten years have seen exponential growth in research on disruptive technologies and their impact on industries, supply chains, resources, training, education and employment markets … The debate is still open on who will be the winners and losers of future industries, but what is certain is that change has picked up pace and we are now in a new technology revolution whose impact is potentially greater than the industrial revolution.”
      – Gary L. Evans

      Exponential advancement will ensure that life in the next decade will be very different from life today.

      • Linear growth happens one step at a time.
      • The difference between linear and exponential is hard to notice, at first.
      • We are now at the knee of the curve.

      What about email?

      • Consider the amount of email you get daily
      • Double it
      • Triple it

      Exponential growth happens much faster than linear growth, especially when it hits the knee of the curve. Technology grows exponentially, and we are approaching the knee of the curve.

      This graph is adapted from research by Ray Kurzweil.

      Growth: Linear vs. Exponential

      This image contains a graph demonstrating examples of exponential and linear trends.

      1.2.B Crash course on futurology principles

      1 hour

      “An analysis of the history of technology shows that technological change is exponential, contrary to the common-sense ‘intuitive linear’ view. So we won’t experience 100 years of progress in the 21st century — it will be more like 20,000 years of progress (at today’s rate).”
      - Ray Kurzweil

      Review the differences between exponential and linear growth

      The pace of technological advances makes progress difficult to predict.

      Technology advances exponentially. Rather than improving by the same amount of capability each year, it multiplies in capability each year.

      Think like a futurist to anticipate technology before it goes mainstream.

      Exponential growth happens much faster than linear growth, especially when it hits the knee of the curve. Even those who acknowledge exponential growth underestimate how capabilities can improve.

      The following case study illustrates the rise of social media providers

      “There are 7.7 billion people in the world, with at least 3.5 billion of us online. This means social media platforms are used by one in three people in the world and more than two-thirds of all internet users.”
      – Esteban Ortiz-Ospina

      This graph depicts the trend of the number of people using social media platforms between 2005 and 2019

      The following case study illustrates the rapid growth of Machine to Machine (M2M) connections

      A bar graph is shown which depicts the proportion of technology use from 2018-2022. the included devices are: Tablets; PCs; TVs; Non-smartphones; Smartphones; M2M

      Ray Kurzweil’s Law of Accelerating Returns

      “Ray Kurzweil has been described as ‘the restless genius’ by The Wall Street Journal, and ‘the ultimate thinking machine’ by Forbes. He was ranked #8 among entrepreneurs in the United States by Inc Magazine, calling him the ‘rightful heir to Thomas Edison,’ and PBS included Ray as one of 16 ‘revolutionaries who made America,’ along with other inventors of the past two centuries.”
      Source: KurzweilAI.net

      Growth is linear?

      “Information technology is growing exponentially. That’s really my main thesis, and our intuition about the future is not exponential, it’s really linear. People think things will go at the current pace …1, 2, 3, 4, 5, and 30 steps later, you’re at 30.”

      Better IT strategy enables future business innovation

      “The reality of information technology like computers, like biological technologies now, is it goes exponentially … 2, 4, 8, 16. At step 30, you’re at a billion, and this is not an idle speculation about the future.” [emphasis added]

      “When I was a student at MIT, we all shared a computer that cost tens of millions of dollars. This computer [pulling his smartphone out of his pocket] is a million times cheaper, a thousand times more powerful — that’s a billion-fold increase in MIPS per dollar, bits per dollar… and we’ll do it again in 25 years.”
      Source: “IT growth and global change: A conversation with Ray Kurzweil,” McKinsey & Company

      1.2.C Peak into the future

      1 hour

      Leverage industry roundtables and trend reports to understand the art of the possible

      • Uncover important business and industry trends that can inform possibilities for technology disruption.
      • Market research is critical in identifying factors external to your organization and identifying technology innovation that will provide a competitive edge. It’s important to evaluate the impact each trend or opportunity will have in your organization and market.

      Visit Info-Tech’s Trends & Priorities Research Center

      Visit Info-Tech’s Industry Coverage Research to get started.

      Phase 1: Identify

      Create your working group

      Activities:

      Step 1.1: Establish the core working group and select a leader; select a group of visionaries
      Step 1.2: Train the group to think like futurists
      Step 1.3: Hold the initial meeting

      This step involves the following participants:

      • IT Infrastructure Manager
      • CIO or CTO
      • Potential members and visionaries of the working group

      Outcomes of this phase:

      • Establish a team of subject matter experts that will evaluate new, emerging, and potentially disruptive technologies.
      • Establish a process for including visionaries from outside of the working group who will provide insight and direction.
      • Introduce the core working group members.
      • Gain a better understanding of how technology advances.
      • Brainstorm a list of organizational processes.
      • Brainstorm an initial longlist.

      Info-Tech Insight

      Establish the longlist. The longlist help create a holistic view of most technologies that could impact the business. Assigning values and quadrant scoring will shortlist the options and focus your PoC option.

      Step 1.3

      Hold the initial meeting

      Activities:

      1. Create an agenda for the meeting
      2. Start the kick-off meeting with introductions and a recap
      3. Brainstorm about creating a better future
      4. Begin brainstorming an initial longlist
      5. Have team members develop separate longlists for their next meeting

      This step involves the following participants:

      • IT Infrastructure Manager
      • CIO or CTO
      • Core working group members
      • Visionaries

      Outcomes of this step

      • Introduce the core working group members
      • Gain a better understanding of how technology advances
      • Brainstorm a list of organizational processes
      • Brainstorm an initial longlist

      1.3.A Create an agenda for the meeting

      1 hour

      Kick-off this cycle of the disruptive technology process by welcoming your visionaries and introducing your core working group.

      The purpose of the initial meeting is to brainstorm where new technology will be the most disruptive within the organization. You’ll develop two longlists: one of business processes and one of disruptive technology. These longlists are in addition to the independent research your core working group will perform before Phase 2.

      • Find an outgoing facilitator. Sitting back will let you focus more on ideating, and an engaging presenter will help bring out ideas from your visionaries.
      • The training deck (see step 1.2c) includes presenting a video. We’ve included some of our top choices for you to choose from.
        • Feel free to find your own video or bring in a keynote speaker.
        • The object of the video is to get the group thinking about the future.
        • Customize the training deck as needed.
      • If a cycle has been completed, present your findings and all of the group’s completed deliverables in the first section.
      • This session is the only time you have with your visionaries. Get their ideas on what technologies will be disruptive to start forming a longlist.

      Info-Tech Insight

      The disruptive tech team is prestigious. If your organization is large enough or has the resources, consider having this meeting in an offsite location. This will drive excitement to join the working group if the opportunity arises and incentivize good work.

      Meeting Agenda (Sample)

      Time

      Activity

      8:00am-8:30am Introductions and previous meeting recap
      8:30am-9:30am Training deck
      9:30 AM-10:00am Brainstorming
      10:00am-10:15am Break
      10:15am-10:45am Develop good research techniques
      10:45am-12:00pm Begin compiling your longlist

      Info-Tech Insight

      The disruptive tech team is prestigious. If your organization is large enough or has the resources, consider having this meeting in an offsite location. This will drive excitement to join the working group if the opportunity arises and incentivize good work.

      1.3.B Start the kick-off meeting with introductions and a summary of what work has been done so far

      30 minutes

      1. Start the meeting off with an icebreaker activity. This isn’t an ordinary business meeting – or even group – so we recommend starting off with an activity that will emphasize this unique nature. To get the group in the right mindset, try this activity:
        1. Go around the group and have people present:
        2. Their names and roles
        3. Pose some or all of the following questions/prompts to the group:
          • “Tell me about something you have created.”
          • “Tell me about a time you created a process or program considered risky.”
          • “Tell me about a situation in which you had to come up with several new ideas in a hurry. Were they accepted? Were they successful?”
          • “Tell me about a time you took a risk.”
          • “Tell me about one of your greatest failures and what you learned from it.”
      2. Once everyone has been introduced, present any work that has already been completed.
        1. If you have already completed a cycle, give a summary of each technology that you investigated and the results from any piloting.
        2. If this is the first cycle for the working group, present the information decided in Step 1.1.

      Input

      • Disruptive technology exploitation plan

      Output

      • Networking
      • Brainstorming

      Materials

      • Meeting agenda

      Participants

      • Core working group
      • Visionaries
      • Facilitator

      1.3.C Brainstorm about creating a better future for the company, the stakeholders, and the employees

      30 minutes

      Three sticky notes are depicted, at the top of each note are the following titles: What can we do better; How can we make a better future; How can we continue being successful

      1. Have everyone put up at least two ideas for each chart paper.
      2. Go around the room and discuss their ideas. You may generate some new ideas here.

      These generated ideas are organizational processes that can be improved or disrupted with emerging technologies. This list will be referenced throughout Phases 2 and 3.

      Input

      • Inspiration
      • Anonymous ideas

      Output

      • List of processes

      Materials

      • Chart paper and markers
      • Pen and paper

      Participants

      • Core working group
      • Visionaries

      1.3.D Begin brainstorming a longlist of future technology, and discuss how these technologies will impact the business

      30 minutes

      • Use the Disruptive Technology Research Database Tool to organize technologies and ideas. Longstanding working groups can track technologies here over the course of several years, updating the tool between meetings.
      • Guide the discussion with the following questions, and make sure to focus on the processes generated from Step 1.2.d.

      Focus on

      The Technology

      • What is the technology and what does it do?
      • What processes can it support?

      Experts and Other Organizations

      • What are the vendors saying about the technology?
      • Are similar organizations implementing the technology?

      Your Organization

      • Is the technology ready for wide-scale distribution?
      • Can the technology be tested and implemented now?

      The Technology’s Value

      • Is there any indication of the cost of the technology?
      • How much value will the technology bring?

      Download the Disruptive Technology Database Tool

      Input

      • Inspiration
      • List of processes

      Output

      • Initial longlist

      Materials

      • Chart paper and markers
      • Pen and paper
      • Disruptive Technology Research Database Tool

      Participants

      • Core working group
      • Visionaries

      1.3.E Explore these sources to generate your disruptive technology longlist for the next meeting

      30 Minutes

      There are many sources of information on new and emerging technology. Explore as many sources as you can.

      Science fiction is a valid source of learning. It drives and is influenced by disruptive technology.

      “…the inventor of the first liquid-fuelled rocket … was inspired by H.G. Wells’ science fiction novel War of the Worlds (1898). More recent examples include the 3D gesture-based user interface used by Tom Cruise’s character in Minority Report (2002), which is found today in most touch screens and the motion sensing capability of Microsoft’s Kinect. Similarly, the tablet computer actually first appeared in Stanley Kubrick’s 2001: A Space Odyssey (1968) and the communicator – which we’ve come to refer today as the mobile phone – was first used by Captain Kirk in Star Trek (1966).”
      – Emmanuel Tsekleves, senior lecturer, University of Lancaster

      Right sources: blogs, tech news sites, tech magazines, the tech section of business sites, popular science books about technology, conferences, trade publications, and vendor announcements

      Quantity over quality: early research is not the time to dismiss ideas.

      Discuss with your peers: spark new and innovative ideas

      Insert a brief summary of how independent research is conducted in Section 2.1 of the Disruptive Technology Exploitation Plan Template.

      1.3.E (Cont.) Explore these sources to generate your disruptive technology longlist for the next meeting

      30 Minutes

      There are many sources of information on new and emerging technology. Use this list to kick-start your search.

      Connect with practitioners that are worth their weight in Reddit gold. Check out topic-based LinkedIn groups and subreddits such as r/sysadmin and r/tech. People experienced with technology frequent these groups.

      YouTube is for more than cat videos. Many vendors use YouTube for distributing their previous webinars. There are also videos showcasing various technologies that are uploaded by lecturers, geeks, researchers, and other technology enthusiasts.

      Test your reasonability. Check your “Think Like a Futurist” Tool

      Resolve

      Evaluate Disruptive Technologies

      PHASE 2

      Phase 2: Resolve

      Evaluate disrupted technologies

      Activities:

      Step 2.1: Create and Winnow a Longlist
      Step 2.2: Assess Shortlist

      Info-Tech Insight

      Long to short … that’s the short of it. Using SWOT, value readiness, and quadrant mapping review sessions will focus the longlist, creating a shortlist of potential PoC candidates to review and consider.

      This step involves the following participants:

      • Core working group
      • Infrastructure Management

      Outcomes of this step:

      • Finalized longlist
      • Finalized shortlist
      • Initial analysis of each technology on the shortlist

      Step 2.1

      Create and winnow a longlist

      Activities:

      1. Converge everyone’s longlists
      2. Narrow technologies from the longlist down to a shortlist using Info-Tech’s Disruptive Technology Shortlisting Tool
      3. Use the shortlisting tool to help participants visualize the potential
      4. Input the technologies on your longlist into the Disruptive Technology Shortlisting Tool to produce a shortlist

      This step involves the following participants:

      • Core working group members

      Outcomes of this step:

      • Finalized longlist
      • Finalized shortlist
      • Initial analysis of each technology on the shortlist

      2.1 Organize a meeting with the core working group to combine your longlists and create a shortlist

      1 hour

      Plan enough time to talk about each technology on the list. Each technology was included for a reason.

      • Start with the longlist. Review the longlist compiled at the initial meeting, and then have everyone present the lists that they independently researched.
      • Focus on the company’s context. Make sure that the working group analyzes these disruptive technologies in the context of the organization.
      • Start to compile the shortlist. Begin narrowing down the longlist by excluding technologies that are not relevant.

      Meeting Agenda (Sample)

      TimeActivity
      8:00am-9:30amConverge longlists
      9:30am-10:00amBreak
      10:00am-10:45amDiscuss tech in organizational context
      10:45am-11:15amBegin compiling the shortlist

      Disruptive Technology Exploitation Plan Template

      2.1.A Converge the longlists developed by your team

      90 minutes

      • Start with the longlist developed at the initial meeting. Write this list on the whiteboard.
      • If applicable, have a member present the longlist that was created in the last cycle. Remove technologies that:
        • Are no longer disruptive (e.g. have been implemented or rejected).
        • Have become foundational.
      • Eliminate redundancy: remove items that are very similar.
      • Have members “pitch” items on their lists:
        • Explain why their technologies will be disruptive (2-5 minutes maximum)
        • Add new technologies to the whiteboard
      • Record the following for metrics:
        • Each presented technology
        • Reasons the technology could be disruptive
        • Source of the information
      • Use Info-Tech’s Disruptive Technology Research Database Tool as a starting point.

      Insert the final longlist into Section 2.2 of your Disruptive Technology Exploitation Plan Template.

      Input

      • Longlist developed at first meeting
      • Independent research
      • Previous longlist

      Output

      • Finalized longlist

      Materials

      • Disruptive Technology Research Database Tool
      • Whiteboard and markers
      • Virtual whiteboard

      Participants

      • Core working group

      Review the list of processes that were brainstormed by the visionary group, and ask for input from others

      • IT innovation is most highly valued by the C-suite when it improves business processes, reduces costs, and improves core products and services.
      • By incorporating this insight into your working group’s analysis, you help to attract the attention of senior management and reinforce the group’s necessity.
      • Any input you can get from outside of IT will help your group understand how technology can be disruptive.
        • Visionaries consulted in Phase 1 are a great source for this insight.
      • The list of processes that they helped to brainstorm in Step 1.2 reflects processes that can be impacted by technology.
      • Info-Tech’s research has shown time and again that both CEOs and CIOs want IT to innovate around:
        • Improving business processes
        • Improving core products and services
        • Reducing costs

      Improved business processes

      80%

      Core product and service improvement

      48%

      Reduced costs

      48%

      Increased revenues

      23%

      Penetration into new markets

      21%

      N=364 CXOs & CIOs from the CEO-CIO Alignment Diagnostic Questions were asked on a 7-point scale of 1 = Not at all to 7 = Very strongly. Results are displayed as percentage of respondents selecting 6 or 7.

      Info-Tech Insight

      The disruptive tech team is prestigious. If your organization is large enough or has the resources, consider having this meeting in an offsite location. This will drive excitement to join the working group if the opportunity arises and incentivize good work.

      2.1.B Narrow technologies from the longlist down to a shortlist using Info-Tech’s Disruptive Technology Shortlisting Tool

      90 minutes

      To decide which technology has potential for your organization, have the working group or workshop participants evaluate each technology:

      1. Record each potentially disruptive technology in the longlist on a whiteboard.
      2. Making sure to carefully consider the meaning of the terms, have each member of the group evaluate each technology as “high” or “low” along each of the axes, innovation and transformation, on a piece of paper.
      3. The facilitator collects each piece of paper and inputs the results by technology into the Disruptive Technology Shortlisting Tool.
      Technology Innovation Transformation
      Conversational Commerce High High

      Insert the final shortlist into Section 2.2 of your Disruptive Technology Exploitation Plan Template.

      Input

      • Longlist
      • Futurist brainstorming

      Output

      • Shortlist

      Materials

      • Disruptive Technology Research Database Tool
      • Whiteboard and markers
      • Virtual whiteboard

      Participants

      • Core working group

      Disruptive technologies are innovative and transformational

      Innovation

      Transformation

      • Elements:
        • Creative solution to a problem that is relatively new on the scene.
        • It is different, counterintuitive, or insightful or has any combination of these qualities.
      • Questions to Ask:
        • How new is the technology?
        • How different is the technology?
        • Have you seen anything like it before? Is it counterintuitive?
        • Does it offer an insightful solution to a persistent problem?
      • Example:
        • The sharing economy: Today, simple platforms allow people to share rides and lodgings cheaply and have disrupted traditional services.
      • Elements:
        • Positive change to the business process.
        • Highly impactful: impacts a wide variety of roles in a company in a nontrivial way or impacts a smaller number of roles more significantly.
      • Questions to Ask:
        • Will this technology have a big impact on business operations?
        • Will it add substantial value? Will it change the structure of the company?
        • Will it impact a significant number of employees in the organization?
      • Example:
        • Flash memory improved storage technology incrementally by building on an existing foundation.

      Info-Tech Insight

      Technology can be transformational but not innovative. Not every new technology is disruptive. Even where technology has improved the efficiency of the business, if it does this in an incremental way, it might not be worth exploring using this storyboard.

      2.1.C Use the shortlisting tool to help participants visualize the potential

      1 hour

      Use the Disruptive Technology Shortlisting Tool, tabs 2 and 3.

      Assign quadrants

      • Input group members’ names and the entire longlist (up to 30 technologies) into tab 2 of the Disruptive Technology Shortlisting Tool.
      • On tab 3 of the Disruptive Technology Shortlisting Tool, input the quadrant number that corresponds to the innovation and transformation scores each participant has assigned to each technology.

      Note

      This is an assessment meant to serve as a guide. Use discretion when moving forward with a proof-of-concept project for any potentially disruptive technology.

      Participant Evaluation Quadrant
      High Innovation, High Transformation 1
      High Innovation, Low Transformation 2
      Low Innovation, Low Transformation 3
      Low Innovation, High Transformation 4

      four quadrants are depicted, labeled 1-4. The quadrants are coloured as follows: 1- green; 2- yellow; 3; red; 4; yellow

      2.1.D Use the Disruptive Technology Shortlisting Tool to produce a shortlist

      1 hour

      Use the Disruptive Technology Shortlisting Tool, tabs 3 and 4.

      Use the populated matrix and the discussion list to arrive at a shortlist of four to six potentially disruptive technologies.

      • The tool populates each quadrant based on how many votes it received in the voting exercise.
      • Technologies selected for a particular quadrant by a majority of participants are placed in the quadrant on the graph. Where there was no consensus, the technology is placed in the discussion list.
      • Technologies in the upper right quadrant – high transformation and high innovation – are more likely to be good candidates for a proof-of-concept project. Those in the bottom left are likely to be poor candidates, while those in the remaining quadrants are strong on one of the axes and are unlikely candidates for further systematic evaluation.

      This image contains a screenshot from tab 3 of the Disruptive Technology Shortlisting Tool.

      Input the results of the vote into tab 3 of the Disruptive Technology Shortlisting Tool.

      This image contains a screenshot from tab 4 of the Disruptive Technology Shortlisting Tool.

      View the results on tab 4.

      Phase 2: Resolve

      Evaluate disrupted technologies

      Activities:

      Step 2.1: Create and Winnow a Longlist
      Step 2.2:- Assess Shortlist

      This step involves the following participants:

      • Core working group
      • Infrastructure Management

      Outcomes of this step:

      • Finalized longlist
      • Finalized shortlist
      • Initial analysis of each technology on the shortlist

      Assess Shortlist

      Activities:

      1. Assess the value of each technology to your organization by breaking it down into quality and cost
      2. Investigate the overall readiness of the technologies on the shortlist
      3. Interpret each technology’s value score
      4. Conduct a SWOT analysis for each technology on the shortlist
      5. Use Info-Tech’s disruptive technology shortlist analysis to visualize the tool’s outputs
      6. Select the shortlisted technologies you would like to move forward with

      This step involves the following participants:

      • Core working group members
      • IT Management

      Outcomes of this step:

      • Finalized shortlist
      • Initial analysis of each technology on the shortlist

      2.2 Evaluate technologies based on their value and readiness, and conduct a SWOT analysis for each one

      Use the Disruptive Technology Value-Readiness and SWOT Analysis Tool

      • A technology monitor diagram prioritizes investment in technology by analyzing its readiness and value.
        • Readiness: how close the technology is to being practical and implementable in your industry and organization.
        • Value: how worthwhile the technology is, in terms of its quality and its cost.
      • Value and readiness questionnaires are included in the tool to help determine current and future values for each, and the next four slides explain the ratings further.
      • Categorize technology by its value-readiness score, and evaluate how much potential value each technology has and how soon your company can realize that value.
      • Use a SWOT analysis to qualitatively evaluate the potential that each technology has for your organization in each of the four categories (strengths, weaknesses, opportunities, and threats).

      The technology monitor diagram appears in tab 9 of the Disruptive Technology Value-Readiness and SWOT Analysis Tool

      This image depicts tab 9 of the Disruptive Technology Value-Readiness and SWOT Analysis Tool

      2.2.A Assess the value of each technology to your organization by breaking it down into quality and cost

      1 hour

      Update the Disruptive Technology Value-Readiness and SWOT Analysis Tool, tab 4.

      Populate the chart to produce a score for each technology’s overall value to the company conceptualized as the interaction of quality and cost.

      Overall Value

      Quality Cost

      Each technology, if it has a product associated with it, can be evaluated along eight dimensions of quality. Consider how well the product performs, its features, its reliability, its conformance, its durability, its serviceability, its aesthetics, and its perceived quality.

      IT budgets are broken down into capital and operating expenditures. A technology that requires a significant investment along either of these lines is unlikely to produce a positive return. Also consider how much time it will take to implement and operate each technology.

      The value assessment is part of the Disruptive Technology Value-Readiness and SWOT Analysis Tool

      This image contains a screenshot from tab 4 of the Disruptive Technology Value-Readiness and SWOT Analysis Tool.

      Info-Tech Insight

      Watch your costs: Technology that seems cheap at first can actually be expensive over time. Be sure to account for operational and opportunity costs as well.

      2.2.B Investigate the overall readiness of the technologies on the shortlist

      1 hour

      Update the Disruptive Technology Value-Readiness and SWOT Analysis Tool, tab 4.

      Overall Readiness

      Age

      How much time has the technology had to mature? Older technology is more likely to be ready for adoption.

      Venture Capital

      The amount of venture capital gathered by important firms in the space is an indicator of market faith.

      Market Size

      How big is the market for the technology? It is more difficult to break into a giant market than a niche market.

      Market Players

      Have any established vendors (Microsoft, Facebook, Google, etc.) thrown their weight behind the technology?

      Fragmentation

      A large number of small companies in the space indicates that the market has yet to reach equilibrium.

      The readiness assessment is part of the Disruptive Technology Value-Readiness and SWOT Analysis Tool

      This image contains a screenshot of the Readiness Scoring tab of the Disruptive Technology Value-Readiness and SWOT Analysis Tool.

      Use a variety of sources to populate the chart

      Google is your friend: search each shortlisted technology to find details about its development and important vendors.

      Websites like Crunchbase, VentureBeat, and Mashable are useful sources for information on the companies involved in a space and the amount of money they have each raised.

      2.2.C Interpret each technology’s value score

      1 hour

      Insert the result of the SWOT analysis into tab 7 of Info-Tech’s Disruptive Technology Value-Readiness and SWOT Analysis Tool.

      Visualize the results of the quality-cost analysis

      • Quality and cost are independently significant; it is essential to understand how each technology stacks up on the axes.
      • Use tab 6 of the Disruptive Technology Value-Readiness and SWOT Analysis Tool for an illustration of how quality and cost interact to produce each technology’s final position on the tech monitor graph.
      • Remember: the score is notional and reflects the values that you have assigned. Be sure to treat it accordingly.

      This image contains a screenshot of the Value Analysis tab of the Disruptive Technology Value-Readiness and SWOT Analysis Tool

      Green represents a technology that scores extremely high on one axis or the other, or quite high on both. These technologies are the best candidates for proof-of-concept projects from a value perspective.

      Red represents a technology that has scored very low on both axes. These technologies will be expensive, time consuming, and of poor quality.

      Yellow represents the fuzzy middle ground. These technologies score moderately on both axes. Be especially careful when considering the SWOT analysis of these technologies.

      2.2.D Conduct a SWOT analysis for each technology on the shortlist

      1 hour

      Use tab 6 of the Disruptive Technology Value-Readiness and SWOT Analysis Tool.

      A formal process for analyzing disruptive technology is the only way to ensure that it is taken seriously.

      Write each technology as a heading on a whiteboard. Spend 10-15 minutes on each technology conducting a SWOT analysis together.

      Consider four categories for each technology:

      • Strengths: Current uses of the technology or supporting technology and ways in which it helps your organization.
      • Weaknesses: Current limitations of the technology and challenges or barriers to adopting it in your organization.
      • Opportunities: Potential uses of the technology, especially as it advances or improves.
      • Threats: Potential negative disruptions resulting from the technology, especially as it advances or improves.

      The list of processes generated at the cycle’s initial meeting is a great source for opportunities and threats.

      Disruptive Technology Value-Readiness and SWOT Analysis Tool

      This image contains screenshots of the technology tab of the Disruptive Technology Value-Readiness and SWOT Analysis Tool.

      2.2.E Use Info-Tech’s disruptive technology shortlist analysis to visualize the tool’s outputs

      1 hour

      Disruptive Technology Value-Readiness and SWOT Analysis Tool, tab 9

      The tool’s final tab displays the results of the value-readiness analysis and the SWOT analysis in a single location.

      This image contains a screenshot from tab 9 of the Disruptive Technology Value-Readiness and SWOT Analysis Tool

      Insert the shortlist analysis report into Section 3 of your Disruptive Technology Exploitation Plan Template.

      2.2.F Select the shortlisted technologies you would like to move forward with

      1 hour

      Present your findings to the working group.

      • The Disruptive Technology Value-Readiness and SWOT Analysis Tool aggregates your inputs in an easy-to-read, consistent way.
      • Present the tool’s outputs to members of the core working group.
      • Explain the scoring and present the graphic to the group. Go over each technology’s strengths and weaknesses as well as the opportunities and threats it presents/poses to the organization.
      • Go through the proof-of-concept planning phase before striking any technologies from the list.

      This image contains a screenshot of the disruptive technology shortlist analysis from the Disruptive Technology Value-Readiness and SWOT Analysis Tool

      Info-Tech Insight

      A technology’s exceptional value and immediate usability make it the best. A technology can be promising and compelling, but it is unsuitable unless it can bring immediate and exceptional value to your organization. Don’t get caught up in the hype.

      Evaluate

      Create an Action Plan to Exploit Disruptive Technologies

      PHASE 3

      Phase 3: Evaluate

      Create an Action Plan to Exploit Disruptive Technologies

      Activities:

      Step 3.1: Create Process Maps
      Step 3.2: Develop Proof of Concept Charter

      This step involves the following participants:

      • Core working group
      • Infrastructure Management
      • Working group leader
      • CIO

      Outcomes of this step:

      • Business process maps before and after disruption
      • Proof of concept charter
      • Key performance indicators
      • Estimation of required resources

      Step 3.1

      Create Process Maps

      Activities:

      1. Creating a problem canvas by identifying stakeholders, jobs, pains, and gains
      2. Clarify the problem the proof-of-concept project will solve
      3. Identify jobs and stakeholders
      4. Outline how disruptive technology will solve the problem
      5. Map business processes
      6. Identify affected business units
      7. Outline and map the business processes likely to be disrupted
      8. Recognize how the new technology will impact business processes
      9. Make the case: Outline why the new business process is superior to the old

      This step involves the following participants:

      • Working group leader
      • CIO

      Outcomes of this step:

      • Business process maps before and after disruption

      3.1 Create an action plan to exploit disruptive technologies

      Clarify the problem in order to make the case. Fill in section 1.1 of Info-Tech’s Proof of Concept Template to clearly outline the problem each proof of concept is designed to solve.

      Establish roles and responsibilities. Use section 1.2 of the template to outline the roles and responsibilities that fall to each member of the team. Ensure that clear lines of authority are delineated and that the list of stakeholders is exhaustive: include the executives whose input will be required for project approval, all the way to the technicians on the frontline responsible for implementing it.

      Outline the solution to the problem. Demonstrate how each proof-of-concept project provides a solution to the problem outlined in section 1.1. Be sure to clarify what makes the particular technology under investigation a potential solution and record the results in section 1.3.

      This image contains a screenshot of the Proof of concept project template

      Use the Proof of Concept Project Template to track the information you gather throughout Phase 3.

      3.1.A Creating a problem canvas by identifying stakeholders, jobs, pains, and gains

      2 hours

      Instructions:

      1. On a whiteboard, draw the visual canvas supplied below.
      2. Select your issue area, and list jobs, pains, and gains in the associated sections.
      3. Record the pains, jobs, and gains in sections 1.1-1.3 of the Proof of Concept Template.

      Gains

      1. More revenue

      2. Job security

      3. ……

      Jobs

      1. Moving product

      2. Per sale value

      3. ……

      Pains

      1. Clunky website

      2. Bad site navigation

      3. ……

      Input

      • Inspiration
      • Anonymous ideas

      Output

      • List of processes

      Materials

      • Chart paper and markers
      • Pen and paper

      Participants

      • Core working group
      • Visionaries

      3.1.B Clarify the problem the proof-of-concept project will solve

      2 hours

      What is the problem?

      • Every technology is designed to solve a problem faced by somebody somewhere. For each technology that your team has decided to move forward with, identify and clearly state the problem it would solve.
      • A clear problem statement is a crucial part of a new technology’s business case. It is impossible to earn buy-in from the rest of the organization without demonstrating the necessity of a solution.
      • Perfection is impossible to achieve: during the course of their work, everyone encounters pain points. Identify those pain points to arrive at the problem that needs to be solved.

      Example:

      List of pains addressed by conversational commerce:

      • Search functions can be clunky and unresponsive.
      • Corporate websites can be difficult to navigate.
      • Customers are uncomfortable in unfamiliar internet environments.
      • Customers do not like waiting in a long queue to engage with customer service representatives when they have concerns.

      “If I were given one hour to solve a problem, I would spend 59 minutes defining the problem and one minute resolving it.”
      – Albert Einstein

      Input the results of this exercise into Section 1.1 of the Proof of Concept Template.

      3.1.C Identify jobs and stakeholders

      1 hour

      Jobs

      Job: Anything that the “customer” (the target of the solution) needs to get done but that is complicated by a pain.

      Examples:
      The job of the conversational commerce interface is to make selling products easier for the company.
      From the customer perspective, the job of the conversational interface is to make the act of purchasing a product simpler and easier.

      Stakeholders

      Stakeholder: Anyone who is impacted by the new technology and who will end up using, approving, or implementing it.

      Examples:
      The executive is responsible for changing the company’s direction and approving investment in a new sales platform.
      The IT team is responsible for implementing the new technology.
      Marketing will be responsible for selling the change to customers.
      Customers, the end users, will be the ones using the conversational commerce user interface.

      Input the results of this exercise into Section 1.2 of the Proof of Concept Template.

      Info-Tech Insight

      Process deconstruction reveals strengths and weaknesses. Promising technology should improve stakeholders’ abilities to do jobs.

      3.1.D Outline how disruptive technology will solve the problem

      1 hour

      How will the technology in question make jobs easier?

      • How will the disruptive technology you have elected to move forward with create gains for the organization?
      • First, identify the gains that are supposed to come with the project. Consider the benefits that the various stakeholders expect to derive from the jobs identified.
      • Second, make note of how the technology in question facilitates the gains you have noted. Be sure to articulate the exclusive features of the new technology that make it an improvement over the current state.

      Note: The goal of this exercise is to make the case for a particular technology. Sell it!

      Expected Gain: Increase in sales.

      Conversational Commerce’s Contribution: Customers are more likely to purchase products using interfaces they are comfortable with.

      Expected Gain: Decrease in costs.

      Conversational Commerce’s Contribution: Customers who are satisfied with the conversational interface are less likely to interact with live agents, saving labor costs.

      Input the results of this exercise into Section 1.3 of the Proof of Concept Template.

      3.1.E Map business processes

      1 hour

      Map the specific business processes the new technology will impact.

      • Disruptive technologies will impact a wide variety of business processes.
      • Map business processes to visualize what parts of your organization (departments, silos, divisions) will be impacted by the new technology, should it be adopted after the proof of concept.
      • Identify how the disruption will take place.
      • Demonstrate the value of each technology by including the results of the Disruptive Technology Value-Readiness and SWOT Analysis Tool with your process map.

      This image contains a screenshot of the Proof of concept project template

      Use the Proof of Concept Project Template to track the information you gather throughout Phase 3.

      3.1.F Identify affected business units

      30 minutes per technology

      Disruptive technology will impact business units.

      • Using the stakeholders identified earlier in the project, map each technology to the business units that will be affected.
      • Make your list exhaustive. While some technologies will have a limited impact on the business as a whole, others will have ripple effects throughout the organization.
      • Examine affected units at all scales: How will the technology impact operations at the team level? The department level? The division level?

      “The disruption is not just in the technology. Sometimes a good business model can be the disruptor.”
      – Jason Hong, Associate Professor, Carnegie Mellon

      Example:

      • Customer service teams: Conversational commerce will replace some of the duties of the customer service representative. They will have to reorganize to account for this development.
      • IT department: The IT department will be responsible for building/maintaining the conversational interface (or, more likely, they will be responsible for managing the contract with the vendor).
      • Sales analytics: New data from customers in natural language might provide a unique opportunity for the analytics team to develop new initiatives to drive sales growth.

      Input the results of this exercise into Section 2.1 of the Proof of Concept Template.

      3.1.G Outline and map the business processes likely to be disrupted

      15 minutes per technology

      Leverage the insights of the diverse working group.

      • Processes are designed to transform inputs into outputs. All business activities can be mapped into processes.
      • A process map illustrates the sequence of actions and decisions that transform an input into an output.
      • Effective mapping gives managers an “aerial” view of the company’s processes, making it easier to identify inefficiencies, reduce waste, and ultimately, streamline operations.
      • To identify business processes, have group members familiar with the affected business units identify how jobs are typically accomplished within those units.

      “To truly understand a business process, we need information from both the top-down and bottom-up points of view. Informants higher in the organizational hierarchy with a strategic focus are less likely to know process details or problems. But they might advocate and clearly articulate an end-to-end, customer-oriented philosophy that describes the process in an idealized form. Conversely, the salespeople, customer service representatives, order processors, shipping clerks, and others who actually carry out the processes will be experts about the processes, their associated documents, and problems or exception cases they encounter.”
      – Robert J. Glushko, Professor at UC Berkeley and Tim McGrath, Business Consultant

      Info-Tech Insight

      Opinions gathered from a group that reflect the process in question are far more likely to align with your organization’s reality. If you have any questions about a particular process, do not be afraid to go outside of the working group to ask someone who might know.

      3.1.G Outline and map the business processes likely to be disrupted (continued)

      15 minutes per technology

      Create a simple diagram of identified processes.

      • Use different shapes to identify different points in the process.
      • Rectangles represent actions, diamonds represent decisions.
      • On a whiteboard, map out the actions and decisions that take place to transform an input into an output.
      • Input the result into section 2.2 of the Proof of Concept Template.

      This image contains a screenshot of the Software Service Cross-Function Process tab from Edraw Visualization Solutions.

      Source: Edraw Visualization Solutions

      Example: simplified process map

      1. User: visits company website
      2. User: engages search function or browses links
      3. User: selects and purchases product from a menu
      4. Company: ships product to customer

      3.1.H Recognize how the new technology will impact business processes

      15 minutes per technology

      Using the information gleaned from the previous activities, develop a new process map that takes the new technology into account.

      Identify the new actions or decisions that the new technology will affect.

      User: visits company website; User: engages conversational; commerce platform; User: engages search function or browses links; User: makes a natural language query; User: selects and purchases product from a menu</p data-verified=

      User: selects and purchases product from a menu; Company: ships product to customer; Company: ships product to customer">

      Info-Tech Insight

      It’s ok to fail! The only way to know you’re getting close to the “knee of curve" is from multiple failed PoC tests. The more PoC options you have, the more likely it will be that you will have two to three successful results.

      3.1.I Make the case: Outline why the new business process is superior to the old

      15 minutes per technology

      Articulate the main benefits of the new process.

      • Using the revised process map, make the case for each new action.
      • Questions to consider: How does the new technology relieve end-user/customer pains? How does the new technology contribute to the streamlining of the business process? Who will benefit from the new action? What are the implications of those benefits?
      • Record the results of this exercise in section 2.4 of the Proof of Concept Template.

      This image contains an example of an outline comparing the benefits of new and the old business processes.

      Info-Tech Insight

      If you cannot articulate how a new technology will benefit a business process, reconsider moving forward with the proof-of-concept project.

      Phase 3: Evaluate

      Create an Action Plan to Exploit Disruptive Technologies

      Activities:

      Step 3.1: Create Process Maps
      Step 3.2: Develop Proof of Concept Charter

      Develop Proof of Concept Charter

      This step involves the following participants:

      • Core working group
      • Infrastructure Management
      • Working group leader
      • CIO

      Outcomes of this step:

      • Business process maps before and after disruption
      • Proof of concept charter
      • Key performance indicators
      • Estimation of required resources

      Step 3.2

      Develop Proof of Concept Charter

      Activities:

      1. Use SMART success metrics to define your objectives
      2. Develop key performance indicators (KPIs)
      3. Identify key success factors for the project
      4. Outline the project’s scope
      5. Identify the structure of the team responsible for the proof-of-concept project
      6. Estimate the resources required by the project
      7. Be aware of common IT project concerns
      8. Communicate your working group’s findings and successes to a wide audience
      9. Hand off the completed proof-of-concept project plan
      10. Disruption is constant: Repeat the evaluation process regularly to protect the business

      This step involves the following participants:

      • Working group leader
      • CIO

      Outcomes of this step:

      • Proof of concept charter
      • Key performance indicators
      • Estimation of required resources

      3.2 Develop a proof of concept charter

      Keep your proof of concept on track by defining five key dimensions.

      1. Objective: Giving an overview of the planned proof of concept will help to focus and clarify the rest of this section. What must the proof of concept achieve? Objectives should be: specific, measurable, attainable, relevant, and time bound. Outline and track key performance indicators.
      2. Key Success Factors: These are conditions that will positively impact the proof of concept’s success.
      3. Scope: High-level statement of scope. More specifically, state what is in scope and what is out of scope.
      4. Project Team: Identify the team’s structure, e.g. sponsors, subject-matter experts.
      5. Resource Estimation: Identify what resources (time, materials, space, tools, expertise, etc.) will be needed to build and socialize your prototype. How will they be secured?

      Input the results of this exercise into Section 3.0 of the Proof of Concept Template.

      3.2.A Use SMART success metrics to define your objectives

      Specific

      Measurable

      Actionable

      Realistic

      Time Bound

      Make sure the objective is clear and detailed.

      Objectives are measurable if there are specific metrics assigned to measure success. Metrics should be objective.

      Objectives become actionable when specific initiatives designed to achieve the objective are identified.

      Objectives must be achievable given your current resources or known available resources.

      An objective without a timeline can be put off indefinitely. Furthermore, measuring success is challenging without a timeline.

      Who, what, where, why?

      How will you measure the extent to which the goal is met?

      What is the action-oriented verb?

      Is this within my capabilities?

      By when: deadline, frequency?

      Examples:

      1. Increase in sales by $40,000 per month by the end of next quarter.
      2. Immediate increase in web traffic by 600 unique page views per day.
      3. Number of pilots approved per year.
      4. Number of successfully deployed solutions per year.

      Input the results of this exercise into Section 3.0 of the Proof of Concept Template.

      3.2.B Develop key performance indicators (KPIs)

      30 minutes per technology

      Key performance indicators allow for rigorous analysis, which generates insight into utilization by platform and consumption by business activity.

      • Use the process improvements identified in step 3.1 to brainstorm metrics that indicate when process improvement is actually taking place.
      • Have members of the group pitch KPIs; the facilitator should record each suggestion on a whiteboard.
      • Make sure to have everyone justify the inclusion of each metric: How does it relate to the improvement that the proof of concept project is intended to drive? How does it relate to the overall goals of the business?
      • Include a list of KPIs, along with a description and a target (ensuring that it aligns with SMART metrics) in section 3.1 of the Proof of Concept Template.

      “An estimated 70% of performance measurement systems fail after implementation. Carefully select your KPIs and avoid this trap!”
      Source: Collins et al. 2016

      Key Performance Indicator Description Target

      Result

      Conversion rate What percentage of customers who visit the site/open the conversational interface continue on to make a purchase? 40%
      Average order value

      How much does each customer spend per visit to the website?

      $212
      Repeat customer rate What percentage of customers have made more than one purchase over time? 65%
      Lifetime customer value Over the course of their interaction with the company, what is the typical value each customer brings? $1566

      Input the results of this exercise into Section 3.1 of the Proof of Concept Template.

      3.2.C Identify key success factors for the project

      30 minutes per technology

      Effective project management involves optimizing four key success factors (Clarke, 1999)

      • Communication: Communicate the expected changes to stakeholders, making sure that everyone who needs to know does know. Example: Make sure customer service representatives know their duties will be impacted by the conversational UI well before the proof-of-concept project begins.
      • Clarity: All involved in the project should be apprised of what the project is intended to accomplish and what the project is not intended to accomplish. Example: The conversational commerce project is not intended to be rolled out to the entire customer base all at once; it is not intended to disrupt normal online sales.
      • Compartmentalization: The working group should suggest some ways that the project can be broken down to facilitate its effective implementation. Example: Sales provides details of customers who might be amenable to a trial, IT secures a vendor, customer service writes a script.
      • Flexibility: The working group’s final output should not be treated as gospel. Ensure that the document can be altered to account for unexpected events. Example: The conversational commerce platform might drive sales of a particular product more than others, necessitating adjustments at the warehouse and shipping level.

      Input the results of this exercise into Section 3.0 of the Proof of Concept Template.

      3.2.D Outline the project’s scope

      10 minutes per technology

      Create a high-level outline of the project’s scope.

      • Questions to consider: Broadly speaking, what are the project’s goals? What is the desired future state? Where in the company will the project be rolled out? What are some of the company’s goals that the project is not designed to cover?
      • Be sure to avoid scope creep! Remember: The goal of the proof-of-concept project is to produce a minimum case for viability in a carefully defined area. Reserve a detailed accounting of costs and benefits for the post-proof-of-concept stage.
      • Example: The conversational user interface will only be rolled out in an e-commerce setting. Other business units (HR, for example) are beyond the scope of this particular project.

      “Although scope creep is not the only nemesis a project can have, it does tend to have the farthest reach. Without a properly defined project and/or allowing numerous changes along the way, a project can easily go over budget, miss the deadline, and wreak havoc on project success.”
      – University Alliance, Villanova University

      Input the results of this exercise into Section 3.0 of the Proof of Concept Template.

      3.2.E Identify the structure of the team responsible for the proof-of-concept project

      10 minutes per technology

      Brainstorm who will be involved in project implementation.

      • Refer back to the list of stakeholders identified in 3.1.a. Which stakeholders should be involved in implementing the proof-of-concept plan?
      • What business units do they represent?
      • Who should be accountable for the project? At a high level, sketch the roles of each of the participants. Who will be responsible for doing the work? Who will approve it? Who needs to be informed at every stage? Who are the company’s internal subject matter experts?

      Example

      Name/Title Role
      IT Manager Negotiate the contract for the software with vendor
      CMO Promote the conversational interface to customers

      Input the results of this exercise into Section 3.0 of the Proof of Concept Template.

      3.2.F Estimate the resources required by the project

      10 minutes per technology

      Time and Money

      • Recall: Costs can be operational, capital, or opportunity.
      • Revisit the Disruptive Technology Value-Readiness and SWOT Analysis Tool. Record the capital and operational expenses expected to be associated with each technology, and add detail where possible (use exact figures from particular vendors instead of percentages).
      • Write the names and titles of each expected participant in the project on a whiteboard. Next to each name, write the number of hours they are expected to devote to the project and include a rough estimate of the cost of their participation to the company. Use full-time employee equivalent (FTE measures) as a base.
      • Outline how other necessary resources (space, tools, expertise, etc.) will be secured.

      Example: Conversational Commerce

      • OpEx: $149/month + 2.9¢/transaction* (2,000 estimated transactions)
      • CapEx: $0!
      • IT Manager: 5 hours at $100/hour
      • IT Technician: 40 hours at $45/hour
      • CMO: 1 hour at $300/hour
      • Customer Service Representative: 10 hours at $35/hour
      • *Estimated total cost for a one-month proof-of-concept project: $3,157

      *This number is a sample taken from the vendor Rhombus

      Input the results of this exercise into Section 3.0 of the Proof of Concept Template.

      3.2.G Be aware of common IT project concerns

      Of projects that did not meet business expectations or were cancelled, how significant were the following issues?

      A bar graph is depicted, comparing small, medium, and large businesses for the following datasets: Over budget; Project failed to be delivered on time; Breach of scope; Low quality; Failed to deliver expected benefit or value

      This survey data did not specifically address innovation projects.

      • Disruptive technology projects will be under increased scrutiny in comparison to other projects.
      • Be sure to meet deadlines and stay within budget.
      • Be cognizant that your projects can go out of scope, and there will be projects that may have to be cancelled due to low quality. Remember: Even a failed test is a learning opportunity!

      Info-Tech’s CIO-CEO Alignment Survey, N=225

      Organization size was determined by the number of IT employees within the organization

      Small = 10 or fewer IT staff, medium = 11 to 25 IT staff, and large/enterprise = 26 or greater IT staff

      3.2.H Communicate your working group’s findings and successes to a wide audience

      Advertise the group’s successes and help prevent airline magazine syndrome from occurring.

      • Share your group’s results internally:
        • Run your own analysis by senior management and then share it across the organization.
        • Maintain a list of technologies that the working group has analyzed and solicit feedback from the wider organization.
        • Post summaries of the technologies in a publicly available repository. The C-suite may not read it right away, but it will be easy to provide when they ask.
        • If senior management has declined to proceed with a certain technology, avoid wasting time and resources on it. However, include notes about why the technology was rejected.
      • These postings will also act as an advertisement for the group. Use the garnered interest to attract visionaries for the next cycle.
      • These postings will help to reiterate the innovative value of the IT department and help bring you to the decision-making table.

      “Some CIOs will have to battle the bias that they belong in the back office and shouldn’t be included in product architecture planning. CIOs must ‘sell’ IT’s strength in information architecture.”
      – Chris Curran, Chief Technologist, PwC (Curran, 2014)

      Info-Tech Insight

      Cast a wide net. By sharing your results with as many people as possible within your organization, you’ll not only attract more attention to your working group, but you will also get more feedback and ideas.

      3.2.I Hand off the completed proof-of-concept project plan

      The proof of concept template is filled out – now what?

      • The core working group is responsible for producing a vision of the future and outlining new technology’s disruptive potential. The actual implementation of the proof of concept (purchasing the hardware, negotiating the SLA with the vendor) is beyond the working group’s responsibilities.
      • If the proof of concept goes ahead, the facilitator should block some time to evaluate the completed project against the key performance indicators identified in the initial plan.
      • A cure for airline magazine syndrome: Be prepared when executives ask about new technology. Present them with the results of the shortlist analysis and the proof-of-concept plan. A clear accounting of the value, readiness, strengths, weaknesses, opportunities, and threats posed by each technology, along with its impact on business processes, is an invaluable weapon against poor technology choices.

      Use section 3.2.b to identify the decision-making stakeholder who has the most to gain from a successful proof-of-concept project. Self-interest is a powerful motivator – the project is more likely to succeed in the hands of a passionate champion.

      Info-Tech Insight

      Set a date for the first meeting of the new iteration of the disruptive technology working group before the last meeting is done. Don’t risk pushing it back indefinitely.

      3.2.J Hand off the completed proof-of-concept project plan

      Record the results of the proof of concept. Keep track of what worked and what didn’t.

      Repeat the process regularly.

      • Finalize the proof of concept template, but don’t stop there: Keep your ear to the ground; follow tech developments using the sources identified in step 1.2.
      • Continue expanding the potential longlist with independent research: Be prepared to expand your longlist. Remember, the more technologies you have on the longlist, the more potential airline magazine syndrome cures you have access to.
      • Have the results of the previous session’s proof of concept plan on hand: At the start of each new iteration, conduct a review. What technologies were successful beyond the proof of concept phase? Which parts of the process worked? Which parts did not? How could they be improved?

      Info-Tech Insight

      The key is in anticipation. This is not a one-and-done exercise. Technology innovation operates at a faster pace than ever before, well below the Moores Law "18 month" timeline as an example. Success is in making EDIT a repeatable process.

      Related Info-Tech Research

      Define Your Digital Business Strategy
      After a major crisis, find your place in the digital economy.

      Develop a Project Portfolio Management Strategy
      Drive project throughput by throttling resource capacity.

      Adopt Design Thinking in Your Organization
      Innovation needs design thinking.

      Digital Maturity Improvement Service
      Prepare your organization for digital transformation – or risk falling behind.

      Research contributors and experts

      Nitin Babel

      Nitin Babel, Co-Founder, niki.ai

      Nitin Babel, MSc, co-created conversational commerce platform niki.ai in early 2015. Since then, the technology has been featured on the front page of the Economic Times, and has secured the backing of Ratan Tata, former chairman of the Tata Group, one of the largest companies in the world.

      Mark Hubbard

      Mark Hubbard, Senior Vice President, FirstOnSite

      Mark is the SVP for Information Technology in Canada with FirstOnSite, a full service disaster recovery and property restoration company. Mark has over 25 years of technology leadership guiding global organizations through the development of strategic and tactical plans to strengthen their technology platforms and implement business aligned technology strategies.

      Chris Green

      Chris Green, Enterprise Architect, Boston Private
      Chris is an IT architect with over 15 years’ experience designing, building, and implementing solutions. He is a results-driven leader and contributor, skilled in a broad set of methods, tools, and platforms. He is experienced with mobile, web, enterprise application integration, business process, and data design.

      Andrew Kope

      Andrew Kope, Head of Data Analytics
      Big Blue Bubble
      Andrew Kope, MSc, oversees a team that develops and maintains a user acquisition tracking solution and a real-time metrics dashboard. He also provides actionable recommendations to the executive leadership of Big Blue Bubble – one of Canada’s largest independent mobile game development studios.

      Jason Hong

      Jason Hong, Associate Professor, School of Computer Science, Human-Computer Interaction Institute, Carnegie Mellon University

      Jason Hong is a member of the faculty at Carnegie Mellon’s School of Computer Science. His research focus lies at the intersection of human-computer interaction, privacy and security, and systems. He is a New America National Cyber Security Fellow (2015-2017) and is widely published in academic and industry journals.

      Tim Lalonde

      Tim Lalonde, Vice President, Mid-Range

      Tim Lalonde is the VP of Technical Operations at Mid-Range. He works with leading-edge companies to be more competitive and effective in their industries. He specializes in developing business roadmaps leveraging technology that create and support change from within — with a focus on business process re-engineering, architecture and design, business case development and problem-solving. With over 30 years of experience in IT, Tim’s guiding principle remains simple: See a problem, fix a problem.

      Jon Mavor

      Jon Mavor, Co-Founder and CTO, Envelop VR
      Jon Mavor is a programmer and entrepreneur, whose past work includes writing the graphics engine for the PC game Total Annihilation. As Chief Technology Officer of Envelop VR, a virtual reality start-up focused on software for the enterprise, Jon has overseen the launch of Envelop for Windows’s first public beta.

      Dan Pitt

      Dan Pitt, President, Palo Alto Innovation Advisors
      Dan Pitt is a network architect who has extensive experience in both the academy and industry. Over the course of his career, Dan has served as Executive Director of the Open Networking Foundation, Dean of Engineering at Santa Clara University, Vice President of Technology and Academic Partnerships at Nortel, Vice President of the Architecture Lab at Bay Networks, and, currently, as President of Palo Alto Innovation Advisors, where he advises and serves as an executive for technology start-ups in the Palo Alto area and around the world.

      Courtney Smith

      Courtney Smith, Co-Founder, Executive Creative Director
      PureMatter

      Courtney Smith is an accomplished creative strategist, storyteller, writer, and designer. Under her leadership, PureMatter has earned hundreds of creative awards and been featured in the PRINT International Design Annual. Courtney has juried over 30 creative competitions, including Creativity International. She is an invited member of the Academy of Interactive and Visual Arts.

      Emmanuel Tsekleves

      Emmanuel Tsekleves, Senior Lecturer in Design Interactions, University of Lancaster
      Dr. Emmanuel Tsekleves is a senior lecturer and writer based out of the United Kingdom. Emmanuel designs interactions between people, places, and products by forging creative design methods along with digital technology. His design-led research in the areas of health, ageing, well-being, and defence has generated public interest and attracted media attention by the national press, such as the Daily Mail, Daily Mirror, The Times, the Daily Mail, Discovery News, and several other international online media outlets.

      Bibliography

      Airini Ab Rahman. “Emerging Technologies with Emerging Effects; A Review”. Universiti Teknologi Malaysia. PERINTIS eJournal, June 2017. Web.

      Anthony, Scott. “Kodak’s Downfall Wasn’t About Technology.” Harvard Business Review, 15 July 2016. Web.

      ARM. The Intelligent Flexible Cloud. 26 Feb. 2015. Web.

      Association of Computing Machinery. Communications of the ACM, n.d. Web.

      Barnett, Thomas. “Three Mobile Trends to Watch.” Cisco Blogs, 3 Feb. 2015. Web.

      Batelle, John. “The 70 Percent Solution.” CNN, 1 Dec 2005. Web.

      Booz Allen Hamilton. Managing Technological Change: 7 Ways to Talk Tech with Management, n.d. Web.

      Brynjolfsson, Erik, and Andrew McAfee. The Second Machine Age: Work, Progress, and Prosperity in a Time of Brilliant Technologies. W. W. Norton, 2014. Print.

      Christensen, Clayton M. “What is Disruptive Innovation?” Harvard Business Review, Dec 2015. Web.

      Christensen, Clayton M. and James Euchner. “Managing Disruption: An Interview With Clayton Christensen.” Research-Technology Management, 22 Dec 2015. vol. 54, no. 1. Web.

      Christensen, Clayton M., Rory McDonald, and Elizabeth J. Altman. “Disruptive Innovation: An Intellectual History and Directions for Future Research”. Wiley Online Library. Web.

      Christensen, Clayton M., Taddy Hall, Karen Dillon, and David S. Duncan. “Know Your Customers’ Jobs to be Done.” Harvard Business Review, Sept. 2016. Web.

      Cisco. “Cisco Annual Internet Report.” n.d. Web.

      Cisco. Cisco Visual Networking Index: Forecast and Methodology, 2014-2019, 27 May 2015. Web.

      Clark, Steven. “Elon Musk hopes SpaceX will send humans to Mars in 2024.” Spaceflight Now, 2 June 2016. Web.

      Clarke, Angela. “A practical use of key success factors to improve the effectiveness of project management,” International Journal of Project Management, June 1999 (17): 139-145.

      Collins, Andrew L., Patrick Hester, Barry Ezell, and John Horst. “An improvement selection methodology for key performance indicators.” Environmental Systems and Decisions, June 2016, 36 (2): 196-208.

      Computer Sciences Corporation. CSC Global CIO Survey: 2014-2015: CIOs Emerge as Disruptive Innovators: An Annual Barometer of Global CIOs’ Plans, Priorities, Threats, and Opportunities, 2014. Web.

      Constine, John. “Voice is Chat’s Next Battleground.” TechCrunch, 19 Sept. 2016. Web.

      Cressman, Daryl. “Disruptive Innovation and the Idea of Technology”. Maastricht University, June 2019. Web.

      Crown Prosecution Service. A Guide to Process Mapping and Improvement. n.d. Web.

      Curran, Chris. “The CIO’s Role in the Internet of Things.” PwC, 13 Mar. 2014. Web.

      Darbha, Sheta, Mike Shevenell, and Jason Normandin. “Impact of Software-Defined Networking on Infrastructure Management.” CA Technology Exchange, 4.3, Nov. 2013, pp. 33-43. Web.

      Denecken, Sven. Conquering Disruption Through Digital Transformation: Technologies, Leadership Strategies, and Best Practices to Create Opportunities for Innovation. SAP, 2014. Web.

      DHL Trend Research and Cisco Consulting Services. Internet of Things in Logistics: A Collaborative Report by DHL and Cisco on Implications and Use Cases for the Logistics Industry, 2015. Web.

      Dirican, Cüneyt. “The Impacts of Robotics, Artificial Intelligence on Business and Economics.” Procedia: Social and Behavioral Sciences, vol. 195, 2015, pp. 564-573. Web.

      Edraw Visualization Solutions. Examples of Flowcharts, Org Charts and More. “Cross-Function Flowchart Examples – Service Flowchart.”

      Emerson. Data Center 2025: Exploring the Possibilities, 2014. Web.

      Ericsson. Next-Generation Data Center Infrastructure, Feb. 2015. Web.

      Eurotech. Connecting M2M Applications to the Cloud to Bolster Hardware Sales, 2014. Web.

      Evans Gary, Llewellyn. “Disruptive Technology and the Board: The Tip of the Iceberg”. Economics and Business Review, n.d. Web.

      Evans Gary, Llewellyn. “Disruptive Technology and the Board: The Tip of the Iceberg”. Economics and Business Review, n.d. Web.

      Gage, Deborah. “The Venture Capital Secret: 3 Out of 4 Start-Ups Fail.” Wall Street Journal, 20 Sept. 2012. Web.

      Garvin, David A. “Competing on the Eight Dimensions of Quality.” Harvard Business Review, November 1987. Web.

      Gibbs, Colin. Augmented Reality in the Enterprise: Opportunities and Challenges. Gigaom Research, 26 Jan. 2015. Web.

      Glushko, Robert J. and Tim McGrath. Document Engineering: Analyzing and Designing Documents for Business Informatics and Web Services. MIT Press, 2005.

      Hadfield, Tom. “Facebook’s Messenger Bot Store could be the most important launch since the App Store.” TechCrunch, 17 March 2016. Web.

      Healey, Nic. “Microsoft's mixed reality vision: 80 million devices by 2020.” CNET, 1 June 2016. Web.

      Hewlett-Packard. Go Beyond Cost Reduction: Use Robotic Process Automation, Oct. 2015. Web.

      Hewlett-Packard. HP Composable Infrastructure: Bridging Traditional IT with the New Style of Business, June 2015. Web.

      Hewlett-Packard. HP Labs, n.d. Web.

      Hong, Jason. “Inside the Great Wall.” Communications of the ACM, 25 May 2016. Web.

      IBM Institute for Value. Your Cognitive Future: How Next-Gen Computing Changes the Way We Live and Work, 2015. Web.

      IBM. A New Way to Work: Futurist Insights to 2025 and Beyond, Jan. 2015. Web.

      Infinity. The Evolution of the Data Centre [sic], 2015. Web.

      Intel Corporation. Intel Annual Report, 1997. Web.

      Isaac, Mike. “Facebook Bets on Bots for its Messenger App.” New York Times, 12 April 2016. Web.

      ISACA. COBIT 5: Enabling Processes. ISACA, 2012. Print.

      K-12 Blueprint. “Planning a Proof of Concept.” 2014. Web.

      Kaushik Rukmini, Meenakshi. “The Impact of Pandemic COVID -19 in Workplace.” European Journal of Business Management and Research, May 2020. Web.

      Knight, Will. “Conversational Interfaces Powerful speech technology from China’s leading Internet company makes it much easier to use a smartphone.” MIT Technology Review, n.d. Web.

      Kostoff, Ronald N., Robert Boylan, and Gene R. Simons. “Disruptive Technology Roadmaps.” Technological Forecasting and Social Change, 2004. Vol. 71. Web.

      Kurzweil, Ray. “The Accelerating Power of Technology.” TED, Feb. 2005. Web.

      Kurzweil, Ray. Kurzweil: Accelerating Intelligence, 2015. Web.

      MacFarquhar, Larissa. “When Giants Fall: What Business Has Learned From Clayton Christensen,” New Yorker, 14 May 2012. Web.

      McClintock, Cat. “2016: The Year for Augmented Reality in the Enterprise.” PTC, n.d. Web.

      McKinsey & Company. IT Growth and Global Change: A Conversation with Ray Kurzweil. 29 Feb. 2012, YouTube. Web.

      Messina, Chris. “2016 Will be the Year of Conversational Commerce.” Medium, 19 Jan 2016. Web.

      Microsoft. Microsoft Research, n.d. Web.

      Miller, Ron. “Forget the Apple Watch, Think Drones in the Enterprise.” TechCrunch, 10 Sep. 2015. Web.

      Nokia Networks. FutureWorks [sic]: Teaching Networks to be Self-Aware: Technology Vision 2020. 2014. Web.

      Nokia Networks. Internet of Things. n.d. Web.

      O’Reilly, Charles, and Andrew J. M. Binns, “The Three Stages of Disruptive Innovation: Idea Generation, Incubation, and Scaling”. Sage Journals, n.d. Web.

      Pew Research Center. AI, Robotics, and the Future of Jobs: Experts Envision Automation and Intelligent Digital Agents Permeating Vast Areas of Our Work and Personal Lives by 2025, but they are Divided on Whether these Advances will Displace More Jobs than they Create. Aug. 2014. Web.

      Ramiller, Neil. “Airline Magazine Syndrome: Reading a Myth of Mismanagement.” Information Technology & People, Sept 2001. Print.

      Raymond James & Associates. The Internet of Things: A Study in Hype, Reality, Disruption, and Growth. 2014. Web.

      Richter, Felix. “No Growth in Sight for Global PC Market.” Statista, 14 March 2016. Web.

      Roy, Mekhala. “4 Examples of Digital Transformation Success in Business”. TechTarget, n.d. Web.

      Simon Weinreich, “How to Manage Disruptive Innovation - a conceptional methodology for value-oriented portfolio planning,” Sciencedirect. 31st CIRP Design Conference 2021.

      Spice Works. The Devices are Coming! How the “Internet of Things” will affect IT… and why resistance is futile. May 2014. Web.

      Spradlin, Dwayne. “Are You Solving the Right Problem?” Harvard Business Review, Sept. 2012. Web.

      Statista. “Number of smartphones sold to end users worldwide from 2007 to 2015 (in million units).” N.d. Web.

      Statista. “Worldwide tablet shipments from 2nd quarter 2010 to 2nd quarter 2016 (in million units).” N.d. Web.

      Sven Schimpf, “Disruptive Field Study; How Companies Identify, Evaluate, Develop and Implement Disruptive Technologies.” Fraunhofer Group for Innovation Research, 2020. Web.

      Tsekleves, Emmanuel. “Science fiction as fact: how desires drive discoveries.” The Guardian. 13 Aug. 2015. Web.

      Tsekleves, Emmanuel. “Science fiction as fact: how desires drive discoveries.” The Guardian, 13 Aug. 2015. Web.

      United States Department of Transportation. “National Motor Vehicle Crash Causation Survey: Report to Congress.” National Highway Traffic Safety Administration, July 2008. Web.

      United States Department of Transportation. “National Motor Vehicle Crash Causation Survey: Report to Congress.” National Highway Traffic Safety Administration, July 2008. Web.

      University Alliance (Villanova U). Managing Scope Creep in Project Management. N.d. Web.

      Vavoula, Giasemi N., and Mike Sharples. “Future Technology Workshop: A Collaborative Method for the Design of New Learning Technologies and Activities.” International Journal of Computer Supported Collaborative Learning, Dec 2007. Vol. 2 no. 4. Web.

      Walraven Pieter. “It’s Operating Systems Vs. Messaging Apps In The Battle For Tech’s Next Frontier.” TechCrunch, 11 Aug 2015. Web.

      Webb, Amy. “The Tech Trends You Can’t Ignore in 2015.” Harvard Business Review, 5 Jan. 2015. Web.

      Wenger, Albert. “The Great Bot Rush of 2015-16.” Continuations, 16 Dec 2015. Web.

      White, Chris. “IoT Tipping Point Propels Digital Experience Era.” Cisco Blogs, 12 Nov. 2014. Web.

      World Economic Forum and Accenture. Industrial Internet of Things: Unleashing the Potential of Connected Products and Services. 2015. Web.

      Yu Dan and Hang Chang Chieh, "A reflective review of disruptive innovation theory," PICMET '08 - 2008 Portland International Conference on Management of Engineering & Technology, 2008, pp. 402-414, doi: 10.1109/PICMET.2008.4599648.

      Improve IT Governance to Drive Business Results

      • Buy Link or Shortcode: {j2store}190|cart{/j2store}
      • member rating overall impact: 9.3/10 Overall Impact
      • member rating average dollars saved: $194,553 Average $ Saved
      • member rating average days saved: 32 Average Days Saved
      • Parent Category Name: IT Governance, Risk & Compliance
      • Parent Category Link: /it-governance-risk-and-compliance
      • IT governance is the number-one predictor of value generated by IT, yet many organizations struggle to organize their governance effectively.
      • Current IT governance does not address the changing goals, risks, or context of the organization, so IT spend is not easily linked to value.
      • The right people are not making the right decisions about IT.

      Our Advice

      Critical Insight

      • Organizations do not have a governance framework in place that optimally aligns IT with the business objectives and direction.
      • Implementing IT governance requires the involvement of key business stakeholders who do not see IT’s value in corporate governance and strategy.
      • The current governance processes are poorly designed, making the time to decisions too long and driving non-compliance.

      Impact and Result

      • Use Info-Tech’s four-step process to optimize your IT governance framework.
      • Our client-tested methodology supports the enablement of IT-business alignment, decreases decision-making cycle times, and increases IT’s transparency and effectiveness in decisions around benefits realization, risks, and resources.
      • Successful completion of the IT governance redesign will result in the following outcomes:
        1. Align IT with the business context.
        2. Assess the current governance framework.
        3. Redesign the governance framework.
        4. Implement governance redesign.

      Improve IT Governance to Drive Business Results Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should redesign IT governance, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Align IT with the business context

      Align IT’s direction with the business using the Statement of Business Context.

      • Redesign IT Governance to Drive Optimal Business Results – Phase 1: Align IT With the Business Context
      • Make the Case for an IT Governance Redesign
      • Stakeholder Power Map Template
      • IT Governance Stakeholder Communication Planning Tool
      • PESTLE Analysis Template
      • Business SWOT Analysis Template
      • Statement of Business Context Template

      2. Assess the current governance framework

      Evaluate the strengths and weaknesses of current governance using the Current State Assessment.

      • Redesign IT Governance to Drive Optimal Business Results – Phase 2: Assess the Current Governance Framework
      • Current State Assessment of IT Governance

      3. Redesign the governance framework

      Build a redesign of the governance framework using the Future State Design template.

      • Redesign IT Governance to Drive Optimal Business Results – Phase 3: Redesign the Governance Framework
      • Future State Design for IT Governance
      • IT Governance Terms of Reference

      4. Implement governance redesign

      Create an implementation plan to jump-start the communication of the redesign and set it up for success.

      • Redesign IT Governance to Drive Optimal Business Results – Phase 4: Implement Governance Redesign
      • Redesign IT Governance to Drive Optimal Business Results Executive Presentation Template
      • IT Governance Implementation Plan
      [infographic]

      Workshop: Improve IT Governance to Drive Business Results

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Identify the Need for Governance

      The Purpose

      Identify the need for governance in your organization and engage the leadership team in the redesign process.

      Key Benefits Achieved

      Establish an engagement standard for the leadership of your organization in the IT governance redesign.

      Activities

      1.1 Identify stakeholders.

      1.2 Make the case for improved IT governance.

      1.3 Customize communication plan.

      Outputs

      Stakeholder Power Map

      Make the Case Presentation

      Communication Plan

      2 Align IT With the Business Context

      The Purpose

      Create a mutual understanding with the business leaders of the current state of the organization and the state of business it is moving towards.

      Key Benefits Achieved

      The understanding of the business context will provide an aligned foundation on which to redesign the IT governance framework.

      Activities

      2.1 Review documents.

      2.2 Analyze frameworks.

      2.3 Conduct brainstorming.

      2.4 Finalize the Statement of Business Context.

      Outputs

      PESTLE Analysis

      SWOT Analysis

      Statement of Business Context

      3 Assess the Current Governance Framework

      The Purpose

      Establish a baseline of the current governance framework.

      Key Benefits Achieved

      Develop guidelines based off results from the current state that will guide the future state design.

      Activities

      3.1 Create committee profiles.

      3.2 Build governance structure map.

      3.3 Establish governance guidelines.

      Outputs

      Current State Assessment

      4 Redesign the Governance Framework

      The Purpose

      Redesign the governance structure and the committees that operate within it.

      Key Benefits Achieved

      Build a future state of governance where the relationships and processes that are built drive optimal business results.

      Activities

      4.1 Build governance structure map.

      4.2 Create committee profiles.

      Outputs

      Future State Design

      IT Governance Terms of Reference

      5 Implement Governance Redesign

      The Purpose

      Build a roadmap for implementing the governance redesign.

      Key Benefits Achieved

      Create a transparent and relationship-oriented implementation strategy that will pave the way for a successful redesign implementation.

      Activities

      5.1 Identify next steps for the redesign.

      5.2 Establish communication plan.

      5.3 Lead executive presentation.

      Outputs

      Implementation Plan

      Executive Presentation

      Further reading

      Improve IT Governance to Drive Business Results

      Avoid bureaucracy and achieve alignment with a minimalist approach.

      ANALYST PERSPECTIVE

      Governance optimization is achieved where decision making, authority, and context meet.

      "Governance is something that is done externally to IT and well as internally by IT, with the intention of providing oversight to direct the organization to meet goals and keep things on target.

      Optimizing IT governance is the most effective way to consistently direct IT spend to areas that provide the most value in producing or supporting business outcomes, yet it is rarely done well.

      IT governance is more than just identifying where decisions are made and who has the authority to make them – it must also provide the context and criteria under which decisions are made in order to truly provide business value" (Valence Howden, Director, CIO Practice Info-Tech Research Group)

      Our understanding of the problem

      This Research is Designed For:

      • CIOs
      • CTOs
      • IT Directors

      This Research Will Help You:

      • Achieve and maintain executive and business support for optimizing IT governance.
      • Optimize your governance structure.
      • Build high-level governance processes.
      • Build governance committee charters and set accountability for decision making.
      • Plan the transition to the optimized governance structure and processes.

      This Research Will Also Assist:

      • Executive Leadership
      • IT Managers
      • IT Customers
      • Project Managers

      This Research Will Help Them:

      • Improve alignment between business decisions and IT initiatives.
      • Establish a mechanism to validate, redirect, and reprioritize IT initiatives.
      • Realize greater value from more effective decision making.
      • Receive a better overall quality of service.

      Executive Summary

      Situation

      • IT governance is the #1 predictor of value generated by IT, yet many organizations struggle to organize their governance effectively.*
      • Current IT governance does not address the changing goals, risks, or context of the organization so IT spend is not easily linked to value.
      • The right people are not making the right decisions about IT.

      Complication

      • Organizations do not have a governance framework in place that optimally aligns IT with the business objectives and direction.
      • Implementing IT governance requires the involvement of key business stakeholders who do not see IT’s value in governance and strategy.
      • The current governance processes are poorly designed, creating long decision-making cycles and driving non-compliance with regulation.

      Resolution

      • Use Info-Tech’s four-step process for optimizing your IT governance framework. Our client-tested methodology supports the enablement of IT-business alignment, decreases decision-making cycle times, and increases IT’s transparency and effectiveness in making decisions around benefits realization, risks, and resources.
      • Successful completion of the IT governance redesign will result in the following outcomes:
        1. Align IT with the business context.
        2. Assess the current governance framework.
        3. Redesign the governance framework.
        4. Implement governance redesign.

      Info-Tech Insight

      • Establish IT-business fusion. In governance, alignment is not enough. Merge IT and the business through governance to ensure business success.
      • With great governance comes great responsibility. Involve relevant business leaders, who will be impacted by IT outcomes, to take on governing responsibility of IT.
      • Let IT manage and the business govern. IT governance should be a component of enterprise governance, allowing IT leaders to focus on managing.

      IT governance is...

      An enabling framework for decision-making context and accountabilities for related processes.

      A means of ensuring business-IT collaboration, leading to increased consistency and transparency in decision making and prioritization of initiatives.

      A critical component of ensuring delivery of business value from IT spend and driving high satisfaction with IT.

      IT governance is not...

      An annoying, finger-waving roadblock in the way of getting things done.

      Limited to making decisions about technology.

      Designed tacitly; it is purposeful, with business objectives in mind.

      A one-time project; you must review and revalidate the efficiency.

      Avoid common misconceptions of IT governance

      Don’t blur the lines between governance and management; each has a unique role to play. Confusing these results in wasted time and confusion around ownership.

      Governance

      A cycle of 'Governance Processes' and 'Management Processes'. On the left side of the cycle 'Governance Processes' begins with 'Evaluate', then 'Direct', then 'Monitor'. This leads to 'Management Processes' on the right side with 'Plan', 'Build', 'Run', and 'Monitor', which then feeds back into 'Evaluate'.

      Management

      IT governance sets direction through prioritization and decision making, and monitors overall IT performance.

      Governance aligns with the mission and vision of the organization to guide IT.

      Management is responsible for executing on, operating, and monitoring activities as determined by IT governance.

      Management makes decisions for implementing based on governance direction.

      The IT Governance Framework

      An IT governance framework is a system that will design structures, processes, authority definitions, and membership assignments that lead IT toward optimal results for the business.

      Governance is performed in three ways:
      1. Evaluate

        Governance ensures that business goals are achieved by evaluating stakeholder needs, criteria, metrics, portfolio, risk, and definition of value.
      2. Direct

        Governance sets the direction of IT by delegating priorities and determining the decisions that will guide the IT organization.
      3. Monitor

        Governance establishes a framework to monitor performance, compliance to regulation, and progress on expected outcomes.

      "Everyone needs good IT, but no one wants to talk about it. Most CFOs would rather spend time with their in-laws than in an IT steering-committee meeting. But companies with good governance consistently outperform companies with bad. Which group do you want to be in?" (Martha Heller, President, Heller Search Associates)

      Create impactful IT governance by embedding it within enterprise governance

      The business should engage in IT governance and IT should influence the direction of the business.

      Enterprise Governance

      IT Governance

      Authority for enterprise governance falls to the board and executive management.

      Responsibilities Include:
      • Provide strategic direction for the organization.
      • Ensure objectives are met.
      • Set the risk standards or profile.
      • Delegate resources responsibly.
      –› Engage in –›

      ‹– Influence ‹–

      Governance of IT is a component of enterprise governance.

      Responsibilities Include:
      • Build structure, authority, process, and membership designations in a governance framework.
      • Ensure the IT organization is aligned with business goals.
      • Influence the direction of the business to ensure business success.

      Identify signals of sub-optimal IT governance within any of these domains

      If you notice any of these signals, governance redesign is right for you!

      Inability to Realize Benefits

      1. IT is unable to articulate the value of its initiatives or spend.
      2. IT is regularly delegated unplanned projects.
      3. The is no standard approach to prioritization.
      4. Projects do not meet target metrics.

      Resource Misallocation

      1. Resources are wasted due to duplication or overlap in IT initiatives.
      2. IT projects fail at an unacceptable rate, leading to wasted resources.
      3. IT’s costs continue to increase without reciprocal performance increase.

      Misdiagnosed Risks

      1. Risk appetite is incorrectly identified or not identified at all.
      2. Disagreement on the approach to risk in the organization.
      3. Increasing rate of IT incidents related to risk.
      4. IT is failing to meet regulatory requirements.

      Dissatisfied Stakeholders

      1. There are no ways to measure stakeholder satisfaction with IT.
      2. Business strategies and IT strategies are misaligned.
      3. IT’s relationship with key stakeholders is unstable and there is a lack of mutual trust.

      A majority of organizations experience significant alignment gaps

      The majority of organizations and their key stakeholders experience highly visible gaps in the alignment of IT investments and organizational goals.

      There are two bars with percentages of their length marked out for different CXO responses. The possible responses are from '1, Critical Gap' to '7, No Gap'. The top bar says '57% of CXOs identify a major gap in IT's ability to support business goals', and shows 13% answered '1, Critical Gap', 22% answered '2', and 22% answered '3'. The bottom bar says '84% of CXOs often perceive that IT is investing in areas that do not support the business' and shows 38% answered '1, Critical Gap', 33% answered '2', and 13% answered '3'.

      88% of CIOs believe that their governance is not effective. (Info-Tech Diagnostics)

      Leverage governance as the catalyst for connecting IT and the business

      49% of firms are misaligned on current performance expectations for IT.

      • 49% Misaligned
      • 51% Aligned

      67% of firms are misaligned on the target role for IT.

      • 34% Highly Misaligned
      • 33% Somewhat Misaligned
      • 33% Aligned

      A well-designed IT governance framework will hep you to:

      1. Make sure IT keeps up with the evolving business context.
      2. Align IT with the mission and the vision of the organization.
      3. Optimize the speed and quality of decision making.
      4. Meet regulatory and compliance needs in the external environment.
      5. (Info-Tech Diagnostics)

      Align with business goals through governance to attain business-IT fusion

      Create a state of business-IT fusion, in which the two become one.

      Without business-IT fusion, IT will go in a different direction, leading to a divergence of purpose and outcomes. IT can transform into a fused partner of the business by ensuring that they govern toward the same goal.

      Firefighter
      • Delivers lower value
      • Duplication of effort
      • Unclear risk profile
      • High risk exposure
      Three sets of arrows, each pointing upward and arranged in an ascending stair pattern. The first, lowest set of arrows has a large blue arrow with a small green arrow veering off to the side, unaligned. The second, middle set of arrows has a large blue arrow with a medium green arrow overlaid on its center, somewhat aligned. The third, highest set of arrows has half of a large blue arrow, and the other half is a large green arrow, aligned. Business Partner
      • Increased speed of decision making
      • Aligned with business priorities
      • Optimized utility of people, financial, and time resources
      • Monitors and mitigates risk and compliance issues

      Redesign IT governance in accordance with COBIT and proven good practice

      Info-Tech’s approach to governance redesign is rooted in COBIT, the world-class and open-source IT governance standard.

      COBIT begins with governance, EDM – Evaluate, Direct, and Monitor.

      We build upon these standards with industry best practices and add a practical approach based on member feedback.

      This blueprint will help you optimize your governance framework.

      The upper image is a pyramid with 'Info-Tech Insights, Analysts, Experts, Clients' on top, 'IT Governance Best Practices' in the middle, and 'COBIT 5' on the bottom, indicating that Info-Tech's Governance guidance is based in COBIT 5. 'This project will focus on EDM01, Set/Maintain Governance Framework.'

      Use Info-Tech’s approach to implementing an IT governance redesign

      The four phases of Info-Tech’s governance redesign methodology will help you drive greater value for the business.

      1. Align IT With the Business Context
        Align IT’s direction with the business using the Statement of Business Context Template.
      2. Assess the Current Governance Framework
        Evaluate the strengths and weaknesses of current governance using the Current State Assessment of IT Governance.
      3. Redesign the Governance Framework
        Build a redesign of the governance framework using the Future State Design for IT Governance tool.
      4. Implement Governance Redesign
        Create an IT Governance Implementation Plan to jumpstart the communication of the redesign and set it up for success.
      5. Continuously assess your governance framework to ensure alignment.

      Leverage Info-Tech’s insights for an optimal redesign process

      Common Pitfalls

      Info-Tech Solutions

      Phase 1

      There must be an active understanding of the current and future state of the business for governance to address the changing needs of the business. –›
      1. Make the case for a governance redesign.
      2. Create a custom communication plan to facilitate support.
      3. Establish a collectively agreed upon statement of business context.

      Phase 2

      Take a proactive approach to revising your governance framework. Understand why you are making decisions before actually making them. –›
      1. Conduct the IT governance current state assessment.
      2. Create governance guidelines for redesign.

      Phase 3

      Keep the current and future goals in sight to build an optimized governance framework that maintains the minimum bar of oversight required. –›
      1. Redesign the future state of IT governance in your organization.

      Phase 4

      Don’t overlook the politics and culture of your organization in redesigning your governance framework. –›
      1. Rationalize steps in an implementation plan.
      2. Outline a communication strategy to navigate culture and politics.
      3. Construct an executive presentation to facilitate transparency for the governing framework.

      Leverage both COBIT and Info-Tech-defined metrics to evaluate the success of your redesign

      These metrics will help you determine the extent to which your governance is supporting your business goals, and whether the governance in place promotes business-IT fusion.

      Benefits Realization

      1. Percent of IT-enabled investments where benefit realization is monitored through the full economic life. (COBIT-defined metric)
      2. Percent of enterprise strategic goals and requirements supported by IT strategic goals. (COBIT-defined metric)
      3. Percent of IT services where expected benefits are realized or exceeded. (COBIT-defined metric)

      Resources

      1. Satisfaction level of business and IT executives with IT-related costs and capabilities. (COBIT-defined metric)
      2. Average time to turn strategic IT objectives into an agreed-upon and approved initiative. (COBIT-defined metric)
      3. Number of deviations from resource utilization plan.

      Risks

      1. Number of security incidents causing financial loss, business disruption, or public embarrassment. (COBIT-defined metric)
      2. Number of issues related to non-compliance with policies. (COBIT-defined metric)
      3. Percentage of enterprise risk assessments that include IT-related risks. (COBIT-defined metric)
      4. Frequency with which the risk profile is updated. (COBIT-defined metric)

      Stakeholders

      1. Change in score of alignment with the scope of the planned portfolio of programs and services (using CIO-CXO Alignment Diagnostic).
      2. Percent of executive management roles with clearly defined accountabilities for IT decisions. (COBIT-defined metric)
      3. Percent of business stakeholders satisfied that IT service delivery meets agreed-upon service levels. (COBIT-defined metric)
      4. Percent of key business stakeholders involved in IT governance.

      Capture monetary value by establishing and monitoring key metrics

      While benefits of governance are often qualitative, the power of effective governance can be demonstrated through quantitative financial gains.

      Scenario 1 – Realizing Expected Gains

      Scenario 2 – Mitigating Unexpected Losses

      Metric

      Track the percentage of initiatives that provided expected ROI year over year. The optimization of the governance framework should generate an increase in this metric. Monitor this metric for continuous improvement opportunities. Track the financial losses related to non-compliance with policy or regulation. An optimized governance framework should better protect the organization against policy breach and mitigate the possibility and impact of “rogue” actions.

      Formula

      ROI of all initiatives / number of initiatives in year 2 – ROI of all initiatives / number of initiatives in year 1

      The expected result should be positive.

      Cost of non-compliance in year 2 – cost of non-compliance in year 1

      The expected result should be negative.

      Redesign IT governance to achieve optimal business outcomes

      CASE STUDY

      Industry: Healthcare
      Source: Info-Tech

      Situation

      The IT governance had been structured based on regulations and had not changed much since it was put in place. However, a move to become an integration and service focused organization had moved the organization into the world of web services, Agile development, and service-oriented architecture.

      Complication

      The existing process was well defined and entrenched, but did not enable rapid decision making and Agile service delivery. This was due to the number of committees where initiatives were reviewed, made worse by their lack of approval authority. This led to issues moving initiatives forward in the timeframes required to meet clinician needs and committed governmental deadlines.

      In addition, the revised organizational mandate had created confusion regarding the primary purpose and function of the organization and impacted the ability to prioritize spend on a limited budget.

      To complicate matters further, there was political sensitivity tied to the membership and authority of different governing committees.

      Result:

      The CEO decided that a project would be initiated by the Enterprise Architecture Group, but managed by an external consultant to optimize and restructure the governance within the organization.

      The purpose of using the external consultant was to help remove internal politics from the discussion. This allowed the organization to establish a shared view of the organization’s revised mission and IT’s role in its execution.

      The exercise led to the removal of one governing committee and the merger of two others, modification to committee authority and membership, and a refined decision-making context that was agreed to by all parties.

      The redesigned governance process led to a 30% reduction in cycle time from intake to decision, and a 15% improvement in alignment of IT spend with strategic priorities.

      Use these icons to help direct you as you navigate this research

      Use these icons to help guide you through each step of the blueprint and direct you to content related to the recommended activities.

      A small monochrome icon of a wrench and screwdriver creating an X.

      This icon denotes a slide where a supporting Info-Tech tool or template will help you perform the activity or step associated with the slide. Refer to the supporting tool or template to get the best results and proceed to the next step of the project.

      A small monochrome icon depicting a person in front of a blank slide.

      This icon denotes a slide with an associated activity. The activity can be performed either as part of your project or with the support of Info-Tech team members, who will come onsite to facilitate a workshop for your organization.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      Guided Implementation

      Workshop

      Consulting

      "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful." "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track." "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place." "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

      Diagnostics and consistent frameworks used throughout all four options

      Redesign IT Governance – project overview

      Align IT With the Business Context

      Assess the Current State

      Redesign Governance

      Implement Redesign

      Supporting Tool icon

      Best-Practice Toolkit

      1.1 Identify Stakeholders
      1.2 Make the Case
      1.3 Present to Executives
      1.4 Customize Comm. Plan
      1.5 Review Documents
      1.6 Analyze Frameworks
      1.7 Conduct Brainstorming
      1.8 Finalize the SoBC
      2.1 Create Committee Profiles

      2.2 Build a Governance Structure Map

      2.3 Establish Governance Guidelines

      3.1 Build Governance Structure Map

      3.2 Create Committee Profiles

      3.3 Leverage Process Specific Governance Blueprints

      4.1 Identify Next Steps for the Redesign

      4.2 Establish Communication Plan

      4.3 Lead Executive Presentation

      Guided Implementations

      • Move towards gaining buy-in from the business if necessary. Then identify the major components of the SoBC.
      • Review SoBC and discuss a strategy to engage key stakeholders in the redesign.
      • Explore the process of identifying the four major elements of governance. Build guidelines for the future state.
      • Review the current state of governance and discuss the implications and guidelines.
      • Identify the changes that will need to be made.
      • Review redesigned structure and authority.
      • Review redesigned process and membership.
      • Discuss and review the implementation plan.
      • Prepare the presentation for the executives. Provide support on any final questions.
      Associated Activity icon

      Onsite Workshop

      Module 1:
      Align IT with the business context
      Module 2:
      Assess the current governance framework
      Module 3:
      Redesign the governance framework
      Module 4:
      Implement governance redesign
      Phase 1 Results:
      • Align IT’s direction with the business.
      Phase 2 Results:
      • Evaluate the strengths and weaknesses of current governance and build guidelines.
      Phase 3 Results:
      • Establish a redesign of the governance framework.
      Phase 4 Results:
      • Create an implementation plan for the communication of the redesign.

      Workshop overview

      Contact your account representative or email Workshops@InfoTech.com for more information.

      Workshop Day 1

      Workshop Day 2

      Workshop Day 3

      Workshop Day 4

      Workshop Day 5

      Task – Identify the Need for Governance Task – Align IT with the Business Context Task – Assess the Current State Task – Redesign Governance Framework Task – Implement Governance Redesign

      Activities

      • 1.1 Identify Stakeholders
      • 1.2 Make the Case
      • 1.3 Present to Executives
      • 1.4 Customize Communication Plan
      • 2.1 Review Documents
      • 2.2 Analyze Frameworks
      • 2.3 Conduct Brainstorming
      • 2.4 Finalize the Statement of Business Context
      • 3.1 Create Committee Profiles
      • 3.2 Build Governance Structure Map
      • 3.3 Establish Governance Guidelines
      • 4.1 Build Governance Structure Map
      • 4.2 Create Committee Profiles
      • 4.3 Leverage Process Specific Governance Blueprints
      • 5.1 Identify Next Steps for the Redesign
      • 5.2 Establish Communication Plan
      • 5.3 Lead Executive Presentation

      Deliverables

      1. Make the Case Presentation
      2. Stakeholder Power Map Template
      3. Communication Plan
      1. PESTLE Analysis
      2. SWOT Analysis
      3. Statement of Business Context
      1. Current State Assessment
      1. Future State Design Tool
      2. IT Governance Terms of Reference
      1. Implementation Plan
      2. Executive Presentation

      Improve IT Governance to Drive Business Results

      PHASE 1

      Align IT With the Business Context

      Phase 1 outline

      Associated Activity icon Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

      Complete these steps on your own, or call us to complete a guided implementation. A guided implementation is a series of 2-3 advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

      Guided Implementation 1: Align IT With the Business Context

      Proposed Time to Completion: 2-4 weeks
      Step 1.1: Identify the Need for Governance Step 1.2: Create the Statement of Business Context
      Start with an analyst kick-off call:
      • Understand the core concepts of IT governance.
      • Create a strategy for key stakeholder support.
      • Identify key communication milestones.
      Review findings with analyst:
      • Identify and discuss the process of engaging senior leadership.
      • Review findings from business analysis.
      • Review diagnostic and interview outcomes.
      Then complete these activities…
      • Identify stakeholders.
      • Make the case to executives.
      • Build a communication plan.
      Then complete these activities…
      • Review business documents.
      • Review the PESTLE and SWOT analyses.
      • Analyze outcomes of CIO-CEO Alignment Diagnostic.
      • Complete the Statement of Business Context.
      With these tools & templates:
      • Make the Case for an IT Governance Redesign
      • Stakeholder Power Map Template
      • IT Governance Stakeholder Communication Planning Tool
      With these tools & templates:
      • PESTLE Analysis Template
      • Business SWOT Analysis Template
      • CIO-CEO Alignment Diagnostic
      • Statement of Business Context Template

      Phase 1: Align IT With the Business Context

      1 2 3 4
      Align IT With the Business Context Assess the Current Governance Framework Redesign the Governance Framework Implement Governance Redesign

      Activities:

      • 1.1 Identify Stakeholders
      • 1.2 Customize Make the Case Presentation
      • 1.3 Present to Executives
      • 1.4 Customize Communication Plan
      • 1.5 Review Business Documents
      • 1.6 Analyze Business Frameworks
      • 1.7 Conduct Brainstorming Efforts
      • 1.8 Finalize the SoBC

      Outcomes:

      • Make the case for a governance redesign.
      • Create a custom communication plan to facilitate support for the redesign process.
      • Establish a collectively agreed upon statement of business context.

      Set up business-driven governance by gaining an understanding of the business context

      Fuse IT with the business by establishing a common context of what the business is trying to achieve. Align IT with the business by developing an understanding of the business state, creating a platform to build a well-aligned governance framework.

      "IT governance philosophies can no longer be a ‘black box’ … IT governance can no longer be ignored by senior executives." (Iskandar and Mohd Salleh, University of Malaya, International Journal of Digital Society)

      Info-Tech Insight

      Get consensus on the changing state of business. There must be an active understanding of the current and future state of the business for governance to address the changing needs of the business.

      The source for the governance redesign directive will dictate the route for attaining leadership buy-in

      "Without an awareness of IT governance, there is no chance that it will be followed … The higher the percentage of managers who can describe your governance, the higher the governance performance." (Jeanne Ross, Director, MIT Center for Information Systems Research)

      The path you will choose for your governance buy-in tactics will be based on the original directive to redesign governance.

      Enterprise Directive.
      In the case that the redesign is an enterprise directive, jump directly to building a communication plan.

      IT Directive.
      In the case that the redesign is an IT directive, make the case to get the business on board.

      Use the Make the Case presentation template to get buy-in from the business

      Supporting Tool icon 1A Convince senior management to redesign governance

      INSTRUCTIONS

      1. Identify Stakeholders
        Determine which business stakeholders will be impacted or involved in the redesign process.
      2. Customize the Presentation
        Identify specific pain points regarding IT-business alignment.
      3. Present to Executives
        Present the make the case presentation.

      Info-Tech Best Practice

      Use the Make the Case customizable deliverable to lead a boardroom-quality presentation proving the specific need for senior executive involvement in the governance redesign.

      Determine which business stakeholders will be impacted or involved in the redesign process

      Associated Activity icon 1.1 Identify the stakeholders for the IT governance redesign

      It is vital to identify key business and IT stakeholders before the IT governance redesign has begun. Consider whose input and influence will be necessary in order to align with the business context and redesign the governance framework accordingly.

      Business

      • Shareholders
      • Board
      • Chief Executive Officer
      • –› Example: the CEO wants to know how IT will support the achievement of strategic corporate objectives.
      • Chief Financial Officer
      • Chief Operating Officer
      • Business Executives
      • Business Process Owners
      • Strategy Executive Committee
      • Chief Risk Officer
      • Chief Information Security Officer
      • Architecture Board
      • Enterprise Risk Committee
      • Head of Human Resources
      • Compliance
      • Audit

      IT

      • Chief Information Officer
      • –› Example: the CIO would like validation from the business with regards to prioritization criteria.
      • Head Architect
      • Head of Development
      • Head of IT Operations
      • Head of IT Administration
      • Service Manager
      • Information Security Manager
      • Business Continuity Manager
      • Privacy Officer

      External

      • Government Agency
      • –› Example: some governments mandate that organizations develop and implement an IT governance framework.
      • Audit Firm

      Build a power map to prioritize stakeholders

      Associated Activity icon 1.1 2-4 hours

      Stakeholders may have competing concerns – that is, concerns that cannot be addressed with one solution. The governance redesigner must prioritize their time to address the concerns of the stakeholders who have the most power and who are most impacted by the IT governance redesign.

      Draw a stakeholder power map to visualize the importance of various stakeholders and their concerns, and to help prioritize your time with those stakeholders.

      • Power: How much influence does the stakeholder have? Enough to drive the project forward or into the ground?
      • Involvement: How interested is the stakeholder? How much involvement does the stakeholder have in the project already?
      • Impact: To what degree will the stakeholder be impacted? Will this significantly change the job?
      • Support: Is the stakeholder a supporter of the project? Neutral? A resistor?
      A power map of stakeholders with two axes and four quadrants. The vertical axis is 'Low Power' on the bottom and 'High Power' on top. The horizontal axis is 'Low Involvement' on the left and 'High Involvement' on the right. The top left quadrant is labeled 'Keep satisfied' and contains 'CFO', a Strongly Impacted Resistor, and 'COO', a Weakly Impacted Resistor. The top right quadrant is labeled 'Key Players' and contains 'CIO' and 'CEO', both Strongly Impacted Supporters. The bottom left quadrant is labeled 'Minimal effort' and contains 'Marketing Head', a Weakly Impacted Neutral, and 'Production Head', a Moderately Impacted Neutral. The bottom right quadrant is labeled 'Keep informed' and contains 'Director of Ops', a Strongly Impacted Supporter, and 'Chief Architect', a Strongly Impacted Neutral.

      Download Info-Tech’s Stakeholder Power Map Template to help you visualize your key stakeholders.

      Build a power map to prioritize stakeholders

      Associated Activity icon 1.1

      It is important to identify who will be impacted and who has power, and the level of involvement they have in the governance redesign. If they have power, will be highly impacted, and are not involved in governance, you have already lost – because they will resist later. You need to get them involved early.

      • Focus on key players – relevant stakeholders who have high power, are highly impacted, and should have a high level of involvement.
      • Engage the stakeholders that are impacted most and have the power to impede the success of redesigning IT governance.
        • For example, if a CFO, who has the power to block project funding, is heavily impacted and not involved, the IT governance redesign success will be put at risk.
      • Some stakeholders may have influence over others so you should focus your efforts on the influencer rather than the influenced.
        • For example, if an uncooperative COO is highly influenced by the Director of Operations, it is recommended to engage the latter.

      The same power map of stakeholders with two axes and four quadrants, but with focus points and notes. The vertical axis is 'Low Power' on the bottom and 'High Power' on top. The horizontal axis is 'Low Involvement' on the left and 'High Involvement' on the right. The top left quadrant is labeled 'Keep satisfied' and contains 'CFO', a Strongly Impacted Resistor, and 'COO', a Weakly Impacted Resistor, as well as a dotted line moving 'CFO' to the top right quadrant with the note 'A) needs to be engaged'. The top right quadrant is labeled 'Key Players' and contains 'CIO' and 'CEO', both Strongly Impacted Supporters, as well as the new required position of 'CFO'. The bottom left quadrant is labeled 'Minimal effort' and contains 'Marketing Head', a Weakly Impacted Neutral, and 'Production Head', a Moderately Impacted Neutral. The bottom right quadrant is labeled 'Keep informed' and contains 'Director of Ops', a Strongly Impacted Supporter, and 'Chief Architect', a Strongly Impacted Neutral, as well as a line from 'Director of Ops' to 'COO' in the top left quadrant with a note that reads 'B) Influences'.

      Identify specific pain points regarding business-IT alignment

      Associated Activity icon 1.2 2-4 hours

      INPUT: Signal Questions, CIO-CXO Alignment Diagnostic

      OUTPUT: List of Categorized Pain Points

      Materials: Make the Case for an IT Governance Redesign

      Participants: Identified Key Business Stakeholders

      1. Consider Signals for Redesign
        Refer to the Executive Brief for questions to identify pain points related to governance.
        • Benefits Realization
        • Resources
        • Risks
        • Stakeholders
      2. Conduct CIO-CEO Alignment Diagnostic
        Assess the current state of alignment between the CIO and the major stakeholders of the organization.

      See the CEO-CIO Alignment Program for more information.

      Conduct the CEO-CIO Alignment Diagnostic

      Why CEO-CIO Alignment?

      The CEO-CIO Alignment Program helps you understand the gaps between what the CEO wants for IT and what the CIO wants for IT. The program will also evaluate the current state of IT, from a strategic and tactical perspective, based on the CEO’s opinion.

      The CEO-CIO Alignment Program helps to:

      • Evaluate how the executive leadership currently feels about the IT organization’s performance along the following dimensions:
        • IT budgeting and staffing
        • IT strategic planning
        • Degree of project success
        • IT-business alignment
      • Answer the question, “What does the CEO want from IT?”
      • Understand the CEO’s perception of and vision for IT in the business.
      • Define the current and target roles for IT. Understanding IT’s current and target roles, in the eyes of the CEO, is crucial to creating IT governance. By focusing the IT governance on achieving the target role, you will ensure that the senior leadership will support the implementation of the IT governance.

      To conduct the CEO-CIO Alignment Program, follow the steps outlined below.

      1. Select the senior business leader to participate in the program. While Info-Tech suggests that the CEO participate, you might have other senior stakeholders who should be involved.
      2. Send the survey link to your senior business stakeholder and ensure the survey’s completion.
      3. Complete your portion of the survey.
      4. Hold a meeting to discuss the results and document your findings.

      See the CEO-CIO Alignment Program for more information.

      Present the “Make the Case” for IT governance redesign

      Associated Activity icon 1.3 30 minutes

      1. Review Finalized Stakeholder List
        Consolidate a list of the most important and impactful stakeholders who need further convincing to participate in the governance redesign and implementation.
      2. Present the Deck
        Include the information gathered throughout the discovery into the presentation deck and hold a meeting to review the findings.

      Business

      • Shareholders
      • Board
      • Chief Executive Officer
      • Chief Financial Officer
      • Chief Operating Officer
      • Business Executives
      • Strategy Executive Committee
      • Chief Risk Officer
      • Architecture Board
      • Enterprise Risk Committee
      • Head of Human Resources
      • Compliance

      IT

      • Chief Information Officer

      External

      • Government Agency
      • Audit Firm

      Use the Make the Case for an IT Governance Redesign template for more information.

      Create a custom communication plan to facilitate support for the redesign process

      Supporting Tool icon 1B Create a plan to engage the key stakeholders

      INSTRUCTIONS

      1. Identify Stakeholders
        Determine which business stakeholders will be involved (refer to Activity 1.1).
      2. Customize Communication Plan
        Follow up with individual communication plans.

      Info-Tech Best Practice

      Create personal communication plans to provide individualized engagement, instead of assuming that everyone will respond to the same communication style.

      Download the IT Governance Stakeholder Communication Planning Tool for more information.

      Create a communication plan to engage key stakeholders

      Associated Activity icon 1.4 1 hour
      1. Input Stakeholders
        Determine which business stakeholders will be involved (refer to Activity 1.1). Then, insert their position on the power map, the rationale to inform them, the timing of communications, and what inputs they will be needed to provide.

        Stakeholder role

        Power map position

        Why inform them

        When to inform them

        What we need from them

        Chief Executive Officer
        Chief Financial Officer
        Chief Operating Officer
      2. Identify Communication Strategy
        Outline the most effective communication plan for that stakeholder. Identify how to best communicate to the stakeholders to make sure they are appropriately engaged in the redesign process.

        Vehicle

        Audience

        Purpose

        Frequency

        Owner

        Distribution

        Level of detail

        Status Report IT Managers Project progress and deliverable status Weekly CIO, John Smith Email Details for milestones, deliverables, budget, schedule, issues, next steps
        Status Report Marketing Manager Project progress Monthly CIO, John Smith Email High-level detail for major milestone update and impact to the marketing unit

      Establish a collectively agreed upon statement of business context (SoBC)

      Supporting Tool icon 1C Document the mutual understanding of the business context

      INSTRUCTIONS

      1. Review Business Documents
        Review business documents from broad areas of the business to assess the business context.
      2. Analyze Business Frameworks
        Analyze business frameworks to articulate the current and projected future business context.
      3. Brainstorm With Key Stakeholders
        Conduct stakeholder brainstorming efforts to gain insights from key business stakeholders.
      4. Finalize the SoBC
        Document and sign the SoBC with identified stakeholders.

      Info-Tech Best Practice

      Use the Statement of Business Context customizable deliverable as a point of reference that will guide the direction of the governance redesign.

      Use the Statement of Business Context to identify the critical information needed to guide governance

      Components of the SoBC

      1. Mission
        • Who are you as an organization?
        • Who are your internal and external customers?
        • What are your core business functions?

        Example (Higher Education)
        Nurture global leaders and provide avenues for intellectual exploration.
      2. Vision
        • Is your vision statement future-facing?
        • Is your vision statement concise?
        • Is your vision statement achievable?
        • Does your vision statement involve change?

        Example
        Be a catalyst for creating the future leaders of tomorrow through dynamic and immersive educational experiences. The university will be recognized for being a prestigious innovative research hub and educational institution.
      Sample of Info-Tech's Statement of Business Context Template with the Mission and Vision Statements.

      Use the Statement of Business Context to identify the critical information needed to guide governance (cont.)

      More Components of the SoBC

      1. Strategic Objectives
        • What are the strategic initiatives of the organization?
        • Do you have a roadmap to accomplish your mission?
        • What are the primary goals of senior leaders for the organization?

        Example
        1. Meeting government regulation
        2. Revenue generation
        3. Top research quality
        4. High teaching quality
      Sample of Info-Tech's Statement of Business Context Template with Strategic Objectives.
      1. State of Business
        • Consider what the current state and future state are.
        • How does the operating model used define the state?
        • How do industry trends shape the business?
        • What internal changes impact the business model?

        Example
        Our organization aims to make quick decisions and navigate the fast-paced industry with agility, uniting the development and operational sides of the business.
      Sample of Info-Tech's Statement of Business Context Template with State of the Business.

      Leverage core concepts to determine the direction of the organization’s state of the business

      1. Mission
      2. Vision
      3. Strategic Objectives
      –›
      1. State of Business

      2. Work through if your organization’s state is small vs. large, public vs. private, and lean vs. DevOps vs. traditional.

      Small

      IT team is 30 people or less.

      Large

      IT team is more than 30 people.

      Public

      Wholly or partly funded by the government.

      Private

      No government funding is provided.
      Lean: The business aims to eliminate any waste of resources (time, effort, or money) by removing steps in the business process that do not create value. Devops/Agile: Our organization aims to make quick decisions and navigate the fast-paced industry with agility. Uniting the development and operational sides of the business. Hierarchical: Departments in the organization are siloed by function. The organization is top-down and hierarchical, and takes more time with decision making.

      ‹– Multi-State (any combination) –›

      Review business documents to assess business context

      Associated Activity icon 1.5 2-4 hours

      INPUT: Strategic Documents, Financial Documents

      OUTPUT: Mission, Vision, Strategic Objectives

      Materials: Corporate Documents

      Participants: IT Governance Redesign Owner

      Start assessing the state of the business context by leveraging easily accessible information. Many organization have strategic plans, documents, and presentations that already include a large portion of the information for the SoBC – use these sources first.

      Instructions

      1. Strategic Documents
        Leverage your organization’s strategic documents to gain understanding of the business context.

      2. Documents to Review:
      • Corporate strategy document.
      • Business unit strategy documents.
      • Annual general reports.
    • Financial Documents
      Leverage your organization’s financial documents to gain understanding of the business context.

    • Documents to Review:
      • Look for large capital expenditures.
      • Review operating costs.
      • Business cases submitted.

      Review strategic planning documents

      Overview

      Some organizations (and business units) create an authoritative strategy document. These documents contain the organization’s corporate aspirations and outline initiatives, reorganizations, and shifts in strategy. Additionally, some documents contain strategic analysis (Porter’s Five Forces, etc.).

      Action

      • Read through any of the following:
        • Corporate strategy document
        • Business unit strategy documents
        • Annual general reports
      • Watch out for key future-looking words:
        • We will be…
        • We are planning to…

      Overt Statements

      • Corporate objectives and initiatives are often explicitly stated in these documents. Look for statements that begin with phrases such as “Our corporate objectives are…”
      • Remember that different organizations use different terminology – if you cannot find the word “goal” or “objective” then look for “pillar,” “imperative,” “theme,” etc.
      • Ask a business partner to assist if you need some help.

      Covert, Outdated, and Non-Existent Statements

      • Some corporate objectives and initiatives will be mentioned in passing and will require clarification, for example:
        “As we continue to penetrate new markets, we will be diversifying our manufacturing geography to simplify distribution.”
      • Some corporate strategies may be outdated and therefore of limited use for understanding the state of business – validate the statement to ensure it is up to date.
      • Some organizations lack a strategic plan altogether. Use stakeholder interviews to identify imperatives and validate conflicting statements before moving on.

      Review financial documentation

      Overview

      Departmental budgets highlight the new projects that will launch in the next fiscal year. The overwhelming majority of these projects will have IT implications. Additionally, identifying where the department is spending money will allow you to identify business unit initiatives and operational change.

      Action

      • Scan budgets:
        • Look for large capital expenditures
        • Review operating costs
        • Review business cases submitted
      • Look for abnormalities or changes:
        • What does an increase in spending mean?
        • Does IT need to change as a result?

      Capital Budgets

      • Capital expenditures are driven by projects, which map to corporate goals and initiatives.
      • Look for large capital expenditures and cross-reference the outflows with any project plans that have been collected.
      • If an expenditure cannot be explained by project plans, request additional information.

      Operating Budgets

      • Major changes to operating costs typically reflect changes to a business unit. Some of these changes affect IT capabilities and can be classified as corporate initiatives.
      • Changes that should be classified as corporate initiatives are expansion or contraction of a labor force, outsourcing initiatives, and significant process changes.
      • Changes that should not be classified as corporate initiatives are changes in third-party fees, consulting engagements, and changes caused by inflation or growth.

      Analyze business frameworks to articulate context

      Associated Activity icon 1.6 2-4 hours

      INPUT: Industry Research, Organizational Research, Analysis Templates

      OUTPUT: PESTLE and SWOT Analysis

      Materials: Computer or Whiteboards and Markers

      Participants: IT Governance Redesign Owner

      If corporate documents denoting the key components of the SoBC are not easily available, or do not provide all information required, refer to business analysis frameworks to discover internal and external trends that impact the mission, vision, strategic objectives, and state of the business.

      1. Conduct a PESTLE Analysis
        The PESTLE analysis will support the organization in identifying external factors that impact the business. Keep watch for trends and changes in the industry.
      2. Political

        Economic

        Social

        Technological

        Legal

        Environmental

      3. Conduct a SWOT Analysis
        The SWOT analysis will be more specific to the organization and the industry in which it operates. Identify the unique strengths, weaknesses, opportunities, and threats for your organization.
      4. Strengths

        Weaknesses

        Opportunities

        Threats

      Conduct a PESTLE analysis

      Associated Activity icon 1.6 Conduct a PESTLE analysis
      • Break participants into teams and divide the categories amongst them:
        • Political trends
        • Economic trends
        • Social trends
        • Technological trends
        • Legal trends
        • Environmental trends
      • Have each group identify relevant trends under their respective categories. You must relate each trend back to the business by considering:
        • How does this affect my business?
        • Why do we care?
      • Use the prompt questions on the next slide to help the brainstorming process.
      • Have each team present its list and have remaining teams give feedback and additional suggestions.

      Political. Examine political factors such as taxes, environmental regulations, and zoning restrictions.

      Economic Examine economic factors such as interest rates, inflation rate, exchange rates, the financial and stock markets, and the job market.

      Social. Examine social factors such as gender, race, age, income, disabilities, educational attainment, employment status, and religion.

      Technological. Examine technological factors such as servers, computers, networks, software, database technologies, wireless capabilities, and availability of software as a service.

      Legal. Examine legal factors such as trade laws, labor laws, environmental laws, and privacy laws.

      Environmental. Examine environmental factors such as green initiatives, ethical issues, weather patterns, and pollution.

      Download Info-Tech’s PESTLE Analysis Template to help get started.

      Review these questions to help you conduct a PESTLE analysis

      For each prompt below, always try to answer the question: how does this affect my business?

      Political

      • Will a change in government (at any level) affect your organization?
      • Do inter-government or trade relations affect you?
      • Are there shareholder needs or demands that must be considered?

      Economical

      • How are your costs changing (moving off-shore, fluctuations in markets, etc.)?
      • Do currency fluctuations have an effect on your business?
      • Can you attract and pay for top-quality talent (e.g. desirable location, reasonable cost of living, changes to insurance requirements)?

      Social

      • What are the demographics of your customers or employees?
      • What are the attitudes of your customers or staff (do they require social media, collaboration, transparency of costs, etc.)?
      • What is the general lifecycle of an employee (i.e. is there high turnover)?
      • Is there a market of qualified staff?
      • Is your business seasonal?

      Technological

      • Do you require constant technology upgrades (faster network, new hardware, etc.)?
      • What is the appetite for innovation within your industry or business?
      • Are there demands for increasing data storage, quality, BI, etc.?
      • Are you looking at cloud technologies?
      • What is the stance on “bring your own device”?
      • Are you required to do a significant amount of development work in-house?

      Legal

      • Are there changes to trade laws?
      • Are there changes to regulatory requirements, e.g. data storage policies or privacy policies?
      • Are there union factors that must be considered?

      Environmental

      • Is there a push towards being environmentally friendly?
      • Does the weather have any effect on your business (hurricanes, flooding, etc.)?

      Conduct a SWOT analysis on the business

      Associated Activity icon 1.6 Conduct a business SWOT analysis

      Break the group into two teams.

      Assign team A internal strengths and weaknesses.

      Assign team B external opportunities and threats.

      • Have the teams brainstorm items that fit in their assigned grids. Use the prompt questions on the next slide to help you with your SWOT analysis.
      • Pick someone from each group to fill in the grids on the whiteboard.
      • Conduct a group discussion about the items on the list. Identify implications for IT and opportunities to innovate as you did for the other business and external drivers.
      Helpful
      to achieve the objective
      Harmful
      to achieve the objective
      Internal Origin
      attributes of the organization
      Strength Weaknesses
      External Origin
      attributes of the environment
      Opportunities Threats

      Download Info-Tech’s Business SWOT Analysis Template to help get started.

      Review these questions to help you conduct your SWOT analysis on the business

      Strengths (Internal)

      • What competitive advantage does your organization have?
      • What do you do better than anyone else?
      • What makes you unique (human resources, product offering, experience, etc.)?
      • Do you have location advantages?
      • Do you have price, cost, or quality advantages?
      • Does your organizational culture offer an advantage (hiring the best people, etc.)?

      Weaknesses (Internal)

      • What areas of your business require improvement?
      • Are there gaps in capabilities?
      • Do you have financial vulnerabilities?
      • Are there leadership gaps (succession, poor management, etc.)?
      • Are there reputational issues?
      • Are there factors that are making you lose sales?

      Opportunities (External)

      • Are there market developments or new markets?
      • Industry or lifestyle trends, e.g. move to mobile?
      • Are there geographical changes in the market?
      • Are there new partnerships or M&A opportunities?
      • Are there seasonal factors that can be used to the advantage of the business?
      • Are there demographic changes that can be used to the advantage of the business?

      Threats (External)

      • Are there obstacles that the organization must face?
      • Are there issues with respect to sourcing of staff or technologies?
      • Are there changes in market demand?
      • Are your competitors making changes that you are not making?
      • Are there economic issues that could affect your business?

      Conduct brainstorming efforts to gain insights from key business stakeholders

      Associated Activity icon 1.7 2-4 hours

      INPUT: SoBC Template

      OUTPUT: Completed SoBC

      Materials: Computer, Phone, or Other Mechanism of Connection

      Participants: CEO, CFO, COO, CMO, CHRO, and Business Unit Owners

      There are two ways to gather primary knowledge on the key components of the SoBC:

      1. Stakeholder Interviews
        Approach each individual to have a conversation about the key components of the SoBC. Go through the SoBC and fill it in together.
      2. Stakeholder Survey
        In the case that you are in a very large organization, create a stakeholder survey. Input the key components of the SoBC into an online survey maker and send it off the key stakeholders.

      Use the SoBC as the guide to both the interview and the survey. Be clear about the purpose of understanding the business context when connecting with key business stakeholders to participate in the brainstorming. This is a perfect opportunity to establish or develop a relationship with the stakeholders who will need to buy into the redesigned governance framework since it will involve and impact them significantly.

      Go directly to the information source – the key stakeholders

      Overview

      Talking to key stakeholders will allow you to get a holistic view of the business strategy. You will be able to ask follow-up questions to get a better understanding of abstract or complex concepts. Interviews also allow you to have targeted discussions with specific stakeholders who have in-depth subject-matter knowledge.

      Action

      • Talk to key stakeholders:
        • Structure focused, i.e. CEO or CFO
        • Customer focused, i.e. CMO or Head of Sales
        • Operational focused, i.e. COO
        • Lower-level employees or managers
      • Listen for key pains that IT could alleviate.

      Overcome the Unstructured Nature of Interviews

      • Interviewees will often explicitly state objectives and initiatives.
      • However, interviews are less formal and less structured than objective-oriented strategy documents. Objectives are often stated using informal language.
        “We’re talking rev gen here. That’s the name of the game. If we can get a foothold in India, there’s huge upside potential.” (VP Marketing)
      • Further analysis might translate this into a corporate imperative: increase revenue by growing our market share in India to 8% by January of next year.
      • If an imperative is unclear, ask the stakeholder for more detail.
      • Understand how key stakeholders evaluate, direct, and monitor their own areas of the business; this will give you insight as to their style.

      Receive final sign-off to proceed with developing the IT governance redesign

      Associated Activity icon 1.8 30 minutes

      Document any project assumptions or constraints. Before proceeding with the IT governance activities, validate the statement of business context with senior stakeholders. When consensus has been reached, have them sign the final page of the document.

      How to ensure sign-off:

      • Schedule a meeting with the senior stakeholders and conduct a review of the document. This meeting presents a great opportunity to deliver your interpretation of management expectations and make any modifications.
      • Obtaining stakeholder approval in person ensures there is no miscommunication or misunderstandings around the tasks that need to be accomplished to develop a successful IT governance.
      • This is an iterative process; if senior stakeholders have concerns over certain aspects of the document, revise and review again.
      • Final sign-off should only take place when mutual understanding has been reached.

      Download the SoBC Template and complete for final approval.

      Info-Tech Tip

      In most circumstances, you should have the SoBC validated with the following stakeholders:

      • CIO
      • CEO
      • CFO
      • Business Unit Leaders

      Understand the business context to set the foundation for governance redesign

      CASE STUDY

      Industry: Healthcare
      Source: Info-Tech

      Challenge

      The new business direction to become an integrator shifted focus to faster software iteration and on enabling integration and translation technologies, while moving away from creating complete, top-to-bottom IT solutions to be leveraged by clinicians and patients.

      Internal to the IT organization, this created a different in perspective on what was important to prioritize: foundational elements, web services, development, or data compliance issues. There was no longer agreement on which initiatives should move forward.

      Solution

      A series of mandatory meetings were held with key decision makers and SMEs within the organization in order to re-orient everyone on the overall purpose, goals, and outcomes of the organization.

      All attendees were asked to identify what they saw as the mission and vision of the organization.

      Finally, clinicians and patient representatives were brought in to describe how they were going to use the services the organization was providing and how it would enable better patient outcomes.

      Results

      Identifying the purpose of the work the IT organization was doing and how the services were going to be used realigned the different perspectives in the context of the healthcare outcomes they enabled.

      This activity provided a unifying view of the purpose and the state of the business. Understanding the business context prepared the organization to move forward with the governance redesign.

      If you want additional support, have our analysts guide you through this phase as part of an Info-Tech Workshop Associated Activity icon

      Book a workshop with our Info-Tech analysts:

      Photo of an Info-Tech analyst.
      • To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.
      • Info-Tech analyst will join you and your team onsite at your location or welcome you to Info-Tech's historic Toronto office to participate in an innovative onsite workshop.
      • Contact your account manager (www.infotech.com/account), or email Workshops@InfoTech.com for more information.

      The following are sample activities that will be conducted by Info-Tech analysts with your team:

      1.1

      Sample of activity 1.1 'Determine which business stakeholders will be impacted or involved in the redesign process'. Identify Relevant Stakeholders

      Build a list of relevant stakeholders and identify their position on the stakeholder power map.

      1.4

      Sample of activity 1.4 'Create a communication plan to engage key stakeholders'. Communication Plan

      Build customized communication plans to engage the key stakeholders in IT governance redesign.

      If you want additional support, have our analysts guide you through this phase as part of an Info-Tech Workshop

      Book a workshop with our Info-Tech analysts:

      1.7

      Sample of activity 1.7 'Review business documents to assess business context'. Gather Business Information

      Review business documents, leverage business analysis tools, and brainstorm with key executives to document the Statement of Business Context.

      1.8

      Sample of activity 1.8 'Receive final sign-off to proceed with developing the IT Governance redesign'. Finalize the Statement of Business Context

      Get final approval and acceptance on the Statement of Business Context that will guide your redesign.

      Improve IT Governance to Drive Business Results

      PHASE 2

      Assess the Current Governance Framework

      Phase 2 outline

      Associated Activity icon Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

      Complete these steps on your own, or call us to complete a guided implementation. A guided implementation is a series of 2-3 advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

      Guided Implementation 2: Assess the Current Governance Framework

      Proposed Time to Completion: 2 weeks
      Step 2.1: Outline the Current State AssessmentStep 2.2: Review the Current State Assessment
      Start with an analyst kick-off call:
      • Connect the current business state identified in Phase 1 with the current state of governance.
      • Identify the key elements of current governance.
      • Begin building the structure and committee profiles.
      Review findings with analyst:
      • Review the current governing bodies that were identified.
      • Review the current structure that was identified.
      • Determine the strengths, weaknesses, and guidelines from the implications in the current state assessment.
      Then complete these activities…
      • Identify stakeholders.
      • Make the case to executives.
      • Build a communication plan.
      Then complete these activities…
      • Create committee profiles.
      • Build governance structure map.
      With these tools & templates:
      • Current State Assessment of IT Governance
      With these tools & templates:
      • Current State Assessment of IT Governance

      Phase 2: Assess the Current Governance Framework

      1 2 3 4
      Align IT With the Business Context Assess the Current Governance Framework Redesign the Governance Framework Implement Governance Redesign

      Activities:

      • 2.1 Create Committee Profiles
      • 2.2 Build a Governance Structure Map
      • 2.3 Establish Governance Guidelines

      Outcomes:

      • Use the Current State Assessment of IT Governance to determine governance guidelines.

      Info-Tech Insight

      Don’t be passive; take action! Take an active approach to revising your governance framework. Understand why you are making decisions before actually making them.

      Explore the current governance that exists within your organization

      Your current governance framework will give you a strong understanding of the way the key stakeholders in your business currently view IT governance.

      "Much of the focus of governance today has been on the questions:
      • Are we doing [things] the right way?
      • And are we getting them done well?"
      –› "We need to shift to…
      • Are we doing the right things?
      • Are we getting the benefits?
      • What are the outcomes?
      • What do we want to achieve?
      • How do we make intelligent decisions about what will help us achieve those outcomes?"
      (John Thorp, Author of The Information Paradox)

      Leverage this understanding of IT governance to determine where governance is occurring and how it transpires.

      Conduct a current state assessment

      Supporting Tool icon 2A Assess the current governance framework

      Use this tool to critically assess each governing body to determine the areas of improvement that are necessary in order to achieve optimal business results.

      1. Identify All Governing Bodies
        Some bodies govern intentionally, and some govern through habit and practice. Outline all bodies that take on an element of governance.
      2. Create a Governance Structure Map
        Configure the structural relationships for the governing bodies using the structure map.
      3. Reveal Strengths and Weaknesses
        Identify the strengths and weaknesses of the governance structure, authority definitions, processes, and membership.
      4. Establish Governance Guidelines
        Based on the SoBC, express clear and applicable guidelines to improve on the weaknesses while retaining the strengths of your governance framework.

      Download the Current State Assessment of IT Governance to work toward these outcomes

      Conduct a current state assessment to identify governance guidelines

      Supporting Tool icon 2A Assess the current governance framework

      How to use the Current State Assessment of IT Governance deliverable: Follow the steps below to create a cohesive understanding of the current state of IT governance and the challenges that the current system poses.

      Part A – Committee Profiles

      1. Identify Governing Bodies
      2. Leverage Committee Templates
      3. Create Committee Profiles
        Use the Committee Profile Template

      Part B – Structure Map

      1. Assess Inputs and Outputs to Express Structural Relationships
      2. Create Structure Map
        Use the Governance Structure Map

      Part C – Governance Guidelines

      1. Choose Operating Model Template
      2. Identify Strengths and Weaknesses
      3. Establish Governance Guidelines
        Use the Governance Guideline Template

      What makes up the “governance framework”?

      There are four major elements of the governance framework:

      1. Structure
        Structural relationships are shown by mapping the connections between committees.
      2. Authority
        Each committee will have a purpose and area of decision making that it is accountable for.
      3. Process
        The process includes the inputs, outputs, and activities required for the committee to function.
      4. Membership The individuals or roles who sit on each committee. Take into account members’ knowledge, capability, and political influence.

      Create governing board or committee profiles

      Supporting Tool icon 2A.1 Assess the current governance framework

      Part A – Committee Profiles

      1. Identify Governing Bodies

        Establish where governance happens and who is governing. For different organizations, the governance framework will contain a variety of governing bodies or people. Use a list format to identify governing bodies that exist in your organization.
      2. Leverage Committee Templates

        Use the templates provided. Create a profile for each governing body that currently operates in your IT governance framework as listed in step 1.
      3. Create Committee Profiles

        Identify what they are governing and how they are governing.
        Using the profiles created in step 2, identify each body’s membership roles, purpose, decision areas, inputs, and outputs. Refer to the example text in the template to guide you, but feel free to adjust the text to reflect the reality of your governing body. Screenshot of the 'Committee Template - Executive Management Committee'.
        Consider the following domains of governance:
        (refer to Executive Brief)
        • Benefits realization
        • Risks
        • Resources
        Refer to our examples for some common governing bodies.

      Consistently define the components of governance in the committee profiles

      Membership

      Membership Roles
      Insert information here that reflects who the individuals are that sit on that governing body and what their role is. Include other important information about the individuals’ knowledge, skills, or capabilities that are relevant.

      Authority

      Purpose
      Define why the committee was established in the first place.

      Decision Areas
      Explain the specific areas of decision making this group is responsible for overseeing.

      Process

      Inputs
      Consider the information and materials that are needed to make decisions.

      Outputs
      Describe the outcomes of the committee. Think about decisions that were made through the governance process.

      Screenshot of the components of governance section from the 'Committee Template'.

      Map out relationships on the Governance Map

      Supporting Tool icon 2A.2 Assess the current governance framework

      Part B – Structure Map

      Structure
      1. Assess Inputs and Outputs

        Governing Bodies

        Inputs

        Outputs

        Committee #1
        Committee #2
        Committee #3
        CFO
        IT Director
        CIO
        To understand relationships between governing bodies, list the inputs and outputs for each unique committee that rely on other committees in the table provided.
      2. Create Structure Map
        Sample of the 'Current State Structure Map'. Using the outline provided, create your own governance structure map to represent the way the governing bodies interact and feed into each other. This is crucial to ensure that the governing structure is streamlined. It will ensure that communication occurs efficiently and that there are no barriers to making decisions swiftly.

      Outline the governance structure in the governance structure map

      Associated Activity icon 2.2 30 minutes
      The 'Current State Structure Map' from the last slide, but with added description. There are three tiers of groups. At the bottom is 'Run', described as 'The lowest level of governance will be an oversight of more specific initiatives and capabilities within IT.' 'Design and Build', described as 'The second tier of groups will oversee prioritization of a certain area of governance as well as second-tier decisions that feed into strategic decisions.' At the top is 'Strategy', described as 'These groups will focus on decisions that directly connect to the strategic direction of the organization.' The specific groups laid out in the map are 'Risk and Compliance Committee' which straddle the line between 'Run' and 'Design and Build', 'Portfolio Review Board' and 'IT Steering Committee (ITSC)' both of which straddle the line between 'Design and Build' and 'Strategy', 'Executive Management Committee (EMC)' which is in 'Strategy', and 'Other' in all tiers.

      Identify strengths and weaknesses of the governance framework

      Supporting Tool icon 2A.3 Assess the current governance framework

      Part C – Governance Guidelines

      1. Choose Business State Template Choose the template that represents the identified future state of business in the Statement of Business Context. Mini sample of the 'State of Business' table from the 'Statement of Business Context'.
      2. Identify Strengths and Weaknesses Input the major strengths and weaknesses of your governance that were highlighted in the brainstorming activity. Mini sample of a Strengths and Weaknesses table.
      3. Establish Governance Guidelines Draw your own implications from the strength and weaknesses that will drive the design of your governance in its future state. These guidelines should be concise and easy to implement. Mini sample of an expanded Strengths and Weaknesses table including a row for 'Implication/Guideline'. Note: Refer to the example guidelines in the Current State Assessment of IT Governance after you have considered your own specific guidelines. The examples are supplementary for your convenience.

      Distinguish your business state from the others to ensure implications act as accurate guidelines

      Business State Options

      1

      Small

      IT team is 30 people or less.

      Large

      IT team is more than 30 people.

      2

      Public

      Wholly or partly funded by the government.

      Private

      No government funding is provided.

      3

      Lean: The business aims to eliminate any waste of resources (time, effort, or money) by removing steps in the business process that do not create value.Devops: Our organization aims to make quick decisions and navigate the fast-paced industry with agility. Uniting the development and operational sides of the business. Hierarchical: Departments in the organization are siloed by function. The organization is top-down and hierarchical, and takes more time with decision making.

      ‹– Multi-State (any combination) –›

      Multi-State Example A: If you are small organization that is publicly funded and you are shifting towards a lean methodology, combine the implications of all those groups in a way that fits your organization.

      Multi-State Example B: Your organization is shifting from a more traditional state of operating to combining the development and operations groups. Use hierarchical implications to govern one group and DevOps implications for the other.

      Identify strengths and weaknesses of the governance framework

      Associated Activity icon 2.3 2 hours

      INSTRUCTIONS

      1. Input Strengths of Governance
        Include useful components of the current framework; that may include elements that are operating well, fit the future state, or are required due to regulations or statutes.
      2. Determine Weaknesses and Challenges
        Discuss the pain points of the current governance framework by looking through the lenses of structure, authority, process, or membership.

      Consider:

      • Where is governance not meeting expectations?
      • Are we doing the right things?
      • Are we getting the benefits?
      • What are the outcomes?
      • What do we want to achieve?
      • How do we make intelligent decisions about what will help us achieve those outcomes?
      *Example

      Structure

      Authority

      Process

      Membership

      Strength

      • We must maintain a legal compliance committee due to the high level of legislation in the industry
      • The ITSC gathers and prioritizes investment options, saving time for the EMC
      • The EMC only make decisions on investments that are greater than $200,000
      • The legal board has a narrow focus, allowing it to maintain its necessary purpose efficiently
      • The information flow from ITSC to the EMC allows the EMC to spend their time effectively
      • The CIO sits on the EMC and the ITSC
      • The EMC is made up of senior leadership who have stakes in all areas of the business

      Weakness

      • Wrong number (too many/little groups)
      • Relationship is misaligned (input/output problems)
      • The tier it sits on the map is misguided
      • Duplication of the same tier of decisions in different groups
      • Approval for one specific topic occurs in more than one group
      • Lack of clarity in which group makes which decisions
      • Intake – where the information is coming from is the wrong source/inaccurate
      • Time to decision (too slow)
      • Poor results of governance (redoing projects, low value)
      • There is lack of knowledge in committee membership
      • Misplaced seniority (too Jr./Sr.)
      • Lack of representation in group (breadth across the business or depth of specific area)

      Derive governance implications from strengths and weaknesses

      Associated Activity icon 2.3 2-4 hours

      INSTRUCTIONS

      1. Copy and paste your strengths and weaknesses from part B into the template that reflects your business state.
      2. Draw your own implications from the strengths and weaknesses that will drive the design of your governance in its future state. These guidelines should be concise and practical.
      *Example

      Structure

      Authority

      Process

      Membership

      Strength

      Weakness

      Implication / Guideline

      • Make sure that the decision-making authority for most areas are at the lower tier
      • Governing bodies should be lower in the organization
      • One overarching governing body – directing priorities
      • High authority at a lower point of the organization
      • Highest tier is responsible for major budget shifts
      • High-level tier - reporting and feed in from lower level groups
      • Prioritization and sequencing occur at the mid-tier
      • Lowest governing tiers will have direct links to the customer to allow for interaction
      • Project or initiative owner as the leader of the body

      Note: Use the examples of guidelines provided in the Current State Assessment of IT Governance to help formulate your own.

      Conduct a current state assessment to identify guidelines for the future state of governance

      CASE STUDY

      Industry: Healthcare
      Source: Anonymous

      Challenge

      Over time, the organization had to create a large amount of governing committees and subcommittees in order to comply with governance frameworks applied to them and to meet regulatory compliance requirements.

      The current structure was no longer optimal to meet the newly identified mandate of the organization. However, the organization did not want to start from scratch and scrap the elements that worked, such as the dates and times that had been embedded into the organization.

      Solution

      A current state assessment was planned and executed in order to review what was currently being done and identify what could be retained and what should be added, changed, or removed to improve the governance outcomes.

      The scope involved examining how current and near-term governance needs were, or were not, met through the existing structure, bodies, and their processes.

      The organization investigated governance approaches of organizations with similar governance needs and with similar constraints to model their own.

      Results

      The outputs of this exercise included:

      • A list of effective practices and committee guidelines that could be leveraged with little to no change in the future state.
      • A list of opportunities to streamline the structure and processes.

      These guidelines were used to drive recommendations for improvements to the governance structures and processes in the organization.

      If you want additional support, have our analysts guide you through this phase as part of an Info-Tech Workshop Associated Activity icon

      Book a workshop with our Info-Tech analysts:

      Photo of an Info-Tech analyst.
      • To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.
      • Info-Tech analyst will join you and your team onsite at your location or welcome you to Info-Tech's historic Toronto office to participate in an innovative onsite workshop.
      • Contact your account manager (www.infotech.com/account), or email Workshops@InfoTech.com for more information.

      The following are sample activities that will be conducted by Info-Tech analysts with your team:

      2.1

      Sample of activity 2.1 'Outline the governance structure in the governance structure map'. Create Current State Structure and Profiles

      Take the time to clearly articulate the current governance framework of your organization. Outline the structure and build the committee profiles for the governing bodies in your organization.

      2.3

      Sample of activity 2.3 'Identify strengths and weaknesses of the governance framework'. Determine Strengths, Weaknesses, and Guidelines

      Evaluate the strengths of your governance framework, the weaknesses that it exhibits, and the guidelines that will help maintain the strengths and alleviate the pains.

      Improve IT Governance to Drive Business Results

      PHASE 3

      Redesign the Governance Framework

      Phase 3 Guided Implementation

      Associated Activity icon Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

      Complete these steps on your own, or call us to complete a guided implementation. A guided implementation is a series of 2-3 advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

      Guided Implementation 3: Redesign the Governance Framework

      Proposed Time to Completion: 4 weeks
      Step 3.1: Understand the Redesign Process Step 3.2: Review Governance Structure Step 3.3: Review Governance Committees
      Start with an analyst kick-off call:
      • Review the guidelines from the current state assessment.
      • Begin modifying the governance structure, authorities, processes, and memberships.
      Review findings with analyst:
      • Determine the impact of the guidelines on the structural layout of the framework.
      • Determine the impact of the guidelines on the authority element of the framework.
      Finalize phase deliverable:
      • Determine the impact of the guidelines on the processes within the framework.
      • Determine the impact of the guidelines on the membership element of the framework.
      Then complete these activities…
      • Break down guidelines to make sure they are actionable and realistic.
      • Identify what to add, modify, or remove.
      • Review additional sources of information.
      Then complete these activities…
      • Build and review the governance structure map.
      • Identify additions, changes, or reductions in governing bodies and their areas of authority.
      Then complete these activities…
      • Use the template provided to build committee profiles for each identified committee.
      • Identify the membership, purpose, decision areas, inputs, and outputs of each.
      • Build committee charters if needed.
      With these tools & templates:
      • Current State Assessment
      • Future State Design for IT Governance
      With these tools & templates:
      • Future State Design for IT Governance
      With these tools & templates:
      • Future State Design for IT Governance
      • IT Governance Terms of Reference

      Phase 3: Redesign the Governance Framework

      1 2 3 4
      Align IT With the Business Context Assess the Current Governance Framework Redesign the Governance Framework Implement Governance Redesign

      Activities:

      • 3.1 Build a Governance Structure Map
      • 3.2 Create Committee Profiles
      • 3.3 Leverage Process-Specific Governance Blueprints

      Outcomes:

      • Use the Future State Design for IT Governance template to build the optimal governance framework for your organization.

      Info-Tech Insight

      Keep the current and future goals in sight to build an optimized governance framework that maintains the minimum bar of oversight required.

      Anticipate the outcomes of the Future State Design for IT Governance tool

      Supporting Tool icon 3A Redesign the governance frameworks

      Use this tool to guide your organization toward transformative outcomes gleaned from an optimized governance framework.

      1. Implement Structural Guidelines
        Determine what governing bodies to add, change, or remove from your governance structure.
      2. Create a Governance Structure Map
        Configure the structural relationships for the redesigned governing bodies using the structure map.
      3. Build Effective Committees
        Use the IT Governance Terms of Reference to build profiles for each newly created committee and to alter any existing committees.
      4. Determine Follow-up Governance Support
        Access external material on governance from other Info-Tech blueprints that will help with specific governance areas.

      Download the Future State Design for IT Governance template to work toward these outcomes.

      Use the Future State Design for IT Governance tool to create a custom governance framework for your organization

      Supporting Tool icon 3A Redesign the governance frameworks

      How to use the Future State Design for IT Governance deliverable: Follow the steps below to redesign the future state of IT governance. Use the guidelines to respond to challenges identified in the current governance framework based on the current state assessment.

      Part A – Structure Map

      Part B – Committee Profiles

      1a. Input Structural Guidelines 1b. Input Authority Guidelines 1a. Input Process Guidelines 1b. Input Member Guidelines
      2. Guiding Questions
      Do governing bodies operate at a tier that matches the guidelines?

      Do governing bodies focus on the decisions that align with the guidelines?
      2. Guiding Questions
      Do the process inputs and outputs reflect the structure and authority guidelines?

      Do governing bodies engage the right people who have the roles, capacity, and knowledge to govern?
      3. Add / Change (Tier/Authority) / Remove
      Governing Bodies – Structure
      3. Adapt / Refine
      Governing Bodies – Profiles
      4. Use the Structure Map to Show Redesign Use the IT Governance Terms of Reference for Redesign

      Connect key learnings to initiate governance redesign

      The future state design will reflect the state of business that was identified in Phase 1 along with the guidelines defined in Phase 2 to build a governance framework that promotes business-IT fusion.

      Statement of Business Context –› Current State Assessment

      Identified Future Business State

      Structure
      Authority

      Leverage the structure and authority guidelines to build the governance structure.

      Defined Governance Guidelines

      Process
      Membership

      Leverage the process and membership guidelines to build the governance committees.

      Future State Design

      Use structure and authority guidelines to build a new governance structure map

      Supporting Tool icon 3A.1 Redesign the governance frameworks

      Part A – Structure Map

      Structure
      Authority
      1a. Structural Guidelines1b. Authority Guidelines
      Input the guidelines from the current state assessment to guide the redesign.

      2. Leverage Guiding Questions

      Use the guiding questions provided to assess the needed changes.
      Guiding Questions


      Do governing bodies operate at a tier that matches the guidelines?


      Do governing bodies focus on the decisions that align with the guidelines?
      Build the “where/why” of governance. Consider at what tier each committee will reside and what area of governance will be part of its domain. Modify the current structure; do not start from scratch.

      3. Add / Change (Tier/Authority) / Remove

      Determine changes to structure or authority that will be occurring for each of the current governing bodies. Work within the current structure as much as possible.A mini sample of an 'Add/Change/Remove' table for governing bodies.

      4. Use the Structure Map to Show Redesign

      Create your own governance structure map to represent the way the governing bodies interact and feed into each other. A mini sample of the 'Current State Structure Map' from before.

      Maintain as much of the existing framework as possible in the redesign

      Associated Activity icon 3.1 2-4 hours

      Future State Design

      • Structure
      • Authority

      Info-Tech Best Practice

      Keep the number of added or removed committees as low as possible, while still optimizing. The less change to the structure, the easier it will be to implement.

      Refer to the example to help guide your committee redesign.

        Determine:
      1. Do the guidelines impact committees you already have? Will you have to modify the tier or the authority of those committees?
      2. Do the guidelines require you to build a new committee to meet needs?
      3. Do the guidelines require you to remove a committee that isn’t necessary?

      All Governing Bodies

      Add

      Change

      Remove

      ITSC Structure

      Authority
      Delegate the authority of portfolio investment decisions over $200K to this body
      Portfolio Review Board This committee no longer needs to exist since its authority of portfolio investment decisions over $200K has been redelegated
      Risk and Compliance Committee Create a new governing body to address increasing risk and compliance issues that face the organization

      Outline the new governance structure in the governance structure map in the Future State Design for IT Governance tool

      Associated Activity icon 3.1 The 'Current State Structure Map' from before, but with some abbreviated terms. There are three tiers of groups. At the bottom is 'Run', described as 'The lowest level of governance will be an oversight of more specific initiatives and capabilities within IT.' 'Design and Build', described as 'The second tier of groups will oversee prioritization of a certain area of governance as well as second-tier decisions that feed into strategic decisions.' At the top is 'Strategy', described as 'These groups will focus on decisions that directly connect to the strategic direction of the organization.' The specific groups laid out in the map are 'Risk and Compliance Committee' which straddle the line between 'Run' and 'Design and Build', 'Portfolio Review Board' and 'ITSC' both of which straddle the line between 'Design and Build' and 'Strategy', 'EMC' which is in 'Strategy', and 'Other' in all tiers.

      Use process and membership guidelines along with the IT Governance Terms of Reference to build committees

      Supporting Tool icon 3A.2 Redesign the governance frameworks

      Part B – Committee Profiles

      Process
      Membership
      1a. Process Guidelines 1b. Authority Guidelines
      Input the guidelines from the current state assessment to guide the redesign.

      2. Leverage Guiding Questions

      Use the guiding questions provided to assess the needed changes.
      Guiding Questions
      Do the process inputs and outputs reflect the structure and authority guidelines?

      Do governing bodies engage the right people who have the roles, capacity, and knowledge to govern?
      Build the “what/how” of governance. Build out the process and procedures that each committee will use.

      3. Adapt / Refine Governing Body Profiles

      Using your customized guidelines, create a profile for each committee.

      We have provided templates for some common committees. To make these committee profiles reflective of your organization, use the information you have gathered in your Current State Assessment of IT Governance guidelines.

      For a more detailed approach to building out specific charters for each committee refer to the IT Governance Terms of Reference.

      A mini sample of the 'Committee Template - Executive Management Committee'.

      A mini sample of the 'IT Governance Terms of Reference'.

      Use the IT Governance Terms of Reference to establish operational procedures for governing bodies

      Associated Activity icon 3.2 3-6 hours

      Future State Design

      • Process
      • Membership

      Info-Tech Best Practice

      The people on the committee matter. Governance committee membership does not have to correspond with the organizational structure, but it should correspond with the purpose and decision areas of the governance structure.

      Refer to the example to help guide your committee redesign.

        Determine:
      1. Do the guidelines alter the members needed to achieve the outcomes?
      2. Do the guidelines change the purpose and decision areas of the committee?
      3. How do the new structure’s guidelines impact the inputs and outputs of the governing body?

      Screenshot of the 'Committee Template - Executive Management Committee'.

      Add depth to the committee profiles using the IT Governance Terms of Reference

      Supporting Tool icon 3A.3 Redesign the governance frameworks

      Refer to the sections outlined below to build a committee charter for your governance committees. Four examples are provided in the tool and can be edited for your convenience. They are: Executive Management Committee, IT Steering Committee, Portfolio Review Board, and Risk and Compliance Committee.

      1. Purpose
      2. Goals
      3. Responsibilities
      4. Committee Members
      5. RACI
      6. Procedures
      7. Agenda

      Be sure to embed the domains of governance in the charters so that committees focus on the appropriate elements of benefits realization, risk optimization, and resource optimization.

      Download the IT Governance Terms of Reference for more in-depth committee charters.

      Three pillars of planning effective governance meetings

      The effectiveness of the governance is reliant on the ability to work within operational dependencies that will exist in the governance framework. Consider these questions to guide the duration, frequency, and sequencing of your governing body meetings.

      Frequency

      • What is the quantity of decisions that must be made?
      • Is a rapid or urgent response typically required?

      Duration

      • How long should your meeting run based on your meeting frequency and the volume of work to be accomplished?

      Sequencing

      • Are there other decisions that rely on the outcomes of this meeting?
      • Are there any decisions that must be made first for others to occur?
      A venn diagram of the three pillars of planning effective governance meetings, 'Frequency', 'Duration', and 'Sequencing'.

      Leverage process-specific governance blueprints

      Associated Activity icon 3.3

      If there are specific areas of IT governance that you require further support on, refer to Info-Tech’s library of DIY blueprints, Guided Implementations, and workshops for further support. We cover IT governance in the following areas:

      Enterprise Architecture Governance

      Service Portfolio Governance

      Security Governance

      Titlecard of 'Create a Right-Sized Enterprise Architecture Governance Framework' blueprint. Titlecard of 'Lead Strategic Decision Making With Service Portfolio Management' blueprint. Titlecard of 'Build a Security Governance and Management Plan' blueprint.

      Consider the challenges and solutions when identifying a multi-state reality for your business state

      A multi-state business will face unique challenges in navigating the redesign process with the goal of combining all related business states in governance.

      1. Divergent Governance Models
        Separate the governance groups that need to function differently, and bring them back together at the highest level.
      2. Reflecting the Organizational Structure
        Unlike single-state governance, multi-state organizations should model the governance framework in reflection of the organizational structure.
      3. Combining Implications
        Prioritize which implications are the most important and make sure they work first, then see what else fits (e.g. start with regulation, then insert lean guidelines).

      The multi-state business will not fit into one “box” – consider implications from the overlapping business states.

      As business needs change, ensure that you establish triggers to reassess the design of your governance framework.

      Leverage the outcomes of the Current State Assessment and Statement of Business Context to build the future state

      CASE STUDY

      Industry: Healthcare
      Source: Info-Tech

      Challenge

      Identifying the committees and processes that should be in place in the target state required a lot of different inputs.

      A number of high-profile senior management team members were still resistant to the overall idea of applying governance to their initiatives since they were clinician driven.

      The approach and target state, including the implementation plan, had to be approved and built out.

      Solution

      The information pulled together from the current state assessment, including best practices and jurisdictional scans, were tied together with the updated mandate and future state, and a list of recommended improvements were documented.

      The improvements were presented to the optimization committee and the governance committee members to ensure agreement on the approach and confirm the timeline for agreed improvements.

      Results

      A future state mapping of the new committee structure was created, as well as the revised membership requirements, responsibilities, and terms of reference.

      The approved recommendations were prioritized and turned into an implementation plan, with each improvement being assigned an owner who would be responsible for driving the effort to completion.

      Integration points in other processes, like SDLC, where change would be required were highlighted and included in the implementation plan.

      If you want additional support, have our analysts guide you through this phase as part of an Info-Tech Workshop Associated Activity icon

      Book a workshop with our Info-Tech analysts:

      Photo of an Info-Tech analyst.
      • To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.
      • Info-Tech analyst will join you and your team onsite at your location or welcome you to Info-Tech's historic Toronto office to participate in an innovative onsite workshop.
      • Contact your account manager (www.infotech.com/account), or email Workshops@InfoTech.com for more information.

      The following are sample activities that will be conducted by Info-Tech analysts with your team:

      3.1

      Sample of activity 3.1 'Maintain as much of the existing framework as possible in the redesign'. Redesign the Governance Structure

      Identify committees that need to be added, ones that must be changed, and the no-longer-needed governing bodies in an optimized and streamlined structure. Draw it out in the governance structure map.

      3.2

      Sample of activity 3.2 'Utilize the IT Governance Terms of Reference to establish operational procedures for governing bodies'. Redesign the Governing Bodies

      Use the IT Governance Terms of Reference and the Committee Template to build a committee profile for each governing body identified. Use these activities to build out and establish the processes of the modified governing groups.

      Improve IT Governance to Drive Business Results

      PHASE 4

      Implement Governance Redesign

      Phase 4 outline

      Associated Activity icon Call 1-888-670-8889 or email GuidedImplementations@InfoTech.com for more information.

      Complete these steps on your own, or call us to complete a guided implementation. A guided implementation is a series of 2-3 advisory calls that help you execute each phase of a project. They are included in most advisory memberships.

      Guided Implementation 4: Implement Governance Redesign

      Proposed Time to Completion: 2-3 weeks
      Step 4.1: Identify Steps for Implementation Step 4.2: Finalized Implementation Plan
      Start with an analyst kick-off call:
      • Identify major steps required to implement the governance redesign.
      • Outline the components and milestones of the implementation plan.
      • Review materials needed for the executive presentation.
      Review findings with analyst:
      • Review the major milestones identified in the implementation plan.
      • Discuss potential challenges and stakeholder objections.
      • Strategize for the executive presentation.
      Then complete these activities…
      • Then complete these activities…
      • Identify next steps for the redesign.
      • Establish a communication plan.
      Then complete these activities…
      • Review the implementation plan.
      • Assess any challenging milestones and build implementation strategies.
      • Finalize the executive presentation.
      With these tools & templates:
      • IT Governance Implementation Plan
      • Redesign IT Governance to Drive Optimal Business Results Executive Presentation Template
      With these tools & templates:
      • IT Governance Implementation Plan
      • Redesign IT Governance to Drive Optimal Business Results Executive Presentation Template

      Phase 4: Implement Governance Redesign

      1 2 3 4
      Align IT With the Business Context Assess the Current Governance Framework Redesign the Governance Framework Implement Governance Redesign

      Activities:

      • 4.1 Identify Next Steps for the Redesign
      • 4.2 Establish a Communication Plan
      • 4.3 Lead the Executive Presentation

      Outcomes:

      • Rationalize steps in the Implementation Plan tool.
      • Construct an executive presentation to facilitate transparency for the governing framework.

      Anticipate and overcome implementation obstacles for the redesign

      Often high-level organizational changes create challenges. We will help you break down the barriers to optimal IT governance by addressing key obstacles.

      Key Obstacles

      Solutions

      Identifying Steps The prioritization must be driven by the common view of what is important for the organization to succeed. Prioritize the IT governance next steps according to the value they are anticipated to provide to the business.
      Communicating the Redesign The redesign of IT governance will bring impactful changes to diverse stakeholders across the organization. This phase will help you plan communication strategies for the different stakeholders.

      Info-Tech Insight

      Don’t overlook the politics and culture of your organization while redesigning your governance framework.

      Create an implementation roadmap to organize a plan for the redesign

      Supporting Tool icon 4A Create an implementation and communication plan

      INSTRUCTIONS

      1. Identify Tasks
        Decide on the order of tasks for your implementation plan. Consider the dependencies of actions and plan the sequence accordingly.
      2. Determine Communication Method
        Identify the most appropriate and impactful method of communicating at each milestone identified in step 1.

      Download the IT Governance Implementation Plan to organize your customized implementation and communication plan.

      Screenshot of a table in the 'IT Governance Implementation Plan'.

      Outline next steps for governance redesign

      Associated Activity icon 4.1

      INPUT: Tasks Identified in the Future State Design

      OUTPUT: Identified Tasks for Implementation as Well as the Audience

      Materials: N/A

      Participants: IT Governance Redesign Owner

      INSTRUCTIONS

      Keep these questions in mind as you analyze and assess what steps to take first in the redesign implementation.

      1. What needs to happen?
        Use the identified changes from the redesign as your guiding list of tasks that need to occur. If they are larger tasks, break them down into smaller parts to make the milestones more achievable.
      2. What are the dependencies?
        Throughout the implementation of the redesign, certain tasks will need to occur to enable other tasks to be performed. Make sure to clearly identify what dependencies exist in the implementation process and clearly identify the order of the tasks.
      3. Who do the changes impact?
        Consider the groups and individuals that will be impacted by changes to the governance framework. This includes key business stakeholders, IT leaders, members of governing boards, and anyone who provides an input or requires an output from one of the committees.

      Use a big-bang approach to implement the IT governance redesign

      While there are other methods to implementing change, the big-bang approach is the most effective for governance redesign and will maintain the momentum of the change as well as the support needed to make it successful.

      Phased

      Parallel

      Big Bang

      Implementation of redesign occurs in steps over a significant period of time.

      Three arrows, each beginning where the previous one ends, separated.

      Components of the redesign are brought into the governance framework, while maintaining some of the old components.

      Three arrows, each beginning slightly after the previous one begins, overlapping.

      Implementation of redesign occurs all at once. This requires significant preparation.

      One large arrow, spanning the length of the other grouped arrows, circled to emphasize.
      • Some committees will be operating under a new structure while others are not, which will undermine the changes being made.
      • This method proliferates a lack of transparency and trust.
      • Releasing IT governance in parallel leads to members sitting on too many boards and spending too much time on governance.
      • There will be a lack of clarity on a committee’s authority.
      • This approach will lead to consistency and transparency in the new process.
      • The change will be clear and fully embedded in the organization with stronger boundaries and well-defined expectations.

      Determine the most effective and impactful communication mediums for relevant stakeholders

      Associated Activity icon 4.2 1 hour

      INSTRUCTIONS

      1. Consider the Individual or Group
        Consider the group and individuals identified in step 4.1. Determine the most appropriate mechanism for communicating with that person or group. Keep in mind: If they are local, how much influence they have and if they are already engaged in the redesign process.
      2. Consider the Message
        The type of message that you are communicating will vary in impact and importance depending on the task. Make sure that the communication medium reflects your message. Keep in mind: If the you are communicating an important or more personal issue, the medium should be more personal as well.

      Screenshot of the same table in the 'IT Governance Implementation Plan'.

      Communicate the changes that result from the redesign

      Plan the message first, then deliver it to your stakeholders through the most appropriate medium to avoid message avoidance or confusion.

      Communication Medium

      Face-to-Face Communication

      Face-to-face communication helps to ensure that the audience is receiving and understanding a clear message, and allows them to voice their concerns and clarify any confusion or questions.

      • Use one-on-one meetings for key stakeholders and large organizational meetings to introduce large changes in the redesign.
      Emails

      Use email to communicate information to broad audiences. In addition, use email as the mass feedback mechanism.

      • Use email to follow up on meetings, or to invite people to next ones, but not as the sole medium of communication.
      Internal Website or Drive

      Use an internal website or drive as an information repository.

      • Store meeting minutes, policies, procedures, terms of reference, and feedback online to ensure transparency.

      Message Delivery

      1. Plan Your Message
        Emphasize what the audience really needs to know and how the change will impact them.
      2. Test Your Message
        If possible, test your communications with a small audience (2-3 people) first to get feedback and adjust messages before delivering them more broadly.
      3. Deliver and Repeat Your Message
        “Tell them what you’re going to tell them, then tell them, then tell them what you told them.”
      4. Gather Feedback and Evaluate Communications
        Evaluate the effectiveness of the communications (through surveys, stakeholder interviews, or metrics) to ensure the message was delivered and received successfully and communication goals were met.

      Construct an executive presentation to facilitate transparency for the governing framework

      Supporting Tool icon 4B Present the redesign to the key business stakeholders

      INSTRUCTIONS

      1. Identify Stakeholders
        Determine which business stakeholders have been the most involved in the redesign process.
      2. Customize Presentation
        Use the deliverables that you have built throughout this redesign to communicate the changes to the structure, authority, processes, and memberships in the governance framework.
      3. Present to Executives
        Present the executive presentation to the key business stakeholders who have been involved in the redesign process.

      Info-Tech best Practice

      Use the Executive Presentation customizable deliverable to lead a boardroom-quality presentation outlining the process and outcomes of the IT governance redesign.

      Present the executive presentation

      Associated Activity icon 4.3 1 hour

      INSTRUCTIONS

      1. Input SoBC Outcomes
        Input the outcomes of the SoBC. Specify the state of the business you have identified through the process of Phase 1.
      2. Input Current State Framework and Guidelines
        Input the outcomes of the current state assessment. Explain the process you used to identify the current governance framework and how you determined the strengths, weaknesses, and guidelines.
      3. Input Redesigned Governance Framework
        Input the governance redesign outcomes. Explain the process you used to modify and reconstruct the governance framework to drive optimal business results. Show the new structure and committee profiles.

      Use the Redesign IT Governance to Drive Optimal Business Results Executive Presentation Template for more information.

      Implement the governance redesign to optimize governance and, in turn, business results

      CASE STUDY

      Industry: Healthcare
      Source: Info-Tech

      Challenge

      Members of the project management group and in the larger SDLC process identified a lack of clarity on how to best govern active projects and initiatives that were moving through the governance process during the changes to the governance framework.

      These projects had already begun under the old frameworks and applying the redesigned governance framework would lead to work duplication and wasted time.

      Solution

      The organization decided that instead of applying the redesign to all initiatives across the organization, it would only be applied to new initiatives and ones that were still working within the first part of the “gating” process, where revised intake information could still be provided.

      Active initiatives that fell into the grandfathered category were identified and could proceed based on the old process. Yet, those that did not receive this status were provided carry-over lead time to revise their documentation during the changes.

      Results

      The implementation plan and timeframes were approved and an official change-over date identified.

      A communication plan was provided, including the grandfathered approach to be used with in-flight initiatives.

      A review cycle was also established for three months after launch to ensure the process was working as expected and would be repeated annually.

      The revised process improved the cycle time by 30% and improved the ability of the organization to govern high-speed requests and decisions.

      Summary of accomplishment

      Insights

      • IT governance requires business leadership.
        Instead of IT managing and governing IT, engage business leaders to take responsibility for governing IT.
      • With great governance comes great responsibility.
        Involve relevant business leaders, who will be impacted by IT outcomes, to share governing authority of IT.
      • Establish IT-business fusion.
        In governance, alignment is not enough. Merge IT and the business through governance to ensure business success.

      Knowledge Gained

      • There must be an active understanding of the current and future state of the business for governance to address the changing needs of the business.
      • Take a proactive approach to revising your governance framework. Understand why you are making decisions before actually making them.
      • Keep the current and future goals in sight to build an optimized governance framework that maintains the minimum bar of oversight required.

      Processes Optimized

      • EDM01 – Establishing a Governance Framework
      • Understanding the four elements of governance:
        • Structure
        • Authority
        • Process
        • Members
      • Embedding the benefits realization criteria, risk optimization, and resource optimization in governance.

      Deliverables Completed

      • Statement of Business Context
      • Current State Assessment of IT Governance
      • Future State Design for IT Governance
      • IT Governance Implementation Plan

      If you want additional support, have our analysts guide you through this phase as part of an Info-Tech Workshop Associated Activity icon

      Book a workshop with our Info-Tech analysts:

      Photo of an Info-Tech analyst.
      • To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.
      • Info-Tech analyst will join you and your team onsite at your location or welcome you to Info-Tech's historic Toronto office to participate in an innovative onsite workshop.
      • Contact your account manager (www.infotech.com/account), or email Workshops@InfoTech.com for more information.

      The following are sample activities that will be conducted by Info-Tech analysts with your team:

      4.1

      Sample of activity 4.1 'Outline next steps for governance redesign'. Build and Deploy the Implementation Plan

      Construct a list of tasks and consider the individuals or groups that those tasks will impact when implementing the governance redesign. Ensure consistent and transparent communication for successful outcomes.

      4.3

      Sample of activity 4.3 'Present the Executive Presentation'. Build the Executive Presentation

      Insert the state of business, current state, and future state design outcomes into a presentation to inform the key business stakeholders on the process and outcomes of the governance redesign.

      Research contributors and experts

      Deborah Eyzaguirre, IT Business Relationship Manager, UNT System

      Herbert Kraft, MIS Manager, Prairie Knights Casino

      Roslyn Kaman, CFO, Miles Nadal JCC

      Nicole Haggerty, Associate Professor of Information Systems, Ivey Business School

      Chris Austin, CTO, Ivey Business School

      Adriana Callerio, IT Director Performance Management, Molina Healthcare Inc.

      Joe Evers, Consulting Principal, JcEvers Consulting Corp

      Huw Morgan, IT Research Executive

      Joy Thiele, Special Projects Manager, Dunns Creek Baptist Church

      Rick Daoust, CIO, Cambrian College

      Related Info-Tech Research

      Bibliography

      A.T. Kearney. “The 7 Habits of Highly Effective Governance.” A.T. Kearney, 2008. Web. Nov. 2016.

      Bertolini, Phil. “The Transformational Effect of IT Governance.” Government Finance Review, Dec. 2012. Web. Nov. 2016.

      CGI. “IT Governance and Managed Services – Creative a win-win relationship” CGI Group Inc., 2015. Web. Dec. 2016.

      De Haes, Steven, and Wim Van Grembergen. “An Exploratory Study into the Design of an IT Governance Minimum Baseline through Delphi Research.” Communications of the Association for Information Systems: Vol. 22 , Article 24. 2008. Web. Nov. 2016.

      Deloitte LLP. “The Role of Senior Leaders in IT Governance.” The Wall Street Journal, 22 Jun. 2015. Web. Oct. 2016.

      Dragoon, Alice. “Four Governance Best Practices.” CIO From IDG, 15 Aug. 2003. Web. Dec. 2016.

      du Preez, Gert. “Company Size Matters: Perspectives on IT Governance.” PricewaterhouseCoopers, Aug. 2011. Web. Nov. 2016.

      Hagen, Christian, et. al. “Building a Capability-Driven IT Organization.” A.T. Kearney, Jun. 2011. Web. Nov. 2016.

      Heller, Martha. “Five Best Practices for IT Governance.” CFO.com, 27 Aug. 2012. Web. Oct. 2016.

      Hoch, Detlev, and Payan, Miguel. “Establishing Good IT Governance in the Public Sector.” McKinsey Dusseldorf, Mar. 2008. Web. Oct. 2016.

      Horne, Andrew, and Brian Foster. “IT Governance Is Killing Innovation.” Harvard Business Review, 22 Aug. 2013. Web. Dec. 2016.

      ISACA. “COBIT 5: Enabling Processes.” ISACA, 2012. Web. Oct. 2016.

      IT Governance Institute. “An Executive View of IT Governance.” IT Governance Institute, in association with PricewaterhouseCoopers. 2009. Web. Nov. 2016.

      Bibliography continued

      IT Governance Institute. “IT Governance Roundtable: Defining IT Governance.” IT Governance Institute, 2009. Web. Nov. 2016.

      Macgregor, Stuart. “The linchpin between Corporate Governance and IT Governance.” The Open Group’s EA Forum Johannesburg and Cape Town, Nov. 2013. Web. Nov. 2016.

      Mallette, Debra. “Implementing IT Governance An Introduction.” ISACA San Francisco Chapter, 23 Sep. 2009. Web. Oct. 2016.

      Massachusetts Institute of Technology. “IT Governance Introduction.” MIT Centre for Information System Research, 2016. Web. Nov. 2016.

      Mueller, Lynn, et. al. “IBM IT Governance Approach – Business Performance through IT Execution.” IBM Redbooks, Feb. 2008. Web. Nov. 2016.

      National Computing Centre. “IT Governance: Developing a successful governance strategy.” The National Computing Centre, Nov. 2005. Web. Oct. 2016.

      Pittsburgh ISACA Chapter. “Practical Approach to COBIT 5.0.” Pittsburgh ISACA Chapter, 17 Sep. 2012. Web. Nov. 2016.

      PricewaterhouseCoopers. “Great by governance: Improve IT performance and Value While Managing Risks.” PricewaterhouseCoopers, Nov. 2014. Web. Dec. 2016.

      PricewaterhouseCoopers. “IT Governance in Practice: Insights from leading CIOs.” PricewaterhouseCoopers, 2006. Web. Nov. 2016.

      Routh, Richard L. “IT Governance Part 1 of 2.” Online video clip. YouTube. The Institute of CIO Excellence, 01 Aug. 2012. Web. Nov. 2016.

      Salleh, Noor Akma Mohd, et. al. “IT Governance in Airline Industry: A Multiple Case Study.” International Journal of Digital Society, Dec. 2010. Web. Nov. 2016.

      Bibliography continued

      Speckert, Thomas, et. al. “IT Governance in Organizations Facing Decentralization – Case Study in Higher Education.” Department of Computer and Systems Sciences. Stockholm University, 2014. Web. Nov. 2016.

      Thorp, John. The Information Paradox—Realizing the Business Benefits of Information Technology. Revised Edition, McGraw Hill, 2003 (written jointly with Fujitsu).

      Vandervost, Guido, et. al. “IT Governance for the CxO.” Deloitte, Nov. 2013. Web. Nov. 2016.

      Weill, Peter, and Jeanne W. Ross. “IT Governance: How Top Performers Manage IT Decision Rights for Superior Results.” Boston: Harvard Business School, 2004. Print. Oct. 2016.

      Wong, Daron, et. al. “IT Governance in Oil and Gas: CIO Roundtable, Priorities for Surviving and Thriving in Lean Times.” Online video clip. YouTube. IT Media Group, Jun. 2016. Web. Nov. 2016.

      Define Your Digital Business Strategy

      • Buy Link or Shortcode: {j2store}55|cart{/j2store}
      • member rating overall impact: 9.0/10 Overall Impact
      • member rating average dollars saved: $83,641 Average $ Saved
      • member rating average days saved: 26 Average Days Saved
      • Parent Category Name: Innovation
      • Parent Category Link: /innovation
      • Your organizational digital business strategy sits on the shelf because it fails to guide implementation.
      • Your organization has difficulty adapting new technologies or rethinking their existing business models.
      • Your organization lacks a clear vision for the digital customer journey.
      • Your management team lacks a framework to rethink how your organization delivers value today, which causes annual planning to become an ideation session that lacks focus.

      Our Advice

      Critical Insight

      • Pre-pandemic digital strategies have been primarily focused on automation. However, your post-pandemic digital strategy must focus on driving resilience for growth opportunities.

      Impact and Result

      • Design a strategy that applies innovation to your business model, streamline and transform processes, and make use of technologies to enhance interactions with customers and employees.
      • Use digital for transforming non-routine cognitive activities and for derisking key elements of the value chain.
      • Create a balanced roadmap that improves digital maturity and prepares you for long-term success in a digital economy.

      Define Your Digital Business Strategy Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Digital Business Strategy Deck – A step-by-step document that walks you through how to identify top value chains and a digitally enabled growth opportunity, transform stakeholder journeys, and build a digital transformation roadmap.

      This blueprint guides you through a value-driven approach to digital transformation that allows you to identify what aspects of the business to transform, what technologies to embrace, what processes to automate, and what new business models to create. This approach to digital transformation unifies digital possibilities with your customer experiences.

      • Define Your Digital Business Strategy – Phases 1-4

      2. Digital Business Strategy Workbook – A tool to guide you in planning and prioritizing projects to build an effective digital business strategy.

      This tool guides you in planning and prioritizing projects to build an effective digital business strategy. Key activities include conducting a horizon scan, conducting a journey mapping exercise, prioritizing opportunities from a journey map, expanding opportunities into projects, and lastly, building the digital transformation roadmap using a Gantt chart visual to showcase project execution timelines.

      • Digital Strategy Workbook

      3. Digital Business Strategy Final Report Template – Use this template to capture the synthesized content from outputs of the activities.

      This deck is a visual presentation template for this blueprint. The intent is to capture the contents of the activities in a presentation PowerPoint. It uses sample data from “City of X” to demonstrate the digital business strategy.

      • Digital Business Strategy Final Report Template
      [infographic]

      Workshop: Define Your Digital Business Strategy

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Identify Two Existing Value Chains

      The Purpose

      Understand how your organization creates value today.

      Key Benefits Achieved

      Identify opportunities for digital transformation in how you currently deliver value today.

      Activities

      1.1 Validate business context.

      1.2 Assess business ecosystem.

      1.3 Identify and prioritize value streams.

      1.4 Break down value stream into value chains.

      Outputs

      Business context

      Overview of business ecosystem

      Value streams and value chains

      2 Identify a Digitally Enabled Growth Opportunity

      The Purpose

      Leverage strategic foresight to evaluate how complex trends can evolve over time and identify opportunities to leapfrog competitors.

      Key Benefits Achieved

      Identify a leapfrog idea to sidestep competitors.

      Activities

      2.1 Conduct a horizon scan.

      2.2 Identify leapfrog ideas.

      2.3 Identify impact to existing or new value chains.

      Outputs

      One leapfrog idea

      Corresponding value chain

      3 Transform Stakeholder Journeys

      The Purpose

      Design a journey map to empathize with your customers and identify opportunities to streamline or enhance existing and new experiences.

      Key Benefits Achieved

      Identify a unified view of customer experience.

      Identify opportunities to automate non-routine cognitive tasks.

      Identify gaps in value delivery.

      Improve customer journey.

      Activities

      3.1 Identify stakeholder persona.

      3.2 Identify journey scenario.

      3.3 Conduct one journey mapping exercise.

      3.4 Identify opportunities to improve stakeholder journey.

      3.5 Break down opportunities into projects.

      Outputs

      Stakeholder persona

      Stakeholder scenario

      Journey map

      Journey-based projects

      4 Build a Digital Transformation Roadmap

      The Purpose

      Build a customer-centric digital transformation roadmap.

      Key Benefits Achieved

      Keep your team on the same page with key projects, objectives, and timelines.

      Activities

      4.1 Prioritize and categorize initiatives.

      4.2 Build roadmap.

      Outputs

      Digital goals

      Unified roadmap

      Further reading

      Define Your Digital Business Strategy

      After a major crisis, find your place in the digital economy.

      Info-Tech Research Group

      Info-Tech is a provider of best-practice IT research advisory services that make every IT leader’s job easier.

      35,000 members sharing best practices you can leverage

      Millions spent developing tools and templates annually

      Leverage direct access to over 100 analysts as an extension of your team

      Use our massive database of benchmarks and vendor assessments

      Get up to speed in a fraction of the time

      Analyst Perspective

      Build business resilience and prepare for a digital economy.

      This is a picture of Senior Research Analyst, Dana Daher

      Dana Daher
      Senior Research Analyst

      To survive one of the greatest economic downturns since the Great Depression, organizations had to accelerate their digital transformation by engaging with the Digital Economy. To sustain growth and thrive as the pandemic eases, organizations must focus their attention on building business resilience by transforming how they deliver value today.
      This requires a value-driven approach to digital transformation that is capable of identifying what aspects of the business to transform, what technologies to embrace, what processes to automate, and what new business models to create. And most importantly, it needs to unify digital possibilities with your customer experiences.
      If there was ever a time for an organization to become a digital business, it is today.

      Executive Summary

      Your Challenge

      • Your organization has difficulty adapting new technologies or rethinking the existing business models.
      • Your management lacks a framework to rethink how your organization delivers value today, which causes annual planning to become an ideation session that lacks focus.
      • There is uncertainty on how to meet evolving customer needs and how to compete in a digital economy.

      Common Obstacles

      • Your organization might approach digital transformation as if we were still in 2019, not recognizing that the pandemic resulted in a major shift to an end-to-end digital economy.
      • Your senior-most leadership thinks digital is "IT's problem" because digital is viewed synonymously with technology.
      • On the other hand, your IT team lacks the authority to make decisions without the executives’ involvement in the discussion around digital.

      Info-Tech’s Approach

      • Design a strategy that applies innovation to your business model, streamline and transform processes, and make use of technologies to enhance interactions with customers and employees.
      • Use digital for transforming non-routine cognitive activities and for de-risking key elements of the value chain.
      • Create a balanced roadmap that improves digital maturity and prepares you for long-term success in a digital economy.

      Info-Tech Insight

      After a major crisis, focus on restarting the growth engine and bolstering business resilience.

      Your digital business strategy aims to transform the business

      Digital Business Strategy

      • Looks for ways to transform the business by identifying what technologies to embrace, what processes to automate, and what new business models to create.
      • Unifies digital possibilities with your customer experiences.
      • Accountability lies with the executive leadership.
      • Must involve cross-functional participation from senior management from the different areas of the organization.

      IT Strategy

      • Aims to identify how to change, fix, or improve technology in support of the organization’s business strategy.
      • Accountability lies with the CIO.
      • Must involve IT management and gather strategic input from the business.

      Becoming a digital business

      Automate tasks to free up time for innovation.

      Business activities (tasks, procedures, and processes, etc.) are used to create, sell, buy, and deliver goods and services.

      When we convert information into a readable format used by computers, we call this digitization (e.g. converting paper into digital format). When we convert these activities into a format to be processed by a computer, we have digitalization (e.g. scheduling appointments online).

      These two processes alter how work takes place in an organization and form the foundation of the concept digital transformation.

      We maintain that digital transformation is all about becoming a “digital business” – an organization that performs more than 66% of all work activities via executable code.

      As organizations take a step closer to this optimal state, new avenues are open to identify advances to promote growth, enhance customer experiences, secure sustainability, drive operational efficiencies, and unearth potential future business ventures.

      Key Concepts:

      Digital: The representation of a physical item in a format used by computers

      Digitization: Conversion of information and processes into a digital format

      Digitalization: Conversion of information into a format to be processed by a computer

      Why transform your business?

      COVID-19 has irrefutably changed livelihoods, businesses, and the economy. During the pandemic, digital tools have acted as a lifeline, helping businesses and economies survive, and in the process, have acted as a catalyst for digital transformation.

      As organizations continue to safeguard business continuity and financial recovery, in the long term, recovery won’t be enough.

      Although many pandemic/recession recovery periods have occurred before, this next recovery period will present two first-time challenges no one has faced before. We must find ways to:

      • Recover from the COVID-19 recession.
      • Compete in a digital economy.

      To grow and thrive in this post-pandemic world, organizations must provide meaningful and lasting changes to brace for a future defined by digital technologies. – Dana Daher, Info-Tech Research Group

      We are amid an economic transformation

      What we are facing today is a paradigm shift transforming the ways in which we work, live, and relate to one another.

      In the last 60 years alone, performance and productivity have been vastly improved by IT in virtually all economic activities and sectors. And today, digital technologies continue to advance IT's contribution even further by bringing unprecedented insights into economic activities that have largely been untouched by IT.

      As technological innovation and the digitalization of products and services continue to support economic activities, a fundamental shift is occurring that is redefining how we live, work, shop, and relate to one another.

      These rapid changes are captured in a new 21st century term:

      The Digital Economy.

      90% of CEOs believe the digital economy will impact their industry. But only 25% have a plan in place. – Paul Taylor, Forbes, 2020

      Analyst Perspective

      Become a Digital Business

      this is a picture of Research Fellow, Kenneth McGee

      Kenneth McGee
      Research Fellow

      Today, the world faces two profoundly complex, mega-challenges simultaneously:

      1. Ending the COVID-19 pandemic and recession.
      2. Creating strategies for returning to business growth.

      Within the past year, healthcare professionals have searched for and found solutions that bring real hope to the belief the global pandemic/recession will soon end.

      As progress towards ending COVID-19 continues, business professionals are searching for the most effective near-term and long-term methods of restoring or exceeding the rates of growth they were enjoying prior to 2020.

      We believe developing a digital business strategy can deliver cost savings to help achieve near-term business growth while preparing an enterprise for long-term business growth by effectively competing within the digital economy of the future.

      The Digital Economy

      The digital economy refers to a concept in which all economic activity is facilitated or managed through digital technologies, data, infrastructure, services, and products (OECD, 2020).

      The digital economy captures decades of digital trends including:

      • Declining enterprise computing costs
      • Improvements in computing power and performance; unprecedent analytic capabilities
      • Rapid growth in network speeds, affordability, and geographic reach
      • High adoption rates of PCs, mobile, and other computing devices

      These trends among others have set the stage to permanently alter how buying and selling will take place within and between local, regional, national, and international economies.

      The emerging digital economy concept is so compelling that the world economists, financial experts, and others are currently investigating how they must substantially rewrite the rules governing how taxes, trade, tangible and intangible assets, and countless other financial issues will be assessed and valued in a digital economy.

      Download Info-Tech’s Digital Economy Report

      Signals of Change

      60%
      of People on Earth Use the Internet
      (DataReportal, 2021)
      20%
      of Global Retail Sales Performed via E-commerce
      (eMarketer, 2021)
      6.64T
      Global Business-to-Business
      E-commerce Market
      (Derived from The Business Research Company, 2021)
      9.6%
      of US GDP ($21.4T) accounted for by the digital economy ($2.05T)
      (Bureau of Economic Analysis, 2021)

      The digital economy captures technological developments transforming the way in which we live, work, and socialize

      Technological evolution

      this image contains a timeline of technological advances, from computers and information technology, to the digital economy of the future

      Info-Tech’s approach to digital business strategy

      A path to thrive in a digital economy.

      1. Identify top value chains to be transformed
      2. Identify a digitally enabled growth opportunity
      3. Transform stakeholder journeys
      4. Build a digital transformation roadmap

      Info-Tech Insight

      Pre-pandemic digital strategies have been primarily focused on automation. However, your post-pandemic digital strategy must focus on driving resilience for growth opportunities.

      The Info-Tech difference:

      • Understand how your organization creates value today to identify opportunities for digital transformation.
      • Leverage strategic foresight to evaluate how complex trends can evolve over time and identify opportunities to leapfrog competitors.
      • Design a journey map to empathize with your customers and identify opportunities to streamline or enhance existing and new experiences.
      • Create a balanced roadmap that improves digital maturity and prepares you for long-term success in a digital economy.

      A digital transformation starts by transforming how you deliver value today

      As digital transformation is an effort to transform how you deliver value today, it is important to understand the different value-generating activities that deliver an outcome for and from your customers.

      We do this by looking at value streams –which refer to the specific set of activities an industry player undertakes to create and capture value for and from the end consumer (and so the question to ask is, how do you make money as an organization?).

      Our approach helps you to digitally transform those value streams that generate the most value for your organization.

      Higher Education Value stream

      Recruitment → Admission → Student Enrolment → Instruction & Research → Graduation → Advancement

      Local Government Value Stream

      Sustain Land, Property, and the Environment → Facilitate Civic Engagement → Protect Local Health and Safety → Grow the Economy → Provide Regional Infrastructure

      Manufacturing Value Stream

      Design Product → Produce Product → Sell Product

      Visit Info-Tech’s Industry Coverage Research to identify your industry’s value streams

      Assess your external environment to identify new value generators

      Assessing your external environment allows you to identify trends that will have a high impact on how you deliver value today.

      Traditionally, a PESTLE analysis is used to assess the external environment. While this is a helpful tool, it is often too broad as it identifies macro trends that are not relevant to an organization's addressable market. That is because not every factor that affects the macro environment (for example, the country of operation) affects a specific organization’s industry in the same way.

      And so, instead of simply assessing the macro environment and trying to project its evolution along the PESTLE factors, we recommend to:

      • Conduct a PESTLE first and deduce, from the analysis, what are possible shifts in six characteristics of an organization’s industry, or
      • Proceed immediately with identifying evolutionary trends that impact the organization’s direct market.

      the image depicts the relationship of factors from the Macro Environment, to the Industry/Addressable Market, to the Organization. the macro environmental factors are Political; Economic; Social; Technological; Legal; and Environmental. the Industry/addressable market factors are the Customer; Talent; Regulation; technology and; Supply chain.

      Info-Tech Insight

      While PESTLE is helpful to scan the macro environment, the analysis often lacks relevance to an organization’s industry.

      An analysis of evolutionary shifts in five industry-specific characteristics would be more effective for identifying trends that impact the organization

      A Market Evolution Trend Analysis (META) identifies changes in prevailing market conditions that are directly relevant to an organization’s industry, and thus provides some critical input to the strategy design process, since these trends can bring about strategic risks or opportunities.
      Shifts in these five characteristics directly impact an organization:

      ORGANIZATION

      • Customer Expectations
      • Talent Availability
      • Regulatory System
      • Supply Chain Continuity
      • Technological Landscape

      Capture existing and new value generators through a customer journey map

      As we prioritize value streams, we break them down into value chains – that is the “string” of processes that interrelate that work.

      However, once we identify these value chains and determine what parts we wish to digitally transform, we take on the perspective of the user, as the way they interact with your products and services will be different to the view of those within the organization who implement and provide those services.

      This method allows us to build an empathetic and customer-centric lens, granting the capability to uncover challenges and potential opportunities. Here, we may define new experiences or redesign existing ones.

      This image contains an example of how a school might use a value chain and customer journey map. the value streams listed include: Recruitment; Admission; Student Enrolment; Instruction& Research; Graduation; and Advancement. the Value chain for the Instruction and Research Value stream. The value chain includes: Research; Course Creation, Delivery, and assessment. The Customer journey map for curricula delivery includes: Understanding the needs of students; Construct the course material; Deliver course material; Conduct assessment and; Upload Grades into system

      A digital transformation is not just about customer journeys but also about building business resilience

      Pre-pandemic, a digital transformation was primarily focused around improving customer experiences. Today, we are facing a paradigm shift in the way in which we capture the priorities and strategies for a digital transformation.

      As the world grows increasingly uncertain, organizations need to continue to focus on improving customer experience while simultaneously protecting their enterprise value.

      Ultimately, a digital transformation has two purposes:

      1. The classical model – whereby there is a focus on improving digital experiences.
      2. Value protection or the reduction of enterprise risk by systematically identifying how the organization delivers value and digitally transforming it to protect future cashflows and improve the overall enterprise value.
      Old Paradigm New Paradigm
      Predictable regulatory changes with incremental impact Unpredictable regulatory changes with sweeping impact
      Reluctance to use digital collaboration Wide acceptance of digital collaboration
      Varied landscape of brick-and-mortar channels Last-mile consolidation
      Customers value brand Customers value convenience/speed of fulfilment
      Intensity of talent wars depends on geography Broadened battlefields for the war for talent
      Cloud-first strategies Cloud-only strategies
      Physical assets Aggressive asset decapitalization
      Digitalization of operational processes Robotization of operational processes
      Customer experience design as an ideation mechanism Business resilience for value protection and risk reduction

      Key deliverable:

      Digital Business Strategy Presentation Template

      A highly visual and compelling presentation template that enables easy customization and executive-facing content.

      three images are depicted, which contain slides from the Digital Business Strategy presentation template, which will be available in 2022.

      *Coming in 2022

      Blueprint deliverables

      The Digital Business Strategy Workbook supports each step of this blueprint to help you accomplish your goals:

      Initiative Prioritization

      A screenshot from the Initiative Prioritization blueprint is depicted, no words are legible in the image.

      Use the weighted scorecard approach to evaluate and prioritize your opportunities and initiatives.

      Roadmap Gantt Chart

      A screenshot from the Roadmap Gantt Chart blueprint is depicted, no words are legible in the image.

      Populate your Gantt chart to visually represent your key initiative plan over the next 12 months.

      Journey Mapping Workbook

      A screenshot from the Journey Mapping Workbook blueprint is depicted, no words are legible in the image.

      Populate the journey maps to evaluate a user experience over its end-to-end journey.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

      Guided Implementation

      “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

      Workshop

      “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

      Consulting

      “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

      Diagnostics and consistent frameworks used throughout all four options

      Guided Implementation

      What does a typical GI on this topic look like?

      Phase 0 Phase 1 Phase 2 Phase 3 Phase 4
      Call #1:
      Discuss business context and customize your organization’s capability map.
      Call #2:
      Assess business ecosystem.
      Call #3:
      Perform horizon scanning and trends identification.
      Call #5:
      Identify stakeholder personas and scenarios.
      Call #7:
      Discuss initiative generation and inputs into roadmap.
      Call #3:
      Identify how your organization creates value.
      Call #4:
      Discuss value chain impact.
      Call #6:
      Complete journey mapping exercise.
      Call #8:
      Summarize results and plan next steps.

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.
      A typical GI is between 8 to 12 calls over the course of 2 to 4 months.

      Workshop Requirements

      Business Inputs

      Gather business strategy documents and find information on:

      • Business goals
      • Current transformation initiatives
      • Business capabilities to create or enhance
      • Identify top ten revenue and expense generators
      • Identify stakeholders

      Interview the following stakeholders to uncover business context information:

      • CEO
      • CIO

      Download the Business Context Discovery Tool

      Optional Diagnostic

      • Assess your digital maturity (Concierge Service)

      Visit Assess Your Digital Maturity

      Phase 1

      Identify top value chains to be transformed

      • Understand the business
      • Assess your business ecosystem
      • Identify two value chains for transformation

      This phase will walk you through the following activities:

      Understand how your organization delivers value today and identify value chains to be transformed.

      This phase involves the following participants:

      A cross-functional cohort across all levels of the organization.

      Outcomes

      • Business ecosystem
      • Existing value chains to be transformed

      Step 1.1

      Understand the business

      Activities

      • Review business documents.

      Identify top value chains to be transformed

      This step will walk you through the following activities:

      In this section you will gain an understanding of the business context for your strategy.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      Business Context

      Understand the business context

      Understanding the business context is a must for all strategic initiatives. A pre-requisite to all strategic planning should be to elicit the business context from your business stakeholders.

      Inputs Document(s)/ Method Outputs
      Key stakeholders Strategy Document Stakeholders that are actively involved in, affected by or influence outcome of the organization, e.g. employers, customers, vendors.
      Vision and mission of the organization Website Strategy Document What the organization wants to achieve and how it strives to accomplish those goals.
      Business drivers CEO Interview Inputs and activities that drive the operational and financial results of the organization.
      Key targets CEO Interview Quantitative benchmarks to support strategic goals, e.g. double the enterprise EBITD, improve top-of-mind brand awareness by 15%,
      Strategic investment goals CFO Interview
      Digital Strategy
      Financial investments corresponding with strategic objectives of the organization, e.g. geographic expansion, digital investments.
      Top three value-generating lines of business Financial Document Identification of your top three value-generating products and services or lines of business.
      Goals of the organization over the next 12 months Strategy Document
      Corporate Retreat Notes
      Strategic goals to support the vision, e.g. hire 100 new sales reps, improve product management and marketing.
      Top business initiatives over the next 12 months Strategy Document
      CEO Interview
      Internal campaigns to support strategic goals, e.g. invest in sales team development, expand the product innovation team.
      Business model Strategy Document Products or services that the organization plans to sell, the identified market and customer segments, price points, channels and anticipated expenses.
      Competitive landscape Internal Research Analysis Who your typical or atypical competitors are.

      1.1 Understand the business context

      Objective: Elicit the business context with a careful review of business and strategy documents.

      1. Gather the strategy creation team and review your business context documents. This includes business strategy documents, interview notes from executive stakeholders, and other sources for uncovering the business strategy.
      2. Brainstorm in smaller groups answers to the question you were assigned:
        • What are the strengths and weaknesses of the organization?
        • What are some areas of improvement or opportunity?
        • What does it mean to have a digital business strategy?
      3. Discuss the questions above with participants and document key findings. Share with the group and work through the balanced scorecard questions to complete this exercise.
      4. Document your findings.

      Assess your digital readiness with Info-Tech’s Digital Maturity Assessment

      Input

      • Business Strategy Documents
      • Executive Stakeholder Interviews

      Output

      • Business Context Information

      Materials

      • Collaboration/ Brainstorming Tool (whiteboard, flip chart, digital equivalent)

      Participants

      • Executive Team

      Step 1.2

      Assess your business ecosystem

      Activities

      • Identify disruptors and incumbents.

      Info-Tech Insight

      Your digital business strategy cannot be formulated without a clear vision of the evolution of your industry.

      Identify top value chains to be transformed

      This step will walk you through the following activities:

      In this section, we will assess who the incumbents and disruptors are in your ecosystem and identify who your stakeholders are.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      Business Ecosystem

      Assess your business ecosystem

      Understand the nature of your competition.

      Learn what your competitors are doing.

      To survive, grow, or transform in today's digital era, organizations must first have a strong pulse on their business ecosystem. Learning what your competitors are doing to grow their bottom line is key to identifying how to grow your own. Start by understanding who the key incumbents and disruptors in your industry are to identify where your industry is heading.

      Incumbents: These are established leaders in the industry that possess the largest market share. Incumbents often focus their attention to their most demanding or profitable customers and neglect the needs of those down market.

      Disruptors: Disruptors are primarily new entrants (typically startups) that possess the ability to displace the existing market, industry, or technology. Disruptors are often focused on smaller markets that the incumbents aren’t focused on. (Clayton Christenson, 1997)

      An image is shown demonstrating the relationship within an industry between incumbents, disruptors, and the organization. The incumbents are represented by two large purple circles. The disruptors are represented by 9 smaller blue circles, which represent smaller individual customer bases, but overall account for a larger portion of the industry.

      ’Disruption’ specifically refers to what happens when the incumbents are so focused on pleasing their most profitable customers that they neglect or misjudge the needs of their other segments.– Ilan Mochari, Inc., 2015

      Example Business Ecosystem Analysis

      Business Target Market & Customer Product/Service & Key Features Key Differentiators Market Positioning
      University XYZ
      • Local Students
      • Continuous Learner
      • Certificate programs
      • Associate degrees
      • Strong engineering department with access to high-quality labs
      • Strong community impact
      Affordable education with low tuition cost and access to bursaries & scholarships.
      University CDE University CDE
      • Local students
      • International students
      • Continuous learning students
      • Continuous learning offerings (weekend classes)
      • Strong engineering program
      • Strong continuous learning programs
      Outcome focused university with strong co-ops/internship programs and career placements for graduates
      University MNG
      • Local students
      • Non degree, freshman and continuous learning adults
      • Associate degrees
      • Certificate programs (IT programs)
      • Dual credit program
      • More locations/campuses
      • Greater physical presence
      • High web presence
      Nurturing university with small student population and classroom sizes. University attractive to adult learners.
      Disruptors Online Learning Company EFG
      • Full-time employees & executives– (online presence important)
      • Shorter courses
      • Full-time employees & executives– (online presence important)
      Competitive pricing with an open acceptance policy
      University JKL Online Credential Program
      • High school
      • University students
      • Adult learners
      • Micro credentials
      • Ability to acquire specific skills
      Borderless and free (or low cost) education

      1.2 Understand your business ecosystem

      Objective: Identify the incumbents and disruptors in your business ecosystem.

      1. Identify the key incumbents and disruptors in your business ecosystem.
        • Incumbents: These are established leaders in the industry that possess the largest market share.
        • Disruptors: Disruptors are primarily new entrants (startups) that possess the ability to displace the existing market, industry, or technology.
      2. Identify target market and key customers. Who are the primary beneficiaries of your products or service offerings? Your key customers are those who keep you in business, increase profits, and are impacted by your operations.
      3. Identify what their core products or services are. Assess what core problem their products solve for key customers and what key features of their solution support this.
      4. Assess what the competitors' key differentiators are. There are many differentiators that an organization can have, examples include product, brand, price, service, or channel.
      5. Identify what the organization’s value proposition is. Why do customers come to them specifically? Leverage insights from the key differentiators to derive this.
      6. Finally, assess how your organization derives value relative to your competitors.

      Input

      • Market Assessment

      Output

      • Key Incumbents and Disruptors

      Materials

      • Collaboration/ Brainstorming Tool (whiteboard, flip chart, digital equivalent)

      Participants

      • Executive Team

      Step 1.3

      Value-chain prioritization

      Activities

      • Identify and prioritize value chains for innovation.

      Identify top value chains to be transformed

      This step will walk you through the following activities:

      Identify and prioritize how your organization currently delivers value today and identify value chains to be transformed.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      Prioritized Value Chains

      Determine what value the organization creates

      Identify areas for innovation.

      Value streams and value chains connect business goals to the organization’s value realization activities. They enable an organization to create and capture value in the market place by engaging in a set of interconnected activities. Those activities are dependent on the specific industry segment an organization operates within.

      Different types of value your organization creates

      This an example of a value chain which a school would use to analyze how their organization creates value. The value streams listed include: Recruitment; Admission; Student Enrolment; Instruction& Research; Graduation; and Advancement. the Value chain for the Student enrolment stream is displayed. The value chain includes: Matriculation; Enrolment into a Program and; Unit enrolment.

      Value Streams

      A value stream refers to the specific set of activities an industry player undertakes to create and capture value for and from the end consumer.

      Value Chains

      A value chain is a ”string” of processes within a company that interrelate and work together to meet market demand. Examining the value chain of a company will reveal how it achieves competitive advantage.

      Visit Info-Tech’s Industry Coverage Research to identify value streams

      Begin with understanding your industry’s value streams

      Value Streams

      Recruitment

      • The promotion of the institution and the communication with prospective students is accommodated by the recruitment component.
      • Prospective students are categorized as domestic and international, undergraduate and graduate. Each having distinct processes.

      Admission

      • Admission into the university involves processes distinct from recruitment. Student applications are processed and evaluated and the students are informed of the decision.
      • This component is also concerned with transfer students and the approval of transfer credits.

      Student Enrolment

      • Student enrolment is concerned with matriculation when the student first enters the institution, and subsequent enrolment and scheduling of current students.
      • The component is also concerned with financial aid and the ownership of student records.

      Instruction & Research

      • Instruction involves program development, instructional delivery and assessment, and the accreditation of courses of study.
      • The research component begins with establishing policy and degree fundamentals and concerns the research through to publication and impact assessment.

      Graduation

      • Graduation is not only responsible for the ceremony but also the eligibility of the candidate for an award and the subsequent maintenance of transcripts.

      Advancement

      • Alumni relations are the first responsibility of advancement. This involves the continual engagement with former students.
      • Fundraising is the second responsibility. This includes the solicitation and stewardship of gifts from alumni and other benefactors.

      Value stream defined…

      Value streams connect business goals to the organization’s value realization activities in the marketplace. Those activities are dependent on the specific industry segment in which an organization operates.

      There are two types of value streams: core value streams and support value streams.

      • Core value streams are mostly externally facing. They deliver value to either an external or internal customer and they tie to the customer perspective of the strategy map.
      • Support value streams are internally facing and provide the foundational support for an organization to operate.

      An effective method for ensuring all value streams have been considered is to understand that there can be different end-value receivers.

      Leverage your industry’s capability maps to identify value chains

      Business Capability Map Defined

      A business capability defines what a business does to enable value creation, rather than how. Business capabilities:

      • Represent stable business functions.
      • Are unique and independent of each other.
      • Typically, will have a defined business outcome.

      A capability map is a great starting point to identify value chains within an organization as it is a strong indicator of the processes involved to deliver on the value streams.

      this image contains an example of a business capability map using the value streams identified earlier in this blueprint.

      Info-Tech Insight

      Leverage your industry reference architecture to define value streams and value chains.

      Visit Info-Tech’s Industry Coverage Research to identify value streams

      Prioritize value streams to be supported or enhanced

      Use an evaluation criteria that considers both the human and business value generators that these streams provide.

      two identical value streams are depicted. The right most value stream has Student Enrolment and Instruction Research highlighted in green. between the two streams, are two boxes. In these boxes is the following: Business Value: Profit; Enterprise Value; Brand value. Human Value: Faculty satisfaction; Student satisfaction; Community impact.

      Info-Tech Insight

      To produce maximum impact, focus on value streams that provide two-thirds of your enterprise value.

      Business Value

      Assess the value generators to the business, e.g. revenue dollars, enterprise value, cost or differentiation (competitiveness), etc.

      Human Value

      Assess the value generators to people, e.g. student/faculty satisfaction, well-being, and social cohesion.

      Identify value chains for transformation

      Value chains, pioneered by the academic Michael Porter, refer to the ”string” of processes within a company that interrelate and work together to meet market demand. An organization’s value chain is connected to the larger part of the value stream. This perspective of how value is generated encourages leaders to see each activity as a part of a series of steps required deliver value within the value stream and opens avenues to identify new opportunities for value generation.

      this image depicts two sample value chains for the value streams: student enrolment and Instruction & Research. Each value chain has a stakeholder associated with it. This is the primary stakeholder that seeks to gain value from that value chain.

      Prioritize value chains for transformation

      Once we have identified the key value chains within each value stream element, evaluate the individual processes within the value chain to identify opportunities for transformation. Evaluate the value chain processes based on the level of pain experienced by a stakeholder to accomplish that task, and the financial impact that level of the process has on the organization.

      this image depicts the same value chains as the image above, with a legend showing which steps have a financial impact, which steps have a high degree of risk, and which steps are prioritized for transformation. Matriculation and publishing are shown to have a financial impact. Research foundation is shown to have a high degree of risk, and enrollment into a program and conducting research are prioritized for transformation.

      1.3 Value chain analysis

      Objective: Determine how the organization creates value, and prioritize value chains for innovation.

      1. The first step of delivering value is defining how it will happen. Use the organization’s industry segment to start a discussion on how value is created for customers. Working back from the moment value is realized by the customer, consider the sequential steps required to deliver value in your industry segment.
      2. Define and validate the organization’s value stream. Write a short description of the value stream that includes a statement about the value provided and a clear start and end for the value stream.
      3. Prioritize the value streams based on an evaluation criteria that reflects business and human value generators to the organization.
      4. Identify value chains that are associated with each value stream. The value chains refer to a string of processes within the value stream element. Each value chain also captures a particular stakeholder that benefits from the value chain.
      5. Once we have identified the key value chains within each value stream element, evaluate the individual processes within the value chain and identify areas for transformation. Evaluate the value chain processes based on the level of pain or exposure to risk experienced by a stakeholder to accomplish that task and the financial impact that level of the process has on the organization.

      Visit Info-Tech’s Industry Coverage Research to identify value streams and capability maps

      Input

      • Market Assessment

      Output

      • Key Incumbents and Disruptors

      Materials

      • Collaboration/ Brainstorming Tool (whiteboard, flip chart, digital equivalent)

      Participants

      • Executive Team

      Phase 2

      Identify a digitally enabled growth opportunity

      • Conduct horizon scan
      • Identify leapfrog idea
      • Conduct value chain impact analysis

      This phase will walk you through the following activities:

      Assess trends that are impacting your industry and identify strategic growth opportunities.

      This phase involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes

      Identify new growth opportunities and value chains impacted

      Phase 2.1

      Horizon scanning

      Activities

      • Scan the internal and external environment for trends.

      Info-Tech Insight

      Systematically scan your environment to identify avenues or opportunities to skip one or several stages of technological development and stay ahead of disruption.

      Identify a digitally enabled growth opportunity

      This step will walk you through the following activities:

      Scan the environment for external environment for megatrends, trends, and drivers. Prioritize trends and build a trends radar to keep track of trends within your environment.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      Growth opportunity

      Horizon scanning

      Understand how your industry is evolving.

      Horizon scanning is a systematic analysis of detecting early signs of future changes or threats.

      Horizon scanning involves scanning, analyzing, and communicating changes in an organization’s environment to prepare for potential threats and opportunities. Much of what we know about the future is based around the interactions and trajectory of macro trends, trends, and drivers. These form the foundations for future intelligence.

      Macro Trends

      A macro trend captures a large-scale transformative trend that could impact your addressable market.

      Trends

      A trend captures a business use case of the macro trend. Consider trends in relation to competitors in your industry.

      Drivers

      A driver is an underlying force causing the trend to occur. There can be multiple causal forces, or drivers, that influence a trend, and multiple trends can be influenced by the same causal force.

      Identify signals of change in the present and their potential future impacts.

      Identifying macro trends

      A macro trend captures a large-scale transformative trend that could change the addressable market. Here are some examples of macro trends to consider when horizon scanning for your own organization:

      Talent Availability

      • Decentralized workforce
      • Hybrid workforce
      • Diverse workforce
      • Skills gap
      • Digital workforce
      • Multigenerational workforce

      Customer Expectations

      • Personalization
      • Digital experience
      • Data ownership
      • Transparency
      • Accessibility

      Technological Landscape

      • AI & robotics
      • Virtual world
      • Ubiquitous connectivity,
      • Genomics
      • Materials (smart, nano, bio)

      Regulatory System

      • Market control
      • Economic shifts
      • Digital regulation
      • Consumer protection
      • Global green

      Supply Chain Continuity

      • Resource scarcity
      • Sustainability
      • Supply chain digitization
      • Circular supply chains
      • Agility

      Identifying trends and drivers

      A trend captures a business use case of a macro trend. Assessing trends can reduce some uncertainties about the future and highlight potential opportunities for your organization. A driver captures the internal or external forces that lead the trend to occur. Understanding and capturing drivers is important to understanding why these trends are occurring and the potential impacts to your value chains.

      This image contains a flow chart, demonstrating the relationship between Macro trends, Trends, and Drivers. in this example, the macro trend is Accessibility. The Trends, or patterns of change, are an increase in demands for micro-credentials, and Preference for eLearning. The Drivers, or the why, are addressing skill gaps for increase in demand for micro-credentials, and Accommodating adult/working learners- for Preference for eLearning.

      Leverage industry roundtables and trend reports to understand the art of the possible

      Uncover important business and industry trends that can inform possibilities for technology innovation.

      Explore trends in areas such as:

      • Machine Learning
      • Citizen Dev 2.0
      • Venture Architecture
      • Autonomous Organizations
      • Self-Sovereign Cloud
      • Digital Sustainability

      Market research is critical in identifying factors external to your organization and identifying technology innovation that will provide a competitive edge. It’s important to evaluate the impact each trend or opportunity will have in your organization and market.

      Visit Info-Tech’s Trends & Priorities Research Center

      Visit Info-Tech’s Industry Coverage Research to identify your industry’s value streams

      this image contains three screenshots from Rethinking Higher Education Report and 2021 Tech Trends Report

      Images are from Info-Tech’s Rethinking Higher Education Report and 2021 Tech Trends Report

      Example horizon scanning activity

      Macro Trends Trends Drivers
      Talent Availability Diversity Inclusive campus culture Systemic inequities
      Hybrid workforce Online learning staff COVID-19 and access to physical institutions
      Customer Expectations Digital experience eLearning for working learners Accommodate adult learners
      Accessibility Micro-credentials for non-traditional students Addressing skills gap
      Technological Landscape Artificial intelligence and robotics AI for personalized learning Hyper personalization
      IoT IoT for monitoring equipment Asset tracking
      Augmented reality Immersive education AR and VR Personalized experiences
      Regulatory System Regulatory System Alternative funding for research Changes in federal funding
      Global Green Environmental and sustainability education curricula Regulatory and policy changes
      Supply Chain Continuity Circular supply chains Vendors recycling outdated technology Sustainability
      Cloud-based solutions Cloud-based eLearning software Convenience and accessibility

      Visit Info-Tech’s Industry Coverage Research to identify your industry’s value streams

      Prioritize trends

      Develop a cross-industry holistic view of trends.

      Visualize emerging and prioritize action.

      Moving from horizon scanning to action requires an evaluation process to determine which trends can lead to growth opportunities. First, we need to make a short list of trends to analyze. For your digital strategy, consider trends on the time horizon that are under 24 months. Next, we need to evaluate the shortlisted opportunities by a second set of criteria: relevance to your organization and impact on industry.

      Timing

      The estimated time to disruption this trend will have for your industry. Assess whether the trend will require significant developments to support its entry into the ecosystem.

      Relevance

      The relevance of the trend to your organization. Does the trend fulfil the vision or goals of the organization?

      Impact

      The degree of impact the trend will have on your industry. A trend with high impact will drive new business models, products, or services.

      Prioritize trends to adopt into your organization

      Prioritize trends based on timing, impact, and relevance.

      Trend Timing
      (S/M/L)
      Impact
      (1-5)
      Relevance
      ( 1-5)
      1. Micro-credentialing S 5 5
      2. IoT-connected devices for personalized experience S 1 3
      3. International partnerships with educational institutions M
      4. Use of chatbots throughout enrollment process L
      5. IoT for energy management of campus facilities L
      6. Gamification of digital course content M
      7. Flexible learning curricula S 4 3
      Deprioritize trends
      that have a time frame
      to disruption of more
      than 24 months.
      this image contains a graph demonstrating the relationship between relevance (x axis) and Impact (Y axis).

      2.1 Scanning the horizon

      Objective: Generate trends

      60 minutes

      • Start by selecting macro trends that are occurring in your environment using the five categories. These are the large-scale transformative trends that impact your addressable market. Macro trends have three key characteristics:
        • They span over a long period of time.
        • They impact all geographic regions.
        • They impact governments, individuals, and organizations.
      • Begin to break down these macro trends into trends. Trends should reflect the direction of a macro trend and capture the pattern in events. Consider trends that directly impact your organization.
      • Understand the drivers behind these trends. Why are they occurring? What is driving them? Understanding the drivers helps us understand the value they may generate.
      • Deprioritize trends that are expected to happen beyond 24 months.
      • Prioritize trends that have a high impact and relevance to the organization.
      • If you identify more than one trend, discuss with the group which trend you would like to pursue and limit it to one opportunity.

      Input

      • Macro Trends
      • Trends

      Output

      • Trends Prioritization

      Materials

      • Digital Strategy Workbook

      Participants

      • Executive Team

      Step 2.2

      Leapfrogging ideation

      Activities

      • Identify leapfrog ideas.
      • Identify impact to value chain.

      Info-Tech Insight

      A systematic approach to leapfrog ideation is one of the most critical ways in which an organization can build the capacity for resilient innovation.

      This step will walk you through the following activities:

      Evaluate trend opportunities and determine the strategic opportunities they pose. You will also work towards identifying the impact the trend has on your value chain.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      • Strategic growth opportunities
      • Value chain impact

      Leapfrog into the future

      Turn trends into growth opportunities.

      To thrive in the digital age, organizations must innovate big, leverage internal creativity, and prepare for flexibility.

      In this digital era, organizations are often playing catch up to a rapidly evolving technological landscape and following a strict linear approach to innovation. However, this linear catch-up approach does not help companies get ahead of competitors. Instead, organizations must identify avenues to skip one or several stages of technological development to leapfrog ahead of their competitors.

      The best way to predict the future is to invent it. – Alan Kay

      Leapfrogging takes place when an organization introduces disruptive innovation into the market and sidesteps competitors who are unable to mobilize to respond to the opportunities.

      Case Study

      Classroom of the Future

      Higher Education: Barco’s Virtual Classroom at UCL

      University College London (UCL), in the United Kingdom, selected Barco weConnect virtual classroom technology for its continuing professional development medical education offering. UCL uses the platform for synchronous teaching, where remote students can interact with a lecturer.

      One of the main advantages of the system is that it enables direct interaction with students through polls, questions, and whiteboarding. The system also allows you to track student engagement in real time.

      The system has also been leveraged for scientific research and publications. In their “Delphi” process, key opinion leaders were able to collaborate in an effective way to reach consensus on a subject matter. The processes that normally takes months were successfully completed in 48 hours (McCann, 2020).

      Results

      The system has been largely successful and has supported remote, real-time teaching, two-way engagement, engagement with international staff, and an overall enriched teaching experience.

      Funnel trends into leapfrog ideas

      Go from trend insights into ideas.

      Brainstorm ways of generating leapfrog ideas from trend insights.

      Dealing with trends is one of the most important tasks for innovation. It provides the basis of developing the future orientation of the organization. However, being aware of a trend is one thing, to develop strategies for response is another.

      To identify the impact the trend has on the organization, consider the four areas of growth strategies for the organization:

      1. New Customers: Leverage the trend to target new customers for existing products or services.
      2. New Business Models: Adjust the business model to capture a change in how the organization delivers value.
      3. New Markets: Enter or create new markets by applying existing products or services to different problems.
      4. New Product or Service Offerings: Introduce new products or services to the existing market.
      A funnel shaped image is depicted. At the top, at the entrance of the funnel, is the word Trend. At the bottom of the image, at the output of the funnel, is the word Opportunity.

      From trend to leapfrog ideas

      Trend New Customer New Market New Business Model New Product or Service
      What trends pose a high-immediate impact to the organization? Target new customers for existing products or services Enter or create new markets by applying existing products or services to different problems Adjust the business model to capture a change in how the organization delivers value Introduce new products or services to the existing market
      Micro-credentials for non-traditional students Target non-traditional learners/students - Online delivery Introduce mini MBA program

      2.2 Identify and prioritize opportunities

      60 minutes

      1. Gather the prioritized trend identified in the horizon scanning exercise (the trend identified to be “adopted” within the organization).
      2. Analyze each trend identified and assess whether the trend provides an opportunity for a new customers, new markets, new business models, or new products and services.

      Input

      • “Adopt” Trends

      Output

      • Trends to pursue
      • Breakdown of strategic opportunities that the trends pose

      Materials

      • Collaboration/ Brainstorming Tool (whiteboard, flip chart, digital equivalent)

      Participants

      • Executive Team

      Step 2.3

      Value chain impact

      Activities

      • Identify impact to value chain.

      This step will walk you through the following activities:

      Evaluate trend opportunities and determine the strategic opportunities they pose. Prioritize the opportunities and identify impact to your value chain.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      • Strategic growth opportunities

      Value chain analysis

      Identify implications of strategic growth opportunities to the value chains.

      As we identify and prioritize the opportunities available to us, we need to assess their impacts on value chains. Does the opportunity directly impact an existing value chain? Or does it open us to the creation of a new value chain?

      The value chain perspective allows an organization to identify how to best minimize or enhance impacts and generate value.
      As we move from opportunity to impact, it is important to break down opportunities into the relevant pieces so we can see a holistic picture of the sources of differentiation.

      this image depicts the value chain for the value stream, student enrolment.

      2.3 Value chain impact

      Objective: Identify impacts to the value chain from the opportunities identified.
      60 minutes

      1. Once you have identified the opportunity, turn back to the value stream, and with the working group, identify the value stream impacted most by the opportunity. Leverage the human impact/business impact criteria to support the identification of the value stream to be impacted.
      2. Within the value stream, brainstorm what parts of the value chain will be impacted by the new opportunity. Or ask whether this new opportunity provides you with a new value chain to be created.
      3. If this opportunity will require a new value chain, identify what set of new processes or steps will be created to support this new entrant.
      4. Identify any critical value chains that will be impacted by the new opportunity. What areas of the value chain pose the greatest risk? And where can we estimate the financial revenue will be impacted the most?

      Input

      • Opportunity

      Output

      • Value chains impacted

      Materials

      • Collaboration/ Brainstorming Tool (whiteboard, flip chart, digital equivalent)

      Participants

      • Executive Team

      Phase 3

      Transform stakeholder journeys

      • Identify stakeholder personas and scenarios
      • Conduct journey map
      • Identify projects

      This phase will walk you through the following activities:

      Take the prioritized value chains and create a journey map to capture the end-to-end experience of a stakeholder.

      Through a journey mapping exercise, you will identify opportunities to digitize parts of the journey. These opportunities will be broken down into functional initiatives to tackle in your strategy.

      This phase involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes

      1. Stakeholder persona
      2. Stakeholder scenario
      3. Stakeholder journey map
      4. Opportunities

      Step 3.1

      Identify stakeholder persona and journey scenario

      Activities

      • Identify stakeholder persona.
      • Identify stakeholder journey scenario.

      Transform stakeholder journeys

      This step will walk you through the following activities:

      In this step, you with identify stakeholder personas and scenarios relating to the prioritized value chains.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      • A taxonomy of critical stakeholder journeys.

      Identify stakeholder persona and journey scenario

      From value chain to journey scenario.

      Stakeholder personas and scenarios help us build empathy towards our customers. It helps put us into the shoes of a stakeholder and relate to their experience to solve problems or understand how they experience the steps or processes required to accomplish a goal. A user persona is a valuable basis for stakeholder journey mapping.

      A stakeholder scenario describes the situation the journey map addresses. Scenarios can be real (for existing products and services) or anticipated.

      A stakeholder persona is a fictitious profile to represent a customer or a user segment. Creating this persona helps us understand who your customers really are and why they are using your service or product.

      Learn more about applying design thinking methodologies

      Identify stakeholder scenarios to map

      For your digital strategy, leverage the existing and opportunity value chains identified in phase 1 and 2 for journey mapping.

      Identify two existing value chains to be transformed.
      In section 1, we identified existing value chains to be transformed. For example, your stakeholder persona is a member of the faculty (engineering), and the scenario is the curricula design process.
      this image contains the value chains for instruction (engineering) and enrolment of engineering student. the instruction(engineering) value chain includes curricula research, curricula design, curricula delivery, and Assessment for the faculty-instructor. The enrolment of engineering student value chain includes matriculation, enrolment into a program, and unit enrolment for the student. In the instruction(engineering) value chain, curricula design is highlighted in blue. In the enrolment of engineering student value chain, Enrolment into a program is highlighted.
      Identify one new value chain.
      In section 2, we identified a new value chain. However, for a new opportunity, the scenario is more complex as it may capture many different areas of a value chain. Subsequently, a journey map for a new opportunity may require mapping all parts of the value chain.
      this image contains an example of a value chain for micro-credentialing (mini online MBA)

      Identify stakeholder persona

      Who are you transforming for?

      To define a stakeholder scenario, we need to understand who we are mapping for. In each value chain, we identified a stakeholder who gains value from that value chain. We now need to develop a stakeholder persona: a representation of the end user to gain a strong understanding of who they are, what they need, and their pains and gains.

      One of the best ways to flesh out your stakeholder persona is to engage with the stakeholders directly or to gather the input of those who may engage with them within the organization.

      For example, if we want to define a journey map for a student, we might want to gather the input of students or teaching faculty that have firsthand encounters with different student types and are able to define a common student type.

      Info-Tech Insight

      Run a survey to understand your end users and develop a stronger picture of who they are and what they are seeking to gain from your organization.

      Example Stakeholder Persona

      Name: Anne
      Age: 35
      Occupation: Engineering Faculty
      Location: Toronto, Canada

      Pains

      What are their frustrations, fears, and anxieties?

      • Time restraints
      • Using new digital tools
      • Managing a class while incorporating individual learning
      • Varying levels within the same class
      • Unmotivated students

      What do they need to do?

      What do they want to get done? How will they know they are successful?

      • Design curricula in a hybrid mode without loss of quality of experience of in-classroom learning.

      Gains

      What are their wants, needs, hopes, and dreams?

      • Interactive content for students
      • Curriculum alignment
      • Ability to run a classroom lab (in hybrid format)
      • Self-paced and self-directed learning opportunities for students

      (Adapted from Osterwalder, et al., 2014)

      Define a journey statement for mapping

      Now that we understand who we are mapping for, we need to define a journey statement to capture the stakeholder journey.
      Leverage the following format to define the journey statement.
      As a [stakeholder], I need to [prioritized value chain task], so that I can [desired result or overall goal].

      this image contains the instruction(engineering) value chain shown above. next to it is a stakeholder journey statement, which states: As an engineering faculty member, I want to design my curricula in a hybrid mode of delivery so that I can simulate in-classroom experiences.

      3.1 Identify stakeholder persona and journey scenario

      Objective: Identify stakeholder persona and journey scenario statement for journey mapping exercise.

      1. Start by identifying who your stakeholder is. Give your stakeholder a demographic profile – capture a typical stakeholder for this value chain.
      2. Identify what the gains and pains are during this value chain and what the stakeholder is seeking to accomplish.
      3. Looking at the value chain, create a statement that captures the goals and needs of the stakeholder. Use the following format to create a statement:
        As a [stakeholder], I need to [prioritized value chain task], so that I can [desired result or overall goal].

      Input

      • Prioritized Value Chains (existing and opportunity)

      Output

      • Stakeholder Persona
      • Stakeholder Journey Statement

      Materials

      • Collaboration/ Brainstorming Tool (whiteboard, flip chart, digital equivalent)
      • Stakeholder Persona Canvas

      Participants

      • Executive Team
      • Stakeholders (if possible)
      • Individual who works directly with stakeholders

      Step 3.2

      Map stakeholder journeys

      Activities

      • Map stakeholder journeys.

      Transform stakeholder journeys

      This step will walk you through the following activities:

      Prioritize the journeys by focusing on what matters most to the stakeholders and estimating the organizational effort to improve those experiences.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      • Candidate journeys identified for redesign or build.

      Leverage customer journey mapping to capture value chains to be transformed

      Conduct a journey mapping exercise to identify opportunities for innovation or automation.

      A journey-based approach helps an organization understand how a stakeholder moves through a process and interacts with the organization in the form of touch points, channels, and supporting characters. By identifying pain points in the journey and the activity types, we can identify opportunities for innovation and automation along the journey.

      Embrace design thinking methodologies to elevate the stakeholder journey and to build a competitive advantage for your organization.

      this image contains an example of the result of a journey mapping exercise. the main headings are Awareness, Consideration, Acquisition, Service and, Loyalty.

      Internal vs. external stakeholder perspective

      In journey mapping, we always start with the stakeholder's perspective, then eventually transition into what the organization does business-wise to deliver value to each stakeholder. It is important to keep in mind both perspectives while conducting a journey mapping exercise as there are often different roles, processes, and technologies associated with each of the journey steps.

      Stakeholder Journey
      (External Perspective)

      • Awareness
      • Consideration
      • Selecting
      • Negotiating
      • Approving

      Business Processes
      (Internal Perspective)

      • Preparation
      • Prospecting
      • Presentation
      • Closing
      • Follow-Up

      Info-Tech Insight

      Take the perspective of an end user, who interacts with your products and services, as it is different from the view of those inside the organization, who implement and provide those services.

      Build a stakeholder journey map

      A stakeholder journey map is a tool used to illustrate the user’s perceptions, emotions, and needs as they move through a process and interact with the organization in the form of touch points, channels, and supporting characters.

      this image depicts an example of a stakeholder journey map, the headings in the map are: Journey Activity; Touch Points; Metrics; Nature of Activity; Key Moments & Pain Points; Opportunities

      Stakeholder Journey Map: Journey Activity

      The journey activity refers to the steps taken to accomplish a goal.

      The journey activity comprises the steps or sequence of tasks the stakeholder takes to accomplish their goal. These steps reflect the high-level process your candidates perform to complete a task or solve a problem.

      Stakeholder Journey Map: Touch Points

      Touch points are the points of interaction between a stakeholder and the organization.

      A touch point refers to any time a stakeholder interacts with your organization or brand. Consider three main points of interaction with the customer in the journey:

      • Before: How did they find out about you? How did they first contact you to start this journey? What channels or mediums were used?
        • Social media
        • Rating & reviews
        • Word of mouth
        • Advertising
      • During: How was the sale or service accomplished?
        • Website
        • Catalog
        • Promotions
        • Point of sale
        • Phone system
      • After: What happened after the sale or service?
        • Billing
        • Transactional emails
        • Marketing emails
        • Follow-ups
        • Thank-you emails

      Stakeholder Journey Map: Nature of Activity

      The nature of activity refers to the type of task the journey activity captures.

      We categorize the activity type to identify opportunities for automation. There are four main types of task types, which in combination (as seen in the table below) capture a task or job to be automated.

      Routine Non-Routine
      Cognitive Routine Cognitive: repeatable tasks that rely on knowledge work, e.g. sales, administration
      Prioritize for automation (2)
      Non-Routine Cognitive: infrequent tasks that rely on knowledge work, e.g. driving, fraud detection
      Prioritize for automation (3)
      Non-Routine Cognitive: infrequent tasks that rely on knowledge work, e.g. driving, fraud detection Prioritize for automation (3) Routine Manual: repeatable tasks that rely on physical work, e.g. manufacturing, production
      Prioritize for automation (1)
      Non-Routine Manual: infrequent tasks that rely on physical work, e.g. food preparation
      Not mature for automation

      Info-Tech Insight

      Where automation makes sense, routine manual activities should be transformed first, followed by routine cognitive activities. Non-routine cognitive activities are the final frontier.

      Stakeholder Journey Map: Metrics

      Metrics are a quantifiable measurement of a process, activity, or initiative.

      Metrics are crucial to justify expenses and to estimate growth for capacity planning and resourcing. There are multiple benefits to identifying and implementing metrics in a journey map:

      • Metrics provide accurate indicators for accurate IT and business decisions.
      • Metrics help you identify stakeholder touch point efficiencies and problems and solve issues before they become more serious.
      • Active metrics tracking makes root cause analysis of issues much easier.

      Example of journey mapping metrics: Cost, effort, turnaround time, throughput, net promoter score (NPS), satisfaction score

      Stakeholder Journey Map: Key Moments & Pain Points

      Key moments and pain points refer to the emotional status of a stakeholder at each stake of the customer journey.

      The key moments are defining pieces or periods in a stakeholder's experience that create a critical turning point or memory.

      The pain points are the critical problems that the stakeholder is facing during the journey or business continuity risks. Prioritize identifying pain points around key moments.

      Info-Tech Insight

      To identify key moments, look for moments that can dramatically influence the quality of the journey or end the journey prematurely. To improve the experience, analyze the hidden needs and how they are or aren’t being met.

      Stakeholder Journey Map: Opportunities

      An opportunity is an investment into people, process, or technology for the purposes of building or improving a business capability and accomplishing a specific organizational objective.

      An opportunity refers to the initiatives or projects that should address a stakeholder pain. Opportunities should also produce a demonstrable financial impact – whether direct (e.g. cost reduction) or indirect (e.g. risk mitigation) – and be evaluated based on how technically difficult it will be to implement.

      Customer

      Create new or different experiences for customers

      Workforce

      Generate new organizational skills or new ways of working

      Operations

      Improve responsiveness and resilience of operations

      Innovation

      Develop different products or services

      Example of stakeholder journey output: Higher Education

      Stakeholder: A faculty member
      Journey: As an engineering faculty member, I want to design my curricula in a hybrid mode of delivery so that I can simulate in-classroom experiences

      Journey activity Understanding the needs of students Construct the course material Deliver course material Conduct assessments Upload grades into system
      Touch Points
      • Research (primary or secondary)
      • Teaching and learning center
      • Training on tools
      • Office suite
      • Video tools
      • PowerPoint live
      • Chat (live)
      • Forum (FAQ
      • Online assessment tool
      • ERP
      • LMS
      Nature of Activity Non-routine cognitive Non-routine cognitive Non-routine cognitive Routine cognitive Routine Manual
      Metrics
      • Time to completion
      • Time to completion
      • Student satisfaction
      • Student satisfaction
      • Student scores
      Ken Moments & Pain Points Lack of centralized repository for research knowledge
      • Too many tools to use
      • Lack of Wi-Fi connectivity for students
      • Loss of social aspects
      • Adjusting to new forms of assessments
      No existing critical pain points; process already automated
      Opportunities
      • Centralized repository for research knowledge
      • Rationalize course creation tool set
      • Connectivity self-assessment/checklist
      • Forums for students
      • Implement an online proctoring tool

      3.2 Stakeholder journey mapping

      Objective: Conduct journey mapping exercise for existing value chains and for opportunities.

      1. Gather the working group and, with the journey mapping workbook, begin to map out the journey scenario statements identified in the value chain analysis. In total, there should be three journey maps:
        • Two for the existing value chains. Map out the specific point in the value chain that is to be transformed.
        • One for the opportunity value chain. Map out all parts of the value chain to be impacted by the new opportunity.
      2. Start with the journey activity and map out the steps involved to accomplish the goal of the stakeholder.
      3. Identify the touch points involved in the value chain.
      4. Categorize the nature of the activity in the journey activity.
      5. Identify metrics for the journey. How can we measure the success of the journey?
      6. Identify pain points and opportunities in parallel with one another.

      Input

      • Value Chain Analysis
      • Stakeholder Personas
      • Journey Mapping Scenario

      Output

      • Journey Map

      Materials

      • Digital Strategy Workbook, Stakeholder Journey tab

      Participants

      • Executives
      • Individuals in the organization that have a direct interaction with the stakeholders

      Info-Tech Insight

      Aim to build out 90% of the stakeholder journey map with the working team; validate the last 10% with the stakeholder themselves.

      Step 3.3

      Prioritize opportunities

      Activities

      • Prioritize opportunities.

      Transform stakeholder journeys

      This step will walk you through the following activities:

      Prioritize the opportunities that arose from the stakeholder journey mapping exercise.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      Prioritized opportunities

      Prioritization of opportunities

      Leverage design-thinking methods to prioritize opportunities.

      As there may be many opportunities arising from the journey map, we need to prioritize ideas to identify which ones we can tackle first – or at all. Leverage IDEO’s design-thinking “three lenses of innovation” to support prioritization:

      • Feasibility: Do you currently have the capabilities to deliver on this opportunity? Do we have the right partners, resources, or technology?
      • Desirability: Is this a solution the stakeholder needs? Does it solve a known pain point?
      • Viability: Does this initiative have an impact on the financial revenue of the organization? Is it a profitable solution that will support the business model? Will this opportunity require a complex cost structure?
      Opportunities Feasibility
      (L/M/H)
      Desirability
      (L/M/H)
      Viability
      (L/M/H)
      Centralized repository for research knowledge H H H
      Rationalize course creation tool set H H H
      Connectivity self-assessment/ checklist H M H
      Forums for students M H H
      Exam preparation (e.g. education or practice exams) H H H

      3.3 Prioritization of opportunities

      Objective: Prioritize opportunities for creating a roadmap.

      1. Gather the opportunities identified in the journey mapping exercise
      2. Assess the opportunities based on IDEO’s three lenses of innovation:
        • Feasibility: Do you currently have the capabilities to deliver on this opportunity? Do we have the right partners, resources, or technology?
        • Viability: Does this initiative have an impact on the financial revenue of the organization? Is it a profitable solution that will support the business model? Will this opportunity require a complex cost structure?
        • Desirability: Is this a solution the stakeholder needs? Does it solve a known pain point?
      3. Opportunities that score high in all three areas are prioritized for the roadmap.

      Input

      • Opportunities From Journey Map

      Output

      • Prioritized Opportunities

      Materials

      • Digital Strategy Workbook

      Participants

      • Executives

      Step 3.4

      Define digital goals

      Activities

      Transform stakeholder journeys

      This step will walk you through the following activities:

      Define a digital goal as it relates to the prioritized opportunities and the stakeholder journey map.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      Digital goals

      Define digital goals

      What digital goals can be derived from the stakeholder journey?

      With the prioritized set of opportunities for each stakeholder journey, take a step back and assess what the sum of these opportunities mean for the journey. What is the overall goal or objective of these opportunities? How do these opportunities change or facilitate the journey experience? From here, identify a single goal statement for each stakeholder journey.

      Stakeholder Scenario Prioritized Opportunities Goal
      Faculty (Engineering) As a faculty (Engineering), I want to prepare and teach my course in a hybrid mode of delivery Centralized repository for research knowledge
      Rationalized course creation tool set
      Support hybrid course curricula development through value-driven toolsets and centralized knowledge

      3.4 Define digital goals

      Objective: Identify digital goals derived from the journey statements.

      1. With the prioritized set of opportunities for each stakeholder journey (the two existing journeys and one opportunity journey) take a step back and assess what the sum of these opportunities means for each journey.
        • What is the overall goal or objective of these opportunities?
        • How do these opportunities change or facilitate the journey experience?
      2. From here, identify a single goal for each stakeholder journey.

      Input

      • Opportunities From Journey Map
      • Stakeholder Persona

      Output

      • Digital Goals

      Materials

      • Prioritization Matrix

      Participants

      • Executives

      Step 3.5

      Breakdown opportunities into series of initiatives

      Activities

      • Identify initiatives from the opportunities.

      Transform stakeholder journeys

      This step will walk you through the following activities:

      Identify people, process, and technology initiatives for the opportunities identified.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      • People, process, and technology initiatives

      Break down opportunities into a series of initiatives

      Brainstorm initiatives for each high-priority opportunity using the framework below. Describe each initiative as a plan or action to take to solve the problem.

      Opportunity → Initiatives:

      People: What initiatives are required to manage people, data, and other organizational factors that are impacted by this opportunity?

      Process: What processes must be created, changed, or removed based on the data?

      Technology: What systems are required to support this opportunity?

      Break down opportunities into a series of initiatives

      Initiatives
      Centralized repository for research knowledge Technology Acquire and implement knowledge management application
      People Train researchers on functionality
      Process Periodically review and validate data entries into repository
      Initiatives
      Rationalize course creation toolset Technology Retire duplicate or under-used tools
      People Provide training on tool types and align to user needs
      Process Catalog software applications and tools across the organization
      Identify under-used or duplicate tools/applications

      Info-Tech Insight

      Ruthlessly evaluate if a initiative should stand alone or if it can be rolled up with another. Fewer initiatives or opportunities increases focus and alignment, allowing for better communication.

      3.5 Break down opportunities into initiatives

      Objective: Break down opportunities into people, process, and technology initiatives.

      1. Split into groups and identify initiatives required to deliver on each opportunity. Document each initiative on sticky notes.
      2. Have each team answer the following questions to identify initiatives for the prioritized opportunities:
        • People: What initiatives are required to manage people, data, and other organizational factors that are impacted by this opportunity?
        • Process: What processes must be created, changed, or removed based on the data?
        • Technology: What systems are required to support this opportunity?
      3. Document findings in the Digital Strategy Workbook.

      Input

      • Opportunities

      Output

      • Opportunity initiatives categorized by people, process and technology

      Materials

      • Digital Strategy Workbook

      Participants

      • Executive team

      Phase 4

      Build a digital transformation roadmap

      • Detail initiatives
      • Build a unified roadmap roadmap

      This phase will walk you through the following activities:

      Build a digital transformation roadmap that captures people, process, and technology initiatives.

      This phase involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes

      • Digital transformation roadmap

      Step 4.1

      Detail initiatives

      Activities

      • Detail initiatives.

      Build a digital transformation roadmap

      This step will walk you through the following activities:

      Detail initiatives for each priority initiative on your horizon.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      • A roadmap for your digital business strategy.

      Create initiative profiles for each high-priority initiative on your strategy

      this image contains a screenshot of an example initiative profile

      Step 4.2

      Build a roadmap

      Activities

      • Create a roadmap of initiatives.

      Build a digital transformation roadmap

      Info-Tech Insight

      A roadmap that balances growth opportunities with business resilience will transform your organization for long-term success in the digital economy.

      This step will walk you through the following activities:

      Identify timing of initiatives and build a Gantt chart roadmap.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      • A roadmap for your digital transformation and the journey canvases for each of the prioritized journeys.

      Build a roadmap to visualize your key initiative plan

      Visual representations of data are more compelling than text alone.

      Develop a high-level document that travels with the initiative from inception through executive inquiry, project management, and finally execution.

      A initiative needs to be discrete: able to be conceptualized and discussed as an independent item. Each initiative must have three characteristics:

      • Specific outcome: Describe an explicit change in the people, processes, or technology of the enterprise.
      • Target end date: When the described outcome will be in effect.
      • Owner: Who on the IT team is responsible for executing on the initiative.
      this image contains screenshots of a sample roadmap for supporting hybrid course curricula development through value-driven toolsets and centralized knowledge.

      4.2 Build your roadmap (30 minutes)

      1. For the Gantt chart:
        • Input the Roadmap Start Year date.
        • Change the months and year in the Gantt chart to reflect the same roadmap start year.
        • Populate the planned start and planned end date for the pre-populated list of high-priority initiatives in each category (people, process, and technology).

      Input

      • Initiatives
      • Initiative start & end dates
      • Initiative category

      Output

      • Digital strategy roadmap visual

      Materials

      • Digital Strategy Workbook

      Participants

      • Senior Executive

      Learn more about project portfolio management strategy

      Step 4.3

      Create a refresh strategy

      Activities

      • Refresh your strategy.

      Build a digital transformation roadmap

      Info-Tech Insight

      A digital strategy is a design process, it must be revisited to pressure test and account for changes in the external environment.

      This step will walk you through the following activities:

      Detail a refresh strategy.

      This step involves the following participants:

      A cross-functional cohort across levels in the organization.

      Outcomes of this step

      • Refresh strategy

      Create a refresh strategy

      It is important to dedicate time to your strategy throughout the year. Create a refresh plan to assess for the changing business context and its impact on the digital business strategy. Make sure the regular planning cycle is not the primary trigger for strategy review. Put a process in place to review the strategy and make your organization proactive. Start by examining the changes to the business context and how the effect would trickle downwards. It’s typical for organizations to build a refresh strategy around budget season and hold planning and touch points to accommodate budget approval time.
      Example:

      this image contains an example of a refresh strategy.

      4.3 Create a refresh strategy (30 minutes)

      1. Work with the digital strategy creation team to identify the time frequencies the organization should consider to refresh the digital business strategy. Time frequencies can also be events that trigger a review (i.e. changing business goals). Record the different time frequencies in the Refresh of the Digital Business Strategy slide of the section.
      2. Discuss with the team the different audience members for each time frequency and the scope of the refresh. The scope represents what areas of the digital business strategy need to be re-examined and possibly changed.

      Example:

      Frequency Audience Scope Date
      Annually Executive Leadership Resurvey, review/ validate, update schedule Pre-budget
      Touch Point Executive Leadership Status update, risks/ constraints, priorities Oct 2021
      Every Year (Re-build) Executive Leadership Full planning Jan 2022

      Input

      • Digital Business Strategy

      Output

      • Refresh Strategy

      Materials

      • Digital Business Strategy Presentation Template
      • Collaboration/ Brainstorming Tool (whiteboard, flip chart, digital equivalent)

      Participants

      • Executive Leaders

      Related Info-Tech Research

      Design a Customer-Centric Digital Operating Model

      Design a Customer-Centric Digital Operating Model

      Establish a new way of working to deliver value on your digital transformation initiatives.

      Develop a Project Portfolio Management Strategy

      Develop a Project Portfolio Management Strategy

      Drive project throughput by throttling resource capacity.

      Adopt Design Thinking in Your Organization

      Adopt Design Thinking in Your Organization

      Innovation needs design thinking.

      Digital Maturity Improvement Service

      Digital Maturity Improvement Service

      Prepare your organization for digital transformation – or risk falling behind.

      Research Contributors and Experts

      Kenneth McGee

      this is a picture of Research Fellow, Kenneth McGee

      Research Fellow
      Info-Tech Research Group

      Kenneth McGee is a Research Fellow within the CIO practice at Info-Tech Research Group and is focused on IT business and financial management issues, including IT Strategy, IT Budgets and Cost Management, Mergers & Acquisitions (M&A), and Digital Transformation. He also has extensive experience developing radical IT cost reduction and return-to-growth initiatives during and following financial recessions.

      Ken works with CIOs and IT leaders to help establish twenty-first-century IT organizational charters, structures, and responsibilities. Activities include IT organizational design, IT budget creation, chargeback, IT strategy formulation, and determining the business value derived from IT solutions. Ken’s research has specialized in conducting interviews with CEOs of some of the world’s largest corporations. He has also interviewed a US Cabinet member and IT executives at the White

      House. He has been a frequent keynote speaker at industry conventions, client sales kick-off meetings, and IT offsite planning sessions.

      Ken obtained a BA in Cultural Anthropology from Dowling College, Oakdale, NY, and has pursued graduate studies at Polytechnic Institute (now part of NYU University). He has been an adjunct instructor at State University of New York, Westchester Community College.

      Jack Hakimian

      this is a picture of Vice President of the Info-Tech Research Group, Jack Hakimian

      Vice President
      Info-Tech Research Group

      Jack has more than 25 years of technology and management consulting experience. He has served multi-billion dollar organizations in multiple industries including Financial Services and Telecommunications. Jack also served a number of large public sector institutions.

      Prior to joining the Info-Tech Research Group, he worked for leading consulting players such as Accenture, Deloitte, EY, and IBM.

      Jack led digital business strategy engagements as well as corporate strategy and M&A advisory services for clients across North America, Europe, the Middle East, and Africa. He is a seasoned technology consultant who has developed IT strategies and technology roadmaps, led large business transformations, established data governance programs, and managed the deployment of mission-critical CRM and ERP applications.

      He is a frequent speaker and panelist at technology and innovation conferences and events and holds a Master’s degree in Computer Engineering as well as an MBA from the ESCP-EAP European School of Management.

      Bibliography

      Abrams, Karin von. “Global Ecommerce Forecast 2021.” eMarketer, Insider Intelligence, 7 July 2021. Web.

      Christenson, Clayton. The Innovator's Dilemma: When New Technologies Cause Great Firms to Fail. Harvard Business School, 1997. Book.

      Drucker, Peter F., and Joseph A. Maciariello. Innovation and Entrepreneurship. Routledge, 2015.

      Eagar, Rick, David Boulton, and Camille Demyttenaere. “The Trends in Megatrends.” Arthur D Little, Prism, no. 2, 2014. Web.

      Enright, Sara, and Allison Taylor. “The Future of Stakeholder Engagement.” The Business of a Better World, October 2016. Web.

      Hatem, Louise, Daniel Ker, and John Mitchell. “A roadmap toward a common framework for measuring the digital economy.” Report for the G20 Digital Economy Task Force, OECD, 2020. Web.

      Kemp, Simon. “Digital 2021 April Statshot Report.” DataReportal, Global Digital Insights, 21 Apr. 2021. Web.

      Larson, Chris. “Disruptive Innovation Theory: 4 Key Concepts.” Business Insights, Harvard Business School, HBS Online, 15 Nov. 2016. Web.

      McCann, Leah. “Barco's Virtual Classroom at UCL: A Case Study for the Future of All University Classrooms?” rAVe, 2 July 2020. Web.

      Mochari, Ilan. “The Startup Buzzword Almost Everyone Uses Incorrectly.” Inc., 19 Nov. 2015. Web.

      Osterwalder, Alexander, et al. Value Proposition Design. Wiley, 2014.

      Reed, Laura. “Artificial Intelligence: Is Your Job at Risk?” Science Node, 9 August 2017.

      Rodeck, David. “Alphabet Soup: Understanding the Shape of a Covid-19 Recession.” Forbes, 8 June 2020. Web.

      Tapscott, Don. Wikinomics. Atlantic Books, 2014.

      Taylor, Paul. “Don't Be A Dodo: Adapt to the Digital Economy.” Forbes, 27 Aug. 2015. Web.

      The Business Research Company. "Wholesale Global Market Report 2021: COVID-19 Impact and Recovery to 2030." Research and Markets, January 2021. Press Release.

      “Topic 1: Megatrends and Trends.” BeFore, 11 October 2018.

      “Updated Digital Economy Estimates – June 2021.” Bureau of Economic Analysis, June 2021. Web.

      Williamson, J. N. The Leader Manager. John Wiley & Sons, 1984.

      Responsibly Resume IT Operations in the Office

      • Buy Link or Shortcode: {j2store}423|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: DR and Business Continuity
      • Parent Category Link: /business-continuity

      Having shifted operations almost overnight to a remote work environment, and with the crisis management phase of the COVID-19 pandemic winding down, IT leaders and organizations are faced with the following issues:

      • A reduced degree of control with respect to the organization’s assets.
      • Increased presence of unapproved workaround methods, including applications and devices not secured by the organization.
      • Pressure to resume operations at pre-pandemic cadence while still operating in recovery mode.
      • An anticipated game plan for restarting the organization’s project activities.

      Our Advice

      Critical Insight

      An organization’s shift back toward the pre-pandemic state cannot be carried out in isolation. Things have changed. Budgets, resource availability, priorities, etc., will not be the same as they were in early March. Organizations must ensure that all departments work collaboratively to support office repatriation. IT must quickly identify the must-dos to allow safe return to the office, while prioritizing tasks relating to the repopulation of employees, technical assets, and operational workloads via an informed and streamlined roadmap.

      As employees return to the office, PMO and portfolio leaders must sift through unclear requirements and come up with a game plan to resume project activities mid-pandemic. You need to develop an approach, and fast.

      Impact and Result

      Responsibly resume IT operations in the office:

      • Evaluate risk tolerance
      • Prepare to repatriate people to the office
      • Prepare to repatriate assets to the office
      • Prepare to repatriate workloads to the office
      • Prioritize your tasks and build your roadmap

      Quickly restart the engine of your PPM:

      • Restarting the engine of the project portfolio won’t be as simple as turning a key and hitting the gas. The right path forward will differ for every project portfolio practice.
      • Therefore, in this publication we put forth a multi-pass approach that PMO and portfolio managers can follow depending on their unique situations and needs.
      • Each approach is accompanied by a checklist and recommendations for next steps to get you on right path fast.

      Responsibly Resume IT Operations in the Office Research & Tools

      Start here – read the Executive Brief

      As the post-pandemic landscape begins to take shape, ensure that IT can effectively prepare and support your employees as they move back to the office.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Evaluate your new risk tolerance

      Identify the new risk landscape and risk tolerance for your organization post-pandemic. Determine how this may impact the second wave of pandemic transition tasks.

      • Responsibly Resume IT Operations in the Office – Phase 1: Evaluate Your New Risk Tolerance
      • Resume Operations Information Security Pressure Analysis Tool

      2. Repatriate people to the office

      Prepare to return your employees to the office. Ensure that IT takes into account the health and safety of employees, while creating an efficient and sustainable working environment

      • Responsibly Resume IT Operations in the Office – Phase 2: Repatriate People to the Office
      • Mid-Pandemic IT Prioritization Tool

      3. Repatriate assets to the office

      Prepare the organization's assets for return to the office. Ensure that IT takes into account the off-license purchases and new additions to the hardware family that took place during the pandemic response and facilitates a secure reintegration to the workplace.

      • Responsibly Resume IT Operations in the Office – Phase 3: Repatriate Assets to the Office

      4. Repatriate workloads to the office

      Prepare and position IT to support workloads in order to streamline office reintegration. This may include leveraging pre-existing solutions in different ways and providing additional workstreams to support employee processes.

      • Responsibly Resume IT Operations in the Office – Phase 4: Repatriate Workloads to the Office

      5. Prioritize your tasks and build the roadmap

      Once you've identified IT's supporting tasks, it's time to prioritize. This phase walks through the activity of prioritizing based on cost/effort, alignment to business, and security risk reduction weightings. The result is an operational action plan for resuming office life.

      • Responsibly Resume IT Operations in the Office – Phase 5: Prioritize Your Tasks and Build the Roadmap

      6. Restart the engine of your project portfolio

      Restarting the engine of the project portfolio mid-pandemic won’t be as simple as turning a key and hitting the gas. Use this concise research to find the right path forward for your organization.

      • Restart the Engine of Your Project Portfolio
      [infographic]

      Renovate the Data Center

      • Buy Link or Shortcode: {j2store}497|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Data Center & Facilities Optimization
      • Parent Category Link: /data-center-and-facilities-optimization
      • 33% of enterprises will be undertaking facility upgrades or refreshes in 2010 aimed at extending the life of their existing data centers.
      • Every upgrade or refresh targeting specific components in the facility to address short-term pain will have significant impact on the data center environment as a whole. Planning upfront and establishing a clear project scope will minimize expensive changes in later years.
      • This solution set will provide you with step-by-step design, planning, and selection tools to define a Data Center renovation plan to reduce cost and risk while supporting cost-effective long-term growth for power, cooling, standby power, and fire protection renovations.

      Our Advice

      Critical Insight

      • 88% of organizations cited they would spend more time and effort on documenting and identifying facility requirements for initial project scoping. Organizations can prevent scope creep by conducting the necessary project planning up front and identify requirements and the effect that the renovation project will have in all areas of the data center facility.
      • Data Center facilities renovations must include the specific requirements related to power provisioning, stand-by power, cooling, and fire protection - not just the immediate short-term pain.
      • 39% of organizations cited they would put more emphasis on monitoring contractor management and performance to improve the outcome of the data center renovation project.

      Impact and Result

      • Early internal efforts to create a budget and facility requirements yields better cost and project outcomes when construction begins. Each data center renovation project is unique and should have its own detailed budget.
      • Upfront planning and detailed project scoping can prevent a cascading impact on data center renovation projects to other areas of the data center that can increase project size, scope and spend.
      • Contractor selection is one of the most important first steps in a complex data center renovation. Organizations must ensure the contractor selected has experience specifically in data center renovation.

      Renovate the Data Center Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Identify and understand the renovation project.

      • Storyboard: Renovate the Data Center
      • None
      • Data Center Annual Review Checklist

      2. Renovate power in the data center.

      • Data Center Power Requirements Calculator

      3. Renovate cooling in the data center.

      • Data Center Cooling Requirements Calculator

      4. Renovate standby power in the data center.

      • Data Center Standby Power Requirements Calculator

      5. Define current and future fire protection requirements.

      • Fire Protection & Suppression Engineer Selection Criteria Checklist
      • None

      6. Assess the opportunities and establish a clear project scope.

      • Data Center Renovation Project Charter
      • Data Center Renovation Project Planning & Monitoring Tool

      7. Establish a budget for the data center renovation project.

      • Data Center Renovation Budget Tool

      8. Select a general contractor to execute the project.

      • None
      • Data Center Renovation Contractor Scripted Interview
      • Data Center Renovation Contractor Scripted Interview Scorecard
      • Data Center Renovation Contractor Reference Checklist
      [infographic]

      Redesign Your IT Organizational Structure

      • Buy Link or Shortcode: {j2store}275|cart{/j2store}
      • member rating overall impact: 9.2/10 Overall Impact
      • member rating average dollars saved: $71,830 Average $ Saved
      • member rating average days saved: 25 Average Days Saved
      • Parent Category Name: Organizational Design
      • Parent Category Link: /organizational-design

      Most organizations go through an organizational redesign to:

      • Better align to the strategic objectives of the organization.
      • Increase the effectiveness of IT as a function.
      • Provide employees with clarity in their roles and responsibilities.
      • Support new capabilities.
      • Better align IT capabilities to suit the vision.
      • Ensure the IT organization can support transformation initiatives.

      Our Advice

      Critical Insight

      • Organizational redesign is only as successful as the process leaders engage in. It shapes a story framed in a strong foundation of need and a method to successfully implement and adopt the new structure.
      • Benchmarking your organizational redesign to other organizations will not work. Other organizations have different strategies, drivers, and context. It’s important to focus on your organization, not someone else's.
      • You could have the best IT employees in the world, but if they aren’t structured well your organization will still fail in reaching its vision.

      Impact and Result

      • We are often unsuccessful in organizational redesign because we lack an understanding of why this initiative is required or fail to recognize that it is a change initiative.
      • Successful organizational design requires a clear understanding of why it is needed and what will be achieved by operating in a new structure.
      • Additionally, understanding the impact of the change initiative can lead to greater adoption by core stakeholders.

      Redesign Your IT Organizational Structure Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Redesign Your IT Organizational Structure Deck – A defined method of redesigning your IT structure that is founded by clear drivers and consistently considering change management practices.

      The purpose of this storyboard is to provide a four-phased approach to organizational redesign.

      • Redesign Your IT Organizational Structure – Phases 1-4

      2. Communication Deck – A method to communicate the new organizational structure to critical stakeholders to gain buy-in and define the need.

      Use this templated Communication Deck to ensure impacted stakeholders have a clear understanding of why the new organizational structure is needed and what that structure will look like.

      • Organizational Design Communications Deck

      3. Redesign Your IT Organizational Structure Executive Summary Template – A template to secure executive leadership buy-in and financial support for the new organizational structure to be implemented.

      This template provides IT leaders with an opportunity to present their case for a change in organizational structure and roles to secure the funding and buy-in required to operate in the new structure.

      • Redesign Your IT Organizational Structure Executive Summary

      4. Redesign Your IT Organizational Structure Workbook – A method to document decisions made and rationale to support working through each phase of the process.

      This Workbook allows IT and business leadership to work through the steps required to complete the organizational redesign process and document key rationale for those decisions.

      • Redesign Your IT Organizational Structure Workbook

      5. Redesign Your IT Organizational Structure Operating Models and Capability Definitions – A tool that can be used to provide clarity on the different types of operating models that exist as well as the process definitions of each capability.

      Refer to this tool when working through the redesign process to better understand the operating model sketches and the capability definitions. Each capability has been tied back to core frameworks that exist within the information and technology space.

      • Redesign Your IT Organizational Structure Operating Models and Capability Definitions

      Infographic

      Workshop: Redesign Your IT Organizational Structure

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Establish the Organizational Design Foundation

      The Purpose

      Lay the foundation for your organizational redesign by establishing a set of organizational design principles that will guide the redesign process.

      Key Benefits Achieved

      Clearly articulate why this organizational redesign is needed and the implications the strategies and context will have on your structure.

      Activities

      1.1 Define the org design drivers.

      1.2 Document and define the implications of the business context.

      1.3 Align the structure to support the strategy.

      1.4 Establish guidelines to direct the organizational design process.

      Outputs

      Clear definition of the need to redesign the organizational structure

      Understanding of the business context implications on the organizational structure creation.

      Strategic impact of strategies on organizational design.

      Customized Design Principles to rationalize and guide the organizational design process.

      2 Create the Operating Model Sketch

      The Purpose

      Select and customize an operating model sketch that will accurately reflect the future state your organization is striving towards. Consider how capabilities will be sourced, gaps in delivery, and alignment.

      Key Benefits Achieved

      A customized operating model sketch that informs what capabilities will make up your IT organization and how those capabilities will align to deliver value to your organization.

      Activities

      2.1 Augmented list of IT capabilities.

      2.2 Capability gap analysis

      2.3 Identified capabilities for outsourcing.

      2.4 Select a base operating model sketch.

      2.5 Customize the IT operating model sketch.

      Outputs

      Customized list of IT processes that make up your organization.

      Analysis of which capabilities require dedicated focus in order to meet goals.

      Definition of why capabilities will be outsourced and the method of outsourcing used to deliver the most value.

      Customized IT operating model reflecting sourcing, centralization, and intended delivery of value.

      3 Formalize the Organizational Structure

      The Purpose

      Translate the operating model sketch into a formal structure with defined functional teams, roles, reporting structure, and responsibilities.

      Key Benefits Achieved

      A detailed organizational chart reflecting team structures, reporting structures, and role responsibilities.

      Activities

      3.1 Categorize your IT capabilities within your defined functional work units.

      3.2 Create a mandate statement for each work unit.

      3.3 Define roles inside the work units and assign accountability and responsibility.

      3.4 Finalize your organizational structure.

      Outputs

      Capabilities Organized Into Functional Groups

      Functional Work Unit Mandates

      Organizational Chart

      4 Plan for the Implementation & Change

      The Purpose

      Ensure the successful implementation of the new organizational structure by strategically communicating and involving stakeholders.

      Key Benefits Achieved

      A clear plan of action on how to transition to the new structure, communicate the new organizational structure, and measure the effectiveness of the new structure.

      Activities

      4.1 Identify and mitigate key org design risks.

      4.2 Define the transition plan.

      4.3 Create the change communication message.

      4.4 Create a standard set of FAQs.

      4.5 Align sustainment metrics back to core drivers.

      Outputs

      Risk Mitigation Plan

      Change Communication Message

      Standard FAQs

      Implementation and sustainment metrics.

      Further reading

      Redesign Your IT Organizational Structure

      Designing an IT structure that will enable your strategic vision is not about an org chart – it’s about how you work.

      EXECUTIVE BRIEF

      Analyst Perspective

      Structure enables strategy.

      The image contains a picture of Allison Straker.

      Allison Straker

      Research Director,

      Organizational Transformation

      The image contains a picture of Brittany Lutes.

      Brittany Lutes

      Senior Research Analyst,

      Organizational Transformation

      An organizational structure is much more than a chart with titles and names. It defines the way that the organization operates on a day-to-day basis to enable the successful delivery of the organization’s information and technology objectives. Moreover, organizational design sees beyond the people that might be performing a specific role. People and role titles will and often do change frequently. Those are the dynamic elements of organizational design that allow your organization to scale and meet specific objectives at defined points of time. Capabilities, on the other hand, are focused and related to specific IT processes.

      Redesigning an IT organizational structure can be a small or large change transformation for your organization. Create a structure that is equally mindful of the opportunities and the constraints that might exist and ensure it will drive the organization towards its vision with a successful implementation. If everyone understands why the IT organization needs to be structured that way, they are more likely to support and adopt the behaviors required to operate in the new structure.

      Executive Summary

      Your Challenge

      Your organization needs to reorganize itself because:

      • The current IT structure does not align to the strategic objectives of the organization.
      • There are inefficiencies in how the IT function is currently operating.
      • IT employees are unclear about their role and responsibilities, leading to inconsistencies.
      • New capabilities or a change in how the capabilities are organized is required to support the transformation.

      Common Obstacles

      Many organizations struggle when it comes redesigning their IT organizational structure because they:

      • Jump right into creating the new organizational chart.
      • Do not include the members of the IT leadership team in the changes.
      • Do not include the business in the changes.
      • Consider the context in which the change will take place and how to enable successful adoption.

      Info-Tech’s Approach

      Successful IT organization redesign includes:

      • Understanding the drivers, context, and strategies that will inform the structure.
      • Remaining objective by focusing on capabilities over people or roles.
      • Identifying gaps in delivery, sourcing strategies, customers, and degrees of centralization.
      • Remembering that organizational design is a change initiative and will require buy-in.

      Info-Tech Insight

      A successful redesign requires a strong foundation and a plan to ensure successful adoption. Without these, the organizational chart has little meaning or value.

      Your challenge

      This research is designed to help organizations who are looking to:

      • Redesign the IT structure to align to the strategic objectives of the enterprise.
      • Increase the effectiveness in how the IT function is operating in the organization.
      • Provide clarity to employees around their roles and responsibilities.
      • Ensure there is an ability to support new IT capabilities and/or align capabilities to better support the direction of the organization.
      • Align the IT organization to support a business transformation such as becoming digitally enabled or engaging in M&A activities.

      Organizational design is a challenge for many IT and digital executives

      69% of digital executives surveyed indicated challenges related to structure, team silos, business-IT alignment, and required roles when executing on a digital strategy.

      Source: MIT Sloan, 2020

      Common obstacles

      These barriers make IT organizational redesign difficult to address for many organizations:

      • Confuse organizational design and organizational charts as the same thing.
      • Start with the organizational chart, not taking into consideration the foundational elements that will make that chart successful.
      • Fail to treat organizational redesign as a change management initiative and follow through with the change.
      • Exclude impacted or influential IT leaders and/or business stakeholders from the redesign process.
      • Leverage an operating model because it is trending.

      To overcome these barriers:

      • Understand the context in which the changes will take place.
      • Communicate the changes to those impacted to enable successful adoption and implementation of a new organizational structure.
      • Understand that organizational design is for more than just HR leaders now; IT executives should be driving this change.

      Succeed in Organizational Redesign

      75% The percentage of change efforts that fail.

      Source: TLNT, 2019

      55% The percentage of practitioners who identify how information flows between work units as a challenge for their organization.

      Source: Journal of Organizational Design, 2019

      Organizational design defined

      If your IT strategy is your map, your IT organizational design represents the optimal path to get there.

      IT organizational design refers to the process of aligning the organization’s structure, processes, metrics, and talent to the organization’s strategic plan to drive efficiency and effectiveness.

      Why is the right IT organizational design so critical to success?

      Adaptability is at the core of staying competitive today

      Structure is not just an organizational chart

      Organizational design is a never-ending process

      Digital technology and information transparency are driving organizations to reorganize around customer responsiveness. To remain relevant and competitive, your organizational design must be forward looking and ready to adapt to rapid pivots in technology or customer demand.

      The design of your organization dictates how roles function. If not aligned to the strategic direction, the structure will act as a bungee cord and pull the organization back toward its old strategic direction (ResearchGate.net, 2014). Structure supports strategy, but strategy also follows structure.

      Organization design is not a one-time project but a continuous, dynamic process of organizational self-learning and continuous improvement. Landing on the right operating model will provide a solid foundation to build upon as the organization adapts to new challenges and opportunities.

      Understand the organizational differences

      Organizational Design

      Organizational design the process in which you intentionally align the organizational structure to the strategy. It considers the way in which the organization should operate and purposely aligns to the enterprise vision. This process often considers centralization, sourcing, span of control, specialization, authority, and how those all impact or are impacted by the strategic goals.

      Operating Model

      Operating models provide an architectural blueprint of how IT capabilities are organized to deliver value. The placement of the capabilities can alter the culture, delivery of the strategic vision, governance model, team focus, role responsibility, and more. Operating model sketches should be foundational to the organizational design process, providing consistency through org chart changes.

      Organizational Structure

      The organizational structure is the chosen way of aligning the core processes to deliver. This can be strategic, or it can be ad hoc. We recommend you take a strategic approach unless ad hoc aligns to your culture and delivery method. A good organizational structure will include: “someone with authority to make the decisions, a division of labor and a set of rules by which the organization operates” (Bizfluent, 2019).

      Organizational Chart

      The capstone of this change initiative is an easy-to-read chart that visualizes the roles and reporting structure. Most organizations use this to depict where individuals fit into the organization and if there are vacancies. While this should be informed by the structure it does not necessarily depict workflows that will take place. Moreover, this is the output of the organizational design process.

      Sources: Bizfluent, 2019; Strategy & Business, 2015; SHRM, 2021

      The Technology Value Trinity

      The image contains a diagram of the Technology Value Trinity as described in the text below.

      All three elements of the Technology Value Trinity work in harmony to delivery business value and achieve strategic needs. As one changes, the others need to change as well.

      How do these three elements relate?

      • Digital and IT strategy tells you what you need to achieve to be successful.
      • Operating model and organizational design align resources to deliver on your strategy and priorities. This is done by strategically structuring IT capabilities in a way that enables the organizations vision and considers the context in which the structure will operate.
      • I&T governance is the confirmation of IT’s goals and strategy, which ensures the alignment of IT and business strategy and is the mechanism by which you continuously prioritize work to ensure that what is delivered is in line with the strategy.

      Too often strategy, organizational design, and governance are considered separate practices – strategies are defined without teams and resources to support. Structure must follow strategy.

      Info-Tech’s approach to organizational design

      Like a story, a strategy without a structure to deliver on it is simply words on paper.

      Books begin by setting the foundation of the story.

      Introduce your story by:

      • Defining the need(s) that are driving this initiative forward.
      • Introducing the business context in which the organizational redesign must take place.
      • Outlining what’s needed in the redesign to support the organization in reaching its strategic IT goals.

      The plot cannot thicken without the foundation. Your organizational structure and chart should not exist without one either.

      The steps to establish your organizational chart - with functional teams, reporting structure, roles, and responsibilities defined – cannot occur without a clear definition of goals, need, and context. An organizational chart alone won’t provide the insight required to obtain buy-in or realize the necessary changes.

      Conclude your story through change management and communication.

      Good stories don’t end without referencing what happened before. Use the literary technique of foreshadowing – your change management must be embedded throughout the organizational redesign process. This will increase the likelihood that the organizational structure can be communicated, implemented, and reinforced by stakeholders.

      Info-Tech uses a capability-based approach to help you design your organizational structure

      Once your IT strategy is defined, it is critical to identify the capabilities that are required to deliver on those strategic initiatives. Each initiative will require a combination of these capabilities that are only supported through the appropriate organization of roles, skills, and team structures.

      The image contains a diagram of the various services and blueprints that Info-Tech has to offer.

      Embed change management into organizational design

      Change management practices are needed from the onset to ensure the implementation of an organizational structure.

      For each phase of this blueprint, its important to consider change management. These are the points when you need to communicate the structure changes:

      • Phase 1: Begin to socialize the idea of new organizational structure with executive leadership and explain how it might be impactful to the context of the organization. For example, a new control, governance model, or sourcing approach could be considered.
      • Phase 2: The chosen operating model will influence your relationships with the business and can create/eliminate silos. Ensure IT and business leaders have insight into these possible changes and a willingness to move forward.
      • Phase 3: The new organizational structure could create or eliminate teams, reduce or increase role responsibilities, and create different reporting structures than before. It’s time to communicate these changes with those most impacted and be able to highlight the positive outcomes of the various changes.
      • Phase 4: Should consider the change management practices holistically. This includes the type of change and length of time to reach the end state, communication, addressing active resistors, acquiring the right skills, and measuring the success of the new structure and its adoption.

      Info-Tech Insight

      Do not undertake an organizational redesign initiative if you will not engage in change management practices that are required to ensure its successful adoption.

      Measure the value of the IT organizational redesign

      Given that the organizational redesign is intended to align with the overall vision and objectives of the business, many of the metrics that support its success will be tied to the business. Adapt the key performance indicators (KPIs) that the business is using to track its success and demonstrate how IT can enable the business and improve its ability to reach those targets.

      Strategic Resources

      The percentage of resources dedicated to strategic priorities and initiatives supported by IT operating model. While operational resources are necessary, ensuring people are allocating time to strategic initiatives as well will drive the business towards its goal state. Leverage Info-Tech’s IT Staffing Assessment diagnostic to benchmark your IT resource allocation.

      Business Satisfaction

      Assess the improvement in business satisfaction overall with IT year over year to ensure the new structure continues to drive satisfaction across all business functions. Leverage Info-Tech’s CIO Business Vision diagnostic to see how your IT organization is perceived.

      Role Clarity

      The degree of clarity that IT employees have around their role and its core responsibilities can lead to employee engagement and retention. Consider measuring this core job driver by leveraging Info-Tech’s Employee Engagement Program.

      Customer & User Satisfaction

      Measure customer satisfaction with technology-enabled business services or products and improvements in technology-enabled client acquisition or retention processes. Assess the percentage of users satisfied with the quality of IT service delivery and leverage Info-Tech’s End-User Satisfaction Survey to determine improvements.

      Info-Tech’s methodology for Redesigning Your IT Organization

      Phase

      1. Establish the Organizational Design Foundation

      2. Create the Operating Model Sketch

      3. Formalize the Organizational Structure

      4. Plan for Implementation and Change

      Phase Outcomes

      Lay the foundation for your organizational redesign by establishing a set of organizational design principles that will guide the redesign process.

      Select and customize an operating model sketch that will accurately reflect the future state your organization is striving towards. Consider how capabilities will be sourced, gaps in delivery, and alignment.

      Translate the operating model sketch into a formal structure with defined functional teams, roles, reporting structure, and responsibilities.

      Ensure the successful implementation of the new organizational structure by strategically communicating and involving stakeholders.

      Insight summary

      Overarching insight

      Organizational redesign processes focus on defining the ways in which you want to operate and deliver on your strategy – something an organizational chart will never be able to convey.

      Phase 1 insight

      Focus on your organization, not someone else's’. Benchmarking your organizational redesign to other organizations will not work. Other organizations have different strategies, drivers, and context.

      Phase 2 insight

      An operating model sketch that is customized to your organization’s specific situation and objectives will significantly increase the chances of creating a purposeful organizational structure.

      Phase 3 insight

      If you follow the steps outlined in the first three phases, creating your new organizational chart should be one of the fastest activities.

      Phase 4 insight

      Throughout the creation of a new organizational design structure, it is critical to involve the individuals and teams that will be impacted.

      Tactical insight

      You could have the best IT employees in the world, but if they aren’t structured well your organization will still fail in reaching its vision.

      Blueprint deliverables

      Each step of this blueprint is accompanied by supporting deliverables to help you accomplish your goals:


      Communication Deck

      Communicate the changes to other key stakeholders such as peers, managers, and staff.

      Workbook

      As you work through each of the activities, use this workbook as a place to document decisions and rationale.

      Reference Deck

      Definitions for every capability, base operating model sketches, and sample organizational charts aligned to those operating models.

      Job Descriptions

      Key deliverable:

      Executive Presentation

      Leverage this presentation deck to gain executive buy-in for your new organizational structure.

      Blueprint benefits

      IT Benefits

      • Create an organizational structure that aligns to the strategic goals of IT and the business.
      • Provide IT employees with clarity on their roles and responsibilities to ensure the successful delivery of IT capabilities.
      • Highlight and sufficiently staff IT capabilities that are critical to the organization.
      • Define a sourcing strategy for IT capabilities.
      • Increase employee morale and empowerment.

      Business Benefits

      • IT can carry out the organization’s strategic mission and vision of all technical and digital initiatives.
      • Business has clarity on who and where to direct concerns or questions.
      • Reduce the likelihood of turnover costs as IT employees understand their roles and its importance.
      • Create a method to communicate how the organizational structure aligns with the strategic initiatives of IT.
      • Increase ability to innovate the organization.

      Executive Brief Case Study

      IT design needs to support organizational and business objectives, not just IT needs.

      INDUSTRY: Government

      SOURCE: Analyst Interviews and Working Sessions

      Situation

      IT was tasked with providing equality to the different business functions through the delivery of shared IT services. The government created a new IT organizational structure with a focus on two areas in particular: strategic and operational support capabilities.

      Challenge

      When creating the new IT structure, an understanding of the complex and differing needs of the business functions was not reflected in the shared services model.

      Outcome

      As a result, the new organizational structure for IT did not ensure adequate meeting of business needs. Only the operational support structure was successfully adopted by the organization as it aligned to the individual business objectives. The strategic capabilities aspect was not aligned to how the various business lines viewed themselves and their objectives, causing some partners to feel neglected.

      Info-Tech offers various levels of support to best suit your needs.

      DIY Toolkit

      "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful."

      Guided Implementation

      "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track."

      Workshop

      "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place."

      Consulting

      "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

      Diagnostics and consistent frameworks are used throughout all four options.

      Guided Implementation

      What does a typical GI on this topic look like?

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization. A typical GI is 8 to 12 calls over the course of 4 to 6 months.

      Phase 1

      Call #1: Define the process, understand the need, and create a plan of action.

      Phase 2

      Call #2: Define org. design drivers and business context.

      Call #3: Understand strategic influences and create customized design principles.

      Call #4: Customize, analyze gaps, and define sourcing strategy for IT capabilities.

      Call #5: Select and customize the IT operating model sketch.

      Phase 3

      Call #6: Establish functional work units and their mandates.

      Call #7: Translate the functional organizational chart to an operational organizational chart with defined roles.

      Phase 4

      Call #8: Consider risks and mitigation tactics associated with the new structure and select a transition plan.

      Call #9: Create your change message, FAQs, and metrics to support the implementation plan.

      Workshop Overview

      Contact your account representative for more information.

      workshops@infotech.com 1-888-670-8889

      Day 1

      Day 2

      Day 3

      Day 4

      Day 5

      Establish the Organizational Redesign Foundation

      Create the Operating Model Sketch

      Formalize the Organizational Structure

      Plan for Implementation and Change

      Next Steps and
      Wrap-Up (offsite)

      Activities

      1.1 Define the org. design drivers.

      1.2 Document and define the implications of the business context.

      1.3 Align the structure to support the strategy.

      1.4 Establish guidelines to direct the organizational design process.

      2.1 Augment list of IT capabilities.

      2.2 Analyze capability gaps.

      2.3 Identify capabilities for outsourcing.

      2.4 Select a base operating model sketch.

      2.5 Customize the IT operating model sketch.

      3.1 Categorize your IT capabilities within your defined functional work units.

      3.2 Create a mandate statement for each work unit.

      3.3 Define roles inside the work units and assign accountability and responsibility.

      3.4 Finalize your organizational structure.

      4.1 Identify and mitigate key org. design risks.

      4.2 Define the transition plan.

      4.3 Create the change communication message.

      4.4 Create a standard set of FAQs.

      4.5 Align sustainment metrics back to core drivers.

      5.1 Complete in-progress deliverables from previous four days.

      5.2 Set up review time for workshop deliverables and to discuss next steps.

      Deliverables

      1. Foundational components to the organizational design
      2. Customized design principles
      1. Heat mapped IT capabilities
      2. Defined outsourcing strategy
      3. Customized operating model
      1. Capabilities organized into functional groups
      2. Functional work unit mandates
      3. Organizational chart
      1. Risk mitigation plan
      2. Change communication message
      3. Standard FAQs
      4. Implementation and sustainment metrics
      1. Completed organizational design communications deck

      This blueprint is part one of a three-phase approach to organizational transformation

      PART 1: DESIGN

      PART 2: STRUCTURE

      PART 3: IMPLEMENT

      IT Organizational Architecture

      Organizational Sketch

      Organizational Structure

      Organizational Chart

      Transition Strategy

      Implement Structure

      1. Define the organizational design drivers, business context, and strategic alignment.

      2. Create customized design principles.

      3. Develop and customize a strategically aligned operating model sketch.

      4. Define the future-state work units.

      5. Create future-state work unit mandates.

      6. Define roles by work unit.

      7. Turn roles into jobs with clear capability accountabilities and responsibilities.

      8. Define reporting relationships between jobs.

      9. Assess options and select go-forward organizational sketch.

      11. Validate organizational sketch.

      12. Analyze workforce utilization.

      13. Define competency framework.

      14. Identify competencies required for jobs.

      15. Determine number of positions per job

      16. Conduct competency assessment.

      17. Assign staff to jobs.

      18. Build a workforce and staffing plan.

      19. Form an OD implementation team.

      20. Develop change vision.

      21. Build communication presentation.

      22. Identify and plan change projects.

      23. Develop organizational transition plan.

      24. Train managers to lead through change.

      25. Define and implement stakeholder engagement plan.

      26. Develop individual transition plans.

      27. Implement transition plans.

      Risk Management: Create, implement, and monitor risk management plan.

      HR Management: Develop job descriptions, conduct job evaluation, and develop compensation packages.

      Monitor and Sustain Stakeholder Engagement

      Phase 1

      Establish the Organizational Redesign Foundation

      This phase will walk you through the following activities:

      1.1 Define the organizational redesign driver(s)

      1.2 Create design principles based on the business context

      1.3a (Optional Exercise) Identify the capabilities from your value stream

      1.3b Identify the capabilities required to deliver on your strategies

      1.4 Finalize your list of design principles

      This phase involves the following participants:

      • CIO
      • IT Leadership
      • Business Leadership

      Embed change management into the organizational design process

      Articulate the Why

      Changes are most successful when leaders clearly articulate the reason for the change – the rationale for the organizational redesign of the IT function. Providing both staff and executive leaders with an understanding for this change is imperative to its success. Despite the potential benefits to a redesign, they can be disruptive. If you are unable to answer the reason why, a redesign might not be the right initiative for your organization.

      Employees who understand the rationale behind decisions made by executive leaders are 3.6 times more likely to be engaged.

      McLean & Company Engagement Survey Database, 2021; N=123,188

      Info-Tech Insight

      Successful adoption of the new organizational design requires change management from the beginning. Start considering how you will convey the need for organizational change within your IT organization.

      The foundation of your organizational design brings together drivers, context, and strategic implications

      All aspects of your IT organization’s structure should be designed with the business’ context and strategic direction in mind.

      Use the following set of slides to extract the key components of your drivers, business context, and strategic direction to land on a future structure that aligns with the larger strategic direction.

      REDESIGN DRIVERS

      Driver(s) can originate from within the IT organization or externally. Ensuring the driver(s) are easy to understand and articulate will increase the successful adoption of the new organizational structure.

      BUSINESS CONTEXT

      Defines the interactions that occur throughout the organization and between the organization and external stakeholders. The context provides insight into the environment by both defining the purpose of the organization and the values that frame how it operates.

      STRATEGY IMPLICATIONS

      The IT strategy should be aligned to the overall business strategy, providing insight into the types of capabilities required to deliver on key IT initiatives.

      Understand IT’s desired maturity level, alignment with business expectations, and capabilities of IT

      Where are we today?

      Determine the current overall maturity level of the IT organization.

      Where do we want to be as an organization?

      Use the inputs from Info-Tech’s diagnostic data to determine where the organization should be after its reorganization.

      How can you leverage these results?

      The result of these diagnostics will inform the design principles that you’ll create in this phase.

      Leverage Info-Tech’s diagnostics to provide an understanding of critical areas your redesign can support:

      CIO Business Vision Diagnostic

      Management & Governance Diagnostic

      IT Staffing Diagnostic

      The image contains a picture of Info-Tech's maturity ladder.

      Consider the organizational design drivers

      Consider organizational redesign if …

      Effectiveness is a concern:

      • Insufficient resources to meet demand
      • Misalignment to IT (and business) strategies
      • Lack of clarity around role responsibility or accountability
      • IT functions operating in silos

      New capabilities are needed:

      • Organization is taking on new capabilities (digital, transformation, M&A)
      • Limited innovation
      • Gaps in the capabilities/services of IT
      • Other external environmental influences or changes in strategic direction

      Lack of business understanding

      • Misalignment between business and IT or how the organization does business
      • Unhappy customers (internal or external)

      Workforce challenges

      • Frequent turnover or inability to attract new skills
      • Low morale or employee empowerment

      These are not good enough reasons …

      • New IT leader looking to make a change for the sake of change or looking to make their legacy known
      • To work with specific/hand-picked leaders over others
      • To “shake things up” to see what happens
      • To force the organization to see IT differently

      Info-Tech Insight

      Avoid change for change’s sake. Restructuring could completely miss the root cause of the problem and merely create a series of new ones.

      1.1 Define the organizational redesign driver(s)

      1-2 hours

      1. As a group, brainstorm a list of current pain points or inhibitors in the current organizational structure, along with a set of opportunities that can be realized during your restructuring. Group these pain points and opportunities into themes.
      2. Leverage the pain points and opportunities to help further define why this initiative is something you’re driving towards. Consider how you would justify this initiative to different stakeholders in the organization.
      3. Questions to consider:
        1. Who is asking for this initiative?
        2. What are the primary benefits this is intended to produce?
        3. What are you optimizing for?
        4. What are we capable of achieving as an IT organization?
        5. Are the drivers coming from inside or outside the IT organization?
      4. Once you’ve determined the drivers for redesigning the IT organization, prioritize those drivers to ensure there is clarity when communicating why this is something you are focusing time and effort on.

      Input

      Output

      • Knowledge of the current organization
      • Pain point and opportunity themes
      • Defined drivers of the initiative

      Materials

      Participants
      • Whiteboard/flip charts (physical or electronic)
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Communications Deck

      Frame the organizational design within the context of the business

      Workforce Considerations:

      • How does your organization view its people resources? Does it have the capacity to increase the number of resources?
      • Do you currently have sufficient staff to meet the demands of the organization? Are you able to outsource resources when demand requires it?
      • Are the members of your IT organization unionized?
      • Is your workforce distributed? Do time zones impact how your team can collaborate?

      Business Context Consideration

      IT Org. Design Implication

      Culture:

      Culture, "the way we do things here,” has huge implications for executing strategy, driving engagement, and providing a guiding force that ensures organizations can work together toward common goals.

      • What is the culture of your organization? Is it cooperative, traditional, competitive, or innovative? (See appendix for details.)
      • Is this the target culture or a stepping-stone to the ideal culture?
      • How do the attitudes and behaviors of senior leaders in the organization reinforce this culture?

      Consider whether your organization’s culture can accept the operating model and organizational structure changes that make sense on paper.

      Certain cultures may lean toward particular operating models. For example, the demand-develop-service operating model may be supported by a cooperative culture. A traditional organization may lean towards the plan-build-run operating model.

      Ensure you have considered your current culture and added exercises to support it.

      If more capacity is required to accomplish the goals of the organization, you’ll want to prepare the leaders and explain the need in your design principles (to reflect training, upskilling, or outsourcing). Unionized environments require additional consideration. They may necessitate less structural changes, and so your principles will need to reflect other alternatives (hiring additional resources, creative options) to support organizational needs. Hybrid or fully remote workforces may impact how your organization interacts.

      Business context considerations

      Business Context Consideration

      IT Org. Design Implication

      Control & Governance:

      It is important to consider how your organization is governed, how decisions are made, and who has authority to make decisions.

      Strategy tells what you do, governance validates you’re doing the right things, and structure is how you execute on what’s been approved.

      • How do decisions get considered and approved in your organization? Are there specific influences that impact the priorities of the organization?
      • Are those in the organization willing to release decision-making authority around specific IT components?
      • Should the organization take on greater accountability for specific IT components?

      Organizations that require more controls may lean toward more centralized governance. Organizations that are looking to better enable and empower their divisions (products, groups, regions, etc.) may look to embed governance in these parts of the organization.

      For enterprise organizations, consider where IT has authority to make decisions (at the global, local, or system level). Appropriate governance needs to be built into the appropriate levels.

      Business context considerations

      Business Context Consideration

      IT Org. Design Implication

      Financial Constraints:

      Follow the money: You may need to align your IT organization according to the funding model.

      • Do partners come to IT with their budgets, or does IT have a central pool that they use to fund initiatives from all partners?
      • Are you able to request finances to support key initiatives/roles prioritized by the organization?
      • How is funding aligned: technology, data, digital, etc.? Is your organization business-line funded? Pooled?
      • Are there special products or digital transformation initiatives with resources outside IT? Product ownership funding?
      • How are regulatory changes funded?
      • Do you have the flexibility to adjust your budget throughout the fiscal year?
      • Are chargebacks in place? Are certain services charged back to business units

      Determine if you can move forward with a new model or if you can adjust your existing one to suit the financial constraints.

      If you have no say over your funding, pre-work may be required to build a business case to change your funding model before you look at your organizational structure – without this, you might have to rule out centralized and focus on hybrid/centralized. If you don’t control the budget (funding comes from your partners), it will be difficult to move to a more centralized model.

      A federated business organization may require additional IT governance to help prioritize across the different areas.

      Budgets for digital transformation might come from specific areas of the business, so resources may need to be aligned to support that. You’ll have to consider how you will work with those areas. This may also impact the roles that are going to exist within your IT organization – product owners or division owners might have more say.

      Business context considerations

      Business Context Consideration

      IT Org. Design Implication

      Business Perspective of IT:

      How the business perceives IT and how IT perceives itself are sometimes not aligned. Make sure the business’ goals for IT are well understood.

      • Are your business partners satisfied if IT is an order taker? Do they agree with the need for IT to become a business partner? Is IT expected to innovate and transform the organization?
      • Is what the business needs from IT the same as what IT is providing currently?

      Business Organization Structure and Growth:

      • How is the overall organization structured: Centralized/decentralized? Functionally aligned? Divided by regions?
      • In what areas does the organization prioritize investments?
      • Is the organization located across a diverse geography?
      • How big is the organization?
      • How is the organization growing and changing – by mergers and acquisitions?

      If IT needs to become more of a business partner, you’ll want to define what that means to your organization and focus on the capabilities to enable this. Educating your partners might also be required if you’re not aligned.

      For many organizations, this will include stakeholder management, innovation, and product/project management. If IT and its business partners are satisfied with an order-taker relationship, be prepared for the consequences of that.

      A global organization will require different IT needs than a single location. Specifically, site reliability engineering (SRE) or IT support services might be deployed in each region. Organizations growing through mergers and acquisitions can be structured differently depending on what the organization needs from the transaction. A more centralized organization may be appropriate if the driver is reuse for a more holistic approach, or the organization may need a more decentralized organization if the acquisitions need to be handled uniquely.

      Business context considerations

      Business Context Consideration

      IT Org. Design Implication

      Sourcing Strategy:

      • What are the drivers for sourcing? Staff augmentation, best practices, time zone support, or another reason?
      • What is your strategy for sourcing?
      • Does IT do all of your technology work, or are parts being done by business or other units?
      • Are we willing/able to outsource, and will that place us into non-compliance (regulations)?
      • Do you have vendor management capabilities in areas that you might outsource?
      • How cloud-driven is your organization?
      • Do you have global operations?

      Change Tolerance:

      • What’s your organization’s tolerance to make changes around organizational design?
      • What's the appetite and threshold for risk?

      Your sourcing strategy affects your organizational structure, including what capabilities you group together. Since managing outsourced capabilities also includes the need for vendor management, you’ll need to ensure there aren’t too many capabilities required per leader. Look closely at what can be achieved through your operating model if IT is done through other groups. Even though these groups may not be in scope of your organization changes, you need to ensure your IT team works with them effectively.

      If your organization is going to push back if there are big structural changes, consider whether the changes are truly necessary. It may be preferred to take baby steps – use an incremental versus big-bang approach.

      A need for incremental change might mean not making a major operating model change.

      Business context considerations

      Business Context Consideration

      IT Org Design. Implication

      Stakeholder Engagement & Focus:

      Identify who your customers and stakeholders are; clarify their needs and engagement model.

      • Who is the customer for IT products and services?
      • Is your customer internal? External? Both?
      • How much of a priority is customer focus for your organization?
      • How will IT interact with customers, end users, and partners? What is the engagement model desired?

      Business Vision, Services, and Products:

      Articulate what your organization was built to do.

      • What does the organization create or provide?
      • Are these products and services changing?
      • What are the most critical capabilities to your organization?
      • What makes your organization a success? What are critical success factors of the organization and how are they measuring this to determine success?

      For a customer or user focus, ensure capabilities related to understanding needs (stakeholder, UX, etc.) are prioritized. Hybrid, decentralized, or demand-develop-service models often have more of a focus on customer needs.

      Outsourcing the service desk might be a consideration if there’s a high demand for the service. A differentiation between these users might mean there’s a different demand for services.

      Think broadly in terms of your organizational vision, not just the tactical (widget creation). You might need to choose an operating model that supports vision.

      Do you need to align your organization with your value stream? Do you need to decentralize specific capabilities to enable prioritization of the key capabilities?

      1.2 Create design principles based on the business context

      1-3 hours

      1. Discuss the business context in which the IT organizational redesign will be taking place. Consider the following standard components of the business context; include other relevant components specific to your organization:
      • Culture
      • Workforce Considerations
      • Control and Governance
      • Financial Constraints
      • Business Perspective of IT
      • Business Organization Structure and Growth
      • Sourcing Strategy
      • Change Tolerance
      • Stakeholder Engagement and Focus
      • Business Vision, Services, and Products
    • Different stakeholders can have different perspectives on these questions. Be sure to consider a holistic approach and engage these individuals.
    • Capture your findings and use them to create initial design principles.
    • Input

      Output

      • Business context
      • Design principles reflecting how the business context influences the organizational redesign for IT

      Materials

      Participants

      • Whiteboard/flip charts (physical or electronic)
      • List of Context Questions
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Communications Deck

      How your IT organization is structured needs to reflect what it must be built to do

      Structure follows strategy – the way you design will impact what your organization can produce.

      Designing your IT organization requires an assessment of what it needs to be built to do:

      • What are the most critical capabilities that you need to deliver, and what does success look like in those different areas?
      • What are the most important things that you deliver overall in your organization?

      The IT organization must reflect your business needs:

      • Understand your value stream and/or your prioritized business goals.
      • Understand the impact of your strategies – these can include your overall digital strategy and/or your IT strategy

      1.3a (Optional Exercise) Identify the capabilities from your value stream

      1 hour

      1. Identify your organization’s value stream – what your overall organization needs to do from supplier to consumer to provide value. Leverage Info-Tech’s industry reference architectures if you haven’t identified your value stream, or use the Document Your Business Architecture blueprint to create yours.
      2. For each item in your value stream, list capabilities that are critical to your organizational strategy and IT needs to further invest in to enable growth.
      3. Also, list those that need further support, e.g. those that lead to long wait times, rework time, re-tooling, down-time, unnecessary processes, unvaluable processes.*
      4. Capture the IT capabilities required to enable your business in your draft principles.
      The image contains a screenshot of the above activity: Sampling Manufacturing Business Capabilities.
      Source: Six Sigma Study Guide, 2014
      Input Output
      • Organization’s value stream
      • List of IT capabilities required to support the IT strategy
      Materials Participants
      • Whiteboard/flip charts (physical or electronic)
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Communications Deck

      Your strategy will help you decide on your structure

      Ensure that you have a clear view of the goals and initiatives that are needed in your organization. Your IT, digital, business, and/or other strategies will surface the IT capabilities your organization needs to develop. Identify the goals of your organization and the initiatives that are required to deliver on them. What capabilities are required to enable these? These capabilities will need to be reflected in your design principles.

      Sample initiatives and capabilities from an organization’s strategies

      The image contains a screenshot of sample initiatives and capabilities from an organization's strategies.

      1.3b Identify the capabilities required to deliver on your strategies

      1 hour

      1. For each IT goal, there may be one or more initiatives that your organization will need to complete in order to be successful.
      2. Document those goals and infinitives. For each initiative, consider which core IT capabilities will be required to deliver on that goal. There might be one IT capability or there might be several.
      3. Identify which capabilities are being repeated across the different initiatives. Consider whether you are currently investing in those capabilities in your current organizational structure.
      4. Highlight the capabilities that require IT investment in your design principles.
      InputOutput
      • IT goals
      • IT initiatives
      • IT, digital, and business strategies
      • List of IT capabilities required to support the IT strategy
      MaterialsParticipants
      • Whiteboard/flip charts (physical or electronic)
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Communications Deck

      Create your organizational design principles

      Your organizational design principles should define a set of loose rules that can be used to design your organizational structure to the specific needs of the work that needs to be done. These rules will guide you through the selection of the appropriate operating model that will meet your business needs. There are multiple ways you can hypothetically organize yourself to meet these needs, and the design principles will point you in the direction of which solution is the most appropriate as well as explain to your stakeholders the rationale behind organizing in a specific way. This foundational step is critical: one of the key reasons for organizational design failure is a lack of requisite time spent on the front-end understanding what is the best fit.

      The image contains an example of organizing design principles as described above.

      1.4 Finalize your list of design principles

      1-3 hours

      1. As a group, review the key outputs from your data collection exercises and their implications.
      2. Consider each of the previous exercises – where does your organization stand from a maturity perspective, what is driving the redesign, what is the business context, and what are the key IT capabilities requiring support. Identify how each will have an implication on your organizational redesign. Leverage this conversation to generate design principles.
      3. Vote on a finalized list of eight to ten design principles that will guide the selection of your operating model. Have everyone leave the meeting with these design principles so they can review them in more detail with their work units or functional areas and elicit any necessary feedback.
      4. Reconvene the group that was originally gathered to create the list of design principles and make any final amendments to the list as necessary. Use this opportunity to define exactly what each design principle means in the context of your organization so everyone has the same understanding of what this means moving forward.
      InputOutput
      • Organizational redesign drivers
      • Business context
      • IT strategy capabilities
      • Organizational design principles to help inform the selection of the right operating model sketch
      MaterialsParticipants
      • Whiteboard/flip charts (physical or electronic)
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Communications Deck

      Example design principles

      Your eight to ten design principles will be those that are most relevant to YOUR organization. Below are samples that other organizations have created, but yours will not be the same.

      Design Principle

      Description

      Decision making

      We will centralize decision making around the prioritization of projects to ensure that the initiatives driving the most value for the organization as a whole are executed.

      Fit for purpose

      We will build and maintain fit-for-purpose solutions based on business units’ unique needs.

      Reduction of duplication

      We will reduce role and application duplication through centralized management of assets and clearly differentiated roles that allow individuals to focus within key capability areas.

      Managed security

      We will manage security enterprise-wide and implement compliance and security governance policies.

      Reuse > buy > build

      We will maximize reuse of existing assets by developing a centralized application portfolio management function and approach.

      Managed data

      We will create a specialized data office to provide data initiatives with the focus they need to enable our strategy.

      Design Principle

      Description

      Controlled technical diversity

      We will control the variety of technology platforms we use to allow for increased operability and reduction of costs.

      Innovation

      R&D and innovation are critical – we will build an innovation team into our structure to help us meet our digital agenda.

      Resourcing

      We will separate our project and maintenance activities to ensure each are given the dedicated support they need for success and to reduce the firefighting mentality.

      Customer centricity

      The new structure will be directly aligned with customer needs – we will have dedicated roles around relationship management, requirements, and strategic roadmapping for business units.

      Interoperability

      We will strengthen our enterprise architecture practices to best prepare for future mergers and acquisitions.

      Cloud services

      We will move toward hosted versus on-premises infrastructure solutions, retrain our data center team in cloud best practices, and build roles around effective vendor management, cloud provisioning, and architecture.

      Phase 2

      Create the Operating Model Sketch

      This phase will walk you through the following activities:

      2.1 Augment the capability list

      2.2 Heatmap capabilities to determine gaps in service

      2.3 Identify the target state of sourcing for your IT capabilities

      2.4 Review and select a base operating model sketch

      2.5 Customize the selected overlay to reflect the desired future state

      This phase involves the following participants:

      • CIO
      • IT Leadership

      Embed change management into the organizational design process

      Gain Buy-In

      Obtain desire from stakeholders to move forward with organizational redesign initiative by involving them in the process to gain interest. This will provide the stakeholders with assurance that their concerns are being heard and will help them to understand the benefits that can be anticipated from the new organizational structure.

      “You’re more likely to get buy-in if you have good reason for the proposed changes – and the key is to emphasize the benefits of an organizational redesign.”

      Source: Lucid Chart

      Info-Tech Insight

      Just because people are aware does not mean they agree. Help different stakeholders understand how the change in the organizational structure is a benefit by specifically stating the benefit to them.

      Info-Tech uses capabilities in your organizational design

      We differentiate between capabilities and competencies.

      Capabilities

      • Capabilities are focused on the entire system that would be in place to satisfy a particular need. This includes the people who are competent to complete a specific task and also the technology, processes, and resources to deliver.
      • Capabilities work in a systematic way to deliver on specific need(s).
      • A functional area is often made up of one or more capabilities that support its ability to deliver on that function.
      • Focusing on capabilities rather then the individuals in organizational redesign enables a more objective and holistic view of what your organization is striving toward.

      Competencies

      • Competencies on the other hand are specific to an individual. It determines if the individual poses the skills or ability to perform.
      • Competencies are rooted in the term competent, which looks to understand if you are proficient enough to complete the specific task at hand.
      • Source: The People Development Magazine, 2020

      Use our IT capabilities to establish your IT organization design

      The image contains a diagram of the various services and blueprints that Info-Tech has to offer.

      2.1 Augment the capability list

      1-3 hours

      1. Using the capability list on the previous slide, go through each of the IT capabilities and remove any capabilities for which your IT organization is not responsible and/or accountable. Refer to the Operating Model and Capability Definition List for descriptions of each of the IT capabilities.
      2. Augment the language of specific capabilities that you feel are not directly reflective of what is being done within your organizational context or that you feel need to be changed to reflect more specifically how work is being done in your organization.
      • For example, some organizations may refer to their service desk capability as help desk or regional support. Use a descriptive term that most accurately reflects the terminology used inside the organization today.
    • Add any core capabilities from your organization that are missing from the provided IT capability list.
      • For example, organizations that leverage DevOps capabilities for their product development may desire to designate this in their operating model.
    • Document the rationale for decisions made for future reference.
    • Input Output
      • Baseline list of IT capabilities
      • IT capabilities required to support IT strategy
      • Customized list of IT capabilities
      Materials Participants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership

      Record the results in the Organizational Design Workbook

      Gaps in delivery

      Identify areas that require greater focus and attention.

      Assess the gaps between where you currently are and where you need to be. Evaluate how critical and how effective your capabilities are:

      • Criticality = Importance
        • Try to focus on those which are highly critical to the organization.
        • These may be capabilities that have been identified in your strategies as areas to focus on.
      • Effectiveness = Performance
        • Identify those where the process or system is broken or ineffective, preventing the team from delivering on the capability.
        • Effectiveness could take into consideration how scalable, adaptable, or sustainable each capability is.
        • Focus on the capabilities that are low or medium in effectiveness but highly critical. Addressing the delivery of these capabilities will lead to the most positive outcomes in your organization.

      Remember to identify what allows the highly effective capabilities to perform at the capacity they are. Leverage this when increasing effectiveness elsewhere.

      High Gap

      There is little to no effectiveness (high gap) and the capability is highly important to your organization.

      Medium Gap

      Current ability is medium in effectiveness (medium gap) and there might be some priority for that capability in your organization.

      Low Gap

      Current ability is highly effective (low gap) and the capability is not necessarily a priority for your organization.

      2.2 Heatmap capabilities to determine gaps in delivery

      1-3 hours

      1. At this point, you should have identified what capabilities you need to have to deliver on your organization's goals and initiatives.
      2. Convene a group of the key stakeholders involved in the IT organizational design initiative.
      3. Review your IT capabilities and color each capability border according to the effectiveness and criticality of that capability, creating a heat map.
      • Green indicates current ability is highly effective (low gap) and the capability is not necessarily a priority for your organization.
      • Yellow indicates current ability is medium in effectiveness (medium gap) and there might be some priority for that capability in your organization.
      • Red indicates that there is little to no effectiveness (high gap) and the capability is highly important to your organization.
      Input Output
      • Selected capabilities from activity 2.1
      • Gap analysis in delivery of capabilities currently
      Materials Participants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership

      Record the results in the Organizational Design Workbook

      Don’t forget the why: why are you considering outsourcing?

      There are a few different “types” of outsourcing:

      1. Competitive Advantage – Working with a third-party organization for the knowledge, insights, and best practices they can bring to your organization.
      2. Managed Service– The third party manages a capability or function for your organization.
      3. Staff Augmentation – Your organization brings in contractors and third-party organizations to fill specific skills gaps.

      Weigh which sourcing model(s) will best align with the needed capabilities to deliver effectively

      Insourcing

      Staff Augmentation

      Managed Service

      Competitive Advantage

      Description

      The organization maintains full responsibility for the management and delivery of the IT capability or service.

      Vendor provides specialized skills and enables the IT capability or service together with the organization to meet demand.

      Vendor completely manages the delivery of value for the IT capability, product or service.

      Vendor has unique skills, insights, and best practices that can be taught to staff to enable insourced capability and competency.

      Benefits

      • Retains in-house control over proprietary knowledge and assets that provide competitive or operational advantage.
      • Gains efficiency due to integration into the organization’s processes.
      • Provision of unique skills.
      • Addresses variation in demand for resources.
      • Labor cost savings.
      • Improves use of internal resources.
      • Improves effectiveness due to narrow specialization.
      • Labor cost savings.
      • Gain insights into aspects that could provide your organization with advantages over competitors.
      • Long-term labor cost savings.
      • Short-term outsourcing required.
      • Increase in-house competencies.

      Drawbacks

      • Quality of services/capabilities might not be as high due to lack of specialization.
      • No labor cost savings.
      • Potentially inefficient distribution of labor for the delivery of services/capabilities.
      • Potential conflicts in management or delivery of IT services and capabilities.
      • Negative impact on staff morale.
      • Limited control over services/capabilities.
      • Limited integration into organization’s processes.
      • Short-term labor expenses.
      • Requires a culture of continuous learning and improvement.

      Your strategy for outsourcing will vary with capability and capacity

      The image contains a diagram to show the Develop Vendor Management Capabilities, as described in the text below.

      Capability

      Capacity

      Outsourcing Model

      Low

      Low

      Your solutions may be with you for a long time, so it doesn’t matter whether it is a strategic decision to outsource development or if you are not able to attract the talent required to deliver in your market. Look for a studio, agency, or development shop that has a proven reputation for long-term partnership with its clients.

      Low

      High

      Your team has capacity but needs to develop new skills to be successful. Look for a studio, agency, or development shop that has a track record of developing its customers and delivering solutions.

      High

      Low

      Your organization knows what it is doing but is strapped for people. Look at “body shops” and recruiting agencies that will support short-term development contracts that can be converted to full-time staff or even a wholesale development shop acquisition.

      High

      High

      You have capability and capacity for delivering on your everyday demands but need to rise to the challenge of a significant, short-term rise in demand on a critical initiative. Look for a major system integrator or development shop with the specific expertise in the appropriate technology.

      Use these criteria to inform your right sourcing strategy

      Sourcing Criteria

      Description

      Determine whether you’ll outsource using these criteria

      1. Critical or commodity

      Determine whether the component to be sourced is critical to your organization or if it is a commodity. Commodity components, which are either not strategic in nature or related to planning functions, are likely candidates for outsourcing. Will you need to own the intellectual property created by the third party? Are you ok if they reuse that for their other clients?

      2. Readiness to outsource

      Identify how easy it would be to outsource a particular IT component. Consider factors such as knowledge transfer, workforce reassignment or reduction, and level of integration with other components.

      Vendor management readiness – ensuring that you have sufficient capabilities to manage vendors – should also be considered here.

      3. In-house capabilities

      Determine if you have the capability to deliver the IT solutions in-house. This will help you establish how easy it would be to insource an IT component.

      4. Ability to attract resources (internal vs. outsourced)

      Determine if the capability is one that is easily sourced with full-time, internal staff or if it is a specialty skill that is best left for a third-party to source.

      Determine your sourcing model using these criteria

      5. Cost

      Consider the total cost (investment and ongoing costs) of the delivery of the IT component for each of the potential sourcing models for a component.

      6. Quality

      Define the potential impact on the quality of the IT component being sourced by the possible sourcing models.

      7. Compliance

      Determine whether the sourcing model would fit with regulations in your industry. For example, a healthcare provider would only go for a cloud option if that provider is HIPAA compliant.

      8. Security

      Identify the extent to which each sourcing option would leave your organization open to security threats.

      9. Flexibility

      Determine the extent to which the sourcing model will allow your organization to scale up or down as demand changes.

      2.3 Identify capabilities that could be outsourced

      1-3 hours

      1. For each of the capabilities that will be in your future-state operating model, determine if it could be outsourced. Review the sourcing criteria available on the previous slide to help inform which sourcing strategy you will use for each capability.
      2. When looking to outsource or co-source capabilities, consider why that capability would be outsourced:
      • Competitive Advantage – Work with a third-party organization for the knowledge, insights, and best practices they can bring to your organization.
      • Managed Service – The third party manages a capability or function for your organization.
      • Staff Augmentation – Your organization brings in contractors and third-party organizations to fill specific skills gaps.
    • Place an asterisk (*) around the capabilities that will be leveraging one of the three previous sourcing options.
    • InputOutput
      • Customized IT capabilities
      • Sourcing strategy for each IT capability
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership

      Record the results in the Organizational Design Workbook

      What is an operating model?

      Leverage a cohesive operating model throughout the organizational design process.

      An IT operating model sketch is a visual representation of the way your IT organization needs to be designed and the capabilities it requires to deliver on the business mission, strategic objectives, and technological ambitions. It ensures consistency of all elements in the organizational structure through a clear and coherent blueprint.

      The visual should be the optimization and alignment of the IT organization’s structure to deliver the capabilities required to achieve business goals. Additionally, it should clearly show the flow of work so that key stakeholders can understand where inputs flow in and outputs flow out of the IT organization. Investing time in the front end getting the operating model right is critical. This will give you a framework to rationalize future organizational changes, allowing you to be more iterative and your model to change as the business changes.

      The image contains an example of an operating model as described in the text above.

      Info-Tech Insight

      Every structure decision you make should be based on an identified need, not on a trend.Build your IT organization to enable the priorities of the organization.

      Each IT operating model is characterized by a variety of advantages and disadvantages

      Centralized

      Hybrid

      Decentralized

      Advantages
      • Maximum flexibility to allocate IT resources across business units.
      • Low-cost delivery model and greatest economies of scale.
      • Control and consistency offers opportunity for technological rationalization and standardization and volume purchasing at the highest degree.
      • Centralizes processes and services that require consistency across the organization.
      • Decentralizes processes and services that need to be responsive to local market conditions.
      • Eliminates duplication and redundancy by allowing effective use of common resources (e.g. shared services, standardization).
      • Goals are aligned to the distinct business units or functions.
      • Greater flexibility and more timely delivery of services.
      • Development resources are highly knowledgeable about business-unit-specific applications.
      • Business unit has greatest control over IT resources and can set and change priorities as needed.

      Disadvantages

      • Less able to respond quickly to local requirements with flexibility.
      • IT can be resistant to change and unwilling to address the unique needs of end users.
      • Business units can be frustrated by perception of lack of control over resources.
      • Development of special business knowledge can be limited.
      • Requires the most disciplined governance structure and the unwavering commitment of the business; therefore, it can be the most difficult to maintain.
      • Requires new processes as pooled resources must be staffed to approved projects.
      • Redundancies, conflicts, and incompatible technologies can result from business units having differentiated services and applications – increasing cost.
      • Ability to share IT resources is low due to lack of common approaches.
      • Lack of integration limits the communication of data between businesses and reduces common reporting.

      Decentralization can take many forms – define what it means to your organization

      Decentralization can take a number of different forms depending on the products the organization supports and how the organization is geographically distributed. Use the following set of explanations to understand the different types of decentralization possible and when they may make sense for supporting your organizational objectives.

      Line of Business

      Decentralization by lines of business (LoB) aligns decision making with business operating units based on related functions or value streams. Localized priorities focus the decision making from the CIO or IT leadership team. This form of decentralization is beneficial in settings where each line of business has a unique set of products or services that require specific expertise or flexible resourcing staffing between the teams.

      Product Line

      Decentralization by product line organizes your team into operationally aligned product families to improve delivery throughput, quality, and resource flexibility within the family. By adopting this approach, you create stable product teams with the right balance between flexibility and resource sharing. This reinforces value delivery and alignment to enterprise goals within the product lines.

      Geographical

      Geographical decentralization reflects a shift from centralized to regional influences. When teams are in different locations, they can experience a number of roadblocks to effective communication (e.g. time zones, regulatory differences in different countries) that may necessitate separating those groups in the organizational structure, so they have the autonomy needed to make critical decisions.

      Functional

      Functional decentralization allows the IT organization to be separated by specialty areas. Organizations structured by functional specialization can often be organized into shared service teams or centers of excellence whereby people are grouped based on their technical, domain, or functional area within IT (Applications, Data, Infrastructure, Security, etc.). This allows people to develop specialized knowledge and skills but can also reinforce silos between teams.

      2.4 Review and select a base operating model sketch

      1 hour

      1. Review the set of base operating model sketches available on the following slides.
      2. For each operating model sketch, there are benefits and risks to be considered. Make an informed selection by understanding the risks that your organization might be taking on by adopting that particular operating model.
      3. If at any point in the selection process the group is unsure about which operating model will be the right fit, refer back to your design principles established in activity 1.4. These should guide you in the selection of the right operating model and eliminate those which will not serve the organization.
      InputOutput
      • Organizational design principles
      • Customized list of IT capabilities
      • Operating model sketch examples
      • Selected operating model sketch
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership

      Record the results in the Organizational Design Workbook

      Centralized Operating Model #1: Plan-Build-Run

      I want to…

      • Establish a formalized governance process that takes direction from the organization on which initiatives should be prioritized by IT.
      • Ensure there is a clear separation between teams that are involved in strategic planning, building solutions, and delivering operational support.
      • Be able to plan long term by understanding the initiatives that are coming down the pipeline and aligning to an infrequent budgeting plan.

      BENEFITS

      • Effective at implementing long-term plans efficiently; separates maintenance and projects to allow each to have the appropriate focus.
      • More oversight over financials; better suited for fixed budgets.
      • Works across centralized technology domains to better align with the business’ strategic objectives – allows for a top-down approach to decision making.
      • Allows for economies of scale and expertise pooling to improve IT’s efficiency.
      • Well-suited for a project-driven environment that employs waterfall or a hybrid project management methodology that is less iterative.

      RISKS

      • Creates artificial silos between the build (developers) and run (operations staff) teams, as both teams focus on their own responsibilities and often fail to see the bigger picture.
      • Miss opportunities to deliver value to the organization or innovate due to an inability to support unpredictable/shifting project demands as decision making is centralized in the plan function.
      • The portfolio of initiatives being pursued is often determined before requirements analysis takes place, meaning the initiative might be solving the wrong need or problem.
      • Depends on strong hand-off processes to be defined and strong knowledge transfer from build to run functions in order to be successful.
      The image contains an example of a Centralized Operating Model: Plan-Build-Run.

      Centralized Operating Model #2: Demand-Develop-Service

      I want to…

      • Listen to the business to understand new initiatives or service enhancements being requested.
      • Enable development and operations to work together to seamlessly deliver in a DevOps culture.
      • Govern and confirm that initiatives being requested by the business are still aligned to IT’s overarching strategy and roadmap before prioritizing those initiatives.

      BENEFITS

      • Aligns well with an end-to-end services model; constant attention to customer demand and service supply.
      • Centralizes service operations under one functional area to serve shared needs across lines of business.
      • Allows for economies of scale and expertise pooling to improve IT’s efficiency.
      • Elevates sourcing and vendor management as its own strategic function; lends well to managed service and digital initiatives.
      • Development and operations housed together; lends well to DevOps-related initiatives and reduces the silos between these two core groups.

      RISKS

      • IT prioritizes the initiatives it thinks are a priority to the business based on how well it establishes good stakeholder relations and communications.
      • Depends on good governance to prevent enhancements and demands from being prioritized without approval from those with accountability and authority.
      • This model thrives in a DevOps culture but does not mean it ensures your organization is a “DevOps” organization. Be sure you're encouraging the right behaviors and attitudes.

      The image contains an example of a Centralized Operating Model: Demand, Develop, Service.

      Hybrid Operating Model #1: LOB/Functional Aligned

      I want to…

      • Better understand the various needs of the organization to align IT priorities and ensure the right services can be delivered.
      • Keep all IT decisions centralized to ensure they align with the overarching strategy and roadmap that IT has set.
      • Organize your shared services in a strategic manner that enables delivery of those services in a way that fits the culture of the organization and the desired method of operating.

      BENEFITS

      • Best of both worlds of centralization and decentralization; attempts to channel benefits from both centralized and decentralized models.
      • Embeds key IT functions that require business knowledge within functional areas, allowing for critical feedback and the ability to understand those business needs.
      • Places IT in a position to not just be “order takers” but to be more involved with the different business units and promote the value of IT.
      • Achieves economies of scale where necessary through the delivery of shared services that can be requested by the function.
      • Shared services can be organized to deliver in the best way that suits the organization.

      RISKS

      • Different business units may bypass governance to get their specific needs met by functions – to alleviate this, IT must have strong governance and prioritize amongst demand.
      • Decentralized role can be viewed as an order taker by the business if not properly embedded and matured.
      • No guaranteed synergy and integration across functions; requires strong communication, collaboration, and steering.
      • Cannot meet every business unit’s needs – can cause tension from varying effectiveness of the IT functions.

      The image contains an example of a Hybrid Operating Model: LOB/Functional Aligned.

      Hybrid Model #2: Product-Aligned Operating Model

      I want to…

      • Align my IT organization into core products (services) that IT provides to the organization and establish a relationship with those in the organization that have alignment to that product.
      • Have roles dedicated to the lifecycle of their product and ensure the product can continuously deliver value to the organization.
      • Maintain centralized set of standards as it applies to overall IT strategy, security, and architecture to ensure consistency across products and reduce silos.

      BENEFITS

      • Focus is on the full lifecycle of a product – takes a strategic view of how technology enables the organization.
      • Promotes centralized backlog around a specific value creator, rather than a traditional project focus that is more transactional.
      • Dedicated teams around the product family ensure you have all of the resources required to deliver on your product roadmap.
      • Reduces barriers between IT and business stakeholders; focuses on technology as a key strategic enabler.
      • Delivery is largely done through frequent releases that can deliver value.

      RISKS

      • If there is little or no business involvement, it could prevent IT from truly understanding business demand and prioritizing the wrong work.
      • A lack of formal governance can create silos between the IT products, causing duplication of efforts, missed opportunities for collaboration, and redundancies in application or vendor contracts.
      • Members of each product can interpret the definition of standards (e.g. architecture, security) differently.

      The image contains an example of the Hybrid Operating Model: Product-Aligned Operating Model.

      Hybrid Operating Model #3: Service-Aligned Operating Model

      I want to…

      • Decentralize the IT organization by the various IT services it offers to the organization while remaining centralized with IT strategy, governance, security and operational services.
      • Ensure IT services are defined and people resources are aligned to deliver on those services.
      • Enable each of IT’s services to have the autonomy to understand the business needs and be able to manage the operational and new project initiatives with a dedicated service owner or business relationship manager.

      BENEFITS

      • Strong enabler of agility as each service has the autonomy to make decisions around operational work versus project work based on their understanding of the business demand.
      • Individuals in similar roles that are decentralized across services are given coaching to provide common direction.
      • Allows teams to efficiently scale with service demand.
      • This is a structurally baseline DevOps model. Each group will have services built within that have their own dedicated teams that will handle the full gambit of responsibilities, from new features to enhancements and maintenance.

      RISKS

      • Service owners require a method to collaborate to avoid duplication of efforts or projects that conflict with the efforts of other IT services.
      • May result in excessive cost through role redundancies across different services, as each will focus on components like integration, stakeholder management, project management, and user experiences.
      • Silos cause a high degree of specialization, making it more difficult for team members to imagine moving to another defined service group, limiting potential career advancement opportunities.
      • The level of complex knowledge required by shared services (e.g. help desk) is often beyond what they can provide, causing them to rely on and escalate to defined service groups more than with other operating models.

      The image contains an example of the Hybrid Operating Model: Service-Aligned Operating Model.

      Decentralized Model: Division Decentralization (LoB, Geography, Function, Product)

      I want to…

      • Decentralize the IT organization to enable greater autonomy within specific groups that have differing customer demands and levels of support.
      • Maintain a standard level of service that can be provided by IT for all divisions.
      • Ensure each division has access to critical data and reports that supports informed decision making.

      BENEFITS

      • Organization around functions allows for diversity in approach in how areas are run to best serve a specific business unit’s needs.
      • Each functional line exists largely independently, with full capacity and control to deliver service at the committed SLAs.
      • Highly responsive to shifting needs and demands with direct connection to customers and all stages of the solution development lifecycle.
      • Accelerates decision making by delegating authority lower into the function.
      • Promotes a flatter organization with less hierarchy and more direct communication with the CIO.

      RISKS

      • Requires risk and security to be centralized and have oversight of each division to prevent the decisions of one division from negatively impacting other divisions or the enterprise.
      • Less synergy and integration across what different lines of business are doing can result in redundancies and unnecessary complexity.
      • Higher overall cost to the IT group due to role and technology duplication across different divisions.
      • It will be difficult to centralize aspects of IT in the future, as divisions adopt to a culture of IT autonomy.

      The image contains an example of the Decentralized Model: Division Decentralization.

      Enterprise Model: Multi-Modal

      I want to…

      • Have an organizational structure that leverages several different operating models based on the needs and requirements of the different divisions.
      • Provide autonomy and authority to the different divisions so they can make informed and necessary changes as they see fit without seeking approval from a centralized IT group.
      • Support the different initiatives the enterprise is focused on delivering and ensure the right model is adopted based on those initiatives.

      BENEFITS

      • Allows for the organization to work in ways that best support individual areas; for example, areas that support legacy systems can be supported through traditional operating models while areas that support digital transformations may be supported through more flexible operating models.
      • Enables a specialization of knowledge related to each division.

      RISKS

      • Inconsistency across the organization can lead to confusion on how the organization should operate.
      • Parts of the organization that work in more traditional operating models may feel limited in career growth and innovation.
      • Cross-division initiatives may require greater oversight and a method to enable operations between the different focus areas.

      The image contains an example of the Enterprise Model: Multi-Modal.

      Create enabling teams that bridge your divisions

      The following bridges might be necessary to augment your divisions:

      • Specialized augmentation: There might not be a sufficient number of resources to support each division. These teams will be leveraged across the divisions; this means that the capabilities needed for each division will exist in this bridge team, rather than in the division.
      • Centers of Excellence: Capabilities that exist within divisions can benefit from shared knowledge across the enterprise. Your organization might set up centers of excellence to support best practices in capabilities organization wide. These are Forums in the unfix model, or communities of practice and support capability development rather than deliveries of each division.
      • Facilitation teams might be required to support divisions through coaching. This might include Agile or other coaches who can help teams adopt practices and embed learnings.
      • Holistic teams provide an enterprise view as they work with various divisions. This can include capabilities like user experience, which can benefit from the holistic perspective rather than a siloed one. People with these capabilities augment the divisions on an as-needed basis.
      The image contains a diagram to demonstrate the use of bridges on divisions.

      2.5 Customize the selected sketch to reflect the desired future state

      1-3 hours

      1. Using the baseline operating model sketch, walk through each of the IT capabilities. Based on the outputs from activity 2.1:
        1. Remove any capabilities for which your IT organization is not responsible and/or accountable.
        2. Augment the language of specific capabilities that you feel are not directly reflective of what is being done within your organizational context or that you feel need to be changed to reflect more specifically how work is being done in your organization.
        3. Add any core capabilities from your organization that are missing from the provided IT capability list.
      2. Move capabilities to the right places in the operating model to reflect how each of the core IT processes should interact with one another.
      3. Add bridges as needed to support the divisions in your organization. Identify which capabilities will sit in these bridges and define how they will enable the operating model sketch to deliver.
      InputOutput
      • Selected base operating model sketch
      • Customized list of IT capabilities
      • Understanding of outsourcing and gaps
      • Customized operating model sketch
      MaterialsParticipants
      • Whiteboard/flip charts
      • Operating model sketch examples
      • CIO
      • IT Leadership

      Record the results in the Organizational Design Workbook

      Document the final operating model sketch in the Communications Deck

      Phase 3

      Formalize the Organizational Structure

      This phase will walk you through the following activities:

      3.1 Create work units

      3.2 Create work unit mandates

      3.3 Define roles inside the work units

      3.4 Finalize the organizational chart

      3.5 Identify and mitigate key risks

      This phase involves the following participants:

      • CIO
      • IT Leadership
      • Business Leadership

      Embed change management into the organizational design process

      Enable adoption of the new structure.

      You don’t have to make the change in one big bang. You can adopt alternative transition plans such as increments or pilots. This allows people to see the benefits of why you are undergoing the change, allows the change message to be repeated and applied to the individuals impacted, and provides people with time to understand their role in making the new organizational structure successful.

      “Transformational change can be invigorating for some employees but also highly disruptive and stressful for others.”

      Source: OpenStax, 2019

      Info-Tech Insight

      Without considering the individual impact of the new organizational structure on each of your employees, the change will undoubtedly fail in meeting its intended goals and your organization will likely fall back into old structured habits.

      Use a top-down approach to build your target-state IT organizational sketch

      The organizational sketch is the outline of the organization that encompasses the work units and depicts the relationships among them. It’s important that you create the structure that’s right for your organization, not one that simply fits with your current staff’s skills and knowledge. This is why Info-Tech encourages you to use your operating model as a mode of guidance for structuring your future-state organizational sketch.

      The organizational sketch is made up of unique work units. Work units are the foundational building blocks on which you will define the work that IT needs to get done. The number of work units you require and their names will not match your operating model one to one. Certain functional areas will need to be broken down into smaller work units to ensure appropriate leadership and span of control.

      Use your customized operating model to build your work units

      WHAT ARE WORK UNITS?

      A work unit is a functional group or division that has a discrete set of processes or capabilities that it is responsible for, which don’t overlap with any others. Your customized list of IT capabilities will form the building blocks of your work units. Step one in the process of building your structure is grouping IT capabilities together that are similar or that need to be done in concert in the case of more complex work products. The second step is to iterate on these work units based on the organizational design principles from Phase 1 to ensure that the future-state structure is aligned with enablement of the organization’s objectives.

      Work Unit Examples

      Here is a list of example work units you can use to brainstorm what your organization’s could look like. Some of these overlap in functionality but should provide a strong starting point and hint at some potential alternatives to your current way of organizing.

      • Office of the CIO
      • Strategy and Architecture
      • Architecture and Design
      • Business Relationship Management
      • Projection and Portfolio Management
      • Solution Development
      • Solution Delivery
      • DevOps
      • Infrastructure and Operations
      • Enterprise Information Security
      • Security, Risk & Compliance
      • Data and Analytics

      Example of work units

      The image contains an example of work units.

      3.1 Create functional work units

      1-3 hours

      1. Using a whiteboard or large tabletop, list each capability from your operating model on a sticky note and recreate your operating model. Use one color for centralized activities and a second color for decentralized activities.
      2. With the group of key IT stakeholders, review the operating model and any important definitions and rationale for decisions made.
      3. Starting with your centralized capabilities, review each in turn and begin to form logical groups of compatible capabilities. Review the decentralized capabilities and repeat the process, writing additional sticky notes for capabilities that will be repeated in decentralized units.
      4. Note: Not all capabilities need to be grouped. If you believe that a capability has a high enough priority, has a lot of work, or is significantly divergent from others put this capability by itself.
      5. Define a working title for each new work unit, and discuss the pros and cons of the model. Ensure the work units still align with the operating model and make any changes to the operating model needed.
      6. Review your design principles and ensure that they are aligned with your new work units.
      InputOutput
      • Organizational business objectives
      • Customized operating model
      • Defined work units
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Workbook

      Group formation

      Understand the impact of the functional groups you create.

      A group consists of two or more individuals who are working toward a common goal. Group formation is how those individuals are organized to deliver on that common goal. It should take into consideration the levels of hierarchy in your structure, the level of focus you give to processes, and where power is dispersed within your organizational design.

      Importance: Balance highly important capabilities with lower priority capabilities

      Specialization: The scope of each role will be influenced by specialized knowledge and a dedicated leader

      Effectiveness: Group capabilities that increase their efficacy

      Span of Control: Identify the right number of employees reporting to a single leader

      Choose the degree of specialization required

      Be mindful of the number of hats you’re placing on any one role.

      • Specialization exists when individuals in an organization are dedicated to performing specific tasks associated with a common goal and requiring a particular skill set. Aligning the competencies required to carry out the specific tasks based on the degree of complexity associated with those tasks ensures the right people and number of people can be assigned.
      • When people are organized by their specialties, it reduces the likelihood of task switching, reduces the time spent training or cross-training, and increases the focus employees can provide to their dedicated area of specialty.
      • There are disadvantages associated with aligning teams by their specialization, such as becoming bored and seeing the tasks they are performing as monotonous. Specialization doesn’t come without its problems. Monitor employee motivation

      Info-Tech Insight

      Smaller organizations will require less specialization simply out of necessity. To function and deliver on critical processes, some people might be asked to wear several hats.

      Avoid overloading the cognitive capacity of employees

      Cognitive load refers to the number of responsibilities that one can successfully take on.

      • When employees are assigned an appropriate number of responsibilities this leads to:
        • Engaged employees
        • Less task switching
        • Increased effectiveness on assigned responsibilities
        • Reduced bottlenecks
      • While this cognitive load can differ from employee to employee, when assigning role responsibilities, ensure each role isn’t being overburdened and spreading their focus thin.
      • Moreover, capable does not equal successful. Just because someone has the capability to take on more responsibilities doesn’t mean they will be successful.
      • Leverage the cognitive load being placed on your team to help create boundaries between teams and demonstrate clear role expectations.
      Source: IT Revolution, 2021

      Info-Tech Insight

      When you say you are looking for a team that is a “jack of all trades,” you are likely exceeding appropriate cognitive loads for your staff and losing productivity to task switching.

      Factors to consider for span of control

      Too many and too few direct reports have negative impacts on the organization.

      Complexity: More complex work should have fewer direct reports. This often means the leader will need to provide lots of support, even engaging in the work directly at times.

      Demand: Dynamic shifts in demand require more managerial involvement and therefore should have a smaller span of control. Especially if this demand is to support a 24/7 operation.

      Competency Level: Skilled employees should require less hands-on assistance and will be in a better position to support the business as a member of a larger team than those who are new to the role.

      Purpose: Strategic leaders are less involved in the day-to-day operations of their teams, while operational leaders tend to provide hands-on support, specifically when short-staffed.

      Group formation will influence communication structure

      Pick your poison…

      It’s important to understand the impacts that team design has on your services and products. The solutions that a team is capable of producing is highly dependent on how teams are structured. For example, Conway’s Law tells us that small distributed software delivery teams are more likely to produce modular service architecture, where large collocated teams are better able to create monolithic architecture. This doesn’t just apply to software delivery but also other products and services that IT creates. Note that small distributed teams are not the only way to produce quality products as they can create their own silos.

      Sources: Forbes, 2017

      Create mandates for each of your identified work units

      WHAT ARE WORK UNIT MANDATES?

      The work unit mandate should provide a quick overview of the work unit and be clear enough that any reader can understand why the work unit exists, what it does, and what it is accountable for.

      Each work unit will have a unique mandate. Each mandate should be distinguishable enough from your other work units to make it clear why the work is grouped in this specific way, rather than an alternative option. The mandate will vary by organization based on the agreed upon work units, design archetype, and priorities.

      Don’t just adopt an example mandate from another organization or continue use of the organization’s pre-existing mandate – take the time to ensure it accurately depicts what that group is doing so that its value-added activities are clear to the larger organization.

      Examples of Work Unit Mandates

      The Office of the CIO will be a strategic enabler of the IT organization, driving IT organizational performance through improved IT management and governance. A central priority of the Office of the CIO is to ensure that IT is able to respond to evolving environments and challenges through strategic foresight and a centralized view of what is best for the organization.

      The Project Management Office will provide standardized and effective project management practices across the IT landscape, including an identified project management methodology, tools and resources, project prioritization, and all steps from project initiation through to evaluation, as well as education and development for project managers across IT.

      The Solutions Development Group will be responsible for the high-quality development and delivery of new solutions and improvements and the production of customized business reports. Through this function, IT will have improved agility to respond to new initiatives and will be able to deliver high-quality services and insights in a consistent manner.

      3.2 Create work unit mandates

      1-3 hours

      1. Break into teams of three to four people and assign an equal number of work units to each team.
      2. Have each team create a set of statements that describe the overall purpose of that working group. Each mandate statement should:
      • Be clear enough that any reader can understand.
      • Explain why the work unit exists, what it does, and what it is accountable for.
      • Be distinguishable enough from your other work units to make it clear why the work is grouped in this specific way, rather than an alternative option.
    • Have each group present their work unit mandates and make changes wherever necessary.
    • InputOutput
      • Work units
      • Work unit mandates
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Workbook

      Identify the key roles and responsibilities for the target IT organization

      Now that you have identified the main units of work in the target IT organization, it is time to identify the roles that will perform that work. At the end of this step, the key roles will be identified, the purpose statement will be built, and accountability and responsibility for roles will be clearly defined. Make sure that accountability for each task is assigned to one role only. If there are challenges with a role, change the role to address them (e.g. split roles or shift responsibilities).

      The image contains an example of two work units: Enterprise Architecture and PMO. It then lists the roles of the two work units.

      Info-Tech Insight

      Do not bias your role design by focusing on your existing staff’s competencies. If you begin to focus on your existing team members, you run the risk of artificially narrowing the scope of work or skewing the responsibilities of individuals based on the way it is, rather than the way it should be.

      3.3 Define roles inside the work units

      1-3 hours

      1. Select a work unit from the organizational sketch.
      2. Describe the most senior role in that work unit by asking, “what would the leader of this group be accountable or responsible for?” Define this role and move the capabilities they will be accountable for under that leader. Repeat this activity for the capabilities this leader would be responsible for.
      3. Continue to define each role that will be required in that work unit to deliver or provide oversight related to those capabilities.
      4. Continue until key roles are identified and the capabilities each role will be accountable or responsible for are clarified.
      5. Remember, only one role can have accountability for each capability but several can have responsibility.
      6. For each role, use the list of capabilities that the position will be accountable, responsible, or accountable and responsible for to create a job description. Leverage your own internal job descriptions or visit our Job Descriptions page.
      InputOutput
      • Work units
      • Work unit mandates
      • Responsibilities
      • Accountabilities
      • Roles with clarified responsibilities and accountabilities
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Workbook

      Delivery model for product or solution development

      Can add additional complexity or clarity

      • Certain organizational structures will require a specific type of resourcing model to meet expectations and deliver on the development or sustainment of core products and solutions.
      • There are four common methods that we see in IT organizations:
        • Functional Roles: Completed work is handed off from functional team to functional team sequentially as outlined in the organization’s SDLC.
        • Shared Service & Resource Pools (Matrix): Resources are pulled whenever the work requires specific skills or pushed to areas where product demand is high.
        • Product or System: Work is directly sent to the teams who are directly managing the product or directly supporting the requestor.
        • Skills & Competencies: Work is directly sent to the teams who have the IT and business skills and competencies to complete the work.
      • Each of these will lead to a difference in how the functional team is skilled. They could have a great understanding of their customer, the product, the solution, or their service.

      Info-Tech Insight

      Despite popular belief, there is no such thing as the Spotify model, and organizations that structured themselves based on the original Spotify drawing might be missing out on key opportunities to obtain productivity from employees.

      Sources: Indeed, 2020; Agility Scales

      There can be different patterns to structure and resource your product delivery teams

      The primary goal of any product delivery team is to improve the delivery of value for customers and the business based on your product definition and each product’s demand. Each organization will have different priorities and constraints, so your team structure may take on a combination of patterns or may take on one pattern and then transform into another.

      Delivery Team Structure Patterns

      How Are Resources and Work Allocated?

      Functional Roles

      Teams are divided by functional responsibilities (e.g. developers, testers, business analysts, operations, help desk) and arranged according to their placement in the software development lifecycle (SDLC).

      Completed work is handed off from team to team sequentially as outlined in the organization’s SDLC.

      Shared Service and Resource Pools

      Teams are created by pulling the necessary resources from pools (e.g. developers, testers, business analysts, operations, help desk).

      Resources are pulled whenever the work requires specific skills or pushed to areas where product demand is high.

      Product or System

      Teams are dedicated to the development, support, and management of specific products or systems.

      Work is directly sent to the teams who are directly managing the product or directly supporting the requester.

      Skills and Competencies

      Teams are grouped based on skills and competencies related to technology (e.g. Java, mobile, web) or familiarity with business capabilities (e.g. HR, Finance).

      Work is directly sent to the teams who have the IT and business skills and competencies to complete the work.

      Delivery teams will be structured according to resource and development needs

      Functional Roles

      Shared Service and Resource Pools

      Product or System

      Skills and Competencies

      When your people are specialists versus having cross-functional skills

      Leveraged when specialists such as Security or Operations will not have full-time work on the product

      When you have people with cross-functional skills who can self-organize around a product’s needs

      When you have a significant investment in a specific technology stack

      The image contains a diagram of functional roles.The image contains a diagram of shared service and resource pools.The image contains a diagram of product or system.The image contains a diagram of skills and competencies.

      For more information about delivering in a product operating model, refer to our Deliver Digital Products at Scale blueprint.

      3.4 Finalize the organizational chart

      1-3 hours

      1. Import each of your work units and the target-state roles that were identified for each.
      2. In the place of the name of each work unit in your organizational sketch, replace the work unit name with the prospective role name for the leader of that group.
      3. Under each of the leadership roles, import the names of team members that were part of each respective work unit.
      4. Validate the final structure as a group to ensure each of the work units includes all the necessary roles and responsibilities and that there is clear delineation of accountabilities between the work units.

      Input

      Output

      • Work units
      • Work unit mandates
      • Roles with accountabilities and responsibilities
      • Finalized organizational chart

      Materials

      Participants

      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Workbook & Executive Communications Deck

      Proactively consider and mitigate redesign risks

      Every organizational structure will include certain risks that should have been considered and accepted when choosing the base operating model sketch. Now that the final organizational structure has been created, consider if those risks were mitigated by the final organizational structure that was created. For those risks that weren’t mitigated, have a tactic to control risks that remain present.

      3.5 Identify and mitigate key risks

      1-3 hours

      1. For each of the operating model sketch options, there are specific risks that should have been considered when selecting that model.
      2. Take those risks and transfer them into the correct slide of the Organizational Design Workbook.
      3. Consider if there are additional risks that need to be considered with the new organizational structure based on the customizations made.
      4. For each risk, rank the severity of that risk on a scale of low, medium, or high.
      5. Determine one or more mitigation tactic(s) for each of the risks identified. This tactic should reduce the likelihood or impact of the risk event happening.
      InputOutput
      • Final organizational structure
      • Operating model sketch benefits and risks
      • Redesign risk mitigation plan
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Workbook

      Phase 4

      Plan for Implementation & Change

      This phase will walk you through the following activities:

      4.1 Select a transition plan

      4.2 Establish the change communication messages

      4.3 Be consistent with a standard set of FAQs

      4.4 Define org. redesign resistors

      4.5 Create a sustainment plan

      This phase involves the following participants:

      • CIO
      • IT Leadership
      • Business Leadership
      • HR Business Partners

      All changes require change management

      Change management is:

      Managing a change that requires replanning and reorganizing and that causes people to feel like they have lost control over aspects of their jobs.

      – Padar et al., 2017
      People Process Technology

      Embedding change management into organizational design

      PREPARE A

      Awareness: Establish the need for organizational redesign and ensure this is communicated well.

      This blueprint is mostly focused on the prepare and transition components.

      D

      Desire: Ensure the new structure is something people are seeking and will lead to individual benefits for all.

      TRANSITION K

      Knowledge: Provide stakeholders with the tools and resources to function in their new roles and reporting structure.

      A

      Ability: Support employees through the implementation and into new roles or teams.

      FUTURE R

      Reinforcement: Emphasize and reward positive behaviors and attitudes related to the new organizational structure.

      Implementing the new organizational structure

      Implementing the organizational structure can be the most difficult part of the process.

      • To succeed in the process, consider creating an implementation plan that adequately considers these five components.
      • Each of these are critical to supporting the final organizational structure that was established during the redesign process.

      Implementation Plan

      Transition Plan: Identify the appropriate approach to making the transition, and ensure the transition plan works within the context of the business.

      Communication Strategy: Create a method to ensure consistent, clear, and concise information can be provided to all relevant stakeholders.

      Plan to Address Resistance: Given that not everyone will be happy to move forward with the new organizational changes, ensure you have a method to hear feedback and demonstrate concerns have been heard.

      Employee Development Plan: Provide employees with tools, resources, and the ability to demonstrate these new competencies as they adjust to their new roles.

      Monitor and Sustain the Change: Establish metrics that inform if the implementation of the new organizational structure was successful and reinforce positive behaviors.

      Define the type of change the organizational structure will be

      As a result, your organization must adopt OCM practices to better support the acceptance and longevity of the changes being pursued.

      Incremental Change

      Transformational Change

      Organizational change management is highly recommended and beneficial for projects that require people to:

      • Adopt new tools and workflows.
      • Learn new skills.
      • Comply with new policies and procedures.
      • Stop using old tools and workflows.

      Organizational change management is required for projects that require people to:

      • Move into different roles, reporting structures, and career paths.
      • Embrace new responsibilities, goals, reward systems, and values.
      • Grow out of old habits, ideas, and behaviors.
      • Lose stature in the organization.

      Info-Tech Insight

      How you transition to the new organizational structure can be heavily influenced by HR. This is the time to be including them and leveraging their expertise to support the transition “how.”

      Transition Plan Options

      Description

      Pros

      Cons

      Example

      Big Bang Change

      Change that needs to happen immediately – “ripping the bandage off.”

      • It puts an immediate stop to the current way of operating.
      • Occurs quickly.
      • More risky.
      • People may not buy into the change immediately.
      • May not receive the training needed to adjust to the change.

      A tsunami in Japan stopped all imports and exports. Auto manufacturers were unable to get parts shipped and had to immediately find an alternative supplier.

      Incremental Change

      The change can be rolled out slower, in phases.

      • Can ensure that people are bought in along the way through the change process, allowing time to adjust and align with the change.
      • There is time to ensure training takes place.
      • It can be a timely process.
      • If the change is dragged on for too long (over several years) the environment may change and the rationale and desired outcome for the change may no longer be relevant.

      A change in technology, such as HRIS, might be rolled out one application at a time to ensure that people have time to learn and adjust to the new system.

      Pilot Change

      The change is rolled out for only a select group, to test and determine if it is suitable to roll out to all impacted stakeholders.

      • Able to test the success of the change initiative and the implementation process.
      • Able to make corrections before rolling it out wider, to aid a smooth change.
      • Use the pilot group as an example of successful change.
      • Able to gain buy-in and create change champions from the pilot group who have experienced it and see the benefits.
      • Able to prevent an inappropriate change from impacting the entire organization.
      • Lengthy process.
      • Takes time to ensure the change has been fully worked through.

      A retail store is implementing a new incentive plan to increase product sales. They will pilot the new incentive plan at select stores, before rolling it out broadly.

      4.1 Select a transition plan approach

      1-3 hours

      1. List each of the changes required to move from your current structure to the new structure. Consider:
        1. Changes in reporting structure
        2. Hiring new members
        3. Eliminating positions
        4. Developing key competencies for staff
      2. Once you’ve defined all the changes required, consider the three different transition plan approaches: big bang, incremental, and pilot. Each of the transition plan approaches will have drawbacks and benefits. Use the list of changes to inform the best approach.
      3. If you are proceeding with the incremental or the pilot, determine the order in which you will proceed with the changes or the groups that will pilot the new structure first.
      InputOutput
      • Customized operating model sketch
      • New org. chart
      • Current org. chart
      • List of changes to move from current to future state
      • Transition plan to support changes
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • HR Business Partners

      Record the results in the Organizational Design Workbook

      Make a plan to effectively manage and communicate the change

      Success of your new organizational structure hinges on adequate preparation and effective communication.

      The top challenge facing organizations in completing the organizational redesign is their organizational culture and acceptance of change. Effective planning for the implementation and communication throughout the change is pivotal. Make sure you understand how the change will impact staff and create tailored plans for communication.

      65% of managers believe the organizational change is effective when provided with frequent and clear communication.

      Source: SHRM, 2021

      Communicate reasons for organizational structure changes and how they will be implemented

      Leaders of successful change spend considerable time developing a powerful change message, i.e. a compelling narrative that articulates the desired end state, and that makes the change concrete and meaningful to staff.

      The organizational change message should:

      • Explain why the change is needed.
      • Summarize what will stay the same.
      • Highlight what will be left behind.
      • Emphasize what is being changed.
      • Explain how change will be implemented.
      • Address how change will affect various roles in the organization.
      • Discuss the staff’s role in making the change successful.

      Five elements of communicating change

      • What is the change?
      • Why are we doing it?
      • How are we going to go about it?
      • How long will it take us to do it?
      • What will the role be for each department and individual?
      Source: Cornelius & Associates, 2010

      4.2 Establish the change communication messages

      2 hours

      1. The purpose of this activity is to establish a change communication message you can leverage when talking to stakeholders about the new organizational structure.
      2. Review the questions in the Organizational Design Workbook.
      3. Establish a clear message around the expected changes that will have to take place to help realize the new organizational structure.
      InputOutput
      • Customized operating model sketch
      • New org. chart
      • Current org. chart
      • List of changes
      • Transition plan
      • Change communication message for new organizational structure
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Workbook

      Apply the following communication principles to make your IT organization redesign changes relevant to stakeholders

      Be Clear

      • Say what you mean and mean what you say.
      • Choice of language is important: “Do you think this is a good idea? I think we could really benefit from your insights and experience here.” Or do you mean: “I think we should do this. I need you to do this to make it happen.”
      • Don’t use jargon.

      Be Consistent

      • The core message must be consistent regardless of audience, channel, or medium.
      • Test your communication with your team or colleagues to obtain feedback before delivering to a broader audience.
      • A lack of consistency can be interpreted as an attempt at deception. This can hurt credibility and trust.

      Be Concise

      • Keep communication short and to the point so key messages are not lost in the noise.
      • There is a risk of diluting your key message if you include too many other details.

      Be Relevant

      • Talk about what matters to the stakeholder.
      • Talk about what matters to the initiative.
      • Tailor the details of the message to each stakeholder’s specific concerns.
      • IT thinks in processes but stakeholders only care about results: talk in terms of results.
      • IT wants to be understood but this does not matter to stakeholders. Think: “what’s in it for them?”
      • Communicate truthfully; do not make false promises or hide bad news.

      Frequently asked questions (FAQs) provide a chance to anticipate concerns and address them

      As a starting point for building an IT organizational design implementation, look at implementing an FAQ that will address the following:

      • The what, who, when, why, and where
      • The transition process
      • What discussions should be held with clients in business units
      • HR-centric questions

      Questions to consider answering:

      • What is the objective of the IT organization?
      • What are the primary changes to the IT organization?
      • What does the new organizational structure look like?
      • What are the benefits to our IT staff and to our business partners?
      • How will the IT management team share new information with me?
      • What is my role during the transition?
      • What impact is there to my reporting relationship within my department?
      • What are the key dates I should know about?

      4.3 Be consistent with a standard set of FAQs

      1 hour

      1. Beyond the completed communications plans, brainstorm a list of answers to the key “whats” of your organizational design initiative:
      • What is the objective of the IT organization?
      • What are the primary changes to the IT organization?
      • What does the new organizational structure look like?
      • What are the benefits to our IT staff and to our business partners?
    • Think about any key questions that may rise around the transition:
      • How will the IT management team share new information with me?
      • What is my role during the transition?
      • What impact is there to my reporting relationship within my department?
      • What are the key dates I should know about?
    • Determine the best means of socializing this information. If you have an internal wiki or knowledge-sharing platform, this would be a useful place to host the information.
    • InputOutput
      • Driver(s) for the new organizational structure
      • List of changes to move from current to future state
      • Change communication message
      • FAQs to provide to staff about the organizational design changes
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Workbook

      The change reaction model

      The image contains a picture of the change reaction model. The model includes a double arrow pointing in both directions of left and right. On top of the arrow are 4 circles spread out on the arrow. They are labelled: Active Resistance, Detachment, Questioning, Acceptance.

      (Adapted from Cynthia Wittig)

      Info-Tech Insight

      People resist changes for many reasons. When it comes to organizational redesign changes, some of the most common reasons people resist change include a lack of understanding, a lack of involvement in the process, and fear.

      Include employees in the employee development planning process

      Prioritize

      Assess employee to determine competency levels and interests.

      Draft

      Employee drafts development goals; manager reviews.

      Select

      Manager helps with selection of development activities.

      Check In

      Manager provides ongoing check-ins, coaching, and feedback.

      Consider core and supplementary components that will sustain the new organizational structure

      Supplementary sustainment components:

      • Tools & Resources
      • Structure
      • Skills
      • Work Environment
      • Tasks
      • Disincentives

      Core sustainment components:

      • Empowerment
      • Measurement
      • Leadership
      • Communication
      • Incentives

      Sustainment Plan

      Sustain the change by following through with stakeholders, gathering feedback, and ensuring that the change rationale and impacts are clearly understood. Failure to so increases the potential that the change initiative will fail or be a painful experience and cost the organization in terms of loss of productivity or increase in turnover rates.

      Support sustainment with clear measurements

      • Measurement is one of the most important components of monitoring and sustaining the new organizational structure as it provides insight into where the change is succeeding and where further support should be added.
      • There should be two different types of measurements:
      1. Standard Change Management Metrics
      2. Organizational Redesign Metrics
    • When gathering data around metrics, consider other forms of measurement (qualitative) that can provide insights on opportunities to enhance the success of the organizational redesign change.
      1. Every measurement should be rooted to a goal. Many of the goals related to organizational design will be founded in the driver of this change initiative
      2. Once the goals have been defined, create one or more measurements that determines if the goal was successful.
      3. Use specific key performance indicators (KPIs) that contain a metric that is being measured and the frequency of that measurement.

      Info-Tech Insight

      Obtaining qualitative feedback from employees, customers, and business partners can provide insight into where the new organizational structure is operating optimally versus where there are further adjustments that could be made to support the change.

      4.4 Consider sustainment metrics

      1 hour

      1. Establish metrics that bring the entire process together and that will ensure the new organizational design is a success.
      2. Go back to your driver(s) for the organizational redesign. Use these drivers to help inform a particular measurement that can be used to determine if the new organizational design will be successful. Each measurement should be related to the positive benefits of the organization, an individual, or the change itself.
      3. Once you have a list of measurements, use these to determine the specific KPI that can be qualified through a metric. Often you are looking for an increase or decrease of a particular measurement by a dollar or percentage within a set time frame.
      4. Use the example metrics in the workbook and update them to reflect your organization’s drivers.
      InputOutput
      • Driver(s) for the new organizational structure
      • List of changes to move from current to future state
      • Change communication message
      • Sustainment metrics
      MaterialsParticipants
      • Whiteboard/Flip Charts
      • CIO
      • IT Leadership
      • Business Leadership

      Record the results in the Organizational Design Workbook

      Related Info-Tech Research

      Build a Strategic IT Workforce Plan

      • Continue into the second phase of the organizational redesign process by defining the required workforce to deliver.
      • Leveraging trends, data, and feedback from your employees, define the competencies needed to deliver on the defined roles.

      Implement a New IT Organizational Structure

      • Organizational design implementations can be highly disruptive for IT staff and business partners.
      • Without a structured approach, IT leaders may experience high turnover, decreased productivity, and resistance to the change.

      Define the Role of Project Management in Agile and Product-Centric Delivery

      • There are many voices with different opinions on the role of project management. This causes confusion and unnecessary churn.
      • Project management and product management naturally align to different time horizons. Harmonizing their viewpoints can take significant work.

      Research Contributors and Experts

      The image contains a picture of Jardena London.

      Jardena London

      Transformation Catalyst, Rosetta Technology Group

      The image contains a picture of Jodie Goulden.

      Jodie Goulden

      Consultant | Founder, OrgDesign Works

      The image contains a picture of Shan Pretheshan.

      Shan Pretheshan

      Director, SUPA-IT Consulting

      The image contains a picture of Chris Briley.

      Chris Briley

      CIO, Manning & Napier

      The image contains a picture of Dean Meyer.

      Dean Meyer

      President N. Dean Meyer and Associates Inc.

      The image contains a picture of Jimmy Williams.

      Jimmy Williams

      CIO, Chocktaw Nation of Oklahoma

      Info-Tech Research Group

      Cole Cioran, Managing Partner

      Dana Daher, Research Director

      Hans Eckman, Principal Research Director

      Ugbad Farah, Research Director

      Ari Glaizel, Practice Lead

      Valence Howden, Principal Research Director

      Youssef Kamar, Senior Manager, Consulting

      Carlene McCubbin, Practice Lead

      Baird Miller, Executive Counsellor

      Josh Mori, Research Director

      Rajesh Parab, Research Director

      Gary Rietz, Executive Counsellor

      Bibliography

      “A Cheat Sheet for HR Professionals: The Organizational Development Process.” AIHR, 2021. Web.

      Acharya, Ashwin, Roni Lieber, Lissa Seem, and Tom Welchman. “How to identify the right ‘spans of control’ for your organization.” McKinsey, 21 December 2017. Web.

      Anand. N., and Jean-Louis Barsoux. “What everyone gets wrong about change management. Harvard Business Review, December 2017. Web.

      Atiken, Chris. “Operating model design-first principles.” From Here On, 24 August 2018. Web.

      “Avoid common digital transformation challenges: Address your IT Operating Model Now.” Sofigate, 5 May 2020. Web.

      Baumann, Oliver, and Brian Wu. “The many dimensions of research on designing flat firms.” Journal of Organizational Design, no. 3, vol. 4. 09 May 2022.Web.

      Bertha, Michael. “Cross the project to product chasm.” CIO, 1 May 2020. Web.

      Blenko, Marcia, and James Root. “Design Principles for a Robust Operating Model.” Bain & Company, 8 April 2015. Web.

      Blenko, Marcia, Leslie Mackrell, and Kevin Rosenberg. “Operating models: How non-profits get from strategy to results.” The Bridge Span Group, 15 August 2019. Web.

      Boulton, Clint. “PVH finds perfect fit in hybrid IT operating model amid pandemic.” CIO, 19 July 2021. Web.

      Boulton, Clint. “Why digital disruption leaves no room for bimodal IT.” CIO, 11 May 2017. Web.

      Bright, David, et al. “Chapter 10: Organizational Structure & Change.” Principles of Management, OpenStax, Rice University, 20 March 2019. Book.

      Campbell, Andrew. “Design Principles: How to manage them.” Ashridge Operating Models. 1 January 2022. Web.

      D., Maria. “3 Types of IT Outsourcing Models and How to Choose Between Them.” Cleveroad, 29 April 2022. Web.

      Devaney, Eric. “9 Types of Organizational Structure Every Company Should Consider.” HubSpot, 11 February 2022. Web.

      Devaney, Erik. “The six building blocks of organizational structure.” Hubspot, 3 June 2020. Web.

      Eisenman, M., S. Paruchuri, and P. Puranam. “The design of emergence in organizations.” Journal of Organization Design, vol. 9, 2020. Web.

      Forbes Business Development Council. “15 Clear Signs It’s Time to Restructure the Business.” Forbes, 10 February 2020. Web.

      Freed, Joseph. “Why Cognitive Load Could Be The Most Important Employee Experience Metric In The Next 10 Years.” Forbes, 30 June 2020. Web.

      Galibraith, Jay. “The Star Model.” JayGalbraith.com, n.d. Web.

      Girod, Stéphane, and Samina Karim. “Restructure or reconfigure?” Harvard Business Review, April 2017. Web.

      Goldman, Sharon. “The need for a new IT Operating Model: Why now?” CIO, 27 August 2019. Web.

      Halapeth, Milind. “New age IT Operating Model: Creating harmony between the old and the new.” Wirpo, n.d. Web.

      Harvey, Michelle. “Why a common operating model is efficient for business productivity.” CMC, 10 May 2020. Web.

      Helfand, Heidi. “Dynamic Reteaming.” O’Reilly Media, 7 July 2020. Book.

      JHeller, Martha. “How Microsoft CIO Jim DuBois changed the IT Operating Model.” CIO, 2 February 2016. Web.

      Heller, Martha. “How Stryker IT Shifted to a global operating model.” CIO, 19 May 2021. Web.

      Heller, Michelle. “Inside blue Shields of California’s IT operating model overhaul.” CIO, 24 February 2021. Web.

      Hessing, Ted. “Value Stream Mapping.” Six Sigma Study Guide, 11 April 2014. Web.

      Huber, George, P. “What is Organization Design.” Organizational Design Community, n.d. Web.

      Indeed Editorial Team. “5 Advantages and Disadvantages of the Matrix Organizational Structure.” Indeed, 23 November 2020. Web.

      Indeed Editorial Team. “How to plan an effective organization restructure.” Indeed, 10 June 2021. Web.

      “Insourcing vs Outsourcing vs Co-Sourcing.” YML Group, n.d. Web.

      “Investing in more strategic roles.” CAPS Research, 3 February 2022. Web.

      Jain, Gagan. “Product IT Operating Model: The next-gen model for a digital work.” DevOps, 22 July 2019. Web.

      Kane, Gerald, D. Plamer, and Anh Phillips. “Accelerating Digital Innovation Inside and Out.” Deloitte Insights, 4 June 2019. Web.

      Krush, Alesia. “IT companies with ‘flat’ structures: utopia or innovative approach?” Object Style, 18 October 2018. Web.

      Law, Michael. “Adaptive Design: Increasing Customer Value in Your Organisation.” Business Agility Institute, 5 October 2020. Web.

      LucidContent Team. “How to get buy-in for changes to your organizational structure.” Lucid Chart, n.d. Web.

      Matthews, Paul. “Do you know the difference between competence and capability?” The People Development Magazine, 25 September 2020. Web.

      Meyer, Dean N. “Analysis: Common symptoms of organizational structure problems.” NDMA, n.d. Web.

      Meyer, N. Dean. “Principle-based Organizational Structure.” NDMA Publishing, 2020. Web.

      Morales Pedraza, Jorge. Answer to posting, “What is the relationship between structure and strategy?” ResearchGate.net, 5 March 2014. Web.

      Nanjad, Len. “Five non-negotiables for effective organization design change.” MNP, 01 October 2021. Web.

      Neilson, Gary, Jaime Estupiñán, and Bhushan Sethi. “10 Principles of Organizational Design.” Strategy & Business, 23 March 2015. Web.

      Nicastro, Dom. “Understanding the Foundational Concepts of Organizational Design.” Reworked, 24 September 2020. Web.

      Obwegeser, Nikolaus, Tomoko Yokoi, Michael Wade, and Tom Voskes. “7 Key Principles to Govern Digital Initiatives.” MIT Sloan, 1 April 2020. Web.

      “Operating Models and Tools.” Business Technology Standard, 23 February 2021. Web.

      “Organizational Design Agility: Journey to a combined community.” ODF-BAI How Space, Organizational Design Forum, 2022. Web.

      “Organizational Design: Understanding and getting started.” Ingentis, 20 January 2021. Web.

      Padar, Katalin, et al. “Bringing project and change management roles into sync.” Journal of Change Management, 2017. Web.

      Partridge, Chris. “Evolve your Operating Model- It will drive everything.” CIO, 30 July 2021. Web.

      Pijnacker, Lieke. “HR Analytics: role clarity impacts performance.” Effectory, 25 September 2019. Web.

      Pressgrove, Jed. “Centralized vs. Federated: Breaking down IT Structures.” Government Technology, March 2020. Web.

      Sherman, Fraser. “Differences between Organizational Structure and Design.” Bizfluent, 20 September 2019. Web.

      Skelton, Matthew, and Manual Pais. “Team Cognitive Load.” IT Revolution, 19 January 2021. Web.

      Skelton, Matthew, and Manual Pais. Team Topologies. IT Revolution Press, 19 September 2019. Book

      Spencer, Janet, and Michael Watkins. “Why organizational change fails.” TLNT, 26 November 2019. Web.

      Storbakken, Mandy. “The Cloud Operating Model.” VMware, 27 January 2020. Web.

      "The Qualities of Leadership: Leading Change.” Cornelius & Associates, 2010. Web.

      “Understanding Organizational Structures.” SHRM, 31 August 2021. Web.

      "unfix Pattern: Base.” AgilityScales, n.d. Web.

      Walker, Alex. “Half-Life: Alyx helped change Valve’s Approach to Development.” Kotaku, 10 July 2020. Web.

      "Why Change Management.” Prosci, n.d. Web.

      Wittig, Cynthia. “Employees' Reactions to Organizational Change.” OD Practioner, vol. 44, no. 2, 2012. Web.

      Woods, Dan. “How Platforms are neutralizing Conway’s Law.” Forbes, 15 August 2017. Web.

      Worren, Nicolay, Jeroen van Bree, and William Zybach. “Organization Design Challenges. Results from a practitioner survey.” Journal of Organizational Design, vol. 8, 25 July 2019. Web.

      Appendix

      IT Culture Framework

      This framework leverages McLean & Company’s adaptation of Quinn and Rohrbaugh’s Competing Values Approach.

      The image contains a diagram of the IT Culture Framework. The framework is divided into four sections: Competitive, Innovative, Traditional, and Cooperative, each with their own list of descriptors.

      Acquire the Right Hires with Effective Interviewing

      • Buy Link or Shortcode: {j2store}576|cart{/j2store}
      • member rating overall impact: 8.5/10 Overall Impact
      • member rating average dollars saved: $15,749 Average $ Saved
      • member rating average days saved: 2 Average Days Saved
      • Parent Category Name: Attract & Select
      • Parent Category Link: /attract-and-select
      • Scope: Acquiring the best talent relies heavily on an effective interviewing process, which involves the strategic preparation of stakeholders, including interviewers. Asking the most effective questions will draw out the most appropriate information to best assess the candidate. Evaluating the interview process and recording best practices will inspire continuous interviewing improvement within the organization.
      • Challenge: The majority of organizations do not have a solid interviewing process in place, and most interviewers are not practiced at interviewing. This results in many poor hiring decisions, costing the organization in many ways. Upsizing is on the horizon, the competition for good talent is escalating, and distinguishing between a good interviewee and a good candidate fit for a position is becoming more difficult.
      • Pain/Risk: Although properly preparing for and conducting an interview requires additional time on the part of HR, the hiring manager, and all interviewers involved, the long-term benefits of an effective interview process positively affect the organization’s bottom line and company morale.

      Our Advice

      Critical Insight

      • Most interviewers are not as good as they think they are, resulting in many poor hiring decisions. A poor hire can cost an organization up to 15 times the position’s annual salary, as well as hurt employee morale.
      • The Human Resources department needs to take responsibility for an effective interview process, but the business needs to take responsibility for developing its new hire needs, and assessing the candidates using the best questions and the most effective interview types and techniques.
      • All individuals with a stake in the interview process need to invest sufficient time to help define the ideal candidate, understand their roles and decision rights in the process, and prepare individually to interview effectively.
      • There are hundreds of different interview types, techniques, and tools for an organization to use, but the most practiced and most effective is behavioral interviewing.
      • There is no right interview type and technique. Each hiring scenario needs to be evaluated to pick the appropriate type and technique that should be practiced, and the right questions that should be asked.

      Impact and Result

      • Gain insight into and understand the need for a strong interview process.
      • Strategize and plan your organization’s interview process, including how to make up an ideal candidate profile, who should be involved in the process, and how to effectively match interview types, techniques, and questions to assess the ideal candidate attributes.
      • Understand various hiring scenarios, and how an interview process may be modified to reflect your organization’s scenario.
      • Learn about the most common interview types and techniques, when they are appropriate to use, and best practices around using them effectively.
      • Evaluate your interview process and yourself as an interviewer to better inform future candidate interviewing strategy.

      Acquire the Right Hires with Effective Interviewing Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Implement an effective interview and continuous improvement process

      Acquire the right hire.

      • Storyboard: Acquire the Right Hires with Effective Interviewing

      2. Document all aspects of your interview strategy and plan with stakeholders

      Ensure an effective and seamless interview process.

      • Candidate Interview Strategy and Planning Guide

      3. Recognize common interviewing errors and study best practices to address these errors

      Be an effective interviewer.

      • Screening Interview Template
      • Interview Guide Template
      • Supplement: Quick Fixes to Common Interview Errors
      • Pre-interview Guide for Interviewers
      • Candidate Communication Template
      [infographic]

      Take a Realistic Approach to Disaster Recovery Testing

      • Buy Link or Shortcode: {j2store}414|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: DR and Business Continuity
      • Parent Category Link: /business-continuity

      You have made significant investments in availability and disaster recovery – but your ability to recover hasn’t been tested in years. Testing will:

      • Improve your DR capabilities.
      • Identify required changes to planning documentation and procedures.
      • Validate DR capabilities for interested customers and auditors.

      Our Advice

      Critical Insight

      • If you treat testing as a pass/fail exercise, you aren’t meeting the end goal of improving organizational resilience.
      • Focus on identifying gaps and risks, and addressing them, before a real disaster hits.
      • Take a realistic, iterative approach to resilience testing that starts with small, low-risk tests and builds on lessons learned.

      Impact and Result

      • Identify testing scenarios and scope that can deliver value to your organization.
      • Create practical test plans with Info-Tech’s template.
      • Demonstrate value from testing to gain buy-in for additional tests.

      Take a Realistic Approach to Disaster Recovery Testing Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Take a Realistic Approach to Disaster Recovery Testing Storyboard – A guide to establishing a right-sized approach to DR testing that delivers durable value to your organization.

      Use this research to understand the different types of tests, prioritize and plan tests for your organization, review the results, and establish a cadence for testing.

      • Take a Realistic Approach to Disaster Recovery Testing Storyboard

      2. Disaster Recovery Test Plan Template – A template to document your organization's DR test plan.

      Use this template to document scope and goals, participants, key pre-test milestones, the test-day schedule, and your findings from the testing exercise.

      • Disaster Recovery Test Plan Template

      3. Disaster Recovery Testing Program Summary – A template to outline your organization's DR testing program.

      Identify the tests you will run over the next year and the expertise, governance, process, and funding required to support testing.

      • Disaster Recovery Testing Program Summary

      [infographic]

       

      Further reading

      Take a Realistic Approach to Disaster Recovery Testing

      Reduce costly downtime with a right-sized testing program that improves IT resilience.

      Analyst Perspective

      Reduce costly downtime with a right-sized testing program that improves IT resilience.

      Andrew Sharp

      Most businesses make significant investments in disaster recovery and technology resilience. Redundant sites and systems, monitoring, intrusion prevention, backups, training, documentation: it all costs time and money.

      But does this investment deliver expected value? Specifically, can you deliver service continuity in a way that meets business requirements?

      You can’t know the answer without regularly testing recovery processes and systems. And more than just validation, testing helps you deliver service continuity by finding and addressing gaps in your plans and training your staff on recovery procedures.

      Use the insights, tools, and templates in this research to create a streamlined and effective resilience testing program that helps validate recovery capabilities and enhance service reliability, availability, and continuity.

      Andrew Sharp

      Research Director, Infrastructure & Operations
      Info-Tech Research Group

      Executive Summary

      Your Challenge

      You have made significant investments in availability and disaster recovery (DR) – but your ability to recover hasn’t been tested in years. Testing will:

      • Improve your DR capabilities.
      • Identify required changes to planning documentation and procedures.
      • Validate DR capabilities for interested customers and auditors.

      Common Obstacles

      Despite the value testing can offer, actually executing on DR tests is difficult because:

      • Testing is often an IT-driven initiative, and it can be difficult to secure business buy-in to redirect resources away from other urgent projects or accept risks that come with testing.
      • Previous tests have been overly complex and challenging to coordinate and leave a hangover so bad that no one wants to do them again.

      Info-Tech's Approach

      Take a realistic approach to resilience testing by starting with small, low-risk tests, then iterating with the lessons you’ve learned:

      • Identify testing scenarios and scope that can deliver value to your organization.
      • Create practical test plans with Info-Tech’s template.
      • Get buy-in for regular DR testing from key stakeholders with a testing program summary.

      Info-Tech Insight

      If you treat testing as a pass/fail exercise, you aren’t meeting the end goal of improving organizational resilience. Focus on identifying gaps and risks so you can address them before a real disaster hits.

      Process and Outputs

      This research is accompanied by templates to help you achieve your goals faster.

      1 - Establish the business rationale for DR testing.
      2 - Review a range of options for testing.
      3 - Prioritize tests that are most valuable to your business.
      4 - Create a disaster recovery test plan.
      5 - Establish a Test Program to support a regular testing cycle.

      Outputs:

      DR Test Plan
      DR Testing Program Summary

      Example Orange Activity slide.
      Orange activity slides like the one on the left provide directions to help you make key decisions.

      Key Deliverable:

      Disaster Recovery Test Plan Template

      Build a plan for your first disaster recovery test.

      This document provides a complete example you can use to quickly build your own plan, including goals, milestones, participants, the test-day schedule, and findings from the after-action review.

      Why test?

      Testing helps you avoid costly downtime

      • In a disaster scenario, speed matters. Immediately after an outage, the impact on the organization is small, but impact increases rapidly the longer the outage continues.
      • A quick and reliable response and recovery can protect the organization from significant losses.
      • A DRP testing and maintenance program helps ensure you’re ready to recover when you need to, rather than figuring it out as you go.

      “Routine testing is vital to survive a disaster… that’s when muscle memory sets in. If you don’t test your DR plan it falls [in importance], and you never see how routine changes impact it.”

      – Jennifer Goshorn
      Chief Administrative Officer
      Gunderson Dettmer LLP

      Info-Tech members estimated even one day of system downtime could lead to significant revenue losses. Estimated loss of revenue over 24 hours. Core Infrastructure has the highest potential for lost revenue.

      Average estimated potential loss* in thousands of USD due to a 24-hour outage (N=41)

      *Data aggregated from 41 business impact analyses (BIAs) conducted with Info-Tech advisory assistance. BIAs evaluate potential revenue loss due to a full day of system downtime, at the worst possible time.

      Run tests to enhance disaster recovery plans

      Testing improves organizational resilience

      • Identify and address gaps in your plans before a real disaster strikes.
      • Cross-train staff on systems recovery.
      • Go beyond testing technology to test recovery processes.
      • Establish a culture that centers resilience in everyday decision-making.

      Testing keeps DR documentation ready for action

      • Update documentation ahead of tests to prepare for the testing exercise.
      • Update documentation after testing to incorporate any lessons learned.

      Testing validates that investments in resilience deliver value

      • Confirm your organization can meet defined recovery time objectives (RTOs) and recovery point objectives (RPOs).
      • Provide proof of testing for auditors, prospective customers, and insurance applications

      Overcome testing challenges

      Despite the value of effective recovery testing, most IT organizations struggle to test recovery plans

      Common challenges

      • Key resources don’t have time for testing exercises.
      • You don’t have the technology to support live recovery testing.
      • Tests are done ad hoc and lessons learned are lost.
      • A lack of business support for test exercises as the value isn’t understood.
      • Tests are always artificially simple because RTOs and RPOs must be met to satisfy customer or auditor inquiries

      Overcome challenges with a realistic approach:

      • Start small with tabletop and recovery tests for specific systems.
      • Include recovery tests in operational tasks (e.g. restore systems when you have a maintenance window).
      • Create testing plans for larger testing exercises.
      • Build on successful tests to streamline testing exercises in the future.
      • Don’t make testing a pass-fail exercise. Focus on identifying gaps and risks so you can address them before a real disaster hits.

      Go beyond traditional testing

      Different test techniques help validate recovery against different threats

      • There are many threats to service continuity, including ransomware, severe weather events, geopolitical conflict, legacy systems, staff turnover, and day-to-day outages caused by human error, software updates, hardware failures, or network outages.
      • At its core, disaster recovery planning is about recovery. A plan for service recovery will help you mitigate against many threats at once. The testing approaches on the right will help you validate different aspects of that recovery process.
      • This research will provide an overview of the approaches outlined on the right and help you prioritize tests that are most valuable to your organization.
      Different test techniques for disaster recover training: System Failover tests, tabletop exercises, ransomware recovery tests, etc.

      00 Identify a working group

      30 minutes

      Identify a group of participants who can fill the following roles and inform the discussions around testing in this research. A single person could fill multiple roles and some roles could be filled by multiple people. Many participants will be drawn from the larger DRP team.

      Roles and expectations for Disaster Recovery Planning. DRP sponsor, Testing coordinator, System testers, business liaisons, executive team.

      Input

      • Organizational context

      Output

      • A list of key participants for test planning and execution

      Participants

      • Typically, start by identifying the sponsor and coordinator and have them identify the other members of the working group.

      Start by updating your disaster recovery plan (DRP)

      Use Info-Tech’s Create a Right-Sized Disaster Recovery Plan research to identify recovery objectives based on business impact and outline recovery processes. Both are tremendously valuable inputs to your test plans.

      Overall Business Continuity Plan

      IT Disaster Recovery Plan

      A plan to restore IT services (e.g. applications and infrastructure) following a disruption. A DRP:

      • Identifies critical applications and dependencies.
      • Defines appropriate recovery objectives based on a business impact analysis (BIA).
      • Creates a step-by-step incident response plan.

      BCP for Each Business Unit

      A set of plans to resume business processes for each business unit. A business continuity plan (BCP) is also sometimes called a continuity of operations plan (COOP).

      BCPs are created and owned by each business unit, and creating a BCP requires deep involvement from the leadership of each business unit.

      Info-Tech’s Develop a Business Continuity Plan blueprint provides a methodology for creating business unit BCPs as part of an overall BCP for the organization.

      Crisis Management Plan

      A plan to manage a wide range of crises, from health and safety incidents to business disruptions to reputational damage.

      Info-Tech’s Implement Crisis Management Best Practices blueprint provides a framework for planning a response to any crisis, from health and safety incidents to reputational damage.

      01 Confirm: why test at all?

      15-30 minutes

      Identify the value recovery testing for your organization. Use language appropriate for a nontechnical audience. Start with the list below and add, modify, or delete bullet points to reflect your own organization.

       

      Drivers for testing – Examples:

       

      • Improve service continuity.
      • Identify and address gaps in recovery plans before a real disaster strikes.
      • Cross-train staff on systems recovery to minimize single points of failure.
      • Identify how we coordinate across teams during a major systems outage.
      • Exercise both recovery processes and technology.
      • Support a culture that centers system resilience in everyday decision-making.
      • Keep recovery documentation up-to-date and ready for action.
      • Confirm that our stated recovery objectives can be met.
      • Provide proof of testing for auditors, prospective customers, and insurance applications.
      • We require proof of testing to pass audits and renew cybersecurity insurance.

      Info-Tech Insight

      Time-strapped technical staff will sometimes push back on planning and testing, objecting that the team will “figure it out” in a disaster. But the question isn’t whether recovery is possible – it’s whether the recovery aligns with business needs. If your plan is to “MacGyver” a solution on the fly, you can’t know if it’s the right solution for your organization.

      Input

      • Business drivers and context for testing

      Output

      • Specific goals that are driving testing

      Participants

      • DR sponsor
      • Test coordinator

      Think about what and how you test

      Different layers of the stack to test: Network, Authentication, compute and storage, visualization platforms, database services, middleware, app servers, web servers.

      Find gaps and risks with tabletop testing

      Tabletop planning had the greatest impact on meeting recovery objectives (RTOs/RPOs).

      In a tabletop planning exercise, the team walks through a disaster scenario to outline the recovery workflow, and risks or gaps that could disrupt that workflow.

      Tabletops are particularly effective because:

      • It enables you to play out a wider range of scenarios than technology-based testing (e.g. full-scale, parallel) due to cost and complexity factors.
      • It is non-intrusive, so it can be executed more easily than other testing methodologies.
      • The exercise translates into recovery documentation: you create a workflow as you go.
      • A major site or service recovery scenario will review all aspects of the recovery process and create the backbone of your recovery plan.

      02 Run a tabletop exercise

      2 hours

      Tabletop testing is part of our core DRP methodology, Create a Right-Sized Disaster Recovery Plan. This exercise can be run using cue cards, sticky notes, or on a whiteboard; many of our facilitators find building the workflow directly in flowchart software to be very effective.

      Use our Recovery Workflow Template as a starting point.

      Some tips for running your first tabletop exercise:

      Do

      • Review the complete workflow from notification all the way to user acceptance testing.
      • Keep focused; stay on task and on time.
      • Revisit each step and record gaps and risks (and known solutions, but don’t dwell on this).
      • Revise and improve the plan with task owners.

      Don't

      • Get weighed down by tools.
      • Try to find solutions to every gap/risk as you go. Save in-depth research/discussion for later.
      • Document the details right away – stick to the high-level plan for the first exercise.
      1. Ahead of the exercise, decide on a scenario, identify participants, and book a meeting time.
        • For your first walkthrough of a DR scenario, we often recommend a scenario that considers a site failure requiring failover to a DR site.
        • For the first exercise, focus on technical aspects of recovery before bringing in members of the business. The technical team may need space to discuss the appropriate steps in the recovery process before you bring in business liaisons to discuss user acceptance testing (UAT).
        • A complete failover considers all systems, the viability of your second site, and can help identify parts of the process that require additional exercises.
      2. Review the scenario with participants. Then, discuss and document the recovery process, starting with initial notification of an event.
        • Record steps in the process on white cards or boxes.
        • On yellow and red cards, document gaps and risks in people process and technology requirements.
      3. Once you’ve walked through the process, return to the start.
        • Record the time required to complete each step. Consider identifying who is responsible for key steps. Identify any additional gaps and risks.
      4. Clean up and record the results of the workflow. Save a copy with your DRP documentation.

      Input

      • Expert knowledge on systems recovery

      Output

      • Recovery workflow, including gaps and risks

      Participants

      • Test coordinator
      • Technical SMEs

      Move from tabletop testing to functional exercises

      See how your plans fare in the real world

      In live exercises, some portion of your recovery plans are executed in a way that mimics a real recovery scenario. Some advantages of live testing:

      • See how standby systems behave. A tabletop exercise can miss small issues that can make or break the recovery process. For example, connectivity or integration issues on a new subnet might be difficult to predict prior to actually running services in that environment.
      • Hands-on practice: Familiarize the team with the steps, commands, and interfaces of your recovery toolset.
      • Manage the pressure of the DR scenario: Nothing’s quite like the real thing, but a live exercise may be the closest your team can get to a disaster situation without experiencing it firsthand.

      Examples of live exercises

      Boot and smoke test Turn on a standby system and confirm it boots up correctly.
      Restore and validate data Restore data or servers from backup. Confirm data integrity.
      Parallel testing Send familiar transactions to production and standby systems. Confirm both systems produce the same result.
      Failover systems Shut down the production system and use the standby system in production.

      Run local tests ahead of releases

      Think small

      Most unacceptable downtime is caused by localized issues, such as hardware or software failures, rather than widespread destructive events. Regular local testing can help validate the recovery plan for local issues and improve overall service continuity.

      Make local testing a standard step in maintenance work and new deployments to embed resilience considerations in day-to-day activities. Run the same tests in both your primary and your DR environment.

      Some examples of localized tests:

      • Review backup logs and check for errors.
      • Restore files or whole systems from backup.
      • Run application-based tests as part of release management, including unit, regression, and performance tests.
        • Ensure application tests are run for both the primary and DR environment.
        • For a deep-dive on application testing, see Info-Tech’s research Automate Testing to Get More Done.

      Info-Tech Insight

      Local tests will vary between different services, and local test design is usually best left to the system SMEs. At the same time, centralize reporting to understand where tests are being done.

      Investigate whether your IT Service Management or ticketing system can create recurring tasks or work orders to schedule, document, and track test exercises. Tasks can be pre-populated with checklists and documentation to support the test and provide a record of completed tests to support oversight and reporting.

      Have the business validate recovery

      If your business doesn’t think a system’s recovered, it’s not recovered.

      User acceptance testing (UAT) after system recovery is a key step in the recovery process. Like any step in the process, there’s value in testing it before it actually needs to be done. Assign responsibility for building UATs to the person who will be responsible for executing them.

      An acceptance test script might look something like the checklist below.

      • Does the application open?
      • Does the interface look right?
      • Do you see any unusual notifications or warnings?
      • Can you conduct a key transaction with dummy data?
      • Can you run key reports?

      “I cannot stress how important it is to assign ownership of responsibilities in a test; this is the only way to truly mitigate against issues in a test.”

      – Robert Nardella
      IT Service Management
      Certified z/OS Mainframe Professional

      Info-Tech Insight

      Build test scripts and test transactions ahead of time to minimize the amount of new work required during a recovery scenario.

      Beyond the Basics: Full Failover Testing

      • A failover test – a full failover of your production environment to a secondary environment – is what many IT and businesspeople think about when they think of disaster recovery testing.
      • A full test can validate previous local or tabletop tests, identify additional gaps and risks, and provide hands-on training experience with recovery processes and technologies.
      • Setting a date for failover testing can also inject some urgency into otherwise low-priority (but high importance) disaster recovery planning and documentation exercises, which need to be completed prior to the test.
      • Despite these benefits, full failover tests carry significant risk and require a great deal of effort and cost. Typically, only businesses that already have an active-active environment capable of supporting in-scope production systems are able to run a full environment failover.
      • This is especially true the first time you test. While in theory a DR plan should be ready to go at any time, there will be documents to update, gaps to address, and risks to mitigate before you go ahead with the test.

      Full Failover Testing

      What you get:

      • Provide hands-on experience with recovery processes and technology.
      • Confirm that site failover works in practice as you assumed in tabletop or local testing exercises.
      • Identify critical gaps you might have missed without a full failover test.

      What you need:

      • An active-active secondary site, with sufficient standby equipment, data, and licensed standby software to support production.
      • A completed tabletop exercise and documented recovery workflow.
      • A documented test plan, backout plan, and formal sign-off.
      • An off-hours downtime window.
      • Time from technical SMEs and business resources, both for creating the plan and executing the test.

      Beyond the Basics: Site Reliability Engineering

      • Site reliability engineering (SRE) is an application of skills and approaches from software engineering to improve system resilience.
      • SRE is focused on “availability, latency, performance, efficiency, change management, monitoring, emergency response, and capacity planning” across a set portfolio of services (Sloss, 2017).
      • In many organizations, SRE is implemented as a team that supports separate applications teams.
      • Applications must have defined and granular resilience requirements, translated into service objectives. The SRE team and applications teams will work together to meet these objectives.
      • Site reliability engineers (the folks that do SRE, and often also abbreviated as SREs) are expected to build solutions and processes to ensure services remain stable and performant, not just respond when they fail. For example, Google allows their SREs to spend just half their time on incident response, with the rest of their time focused on development and automation tasks.

      Site Reliability Testing

      What you get:

      • Improved reliability and reduced frequency and impact of downtime.
      • Increased use of automation to address problems before they cause an incident.
      • Granular resilience objectives.

      What you need:

      • Systems running on software-defined infrastructure.
      • Specialized skills in programming, infrastructure-as-code.
      • Business & product owners able to define and fund acceptable and appropriate resilience objectives.
      • Technical experts able to translate product requirements into technical design requirements.

      Beyond the Basics: Chaos Engineering

      • Chaos engineering, a term and approach first popularized by the team at Netflix, aims to improve the resilience of particularly large and distributed systems by simulating system failures and evaluating performance against a baseline.
      • Experiments simulate a variety of real-world events that could cause outages (e.g. network slowdowns or server failures). Experiments run continuously, and the recommendation is to run them in production where feasible while minimizing the impact on customers.
      • Tools to help you run chaos testing exist, including open-source toolkits like Chaos Monkey or Mangle and paid software as a service (SaaS) solutions like Gremlin.
      • Deciding whether the long-term benefits of tests that can degrade production are worth the potential risk of system slowdowns or outages is a business or product decision. Technical considerations aside, if the business owner of a particular system doesn’t see the value of continuous testing outweighing the introduced risk, this approach to testing isn’t going to happen.

      Chaos Engineering

      What you get:

      • Confidence that systems can weather volatile and unpredictable conditions in a production environment.
      • An embedded resilience culture.

      What you need:

      • High-maturity IT incident, monitoring and event practices.
      • Standby/resilient systems to minimize downtime impact.
      • Business buy-in for introducing risk into the production environment.
      • Specialized skills to identify, develop, and run tests that degrade production performance in a controlled way.
      • Budget and time to act on issues identified through testing.

      Beyond the Basics: Security Event Simulations

      • Ransomware is driving demands for proof of recovery testing from customers, executives, auditors, and insurance companies. Systems recovery is part of ransomware recovery, but recovering from a breach includes detection, analysis, containment, and eradication of the attack vector before systems recovery can begin.
      • Beyond technical recovery, internal legal and communications teams will have a role, as will your insurance provider, consultants specialized in ransomware recovery, or professional ransom negotiators.
      • A tabletop exercise focused on ransomware incident response is a key first step. You can find Info-Tech’s methodology for a ransomware tabletop in Phase 3 of Build Resilience Against Ransomware Attacks.
      • Live testing approaches can offer hands-on experience and further insight into how your systems are vulnerable to malware. A variety of open source and proprietary tools can simulate ransomware and help you identify problems, though it’s important to understand the limitations of different simulators (Allon, 2022).
      • A “red team” exercise simulates an adversarial attack against your processes and systems. A specialized penetration tester will often take on the role of the red team and provide a report of identified gaps and risks after the engagement.

      Security Event Simulation

      What you get:

      • Hands-on experience managing and recovering from a ransomware attack in a controlled environment.
      • A better understanding of gaps in your response process.

      What you need:

      • A completed ransomware tabletop exercise and mature security incident response processes.
      • For Ransomware Simulators: An air-gapped sandbox environment hosting a copy of your production systems and security tools, and time from your technical SMEs.
      • For Red Team Exercises: A trusted provider, scope for your testing plans, and time from your security incident response team.

      Prioritize tests by asking these three questions

      1. Will the scope of this test deliver sufficient value?

      • Yes, these are critical systems with low tolerance for downtime or data loss.
      • Yes, major changes or new systems require validation of DR capabilities.
      • Yes, there’s high probability of an outage, or recent experience of an outage.
      • •Yes, we have audit requirements or customer demands for testing.

      2. Are we ready for this test?

      • Yes, recovery plans and recovery objectives are documented.
      • Yes, key technical and business resources have time to commit to testing exercises.
      • Yes, technology is currently able to support proposed tests.

      3. Is it easy to do?

      • Yes, effort required to complete the test is low (i.e. minimal work, few participants).
      • Yes, the risks related to testing are low.
      • Yes, it won’t cost much.

      Info-Tech Insight

      More complex, challenging, risky, or costly tests, such as full failover tests, can deliver value. But do the high-value, low-effort stuff first!

      03 Brainstorm and prioritize test ideas

      30-60 minutes

      Even if you have an idea of what you need to test and how you want to run those tests, this brainstorming exercise can generate useful ideas for testing that might otherwise have been missed.

        1. Review the slides above to develop ideas on how and what you want to test. These slides may be enough to kickstart a brainstorming process. Don’t debate or discount ideas at this point. Write down these ideas in a space where all participants can see them (e.g. whiteboard or shared screen).

      The next steps will help you prioritize the list – if needed – to tests that are highest value and lowest effort.

      1. Discuss where you have the greatest need to test. Assign a score of 0 – 3 for each test, with a score of 3 being high-need and a score of zero being low-need. Consider whether:
        • These applications have a low tolerance for downtime.
        • There’s a high chance of an outage, or recent experience with an outage.
        • There’s a need to train or cross-train staff on recovery for the system(s) in question.
        • Major changes require a review or validation of DR capabilities.
        • Audit requirements or customer/executive demands can be met via testing.
      2. Discuss which tests will require the least effort to complete – where readiness is high and tests are easier to do. Assign a score between 0 and 3 for each test, with a score of 3 being least effort and a score of 0 being high effort. Consider whether:
        • Recovery plans and recovery objectives are documented for these systems.
        • Technical experts are available to work on testing exercises.
        • For active testing, standby/sandbox systems are available and capable of supporting proposed tests.
        • The effort required to complete the test is low (e.g. minimal new work, few participants).
        • The risks related to testing are low.
        • You will need to secure additional funding.
      3. Sum together the assigned scores for each test. Higher scores should be the highest priority, but of course use your judgement to validate the results and select one or two tests to execute in the coming year.

      “There are different levels of testing and it is very progressive. I do not recommend my clients to do anything, unless they do it in a progressive fashion. Don’t try to do a live failover test with your users, right out of the box.”

      – Steve Tower
      Principal Consultant
      Prompta Consulting Group

      Input

      • Organizational and technical context

      Output

      • Prioritize list of DR testing ideas

      Participants

      • DR sponsor
      • Test coordinator

      04 Build a test plan

      3-5 days

      Building a test plan helps the test run smoothly and can uncover issues with the underlying DRP as you dig into the details.

      The test coordinator will own the plan document but will rely on the sponsor to confirm scope and goals, technical SMEs to develop system recovery plans, and business liaisons to create UAT scripts.

      Download Info-Tech’s Disaster Recovery Test Plan Template. Use the structure of the template to build your own document, deleting example data as you go. Consider saving a separate copy of this document as an example and working from a second copy.

      Key sections of the document include:

      • Goals, scenario, and scope of the test.
      • Assumptions, constraints, risks, and mitigation strategies.
      • Test participants.
      • Key pre-test milestones, and test-day schedule.
      • After-action review.

      Download the Disaster Recovery Test Plan Template

      Input

      • Scope
      • High-level goals

      Output

      • Test plan, including goals, scope, key milestones, risks and mitigations, and test-day schedule

      Participants

      • Test coordinator develops the plan with support from:
        • Technical SMEs
        • Business liaisons
        • DR sponsor

      05 Run an after-action review

      30-60 minutes

      Take time after test exercises – especially large-scale tests with many participants – to consider what went well, what didn’t, and where you can improve future testing exercises. Track lessons learned and next steps at the bottom of your test plan.

      1. Start with a short (5-10 minute) debrief of the test and allow participants to ask questions. Confirm:
        • Did we meet the goals we set for the exercise, including RTOs and RPOs?
        • What was done well? What issues, gaps, and risks were identified?
      2. Work through variations of the following questions:
        • Was the test plan effective, and was the test well organized?
        • Was the documentation effective? Where did we follow the plan as documented, and where did we deviate from the plan?
        • Was our communication/collaboration during the test effective?
        • Have gaps and issues found during the test been reported to the testing coordinator? Could some of the issues uncovered apply more broadly to other IT services as well?
        • What could we test next, based on what was discovered?
        • Are there other tools or approaches that could be useful?

      Input

      • Insights and experience from a recent testing exercise

      Output

      • Identified gaps and risks, and action items to address them
      • Ideas to improve future test exercises

      Participants

      • Test coordinator develops the plan with support from:
        • Test coordinator
        • Test participants

      Follow a testing cycle

      All tests are expected to drive actions to improve resilience, as appropriate. Experience from previous tests will be applied to future testing exercises.

      The testing cycle: 1. Plan a test, 2. Run test, 3. Take action.

      Use your experience to simplify testing

      The fifth testing exercise should be easier than the first

      Outputs and lessons learned from testing should help you run future tests.

      • With past experience under their belt, participants should have a better understanding of their role, and of their peers’ roles, and the goal of the exercise.
      • Facilitators will be more comfortable facilitating the exercise, and everyone should be more confident in the steps required to recover their systems.
      • Gather feedback from participants through after-action reviews to identify what worked and what didn’t.
      • Documentation from previous tests can provide a template for future tests.
      • Gaps identified in previous tests can provide ideas for future tests.

      Experience, lessons learned, improved process, new test targets, repeat.

      Info-Tech Insight

      Testing should get easier over time. But if you’re easily passing every test, it’s a sign that you’re ready to run more challenging tests.

      06 Create a test program summary

      2-4 hours

      Regular testing allows you to build on prior tests and helps keep plans current despite changes to your environment.

      Keeping a regular testing schedule requires expertise, a process to coordinate your efforts, and a level of governance to provide oversight and ensure testing continues to deliver value. Create a call to action using Info-Tech’s Disaster Recovery Testing Program Summary Template.

      The result is a summary document that:

      • Identifies key takeaways and testing goals
      • Presents key elements of the testing program
      • Outlines the testing cycle
      • Lists expected milestones for the next year
      • Identifies participants
      • Recommends next steps

      “It is extremely important in the early stages of development to concentrate the focus on actual recoverability and data protection, enhancing these capabilities over time into a fully matured program that can truly test the recovery, and not simply focusing on the testing process itself.”

      – Joe Starzyk
      Senior Business Development Executive
      IBM Global Services

      Research Contributors and Experts

      • Bernard A. Jones, Business Continuity & Disaster Recovery Expert
      • Robert Nardella, IT Service Management, Certified z/OS Mainframe Professional
      • Larry Liss, Chief Technology Officer, Blank Rome LLP
      • Jennifer Goshorn, Chief Administrative and Chief Compliance Officer, Gunderson Dettmer LLP
      • Paul Kirvan, FBCI, CISA, Independent IT Consultant/Auditor, Paul Kirvan Associates
      • Steve Tower, Principal Consultant, Prompta Consulting Group
      • Joe Starzyk, Senior Business Development Executive, IBM Global Services
      • Thomas Bronack, Enterprise Resiliency and Corporate Certification Consultant, DCAG
      • Paul S. Randal, CEO & Owner, SQLskills.com
      • Tom Baumgartner, Disaster Recovery Analyst, Catholic Health

      Bibliography

      Alton, Yoni. “Ransomware simulators – reality or a bluff?” Palo Alto Blog, 2 May 2022. Accessed 31 Jan 2023.
      https://www.paloaltonetworks.com/blog/security-operations/ransomware-simulators-reality-or-a-bluff/

      Brathwaite, Shimon. “How to Test your Business Continuity and Disaster Recovery Plan,” Security Made Simple, 13 Nov 2022. Accessed 31 Jan 2023.
      https://www.securitymadesimple.org/cybersecurity-blog/how-to-test-your-business-continuity-and-disaster-recovery-plan

      The Business Continuity Institute. Good Practice Guidelines: 2018 Edition. The Business Continuity Institute, 2017.

      Emigh, Jacqueline. “Disaster Recovery Testing: Ensuring Your DR Plan Works,” Enterprise Storage Forum, 28 May 2019. Accessed 31 Jan 2023.
      Disaster Recovery Testing: Ensuring Your DR Plan Works | Enterprise Storage Forum

      Gardner, Dana. "Case Study: Strategic Approach to Disaster Recovery and Data Lifecycle Management Pays off for Australia's SAI Global." ZDNet. BriefingsDirect, 26 Apr 2012. Accessed 31 Jan 2023.
      http://www.zdnet.com/article/case-study-strategic-approach-to-disaster-recovery-and-data-lifecycle-management-pays-off-for-australias-sai-global/.

      IBM. “Section 11. Testing the Disaster Recovery Plan.” IBM, 2 Aug 2021. Accessed 31 Jan 2023. Section 11. Testing the disaster recovery plan - IBM Documentation Lutkevich, Ben and Alexander Gillis. “Chaos Engineering”. TechTarget, Jun 2021. Accessed 31 Jan 2023.
      https://www.techtarget.com/searchitoperations/definition/chaos-engineering

      Monperrus, Martin. “Principles of Antifragility.” Arxiv Forum, 7 June 2017. Accessed 31 Jan 2023.
      https://arxiv.org/ftp/arxiv/papers/1404/1404.3056.pdf

      “Principles of Chaos Engineering.” Principles of Chaos Engineering, 2019 March. Accessed 31 Jan 2023.
      https://principlesofchaos.org/

      Sloss, Benjamin Treynor. “Introduction.” Site Reliability Engineering. Ed. Betsy Beyer. O’Reilly Media, 2017. Accessed 31 Jan 2023.
      https://sre.google/sre-book/introduction/

      Enterprise Architecture Trends

      • Buy Link or Shortcode: {j2store}584|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Strategy & Operating Model
      • Parent Category Link: /strategy-and-operating-model
      • The digital transformation journey brings business and technology increasingly closer.
      • Because the two become more and more intertwined, the role of the enterprise architecture increases in importance, aligning the two in providing additional efficiencies.
      • The current need for an accelerated digital transformation elevates the importance of enterprise architecture.

      Our Advice

      Critical Insight

      • Enterprise architecture is impacted and has an increasing role in the following areas:
        • Business agility
        • Security
        • Innovation
        • Collaborative EA
        • Tools and automation

      Impact and Result

      EA’s role in brokering and negotiating overlapping areas can lead to the creation of additional efficiencies at the enterprise level.

      Enterprise Architecture Trends Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Enterprise Architecture Trends Deck – A trend report to support executives as they digitally transform the enterprise.

      In an accelerated path to digitization, the increasingly important role of enterprise architecture is one of collaboration across siloes, inside and outside the enterprise, in a configurable way that allows for quick adjustment to new threats and conditions, while embracing unprecedented opportunities to scale, stimulating innovation, in order to increase the organization’s competitive advantage.

      • Enterprise Architecture Trends Report

      Infographic

      Further reading

      Enterprise Architecture Trends

      Supporting Executives to Digitally Transform the Enterprise

      Analyst Perspective

      Enterprise architecture, seen as the glue of the organization, aligns business goals with all the other aspects of the organization, providing additional effectiveness and efficiencies while also providing guardrails for safety.

      In an accelerated path to digitization, the increasingly important role of enterprise architecture (EA) is one of collaboration across siloes, inside and outside the enterprise, in a configurable way that allows for quick adjustment to new threats and conditions while embracing unprecedented opportunities to scale, stimulating innovation to increase the organization’s competitive advantage.

      Photo of Milena Litoiu, Principal/Senior Director, Enterprise Architecture, Info-Tech Research Group.

      Milena Litoiu
      Principal/Senior Director, Enterprise Architecture
      Info-Tech Research Group

      Accelerated digital transformation elevates the importance of EA

      The Digital transformation journey brings Business and technology increasingly closer.

      Because the two become more and more intertwined, the role OF Enterprise Architecture increases in importance, aligning the two in providing additional efficiencies.

      THE Current need for an accelerated Digital transformation elevates the importance of Enterprise Architecture.

      More than 70% of organizations revamp their enterprise architecture programs. (Info-Tech Tech Trends 2022 Survey)

      Most organizations still see a significant gap between the business and IT.

      Enterprise Architecture (EA) is impacted and has an increasing role in the following areas

      Accelerated Digital Transformation

      • Business agility Business agility, needed more that ever, increases reliance on enterprise strategies.
        EA creates alignment between business and IT to improve business nimbleness.
      • Security More sophisticated attacks require more EA coordination.
        EA helps adjust to the increasing sophistication of external threats. Partnering with the CISO office to develop strategies to protect the enterprise becomes a prerequisite for survival.
      • Innovation EA's role in an innovation increases synergies at the enterprise level.
        EA plays an increasingly stronger role in innovation, from business endeavors to technology, across business units, etc.
      • Collaborative EA Collaborative EA requires new ways of working.
        Enterprise collaboration gains new meaning, replacing stiff governance.
      • Tools & automation Tools-based automation becomes increasingly common.
        Tools support as well as new artificial intelligence or machine- learning- powered approaches help achieve tools-assisted coordination across viewpoints and teams.

      Info-Tech Insight

      EA's role in brokering and negotiating overlapping areas can lead to the creation of additional efficiencies at the enterprise level.

      EA Enabling Business Agility

      Trend 01 — Business Agility is needed more than ever and THIS increases reliance on enterprise Strategies. to achieve nimbleness, organizations need to adapt timely to changes in the environment.

      Approaches:
      A plethora of approaches are needed (e.g. architecture modularity, data integration, AI/ML) in addition to other Agile/iterative approaches for the entire organization.

      Tech Trend Update: If Contact Tracing Then Distributed Trust

      • Buy Link or Shortcode: {j2store}424|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: DR and Business Continuity
      • Parent Category Link: /business-continuity

      With COVID-19's rapid spread through populations, governments are looking for technology tools that can augment the efforts of manual contact tracing processes. How the system is designed is crucial to a positive outcome.

      • CIOs must understand how distributed trust principles achieve embedded privacy and help encourage user adoption.
      • CEOs must consider how society's waning trust in institutions affects the way they engage their customers.

      Our Advice

      Critical Insight

      Mobile contact tracing apps that use a decentralized design approach will be the most likely to be adopted by a wide swath of the population.

      Impact and Result

      There are some key considerations to realize from the way different governments are approaching contact tracing:

      1. If centralized, then seek to ensure privacy protections.
      2. If decentralized, then seek to enable collaboration.
      3. In either case, put in place data governance to create trust.

      Tech Trend Update: If Contact Tracing Then Distributed Trust Research & Tools

      Learn why distributed trust is becoming critical to technology systems design

      Understand the differences between mobile app architectures available to developers and how to achieve success in implementation based on your goals.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      • Tech Trend Update: If Contact Tracing Then Distributed Trust Storyboard
      [infographic]

      Security Priorities 2023

      • Buy Link or Shortcode: {j2store}254|cart{/j2store}
      • member rating overall impact: 9.0/10 Overall Impact
      • member rating average dollars saved: $909 Average $ Saved
      • member rating average days saved: 1 Average Days Saved
      • Parent Category Name: Security Strategy & Budgeting
      • Parent Category Link: /security-strategy-and-budgeting
      • Most people still want a hybrid work model but there is a shortage in security workforce to maintain secure remote work, which impacts confidence in the security practice.
      • Pressure of operational excellence drives organizational modernization with the consequence of higher risks of security attacks that impact not only cyber but also physical systems.
      • The number of regulations with stricter requirements and reporting is increasing, along with high sanctions for violations.
      • Accurate assessment of readiness and benefits to adopt next-gen cybersecurity technologies can be difficult. Additionally, regulation often faces challenges to keep up with next-gen cybersecurity technologies implications and risks of adoption, which may not always be explicit.
      • Software is usually produced as part of a supply chain instead in a silo. Thus, a vulnerability in any part of the supply chain can become a threat surface.

      Our Advice

      Critical Insight

      • Secure remote work still needs to be maintained to facilitate the hybrid work model post pandemic.
      • Despite all the cybersecurity risks, organizations continue modernization plans due to the long-term overall benefits. Hence, we need to secure organization modernization.
      • Organizations should use regulatory changes to improve security practices, instead of treating them as a compliance burden.
      • Next-gen cybersecurity technologies alone are not the silver bullet. A combination of technologies with skilled talent, useful data, and best practices will give a competitive advantage.

      Impact and Result

      • Use this report to help decide your 2023 security priorities by:
        • Collecting and analyzing your own related data, such as your organization 2022 incident reports. Use Info-Tech’s Security Priorities 2023 material for guidance.
        • Identifying your needs and analyzing your capabilities. Use Info-Tech's template to explain the priorities you need to your stakeholders.
        • Determining the next steps. Refer to Info-Tech's recommendations and related research.

      Security Priorities 2023 Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Security Priorities 2023 Report – A report to help decide your 2023 security priorities.

      Each organization is different, so a generic list of security priorities will not be applicable to every organization. Thus, you need to:

    • Collect and analyze your own related data such as your organization 2022 incident reports. Use Info-Tech’s Security Priorities 2023 material for guidance.
    • Identify your needs and analyze your capabilities. Use Info-Tech's template to explain the priorities you need to your stakeholders.
    • Refer to Info-Tech's recommendations and related research for guidance on the next steps.
      • Security Priorities 2023 Report

      Infographic

      Further reading

      Security Priorities 2023

      How we live post pandemic

      Each organization is different, so a generic list of priorities will not be applicable to every organization.

      During 2022, ransomware campaigns declined from quarter to quarter due to the collapse of experienced groups. Several smaller groups are developing to recapture the lost ransomware market. However, ransomware is still the most worrying cyber threat.

      Also in 2022, people returned to normal activities such as traveling and attending sports or music events but not yet to the office. The reasons behind this trend can be many fold, such as employees perceive that work from home (WFH) has positive productivity effects and time flexibility for employees, especially for those with families with younger children. On the other side of the spectrum, some employers perceive that WFH has negative productivity effects and thus are urging employees to return to the office. However, employers also understand the competition to retain skilled workers is harder. Thus, the trend is to have hybrid work where eligible employees can WFH for a certain portion of their work week.

      Besides ransomware and the hybrid work model, in 2022, we saw an evolving threat landscape, regulatory changes, and the potential for a recession by the end of 2023, which can impact how we prioritize cybersecurity this year. Furthermore, organizations are still facing the ongoing issues of insufficient cybersecurity resources and organization modernization.

      This report will explore important security trends, the security priorities that stem from these trends, and how to customize these priorities for your organization.

      In Q2 2022, the median ransom payment was $36,360 (-51% from Q1 2022), a continuation of a downward trend since Q4 2021 when the ransom payment median was $117,116.
      Source: Coveware, 2022

      From January until October 2022, hybrid work grew in almost all industries in Canada especially finance, insurance, real estate, rental and leasing (+14.7%), public administration and professional services (+11.8%), and scientific and technical services (+10.8%).
      Source: Statistics Canada, Labour Force Survey, October 2022; N=3,701

      Hybrid work changes processes and infrastructure

      Investment on remote work due to changes in processes and infrastructure

      As part of our research process for the 2023 Security Priorities Report, we used the results from our State of Hybrid Work in IT Survey, which collected responses between July 10 and July 29, 2022 (total N=745, with n=518 completed surveys). This survey details what changes in processes and IT infrastructure are likely due to hybrid work.

      Process changes to support hybrid work

      A bar graph is depicted with the following dataset: None of the above - 12%; Change management - 29%; Asset management - 34%; Service request support - 41%; Incident management - 42%

      Survey respondents (n=518) were asked what processes had the highest degree of change in response to supporting hybrid work. Incident management is the #1 result and service request support is #2. This is unsurprising considering that remote work changed how people communicate, how they access company assets, and how they connect to the company network and infrastructure.

      Infrastructure changes to support hybrid work

      A bar graph is depicted with the following dataset: Changed queue management and ticketing system(s) - 11%; Changed incident and service request processes - 23%; Addition of chatbots as part of the Service Desk intake process - 29%; Reduced the need for recovery office spaces and alternative work mitigations - 40%; Structure & day-to-day operation of Service Desk - 41%; Updated network architecture - 44%

      For 2023, we believe that hybrid work will remain. The first driver is that employees still prefer to work remotely for certain days of the week. The second driver is the investment from employers on enabling WFH during the pandemic, such as updated network architecture (44%) and the infrastructure and day-to-day operations (41%) as shown on our survey.

      Top cybersecurity concerns and organizational preparedness for them

      Concerns may correspond to readiness.

      In the Info-Tech Research Group 2023 Trends and Priorities Survey of IT professionals, we asked about cybersecurity concerns and the perception about readiness to meet current and future government legislation regarding cybersecurity requirements.

      Cybersecurity issues

      A bar graph is depicted with the following dataset: Cyber risks are not on the radar of the executive leaders or board of directors - 3.19; Organization is not prepared to respond to a cyber attack - 3.08; Supply chain risks related to cyber threats - 3.18; Talent shortages leading to capacity constraints in cyber security - 3.51; New government or industry-imposed regulations - 3.15

      Survey respondents were asked how concerned they are about certain cybersecurity issues from 1 (not concerned at all) to 5 (very concerned). The #1 concern was talent shortages. Other issues with similar concerns included cyber risks not on leadership's radar, supply chain risks, and new regulations (n=507).

      Cybersecurity legislation readiness

      A bar graph is depicted with the following dataset: 1 (Not confident at all) - 2.4%; 2 - 11.2%; 3 - 39.7%; 4 - 33.3%; 5 (Very confident) - 13.4%

      When asked about how confident organizations are about being prepared to meet current and future government legislation regarding cybersecurity requirements, from 1 (not confident at all) to 5 (very confident), the #1 response was 3 (n=499).

      Unsurprisingly, the ever-changing government legislation environment in a world emerging from a pandemic and ongoing wars may not give us the highest confidence.

      We know the concerns and readiness…

      But what is the overall security maturity?

      As part of our research process for the 2023 Security Priorities Report, we reviewed results of completed Info-Tech Research Group Security Governance and Management Benchmark diagnostics (N=912). This report details what we see in our clients' security governance maturity. Setting aside the perception on readiness – what are their actual security maturity levels?

      A bar graph is depicted with the following dataset: Security Culture - 47%; Policy and Process Governance - 47%; Event and Incident Management - 58%; Vulnerability - 57%; Auditing - 52%; Compliance Management - 58%; Risk Analysis - 52%

      Overall, assessed organizations are still scoring low (47%) on Security Culture and Policy and Process Governance. This justifies why most security incidents are still due to gaps in foundational security and security awareness, not lack of advanced controls such as event and incident management (58%).

      And how will the potential recession impact security?

      Organizations are preparing for recession, but opportunities for growth during recession should be well planned too.

      As part of our research process for the 2023 Security Priorities Report, we reviewed the results of the Info-Tech Research Group 2023 Trends and Priorities Survey of IT professionals, which collected responses between August 9 and September 9, 2022 (total N=813 with n=521 completed surveys).

      Expected organizational spending on cybersecurity compared to the previous fiscal year

      A bar graph is depicted with the following dataset: A decrease of more than 10% - 2.2%; A decrease of between 1-10% - 2.6%; About the same - 41.4%; An increase of between 1-10% - 39.6%; An increase of more than 10% - 14.3%

      Keeping the same spending is the #1 result and #2 is increasing spending up to 10%. This is a surprising finding considering the survey was conducted after the middle of 2022 and a recession has been predicted since early 2022 (n=489).

      An infographic titled Cloudy with a Chance of Recession

      Source: Statista, 2022, CC BY-ND

      US recession forecast

      Contingency planning for recessions normally includes tight budgeting; however, it can also include opportunities for growth such as hiring talent who have been laid off by competitors and are difficult to acquire in normal conditions. This can support our previous findings on increasing cybersecurity spending.

      Five Security Priorities for 2023

      This image describes the Five Security Priorities for 2023.

      Maintain Secure Hybrid Work

      PRIORITY 01

      • HOW TO STRATEGICALLY ACQUIRE, RETAIN, OR UPSKILL TALENT TO MAINTAIN SECURE SYSTEMS.

      Executive summary

      Background

      If anything can be learned from COVID-19 pandemic, it is that humans are resilient. We swiftly changed to remote workplaces and adjusted people, processes, and technologies accordingly. We had some hiccups along the way, but overall, we demonstrated that our ability to adjust is amazing.

      The pandemic changed how people work and how and where they choose to work, and most people still want a hybrid work model. However, the number of days for hybrid work itself varies. For example, from our survey in July 2022 (n=516), 55.8% of employees have the option of 2-3 days per week to work offsite, 21.0% for 1 day per week, and 17.8% for 4 days per week.

      Furthermore, the investment (e.g. on infrastructure and networks) to initiate remote work was huge, and the cost doesn't end there, as we need to maintain the secure remote work infrastructure to facilitate the hybrid work model.

      Current situation

      Remote work: A 2022 survey by WFH Research (N=16,451) reports that ~14% of full-time employees are fully remote and ~29% are in a hybrid arrangement as of Summer-Fall 2022.

      Security workforce shortage: A 2022 survey by Bridewell (N=521) reports that 68% of leaders say it has become harder to recruit the right people, impacting organizational ability to secure and monitor systems.

      Confidence in the security practice: A 2022 diagnostic survey by Info-Tech Research Group (N=55) reports that importance may not correspond to confidence; for example, the most important selected cybersecurity area, namely Data Access/Integrity (93.7%), surprisingly has the lowest confidence of the practice (80.5%).

      "WFH doubled every 15 years pre-pandemic. The increase in WFH during the pandemic was equal to 30 years of pre-pandemic growth."

      Source: National Bureau of Economic Research, 2021

      Leaders must do more to increase confidence in the security practice

      Importance may not correspond to confidence

      As part of our research process for the 2023 Security Priorities Report, we analyzed results from the Info-Tech Research Group diagnostics. This report details what we see in our clients' perceived importance of security and their confidence in existing security practices.

      Cybersecurity importance

      A bar graph is depicted with the following dataset: Importance to the Organization - 94.3%; Importance to My Department	92.2%

      Cybersecurity importance areas

      A bar graph is depicted with the following dataset: Mobility (Remote & Mobile Access) - 90.2%; Regulatory Compliance - 90.1%; Desktop Computing - 90.9%; Data Access / Integrity - 93.7%

      Confidence in cybersecurity practice

      A bar graph is depicted with the following dataset: Confidence in the Organization's Overall Security - 79.4%; Confidence in Security for My Department - 79.8%

      Confidence in cybersecurity practice areas

      A bar graph is depicted with the following dataset: Mobility (Remote & Mobile Access) - 75.8%; Regulatory Compliance - 81.5%; Desktop Computing - 80.9%; Data Access / Integrity - 80.5%

      Diagnostics respondents (N=55) were asked about how important security is to their organization or department. Importance to the overall organization is 2.1 percentage points (pp) higher, but confidence in the organization's overall security is slightly lower (-0.4 pp).

      If we break down to security areas, we can see that the most important area, Data Access/Integrity (93.7%), surprisingly has the lowest confidence of the practice: 80.5%. From this data we can conclude that leaders must build a strong cybersecurity workforce to increase confidence in the security practice.

      Use this template to explain the priorities you need your stakeholders to know about.

      Maintain secure hybrid work plan

      Provide a brief value statement for the initiative.

      Build a strong cybersecurity workforce to increase confidence in the security practice to facilitate hybrid work.

      Initiative Description:

      • Description must include what organization will undertake to complete the initiative.
      • Review your security strategy for hybrid work.
      • Identify skills gaps that hinder the successful execution of the hybrid work security strategy.
      • Use the identified skill gaps to define the technical skill requirements for current and future work roles.
      • Conduct a skills assessment on your current workforce to identify employee skill gaps.
      • Decide whether to train, hire, contract, or outsource each skill gap.

      Drivers:

      List initiative drivers.

      • Employees still prefer to WFH for certain days of the week.
      • The investment on WFH during pandemic such as updated network architecture and infrastructure and day-to-day operations.
      • Tech companies' huge layoffs, e.g. Meta laid off more than 11,000 employees.

      Risks:

      List initiative risks and impacts.

      • Unskilled workers lacking certificates or years of experience who are trained and become skilled workers then quit or are hijacked by competitors.
      • Organizational and cultural changes cause friction with work-life balance.
      • Increased attack surface of remote/hybrid workforce.

      Benefits:

      List initiative benefits and align to business benefits or benefits for the stakeholder groups that it impacts.

      • Increase perceived productivity by employees and increase retention.
      • Increase job satisfaction and work-life balance.
      • Hiring talent that has been laid off who are difficult to acquire in normal conditions.

      Related Info-Tech Research:

      Recommended Actions

      1. Identify skill requirements to maintain secure hybrid work

      Review your security strategy for hybrid work.

      Determine the skill needs of your security strategy.

      2. Identify skill gaps

      Identify skills gaps that hinder the successful execution of the hybrid work security strategy.

      Use the identified skill gaps to define the technical skill requirements for work roles.

      3. Decide whether to build or buy skills

      Conduct a skills assessment on your current workforce to identify employee skill gaps.

      Decide whether to train, hire, contract, or outsource each skill gap.

      Source: Close the InfoSec Skills Gap: Develop a Technical Skills Sourcing Plan, Info-Tech

      Secure Organization Modernization

      PRIORITY 02

      • TRENDS SUGGEST MODERNIZATION SUCH AS DIGITAL
        TRANSFORMATION TO THE CLOUD, OPERATIONAL TECHNOLOGY (OT),
        AND THE INTERNET OF THINGS (IOT) IS RISING; ADDRESSING THE RISK
        OF CONVERGING ENVIRONMENTS CAN NO LONGER BE DEFERRED.

      Executive summary

      From computerized milk-handling systems in Wisconsin farms, to automated railway systems in Europe, to Ausgrid's Distribution Network Management System (DNMS) in Australia, to smart cities and beyond; system modernization poses unique challenges to cybersecurity.

      The threats can be safety, such as the trains stopped in Denmark during the last weekend of October 2022 for several hours due to an attack on a third-party IT service provider; economics, such as a cream cheese production shutdown that occurred at the peak of cream cheese demand in October 2021 due to hackers compromising a large cheese manufacturer's plants and distribution centers; and reliability, such as the significant loss of communication for the Ukrainian military, which relied on Viasat's services.

      Despite all the cybersecurity risks, organizations continue modernization plans due to the long-term overall benefits.

      Current situation

      • Pressure of operational excellence: Competitive markets cannot keep pace with demand without modernization. For example, in automated milking systems, the labor time saved from milking can be used to focus on other essential tasks such as the decision-making process.
      • Technology offerings: Technologies are available and affordable such as automated equipment, versatile communication systems, high-performance human machine interaction (HMI), IIoT/Edge integration, and big data analytics.
      • Higher risks of cyberattacks: Modernization enlarges attack surfaces, which are not only cyber but also physical systems. Most incidents indicate that attackers gained access through the IT network, which was followed by infiltration into OT networks.

      IIoT market size is USD 323.62 billion in 2022 and projected to be around USD 1 trillion in 2028.

      Source: Statista,
      March 2022

      Modernization brings new opportunities and new threats

      Higher risks of cyberattacks on Industrial Control System (ICS)

      Target: Australian sewage plant.

      Method: Insider attack. Impact: 265,000 gallons of untreated sewage released.

      Target: Middle East energy companies.

      Method: Shamoon.

      Impact: Overwritten Windows-based systems files.

      Target: German Steel Mill

      Method: Spear-phishing

      Impact: Blast furnace control shutdown failure.

      Target: Middle East Safety Instrumented System (SIS).

      Method: TRISIS/TRITON.

      Impact: Modified safety system ladder logic.

      Target: Viasat's KA-SAT Network.

      Method: AcidRain.

      Impact: Significant loss of communication for the Ukrainian military, which relied on Viasat's services.

      A timeline displaying the years 1903; 2000; 2010; 2012; 2013; 2014; 2018; 2019; 2021; 2022 is displayed.

      Target: Marconi wireless telegraphs presentation. Method: Morse code.

      Impact: Fake message sent "Rats, rats, rats, rats. There was a young fellow of Italy, Who diddled the public quite prettily."

      Target: Iranian uranium enrichment plant.

      Method: Stuxnet.

      Impact: Compromised programmable logic controllers (PLCs).

      Target: ICS supply chain.

      Method: Havex.

      Impact: Remote Access Trojan (RAT) collected information and uploaded data to command-and-control (C&C) servers.

      Target: Ukraine power grid.

      Method: BlackEnergy.

      Impact: Manipulation of HMI View causing 1-6 hour power outages for 230,000 consumers.

      Target: Colonial Pipeline.

      Method: DarkSide ransomware.

      Impact: Compromised billing infrastructure halted the pipeline operation.

      Sources:

      • DOE, 2018
      • CSIS, 2022
      • MIT Technology Review, 2022

      Info-Tech Insight

      Most OT incidents start with attacks against IT networks and then move laterally into the OT environment. Therefore, converging IT and OT security will help protect the entire organization.

      Use this template to explain the priorities you need your stakeholders to know about.

      Secure organization modernization

      Provide a brief value statement for the initiative.

      The systems (OT, IT, IIoT) are evolving now – ensure your security plan has you covered.

      Initiative Description:

      • Description must include what organization will undertake to complete the initiative.
      • Identify the drivers to align with your organization's business objectives.
      • Build your case by leveraging a cost-benefit analysis and update your security strategy.
      • Identify people, process, and technology gaps that hinder the modernization security strategy.
      • Use the identified skill gaps to update risks, policies and procedures, IR, DR, and BCP.
      • Evaluate and enable modernization technology top focus areas and refine security processes.
      • Decide whether to train, hire, contract, or outsource to fill the security workforce gap.

      Drivers:

      List initiative drivers.

      • Pressure of operational excellence
      • Technology offerings
      • Higher risks of cyberattacks

      Risks:

      List initiative risks and impacts.

      • Complex systems with many components to implement and manage require diligent change management.
      • Organizational and cultural changes cause friction between humans and machines.
      • Increased attack surface of cyber and physical systems.

      Benefits:

      List initiative benefits and align to business benefits or benefits for the stakeholder groups that it impacts.

      • Improve service reliability through continuous and real-time operation.
      • Enhance efficiency through operations visibility and transparency.
      • Gain cost savings and efficiency to automate operations of complex and large equipment and instrumentations.

      Related Info-Tech Research:

      Recommended Actions

      1. Identify modernization business cases to secure

      Identify the drivers to align with your organization's business objectives.

      Build your case by leveraging a cost-benefit analysis, and update your security strategy.

      2. Identify gaps

      Identify people, process, and technology gaps that hinder the modernization
      security strategy.

      Use the identified skill gaps to update risks, policies and procedures, IR, DR, and BCP.

      3. Decide whether to build or buy capabilities

      Evaluate and enable modernization technology top focus areas and refine
      security processes.

      Decide whether to train, hire, contract, or outsource to fill the security workforce gap.

      Sources:

      Industrial Control System (ICS) Modernization: Unlock the Value of Automation in Utilities, Info-Tech

      Secure IT-OT Convergence, Info-Tech

      Develop a cost-benefit analysis

      Identify a modernization business case for security.

      Benefits

      Metrics

      Operational Efficiency and Cost Savings

      • Reduction in truck rolls and staff time of manual operations of equipment or instrumentation.
      • Cost reduction in energy usage such as substation power voltage level or water treatment chemical level.

      Improve Reliability and Resilience

      • Reduction in field crew time to identify the outage locations by remotely accessing field equipment to narrow down the
        fault areas.
      • Reduction in outage time impacting customers and avoiding financial penalty in service quality metrics.
      • Improve operating reliability through continuous and real-time trend analysis of equipment performance.

      Energy & Capacity Savings

      • Optimize energy usage of operation to reduce overall operating cost and contribution to organizational net-zero targets.

      Customers & Society Benefits

      • Improve customer safety for essential services such as drinkable water consumption.
      • Improve reliability of services and address service equity issues based on data.

      Cost

      Metrics

      Equipment and Infrastructure

      Upgrade existing security equipment or instrumentation or deploy new, e.g. IPS on Enterprise DMZ and Operations DMZ.

      Implement communication network equipment and labor to install and configure.

      Upgrade or construct server room including cooling/heating, power backup, and server and rack hardware.

      Software and Commission

      The SCADA/HMI software and maintenance fee as well as lifecycle upgrade implementation project cost.

      Labor cost of field commissioning and troubleshooting.

      Integration with security systems, e.g. log management and continuous monitoring.

      Support and Resources

      Cost to hire/outsource security FTEs for ongoing managing and operating security devices, e.g. SOC.

      Cost to hire/outsource IT/OT FTEs to support and troubleshoot systems and its integrations with security systems, e.g. MSSP.

      An example of a cost-benefit analysis for ICS modernization

      Sources:

      Industrial Control System (ICS) Modernization: Unlock the Value of Automation in Utilities, Info-Tech

      Lawrence Berkeley National Laboratory, 2021

      IT-OT convergence demands new security approach and solutions

      Identify gaps

      Attack Vectors

      IT

      • User's compromised credentials
      • User's access device, e.g. laptop, smartphone
      • Access method, e.g. denial-of-service to modem, session hijacking, bad data injection

      OT

      • Site operations, e.g. SCADA server, engineering workstation, historian
      • Controls, e.g. SCADA Client, HMI, PLCs, RTUs
      • Process devices, e.g. sensors, actuators, field devices

      Defense Strategies

      • Limit exposure of system information
      • Identify and secure remote access points
      • Restrict tools and scripts
      • Conduct regular security audits
      • Implement a dynamic network environment

      (Control System Defense: Know the Opponent, CISA)

      An example of a high-level architecture of an electric utility's control system and its interaction with IT systems.

      An example of a high-level architecture of an electric utility's control system and its interaction with IT systems.

      Source: ISA-99, 2007

      RESPOND TO REGULATORY CHANGES

      PRIORITY 03

      • GOVERNMENT-ENACTED POLICY CHANGES AND INDUSTRY REGULATORY CHANGES COULD BE A COMPLIANCE BURDEN … OR PREVENT YOUR NEXT SECURITY INCIDENT.

      Executive summary

      Background

      Government-enacted regulatory changes are occurring at an ever-increasing rate these days. As one example, on November 10, 2022, the EU Parliament introduced two EU cybersecurity laws: the Network and Information Security (NIS2) Directive (applicable to organizations located within the EU and organizations outside the EU that are essential within an EU country) and the Digital Operational Resilience Act (DORA). There are also industry regulatory changes such as PCI DSS v4.0 for the payment sector and the North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) for Bulk Electric Systems (BES).

      Organizations should use regulatory changes as a means to improve security practices, instead of treating them as a compliance burden. As said by lead member of EU Parliament Bart Groothuis on NIS2, "This European directive is going to help around 160,000 entities tighten their grip on security […] It will also enable information sharing with the private sector and partners around the world. If we are being attacked on an industrial scale, we need to respond on an industrial scale."

      Current situation

      Stricter requirements and reporting: Regulations such as NIS2 include provisions for incident response, supply chain security, and encryption and vulnerability disclosure and set tighter cybersecurity obligations for risk management reporting obligations.

      Broader sectors: For example, the original NIS directive covers 19 sectors such as Healthcare, Digital Infrastructure, Transport, and Energy. Meanwhile, the new NIS2 directive increases to 35 sectors by adding other sectors such as providers of public electronic communications networks or services, manufacturing of certain critical products (e.g. pharmaceuticals), food, and digital services.

      High sanctions for violations: For example, Digital Services Act (DSA) includes fines of up to 6% of global turnover and a ban on operating in the EU single market in case of repeated serious breaches.

      Approximately 100 cross-border data flow regulations exist in 2022.

      Source: McKinsey, 2022

      Stricter requirements for payments

      Obligation changes to keep up with emerging threats and technologies

      64 New requirements were added
      A total of 64 requirements have been added to version 4.0 of the PCI DSS.

      13 New requirements become effective March 31, 2024
      The other 51 new requirements are considered best practice until March 31, 2025, at which point they will become effective.

      11 New requirements only for service providers
      11 of the new requirements are applicable only to entities that provide third-party services to merchants.

      Defined roles must be assigned for requirements.

      Focus on periodically assessing and documenting scope.

      Entities may choose a defined approach or a customized approach to requirements.

      An example of new requirements for PCI DSS v4.0

      Source: Prepare for PCI DSS v4.0, Info-Tech

      Use this template to explain the priorities you need your stakeholders to know about.

      Respond to regulatory changes

      Provide a brief value statement for the initiative.

      The compliance obligations are evolving – ensure your security plan has you covered.

      Initiative Description:

      Description must include what organization will undertake to complete the initiative.

      • Identify relevant security and privacy compliance and conformance levels.
      • Identify gaps for updated obligations, and map obligations into control framework.
      • Review, update, and implement policies and strategy.
      • Develop compliance exception process and forms.
      • Develop test scripts.
      • Track status and exceptions

      Drivers:

      List initiative drivers.

      • Pressure of new regulations
      • Governance, risk & compliance (GRC) tool offerings
      • High administrative or criminal penalties of non-compliance

      Risks:

      List initiative risks and impacts.

      • Complex structures and a great number of compliance requirements
      • Restricted budget and lack of skilled workforce for organizations such as local municipalities and small or medium organizations compared to private counterparts
      • Personal liability for some regulations for non-compliance

      Benefits:

      List initiative benefits and align to business benefits or benefits for the stakeholder groups that it impacts.

      • Reduces compliance risk.
      • Reduces complexity within the control environment by using a single framework to align multiple compliance regimes.
      • Reduces costs and efforts related to managing IT audits through planning and preparation.

      Related Info-Tech Research:

      Recommended Actions

      1. Identify compliance obligations

      Identify relevant security and privacy obligations and conformance levels.

      Identify gaps for updated obligations, and map obligations into control framework.

      2. Implement compliance strategy

      Review, update, and implement policies and strategy.

      Develop compliance exception process.

      3. Track and report

      Develop test scripts to check your remediations to ensure they are effective.

      Track and report status and exceptions.

      Sources: Build a Security Compliance Program and Prepare for PCI DSS v4.0, Info-Tech

      Identify relevant security and privacy compliance obligations

      Identify obligations

      # Security Jurisdiction
      1 Network and Information Security (NIS2) Directive European Union (EU) and organizations outside the EU that are essential within an EU country
      2 North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) North American electrical utilities
      3 Executive Order (EO) 14028: Improving the Nation's Cybersecurity, The White House, 2021 United States

      #

      Privacy Jurisdiction
      1 General Data Protection Regulation (GDPR) EU and EU citizens
      2 Personal Information Protection and Electronic Documents Act (PIPEDA) Canada
      3 California Consumer Privacy Act (CCPA) California, USA
      4 Personal Information Protection Law of the People’s Republic of China (PIPL) China

      An example of security and privacy compliance obligations

      How much does it cost to become compliant?

      • It is important to understand the various frameworks and to adhere to the appropriate compliance obligations.
      • Many factors influence the cost of compliance, such as the size of organization, the size of network, and current security readiness.
      • To manage compliance obligations, it is important to use a platform that not only performs internal and external monitoring but also provides third-party vendors (if applicable) with visibility into potential threats in their organization.

      Adopt Next-Generation Cybersecurity Technologies

      PRIORITY 04

      • GOVERNMENTS AND HACKERS ARE RECOGNIZING THE IMPORTANCE OF EMERGING TECHNOLOGIES, SUCH AS ZERO TRUST ARCHITECTURE AND AI-BASED CYBERSECURITY. SO SHOULD YOUR ORGANIZATION.

      Executive summary

      Background

      The cat and mouse game between threat actors and defenders is continuing. The looming question "can defenders do better?" has been answered with rapid development of technology. This includes the automation of threat analysis (signature-based, specification-based, anomaly-based, flow-based, content-based, sandboxing) not only on IT but also on other relevant environments, e.g. IoT, IIoT, and OT based on AI/ML.

      More fundamental approaches such as post-quantum cryptography and zero trust (ZT) are also emerging.
      ZT is a principle, a model, and also an architecture focused on resource protection by always verifying transactions using the least privilege principle. Hopefully in 2023, ZT will be more practical and not just a vendor marketing buzzword.

      Next-gen cybersecurity technologies alone are not a silver bullet. A combination of skilled talent, useful data, and best practices will give a competitive advantage. The key concepts are explainable, transparent, and trustworthy. Furthermore, regulation often faces challenges to keep up with next-gen cybersecurity technologies, especially with the implications and risks of adoption, which may not always be explicit.

      Current situation

      ZT: Performing an accurate assessment of readiness and benefits to adopt ZT can be difficult due to ZT's many components. Thus, an organization needs to develop a ZT roadmap that aligns with organizational goals and focuses on access to data, assets, applications, and services; don't select solutions or vendors too early.

      Post-quantum cryptography: Current cryptographic applications, such as RSA for PKI, rely on factorization. However, algorithms such as Shor's show quantum speedup for factorization, which can break current crypto when sufficient quantum computing devices are available. Thus, threat actors can intercept current encrypted information and store it to decrypt in the future.

      AI-based threat management: AI helps in analyzing and correlating data extremely fast compared to humans. Millions of telemetries, malware samples, raw events, and vulnerability data feed into the AI system, which humans cannot process manually. Furthermore, AI does not get tired in processing this big data, thus avoiding human error and negligence.

      Data breach mitigation cost without AI: USD 6.20 million; and with AI: USD 3.15 million

      Source: IBM, 2022

      Traditional security is not working

      Alert Fatigue

      Too many false alarms and too many events to process. Evolving threat landscapes waste your analysts' valuable time on mundane tasks, such as evidence collection. Meanwhile, only limited time is spared for decisions and conclusions, which results in the fear of missing an incident and alert fatigue.

      Lack of Insight

      To report progress, clear metrics are needed. However, cybersecurity still lacks in this area as the system itself is complex and some systems work in silos. Furthermore, lessons learned are not yet distilled into insights for improving future accuracy.

      Lack of Visibility

      System integration is required to create consistent workflows across the organization and to ensure complete visibility of the threat landscape, risks, and assets. Also, the convergence of OT, IoT, and IT enhances this challenge.

      Source: IBM Security Intelligence, 2020

      A business case for AI-based cybersecurity

      Threat management

      Prevention

      Risk scores are generated by machine learning based on variables such as behavioral patterns and geolocation. Zero trust architecture is combined with machine learning. Asset management leverages visibility using machine learning. Comply with regulations by improving discovery, classification, and protection of data using machine learning. Data security and data privacy services use machine learning for data discovery.

      Detection

      AI, advanced machine learning, and static approaches, such as code file analysis, combine to automatically detect and analyze threats and prevent threats from spreading, assisted by threat intelligence.

      Response

      AI helps in orchestrating security technologies for organizations to reduce the number of security agents installed, which may not talk to each other or, worse, may conflict with each other.

      Recovery

      AI continuously tunes based on lessons learned, such as creating security policies for improving future accuracy. AI also does not get fatigue, and it assists humans in a faster recovery.

      Prevention; Detection; Response; Recovery

      AI has been around since the 1940s, but why is it only gaining traction now? Because supporting technologies are only now available, including faster GPUs for complex computations and cheaper storage for massive volumes of data.

      Use this template to explain the priorities you need your stakeholders to know about.

      Adopt next-gen cybersecurity technologies

      Use this template to explain the priorities you need your stakeholders to know about.

      Develop a practical roadmap that shows the business value of next-gen cybersecurity technologies investment.

      Initiative Description:

      Description must include what organization will undertake to complete the initiative.

      • Identify the stakeholders who will be affected by the next-gen cybersecurity technologies implementation and define responsibilities based on skillsets and the degree of support.
      • Adopt well-established data governance practices for cross-functional teams.
      • Conduct a maturity assessment of key processes and highlight interdependencies.
      • Develop a baseline and periodically review risks, policies and procedures, and business plan.
      • Develop a roadmap and deploy next-gen cybersecurity architecture and controls step by step, working with trusted technology partners.
      • Monitor metrics on effectiveness and efficiency.

      Drivers:

      List initiative drivers.

      • Pressure of attacks by sophisticated threat actors
      • Next-gen cybersecurity technologies tool offerings
      • High cost of traditional security, e.g. longer breach lifecycle

      Risks:

      List initiative risks and impacts.

      • Lack of transparency of the model or bias, leading to non-compliance with policies/regulations
      • Risks related with data quality and inadequate data for model training
      • Adversarial attacks, including, but not limited to, adversarial input and model extraction

      Benefits:

      List initiative benefits and align to business benefits or benefits for the stakeholder groups that it impacts.

      • Reduces the number of alerts, thus reduces alert fatigue.
      • Increases the identification of unknown threats.
      • Leads to faster detection and response.
      • Closes skills gap and increases productivity.

      Related Info-Tech Research:

      Recommended Actions

      1. People

      Identify the stakeholders who will be affected by the next-gen cybersecurity technologies implementation and define responsibilities based on skillsets and the degree of support.

      Adopt well-established data governance practices for cross-functional teams.

      2. Process

      Conduct a maturity assessment of key processes and highlight interdependencies.

      Develop a baseline and periodically review risks, policies and procedures, and business plan.

      3. Technology

      Develop a roadmap and deploy next-gen cybersecurity architecture and controls step by step, working with trusted technology partners.

      Monitor metrics on effectiveness and efficiency.

      Source: Leverage AI in Threat Management (keynote presentation), Info-Tech

      Secure Services and Applications

      PRIORITY 05

      • APIS ARE STILL THE #1 THREAT TO APPLICATION SECURITY.

      Executive summary

      Background

      Software is usually produced as part of a supply chain instead of in silos. A vulnerability in any part of the supply chain can become a threat surface. We have learned this from recent incidents such as Log4j, SolarWinds, and Kaseya where attackers compromised a Virtual System Administrator tool used by managed service providers to attack around 1,500 organizations.

      DevSecOps is a culture and philosophy that unifies development, security, and operations to answer this challenge. DevSecOps shifts security left by automating, as much as possible, development and testing. DevSecOps provides many benefits such as rapid development of secure software and assurance that, prior to formal release and delivery, tests are reliably performed and passed.

      DevSecOps practices can apply to IT, OT, IoT, and other technology environments, for example, by integrating a Secure Software Development Framework (SSDF).

      Current situation

      Secure Software Supply Chain: Logging is a fundamental feature of most software, and recently the use of software components, especially open source, are based on trust. From the Log4j incident we learned that more could be done to improve the supply chain by adopting ZT to identify related components and data flows between systems and to apply the least privilege principle.

      DevSecOps: A software error wiped out wireless services for thousands of Rogers customers across Canada in 2021. Emergency services were also impacted, even though outgoing 911 calls were always accessible. Losing such services could have been avoided, if tests were reliably performed and passed prior to release.

      OT insecure-by-design: In OT, insecurity-by-design is still a norm, which causes many vulnerabilities such as insecure protocols implementation, weak authentication schemes, or insecure firmware updates. Additional challenges are the lack of CVEs or CVE duplication, the lack of Software Bill of Materials (SBOM), and product supply chains issues such as vulnerable products that are certified because of the scoping limitation and emphasis on functional testing.

      Technical causes of cybersecurity incidents in EU critical service providers in 2019-2021 shows: software bug (12%) and faulty software changes/update (9%).

      Source: CIRAS Incident reporting, ENISA (N=1,239)

      Software development keeps evolving

      DOD Maturation of Software Development Best Practices

      Best Practices 30 Years Ago 15 Years Ago Present Day
      Lifecycle Years or Months Months or Weeks Weeks or Days
      Development Process Waterfall Agile DevSecOps
      Architecture Monolithic N-Tier Microservices
      Deployment & Packaging Physical Virtual Container
      Hosting Infrastructure Server Data Center Cloud
      Cybersecurity Posture Firewall + SIEM + Zero Trust

      Best practices in software development are evolving as shown on the diagram to the left. For example, 30 years ago the lifecycle was "Years or Months," while in the present day it is "Weeks or Days."

      These changes also impact security such as the software architecture, which is no longer "Monolithic" but "Microservices" normally built within the supply chain.

      The software supply chain has known integrity attacks that can happen on each part of it. Starting from bad code submitted by a developer, to compromised source control platform (e.g. PHP git server compromised), to compromised build platform (e.g. malicious behavior injected on SolarWinds build), to a compromised package repository where users are deceived into using the bad package by the similarity between the malicious and the original package name.

      Therefore, we must secure each part of the link to avoid attacks on the weakest link.

      Software supply chain guidance

      Secure each part of the link to avoid attacks on the weakest link.

      Guide for Developers

      Guide for Suppliers

      Guide for Customers

      Secure product criteria and management, develop secure code, verify third-party components, harden build environment, and deliver code.

      Define criteria for software security checks, protect software, produce well-secured software, and respond to vulnerabilities.

      Secure procurement and acquisition, secure deployment, and secure software operations.

      Source: "Securing the Software Supply Chain" series, Enduring Security Framework (ESF), 2022

      "Most software today relies on one or more third-party components, yet organizations often have little or no visibility into and understanding of how these software components are developed, integrated, and deployed, as well as the practices used to ensure the components' security."

      Source: NIST – NCCoE, 2022

      Use this template to explain the priorities you need your stakeholders to know about.

      Secure services and applications

      Provide a brief value statement for the initiative.

      Adopt recommended practices for securing the software supply chain.

      Initiative Description:

      Description must include what organization will undertake to complete the initiative.

      • Define and keep security requirements and risk assessments up to date.
      • Require visibility into provenance of product, and require suppliers' self-attestation of security hygiene.
      • Verify distribution infrastructure, product and individual components integrity, and SBOM.
      • Use multi-layered defenses, e.g. ZT for integration and control configuration.
      • Train users on how to detect and report anomalies and when to apply updates to a system.
      • Ensure updates from authorized and authenticated sources and verify the integrity of the updated SBOM.

      Drivers:

      List initiative drivers.

      • Cyberattacks exploit the vulnerabilities of weak software supply chain
      • Increased need to enhance software supply chain security, e.g. under the White House Executive Order (EO) 14028
      • OT insecure-by-design hinders OT modernization

      Risks:

      List initiative risks and impacts.

      Only a few developers and suppliers explicitly address software security in detail.

      Time pressure to deliver functionality over security.

      Lack of security awareness and lack of trained workforce.

      Benefits:

      List initiative benefits and align to business benefits or benefits for the stakeholder groups that it impacts.

      Customers (acquiring organizations) achieve secure acquisition, deployment, and operation of software.

      Developers and suppliers provide software security with minimal vulnerabilities in its releases.

      Automated processes such as automated testing avoid error-prone and labor-intensive manual test cases.

      Related Info-Tech Research:

      Recommended Actions

      1. Procurement and Acquisition

      Define and keep security requirements and risk assessments up to date.

      Perform analysis on current market and supplier solutions and acquire security evaluation.

      Require visibility into provenance of product, and require suppliers' self-attestation of security hygiene

      2. Deployment

      Verify distribution infrastructure, product and individual components integrity, and SBOM.

      Save and store the tests and test environment and review and verify the
      self-attestation mechanism.

      Use multi-layered defenses, e.g. ZT for integration and control configuration.

      3. Software Operations

      Train users on how to detect and report anomalies and when to apply updates to a system.

      Ensure updates from authorized and authenticated sources and verify the integrity of the updated SBOM.

      Apply supply chain risk management (SCRM) operations.

      Source: "Securing the Software Supply Chain" series, Enduring Security Framework (ESF), 2022

      Bibliography

      Aksoy, Cevat Giray, Jose Maria Barrero, Nicholas Bloom, Steven J. Davis, Mathias Dolls, and Pablo Zarate. "Working from Home Around the World." Brookings Papers on Economic Activity, 2022.
      Barrero, Jose Maria, Nicholas Bloom, and Steven J. Davis. "Why working from home will stick." WFH Research, National Bureau of Economic Research, Working Paper 28731, 2021.
      Boehm, Jim, Dennis Dias, Charlie Lewis, Kathleen Li, and Daniel Wallance. "Cybersecurity trends: Looking over the horizon." McKinsey & Company, March 2022. Accessed
      31 Oct. 2022.
      "China: TC260 issues list of national standards supporting implementation of PIPL." OneTrust, 8 Nov. 2022. Accessed 17 Nov. 2022.
      Chmielewski, Stéphane. "What is the potential of artificial intelligence to improve cybersecurity posture?" before.ai blog, 7 Aug. 2022. Accessed 15 Aug. 2022.
      Conerly, Bill. "The Recession Will Begin Late 2023 Or Early 2024." Forbes, 1 Nov. 2022. Accessed 8 Nov. 2022.
      "Control System Defense: Know the Opponent." CISA, 22 Sep. 2022. Accessed 17 Nov. 2022.
      "Cost of a Data Breach Report 2022." IBM, 2022.
      "Cybersecurity: Parliament adopts new law to strengthen EU-wide resilience." European Parliament News, 10 Nov. 2022. Press Release.
      "Cyber Security in Critical National Infrastructure Organisations: 2022." Bridewell, 2022. Accessed 7 Nov. 2022.
      Davis, Steven. "The Big Shift to Working from Home." NBER Macro Annual Session On
      "The Future of Work," 1 April 2022.
      "Digital Services Act: EU's landmark rules for online platforms enter into force."
      EU Commission, 16 Nov. 2022. Accessed 16 Nov. 2022.
      "DoD Enterprise DevSecOps Fundamentals." DoD CIO, 12 May 2022. Accessed 21 Nov. 2022.
      Elkin, Elizabeth, and Deena Shanker. "That Cream Cheese Shortage You Heard About? Cyberattacks Played a Part." Bloomberg, 09 Dec. 2021. Accessed 27 Oct. 2022.
      Evan, Pete. "What happened at Rogers? Day-long outage is over, but questions remain." CBC News, 21 April 2022. Accessed 15 Nov. 2022.
      "Fewer Ransomware Victims Pay, as Median Ransom Falls in Q2 2022." Coveware,
      28 July 2022. Accessed 18 Nov. 2022.
      "Fighting cybercrime: new EU cybersecurity laws explained." EU Commission, 10 Nov. 2022. Accessed 16 Nov. 2022.
      "Guide to PCI compliance cost." Vanta. Accessed 18 Nov. 2022.
      Hammond, Susannah, and Mike Cowan. "Cost of Compliance 2022: Competing priorities." Thomson Reuters, 2022. Accessed 18 Nov. 2022.
      Hemsley, Kevin, and Ronald Fisher. "History of Industrial Control System Cyber Incidents." Department of Energy (DOE), 2018. Accessed 29 Aug. 2022.
      Hofmann, Sarah. "What Is The NIS2 And How Will It Impact Your Organisation?" CyberPilot,
      5 Aug. 2022. Accessed 16 Nov. 2022.
      "Incident reporting." CIRAS Incident Reporting, ENISA. Accessed 21 Nov. 2022.
      "Introducing SLSA, an End-to-End Framework for Supply Chain Integrity." Google,
      16 June 2021. Accessed 25 Nov. 2022.
      Kovacs, Eduard. "Trains Vulnerable to Hacker Attacks: Researchers." SecurityWeek, 29 Dec. 2015. Accessed 15 Nov. 2022.
      "Labour Force Survey, October 2022." Statistics Canada, 4 Nov. 2022. Accessed 7 Nov. 2022.
      Malacco, Victor. "Promises and potential of automated milking systems." Michigan State University Extension, 28 Feb. 2022. Accessed 15 Nov. 2022.
      Maxim, Merritt, et al. "Planning Guide 2023: Security & Risk." Forrester, 23 Aug. 2022. Accessed 31 Oct. 2022.
      "National Cyber Threat Assessment 2023-2024." Canadian Centre for Cyber Security, 2022. Accessed 18 Nov. 2022.
      Nicaise, Vincent. "EU NIS2 Directive: what's changing?" Stormshield, 20 Oct. 2022. Accessed
      17 Nov. 2022.
      O'Neill, Patrick. "Russia hacked an American satellite company one hour before the Ukraine invasion." MIT Technology Review, 10 May 2022. Accessed 26 Aug. 2022.
      "OT ICEFALL: The legacy of 'insecure by design' and its implications for certifications and risk management." Forescout, 2022. Accessed 21 Nov. 2022.
      Palmer, Danny. "Your cybersecurity staff are burned out - and many have thought about quitting." ZDNet, 8 Aug. 2022. Accessed 19 Aug. 2022.
      Placek, Martin. "Industrial Internet of Things (IIoT) market size worldwide from 2020 to 2028 (in billion U.S. dollars)." Statista, 14 March 2022. Accessed 15 Nov. 2022.
      "Revised Proposal Attachment 5.13.N.1 ADMS Business Case PUBLIC." Ausgrid, Jan. 2019. Accessed 15 Nov. 2022.
      Richter, Felix. "Cloudy With a Chance of Recession." Statista, 6 April 2022. Web.
      "Securing the Software Supply Chain: Recommended Practices Guide for Developers." Enduring Security Framework (ESF), Aug. 2022. Accessed 22 Sep. 2022.
      "Securing the Software Supply Chain: Recommended Practices Guide for Suppliers." Enduring Security Framework (ESF), Sep. 2022. Accessed 21 Nov. 2022.
      "Securing the Software Supply Chain: Recommended Practices Guide for Customers." Enduring Security Framework (ESF), Oct. 2022. Accessed 21 Nov. 2022.
      "Security Guidelines for the Electricity Sector: Control System Electronic Connectivity."
      North American Electric Reliability Corporation (NERC), 28 Oct. 2013. Accessed 25 Nov. 2022.
      Shepel, Jan. "Schreiber Foods hit with cyberattack; plants closed." Wisconsin State Farmer,
      26 Oct. 2022. Accessed 15 Nov. 2022.
      "Significant Cyber Incidents." Center for Strategic and International Studies (CSIS). Accessed
      1 Sep. 2022.
      Souppaya, Murugiah, Michael Ogata, Paul Watrobski, and Karen Scarfone. "Software Supply Chain and DevOps Security Practices: Implementing a Risk-Based Approach to DevSecOps." NIST - National Cybersecurity Center of Excellence (NCCoE), Nov. 2022. Accessed
      22 Nov. 2022.
      "Ten Things Will Change Cybersecurity in 2023." SOCRadar, 23 Sep. 2022. Accessed
      31 Oct. 2022.
      "The Nature of Cybersecurity Defense: Pentagon To Reveal Updated Zero-Trust Cybersecurity Strategy & Guidelines." Cybersecurity Insiders. Accessed 21 Nov. 2022.
      What Is Threat Management? Common Challenges and Best Practices." IBM Security Intelligence, 2020.
      Woolf, Tim, et al. "Benefit-Cost Analysis for Utility-Facing Grid Modernization Investments: Trends, Challenges, and Considerations." Lawrence Berkeley National Laboratory, Feb. 2021. Accessed 15 Nov. 2022.
      Violino, Bob. "5 key considerations for your 2023 cybersecurity budget planning." CSO Online,
      14 July 2022. Accessed 27 Oct. 2022

      Research Contributors and Experts

      Andrew Reese
      Cybersecurity Practice Lead
      Zones

      Ashok Rutthan
      Chief Information Security Officer (CISO)
      Massmart

      Chris Weedall
      Chief Information Security Officer (CISO)
      Cheshire East Council

      Jeff Kramer
      EVP Digital Transformation and Cybersecurity
      Aprio

      Kris Arthur
      Chief Information Security Officer (CISO)
      SEKO Logistics

      Mike Toland
      Chief Information Security Officer (CISO)
      Mutual Benefit Group

      Adopt Generative AI in Solution Delivery

      • Buy Link or Shortcode: {j2store}146|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Development
      • Parent Category Link: /development
      • Delivery teams are under continuous pressure to deliver high value and quality solutions with limited capacity in complex business and technical environments. Common challenges experienced by these teams include:
        • Attracting and retaining talent
        • Maximizing the return on technology
        • Confidently shifting to digital
        • Addressing competing priorities
        • Fostering a collaborative culture
        • Creating high-throughput teams
      • Gen AI offers a unique opportunity to address many of these challenges.

      Our Advice

      Critical Insight

      • Your stakeholders' understanding of Gen AI, its value, and its application can be driven by hype and misinterpretation. This confusion can lead to unrealistic expectations and set the wrong precedent for the role Gen AI is intended to play.
      • Your SDLC is not well documented and is often executed inconsistently. An immature practice will not yield the benefits stakeholders expect.
      • The Gen AI marketplace is broad and diverse. Selecting the appropriate tools and partners is confusing and overwhelming.
      • There is a skills gap for what is needed to configure, adopt, and operate Gen AI.

      Impact and Result

      • Ground your Gen AI expectations. Set realistic and achievable goals centered on driving business value and efficiency across the entire SDLC by enabling Gen AI in key tasks and activities. Propose the SDLC as the ideal pilot for Gen AI.
      • Select the right Gen AI opportunities. Discuss how proven Gen AI capabilities can be applied to your solution delivery practice to achieve the outcomes and priorities stakeholders expect. Lessons learned sow the foundation for future Gen AI scaling.
      • Assess your Gen AI readiness in your solution delivery teams. Clarify the roles, processes, and tools needed for the implementation, use, and maintenance of Gen AI.

      Adopt Generative AI in Solution Delivery Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Adopt Generative AI in Solution Delivery Storyboard – A step-by-step guide that helps you assess whether Gen AI is right for your solution delivery practices.

      Gain an understanding of the potential opportunities that Gen AI can provide your solution delivery practices and answer the question "What should I do next?"

      • Adopt Generative AI in Solution Delivery Storyboard

      2. Gen AI Solution Delivery Readiness Assessment Tool – A tool to help you understand if your solution delivery practice is ready for Gen AI.

      Assess the readiness of your solution delivery team for Gen AI. This tool will ask several questions relating to your people, process, and technology, and recommend whether or not the team is ready to adopt Gen AI practices.

      • Gen AI Solution Delivery Readiness Assessment Tool
      [infographic]

      Further reading

      Adopt Generative AI in Solution Delivery

      Drive solution quality and team productivity with the right generative AI capabilities.

      Analyst Perspective

      Build the case for Gen AI with the right opportunities.

      Generative AI (Gen AI) presents unique opportunities to address many solution delivery challenges. Code generation can increase productivity, synthetic data generation can produce usable test data, and scanning tools can identify issues before they occur. To be successful, teams must be prepared to embrace the changes that Gen AI brings. Stakeholders must also give teams the opportunity to optimize their own processes and gauge the fit of Gen AI.

      Start small with the intent to learn. The right pilot initiative helps you learn the new technology and how it benefits your team without the headache of complex setups and lengthy training and onboarding. Look at your existing solution delivery tools to see what Gen AI capabilities are available and prioritize the use cases where Gen AI can be used out of the box.

      This is a picture of Andrew Kum-Seun

      Andrew Kum-Seun
      Research Director,
      Application Delivery and Management
      Info-Tech Research Group

      Executive Summary

      Your Challenge

      Delivery teams are under continuous pressure to deliver high-value, high-quality solutions with limited capacity in complex business and technical environments. Common challenges experienced by these teams include:

      • Attracting and retaining talent
      • Maximizing the return on technology
      • Confidently shifting to digital
      • Addressing competing priorities
      • Fostering a collaborative culture
      • Creating high-throughput teams

      Generative AI (Gen AI) offers a unique opportunity to address many of these challenges.

      Common Obstacles

      • Your stakeholders' understanding of what is Gen AI, its value and its application, can be driven by hype and misinterpretation. This confusion can lead to unrealistic expectations and set the wrong precedent for the role Gen AI is intended to play.
      • Your solution delivery process is not well documented and is often executed inconsistently. An immature practice will not yield the benefits stakeholders expect.
      • The Gen AI marketplace is very broad and diverse. Selecting the appropriate tools and partners is confusing and overwhelming.
      • There is a skills gap for what is needed to configure, adopt, and operate Gen AI.

      Info-Tech's Approach

      • Ground your Gen AI expectations. Set realistic and achievable goals centered on driving business value and efficiency across the entire solution delivery process by enabling Gen AI in key tasks and activities. Propose this process as the ideal pilot for Gen AI.
      • Select the right Gen AI opportunities. Discuss how proven Gen AI capabilities can be applied to your solution delivery practice and achieve the outcomes and priorities stakeholders expect. Lessons learned sow the foundation for future Gen AI scaling.
      • Assess your Gen AI readiness in your solution delivery teams. Clarify the roles, processes, and tools needed for the implementation, use, and maintenance of Gen AI.

      Info-Tech Insight

      Position Gen AI as a tooling opportunity to enhance the productivity and depth of your solution delivery practice. Current Gen AI tools are unable to address the various technical and human complexities that commonly occur in solution delivery. Assess the fit of Gen AI by augmenting low-risk, out-of-the-box tools in key areas of your solution delivery process and teams.

      Insight Summary

      Overarching Info-Tech Insight

      Position Gen AI is a tooling opportunity to enhance the productivity and depth of your solution delivery practice. However, current Gen AI tools are unable to address the various technical and human complexities that commonly occur in solution delivery. Assess the fit of Gen AI by augmenting low-risk, out-of-the-box tools in key areas of your solution delivery process and teams.

      Understand and optimize first, automate with Gen AI later.
      Gen AI magnifies solution delivery inefficiencies and constraints. Adopt a user-centric perspective to understand your solution delivery teams' interactions with solution delivery tools and technologies to better replicate how they complete their tasks and overcome challenges.

      Enable before buy. Buy before build.
      Your solution delivery vendors see AI as a strategic priority in their product and service offering. Look into your existing toolset and see if you already have the capabilities. Otherwise, prioritize using off-the-shelf solutions with pre-trained Gen AI capabilities and templates.

      Innovate but don't experiment.
      Do not reinvent the wheel and lower your risk of success. Stick to the proven use cases to understand the value and fit of Gen AI tools and how your teams can transform the way they work. Use your lessons learned to discover scaling opportunities.

      Blueprint benefits

      IT benefits

      Business benefits

      • Select the Gen AI tools and capabilities that meet both the solution delivery practice and team goals, such as:
      • Improved team productivity and throughput.
      • Increased solution quality and value.
      • Greater team satisfaction.
      • Motivate stakeholder buy-in for the investment in solution delivery practice improvements.
      • Validate the fit and opportunities with Gen AI for future adoption in other IT departments.
      • Increase IT satisfaction by improving the throughput and speed of solution delivery.
      • Reduce the delivery and operational costs of enterprise products and services.
      • Use a pilot to demonstrate the fit and value of Gen AI capabilities and supporting practices across business and IT units.

      What is Gen AI?

      An image showing where Gen AI sits within the artificial intelligence.  It consists of four concentric circles.  They are labeled from outer-to-inner circle in the following order: Artificial Intelligence; Machine Learning; Deep Learning; Gen AI

      Generative AI (Gen AI)
      A form of ML whereby, in response to prompts, a Gen AI platform can generate new output based on the data it has been trained on. Depending on its foundational model, a Gen AI platform will provide different modalities and use case applications.

      Machine Learning (ML)
      The AI system is instructed to search for patterns in a data set and then make predictions based on that set. In this way, the system learns to provide accurate content over time. This requires a supervised intervention if the data is inaccurate. Deep learning is self-supervised and does not require intervention.

      Artificial Intelligence (AI)
      A field of computer science that focuses on building systems to imitate human behavior. Not all AI systems have learning behavior; many systems (such as customer service chatbots) operate on preset rules.

      Info-Tech Insight

      Many vendors have jumped on Gen AI as the latest marketing buzzword. When vendors claim to offer Gen AI functionality, pin down what exactly is generative about it. The solution must be able to induce new outputs from inputted data via self-supervision – not trained to produce certain outputs based on certain inputs.

      Augment your solution delivery teams with Gen AI

      Position Gen AI as a tooling opportunity to enhance the productivity and depth of your solution delivery practice. Current Gen AI tools are unable to address the various technical and human complexities that commonly occur in solution delivery; assess the fit of Gen AI by augmenting low-risk, out-of-the-box tools in key areas of your solution delivery process and teams.

      Solution Delivery Team

      Humans

      Gen AI Bots

      Product owner and decision maker
      Is accountable for the promised delivery of value to the organization.

      Business analyst and architect
      Articulates the requirements and aligns the team to the business and technical needs.

      Integrator and builder
      Implements the required solution.

      Collaborator
      Consults and supports the delivery.

      Administrator
      Performs common administrative tasks to ensure smooth running of the delivery toolchain and end-solutions.

      Designer and content creator
      Provides design and content support for common scenarios and approaches.

      Paired developer and tester
      Acts as a foil for existing developer or tester to ensure high quality output.

      System monitor and support
      Monitors and recommends remediation steps for operational issues that occur.

      Research deliverable

      This research is accompanied by a supporting deliverable to help you accomplish your goals.

      Gen AI Solution Delivery Readiness Assessment Tool

      Assess the readiness of your solution delivery team for Gen AI. This tool will ask several questions relating to your people, process, and technology, and recommend whether the team is ready to adopt Gen AI practices.

      This is a series of three screenshots from the Gen AI Solution Delivery Readiness Assessment Tool

      Step 1.1

      Set the context

      Activities

      1.1.1 Understand the challenges of your solution delivery teams.

      1.1.2 Outline the value you expect to gain from Gen AI.

      This step involves the following participants:

      • Applications VP
      • Applications Director
      • Solution Delivery Manager
      • Solution Delivery Team

      Outcomes of this step

      • SWOT Analysis to help articulate the challenges facing your teams.
      • A Gen AI Canvas that will articulate the value you expect to gain.

      IT struggles to deliver solutions effectively

      • Lack of skills and resources
        Forty-six percent of respondents stated that it was very or somewhat difficult to attract, hire, and retain developers (GitLab, 2023; N=5,010).
      • Delayed software delivery
        Code development (37%), monitoring/observability (30%), deploying to non-production environments (30%), and testing (28%) were the top areas where software delivery teams or organizations encountered the most delays (GitLab, 2023, N=5,010).
      • Low solution quality and satisfaction
        Only 64% of applications were identified as effective by end users. Effective applications are identified as at least highly important and have high feature and usability satisfaction (Application Portfolio Assessment, August 2021 to July 2022; N=315).
      • Burnt out teams
        While workplace flexibility comes with many benefits, longer work hours jeopardize wellbeing. Sixty-two percent of organizations reported increased working hours, while 80% reported an increase in flexibility ("2022 HR Trends Report," McLean & Company, 2022; N=394) .

      Creating high-throughput teams is an organizational priority.

      CXOs ranked "optimize IT service delivery" as the second highest priority. "Achieve IT business" was ranked first.

      (CEO-CIO Alignment Diagnostics, August 2021 to July 2022; n=568)

      1.1.1 Understand the challenges of your solution delivery teams

      1-3 hours

      1. Complete a SWOT analysis of your solution delivery team to discover areas where Gen AI can be applied.
      2. Record this information in the Gen AI Solution Delivery Readiness Assessment Tool.

      Strengths

      Internal characteristics that are favorable as they relate to solution delivery

      Weaknesses

      Internal characteristics that are unfavorable or need improvement

      Opportunities

      External characteristics that you may use to your advantage

      Threats

      External characteristics that may be potential sources of failure or risk

      Record the results in the Gen AI Solution Delivery Readiness Assessment Tool

      Output

      • SWOT analysis of current state of solution delivery practice

      Participants

      • Applications VP
      • Applications Director
      • Solution Delivery Manager
      • Solution Delivery Team

      Gen AI can help solve your solution delivery challenges

      Why is software delivery an ideal pilot candidate for Gen AI?

      • Many software delivery practices are repeatable and standardized.
      • Software delivery roles that are using and implementing Gen AI are technically savvy.
      • Automation is a staple in many commonly used tools.
      • Change will likely not impact business operations.

      Improved productivity

      Gen AI jumpstarts the most laborious and mundane parts of software delivery. Delivery teams saved 22 hours (avg) per software use case when using AI in 2022, compared to last year when AI was not used ("Generative AI Speeds Up Software Development," PRNewswire, 2023).

      Fungible resources

      Teams are transferrable across different frameworks, platforms, and products. Gen AI provides the structure and guidance needed to work across a wider range of projects ("Game changer: The startling power generative AI is bringing to software development," KPMG, 2023).

      Improved solution quality

      Solution delivery artifacts (e.g. code) are automatically scanned to quickly identify bugs and defects based on recent activities and trends and validate against current system performance and capacity.

      Business empowerment

      AI enhances the application functionalities workers can build with low- and no-code platforms. In fact, "AI high performers are 1.6 times more likely than other organizations to engage non-technical employees in creating AI applications" ("The state of AI in 2022 — and a half decade in review." McKinsey, 2022, N=1,492).

      However, various fears, uncertainties, and doubts challenge Gen AI adoption

      Black Box

      Little transparency is provided on the tool's rationale behind content creation, decision making, and the use and storage of training data, creating risks for legal, security, intellectual property, and other areas.

      Role Replacement

      Some workers have job security concerns despite Gen AI being bound to their rule-based logic framework, the quality of their training data, and patterns of consistent behavior.

      Skills Gaps

      Teams need to gain expertise in AI/ML techniques, training data preparation, and continuous tooling improvements to support effective Gen AI adoption across the delivery practice and ensure reliable operations.

      Data Inaccuracy

      Significant good quality data is needed to build trust in the applicability and reliability of Gen AI recommendations and outputs. Teams must be able to combine Gen AI insights with human judgment to generate the right outcome.

      Slow Delivery of AI Solution

      Timelines are sensitive to organizational maturity, experience with Gen AI, and investments in good data management practices. 65% of organizations said it took more than three months to deploy an enterprise-ready AIOps solution (OpsRamp, 2022).

      Define the value you want Gen AI to deliver

      Well-optimized Gen AI instills stakeholder confidence in ongoing business value delivery and ensures stakeholder buy-in, provided proper expectations are set and met. However, business value is not interpreted or prioritized the same across the organization. Come to a common business value definition to drive change in the right direction by balancing the needs of the individual, team, and organization.

      Business value cannot always be represented by revenue or reduced expenses. Dissecting value by the benefit type and the value source's orientation allows you to see the many ways in which Gen AI brings value to the organization.

      Financial benefits vs. intrinsic needs

      • Financial benefits refers to the degree to which the value source can be measured through monetary metrics, such as revenue generation and cost saving.
      • Intrinsic needs refers to how a product, service, or business capability enhanced with Gen AI meets functional, user experience, and existential needs.

      Inward vs. outward orientation

      • Inward refers to value sources that are internally impacted by Gen AI and improve your employees' and teams' effectiveness in performing their responsibilities.
      • Outward refers to value sources that come from your interaction with external stakeholders and customers and were improved from using Gen AI.

      See our Build a Value Measurement Framework blueprint for more information about business value definition.

      An image of the Business Value Matrix for Gen AI

      Measure success with the right metrics

      Establishing and monitoring metrics are powerful ways to drive behavior and strategic changes in your organization. Determine the right measures that demonstrate the value of your Gen AI implementation by aligning them with your Gen AI objectives, business value drivers, and non-functional requirements.

      Select metrics with different views

      1. Solution delivery practice effectiveness
        The ability of your practice to deliver, support, and operate solutions with Gen AI
        Examples: Solution quality and throughput, delivery and operational costs, number of defects and issues, and system quality
      2. Solution quality and value
        The outcome of your solutions delivered with Gen AI tools
        Examples: Time and money saved, utilization of products and services, speed of process execution, number of errors, and compliance with standards
      3. Gen AI journey goals and milestones
        Your organization's position in your Gen AI journey
        Examples: Maturity score, scope of Gen AI adoption, comfort and
        confidence with Gen AI capabilities, and complexity of Gen AI use cases

      Leverage Info-Tech's Diagnostics

      IT Management & Governance

      • Improvement to application development quality and throughput effectiveness
      • Increased importance of application delivery and maintenance capabilities across the IT organization
      • Delegation of delivery accountability across more IT roles

      CIO Business Vision

      • Improvements to IT satisfaction and value from delivered solutions
      • Changes to the value and importance of IT core services enabled with Gen AI
      • The state of business and IT relationships
      • Capability to deliver and support Gen AI effectively

      1.1.2 Outline the value you expect to gain from Gen AI

      1-3 hours

      1. Complete the following fields to build your Gen AI canvas:
        1. Problem that Gen AI is intending to solve
        2. List of stakeholders
        3. Desired business and IT outcomes
        4. In-scope solution delivery teams, systems, and capabilities.
      2. Record this information in the Gen AI Solution Delivery Readiness Assessment Tool.

      Output

      • Gen AI Canvas

      Participants

      • Applications VP
      • Applications Director
      • Solution Delivery Manager
      • Solution Delivery Team

      Record the results in the Gen AI Solution Delivery Readiness Assessment Tool

      1.1.2 Example

      Example of an outline of the value you expect to gain from Gen AI

      Problem statements

      • Manual testing procedures hinder pace and quality of delivery.
      • Inaccurate requirement documentation leads to constant redesigning.

      Business and IT outcomes

      • Improve code quality and performance.
      • Expedite solution delivery cycle.
      • Improve collaboration between teams and reduce friction.

      List of stakeholders

      • Testing team
      • Application director
      • CIO
      • Design team
      • Project manager
      • Business analysts

      In-scope solution delivery teams, system, and capabilities

      • Web
      • Development
      • App development
      • Testing
      • Quality assurance
      • Business analysts
      • UI/UX design

      Align your objectives to the broader AI strategy

      Why is an organizational AI strategy important for Gen AI?

      • All Gen AI tactics and capabilities are designed, delivered, and managed to support a consistent interpretation of the broader AI vision and goals.
      • An organizational strategy gives clear understanding of the sprawl, criticality, and risks of Gen AI solutions and applications to other IT capabilities dependent on AI.
      • Gen AI initiatives are planned, prioritized, and coordinated alongside other software delivery practice optimizations and technology modernization initiatives.
      • Resources, skills, and capacities are strategically allocated to meet the needs of Gen AI considering other commitments in the software delivery optimization backlog and roadmap.
      • Gen AI expectations and practices uphold the persona, values, and principles of the software delivery team.

      What is an AI strategy?

      An AI strategy details the direction, activities, and tactics to deliver on the promise of your AI portfolio. It often includes:

      • AI vision and goals
      • Application, automation, and process portfolio involved or impacted by AI
      • Values and principles
      • Health of your AI portfolio
      • Risks and constraints
      • Strategic roadmap

      Step 1.2

      Evaluate opportunities for Gen AI

      Activities

      1.2.1 Align Gen AI opportunities with teams and capabilities.

      This step involves the following participants:

      • Applications VP
      • Applications Director
      • Solution Delivery Manager
      • Solution Delivery Team

      Outcomes of this step

      • Understand the Gen AI opportunities for your solution delivery practice.

      Learn how Gen AI is employed in solution delivery

      Gen AI opportunity Common Gen AI tools and vendors Teams than can benefit How can teams leverage this? Case study
      Synthetic data generation
      • Testing
      • Data Analysts
      • Privacy and Security
      • Create test datasets
      • Replace sensitive personal data

      How Unity Leverages Synthetic Data

      Code generation
      • Development
      • Testing
      • Code Templates & Boilerplate
      • Code Refactoring

      How CI&T accelerated development by 11%

      Defect forecasting and debugging
      • Project Manager & Quality Assurance
      • Development
      • Testing
      • Identify root cause
      • Static and dynamic code analysis
      • Debugging assistance

      Altran Uses Microsoft Code Defect AI Solution

      Requirements documentation and elicitation
      • Business Analysts
      • Development
      • Document functional requirements
      • Writing test cases

      Google collaborates with Replit to reduce time to bring new products to market by 30%

      UI design and prototyping
      • UI/UX Design
      • Development
      • Deployment
      • Rapid prototyping
      • Design assistance

      How Spotify is Upleveling Their Entire Design Team

      Other common AI opportunities solutions include test case generation, code translation, use case creation, document generation, and automated testing.

      Opportunity 1: Synthetic data generation

      Create artificial data that mimics the structure of real-life data.

      What are the expected benefits?

      • Availability of test data: Creation of large volumes of data compatible for testing multiple systems within the organization.
      • Improved privacy: Substituting real data with artificial leads to reduced data leaks.
      • Quicker data provisioning: Automated generation of workable datasets aligned to company policies.

      What are the notable risks and challenges?

      • Generalization and misrepresentations: Data models used in synthetic data generation may not be an accurate representation of production data because of potentially conflicting definitions, omission of dependencies, and multiple sources of truth.
      • Lack of accurate representation: It is difficult for synthetic data to fully capture real-world data nuances.
      • Legal complexities: Data to build and train the Gen AI tool does not comply with data residency and management standards and regulations.

      How should teams prepare for synthetic data generation?

      It can be used:

      • To train machine learning models when there is not enough real data, or the existing data does not meet specific needs.
      • To improve quality of test by using data that closely resembles production without the risk of leveraging sensitive and private information.

      "We can simply say that the total addressable market of synthetic data and the total addressable market of data will converge,"
      Ofir Zuk, CEO, Datagen (Forbes, 2022)

      Opportunity 2: Code generation

      Learn patterns and automatically generate code.

      What are the expected benefits?

      • Increased productivity: It allows developers to generate more code quickly.
      • Improved code consistency: Code is generated using a standardized model and lessons learnt from successful projects.
      • Rapid prototyping: Expedite development of a working prototype to be verified and validated.

      What are the notable risks and challenges?

      • Limited contextual understanding: AI may lack domain-specific knowledge or understanding of requirements.
      • Dependency: Overreliance on AI generated codes can affect developers' creativity.
      • Quality concerns: Generated code is untested and its alignment to coding and quality standards is unclear.

      How should teams prepare for code generation?

      It can be used to:

      • Build solutions without the technical expertise of traditional development.
      • Discover different solutions to address coding challenges.
      • Kickstart new development projects with prebuilt code.

      According to a survey conducted by Microsoft's GitHub, a staggering 92% of programmers were reported as using AI tools in their workflow (GitHub, 2023).

      Opportunity 3: Defect forecasting & debugging

      Predict and proactively address defects before they occur.

      What are the expected benefits?

      • Reduced maintenance cost: Find defects earlier in the delivery process, when it's cheaper to fix them.
      • Increased efficiency: Testing efforts can remain focused on critical and complex areas of solution.
      • Reduced risk: Find critical defects before the product is deployed to production.

      What are the notable risks and challenges?

      • False positives and negatives: Incorrect interpretation and scope of defect due to inadequate training of the Gen AI model.
      • Inadequate training: Training data does not reflect the complexity of the solutions code.
      • Not incorporating feedback: Gen AI models are not retrained in concert with solution changes.

      How should teams prepare for defect forecasting and debugging?

      It can be used to:

      • Perform static and dynamic code analysis to find vulnerabilities in the solution source code.
      • Forecast potential issues of a solution based on previous projects and industry trends.
      • Find root cause and suggest solutions to address found defects.

      Using AI technologies, developers can reduce the time taken to debug and test code by up to 70%, allowing them to finish projects faster and with greater accuracy (Aloa, 2023).

      Opportunity 4: Requirements documentation & elicitation

      Capturing, documenting, and analyzing function and nonfunctional requirements.

      What are the expected benefits?

      • Improve quality of requirements: Obtain different perspectives and contexts for the problem at hand and help identify ambiguities and misinterpretation of risks and stakeholder expectation.
      • Increased savings: Fewer resources are consumed in requirements elicitation activities.
      • Increased delivery confidence: Provide sufficient information for the solution delivery team to confidently estimate and commit to the delivery of the requirement.

      What are the notable risks and challenges?

      • Conflicting bias: Gen AI models may interpret the problem differently than how the stakeholders perceive it.
      • Organization-specific interpretation: Inability of the Gen AI models to accommodate unique interpretation of terminologies, standards, trends and scenarios.
      • Validation and review: Interpreting extracted insights requires human validation.

      How should teams prepare for requirements documentation & elicitation?

      It can be used to:

      • Document requirements in a clear and concise manner that is usable to the solution delivery team.
      • Analyze and test requirements against various user, business, and technical scenarios.

      91% of top businesses surveyed report having an ongoing investment in AI (NewVantage Partners, 2021).

      Opportunity 5: UI design and prototyping

      Analyze existing patterns and principles to generate design, layouts, and working solutions.

      What are the expected benefits?

      • Increased experimentation: Explore different approaches and tactics to solve a solution delivery problem.
      • Improved collaboration: Provide quick design layouts that can be reshaped based on stakeholder feedback.
      • Ensure design consistency: Enforce a UI/UX design standard for all solutions.

      What are the notable risks and challenges?

      • Misinterpretation of UX Requirements: Gen AI model incorrectly assumes a specific interpretation of user needs, behaviors, and problem.
      • Incorrect or missing requirements: Lead to extensive redesigns and iterations, adding to costs while hampering user experience.
      • Design creativity: May lack originality and specific brand aesthetics if not augmented well with human customizability and creativity.

      How should teams prepare for UI design and prototyping?

      It can be used to:

      • Visualize the solution through different views and perspectives such as process flows and use-case diagrams.
      • Create working prototypes that can be verified and validated by stakeholders and end users.

      A study by McKinsey & Company found that companies that invest in AI-driven design outperform their peers in revenue growth and customer experience metrics. They were found to achieve up to two times higher revenue growth than industry peers and up to 10% higher net promoter score (McKinsey & Company, 2018).

      Determine the importance of your opportunities by answering these questions

      Realizing the complete potential of Gen AI relies on effectively fostering its adoption and resulting changes throughout the entire solution delivery process.

      What are the challenges faced by your delivery teams that could be addressed by Gen AI?

      • Recognize the precise pain points, bottlenecks, or inefficiencies faced by delivery teams.
      • Include all stakeholders' perspectives during problem discovery and root cause analysis.

      What's holding back Gen AI adoption in the organization?

      • Apart from technical barriers, address cultural and organizational challenges and discuss how organizational change management strategies can mitigate Gen AI adoption risk.

      Are your objectives aligned with Gen AI capabilities?

      • Identify areas where processes can be modernized and streamlined with automation.
      • Evaluate the current capabilities and resources available within the organization to leverage Gen AI technologies effectively.

      How can Gen AI improve the entire solution delivery process?

      • Investigate and evaluate the improvements Gen AI can reasonably deliver, such as increased accuracy, quickened delivery cycles, improved code quality, or enhanced cross-functional collaboration.

      1.2.1 Align Gen AI opportunities to teams and capabilities

      1-3 hours

      1. Associate the Gen AI opportunities that can be linked to your system capabilities. These opportunities refer to the potential applications of generative AI techniques, such as code generation or synthetic data, to address specific challenges.
        1. Start by analyzing your system's requirements, constraints, and areas where Gen AI techniques can bring value. Identify the potential benefits of integrating Gen AI, such as increased productivity, or enhanced creativity.
        2. Next, discern potential risks or challenges, such as dependency or quality concerns, associated with the opportunity implementation.
      2. Record this information in the Gen AI Solution Delivery Readiness Assessment Tool.

      Output

      • Gen AI opportunity selection

      Participants

      • Applications VP
      • Applications Director
      • Solution Delivery Manager
      • Solution Delivery Team

      Record the results in the Gen AI Solution Delivery Readiness Assessment Tool

      Keep an eye out for red flags

      Not all Gen AI opportunities are delivered and adopted the same. Some present a bigger risk than others.

      • Establishing vague targets and success criteria
      • Defining Gen AI as substitution of human capital
      • Open-source software not widely adopted or validated
      • High level of dependency on automation
      • Unadaptable cross-functional training across organization
      • Overlooking privacy, security, legal, and ethical implications
      • Lack of Gen AI expertise and understanding of good practices

      Step 1.3

      Assess your readiness for Gen AI

      Activities

      1.3.1 Assess your readiness for Gen AI.

      This step involves the following participants:

      • Applications VP
      • Applications Director
      • Solution Delivery Manager
      • Solution Delivery Team

      Outcomes of this step

      • A completed Gen AI Readiness Assessment to confirm how prepared you are to embrace Gen AI in your solution delivery team.

      Prepare your SDLC* to leverage Gen AI

      As organizations evolve and adopt more tools and technology, their solution delivery processes become more complex. Process improvement is needed to simplify complex and undocumented software delivery activities and artifacts and prepare it for Gen AI. Gen AI scales process throughput and output quantity, but it multiplies the negative impact of problems the process already has.

      When is your process ready for Gen AI?

      • Solution value Ensures the accuracy and alignment of the committed feature and change requests to what the stakeholder truly expects and receives.
      • ThroughputDelivers new products, enhancements, and changes at a pace and frequency satisfactory to stakeholder expectations and meets delivery commitments.
      • Process governance Has clear ownership and appropriate standardization. The roles, activities, tasks, and technologies are documented and defined. At each stage of the process someone is responsible and accountable.
      • Process management Follows a set of development frameworks, good practices, and standards to ensure the solution and relevant artifacts are built, tested, and delivered consistently and repeatably.
      • Technical quality assurance – Accommodates committed non-functional requirements within the stage's outputs to ensure products meet technical excellence expectations.

      *software development lifecycle

      To learn more, visit Info-Tech's Modernize Your SDLC blueprint.

      To learn more, visit Info-Tech's Build a Winning Business Process Automation Playbook

      Assess the impacts from Gen AI changes

      Ensure that no stone is left unturned as you evaluate the fit of Gen AI and prepare your adoption and support plans.

      By shining a light on considerations that might have otherwise escaped planners and decision makers, an impact analysis is an essential component to Gen AI success. This analysis should answer the following questions on the impact to your solution delivery teams.

      1. Will the change impact how our clients/customers receive, consume, or engage with our products/services?
      2. Will there be an increase in operational costs, and a change to compensation and/or rewards?
      3. Will this change increase the workload and alter staffing levels?
      4. Will the vision or mission of the team change?
      5. Will a new or different set of skills be needed?
      6. Will the change span multiple locations/time zones?
      7. Are multiple products/services impacted by this change?
      8. Will the workflow and approvals be changed, and will there be a substantial change to scheduling and logistics?
      9. Will the tools of the team be substantially different?
      10. Will there be a change in reporting relationships?

      See our Master Organizational Change Management Practices blueprint for more information.

      Brace for impact

      A thorough analysis of change impacts will help your software delivery teams and change leaders:

      • Bypass avoidable problems.
      • Remove non-fixed barriers to success.
      • Acknowledge and minimize the impact of unavoidable barriers.
      • Identify and leverage potential benefits.
      • Measure the success of the change.

      Many key IT capabilities are required to successfully leverage Gen AI

      Portfolio Management

      An accurate and rationalized inventory of all Gen AI tools verifies they support the goals and abide to the usage policies of the broader delivery practice. This becomes critical when tooling is updated frequently and licenses and open- source community principles drastically change (e.g. after an acquisition).

      Quality Assurance

      Gen AI tools are routinely verified and validated to ensure outcomes are accurate, complete, and aligned to solution delivery quality standards. Models are retrained using lessons learned, new use cases, and updated training data.

      Security & Access Management

      Externally developed and trained Gen AI models may not include the measures, controls, and tactics you need to prevent vulnerabilities and protect against threats that are critical in your security frameworks, policies, and standards.

      Data Management & Governance

      All solution delivery data and artifacts can be transformed and consumed in various ways as they transit through solution delivery and Gen AI tools. Data integrations, structures, and definitions must be well-defined, governed, and monitored.

      OPERATIONAL SUPPORT

      Resources are available to support the ongoing operations of the Gen AI tool, including infrastructure, preparing training data, and managing integration with other tools. They are also prepared to recover backups, roll back, and execute recovery plans at a moment's notice.

      Apply Gen AI good practices in your solution delivery practice

      1. Keep the human in the loop.
        Gen AI models cannot produce high-quality content with 100% confidence. Keeping the human in the loop allows people to directly give feedback to the model to improve output quality.
      2. Strengthen prompt and query engineering.
        The value of the outcome is dependent on what is being asked. Good prompts and queries focus on creating the optimal input by selecting and phrasing the appropriate words, sentence structures, and punctuation to illustrate the focus, scope, problem, and boundaries.
      3. Thoughtfully prepare your training data.
        Externally hosted Gen AI tools may store your training data in their systems or use it to train their other models. Intellectual property and sensitive data can leak into third-party systems and AI models if it is not properly masked and sanitized.
      4. Build guardrails into your Gen AI models.
        Guardrails can limit the variability of any misleading Gen AI responses by defining the scope and bounds of the response, enforcing the policies of its use, and clarifying the context of its response.
      5. Monitor your operational costs.
        The cost breakdown will vary among the types of Gen AI solution and the vendor offerings. Cost per query, consultant fees, infrastructure hosting, and licensing costs are just a few cost factors. Open source can be an attractive cost-saving option, but you must be willing to invest in the roles to assume traditional vendor accountabilities.
      6. Check the licenses of your Gen AI tool.
        Each platform has licenses and agreements on how their solution can or cannot be used. They limit your ability to use the tool for commercial purposes or reproductions or may require you to purchase and maintain a specific license to use their solution and materials.

      See Build Your Generative AI Roadmap for more information.

      Assess your Gen AI readiness

      • Solution delivery team
        The team is educated on Gen AI, its use cases, and the tools that enable it. They have the skills and capacity to implement, create, and manage Gen AI.
      • Solution delivery process and tools
        The solution delivery process is documented, repeatable, and optimized to use Gen AI effectively. Delivery tools are configured to enable, leverage and manage Gen AI assets to improve their performance and efficiency.
      • Solution delivery artifacts
        Delivery artifacts (e.g. code, scripts, documents) that will be used to train and be leveraged by Gen AI tools are discoverable, accurate, complete, standardized, of sufficient quantity, optimized for Gen AI use, and stored in an accessible shared central repository.
      • Governance
        Defined policies, role definitions, guidelines, and processes that guide the implementation, development, operations, and management of Gen AI.
      • Vision and executive support
        Clear alignment of Gen AI direction, ambition, and objectives with broader business and IT priorities. Stakeholders support the Gen AI initiative and allocate human and financial resources for its implementation within the solution delivery team.
      • Operational support
        The capabilities to manage the Gen AI tools and ensure they support the growing needs of the solution delivery practice, such as security management, hosting infrastructure, risk and change management, and data and application integration.

      1.3.1 Assess your readiness for Gen AI

      1-3 hours

      1. Review the current state of your solution delivery teams including their capacity, skills and knowledge, delivery practices, and tools and technologies.
      2. Determine the readiness of your team to adopt Gen AI.
      3. Discuss the gaps that need to be filled to be successful with Gen AI.
      4. Record this information in the Gen AI Solution Delivery Readiness Assessment Tool.

      Record the results in the Gen AI Solution Delivery Readiness Assessment Tool

      Output

      • Gen AI Solution Delivery Readiness Assessment

      Participants

      • Applications VP
      • Applications Director
      • Solution Delivery Manager
      • Solution Delivery Team

      Recognize that Gen AI does not require a fully optimized solution delivery process

      1. Consideration; 2. Exploration; 3. Incorporation; 4. Proliferation; 5. Optimization.  Steps 3-5 are Recommended maturity levels to properly embrace Gen AI.

      To learn more, visit Info-Tech's Develop Your Value-First Business Process Automation (BPA) Strategy.

      Be prepared to take the next steps

      Deliver Gen AI to your solution delivery teams

      Modernize Your SDLC
      Efficient and effective SDLC practices are vital, as products need to readily adjust to evolving and changing business needs and technologies.

      Adopt Generative AI in Solution Delivery
      Generative AI can drive productivity and solution quality gains to your solution delivery teams. Level set expectations with the right use case to demonstrate its value potential.

      Select Your AI Vendor & Implementation Partner
      The right vendor and partner are critical for success. Build the selection criteria to shortlist the products and services that best meets the current and future needs of your teams.

      Drive Business Value With Off-the-Shelf AI
      Build a framework that will guide your teams through the selection of an off-the-shelf AI tool with a clear definition of the business case and preparations for successful adoption.

      Build Your Enterprise Application Implementation Playbook
      Your Gen AI implementation doesn't start with technology, but with an effective plan that your team supports and is aligned to broader stakeholder and sponsor priorities and goals.

      Build your Gen AI practice

      • Get Started With AI
      • AI Strategy & Generative AI Roadmap
      • AI Governance

      Related Info-Tech Research

      Build a Winning Business Process Automation Playbook
      Optimize and automate your business processes with a user-centric approach.

      Embrace Business Managed Applications
      Empower the business to implement their own applications with a trusted business-IT relationship.

      Application Portfolio Management Foundations
      Ensure your application portfolio delivers the best possible return on investment.

      Maximize the Benefits from Enterprise Applications with a Center of Excellence
      Optimize your organization's enterprise application capabilities with a refined and scalable methodology.

      Create an Architecture for AI
      Build your target state architecture from predefined best-practice building blocks.

      Deliver on Your Digital Product Vision
      Build a product vision your organization can take from strategy through execution.

      Enhance Your Solution Architecture Practices
      Ensure your software systems solution is architected to reflect stakeholders' short- and long-term needs.

      Apply Design Thinking to Build Empathy With the Business
      Use design thinking and journey mapping to make IT the business' go-to problem solver.

      Modernize Your SDLC
      Deliver quality software faster with new tools and practices.

      Drive Business Value With Off-the-Shelf AI
      A practical guide to ensure return on your off-the-shelf AI investment.

      Bibliography

      "Altran Helps Developers Write Better Code Faster with Azure AI." Microsoft, 2020.
      "Apply Design Thinking to Complex Teams, Problems, and Organizations." IBM, 2021.
      Bianca. "Unleashing the Power of AI in Code Generation: 10 Applications You Need to Know — AITechTrend." AITechTrend, 16 May 2023.
      Biggs, John. "Deep Code Cleans Your Code with the Power of AI." TechCrunch, 26 Apr 2018.
      "Chat GPT as a Tool for Business Analysis — the Brazilian BA." The Brazilian BA, 24 Jan 2023.
      Davenport, Thomas, and Randy Bean. "Big Data and AI Executive Survey 2019." New Vantage Partners, 2019.
      Davenport, Thomas, and Randy Bean. "Big Data and AI Executive Survey 2021." New Vantage Partners, 2021.
      Das, Tamal. "9 Best AI-Powered Code Completion for Productive Development." Geek flare, 5 Apr 2023.
      Gondrezick, Ilya. "Council Post: How AI Can Transform the Software Engineering Process." Forbes, 24 Apr 2020.
      "Generative AI Speeds up Software Development: Compass UOL Study." PR Newswire, 29 Mar 2023.
      "GitLab 2023 Global Develops Report Series." Gitlab, 2023.
      "Game Changer: The Startling Power Generative AI Is Bringing to Software Development." KPMG, 30 Jan 2023.
      "How AI Can Help with Requirements Analysis Tools." TechTarget, 28 July 2020.
      Indra lingam, Ashanta. "How Spotify Is Upleveling Their Entire Design Team." Framer, 2019.
      Ingle, Prathamesh. "Top Artificial Intelligence (AI) Tools That Can Generate Code to Help Programmers." Matchcoat, 1 Jan 2023.
      Kaur, Jagreet . "AI in Requirements Management | Benefits and Its Processes." Xenon Stack, 13 June 2023.
      Lange, Danny. "Game On: How Unity Is Extending the Power of Synthetic Data beyond the Gaming Industry." CIO, 17 Dec 2020.
      Lin, Ying. "10 Artificial Intelligence Statistics You Need to Know in 2020." OBERLO, 17 Mar. 2023.
      Mauran, Cecily. "Whoops, Samsung Workers Accidentally Leaked Trade Secrets via ChatGPT." Mashable, 6 Apr 2023.

      2020 CIO Priorities Report

      • Buy Link or Shortcode: {j2store}97|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Innovation
      • Parent Category Link: /innovation
      • The velocity and magnitude of technology changes today has increased dramatically compared to anything that has come before.
      • The velocity and magnitude of advancements in technology has always seemed unprecedented in every wave of technology change we have experienced over the past 40 years. With each new wave of innovation, “unprecedented” is redefined to a new level, and so it remains true that today’s CIO is faced with unprecedented levels of change as a direct result of emerging technologies.
      • What is different today is that we are at the point where the emerging technology itself is now capable of accelerating the pace of change even more through artificial intelligence capabilities.
      • If we are to realize the business value through the adoption of emerging technologies, CIOs must address significant challenges. We believe addressing these challenges lies in the CIO priorities for 2020.

      Our Advice

      Critical Insight

      • First there was IT/business alignment, then there was IT/business integration – both states characterized as IT “getting on the same page” as the business. In the context of emerging technologies, the CIO should no longer be focused on getting on the same page as the CEO.
      • Today it is about the CEO and the CIO collaborating to write a new book about convergence of all things: technology (infrastructure and applications), people (including vendors), process, and data.
      • Digital transformation and adoption of emerging technologies is not a goal, it is a journey – a means to the end, not the end unto itself.

      Impact and Result

      • Use Info-Tech's 2020 CIO Priorities Report to ascertain, based on our research, what areas of focus for 2020 are critical for success in adopting emerging technologies.
      • Adopting these technologies requires careful planning and consideration for what is critical to your business customers.
      • This report provides focus on the business benefits of the technology and not just the capabilities themselves. It puts the CIO in a position to better understand the true value proposition of any of today’s technology advancements.

      2020 CIO Priorities Report Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to understand the top five priorities for CIOs in 2020 and why these are so critical to success.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Refine and adapt processes

      Learn about how processes can make or break your adoption of emerging technologies.

      • 2020 CIO Priorities Report – Priority 1: Refine and Adapt Processes

      2. Re-invent IT as collaboration engine

      Learn about how IT can transform its role within the organization to optimize business value.

      • 2020 CIO Priorities Report – Priority 2: Re-Invent IT as Collaboration Engine

      3. Acquire and retain talent for roles in emerging technologies

      Learn about how IT can attract and keep employees with the skills and knowledge needed to adopt these technologies for the business.

      • 2020 CIO Priorities Report – Priority 3: Acquire and Retain Talent for Roles in Emerging Technologies

      4. Define and manage cybersecurity and cyber resilience requirements related to emerging technologies

      Understand how the adoption of emerging technologies has created new levels of risk and how cybersecurity and resilience can keep pace.

      • 2020 CIO Priorities Report – Priority 4: Define and Manage Cybersecurity and Cyber Resilience Requirements Related to Emerging Technologies

      5. Leverage emerging technology to create Wow! customer experiences

      Learn how IT can leverage emerging technology for its own customers and those of its business partners.

      • 2020 CIO Priorities Report – Priority 5: Leverage Emerging Technology to Create Wow! Customer Experiences
      [infographic]

      Measure and Manage Customer Satisfaction Metrics That Matter the Most

      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Marketing Solutions
      • Parent Category Link: /marketing-solutions
      • Lack of understanding of what is truly driving customer satisfaction or dissatisfaction.
      • Lack of insight into who our satisfied and dissatisfied customers are.
      • Lack of a system for early detection of declines in satisfaction.
      • Lack of clarity on what to improve and how resources should be allocated.

      Our Advice

      Critical Insight

      • All software companies measure satisfaction in some way, but many lack understanding of what’s truly driving customers to stay or leave. By understanding the true drivers of satisfaction, solution providers can measure and monitor satisfaction more effectively, pull actionable insights and feedback, and make changes to products and services that customers really care about and will keep them coming back to you to have their needs met.
      • Obstacles:
        • Use of metrics that don’t provide the insight needed to make impactful changes that will boost satisfaction and ultimately, retention and profit.
        • Lack of a clear definition of what satisfaction means to customers, metric definitions and/or standard methods of measurement, and a consistent monitoring cadence.

      Impact and Result

      • Understanding of who your satisfied and dissatisfied customers are.
      • Understanding of the true drivers of satisfaction and dissatisfaction among your customer segments.
      • Establishment of a repeatable process and cadence for effective satisfaction measurement and monitoring.
      • Development of an executable customer satisfaction improvement plan that identifies customer journey pain points and areas of dissatisfaction, and outlines how to improve them.
      • Knowledge of where money, time, and other resources are needed most to improve satisfaction levels and ultimately increase retention.

      Measure and Manage Customer Satisfaction Metrics That Matter the Most Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Measure and Manage the Customer Satisfaction Metrics that Matter the Most Deck – An overview of how to understand what drives customer satisfaction and how to measure and manage it for improved business outcomes.

      Understand the true drivers of customer satisfaction and build a process for managing and improving customer satisfaction.

      [infographic]

      Further reading

      Measure and Manage the Customer Satisfaction Metrics that Matter the Most

      Understand what truly keeps your customer satisfied. Start to measure what matters to improve customer experience and increase satisfaction and advocacy. 

      EXECUTIVE BRIEF

      Analyst perspective

      Understanding and measuring the true drivers of satisfaction enable the delivery of real customer value

      The image contains a picture of Emily Wright.

      “Healthy customer relationships are the paramount to long-term growth. When customers are satisfied, they remain loyal, spend more, and promote your company to others in their network. The key to high satisfaction is understanding and measuring the true drivers of satisfaction to enable the delivery of real customer value.

      Most companies believe they know who their satisfied customers are and what keeps them satisfied, and 76% of B2B buyers expect that providers understand their unique needs (Salesforce Research, 2020). However, on average B2B companies have customer experience scores of less than 50% (McKinsey, 2016). This disconnect between customer expectations and provider experience indicates that businesses are not effectively measuring and monitoring satisfaction and therefore are not making meaningful enhancements to their service, offerings, and overall experience.

      By focusing on the underlying drivers of customer satisfaction, organizations develop a truly accurate picture of what is driving deep satisfaction and loyalty, ensuring that their company will achieve sustainable growth and stay competitive in a highly competitive market.”

      Emily Wright

      Senior Research Analyst, Advisory

      SoftwareReviews

      Executive summary

      Your Challenge

      Common Obstacles

      SoftwareReviews’ Approach

      Getting a truly accurate picture of satisfaction levels among customers, and where to focus efforts to improve satisfaction, is challenging. Providers often find themselves reacting to customer challenges and being blindsided when customers leave. More effective customer satisfaction measurement is possible when providers self-assess for the following challenges:

      • Lack of understanding of what is truly driving customer satisfaction or dissatisfaction.
      • Lack of insight into who our satisfied and dissatisfied customers are.
      • Lack of a system for early detection of declines in satisfaction.
      • Lack of clarity of what needs to be improved and how resources should be allocated.
      • Lack of reliable internal data for effective customer satisfaction monitoring.

      What separates customer success leaders from developing a full view of their customers are several nagging obstacles:

      • Use of metrics that don’t provide the insight needed to make impactful changes that will boost satisfaction and ultimately, retention and profit.
      • Friction from customers participating in customer satisfaction studies.
      • Lack of data, or integrated databases from which to track, pull, and analyze customer satisfaction data.
      • Lack a clear definition of what satisfaction means to customers, metric definitions, and/or standard methods of measurement and a consistent monitoring cadence.
      • Lack of time, resources, or technology to uncover and effectively measure and monitor satisfaction drivers.

      Through the SoftwareReviews’ approach, customer success leaders will:

      • Understand who your satisfied and dissatisfied customers are.
      • Understand the true drivers of satisfaction and dissatisfaction among your customer segments.
      • Establish a repeatable process and cadence for effective satisfaction measurement and monitoring.
      • Develop an executable customer satisfaction improvement plan that identifies customer journey pain points and areas of dissatisfaction, and outlines how to improve them.
      • Know where money, time, and resources are needed most to improve satisfaction levels and ultimately retention.

      Overarching SoftwareReviews Advisory Insight:

      All companies measure satisfaction in some way, but many lack understanding of what’s truly driving customers to stay or leave. By understanding the true drivers of satisfaction, solution providers can measure and monitor satisfaction more effectively, pull actionable insights and feedback, and make changes to products and services that customers really care about. This will keep them coming back to you to have their needs met.

      Healthy Customer Relationships are vital for long-term success and growth

      Measuring customer satisfaction is critical to understanding the overall health of your customer relationships and driving growth.

      Through effective customer satisfaction measurement, organizations can:

      Improve Customer Experience

      Increase Retention and CLV

      Increase Profitability

      Reduce Costs

      • Provide insight into where and how to improve.
      • Enhance experience, increase loyalty.
      • By providing strong CX, organizations can increase revenue by 10-15% (McKinsey, 2014).
      • Far easier to retain existing customers than to acquire new ones.
      • Ensuring high satisfaction among customers increases Customer Lifetime Value (CLV) through longer tenure and higher spending.
      • NPS Promoter score has a customer lifetime value that's 600%-1,400% higher than a Detractor (Bain & Company, 2015).
      • Highly satisfied customers spend more through expansions and add-ons, as well as through their long tenure with your company.
      • They also spread positive word of mouth, which brings in new customers.
      • “Studies demonstrate a strong correlation between customer satisfaction and increased profits — with companies with high customer satisfaction reporting 5.7 times more revenue than competitors.” (Matthew Loper, CEO and Co-Founder of WELLTH, 2022)
      • Measuring, monitoring, and maintaining high satisfaction levels reduces costs across the board.
      • “Providing a high-quality customer experience can save up to 33% of customer service costs” (Deloitte, 2018).
      • Satisfied customers are more likely to spread positive word of mouth which reduces acquisition / marketing costs for your company.

      “Measuring customer satisfaction is vital for growth in any organization; it provides insights into what works and offers opportunities for optimization. Customer satisfaction is essential for improving loyalty rate, reducing costs and retaining your customers.”

      -Ken Brisco, NICE, 2019

      Poor customer satisfaction measurement is costly

      Virtually all companies measure customer satisfaction, but few truly do it well. All too often, customer satisfaction measurement consists of a set of vanity metrics that do not result in actionable insight for product/service improvement. Improper measurement can result in numerous consequences:

      Direct and Indirect Costs

      Being unaware of true drivers of satisfaction that are never remedied costs your business directly through customer churn, service costs, etc.

      Tarnished Brand

      Tarnished brand through not resolving issues drives dissatisfaction; dissatisfied customers share their negative experiences, which can damage brand image and reputation.

      Waste Limited Resources

      Putting limited resources towards vanity programs and/or fixes that have little to no bearing on core satisfaction drivers wastes time and money.

      “When customer dissatisfaction goes unnoticed, it can slowly kill a company. Because of the intangible nature of customer dissatisfaction, managers regularly underestimate the magnitude of customer dissatisfaction and its impact on the bottom line.”

      - Lakshmiu Tatikonda, “The Hidden Costs of Customer Dissatisfaction”, 2013

      SoftwareReviews Advisory Insight:

      Most companies struggle to understand what’s truly driving customers to stay or leave. By understanding the true satisfaction drivers, tech providers can measure and monitor satisfaction more effectively, avoiding the numerous harmful consequences that result from average customer satisfaction measurement.

      Does your customer satisfaction measurement process need improvement?

      Getting an accurate picture of customer satisfaction is no easy task. Struggling with any of the following means you are ready for a detailed review of your customer satisfaction measurement efforts:

      • Not knowing who your most satisfied customers are.
      • Lacking early detection for declining satisfaction – either reactive, or unaware of dissatisfaction as it’s occurring.
      • Lacking a process for monitoring changes in satisfaction and lack ability to be proactive; you feel blindsided when customers leave.
      • Inability to fix the problem and wasting money on the wrong areas, like vanity metrics that don’t bring value to customers.
      • Spending money and other resources towards fixes based on a gut feeling, without quantifying the real root cause drivers and investing in their improvement.
      • Having metrics and data but lacking context; don’t know what contributed to the metrics/results, why people are dissatisfied or what contributes to satisfaction.
      • Lacking clear definition of what satisfaction means to customers / customer segments.
      • Difficulty tying satisfaction back to financial results.

      Customers are more satisfied with software vendors who understand the difference between surface level and short-term satisfaction, and deep or long-term satisfaction

      Surface-level satisfaction

      Surface-level satisfaction has immediate effects, but they are usually short-term or limited to certain groups of users. There are several factors that contribute to satisfaction including:

      • Novelty of new software
      • Ease of implementation
      • Financial savings
      • Breadth of features

      Software Leaders Drive Deep Satisfaction

      Deep satisfaction has long-term and meaningful impacts on the way that organizations work. Deep satisfaction has staying power and increases or maintains satisfaction over time, by reducing complexity and delivering exceptional quality for end-users and IT alike. This report found that the following capabilities provided the deepest levels of satisfaction:

      • Usability and intuitiveness
      • Quality of features
      • Ease of customization
      • Vendor-specific capabilities

      The above solve issues that are part of everyday problems, and each drives satisfaction in deep and meaningful ways. While surface-level satisfaction is important, deep and impactful capabilities can sustain satisfaction for a longer time.

      Deep Customer Satisfaction Among Software Buyers Correlates Highly to “Emotional Attributes”

      Vendor Capabilities and Product Features remain significant but are not the primary drivers

      The image contains a graph to demonstrate a correlation to Satisfaction, all Software Categories.
      Source: SoftwareReviews buyer reviews (based on 82,560 unique reviews).

      Driving deep satisfaction among software customers vs. surface-level measures is key

      Vendor capabilities and product features correlate significantly to buyer satisfaction

      Yet, it’s the emotional attributes – what we call the “Emotional Footprint”, that correlate more strongly

      Business-Value Created and Emotional Attributes are what drives software customer satisfaction the most

      The image contains a screenshot of a graph to demonstrate Software Buyer Satisfaction Drivers and Emotional Attributes are what drives software customer satisfaction.

      Software companies looking to improve customer satisfaction will focus on business value created and the Emotional Footprint attributes outlined here.

      The essential ingredient is understanding how each is defined by your customers.

      Leaders focus on driving improvements as described by customers.

      SoftwareReviews Insight:

      These true drivers of satisfaction should be considered in your customer satisfaction measurement and monitoring efforts. The experience customers have with your product and brand is what will differentiate your brand from competitors, and ultimately, power business growth. Talk to a SoftwareReviews Advisor to learn how users rate your product on these satisfaction drivers in the SoftwareReviews Emotional Footprint Report.

      Benefits of Effective Customer Satisfaction Measurement

      Our research provides Customer Success leaders with the following key benefits:

      • Ability to know who is satisfied, dissatisfied, and why.
      • Confidence in how to understand or uncover the factors behind customer satisfaction; understand and identify factors driving satisfaction, dissatisfaction.
      • Ability to develop a clear plan for improving customer satisfaction.
      • Knowledge of how to establish a repeatable process for customer satisfaction measurement and monitoring that allows for proactivity when declines in satisfaction are detected.
      • Understanding of what metrics to use, how to measure them, and where to find the right information/data.
      • Knowledge of where money, time, and other resources are needed most to drive tangible customer value.

      “81% of organizations cite CX as a competitive differentiator. The top factor driving digital transformation is improving CX […] with companies reporting benefits associated with improving CX including:

      • Increased customer loyalty (92%)
      • An uplift in revenue (84%)
      • Cost savings (79%).”

      – Dan Cote, “Advocacy Blooms and Business Booms When Customers and Employees Engage”, Influitive, 2021

      The image contains a screenshot of a thought model that focuses on Measure & Manage the Customer Satisfaction Metrics That Matter the Most.

      Who benefits from improving the measurement and monitoring of customer satisfaction?

      This Research Is Designed for:

      • Customer Success leaders and marketers who are:
        • Responsible for understanding how to benchmark, measure, and understand customer satisfaction to improve satisfaction, NPS, and ROI.
        • Looking to take a more proactive and structured approach to customer satisfaction measurement and monitoring.
        • Looking for a more effective and accurate way to measure and understand how to improve customer satisfaction around products and services.

      This Research Will Help You:

      • Understand the factors driving satisfaction and dissatisfaction.
      • Know which customers are satisfied/dissatisfied.
      • Know where time, money, and resources are needed the most in order to improve or maintain satisfaction levels.
      • Develop a formal plan to improve customer satisfaction.
      • Establish a repeatable process for customer satisfaction measurement and monitoring that allows for proactivity when declines in satisfaction are detected.

      This Research Will Also Assist:

      • Customer Success Leaders, Marketing and Sales Directors and Managers, Product Marketing Managers, and Advocacy Managers/Coordinators who are responsible for:
        • Product improvements and enhancements
        • Customer service and onboarding
        • Customer advocacy programs
        • Referral/VoC programs

      This Research Will Help Them:

      • Coordinate and align on customer experience efforts and actions.
      • Gather and make use of customer feedback to improve products, solutions, and services provided.
      • Provide an amazing customer experience throughout the entirety of the customer journey.

      SoftwareReviews’ methodology for measuring the customer satisfaction metrics that matter the most

      1. Identify true customer satisfaction drivers

      2. Develop metrics dashboard

      3. Develop customer satisfaction measurement and management plan

      Phase Steps

      1. Identify data sources, documenting any gaps in data
      2. Analyze all relevant data on customer experiences and outcomes
      3. Document top satisfaction drivers
      1. Identify business goals, problems to be solved / define business challenges and marketing/customer success goals
      2. Use SR diagnostic to assess current state of satisfaction measurement, assessing metric alignment to satisfaction drivers
      3. Define your metrics dashboard
      4. Develop common metric definitions, language for discussing, and standards for measuring customer satisfaction
      1. Determine committee structure to measure performance metrics over time
      2. Map out gaps in satisfaction along customer journey/common points in journey where customers are least dissatisfied
      3. Build plan that identifies weak areas and shows how to fix using SR’s emotional footprint, other measures
      4. Create plan and roadmap for CSat improvement
      5. Create communication deck

      Phase Outcomes

      1. Documented satisfaction drivers
      2. Documented data sources and gaps in data
      1. Current state customer satisfaction measurement analysis
      2. Common metric definitions and measurement standards
      3. Metrics dashboard
      1. Customer satisfaction measurement plan
      2. Customer satisfaction improvement plan
      3. Customer journey maps
      4. Customer satisfaction improvement communication deck
      5. Customer Satisfaction Committee created

      Insight summary

      Understanding and measuring the true drivers of satisfaction enable the delivery of real customer value

      All software companies measure satisfaction in some way, but many lack understanding of what’s truly driving customers to stay or leave. By understanding the true drivers of satisfaction, solution providers can measure and monitor satisfaction more effectively, pull actionable insights and feedback, and make changes to products and services that customers really care about and which will keep them coming back to you to have their needs met.

      Positive experiences drive satisfaction more so than features and cost

      According to our analysis of software buyer reviews data*, the biggest drivers of satisfaction and likeliness to recommend are the positive experiences customers have with vendors and their products. Customers want to feel that:

      1. Their productivity and performance is enhanced, and the vendor is helping them innovate and grow as a company.
      2. Their vendor inspires them and helps them to continually improve.
      3. They can rely on the vendor and the product they purchased.
      4. They are respected by the vendor.
      5. They can trust that the vendor will be on their side and save them time.
      *8 million data points across all software categories

      Measure Key Relationship KPIs to gauge satisfaction

      Key metrics to track include the Business Value Created score, Net Emotional Footprint, and the Love/Hate score (the strength of emotional connection).

      Orient the organization around customer experience excellence

      1. Arrange staff incentives around customer value instead of metrics that are unrelated to satisfaction.
      2. Embed customer experience as a core company value and integrate it into all functions.
      3. Make working with your organization easy and seamless for customers.

      Have a designated committee for customer satisfaction measurement

      Best in class organizations create customer satisfaction committees that meet regularly to measure and monitor customer satisfaction, resolve issues quickly, and work towards improved customer experience and profit outcomes.

      Use metrics that align to top satisfaction drivers

      This will give you a more accurate and fulsome view of customer satisfaction than standard satisfaction metrics alone will.

      Guided Implementation

      What is our GI on measuring and managing the customer satisfaction metrics that matter most?

      Identify True Customer Satisfaction Drivers

      Develop Metrics Dashboard Develop Customer Satisfaction Measurement and Management Plan

      Call #1: Discuss current pain points and barriers to successful customer satisfaction measurement, monitoring and maintenance. Plan next call – 1 week.

      Call #2: Discuss all available data, noting any gaps. Develop plan to fill gaps, discuss feasibility and timelines. Plan next call – 1 week.

      Call #3: Walk through SoftwareReviews reports to understand EF and satisfaction drivers. Plan next call – 3 days.

      Call #4: Segment customers and document key satisfaction drivers. Plan next call – 2 week.

      Call #5: Document business goals and align them to metrics. Plan next call – 1 week.

      Call #6: Complete the SoftwareReviews satisfaction measurement diagnostic. Plan next call – 3 days.

      Call #7: Score list of metrics that align to satisfaction drivers. Plan next call – 2 days.

      Call #8: Develop metrics dashboard and definitions. Plan next call – 2 weeks.

      Call #9: Finalize metrics dashboard and definitions. Plan next call – 1 week.

      Call #10: Discuss committee and determine governance. Plan next call – 2 weeks.

      Call #11: Map out gaps in satisfaction along customer journey as they relate to top satisfaction drivers. Plan next call –2 weeks.

      Call #12: Develop plan and roadmap for satisfaction improvement. Plan next call – 1 week.

      Call #13: Finalize plan and roadmap. Plan next call – 1 week.

      Call # 14: Review and coach on communication deck.

      A Guided Implementation (GI) is series of calls with a SoftwareReviews Advisory analyst to help implement our best practices in your organization.

      For guidance on marketing applications, we can arrange a discussion with an Info-Tech analyst.

      Your engagement managers will work with you to schedule analyst calls.

      Software Reviews offers various levels of support to best suit your needs

      DIY Toolkit

      Guided Implementation

      Workshop

      Consulting

      “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.” “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.” “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.” “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”
      Included within Advisory Membership Optional add-ons

      Bibliography

      “Are you experienced?” Bain & Company, Apr. 2015. Accessed 6 June. 2022.

      Brisco, Ken. “Measuring Customer Satisfaction and Why It’s So Important.” NICE, Feb. 2019. Accessed 6 June. 2022.

      CMO.com Team. “The Customer Experience Management Mandate.” Adobe Experience Cloud Blog, July 2019. Accessed 14 June. 2022.

      Cote, Dan. “Advocacy Blooms and Business Booms When Customers and Employees Engage.” Influitive, Dec. 2021. Accessed 15 June. 2022.

      Fanderl, Harald and Perrey, Jesko. “Best of both worlds: Customer experience for more revenues and lower costs.” McKinsey & Company, Apr. 2014. Accessed 15 June. 2022.

      Gallemard, Jeremy. “Why – And How – Should Customer Satisfaction Be Measured?” Smart Tribune, Feb. 2020. Accessed 6 June. 2022.

      Kumar, Swagata. “Customer Success Statistics in 2021.” Customer Success Box, 2021. Accessed 17 June. 2022.

      Lakshmiu Tatikonda, “The Hidden Costs of Customer Dissatisfaction”, Management Accounting Quarterly, vol. 14, no. 3, 2013, pp 38. Accessed 17 June. 2022.

      Loper, Matthew. “Why ‘Customer Satisfaction’ Misses the Mark – And What to Measure Instead.” Newsweek, Jan. 2022. Accessed 16 June. 2022.

      Maechler, Nicolas, et al. “Improving the business-to-business customer experience.” McKinsey & Company, Mar. 2016. Accessed 16 June.

      “New Research from Dimension Data Reveals Uncomfortable CX Truths.” CISION PR Newswire, Apr. 2017. Accessed 7 June. 2022.

      Sheth, Rohan. 75 Must-Know Customer Experience Statistics to move Your Business Forward in 2022.” SmartKarrot, Feb. 2022. Accessed 17 June. 2022.

      Smith, Mercer. “111 Customer Service Statistics and Facts You Shouldn’t Ignore.” HelpScout, May 2022. Accessed 17 June. 2022.

      “State of the Connected Customer.” Salesforce, 2020. Accessed 14 June. 2022

      “The true value of customer experiences.” Deloitte, 2018. Accessed 15 June. 2022.

      Explore the Secrets of Workday Licensing

      • Buy Link or Shortcode: {j2store}144|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Licensing
      • Parent Category Link: /licensing
      • Organizations examining a move to Workday or renewing a contract struggle to gain information and leverage in the negotiation process on commercial components such as pricing transparency, contractual flexibility, terms, and license use rights.
      • Implementations and customization can become difficult if adequate planning steps and communication are not taken beforehand.
      • The FSE Worker Calculation formula is used in the pricing process and can be negotiable.
      • Information and training documentation must be searched in online handbooks, making it difficult to find and time consuming
      • Workday’s partner ecosystem, while closely managed, isn’t flowing with resources. Finding the right partner, at the right cost to support an implementation can be challenging.

      Our Advice

      Critical Insight

      1. Know which defined areas of the agreement can be negotiated and which can't.
      2. Workday closely manages the Partner ecosystem and requests feedback on how to better support and implement its technologies. However, resource availability and talent management can be difficult as not many have the necessary skills.
      3. Recognize and accept that you’ve chosen the premium priced product in the market, so be prepared to pay up for best-in-class capabilities on a cloud-native ERP platform.

      Impact and Result

      • Focus on needs first. Conduct a thorough needs assessment and document the results. Well-documented worker counts by category and licenses required will be your best asset in navigating Workday licensing and negotiating your agreement.
      • Ensure the chosen implementation partner isn’t simply an integrator but provides consultative help and service.
      • Leverage executive relationships, downstream increased spending opportunities, and effective communication to drive and manage the relationship and attain necessary information to make effective decisions.

      Explore the Secrets of Workday Licensing Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should explore the secrets of Workday licensing, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Understand Workday

      Understand Workday’s business model, competitive options, and what to know when conducting due diligence and requirements gathering.

      • Explore the Secrets of Workday Licensing – Phase 1: Understand Workday

      2. Understand licensing, negotiate commercial terms, and purchase

      Review product options and licensing rules. Determine negotiation points. Evaluate and finalize the contract.

      • Explore the Secrets of Workday Licensing – Phase 2: Understand Licensing, Negotiate Commercial Terms, and Purchase
      • Workday Terms and Conditions Evaluation Tool
      [infographic]

      Craft a Customer-Driven Market Strategy With Unbiased Data

      • Buy Link or Shortcode: {j2store}611|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Selection & Implementation
      • Parent Category Link: /selection-and-implementation
      • Market strategies are informed by gut feel and endless brainstorming instead of market data to take their product from concept to customer.
      • Hiring independent market research firms results in a lack of unbiased third-party data. Research firms tell vendors what they want to hear instead of offering an agnostic view of software trends.
      • Dissatisfied customers don’t tell you directly why they are leaving, so there is no feedback loop back into product improvements.
      • Often a market strategy is built after a product is developed to force the product’s fit in the market. The product marketing team has no say in the product vision or future improvements.

      Our Advice

      Critical Insight

      • Adopt the 5 P’s to building a winning market strategy: Proposition, Product, Pricing, Placement, and Promotion.
      • You can’t be everything to everyone. Testing your proposition in the market to see what sticks is a risky move. Promise future value using past successes by gaining a deeper understanding of which customers and submarkets truly align to your product.
      • Customers have learned to avoid shiny new objects but still expect rapid feature releases. Differentiating features require a closer look at the underpinning vendor capabilities. Having intentional feature releases requires a feedback loop into the product roadmap and increases influence by the product marketing team.
      • Price transparency and sensitivity should drive what you offer to customers. Negotiating solely on price is a race to the bottom.

      Impact and Result

      • Leverage this report to gain insights on the software selection process and what top vendors do best.
      • Gain a bird’s-eye view on customer purchasing behavior using over 40,000 data points on satisfaction and importance collected directly from the source.
      • Build a winning market strategy influenced by real customer data that drives vendor success.

      Craft a Customer-Driven Market Strategy With Unbiased Data Research & Tools

      Read the storyboard

      Read our storyboard to find out why you should leverage SoftwareReviews data to craft your market strategy, review Info-Tech’s methodology, and understand unbiased customer data on software purchasing triggers.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      • Craft a Customer-Driven Market Strategy With Unbiased Data Storyboard
      [infographic]

      Mergers & Acquisitions: The Sell Blueprint

      • Buy Link or Shortcode: {j2store}324|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: IT Strategy
      • Parent Category Link: /it-strategy

      There are four key scenarios or entry points for IT as the selling/divesting organization in M&As:

      • IT can suggest a divestiture to meet the business objectives of the organization.
      • IT is brought in to strategy plan the sale/divestiture from both the business’ and IT’s perspectives.
      • IT participates in due diligence activities and complies with the purchasing organization’s asks.
      • IT needs to reactively prepare its environment to enable the separation.

      Consider the ideal scenario for your IT organization.

      Our Advice

      Critical Insight

      Divestitures are inevitable in modern business, and IT’s involvement in the process should be too. This progression is inspired by:

      • The growing trend for organizations to increase, decrease, or evolve through these types of transactions.
      • A maturing business perspective of IT, preventing the difficulty that IT is faced with when invited into the transaction process late.
      • Transactions that are driven by digital motivations, requiring IT’s expertise.
      • There never being such a thing as a true merger, making the majority of M&A activity either acquisitions or divestitures.

      Impact and Result

      Prepare for a sale/divestiture transaction by:

      • Recognizing the trend for organizations to engage in M&A activity and the increased likelihood that, as an IT leader, you will be involved in a transaction in your career.
      • Creating a standard strategy that will enable strong program management.
      • Properly considering all the critical components of the transaction and integration by prioritizing tasks that will reduce risk, deliver value, and meet stakeholder expectations.

      Mergers & Acquisitions: The Sell Blueprint Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out how your organization can excel its reduction strategy by engaging in M&A transactions. Review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Proactive Phase

      Be an innovative IT leader by suggesting how and why the business should engage in an acquisition or divestiture.

      • One-Pager: M&A Proactive
      • Case Study: M&A Proactive
      • Information Asset Audit Tool
      • Data Valuation Tool
      • Enterprise Integration Process Mapping Tool
      • Risk Register Tool
      • Security M&A Due Diligence Tool
      • Service Catalog Internal Service Level Agreement Template

      2. Discovery & Strategy

      Create a standardized approach for how your IT organization should address divestitures or sales.

      • One-Pager: M&A Discovery & Strategy – Sell
      • Case Study: M&A Discovery & Strategy – Sell

      3. Due Diligence & Preparation

      Comply with due diligence, prepare the IT environment for carve-out possibilities, and establish the separation project plan.

      • One-Pager: M&A Due Diligence & Preparation – Sell
      • Case Study: M&A Due Diligence & Preparation – Sell
      • IT Due Diligence Charter
      • IT Culture Diagnostic
      • M&A Separation Project Management Tool (SharePoint)
      • SharePoint Template: Step-by-Step Deployment Guide
      • M&A Separation Project Management Tool (Excel)

      4. Execution & Value Realization

      Deliver on the separation project plan successfully and communicate IT’s transaction value to the business.

      • One-Pager: M&A Execution & Value Realization – Sell
      • Case Study: M&A Execution & Value Realization – Sell

      Infographic

      Workshop: Mergers & Acquisitions: The Sell Blueprint

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Pre-Transaction Discovery & Strategy

      The Purpose

      Establish the transaction foundation.

      Discover the motivation for divesting or selling.

      Formalize the program plan.

      Create the valuation framework.

      Strategize the transaction and finalize the M&A strategy and approach.

      Key Benefits Achieved

      All major stakeholders are on the same page.

      Set up crucial elements to facilitate the success of the transaction.

      Have a repeatable transaction strategy that can be reused for multiple organizations.

      Activities

      1.1 Conduct the CIO Business Vision and CEO-CIO Alignment diagnostics.

      1.2 Identify key stakeholders and outline their relationship to the M&A process.

      1.3 Understand the rationale for the company's decision to pursue a divestiture or sale.

      1.4 Assess the IT/digital strategy.

      1.5 Identify pain points and opportunities tied to the divestiture/sale.

      1.6 Create the IT vision statement and mission statement and identify IT guiding principles and the transition team.

      1.7 Document the M&A governance.

      1.8 Establish program metrics.

      1.9 Create the valuation framework.

      1.10 Establish the separation strategy.

      1.11 Conduct a RACI.

      1.12 Create the communication plan.

      1.13 Prepare to assess target organizations.

      Outputs

      Business perspectives of IT

      Stakeholder network map for M&A transactions

      Business context implications for IT

      IT’s divestiture/sale strategic direction

      Governance structure

      M&A program metrics

      IT valuation framework

      Separation strategy

      RACI

      Communication plan

      Prepared to assess target organization(s)

      2 Mid-Transaction Due Diligence & Preparation

      The Purpose

      Establish the foundation.

      Discover the motivation for separation.

      Identify expectations and create the carve-out roadmap.

      Prepare and manage employees.

      Plan the separation roadmap.

      Key Benefits Achieved

      All major stakeholders are on the same page.

      Methodology identified to enable compliance during due diligence.

      Employees are set up for a smooth and successful transition.

      Separation activities are planned and assigned.

      Activities

      2.1 Gather and evaluate the stakeholders involved, M&A strategy, future-state operating model, and governance.

      2.2 Review the business rationale for the divestiture/sale.

      2.3 Establish the separation strategy.

      2.4 Create the due diligence charter.

      2.5 Create a list of IT artifacts to be reviewed in the data room.

      2.6 Create a carve-out roadmap.

      2.7 Create a service/technical transaction agreement.

      2.8 Measure staff engagement.

      2.9 Assess the current culture and identify the goal culture.

      2.10 Create employee transition and functional workplans.

      2.11 Establish the separation roadmap.

      2.12 Establish and align project metrics with identified tasks.

      2.13 Estimate integration costs.

      Outputs

      Stakeholder map

      IT strategy assessed

      IT operating model and IT governance structure defined

      Business context implications for IT

      Separation strategy

      Due diligence charter

      Data room artifacts

      Carve-out roadmap

      Service/technical transaction agreement

      Engagement assessment

      Culture assessment

      Employee transition and functional workplans

      Integration roadmap and associated resourcing

      3 Post-Transaction Execution & Value Realization

      The Purpose

      Establish the transaction foundation.

      Discover the motivation for separation.

      Plan the separation roadmap.

      Prepare employees for the transition.

      Engage in separation.

      Assess the transaction outcomes.

      Key Benefits Achieved

      All major stakeholders are on the same page.

      Separation activities are planned and assigned.

      Employees are set up for a smooth and successful transition.

      Separation strategy and roadmap are executed to benefit the organization.

      Review what went well and identify improvements to be made in future transactions.

      Activities

      3.1 Identify key stakeholders and outline their relationship to the M&A process.

      3.2 Gather and evaluate the M&A strategy, future-state operating model, and governance.

      3.3 Review the business rationale for the divestiture/sale.

      3.4 Establish the separation strategy.

      3.5 Prioritize separation tasks.

      3.6 Establish the separation roadmap.

      3.7 Establish and align project metrics with identified tasks.

      3.8 Estimate separation costs.

      3.9 Measure staff engagement.

      3.10 Assess the current culture and identify the goal culture.

      3.11 Create employee transition and functional workplans.

      3.12 Complete the separation by regularly updating the project plan.

      3.13 Assess the service/technical transaction agreement.

      3.14 Confirm separation costs.

      3.15 Review IT’s transaction value.

      3.16 Conduct a transaction and separation SWOT.

      3.17 Review the playbook and prepare for future transactions.

      Outputs

      M&A transaction team

      Stakeholder map

      IT strategy assessed

      IT operating model and IT governance structure defined

      Business context implications for IT

      Separation strategy

      Separation roadmap and associated resourcing

      Engagement assessment

      Culture assessment

      Employee transition and functional workplans

      Updated separation project plan

      Evaluated service/technical transaction agreement

      SWOT of transaction

      M&A Sell Playbook refined for future transactions

      Further reading

      Mergers & Acquisitions: The Sell Blueprint

      For IT leaders who want to have a role in the transaction process when their business is engaging in an M&A sale or divestiture.

      EXECUTIVE BRIEF

      Analyst Perspective

      Don’t wait to be invited to the M&A table, make it.

      Photo of Brittany Lutes, Research Analyst, CIO Practice, Info-Tech Research Group.
      Brittany Lutes
      Research Analyst,
      CIO Practice
      Info-Tech Research Group
      Photo of Ibrahim Abdel-Kader, Research Analyst, CIO Practice, Info-Tech Research Group.
      Ibrahim Abdel-Kader
      Research Analyst,
      CIO Practice
      Info-Tech Research Group

      IT has always been an afterthought in the M&A process, often brought in last minute once the deal is nearly, if not completely, solidified. This is a mistake. When IT is brought into the process late, the business misses opportunities to generate value related to the transaction and has less awareness of critical risks or inaccuracies.

      To prevent this mistake, IT leadership needs to develop strong business relationships and gain respect for their innovative suggestions. In fact, when it comes to modern M&A activity, IT should be the ones suggesting potential transactions to meet business needs, specifically when it comes to modernizing the business or adopting digital capabilities.

      IT needs to stop waiting to be invited to the acquisition or divestiture table. IT needs to suggest that the table be constructed and actively work toward achieving the strategic objectives of the business.

      Executive Summary

      Your Challenge

      There are four key scenarios or entry points for IT as the selling/divesting organization in M&As:

      • IT can suggest a divestiture to meet the business objectives of the organization.
      • IT is brought in to strategy plan the sale/divestiture from both the business’ and IT’s perspectives.
      • IT participates in due diligence activities and complies with the purchasing organization’s asks.
      • IT needs to reactively prepare its environment to enable the separation.

      Consider the ideal scenario for your IT organization.

      Common Obstacles

      Some of the obstacles IT faces include:

      • IT is often told about the transaction once the deal has already been solidified and is now forced to meet unrealistic business demands.
      • The business does not trust IT and therefore does not approach IT to define value or reduce risks to the transaction process.
      • The people and culture element is forgotten or not given adequate priority.

      These obstacles often arise when IT waits to be invited into the transaction process and misses critical opportunities.

      Info-Tech's Approach

      Prepare for a sale/divestiture transaction by:

      • Recognizing the trend for organizations to engage in M&A activity and the increased likelihood that, as an IT leader, you will be involved in a transaction in your career.
      • Creating a standard strategy that will enable strong program management.
      • Properly considering all the critical components of the transaction and integration by prioritizing tasks that will reduce risk, deliver value, and meet stakeholder expectations.

      Info-Tech Insight

      As the number of merger, acquisition, and divestiture transactions continues to increase, so too does IT’s opportunity to leverage the growing digital nature of these transactions and get involved at the onset.

      The changing M&A landscape

      Businesses will embrace more digital M&A transactions in the post-pandemic world

      • When the pandemic occurred, businesses reacted by either pausing (61%) or completely cancelling (46%) deals that were in the mid-transaction state (Deloitte, 2020). The uncertainty made many organizations consider whether the risks would be worth the potential benefits.
      • However, many organizations quickly realized the pandemic is not a hindrance to M&A transactions but an opportunity. Over 16,000 American companies were involved in M&A transactions in the first six months of 2021 (The Economist). For reference, this had been averaging around 10,000 per six months from 2016 to 2020.
      • In addition to this transaction growth, organizations have increasingly been embracing digital. These trends increase the likelihood that, as an IT leader, you will engage in an M&A transaction. However, it is up to you when you get involved in the transactions.

      The total value of transactions in the year after the pandemic started was $1.3 billion – a 93% increase in value compared to before the pandemic. (Nasdaq)

      71% of technology companies anticipate that divestitures will take place as a result of the COVID-19 pandemic. (EY, 2020)

      Your challenge

      IT is often not involved in the M&A transaction process. When it is, it’s often too late.

      • The most important driver of an acquisition is the ability to access new technology (DLA Piper), and yet 50% of the time, IT isn’t involved in the M&A transaction at all (IMAA Institute, 2017).
      • Additionally, IT’s lack of involvement in the process negatively impacts the business:
        • Most organizations (60%) do not have a standardized approach to integration (Steeves and Associates), let alone separation.
        • Two-thirds of the time, the divesting organization and acquiring organization will either fail together or succeed together (McKinsey, 2015).
        • Less than half (47%) of organizations actually experience the positive results sought by the M&A transaction (Steeves and Associates).
      • Organizations pursuing M&A and not involving IT are setting themselves up for failure.

      Only half of M&A deals involve IT (Source: IMAA Institute, 2017)

      Common Obstacles

      These barriers make this challenge difficult to address for many organizations:

      • IT is rarely afforded the opportunity to participate in the transaction deal. When IT is invited, this often happens later in the process where separation will be critical to business continuity.
      • IT has not had the opportunity to demonstrate that it is a valuable business partner in other business initiatives.
      • One of the most critical elements that IT often doesn’t take the time or doesn’t have the time to focus on is the people and leadership component.
      • IT waits to be invited to the process rather then actively involving themselves and suggesting how value can be added to the process.

      In hindsight, it’s clear to see: Involving IT is just good business.

      47% of senior leaders wish they would have spent more time on IT due diligence to prevent value erosion. (Source: IMAA Institute, 2017)

      “Solutions exist that can save well above 50 percent on divestiture costs, while ensuring on-time delivery.” (Source: SNP)

      Info-Tech's approach

      Acquisitions & Divestitures Framework

      Acquisitions and divestitures are inevitable in modern business, and IT’s involvement in the process should be too. This progression is inspired by:

      1. The growing trend for organizations to increase, decrease, or evolve through these types of transactions.
      2. Transactions that are driven by digital motivations, requiring IT’s expertise.
      3. A maturing business perspective of IT, preventing the difficulty that IT is faced with when invited into the transaction process late.
      4. There never being such a thing as a true merger, making the majority of M&A activity either acquisitions or divestitures.
      A diagram highlighting the 'IT Executives' Role in Acquisitions and Divestitures' when they are integrated at different points in the 'Core Business Timeline'. There are four main entry points 'Proactive', 'Discovery and Strategy', 'Due Diligence and Preparation', and 'Execution and Value Realized'. It is highlighted that IT can and should start at 'Proactive', but most organizations start at 'Execution and Value Realized'. 'Proactive': suggest opportunities to evolve the organization; prove IT's value and engage in growth opportunities early. Innovators start here. Steps of the business timeline in 'Proactive' are 'Organization strategies are defined' and 'M and A is considered to enable strategy'. After a buy or sell transaction is initiated is 'Discovery and Strategy': pre-transaction state. If it is a Buy transaction, 'Establish IT's involvement and approach'. If it is a Sell transaction, 'Prepare to engage in negotiations'. Business Partners start here. Steps of the business timeline in 'Discovery and Strategy' are 'Searching criteria is set', 'Potential candidates are considered', and 'LOI is sent/received'. 'Due Diligence and Preparation': mid-transaction state. If it is a Buy transaction, 'Identify potential transaction benefits and risks'. If it is a Sell transaction, 'Comply, communicate, and collaborate in transaction'. Trusted Operators start here. Steps of the business timeline in 'Due Diligence and Preparation' are 'Due diligence engagement occurs', 'Final agreement is reached', and 'Preparation for transaction execution occurs'. 'Execution and Value Realization': post-transaction state. If it is a Buy transaction, 'Integrate the IT environments and achieve business value'. If it is a Sell transaction, 'Separate the IT environment and deliver on transaction terms'. Firefighters start here. Steps of the business timeline in 'Execution and Value Realization' are 'Staff and operations are addressed appropriately', 'Day 1 of implementation and integration activities occurs', '1st 100 days of new entity state occur' and 'Ongoing risk mitigating and value creating activities occur'.

      The business’ view of IT will impact how soon IT can get involved

      There are four key entry points for IT

      A colorful visualization of the four key entry points for IT and a fifth not-so-key entry point. Starting from the top: 'Innovator', Information and Technology as a Competitive Advantage, 90% Satisfaction; 'Business Partner', Effective Delivery of Strategic Business Projects, 80% Satisfaction; 'Trusted Operator', Enablement of Business Through Application and Work Orders, 70% Satisfaction; 'Firefighter', Reliable Infrastructure and IT Service Desk, 60% Satisfaction; and then 'Unstable', Inability to Consistently Deliver Basic Services, <60% Satisfaction.
      1. Innovator: IT suggests a sale or divestiture to meet the business objectives of the organization.
      2. Business Partner: IT is brought in to strategy plan the sale/divestiture from both the business’ and IT’s perspective.
      3. Trusted Operator: IT participates in due diligence activities and complies with the purchasing organization’s asks.
      4. Firefighter: IT needs to reactively prepare its environment in order to enable the separation.

      Merger, acquisition, and divestiture defined

      Merger

      A merger looks at the equal combination of two entities or organizations. Mergers are rare in the M&A space, as the organizations will combine assets and services in a completely equal 50/50 split. Two organizations may also choose to divest business entities and merge as a new company.

      Acquisition

      The most common transaction in the M&A space, where an organization will acquire or purchase another organization or entities of another organization. This type of transaction has a clear owner who will be able to make legal decisions regarding the acquired organization.

      Divestiture

      An organization may decide to sell partial elements of a business to an acquiring organization. They will separate this business entity from the rest of the organization and continue to operate the other components of the business.

      Info-Tech Insight

      A true merger does not exist, as there is always someone initiating the discussion. As a result, most M&A activity falls into acquisition or divestiture categories.

      Selling vs. buying

      The M&A process approach differs depending on whether you are the selling or buying organization

      This blueprint is only focused on the sell side:

      • Examples of sell-related scenarios include:
        • Your organization is selling to another organization with the intent of keeping its regular staff, operations, and location. This could mean minimal separation is required.
        • Your organization is selling to another organization with the intent of separating to be a part of the purchasing organization.
        • Your organization is engaging in a divestiture with the intent of:
          • Separating components to be part of the purchasing organization permanently.
          • Separating components to be part of a spinoff and establish a unit as a standalone new company.
      • As the selling organization, you could proactively seek out suitors to purchase all or components of your organization, or you could be approached by an organization.

      The buy side is focused on:

      • More than two organizations could be involved in a transaction.
      • Examples of buy-related scenarios include:
        • Your organization is buying another organization with the intent of having the purchased organization keep its regular staff, operations, and location. This could mean minimal integration is required.
        • Your organization is buying another organization in its entirety with the intent of integrating it into your original company.
        • Your organization is buying components of another organization with the intent of integrating them into your original company.
      • As the purchasing organization, you will probably be initiating the purchase and thus will be valuating the selling organization during due diligence and leading the execution plan.

      For more information on acquisitions or purchases, check out Info-Tech’s Mergers & Acquisitions: The Buy Blueprint.

      Core business timeline

      For IT to be valuable in M&As, you need to align your deliverables and your support to the key activities the business and investors are working on.

      Info-Tech’s methodology for Selling Organizations in Mergers, Acquisitions, or Divestitures

      1. Proactive

      2. Discovery & Strategy

      3. Due Diligence & Preparation

      4. Execution & Value Realization

      Phase Steps

      1. Identify Stakeholders and Their Perspective of IT
      2. Assess IT’s Current Value and Future State
      3. Drive Innovation and Suggest Growth Opportunities
      1. Establish the M&A Program Plan
      2. Prepare IT to Engage in the Separation or Sale
      1. Engage in Due Diligence and Prepare Staff
      2. Prepare to Separate
      1. Execute the Transaction
      2. Reflection and Value Realization

      Phase Outcomes

      Be an innovative IT leader by suggesting how and why the business should engage in an acquisition or divestiture.

      Create a standardized approach for how your IT organization should address divestitures or sales.

      Comply with due diligence, prepare the IT environment for carve-out possibilities, and establish the separation project plan.

      Deliver on the separation project plan successfully and communicate IT’s transaction value to the business.

      Metrics for each phase

      1. Proactive

      2. Discovery & Strategy

      3. Valuation & Due Diligence

      4. Execution & Value Realization

      • % Share of business innovation spend from overall IT budget
      • % Critical processes with approved performance goals and metrics
      • % IT initiatives that meet or exceed value expectation defined in business case
      • % IT initiatives aligned with organizational strategic direction
      • % Satisfaction with IT's strategic decision-making abilities
      • $ Estimated business value added through IT-enabled innovation
      • % Overall stakeholder satisfaction with IT
      • % Percent of business leaders that view IT as an Innovator
      • % IT budget as a percent of revenue
      • % Assets that are not allocated
      • % Unallocated software licenses
      • # Obsolete assets
      • % IT spend that can be attributed to the business (chargeback or showback)
      • % Share of CapEx of overall IT budget
      • % Prospective organizations that meet the search criteria
      • $ Total IT cost of ownership (before and after M&A, before and after rationalization)
      • % Business leaders that view IT as a Business Partner
      • % Defects discovered in production
      • $ Cost per user for enterprise applications
      • % In-house-built applications vs. enterprise applications
      • % Owners identified for all data domains
      • # IT staff asked to participate in due diligence
      • Change to due diligence
      • IT budget variance
      • Synergy target
      • % Satisfaction with the effectiveness of IT capabilities
      • % Overall end-customer satisfaction
      • $ Impact of vendor SLA breaches
      • $ Savings through cost-optimization efforts
      • $ Savings through application rationalization and technology standardization
      • # Key positions empty
      • % Frequency of staff turnover
      • % Emergency changes
      • # Hours of unplanned downtime
      • % Releases that cause downtime
      • % Incidents with identified problem record
      • % Problems with identified root cause
      • # Days from problem identification to root cause fix
      • % Projects that consider IT risk
      • % Incidents due to issues not addressed in the security plan
      • # Average vulnerability remediation time
      • % Application budget spent on new build/buy vs. maintenance (deferred feature implementation, enhancements, bug fixes)
      • # Time (days) to value realization
      • % Projects that realized planned benefits
      • $ IT operational savings and cost reductions that are related to synergies/divestitures
      • % IT staff–related expenses/redundancies
      • # Days spent on IT separation
      • $ Accurate IT budget estimates
      • % Revenue growth directly tied to IT delivery
      • % Profit margin growth

      IT's role in the selling transaction

      And IT leaders have a greater likelihood than ever of needing to support a merger, acquisition, or divestiture.

      1. Reduced Risk

        IT can identify risks that may go unnoticed when IT is not involved.
      2. Increased Accuracy

        The business can make accurate predictions around the costs, timelines, and needs of IT.
      3. Faster Integration

        Faster integration means faster value realization for the business.
      4. Informed Decision Making

        IT leaders hold critical information that can support the business in moving the transaction forward.
      5. Innovation

        IT can suggest new opportunities to generate revenue, optimize processes, or reduce inefficiencies.

      The IT executive’s critical role is demonstrated by:

      • Reduced Risk

        47% of senior leaders wish they would have spent more time on IT due diligence to prevent value erosion (IMAA Institute, 2017).
      • Increased Accuracy

        Sellers often only provide 15 to 30 days for the acquiring organization to decide (Forbes, 2018), increasing the necessity of accurate pricing.
      • Faster Integration

        36% of CIOs have visibility into only business unit data, making the divestment a challenge (EY, 2021).
      • Informed Decision Making

        Only 38% of corporate and 22% of private equity firms include IT as a significant aspect in their transaction approach (IMAA Institute, 2017).
      • Innovation

        Successful CIOs involved in M&As can spend 70% of their time on aspects outside of IT and 30% of their time on technology and delivery (CIO).

      Playbook benefits

      IT Benefits

      • IT will be seen as an innovative partner to the business, and its suggestions and involvement in the organization will lead to benefits, not hindrances.
      • Develop a streamlined method to prepare the IT environment for potential carve-out and separations, ensuring risk management concerns are brought to the business’ attention immediately.
      • Create a comprehensive list of items that IT needs to do during the separation that can be prioritized and actioned.

      Business Benefits

      • The business will get accurate and relevant information about its IT environment in order to sell or divest the company to the highest bidder for a true price.
      • Fewer business interruptions will happen, because IT can accurately plan for and execute the high-priority separation tasks.
      • The business can obtain a high-value offer for the components of IT being sold and can measure the ongoing value the sale will bring.

      Insight summary

      Overarching Insight

      IT controls if and when it gets invited to support the business through a purchasing growth transaction. Take control of the process, demonstrate the value of IT, and ensure that separation of IT environments does not lead to unnecessary and costly decisions.

      Proactive Insight

      CIOs on the forefront of digital transformation need to actively look for and suggest opportunities to acquire or partner on new digital capabilities to respond to rapidly changing business needs.

      Discovery & Strategy Insight

      IT organizations that have an effective M&A program plan are more prepared for the transaction, enabling a successful outcome. A structured strategy is particularly necessary for organizations expected to deliver M&As rapidly and frequently.

      Due Diligence & Preparation Insight

      IT often faces unnecessary separation challenges because of a lack of preparation. Secure the IT environment and establish how IT will retain employees early in the transaction process.

      Execution & Value Realization Insight

      IT needs to demonstrate value and cost savings within 100 days of the transaction. The most successful transactions are when IT continuously realizes synergies a year after the transaction and beyond.

      Blueprint deliverables

      Key Deliverable: M&A Sell Playbook

      The M&A Sell Playbook should be a reusable document that enables your IT organization to successfully deliver on any divestiture transaction.

      Screenshots of the 'M and A Sell Playbook' deliverable.

      M&A Sell One-Pager

      See a one-page overview of each phase of the transaction.

      Screenshots of the 'M and A Sell One-Pagers' deliverable.

      M&A Sell Case Studies

      Read a one-page case study for each phase of the transaction.

      Screenshots of the 'M and A Sell Case Studies' deliverable.

      M&A Separation Project Management Tool (SharePoint)

      Manage the separation process of the divestiture/sale using this SharePoint template.

      Screenshots of the 'M and A Separation Project Management Tool (SharePoint)' deliverable.

      M&A Separation Project Management Tool (Excel)

      Manage the separation process of the divestiture/sale using this Excel tool if you can’t or don’t want to use SharePoint.

      Screenshots of the 'M and A Separation Project Management Tool (Excel)' deliverable.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      Guided Implementation

      Workshop

      Consulting

      "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful." "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track." "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place." "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

      Diagnostics and consistent frameworks used throughout all four options

      Guided Implementation

      What does a typical GI on this topic look like?

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

      A typical GI is between 6 to 10 calls over the course of 2 to 4 months.

        Proactive Phase

      • Call #1: Scope requirements, objectives, and your specific challenges.
      • Discovery & Strategy Phase

      • Call #2: Determine stakeholders and business perspectives on IT.
      • Call #3: Identify how M&A could support business strategy and how to communicate.
      • Due Diligence & Preparation Phase

      • Call #4: Establish a transaction team and divestiture/sale strategic direction.
      • Call #5: Create program metrics and identify a standard separation strategy.
      • Call #6: Prepare to carve out the IT environment.
      • Call #7: Identify the separation program plan.
      • Execution & Value Realization Phase

      • Call #8: Establish employee transitions to retain key staff.
      • Call #9: Assess IT’s ability to deliver on the divestiture/sale transaction.

      The Sell Blueprint

      Phase 1

      Proactive

      Phase 1

      Phase 2 Phase 3 Phase 4
      • 1.1 Identify Stakeholders and Their Perspective of IT
      • 1.2 Assess IT’s Current Value and Future State
      • 1.3 Drive Innovation and Suggest Reduction Opportunities
      • 2.1 Establish the M&A Program Plan
      • 2.2 Prepare IT to Engage in the Separation or Sale
      • 3.1 Engage in Due Diligence and Prepare Staff
      • 3.2 Prepare to Separate
      • 4.1 Execute the Transaction
      • 4.2 Reflection and Value Realization

      This phase will walk you through the following activities:

      • Conduct the CEO-CIO Alignment diagnostic
      • Conduct the CIO Business Vision diagnostic
      • Visualize relationships among stakeholders to identify key influencers
      • Group stakeholders into categories
      • Prioritize your stakeholders
      • Plan to communicate
      • Valuate IT
      • Assess the IT/digital strategy
      • Determine pain points and opportunities
      • Align goals to opportunities
      • Recommend reduction opportunities

      This phase involves the following participants:

      • IT and business leadership

      What is the Proactive phase?

      Embracing the digital drivers

      As the number of merger, acquisition, or divestiture transactions driven by digital means continues to increase, IT has an opportunity to not just be involved in a transaction but actively seek out potential deals.

      In the Proactive phase, the business is not currently considering a transaction. However, the business could consider one to reach its strategic goals. IT organizations that have developed respected relationships with the business leaders can suggest these potential transactions.

      Understand the business’ perspective of IT, determine who the critical M&A stakeholders are, valuate the IT environment, and examine how it supports the business goals in order to suggest an M&A transaction.

      In doing so, IT isn’t waiting to be invited to the transaction table – it’s creating it.

      Goal: To support the organization in reaching its strategic goals by suggesting M&A activities that will enable the organization to reach its objectives faster and with greater-value outcomes.

      Proactive Prerequisite Checklist

      Before coming into the Proactive phase, you should have addressed the following:

      • Understand what mergers, acquisitions, and divestitures are.
      • Understand what mergers, acquisitions, and divestitures mean for the business.
      • Understand what mergers, acquisitions, and divestitures mean for IT.

      Review the Executive Brief for more information on mergers, acquisitions, and divestitures for selling organizations.

      Proactive

      Step 1.1

      Identify M&A Stakeholders and Their Perspective of IT

      Activities

      • 1.1.1 Conduct the CEO-CIO Alignment diagnostic
      • 1.1.2 Conduct the CIO Business Vision diagnostic
      • 1.1.3 Visualize relationships among stakeholders to identify key influencers
      • 1.1.4 Group stakeholders into categories
      • 1.1.5 Prioritize your stakeholders
      • 1.16 Plan to communicate

      This step involves the following participants:

      • IT executive leader
      • IT leadership
      • Critical M&A stakeholders

      Outcomes of Step

      Understand how the business perceives IT and establish strong relationships with critical M&A stakeholders.

      Business executives' perspectives of IT

      Leverage diagnostics and gain alignment on IT’s role in the organization

      • To suggest or get involved with a merger, acquisition, or divestiture, the IT executive leader needs to be well respected by other members of the executive leadership team and the business.
      • Specifically, the Proactive phase relies on the IT organization being viewed as an Innovator within the business.
      • Identify how the CEO/business executive currently views IT and where they would like IT to move within the Maturity Ladder.
      • Additionally, understand how other critical department leaders view IT and how they view the partnership with IT.
      A colorful visualization titled 'Maturity Ladder' detailing levels of IT function that a business may choose from based on the business executives' perspectives of IT. Starting from the bottom: 'Struggle', Does not embarrass, Does not crash; 'Support', Keeps business happy, Keeps costs low; 'Optimize', Increases efficiency, Decreases costs; 'Expand', Extends into new business, Generates revenue; 'Transform', Creates new industry.

      Misalignment in target state requires further communication between the CIO and CEO to ensure IT is striving toward an agreed-upon direction.

      Info-Tech’s CIO Business Vision (CIO BV) diagnostic measures a variety of high-value metrics to provide a well-rounded understanding of stakeholder satisfaction with IT.

      Sample of Info-Tech's CIO Business Vision diagnostic measuring percentages of high-value metrics like 'IT Satisfaction' and 'IT Value' regarding business leader satisfaction. A note for these two reads 'Evaluate business leader satisfaction with IT this year and last year'. A section titled 'Relationship' has metrics such as 'Understands Needs' and 'Trains Effectively'. A note for this section reads 'Examine relationship indicators between IT and the business'. A section titled 'Security Friction' has metrics such as 'Regulatory Compliance-Driven' and 'Office/Desktop Security'.

      Business Satisfaction and Importance for Core Services

      The core services of IT are important when determining what IT should focus on. The most important services with the lowest satisfaction offer the largest area of improvement for IT to drive business value.

      Sample of Info-Tech's CIO Business Vision diagnostic specifically comparing the business satisfaction of 12 core services with their importance. Services listed include 'Service Desk', 'IT Security', 'Requirements Gathering', 'Business Apps', 'Data Quality', and more. There is a short description of the services, a percentage for the business satisfaction with the service, a percentage comparing it to last year, and a numbered ranking of importance for each service. A note reads 'Assess satisfaction and importance across 12 core IT capabilities'.

      1.1.1 Conduct the CEO-CIO Alignment diagnostic

      2 weeks

      Input: IT organization expertise and the CEO-CIO Alignment diagnostic

      Output: An understanding of an executive business stakeholder’s perception of IT

      Materials: M&A Sell Playbook, CEO-CIO Alignment diagnostic

      Participants: IT executive/CIO, Business executive/CEO

      1. The CEO-CIO Alignment diagnostic can be a powerful input. Speak with your Info-Tech account representative to conduct the diagnostic. Use the results to inform current IT capabilities.
      2. You may choose to debrief the results of your diagnostic with an Info-Tech analyst. We recommend this to help your team understand how to interpret and draw conclusions from the results.
      3. Examine the results of the survey and note where there might be specific capabilities that could be improved.
      4. Determine whether there are any areas of significant disagreement between the you and the CEO. Mark down those areas for further conversations. Additionally, take note of areas that could be leveraged to support transactions or support your rationale in recommending transactions.

      Download the sample report.

      Record the results in the M&A Sell Playbook.

      1.1.2 Conduct the CIO Business Vision diagnostic

      2 weeks

      Input: IT organization expertise, CIO BV diagnostic

      Output: An understanding of business stakeholder perception of certain IT capabilities and services

      Materials: M&A Buy Playbook, CIO Business Vision diagnostic

      Participants: IT executive/CIO, Senior business leaders

      1. The CIO Business Vision (CIO BV) diagnostic can be a powerful tool for identifying IT capability focus areas. Speak with your account representative to conduct the CIO BV diagnostic. Use the results to inform current IT capabilities.
      2. You may choose to debrief the results of your diagnostic with an Info-Tech analyst. We recommend this to help your team understand how to interpret the results and draw conclusions from the diagnostic.
      3. Examine the results of the survey and take note of any IT services that have low scores.
      4. Read through the diagnostic comments and note any common themes. Especially note which stakeholders identified they have a favorable relationship with IT and which stakeholders identified they have an unfavorable relationship. For those who have an unfavorable relationship, identify if they will have a critical role in a growth transaction.

      Download the sample report.

      Record the results in the M&A Sell Playbook.

      Create a stakeholder network map for M&A transactions

      Follow the trail of breadcrumbs from your direct stakeholders to their influencers to uncover hidden stakeholders.

      Example:

      Diagram of stakeholders and their relationships with other stakeholders, such as 'Board Members', 'CFO/Finance', 'Compliance', etc. with 'CIO/IT Leader' highlighted in the middle. There are unidirectional black arrows and bi-directional green arrows indicating each connection.

        Legend
      • Black arrows indicate the direction of professional influence
      • Dashed green arrows indicate bidirectional, informal influence relationships

      Info-Tech Insight

      Your stakeholder map defines the influence landscape that the M&A transaction will occur within. This will identify who holds various levels of accountability and decision-making authority when a transaction does take place.

      Use connectors to determine who may be influencing your direct stakeholders. They may not have any formal authority within the organization, but they may have informal yet substantial relationships with your stakeholders.

      1.1.3 Visualize relationships among stakeholders to identify key influencers

      1-3 hours

      Input: List of M&A stakeholders

      Output: Relationships among M&A stakeholders and influencers

      Materials: Flip charts, Markers, Sticky notes, M&A Sell Playbook

      Participants: IT executive leadership

      1. The purpose of this activity is to list all the stakeholders within your organization that will have a direct or indirect impact on the M&A transaction.
      2. Determine the critical stakeholders, and then determine the stakeholders of your stakeholders and consider adding each of them to the stakeholder list.
      3. Assess who has either formal or informal influence over your stakeholders; add these influencers to your stakeholder list.
      4. Construct a diagram linking stakeholders and their influencers together.
        • Use black arrows to indicate the direction of professional influence.
        • Use dashed green arrows to indicate bidirectional, informal influence relationships.

      Record the results in the M&A Sell Playbook.

      Categorize your stakeholders with a prioritization map

      A stakeholder prioritization map helps IT leaders categorize their stakeholders by their level of influence and ownership in the merger, acquisition, or divestiture process.

      A prioritization map of stakeholder categories split into four quadrants. The vertical axis is 'Influence', from low on the bottom to high on top. The horizontal axis is 'Ownership/Interest', from low on the left to high on the right. 'Spectators' are low influence, low ownership/interest. 'Mediators' are high influence, low ownership/interest. 'Noisemakers' are low influence, high ownership/interest. 'Players' are high influence, high ownership/interest.

      There are four areas in the map, and the stakeholders within each area should be treated differently.

      Players – players have a high interest in the initiative and the influence to effect change over the initiative. Their support is critical, and a lack of support can cause significant impediment to the objectives.

      Mediators – mediators have a low interest but significant influence over the initiative. They can help to provide balance and objective opinions to issues that arise.

      Noisemakers – noisemakers have low influence but high interest. They tend to be very vocal and engaged, either positively or negatively, but have little ability to enact their wishes.

      Spectators – generally, spectators are apathetic and have little influence over or interest in the initiative.

      1.1.4 Group stakeholders into categories

      30 minutes

      Input: Stakeholder map, Stakeholder list

      Output: Categorization of stakeholders and influencers

      Materials: Flip charts, Markers, Sticky notes, M&A Sell Playbook

      Participants: IT executive leadership, Stakeholders

      1. Identify your stakeholders’ interest in and influence on the M&A process as high, medium, or low by rating the attributes below.
      2. Map your results to the model to the right to determine each stakeholder’s category.

      Same prioritization map of stakeholder categories as before. This one has specific stakeholders mapped onto it. 'CFO' is mapped as low interest and middling influence, between 'Mediator' and 'Spectator'. 'CIO' is mapped as higher than average interest and high influence, a 'Player'. 'Board Member' is mapped as high interest and high influence, a 'Player'.

      Level of Influence
      • Power: Ability of a stakeholder to effect change.
      • Urgency: Degree of immediacy demanded.
      • Legitimacy: Perceived validity of stakeholder’s claim.
      • Volume: How loud their “voice” is or could become.
      • Contribution: What they have that is of value to you.
      Level of Interest

      How much are the stakeholder’s individual performance and goals directly tied to the success or failure of the product?

      Record the results in the M&A Sell Playbook.

      Prioritize your stakeholders

      There may be too many stakeholders to be able to manage them all. Focus your attention on the stakeholders that matter most.

      Level of Support

      Supporter

      Evangelist

      Neutral

      Blocker

      Stakeholder Category Player Critical High High Critical
      Mediator Medium Low Low Medium
      Noisemaker High Medium Medium High
      Spectator Low Irrelevant Irrelevant Low

      Consider the three dimensions for stakeholder prioritization: influence, interest, and support. Support can be determined by answering the following question: How significant is that stakeholder to the M&A or divestiture process?

      These parameters are used to prioritize which stakeholders are most important and should receive your focused attention.

      1.1.5 Prioritize your stakeholders

      30 minutes

      Input: Stakeholder matrix

      Output: Stakeholder and influencer prioritization

      Materials: Flip charts, Markers, Sticky notes, M&A Sell Playbook

      Participants: IT executive leadership, M&A/divestiture stakeholders

      1. Identify the level of support of each stakeholder by answering the following question: How significant is that stakeholder to the M&A transaction process?
      2. Prioritize your stakeholders using the prioritization scheme on the previous slide.

      Stakeholder

      Category

      Level of Support

      Prioritization

      CMO Spectator Neutral Irrelevant
      CIO Player Supporter Critical

      Record the results in the M&A Sell Playbook.

      Define strategies for engaging stakeholders by type

      A revisit to the map of stakeholder categories, but with strategies listed for each one, and arrows on the side instead of an axis. The vertical arrow is 'Authority', which increases upward, and the horizontal axis is Ownership/Interest which increases as it moves to the right. The strategy for 'Players' is 'Engage', for 'Mediators' is 'Satisfy', for 'Noisemakers' is 'Inform', and for 'Spectators' is 'Monitor'.

      Type

      Quadrant

      Actions

      Players High influence, high interest – actively engage Keep them updated on the progress of the project. Continuously involve Players in the process and maintain their engagement and interest by demonstrating their value to its success.
      Mediators High influence, low interest – keep satisfied They can be the game changers in groups of stakeholders. Turn them into supporters by gaining their confidence and trust and including them in important decision-making steps. In turn, they can help you influence other stakeholders.
      Noisemakers Low influence, high interest – keep informed Try to increase their influence (or decrease it if they are detractors) by providing them with key information, supporting them in meetings, and using Mediators to help them.
      Spectators Low influence, low interest – monitor They are followers. Keep them in the loop by providing clarity on objectives and status updates.

      Info-Tech Insight

      Each group of stakeholders draws attention and resources away from critical tasks. By properly identifying stakeholder groups, the IT executive leader can develop corresponding actions to manage stakeholders in each group. This can dramatically reduce wasted effort trying to satisfy Spectators and Noisemakers while ensuring the needs of Mediators and Players are met.

      1.1.6 Plan to communicate

      30 minutes

      Input: Stakeholder priority, Stakeholder categorization, Stakeholder influence

      Output: Stakeholder communication plan

      Materials: Flip charts, Markers, Sticky notes, M&A Sell Playbook

      Participants: IT executive leadership, M&A/divestiture stakeholders

      The purpose of this activity is to make a communication plan for each of the stakeholders identified in the previous activities, especially those who will have a critical role in the M&A transaction process.

      1. In the M&A Sell Playbook, input the type of influence each stakeholder has on IT, how they would be categorized in the M&A process, and their level of priority. Use this information to create a communication plan.
      2. Determine the methods and frequency of communication to keep the necessary stakeholder satisfied and maintain or enhance IT’s profile within the organization.

      Record the results in the M&A Sell Playbook.

      Proactive

      Step 1.2

      Assess IT’s Current Value and Method to Achieve a Future State

      Activities

      • 1.2.1 Valuate IT
      • 1.2.2 Assess the IT/digital strategy

      This step involves the following participants:

      • IT executive leader
      • IT leadership
      • Critical stakeholders to M&A

      Outcomes of Step

      Identify critical opportunities to optimize IT and meet strategic business goals through a merger, acquisition, or divestiture.

      How to valuate your IT environment

      And why it matters so much

      • Valuating your current organization’s IT environment is a critical step that all IT organizations should take, whether involved in an M&A or not, to fully understand what it might be worth.
      • The business investments in IT can be directly translated into a value amount. For every $1 invested in IT, the business might be gaining $100 in value back or possibly even loosing $100.
      • Determining, documenting, and communicating this information ensures that the business takes IT’s suggestions seriously and recognizes why investing in IT is so critical.
      • There are three ways a business or asset can be valuated:
        • Cost Approach: Look at the costs associated with building, purchasing, replacing, and maintaining a given aspect of the business.
        • Market Approach: Look at the relative value of a particular aspect of the business. Relative value can fluctuate and depends on what the markets and consequently society believe that particular element is worth.
        • Discounted Cash Flow Approach: Focus on what the potential value of the business could be or the intrinsic value anticipated due to future profitability.
      • (Source: “Valuation Methods,” Corporate Finance Institute)

      Four ways to create value through digital

      1. Reduced costs
      2. Improved customer experience
      3. New revenue sources
      4. Better decision making
      5. (Source: McKinsey & Company)

      1.2.1 Valuate IT

      1 day

      Input: Valuation of data, Valuation of applications, Valuation of infrastructure and operations, Valuation of security and risk

      Output: Valuation of IT

      Materials: Relevant templates/tools listed on the following slides, Capital budget, Operating budget, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership

      The purpose of this activity is to demonstrate that IT is not simply an operational functional area that diminishes business resources. Rather, IT contributes significant value to the business.

      1. Review each of the following slides to valuate IT’s data, applications, infrastructure and operations, and security and risk. These valuations consider several tangible and intangible factors and result in a final dollar amount.
      2. Input the financial amounts identified for each critical area into a summary slide. Use this information to determine where IT is delivering value to the organization.

      Info-Tech Insight

      Consistency is key when valuating your IT organization as well as other IT organizations throughout the transaction process.

      Record the results in the M&A Sell Playbook.

      Data valuation

      Data valuation identifies how you monetize the information that your organization owns.

      Create a data value chain for your organization

      When valuating the information and data that exists in an organization, there are many things to consider.

      Info-Tech has two tools that can support this process:

      1. Information Asset Audit Tool: Use this tool first to take inventory of the different information assets that exist in your organization.
      2. Data Valuation Tool: Once information assets have been accounted for, valuate the data that exists within those information assets.

      Data Collection

      Insight Creation

      Value Creation

      Data Valuation

      01 Data Source
      02 Data Collection Method
      03 Data
      04 Data Analysis
      05 Insight
      06 Insight Delivery
      07 Consumer
      08 Value in Data
      09 Value Dimension
      10 Value Metrics Group
      11 Value Metrics
      Screenshots of Tab 2 of Info-Tech's Data Valuation Tool.

      Instructions

      1. Using the Data Valuation Tool, start gathering information based on the eight steps above to understand your organization’s journey from data to value.
      2. Identify the data value spectrum. (For example: customer sales service, citizen licensing service, etc.)
      3. Fill out the columns for data sources, data collection, and data first.
      4. Capture data analysis and related information.
      5. Then capture the value in data.
      6. Add value dimensions such as usage, quality, and economic dimensions.
        • Remember that economic value is not the only dimension, and usage/quality has a significant impact on economic value.
      7. Collect evidence to justify your data valuation calculator (market research, internal metrics, etc.).
      8. Finally, calculate the value that has a direct correlation with underlying value metrics.

      Application valuation

      Calculate the value of your IT applications

      When valuating the applications and their users in an organization, consider using a business process map. This shows how business is transacted in the company by identifying which IT applications support these processes and which business groups have access to them. Info-Tech has a business process mapping tool that can support this process:

      • Enterprise Integration Process Mapping Tool: Complete this tool first to map the different business processes to the supporting applications in your organization.

      Instructions

      1. Start by calculating user costs. This is the multiplication of: (# of users) × (% of time spent using IT) × (fully burdened salary).
      2. Identify the revenue per employee and divide that by the average cost per employee to calculate the derived productivity ratio (DPR).
      3. Once you have calculated the user costs and DPR, multiply those total values together to get the application value.
      4. User Costs

        Total User Costs

        Derived Productivity Ratio (DPR)

        Total DPR

        Application Value

        # of users % time spent using IT Fully burdened salary Multiply values from the 3 user costs columns Revenue per employee Average cost per employee (Revenue P.E) ÷ (Average cost P.E) (User costs) X (DPR)

      5. Once the total application value is established, calculate the combined IT and business costs of delivering that value. IT and business costs include inflexibility (application maintenance), unavailability (downtime costs, including disaster exposure), IT costs (common costs statistically allocated to applications), and fully loaded cost of active (full-time equivalent [FTE]) users.
      6. Calculate the net value of applications by subtracting the total IT and business costs from the total application value calculated in step 3.
      7. IT and Business Costs

        Total IT and Business Costs

        Net Value of Applications

        Application maintenance Downtime costs (include disaster exposure) Common costs allocated to applications Fully loaded costs of active (FTE) users Sum of values from the four IT and business costs columns (Application value) – (IT and business costs)

      (Source: CSO)

      Infrastructure valuation

      Assess the foundational elements of the business’ information technology

      The purpose of this exercise is to provide a high-level infrastructure valuation that will contribute to valuating your IT environment.

      Calculating the value of the infrastructure will require different methods depending on the environment. For example, a fully cloud-hosted organization will have different costs than a fully on-premises IT environment.

      Instructions:

      1. Start by listing all of the infrastructure-related items that are relevant to your organization.
      2. Once you have finalized your items column, identify the total costs/value of each item.
        • For example, total software costs would include servers and storage.
      3. Calculate the total cost/value of your IT infrastructure by adding all of values in the right column.

      Item

      Costs/Value

      Hardware Assets Total Value +$3.2 million
      Hardware Leased/Service Agreement -$
      Software Purchased +$
      Software Leased/Service Agreement -$
      Operational Tools
      Network
      Disaster Recovery
      Antivirus
      Data Centers
      Service Desk
      Other Licenses
      Total:

      For additional support, download the M&A Runbook for Infrastructure and Operations.

      Risk and security

      Assess risk responses and calculate residual risk

      The purpose of this exercise is to provide a high-level risk assessment that will contribute to valuating your IT environment. For a more in-depth risk assessment, please refer to the Info-Tech tools below:

      1. Risk Register Tool
      2. Security M&A Due Diligence Tool

      Instructions

      1. Review the probability and impact scales below and ensure you have the appropriate criteria that align to your organization before you conduct a risk assessment.
      2. Identify the probability of occurrence and estimated financial impact for each risk category detail and fill out the table on the right. Customize the table as needed so it aligns to your organization.
      3. Probability of Risk Occurrence

        Occurrence Criteria
        (Classification; Probability of Risk Event Within One Year)

        Negligible Very Unlikely; ‹20%
        Very Low Unlikely; 20 to 40%
        Low Possible; 40 to 60%
        Moderately Low Likely; 60 to 80%
        Moderate Almost Certain; ›80%

      Note: If needed, you can customize this scale with the severity designations that you prefer. However, make sure you are always consistent with it when conducting a risk assessment.

      Financial & Reputational Impact

      Budgetary and Reputational Implications
      (Financial Impact; Reputational Impact)

      Negligible (‹$10,000; Internal IT stakeholders aware of risk event occurrence)
      Very Low ($10,000 to $25,000; Business customers aware of risk event occurrence)
      Low ($25,000 to $50,000; Board of directors aware of risk event occurrence)
      Moderately Low ($50,000 to $100,000; External customers aware of risk event occurrence)
      Moderate (›$100,000; Media coverage or regulatory body aware of risk event occurrence)

      Risk Category Details

      Probability of Occurrence

      Estimated Financial Impact

      Estimated Severity (Probability X Impact)

      Capacity Planning
      Enterprise Architecture
      Externally Originated Attack
      Hardware Configuration Errors
      Hardware Performance
      Internally Originated Attack
      IT Staffing
      Project Scoping
      Software Implementation Errors
      Technology Evaluation and Selection
      Physical Threats
      Resource Threats
      Personnel Threats
      Technical Threats
      Total:

      1.2.2 Assess the IT/digital strategy

      4 hours

      Input: IT strategy, Digital strategy, Business strategy

      Output: An understanding of an executive business stakeholder’s perception of IT, Alignment of IT/digital strategy and overall organization strategy

      Materials: Computer, Whiteboard and markers, M&A Sell Playbook

      Participants: IT executive/CIO, Business executive/CEO

      The purpose of this activity is to review the business and IT strategies that exist to determine if there are critical capabilities that are not being supported.

      Ideally, the IT and digital strategies would have been created following development of the business strategy. However, sometimes the business strategy does not directly call out the capabilities it requires IT to support.

      1. On the left half of the corresponding slide in the M&A Sell Playbook, document the business goals, initiatives, and capabilities. Input this information from the business or digital strategies. (If more space for goals, initiatives, or capabilities is needed, duplicate the slide).
      2. On the other half of the slide, document the IT goals, initiatives, and capabilities. Input this information from the IT strategy and digital strategy.

      For additional support, see Build a Business-Aligned IT Strategy.

      Record the results in the M&A Sell Playbook.

      Proactive

      Step 1.3

      Drive Innovation and Suggest Growth Opportunities

      Activities

      • 1.3.1 Determine pain points and opportunities
      • 1.3.2 Align goals with opportunities
      • 1.3.3 Recommend reduction opportunities

      This step involves the following participants:

      • IT executive leader
      • IT leadership
      • Critical M&A stakeholders

      Outcomes of Step

      Establish strong relationships with critical M&A stakeholders and position IT as an innovative business partner that can suggest reduction opportunities.

      1.3.1 Determine pain points and opportunities

      1-2 hours

      Input: CEO-CIO Alignment diagnostic, CIO Business Vision diagnostic, Valuation of IT environment, IT-business goals cascade

      Output: List of pain points or opportunities that IT can address

      Materials: Computer, Whiteboard and markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Business stakeholders

      The purpose of this activity is to determine the pain points and opportunities that exist for the organization. These can be external or internal to the organization.

      1. Identify what opportunities exist for your organization. Opportunities are the potential positives that the organization would want to leverage.
      2. Next, identify pain points, which are the potential negatives that the organization would want to alleviate.
      3. Spend time considering all the options that might exist, and keep in mind what has been identified previously.

      Opportunities and pain points can be trends, other departments’ initiatives, business perspectives of IT, etc.

      Record the results in the M&A Sell Playbook.

      1.3.2 Align goals with opportunities

      1-2 hours

      Input: CEO-CIO Alignment diagnostic, CIO Business Vision diagnostic, Valuation of IT environment, IT-business goals cascade, List of pain points and opportunities

      Output: An understanding of an executive business stakeholder’s perception of IT, Foundations for reduction strategy

      Materials: Computer, Whiteboard and markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Business stakeholders

      The purpose of this activity is to determine whether a growth or separation strategy might be a good suggestion to the business in order to meet its business objectives.

      1. For the top three to five business goals, consider:
        1. Underlying drivers
        2. Digital opportunities
        3. Whether a growth or reduction strategy is the solution
      2. Just because a growth or reduction strategy is a solution for a business goal does not necessarily indicate M&A is the way to go. However, it is important to consider before you pursue suggesting M&A.

      Record the results in the M&A Sell Playbook.

      1.3.3 Recommend reduction opportunities

      1-2 hours

      Input: Growth or separation strategy opportunities to support business goals, Stakeholder communication plan, Rationale for the suggestion

      Output: M&A transaction opportunities suggested

      Materials: M&A Sell Playbook

      Participants: IT executive/CIO, Business executive/CEO

      The purpose of this activity is to recommend a merger, acquisition, or divestiture to the business.

      1. Identify which of the business goals the transaction would help solve and why IT is the one to suggest such a goal.
      2. Leverage the stakeholder communication plan identified previously to give insight into stakeholders who would have a significant level of interest, influence, or support in the process.

      Info-Tech Insight

      With technology and digital driving many transactions, leverage your organizations’ IT environment as an asset and reason why the divestiture or sale should happen, suggesting the opportunity yourself.

      Record the results in the M&A Sell Playbook.

      By the end of this Proactive phase, you should:

      Be prepared to suggest M&A opportunities to support your company’s goals through sale or divestiture transactions

      Key outcome from the Proactive phase

      Develop progressive relationships and strong communication with key stakeholders to suggest or be aware of transformational opportunities that can be achieved through sale or divestiture strategies.

      Key deliverables from the Proactive phase
      • Business perspective of IT examined
      • Key stakeholders identified and relationship to the M&A process outlined
      • Ability to valuate the IT environment and communicate IT’s value to the business
      • Assessment of the business, digital, and IT strategies and how M&As could support those strategies
      • Pain points and opportunities that could be alleviated or supported through an M&A transaction
      • Sale or divestiture recommendations

      The Sell Blueprint

      Phase 2

      Discovery & Strategy

      Phase 1

      Phase 2

      Phase 3Phase 4
      • 1.1 Identify Stakeholders and Their Perspective of IT
      • 1.2 Assess IT’s Current Value and Future State
      • 1.3 Drive Innovation and Suggest Reduction Opportunities
      • 2.1 Establish the M&A Program Plan
      • 2.2 Prepare IT to Engage in the Separation or Sale
      • 3.1 Engage in Due Diligence and Prepare Staff
      • 3.2 Prepare to Separate
      • 4.1 Execute the Transaction
      • 4.2 Reflection and Value Realization

      This phase will walk you through the following activities:

      • Create the mission and vision
      • Identify the guiding principles
      • Create the future-state operating model
      • Determine the transition team
      • Document the M&A governance
      • Create program metrics
      • Establish the separation strategy
      • Conduct a RACI
      • Create the communication plan
      • Assess the potential organization(s)

      This phase involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Company M&A team

      Workshop Overview

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      Pre-Work

      Day 1

      Day 2

      Day 3

      Day 4

      Day 5

      Establish the Transaction FoundationDiscover the Motivation for Divesting or SellingFormalize the Program PlanCreate the Valuation FrameworkStrategize the TransactionNext Steps and Wrap-Up (offsite)

      Activities

      • 0.1 Conduct the CIO Business Vision and CEO-CIO Alignment diagnostics
      • 0.2 Identify key stakeholders and outline their relationship to the M&A process
      • 0.3 Identify the rationale for the company's decision to pursue a divestiture or sale
      • 1.1 Review the business rationale for the divestiture/sale
      • 1.2 Assess the IT/digital strategy
      • 1.3 Identify pain points and opportunities tied to the divestiture/sale
      • 1.4 Create the IT vision statement, create the IT mission statement, and identify IT guiding principles
      • 2.1 Create the future-state operating model
      • 2.2 Determine the transition team
      • 2.3 Document the M&A governance
      • 2.4 Establish program metrics
      • 3.1 Valuate your data
      • 3.2 Valuate your applications
      • 3.3 Valuate your infrastructure
      • 3.4 Valuate your risk and security
      • 3.5 Combine individual valuations to make a single framework
      • 4.1 Establish the separation strategy
      • 4.2 Conduct a RACI
      • 4.3 Review best practices for assessing target organizations
      • 4.4 Create the communication plan
      • 5.1 Complete in-progress deliverables from previous four days
      • 5.2 Set up review time for workshop deliverables and to discuss next steps

      Deliverables

      1. Business perspectives of IT
      2. Stakeholder network map for M&A transactions
      1. Business context implications for IT
      2. IT’s divestiture/sale strategic direction
      1. Operating model for future state
      2. Transition team
      3. Governance structure
      4. M&A program metrics
      1. IT valuation framework
      1. Separation strategy
      2. RACI
      3. Communication plan
      1. Completed M&A program plan and strategy
      2. Prepared to assess target organization(s)

      What is the Discovery & Strategy phase?

      Pre-transaction state

      The Discovery & Strategy phase during a sale or divestiture is a unique opportunity for many IT organizations. IT organizations that can participate in the transaction at this stage are likely considered a strategic partner of the business.

      For one-off sales/divestitures, IT being invited during this stage of the process is rare. However, for organizations that are preparing to engage in many divestitures over the coming years, this type of strategy will greatly benefit from IT involvement. Again, the likelihood of participating in an M&A transaction is increasing, making it a smart IT leadership decision to, at the very least, loosely prepare a program plan that can act as a strategic pillar throughout the transaction.

      During this phase of the pre-transaction state, IT may be asked to participate in ensuring that the IT environment is able to quickly and easily carve out components/business lines and deliver on service-level agreements (SLAs).

      Goal: To identify a repeatable program plan that IT can leverage when selling or divesting all or parts of the current IT environment, ensuring customer satisfaction and business continuity

      Discovery & Strategy Prerequisite Checklist

      Before coming into the Discovery & Strategy phase, you should have addressed the following:

      • Understand the business perspective of IT.
      • Know the key stakeholders and have outlined their relationship to the M&A process.
      • Be able to valuate the IT environment and communicate IT's value to the business.
      • Understand the rationale for the company's decision to pursue a sale or divestiture and the opportunities or pain points the sale should address.

      Discovery & Strategy

      Step 2.1

      Establish the M&A Program Plan

      Activities

      • 2.1.1 Create the mission and vision
      • 2.1.2 Identify the guiding principles
      • 2.1.3 Create the future-state operating model
      • 2.1.4 Determine the transition team
      • 2.1.5 Document the M&A governance
      • 2.1.6 Create program metrics

      This step involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Company M&A team

      Outcomes of Step

      Establish an M&A program plan that can be repeated across sales/divestitures.

      The vision and mission statements clearly articulate IT’s aspirations and purpose

      The IT vision statement communicates a desired future state of the IT organization, whereas the IT mission statement portrays the organization’s reason for being. While each serves its own purpose, they should both be derived from the business context implications for IT.

      Vision Statements

      Mission Statements

      Characteristics

      • Describe a desired future
      • Focus on ends, not means
      • Concise
      • Aspirational
      • Memorable
      • Articulate a reason for existence
      • Focus on how to achieve the vision
      • Concise
      • Easy to grasp
      • Sharply focused
      • Inspirational

      Samples

      To be a trusted advisor and partner in enabling business innovation and growth through an engaged IT workforce. (Source: Business News Daily) IT is a cohesive, proactive, and disciplined team that delivers innovative technology solutions while demonstrating a strong customer-oriented mindset. (Source: Forbes, 2013)

      2.1.1 Create the mission and vision statements

      2 hours

      Input: Business objectives, IT capabilities, Rationale for the transaction

      Output: IT’s mission and vision statements for reduction strategies tied to mergers, acquisitions, and divestitures

      Materials: Flip charts/whiteboard, Markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to create mission and vision statements that reflect IT’s intent and method to support the organization as it pursues a reduction strategy.

      1. Review the definitions and characteristics of mission and vision statements.
      2. Brainstorm different versions of the mission and vision statements.
      3. Edit the statements until you get to a single version of each that accurately reflects IT’s role in the reduction process.

      Record the results in the M&A Sell Playbook.

      Guiding principles provide a sense of direction

      IT guiding principles are shared, long-lasting beliefs that guide the use of IT in constructing, transforming, and operating the enterprise by informing and restricting IT investment portfolio management, solution development, and procurement decisions.

      A diagram illustrating the place of 'IT guiding principles' in the process of making 'Decisions on the use of IT'. There are four main items, connecting lines naming the type of process in getting from one step to the next, and a line underneath clarifying the questions asked at each step. On the far left, over the question 'What decisions should be made?', is 'Business context and IT implications'. This flows forward to 'IT guiding principles', and they are connected by 'Influence'. Next, over the question 'How should decisions be made?', is the main highlighted section. 'IT guiding principles' flows forward to 'Decisions on the use of IT', and they are connected by 'Guide and inform'. On the far right, over the question 'Who has the accountability and authority to make decisions?', is 'IT policies'. This flows back to 'Decisions on the use of IT', and they are connected by 'Direct and control'.

      IT principles must be carefully constructed to make sure they are adhered to and relevant

      Info-Tech has identified a set of characteristics that IT principles should possess. These characteristics ensure the IT principles are relevant and followed in the organization.

      Approach focused. IT principles should be focused on the approach – how the organization is built, transformed, and operated – as opposed to what needs to be built, which is defined by both functional and non-functional requirements.

      Business relevant. Create IT principles that are specific to the organization. Tie IT principles to the organization’s priorities and strategic aspirations.

      Long lasting. Build IT principles that will withstand the test of time.

      Prescriptive. Inform and direct decision making with actionable IT principles. Avoid truisms, general statements, and observations.

      Verifiable. If compliance can’t be verified, people are less likely to follow the principle.

      Easily Digestible. IT principles must be clearly understood by everyone in IT and by business stakeholders. IT principles aren’t a secret manuscript of the IT team. IT principles should be succinct; wordy principles are hard to understand and remember.

      Followed. Successful IT principles represent a collection of beliefs shared among enterprise stakeholders. IT principles must be continuously communicated to all stakeholders to achieve and maintain buy-in.

      In organizations where formal policy enforcement works well, IT principles should be enforced through appropriate governance processes.

      Consider the example principles below

      IT Principle Name

      IT Principle Statement

      1. Risk Management We will ensure that the organization’s IT Risk Management Register is properly updated to reflect all potential risks and that a plan of action against those risks has been identified.
      2. Transparent Communication We will ensure employees are spoken to with respect and transparency throughout the transaction process.
      3. Separation for Success We will create a carve-out strategy that enables the organization and clearly communicates the resources required to succeed.
      4. Managed Data We will handle data creation, modification, separation, and use across the enterprise in compliance with our data governance policy.
      5.Deliver Better Customer Service We will reduce the number of products offered by IT, enabling a stronger focus on specific products or elements to increase customer service delivery.
      6. Compliance With Laws and Regulations We will operate in compliance with all applicable laws and regulations for both our organization and the potentially purchasing organization.
      7. Defined Value We will create a plan of action that aligns with the organization’s defined value expectations.
      8. Network Readiness We will ensure that employees and customers have immediate access to the network with minimal or no outages.
      9. Value Generator We will leverage the current IT people, processes, and technology to turn the IT organization into a value generator by developing and selling our services to purchasing organizations.

      2.1.2 Identify the guiding principles

      2 hours

      Input: Business objectives, IT capabilities, Rationale for the transaction, Mission and vision statements

      Output: IT’s guiding principles for reduction strategies tied to mergers, acquisitions, and divestitures

      Materials: Flip charts/whiteboard, Markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to create the guiding principles that will direct the IT organization throughout the reduction strategy process.

      1. Review the role of guiding principles and the examples of guiding principles that organizations have used.
      2. Brainstorm different versions of the guiding principles. Each guiding principle should start with the phrase “We will…”
      3. Edit and consolidate the statements until you have a list of approximately eight to ten statements that accurately reflect IT’s role in the reduction process.
      4. Review the guiding principles every six months to ensure they continue to support the delivery of the business’ reduction strategy goals.

      Record the results in the M&A Sell Playbook.

      Create two IT teams to support the transaction

      IT M&A Transaction Team

      • The IT M&A Transaction Team should consist of the strongest members of the IT team who can be expected to deliver on unusual or additional tasks not asked of them in normal day-to-day operations.
      • The roles selected for this team will have very specific skills sets or deliver on critical separation capabilities, making their involvement in the combination of two or more IT environments paramount.
      • These individuals need to have a history of proving themselves very trustworthy, as they will likely be required to sign an NDA as well.
      • Expect to have to certain duplicate capabilities or roles across the M&A Team and Operational Team.

      IT Operational Team

      • This group is responsible for ensuring the business operations continue.
      • These employees might be those who are newer to the organization but can be counted on to deliver consistent IT services and products.
      • The roles of this team should ensure that end users or external customers remain satisfied.

      Key capabilities to support M&A

      Consider the following capabilities when looking at who should be a part of the IT Transaction Team.

      Employees who have a significant role in ensuring that these capabilities are being delivered will be a top priority.

      Infrastructure & Operations

      • System Separation
      • Data Management
      • Helpdesk/Desktop Support
      • Cloud/Server Management

      Business Focus

      • Service-Level Management
      • Enterprise Architecture
      • Stakeholder Management
      • Project Management

      Risk & Security

      • Privacy Management
      • Security Management
      • Risk & Compliance Management

      Build a lasting and scalable operating model

      An operating model is an abstract visualization, used like an architect’s blueprint, that depicts how structures and resources are aligned and integrated to deliver on the organization’s strategy.

      It ensures consistency of all elements in the organizational structure through a clear and coherent blueprint before embarking on detailed organizational design.

      The visual should highlight which capabilities are critical to attaining strategic goals and clearly show the flow of work so that key stakeholders can understand where inputs flow in and outputs flow out of the IT organization.

      As you assess the current operating model, consider the following:

      • Does the operating model contain all the necessary capabilities your IT organization requires to be successful?
      • What capabilities should be duplicated?
      • Are there individuals with the skill set to support those roles? If not, is there a plan to acquire or develop those skills?
      • A dedicated project team strictly focused on M&A is great. However, is it feasible for your organization? If not, what blockers exist?
      A diagram with 'Initiatives' and 'Solutions' on the left and right of an area chart, 'Customer' at the top, the area between them labelled 'Functional Area n', and six horizontal bars labelled 'IT Capability' stacked on top of each other. The 'IT Capability' bars are slightly skewed to the 'Solutions' side of the chart.

      Info-Tech Insight

      Investing time up-front getting the operating model right is critical. This will give you a framework to rationalize future organizational changes, allowing you to be more iterative and allowing your model to change as the business changes.

      2.1.3 Create the future-state operating model

      4 hours

      Input: Current operating model, IT strategy, IT capabilities, M&A-specific IT capabilities, Business objectives, Rationale for the transaction, Mission and vision statements

      Output: Future-state operating model for divesting organizations

      Materials: Operating model, Capability overlay, Flip charts/whiteboard, Markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to establish what the future-state operating model will be if your organization needs to adjust to support a divestiture transaction. If your organization plans to sell in its entirety, you may choose to skip this activity.

      1. Ensuring that all the IT capabilities are identified by the business and IT strategy, document your organization’s current operating model.
      2. Identify what core capabilities would be critical to the divesting transaction process and separation. Highlight and make copies of those capabilities in the M&A Sell Playbook. As a result of divesting, there may also be capabilities that will become irrelevant in your future state.
      3. Ensure the capabilities that will be decentralized are clearly identified. Decentralized capabilities do not exist within the central IT organization but rather in specific lines of businesses, products, or locations to better understand needs and deliver on the capability.

      An example operating model is included in the M&A Sell Playbook. This process benefits from strong reference architecture and capability mapping ahead of time.

      Record the results in the M&A Sell Playbook.

      2.1.4 Determine the transition team

      3 hours

      Input: IT capabilities, Future-state operating model, M&A-specific IT capabilities, Business objectives, Rationale for the transaction, Mission and vision statements

      Output: Transition team

      Materials: Reference architecture, Organizational structure, Flip charts/whiteboard, Markers

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to create a team that will support your IT organization throughout the transaction. Determining which capabilities and therefore which roles will be required ensures that the business will continue to get the operational support it needs.

      1. Based on the outcome of activity 2.1.3, review the capabilities that your organization will require on the transition team. Group capabilities into functional groups containing capabilities that are aligned well with one another because they have similar responsibilities and functionalities.
      2. Replace the capabilities with roles. For example, stakeholder management, requirements gathering, and project management might be one functional group. Project management and stakeholder management might combine to create a project manager role.
      3. Review the examples in the M&A Sell Playbook and identify which roles will be a part of the transition team.

      For more information, see Redesign Your Organizational Structure

      What is governance?

      And why does it matter so much to IT and the M&A process?

      • Governance is the method in which decisions get made, specifically as they impact various resources (time, money, and people).
      • Because M&A is such a highly governed transaction, it is important to document the governance bodies that exist in your organization.
      • This will give insight into what types of governing bodies there are, what decisions they make, and how that will impact IT.
      • For example, funds to support separation need to be discussed, approved, and supplied to IT from a governing body overseeing the acquisition.
      • A highly mature IT organization will have automated governance, while a seemingly non-existent governance process will be considered ad hoc.
      A pyramid with four levels representing the types of governing bodies that are available with differing levels of IT maturity. An arrow beside the pyramid points upward. The bottom of the arrow is labelled 'Traditional (People and document centric)' and the top is labelled 'Adaptive (Data centric)'. Starting at the bottom of the pyramid is level 1 'Ad Hoc Governance', 'Governance that is not well defined or understood within the organization. It occurs out of necessity but often not by the right people'. Level 2 is 'Controlled Governance', 'Governance focused on compliance and decisions driven by hierarchical authority. Levels of authority are defined and often driven by regulatory'. Level 3 is 'Agile Governance', 'Governance that is flexible to support different needs and quick response in the organization. Driven by principles and delegated throughout the company'. At the top of the pyramid is level 4 'Automated Governance', 'Governance that is entrenched and automated into organizational processes and product/service design. Empowered and fully delegated governance to maintain fit and drive organizational success and survival'.

      2.1.5 Document M&A governance

      1-2 hours

      Input: List of governing bodies, Governing body committee profiles, Governance structure

      Output: Documented method on how decisions are made as it relates to the M&A transaction

      Materials: Flip charts/whiteboard, Markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to determine the method in which decisions are made throughout the M&A transaction as it relates to IT. This will require understanding both governing bodies internal to IT and those external to IT.

      1. First, determine the other governance structures within the organization that will impact the decisions made about M&A. List out these bodies or committees.
      2. Create a profile for each committee that looks at the membership, purpose of the committee, decision areas (authority), and the process of inputs and outputs. Ensure IT committees that will have a role in this process are also documented. Consider the benefits realized, risks, and resources required for each.
      3. Organize the committees into a structure, identifying the committees that have a role in defining the strategy, designing and building, and running.

      Record the results in the M&A Sell Playbook.

      Current-state structure map – definitions of tiers

      Strategy: These groups will focus on decisions that directly connect to the strategic direction of the organization.

      Design & Build: The second tier of groups will oversee prioritization of a certain area of governance as well as design and build decisions that feed into strategic decisions.

      Run: The lowest level of governance will be oversight of more-specific initiatives and capabilities within IT.

      Expect tier overlap. Some committees will operate in areas that cover two or three of these governance tiers.

      Measure the IT program’s success in terms of its ability to support the business’ M&A goals

      Upper management will measure IT’s success based on your ability to support the underlying reasons for the M&A. Using business metrics will help assure business stakeholders that IT understands their needs and is working with the business to achieve them.

      Business-Specific Metrics

      • Revenue Growth: Increase in the top line as seen by market expansion, product expansion, etc. by percentage/time.
      • Synergy Extraction: Reduction in costs as determined by the ability to identify and eliminate redundancies over time.
      • Profit Margin Growth: Increase in the bottom line as a result of increased revenue growth and/or decreased costs over time.

      IT-Specific Metrics

      • IT operational savings and cost reductions due to synergies: Operating expenses, capital expenditures, licenses, contracts, applications, infrastructure over time.
      • Reduction in IT staff expense and headcount: Decreased budget allocated to IT staff, and ability to identify and remove redundancies in staff.
      • Meeting or improving on IT budget estimates: Delivering successful IT separation on a budget that is the same or lower than the budget estimated during due diligence.
      • Meeting or improving on IT time-to-separation estimates: Delivering successful IT carve-out on a timeline that is the same or shorter than the timeline estimated during due diligence.
      • Business capability support: Delivering the end state of IT that supports the expected business capabilities and growth.

      Establish your own metrics to gauge the success of IT

      Establish SMART M&A Success Metrics

      S pecific Make sure the objective is clear and detailed.
      M easurable Objectives are measurable if there are specific metrics assigned to measure success. Metrics should be objective.
      A ctionable Objectives become actionable when specific initiatives designed to achieve the objective are identified.
      R ealistic Objectives must be achievable given your current resources or known available resources.
      T ime-Bound An objective without a timeline can be put off indefinitely. Furthermore, measuring success is challenging without a timeline.
      • What should IT consider when looking to identify potential additions, deletions, or modifications that will either add value to the organization or reduce costs/risks?
      • Provide a definition of synergies.
      • IT operational savings and cost reductions due to synergies: Operating expenses, capital expenditures, licenses, contracts, applications, infrastructure.
      • Reduction in IT staff expense and headcount: Decreased budget allocated to IT staff, and ability to identify and remove redundancies in staff.
      • Meeting or improving on IT budget estimates: Delivering successful IT separation on a budget that is the same or lower than the budget estimated during due diligence.
      • Meeting or improving on IT time-to-separation estimates: Delivering successful IT carve-out on a timeline that is the same or shorter than the timeline estimated during due diligence.
      • Revenue growth: Increase in the top line as a result, as seen by market expansion, product expansion, etc., as a result of divesting lines of the business and selling service-level agreements to the purchasing organization.
      • Synergy extraction: Reduction in costs, as determined by the ability to identify and eliminate redundancies.
      • Profit margin growth: Increase in the bottom line as a result of increased revenue growth and/or decreased costs.

      Metrics for each phase

      1. Proactive

      2. Discovery & Strategy

      3. Valuation & Due Diligence

      4. Execution & Value Realization

      • % Share of business innovation spend from overall IT budget
      • % Critical processes with approved performance goals and metrics
      • % IT initiatives that meet or exceed value expectation defined in business case
      • % IT initiatives aligned with organizational strategic direction
      • % Satisfaction with IT's strategic decision-making abilities
      • $ Estimated business value added through IT-enabled innovation
      • % Overall stakeholder satisfaction with IT
      • % Percent of business leaders that view IT as an Innovator
      • % IT budget as a percent of revenue
      • % Assets that are not allocated
      • % Unallocated software licenses
      • # Obsolete assets
      • % IT spend that can be attributed to the business (chargeback or showback)
      • % Share of CapEx of overall IT budget
      • % Prospective organizations that meet the search criteria
      • $ Total IT cost of ownership (before and after M&A, before and after rationalization)
      • % Business leaders that view IT as a Business Partner
      • % Defects discovered in production
      • $ Cost per user for enterprise applications
      • % In-house-built applications vs. enterprise applications
      • % Owners identified for all data domains
      • # IT staff asked to participate in due diligence
      • Change to due diligence
      • IT budget variance
      • Synergy target
      • % Satisfaction with the effectiveness of IT capabilities
      • % Overall end-customer satisfaction
      • $ Impact of vendor SLA breaches
      • $ Savings through cost-optimization efforts
      • $ Savings through application rationalization and technology standardization
      • # Key positions empty
      • % Frequency of staff turnover
      • % Emergency changes
      • # Hours of unplanned downtime
      • % Releases that cause downtime
      • % Incidents with identified problem record
      • % Problems with identified root cause
      • # Days from problem identification to root cause fix
      • % Projects that consider IT risk
      • % Incidents due to issues not addressed in the security plan
      • # Average vulnerability remediation time
      • % Application budget spent on new build/buy vs. maintenance (deferred feature implementation, enhancements, bug fixes)
      • # Time (days) to value realization
      • % Projects that realized planned benefits
      • $ IT operational savings and cost reductions that are related to synergies/divestitures
      • % IT staff–related expenses/redundancies
      • # Days spent on IT separation
      • $ Accurate IT budget estimates
      • % Revenue growth directly tied to IT delivery
      • % Profit margin growth

      2.1.6 Create program metrics

      1-2 hours

      Input: IT capabilities, Mission, vision, and guiding principles, Rationale for the acquisition

      Output: Program metrics to support IT throughout the M&A process

      Materials: Flip charts/whiteboard, Markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to determine how IT’s success throughout a growth transaction will be measured and determined.

      1. Document a list of appropriate metrics on the whiteboard. Remember to include metrics that demonstrate the business impact. You can use the sample metrics listed on the previous slide as a starting point.
      2. Set a target and deadline for each metric. This will help the group determine when it is time to evaluate progression.
      3. Establish a baseline for each metric based on information collected within your organization.
      4. Assign an owner for tracking each metric as well as someone to be accountable for performance.

      Record the results in the M&A Sell Playbook.

      Discovery & Strategy

      Step 2.2

      Prepare IT to Engage in the Separation or Sale

      Activities

      • 2.2.1 Establish the separation strategy
      • 2.2.2 Conduct a RACI
      • 2.2.3 Create the communication plan
      • 2.2.4 Assess the potential organization(s)

      This step involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Company M&A team

      Outcomes of Step

      Identify IT’s plan of action when it comes to the separation/sale and align IT’s separation/sale strategy with the business’ M&A strategy.

      Separation strategies

      There are several IT separation strategies that will let you achieve your target technology environment.

      IT Separation Strategies
      • Divest. Carve out elements of the IT organization and sell them to a purchasing organization with or without a service-level agreement.
      • Sell. Sell the entire IT environment to a purchasing organization. The purchasing organization takes full responsibility in delivering and running the IT environment.
      • Spin-Off Joint Venture. Carve out elements of the IT organization and combine them with elements of a new or purchasing organization to create a new entity.

      The approach IT takes will depend on the business objectives for the M&A.

      • Generally speaking, the separation strategy is well understood and influenced by the frequency of and rationale for selling.
      • Based on the initiatives generated by each business process owner, you need to determine the IT separation strategy that will best support the desired target technology environment, especially if you are still operating or servicing elements of that IT environment.

      Key considerations when choosing an IT separation strategy include:

      • What are the main business objectives of the M&A?
      • What are the key synergies expected from the transaction?
      • What IT separation strategy best helps obtain these benefits?
      • What opportunities exist to position the business for sustainable and long-term growth?

      Separation strategies in detail

      Review highlights and drawbacks of different separation strategies

      Divest
        Highlights
      • Recommended for businesses striving to reduce costs and potentially even generate revenue for the business through the delivery of SLAs.
      • Opportunity to reduce or scale back on lines of business or products that are not driving profits.
        Drawbacks
      • May be forced to give up critical staff that have been known to deliver high value.
      • The IT department is left to deliver services to the purchasing organization with little support or consideration from the business.
      • There can be increased risk and security concerns that need to be addressed.
      Sell
        Highlights
      • Recommended for businesses looking to gain capital to exit the market profitably or to enter a new market with a large sum of capital.
      • The business will no longer exist, and as a result all operational costs, including IT, will become redundant.
        Drawbacks
      • IT is no longer needed as an operating or capital service for the organization.
      • Lost resources, including highly trained and critical staff.
      • May require packaging employees off and using the profit or capital generated to cover any closing costs.
      Spin-Off or Joint Venture
        Highlights
      • Recommended for businesses looking to expand their market presence or acquire new products. Essentially aligning the two organizations in the same market.
      • Each side has a unique offering but complementing capabilities.
        Drawbacks
      • As much as the organization is going through a separation from the original company, it will be going through an integration with the new company.
      • There could be differences in culture.
      • This could require a large amount of investment without a guarantee of profit or success.

      2.2.1 Establish the separation strategy

      1-2 hours

      Input: Business separation strategy, Guiding principles, M&A governance

      Output: IT’s separation strategy

      Materials: Flip charts/whiteboard, Markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to determine IT’s approach to separating or selling. This approach might differ slightly from transaction to transaction. However, the businesses approach to transactions should give insight into the general separation strategy IT should adopt.

      1. Make sure you have clearly articulated the business objectives for the M&A, the technology end state for IT, and the magnitude of the overall separation.
      2. Review and discuss the highlights and drawbacks of each type of separation.
      3. Use Info-Tech’s Separation Posture Selection Framework on the next slide to select the separation posture that will appropriately enable the business. Consider these questions during your discussion:
        1. What are the main business objectives of the M&A? What key IT capabilities will need to support business objectives?
        2. What key synergies are expected from the transaction? What opportunities exist to position the business for sustainable growth?
        3. What IT separation best helps obtain these benefits?

      Record the results in the M&A Sell Playbook.

      Separation Posture Selection Framework

      Business M&A Strategy

      Resultant Technology Strategy

      M&A Magnitude (% of Seller Assets, Income, or Market Value)

      IT Separation Posture

      A. Horizontal Adopt One Model ‹100% Divest
      ›99% Sell
      B. Vertical Create Links Between Critical Systems Any Divest
      C. Conglomerate Independent Model Any Joint Venture
      Divest
      D. Hybrid: Horizontal & Conglomerate Create Links Between Critical Systems Any Divest
      Joint Venture

      M&A separation strategy

      Business M&A Strategy Resultant Technology Strategy M&A Magnitude (% of Seller Assets, Income, or Market Value) IT Separation Posture

      You may need a hybrid separation posture to achieve the technology end state.

      M&A objectives may not affect all IT domains and business functions in the same way. Therefore, the separation requirements for each business function may differ. Organizations will often choose to select and implement a hybrid separation posture to realize the technology end state.

      Each business division may have specific IT domain and capability needs that require an alternative separation strategy.

      • Example: Even when conducting a joint venture by forming a new organization, some partners might view themselves as the dominant partner and want to influence the IT environment to a greater degree.
      • Example: Some purchasing organizations will expect service-level agreements to be available for a significant period of time following the divestiture, while others will be immediately independent.

      2.2.2 Conduct a RACI

      1-2 hours

      Input: IT capabilities, Transition team, Separation strategy

      Output: Completed RACI for Transition team

      Materials: Reference architecture, Organizational structure, Flip charts/whiteboard, Markers, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to identify the core accountabilities and responsibilities for the roles identified as critical to your transition team. While there might be slight variation from transaction to transaction, ideally each role should be performing certain tasks.

      1. First, identify a list of critical tasks that need to be completed to support the sale or separation. For example:
        • Communicate with the company M&A team.
        • Identify the key IT solutions that can and cannot be carved out.
        • Gather data room artifacts and provide them to acquiring organization.
      2. Next, identify at the activity level which role is accountable or responsible for each activity. Enter an A for accountable, R for responsible, or A/R for both.

      Record the results in the M&A Sell Playbook.

      Communication and change

      Prepare key stakeholders for the potential changes

      • Anytime you are starting a project or program that will depend on users and stakeholders to give up their old way of doing things, change will force people to become novices again, leading to lost productivity and added stress.
      • Change management can improve outcomes for any project where you need people to adopt new tools and procedures, comply with new policies, learn new skills and behaviors, or understand and support new processes.
      • M&As move very quickly, and it can be very difficult to keep track of which stakeholders you need to be communicating with and what you should be communicating.
      • Not all organizations embrace or resist change in the same ways. Base your change communications on your organization’s cultural appetite for change in general.
        • Organizations with a low appetite for change will require more direct, assertive communications.
        • Organizations with a high appetite for change are more suited to more open, participatory approaches.

      Three key dimensions determine the appetite for cultural change:

      • Power Distance. Refers to the acceptance that power is distributed unequally throughout the organization.
        In organizations with a high power distance, the unequal power distribution is accepted by the less powerful employees.
      • Individualism. Organizations that score high in individualism have employees who are more independent. Those who score low in individualism fall into the collectivism side, where employees are strongly tied to one another or their groups.
      • Uncertainty Avoidance. Describes the level of acceptance that an organization has toward uncertainty. Those who score high in this area find that their employees do not favor uncertain situations, while those that score low in this area find that their employees are comfortable with change and uncertainty.

      2.2.3 Create the communication plan

      1-2 hours

      Input: IT’s M&A mission, vision, and guiding principles, M&A transition team, IT separation strategy, RACI

      Output: IT’s M&A communication plan

      Materials: Flip charts/whiteboard, Markers, RACI, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to create a communication plan that IT can leverage throughout the initiative.

      1. Create a structured communication plan that allows for continuous communication with the integration management office, senior management, and the business functional heads.
      2. Outline key topics of communication, with stakeholders, inputs, and outputs for each topic.
      3. Review Info-Tech’s example communication plan in the M&A Sell Playbook and update it with relevant information.
      4. Does this communication plan make sense for your organization? What doesn’t make sense? Adjust the communication guide to suit your organization.

      Record the results in the M&A Sell Playbook.

      Assessing potential organizations

      As soon as you have identified organizations to consider, it’s imperative to assess critical risks. Most IT leaders can attest that they will receive little to no notice when the business is pursuing a sale and IT has to assess the IT organization. As a result, having a standardized template to quickly assess the potential acquiring organization is important.

      Ways to Assess

      1. News: Assess what sort of news has been announced in relation to the organization. Have they had any risk incidents? Has a critical vendor announced working with them?
      2. LinkedIn: Scan through the LinkedIn profiles of employees. This will give you a sense of what platforms they have based on employees. It will also give insight into positive or negative employee experiences that could impact retention.
      3. Trends: Some industries will have specific solutions that are relevant and popular. Assess what the key players are (if you don’t already know) to determine the solution.
      4. Business Architecture: While this assessment won’t perfect, try to understand the business’ value streams and the critical business and IT capabilities that would be needed to support them. Will your organization or employee skills be required to support these long term?

      Info-Tech Insight

      Assessing potential organizations is not just for the purchaser. The seller should also know what the purchasing organization’s history with M&As is and what potential risks could occur if remaining connected through ongoing SLAs.

      2.2.4 Assess the potential organization(s)

      1-2 hours

      Input: Publicized historical risk events, Solutions and vendor contracts likely in the works, Trends

      Output: IT’s valuation of the potential organization(s) for selling or divesting

      Materials: M&A Sell Playbook

      Participants: IT executive/CIO

      The purpose of this activity is to assess the organization(s) that your organization is considering selling or divesting to.

      1. Complete the Historical Valuation Worksheet in the M&A Sell Playbook to understand the type of IT organization that your company may support.
        • The business likely isn’t looking for in-depth details at this time. However, as the IT leader, it is your responsibility to ensure critical risks are identified and communicated to the business.
      2. Use the information identified to help the business narrow down which organizations could be the right organizations to sell or divest to.

      Record the results in the M&A Sell Playbook.

      By the end of this pre-transaction phase you should:

      Have a program plan for M&As and a repeatable M&A strategy for IT when engaging in reduction transactions

      Key outcomes from the Discovery & Strategy phase
      • Prepare the IT environment to support the potential sale or divestiture by identifying critical program plan elements and establishing a separation or carve-out strategy that will enable the business to reach its goals.
      • Create a M&A strategy that accounts for all the necessary elements of a transaction and ensures sufficient governance, capabilities, and metrics exist.
      Key deliverables from the Discovery & Strategy phase
      • Create vision and mission statements
      • Establish guiding principles
      • Create a future-state operating model
      • Identify the key roles for the transaction team
      • Identify and communicate the M&A governance
      • Determine target metrics
      • Identify the M&A operating model
      • Select the separation strategy framework
      • Conduct a RACI for key transaction tasks for the transaction team
      • Document the communication plan

      M&A Sell Blueprint

      Phase 3

      Due Diligence & Preparation

      Phase 1Phase 2

      Phase 3

      Phase 4
      • 1.1 Identify Stakeholders and Their Perspective of IT
      • 1.2 Assess IT’s Current Value and Future State
      • 1.3 Drive Innovation and Suggest Reduction Opportunities
      • 2.1 Establish the M&A Program Plan
      • 2.2 Prepare IT to Engage in the Separation or Sale
      • 3.1 Engage in Due Diligence and Prepare Staff
      • 3.2 Prepare to Separate
      • 4.1 Execute the Transaction
      • 4.2 Reflection and Value Realization

      This phase will walk you through the following activities:

      • Drive value with a due diligence charter
      • Gather data room artifacts
      • Measure staff engagement
      • Assess culture
      • Create a carve-out roadmap
      • Prioritize separation tasks
      • Establish the separation roadmap
      • Identify the buyer’s IT expectations
      • Create a service/transaction agreement
      • Estimate separation costs
      • Create an employee transition plan
      • Create functional workplans for employees
      • Align project metrics with identified tasks

      This phase involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Company M&A team
      • Business leaders
      • Purchasing organization
      • Transition team

      Workshop Overview

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      Pre-Work

      Day 1

      Day 2

      Day 3

      Day 4

      Day 5

      Establish the Transaction FoundationDiscover the Motivation for SeparationIdentify Expectations and Create the Carve-Out RoadmapPrepare and Manage EmployeesPlan the Separation RoadmapNext Steps and Wrap-Up (offsite)

      Activities

      • 0.1 Identify the rationale for the company's decision to pursue a divestiture/sale.
      • 0.2 Identify key stakeholders and determine the IT transaction team.
      • 0.3 Gather and evaluate the M&A strategy, future-state operating model, and governance.
      • 1.1 Review the business rationale for the divestiture/sale.
      • 1.2 Identify pain points and opportunities tied to the divestiture/sale.
      • 1.3 Establish the separation strategy.
      • 1.4 Create the due diligence charter.
      • 2.1 Identify the buyer’s IT expectations.
      • 2.2 Create a list of IT artifacts to be reviewed in the data room.
      • 2.3 Create a carve-out roadmap.
      • 2.4 Create a service/technical transaction agreement.
      • 3.1 Measure staff engagement.
      • 3.2 Assess the current culture and identify the goal culture.
      • 3.3 Create an employee transition plan.
      • 3.4 Create functional workplans for employees.
      • 4.1 Prioritize separation tasks.
      • 4.2 Establish the separation roadmap.
      • 4.3 Establish and align project metrics with identified tasks.
      • 4.4 Estimate separation costs.
      • 5.1 Complete in-progress deliverables from previous four days.
      • 5.2 Set up review time for workshop deliverables and to discuss next steps.

      Deliverables

      1. IT strategy
      2. IT operating model
      3. IT governance structure
      4. M&A transaction team
      1. Business context implications for IT
      2. Separation strategy
      3. Due diligence charter
      1. Data room artifacts identified
      2. Carve-out roadmap
      3. Service/technical transaction agreement
      1. Engagement assessment
      2. Culture assessment
      3. Employee transition plans and workplans
      1. Separation roadmap and associated resourcing
      1. Divestiture separation strategy for IT

      What is the Due Diligence & Preparation phase?

      Mid-transaction state

      The Due Diligence & Preparation phase during a sale or divestiture is a critical time for IT. If IT fails to proactively participate in this phase, IT will have to merely react to separation expectations set by the business.

      If your organization is being sold in its entirety, staff will have major concerns about their future in the new organization. Making this transition as smooth as possible and being transparent could go a long way in ensuring their success in the new organization.

      In a divestiture, this is the time to determine where it’s possible for the organization to divide or separate from itself. A lack of IT involvement in these conversations could lead to an overcommitment by the business and under-delivery by IT.

      Goal: To ensure that, as the selling or divesting organization, you comply with regulations, prepare staff for potential changes, and identify a separation strategy if necessary

      Due Diligence Prerequisite Checklist

      Before coming into the Due Diligence & Preparation phase, you must have addressed the following:

      • Understand the rationale for the company's decision to pursue a sale or divestiture and what opportunities or pain points the sale should alleviate.
      • Identify the key roles for the transaction team.
      • Identify the M&A governance.
      • Determine target metrics.
      • Select a separation strategy framework.
      • Conduct a RACI for key transaction tasks for the transaction team.

      Before coming into the Due Diligence & Preparation phase, we recommend addressing the following:

      • Create vision and mission statements.
      • Establish guiding principles.
      • Create a future-state operating model.
      • Identify the M&A operating model.
      • Document the communication plan.
      • Examine the business perspective of IT.
      • Identify key stakeholders and outline their relationship to the M&A process.
      • Be able to valuate the IT environment and communicate IT’s value to the business.

      The Technology Value Trinity

      Delivery of Business Value & Strategic Needs

      • Digital & Technology Strategy
        The identification of objectives and initiatives necessary to achieve business goals.
      • IT Operating Model
        The model for how IT is organized to deliver on business needs and strategies.
      • Information & Technology Governance
        The governance to ensure the organization and its customers get maximum value from the use of information and technology.

      All three elements of the Technology Value Trinity work in harmony to deliver business value and achieve strategic needs. As one changes, the others need to change as well.

      • Digital and IT Strategy tells you what you need to achieve to be successful.
      • IT Operating Model and Organizational Design is the alignment of resources to deliver on your strategy and priorities.
      • Information & Technology Governance is the confirmation of IT’s goals and strategy, which ensures the alignment of IT and business strategy. It’s the mechanism by which you continuously prioritize work to ensure that what is delivered is in line with the strategy. This oversight evaluates, directs, and monitors the delivery of outcomes to ensure that the use of resources results in the achieving the organization’s goals.

      Too often strategy, operating model and organizational design, and governance are considered separate practices. As a result, “strategic documents” end up being wish lists, and projects continue to be prioritized based on who shouts the loudest – not based on what is in the best interest of the organization.

      Due Diligence & Preparation

      Step 3.1

      Engage in Due Diligence and Prepare Staff

      Activities

      • 3.1.1 Drive value with a due diligence charter
      • 3.1.2 Gather data room artifacts
      • 3.1.3 Measure staff engagement
      • 3.1.4 Assess culture

      This step involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Company M&A team
      • Business leaders
      • Prospective IT organization
      • Transition team

      Outcomes of Step

      This step of the process is when IT should prepare and support the business in due diligence and gather the necessary information about staff changes.

      3.1.1 Drive value with a due diligence charter

      1-2 hours

      Input: Key roles for the transaction team, M&A governance, Target metrics, Selected separation strategy framework, RACI of key transaction tasks for the transaction team

      Output: IT Due Diligence Charter

      Materials: M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to create a charter leveraging the items completed in the previous phase, as listed on the Due Diligence Prerequisite Checklist slide, to gain executive sign-off.

      1. In the IT Due Diligence Charter in the M&A Sell Playbook, complete the aspects of the charter that are relevant for you and your organization.
      2. We recommend including these items in the charter:
        • Communication plan
        • Transition team roles
        • Goals and metrics for the transaction
        • Separation strategy
        • Sale/divestiture RACI
      3. Once the charter has been completed, ensure that business executives agree to the charter and sign off on the plan of action.

      Record the results in the M&A Sell Playbook.

      3.1.2 Gather data room artifacts

      4 hours

      Input: Future-state operating model, M&A governance, Target metrics, Selected separation strategy framework, RACI of key transaction tasks for the transaction team

      Output: List of items to acquire and verify can be provided to the purchasing organization while in the data room

      Materials: Critical domain lists on following slides, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team, Transition team, Legal team, Compliance/privacy officers

      The purpose of this activity is to create a list of the key artifacts that you could be asked for during the due diligence process.

      1. Review the lists on the following pages as a starting point. Identify which domains, stakeholders, artifacts, and information should be requested for the data room.
      2. IT leadership may or may not be asked to enter the data room directly. The short notice for having to find these artifacts for the purchasing organization can leave your IT organization scrambling. Identify the critical items worth obtaining ahead of time.
      3. Once you have identified the artifacts, provide the list to the legal team or compliance/privacy officers and ensure they also agree those items can be provided. If changes to the documents need to be made, take the time to do so.
      4. Store all items in a safe and secure file or provide to the M&A team ahead of due diligence.

      **Note that if your organization is not leading/initiating the data room, then you can ignore this activity.

      Record the results in the M&A Sell Playbook.

      Critical domains

      Understand the key stakeholders and outputs for each domain

      Domain

      Stakeholders

      Key Artifacts

      Key Information to request

      Business
      • Enterprise Architecture
      • Business Relationship Manager
      • Business Process Owners
      • Business capability map
      • Capability map (the M&A team should be taking care of this, but make sure it exists)
      • Business satisfaction with various IT systems and services
      Leadership/IT Executive
      • CIO
      • CTO
      • CISO
      • IT budgets
      • IT capital and operating budgets (from current year and previous year)
      Data & Analytics
      • Chief Data Officer
      • Data Architect
      • Enterprise Architect
      • Master data domains, system of record for each
      • Unstructured data retention requirements
      • Data architecture
      • Master data domains, sources, and storage
      • Data retention requirements
      Applications
      • Applications Manager
      • Application Portfolio Manager
      • Application Architect
      • Applications map
      • Applications inventory
      • Applications architecture
      • Copy of all software license agreements
      • Copy of all software maintenance agreements
      Infrastructure
      • Head of Infrastructure
      • Enterprise Architect
      • Infrastructure Architect
      • Infrastructure Manager
      • Infrastructure map
      • Infrastructure inventory
      • Network architecture (including which data centers host which infrastructure and applications)
      • Inventory (including separation capabilities of vendors, versions, switches, and routers)
      • Copy of all hardware lease or purchase agreements
      • Copy of all hardware maintenance agreements
      • Copy of all outsourcing/external service provider agreements
      • Copy of all service-level agreements for centrally provided, shared services and systems
      Products and Services
      • Product Manager
      • Head of Customer Interactions
      • Product lifecycle
      • Product inventory
      • Customer market strategy

      Critical domains (continued)

      Understand the key stakeholders and outputs for each domain

      Domain

      Stakeholders

      Key Artifacts

      Key Information to request

      Operations
      • Head of Operations
      • Service catalog
      • Service overview
      • Service owners
      • Access policies and procedures
      • Availability and service levels
      • Support policies and procedures
      • Costs and approvals (internal and customer costs)
      IT Processes
      • CIO
      • IT Management
      • VP of IT Governance
      • VP of IT Strategy
      • IT process flow diagram
      • Processes in place and productivity levels (capacity)
      • Critical processes/processes the organization feels they do particularly well
      IT People
      • CIO
      • VP of Human Resources
      • IT organizational chart
      • Competency & capacity assessment
      • IT organizational structure (including resources from external service providers such as contractors) with appropriate job descriptions or roles and responsibilities
      • IT headcount and location
      Security
      • CISO
      • Security Architect
      • Security posture
      • Information security staff
      • Information security service providers
      • Information security tools
      • In-flight information security projects
      Projects
      • Head of Projects
      • Project portfolio
      • List of all future, ongoing, and recently completed projects
      Vendors
      • Head of Vendor Management
      • License inventory
      • Inventory (including what will and will not be transitioning, vendors, versions, number of licenses)

      Retain top talent throughout the transition

      Focus on retention and engagement

      • People are such a critical component of this process, especially in the selling organization.
      • Retaining employees, especially the critical employees who hold specific skills or knowledge, will ensure the success and longevity of the divesting organization, purchasing organization, or the new company.
      • Giving employees a role in the organization and ensuring they do not see their capabilities as redundant will be critical to the process.
      • It is okay if employees need to change what they were doing temporarily or even long-term. However, being transparent about these changes and highlighting their value to the process and organization(s) will help.
      • The first step to moving forward with retention is to look at the baseline engagement and culture of employees and the organization. This will help determine where to focus and allow you to identify changes in engagement that resulted from the transaction.
      • Job engagement drivers are levers that influence the engagement of employees in their day-to-day roles.
      • Organizational engagement drivers are levers that influence an employee’s engagement with the broader organization.
      • Retention drivers are employment needs. They don’t necessarily drive engagement, but they must be met for engagement to be possible.

      3.1.3 Measure staff engagement

      3-4 hours

      Input: Engagement survey

      Output: Baseline engagement scores

      Materials: Build an IT Employee Engagement Program

      Participants: IT executive/CIO, IT senior leadership, IT employees of current organization

      The purpose of this activity is to measure current staff engagement to have a baseline to measure against in the future state. This is a good activity to complete if you will be divesting or selling in entirety.

      The results from the survey should act as a baseline to determine what the organization is doing well in terms of employee engagement and what drivers could be improved upon.

      1. Review Info-Tech’s Build an IT Employee Engagement Program research and select a survey that will best meet your needs.
      2. Conduct the survey and note which drivers employees are currently satisfied with. Likewise, note where there are opportunities.
      3. Document actions that should be taken to mitigate the negative engagement drivers throughout the transaction and enhance or maintain the positive engagement drivers.

      Record the results in the M&A Sell Playbook.

      Assess culture as a part of engagement

      Culture should not be overlooked, especially as it relates to the separation of IT environments

      • There are three types of culture that need to be considered.
      • Most importantly, this transition is an opportunity to change the culture that might exist in your organization’s IT environment.
      • Make a decision on which type of culture you’d like IT to have post transition.

      Target Organization's Culture. The culture that the target organization is currently embracing. Their established and undefined governance practices will lend insight into this.

      Your Organization’s Culture. The culture that your organization is currently embracing. Examine people’s attitudes and behaviors within IT toward their jobs and the organization.

      Ideal Culture. What will the future culture of the IT organization be once separation is complete? Are there aspects that your current organization and the target organization embrace that are worth considering?

      Culture categories

      Map the results of the IT Culture Diagnostic to an existing framework

      Competitive
      • Autonomy
      • Confront conflict directly
      • Decisive
      • Competitive
      • Achievement oriented
      • Results oriented
      • High performance expectations
      • Aggressive
      • High pay for good performance
      • Working long hours
      • Having a good reputation
      • Being distinctive/different
      Innovative
      • Adaptable
      • Innovative
      • Quick to take advantage of opportunities
      • Risk taking
      • Opportunities for professional growth
      • Not constrained by rules
      • Tolerant
      • Informal
      • Enthusiastic
      Traditional
      • Stability
      • Reflective
      • Rule oriented
      • Analytical
      • High attention to detail
      • Organized
      • Clear guiding philosophy
      • Security of employment
      • Emphasis on quality
      • Focus on safety
      Cooperative
      • Team oriented
      • Fair
      • Praise for good performance
      • Supportive
      • Calm
      • Developing friends at work
      • Socially responsible

      Culture Considerations

      • What culture category was dominant for each IT organization?
      • Do you share the same dominant category?
      • Is your current dominant culture category the most ideal to have post-separation?

      3.1.4 Assess Culture

      3-4 hours

      Input: Cultural assessments for current IT organization, Cultural assessment for target IT organization

      Output: Goal for IT culture

      Materials: IT Culture Diagnostic

      Participants: IT executive/CIO, IT senior leadership, IT employees of current organization, IT employees of target organization, Company M&A team

      The purpose of this activity is to assess the different cultures that might exist within the IT environments of the organizations involved. By understanding the culture that exists in the purchasing organization, you can identify the fit and prepare impacted staff for potential changes.

      1. Complete this activity by leveraging the blueprint Fix Your IT Culture, specifically the IT Culture Diagnostic.
      2. Fill out the diagnostic for the IT department in your organization:
        1. Answer the 16 questions in tab 2, Diagnostic.
        2. Find out your dominant culture and review recommendations in tab 3, Results.
      3. Document the results from tab 3, Results, in the M&A Sell Playbook if you are trying to record all artifacts related to the transaction in one place.
      4. Repeat the activity for the purchasing organization.
      5. Leverage the information to determine what the goal for the culture of IT will be post-separation if it will differ from the current culture.

      Record the results in the M&A Sell Playbook.

      Due Diligence & Preparation

      Step 3.2

      Prepare to Separate

      Activities

      • 3.2.1 Create a carve-out roadmap
      • 3.2.2 Prioritize separation tasks
      • 3.2.3 Establish the separation roadmap
      • 3.2.4 Identify the buyer’s IT expectations
      • 3.2.5 Create a service/transaction agreement
      • 3.2.6 Estimate separation costs
      • 3.2.7 Create an employee transition plan
      • 3.2.8 Create functional workplans for employees
      • 3.2.9 Align project metrics with identified tasks

      This step involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Transition team
      • Company M&A team
      • Purchasing organization

      Outcomes of Step

      Have an established plan of action toward separation across all domains and a strategy toward resources.

      Don’t underestimate the importance of separation preparation

      Separation involves taking the IT organization and dividing it into two or more separate entities.

      Testing the carve capabilities of the IT organization often takes 3 months. (Source: Cognizant, 2014)

      Daimler-Benz lost nearly $19 billion following its purchase of Chrysler by failing to recognize the cultural differences that existed between the two car companies. (Source: Deal Room)

      Info-Tech Insight

      Separating the IT organization requires more time and effort than business leaders will know. Frequently communicate challenges and lost opportunities when carving the IT environment out.

      Separation needs

      Identify the business objectives of the sale to determine the IT strategy

      Set up a meeting with your IT due diligence team to:

      • Ensure there will be no gaps in the delivery of products and services in the future state.
      • Discuss the people and processes necessary to achieve the target technology environment and support M&A business objectives.

      Use this opportunity to:

      • Identify data and application complexities between the involved organizations.
      • Identify the IT people and process gaps, initiatives, and levels of support expected.
      • Determine your infrastructure needs to ensure effectiveness and delivery of services:
        • Does IT have the infrastructure to support the applications and business capabilities?
        • Identify any gaps between the current infrastructure in both organizations and the infrastructure required.
        • Identify any redundancies/gaps.
        • Determine the appropriate IT separation strategies.
      • Document your gaps, redundancies, initiatives, and assumptions to help you track and justify the initiatives that must be undertaken and help estimate the cost of separation.

      Separation strategies

      There are several IT separation strategies that will let you achieve your target technology environment.

      IT Separation Strategies
      • Divest. Carve out elements of the IT organization and sell them to a purchasing organization with or without a service-level agreement.
      • Sell. Sell the entire IT environment to a purchasing organization. The purchasing organization takes full responsibility in delivering and running the IT environment.
      • Spin-Off Joint Venture. Carve out elements of the IT organization and combine them with elements of a new or purchasing organization to create a new entity.

      The approach IT takes will depend on the business objectives for the M&A.

      • Generally speaking, the separation strategy is well understood and influenced by the frequency of and rationale for selling.
      • Based on the initiatives generated by each business process owner, you need to determine the IT separation strategy that will best support the desired target technology environment, especially if you are still operating or servicing elements of that IT environment.

      Key considerations when choosing an IT separation strategy include:

      • What are the main business objectives of the M&A?
      • What are the key synergies expected from the transaction?
      • What IT separation strategy best helps obtain these benefits?
      • What opportunities exist to position the business for sustainable and long-term growth?

      Separation strategies in detail

      Review highlights and drawbacks of different separation strategies

      Divest
        Highlights
      • Recommended for businesses striving to reduce costs and potentially even generate revenue for the business through the delivery of SLAs.
      • Opportunity to reduce or scale back on lines of business or products that are not driving profits.
        Drawbacks
      • May be forced to give up critical staff that have been known to deliver high value.
      • The IT department is left to deliver services to the purchasing organization with little support or consideration from the business.
      • There can be increased risk and security concerns that need to be addressed.
      Sell
        Highlights
      • Recommended for businesses looking to gain capital to exit the market profitably or to enter a new market with a large sum of capital.
      • The business will no longer exist, and as a result all operational costs, including IT, will become redundant.
        Drawbacks
      • IT is no longer needed as an operating or capital service for the organization.
      • Lost resources, including highly trained and critical staff.
      • May require packaging employees off and using the profit or capital generated to cover any closing costs.
      Spin-Off or Joint Venture
        Highlights
      • Recommended for businesses looking to expand their market presence or acquire new products. Essentially aligning the two organizations in the same market.
      • Each side has a unique offering but complementing capabilities.
        Drawbacks
      • As much as the organization is going through a separation from the original company, it will be going through an integration with the new company.
      • There could be differences in culture.
      • This could require a large amount of investment without a guarantee of profit or success.

      Preparing the carve-out roadmap

      And why it matters so much

      • When carving out the IT environment in preparation for a divestiture, it’s important to understand the infrastructure, application, and data connections that might exist.
      • Much to the business’ surprise, carving out the IT environment is not easy, especially when considering the services and products that might depend on access to certain applications or data sets.
      • Once the business has indicated which elements they anticipate divesting, be prepared for testing the functionality and ability of this carve-out, either through automation or manually. There are benefits and drawbacks to both methods:
        • Automated requires a solution and a developer to code the tests.
        • Manual requires time to find the errors, possibly more time than automated testing.
      • Identify if there are dependencies that will make the carve-out difficult.
        • For example, the business is trying to divest Product X, but that product is integrated with Product Y, which is not being sold.
        • Consider all the processes and products that specific data might support as well.
        • Moreover, the data migration tool will need to enter the ERP system and identify not just the data but all supporting and historical elements that underlie the data.

      Critical components to consider:

      • Selecting manual or automated testing
      • Determining data dependencies
      • Data migration capabilities
      • Auditing approval
      • People and skills that support specific elements being carved out

      3.2.1 Create a carve-out roadmap

      6 hours

      Input: Items included in the carve-out, Dependencies, Whether testing is completed, If the carve-out will pass audit, If the carve-out item is prepared to be separated

      Output: Carve-out roadmap

      Materials: Business’ divestiture plan, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Business leaders, Transition team

      The purpose of this activity is to prepare the IT environment by identifying a carve-out roadmap, specifically looking at data, infrastructure, and applications. Feel free to expand the roadmap to include other categories as your organization sees fit.

      1. In the Carve-Out Roadmap in the M&A Sell Playbook, identify the key elements of the carve-out in the first column.
      2. Note any dependencies the items might have. For example:
        • The business is selling Product X, which is linked to Data X and Data Y. The organization does not want to sell Data Y. Data X would be considered dependent on Data Y.
      3. Once the dependencies have been confirmed, begin automated or manual testing to examine the possibility of separating the data sets (or other dependencies) from one another.
      4. After identifying an acceptable method of separation, inform the auditing individual or body and confirm that there would be no repercussions for the planned process.

      Record the results in the M&A Sell Playbook.

      3.2.2 Prioritize separation tasks

      2 hours

      Input: Separation tasks, Transition team, M&A RACI

      Output: Prioritized separation list

      Materials: Separation task checklist, Separation roadmap

      Participants: IT executive/CIO, IT senior leadership, Company M&A team

      The purpose of this activity is to prioritize the different separation tasks that your organization has identified as necessary to this transaction. Some tasks might not be relevant for this particular transaction, and others might be critical.

      1. Begin by downloading the SharePoint or Excel version of the M&A Separation Project Management Tool.
      2. Identify which separation tasks you want to have as part of your project plan. Alter or remove any tasks that are irrelevant to your organization. Add in tasks you think are missing.
      3. When deciding criticality of the task, consider the effect on stakeholders, those who are impacted or influenced in the process of the task, and dependencies (e.g. data strategy needs to be addressed first before you can tackle its dependencies, like data quality).
      4. Feel free to edit the way you measure criticality. The standard tool leverages a three-point scale. At the end, you should have a list of tasks in priority order based on criticality.

      Record the updates in the M&A Separation Project Management Tool (SharePoint).

      Record the updates in the M&A Separation Project Management Tool (Excel).

      Separation checklists

      Prerequisite Checklist
      • Build the project plan for separation and prioritize activities
        • Plan first day
        • Plan first 30/100 days
        • Plan first year
      • Create an organization-aligned IT strategy
      • Identify critical stakeholders
      • Create a communication strategy
      • Understand the rationale for the sale or divestiture
      • Develop IT's sale/divestiture strategy
        • Determine goal opportunities
        • Create the mission and vision statements
        • Create the guiding principles
        • Create program metrics
      • Consolidate reports from due diligence/data room
      • Conduct culture assessment
      • Create a transaction team
      • Establish a service/technical transaction agreement
      • Plan and communicate culture changes
      • Create an employee transition plan
      • Assess baseline engagement
      Business
      • Design an enterprise architecture
      • Document your business architecture
      • Meet compliance and regulatory standards
      • Identify and assess all of IT's risks
      Applications
      • Prioritize and address critical applications
        • CRM
        • HRIS
        • Financial
        • Sales
        • Risk
        • Security
        • ERP
        • Email
      • Develop method of separating applications
      • Model critical applications that have dependencies on one another
      • Identify the infrastructure capacity required to support critical applications
      • Prioritize and address critical applications
      Leadership/IT Executive
      • Build an IT budget
      • Structure operating budget
      • Structure capital budget
      • Identify the workforce demand vs. capacity
      • Establish and monitor key metrics
      • Communicate value realized/cost savings
      Data
      • Confirm data strategy
      • Confirm data governance
      • Build a data architecture roadmap
      • Analyze data sources and domains
      • Evaluate data storage (on-premises vs. cloud)
      • Develop an enterprise content management strategy and roadmap
      • Ensure cleanliness/usability of data sets
      • Identify data sets that can remain operational if reduced/separated
      • Develop reporting and analytics capabilities
      • Confirm data strategy
      Operations
      • Manage sales access to customer data
      • Determine locations and hours of operation
      • Separate/terminate phone lists and extensions
      • Split email address books
      • Communicate helpdesk/service desk information

      Separation checklists (continued)

      Infrastructure
      • Manage organization domains
      • Consolidate data centers
      • Compile inventory of vendors, versions, switches, and routers
      • Review hardware lease or purchase agreements
      • Review outsourcing/service provider agreements
      • Review service-level agreements
      • Assess connectivity linkages between locations
      • Plan to migrate to a single email system if necessary
      • Determine network access concerns
      Vendors
      • Establish a sustainable vendor management office
      • Review vendor landscape
      • Identify warranty options
      • Identify the licensing grant
      • Rationalize vendor services and solutions
      People
      • Design an IT operating model
      • Design your future IT organizational structure
      • Conduct a RACI for prioritized activities
      • Conduct a culture assessment and identify goal IT culture
      • Build an IT employee engagement program
      • Determine critical roles and systems/process/products they support
      • Define new job descriptions with meaningful roles and responsibilities
      • Create employee transition plans
      • Create functional workplans
      Projects
      • Identify projects to be on hold
      • Communicate project intake process
      • Reprioritize projects
      Products & Services
      • Redefine service catalog
      • Ensure customer interaction requirements are met
      • Select a solution for product lifecycle management
      • Plan service-level agreements
      Security
      • Conduct a security assessment
      • Develop accessibility prioritization and schedule
      • Establish an information security strategy
      • Develop a security awareness and training program
      • Develop and manage security governance, risk, and compliance
      • Identify security budget
      • Build a data privacy and classification program
      IT Processes
      • Evaluate current process models
      • Determine productivity/capacity levels of processes
      • Identify processes to be changed/terminated
      • Establish a communication plan
      • Develop a change management process
      • Establish/review IT policies
      • Evaluate current process models

      3.2.2 Establish the separation roadmap

      2 hours

      Input: Prioritized separation tasks, Carve-out roadmap, Employee transition plan, Separation RACI, Costs for activities, Activity owners

      Output: Separation roadmap

      Materials: M&A Separation Project Plan Tool (SharePoint), M&A Separation Project Plan Tool (Excel), SharePoint Template: Step-by-Step Deployment Guide

      Participants: IT executive/CIO, IT senior leadership, Transition team, Company M&A team

      The purpose of this activity is to create a roadmap to support IT throughout the separation process. Using the information gathered in previous activities, you can create a roadmap that will ensure a smooth separation.

      1. Use our Separation Project Management Tool to help track critical elements in relation to the separation project. There are a few options available:
        1. Follow the instructions on the next slide if you are looking to upload our SharePoint project template. Additional instructions are available in the SharePoint Template Step-by-Step Deployment Guide.
        2. If you cannot or do not want to use SharePoint as your project management solution, download our Excel version of the tool.
          **Remember that this your tool, so customize to your liking.
      2. Identify who will own or be accountable for each of the separation tasks and establish the time frame for when each project should begin and end. This will confirm which tasks should be prioritized.

      Record the updates in the M&A Separation Project Management Tool (SharePoint).

      Record the updates in the M&A Separation Project Management Tool (Excel).

      Separation Project Management Tool (SharePoint Template)

      Follow these instructions to upload our template to your SharePoint environment

      1. Create or use an existing SP site.
      2. Download the M&A Separation Project Management Tool (SharePoint) .wsp file from the Mergers & Acquisitions: The Sell Blueprint landing page.
      3. To import a template into your SharePoint environment, do the following:
        1. Open PowerShell.
        2. Connect-SPO Service (need to install PowerShell module).
        3. Enter in your tenant admin URL.
        4. Enter in your admin credentials.
        5. Set-SPO Site https://YourDomain.sharepoint.com/sites/YourSiteHe... -DenyAddAndCustomizePages 0
        OR
        1. Turn on both custom script features to allow users to run custom
      4. Screenshot of the 'Custom Script' option for importing a template into your SharePoint environment. Feature description reads 'Control whether users can run custom script on personal sites and self-service created sites. Note: changes to this setting might take up to 24 hours to take effect. For more information, see http://go.microsoft.com/fwlink/?LinkIn=397546'. There are options to prevent or allow users from running custom script on personal/self-service created sites.
      5. Enable the SharePoint Server feature.
      6. Upload the .wsp file in Solutions Gallery.
      7. Deploy by creating a subsite and select from custom options.
        • Allow or prevent custom script
        • Security considerations of allowing custom script
        • Save, download, and upload a SharePoint site as a template
      8. Refer to Microsoft documentation to understand security considerations and what is and isn’t supported:

      For more information, check out the SharePoint Template: Step-by-Step Deployment Guide.

      Supporting the transition and establishing service-level agreements

      The purpose of this part of the transition is to ensure both buyer and seller have a full understanding of expectations for after the transaction.

      • Once the organizations have decided to move forward with a deal, all parties need a clear level of agreement.
      • IT, since it is often seen as an operational division of an organization, is often expected to deliver certain services or products once the transaction has officially closed.
      • The purchasing organization or the new company might depend on IT to deliver these services until they are able to provide those services on their own.
      • Having a clear understanding of what the buyer’s expectations are and what your company, as the selling organization, can provide is important.
      • Have a conversation with the buyer and document those expectations in a signed service agreement.

      3.2.4 Identify the buyer's IT expectations

      3-4 hours

      Input: Carve-out roadmap, Separation roadmap, Up-to-date version of the agreement

      Output: Buyer’s IT expectations

      Materials: Questions for meeting

      Participants: IT executive/CIO, IT senior leadership, Company M&A team, Purchasing company M&A team, Purchasing company IT leadership

      The purpose of this activity is to determine if the buyer has specific service expectations for your IT organization. By identifying, documenting, and agreeing on what services your IT organization will be responsible for, you can obtain a final agreement to protect you as the selling organization.

      1. Buyers should not assume certain services will be provided. Organize a meeting with IT leaders and the company M&A teams to determine what services will be provided.
      2. The next slide has a series of questions that you can start from. Ensure you get detailed information about each of the services.
      3. Once you fully understand the buyer’s IT expectations, create an SLA in the next activity and obtain sign-off from both organizations.

      Questions to ask the buyer

      1. What services would you like my IT organization to provide?
      2. How long do you anticipate those services will be provided to you?
      3. How do you expect your staff/employees to communicate requests or questions to my staff/employees?
      4. Are there certain days or times that you expect these services to be delivered?
      5. How many staff do you expect should be available to support you?
      6. What should be the acceptable response time on given service requests?
      7. When it comes to the services you require, what level of support should we provide?
      8. If a service requires escalation to Level 2 or Level 3 support, are we still expected to support this service? Or are we only Level 1 support?
      9. What preventative security methods does your organization have to protect our environment during this agreement period?

      3.2.5 Create a service/ transaction agreement

      6 hours

      Input: Buyer's expectations, Separation roadmap

      Output: SLA for the purchasing organization

      Materials: Service Catalog Internal Service Level Agreement Template, M&A Separation Project Plan Tool (SharePoint), M&A Separation Project Plan Tool (Excel)

      Participants: IT executive/CIO, IT senior leadership, Company M&A team, Purchasing company M&A team, Purchasing company IT leadership

      The purpose of this activity is to determine if the buyer has specific service expectations for your IT organization post-transaction that your IT organization is agreeing to provide.

      1. Document the expected services and the related details in a service-level agreement.
      2. Provide the SLA to the purchasing organization.
      3. Obtain sign-off from both organizations on the level of service that is expected of IT.
      4. Update the M&A Separation Project Management Tool Excel or SharePoint document to reflect any additional items that the purchasing organization identified.

      *For organizations being purchased in their entirety, this activity may not be relevant.

      Modify the Service Catalog Internal Service Level Agreement with the agreed-upon terms of the SLA.

      Importance of estimating separation costs

      Change is the key driver of separation costs

      Separation costs are dependent on the following:
      • Meeting synergy targets – whether that be cost saving or growth related.
        • Employee-related costs, licensing, and reconfiguration fees play a huge part in meeting synergy targets.
      • Adjustments related to compliance or regulations – especially if there are changes to legal entities, reporting requirements, or risk mitigation standards.
      • Governance or third party–related support required to ensure timelines are met and the separation is a success.
      Separation costs vary by industry type.
      • Certain industries may have separation costs made up of mostly one type, differing from other industries, due to the complexity and demands of the transaction. For example:
        • Healthcare separation costs are mostly driven by regulatory, safety, and quality standards, as well as consolidation of the research and development function.
        • Energy and Utilities tend to have the lowest separation costs due to most transactions occurring within the same sector rather than as cross-sector investments. For example, oil and gas transactions tend to be for oil fields and rigs (strategic fixed assets), which can easily be added to the buyer’s portfolio.

      Separation costs are more related to the degree of change required than the size of the transaction.

      3.2.6 Estimate separation costs

      3-4 hours

      Input: Separation tasks, Transition team, Valuation of current IT environment, Valuation of target IT environment, Outputs from data room, Technical debt, Employees

      Output: List of anticipated costs required to support IT separation

      Materials: Separation task checklist, Separation roadmap, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company M&A team, Transition team

      The purpose of this activity is to estimate the costs that will be associated with the separation. Identify and communicate a realistic figure to the larger M&A team within your company as early in the process as possible. This ensures that the funding required for the transaction is secured and budgeted for in the overarching transaction.

      1. On the associated slide in the M&A Sell Playbook, input:
        • Task
        • Domain
        • Cost type
        • Total cost amount
        • Level of certainty around the cost
      2. Provide a copy of the estimated costs to the company’s M&A team. Also provide any additional information identified earlier to help them understand the importance of those costs.

      Record the results in the M&A Sell Playbook.

      Employee transition planning

      Considering employee impact will be a huge component to ensure successful separation

      • Meet With Leadership
      • Plan Individual and Department Redeployment
      • Plan Individual and Department Layoffs
      • Monitor and Manage Departmental Effectiveness
      • For employees, the transition could mean:
        • Changing from their current role to a new role to meet requirements and expectations throughout the transition.
        • Being laid off because the role they are currently occupying has been made redundant.
      • It is important to plan for what the M&A separation needs will be and what the IT operational needs will be.
      • A lack of foresight into this long-term plan could lead to undue costs and headaches trying to retain critical staff, rehiring positions that were already let go, and keeping redundant employees longer then necessary.

      Info-Tech Insight

      Being transparent throughout the process is critical. Do not hesitate to tell employees the likelihood that their job may be made redundant. This will ensure a high level of trust and credibility for those who remain with the organization after the transaction.

      3.2.7 Create an employee transition plan

      3-4 hours

      Input: IT strategy, IT organizational design

      Output: Employee transition plans

      Materials: M&A Sell Playbook, Whiteboard, Sticky notes, Markers

      Participants: IT executive/CIO, IT senior leadership, Company M&A team, Transition team

      The purpose of this activity is to create a transition plan for employees.

      1. Transition planning can be done at specific individual levels or more broadly to reflect a single role. Consider these four items in the transition plan:
        • Understand the direction of the employee transitions.
        • Identify employees that will be involved in the transition (moved or laid off).
        • Prepare to meet with employees.
        • Meet with employees.
      2. For each employee that will be facing some sort of change in their regular role, permanent or temporary, create a transition plan.
      3. For additional information on transitioning employees, review the blueprint Streamline Your Workforce During a Pandemic.

      **Note that if someone’s future role is a layoff, then there is no need to record anything for skills needed or method for skill development.

      Record the results in the M&A Sell Playbook.

      3.2.8 Create functional workplans for employees

      3-4 hours

      Input: Prioritized separation tasks, Employee transition plan, Separation RACI, Costs for activities, Activity owners

      Output: Employee functional workplans

      Materials: M&A Sell Playbook, Learning and development tools

      Participants: IT executive/CIO, IT senior leadership, IT management team, Company M&A team, Transition team

      The purpose of this activity is to create a functional workplan for the different employees so that they know what their key role and responsibilities are once the transaction occurs.

      1. First complete the transition plan from the previous activity (3.2.7) and the separation roadmap. Have these documents ready to review throughout this process.
      2. Identify the employees who will be transitioning to a new role permanently or temporarily. Creating a functional workplan is especially important for these employees.
      3. Identify the skills these employees need to have to support the separation. Record this in the corresponding slide in the M&A Sell Playbook.
      4. For each employee, identify someone who will be a point of contact for them throughout the transition.

      It is recommended that each employee have a functional workplan. Leverage the IT managers to support this task.

      Record the results in the M&A Sell Playbook.

      Metrics for separation

      Valuation & Due Diligence

      • % Defects discovered in production
      • $ Cost per user for enterprise applications
      • % In-house-built applications vs. enterprise applications
      • % Owners identified for all data domains
      • # IT staff asked to participate in due diligence
      • Change to due diligence
      • IT budget variance
      • Synergy target

      Execution & Value Realization

      • % Satisfaction with the effectiveness of IT capabilities
      • % Overall end-customer satisfaction
      • $ Impact of vendor SLA breaches
      • $ Savings through cost-optimization efforts
      • $ Savings through application rationalization and technology standardization
      • # Key positions empty
      • % Frequency of staff turnover
      • % Emergency changes
      • # Hours of unplanned downtime
      • % Releases that cause downtime
      • % Incidents with identified problem record
      • % Problems with identified root cause
      • # Days from problem identification to root cause fix
      • % Projects that consider IT risk
      • % Incidents due to issues not addressed in the security plan
      • # Average vulnerability remediation time
      • % Application budget spent on new build/buy vs. maintenance (deferred feature implementation, enhancements, bug fixes)
      • # Time (days) to value realization
      • % Projects that realized planned benefits
      • $ IT operational savings and cost reductions that are related to synergies/divestitures
      • % IT staff–related expenses/redundancies
      • # Days spent on IT separation
      • $ Accurate IT budget estimates
      • % Revenue growth directly tied to IT delivery
      • % Profit margin growth

      3.2.9 Align project metrics with identified tasks

      3-4 hours

      Input: Prioritized separation tasks, Employee transition plan, Separation RACI, Costs for activities, Activity owners, M&A goals

      Output: Separation-specific metrics to measure success

      Materials: Separation roadmap, M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Transition team

      The purpose of this activity is to understand how to measure the success of the separation project by aligning metrics to each identified task.

      1. Review the M&A goals identified by the business. Your metrics will need to tie back to those business goals.
      2. Identify metrics that align to identified tasks and measure achievement of those goals. For each metric you consider, ask the following questions:
        • What is the main goal or objective that this metric is trying to solve?
        • What does success look like?
        • Does the metric promote the right behavior?
        • Is the metric actionable? What is the story you are trying to tell with this metric?
        • How often will this get measured?
        • Are there any metrics it supports or is supported by?

      Record the results in the M&A Sell Playbook.

      By the end of this mid-transaction phase you should:

      Have successfully evaluated your IT people, processes, and technology to determine a roadmap forward for separating or selling.

      Key outcomes from the Due Diligence & Preparation phase
      • Participate in due diligence activities to comply with regulatory and auditing standards and prepare employees for the transition.
      • Create a separation roadmap that considers the tasks that will need to be completed and the resources required to support separation.
      Key deliverables from the Due Diligence & Preparation phase
      • Drive value with a due diligence charter
      • Gather data room artifacts
      • Measure staff engagement
      • Assess culture
      • Create a carve-out roadmap
      • Prioritize separation tasks
      • Establish the separation roadmap
      • Identify the buyer’s IT expectations
      • Create a service/transaction agreement
      • Estimate separation costs
      • Create an employee transition plan
      • Create functional workplans for employees
      • Align project metrics with identified tasks

      M&A Sell Blueprint

      Phase 4

      Execution & Value Realization

      Phase 1Phase 2Phase 3

      Phase 4

      • 1.1 Identify Stakeholders and Their Perspective of IT
      • 1.2 Assess IT’s Current Value and Future State
      • 1.3 Drive Innovation and Suggest Reduction Opportunities
      • 2.1 Establish the M&A Program Plan
      • 2.2 Prepare IT to Engage in the Separation or Sale
      • 3.1 Engage in Due Diligence and Prepare Staff
      • 3.2 Prepare to Separate
      • 4.1 Execute the Transaction
      • 4.2 Reflection and Value Realization

      This phase will walk you through the following activities:

      • Monitor service agreements
      • Continually update the project plan
      • Confirm separation costs
      • Review IT’s transaction value
      • Conduct a transaction and separation SWOT
      • Review the playbook and prepare for future transactions

      This phase involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Vendor management team
      • IT transaction team
      • Company M&A team

      Workshop Overview

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      Pre-Work

      Day 1

      Day 2

      Day 3

      Engage in Separation

      Day 4

      Establish the Transaction FoundationDiscover the Motivation for IntegrationPlan the Separation RoadmapPrepare Employees for the TransitionEngage in SeparationAssess the Transaction Outcomes (Must be within 30 days of transaction date)

      Activities

      • 0.1 Identify the rationale for the company's decision to pursue a divestiture/sale.
      • 0.2 Identify key stakeholders and determine the IT transaction team.
      • 0.3 Gather and evaluate the M&A strategy, future-state operating model, and governance.
      • 1.1 Review the business rationale for the divestiture/sale.
      • 1.2 Identify pain points and opportunities tied to the divestiture/sale.
      • 1.3 Establish the separation strategy.
      • 1.4 Create the due diligence charter.
      • 2.1 Prioritize separation tasks.
      • 2.2 Establish the separation roadmap.
      • 2.3 Establish and align project metrics with identified tasks.
      • 2.4 Estimate separation costs.
      • 3.1 Measure staff engagement
      • 3.2 Assess the current culture and identify the goal culture.
      • 3.3 Create an employee transition plan.
      • 3.4 Create functional workplans for employees.
      • S.1 Complete the separation by regularly updating the project plan.
      • S.2 Assess the service/technical transaction agreement.
      • 4.1 Confirm separation costs.
      • 4.2 Review IT’s transaction value.
      • 4.3 Conduct a transaction and separation SWOT.
      • 4.4 Review the playbook and prepare for future transactions.

      Deliverables

      1. IT strategy
      2. IT operating model
      3. IT governance structure
      4. M&A transaction team
      1. Business context implications for IT
      2. Separation strategy
      3. Due diligence charter
      1. Separation roadmap and associated resourcing
      1. Engagement assessment
      2. Culture assessment
      3. Employee transition plans and workplans
      1. Evaluate service/technical transaction agreement
      2. Updated separation project plan
      1. SWOT of transaction
      2. M&A Sell Playbook refined for future transactions

      What is the Execution & Value Realization phase?

      Post-transaction state

      Once the transaction comes to a close, it’s time for IT to deliver on the critical separation tasks. As the selling organization in this transaction, you need to ensure you have a roadmap that properly enables the ongoing delivery of your IT environment while simultaneously delivering the necessary services to the purchasing organization.

      Throughout the separation transaction, some of the most common obstacles IT should prepare for include difficulty separating the IT environment, loss of key personnel, disengaged employees, and security/compliance issues.

      Post-transaction, the business needs to understands the value they received by engaging in the transaction and the ongoing revenue they might obtain as a result of the sale. You also need to ensure that the IT environment is functioning and mitigating any high-risk outcomes.

      Goal: To carry out the planned separation activities and deliver the intended value to the business.

      Execution Prerequisite Checklist

      Before coming into the Execution & Value Realization phase, you must have addressed the following:

      • Understand the rationale for the company's decisions to pursue a sale or divestiture and what opportunities or pain points the sale should alleviate.
      • Identify the key roles for the transaction team.
      • Identify the M&A governance.
      • Determine target metrics.
      • Select a separation strategy framework.
      • Conduct a RACI for key transaction tasks for the transaction team.
      • Create a carve-out roadmap.
      • Prioritize separation tasks.
      • Establish the separation roadmap.
      • Create employee transition plans.

      Before coming into the Execution & Value Realization phase, we recommend addressing the following:

      • Create vision and mission statements.
      • Establish guiding principles.
      • Create a future-state operating model.
      • Identify the M&A operating model.
      • Document the communication plan.
      • Examine the business perspective of IT.
      • Identify key stakeholders and outline their relationship to the M&A process.
      • Establish a due diligence charter.
      • Be able to valuate the IT environment and communicate IT’s value to the business.
      • Gather and present due diligence data room artifacts.
      • Measure staff engagement.
      • Assess and plan for culture.
      • Estimate separation costs.
      • Create functional workplans for employees.
      • Identify the buyer’s IT expectations.
      • Create a service/ transaction agreement.

      Separation checklists

      Prerequisite Checklist
      • Build the project plan for separation and prioritize activities
        • Plan first day
        • Plan first 30/100 days
        • Plan first year
      • Create an organization-aligned IT strategy
      • Identify critical stakeholders
      • Create a communication strategy
      • Understand the rationale for the sale or divestiture
      • Develop IT's sale/divestiture strategy
        • Determine goal opportunities
        • Create the mission and vision statements
        • Create the guiding principles
        • Create program metrics
      • Consolidate reports from due diligence/data room
      • Conduct culture assessment
      • Create a transaction team
      • Establish a service/technical transaction agreement
      • Plan and communicate culture changes
      • Create an employee transition plan
      • Assess baseline engagement
      Business
      • Design an enterprise architecture
      • Document your business architecture
      • Meet compliance and regulatory standards
      • Identify and assess all of IT's risks
      Applications
      • Prioritize and address critical applications
        • CRM
        • HRIS
        • Financial
        • Sales
        • Risk
        • Security
        • ERP
        • Email
      • Develop method of separating applications
      • Model critical applications that have dependencies on one another
      • Identify the infrastructure capacity required to support critical applications
      • Prioritize and address critical applications
      Leadership/IT Executive
      • Build an IT budget
      • Structure operating budget
      • Structure capital budget
      • Identify the workforce demand vs. capacity
      • Establish and monitor key metrics
      • Communicate value realized/cost savings
      Data
      • Confirm data strategy
      • Confirm data governance
      • Build a data architecture roadmap
      • Analyze data sources and domains
      • Evaluate data storage (on-premises vs. cloud)
      • Develop an enterprise content management strategy and roadmap
      • Ensure cleanliness/usability of data sets
      • Identify data sets that can remain operational if reduced/separated
      • Develop reporting and analytics capabilities
      • Confirm data strategy
      Operations
      • Manage sales access to customer data
      • Determine locations and hours of operation
      • Separate/terminate phone lists and extensions
      • Split email address books
      • Communicate helpdesk/service desk information

      Separation checklists (continued)

      Infrastructure
      • Manage organization domains
      • Consolidate data centers
      • Compile inventory of vendors, versions, switches, and routers
      • Review hardware lease or purchase agreements
      • Review outsourcing/service provider agreements
      • Review service-level agreements
      • Assess connectivity linkages between locations
      • Plan to migrate to a single email system if necessary
      • Determine network access concerns
      Vendors
      • Establish a sustainable vendor management office
      • Review vendor landscape
      • Identify warranty options
      • Identify the licensing grant
      • Rationalize vendor services and solutions
      People
      • Design an IT operating model
      • Design your future IT organizational structure
      • Conduct a RACI for prioritized activities
      • Conduct a culture assessment and identify goal IT culture
      • Build an IT employee engagement program
      • Determine critical roles and systems/process/products they support
      • Define new job descriptions with meaningful roles and responsibilities
      • Create employee transition plans
      • Create functional workplans
      Projects
      • Identify projects to be on hold
      • Communicate project intake process
      • Reprioritize projects
      Products & Services
      • Redefine service catalog
      • Ensure customer interaction requirements are met
      • Select a solution for product lifecycle management
      • Plan service-level agreements
      Security
      • Conduct a security assessment
      • Develop accessibility prioritization and schedule
      • Establish an information security strategy
      • Develop a security awareness and training program
      • Develop and manage security governance, risk, and compliance
      • Identify security budget
      • Build a data privacy and classification program
      IT Processes
      • Evaluate current process models
      • Determine productivity/capacity levels of processes
      • Identify processes to be changed/terminated
      • Establish a communication plan
      • Develop a change management process
      • Establish/review IT policies
      • Evaluate current process models

      Execution & Value Realization

      Step 4.1

      Execute the Transaction

      Activities

      • 4.1.1 Monitor service agreements
      • 4.1.2 Continually update the project plan

      This step will walk you through the following activities:

      • Monitor service agreements
      • Continually update the project plan

      This step involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Vendor management team
      • IT transaction team
      • Company M&A team

      Outcomes of Step

      Successfully execute the separation of the IT environments and update the project plan, strategizing against any roadblocks as they come.

      Key concerns to monitor during separation

      If you are entering the transaction at this point, consider and monitor the following three items above all else.

      Your IT environment, reputation as an IT leader, and impact on key staff will depend on monitoring these aspects.

      • Risk & Security. Make sure that the channels of communication between the purchasing organization and your IT environment are properly determined and protected. This might include updating or removing employees’ access to certain programs.
      • Retaining Employees. Employees who do not see a path forward in the organization or who feel that their skills are being underused will be quick to move on. Make sure they are engaged before, during, and after the transaction to avoid losing employees.
      • IT Environment Dependencies. Testing the IT environment several times and obtaining sign-off from auditors that this has been completed correctly should be completed well before the transaction occurs. Have a strong architecture outlining technical dependencies.

      For more information, review:

      • Reduce and Manage Your Organization’s Insider Threat Risk
      • Map Technical Skills for a Changing Infrastructure Operations Organization
      • Build a Data Architecture Roadmap

      4.1.1 Monitor service agreements

      3-6 months

      Input: Original service agreement, Risk register

      Output: Service agreement confirmed

      Materials: Original service agreement

      Participants: IT executive/CIO, IT senior leadership, External organization IT senior leadership

      The purpose of this activity is to monitor the established service agreements on an ongoing basis. Your organization is most at risk during the initial months following the transaction.

      1. Ensure the right controls exist to prevent the organization from unnecessarily opening itself up to risks.
      2. Meet with the purchasing organization/subsidiary three months after the transaction to ensure that everyone is satisfied with the level of services provided.
      3. This is not a quick and completed activity, but one that requires ongoing monitoring. Repeatedly identify potential risks worth mitigating.

      For additional information and support for this activity, see the blueprint Build an IT Risk Management Program.

      4.1.2 Continually update the project plan

      Reoccurring basis following transition

      Input: Prioritized separation tasks, Separation RACI, Activity owners

      Output: Updated separation project plan

      Materials: M&A Separation Project Plan Tool (SharePoint), M&A Separation Project Plan Tool (Excel)

      Participants: IT executive/CIO, IT senior leadership, IT transaction team, Company M&A team

      The purpose of this activity is to ensure that the project plan is continuously updated as your transaction team continues to execute on the various components outlined in the project plan.

      1. Set a regular cadence for the transaction team to meet, update the project plan, review the status of the various separation task items, and strategize how to overcome any roadblocks.
      2. Employ governance best practices in these meetings to ensure decisions can be made effectively and resources allocated strategically.

      Record the updates in the M&A Separation Project Management Tool (SharePoint).

      Record the updates in the M&A Separation Project Management Tool (Excel).

      Execution & Value Realization

      Step 4.2

      Reflection and Value Realization

      Activities

      • 4.2.1 Confirm separation costs
      • 4.2.2 Review IT’s transaction value
      • 4.2.3 Conduct a transaction and separation SWOT
      • 4.2.4 Review the playbook and prepare for future transactions

      This step involves the following participants:

      • IT executive/CIO
      • IT senior leadership
      • Transition team
      • Company M&A team

      Outcomes of Step

      Review the value that IT was able to generate around the transaction and strategize about how to improve future selling or separating transactions.

      4.2.1 Confirm separation costs

      3-4 hours

      Input: Separation tasks, Carve-out roadmap, Transition team, Previous RACI, Estimated separation costs

      Output: Actual separation costs

      Materials: M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Transaction team, Company M&A team

      The purpose of this activity is to confirm the associated costs around separation. While the separation costs would have been estimated previously, it’s important to confirm the costs that were associated with the separation in order to provide an accurate and up-to-date report to the company’s M&A team.

      1. Taking all the original items identified previously in activity 3.2.6, identify if there were changes in the estimated costs. This can be an increase or a decrease.
      2. Ensure that each cost has a justification for why the cost changed from the original estimation.

      Record the results in the M&A Sell Playbook.

      Track cost savings and revenue generation

      Throughout the transaction, the business would have communicated its goals, rationales, and expectations for the transaction. Sometimes this is done explicitly, and other times the information is implicit. Either way, IT needs to ensure that metrics have been defined and are measuring the intended value that the business expects. Ensure that the benefits realized to the organization are being communicated regularly and frequently.

      1. Define Metrics: Select metrics to track synergies through the separation.
        1. You can track value by looking at percentages of improvement in process-level metrics depending on the savings or revenue being pursued.
        2. For example, if the value being pursued is decreasing costs, metrics could range from capacity to output, highlighting that the output remains high despite smaller IT environments.
      2. Prioritize Value-Driving Initiatives: Estimate the cost and benefit of each initiative's implementation to compare the amount of business value to the cost. The benefits and costs should be illustrated at a high level. Estimating the exact dollar value of fulfilling a synergy can be difficult and misleading.
          Steps
        • Determine the benefits that each initiative is expected to deliver.
        • Determine the high-level costs of implementation (capacity, time, resources, effort).
      3. Track Cost Savings and Revenue Generation: Develop a detailed workplan to resource the roadmap and track where costs are saved and revenue is generated as the initiatives are undertaken.

      4.2.2 Review IT’s transaction value

      3-4 hours

      Input: Prioritized separation tasks, Separation RACI, Activity owners, M&A company goals

      Output: Transaction value

      Materials: M&A Sell Playbook

      Participants: IT executive/CIO, IT senior leadership, Company's M&A team

      The purpose of this activity is to track how your IT organization performed against the originally identified metrics.

      1. If your organization did not have the opportunity to identify metrics, determine from the company M&A what those metrics might be. Review activity 3.2.9 for more information on metrics.
      2. Identify whether the metric (which should support a goal) was at, below, or above the original target metric. This is a very critical task for IT to complete because it allows IT to confirm that they were successful in the transaction and that the business can count on them in future transactions.
      3. Be sure to record accurate and relevant information on why the outcomes (good or bad) are supporting the M&A goals set out by the business.

      Record the results in the M&A Sell Playbook.

      4.2.3 Conduct a transaction and separation SWOT

      2 hours

      Input: Separation costs, Retention rates, Value that IT contributed to the transaction

      Output: Strengths, weaknesses, opportunities, and threats

      Materials: Flip charts, Markers, Sticky notes

      Participants: IT executive/CIO, IT senior leadership, Business transaction team

      The purpose of this activity is to assess the positive and negative elements of the transaction.

      1. Consider the internal and external elements that could have impacted the outcome of the transaction.
        • Strengths. Internal characteristics that are favorable as they relate to your development environment.
        • Weaknesses Internal characteristics that are unfavorable or need improvement.
        • Opportunities External characteristics that you may use to your advantage.
        • Threats External characteristics that may be potential sources of failure or risk.

      Record the results in the M&A Sell Playbook.

      M&A Sell Playbook review

      With an acquisition complete, your IT organization is now more prepared then ever to support the business through future M&As

      • Now that the transaction is more than 80% complete, take the opportunity to review the key elements that worked well and the opportunities for improvement.
      • Critically examine the M&A Sell Playbook your IT organization created and identify what worked well to help the transaction and where your organization could adjust to do better in future transactions.
      • If your organization were to engage in another sale or divestiture under your IT leadership, how would you go about the transaction to make sure the company meets its goals?

      4.2.4 Review the playbook and prepare for future transactions

      4 hours

      Input: Transaction and separation SWOT

      Output: Refined M&A playbook

      Materials: M&A Sell Playbook

      Participants: IT executive/CIO

      The purpose of this activity is to revise the playbook and ensure it is ready to go for future transactions.

      1. Using the outputs from the previous activity, 4.2.3, determine what strengths and opportunities there were that should be leveraged in the next transaction.
      2. Likewise, determine which threats and weaknesses could be avoided in the future transactions.
        Remember, this is your M&A Sell Playbook, and it should reflect the most successful outcome for you in your organization.

      Record the results in the M&A Sell Playbook.

      By the end of this post-transaction phase you should:

      Have completed the separation post-transaction and be fluidly delivering the critical value that the business expected of IT.

      Key outcomes from the Execution & Value Realization phase
      • Ensure the separation tasks are being completed and that any blockers related to the transaction are being removed.
      • Determine where IT was able to realize value for the business and demonstrate IT’s involvement in meeting target goals.
      Key deliverables from the Execution & Value Realization phase
      • Monitor service agreements
      • Continually update the project plan
      • Confirm separation costs
      • Review IT’s transaction value
      • Conduct a transaction and separation SWOT
      • Review the playbook and prepare for future transactions

      Summary of Accomplishment

      Problem Solved

      Congratulations, you have completed the M&A Sell Blueprint!

      Rather than reacting to a transaction, you have been proactive in tackling this initiative. You now have a process to fall back on in which you can be an innovative IT leader by suggesting how and why the business should engage in a separation or sale transaction. You have:

      • Created a standardized approach for how your IT organization should address divestitures or sales.
      • Retained critical staff and complied with any regulations throughout the transaction.
      • Delivered on the separation project plan successfully and communicated IT’s transaction value to the business.

      Now that you have done all of this, reflect on what went well and what can be improved if you were to engage in a similar divestiture or sale again.

      If you would like additional support, have our analysts guide you through other phases as part of an Info-Tech workshop.

      Contact your account representative for more information
      workshops@infotech.com 1-888-670-8899

      Research Contributors and Experts

      Ibrahim Abdel-Kader
      Research Analyst | CIO
      Info-Tech Research Group
      Brittany Lutes
      Senior Research Analyst | CIO
      Info-Tech Research Group
      John Annand
      Principal Research Director | Infrastructure
      Info-Tech Research Group
      Scott Bickley
      Principal Research Director | Vendor Management
      Info-Tech Research Group
      Cole Cioran
      Practice Lead | Applications
      Info-Tech Research Group
      Dana Daher
      Research Analyst | Strategy & Innovation
      Info-Tech Research Group
      Eric Dolinar
      Manager | M&A Consulting
      Deloitte Canada
      Christoph Egel
      Director, Solution Design & Deliver
      Cooper Tire & Rubber Company
      Nora Fisher
      Vice President | Executive Services Advisory
      Info-Tech Research Group
      Larry Fretz
      Vice President | Industry
      Info-Tech Research Group

      Research Contributors and Experts

      David Glazer
      Vice President of Analytics
      Kroll
      Jack Hakimian
      Senior Vice President | Workshops and Delivery
      Info-Tech Research Group
      Gord Harrison
      Senior Vice President | Research & Advisory
      Info-Tech Research Group
      Valence Howden
      Principal Research Director | CIO
      Info-Tech Research Group
      Jennifer Jones
      Research Director | Industry
      Info-Tech Research Group
      Nancy McCuaig
      Senior Vice President | Chief Technology and Data Office
      IGM Financial Inc.
      Carlene McCubbin
      Practice Lead | CIO
      Info-Tech Research Group
      Kenneth McGee
      Research Fellow | Strategy & Innovation
      Info-Tech Research Group
      Nayma Naser
      Associate
      Deloitte
      Andy Neill
      Practice Lead | Data & Analytics, Enterprise Architecture
      Info-Tech Research Group

      Research Contributors and Experts

      Rick Pittman
      Vice President | Research
      Info-Tech Research Group
      Rocco Rao
      Research Director | Industry
      Info-Tech Research Group
      Mark Rosa
      Senior Vice President & Chief Information Officer
      Mohegan Gaming and Entertainment
      Tracy-Lynn Reid
      Research Lead | People & Leadership
      Info-Tech Research Group
      Jim Robson
      Senior Vice President | Shared Enterprise Services (retired)
      Great-West Life
      Steven Schmidt
      Senior Managing Partner Advisory | Executive Services
      Info-Tech Research Group
      Nikki Seventikidis
      Senior Manager | Finance Initiative & Continuous Improvement
      CST Consultants Inc.
      Allison Straker
      Research Director | CIO
      Info-Tech Research Group
      Justin Waelz
      Senior Network & Systems Administrator
      Info-Tech Research Group
      Sallie Wright
      Executive Counselor
      Info-Tech Research Group

      Bibliography

      “5 Ways for CIOs to Accelerate Value During Mergers and Acquisitions.” Okta, n.d. Web.

      Altintepe, Hakan. “Mergers and acquisitions speed up digital transformation.” CIO.com, 27 July 2018. Web.

      “America’s elite law firms are booming.” The Economist, 15 July 2021. Web.

      Barbaglia, Pamela, and Joshua Franklin. “Global M&A sets Q1 record as dealmakers shape post-COVID world.” Nasdaq, 1 April 2021. Web.

      Boyce, Paul. “Mergers and Acquisitions Definition: Types, Advantages, and Disadvantages.” BoyceWire, 8 Oct. 2020. Web.

      Bradt, George. “83% Of Mergers Fail -- Leverage A 100-Day Action Plan For Success Instead.” Forbes, 27 Jan. 2015. Web.

      Capgemini. “Mergers and Acquisitions: Get CIOs, IT Leaders Involved Early.” Channel e2e, 19 June 2020. Web.

      Chandra, Sumit, et al. “Make Or Break: The Critical Role Of IT In Post-Merger Integration.” IMAA Institute, 2016. Web.

      Deloitte. “How to Calculate Technical Debt.” The Wall Street Journal, 21 Jan. 2015. Web.

      Ernst & Young. “IT As A Driver Of M&A Success.” IMAA Institute, 2017. Web.

      Fernandes, Nuno. “M&As In 2021: How To Improve The Odds Of A Successful Deal.” Forbes, 23 March 2021. Web.

      “Five steps to a better 'technology fit' in mergers and acquisitions.” BCS, 7 Nov. 2019. Web.

      Fricke, Pierre. “The Biggest Opportunity You’re Missing During an M&Aamp; IT Integration.” Rackspace, 4 Nov. 2020. Web.

      Garrison, David W. “Most Mergers Fail Because People Aren't Boxes.” Forbes, 24 June 2019. Web.

      Harroch, Richard. “What You Need To Know About Mergers & Acquisitions: 12 Key Considerations When Selling Your Company.” Forbes, 27 Aug. 2018. Web.

      Hope, Michele. “M&A Integration: New Ways To Contain The IT Cost Of Mergers, Acquisitions And Migrations.” Iron Mountain, n.d. Web.

      “How Agile Project Management Principles Can Modernize M&A.” Business.com, 13 April 2020. Web.

      Hull, Patrick. “Answer 4 Questions to Get a Great Mission Statement.” Forbes, 10 Jan. 2013. Web.

      Kanter, Rosabeth Moss. “What We Can Learn About Unity from Hostile Takeovers.” Harvard Business Review, 12 Nov. 2020. Web.

      Koller, Tim, et al. “Valuation: Measuring and Managing the Value of Companies, 7th edition.” McKinsey & Company, 2020. Web.

      Labate, John. “M&A Alternatives Take Center Stage: Survey.” The Wall Street Journal, 30 Oct. 2020. Web.

      Lerner, Maya Ber. “How to Calculate ROI on Infrastructure Automation.” DevOps.com, 1 July 2020. Web.

      Loten, Angus. “Companies Without a Tech Plan in M&A Deals Face Higher IT Costs.” The Wall Street Journal, 18 June 2019. Web.

      Low, Jia Jen. “Tackling the tech integration challenge of mergers today” Tech HQ, 6 Jan. 2020. Web.

      Lucas, Suzanne. “5 Reasons Turnover Should Scare You.” Inc. 22 March 2013. Web.

      “M&A Trends Survey: The future of M&A. Deal trends in a changing world.” Deloitte, Oct. 2020. Web.

      Maheshwari, Adi, and Manish Dabas. “Six strategies tech companies are using for successful divesting.” EY, 1 Aug. 2020. Web.

      Majaski, Christina. “Mergers and Acquisitions: What's the Difference?” Investopedia, 30 Apr. 2021.

      “Mergers & Acquisitions: Top 5 Technology Considerations.” Teksetra, 21 Jul. 2020. Web.

      “Mergers Acquisitions M&A Process.” Corporate Finance Institute, n.d. Web.

      “Mergers and acquisitions: A means to gain technology and expertise.” DLA Piper, 2020. Web.

      Nash, Kim S. “CIOs Take Larger Role in Pre-IPO Prep Work.” The Wall Street Journal, 5 March 2015. Web.

      O'Connell, Sean, et al. “Divestitures: How to Invest for Success.” McKinsey, 1 Aug. 2015. Web

      Paszti, Laila. “Canada: Emerging Trends In Information Technology (IT) Mergers And Acquisitions.” Mondaq, 24 Oct. 2019. Web.

      Patel, Kiison. “The 8 Biggest M&A Failures of All Time” Deal Room, 9 Sept. 2021. Web.

      Peek, Sean, and Paula Fernandes. “What Is a Vision Statement?” Business News Daily, 7 May 2020. Web.

      Ravid, Barak. “How divestments can re-energize the technology growth story.” EY, 14 July 2021. Web.

      Ravid, Barak. “Tech execs focus on growth amid increasingly competitive M&A market.” EY, 28 April 2021. Web.

      Resch, Scott. “5 Questions with a Mergers & Acquisitions Expert.” CIO, 25 June 2019. Web.

      Salsberg, Brian. “Four tips for estimating one-time M&A integration costs.” EY, 17 Oct. 2019. Web.

      Samuels, Mark. “Mergers and acquisitions: Five ways tech can smooth the way.” ZDNet, 15 Aug. 2018. Web.

      “SAP Divestiture Projects: Options, Approach and Challenges.” Cognizant, May, 2014. Web.

      Steeves, Dave. “7 Rules for Surviving a Merger & Acquisition Technology Integration.” Steeves and Associates, 5 Feb. 2020. Web.

      Tanaszi, Margaret. “Calculating IT Value in Business Terms.” CSO, 27 May 2004. Web.

      “The CIO Playbook. Nine Steps CIOs Must Take For Successful Divestitures.” SNP, 2016. Web.

      “The Role of IT in Supporting Mergers and Acquisitions.” Cognizant, Feb. 2015. Web.

      Torres, Roberto. “M&A playbook: How to prepare for the cost, staff and tech hurdles.” CIO Dive, 14 Nov. 2019. Web.

      “Valuation Methods.” Corporate Finance Institute, n.d. Web.

      Weller, Joe. “The Ultimate Guide to the M&A Process for Buyers and Sellers.” Smartsheet, 16 May 2019. Web.

      Sprint Toward Data-Driven Culture Using DataOps

      • Buy Link or Shortcode: {j2store}199|cart{/j2store}
      • member rating overall impact: 9.0/10 Overall Impact
      • member rating average dollars saved: $10,399 Average $ Saved
      • member rating average days saved: 9 Average Days Saved
      • Parent Category Name: Enterprise Integration
      • Parent Category Link: /enterprise-integration
      • Data teams do not have a mechanism to integrate with operations teams and operate in a silo.
      • Significant delays in the operationalization of analytical/algorithms due to lack of standards and a clear path to production.
      • Raw data is shared with end users and data scientists due to poor management of data, resulting in more time spent on integration and less on insight generation and analytics.

      Our Advice

      Critical Insight

      • Data and analytics teams need a clear mechanism to separate data exploratory work and repetitive data insights generation. Lack of such separation is the main cause of significant delays, inefficiencies, and frustration for data initiatives.
      • Access to data and exploratory data analytics is critical. However, the organization must learn to share insights and reuse analytics.
      • Once analytics finds wider use in the organization, they need to adopt a disciplined approach to ensure its quality and continuous integration in the production environment.

      Impact and Result

      • Use a metrics-driven approach and common framework across silos to enable the rapid development of data initiatives using Agile principles.
      • Implement an approach that allows business, data, and operation teams to collaboratively work together to provide a better customer experience.
      • Align DataOps to an overall data management and governance program that promotes collaboration, transparency, and empathy across teams, establishes the appropriate roles and responsibilities, and ensures alignment to a common set of goals.
      • Assess the current maturity of the data operations teams and implement a roadmap that considers the necessary competencies and capabilities and their dependencies in moving towards the desired DataOps target state.

      Sprint Toward Data-Driven Culture Using DataOps Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to understand the operational challenges associated with productizing the organization's data-related initiative. Review Info-Tech’s methodology for enabling the improved practice to operationalize data analytics and how we will support you in creating an agile data environment.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Discover benefits of DataOps

      Understand the benefits of DataOps and why organizations are looking to establish agile principles in their data practice, the challenges associated with doing so, and what the new DataOps strategy needs to be successful.

      • Sprint Toward Data-Driven Culture Using DataOps – Phase 1: Discover Benefits of DataOps

      2. Assess your data practice for DataOps

      Analyze DataOps using Info-Tech’s DataOps use case framework, to help you identify the gaps in your data practices that need to be matured to truly realize DataOps benefits including data integration, data security, data quality, data engineering, and data science.

      • Sprint Toward Data-Driven Culture Using DataOps – Phase 2: Assess Your Data Practice for DataOps
      • DataOps Roadmap Tool

      3. Mature your DataOps practice

      Mature your data practice by putting in the right people in the right roles and establishing DataOps metrics, communication plan, DataOps best practices, and data principles.

      • Sprint Toward Data-Driven Culture Using DataOps – Phase 3: Mature Your DataOps Practice
      [infographic]

      Workshop: Sprint Toward Data-Driven Culture Using DataOps

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Identify the Drivers of the Business for DataOps

      The Purpose

      Understand the DataOps approach and value proposition.

      Key Benefits Achieved

      A clear understanding of organization data priorities and metrics along with a simplified view of data using Info-Tech’s Onion framework.

      Activities

      1.1 Explain DataOps approach and value proposition.

      1.2 Review the common business drivers and how the organization is driving a need for DataOps.

      1.3 Understand Info-Tech’s DataOps Framework.

      Outputs

      Organization's data priorities and metrics

      Data Onion framework

      2 Assess DataOps Maturity in Your Organization

      The Purpose

      Assess the DataOps maturity of the organization.

      Key Benefits Achieved

      Define clear understanding of organization’s DataOps capabilities.

      Activities

      2.1 Assess current state.

      2.2 Develop target state summary.

      2.3 Define DataOps improvement initiatives.

      Outputs

      Current state summary

      Target state summary

      3 Develop Action Items and Roadmap to Establish DataOps

      The Purpose

      Establish clear action items and roadmap.

      Key Benefits Achieved

      Define clear and measurable roadmap to mature DataOps within the organization.

      Activities

      3.1 Continue DataOps improvement initiatives.

      3.2 Document the improvement initiatives.

      3.3 Develop a roadmap for DataOps practice.

      Outputs

      DataOps initiatives roadmap

      4 Plan for Continuous Improvement

      The Purpose

      Define a plan for continuous improvements.

      Key Benefits Achieved

      Continue to improve DataOps practice.

      Activities

      4.1 Create target cross-functional team structures.

      4.2 Define DataOps metrics for continuous monitoring.

      4.3 Create a communication plan.

      Outputs

      DataOps cross-functional team structure

      DataOps metrics

      Measure IT Project Value

      • Buy Link or Shortcode: {j2store}431|cart{/j2store}
      • member rating overall impact: 9.5/10 Overall Impact
      • member rating average dollars saved: $5,549 Average $ Saved
      • member rating average days saved: 6 Average Days Saved
      • Parent Category Name: Portfolio Management
      • Parent Category Link: /portfolio-management
      • People treat benefits as a box to tick on the business case, deflating or inflating them to facilitate project approval.
      • Even if benefits are properly defined, they are usually forgotten once the project is underway.
      • Subsequent changes to project scope may impact the viability of the project’s business benefits, resulting in solutions that do not deliver expected value.

      Our Advice

      Critical Insight

      • It is rare for project teams or sponsors to be held accountable for managing and/or measuring benefits. The assumption is often that no one will ask if benefits have been realized after the project is closed.
      • The focus is largely on the project’s schedule, budget, and scope, with little attention paid to the value that the project is meant to deliver to the organization.
      • Without an objective stakeholder to hold people accountable for defining benefits and demonstrating their delivery, benefits will continue to be treated as red tape.
      • Sponsors will not take the time to define benefits properly, if at all. The project team will not take the time to ensure they are still achievable as the project progresses. When the project is complete, no one will investigate actual project success.

      Impact and Result

      • The project sponsor and business unit leaders must own project benefits; IT is only accountable for delivering the solution.
      • IT can play a key role in this process by establishing and supporting a benefits realization process. They can help business unit leaders and sponsors define benefits properly, identify meaningful metrics, and report on benefits realization effectively.
      • The project management office is ideally suited to facilitate this process by providing tools and templates, and a consistent and comparable view across projects.
      • Project managers are accountable for delivering the project, not for delivering the benefits of the project itself. However, they must ensure that changes to project scope are assessed for impact on benefits viability.

      Measure IT Project Value Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should establish a benefits legitimacy practice, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Establish benefits legitimacy during portfolio Intake

      This phase will help you define a benefits management process to help support effective benefits definition during portfolio intake.

      • Deliver Project Value With a Benefits Legitimacy Initiative – Phase 1: Establish Benefits Legitimacy During Portfolio Intake
      • Project Sponsor Role Description Template
      • Benefits Commitment Form Template
      • Right-Sized Business Case Template

      2. Maintain benefits legitimacy throughout project planning and execution

      This phase will help you define a process for effective benefits management during project planning and the execution intake phase.

      • Deliver Project Value With a Benefits Legitimacy Initiative – Phase 2: Maintain Benefits Legitimacy Throughout Project Planning and Execution
      • Project Benefits Documentation Workbook
      • Benefits Legitimacy Workflow Template (PDF)
      • Benefits Legitimacy Workflow Template (Visio)

      3. Close the deal on project benefits

      This phase will help you define a process for effectively tracking and reporting on benefits realization post-project.

      • Deliver Project Value With a Benefits Legitimacy Initiative – Phase 3: Close the Deal on Project Benefits
      • Portfolio Benefits Tracking Tool
      • Benefits Lag Report Template
      • Benefits Legitimacy Handbook Template
      [infographic]

      Workshop: Measure IT Project Value

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Analyze the Current State of Benefits Management

      The Purpose

      Assess the current state of benefits management at your organization and establish a realistic target state.

      Establish project and portfolio baselines for benefits management.

      Key Benefits Achieved

      Set achievable workshop goals and align stakeholder expectations.

      Establish a solid foundation for benefits management success.

      Activities

      1.1 Introductions and overview.

      1.2 Discuss attendee expectations and goals.

      1.3 Complete Info-Tech’s PPM Current State Scorecard.

      1.4 Perform right-wrong-confusing-missing analysis.

      1.5 Define target state for benefits management.

      1.6 Refine project levels.

      Outputs

      Info-Tech’s PPM Current State Scorecard report

      Right-wrong-confusing-missing analysis

      Stakeholder alignment around workshop goals and target state

      Info-Tech’s Project Intake Classification Matrix

      2 Establish Benefits Legitimacy During Portfolio Intake

      The Purpose

      Establish organizationally specific benefit metrics and KPIs.

      Develop clear roles and accountabilities for benefits management.

      Key Benefits Achieved

      An articulation of project benefits and measurements.

      Clear checkpoints for benefits communication during the project are defined.

      Activities

      2.1 Map the current portfolio intake process.

      2.2 Establish project sponsor responsibilities and accountabilities for benefits management.

      2.3 Develop organizationally specific benefit metrics and KPIs.

      2.4 Integrate intake legitimacy into portfolio intake processes.

      Outputs

      Info-Tech’s Project Sponsor Role Description Template

      Info-Tech’s Benefits Commitment Form Template

      Intake legitimacy process flow and RASCI chart

      Intake legitimacy SOP

      3 Maintain Benefits Legitimacy Throughout Project Planning and Execution

      The Purpose

      Develop a customized SOP for benefits management during project planning and execution.

      Key Benefits Achieved

      Ensure that all changes to the project have been recorded and benefits have been updated in preparation for deployment.

      Updated benefits expectations are included in the final sign-off package.

      Activities

      3.1 Map current project management process and audit project management documentation.

      3.2 Identify appropriate benefits control points.

      3.3 Customize project management documentation to integrate benefits.

      3.4 Develop a deployment legitimacy process flow.

      Outputs

      Customized project management toolkit

      Info-Tech’s Project Benefits Documentation Workbook

      Deployment of legitimacy process flow and RASCI chart

      Deployment of legitimacy SOP

      4 Close the Deal on Project Benefits

      The Purpose

      Develop a post-project benefits realization process.

      Key Benefits Achieved

      Clear project sponsorship accountabilities for post-project benefits tracking and reporting.

      A portfolio level benefits tracking tool for reporting on benefits attainment.

      Activities

      4.1 Identify appropriate benefits control points in the post-project process.

      4.2 Configure Info-Tech’s Portfolio Benefits Tracking Tool.

      4.3 Define a post-project benefits reporting process.

      4.4 Formalize protocol for reporting on, and course correcting, benefit lags.

      4.5 Develop a post-project legitimacy process flow.

      Outputs

      Info-Tech’s Portfolio Benefits Tracking Tool

      Post-Project legitimacy process flow and RASCI chart

      Post-Project Legitimacy SOP

      Info-Tech’s Benefits Legitimacy Handbook

      Info-Tech’s Benefits Legitimacy Workflow Template

      Cybersecurity in Healthcare 2024

      Healthcare cybersecurity is a major concern for healthcare organizations and patients alike. In 2024, the healthcare industry faces several cybersecurity challenges, including the growing threat of ransomware, the increasing use of mobile devices in healthcare, and the need to comply with new regulations.

      Continue reading

      Integrate Threat Intelligence Into Your Security Operations

      • Buy Link or Shortcode: {j2store}320|cart{/j2store}
      • member rating overall impact: 9.0/10 Overall Impact
      • member rating average dollars saved: 2 Average Days Saved
      • member rating average days saved: After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve.
      • Parent Category Name: Threat Intelligence & Incident Response
      • Parent Category Link: /threat-intelligence-incident-response
      • Organizations have limited visibility into their threat landscape, and as such are vulnerable to the latest attacks, hindering business practices, workflow, revenue generation, and damaging their public image.
      • Organizations are developing ad hoc intelligence capabilities that result in operational inefficiencies, the misalignment of resources, and the misuse of their security technology investments.
      • It is difficult to communicate the value of a threat intelligence solution when trying to secure organizational buy-in and the appropriate resourcing.
      • There is a vast array of “intelligence” in varying formats, often resulting in information overload.

      Our Advice

      Critical Insight

      1. Information alone is not actionable. A successful threat intelligence program contextualizes threat data, aligns intelligence with business objectives, and then builds processes to satisfy those objectives.
      2. Your security controls are diminishing in value (if they haven’t already). As technology in the industry evolves, threat actors will inevitably adopt new tools, tactics, and procedures; a threat intelligence program can provide relevant situational awareness to stay on top of the rapidly-evolving threat landscape.
      3. Your organization might not be the final target, but it could be a primary path for attackers. If you exist as a third-party partner to another organization, your responsibility in your technology ecosystem extends beyond your own product/service offerings. Threat intelligence provides visibility into the latest threats, which can help you avoid becoming a backdoor in the next big data breach.

      Impact and Result

      • Assess the needs and intelligence requirements of key stakeholders.
      • Garner organizational buy-in from senior management.
      • Identify organizational intelligence gaps and structure your efforts accordingly.
      • Understand the different collection solutions to identify which best supports your needs.
      • Optimize the analysis process by leveraging automation and industry best practices.
      • Establish a comprehensive threat knowledge portal.
      • Define critical threat escalation protocol.
      • Produce and share actionable intelligence with your constituency.
      • Create a deployment strategy to roll out the threat intelligence program.
      • Integrate threat intelligence within your security operations.

      Integrate Threat Intelligence Into Your Security Operations Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should implement a threat intelligence program, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Plan for a threat intelligence program

      Assess current capabilities and define an ideal target state.

      • Integrate Threat Intelligence Into Your Security Operations – Phase 1: Plan for a Threat Intelligence Program
      • Security Pressure Posture Analysis Tool
      • Threat Intelligence Maturity Assessment Tool
      • Threat Intelligence Project Charter Template
      • Threat Intelligence RACI Tool
      • Threat Intelligence Management Plan Template
      • Threat Intelligence Policy Template

      2. Design an intelligence collection strategy

      Understand the different collection solutions to identify which best supports needs.

      • Integrate Threat Intelligence Into Your Security Operations – Phase 2: Design an Intelligence Collection Strategy
      • Threat Intelligence Prioritization Tool
      • Threat Intelligence RFP MSSP Template

      3. Optimize the intelligence analysis process

      Begin analyzing and acting on gathered intelligence.

      • Integrate Threat Intelligence Into Your Security Operations – Phase 3: Optimize the Intelligence Analysis Process
      • Threat Intelligence Malware Runbook Template

      4. Design a collaboration and feedback program

      Stand up an intelligence dissemination program.

      • Integrate Threat Intelligence Into Your Security Operations – Phase 4: Design a Collaboration and Feedback Program
      • Threat Intelligence Alert Template
      • Threat Intelligence Alert and Briefing Cadence Schedule Template
      [infographic]

      Navigate the Digital ID Ecosystem to Enhance Customer Experience

      • Buy Link or Shortcode: {j2store}76|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: IT Strategy
      • Parent Category Link: /it-strategy
      • Amid the pandemic-fueled surge in online services, organizations require secure solutions to safeguard digital interactions. These solutions must be uniform, interoperable, and fortified against security threats.
      • Although the digital identity ecosystem has garnered significant attention and investment, many organizations remain uncertain about its potential for authentication and the authorization required for B2B and B2C transactions, and in turn reducing their cost of operations and transferring their data risks.

      Our Advice

      Critical Insight

      • Limited / lack of understanding of the global digital ID ecosystem and its varying approaches across countries handicaps businesses in defining the benefits digital ID can bring to customer interactions and overall business management.
      • In addition, key obstacles exist in balancing customer privacy, data security, and regulatory requirements while pursuing excellent end-user experience and high customer adoption.
      • Info-Tech Insight: Focusing on customer touchpoints and transforming them are key to excellent experience and increasing their life-time value (LTV) to them and to your organization. Digital ID is that tool of transformation.

      Impact and Result

      • Digital ID has many dimensions, and its ecosystem's sustainability lies in the key principles it is built on. Understanding the digital identity ecosystem and its responsibilities is crucial to formulating an approach to adopt it. Also, focusing on key success factors drives digital ID adoption.
      • Before embarking on the digital identity adoption journey, it is essential to assess your readiness. It is also necessary to understand the risks and challenges. Specific steps to digital ID adoption can help realize the potential of digital identity and enhance the customers' experience.

      Navigate the Digital ID Ecosystem to Enhance Customer Experience Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Navigate the Digital ID Ecosystem to Enhance Customer Experience Storyboard – Learn how to adopt Digital ID to drive benefits, enhance customer experience, improve efficiency, manage data risks, and uncover new opportunities.

      This research focuses on verified digital identity ecosystems and explores risks, opportunities, and challenges of relying on verified digital IDs and also how adopting digital identity initiatives can improve customer experience and operational efficiency. It covers:

    • Definition and dimensions of digital identity
    • Key responsibilities and principles of digital identity ecosystem
    • Success factors for digital identity adoption
    • Global evolution and unique approaches in Estonia, India, Canada, UK, and Australia
    • Industries that benefit most from digital ID development
    • Key use cases of digital ID
    • Benefits to governments, ID providers, ID consumers, and end users
    • Readiness checklist and ten steps to digital ID adoption
    • Risks and challenges of digital identity adoption
    • Key recommendations to realize potential of digital identity
    • Taxonomy and definitions of terms in the digital identity ecosystem
      • Navigate the Digital ID Ecosystem to Enhance Customer Experience Storyboard
      • Familiarize Yourself With the Digital ID Ecosystem Taxonomy
      • Assess Your Digital ID Adoption Readiness

      Infographic

      Further reading

      Navigate the Digital ID Ecosystem to Enhance Customer Experience

      Beyond the hype: How it can help you become more customer-focused?

      Executive Summary

      Your Challenge

      Common Obstacles

      Info-Tech’s Approach

      Amid the pandemic-fueled surge of online services, organizations require secure solutions to safeguard digital interactions. These solutions must be uniform, interoperable, and fortified against security threats.

      Although the digital identity ecosystem has garnered significant attention and investment, many organizations remain uncertain about its potential for authentication and authorization required for B2B and B2C transactions.

      They still wonder if digital ID can help reduce cost of operations and transfer data risks.

      Limited or lack of understanding of the global Digital ID ecosystem and its varying approaches across countries handicap businesses in defining the potential benefits Digital ID can bring to customer interactions and overall business management.

      In addition, key obstacles exist in balancing customer privacy (including the right to be forgotten), data security, and regulatory requirements while pursuing desired end-user experience and high customer adoption.

      Digital ID has many dimensions, and its ecosystem's sustainability lies in the key principles it is built on. Understanding the digital identity ecosystem and its responsibilities is crucial to formulate an approach to adopt it. Also, focusing on key success factors drives digital ID adoption.

      Before embarking on the digital identity adoption journey, it is essential to assess your readiness. It is also necessary to understand the risks and challenges. Specific steps to digital ID adoption can help realize the potential of digital identity and enhance the customers' experience.

      Info-Tech Insight

      Focusing on customer touchpoints and transforming them is key to excellent user experience and increasing their lifetime value (LTV) to them and to your organization. Digital ID is that tool of transformation.

      Analyst Perspective

      Manish Jain.

      Manish Jain

      Principal Research Director

      Analyst Profile

      “I just believed. I believed that the technology would change people's lives. I believed putting real identity online - putting technology behind real identity - was the missing link.”

      - Sheryl Sandberg (Brockes, Emma. “Facebook’s Sheryl Sandberg: who are you calling bossy?” The Guardian, 5 April 2014)

      Sometimes dismissed as mere marketing gimmicks, digital identity initiatives are anything but. While some argue that any online credential is a "Digital ID," rendering the hype around it pointless, the truth is that a properly built digital ID ecosystem has the power to transform laggard economies into global digital powerhouses. Moreover, digital IDs can help businesses transfer some of their cybersecurity risks and unlock new revenue channels by enabling a foundation for secure and efficient value delivery.

      In addition, digital identity is crucial for digital and financial inclusion, simplifying onboarding processes and opening up new opportunities for previously underserved populations. For example, in India, the Aadhaar digital ID ecosystem brought over 481 million1 people into the formal economy by enabling access to financial services. Similarly, in Indonesia, the e-KIP digital ID program paved the way for 10 million new bank accounts, 94% of which were for women2.

      However, digital identity initiatives also come with valid concerns, such as the risk of a single point of failure and the potential to widen the digital divide.

      This research focuses on the verified digital identity ecosystem, exploring the risks, opportunities, and challenges organizations face relying on these verified digital IDs to know their customers before delivering value. By understanding and adopting digital identity initiatives, organizations can unlock their full potential and provide a seamless customer experience while ensuring operational efficiency.

      1 India Aadhaar PMJDY (https://pmjdy.gov.in/account)
      2 Women’s World Banking, 2020.

      Digital Identity Ecosystem and vital ingredients of adoption

      Digital Identity Ecosystem.

      What is digital identity?

      Definitions may vary, depending on the focus.

      “Digital identity (ID) is a set of attributes that links a physical person with their online interactions. Digital ID refers to one’s online persona - an online footprint. It touches important aspects of one’s everyday life, from financial services to health care and beyond.” - DIACC Canada

      “Digital identity is a digital representation of a person. It enables them to prove who they are during interactions and transactions. They can use it online or in person.” - UK Digital Identity and Attributes Trust Framework

      “Digital identity is an electronic representation of an entity (person or other entity such as a business) and it allows people and other entities to be recognized online.” - Australia Trusted Digital Identity Framework

      A digital identity is primarily an electronic form of identity representing an entity uniquely , while abstracting all other identity attributes of the entity. In addition to an electronic form, it may also exist in a physical form (identity certificate), linked through an identifier representing the same entity.

      Digital identity has many dimensions*, and in turn categories

      Trust

      • Verified (Govt. issued IDs)
      • Unverified (Email Id)

      Subject

      • Individual
      • Organization
      • Device
      • Service

      Usability

      • Single-purpose (Disposable)
      • Multi-purpose (Reusable)

      Provider

      • Sovereign Government
      • Provincial Government
      • Local Government
      • Public Organization
      • Private Organization
      • Self

      Jurisdiction

      • Global (Passport)
      • National (DL)
      • State/Provincial (Health Card)
      • Local (Voting Card)
      • Private (Social)

      Form

      • Physical Card
      • Virtual Identifier
      • Online/App Account
      • PKI Keys
      • Tokens

      Governance

      • Sovereign
      • Federated
      • Decentralized
      • Trust Framework -based
      • Self-sovereign

      Expiry

      • Permanent (Lifetime, Years)
      • Temporary (Minutes, Hours)
      • Revocable

      Usage Mode

      • online only
      • offline only
      • Online/offline

      Purpose

      • Authorization (driver’s license, passport, employment)
      • Authentication (birth certificate, social security number)
      • Activity Linking (preferences, habits, and priorities)
      • Historical Record (Resume, educational financial, health history)
      • Social Interactions (Social Media)
      • Machine Connectivity

      Info-Tech Insight

      Digital ID has taken different meanings for different people, serving different purposes in different environments. Based on various aspects of Digital Identification, it can be categorized in several types. However, most of the time when people refer to a form of identification as Digital ID, they refer to a verified id with built-in trust either from the government OR the eco-system.

      * Please refer to Taxonomy for the definition of each of the dimensions

      Understanding a digital identity ecosystem is key to formulating your approach to adopt it

      The image contains a screenshot of a digital identity ecosystem diagram.

      Info-Tech Insight

      Digital identity ecosystems comprise many entities playing different roles, and sometimes more than one. In addition, variations in approach by jurisdictions drive how many active players are in the ecosystem for that jurisdiction.

      For example, in countries like Estonia and India, government plays the role of trust and governance authority as well as ID provider, but didn’t start with any Digital ID wallet. In contrast, in Ukraine, Diia App is primarily a Digital ID Wallet. Similarly, in the US, different states are adopting private Digital ID Wallet providers like Apple.

      Digital ID ecosystem’s sustainability lies in the key principles it is built on

      Social, economic, and legal alignment with target stakeholders
      Transparent governance and operation
      Legally auditable and enforceable
      Robust and Resilient – High availability
      Security – At rest, in progress, and in transit
      Privacy and Control with users
      Omni-channel Convenience – User and Operations
      Minimum data transfer between entities
      Technical interoperability enabled through open standards and protocol
      Scalable and interoperable at policy level
      Cost effective – User and operations
      Inclusive and accessible

      Info-Tech Insight

      A transparent, resilient, and auditable digital ID system must be aligned with socio-economic realities of the target stakeholders. It not only respects their privacy and security of their data by minimizing the data transfer between entities, but also drives desired customer experience by providing an omni-channel, interoperable, scalable, and inclusive ecosystem while still being cost-effective for the collaborators.

      Source: Adapted from Canada PCTF, UK Trust framework, European Commission, Australia TDIF, and others

      Focus on key success factors to drive the digital ID adoption

      Digital ID success factors

      Legislative regulatory framework – Removes uncertainty
      Security & Privacy Assurance- builds trust
      Smooth user experience – Drives preferences
      Transparent ecosystem – Drives inclusivity
      Multi-channel – Drive consistent experience online / offline
      Inter-operability thorough open standards
      Digital literacy – Education and awareness
      Multi-purpose & reusable – Reduce consumer burden
      Collaborative ecosystem –Build network effect

      Source: Adapted from Canada PCTF, UK digital identity & attributes trust framework , European eIDAS, and others

      Info-Tech Insight

      Driving adoption of Digital ID requires affirmative actions from all ecosystem players including governing authorities, identity providers, and identity consumers (relying parties).

      These nine success factors can help drive sustainable adoption of the Digital ID.

      Among many responsibilities the ecosystem players have, identity governance is the key to sustainability

      • Digital identity provision
        • Creating identity attributes
        • Create a reusable identity and attribute service
        • Create a digital identity
        • Assess and manage quality of an identity and attributes
        • Making identity provision inclusive and accessible
      • Digital identity resolution
        • Enabling inclusive access to products and services through digital identity
        • Authenticate and authorize identity subjects before permitting access to their identity and attributes
      • Digital identity governance
        • Manage digital identity and attributes
        • Make Identity service interoperable, and sharable
        • Recover digital identity and attribute accounts
        • Notifying users on accessing identity or making changes on more attributes
        • Report and audit – exclusion, accessibility
        • Retiring an identity or attribute service
        • Respond to complaints and disputes
      • Enterprise risk management and governance
      The image contains a screenshot of a diagram to demonstrate how identity governance is the key to sustainability.
      • Privacy and security
        • Use encryption
        • Privacy compliance framework
        • Consumer Privacy Protection laws (CPPA, GDPR etc.)
        • Acquiring and managing user consents & agreements
        • Prohibited processing of personal data
        • Security controls and governance
      • Information management
        • Record management
        • Archival
        • Disposal (on expiry or to comply with regulations)
        • CIA (confidentiality, integrity, availability)
      • Fraud management
        • Fraud monitoring and reporting
        • Fraud intelligence and analysis
        • Sharing threat indicators
        • Legal, policies and procedures for fraud management
      • Incident response
        • Respond to fraud incidents
        • Respond to a service delivery incident
        • Responding to data breaches
        • Performing and participating in investigation

      Global evolution of digital ID is following the socio-economic aspirations of countries

      The image contains a screenshot of a graph that demonstrates global evolution of digital ID.

      Source: Adapted from the book: Identification Revolution: Can Digital ID be harnessed for Development? (Gelb & Metz), 2018

      Info-Tech Insight

      The world became global a long time ago; however, it sustained economic progress without digital IDs for most of the world's population.

      With the pandemic, when political rhetoric pointed to the demand for localized supply chains, economies became irreversibly digital. In this digital economy, the digital ID ecosystem is the fulcrum of sustainable growth.

      At a time in overlapping jurisdictions, multiple digital IDs can exist. For example, one is issued by a local municipality, one by the province, and another by the national government.

      Global footprint of digital ID is evolving rapidly, but varies in approach

      The image contains a screenshot of a Global footprint of digital ID.

      Info-Tech Insight

      Countries’ approach to the digital ID is rooted in their socio-economic environment and global aspirations.

      Emerging economies with large underserved populations prioritize fast implementation of digital ID through centralized systems.

      Developed economies with smaller populations, low trust in government, and established ID systems prioritize developing trust frameworks to drive decentralized full-scale implementation.

      There is no right way except the one which follows Digital ID principles and aligns with a country’s and its people’s aspirations.

      Estonia's e-identity is the key to its digital agenda 2030

      • Regulatory Body and Operational Governance: Estonian Information System Authority (RIA).
      • Identity Providers: Government of Estonia; Private sector doesn’t issue IDs but can leverage Digital ID ecosystem.
      • Decentralized Approach: Permissioned Blockchain Architecture with built-in data traceability implemented on KSI (Keyless Signature Infrastructure).
      • X-Road – Secure, interoperable open-source data exchange platform between collection point where Data is stored.
      • Digital Identity Form: e-ID
      • Key Use cases:
        • Financial, Telecom: e-KYC, e-Banking
        • Digital Authentication: ID Card, Mobile ID, Smart ID, Digital Signatures
        • E-governance: e-Voting, e-Residency, e-Services Registries, e-Business Register
        • Smart City and mobility: Freight Transportation, Passenger Mobility
        • Healthcare: e-Health Record, e-Prescription, e-Ambulance
      • ID-card
      • Smart ID
      • Mobile ID
      • e-Residency

      Uniqueness

      Estonia pioneered the digital ID implementation with a centralized approach and later transitioned to a decentralized ecosystem driving trust to attract non-citizens into Estonia’s digital economy.

      99% Of Estonian residents have an ID card enabling use of electronic ID

      1.4 B Digital signatures given (2021)

      99% Public Services available as e-Services

      17K+ Productive years saved (five working days/citizen/year saved accessing public services)

      25K E-resident companies contributed more than €32 million in tax

      *Source: https://e-estonia.com/wp-content/uploads/e-estonia-211022_eng.pdf ;

      https://www.e-resident.gov.ee/dashboard

      The image contains a timeline of events from 2001-2020 for Estonia..

      India’s Aadhaar is the foundation of its digital journey through “India stack”

      • Regulatory Accountability and Operational Governance: Unique Identification Authority of India (UIDAI).
      • Identity Provider: Govt. of India.
      • Digital Identity Form: Physical and electronic ID Card; Online (Identifier + OTP), and offline (identifier + biometric) usage; mAadhaar App & Web Portal
      • India Stack: a set of open APIs and digital assets to leverage Aadhaar in identity, data, and payments at scale.
      • Key Use cases:
        • Financial, Telecom: eKYC, Unified Payments Interface (UPI)
        • Digital Wallet: Digi Locker
        • Digital Authentication: eSign, and Aadhaar Auth.
        • Public Welfare: Public Distribution of Service, Social Pension, Employment Guarantee
        • Public service access: Enrollment to School, Healthcare

      1.36B People enrolled

      80% Beneficiaries feel Aadhaar has made PDS, employment guarantee and social pensions more reliable

      91.6% Are very satisfied or somewhat satisfied with Aadhaar

      14B eKYC transactions done by 218 eKYC authentication agencies (KUA)

      Source: https://uidai.gov.in/aadhaar_dashboard/india.php; https://www.stateofaadhaar.in/

      World Bank Report on Private Sector Impacts from ID

      Uniqueness

      “The Aadhaar digital identity system could reduce onboarding costs for Indian firms from 1,500 rupees to as low as an estimated 10 rupees.”

      -World Bank Report on Private Sector Impacts from ID

      With lack of public trust in private sector, government brought in private sector executives in public ecosystem to lead the largest identity program globally and build the India stack to leverage the power of Digital Identity.

      The image contains a screenshot of India's Aadhaar timeline from 2009-2022.

      Ukraine’s Diia is a resilient act to preserve their identities during threat to their existence

      Regulatory Accountability and Operational Governance: Ministry of Digital Transformation.

      Identity provider: Federated govt. agencies.

      Digital identity form: Diia App & Portal as a digital wallet for all IDs including digital driving license.

      • Key use cases:
        • eGovernance – Issuing license and permits, business registration, vaccine certificates.
        • Public communication: air-raid alerts, notifications, court decisions and fines.
        • Financial, Telecom: KYC compliance, mobile donations.
        • eBusiness: Diia City legal framework for IT industry, Diia Business Portal for small and medium businesses.
        • Digital sharing and authentication: Diia signature and Diia QR.
        • Public service access: Diia Education Portal for digital education and digital skills development, healthcare.

      18.5M People downloaded the Diia app.

      14 Digital IDs provided by other ID providers are available through Diia.

      70 Government services are available through Diia.

      ~1M Private Entrepreneurs used Diia to register their companies.

      1300 Tons of paper estimated to be saved by reducing paper applications for new IDs and replacements.

      Source:

      • Ukraine Govt. Website for Invest and trade
      • Diia Case study prepared for the office of Canadian senator colin deacon.

      Uniqueness

      “One of the reasons for the Diia App's popularity is its focus on user experience. In September 2022, the Diia App simplified 25 public services and digitized 16 documents. The Ministry of Digital Transformation aims to make 100% of all public services available online by 2024.”

      - Vladyslava Aleksenko

      Project Lead—digital Identity, Ukraine

      The image contains a screenshot of the timeline for Diia.

      Canada’s PCTF (Pan Canadian Trust Framework) driving the federated digital identity ecosystem

      • Regulatory Accountability: Treasury Board of Canada Secretariat (TBS); Canadian Digital Service (CDS); Office of CIO
      • Standard Setting: Digital Identification and Authentication Council of Canada (DIACC)
      • Frameworks:
        • Treasury Board Directive on Identity Management
        • Pan Canadian Trust Framework (PCTF)
        • Voilà Verified Trustmark Program: ISO aligned compliance certification program on PCTF
        • Governing / Certificate Authority: Trustmark Oversight Board (TOB) and DIACC accredited assessor
        • Operational Governance: Federated between identity providers and identity consumers
        • Identity Providers: Public and Private Sector
        • Other entities involved: Digital ID Lab (Voila Verified Auditor); Kuma (Accredited Assessor)
      The image contains a screenshot of PCTF Components.

      82% People supportive of Digital ID.

      2/3 Canadians prefer public-private partnership for Pan-Canadian digital ID framework.

      >40% Canadians prefer completing various tasks and transactions digitally.

      75% Canadians are willing to share personal information for better experience.

      >80% Trust government, healthcare providers, and financial institutions with their personal information.

      Source: DIACC Survey 2021

      Uniqueness

      Although a few provinces in Canada started their Digital ID journey already, federally, Canada lacked an approach.

      Now Canada is developing a federated Digital ID ecosystem driven through the Pan-Canadian Trust Framework (PCTF) led by a non-profit (DIACC) formed with public and private partnership.

      The image contains a screenshot of Canada's PCTF timeline from 2002-2025.

      Australia’s digital id is pivotal to its vision to become one of the Top-3 digital governments globally by 2025*

      * Australia Digital Government Strategy 2021
      • Regulatory responsibility and standard: Digital Transformation Agency (DTA)’s Digital Identity
      • Operational support and oversight: Service Australia, Interim Oversight Authority (IOA).
      • Accredited identity providers (by 2022): Australian Taxation Office (ATO)’s myGovID, Australia Post’s Digital ID, MasterCard’s ID, OCR Labs App
      • Framework: Trusted Digital Identity Framework (TDIF)
        • Digital Identity Exchange
        • Identity Service Providers and Attribute Verification Service
        • Attribute Service Providers
        • Credential Service Providers
        • Relying Parties
      • Others: States such as NSW, Victoria, and Queensland have their own digital identity programs

      8.6M People using myGovID by Jun-2022

      117 Services accessible through Digital Id System

      The image contains a screenshot diagram of Digital Identity.

      Uniqueness

      Australia started its journey of Digital ID with a centralized Digital ID ecosystem.

      However, now it preparing to transition to a centrally governed Trust framework-based ecosystem expanding to private sector.

      The image contains a screenshot of Australia's Digital id timeline from 2014-2022.

      UK switches gear to the Trust Framework approach to build a public-private digital ID ecosystem

      • Government: Ministry of Digital Infrastructure / Department of Digital, Culture, Media, and Sport
      • Governing Body / Certificate Authority / Operational Governance: TBD
      • Approach: Trust Framework-based UK Digital Identity and attributes trust framework (UKDIATF)
      • Identity providers: Transitioning from “GOV.UK Verify” to a federated digital identity system aligned with “Trust Framework” – enabling both government (“One Login for Government”) and private sector identity providers.
      The image contains a screenshot of the Trust Framework.

      Uniqueness

      UK embarked its Digital ID journey through Gov.UK Verify but decided to scrap it recently.

      It is now preparing to build a trust framework-based federated digital ID ecosystem with roles like schema-owners and orchestration service providers for private sector and drive the collaboration between industry players.

      The image contains a screenshot of UK timeline from 2011-2023.

      Digital ID will transform all industries, though financial services and e-governance will gain most

      Cross Industry

      Financial Services

      Insurance

      E-governance

      Healthcare & Lifesciences

      Travel and Tourism

      E-Commerce

      • Onboarding (customer, employee, patient, etc.)
      • Fraud-prevention (identity theft)
      • Availing restricted services (buying liquor)
      • Secure-sharing of credentials and qualifications (education, experience, gig worker)
      • For businesses, customer 360
      • For businesses, reliable data-driven decision making with lower frequency of ‘astroturfing’ (false identities) and ‘ballot-stuffing’ (duplicate identities)
      • Account opening
      • Asset transfer
      • Payments
      • For businesses, risk management - know your customer (KYC), anti-money laundering (AML), customer due diligence (CDD)
      • Insurance history
      • Insurance claim
      • Public distribution schemes (PDS)
      • Subsidy payments (direct to consumer)
      • Obtain government benefits (maternity, pension, employment guarantee / insurance payments)
      • Tax filing
      • Issuing credentials (birth certificate, passport)
      • Voting
      • For businesses, availing governments supports
      • For SMB businesses, easier regulatory compliance
      • Digital health
      • Out of state public healthcare
      • Secure access to health and diagnostic records
      • For businesses, data sharing between providers and with payers
      • Travel booking
      • Cross-border travel
      • Car rental
      • Secure peer-to-peer sales
      • Secure peer-to-peer sales

      USE CASE

      Car rental

      INDUSTRY: Travel & Tourism

      Source: Info-Tech Research Group

      Challenge

      Solution

      Results

      Verifying the driver’s license (DL) is the first step a car rental company takes before handing over the keys.

      While the rental company only need to know the validity of the DL and if it belongs to the presenter, is bears the liability of much more data presented to them through the DL.

      For customers, it is impossible to rent a car if they forget their DL. If the customer has their driver’s license, they compromise their privacy and security as they hand over their license to the representative.

      The process is not only time consuming, it also creates unnecessary risks to both the business and the renter.

      A digital id-based rental process allows the renter to present the digital id online or in person.

      As the customer approaches the car rental they present their digital id on the mobile app, which has already authenticated the presenter though the biometrics or other credentials.

      The customer selects the purpose of the business as “Car Rental”, and only the customer’s name, photo, and validity of the DL appear on the screen for the representative to see (selective disclosures).

      If the car pick-up is online, only this information is shared with the car rental company, which in turn shares the car and key location with the renter.

      A digital identity-based identity verification can ensure a rental company has access to the minimum data it needs to comply with local laws, which in turn reduces its data leak risk.

      It also reduces customer risks linked to forgetting the DL, and data privacy.

      Digital identity also reduces the risk originated from identity fraud leading to stolen cars.

      USE CASE

      e-Governance public distribution service

      INDUSTRY: Government

      Source: Info-Tech Research Group

      Challenge

      Solution

      Results

      In both emerging and developed economies, public distribution of resources – food, subsidies, or cash – is a critical process through which many people (especially from marginalized sections) survive on.

      They often either don’t have required valid proof of identity or fall prey to low-level corruption when someone defrauds them by claiming the benefit.

      As a result, they either completely miss out on claiming government-provided social benefits OR only receive a part of what they are eligible for.

      A Digital ID based public distribution can help created a Direct Benefit Transfer ecosystem.

      Here beneficiaries register (manually OR automatically from other government records) for the benefits they are eligible for.

      On the specific schedule, they receive their benefit – monetary benefit in their bank accounts, and non-cash benefits, in person from authorized points-of-sales (POS), without any middleman with discretionary decision powers on the distribution.

      India launched its Financial Inclusion Program (Prime Minister's Public Finance Scheme) in 2014.

      The program was linked with India’s Digital Id Aadhaar to smoothen the otherwise bureaucratic and discretionary process for opening a bank account.

      In last eight years, ~481M (Source: PMJDY) beneficiaries have opened a bank account and deposited ~ ₹1.9Trillion (USD$24B), a part of which came as social benefits directly deposited to these accounts from the government of India.

      USE CASE

      Real-estate investment and sale

      INDUSTRY: Asset Management

      Source: Info-Tech Research Group

      Challenge

      Solution

      Results

      “Impersonators posing as homeowners linked to 32 property fraud cases in Ontario and B.C.” – Global News Canada1

      “The level of fraud in the UK is such that it is now a national security threat” – UK Finance Lobby Group2

      Real estate is the most expensive investment people make in their lives. However, lately it has become a soft target for title fraud. Fraudsters steal the title to one’s home and sell it or apply for a new mortgage against it.

      At the root cause of these fraud are usually identity theft when a fraudster steals someone’s identity and impersonates them as the title owner.

      Digital identity tagged to the home ownership / title record can reduce the identity fraud in title transfer.

      When a person wants to sell their house OR apply for a new mortgage on house, multiple notifications will be triggered to their contact attributes on digital ID – phone, email, postal address, and digital ID Wallet, if applicable.

      The homeowner will be mandated to authorize the transaction on at least two channels they had set as preferred, to ensure that the transaction has the consent of the registered homeowner.

      This process will stop any fraud transactions until at least two modes are compromised.

      Even if two modes are compromised, the real homeowner will receive the notification on offline communication modes, and they can then alert the institution or lawyer to block the transaction.

      It will especially help elderly people, who are more prone to fall prey to identity frauds when somebody uses their IDs to impersonate them.

      1 Global News (https://globalnews.ca/news/9437913/homeowner-impersonators-lined-32-fraud-cases-ontario-bc/)

      2 UK Finance Lobby Group (https://www.ukfinance.org.uk/system/files/Half-year-fraud-update-2021-FINAL.pdf)

      Adopting digital ID benefits everybody – governments, id providers, id consumers, and end users

      Governments & identity providers

      (public & private)

      Customers and end users

      (subjects)

      Identity consumer

      (relying parties)

      • Growth in GDP
      • Save costs of providing identity
      • Unlock new revenue source by economic expansion
      • Choice and convenience
      • Control of what data is shared
      • Experience driven by simplicity and data minimalization
      • Reduced cost of availing services
      • Operational efficiency
      • Overall cost efficiency of delivering service and products
      • Reduce risk of potential litigation
      • Reduce risk of fraud
      • Enhanced customer experience leading to increased lifetime value
      • Streamlined storage and access
      • Encourage innovation

      Digital ID will transform all industries, though financial services and e-governance will gain most

      Governments and identity providers (public and private)

      • Growth in GDP by reducing bureaucracy and discretion from the governance processes.
        • As per a McKinsey report, digital ID could unlock the economic value equivalent of 3%-13% of GDP across seven focus countries (Brazil, Ethiopia, India, Nigeria, China, UK, USA) in 2030.
        • “Estonia saves two percent of GDP by signing things digitally; imagine if it could go global.” - aavi Rõivas, Prime Minister of the Republic of Estonia (International Peace Institute)
      • Unlock new revenue source by economic expansion.
        • Estonia earned €32 million in tax revenue from e-resident companies (e-Estonia).
      • Save costs of providing identity in collaboration with 3rd parties and reduce fraud.
        • Canada estimates savings of $482 million for provincial and federal governments, and $4.5 billion for private sector organizations through digital id adoption (2022 Budget Statement).

      Digital ID brings end users choice, convenience, control, and cost-saving, driving overall experience

      Customers and end users (subjects)

      • Choice: Citizens have the choice and convenience to interact safely and conveniently online and offline.
      • Convenience: No compulsion to make physical trips to access service, as end users can identify themselves safely and reliably online, as they do offline.
      • Control: A decentralized, privacy enhancing solution – neither government nor private companies control your digital ID. How and when you use digital ID is entirely up to you.
      • Cost Saving: Save costs of availing service by reducing the offline documentation.
      • Experience: Improved experience while availing service without a need to present multiple documents every time.

      Digital id benefits identity consumers by enhancing multiple dimensions of their value streams

      Identity consumer (relying parties)

      • Operational efficiency: Eliminating unnecessary steps and irrelevant data from the value stream increases overall operational efficiency.
      • Cost efficiency: Helps businesses to reduce overall cost of operations like regulatory requirements.
        • World Bank estimated that the Aadhaar could reduce onboarding costs for Indian firms from ₹1,500/- ($23) to as low as an estimated ₹10/- ($0.15) (*World Bank ID4D)
      • Reduce risk of potential litigation issues: Encourage data minimization.
      • Privacy and security: Businesses can reduce the risk of fraud to organizations and users and can significantly boost the privacy and security of their IT assets.
      • Enhanced customer experience: The decrease in the number of touchpoints and faster turnaround.
      • Streamlined storage and access: Store all available data in a single place, and when required.
      • Encourage innovation: Reduce efforts required in authentication and authorization of users.

      Before embarking on the digital identity adoption journey, assess your readiness

      Legislative coverage

      Does your target jurisdiction have adequate legislative framework to enable uses of digital identities in your industry?

      Trust framework

      If the Digital ID ecosystem in your target jurisdiction is trust framework-based, do you have adequate understanding of it?

      Customer touch-points

      Do you have exact understanding of value stream and customer touch-points where you interact with user identity?

      Relevant identity attributes

      Do you have exact understanding of the identity attributes that your business processes need to deliver customer value?

      Regulatory compliance

      Do you have required systems to ensure your compliance with industry regulations around customer PII and identity?

      Interoperability with IMS

      Is your existing identity management system interoperable with Open-source Digital Identity ecosystem?

      Enterprise governance

      Have you established an integrated enterprise governance framework covering business processes, technical systems, and risk management?

      Communication strategy

      Do have a clear strategy (mode, method, means) to communicate with your target customer and persuade them to adopt digital identity?

      Security operations center

      Do you have security operations center coordinating detection, response, resolution, and communication of potential data breaches?

      Ten steps to adopt to enhance the customer experience

      Considering the complexity of digital identity adoption, and its impact on customer experience, it is vital to assess the ecosystem and adopt an MVP approach before a big-bang launch.

      Diagram to help assess the ecosystem.

      1. Define the use case and identify the customer touchpoint in the value stream which can be improved with a verified digital identity.
      2. Ensure your organization is ready to adopt digital identity (Refer to Digital identity adoption readiness),
      3. Identify an Identity Service Provider (Government, private sector), if there are options.
      4. Understand its technical requirements and assess, to the finer detail, your technical landscape for interoperability.
      5. Set-up a business contract for terms of usages and liabilities.
      6. Create and execute a Minimum Viable Program (MVP) of integration which can be tested with real customers.
      7. Extend MVP to the complete solution and define key success metrics.
      8. Canary-launch with a segment of target customers before a full launch.
      9. Educate customers on the usages and benefits, and adapt your communication plan taking feedback
      10. Monitor and continuously improve the solution based on the feedback from ecosystem partners and end-customers, and regulatory changes.

      Understand and manage the risks and challenges of digital identity adoption

      Digital ID adoption is a major change for everyone in the ecosystem.

      Manage associated risks to avoid the derailing of integration with your business processes and a negative impact on customer experience.

      Manage Risks.

      1. Privacy and security risks – Customer’s sensitive data may get centralized with the identity provider.
      2. Single point of failure while relying a specific IDs; it also increases the impact of identity theft and fraud risk.
      3. Centralization and control risks – Identity provider or identity service broker / orchestrator may control who can participate.
      4. Not universal, interoperability risks – if purpose-specific.
      5. Impact omni-channel experience - Not always available (legal / printable) for offline use.
      6. Exclusion and discrimination risks – Specific data requirements may exclude a group of people.
      7. Scope for misuse and misinterpretation if compromised and not reclaimed in timely manner.
      8. Adoption and usability risks – Subjects / relying parties may not see benefit due to lack of awareness or suspicion.
      9. Liability Agreement gaps between identity provider and identity consumer (relying party).

      Recommendations to help you realize the potential of digital identity into your value streams

      1

      Customer-centricity

      Digital identity initiative should prioritize customer experience when evaluating its fit in the value stream. Adopting it should not sacrifice end-user experience to gain a few brownie points.

      See Info-Tech’s Adopt Design Thinking in Your Organization blueprint, to ensure customer remains at the center of your Digital Adoption initiative.

      2

      Privacy and security

      Adopting digital identity reduces data risk by minimizing data transfer between providers and consumers. However, securing identity attributes in value streams still requires strengthening enterprise security systems and processes.

      See Info-Tech’s Assess and Govern Identity Security blueprint for the actions you may take to secure and govern digital identity.

      3

      Inclusion and awareness

      Adopting digital identity may alter customer interaction with an organization. To avoid excluding target customer segments, design digital identity accordingly. Educating and informing customers about the changes can facilitate faster adoption.

      See Info-Tech’s Social Media blueprint and IT Diversity & Inclusion Tactics to make inclusion and awareness part of digital adoption

      4

      Quantitative success metrics

      To measure the success of a digital ID adoption program, it's essential to use quantitative metrics that align with business KPIs. Some measurable KPIs may include:

      • Reduction in number of IDs business used to serve 90% of customers
      • Reduction in overall cost of operation
        • Reduction in cost of user authentication
      • Reduction in process cycle time (less time required to complete a task – e.g. KYC)

      Taxonomy – Digital ID ecosystem

      (Alphabetical order)

      Continues..

      Attributes: An identity attribute is a statement or information about a specific aspect of entity’s identity ,substantiating they are who they claim to be, own, or have.

      Attribute (or Credential) provider: An attribute or credential provider could be an organization which issues the primary attribute or credential to a subject or entity. They are also responsible for identity-attribute binding, credential maintenance, suspension, recovery, and authentication.

      Attribute (or Credential) service provider: An attribute service provider could be an organization which originally vetted user’s credentials and certified a specific attribute of their identity. It could also be a software, such as digital wallet, which can store and share a user’s attribute with a third party once consented by the user. (Source: UK Govt. Trust Framework)

      Attribute binding: This is a process an attribute service providers uses to link the attributes they created to a person or an organization through an identifier. This process makes attributes useful and valuable for other entities using these attributes. For example, when a new employee joins a company, they are given a unique employee number (an identifier), which links the person with their job title and other aspects (attributes) of his job. (Source: UK Govt. Trust Framework)

      Authentication service provider: An organization which is responsible for creating and managing authenticators and their lifecycle (issuance, suspension, recovery, maintenance, revocation, and destruction of authenticators). (Source: DIACC)

      Authenticator: Information or biometric characteristics under the control of an individual that is a specific instance of something the subject has, knows, or does. E.g. private signing keys, user passwords, or biometrics like face, fingerprints. (Source: Canada PCTF)

      Authentication (identity verification): The process of confirming or denying that the identity presented relates to the subject who is making the claim by comparing the credentials presented with the ones presented during identity proofing.

      Authorization: The process of validating if the authenticated entity has permission to access a resource (service or product).

      Biometrics attributes: Human attributes like retina (iris), fingerprint, heartbeat, facial, handprint, thumbprint, voice print.

      Centralized identity: Digital identities which are fully governed by a centralized government entity. It may have enrollment or registration agencies, private or public sector, to issue the identities, and the technical system may still be decentralized to keep data federated.

      Certificate Authority (CA or accredited assessors): An organization or an entity that conducts assessments to validate the framework compliance of identity or attribute providers (such as websites, email addresses, companies, or individual persons) serving other users, and binding them to cryptographic keys through the issuance of electronic documents known as digital certificates.

      Taxonomy – Digital ID ecosystem

      (Alphabetical order)

      Continues..

      Collective (non-resolvable) attributes: Nationality, domicile, citizenship, immigration status, age group, disability, income group, membership, (outstanding) credit limit, credit score range.

      Contextual identity: A type of identity which establishes an entity’s existence in a specific context – real or virtual. These can be issued by public or private identity providers and are governed by the organizational policies. E.g. employee ID, membership ID, social media ID, machine ID.

      Credentials: A physical or a digital representation of something that establishes an entity’s eligibility to do something for which it is seeking permission, or an association/affiliation with another, generally well-known entity. E.g. Passport, DL, password. In the context of Digital Identity, every identity needs to be attached with a credential to ensure that the subject of the identity can control how and by whom that identity can be used.

      Cryptographic hash function: A hash function is a one-directional mathematical operation performed on a message of any length to get a unique, deterministic, and fixed size numerical string (the hash) which can’t be reverse engineered to get the input data without deploying disproportionate resources. It is the foundation of modern security solutions in DLT / blockchain as they help in verifying the integrity and authenticity of the message.

      Decentralized identity (DID) or self-sovereign identity: This is a way to give back the control of identity to the subject whose identity it is, using an identity wallet in which they collect verified information about themselves from certified issuers (such as the government). By controlling what information is shared from the wallet to requesting third parties (e.g. when registering for a new online service), the user can better manage their privacy, such as only presenting proof that they’re over 18 without needing to reveal their date of birth. Source: (https://www.gsma.com/identity/decentralised-identity)

      Digital identity wallet: A type of digital wallet refers to a secure, trusted software applications (native mobile app, mobile web apps, or Rivas-hosted web applications) based on common standards, allowing a user to store and use their identity attributes, identifiers, and other credentials without loosing or sharing control of them. This is different than Digital Payment Wallets used for financial transactions. (Source: https://www.worldbank.org/content/dam/photos/1440x300/2022/feb/eID_WB_presentation_BS.pdf)

      Digital identity: A digital identity is primarily an electronic form of identity representing an entity uniquely , while abstracting all other identity attributes of the entity. In addition to an electronic form, it may also exist in a physical form (identity certificate), linked through an identifier representing the same entity. E.g. Estonia eID , India Aadhar, digital citizenship ID.

      Digital object architecture: DOA is an open architecture for interoperability among various information systems, including ID wallets, identity providers, and consumers. It focuses on digital objects and comprises three core components: the identifier/resolution system, the repository system, and the registry system. There are also two protocols that connect these components. (Source: dona.net)

      Digital signature: A digital signature is an electronic, encrypted stamp of authentication on digital information such as email messages, macros, or electronic documents. A signature confirms that the information originated from the signer and has not been altered. (Source: Microsoft)

      Taxonomy – Digital ID ecosystem

      (Alphabetical order)

      Continues..

      Entity (or Subject): In the context of identity, an entity is a person, group, object, or a machine whose claims need to be ascertained and identity needs to be established before his request for a service or products can be fulfilled. An entity can also be referred to as a subject whose identity needs to be ascertained before delivering a service.

      Expiry: This is another dimension of an identity and determines the validity of an ID. Most of the identities are longer term, but there can be a few like digital tokens and URLs which can be issued for a few hours or even minutes. There are some which can be revoked after a pre-condition is met.

      Federated identity: Federated identity is an agreement between two organizations about the definition and use of identity attributes and identifiers of a consumer entity requesting a service. If successful, it allows a consumer entity to get authenticated by one organization (identity provider) and then authorized by another organization. E.g. accessing a third-party website using Google credentials.

      Foundational identity: A type of identity which establishes an entity’s existence in the real world. These are generally issued by public sector / government agencies, governed by a legal farmwork within a jurisdiction, and are widely accepted at least in that jurisdiction. E.g. birth certificate, citizenship certificate.

      Governance: This is a dimension of identity that covers the governance model for a digital ID ecosystem. While traditionally it has been under the sovereign government or a federated structure, in recent times, it has been decentralized through DLT technologies or trust-framework based. It can also be self-sovereign, where individuals fully control their data and ID attributes.

      Identifier: A digital identifier is a string of characters that uniquely represents an entity’s identity in a specific context and scope even if one or more identity attributes of the subject change over time. E.g. driver’s license, SSN, SIN, email ID, digital token, user ID, device ID, cookie ID.

      Identity: An identity is an instrument used by an entity to provide the required information about itself to another entity in order to avail a service, access a resource, or exercise a privilege. An identity formed by 1-n identity attributes and a unique identifier.

      Identity and access management (IAM): IAM is a set of frameworks, technologies, and processes to enable the creation, maintenance, and use of digital identity, ensuring that the right people gain access to the right materials and records at the right time. (Source: https://iam.harvard.edu/)

      Identity consumer (Relying party): An organization, or an entity relying on identity provider to mitigate IT risks around knowing its customers before delivering the end-user value (product/service) without deteriorating end-user experience. E.g. Canada Revenue Agency using SecureKey service and relying on Banking institutions to authenticate users; Telecom service providers in India relying on Aadhaar identity system to authenticate the customer's identity.

      Identity form: A dimension of identity that defines its forms depending on the scope it wants to serve. It can be a physical card for offline uses, a virtual identifier like a number, or an app/account with multiple identity attributes. Cryptographic keys and tokens can also be forms of identity.

      Taxonomy – Digital ID ecosystem

      (Alphabetical order)

      Continues...

      Identity infrastructure provider: Organizations involved in creating and maintaining technological infrastructure required to manage the lifecycle of digital identities, attributes, and credentials. They implement functions like security, privacy, resiliency, and user experience as specified in the digital identity policy and trust framework.

      Identity proofing: A process of asserting the identification of a subject at a useful identity assurance level when the subject provides evidence to a credential service provider (CSP), reliably identifying themselves. (Source: NIST Special Publication 800-63A)

      Identity provider (Attestation authority): An organization or an entity validating the foundation or contextual claims of a subject and establishing identifier(s) for a subject. E.g. DMV (US) and MTA (Canada) issuing drivers’ licenses; Google / Facebook issuing authentication tokens for their users logging in on other websites.

      Identity validation: The process of confirming or denying the accuracy of identity information of a subject as established by an authorized party. It doesn’t ensure that the presenter is using their own identity.

      Identity verification (Authentication): The process of confirming or denying that the identity presented relates to the subject who is making the claim by comparing the credentials presented with the ones presented during identity proofing.

      Internationalized resource identifier (IRI): IRIs are equivalent to URIs except that IRIs also allow non-ascii characters in the address space, while URIs only allow us-ascii encoding. (Source: w3.org)

      Jurisdiction: A dimension of identity that covers the physical area or virtual space where an identity is legally acceptable for the purpose defined under law. It can be global, like it is for passport, or it can be local within a municipality for specific services. For unverified digital IDs, it can be the social network.

      Multi-factor Authentication (MFA): Multi-factor authentication is a layered approach to securing digital assets (data and applications), where a system requires a user to present a combination of two or more credentials to verify a user’s identity for login. These factors can be a combination of (i) something you know like a password/PIN; (ii) something you have like a token on mobile device; and (iii) something you are like a biometric. (Adapted from https://www.cisa.gov/publication/multi-factor-authentication-mfa)

      Oauth (Open authorization): OAuth is a standard authorization protocol and used for access delegation. It allows internet users to access websites by using credentials managed by a third-party authorization server / Identity Provider. It is designed for HTTP and allows access tokens to be issued by an authorization server to third-party websites. E.g. Google, Facebook, Twitter, LinkedIn use Oauth to delegate access.

      OpenID: OpenID is a Web Authentication Protocol and implements reliance authentication mechanism. It facilitates the functioning of federated identity by allowing a user to use an existing account (e.g. Google, Facebook, Yahoo) to sign into third-party websites without needing to create new credentials. (Source: https://openid.net/).

      Taxonomy – Digital ID ecosystem

      (Alphabetical order)

      Continues...

      Personally identifiable information (PII): PII is a set of attributes which can be used, through direct or indirect means, to infer the real-world identity of the individual whose information is input. E.g. National ID (SSN/SIN/Aadhar) DL, name, date of birth, age, address, age, identifier, university credentials, health condition, email, domain name, website URI (web resolvable) , phone number, credit card number, username/password, public key / private key. (Source: https://www.dol.gov)

      Predicates: The mathematical or logical operations such as equality or greater than on attributes (e.g. prove your salary is greater than x or your age is greater than y) to prove a claim without sharing the actual values.

      Purpose: This dimension of a digital id defines for what purpose digital id can be used. It can be one or many of these – authentication, authorization, activity linking, historical record keeping, social interactions, and machine connectivity for IoT use cases.

      Reliance authentication: Relying on a third-party authentication before providing a service. It is a method followed in a federated entity system.

      Risk-based authentication: A mechanism to protect against account compromise or identity theft. It correlates an authentication request with transitional facts like requester’s location, past frequency of login, etc. to reduce the risk of potential fraud.

      Scheme in trust framework: A specific set of rules (standard and custom) around the use of digital identities and attributes as agreed by one or more organizations. It is useful when those organizations have similar products, services, business processes. (Source: UK Govt. Trust Framework). E.g. Many credit unions agree on how they will use the identity in loan origination and servicing.

      Selective disclosure (Assertion): A way to present one’s identity by sharing only a limited amount information that is critical to make an authentication / authorization decision. E.g. when presenting your credentials, you could share something proving you are 18 years or above, but not share your name, exact age, address, etc.

      Trust: A dimension of an identity, which essentially is a belief in the reliability, truth, ability, or strength of that identity. While in the physical world all acceptable form of identities come with a verified trust, in online domain, it can be unverified. Also, where an identity is only acceptable as per the contract between two entities, but not widely.

      Trust framework: The trust framework is a set of rules that different organizations agree to follow to deliver one or more of their services. This includes legislation, standards, guidance, and the rules in this document. By following these rules, all services and organizations using the trust framework can describe digital identities and attributes they’ve created in a consistent way. This should make it easier for organizations and users to complete interactions and transactions or share information with other trust framework participants. (Source: UK Govt. Trust Framework)

      Taxonomy – Digital ID ecosystem

      (Alphabetical order)

      Continues...

      Uniform resource identifier (URI): A universal name in registered name spaces and addresses referring to registered protocols or name spaces.

      Uniform resource locator (URL): A type of URI which expresses an address which maps onto an access algorithm using network protocols. (Source: https://www.w3.org/)

      Uniform resource name (URN): A type of URI that includes a name within a given namespace but may not be accessible on the internet.

      Usability: A dimension of identity that defines how many times it can be used. While most of the identities are multi-use, a few digital identities are in token form and can be used only once to authenticate oneself.

      Usage mode: A dimension of identity that defines the service mode in which a digital ID can be used. While all digital IDs are made for online usage, many can also be used in offline interactions.

      Verifiable credentials: This W3C standard specification provides a standard way to express credentials on the Web in a way that is cryptographically secure, privacy-respecting, and machine-verifiable. (Source: https://www.w3.org/TR/vc-data-model/)

      X.509 Certificates: X.509 certificates are standard digital documents that represent an entity providing a service to another entity. They're issued by a certification authority (CA), subordinate CA, or registration authority. These certificates play an important role in ascertaining the validity of an identity provider and in turn the identities issued by it. (Source: https://learn.microsoft.com/en-us/azure/iot-hub/reference-x509-certificates)

      Zero-knowledge proofs: A method by which one party (the prover) can prove to another party (the verifier) that something is true, without revealing any information apart from the fact that this specific statement is true. (Source: 1989 SIAM Paper)

      Zero-trust security: A cybersecurity paradigm focused on resource protection and the premise that trust is never granted implicitly but must be continually evaluated. It evaluates each access request as if it is a fraud attempt, and grants access only if it passes the authentication and authorization test. (Source: Adapted from NIST, SP 800-207: Zero Trust Architecture, 2020)

      Related Info-Tech Research

      Build a Zero Trust Roadmap
      Leverage an iterative and repeatable process to apply zero trust to your organization.

      Assess and Govern Identity Security
      Strong identity security and governance are the keys to the zero-trust future.

      Adopt Design Thinking in Your Organization
      Innovation needs design thinking to ensure customer remains at the center of everything the organization does.

      Social Media
      Leveraging Social Media to connect with your customers and educate them to drive the value proposition of your efforts.

      IT Diversity & Inclusion Tactics
      Equip your teams to create an inclusive environment and mobilize inclusion efforts across the organization.


      Research Contributors and Experts

      David Wallace

      David Wallace
      Executive Counselor

      Erik Avakian

      Erik Avakian
      Technical Counselor, Data Architecture and Governance

      Matthew Bourne

      Matthew Bourne
      Managing Partner, Public Sector Global Services

      Mike Tweedie

      Mike Tweedie
      Practice Lead, CIO Research Development

      Aaron Shum

      Aaron Shum
      Vice President, Security & Privacy

      Works Cited

      India Aadhaar PMJDY (https://pmjdy.gov.in/account)
      Theis, S., Rusconi, G., Panggabean, E., Kelly, S. (2020). Delivering on the Potential of Digitized G2P: Driving Women’s Financial Inclusion and Empowerment through Indonesia’s Program Keluarga Harapan. Women’s World Banking.
      DIACC Canada (https://diacc.ca/the-diacc/)
      UK digital identity & attributes trust framework alpha v2 (0.2) - GOV.UK (https://www.gov.uk/government/publications/uk-digital-identity-attributes-trust-framework-updated-version/uk-digital-identity-and-attributes-trust-framework-alpha-version-2)
      Australia Trusted Digital Identity Framework (https://www.digitalidentity.gov.au/tdif#changes)
      eIDAS (https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation)
      Europe Digital Wallet – POTENTIAL (https://www.digital-identity-wallet.eu/)
      Canada PCTF (https://diacc.ca/trust-framework/)
      Identification Revolution: Can Digital ID be harnessed for Development? (Gelb & Metz), 2018
      e-Estonia website (https://e-estonia.com/solutions/e-identity/id-card/)
      Aadhaar Dashboard (https://uidai.gov.in/)
      DIACC Website (https://diacc.ca/the-diacc/)
      Australia Digital ID website (https://www.digitalidentity.gov.au/tdif#changes)
      UK Policy paper - digital identity & attributes trust framework (https://www.gov.uk/government/publications/uk-digital-identity-attributes-trust-framework-updated-version/uk-digital-identity-and-attributes-trust-framework-alpha-version-2)
      Ukraine Govt. website (https://ukraine.ua/invest-trade/digitalization/)
      Singapore SingPass Website (https://www.tech.gov.sg/products-and-services/singpass/)
      Norway BankID Website (https://www.bankid.no/en/private/about-us/)
      Brazil National ID Card website (https://www.gov.br/casacivil/pt-br/assuntos/noticias/2022/julho/nova-carteira-de-identidade-nacional-modelo-unico-a-partir-de-agosto)
      Indonesia Coverage in Professional Security Magazine (https://www.professionalsecurity.co.uk/products/id-cards/indonesian-cards/)
      Philippine ID System (PhilSys) website (https://www.philsys.gov.ph/)
      China coverage on eGovReview (https://www.egovreview.com/article/news/559/china-announces-plans-national-digital-ids)
      Thales Group Website - DHS’s Automated Biometric Identification System IDENT (https://www.thalesgroup.com/en/markets/digital-identity-and-security/government/customer-cases/ident-automated-biometric-identification-system)
      FranceConnect (https://franceconnect.gouv.fr/)
      Germany: Office for authorization cert. (https://www.personalausweisportal.de/Webs/PA/DE/startseite/startseite-node.html)
      Italian Digital Services Authority (https://www.spid.gov.it/en/)
      Monacco Mconnect (https://mconnect.gouv.mc/en)
      Estonia eID (https://e-estonia.com/wp-content/uploads/e-estonia-211022_eng.pdf)
      E-Residency Dashboard (https://www.e-resident.gov.ee/dashboard)
      Unique ID authority of India (https://uidai.gov.in/aadhaar_dashboard/india.php)
      State of Aadhaar (https://www.stateofaadhaar.in/)
      World Bank (https://documents1.worldbank.org/curated/en/219201522848336907/pdf/Private-Sector-Economic-Impacts-from-Identification-Systems.pdf)
      WorldBank - ID4D 2022 Annual Report (https://documents.worldbank.org/en/publication/documents-reports/documentdetail/099437402012317995/idu00fd54093061a70475b0a3b50dd7e6cdfe147)
      Ukraine Govt. Website for Invest and trade (https://ukraine.ua/invest-trade/digitalization/)
      Diia Case study prepared for the office of Canadian senator colin deacon (https://static1.squarespace.com/static/63851cbda1515c69b8a9a2b9/t/6398f63a9d78ae73d2fd5725/1670968891441/2022-case-study-report-diia-mobile-application.pdf)
      Canadian Digital Identity Research (https://diacc.ca/wp-content/uploads/2022/04/DIACC-2021-Research-Report-ENG.pdf)
      Voilà Verified Trustmark (https://diacc.ca/voila-verified/)
      Digital Identity, 06A Federation Onboarding Guidance paper, March 2022 (https://www.digitalidentity.gov.au/sites/default/files/2022-04/TDIF%2006A%20Federation%20Onboarding%20Guidance%20-%20Release%204.6%20%28Doc%20Version%201.2%29.pdf)
      UK digital identity & attributes trust framework alpha v2 (0.2) - GOV.UK (https://www.gov.uk/government/publications/uk-digital-identity-attributes-trust-framework-updated-version/uk-digital-identity-and-attributes-trust-framework-alpha-version-2)
      A United Nations Estimate of KYC/AML (https://www.imf.org/Publications/fandd/issues/2018/12/imf-anti-money-laundering-and-economic-stability-straight)
      India Aadhaar PMJDY (https://pmjdy.gov.in/account)
      Global News (https://globalnews.ca/news/9437913/homeowner-impersonators-lined-32-fraud-cases-ontario-bc/)
      UK Finance Lobby Group (https://www.ukfinance.org.uk/system/files/Half-year-fraud-update-2021-FINAL.pdf) McKinsey Digital ID report ( https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/digital-identification-a-key-to-inclusive-growth) International Peace Institute ( https://www.ipinst.org/2016/05/information-technology-and-governance-estonia#7)
      E-Estonia Report (https://e-estonia.com/wp-content/uploads/e-estonia-211022_eng.pdf)
      2022 Budget Statement (https://diacc.ca/2022/04/07/2022-budget-statement/)
      World Bank ID4D - Private Sector Economic Impacts from Identification Systems 2018 (https://documents1.worldbank.org/curated/en/219201522848336907/Private-Sector-Economic-Impacts-from-Identification-Systems.pdf)
      DIACC Canada (https://diacc.ca/the-diacc/)
      UK digital identity & attributes trust framework alpha v2 (0.2) - GOV.UK (https://www.gov.uk/government/publications/uk-digital-identity-attributes-trust-framework-updated-version/uk-digital-identity-and-attributes-trust-framework-alpha-version-2)
      https://www.gsma.com/identity/decentralised-identity
      https://www.worldbank.org/content/dam/photos/1440x300/2022/feb/eID_WB_presentation_BS.pdf
      Microsoft Digital signatures and certificates (https://support.microsoft.com/en-us/office/digital-signatures-and-certificates-8186cd15-e7ac-4a16-8597-22bd163e8e96)
      https://www.worldbank.org/content/dam/photos/1440x300/2022/feb/eID_WB_presentation_BS.pdf
      https://www.dona.net/digitalobjectarchitecture
      IAM (https://iam.harvard.edu/)
      NIST Special Publication 800-63A (https://pages.nist.gov/800-63-3/sp800-63a.html)
      https://www.cisa.gov/publication/multi-factor-authentication-mfa
      https://openid.net/
      U.S. DEPARTMENT OF LABOR (https://www.dol.gov/)
      UK govt. trust framework (https://www.gov.uk/government/publications/uk-digital-identity-attributes-trust-framework-updated-version/uk-digital-identity-and-attributes-trust-framework-alpha-version-2)
      https://www.w3.org/
      Verifiable Credentials Data Model v1.1 (https://www.w3.org/TR/vc-data-model/)
      https://learn.microsoft.com/en-us/azure/iot-hub/reference-x509-certificates

      Document Your Cloud Strategy

      • Buy Link or Shortcode: {j2store}468|cart{/j2store}
      • member rating overall impact: 8.9/10 Overall Impact
      • member rating average dollars saved: $35,642 Average $ Saved
      • member rating average days saved: 21 Average Days Saved
      • Parent Category Name: Cloud Strategy
      • Parent Category Link: /cloud-strategy

      Despite the universally agreed-upon benefit of formulating a coherent strategy, several obstacles make execution difficult:

      • Inconsistent understanding of what the cloud means
      • Inability to come to a consensus on key decisions
      • Ungoverned decision-making
      • Unclear understanding of cloud roles and responsibilities

      Our Advice

      Critical Insight

      A cloud strategy might seem like a big project, but it’s just a series of smaller conversations. The methodology presented here is designed to facilitate those conversations, using a curated list of topics, prompts, participant lists, and sample outcomes. We have divided the strategy into four key areas:

      • Vision and alignment
      • People
      • Governance
      • Technology

      Impact and Result

      • A shared understanding of what is necessary to succeed in the cloud
      • An end to ad hoc deployments that solve small problems and create larger ones
      • A unified approach and set of principles that apply to governance, architecture, integration, skills, and roles (and much, much more).

      Document Your Cloud Strategy Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Document Your Cloud Strategy – a phased guide to identifying, validating, and recording the steps you’ll take, the processes you’ll leverage, and the governance you’ll deploy to succeed in the cloud.

      This storyboard comprises four phases, covering mission and vision, people, governance, and technology, and how each of these areas requires forethought when migrating to the cloud.

      • Document Your Cloud Strategy – Phases 1-4

      2. Cloud Strategy Document Template – a template that allows you to record the results of the cloud strategy exercise in a clear, readable way.

      Each section of Document Your Cloud Strategy corresponds to a section in the document template. Once you’ve completed each exercise, you can record your results in the document template, leaving you with an artifact you can share with stakeholders.

      • Cloud Strategy Document Template
      [infographic]

      Workshop: Document Your Cloud Strategy

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Document Your Vision and Alignment

      The Purpose

      Understand and document your cloud vision and its alignment with your other strategic priorities.

      Key Benefits Achieved

      A complete understanding of your strategy, vision, alignment, and a list of success metrics that will help you find your way.

      Activities

      1.1 Record your cloud mission and vision.

      1.2 Document your cloud strategy’s alignment with other strategic plans.

      1.3 Record your cloud guiding principles.

      Outputs

      Documented strategy, vision, and alignment.

      Defined success metrics.

      2 Record Your People Strategy

      The Purpose

      Define how people, skills, and roles will contribute to the broader cloud strategy.

      Key Benefits Achieved

      Sections of the strategy that highlight skills, roles, culture, adoption, and the creation of a governance body.

      Activities

      2.1 Outline your skills and roles strategy.

      2.2 Document your approach to culture and adoption

      2.3 Create a cloud governing body.

      Outputs

      Documented people strategy.

      3 Document Governance Principles

      The Purpose

      This section facilitates governance in the cloud, developing principles that apply to architecture, integration, finance management, and more.

      Key Benefits Achieved

      Sections of the strategy that define governance principles.

      Activities

      3.1 Conduct discussion on architecture.

      3.2 Conduct discussion on integration and interoperability.

      3.3 Conduct discussion on operations management.

      3.4 Conduct discussion on cloud portfolio management.

      3.5 Conduct discussion on cloud vendor management.

      3.6 Conduct discussion on finance management.

      3.7 Conduct discussion on security.

      3.8 Conduct discussion on data controls.

      Outputs

      Documented cloud governance strategy.

      4 Formalize Your Technology Strategy

      The Purpose

      Creation of a formal cloud strategy relating to technology around provisioning, monitoring, and migration.

      Key Benefits Achieved

      Completed strategy sections of the document that cover technology areas.

      Activities

      4.1 Formalize organizational approach to monitoring.

      4.2 Document provisioning process.

      4.3 Outline migration processes and procedures.

      Outputs

      Documented cloud technology strategy.

      Further reading

      Document Your Cloud Strategy

      Get ready for the cloudy future with a consistent, proven strategy.

      Analyst perspective

      Any approach is better than no approach

      The image contains a picture of Jeremy Roberts

      Moving to the cloud is a big, scary transition, like moving from gas-powered to electric cars, or from cable to streaming, or even from the office to working from home. There are some undeniable benefits, but we must reorient our lives a bit to accommodate those changes, and the results aren’t always one-for-one. A strategy helps you make decisions about your future direction and how you should respond to changes and challenges. In Document Your Cloud Strategy we hope to help you accomplish just that: clarifying your overall mission and vision (as it relates to the cloud) and helping you develop an approach to changes in technology, people management, and, of course, governance. The cloud is not a panacea. Taken on its own, it will not solve your problems. But it can be an important tool in your IT toolkit, and you should aim to make the best use of it – whatever “best” happens to mean for you.

      Jeremy Roberts

      Research Director, Infrastructure and Operations

      Info-Tech Research Group

      Executive Summary

      Your Challenge

      The cloud is multifaceted. It can be complicated. It can be expensive. Everyone has an opinion on the best way to proceed – and in many cases has already begun the process without bothering to get clearance from IT. The core challenge is creating a coherent strategy to facilitate your overall goals while making the best use of cloud technology, your financial resources, and your people.

      Common Obstacles

      Despite the universally agreed-upon benefit of formulating a coherent strategy, several obstacles make execution difficult:

      • Inconsistent understanding of what the cloud means
      • Inability to come to a consensus on key decisions
      • Ungoverned decision making
      • Unclear understanding of cloud roles and responsibilities

      Info-Tech’s Approach

      A cloud strategy might seem like a big project, but it’s just a series of smaller conversations. The methodology presented here is designed to facilitate those conversations, using a curated list of topics, prompts, participant lists, and sample outcomes. We have divided the strategy into four key areas:

      1. Vision and alignment
      2. People
      3. Governance
      4. Technology

      The answers might be different, but the questions are the same

      Every organization will approach the cloud differently, but they all need to ask the same questions: When will we use the cloud? What forms will our cloud usage take? How will we manage governance? What will we do about people? How will we incorporate new technology into our environment? The answers to these questions are as numerous as there are people to answer them, but the questions must be asked.

      Your challenge

      This research is designed to help organizations that are facing these challenges or looking to:

      • Ensure that the cloud strategy is complete and accurately reflects organizational goals and priorities.
      • Develop a consistent and coherent approach to adopting cloud services.
      • Design an approach to mitigate risks and challenges associated with adopting cloud services.
      • Create a shared understanding of the expected benefits of cloud services and the steps required to realize those benefits.

      Grappling with a cloud strategy is a top initiative: 43% of respondents report progressing on a cloud-first strategy as a top cloud initiative.

      Source: Flexera, 2021.

      Definition: Cloud strategy

      A document providing a systematic overview of cloud services, their appropriate use, and the steps that an organization will take to maximize value and minimize risk.

      Common obstacles

      These barriers make this challenge difficult to address for many organizations:

      • The cloud means different things to different people, and creating a strategy that is comprehensive enough to cover a multitude of use cases while also being written to be consumable by all stakeholders is difficult.
      • The incentives to adopt the cloud differ based on the expected benefit for the individual customer. User-led decision making and historically ungoverned deployments can make it difficult to reset expectation and align with a formal strategy.
      • Getting all the right people in a room together to agree on the key components of the strategy and the direction undertaken for each one is often difficult.

      Info-Tech’s approach

      Define Your Cloud Vision

      Vision and alignment

      • Mission and vision
      • Alignment to other strategic plans
      • Guiding principles
      • Measuring success

      Technology

      • Monitoring
      • Provisioning
      • Migration

      Governance

      • Architecture
      • Integration and interoperability
      • Operations management
      • Cloud portfolio management
      • Cloud vendor management
      • Finance management
      • Security
      • Data controls

      People

      • Skills and roles
      • Culture and adoption
      • Governing bodies

      Info-Tech’s approach

      Your cloud strategy will comprise the elements listed under “vision and alignment,” “technology,” “governance,” and “people.” The Info-Tech methodology involves breaking the strategy down into subcomponents and going through a three-step process for each one. Start by reviewing a standard set of questions and understanding the goal of the exercise: What do we need to know? What are some common considerations and best practices? Once you’ve had a chance to review, discuss your current state and any gaps: What has been done? What still needs to be done? Finally, outline how you plan to go forward: What are your next steps? Who needs to be involved?

      Review

      • What questions do we need to answer to complete the discussion of this strategy component? What does the decision look like?
      • What are some key terms and best practices we must understand before deciding?

      Discuss

      • What steps have we already taken to address this component?
      • Does anything still need to be done?
      • Is there anything we’re not sure about or need further guidance on?

      Go forward

      • What are the next steps?
      • Who needs to be involved?
      • What questions still need to be asked/answered?
      • What should the document’s wording look like?

      Info-Tech’s methodology for documenting your cloud strategy

      1. Document your vision and alignment

      2. Record your people strategy

      3. Document governance principles

      4. Formalize your technology strategy

      Phase Steps

      1. Record your cloud mission and vision
      2. Document your cloud strategy’s alignment with other strategic plans
      3. Record your cloud guiding principles
      4. Define success
      1. Outline your skills and roles strategy
      2. Document your approach to culture and adoption
      3. Create a cloud governing body

      Document official organizational positions in these governance areas:

      1. Architecture
      2. Integration and interoperability
      3. Operations management
      4. Cloud portfolio management
      5. Cloud vendor management
      6. Finance management
      7. Security
      8. Data controls
      1. Formalize organizational approach to monitoring
      2. Document provisioning process
      3. Outline migration processes and procedures

      Phase Outcomes

      Documented strategy: vision and alignment

      Documented people strategy

      Documented cloud governance strategy

      Documented cloud technology strategy

      Insight summary

      Separate strategy from tactics

      Separate strategy from tactics! A strategy requires building out the framework for ongoing decision making. It is meant to be high level and achieve a large goal. The outcome of a strategy is often a sense of commitment to the goal and better communication on the topic.

      The cloud does not exist in a vacuum

      Your cloud strategy flows from your cloud vision and should align with the broader IT strategy. It is also part of a pantheon of strategies and should exist harmoniously with other strategies – data, security, etc.

      People problems needn’t preponderate

      The cloud doesn’t have to be a great disruptor. If you handle the transition well, you can focus your people on doing more valuable work – and this is generally engaging.

      Governance is a means to an end

      Governing your deployment for its own sake will only frustrate your end users. Articulate the benefits users and the organization can expect to see and you’re more likely to receive the necessary buy-in.

      Technology isn’t a panacea

      Technology won’t solve all your problems. Technology is a force multiplier, but you will still have to design processes and train your people to fully leverage it.

      Key deliverable

      Cloud Strategy Document template

      Inconsistency and informality are the enemies of efficiency. Capture the results of the cloud strategy generation exercises in the Cloud Strategy Document template.

      The image contains a screenshot of the Cloud Strategy Document Template.
      • Record the results of the exercises undertaken as part of this blueprint in the Cloud Strategy Document template.
      • It is important to remember that not every cloud strategy will look exactly the same, but this template represents an amalgamation of best practices and cloud strategy creation honed over several years of advisory service in the space.
      • You know your audience better than anyone. If you would prefer a strategy delivered in a different way (e.g. presentation format) feel free to adapt the Cloud Vision Executive Presentation into a longer strategy presentation.
      • Emphasis is an area where you should exercise discretion as well. A cost-oriented cloud strategy, or one that prioritizes one type of cloud (e.g. SaaS) at the exclusion of others, may benefit from more focus on some areas than others, or the introduction of relevant subcategories. Include as many of these as you think will be relevant.
      • Parsimony is king – if you can distill a concept to its essence, start there. Include additional detail only as needed. You want your cloud strategy document to be read. If it’s too long or overly detailed, you’ll encounter readability issues.

      Blueprint benefits

      IT benefits

      Business benefits

      • A consistent, well-defined approach to the cloud
      • Consensus on key strategy components, including security, architecture, and integration
      • A clear path forward on skill development and talent acquisition/retention
      • A comprehensive resource for information about the organization’s approach to key strategy components
      • Predictable access to cloud services
      • A business-aligned approach to leveraging the resources available in the cloud
      • Efficient and secure consumption of cloud resources where appropriate to do so
      • Answers to questions about the cloud and how it will be leveraged in the environment

      Measure the value of this blueprint

      Don’t take our word for it:

      • Document Your Cloud Strategy has been available for several years in various forms as both a workshop and as an analyst-led guided implementation.
      • After each engagement, we send a survey that asks members how they benefited from the experience. Those who have worked through Info-Tech’s cloud strategy material have given overwhelmingly positive feedback.
      • Additionally, members reported saving between 10 and 20 days and an average of $46,499.
      • Measure the value by calculating the time saved as a result of using Info-Tech’s framework vs. a home-brewed cloud strategy alternative and by comparing the overall cost of a guided implementation or workshop with the equivalent offering from another firm. We’re confident you’ll come out ahead.

      8.8/10 Average reported satisfaction

      13 Days Average reported time savings

      $46,499 Average cost savings

      Executive Brief Case Study

      INDUSTRY: Pharmaceuticals

      SOURCE: Info-Tech workshop

      Pharmaceutical company

      The unnamed pharmaceutical company that is the subject of this case study was looking to make the transition to the cloud. In the absence of a coherent strategy, the organization had a few cloud deployments with no easily discernable overall approach. Representatives of several distinct functions (legal, infrastructure, data, etc.) all had opinions on the uses and abuses of cloud services, but it had been difficult to round everyone up and have the necessary conversations. As a result, the strategy exercise had not proceeded in a speedy or well-governed way. This lack of strategic readiness presented a roadblock to moving forward with the cloud strategy and to work with the cloud implementation partner, tasked with execution.

      Results

      The company engaged Info-Tech for a four-day workshop on cloud strategy documentation. Over the course of four days, participants drawn from across the organization discussed the strategic components and generated consensus statements and next steps. The team was able to formalize the cloud strategy and described the experience as saving 10 days.

      Example output: Document your cloud strategy workshop exercise

      The image contains an example of Document your cloud streatgy workshop exercise.

      Anything in green, the team was reasonably sure they had good alignment and next steps. Those yellow flags warranted more discussion and were not ready for documentation.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful."

      Guided Implementation

      "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track."

      Workshop

      "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place."

      Consulting

      "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

      Diagnostics and consistent frameworks are used throughout all four options.

      Guided Implementation

      What does a typical GI on this topic look like?

      Document your vision and alignment

      Record your people strategy

      Document governance principles

      Formalize your technology strategy

      Call #1: Review existing vision/strategy documentation.

      Call #2: Review progress on skills, roles, and governance bodies.

      Call #3: Work through integration, architecture, finance management, etc. based on reqs. (May be more than one call.)

      Call #4: Discuss challenges with monitoring, provisioning, and migration as-needed.

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization. A typical GI is 4 to 6 calls over the course of 1 to 3 months

      Workshop Overview

      Contact your account representative for more information.

      workshops@infotech.com 1-888-670-8889

      Day 1

      Day 2

      Day 3

      Day 4

      Day 5

      Answer
      “so what?”

      Define the
      IT target state

      Assess the IT
      current state

      Bridge the gap and
      create the strategy

      Next steps and
      wrap-up (offsite)

      Activities

      1.1 Introduction

      1.2 Discuss cloud mission and vision

      1.3 Discuss alignment with other strategic plans

      1.4 Discuss guiding principles

      1.5 Define success metrics

      2.1 Discuss skills and roles

      2.2 Review culture and adoption

      2.3 Discuss a cloud governing body

      2.4 Review architecture position

      2.5 Discuss integration and interoperability

      3.1 Discuss cloud operations management

      3.2 Review cloud portfolio management

      3.3 Discuss cloud vendor management

      3.4 Discuss cloud finance management

      3.5 Discuss cloud security

      4.1 Review and formalize data controls

      4.2 Design a monitoring approach

      4.3 Document the workload provisioning process

      4.4 Outline migration processes and procedures

      5.1 Populate the Cloud Strategy Document

      Deliverables

      Formalized cloud mission and vision, along with alignment with strategic plans, guiding principles, and success metrics

      Position statement on skills and roles, culture and adoption, governing bodies, architecture, and integration/interoperability

      Position statements on cloud operations management, portfolio management, vendor management, finance management, and cloud security

      Position statements on data controls, monitoring, provisioning, and migration

      Completed Cloud Strategy Document

      Phase 1

      Document Your Vision and Alignment

      Phase 1

      Phase 2

      Phase 3

      Phase 4

      1.1 Document your mission and vision

      1.2 Document alignment to other strategic plans

      1.3 Document guiding principles

      1.4 Document success metrics

      2.1 Define approach to skills and roles

      2.2 Define approach to culture and adoption

      2.3 Define cloud governing bodies

      3.1 Define architecture direction

      3.2 Define integration approach

      3.3 Define operations management process

      3.4 Define portfolio management direction

      3.5 Define vendor management direction

      3.6 Document finance management tactics

      3.7 Define approach to cloud security

      3.8 Define data controls in the cloud

      4.1 Define cloud monitoring strategy

      4.2 Define cloud provisioning strategy

      4.3 Define cloud migration strategy

      This phase will walk you through the following activities:

      1. Record your cloud mission and vision
      2. Document your cloud strategy’s alignment with other strategic plans
      3. Record your cloud guiding principles
      4. Define success

      This phase has the following outcome:

      • Documented strategy: vision and alignment

      Record your mission and vision

      Build on the work you’ve already done

      Before formally documenting your cloud strategy, you should ensure that you have a good understanding of your overall cloud vision. How do you plan to leverage the cloud? What goals are you looking to accomplish? How will you distribute your workloads between different cloud service models (SaaS, PaaS, IaaS)? What will your preferred delivery model be (public, private, hybrid)? Will you support your cloud deployment internally or use the services of various consultants or managed service providers?

      The answers to these questions will inform the first section of your cloud strategy. If you haven’t put much thought into this or think you could use a deep dive on the fundamentals of your cloud vision and cloud archetypes, consider reviewing Define Your Cloud Vision, the companion blueprint to this one.

      Once you understand your cloud vision and what you’re trying to accomplish with your cloud strategy, this phase will walk you through aligning the strategy with other strategic initiatives. What decisions have others made that will impact the cloud strategy (or that the cloud strategy will impact)? Who must be involved/informed? What callouts must be involved at what point? Do users have access to the appropriate strategic documentation (and would they understand it if they did)?

      You must also capture some guiding principles. A strategy by its nature provides direction, helping readers understand the decisions they should make and why those decisions align with organizational interests. Creating some top-level principles is a useful exercise because those principles facilitate comprehension and ensure the strategy’s applicability.

      Finally, this phase will walk you through the process of measuring success. Once you know where you’d like to go, the principles that underpin your direction, and how your cloud strategy figures into the broader strategic pantheon, you should record what success actually means. If you’re looking to save money, overall cost should be a metric you track. If the cloud is all about productivity, generate appropriate productivity metrics. If you’re looking to expand into new technology or close a datacenter, you will need to track output specific to those overall goals.

      Review: mission and vision

      The overall organizational mission is a key foundational element of the cloud strategy. If you don’t understand where you’re going, how can you begin the journey to get there? This section of the strategy has four key parts that you should understand and incorporate into the beginning of the strategy document. If you haven’t already, review Define Your Cloud Vision for instructions on how to generate these elements.

      1. Cloud vision statement: This is a succinct encapsulation of your overall perspective on the suitability of cloud services for your environment – what you hope to accomplish. The ideal statement includes a scope (who/what does the strategy impact?), a goal (what will it accomplish?), and a key differentiator (what will make it happen?). This is an example: “[Organization] will leverage public cloud solutions and retire existing datacenter and colocation facilities. This transition will simplify infrastructure administration, support and security, while modernizing legacy infrastructure and reducing the need for additional capital expenditure.” You might also consider reviewing your overall cloud archetype (next slide) and including the output of that exercise in the document

      2. Service model decision framework: Services can be provided as software as a service (SaaS), platform as a service (PaaS), infrastructure as a service (IaaS), or they can be colocated or remain on premises. Not all cloud service models serve the same purpose or provide equal value in all circumstances. Understanding how you plan to take advantage of these distinct service models is an important component of the cloud strategy. In this section of the strategy, a rubric that captures the characteristics of the ideal workload for each of the named service models, along with some justification for the selection, is essential. This is a core component of Define Your Cloud Vision, and if you would like to analyze individual workloads, you can use the Cloud Vision Workbook for that purpose.

      3. Delivery model decision framework: Just as there are different cloud service models that have unique value propositions, there are several unique cloud delivery models as well, distinguished by ownership, operation, and customer base. Public clouds are the purview of third-party providers who make them available to paying customers. Private clouds are built for the exclusive use of a designated organization or group of organizations with internal clients to serve. Hybrid clouds involve the use of multiple, interoperable delivery models (interoperability is the key term here), while multi-cloud deployment models incorporate multiple delivery and service models into a single coherent strategy. What will your preferred delivery model be? Why?

      4. Support model decision framework: Once you have a service model nailed down and understand how you will execute on the delivery, the question then becomes about how you will support your cloud deployment going forward. Broadly speaking, you can choose to manage your deployment in house using internal resources (e.g. staff), to use managed service providers for ongoing support, or to hire consultants to handle specific projects/tasks. Each approach has its strengths and weaknesses, and many cloud customers will deploy multiple support models across time and different workloads. A foundational perspective on the support model is a key component of the cloud vision and should appear early in the strategy.

      Understand key cloud concepts: Archetype

      Once you understand the value of the cloud, your workloads’ general suitability for the cloud, and your proposed risks and mitigations, the next step is to define your cloud archetype. Your organization’s cloud archetype is the strategic posture that IT adopts to best support the organization’s goals. Info-Tech’s model recognizes seven archetypes, divided into three high-level archetypes. After consultation with your stakeholders, and based on the results of the suitability and risk assessment activities, define your archetype. The archetype feeds into the overall cloud vision and provides simple insight into the cloud future state for all stakeholders. The cloud vision itself is captured in a “vision statement,” a short summary of the overall approach that includes the overall cloud archetype.

      The image contains an arrow facing vertically up. The pointed end of the arrow is labelled more cloud, and the bottom of the arrow is labelled less cloud.

      We can best support the organization’s goals by:

      Cloud-Focused

      Cloud-Centric

      Providing all workloads through cloud delivery.

      Cloud-First

      Using the cloud as our default deployment model. For each workload, we should ask “why NOT cloud?”

      Cloud-Opportunistic

      Hybrid

      Enabling the ability to transition seamlessly between on-premises and cloud resources for many workloads.

      Integrated

      Combining cloud and traditional infrastructure resources, integrating data and applications through APIs or middleware.

      Split

      Using the cloud for some workloads and traditional infrastructure resources for others.

      Cloud-Averse

      Cloud-Light

      Using traditional infrastructure resources and limiting our use of the cloud to when it is absolutely necessary.

      Anti-Cloud

      Using traditional infrastructure resources and avoiding the use of cloud wherever possible.

      Implement Lean Management Practices That Work

      • Buy Link or Shortcode: {j2store}116|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Performance Measurement
      • Parent Category Link: /performance-measurement
      • Service delivery teams do not measure, or have difficulty demonstrating, the value they provide.
      • There is a lack of continuous improvement.
      • There is low morale within the IT teams leading to low productivity.

      Our Advice

      Critical Insight

      • Create a problem-solving culture. Frequent problem solving is the differentiator between sustaining Lean or falling back to old management methods.
      • Commit to employee growth. Empower teams to problem solve and multiply your organizational effectiveness.

      Impact and Result

      • Apply Lean management principles to IT to create alignment and transparency and drive continuous improvement and customer value.
      • Implement huddles and visual management.
      • Build team capabilities.
      • Focus on customer value.
      • Use metrics and data to make better decisions.
      • Systematically solve problems and improve performance.
      • Develop an operating rhythm to promote adherence to Lean.

      Implement Lean Management Practices That Work Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out how a Lean management system can help you increase transparency, demonstrate value, engage your teams and customers, continuously improve, and create alignment.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Understand Lean concepts

      Understand what a Lean management system is, review Lean philosophies, and examine simple Lean tools and activities.

      • Implement Lean Management Practices That Work – Phase 1: Understand Lean Concepts
      • Lean Management Education Deck

      2. Determine the scope of your implementation

      Understand the implications of the scope of your Lean management program.

      • Implement Lean Management Practices That Work – Phase 2: Determine the Scope of Your Implementation
      • Lean Management Scoping Tool

      3. Design huddle board

      Examine the sections and content to include in your huddle board design.

      • Implement Lean Management Practices That Work – Phase 3: Design Huddle Board
      • Lean Management Huddle Board Template

      4. Design Leader Standard Work and operating rhythm

      Determine the actions required by leaders and the operating rhythm.

      • Implement Lean Management Practices That Work – Phase 4: Design Leader Standard Work and Operating Rhythm
      • Leader Standard Work Tracking Template
      [infographic]

      Workshop: Implement Lean Management Practices That Work

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Understand Lean Concepts

      The Purpose

      Understand Lean management.

      Key Benefits Achieved

      Gain a common understanding of Lean management, the Lean management thought model, Lean philosophies, huddles, visual management, team growth, and voice of customer.

      Activities

      1.1 Define Lean management in your organization.

      1.2 Create training materials.

      Outputs

      Lean management definition

      Customized training materials

      2 Understand Lean Concepts (Continued) and Determine Scope

      The Purpose

      Understand Lean management.

      Determine the scope of your program.

      Key Benefits Achieved

      Understand metrics and performance review.

      Understand problem identification and continuous improvement.

      Understand Kanban.

      Understand Leader Standard Work.

      Define the scope of the Lean management program.

      Activities

      2.1 Develop example operational metrics

      2.2 Simulate problem section.

      2.3 Simulate Kanban.

      2.4 Build scoping tool.

      Outputs

      Understand how to use operational metrics

      Understand problem identification

      Understand Kanban/daily tasks section

      Defined scope for your program

      3 Huddle Board Design and Huddle Facilitation Coaching

      The Purpose

      Design the sections and content for your huddle board.

      Key Benefits Achieved

      Initial huddle board design.

      Activities

      3.1 Design and build each section in your huddle board.

      3.2 Simulate coaching conversations.

      Outputs

      Initial huddle board design

      Understanding of how to conduct a huddle

      4 Design and Build Leader Standard Work

      The Purpose

      Design your Leader Standard Work activities.

      Develop a schedule for executing Leader Standard Work.

      Key Benefits Achieved

      Standard activities identified and documented.

      Sample schedule developed.

      Activities

      4.1 Identify standard activities for leaders.

      4.2 Develop a schedule for executing Leader Standard Work.

      Outputs

      Leader Standard Work activities documented

      Initial schedule for Leader Standard Work activities

      IT Governance

      • Buy Link or Shortcode: {j2store}22|cart{/j2store}
      • Related Products: {j2store}22|crosssells{/j2store}
      • Up-Sell: {j2store}22|upsells{/j2store}
      • member rating overall impact: 9.2/10
      • member rating average dollars saved: $124,127
      • member rating average days saved: 37
      • Parent Category Name: Strategy and Governance
      • Parent Category Link: /strategy-and-governance
      Read our concise Executive Brief to find out why you may want to redesign your IT governance, Review our methodology, and understand how we can support you in completing this process.

      Build a Strategic IT Workforce Plan

      • Buy Link or Shortcode: {j2store}390|cart{/j2store}
      • member rating overall impact: 9.6/10 Overall Impact
      • member rating average dollars saved: $180,171 Average $ Saved
      • member rating average days saved: 19 Average Days Saved
      • Parent Category Name: Organizational Design
      • Parent Category Link: /organizational-design
      • Talent has become a competitive differentiator. To 46% of business leaders, workforce planning is a top priority – yet only 13% do it effectively.
      • CIOs aren’t sure what they need to give the organization a competitive edge or how current staffing line-ups fall short.

      Our Advice

      Critical Insight

      • A well defined strategic workforce plan (SWP) isn’t just a nice-to-have, it’s a must-have.
      • Integrate as much data as possible into your workforce plan to best prepare you for the future. Without knowledge of your future initiatives, you are filling hypothetical holes.
      • To be successful, you need to understand your strategic initiatives, workforce landscape, and external and internal trends.

      Impact and Result

      The workforce planning process does not need to be onerous, especially with help from Info-Tech’s solid planning tools. With the right people involved and enough time invested, developing an SWP will be easier than first thought and time well spent. Leverage Info-Tech’s client-tested 5-step process to build a strategic workforce plan:

      1. Build a project charter
      2. Assess workforce competency needs
      3. Identify impact of internal and external trends
      4. Identify the impact of strategic initiatives on roles
      5. Build and monitor the workforce plan

      Build a Strategic IT Workforce Plan Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should build a strategic workforce plan for IT, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Initiate the project

      Assess the value of a strategic workforce plan and the IT department’s fit for developing one, and then structure the workforce planning project.

      • Build a Strategic Workforce Plan – Phase 1: Initiate the Project
      • IT Strategic Workforce Planning Project Charter Template
      • IT Strategic Workforce Planning Project Plan Template

      2. Analyze workforce needs

      Gather and analyze workforce needs based on an understanding of the relevant internal and external trends, and then produce a prioritized plan of action.

      • Build a Strategic Workforce Plan – Phase 2: Analyze Workforce Needs
      • Workforce Planning Workbook

      3. Build the workforce plan

      Evaluate workforce priorities, plan specific projects to address them, and formalize and integrate strategic workforce planning into regular planning processes.

      • Build a Strategic Workforce Plan – Phase 3: Build and Monitor the SWP
      [infographic]

      Workshop: Build a Strategic IT Workforce Plan

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Identify Project Goals, Metrics, and Current State

      The Purpose

      Develop a shared understanding of the challenges your organization is facing with regards to talent and workforce planning.

      Key Benefits Achieved

      An informed understanding of whether or not you need to develop a strategic workforce plan for IT.

      Activities

      1.1 Identify goals, metrics, and opportunities

      1.2 Segment current roles

      1.3 Identify organizational culture

      1.4 Assign job competencies

      1.5 Assess current talent

      Outputs

      Identified goals, metrics, and opportunities

      Documented organizational culture

      Aligned competencies to roles

      Identified current talent competency levels

      2 Assess Workforce and Analyze Trends

      The Purpose

      Perform an in-depth analysis of how internal and external trends are impacting the workforce.

      Key Benefits Achieved

      An enhanced understanding of the current talent occupying the workforce.

      Activities

      2.1 Assess environmental trends

      2.2 Identify impact on workforce requirements

      2.3 Identify how trends are impacting critical roles

      2.4 Explore viable options

      Outputs

      Complete internal trends analysis

      Complete external trends analysis

      Identified internal and external trends on specific IT roles

      3 Perform Gap Analysis

      The Purpose

      Identify the changing competencies and workforce needs of the future IT organization, including shortages and surpluses.

      Key Benefits Achieved

      Determined impact of strategic initiatives on workforce needs.

      Identification of roles required in the future organization, including surpluses and shortages.

      Identified projects to fill workforce gaps.

      Activities

      3.1 Identify strategic initiatives

      3.2 Identify impact of strategic initiatives on roles

      3.3 Determine workforce estimates

      3.4 Determine projects to address gaps

      Outputs

      Identified workforce estimates for the future

      List of potential projects to address workforce gaps

      4 Prioritize and Plan

      The Purpose

      Prepare an action plan to address the critical gaps identified.

      Key Benefits Achieved

      A prioritized plan of action that will fill gaps and secure better workforce outcomes for the organization.

      Activities

      4.1 Determine and prioritize action items

      4.2 Determine a schedule for review of initiatives

      4.3 Integrate workforce planning into regular planning processes

      Outputs

      Prioritized list of projects

      Completed workforce plan

      Identified opportunities for integration

      Demystify Oracle Licensing and Optimize Spend

      • Buy Link or Shortcode: {j2store}136|cart{/j2store}
      • member rating overall impact: 9.9/10 Overall Impact
      • member rating average dollars saved: $85,754 Average $ Saved
      • member rating average days saved: 10 Average Days Saved
      • Parent Category Name: Licensing
      • Parent Category Link: /licensing
      • License keys are not needed with optional features accessible upon install. Conducting quarterly checks of the Oracle environment is critical because if products or features are installed, even if they are not actively in use, it constitutes use by Oracle and requires a license.
      • Ambiguous license models and definitions abound: terminology and licensing rules can be vague, making it difficult to purchase licensing even with the best of intentions to keep compliant.
      • Oracle has aggressively started to force new Oracle License and Service Agreements (OLSA) on customers that slightly modify language and remove pre-existing allowances to tilt the contract terms in Oracle's favor.

      Our Advice

      Critical Insight

      • Focus on needs first. Conduct a thorough requirements assessment and document the results. Well-documented license needs will be your core asset in navigating Oracle licensing and negotiating your agreement.
      • Communicate effectively. Be aware that Oracle will reach out to employees at your organization at various levels. Having your executives on the same page will help send a strong message.
      • Manage the relationship. If Oracle is managing you, there is a high probability you are over paying or providing information that may result in an audit.

      Impact and Result

      • Conducting business with Oracle is not typical compared to other vendors. To emerge successfully from a commercial transaction with Oracle, customers must learn the "Oracle way" of conducting business, which includes a best-in-class sales structure, highly unique contracts and license use policies, and a hyper-aggressive compliance function.
      • Map out the process of how to negotiate from a position of strength, examining terms and conditions, discount percentages, and agreement pitfalls.
      • Develop a strategy that leverages and utilizes an experienced Oracle DBA to gather accurate information, and then optimizes it to mitigate and meet the top challenges.

      Demystify Oracle Licensing and Optimize Spend Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you need to understand and document your Oracle licensing strategy, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Establish licensing requirements

      Begin your proactive Oracle licensing journey by understanding which information to gather and assessing the current state and gaps.

      • Demystify Oracle Licensing and Optimize Spend – Phase 1: Establish Licensing Requirements
      • Oracle Licensing Purchase Reference Guide
      • Oracle Database Inventory Tool
      • Effective Licensing Position Tool
      • RASCI Chart

      2. Evaluate licensing options

      Review current licensing models and determine which licensing models will most appropriately fit your environment.

      • Demystify Oracle Licensing and Optimize Spend – Phase 2: Evaluate Licensing Options

      3. Evaluate agreement options

      Review Oracle’s contract types and assess which best fit the organization’s licensing needs.

      • Demystify Oracle Licensing and Optimize Spend – Phase 3: Evaluate Agreement Options
      • Oracle TCO Calculator

      4. Purchase and manage licenses

      Conduct negotiations, purchase licensing, and finalize a licensing management strategy.

      • Demystify Oracle Licensing and Optimize Spend – Phase 4: Purchase and Manage Licenses
      • Oracle Terms & Conditions Evaluation Tool
      • Controlled Vendor Communications Letter
      • Vendor Communication Management Plan
      [infographic]

      Workshop: Demystify Oracle Licensing and Optimize Spend

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Establish Licensing Requirements

      The Purpose

      Assess current state and align goals; review business feedback

      Interview key stakeholders to define business objectives and drivers

      Key Benefits Achieved

      Have a baseline for requirements

      Assess the current state

      Determine licensing position

      Examine cloud options

      Activities

      1.1 Gather software licensing data

      1.2 Conduct a software inventory

      1.3 Perform manual checks

      1.4 Reconcile licenses

      1.5 Create your Oracle licensing team

      1.6 Meet with stakeholders to discuss the licensing position, cloud offerings, and budget allocation

      Outputs

      Copy of your Oracle License Statement

      Software inventory report from software asset management (SAM) tool

      Oracle Database Inventory Tool

      RASCI Chart

      Oracle Licensing Effective License Position (ELP) Template

      Oracle Licensing Purchase Reference Guide

      2 Evaluate Licensing Options

      The Purpose

      Review licensing options

      Review licensing rules

      Key Benefits Achieved

      Understand how licensing works

      Determine if you need software assurance

      Discuss licensing rules, application to current environment.

      Examine cloud licensing

      Understand the importance of documenting changes

      Meet with desktop product owners to determine product strategies

      Activities

      2.1 Review full, limited, restricted, and AST use licenses

      2.2 Calculate license costs

      2.3 Determine which database platform to use

      2.4 Evaluate moving to the cloud

      2.5 Examine disaster recovery strategies

      2.6 Understand purchasing support

      2.7 Meet with stakeholders to discuss the licensing position, cloud offerings, and budget allocation

      Outputs

      Oracle TCO Calculator

      Oracle Licensing Purchase Reference Guide

      3 Evaluate Agreement Options

      The Purpose

      Review contract option types

      Review vendors

      Key Benefits Achieved

      Understand why a type of contract is best for you

      Determine if ULA or term agreement is best

      The benefits of other types and when you should change

      Activities

      3.1 Prepare to sign or renew your ULA

      3.2 Decide on an agreement type that nets the maximum benefit

      Outputs

      Type of contract to be used

      Oracle TCO Calculator

      Oracle Licensing Purchase Reference Guide

      4 Purchase and Manage Licenses

      The Purpose

      Finalize the contract

      Prepare negotiation points

      Discuss license management

      Evaluate and develop a roadmap for future licensing

      Key Benefits Achieved

      Negotiation strategies

      Licensing management

      Introduction of SAM

      Leverage the work done on Oracle licensing to get started on SAM

      Activities

      4.1 Control the flow of communication terms and conditions

      4.2 Use Info-Tech’s readiness assessment in preparation for the audit

      4.3 Assign the right people to manage the environment

      4.4 Meet with stakeholders to discuss the licensing position, cloud offerings, and budget allocation

      Outputs

      Controlled Vendor Communications Letter

      Vendor Communication Management Plan

      Oracle Terms & Conditions Evaluation Tool

      RASCI Chart

      Oracle Licensing Purchase Reference Guide

      Prototype With an Innovation Design Sprint

      • Buy Link or Shortcode: {j2store}90|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Innovation
      • Parent Category Link: /innovation
      • The business has a mandate for IT-led innovation.
      • IT doesn’t have the budget it wants for high-risk, high-reward initiatives.
      • Many innovation projects have failed in the past.
      • Many projects that have moved through the approval process failed to meet their expectations.

      Our Advice

      Critical Insight

      • Don’t let perfect be the enemy of good. Think like a start-up and use experimentation and rapid re-iteration to get your innovative ideas off the ground.

      Impact and Result

      • Build and test a prototype in four days using Info-Tech’s Innovation Design Sprint Methodology.
      • Create an environment for co-creation between IT and the business.
      • Learn techniques for socializing and selling your ideas to business stakeholders.
      • Refine your prototype through rapid iteration and user-experience testing.
      • Socialize design thinking culture, tactics, and methods with the business.

      Prototype With an Innovation Design Sprint Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should evaluate your ideas using a design sprint, review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Understand and ideate

      Define the problem and start ideating potential solutions.

      • Prototype With an Innovation Design Sprint – Day 1: Understand and Ideate
      • Prototyping Workbook

      2. Divide and conquer

      Split off into prototyping teams to build and test the first-iteration prototypes

      • Prototype With an Innovation Design Sprint – Day 2: Divide and Conquer
      • Research Study Log Tool

      3. Unite and integrate

      Integrate the best ideas from the first iterations and come up with a team solution to the problem.

      • Prototype With an Innovation Design Sprint – Day 3: Unite and Integrate
      • Prototype One Pager

      4. Build and sell

      Build and test the team’s integrated prototype, decide on next steps, and come up with a pitch to sell the solution to business executives.

      • Prototype With an Innovation Design Sprint – Day 4: Build and Sell
      [infographic]

      Workshop: Prototype With an Innovation Design Sprint

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Understand and Ideate

      The Purpose

      Align the team around a well-defined business problem and start ideating solutions.

      Key Benefits Achieved

      Ideate solutions in the face of organizational cconstraints and characterize the success of the prototype.

      Activities

      1.1 Frame the problem.

      1.2 Develop evaluation criteria.

      1.3 Diverge and converge.

      Outputs

      Problem statement(s)

      Evaluation criteria

      Ideated solutions

      2 Divide and Conquer

      The Purpose

      Break off into teams to try and develop solutions that address the problem in unique ways.

      Key Benefits Achieved

      Develop and test a first-iteration prototype.

      Activities

      2.1 Design first prototypes in teams.

      2.2 Conduct UX testing.

      Outputs

      First-iteration prototypes

      User feedback and data

      3 Unite and Integrate

      The Purpose

      Bring the team back together to develop a team vision of the final prototype.

      Key Benefits Achieved

      Integrated, second-iteration prototype.

      Activities

      3.1 Create and deliver prototype pitches.

      3.2 Integrate prototypes.

      Outputs

      Prototype practice pitches

      Second-iteration prototype

      4 Build and Sell

      The Purpose

      Build and test the second prototype and prepare to sell it to business executives.

      Key Benefits Achieved

      Second-iteration prototype and a budget pitch.

      Activities

      4.1 Conduct second round of UX testing.

      4.2 Create one pager and budget pitch.

      Outputs

      User feedback and data

      Prototype one pager and budget pitch

      Create a Customized Big Data Architecture and Implementation Plan

      • Buy Link or Shortcode: {j2store}388|cart{/j2store}
      • member rating overall impact: 10.0/10 Overall Impact
      • member rating average dollars saved: After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve.
      • member rating average days saved: Read what our members are saying
      • Parent Category Name: Data Management
      • Parent Category Link: /data-management
      • Big data architecture is different from traditional data for several key reasons, including:
        • Big data architecture starts with the data itself, taking a bottom-up approach. Decisions about data influence decisions about components that use data.
        • Big data introduces new data sources such as social media content and streaming data.
        • The enterprise data warehouse (EDW) becomes a source for big data.
        • Master data management (MDM) is used as an index to content in big data about the people, places, and things the organization cares about.
        • The variety of big data and unstructured data requires a new type of persistence.
      • Many data architects have no experience with big data and feel overwhelmed by the number of options available to them (including vendor options, storage options, etc.). They often have little to no comfort with new big data management technologies.
      • If organizations do not architect for big data, there are a couple of main risks:
        • The existing data architecture is unable to handle big data, which will eventually result in a failure that could compromise the entire data environment.
        • Solutions will be selected in an ad hoc manner, which can cause incompatibility issues down the road.

      Our Advice

      Critical Insight

      • Before beginning to make technology decisions regarding the big data architecture, make sure a strategy is in place to document architecture principles and guidelines, the organization’s big data business pattern, and high-level functional and quality of service requirements.
      • The big data business pattern can be used to determine what data sources should be used in your architecture, which will then dictate the data integration capabilities required. By documenting current technologies, and determining what technologies are required, you can uncover gaps to be addressed in an implementation plan.
      • Once you have identified and filled technology gaps, perform an architectural walkthrough to pull decisions and gaps together and provide a fuller picture. After the architectural walkthrough, fill in any uncovered gaps. A proof-of-technology project can be started as soon as you have evaluation copies (or OSS) products and at least one person who understands the technology.

      Impact and Result

      • Save time and energy trying to fix incompatibilities between technology and data.
      • Allow the Data Architect to respond to big data requests from the business more quickly.
      • Provide the organization with valuable insights through the analytics and visualization technologies that are integrated with the other building blocks.

      Create a Customized Big Data Architecture and Implementation Plan Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Recognize the importance of big data architecture

      Big data is centered on the volume, variety, velocity, veracity, and value of data. Achieve a data architecture that can support big data.

      • Storyboard: Create a Customized Big Data Architecture and Implementation Plan

      2. Define architectural principles and guidelines while taking into consideration maturity

      Understand the importance of a big data architecture strategy. Assess big data maturity to assist with creation of your architectural principles.

      • Big Data Maturity Assessment Tool
      • Big Data Architecture Principles & Guidelines Template

      3. Build the big data architecture

      Come to accurate big data architecture decisions.

      • Big Data Architecture Decision Making Tool

      4. Determine common services needs

      What are common services?

      5. Plan a big data architecture implementation

      Gain business satisfaction with big data requests. Determine what steps need to be taken to achieve your big data architecture.

      • Big Data Architecture Initiative Definition Tool
      • Big Data Architecture Initiative Planning Tool

      Infographic

      Workshop: Create a Customized Big Data Architecture and Implementation Plan

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Recognize the Importance of Big Data Architecture

      The Purpose

      Set expectations for the workshop.

      Recognize the importance of doing big data architecture when dealing with big data.

      Key Benefits Achieved

      Big data defined.

      Understanding of why big data architecture is necessary.

      Activities

      1.1 Define the corporate strategy.

      1.2 Define big data and what it means to the organization.

      1.3 Understand why doing big data architecture is necessary.

      1.4 Examine Info-Tech’s Big Data Reference Architecture.

      Outputs

      Defined Corporate Strategy

      Defined Big Data

      Reference Architecture

      2 Design a Big Data Architecture Strategy

      The Purpose

      Identification of architectural principles and guidelines to assist with decisions.

      Identification of big data business pattern to choose required data sources.

      Definition of high-level functional and quality of service requirements to adhere architecture to.

      Key Benefits Achieved

      Key Architectural Principles and Guidelines defined.

      Big data business pattern determined.

      High-level requirements documented.

      Activities

      2.1 Discuss how maturity will influence architectural principles.

      2.2 Determine which solution type is best suited to the organization.

      2.3 Define the business pattern driving big data.

      2.4 Define high-level requirements.

      Outputs

      Architectural Principles & Guidelines

      Big Data Business Pattern

      High-Level Functional and Quality of Service Requirements Exercise

      3 Build a Big Data Architecture

      The Purpose

      Establishment of existing and required data sources to uncover any gaps.

      Identification of necessary data integration requirements to uncover gaps.

      Determination of the best suited data persistence model to the organization’s needs.

      Key Benefits Achieved

      Defined gaps for Data Sources

      Defined gaps for Data Integration capabilities

      Optimal Data Persistence technology determined

      Activities

      3.1 Establish required data sources.

      3.2 Determine data integration requirements.

      3.3 Learn which data persistence model is best suited.

      3.4 Discuss analytics requirements.

      Outputs

      Data Sources Exercise

      Data Integration Exercise

      Data Persistence Decision Making Tool

      4 Plan a Big Data Architecture Implementation

      The Purpose

      Identification of common service needs and how they differ for big data.

      Performance of an architectural walkthrough to test decisions made.

      Group gaps to form initiatives to develop an Initiative Roadmap.

      Key Benefits Achieved

      Common service needs identified.

      Architectural walkthrough completed.

      Initiative Roadmap completed.

      Activities

      4.1 Identify common service needs.

      4.2 Conduct an architectural walkthrough.

      4.3 Group gaps together into initiatives.

      4.4 Document initiatives on an initiative roadmap.

      Outputs

      Architectural Walkthrough

      Initiative Roadmap

      There should never be only one.

      • Large vertical image:
      • member rating overall impact: High Impact
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A

      Today, we're talking about a concept that’s both incredibly simple and dangerously overlooked: the single point of failure, or SPOF for short.

      Imagine you’ve built an impenetrable fortress. It has high walls, a deep moat, and strong gates. But the entire fortress can only be accessed through a single wooden bridge. That bridge is your single point of failure. If it collapses or is destroyed, your magnificent fortress is completely cut off. It doesn't matter how strong the rest of it is; that one weak link renders the entire system useless.

      In your work, your team, and your processes and technology, these single bridges are everywhere. A SPOF is any part of a system that, if it stops working, will cause the entire system to shut down. It’s the one critical component, the one indispensable person, or the one vital process that everything else depends on.

      When you identify and fix these weak points, you're strengthening the foundation of something that can withstand shocks and surprises. It’s about creating truly resilient systems and teams, not just seemingly strong ones. So, let’s explore where these risks hide and what you can do about them.

      When People Become the Problem

      For those of you who know me, saying something like this feels at odds with who I am. And yet, it's one of the most common and riskiest areas in any organization. Human single points of failure don't happen because of malicious intent. They typically grow out of positive intentions, hard work, and necessity. But the result is the same: a fragile system completely dependent on an individual.

      The Rise of the Hero

      We all know a colleague like this. The “hero” is the one person who has all the answers. When a critical system goes down at 3 AM, they're the only one who can fix it. They understand the labyrinthine codebase nobody else dares to touch. They have the historical context for every major decision made in the last decade. On the surface, this person is indispensable. Management loves them because they solve problems. The team relies on them because they’re a walking encyclopedia.

      But here’s the inconvenient truth: your hero is your most significant liability.

      Such behavior isn’t their fault. They likely became the hero by stepping up when no one else would or could. The hero may actually feel like they are the only ones qualified to handle the issue because “management” does not take the necessary actions to train other people. Or “management” places other priorities. Be aware; the issue is a perception thing. The manager is likely to be very concerned about the well-being of their employees. (I'm taking "black companies," akin to black sites, out of the equation for a moment and concentrating on generally healthy workplaces.) The hero will likely feel a strong bond to their environment. Furthermore, every hero is different. There is a single point of failure, but not a single type of person. Every person has a different driver.

      I watched a YouTube video by a famous entrepreneur the other day. And she said something that triggered a response in me because it sows the seeds of the hero. She said, "Would you rather have an employee who just fixes things, handles problems, and deals with issues?" Or an employee that talks about it? Obviously, the large majority will take the person behind door number 1. I would too. But then you need to step up as a manager, as an owner, and as an executive and enforce knowledge sharing.

      If you channel all critical knowledge and capabilities through one person and let that person become your go-to specialist for everything, you create a massive SPOF. What happens when your hero becomes sick, takes a well-deserved two-week vacation to a place with no internet, or leaves the company for a new opportunity? The system stops working. A minor issue becomes a major crisis because the only person who can fix it is unavailable.

      This overreliance also stifles growth. Other team members don't get the opportunity to learn and develop new skills because the hero is always there to swoop in and save the day. The answer? I guess that depends on your situation and what your ability is to keep this person happy without alienating the rest of the team. The answer may lie in the options discussed later in the article around KPIs.

      The Knowledge Hoarders

      A step beyond the individual hero is the team that acts as a collective SPOF. This group is the team that “protects” its know-how. They might use complex, undocumented tools, speak in a language of acronyms only they understand, or resist any attempts to standardize their processes. They've built a silo around their work, making themselves indispensable as a unit.

      Unlike the hero, their behavior often comes from a place of perceived self-preservation. If they are the only ones who understand how something works, their jobs are secure, right? But this behavior is incredibly damaging to the organization's resilience. It is also just plain wrong. The team becomes inundated with requests for new features but also for help in solving incidents. In numerous instances, the result is that the team fails in both. Next, the manager is called to senior management because the business is complaining that things don't progress as expected. 

      This team thus has become a bottleneck. Any other team that needs to interact with their system is completely at their mercy. Progress slows to a crawl, dependent on their availability and willingness to cooperate. Preservation has turned into survival.  

      The real root cause at the heart of both the hero and the knowledge-hoarding team is a failure of knowledge management. When you don't share, document, and make information accessible, you actively create single points of failure. We'll dive deeper into building a robust knowledge-sharing culture in a future article, but for now, recognize that knowledge kept in one person's or team's head is a disaster waiting to happen.

      When Your Technology is a House of Cards

      People aren't the only source of fragility. The way you build and manage your technology stacks can easily create critical SPOFs that leave you vulnerable. These are often less obvious at first, but they can cause dangerous failures when they finally break.

      The Danger of the Single Node

      Let's start with the most straightforward technical SPOF: the single-node setup. Imagine you have a critical application like maybe your company's main website or an internal database. If you run that entire application on one single server (a single “node”), you've created a classic SPOF.

      It’s like a restaurant with only one chef. If that chef goes home, the kitchen closes. It doesn't matter how many waiters or tables you have. If that single server experiences a hardware failure, a software crash, or even just needs to be rebooted for an update, your entire service goes offline. There is no failover. The service is simply down until that one machine is fixed, patched, or rebooted.

      You need to set up your systems so that when one node goes down, the other takes over. This is not just something for large enterprises. SMEs must do the same. I've had numerous calls from business owners who did something to their web server or system, and now “it doesn't work!” Not only are they down, but now they have to call me, and I then must arrange for subject matter experts to resolve it immediately. Typically at a cost much larger than if they had set up their system with active, warm, or even cold standbys. 

      The Mystery of Closed Technologies

      Another major risk comes from an overreliance on closed, proprietary technologies. This happens when you build a core part of your business on a piece of software or hardware that you don't control and can't inspect. It’s a “black box.” You know what it’s supposed to do, but you have no idea how it works or how to fix it if it breaks. When something goes wrong, you are completely at the mercy of the company that created it. You will need to submit a support ticket and wait.

      This scenario is actually relatable to the next chapter.

      The Trap of Vendor Lock-In

      Closely related to closed technology is the concept of vendor lock-in. This is a subtle but powerful SPOF. It happens when you become so deeply integrated with a single vendor's ecosystem that the cost and effort of switching to a competitor are impossibly high. Your vendor effectively becomes a strategic single point of failure. Your ability to innovate, control costs, and pivot your strategy is now tied to the decisions of another company.

      Such arrangements may even run afoul of legal standards. In Europe, the DORA and NIS2 regulations apply. DORA specifically mandates that companies have exit plans for their systems, starting with their critical and important functions. "Functions" refers to business services, to be clear. 

      But we get there so easily. The native functions of AWS, Azure, and Google Cloud, just to name a few, are very enticing to use. They offer convenience, low code, and performance on tap. It's just that, once you integrate deeply with them, they have you, hook, line, and sinker. And then you have people like me, or worse, your regulator, who demands, “What is your exit plan?”

      Your Resilience Playbook: Practical Steps to Eliminate SPOFs

      Identifying your single points of failure is the first step. The real work is in systematically eliminating them. This isn't about a single, massive project; it's about building new habits and principles into your daily work. Here's a playbook I think you can start using today.

      Mitigate People-Based Risks

      The cure for depending on one person is to create a culture where knowledge is fluid and shared by default. Your goal is to move from individual heroics to collective resilience.

      • Mandate real vacations. This might sound strange, but one of the best ways to reveal and fix a “hero” problem is to make sure your hero takes a real, disconnected vacation. This isn't a punishment; it's a benefit to them and a necessary stress test for the team. It forces others to step up and document their processes in preparation. The first time will be painful, but it becomes easier each time as the team builds its own knowledge.

      • Adopt the “teach, don't just do” rule. Coach your senior experts to see their role as multipliers. When someone asks them a question, their first instinct should be to show, not just to do. This can be a five-minute screen-sharing session, grabbing a colleague to pair program on a fix, or taking ten minutes to write down the answer in a shared knowledge base so it never has to be asked again.

        Many companies have knowledge-sharing solutions in place. Take a moment to actually use them. Prepare for when new people come into the company. Have a place where they can get into the groove and learn the heartbeat of the company. There is a reason why the Madonna song is so captivating to so many people. Getting into the groove elevates you. And the same thing happens in your company. 

      • Rotate responsibilities and run "game days." Actively move people around. Let a developer handle support tickets for a week to understand common customer issues. Have your infrastructure expert sit with the product team. Also, create “game days” where you simulate a crisis. For example: "All right team, our lead developer is 'on vacation' today. Let's practice a full deployment without them.” This makes learning safe and proactive.

      • Celebrate team success, not individual firefighting. Shift your praise and recognition. Instead of publicly thanking a single person for working all night to resolve a problem, celebrate the team that built a system so resilient it didn't break in the first place. Reward the team that wrote excellent documentation that allowed a junior member to solve a complex issue. Culture follows what you celebrate. At the same time, if the team does not pony up, definitely praise the person and follow up with the team to fix the issue.

      • Host internal demos and tech talks. Create a regular, informal forum where people can share what they're working on. This could be a “brown bag lunch” session or a Friday afternoon demo. It demystifies what other teams are doing, breaks down silos, and encourages people to ask questions in a low-pressure environment.

      • Remunerate sharing. Make sharing knowledge a bonus-eligible key performance indicator. The more sharing an expert does, with their peers acknowledging this, the more the expert earns. You can easily incorporate this into your peer feedback system. 

      • Run DRP exercises without your top engineers: This approach is taking a leap of faith, and I would never recommend this until all of the above are in place and proven. 

      Building Resilient Technical Systems

      The core principle here is to assume failure will happen and to design for it. A resilient system isn't one where parts never fail, but one where the system as a whole keeps working even when they do.

      • Embrace the rule of three. This is a simple but powerful guideline. For critical data, aim to have three copies on two different types of media, with one copy stored off-site (or in a different cloud region). For critical services, aim for at least three instances running in different availability zones. This simple rule protects you from a wide range of common failures.

      • Automate everything you can. Every manual process is a potential SPOF. It relies on a person remembering a series of steps perfectly, often under pressure. Automate your testing, your deployments, your server setup, and your backup procedures. Scripts are consistent and repeatable; exhausted humans at 3 AM are not.

      • Use health checks and smart monitoring. It's not enough to have a backup server; you need to know that it's healthy and ready to take over. Implement automated health checks that constantly monitor your primary and redundant systems. Your monitoring should alert you the moment a backup component fails, not just when the primary one does.

      • Practice chaos engineering. Don't wait for a real failure to test your resilience. Intentionally introduce failures in a controlled environment. This is known as chaos engineering. Start small. What happens if you turn off a non-critical service during work hours? Does the system handle it gracefully? Does the team know how to respond? This approach turns a potential crisis into a planned, educational drill.

      Avoiding Technology and Vendor Traps

      Your resilience also depends on the choices you make about the technology and partners you rely on. The goal is to maintain control over your destiny.

      • Build abstraction layers. Instead of having your application code talk directly to a specific vendor's service, create an intermediary layer that you control. This “abstraction layer” acts as a buffer. If you ever need to switch vendors, you only have to update your abstraction layer, not your entire application. It’s more work up front but gives you immense flexibility later.

      • Make “ease of exit” a key requirement. When you evaluate a new technology or vendor, make portability a primary concern. Ask tough questions: How do we get our data out? What is the process for migrating to a competitor? Is the technology based on open standards? Run a small proof of concept to test how hard it would be to leave before you commit fully.

      • Consider a multi-vendor strategy. For your most critical dependencies, like cloud hosting, avoid relying entirely on a single provider if you can. Using services from two or more vendors is an advanced strategy, but it provides the ultimate protection against a massive, platform-wide outage or unfavorable changes in pricing or terms.

      It's a journey, not a destination

      You will never be “ready.” Building resilience by eliminating single points of failure isn't a one-time project you can check off a list. It’s a continuous process. New SPOFs will emerge as your systems evolve, people change roles, and your business grows.

      The key is to make this thinking a part of your culture. Make “What's the bus factor for this project?” a regular question in your planning meetings. Make redundancy and documentation a non-negotiable requirement for new systems. By constantly looking for the one thing that can bring everything down, you can build teams and technology that don't just survive shocks—they eat them for breakfast.

      Increase Grant Application Success

      • Buy Link or Shortcode: {j2store}314|cart{/j2store}
      • member rating overall impact: 9.5/10 Overall Impact
      • member rating average dollars saved: $7,799 Average $ Saved
      • member rating average days saved: 10 Average Days Saved
      • Parent Category Name: Cost & Budget Management
      • Parent Category Link: /cost-and-budget-management
      • Writing grants has not been prioritized by the organization.
      • Your organization is unable to start, finish, and/or continue priority projects or initiatives as it does not have sufficient funds.
      • Grants are applied to in an ad hoc manner by employees who do not have sufficient time and resources to dedicate to the process.

      Our Advice

      Critical Insight

      There are three critical components to the grant application process:

      • Being strategic about the grant opportunities your organization chooses to pursue.
      • Dedicating sufficient time and resources to writing a competitive grant application.
      • Ensuring your organization will be able to adhere to the grant parameters if awarded the funding.

      Impact and Result

      • By leveraging Info-Tech’s methodology, your organization will strategically select, write, and submit competitive grant applications, securing additional funding sources to support the organization and the communities you serve.
      • This research can enhance the grant writing capabilities of the organization and ensure that every grant chosen aligns with your organizational priorities.
      • This blueprint will drive consensus on which grant applications should be prioritized by the organization, ensuring resourcing, feasibility, and significance are considered.

      Increase Grant Application Success Research & Tools

      Start here – read the Executive Brief

      Read our concise Executive Brief to find out why you should enhance your organization's grant application lifecycle and how you can increase the number of grants your organization is awarded. Review Info-Tech’s methodology and understand the four ways Info-Tech can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Identify Opportunities

      Identify grant funding opportunities that align with your organization's priorities. Ensure the programs, services, projects, and initiatives that align with these priorities can be financially supported by grant funding.

      • Increase Grant Application Success – Phase 1: Identify Opportunities
      • Grant Identification and Prioritization Tool for Organizations

      2. Grant Prioritization

      Prioritize applying for the grant opportunities that your organization identified. Be sure to consider the feasibility of implementing the project or initiative if your organization is awarded the grant.

      • Increase Grant Application Success – Phase 2: Grant Prioritization

      3. Write the Grant Application

      Write a competitive grant application that has been strategically developed and actively critiqued by various internal and external reviewers.

      • Increase Grant Application Success – Phase 3: Write the Grant Application
      • Grant Writing Checklist

      4. Submit the Grant Application

      Submit an exemplary grant application that meets the guidelines and expectations of the granting agency prior to the due date.

      • Increase Grant Application Success – Phase 4: Submit the Grant Application
      • Grant Follow-up Email Template

      Infographic

      Workshop: Increase Grant Application Success

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Determine Your Organization's Priorities

      The Purpose

      Determine the key priorities of your organization and identify grant funding opportunities that align with those priorities.

      Key Benefits Achieved

      Prevents duplicate grant applications from being submitted

      Ensures the grant and the organization's priorities are aligned

      Increases the success rate of grant applications

      Activities

      1.1 Discuss grant funding opportunities and their importance to the organization.

      1.2 Identify organizational priorities.

      Outputs

      An understanding of why grants are important to your organization

      A list of priorities being pursued by your organization

      2 Prioritize Grant Funding Opportunities

      The Purpose

      Identify potential grant funding opportunities that align with the projects/initiatives the organization would like to pursue. Prioritize these funding opportunities and identify which should take precedent based on resourcing, importance, likelihood of success, and feasibility.

      Key Benefits Achieved

      Generate a list of potential funding opportunities that can be revisited when resources allow

      Obtain consensus from your working group on which grants should be pursued based on how they have been prioritized

      Activities

      2.1 Develop a list of potential grant funding opportunities.

      2.2 Define the resource capacity your organization has to support the granting writing process.

      2.3 Discuss and prioritize grant opportunities

      Outputs

      A list of potential grant funding opportunities

      Realistic expectations of your organization's capacity to undertake the grant writing lifecycle

      Notes and priorities from your discussion on grant opportunities

      3 Sketch a Grant Application

      The Purpose

      Take the grant that was given top priority in the last section and sketch out a draft of what that application will look like. Think critically about the sketch and determine if there are opportunities to further clarify and demonstrate the goals of the grant application.

      Key Benefits Achieved

      A sketch ready to be developed into a grant application

      A critique of the sketch to ensure that the application will be well understood by the reviewers of your submission

      Activities

      3.1 Sketch the grant application.

      3.2 Perform a SWOT analysis of the grant sketch.

      Outputs

      A sketched version of the grant application ready to be drafted

      A SWOT analysis that critically examines the sketch and offers opportunities to enhance the application

      4 Prepare to Submit the Grant Application

      The Purpose

      Have the grant application actively critiqued by various internal and external individuals. This will increase the grant application's quality and generate understanding of the application submission and post-submission process.

      Key Benefits Achieved

      A list of individuals (internal and external) that can potentially review the application prior to submission

      Preparation for the submission process

      An understanding of why the opportunity to learn how to improve future grant applications is so important

      Activities

      4.1 Identify potential individuals who will review the draft of your grant application.

      4.2 Discuss next steps around the grant submission.

      4.3 Review grant writing best practices.

      Outputs

      A list of potential individuals who can be asked to review and critique the grant application

      An understanding of what the next steps in the process will be

      Knowledge of grant writing best practices

      Prepare Your Organization to Successfully Embrace the “New Normal”

      • Buy Link or Shortcode: {j2store}422|cart{/j2store}
      • member rating overall impact: 9.3/10 Overall Impact
      • member rating average dollars saved: $61,749 Average $ Saved
      • member rating average days saved: 2 Average Days Saved
      • Parent Category Name: DR and Business Continuity
      • Parent Category Link: /business-continuity
      • The COVID-19 pandemic is creating significant challenges across every sector, but even the deepest crisis will eventually pass. However, many of the changes it has brought to how organizations function are here to stay.
      • As an IT leader, it can be challenging to envision what this future state will look like and how to position IT as a trusted partner to the business to help steer the ship as the crisis abates.

      Our Advice

      Critical Insight

      • Organizations need to cast their gaze into the “New Normal” and determine an appropriate strategy to stabilize their operations, mitigate ongoing challenges, and seize new opportunities that will be presented in a post-COVID-19 world.
      • IT needs to understand the key trends and permanent changes that will exist following the crisis and develop a proactive roadmap for rapidly adapting their technology stack, processes, and resourcing to adjust to the new normal.

      Impact and Result

      • Info-Tech recommends a three-step approach for adapting to the new normal: begin by surveying crucial changes that will occur as a result of the COVID-19 pandemic, assess their relevance to your organization’s unique situation, and create an initiatives roadmap to support the new normal.
      • This mini-blueprint will examine five key themes: changing paradigms for remote work, new product delivery models, more self-service options for customers, greater decentralization and agility for organizational decision making, and a renewed emphasis on security architecture.

      Prepare Your Organization to Successfully Embrace the “New Normal” Research & Tools

      Read the Research

      Understand the five key trends that will persist after the pandemic has passed and create a roadmap of initiatives to help your organization adapt to the "New Normal."

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      • Prepare Your Organization to Successfully Embrace the “New Normal” Storyboard
      [infographic]

      Business Process Controls and Internal Audit

      • Buy Link or Shortcode: {j2store}37|cart{/j2store}
      • Related Products: {j2store}37|crosssells{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Security and Risk
      • Parent Category Link: security-and-risk
      Establish an Effective System of Internal IT Controls to Mitigate Risks.

      Data Quality

      • Buy Link or Shortcode: {j2store}19|cart{/j2store}
      • Related Products: {j2store}19|crosssells{/j2store}
      • Teaser Video: Visit Website
      • Teaser Video Title: Big data after pandemic
      • member rating overall impact: 8.3/10
      • member rating average dollars saved: $5,100
      • member rating average days saved: 8
      • Parent Category Name: Data and Business Intelligence
      • Parent Category Link: /data-and-business-intelligence
      Restore trust in your data by aligning your data management approach to the business strategy

      Prepare for Post-Quantum Cryptography

      • Buy Link or Shortcode: {j2store}268|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Security Processes & Operations
      • Parent Category Link: /security-processes-and-operations
      • Fault-tolerant quantum computers, capable of breaking existing encryption algorithms and cryptographic systems, are widely expected to be available sooner than originally projected.
      • Data considered secure today may already be at risk due to the threat of harvest-now-decrypt-later schemes.
      • Many current security controls will be completely useless, including today's strongest encryption techniques.

      Our Advice

      Critical Insight

      The advent of quantum computing is closer than you think: some nations have already demonstrated capability with the potential to break current asymmetric-key encryption. Traditional encryption methods will no longer provide sufficient protection. You need to act now to begin your transformation to quantum-resistant encryption.

      Impact and Result

      • Developing quantum-resistant cryptography capabilities is crucial to maintaining data security and integrity for critical applications.
      • Organizations need to act now to begin their transformation to quantum-resistant encryption.
      • Data security (especially for sensitive data) should be an organization’s top priority. Organizations with particularly critical information need to be on top of this quantum movement.

      Prepare for Post-Quantum Cryptography Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Prepare for Post-Quantum Cryptography Storyboard – Research to help organizations to prepare and implement quantum-resistance cryptography solutions.

      Developing quantum-resistant cryptography capabilities is crucial to maintaining data security and integrity for critical applications. Organizations need to act now to begin their transformation to quantum-resistant encryption.

      • Prepare for Post-Quantum Cryptography Storyboard
      [infographic]

      Further reading

      Prepare for Post-Quantum Cryptography

      It is closer than you think, and you need to act now.

      Analyst Perspective

      It is closer than you think, and you need to act now.

      The quantum realm presents itself as a peculiar and captivating domain, shedding light on enigmas within our world while pushing the boundaries of computational capabilities. The widespread availability of quantum computers is expected to occur sooner than anticipated. This emerging technology holds the potential to tackle valuable problems that even the most powerful classical supercomputers will never be able to solve. Quantum computers possess the ability to operate millions of times faster than their current counterparts.

      As we venture further into the era of quantum mechanics, organizations relying on encryption must contemplate a future where these methods no longer suffice as effective safeguards. The astounding speed and power of quantum machines have the potential to render many existing security measures utterly ineffective, including the most robust encryption techniques used today. To illustrate, a task that currently takes ten years to crack through a brute force attack could be accomplished by a quantum computer in under five minutes.

      Amid this transition into a quantum future, the utmost priority for organizations remains data security, particularly safeguarding sensitive information. Organizations must proactively prepare for the development of countermeasures and essential resilience measures to attain a state of being "quantum safe."

      This is a picture of Alan Tang

      Alan Tang
      Principal Research Director, Security and Privacy
      Info-Tech Research Group

      Executive Summary

      Your Challenge

      • Anticipated advancements in fault-tolerant quantum computers, surpassing existing encryption algorithms and cryptographic systems, are expected to materialize sooner than previously projected. The timeframe for their availability is diminishing daily.
      • Data that is presently deemed secure faces potential vulnerability due to the emergence of harvest-now-decrypt-later strategies.
      • Numerous contemporary security controls, including the most robust encryption techniques, have become obsolete and offer little efficacy.

      Common Obstacles

      • The complexity involved makes it challenging for organizations to incorporate quantum-resistant cryptography into their current IT infrastructure.
      • The endeavor of transitioning to quantum-resilient cryptography demands significant effort and time, with the specific requirements varying for each organization.
      • A lack of comprehensive understanding regarding the cryptographic technologies employed in existing IT systems poses difficulties in identifying and prioritizing systems for upgrading to post-quantum cryptography.

      Info-Tech's Approach

      • The development of quantum-resistant cryptography capabilities is essential for safeguarding the security and integrity of critical applications.
      • Organizations must proactively initiate their transition toward quantum-resistant encryption to ensure data protection.
      • Ensuring the security of corporate data assets should be of utmost importance for organizations, with special emphasis on those possessing highly critical information in light of the advancements in quantum technology.

      Info-Tech Insight

      The advent of quantum computing (QC) is closer than you think: some nations have demonstrated capability with the potential to break current asymmetric-key encryption. Traditional encryption methods will no longer be sufficient as a means of protection. You need to act now to begin your transformation to quantum-resistant encryption.

      Evolvement of QC theory and technologies

      1900-1975

      1976-1997

      1998-2018

      2019-Now

      1. 1900: Max Planck – The energy of a particle is proportional to its frequency: E = hv, where h is a relational constant.
      2. 1926: Erwin Schrödinger – Since electrons can affect each other's states, their energies change in both time and space. The total energy of a particle is expressed as a probability function.
      1. 1976: Physicist Roman Stanisław Ingarden publishes the paper "Quantum Information Theory."
      2. 1980: Paul Benioff describes the first quantum mechanical model of a computer.
      3. 1994: Peter Shor publishes Shor's algorithm.
      1. 1998: A working 2-qubit NMR quantum computer is used to solve Deutsch's problem by Jonathan A. Jones and Michele Mosca at Oxford University.
      2. 2003: DARPA Quantum Network becomes fully operational.
      3. 2011: D-Wave claims to have developed the first commercially available quantum computer, D-Wave One.
      4. 2018: the National Quantum Initiative Act was signed into law by President Donald Trump.
      1. 2019: A paper by Google's quantum computer research team was briefly available, claiming the project has reached quantum supremacy.
      2. 2020: Chinese researchers claim to have achieved quantum supremacy, using a photonic peak 76-qubit system known as Jiuzhang.
      3. 2021: Chinese researchers reported that they have built the world's largest integrated quantum communication network.
      4. 2022: The Quantinuum System Model H1-2 doubled its performance claiming to be the first commercial quantum computer to pass quantum volume 4096.

      Info-Tech Insight

      The advent of QC will significantly change our perception of computing and have a crucial impact on the way we protect our digital economy using encryption. The technology's applicability is no longer a theory but a reality to be understood, strategized about, and planned for.

      Fundamental physical principles and business use cases

      Unlike conventional computers that rely on bits, quantum computers use quantum bits or qubits. QC technology surpasses the limitations of current processing powers. By leveraging the properties of superposition, interference, and entanglement, quantum computers have the capacity to simultaneously process millions of operations, thereby surpassing the capabilities of today's most advanced supercomputers.

      A 2021 Hyperion Research survey of over 400 key decision makers in North America, Europe, South Korea, and Japan showed nearly 70% of companies have some form of in-house QC program.

      Three fundamental QC physical principles

      1. Superposition
      2. Interference
      3. Entanglement

      This is an image of two headings, Optimization; and Simulation. there are five points under each heading, with an arrow above pointing left to right, labeled Qbit Count.

      Info-Tech Insight

      Organizations need to reap the substantial benefits of QC's power, while simultaneously shielding against the same technologies when used by cyber adversaries.

      Percentage of Surveyed Companies That Have QC Programs

      • 31% Have some form of in-house QC program
      • 69% Have no QC program

      Early adopters and business value

      QC early adopters see the promise of QC for a wide range of computational workloads, including machine learning applications, finance-oriented optimization, and logistics/supply chain management.

      This is an image of the Early Adopters, and the business value drivers.

      Info-Tech Insight

      Experienced attackers are likely to be the early adopters of quantum-enabled cryptographic solutions, harnessing the power of QC to exploit vulnerabilities in today's encryption methods. The risks are particularly high for industries that rely on critical infrastructure.

      The need of quantum-safe solution is immediate

      Critical components of classical cryptography will be at risk, potentially leading to the exposure of confidential and sensitive information to the general public. Business, technology, and security leaders are confronted with an immediate imperative to formulate a quantum-safe strategy and establish a roadmap without delay.

      Case Study – Google, 2019

      In 2019, Google claimed that "Our Sycamore processor takes about 200 seconds to sample one instance of a quantum circuit a million times—our benchmarks currently indicate that the equivalent task for a state-of-the-art classical supercomputer would take approximately 10,000 years."
      Source: Nature, 2019

      Why You Should Start Preparation Now

      • The complexity with integrating QC technology into existing IT infrastructure.
      • The effort to upgrade to quantum-resilient cryptography will be significant.
      • The amount of time remaining will decrease every day.

      Case Study – Development in China, 2020

      On December 3, 2020, a team of Chinese researchers claim to have achieved quantum supremacy, using a photonic peak 76-qubit system (43 average) known as Jiuzhang, which performed calculations at 100 trillion times the speed of classical supercomputers.
      Source: science.org, 2020

      Info-Tech Insight

      The emergence of QC brings forth cybersecurity threats. It is an opportunity to regroup, reassess, and revamp our approaches to cybersecurity.

      Security threats posed by QC

      Quantum computers have reached a level of advancement where even highly intricate calculations, such as factoring large numbers into their primes, which serve as the foundation for RSA encryption and other algorithms, can be solved within minutes.

      Threat to data confidentiality

      QC could lead to unauthorized decryption of confidential data in the future. Data confidentiality breaches also impact improperly disposed encrypted storage media.

      Threat to authentication protocols and digital governance

      A recovered private key, which is derived from a public key, can be used through remote control to fraudulently authenticate a critical system.

      Threat to data integrity

      Cybercriminals can use QC technology to recover private keys and manipulate digital documents and their digital signatures.

      Example:

      Consider RSA-2048, a widely used public-key cryptosystem that facilitates secure data transmission. In a 2021 survey, a majority of leading authorities believed that RSA-2048 could be cracked by quantum computers within a mere 24 hours.
      Source: Quantum-Readiness Working Group, 2022

      Info-Tech Insight

      The development of quantum-safe cryptography capabilities is of utmost importance in ensuring the security and integrity of critical applications' data.

      US Quantum Computing Cybersecurity Preparedness Act

      The US Congress considers cryptography essential for the national security of the US and the functioning of the US economy. The Quantum Computing Cybersecurity Preparedness Act was introduced on April 18, 2022, and became a public law (No: 117-260) on December 21, 2022.

      Purpose

      The purpose of this Act is to encourage the migration of Federal Government information technology systems to quantum-resistant cryptography, and for other purposes.

      Scope and Exemption

      • Scope: Systems of government agencies.
      • Exemption: This Act shall not apply to any national security system.

      Main Obligations

      Responsibilities

      Requirements
      Inventory Establishment Not later than 180 days after the date of enactment of this Act, the Director of OMB, shall issue guidance on the migration of information technology to post-quantum cryptography.
      Agency Reports "Not later than 1 year after the date of enactment of this Act, and on an ongoing basis thereafter, the head of each agency shall provide to the Director of OMB, the Director of CISA, and the National Cyber Director— (1) the inventory described in subsection (a)(1); and (2) any other information required to be reported under subsection (a)(1)(C)."
      Migration and Assessment "Not later than 1 year after the date on which the Director of NIST has issued post-quantum cryptography standards, the Director of OMB shall issue guidance requiring each agency to— (1) prioritize information technology described under subsection (a)(2)(A) for migration to post-quantum cryptography; and (2) develop a plan to migrate information technology of the agency to post-quantum cryptography consistent with the prioritization under paragraph (1)."

      "It is the sense of Congress that (1) a strategy for the migration of information technology of the Federal Government to post-quantum cryptography is needed; and (2) the government wide and industry-wide approach to post- quantum cryptography should prioritize developing applications, hardware intellectual property, and software that can be easily updated to support cryptographic agility." – Quantum Computing Cybersecurity Preparedness Act

      The development of post-quantum encryption

      Since 2016, the National Institute of Standards and Technology (NIST) has been actively engaged in the development of post-quantum encryption standards. The objective is to identify and establish standardized cryptographic algorithms that can withstand attacks from quantum computers.

      NIST QC Initiative Key Milestones

      Date Development
      Dec. 20, 2016 Round 1 call for proposals: Announcing request for nominations for public-key post-quantum cryptographic algorithms
      Nov. 30, 2017 Deadline for submissions – 82 submissions received
      Dec. 21, 2017 Round 1 algorithms announced (69 submissions accepted as "complete and proper")
      Jan. 30, 2019 Second round candidates announced (26 algorithms)

      July 22, 2020

      Third round candidates announced (7 finalists and 8 alternates)

      July 5, 2022

      Announcement of candidates to be standardized and fourth round candidates
      2022/2024 (Plan) Draft standards available

      Four Selected Candidates to be Standardized

      CRYSTALS – Kyber

      CRYSTALS – Dilithium

      FALCON

      SPHINCS+

      NIST recommends two primary algorithms to be implemented for most use cases: CRYSTALS-KYBER (key-establishment) and CRYSTALS-Dilithium (digital signatures). In addition, the signature schemes FALCON and SPHINCS+ will also be standardized.

      Info-Tech Insight

      There is no need to wait for formal NIST PQC standards selection to begin your post-quantum mitigation project. It is advisable to undertake the necessary steps and allocate resources in phases that can be accomplished prior to the finalization of the standards.

      Prepare for post-quantum cryptography

      The advent of QC is closer than you think: some nations have demonstrated capability with the potential to break current asymmetric-key encryption. Traditional encryption methods will no longer be sufficient as a means of protection. You need to act now to begin your transformation to quantum-resistant encryption.

      This is an infographic showing the three steps: Threat is Imminent; Risks are Profound; and Take Acton Now.

      Insight summary

      Overarching Insight

      The advent of QC is closer than you think as some nations have demonstrated capability with the potential to break current asymmetric-key encryption. Traditional encryption methods will no longer be sufficient as a means of protection. You need to act now to begin your transformation to quantum-resistant encryption.

      Business Impact Is High

      The advent of QC will significantly change our perception of computing and have a crucial impact on the way we protect our digital economy using encryption. The technology's applicability is no longer a theory but a reality to be understood, strategized about, and planned for.

      It's a Collaborative Effort

      Embedding quantum resistance into systems during the process of modernization requires collaboration beyond the scope of a Chief Information Security Officer (CISO) alone. It is a strategic endeavor shaped by leaders throughout the organization, as well as external partners. This comprehensive approach involves the collective input and collaboration of stakeholders from various areas of expertise within and outside the organization.

      Leverage Industry Standards

      There is no need to wait for formal NIST PQC standards selection to begin your post-quantum mitigation project. It is advisable to undertake the necessary steps and allocate resources in phases that can be accomplished prior to the finalization of the standards.

      Take a Holistic Approach

      The advent of QC poses threats to cybersecurity. It's a time to regroup, reassess, and revamp.

      Blueprint benefits

      IT Benefits

      Business Benefits

      • This blueprint will help organizations to discover and then prioritize the systems to be upgraded to post-quantum cryptography.
      • This blueprint will enable organizations to integrate quantum-resistant cryptography into existing IT infrastructure.
      • Developing quantum-resistant cryptography capabilities is crucial to maintaining data security and integrity for critical applications.
      • This blueprint will help organizations to save effort and time needed upgrade to quantum-resilient cryptography.
      • Organizations will reap the substantial benefits of QC's power, while simultaneously shielding against the same technologies when used by cyber adversaries.
      • Avoid reputation and brand image by preventing data breach and leakage.
      • This blueprint will empower organizations to protect corporate data assets in the post-quantum era.
      • Be compliant with various security and privacy laws and regulations.

      Info-Tech Project Value

      Time, value, and resources saved to obtain buy-in from senior leadership team using our research material:

      1 FTEs*10 days*$100,000/year = $6,000

      Time, value, and resources saved to implement quantum-resistant cryptography using our research guidance:

      2 FTEs* 30 days*$100,000/year = $24,000

      Estimated cost and time savings from this blueprint:

      $6,000 + $24,000 =$30,000

      Get prepared for a post-quantum world

      The advent of sufficiently powerful quantum computers poses a risk of compromising or weakening traditional forms of asymmetric and symmetric cryptography. To safeguard data security and integrity for critical applications, it is imperative to undertake substantial efforts in migrating an organization's cryptographic systems to post-quantum encryption. The development of quantum-safe cryptography capabilities is crucial in this regard.

      Phase 1 - Prepare

      • Obtain buy-in from leadership team.
      • Educate your workforce about the upcoming transition.
      • Create defined projects to reduce risks and improve crypto-agility.

      Phase 2 - Discover

      • Determine the extent of your exposed data, systems, and applications.
      • Establish an inventory of classical cryptographic use cases.

      Phase 3 - Assess

      • Assess the security and data protection risks posed by QC.
      • Assess the readiness of transforming existing classical cryptography to quantum-resilience solutions.

      Phase 4 - Prioritize

      • Prioritize transformation plan based on criteria such as business impact, near-term technical feasibility, and effort, etc.
      • Establish a roadmap.

      Phase 5 - Mitigate

      • Implement post-quantum mitigations.
      • Decommissioning old technology that will become unsupported upon publication of the new standard.
      • Validating and testing products that incorporate the new standard.

      Phase 1 – Prepare: Protect data assets in the post-quantum era

      The rise of sufficiently powerful quantum computers has the potential to compromise or weaken conventional asymmetric and symmetric cryptography methods. In anticipation of a quantum-safe future, it is essential to prioritize crypto-agility. Consequently, organizations should undertake specific tasks both presently and in the future to adequately prepare for forthcoming quantum threats and the accompanying transformations.

      Quantum-resistance preparations must address two different needs:

      Reinforce digital transformation initiatives

      To thrive in the digital landscape, organizations must strengthen their digital transformation initiatives by embracing emerging technologies and novel business practices. The transition to quantum-safe encryption presents a unique opportunity for transformation, allowing the integration of these capabilities to evolve business transactions and relationships in innovative ways.

      Protect data assets in the post-quantum era

      Organizations should prioritize supporting remediation efforts aimed at ensuring the quantum safety of existing data assets and services. The implementation of crypto-agility enables organizations to respond promptly to cryptographic vulnerabilities and adapt to future changes in cryptographic standards. This proactive approach is crucial, as the need for quantum-safe measures existed even before the complexities posed by QC emerged.

      Preparation for the post-quantum world has been recommended by the US government and other national bodies since 2016.

      In 2016, NIST, the National Security Agency (NSA), and Central Security Service stated in their Commercial National Security Algorithm Suite and QC FAQ: "NSA believes the time is now right [to start preparing for the post-quantum world] — consistent with advances in quantum computing."
      Source: Cloud Security Alliance, 2021

      Phase 1 – Prepare: Key tasks

      Preparing for quantum-resistant cryptography goes beyond simply acquiring knowledge and conducting experiments in QC. It is vital for senior management to receive comprehensive guidance on the challenges, risks, and potential mitigations associated with the post-quantum landscape. Quantum and post-quantum education should be tailored to individuals based on their specific roles and the impact of post-quantum mitigations on their responsibilities. This customized approach ensures that individuals are equipped with the necessary knowledge and skills relevant to their respective roles.

      Leadership Buy-In

      • Get senior management commitment to post-quantum project.
      • Determine the extent of exposed data, systems, and applications.
      • Identify near-term, achievable cryptographic maturity goals, creating defined projects to reduce risks and improve crypto-agility.

      Roles and Responsibilities

      • The ownership should be clearly defined regarding the quantum-resistant cryptography program.
      • This should be a cross-functional team within which members represent various business units.

      Awareness and Education

      • Senior management needs to understand the strategic threat to the organization and needs to adequately address the cybersecurity risk in a timely fashion.
      • Educate your workforce about the upcoming transition. All training and education should seek to achieve awareness of the following items with the appropriate stakeholders.

      Info-Tech Insight

      Embedding quantum resistance into systems during the process of modernization requires collaboration beyond the scope of a CISO alone. It is a strategic endeavor shaped by leaders throughout the organization, as well as external partners. This comprehensive approach involves the collective input and collaboration of stakeholders from various areas of expertise within and outside the organization.

      Phase 2 – Discover: Establish a data protection inventory

      During the discovery phase, it is crucial to locate and identify any critical data and devices that may require post-quantum protection. This step enables organizations to understand the algorithms in use and their specific locations. By conducting this thorough assessment, organizations gain valuable insights into their existing infrastructure and cryptographic systems, facilitating the implementation of appropriate post-quantum security measures.

      Inventory Core Components

      1. Description of devices and/or data
      2. Location of all sensitive data and devices
      3. Criticality of the data
      4. How long the data or devices need to be protected
      5. Effective cryptography in use and cryptographic type
      6. Data protection systems currently in place
      7. Current key size and maximum key size
      8. Vendor support timeline
      9. Post-quantum protection readiness

      Key Things to Consider

      • The accuracy and thoroughness of the discovery phase are critical factors that contribute to the success of a post-quantum project.
      • It is advisable to conduct this discovery phase comprehensively across all aspects, not solely limited to public-key algorithms.
      • Performing a data protection inventory can be a time-consuming and challenging phase of the project. Breaking it down into smaller subtasks can help facilitate the process.
      • Identifying all information can be particularly challenging since data is typically scattered throughout an organization. One approach to begin this identification process is by determining the inputs and outputs of data for each department and team within the organization.
      • To ensure accountability and effectiveness, it is recommended to assign a designated individual as the ultimate owner of the data protection inventory task. This person should have the necessary responsibilities and authority to successfully accomplish the task.

      Phase 3 – Assess: The workflow

      Quantum risk assessment entails evaluating the potential consequences of QC on existing security measures and devising strategies to mitigate these risks. This process involves analyzing the susceptibility of current systems to attacks by quantum computers and identifying robust security measures that can withstand QC threats.

      Risk Assessment Workflow

      This is an image of the Risk Assessment Workflow

      By identifying the security gaps that will arise with the advent of QC, organizations can gain insight into the substantial vulnerabilities that core business operations will face when QC becomes a prevalent reality. This proactive understanding enables organizations to prepare and implement appropriate measures to address these vulnerabilities in a timely manner.

      Phase 4 – Prioritize: Balance business value, security risks, and effort

      Organizations need to prioritize the mitigation initiatives based on various factors such as business value, level of security risk, and the effort needed to implement the mitigation controls. In the diagram below, the size of the circle reflects the degree of effort. The bigger the size, the more effort is needed.

      This is an image of a chart where the X axis represents Security Risk level, and the Y axis is Business Value.

      QC Adopters Anticipated Annual Budgets

      This is an image of a bar graph showing the Anticipated Annual Budgets for QC Adopters.
      Source: Hyperion Research, 2022

      Hyperion's survey found that the range of expected budget varies widely.

      • The most selected option, albeit by only 38% of respondents, was US$5 million to US$15 million.
      • About one-third of respondents foresaw annual budgets that exceeded US$15 million, and one-fifth expected budgets to exceed US$25 million.

      Build your risk mitigation roadmap

      2 hours

      1. Review the quantum-resistance initiatives generated in Phase 3 – Assessment.
      2. With input from all stakeholders, prioritize the initiatives based on business value, security risks, and effort using the 2x2 grid.
      3. Review the position of all initiatives and adjust accordingly considering other factors such as dependency, etc.
      4. Place prioritized initiatives to a wave chart.
      5. Assign ownership and target timeline for each initiative.

      This is an image the Security Risk Vs. Business value graph, above an image showing Initiatives Numbered 1-7, divided into Wave 1; Wave 2; and Wave 3.

      Input

      • Data protection inventory created in phase 2
      • Risk assessment produced in phase 3
      • Business unit leaders' and champions' understanding (high-level) of challenges posed by QC

      Output

      • Prioritization of quantum-resistance initiatives

      Materials

      • Whiteboard/flip charts
      • Sticky notes
      • Pen/whiteboard markers

      Participants

      • Quantum-resistance program owner
      • Senior leadership team
      • Business unit heads
      • Chief security officer
      • Chief privacy officer
      • Chief information officer
      • Representatives from legal, risk, and governance

      Phase 5 – Mitigate: Implement quantum-resistant encryption solutions

      To safeguard against cybersecurity risks and threats posed by powerful quantum computers, organizations need to adopt a robust defense-in-depth approach. This entails implementing a combination of well-defined policies, effective technical defenses, and comprehensive education initiatives. Organizations may need to consider implementing new cryptographic algorithms or upgrading existing protocols to incorporate post-quantum encryption methods. The selection and deployment of these measures should be cost-justified and tailored to meet the specific needs and risk profiles of each organization.

      Governance

      Implement solid governance mechanisms to promote visibility and to help ensure consistency

      • Update policies and documents
      • Update existing acceptable cryptography standards
      • Update security and privacy audit programs

      Industry Standards

      • Stay up to date with newly approved standards
      • Leverage industry standards (i.e. NIST's post-quantum cryptography) and test the new quantum-safe cryptographic algorithms

      Technical Mitigations

      Each type of quantum threat can be mitigated using one or more known defenses.

      • Physical isolation
      • Replacing quantum-susceptible cryptography with quantum-resistant cryptography
      • Using QKD
      • Using quantum random number generators
      • Increasing symmetric key sizes
      • Using hybrid solutions
      • Using quantum-enabled defenses

      Vendor Management

      • Work with key vendors on a common approach to quantum-safe governance
      • Assess vendors for possible inclusion in your organization's roadmap
      • Create acquisition policies regarding quantum-safe cryptography

      Research Contributors and Experts

      This is a picture of Adib Ghubril

      Adib Ghubril
      Executive Advisor, Executive Services
      Info-Tech Research Group

      This is a picture of Erik Avakian

      Erik Avakian
      Technical Counselor
      Info-Tech Research Group

      This is a picture of Alaisdar Graham

      Alaisdar Graham
      Executive Counselor
      Info-Tech Research Group

      This is a picture of Carlos Rivera

      Carlos Rivera
      Principal Research Advisor
      Info-Tech Research Group

      This is a picture of Hendra Hendrawan

      Hendra Hendrawan
      Technical Counselor
      Info-Tech Research Group

      This is a picture of Fritz Jean-Louis

      Fritz Jean-Louis
      Principal Cybersecurity Advisor
      Info-Tech Research Group

      Bibliography

      117th Congress (2021-2022). H.R.7535 - Quantum Computing Cybersecurity Preparedness Act. congress.gov, 21 Dec 2022.
      Arute, Frank, et al. Quantum supremacy using a programmable superconducting processor. Nature, 23 Oct 2019.
      Bernhardt, Chris. Quantum Computing for Everyone. The MIT Press, 2019.
      Bob Sorensen. Quantum Computing Early Adopters: Strong Prospects For Future QC Use Case Impact. Hyperion Research, Nov 2022.
      Candelon, François, et al. The U.S., China, and Europe are ramping up a quantum computing arms race. Here's what they'll need to do to win. Fortune, 2 Sept 2022.
      Curioni, Alessandro. How quantum-safe cryptography will ensure a secure computing future. World Economic Forum, 6 July 2022.
      Davis, Mel. Toxic Substance Exposure Requires Record Retention for 30 Years. Alert presented by CalChamber, 18 Feb 2022.
      Eddins, Andrew, et al. Doubling the size of quantum simulators by entanglement forging. arXiv, 22 April 2021.
      Gambetta, Jay. Expanding the IBM Quantum roadmap to anticipate the future of quantum-centric supercomputing. IBM Research Blog, 10 May 2022.
      Golden, Deborah, et al. Solutions for navigating uncertainty and achieving resilience in the quantum era. Deloitte, 2023.
      Grimes, Roger, et al. Practical Preparations for the Post-Quantum World. Cloud Security Alliance, 19 Oct 2021.
      Harishankar, Ray, et al. Security in the quantum computing era. IBM Institute for Business Value, 2023.
      Hayat, Zia. Digital trust: How to unleash the trillion-dollar opportunity for our global economy. World Economic Forum, 17 Aug 2022.
      Mateen, Abdul. What is post-quantum cryptography? Educative, 2023.
      Moody, Dustin. Let's Get Ready to Rumble—The NIST PQC 'Competition.' NIST, 11 Oct 2022.
      Mosca, Michele, Dr. and Dr. Marco Piani. 2021 Quantum Threat Timeline Report. Global Risk Institute, 24 Jan 2022.
      Muppidi, Sridhar and Walid Rjaibi. Transitioning to Quantum-Safe Encryption. Security Intelligence, 8 Dec 2022.
      Payraudeau, Jean-Stéphane, et al. Digital acceleration: Top technologies driving growth in a time of crisis. IBM Institute for Business Value, Nov 2020.
      Quantum-Readiness Working Group (QRWG). Canadian National Quantum-Readiness- Best Practices and Guidelines. Canadian Forum for Digital Infrastructure Resilience (CFDIR), 17 June 2022.
      Rotman, David. We're not prepared for the end of Moore's Law. MIT Technology Review, 24 Feb 2020.
      Saidi, Susan. Calculating a computing revolution. Roland Berger, 2018.
      Shorter., Ted. Why Companies Must Act Now To Prepare For Post-Quantum Cryptography. Forbes.com, 11 Feb 2022.
      Sieger, Lucy, et al. The Quantum Decade, Third edition. IBM, 2022.
      Sorensen, Bob. Broad Interest in Quantum Computing as a Driver of Commercial Success. Hyperion Research, 17 Nov 2021.
      Wise, Jason. How Much Data is Created Every Day in 2022? Earthweb, 22 Sept 2022.
      Wright, Lawrence. The Plague Year. The New Yorker, 28 Dec 2020.
      Yan, Bao, et al. Factoring integers with sublinear resources on a superconducting quantum processor. arXiv, 23 Dec 2022.
      Zhong, Han-Sen, et al. Quantum computational advantage using photons. science.org, 3 Dec 2020.

      Engineer Your Event Management Process

      • Buy Link or Shortcode: {j2store}461|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Operations Management
      • Parent Category Link: /i-and-o-process-management

      Build an event management practice that is situated in the larger service management environment. Purposefully choose valuable events to track and predefine their associated actions to cut down on data clutter.

      Our Advice

      Critical Insight

      Event management is useless in isolation. The goals come from the pain points of other ITSM practices. Build handoffs to other service management practices to drive the proper action when an event is detected.

      Impact and Result

      Create a repeatable framework to define monitored events, their root cause, and their associated action. Record your monitored events in a catalog to stay organized.

      Engineer Your Event Management Process Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Engineer Your Event Management Deck – A step-by-step document that walks you through how to choose meaningful, monitored events to track and action.

      Engineer your event management practice with tracked events informed by the business impact of the related systems, applications, and services. This storyboard will help you properly define and catalog events so you can properly respond when alerted.

      • Engineer Your Event Management Process – Phases 1-3

      2. Event Management Cookbook – A guide to help you walk through every step of scoping event management and defining every event you track in your IT environment.

      Use this tool to define your workflow for adding new events to track. This cookbook includes the considerations you need to include for every tracked event as well as the roles and responsibilities of those involved with event management.

      • Event Management Cookbook

      3. Event Management Catalog – Using the Event Management Cookbook as a guide, record all your tracked events in the Event Management Catalog.

      Use this tool to record your tracked events and alerts in one place. This catalog allows you to record the rationale, root-cause, action, and data governance for all your monitored events.

      • Event Management Catalog

      4. Event Management Workflow – Define your event management handoffs to other service management practices.

      Use this template to help define your event management handoffs to other service management practices including change management, incident management, and problem management.

      • Event Management Workflow (Visio)
      • Event Management Workflow (PDF)

      5. Event Management Roadmap – Implement and continually improve upon your event management practice.

      Use this tool to implement and continually improve upon your event management process. Record, prioritize, and assign your action items from the event management blueprint.

      • Event Management Roadmap
      [infographic]

      Workshop: Engineer Your Event Management Process

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Situate Event Management in Your Service Management Environment

      The Purpose

      Determine goals and challenges for event management and set the scope to business-critical systems.

      Key Benefits Achieved

      Defined system scope of Event Management

      Roles and responsibilities defined

      Activities

      1.1 List your goals and challenges

      1.2 Monitoring and event management RACI

      1.3 Abbreviated business impact analysis

      Outputs

      Event Management RACI (as part of the Event Management Cookbook)

      Abbreviated BIA (as part of the Event Management Cookbook)

      2 Define Your Event Management Scope

      The Purpose

      Define your in-scope configuration items and their operational conditions

      Key Benefits Achieved

      Operational conditions, related CIs and dependencies, and CI thresholds defined

      Activities

      2.1 Define operational conditions for systems

      2.2 Define related CIs and dependencies

      2.3 Define conditions for CIs

      2.4 Perform root-cause analysis for complex condition relationships

      2.5 Set thresholds for CIs

      Outputs

      Event Management Catalog

      3 Define Thresholds and Actions

      The Purpose

      Pre-define actions for every monitored event

      Key Benefits Achieved

      Thresholds and actions tied to each monitored event

      Activities

      3.1 Set thresholds to monitor

      3.2 Add actions and handoffs to event management

      Outputs

      Event Catalog

      Event Management Workflows

      4 Start Monitoring and Implement Event Management

      The Purpose

      Effectively implement event management

      Key Benefits Achieved

      Establish an event management roadmap for implementation and continual improvement

      Activities

      4.1 Define your data policy for event management

      4.2 Identify areas for improvement and establish an implementation plan

      Outputs

      Event Catalog

      Event Management Roadmap

      Further reading

      Engineer Your Event Management Process

      Track monitored events purposefully and respond effectively.

      EXECUTIVE BRIEF

      Analyst Perspective

      Event management is useless in isolation.

      Event management creates no value when implemented in isolation. However, that does not mean event management is not valuable overall. It must simply be integrated properly in the service management environment to inform and drive the appropriate actions.

      Every step of engineering event management, from choosing which events to monitor to actioning the events when they are detected, is a purposeful and explicit activity. Ensuring that event management has open lines of communication and actions tied to related practices (e.g. problem, incident, and change) allows efficient action when needed.

      Catalog your monitored events using a standardized framework to allow you to know:

      1. The value of tracking the event.
      2. The impact when the event is detected.
      3. The appropriate, right-sized reaction when the event is detected.
      4. The tool(s) involved in tracking the event.

      Properly engineering event management allows you to effectively monitor and understand your IT environment and bolster the proactivity of the related service management practices.

      Benedict Chang

      Benedict Chang
      Research Analyst, Infrastructure & Operations
      Info-Tech Research Group

      Executive Summary

      Your Challenge

      Strive for proactivity. Implement event management to reduce response times of technical teams to solve (potential) incidents when system performance degrades.

      Build an integrated event management practice where developers, service desk, and operations can all rely on event logs and metrics.

      Define the scope of event management including the systems to track, their operational conditions, related configuration items (CIs), and associated actions of the tracked events.

      Common Obstacles

      Managed services, subscription services, and cloud services have reduced the traditional visibility of on- premises tools.

      System(s) complexity and integration with the above services has increased, making true cause and effect difficult to ascertain.

      Info-Tech’s Approach

      Clearly define a limited number of operational objectives that may benefit from event management.

      Focus only on the key systems whose value is worth the effort and expense of implementing event management.

      Understand what event information is available from the CIs of those systems and map those against your operational objectives.

      Write a data retention policy that balances operational, audit, and debugging needs against cost and data security needs.

      Info-Tech Insight

      More is NOT better. Even in an AI-enabled world, every event must be collected with a specific objective in mind. Defining the purpose of each tracked event will cut down on data clutter and response time when events are detected.

      Your challenge

      This research is designed to help organizations who are facing these challenges or looking to:

      • Build an event management practice that is situated in the larger service management environment.
      • Purposefully choose events and to track as well as their related actions based on business-critical systems, their conditions, and their related CIs.
      • Cut down on the clutter of current events tracked.
      • Create a framework to add new events when new systems are onboarded.

      33%

      In 2020, 33% of organizations listed network monitoring as their number one priority for network spending. 27% of organizations listed network monitoring infrastructure as their number two priority.
      Source: EMA, 2020; n=350

      Common obstacles

      These barriers make this challenge difficult to address for many organizations:

      • Many organizations have multiple tools across multiple teams and departments that track the current state of infrastructure, making it difficult to consolidate event management into a single practice.
      • Managed services, subscription services, and cloud services have reduced the traditional visibility of on-premises tools
      • System(s) complexity and integration with the above services has increased, making true cause and effect difficult to ascertain.

      Build event management to bring value to the business

      33%

      33% of all IT organizations reported that end users detected and reported incidents before the network operations team was aware of them.
      Source: EMA, 2020; n=350

      64%

      64% of enterprises use 4-10 monitoring tools to troubleshoot their network.
      Source: EMA, 2020; n=350

      Info-Tech’s approach

      Choose your events purposefully to avoid drowning in data.

      A funnel is depicted. along the funnel are the following points: Event Candidates: 1. System Selection by Business Impact; 2. System Decomposition; 3. Event Selection and Thresholding; 4. Event Action; 5. Data Management; Valuable, Monitored, and Actioned Events

      The Info-Tech difference:

      1. Start with a list of your most business-critical systems instead of data points to measure.
      2. Decompose your business-critical systems into their configuration items. This gives you a starting point for choosing what to measure.
      3. Choose your events and label them as notifications, warnings, or exceptions. Choose the relevant thresholds for each CI.
      4. Have a pre-defined action tied to each event. That action could be to log the datapoint for a report or to open an incident or problem ticket.
      5. With your event catalog defined, choose how you will measure the events and where to store the data.

      Event management is useless in isolation

      Define how event management informs other management practices.

      Logging, Archiving, and Metrics

      Monitoring and event management can be used to establish and analyze your baseline. The more you know about your system baselines, the easier it will be to detect exceptions.

      Change Management

      Events can inform needed changes to stay compliant or to resolve incidents and problems. However, it doesn’t mean that changes can be implemented without the proper authorization.

      Automatic Resolution

      The best use case for event management is to detect and resolve incidents and problems before end users or IT are even aware.

      Incident Management

      Events sitting in isolation are useless if there isn’t an effective way to pass potential tickets off to incident management to mitigate and resolve.

      Problem Management

      Events can identify problems before they become incidents. However, you must establish proper data logging to inform problem prioritization and actioning.

      Info-Tech’s methodology for Engineering Your Event Management Process

      1. Situate Event Management in Your Service Management Environment 2. Define Your Monitoring Thresholds and Accompanying Actions 3. Start Monitoring and Implement Event Management

      Phase Steps

      1.1 Set Operational and Informational Goals

      1.2 Scope Monitoring and States of Interest

      2.1 Define Conditions and Related CIs

      2.2 Set Monitoring Thresholds and Alerts

      2.3 Action Your Events

      3.1 Define Your Data Policy

      3.2 Define Future State

      Event Cookbook

      Event Catalog

      Phase Outcomes

      Monitoring and Event Management RACI

      Abbreviated BIA

      Event Workflow

      Event Management Roadmap

      Insight summary

      Event management is useless in isolation.

      The goals come from the pain points of other ITSM practices. Build handoffs to other service management practices to drive the proper action when an event is detected.

      Start with business intent.

      Trying to organize a catalog of events is difficult when working from the bottom up. Start with the business drivers of event management to keep the scope manageable.

      Keep your signal-to-noise ratio as high as possible.

      Defining tracked events with their known conditions, root cause, and associated actions allows you to be proactive when events occur.

      Improve slowly over time.

      Start small if need be. It is better and easier to track a few items with proper actions than to try to analyze events as they occur.

      More is NOT better. Avoid drowning in data.

      Even in an AI-enabled world, every event must be collected with a specific objective in mind. Defining the purpose of each tracked event will cut down on data clutter and response time when events are detected.

      Add correlations in event management to avoid false positives.

      Supplement the predictive value of a single event by aggregating it with other events.

      Blueprint deliverables

      Each step of this blueprint is accompanied by supporting deliverables to help you accomplish your goals:

      Key deliverable:

      This is a screenshot of the Event Management Cookbook

      Event Management Cookbook
      Use the framework in the Event Management Cookbook to populate your event catalog with properly tracked and actioned events.

      This is a screenshot of the Event Management RACI

      Event Management RACI
      Define the roles and responsibilities needed in event management.

      This is a screenshot of the event management workflow

      Event Management Workflow
      Define the lifecycle and handoffs for event management.

      This is a screenshot of the Event Catalog

      Event Catalog
      Consolidate and organize your tracked events.

      This is a screenshot of the Event Roadmap

      Event Roadmap
      Roadmap your initiatives for future improvement.

      Blueprint benefits

      IT Benefits

      • Provide a mechanism to compare operating performance against design standards and SLAs.
      • Allow for early detection of incidents and escalations.
      • Promote timely actions and ensure proper communications.
      • Provide an entry point for the execution of service management activities.
      • Enable automation activity to be monitored by exception
      • Provide a basis for service assurance, reporting and service improvements.

      Business Benefits

      • Less overall downtime via earlier detection and resolution of incidents.
      • Better visibility into SLA performance for supplied services.
      • Better visibility and reporting between IT and the business.
      • Better real-time and overall understanding of the IT environment.

      Case Study

      An event management script helped one company get in front of support calls.

      INDUSTRY - Research and Advisory

      SOURCE - Anonymous Interview

      Challenge

      One staff member’s workstation had been infected with a virus that was probing the network with a wide variety of usernames and passwords, trying to find an entry point. Along with the obvious security threat, there existed the more mundane concern that workers occasionally found themselves locked out of their machine and needed to contact the service desk to regain access.

      Solution

      The system administrator wrote a script that runs hourly to see if there is a problem with an individual’s workstation. The script records the computer's name, the user involved, the reason for the password lockout, and the number of bad login attempts. If the IT technician on duty notices a greater than normal volume of bad password attempts coming from a single account, they will reach out to the account holder and inquire about potential issues.

      Results

      The IT department has successfully proactively managed two distinct but related problems: first, they have prevented several instances of unplanned work by reaching out to potential lockouts before they receive an incident report. They have also successfully leveraged event management to probe for indicators of a security threat before there is a breach.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      “Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful.”

      Guided Implementation

      “Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track.”

      Workshop

      “We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place.”

      Consulting

      “Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project.”

      Diagnostics and consistent frameworks used throughout all four options

      Guided Implementation

      What does a typical GI on this topic look like?

      Phase 1 Phase 2 Phase 3

      Call #1: Scope requirements, objectives, and your specific challenges.

      Call #2: Introduce the Cookbook and explore the business impact analysis.

      Call #4: Define operational conditions.

      Call #6: Define actions and related practices.

      Call #8: Identify and prioritize improvements.

      Call #3: Define system scope and related CIs/ dependencies.

      Call #5: Define thresholds and alerts.

      Call #7: Define data policy.

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

      A typical GI is between 6 to 12 calls over the course of 4 to 6 months.

      Workshop Overview

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      Day 1 Day 2 Day 3 Day 4 Day 5
      Situate Event Management in Your Service Management Environment Define Your Event Management Scope Define Thresholds and Actions Start Monitoring and Implement Event Management Next Steps and Wrap-Up (offsite)

      Activities

      1.1 3.1 Set Thresholds to Monitor

      3.2 Add Actions and Handoffs to Event Management

      Introductions

      1.2 Operational and Informational Goals and Challenges

      1.3 Event Management Scope

      1.4 Roles and Responsibilities

      2.1 Define Operational Conditions for Systems

      2.2 Define Related CIs and Dependencies

      2.3 Define Conditions for CIs

      2.4 Perform Root-Cause Analysis for Complex Condition Relationships

      2.4 Set Thresholds for CIs

      3.1 Set Thresholds to Monitor

      3.2 Add Actions and Handoffs to Event Management

      4.1 Define Your Data Policy for Event Management

      4.2 Identify Areas for Improvement and Future Steps

      4.3 Summarize Workshop

      5.1 Complete In-Progress Deliverables From Previous Four Days

      5.2 Set Up Review Time for Workshop Deliverables and to Discuss Next Steps

      Deliverables
      1. Monitoring and Event Management RACI (as part of the Event Management Cookbook)
      2. Abbreviated BIA (as part of the Event Management Cookbook)
      3. Event Management Cookbook
      1. Event Management Catalog
      1. Event Management Catalog
      2. Event Management Workflows
      1. Event Management Catalog
      2. Event Management Roadmap
      1. Workshop Summary

      Phase 1

      Situate Event Management in Your Service Management Environment

      Phase 1 Phase 2 Phase 3

      1.1 Set Operational and Informational Goals
      1.2 Scope Monitoring and Event Management Using Business Impact

      2.1 Define Conditions and Related CIs
      2.2 Set Monitoring Thresholds and Alerts
      2.3 Action Your Events

      3.1 Define Your Data Policy
      3.2 Set Your Future of Event Monitoring

      Engineer Your Event Management Process

      This phase will walk you through the following activities:

      1.1.1 List your goals and challenges

      1.1.2 Build a RACI chart for event management

      1.2.1 Set your scope using business impact

      This phase involves the following participants:

      Infrastructure management team

      IT managers

      Step 1.1

      Set Operational and Informational Goals

      Activities

      1.1.1 List your goals and challenges

      1.1.2 Build a RACI chart for event management

      Situate Event Management in Your Service Management Environment

      This step will walk you through the following activities:

      Set the overall scope of event management by defining the governing goals. You will also define who is involved in event management as well as their responsibilities.

      This step involves the following participants:

      Infrastructure management team

      IT managers

      Outcomes of this step

      Define the goals and challenges of event management as well as their data proxies.

      Have a RACI matrix to define roles and responsibilities in event management.

      Situate event management among related service management practices

      This image depicts the relationship between Event Management and related service management practices.

      Event management needs to interact with the following service management practices:

      • Incident Management – Event management can provide early detection and/or prevention of incidents.
      • Availability and Capacity Management – Event management helps detect issues with availability and capacity before they become an incident.
      • Problem Management – The data captured in event management can aid in easier detection of root causes of problems.
      • Change Management – Event management can function as the rationale behind needed changes to fix problems and incidents.

      Consider both operational and informational goals for event management

      Event management may log real-time data for operational goals and non-real time data for informational goals

      Event Management

      Operational Goals (real-time)

      Informational Goals (non-real time)

      Incident Response & Prevention

      Availability Scaling

      Availability Scaling

      Modeling and Testing

      Investigation/ Compliance

      • Knowing what the outcomes are expected to achieve helps with the design of that process.
      • A process targeted to fewer outcomes will generally be less complex, easier to adhere to, and ultimately, more successful than one targeted to many goals.
      • Iterate for improvement.

      1.1.1 List your goals and challenges

      Gather a diverse group of IT staff in a room with a whiteboard.

      Have each participant write down their top five specific outcomes they want from improved event management.

      Consolidate similar ideas.

      Prioritize the goals.

      Record these goals in your Event Management Cookbook.

      Priority Example Goals
      1 Reduce response time for incidents
      2 Improve audit compliance
      3 Improve risk analysis
      4 Improve forecasting for resource acquisition
      5 More accurate RCAs

      Input

      • Pain points

      Output

      • Prioritized list of goals and outcomes

      Materials

      • Whiteboard/flip charts
      • Sticky notes

      Participants

      • Infrastructure management team
      • IT managers

      Download the Event Management Cookbook

      Event management is a group effort

      • Event management needs to involve multiple other service management practices and service management roles to be effective.
      • Consider the roles to the right to see how event management can fit into your environment.

      Infrastructure Team

      The infrastructure team is accountable for deciding which events to track, how to track, and how to action the events when detected.

      Service Desk

      The service desk may respond to events that are indicative of incidents. Setting a root cause for events allows for quicker troubleshooting, diagnosis, and resolution of the incident.

      Problem and Change Management

      Problem and change management may be involved with certain event alerts as the resultant action could be to investigate the root cause of the alert (problem management) or build and approve a change to resolve the problem (change management).

      1.1.2 Build a RACI chart for event management

      1. As a group, complete the RACI chart using the template to the right. RACI stands for the following:
        • Responsible. The person doing the work.
        • Accountable. The person who ensures the work is done.
        • Consulted. Two-way communication.
        • Informed. One-way communication
        • There must be one and only one accountable person for each task. There must also be at least one responsible person. Depending on the use case, RACI letters may be combined (e.g. AR means the person who ensures the work is complete but also the person doing the work).
      2. Start with defining the roles in the first row in your own environment.
      3. Look at the tasks on the first column and modify/add/subtract tasks as necessary.
      4. Populate the RACI chart as necessary.

      Download the Event Management Cookbook

      Event Management Task IT Manager SME IT Infrastructure Manager Service Desk Configuration Manager (Event Monitoring System) Change Manager Problem Manager
      Defining systems and configuration items to monitor R C AR R
      Defining states of operation R C AR C
      Defining event and event thresholds to monitor R C AR I I
      Actioning event thresholds: Log A R
      Actioning event thresholds: Monitor I R A R
      Actioning event thresholds: Submit incident/change/problem ticket R R A R R I I
      Close alert for resolved issues AR RC RC

      Step 1.2

      Scope Monitoring and Event Management Using Business Impact

      Activities

      1.2.1 Set your scope using business impact

      Situate Event Management in Your Service Management Environment

      This step will walk you through the following activities:

      • Set your scope of event management using an abbreviated business impact analysis.

      This step involves the following participants:

      • Infrastructure manager
      • IT managers

      Outcomes of this step

      • List of systems, services, and applications to monitor.

      Use the business impact of your systems to set the scope of monitoring

      Picking events to track and action is difficult. Start with your most important systems according to business impact.

      • Business impact can be determined by how costly system downtime is. This could be a financial impact ($/hour of downtime) or goodwill impact (internal/external stakeholders affected).
      • Use business impact to determine the rating of a system by Tier (Gold, Silver, or Bronze):
        • GOLD: Mission-critical services. An outage is catastrophic in terms of cost or public image/goodwill. Example: trading software at a financial institution.
        • SILVER: Important to daily operations but not mission critical. Example: email services at any large organization.
        • BRONZE: Loss of these services is an inconvenience more than anything, though they do serve a purpose and will be missed if they are never brought back online. Example: ancient fax machines.
      • Align a list of systems to track with your previously selected goals for event management to determine WHY you need to track that system. Tracking the system could inform critical SLAs (performance/uptime), vulnerability, compliance obligations, or simply system condition.

      More is not better

      Tracking too many events across too many tools could decrease your responsiveness to incidents. Start tracking only what is actionable to keep the signal-to-noise ratio of events as high as possible.

      % of Incidents Reported by End Users Before Being Recognized by IT Operations

      A bar graph is depicted. It displays the following Data: All Organizations: 40%; 1-3 Tools: 29; 4-10 Tools: 36%; data-verified=11 Tools: 52">

      Source: Riverbed, 2016

      1.2.1 Set your scope using business impact

      Collating an exhaustive list of applications and services is onerous. Start small, with a subset of systems.

      1. Gather a diverse group of IT staff and end users in a room with a whiteboard.
      2. List 10-15 systems and services. Solicit feedback from the group. Questions to ask:
        • What services do you regularly use? What do you see others using?
          (End users)
        • Which service comprises the greatest number of service calls? (IT)
        • What services are the most critical for business operations? (Everybody)
        • What is the cost of downtime (financial and goodwill) for these systems? (Business)
        • How does monitoring these systems align with your goals set in Step 1.1?
      3. Assign an importance to each of these systems from Gold (most important) to Bronze (least important).
      4. Record these systems in your Event Management Cookbook.
      Systems/Services/Applications Tier
      1 Core Infrastructure Gold
      2 Internet Access Gold
      3 Public-Facing Website Gold
      4 ERP Silver
      15 PaperSave Bronze

      Include a variety of services in your analysis

      It might be tempting to jump ahead and preselect important applications. However, even if an application is not on the top 10 list, it may have cross-dependencies that make it more valuable than originally thought.

      For a more comprehensive BIA, see Create a Right-Sized Disaster Recovery Plan
      Download the Event Management Cookbook

      Phase 2

      Define Your Monitoring Thresholds and Accompanying Actions

      Phase 1Phase 2Phase 3

      1.1 Set Operational and Informational Goals
      1.2 Scope Monitoring and Event Management Using Business Impact

      2.1 Define Conditions and Related CIs
      2.2 Set Monitoring Thresholds and Alerts
      2.3 Action Your Events

      3.1 Define Your Data Policy
      3.2 Set Your Future of Event Monitoring

      Engineer Your Event Management Process

      This phase will walk you through the following activities:

      • 2.1.1 Define performance conditions
      • 2.1.2 Decompose services into Related CIs
      • 2.2.1 Verify your CI conditions with a root-cause analysis
      • 2.2.2 Set thresholds for your events
      • 2.3.1 Set actions for your thresholds
      • 2.3.2 Build your event management workflow

      This phase involves the following participants:

      • Business system owners
      • Infrastructure manager
      • IT managers

      Step 2.1

      Define Conditions and Related CIs

      Activities

      2.1.1 Define performance conditions

      2.1.2 Decompose services into related CIs

      Define Your Monitoring Thresholds and Accompanying Actions

      This step will walk you through the following activities:

      For each monitored system, define the conditions of interest and related CIs.

      This step involves the following participants:

      Business system owners

      Infrastructure manager

      IT managers

      Outcomes of this step

      List of conditions of interest and related CIs for each monitored system.

      Consider the state of the system that is of concern to you

      Events present a snapshot of the state of a system. To determine which events you want to monitor, you need to consider what system state(s) of importance.

      • Systems can be in one of three states:
        • Up
        • Down
        • Degraded
      • What do these states mean for each of your systems chosen in your BIA?
      • Up and Down are self-explanatory and a good place to start.
      • However, degraded systems are indicative that one or more component systems of an overarching system has failed. You must uncover the nature of such a failure, which requires more sophisticated monitoring.

      2.1.1 Define system states of greatest importance for each of your systems

      1. With the system business owners and compliance officers in the room, list the performance states of your systems chosen in your BIA.
      2. If you have too many systems listed, start only with the Gold Systems.
      3. Use the following proof approaches if needed:
        • Positive Proof Approach – every system when it has certain technical and business performance expectations. You can use these as a baseline.
        • Negative Proof Approach – users know when systems are not performing. Leverage incident data and end-user feedback to determine failed or degraded system states and work backwards.
      4. Focus on the end-user facing states.
      5. Record your critical system states in the Event Management Cookbook.
      6. Use these states in the next several activities and translate them into measurable infrastructure metrics.

      Input

      • Results of business impact analysis

      Output

      • Critical system states

      Materials

      • Whiteboard/flip charts
      • Sticky notes
      • Markers

      Participants

      • Infrastructure manager
      • Business system owners

      Download the Event Management Cookbook

      2.1.2 Decompose services into relevant CIs

      Define your system dependencies to help find root causes of degraded systems.

      1. For each of your systems identified in your BIA, list the relevant CIs.
      2. Identify dependencies and relationship of those CIs with other CIs (linkages and dependencies).
      3. Starting with the Up/Down conditions for your Gold systems, list the conditions of the CIs that would lead to the condition of the system. This may be a 1:1 relationship (e.g. Core Switches down = Core Infrastructure down) or a many:1 relationship (some virtualization hosts + load balancers down = Core Infrastructure down). You do not need to define specific thresholds yet. Focus on conditions for the CIs.
      4. Repeat step 3 with Degraded conditions.
      5. Repeat step 3 and 4 with Silver and Bronze systems.
      6. Record the results in the Event Management Cookbook.

      Core Infrastructure Example

      An iceberg is depicted. below the surface, are the following terms in order from shallowest to deepest: MPLS Connection, Core Switches, DNS; DHCP, AD ADFS, SAN-01; Load Balancers, Virtualization Hosts (x 12); Power and Cooling

      Download the Event Management Cookbook

      Step 2.2

      Set Monitoring Thresholds and Alerts

      Activities

      2.2.1 Verify your CI conditions with a root-cause analysis

      2.2.2 Set thresholds for your events

      Define Your Monitoring Thresholds and Accompanying Actions

      This step will walk you through the following activities:

      Set monitoring thresholds for each CI related to each condition of interest.

      This step involves the following participants:

      Business system managers

      Infrastructure manager

      IT managers

      Service desk manager

      Outcomes of this step

      List of events to track along with their root cause.

      Event management will involve a significant number of alerts

      Separate the serious from trivial to keep the signal-to-noise ratio high.

      Event Categories: Exceptions: Alarms Indicate Failure; Alerts indicate exceeded thresholds; Normal Operation. Event Alerts: Informational; Exceptional; Warning

      Set your own thresholds

      You must set your own monitoring criteria based on operational needs. Events triggering an action should be reviewed via an assessment of the potential project and associated risks.

      Consider the four general signal types to help define your tracked events

      Latency – time to respond

      Examples:

      • Web server – time to complete request
      • Network – roundtrip ping time
      • Storage – read/write queue times

      Traffic – amount of activity per unit time

      Web sever – how many pages per minute

      Network – Mbps

      Storage – I/O read/writes per sec

      Errors – internally tracked erratic behaviors

      Web Server – page load failures

      Network – packets dropped

      Storage – disk errors

      Saturation – consumption compared to theoretical maximum

      Web Server – % load

      Network – % utilization

      Storage – % full

      2.2.1 Verify your CI conditions with a root-cause analysis

      RCAs postulate why systems go down; use the RCA to inform yourself of the events leading up to the system going down.

      1. Gather a diverse group of IT staff in a room with a whiteboard.
      2. Pick a complex example of a system condition (many:1 correlation) that has considerable data associated with it (e.g. recorded events, problem tickets).
      3. Speculate on the most likely precursor conditions. For example, if a related CI fails or is degraded, which metrics would you likely see before the failure?
      4. If something failed, imagine what you’d most likely see before the failure.
      5. Extend that timeline backward as far as you can be reasonably confident.
      6. Pick a value for that event.
      7. Write out your logic flow from event recognition to occurrence.
      8. Once satisfied, program the alert and ideally test in a non-prod environment.

      Public Website Example

      Dependency CIs Tool Metrics
      ISP WAN SNMP Traps Latency
      Telemetry Packet Loss
      SNMP Pooling Jitter
      Network Performance Web Server Response Time
      Connection Stage Errors
      Web Server Web Page DOM Load Time
      Performance
      Page Load Time

      Let your CIs help you

      At the end of the day, most of us can only monitor what our systems let us. Some (like Exchange Servers) offer a crippling number of parameters to choose from. Other (like MPLS) connections are opaque black boxes giving up only the barest of information. The metrics you choose are largely governed by the art of the possible.

      Case Study

      Exhaustive RCAs proved that 54% of issues were not caused by storage.

      This is the Nimble Storage Logo

      INDUSTRY - Enterprise IT
      SOURCE - ESG, 2017

      Challenge

      Despite a laser focus on building nothing but all-flash storage arrays, Nimble continued to field a dizzying number of support calls.

      Variability and complexity across infrastructure, applications, and configurations – each customer install being ever so slightly different – meant that the problem of customer downtime seemed inescapable.

      Solution

      Nimble embedded thousands of sensors into its arrays, both at a hardware level and in the code. Thousands of sensors per array multiplied by 7,500 customers meant millions of data points per second.

      This data was then analyzed against 12,000 anonymized app-data gap-related incidents.

      Patterns began to emerge, ones that persisted across complex customer/array/configuration combinations.

      These patterns were turned into signatures, then acted on.

      Results

      54% of app-data gap related incidents were in fact related to non-storage factors! Sub-optimal configuration, bad practices, poor integration with other systems, and even VM or hosts were at the root cause of over half of reported incidents.

      Establishing that your system is working fine is more than IT best practice – by quickly eliminating potential options the right team can get working on the right system faster thus restoring the service more quickly.

      Gain an even higher SNR with event correlation

      Filtering:

      Event data determined to be of minimal predictive value is shunted aside.

      Aggregation:

      De-duplication and combination of similar events to trigger a response based on the number or value of events, rather than for individual events.

      Masking:

      Ignoring events that occur downstream of a known failed system. Relies on accurate models of system relationships.

      Triggering:

      Initiating the appropriate response. This could be simple logging, any of the exception event responses, an alert requiring human intervention, or a pre-programmed script.

      2.2.2 Set thresholds for your events

      If the event management team toggles the threshold for an alert too low (e.g. one is generated every time a CPU load reaches 60% capacity), they will generate too many false positives and create far too much work for themselves, generating alert fatigue. If they go the other direction and set their thresholds too high, there will be too many false negatives – problems will slip through and cause future disruptions.

      1. Take your list of RCAs from the previous activity and conduct an activity with the group. The goal of the exercise is to produce the predictive event values that confidently predict an imminent event.
      2. Questions to ask:
        • What are some benign signs of this incident?
        • Is there something we could have monitored that would have alerted us to this issue before an incident occurred?
        • Should anyone have noticed this problem? Who? Why? How?
        • Go through this for each of the problems identified and discuss thresholds. When complete, include the information in the Event Management Catalog.

      Public Website Example

      Dependency Metrics Threshold
      Network Performance Latency 150ms
      Packet Loss 10%
      Jitter >1ms
      Web Server Response Time 750ms
      Performance
      Connection Stage Errors 2
      Web Page Performance DOM Load time 1100ms
      Page Load time 1200ms

      Download the Event Management Cookbook

      Step 2.3

      Action Your Events

      Activities

      2.3.1 Set actions for your thresholds

      2.3.2 Build your event management workflow

      Define Your Monitoring Thresholds and Associated Actions

      This step will walk you through the following activities:

      With your list of tracked events from the previous step, build associated actions and define the handoff from event management to related practices.

      This step involves the following participants:

      Event management team

      Infrastructure team

      Change manager

      Problem manager

      Incident manager

      Outcomes of this step

      Event management workflow

      Set actions for your thresholds

      For each of your thresholds, you will need an action tied to the event.

      • Review the event alert types:
        • Informational
        • Warning
        • Exception
      • Your detected events will require one of the following actions if detected.
      • Unactioned events will lead to a poor signal-to-noise ratio of data, which ultimately leads to confusion in the detection of the event and decreased response effectiveness.

      Event Logged

      For informational alerts, log the event for future analysis.

      Automated Resolution

      For a warning or exception event or a set of events with a well-known root cause, you may have an automated resolution tied to detection.

      Human Intervention

      For warnings and exceptions, human intervention may be needed. This could include manual monitoring or a handoff to incident, change, or problem management.

      2.3.1 Set actions for your thresholds

      Alerts generated by event management are useful for many different ITSM practitioners.

      1. With the chosen thresholds at hand, analyze the alerts and determine if they require immediate action or if they can be logged for later analysis.
      2. Questions to ask:
        1. What kind of response does this event warrant?
        2. How could we improve our event management process?
        3. What event alerts would have helped us with root-cause analysis in the past?
      3. Record the results in the Event Management Catalog.

      Public Website Example

      Outcome Metrics Threshold Response (s)
      Network Performance Latency 150ms Problem Management Tag to Problem Ticket 1701
      Web Page Performance DOM Load time 1100ms Change Management

      Download the Event Management Catalog

      Input

      • List of events generated by event management

      Output

      • Action plan for various events as they occur

      Materials

      • Whiteboard/flip charts
      • Pens
      • Paper

      Participants

      • Event Management Team
      • Infrastructure Team
      • Change Manager
      • Problem Manager
      • Incident Manager

      2.3.2 Build your event management workflow

      1. As a group, discuss your high-level monitoring, alerting, and actioning processes.
      2. Define handoff processes to incident, problem, and change management. If necessary, open your incident, problem, and change workflows and discuss how the event can further pass onto those practices. Discuss the examples below:
        • Incident Management: Who is responsible for opening the incident ticket? Can the incident ticket be automated and templated?
        • Change Management: Who is responsible for opening an RFC? Who will approve the RFC? Can it be a pre-approved change?
        • Problem Management : Who is responsible for opening the problem ticket? How can the event data be useful in the problem management process?
      3. Use and modify the example workflow as needed by downloading the Event Management Workflow.

      Example Workflow:

      This is an image of an example Event Management Workflow

      Download the Event Management Workflow

      Common datapoints to capture for each event

      Data captured will help related service management practices in different ways. Consider what you will need to record for each event.

      • Think of the practice you will be handing the event to. For example, if you’re handing the event off to incident or problem management, data captured will have to help in root-cause analysis to find and execute the right solution. If you’re passing the event off to change management, you may need information to capture the rationale of the change.
      • Knowing the driver for the data can help you define the right data captured for every event.
      • Consider the data points below for your events:

      Data Fields

      Device

      Date/time

      Component

      Parameters in exception

      Type of failure

      Value

      Download the Event Management Catalog

      Start Monitoring and Implement Event Management

      Phase 1Phase 2Phase 3

      1.1 Set Operational and Informational Goals
      1.2 Scope Monitoring and Event Management Using Business Impact

      2.1 Define Conditions and Related CIs
      2.2 Set Monitoring Thresholds and Alerts
      2.3 Action Your Events

      3.1 Define Your Data Policy
      3.2 Set Your Future of Event Monitoring

      Engineer Your Event Management Process

      This phase will walk you through the following activities:

      3.1.1 Define data policy needs

      3.2.1 Build your roadmap

      This phase involves the following participants:

      Business system owners

      Infrastructure manager

      IT managers

      Step 3.1

      Define Your Data Policy

      Activities

      3.1.1 Define data policy needs

      Start Monitoring and Implement Event Management

      This step will walk you through the following activities:

      Your overall goals from Phase 1 will help define your data retention needs. Document these policy statements in a data policy.

      This step involves the following participants:

      CIO

      Infrastructure manager

      IT managers

      Service desk manager

      Outcomes of this step

      Data retention policy statements for event management

      Know the difference between logs and metrics

      Logs

      Metrics

      A log is a complete record of events from a period:

      • Structured
      • Binary
      • Plaintext
      Missing entries in logs can be just as telling as the values existing in other entries. A metric is a numeric value that gives information about a system, generally over a time series. Adjusting the time series allows different views of the data.

      Logs are generally internal constructs to a system:

      • Applications
      • DB replications
      • Firewalls
      • SaaS services

      Completeness and context make logs excellent for:

      • Auditing
      • Analytics
      • Real-time and outlier analysis
      As a time series, metrics operate predictably and consistently regardless of system activity.

      This independence makes them ideal for:

      • Alerts
      • Dashboards
      • Profiling

      Large amounts of log data can make it difficult to:

      • Store
      • Transmit
      • Sift
      • Sort

      Context insensitivity means we can apply the same metric to dissimilar systems:

      • This is especially important for blackbox systems not fully under local control.

      Understand your data requirements

      Amount of event data logged by a 1000 user enterprise averages 113GB/day

      Source: SolarWinds

      Security Logs may contain sensitive information. Best practice is to ensure logs are secure at rest and in transit. Tailor your security protocol to your compliance regulations (PCI, etc.).
      Architecture and Availability When production infrastructure goes down, logging tends to go down as well. Holes in your data stream make it much more difficult to determine root causes of incidents. An independent secondary architecture helps solve problems when your primary is offline. At the very least, system agents should be able to buffer data until the pipeline is back online.
      Performance Log data grows: organically with the rest of the enterprise and geometrically in the event of a major incident. Your infrastructure design needs to support peak loads to prevent it from being overwhelmed when you need it the most.
      Access Control Events have value for multiple process owners in your enterprise. You need to enable access but also ensure data consistency as each group performs their own analysis on the data.
      Retention Near-real time data is valuable operationally; historic data is valuable strategically. Find a balance between the two, keeping in mind your obligations under compliance frameworks (GDPR, etc.).

      3.1.1 Set your data policy for every event

      1. Given your event list in the Event Management Catalog, include the following information for each event:
        • Retention Period
        • Data Sensitivity
        • Data Rate
      2. Record the results in the Event Management Catalog.

      Public Website Example

      Metrics/Log Retention Period Data Sensitivity Data Rate
      Latency 150ms No
      Packet Loss 10% No
      Jitter >1ms No
      Response Time 750ms No
      HAProxy Log 7 days Yes 3GB/day
      DOM Load time 1100ms
      Page Load time 1200ms
      User Access 3 years Yes

      Download the Event Management Catalog

      Input

      • List of events generated by event management
      • List of compliance standards your organization adheres to

      Output

      • Data policy for every event monitored and actioned

      Materials

      • Whiteboard/flip charts
      • Pens
      • Paper

      Participants

      • Event management team
      • Infrastructure team

      Step 3.2

      Set Your Future of Event Monitoring

      Activities

      3.2.1 Build your roadmap

      Start Monitoring and Implement Event Management

      This step will walk you through the following activities:

      Event management maturity is slowly built over time. Define your future actions in a roadmap to stay on track.

      This step involves the following participants:

      CIO

      Infrastructure manager

      IT managers

      Outcomes of this step

      Event management roadmap and action items

      Practice makes perfect

      For every event that generates an alert, you want to judge the predictive power of said event.

      Engineer your event management practice to be predictive. For example:

      • Up/Down Alert – Expected Consequence: Service desk will start working on the incident ticket before a user reports that said system has gone down.
      • SysVol Capacity Alert – Expected Consequence: Change will be made to free up space on the volume prior to the system crashing.

      If the expected consequence is not observed there are three places to look:

      1. Was the alert received by the right person?
      2. Was the alert received in enough time to do something?
      3. Did the event triggering the alert have a causative relationship with the consequence?

      While impractical to look at every action resulting from an alert, a regular review process will help improve your process. Effective alerts are crafted with specific and measurable outcomes.

      Info-Tech Insight

      False positives are worse than missed positives as they undermine confidence in the entire process from stakeholders and operators. If you need a starting point, action your false positives first.

      Mind Your Event Management Errors

      Two Donut charts are depicted. The first has a slice which is labeled 7% False Positive. The Second has a slice which is labeled 33% False Negative.

      Source: IEEE Communications Magazine March 2012

      Follow the Cookbook for every event you start tracking

      Consider building event management into new, onboarded systems as well.

      You now have several core systems, their CIs, conditions, and their related events listed in the Event Catalog. Keep the Catalog as your single reference point to help manage your tracked events across multiple tools.

      The Event Management Cookbook is designed to be used over and over. Keep your tracked events standard by running through the steps in the Cookbook.

      An additional step you could take is to pull the Cookbook out for event tracking for each new system added to your IT environment. Adding events in the Catalog during application onboarding is a good way to manage and measure configuration.

      Event Management Cookbook

      This is a screenshot of the Event Management Cookbook

      Use the framework in the Event Management Cookbook to populate your event catalog with properly tracked and actioned events.

      3.2.1 Build an event management roadmap

      Increase your event management maturity over time by documenting your goals.

      Add the following in-scope goals for future improvement. Include owner, timeline, progress, and priority.

      • Add additional systems/applications/services to event management
      • Expand condition lists for given systems
      • Consolidate tracking tools for easier data analysis and actioning
      • Integrate event management with additional service management practices

      This image contains a screenshot of a sample Event Management Roadmap

      Summary of Accomplishment

      Problem Solved

      You now have a structured event management process with a start on a properly tracked and actioned event catalog. This will help you detect incidents before they become incidents, changes needed to the IT environment, and problems before they spread.

      Continue to use the Event Management Cookbook to add new monitored events to your Event Catalog. This ensures future events will be held to the same or better standard, which allows you to avoid drowning in too much data.

      Lastly, stay on track and continually mature your event management practice using your Event Management Roadmap.

      If you would like additional support, have our analysts guide you through other phases as part of an Info-Tech workshop

      Contact your account representative for more information

      workshops@infotech.com

      1-888-670-8889

      Additional Support

      If you would like additional support, have our analysts guide you through other phases as part of an Info-Tech Workshop.

      To accelerate this project, engage your IT team in an Info-Tech workshop with an Info-Tech analyst team.

      Info-Tech analysts will join you and your team at your location or welcome you to Info-Tech’s historic Toronto office to participate in an innovative onsite workshop.

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      The following are sample activities that will be conducted by Info-Tech analysts with your team:

      This is an example of a RACI Chart for Event Management

      Build a RACI Chart for Event Management

      Define and document the roles and responsibilities in event management.

      This is an example of a business impact chart

      Set Your Scope Using Business Impact

      Define and prioritize in-scope systems and services for event management.

      Related Info-Tech Research

      Standardize the Service Desk

      Improve customer service by driving consistency in your support approach and meeting SLAs.

      Improve Incident and Problem Management

      Don’t let persistent problems govern your department

      Harness Configuration Management Superpowers

      Build a service configuration management practice around the IT services that are most important to the organization.

      Select Bibliography

      DeMattia, Adam. “Assessing the Financial Impact of HPE InfoSight Predictive Analytics.” ESG, Softchoice, Sept. 2017. Web.

      Hale, Brad. “Estimating Log Generation for Security Information Event and Log Management.” SolarWinds, n.d. Web.

      Ho, Cheng-Yuan, et al. “Statistical Analysis of False Positives and False Negatives from Real Traffic with Intrusion Detection/Prevention Systems.” IEEE Communications Magazine, vol. 50, no. 3, 2012, pp. 146-154.

      ITIL Foundation ITIL 4 Edition = ITIL 4. The Stationery Office, 2019.

      McGillicuddy, Shamus. “EMA: Network Management Megatrends 2016.” Riverbed, April 2016. Web.

      McGillicuddy, Shamus. “Network Management Megatrends 2020.” Enterprise Management Associates, APCON, 2020. Web.

      Rivas, Genesis. “Event Management: Everything You Need to Know about This ITIL Process.” GB Advisors, 22 Feb. 2021. Web.

      “Service Operations Processes.” ITIL Version 3 Chapters, 21 May 2010. Web.

      Risk management company

      Expert risk management consultancy firm

      Based on experience
      Implementable advice
      human-based and people-oriented

      Engage Tymans Group, expert risk management and consultancy company, to advise you on mitigating, preventing, and monitoring IT and information security risks within your business. We offer our extensive experience as a risk consulting company to provide your business with a custom roadmap and practical solutions to any risk management problems you may encounter.

      Security and risk management

      Our security and risk services

      Security strategy

      Security Strategy

      Embed security thinking through aligning your security strategy to business goals and values

      Read more

      Disaster Recovery Planning

      Disaster Recovery Planning

      Create a disaster recovey plan that is right for your company

      Read more

      Risk Management

      Risk Management

      Build your right-sized IT Risk Management Program

      Read more

      Check out all our services

      Setting up risk management within your company with our expert help

      Risk is unavoidable when doing business, but that does not mean you should just accept it and move on. Every company should try to manage and mitigate risk as much as possible, be it risks regarding data security or general corporate security. As such, it would be wise to engage an expert risk management and consultancy company, like Tymans Group. Our risk management consulting firm offers business practical solutions for setting up risk management programs and IT risk monitoring protocols as well as solutions for handling IT incidents. Thanks to our experience as a risk management consulting firm, you enjoy practical and proven solutions based on a people-oriented approach.

      Benefit from our expert advice on risk management

      If you engage our risk management consultancy company you get access to various guides and documents to help you set up risk management protocols within you company. Additionally, you can book a one-hour online talk with our risk management consulting firm’s CEO Gert Taeymans to discuss any problems you may be facing or request an on-site appointment in which our experts analyze your problems. The talk can discuss any topic, from IT risk control to external audits and even corporate security consultancy. If you have any questions about our risk management and consulting services for your company, we are happy to answer them. Just contact our risk management consulting firm through the online form and we will get in touch with as soon as possible.

      Register to read more …

      Design Data-as-a-Service

      • Buy Link or Shortcode: {j2store}129|cart{/j2store}
      • member rating overall impact: 9.5/10 Overall Impact
      • member rating average dollars saved: $1,007 Average $ Saved
      • member rating average days saved: 31 Average Days Saved
      • Parent Category Name: Data Management
      • Parent Category Link: /data-management
      • Lack of a consistent approach in accessing internal and external data within the organization and sharing data with third parties.
      • Data consumed by most organizations lacks proper data quality, data certification, standards tractability, and lineage.
      • Organizations are looking for guidance in terms of readily accessible data from others and data that can be shared with others or monetized.

      Our Advice

      Critical Insight

      • Despite data being everywhere, most organizations struggle to find accurate, trustworthy, and meaningful data when required.
      • Connecting to data should be as easy as connecting to the internet. This is achievable if all organizations start participating in the data marketplace ecosystem by leveraging a Data-as-a-Service (DaaS) framework.

      Impact and Result

      • Data marketplaces facilitate data sharing between the data producer and the data consumer. The data product must be carefully designed to truly benefit in today’s connected data ecosystem.
      • Follow Info-Tech’s step-by-step approach to establish your DaaS framework:
        1. Understand Data Ecosystem
        2. Design Data Products
        3. Establish DaaS framework

      Design Data-as-a-Service Research & Tools

      Start here – Read the Executive Brief

      Read our concise Executive Brief to find out why you should design Data-as-a-Service (DaaS), review Info-Tech’s methodology, and understand the four ways we can support you in completing this project.

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Understand data ecosystem

      Provide clear benefits of adopting the DaaS framework and solid rationale for moving towards a more connected data ecosystem and avoiding data silos.

      • Design Data-as-a-Service – Phase 1: Understand Data Ecosystem

      2. Design data product

      Leverage design thinking methodology and templates to document your most important data products.

      • Design Data-as-a-Service – Phase 2: Design Data Product

      3. Establish a DaaS framework

      Capture internal and external data sources critical to data products success for the organization and document an end-to-end DaaS framework.

      • Design Data-as-a-Service – Phase 3: Establish a DaaS Framework
      [infographic]

      Workshop: Design Data-as-a-Service

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Data Marketplace and DaaS Explained

      The Purpose

      The purpose of this module is to provide a clear understanding of the key concepts such as data marketplace, data sharing, and data products.

      Key Benefits Achieved

      This module will provide clear benefits of adopting the DaaS framework and solid rationale for moving towards a more connected data ecosystem and avoiding data silos.

      Activities

      1.1 Review the business context

      1.2 Understand the data ecosystem

      1.3 Draft products ideas and use cases

      1.4 Capture data product metrics

      Outputs

      Data product ideas

      Data sharing use cases

      Data product metrics

      2 Design Data Product

      The Purpose

      The purpose of this module is to leverage design thinking methodology and templates to document the most important data products.

      Key Benefits Achieved

      Data products design that incorporates end-to-end customer journey and stakeholder map.

      Activities

      2.1 Create a stakeholder map

      2.2 Establish a persona

      2.3 Data consumer journey map

      2.4 Document data product design

      Outputs

      Data product design

      3 Assess Data Sources

      The Purpose

      The purpose of this module is to capture internal and external data sources critical to data product success.

      Key Benefits Achieved

      Break down silos by integrating internal and external data sources

      Activities

      3.1 Review the conceptual data model

      3.2 Map internal and external data sources

      3.3 Document data sources

      Outputs

      Internal and external data sources relationship map

      4 Establish a DaaS Framework

      The Purpose

      The purpose of this module is to document end-to-end DaaS framework.

      Key Benefits Achieved

      End-to-end framework that breaks down silos and enables data product that can be exchanged for long-term success.

      Activities

      4.1 Design target state DaaS framework

      4.2 Document DaaS framework

      4.3 Assess the gaps between current and target environments

      4.4 Brainstorm initiatives to develop DaaS capabilities

      Outputs

      Target DaaS framework

      DaaS initiative

      Build an ERP Strategy and Roadmap

      • Buy Link or Shortcode: {j2store}585|cart{/j2store}
      • member rating overall impact: 9.4/10 Overall Impact
      • member rating average dollars saved: $76,462 Average $ Saved
      • member rating average days saved: 22 Average Days Saved
      • Parent Category Name: Enterprise Resource Planning
      • Parent Category Link: /enterprise-resource-planning
      • Organizations often do not know where to start with an ERP project.
      • They focus on tactically selecting and implementing the technology.
      • ERP projects are routinely reported as going over budget, over schedule, and they fail to realize any benefits.

      Our Advice

      Critical Insight

      • An ERP strategy is an ongoing communication tool for the business.
      • Accountability for ERP success is shared between IT and the business.
      • An actionable roadmap provides a clear path to benefits realization.

      Impact and Result

      • Align the ERP strategy and roadmap with business priorities, securing buy-in from the business for the program.
      • Identification of gaps, needs, and opportunities in relation to business processes; ensuring the most critical areas are addressed.
      • Assess alternatives for the critical path(s) most relevant to your organization’s direction.

      Build an ERP Strategy and Roadmap Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Build an ERP Strategy and Roadmap – A comprehensive guide to align business and IT on what the organization needs from their ERP.

      A business-led, top-management-supported initiative partnered with IT has the greatest chance of success.

    • Aligning and prioritizing key business and technology drivers.
    • Clearly defining what is in and out of scope for the project.
    • Getting a clear picture of how the business process and underlying applications support the business strategic priorities.
    • Pulling it all together into an actionable roadmap.
      • Build an ERP Strategy and Roadmap – Phases 1-4
      • ERP Strategy Report Template
      [infographic]

      Workshop: Build an ERP Strategy and Roadmap

      Workshops offer an easy way to accelerate your project. If you are unable to do the project yourself, and a Guided Implementation isn't enough, we offer low-cost delivery of our project workshops. We take you through every phase of your project and ensure that you have a roadmap in place to complete your project successfully.

      1 Introduction to ERP

      The Purpose

      To build understanding and alignment between business and IT on what an ERP is and the goals for the project

      Key Benefits Achieved

      Clear understanding of how the ERP supports the organizational goals

      What business processes the ERP will be supporting

      An initial understanding of the effort involved

      Activities

      1.1 Introduction to ERP

      1.2 Background

      1.3 Expectations and goals

      1.4 Align business strategy

      1.5 ERP vision and guiding principles

      1.6 ERP strategy model

      1.7 ERP operating model

      Outputs

      ERP strategy model

      ERP Operating model

      2 Build the ERP operation model

      The Purpose

      Generate an understanding of the business processes, challenges, and application portfolio currently supporting the organization.

      Key Benefits Achieved

      An understanding of the application portfolio supporting the business

      Detailed understanding of the business operating processes and pain points

      Activities

      2.1 Build application portfolio

      2.2 Map the level 1 ERP processes including identifying stakeholders, pain points, and key success indicators

      2.3 Discuss process and technology maturity for each level 1 process

      Outputs

      Application portfolio

      Mega-processes with level 1 process lists

      3 Project set up

      The Purpose

      A project of this size has multiple stakeholders and may have competing priorities. This section maps those stakeholders and identifies their possible conflicting priorities.

      Key Benefits Achieved

      A prioritized list of ERP mega-processes based on process rigor and strategic importance

      An understanding of stakeholders and competing priorities

      Initial compilation of the risks the organization will face with the project to begin early mitigation

      Activities

      3.1 ERP process prioritization

      3.2 Stakeholder mapping

      3.3 Competing priorities review

      3.4 Initial risk register compilation

      Outputs

      Prioritized ERP operating model

      Stakeholder map.

      Competing priorities list.

      Initial risk register.

      4 Roadmap and presentation review

      The Purpose

      Select a future state and build the initial roadmap to set expectations and accountabilities.

      Key Benefits Achieved

      Identification of the future state

      Initial roadmap with expectations on accountability and timelines

      Activities

      4.1 Discuss future state options

      4.2 Build initial roadmap

      4.3 Review of final deliverable

      Outputs

      Future state options

      Initiative roadmap

      Draft final deliverable

      Further reading

      Build an ERP Strategy and Roadmap

      Align business and IT to successfully deliver on your ERP initiative

      Table of Contents

      Analyst Perspective

      Phase 3: Plan Your Project

      Executive Summary

      Step 3.1: Stakeholders, risk, and value

      Phase 1: Build Alignment and Scope

      Step 3.2: Project set up

      Step 1.1: Aligning Business and IT

      Phase 4: Next Steps

      Step 1.2: Scope and Priorities

      Step 4.1: Build your roadmap

      Phase 2: Define Your ERP

      Step 4.2: Wrap up and present

      Step 2.1: ERP business model

      Summary of Accomplishment

      Step 2.2: ERP processes and supporting applications

      Research Contributors

      Step 2.3: Process pains, opportunities, and maturity

      Related Info-Tech Research

      Bibliography

      Build an ERP Strategy and Roadmap

      Align business and IT to successfully deliver on your ERP initiative

      EXECUTIVE BRIEF

      Analyst Perspective

      A foundational ERP strategy is critical to decision making.

      Photo of Robert Fayle, Research Director, Enterprise Applications, Info-Tech Research Group.

      Enterprise resource planning (ERP) is a core tool that the business leverages to accomplish its goals. An ERP that is doing its job well is invisible to the business. The challenges come when the tool is no longer invisible. It has become a source of friction in the functioning of the business

      ERP systems are expensive, their benefits are difficult to quantify, and they often suffer from poor user satisfaction. Post-implementation, technology evolves, organizational goals change, and the health of the system is not monitored. This is complicated in today’s digital landscape with multiple integration points, siloed data, and competing priorities.

      Too often organizations jump into selecting replacement systems without understanding the needs of the organization. Alignment between business and IT is just one part of the overall strategy. Identifying key pain points and opportunities, assessed in the light of organizational strategy, will provide a strong foundation to the transformation of the ERP system.

      Robert Fayle
      Research Director, Enterprise Applications
      Info-Tech Research Group

      Executive Summary

      Your Challenge

      Organizations often do not know where to start with an ERP project. They focus on tactically selecting and implementing the technology but ignore the strategic foundation that sets the ERP system up for success. ERP projects are routinely reported as going over budget, over schedule, and they fail to realize any benefits.

      Common Obstacles

      ERP projects impact the entire organization – they are not limited to just financial and operating metrics. The disruption is felt during both implementation and in the production environment.

      Missteps early on can cost time, financial resources, and careers. Roughly 55% of ERP projects reported being over budget, and two-thirds of organizations implementing ERP realized less than half of their anticipated benefits.

      Info-Tech’s Approach

      Obtain organizational buy-in and secure top management support. Set clear expectations, guiding principles, and critical success factors.

      Build an ERP operating model/business model that identifies process boundaries, scope, and prioritizes requirements. Assess stakeholder involvement, change impact, risks, and opportunities.

      Understand the alternatives your organization can choose for the future state of ERP. Develop an actionable roadmap and meaningful KPIs that directly align with your strategic goals.

      Info-Tech Insight

      Accountability for ERP success is shared between IT and the business. There is no single owner of an ERP. A unified approach to building your strategy promotes an integrated roadmap so all stakeholders have clear direction on the future state.

      Insight summary

      Enterprise resource planning (ERP) systems facilitate the flow of information across business units. It allows for the seamless integration of systems and creates a holistic view of the enterprise to support decision making.

      In many organizations, the ERP system is considered the lifeblood of the enterprise. Problems with this key operational system will have a dramatic impact on the ability of the enterprise to survive and grow.

      A measured and strategic approach to change will help mitigate many of the risks associated with ERP projects, which will avoid the chances of these changes becoming the dreaded “career killers.”

      A business led, top management supported initiative partnered with IT has the greatest chance of success.

      • A properly scoped ERP project reduces churn and provides all parts of the business with clarity.
      • This blueprint provides the business and IT the methodology to get the right level of detail for the business processes that the ERP supports so you can avoid getting lost in the details.
      • Build a successful ERP Strategy and roadmap by:
        • Aligning and prioritizing key business and technology drivers.
        • Clearly defining what is in and out of scope for the project.
        • Providing a clear picture of how the business process and underlying applications support the business strategic priorities.
        • Pulling it all together into an actionable roadmap.

      Enterprise Resource Planning (ERP)

      What is ERP?

      Enterprise resource planning (ERP) systems facilitate the flow of information across business units. They allow for the seamless integration of systems and create a holistic view of the enterprise to support decision making.

      In many organizations, the ERP system is considered the lifeblood of the enterprise. Problems with this key operational system will have a dramatic impact on the ability of the enterprise to survive and grow.

      An ERP system:

      • Automates processes, reducing the amount of manual, routine work.
      • Integrates with core modules, eliminating the fragmentation of systems.
      • Centralizes information for reporting from multiple parts of the value chain to a single point.

      A diagram visualizing the many aspects of ERP and the categories they fall under. Highlighted as 'Supply Chain Management' are 'Supply Chain: Procure to Pay' and 'Distribution: Forecast to Delivery'. Highlighted as 'Customer Relationship Management' are 'Sales: Quote to Cash', 'CRM: Market to Order', and 'Customer Service: Issue to Resolution'.

      ERP use cases:

      • Product-Centric
        Suitable for organizations that manufacture, assemble, distribute, or manage material goods.
      • Service-Centric
        Suitable for organizations that provide and manage field services and/or professional services.

      ERP by the numbers

      50-70%
      Statistical analysis of ERP projects indicates rates of failure vary from 50 to 70%. Taking the low end of those analyst reports, one in two ERP projects is considered a failure. (Source: Saxena and Mcdonagh)

      85%
      Companies that apply the principles of behavioral economics outperform their peers by 85% in sales growth and more than 25% in gross margin. (Source: Gallup)

      40%
      Nearly 40% of companies said functionality was the key driver for the adoption of a new ERP. (Source: Gheorghiu)

      ERP dissatisfaction

      Drivers of Dissatisfaction
      Business
      • Misaligned objectives
      • Product fit
      • Changing priorities
      • Lack of metrics
      Data
      • Access to data
      • Data hygiene
      • Data literacy
      • One view of the customer
      People and teams
      • User adoption
      • Lack of IT support
      • Training (use of data and system)
      • Vendor relations
      Technology
      • Systems integration
      • Multi-channel complexity
      • Capability shortfall
      • Lack of product support

      Finance, IT, Sales, and other users of the ERP system can only optimize ERP with the full support of each other. The cooperation of the departments is crucial when trying to improve ERP technology capabilities and customer interaction.

      Info-Tech Insight

      While technology is the key enabler of building strong customer experiences, there are many other drivers of dissatisfaction. IT must stand shoulder-to-shoulder with the business to develop a technology framework for ERP.

      Info-Tech’s methodology for developing a foundational ERP strategy and roadmap

      1. Build alignment and scope 2. Define your ERP 3. Plan your project 4. Next Steps
      Phase Steps
      1. Aligning business and IT
      2. Scope and priorities
      1. ERP Business Model
      2. ERP processes and supporting applications
      3. Process pains, opportunities & maturity
      1. Stakeholders, risk & value
      2. Project set up
      1. Build your roadmap
      2. Wrap up and present
      Phase Outcomes Discuss organizational goals and how to advance those using the ERP system. Establish the scope of the project and ensure that business and IT are aligned on project priorities. Build the ERP business model then move on to the top level (mega) processes and an initial list of the sub-processes. Generate a list of applications that support the identified processes. Conclude with a complete view of the mega-processes and their sub-processes. Map out your stakeholders to evaluate their impact on the project, build an initial risk register and discuss group alignment. Conclude the phase by setting the initial core project team and their accountabilities to the project. Review the different options to solve the identified pain points then build out a roadmap of how to get to that solution. Build a communication plan as part of organizational change management, which includes the stakeholder presentation.

      Blueprint deliverables

      Each step of this blueprint is accompanied by supporting deliverables to help you accomplish your goals:

      Sample of the Key Deliverable 'ERP Strategy Report'.

      ERP Strategy Report

      Complete an assessment of processes, prioritization, and pain points, and create an initiative roadmap.

      Samples of blueprint deliverables related to 'ERP Strategy Report'.

      ERP Business Model
      Align your business and technology goals and objectives in the current environment.
      Sample of the 'ERP Business Model' blueprint deliverable.
      ERP Operating Model
      Identify and prioritize your ERP top-level processes.
      Sample of the 'ERP Operating Model' blueprint deliverable.
      ERP Process Prioritization
      Assess ERP processes against the axes of rigor and strategic importance.
      Sample of the 'ERP Process Prioritization' blueprint deliverable.
      ERP Strategy Roadmap
      A data-driven roadmap of how to address the ERP pain points and opportunities.
      Sample of the 'ERP Strategy Roadmap' blueprint deliverable.

      Executive Brief Case Study

      INDUSTRY: Aerospace
      SOURCE: Panorama, 2021

      Aerospace organization assesses ERP future state from opportunities, needs, and pain points

      Challenge

      Several issues plagued the aerospace and defense organization. Many of the processes were ad hoc and did not use the system in place, often relying on Excel. The organization had a very large pain point stemming from its lack of business process standardization and oversight. The biggest gap, however, was from the under-utilization of the ERP software.

      Solution

      By assessing the usage of the system by employees and identifying key workarounds, the gaps quickly became apparent. After assessing the organization’s current state and generating recommendations from the gaps, it realized the steps needed to achieve its desired future state. The analysis of the pain points generated various needs and opportunities that allowed the organization to present and discuss its key findings with executive leadership to set milestones for the project.

      Results

      The overall assessment led the organization to the conclusion that in order to achieve its desired future state and maximize ROI from its ERP, the organization must address the internal issues prior to implementing the upgraded software.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      Guided Implementation

      Workshop

      Consulting

      "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful." "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track." "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place." "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

      Diagnostics and consistent frameworks used throughout all four options

      Guided Implementation

      What does a typical GI on this topic look like?

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

      A typical GI is between eight to twelve calls over the course of four to six months.

      Phase 1

      • Call #1: Scoping call to understand the current situation.
      • Call #2: Establish business & IT alignment and project scope.

      Phase 2

      • Call #3: Discuss the ERP Strategy business model and mega-processes.
      • Call #4: Begin the drill down on the level 1 processes.

      Phase 3

      • Call #5: Establish the stakeholder map and project risks.
      • Call #6: Discuss project setup including stakeholder commitment and accountability.

      Phase 4

      • Call #7: Discuss resolution paths and build initial roadmap.
      • Call #8: Summarize results and plan next steps.

      Workshop Overview

      Contact your account representative for more information.
      workshops@infotech.com1-888-670-8889

      Day 1 Day 2 Day 3 Day 4 Day 5
      Activities
      Introduction to ERP

      1.1 Introduction to ERP

      1.2 Background

      1.3 Expectations and goals

      1.4 Align business strategy

      1.5 ERP vision and guiding principles

      1.6 ERP strategy model

      1.7 ERP operating model

      Build the ERP operating model

      2.1 Build application portfolio

      2.2 Map the level 1 ERP processes including identifying stakeholders, pain points, and key success indicators

      2.3 Discuss process and technology maturity for each level 1 process

      Project set up

      3.1 ERP process prioritization

      3.2 Stakeholder mapping

      3.3 Competing priorities review

      3.4 Initial risk register compilation

      3.5 Workshop retrospective

      Roadmap and presentation review

      4.1 Discuss future state options

      4.2 Build initial roadmap

      4.3 Review of final deliverable

      Next Steps and wrap-up (offsite)

      5.1 Complete in-progress deliverables from previous four days

      5.2 Set up review time for workshop deliverables and to discuss next steps

      Deliverables
      1. ERP strategy model
      2. ERP operating model
      1. Application portfolio
      2. Mega-processes with level 1 process lists
      1. Prioritized ERP operating model
      2. Stakeholder map
      3. Competing priorities list
      4. Initial risk register
      1. Future state options
      2. Initiative roadmap
      3. Draft final deliverable
      1. Completed ERP strategy template
      2. ERP strategy roadmap

      Build an ERP Strategy and Roadmap

      Phase 1

      Build alignment and scope

      Phase 1

      • 1.1 Aligning business and IT
      • 1.2 Scope and priorities

      Phase 2

      • 2.1 ERP Business Model
      • 2.2 ERP processes and supporting applications
      • 2.3 Process pains, opportunities & maturity

      Phase 3

      • 3.1 Stakeholders, risk & value
      • 3.2 Project set up

      Phase 4

      • 4.1 Build your roadmap
      • 4.2 Wrap up and present

      This phase will walk you through the following activities:

      Build a common language to ensure clear understanding of the organizational needs. Define a vision and guiding principles to aid in decision making and enumerate how the ERP supports achievement of the organizational goals. Define the initial scope of the ERP project. This includes the discussion of what is not in scope.

      This phase involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Create a compelling case that addresses strategic business objectives

      When someone at the organization asks you WHY, you need to deliver a compelling case. The ERP project will receive pushback, doubt, and resistance; if you can’t answer the question WHY, you will be left back-peddling.

      When faced with a challenge, prepare for the WHY.

      • Why do we need this?
      • Why are we spending all this money?
      • Why are we bothering?
      • Why is this important?
      • Why did we do it this way?
      • Why did we choose this vendor?

      Most organizations can answer “What?”
      Some organizations can answer “How?”
      Very few organizations have an answer for “Why?”

      Each stage of the project will be difficult and present its own unique challenges and failure points. Re-evaluate if you lose sight of WHY at any stage in the project.

      Step 1.1

      Aligning business and IT

      Activities
      • 1.1.1 Build a glossary
      • 1.1.2 ERP Vision and guiding principles
      • 1.1.3 Corporate goals and ERP benefits

      This step will walk you through the following activities:

      • Building a common language to ensure a clear understanding of the organization’s needs.
      • Creating a definition of your vision and identifying the guiding principles to aid in decision making.
      • Defining how the ERP supports achievement of the organizational goals.

      This step involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Outcomes of this step

      Business and IT have a shared understanding of how the ERP supports the organizational goals.

      Are we all talking about the same thing?

      Every group has their own understanding of the ERP system, and they may use the same words to describe different things. For example, is there a difference between procurement of office supplies and procurement of parts to assemble an item for sale? And if they are different, do your terms differ (e.g., procurement versus purchasing)?

      Term(s) Definition
      HRMS, HRIS, HCM Human Resource Management System, Human Resource Information System, Human Capital Management. These represent four capabilities of HR: core HR, talent management, workforce management, and strategic HR.
      Finance Finance includes the core functionalities of GL, AR, and AP. It also covers such items as treasury, financial planning and analysis (FP&A), tax management, expenses, and asset management.
      Supply Chain The processes and networks required to produce and distribute a product or service. This encompasses both the organization and the suppliers.
      Procurement Procurement is about getting the right products from the right suppliers in a timely fashion. Related to procurement is vendor contract management.
      Distribution The process of getting the things we create to our customers.
      CRM Customer Relationship Management, the software used to maintain records of our sales and non-sales contact with our customers.
      Sales The process of identifying customers, providing quotes, and converting those quotes to sales orders to be invoiced.
      Customer Service This is the process of supporting customers with challenges and non-sales questions related to the delivery of our products/services.
      Field Service The group that provides maintenance services to our customers.

      Activity 1.1.1 Build a glossary

      1 hour
      1. As a group, discuss the organization’s functional areas, business capabilities, value streams, and business processes.
      2. Ask each of the participants if there are terms or “jargon” that they hear used that they may be unclear on or know that others may not be aware of. Record these items in the table along with a description.
        • Acronyms are particularly important to document. These are often bandied about without explanation. For example, people outside of finance may not understand that FP&A is short for Financial Planning and Analysis.

      Record this information in the ERP Strategy Report Template.

      Sample of the 'ERP Strategy Report Template: Glossary'.

      Download the ERP Strategy Report Template

      Activity 1.1.1 Working slide

      Example/working slide for your glossary. Consider this a living document and keep it up to date.

      Term(s) Definition
      HRMS, HRIS, HCM Human Resource Management System, Human Resource Information System, Human Capital Management. These represent four capabilities of HR: core HR, talent management, workforce management, and strategic HR.
      Finance Finance includes the core functionalities of GL, AR, and AP. It also covers such items as treasury, financial planning and analysis (FP&A), tax management, expenses, and asset management.
      Supply Chain The processes and networks required to produce and distribute a product or service. This encompasses both the organization and the suppliers.
      Procurement Procurement is about getting the right products from the right suppliers in a timely fashion. Related to procurement is vendor contract management.
      Distribution The process of getting the things we create to our customers.
      CRM Customer Relationship Management, the software used to maintain records of our sales and non-sales contact with our customers.
      Sales The process of identifying customers, providing quotes, and converting those quotes to sales orders to be invoiced.
      Customer Service This is the process of supporting customers with challenges and non-sales questions related to the delivery of our products/services.
      Field Service The group that provides maintenance services to our customers.

      Vision and Guiding Principles

      GUIDING PRINCIPLES

      Guiding principles are high-level rules of engagement that help to align stakeholders from the outset. Determine guiding principles to shape the scope and ensure stakeholders have the same vision.

      Creating Guiding Principles

      Guiding principles should be constructed as full sentences. These statements should be able to guide decisions.

      EXAMPLES

      • [Organization] is implementing an ERP system to streamline processes and reduce redundancies, saving time and money.
      • [Organization] is implementing an ERP to integrate disparate systems and rationalize the application portfolio.
      • [Organization] is aiming at taking advantage of best industry practices and strives to minimize the level of customization required in solution.

      Questions to Ask

      1. What is a strong statement that will help guide decision making throughout the life of the ERP project?
      2. What are your overarching requirements for business processes?
      3. What do you ultimately want to achieve?
      4. What is a statement that will ensure all stakeholders are on the same page for the project?

      Activity 1.1.2 – ERP Vision and Project Guiding Principles

      1 hour

      1. As a group, discuss whether you want to create a separate ERP vision statement or re-state your corporate vision and/or goals.
        • An ERP vision statement will provide project-guiding principles, encompass the ERP objectives, and give a rationale for the project.
        • Using the corporate vision/goals will remind the business and IT that the project is to find an ERP solution that supports and enhances the organizational objectives.
      2. Review each of the sample guiding principles provided and ask the following questions:
        1. Do we agree with the statement?
        2. Is this statement framed in the language we used internally? Does everyone agree on the meaning of the statement?
        3. Will this statement help guide our decision-making process?

      Record this information in the ERP Strategy Report Template.

      Sample of the 'ERP Strategy Report Template: Guiding Principles.

      Download the ERP Strategy Report Template

      Activity 1.1.2 – ERP Vision and Project Guiding Principles

      We, [Organization], will select and implement an integrated software suite that enhances the growth and profitability of the organization through streamlined global business processes, real time data-driven decisions, increased employee productivity, and IT investment protection.

      • Support Business Agility: A flexible and adaptable integrated business system providing a seamless user experience.
      • Utilize ERP best practices: Do not recreate or replicate what we have today, focus on modernization. Exercise customization governance by focusing on those customizations that are strategically differentiating.
      • Automate: Take manual work out where we can, empowering staff and improving productivity through automation and process efficiencies.
      • Stay focused: Focus on scope around core business capabilities. Maintain scope control. Prioritize demand in line with the strategy.
      • Strive for “One Source of Truth”: Unify data model and integrate processes where possible. Assess integration needs carefully.

      Align the ERP strategy with the corporate strategy

      Corporate Strategy Unified Strategy ERP Strategy
      • Conveys the current state of the organization and the path it wants to take.
      • Identifies future goals and business aspirations.
      • Communicates the initiatives that are critical for getting the organization from its current state to the future state.
      • ERP optimization can be and should be linked, with metrics, to the corporate strategy and ultimate business objectives.
      • Communicates the organization’s budget and spending on ERP.
      • Identifies IT initiatives that will support the business and key ERP objectives.
      • Outlines staffing and resourcing for ERP initiatives.

      Info-Tech Insight

      ERP projects are more successful when the management team understands the strategic importance and the criticality of alignment. Time needs to be spent upfront aligning business strategies with ERP capabilities. Effective alignment between IT and the business should happen daily. Alignment doesn’t just to occur at the executive level alone, but at each level of the organization.

      1.1.3 – Corporate goals and ERP benefits

      1-2 hours

      1. Discuss the business objectives. Identify two or three objectives that are a priority for this year.
      2. Produce several ways a new ERP system will meet each objective.
      3. Think about the modules and ERP functions that will help you realize these benefits.

      Cost Reduction

      • Decrease Total Cost: Reduce total costs by five percent by January 2022.
      • Decrease Specific Costs: Reduce costs of “x” business unit by ten percent by Jan. next year.

      ERP Benefits

      • Reduce headcount
      • Reallocate workers
      • Reduce overtime
      • Increased compliance
      • Streamlined audit process
      • Less rework due to decrease in errors

      Download the ERP Strategy Report Template

      Activity 1.1.3 – Corporate goals and ERP benefits

      Corporate Strategy ERP Benefits
      End customer visibility (consumer experience)
      • Help OEM’s target customers
      • Keep customer information up-to-date, including contact choices
      • [Product A] process support improvements
      • Ability to survey and track responses
      • Track and improve renewals
      • Service support – improve cycle times for claims, payment processing, and submission quality
      Social responsibility
      • Reduce paper internally and externally
      • Facilitating tracking and reporting of EFT
      • One location for all documents
      New business development
      • Track all contacts
      • Measure where in process the contact is
      • Measure impact of promotions
      Employee experience
      • Improve integration of systems reducing manual processes through automation
      • Better tracking of sales for employee comp
      • Ability to survey employees

      Step 1.2

      Scope and priorities

      Activities
      • 1.2.1 Project scope
      • 1.2.2 Competing priorities

      This step will walk you through the following activities:

      • Define the initial scope of the ERP project. This includes the discussion of what is not in scope. For example, a stand-alone warehouse management system may be out of scope while an existing HRMS could be in scope.

      This step involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Outcomes of this step

      A project scope statement and a prioritized list of projects that may compete for organizational resources.

      Understand the importance of setting expectations with a scope statement

      Be sure to understand what is in scope for an ERP strategy project. Prevent too wide of a scope to avoid scope creep – for example, we aren’t tackling MMS or BI under ERP.

      A diamond shape with three layers. Inside is 'In Scope', middle is 'Scope Creep', and outside is 'Out of Scope'.

      Establishing the parameters of the project in a scope statement helps define expectations and provides a baseline for resource allocation and planning. Future decisions about the strategic direction of ERP will be based on the scope statement.

      Well-executed requirements gathering will help you avoid expanding project parameters, drawing on your resources, and contributing to cost overruns and project delays. Avoid scope creep by gathering high-level requirements that lead to the selection of category-level application solutions (e.g. HRIS, CRM, PLM etc.) rather than granular requirements that would lead to vendor application selection (e.g. SAP, Microsoft, Oracle, etc.).

      Out-of-scope items should also be defined to alleviate ambiguity, reduce assumptions, and further clarify expectations for stakeholders. Out-of-scope items can be placed in a backlog for later consideration.

      In Scope Out of Scope
      Strategy High-level ERP requirements, strategic direction
      Software selection Vendor application selection, Granular system requirements

      Activity 1.2.1 – Define scope

      1 hour

      1. Formulate a scope statement. Decide which people, processes, and functions the ERP strategy will address. Generally, the aim of this project is to develop strategic requirements for the ERP application portfolio – not to select individual vendors.
      2. To assist in forming your scope statement, answer the following questions:
        • What are the major coverage points?
        • Who will be using the systems?
        • How will different users interact with the systems?
        • What are the objectives that need to be addressed?
        • Where do we start?
        • Where do we draw the line?

      Record this information in the ERP Strategy Report Template.

      Sample of the 'ERP Strategy Report Template: Scope Statements'.

      Download the ERP Strategy Report Template

      Activity 1.2.1 – Define scope

      Scope statements

      The following systems are considered in scope for this project:

      • Finance
      • HRMS
      • CRM
      • Supply chain

      The following systems are out of scope for this project:

      • PLM – product lifecycle management
      • Project management
      • Contract management

      The following systems are in scope, in that they must integrate into the new system. They will not change.

      • Payroll processing
      • Bank accounts
      • EDI software

      Know your competing priorities

      Organizations typically have multiple projects on the table or in flight. Each of those projects requires resources and attention from business and/or the IT organization.

      Don’t let poor prioritization hurt your ERP implementation.
      BNP Paribas Fortis had multiple projects that were poorly prioritized resulting in the time to bring products to market to double over a three-year period. (Source: Neito-Rodriguez, 2016)

      Project Timeline Priority notes Implications
      Warehouse management system upgrade project Early 2022 implementation High Taking IT staff and warehouse team, testing by finance
      Microsoft 365 October 2021-March 2022 High IT Staff, org impacted by change management
      Electronic Records Management April 2022 – Feb 2023 High Legislative requirement, org impact due to record keeping
      Web site upgrade Early fiscal 2023

      Activity 1.2.2 – Competing priorities

      1 hour

      1. As a group, discuss the projects that are currently in flight as well as any known projects including such things as territory expansion or new regulation compliance.
      2. For each project discuss and record the following items:
        • The project timeline. When does it start and how long is it expected to run?
        • How important is this project to the organization? A lot of high priority projects are going to require more attention from the staff involved.
        • What are the implications of this project?
          • What staff will be impacted? What business users will be impacted, and what is the IT involvement?
          • To what extent will the overall organization be impacted? Is it localized to a location or is it organization wide?
          • Can the project be deferred?

      Record this information in the ERP Strategy Report Template.

      Sample of the 'ERP Strategy Report Template: Priorities'.

      Download the ERP Strategy Report Template

      Activity 1.2.2 – Competing priorities

      List all your known projects both current and proposed. Discuss the prioritization of those projects, whether they are more or less important than your ERP project.

      Project Timeline Priority notes Implications
      Warehouse management system upgrade project Early 2022 implementation High Taking IT staff and warehouse team, testing by finance
      Microsoft 365 October 2021-March 2022 High IT Staff, org impacted by change management
      Electronic Records Management April 2022 – Feb 2023 High Legislative requirement, org impact due to record keeping
      Web site upgrade Early fiscal 2023 Medium
      Point of Sale replacement Oct 2021– Mar 2022 Medium
      ERP utilization and training on unused systems Friday, Sept 17 Medium Could impact multiple staff
      Managed Security Service RFP This calendar year Medium
      Mental Health Dashboard In research phase Low

      Build an ERP Strategy and Roadmap

      Phase 2

      Define your ERP

      Phase 1

      • 1.1 Aligning business and IT
      • 1.2 Scope and priorities

      Phase 2

      • 2.1 ERP Business Model
      • 2.2 ERP processes and supporting applications
      • 2.3 Process pains, opportunities & maturity

      Phase 3

      • 3.1 Stakeholders, risk & value
      • 3.2 Project set up

      Phase 4

      • 4.1 Build your roadmap
      • 4.2 Wrap up and present

      This phase will walk you through the following activities:

      • Build the ERP business model then move on to the top level (mega) processes and an initial list of the sub-processes
      • Generate a list of applications that support the identified processes
      • Assign stakeholders, discuss pain points, opportunities, and key success indicators
      • Assign process and technology maturity to each stakeholder

      This phase involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP applications support team

      Step 2.1

      ERP business model

      Activities
      • 2.1.1 Environmental factors, technology drivers, and business needs
      • 2.1.2 Challenges, pain points, enablers, and organizational goals

      This step will walk you through the following activities:

      • Identify ERP drivers and objectives
      • Explore ERP challenges and pain points
      • Discuss the ERP benefits and opportunities

      This step involves the following participants:

      • ERP implementation team
      • Business stakeholders

      Outcomes of this step

      • ERP business model

      Explore environmental factors and technology drivers

      1. Identify business drivers that are contributing to the organization’s need for ERP.
      2. Understand how the company is running today and what the organization’s future will look like. Try to identify the purpose for becoming an integrated organization.
      3. Consider external considerations, organizational drivers, technology drivers, and key functional requirements
      The ERP Business Model with 'Business Needs', 'Environmental Factors', and 'Technology Drivers' highlighted. At the center is 'ERP Strategy' with 'Barriers' above and 'Enablers' below. Surrounding and feeding into the center group are 'Business Needs', 'Environmental Factors', 'Technology Drivers', and 'Organizational Goals'.
      External Considerations
      • Regulations
      • Elections
      • Availability of resources
      • Staff licensing and certifications
      Organizational Drivers
      • Compliance
      • Scalability
      • Operational efficiency
      • Union agreements
      • Self service
      • Role appropriate dashboards and reports
      • Real time data access
        • Use of data in the system (no exports)
      Technology Considerations
      • Data accuracy
      • Data quality
      • Better reporting
      Functional Requirements
      • Information availability
      • Integration between systems
      • Secure data

      Activity 2.1.1 – Explore environmental factors and technology drivers

      1 hour

      1. Identify business drivers that are contributing to the organization’s need for ERP.
      2. Understand how the company is running today and what the organization’s future will look like. Try to identify the purpose for becoming an integrated organization. Use a whiteboard or flip charts and markers to capture key findings.
      3. Consider External Considerations, Organizational Drivers, Technology Drivers, and Key Functional Requirements.

      Record this information in the ERP Strategy Report Template.

      Sample of the next slide, 'ERP Business Model', with an iconized ERP Business Model and a table highlighting 'Environmental Factors', 'Technology Drivers', and 'Business Needs'.

      Download the ERP Strategy Report Template

      ERP Business Model A iconized version of the ERP Business Model.

      Environmental FactorsTechnology DriversBusiness Needs
      • Regulations
      • Elections
      • Availability of resources
      • Staff licensing and certifications
      • Document storage
      • Cloud security standards
      • Functionality based on deployment
      • Cloud-first based on above
      • Integration with external data suppliers
      • Integration with internal systems (Elite?)
      • Compliance
      • Scalability
      • Operational efficiency
      • Union agreements
      • Self service
      • Role appropriate dashboards and reports
      • Real time data access
      • Use of data in the system (no exports)
      • CapEx vs. OpEx

      Discuss challenges, pain points, enablers and organizational goals

      1. Identify challenges with current systems and processes.
      2. Brainstorm potential barriers to successful ERP selection and implementation. Use a whiteboard and marker to capture key findings.
      3. Consider organizational goals along with barriers and enablers to ERP success.
      The ERP Business Model with 'Organizational Goals', 'Enablers', and 'Barriers' highlighted. At the center is 'ERP Strategy' with 'Barriers' above and 'Enablers' below. Surrounding and feeding into the center group are 'Business Needs', 'Environmental Factors', 'Technology Drivers', and 'Organizational Goals'.
      Functional Gaps
      • No online purchase order requisition
      Technical Gaps
      • Inconsistent reporting – data quality concerns
      Process Gaps
      • Duplication of data
      • Lack of system integration
      Barriers to Success
      • Cultural mindset
      • Resistance to change
      Business Benefits
      • Business-IT alignment
      IT Benefits
      • Compliance
      • Scalability
      Organizational Benefits
      • Data accuracy
      • Data quality
      Enablers of Success
      • Change management
      • Alignment to strategic objectives

      Activity 2.1.2 – Discuss challenges, pain points, enablers, and organizational goals

      1 hour

      1. Identify challenges with the current systems and processes.
      2. Brainstorm potential barriers to successful ERP selection and implementation. Use a whiteboard or flip chart and markers to capture key findings.
      3. Consider functional gaps, technical gaps, process gaps, and barriers to ERP success.
      4. Identify the opportunities and benefits from an integrated system.
      5. Brainstorm potential enablers for successful ERP selection and implementation. Use a whiteboard and markers to capture key findings.
      6. Consider business benefits, IT benefits, organizational benefits, and enablers of success.

      Record this information in the ERP Strategy Report Template.

      Sample of the next slide, 'ERP Business Model', with an iconized ERP Business Model and a table highlighting 'Organizational Goals', 'Enablers', and 'Barriers'.

      Download the ERP Strategy Report Template

      ERP Business Model A iconized version of the ERP Business Model.

      Organizational Goals Enablers Barriers
      • Efficiency
      • Effectiveness
      • Integrity
      • One source of truth for data
      • One team
      • Customer service, external and internal
      • Cross-trained employees
      • Desire to focus on value-add activities
      • Collaborative
      • Top level executive support
      • Effective change management process
      • Organizational silos
      • Lack of formal process documentation
      • Funding availability
      • What goes first? Organizational priorities

      Step 2.2

      ERP processes and supporting applications

      Activities
      • 2.2.1 ERP process inventory
      • 2.2.2 Application portfolio

      This step will walk you through the following activities:

      • Identify the top-level (mega) processes and create an initial list of the sub-processes
      • Generate a list of applications that support the identified processes

      This step involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP applications support team

      Outcomes of this step

      • A list of in scope business processes
      • A list of current applications and services supporting the business processes

      Process Inventory

      In business architecture, the primary view of an organization is known as a business capability map.

      A business capability defines what a business does to enable value creation rather than how.

      Business capabilities:

      • Represent stable business functions
      • Are unique and independent of each other
      • Will typically have a defined business outcome

      A business capability map provides details that help the business architecture practitioner direct attention to a specific area of the business for further assessment.

      A process map titled 'Business capability map (Level 0)' with many processes sectioned off into sections and subsections. The top-left section is 'Products and Services Development' with subsections 'Design'(6 processes) and 'Manufacturing'(3 processes). The top-middle section is 'Revenue Generation'(3 processes) and below that is 'Sourcing'(2 processes). The top-right section is 'Demand Fulfillment'(9 processes). Along the bottom is the section 'Enterprise Management and Planning' with subsections 'Human Resources'(4 processes), 'Business Direction'(4 processes), and 'Finance'(4 processes).

      If you do not have a documented process model, you can use the APQC Framework to help define your inventory of business processes.

      APQC’s Process Classification Framework is a taxonomy of cross-functional business processes intended to allow the objective comparison of organizational performance within and among organizations.

      APQC’s Process Classification Framework

      Activity 2.2.1 – Process inventory

      2-4 hours

      1. As a group, discuss the business capabilities, value streams, and business processes.
      2. For each capability determine the following:
        • Is this capability applicable to our organization?
        • What application, if any, supports this capability?
      3. Are there any missing capabilities to add?

      Record this information in the ERP Strategy Report Template.

      Sample of the 'Process Inventory' table on the next slide.

      Download the ERP Strategy Report Template

      Activity 2.2.1 – Process inventory

      Core Finance Core HR Workforce Management Talent Management Warehouse Management Enterprise Asset Management
      Process Technology Process Technology Process Technology Process Technology Process Technology Process Technology
      • General ledger
      • Accounts payable
      • Accounts receivable
      • GL consolidation
      • Cash management
      • Billing and invoicing
      • Expenses
      • Payroll accounting
      • Tax management
      • Reporting
      • Payroll administration
      • Benefits administration
      • Position management
      • Organizational structure
      • Core HR records
      • Time and attendance
      • Leave management
      • Scheduling
      • Performance management
      • Talent acquisition
      • Offboarding & onboarding
      • Plan layout
      • Manage inventory
      • Manage loading docks
      • Pick, pack, ship
      • Plan and manage workforce
      • Manage returns
      • Transfer product cross-dock
      • Asset lifecycle management
      • Supply chain management
      • Maintenance planning & scheduling
      Planning & Budgeting Strategic HR Procurement Customer Relationship Management Facilities Management Project Management
      Process Technology Process Technology Process Technology Process Technology Process Technology Process Technology
      • Budget reporting
      • Variance analysis
      • Multi-year operating plan
      • Monthly forecasting
      • Annual operating plan
      • Compensation planning
      • Workforce planning
      • Succession planning
      • Supplier management
      • Purchase order management
      • Workflow approvals
      • Contract / tender management
      • Contact management
      • Activity management
      • Analytics
      • Plan and acquire
      • Asset maintenance
      • Disposal
      • Project management
      • Project costing
      • Budget control
      • Document management

      Complete an inventory collection of your application portfolio

      MANAGED vs. UNMANAGED APPLICATION ENVIRONMENTS

      • Managed environments make way for easier inventory collection since there is significant control as to what applications can be installed on a company asset. Organizations will most likely have a comprehensive list of supported and approved applications.
      • Unmanaged environments are challenging to control because users are free to install any applications on company assets, which may or may not be supported by IT.
      • Most organizations fall somewhere in between – there is usually a central repository of applications and several applications that are exceptions to the company policies. Ensure that all applications are accounted for.

      Determine your inventory collection method:

      MANUAL INVENTORY COLLECTION
      • In its simplest form, a spreadsheet is used to document your application inventory.
      • For large organizations, reps interview all business domains to create a list of installed applications.
      • Conducting an end-user survey within your business domains is one way to gather your application inventory and assess quality.
      • This manual approach is most appropriate for smaller organizations with small application portfolios across domains.
      AUTOMATED INVENTORY COLLECTION
      • Using inventory collection compatibility tools, discover all of the supported applications within your organization.
      • This approach may not capture all applications, depending on the parameters of your automated tool.
      • This approach works well in a managed environment.

      Activity 2.2.2 – Understand the current application portfolio

      1-2 hours

      1. Brainstorm a list of the applications that support the ERP business processes inventoried in Activity 2.2.1. If an application has multiple instances, list each instance as a separate line item.
      2. Indicate the following for each application:
        1. User satisfaction. This may be more than one entry as different groups – e.g., IT vs. business – may differ.
        2. Processes supported. Refer to processes defined in Activity 2.2.1. Update 2.2.1 if additional processes are identified during this exercise.
        3. Define a future disposition: Keep, Update, Replace. It is possible to have more than one disposition, e.g., Update or Replace is a valid disposition.
      3. [Optional] Collect the following information about each application. This information can be used to calculate the cost per application and total cost per user:
        1. Number of users or user groups
        2. Estimated maintenance costs
        3. Estimated capital costs
        4. Estimated licensing costs
        5. Estimated support costs

      Record this information in the ERP Strategy Report Template.

      Sample of the 'Application Portfolio' table on the next slide.

      Download the ERP Strategy Report Template

      2.2.2 - Application portfolio

      Inventory your applications and assess usage, satisfaction, and disposition

      Application Name Satisfaction Processes Supported Future Disposition
      PeopleSoft Financials Medium and declining ERP – shares one support person with HR Update or Replace
      Time Entry (custom) Low Time and Attendance Replace
      PeopleSoft HR Medium Core HR Update or Replace
      ServiceNow High ITSM
      CSM: Med-Low
      ITSM and CSM
      CSM – complexity and process changes
      Update
      Data Warehouse High IT
      Business: Med-Low
      BI portal – Tibco SaaS datamart Keep
      Regulatory Compliance Medium Regulatory software – users need training Keep
      ACL Analytics Low Audit Replace
      Elite Medium Supply chain for wholesale Update (in progress)
      Visual Importer Med-High Customs and taxes Keep
      Custom Reporting application Med-High Reporting solution for wholesale (custom for old system, patched for Elite) Replace

      2.3.1 – Visual application portfolio [optional]

      A diagram of applications and how they connect to each other. There are 'External Systems' and 'Internal Systems' split into three divisions, 'Retail Division', 'Wholesale Division', and 'Corporate Services'. Example external systems are 'Moneris', 'Freight Carriers', and 'Banks'. Example internal systems are 'Retail ERP/POS', 'Elite', and 'Excel'.

      Step 2.3

      Process pains, opportunities, and maturity

      Activities
      • 2.3.1 Level one process inventory with stakeholders
      • 2.3.2 Process pain points and opportunities
      • 2.3.3 Process key success indicators
      • 2.3.4 Process and technology maturity
      • 2.3.5 Mega-process prioritization

      This step will walk you through the following activities:

      • Assign stakeholders, discuss pain points, opportunities, and key success indicators for the mega-processes identified in Step 2.1
      • Assign process and technology maturity to each prioritizing the mega-processes

      This step involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP applications support team

      Outcomes of this step

      For each mega-process:

      • Level 1 processes with process and technology maturity assigned
      • Stakeholders identified
      • Process pain points, opportunities, and key success indicators identified
      • Prioritize the mega-processes

      Building out the mega-processes

      Congratulations, you have made it to the “big lift” portion of the blueprint. For each of the processes that were identified in exercise 2.2.1, you will fill out the following six details:

      1. Primary stakeholder(s)
      2. A description of the process
      3. hat level 1 processes/capabilities the mega-process is composed of
      4. Problems the new system must solve
      5. What success will look like when the new system is implemented
      6. The process and technological maturity of each level 1 process.

      Sample of the 'Core Finance' slide in the ERP Strategy Report, as shown on the next slide, with numbers corresponding to the ordered list above. 1 is on a list of 'Stakeholders', 2 is by the 'Description' box, 3 is on the 'Capability' table column, 4 is on the 'Current Pain Points' box, 5 is on the 'Key Success Factors' box, and 6 is on the 'Maturity' ratings column.

      It will take one to three hours per mega-process to complete the six different sections.

      Note:
      For each mega-process identified you will create a separate slide in the ERP Strategy Report. Default slides have been provided. Add or delete as necessary.

      Sample of the 'Core Finance' slide in the ERP Strategy Report. Note on the list of stakeholders reads 'Primary Stakeholders'. Note on the title, Core Finance, reads 'Mega-process name'. Note on the description box reads 'Description of the process'. Note on the 'Key Success Factors' box reads 'What success looks like'. Note on the 'Current Pain Points' box reads 'Problems the new system must solve'. Below is a capability table with columns 'Capability', 'Maturity', and a blank on for notes. Note on the 'Capability' table column reads 'Level 1 process'. Note on the 'Maturity' ratings column reads 'Level 1 process maturity of process and technology'. Note on the notes column reads 'Level 1 process notes'.

      An ERP project is most effective when you follow a structured approach to define, select, implement, and optimize

      Top-down approach

      ERP Strategy
      • Operating Model – Define process strategy, objectives, and operational implications.
      • Level 1 Processes –Define process boundaries, scope at the organization level; the highest level of mega-process.

      • Level 2 Processes – Define processes by function/group which represent the next level of process interaction in the organization.
      • Level 3 Processes – Decompose process by activity and role and identify suppliers, inputs, outputs, customers, metrics, and controls.
      • Functional Specifications; Blueprint and Technical Framework – Refine how the system will support and enable processes; includes functional and technical elements.
      • Org Structure and Change Management – Align org structure and develop change mgmt. strategy to support your target operating model.
      • Implementation and Transition to Operations – Execute new methods, systems, processes, procedures, and organizational structure.
      • ERP Optimization and Continuous Improvement – Establish a program to monitor, govern, and improve ERP systems and processes.

      *A “stage gate” approach should be used: the next level begins after consensus is achieved for the previous level.

      Activity 2.3.1 – Level 1 process inventory with stakeholders

      1 hour per mega-process

      1. Identify the primary stakeholder for the mega-process. The primary stakeholder is usually the process owner. For example, for core finance the CFO is the process owner/primary stakeholder. Name a maximum of three stakeholders.
      2. In the lower section, detail all the capabilities/processes associated with the mega-process. Be careful to remain at the level 1 process level as it is easy to start identifying the “How” of a process. The “How” is too deep.

      Record this information in the ERP Strategy Report Template.

      Sample of the 'Core Finance' slide in the ERP Strategy Report with the 'Stakeholders' list and 'Capability' table column highlighted.

      Download the ERP Strategy Report Template

      Activity 2.3.2 – Process pain points and opportunities

      30+ minutes per mega-process

      1. As a group, write a clear description of the mega-process. This helps establish alignment on the scope of the mega-process.
      2. Start with the discussion of current pain points with the various capabilities. These pain points will be items that the new solution will have to resolve.

      Record this information in the ERP Strategy Report Template.

      Sample of the 'Core Finance' slide in the ERP Strategy Report with the 'Description', 'Key Success Factors', and 'Current Pain Points' boxes highlighted.

      Download the ERP Strategy Report Template

      Activity 2.3.3 – Key success indicators

      30 minutes per mega-process

      1. Document key success factors that should be base-lined in the existing system to show the overall improvement once the new system is implemented. For example, if month-end close takes 12 days in the current system, target three days for month-end close in the new system.

      Record this information in the ERP Strategy Report Template.

      Sample of the 'Core Finance' slide in the ERP Strategy Report with the 'Description', 'Key Success Factors', and 'Current Pain Points' boxes highlighted.

      Download the ERP Strategy Report Template

      Activity 2.3.4 – Process and technology maturity

      1 hour

      1. For each capability/level 1 process identified determine you level of process maturity:
        • Weak – Ad hoc processes without documentation
        • Moderate – Documented processes that are often executed consistently
        • Strong – Documented processes that include exception handling that are rigorously followed
        • Payroll is an example of a strong process, even if every step is manual. The process is executed the same every time to ensure staff are paid properly and on time.
      2. For each capability/level 1 process identified determine you level of technology maturity:
        • Weak – manual execution and often paper-based
        • Moderate – Some technology support with little automation
        • Strong – The process executed entirely within the technology stack with no manual processes

      Record this information in the ERP Strategy Report Template.

      Sample of the 'Core Finance' slide in the ERP Strategy Report with the 'Maturity' and notes columns highlighted.

      Download the ERP Strategy Report Template

      Activity 2.3.5 – Mega-process prioritization

      1 hour

      1. For the mega-processes identified, map each process’s current state in terms of process rigor versus organizational importance.
        • For process rigor, refer to your process maturity in the previous exercises.
      2. Now, as a group discuss how you want to “move the needle” on each of the processes. Remember that you have a limited capacity so focus on the processes that are, or will be, of strategic importance to the organization. The processes that are placed in the top right quadrant are the ones that are likely the strategic differentiators.

      Record this information in the ERP Strategy Report Template.

      A smaller version of the process prioritization map on the next slide.

      Download the ERP Strategy Report Template.

      ERP Process Prioritization

      Establishing an order of importance can impact vendor selection and implementation roadmap; high priority areas are critical for ERP success.

      A prioritization map placing processes by 'Rigor' and 'Organizational Importance' They are numbered 1-9, 0, A, and B and are split into two colour-coded sets for 'Future (green)' and 'Current(red)'. On the x-axis 'Organizational Importance' ranges from 'Operational' to 'Strategic' and on the y-axis 'Process Rigor' ranges from 'Get the Job Done' to 'Best Practice'. Comparing 'Current' to 'Future', they have all moved up from 'Get the Job Done' into 'Best Practice' territory and a few have migrated over from 'Operational' to 'Strategic'. Processes are 1. Core Finance, 2. Core HR, 3. Workforce Management, 4.Talent Management, 5. Employee Health and Safety, 6. Enterprise Asset Management, 7.Planning & Budgeting, 8. Strategic HR, 9. Procurement Mgmt., 0. CRM, A. Facilities, and B. Project Management.

      Build an ERP Strategy and Roadmap

      Phase 3

      Plan your project

      Phase 1

      • 1.1 Aligning business and IT
      • 1.2 Scope and priorities

      Phase 2

      • 2.1 ERP Business Model
      • 2.2 ERP processes and supporting applications
      • 2.3 Process pains, opportunities & maturity

      Phase 3

      • 3.1 Stakeholders, risk & value
      • 3.2 Project set up

      Phase 4

      • 4.1 Build your roadmap
      • 4.2 Wrap up and present

      This phase will walk you through the following activities:

      • Map out your stakeholders to evaluate their impact on the project
      • Build an initial risk register and ensure the group is aligned
      • Set the initial core project team and their accountabilities and get them started on the project

      This phase involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Step 3.1

      Stakeholders, risk, and value

      Activities
      • 3.1.1 Stakeholder analysis
      • 3.1.2 Potential pitfalls and mitigation strategies
      • 3.1.3 Project value [optional]

      This step will walk you through the following activities:

      • Map out your stakeholders to evaluate their impact on the project
      • Build an initial risk register and ensure the group is aligned

      This step involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Outcomes of this step

      • An understanding of the stakeholders and their project influence
      • An initial risk register
      • A consensus on readiness to proceed

      Understand how to navigate the complex web of stakeholders in ERP

      Identify which stakeholders to include and what their level of involvement should be during requirements elicitation based on relevant topic expertise.

      Sponsor End User IT Business
      Description An internal stakeholder who has final sign-off on the ERP project. Front-line users of the ERP technology. Back-end support staff who are tasked with project planning, execution, and eventual system maintenance. Additional stakeholders that will be impacted by any ERP technology changes.
      Examples
      • CEO
      • CIO/CTO
      • COO
      • CFO
      • Warehouse personnel
      • Sales teams
      • HR admins
      • Applications manager
      • Vendor relationship manager(s)
      • Director, Procurement
      • VP, Marketing
      • Manager, HR
      Value Executive buy-in and support is essential to the success of the project. Often, the sponsor controls funding and resource allocation. End users determine the success of the system through user adoption. If the end user does not adopt the system, the system is deemed useless and benefits realization is poor. IT is likely to be responsible for more in-depth requirements gathering. IT possesses critical knowledge around system compatibility, integration, and data. Involving business stakeholders in the requirements gathering will ensure alignment between HR and organizational objectives.

      Large-scale ERP projects require the involvement of many stakeholders from all corners and levels of the organization, including project sponsors, IT, end users, and business stakeholders. Consider the influence and interest of stakeholders in contributing to the requirements elicitation process and involve them accordingly.

      An example stakeholder map, categorizing stakeholders by amount of influence and interest.

      Activity 3.1.1 – Map your stakeholders

      1 hour

      1. As a group, identify all the ERP stakeholders. A stakeholder may be an individual such as the CEO or CFO, or it may be a group such as front-line employees.
      2. Map each stakeholder on the quadrant based on their expected Influence and Involvement in the project
      3. [Optional] Color code the users using the scale below to quickly identify the group that the stakeholder belongs to.
        • Sponsor – An internal stakeholder who has final sign-off on the ERP project.
        • End User – Front-line users of the ERP technology.
        • IT – Back-end support staff who are tasked with project planning, execution, and eventual system maintenance.
        • Business – Additional stakeholders that will be impacted by any ERP technology changes.

      Record this information in the ERP Strategy Report Template.

      Preview of the next slide.

      Download the ERP Strategy Report Template

      Slide titled 'Map the organization's stakeholders with a more in-depth example of a stakeholder map and long 'List of Stakeholders'. The quadrants that stakeholders are sorted into by influence and involvement are labelled 'Keep Satisfied (1)', 'Involve Closely (2)', 'Monitor (3)', and 'Keep Informed (4)'.

      Prepare contingency plans to minimize time spent handling unexpected risks

      Understanding the technical and strategic risks of a project can help you establish contingencies to reduce the likelihood of risk occurrence and devise mitigation strategies to help offset their impact if contingencies are insufficient.

      Risk Impact Likelihood Mitigation Effort
      Inadequate budget for additional staffing resources. 2 1 Use internal transfers and role-sharing rather than external hiring.
      Push-back on an ERP solution. 2 2 Use formal communication plans, an ERP steering committee, and change management to overcome organizational readiness.
      Overworked resources. 1 1 Create a detailed project plan that outlines resources and timelines in advance.
      Rating Scale:
      Impact: 1- High Risk 2- Moderate Risk 3- Minimal Risk
      Likelihood: 1- High/Needs Focus 2- Can Be Mitigated 3- Remote Likelihood

      Remember

      The biggest sources of risk in an ERP strategy are lack of planning, poorly defined requirements, and lack of governance.

      Apply the following mitigation tips to avoid pitfalls and delays.

      Risk Mitigation Tips

      • Upfront planning
      • Realistic timelines
      • Resource support
      • Managing change
      • Executive sponsorship
      • Sufficient funding
      • Setting the right expectations

      Activity 3.1.2 – Identify potential project pitfalls and mitigation strategies

      1-2 hours

      1. Discuss what “Impact” and “Likelihood” mean to your organization. For example, define Impact by what is important to your organization – financial loss, reputational impact, employee loss, and process impairment are all possible factors.
      2. Identify potential risks that may impede the successful completion of each work initiative. Risks may include predictable factors such as low resource capability, or unpredictable factors such as a change in priorities leading to withdrawn buy-in.
      3. For each risk, identify mitigation tactics. In some cases, mitigation tactics might take the form of standalone work initiative. For example, if a risk is lack of end-user buy-in, a work initiative to mitigate that risk might be to build an end-user communication plan.

      Record this information in the ERP Strategy Report Template.

      Preview of the next slide.

      Download the ERP Strategy Report Template

      Risks

      Risk Impact Likelihood Mitigation Effort
      Inadequate budget for additional staffing resources. 2 1 Use internal transfers and role-sharing rather than external hiring.
      Push-back on an ERP solution. 2 2 Use formal communication plans, an ERP steering committee, and change management to overcome organizational readiness.
      Overworked resources. 1 1 Create a detailed project plan that outlines resources and timelines in advance.
      Project approval 1 1 Build a strong business case for project approval and allow adequate time for the approval process
      Software does not work as advertised resulting in custom functionality with associated costs to create/ maintain 1 2 Work with staff to change processes to match the software instead of customizing the system thorough needs analysis prior to RFP creation
      Under estimation of staffing levels required, i.e. staff utilized at 25% for project when they are still 100% on their day job 1 2 Build a proper business case around staffing (be somewhat pessimistic)
      EHS system does not integrate with new HRMS/ERP system 2 2
      Selection of an ERP/HRMS that does not integrate with existing systems 2 3 Be very clear in RFP on existing systems that MUST be integrated to
      Rating Scale:
      Impact: 1- High Risk 2- Moderate Risk 3- Minimal Risk
      Likelihood: 1- High/Needs Focus 2- Can Be Mitigated 3- Remote Likelihood

      Is the organization committed to the ERP project?

      A recent study of critical success factors to an ERP implementation identified top management support and interdepartmental communication and cooperation as the top two success factors.

      By answering the seven questions the key stakeholders are indicating their commitment. While this doesn’t guarantee that the top two critical success factors have been met, it does create the conversation to guide the organization into alignment on whether to proceed.

      A table of example stakeholder questions with options 1-5 for how strongly they agree or disagree. 'Strongly disagree - 1', 'Somewhat disagree - 2', 'Neither agree or disagree - 3', 'Somewhat agree - 4', 'Strongly agree - 5'.

      Activity 3.1.3 – Project value (optional)

      30 minutes

      1. As a group, discuss the seven questions in the table. Ensure everyone agrees on what the questions are asking. If necessary, modify the language so that the meaning is clear to everyone.
      2. Have each stakeholder answer the seven questions on their own. Have someone compile the answers looking for:
        1. Any disagrees, strongly, somewhat, or neither as this indicates a lack of clarity. Endeavour to discover what additional information is required.
        2. [Optional] Have the most positive and most negative respondents present their points of view for the group to discuss. Is someone being overly optimistic, or pessimistic? Did the group miss something?

      There are no wrong answers. It should be okay to disagree with any of these statements. The goal of the exercise is to generate conversation that leads to support of the project and collaboration on the part of the participants.

      Record this information in the ERP Strategy Report Template.

      A preview of the next slide.

      Download the ERP Strategy Report Template

      Ask the right questions now to determine the value of the project to the organization

      Please indicate how much you agree or disagree with each of the following statements.

      Question # Question Strongly disagree Somewhat disagree Neither agree nor disagree Somewhat agree Strongly agree
      1. I have everything I need to succeed. 1 2 3 4 5
      2. The right people are involved in the project. 1 2 3 4 5
      3. I understand the process of ERP selection. 1 2 3 4 5
      4. My role in the project is clear to me. 1 2 3 4 5
      5. I am clear about the vision for this project. 1 2 3 4 5
      6. I am nervous about this project. 1 2 3 4 5
      7. There is leadership support for the project. 1 2 3 4 5

      Step 3.2

      Project set up

      Activities
      • 3.2.1 Create the project team
      • 3.2.2 Set the project RACI

      This step will walk you through the following activities:

      • Set the initial core project team and their accountabilities to the project.

      This step involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Outcomes of this step

      • Identify the core team members and their time commitments.
      • Assign responsibility, accountability or communication needs.

      Identify the right stakeholders for your project team

      Consider the core team functions when composing the project team. It is essential to ensure that all relevant perspectives (business, IT, etc.) are evaluated to create a well-aligned and holistic ERP strategy.

      PROJECT TEAM ROLES

      • Project champion
      • Project advisor
      • Steering committee
      • Project manager
      • Project team
      • Subject matter experts
      • Change management specialist

      PROJECT TEAM FUNCTIONS

      • Collecting all relevant inputs from the business.
      • Gathering high-level requirements.
      • Creating a roadmap.

      Info-Tech Insight

      There may be an inclination towards a large project team when trying to include all relevant stakeholders. Carefully limiting the size of the project team will enable effective decision making while still including functional business units like HR and Finance, as well as IT.

      Activity 3.2.1 – Project team

      1 hour

      1. Considering your ERP project scope, discuss the resources and capabilities necessary, and generate a complete list of key stakeholders considering each of the roles indicated on the chart to the right.
      2. Using the list previously generated, identify a candidate(s) for each role and determine their responsibility in the ERP strategy and their expected time commitment.

      Record this information in the ERP Strategy Report Template.

      Preview of the table on the next slide.

      Download the ERP Strategy Report Template

      Project team

      Of particular importance for this table is the commitment column. It is important that the organization understands the level of involvement for all roles. Failure to properly account for the necessary involvement is a major risk factor.

      Role Candidate Responsibility Commitment
      Project champion John Smith
      • Provide executive sponsorship.
      20 hours/week
      Steering committee
      • Establish goals and priorities.
      • Define scope and approve changes.
      • Provide adequate resources and resolve conflict.
      • Monitor project milestones.
      10 hours/week
      Project manager
      • Prepare and manage project plan.
      • Monitor project team progress.
      • Conduct project team meetings.
      40 hours/week
      Project team
      • Drive day-to-day project activities.
      • Coordinate department communication.
      • Make process and design decisions.
      40 hours/week
      Subject matter experts by area
      • Attend meetings as needed.
      • Respond to questions and inquiries.
      5 hours/week

      Define project roles and responsibilities to improve progress tracking

      Build a list of the core ERP strategy team members and then structure a RACI chart with the relevant categories and roles for the overall project.

      • Responsible – Conducts work to achieve the task
      • Accountable – Answerable for completeness of task
      • Consulted – Provides input for the task
      • Informed – Receives updates on the task

      Benefits of assigning RACI early:

      • Improve project quality by assigning the right people to the right tasks.
      • Improve chances of project task completion by assigning clear accountabilities.
      • Improve project buy-in by ensuring stakeholders are kept informed of project progress, risks, and successes.

      Activity 3.2.2 – Project RACI

      1 hour

      1. The ERP strategy will require a cross-functional team within IT and business units. Make sure the responsibilities are clearly communicated to the selected project sponsor.
      2. Modify the left-hand column to match the activities expected in your project.

      Record this information in the ERP Strategy Report Template.

      Preview of the RACI chart on the next slide.

      Download the ERP Strategy Report Template

      3.2.2 – Project RACI

      Project champion Project advisor Project steering committee Project manager Project team Subject matter experts
      Determine project scope & vision I C A R C C
      Document business goals I I A R I C
      Inventory ERP processes I I A C R R
      Map current state I I A R I R
      Assess gaps and opportunities I C A R I I
      Explore alternatives R R A I I R
      Build a roadmap R A R I I R
      Create a communication plan R A R I I R
      Present findings R A R I I R

      Build an ERP Strategy and Roadmap

      Phase 4

      Next steps

      Phase 1

      • 1.1 Aligning business and IT
      • 1.2 Scope and priorities

      Phase 2

      • 2.1 ERP Business Model
      • 2.2 ERP processes and supporting applications
      • 2.3 Process pains, opportunities & maturity

      Phase 3

      • 3.1 Stakeholders, risk & value
      • 3.2 Project set up

      Phase 4

      • 4.1 Build your roadmap
      • 4.2 Wrap up and present

      This phase will walk you through the following activities:

      • Review the different options to solve the identified pain points
      • Build out a roadmap showing how you will get to those solutions
      • Build a communication plan that includes the stakeholder presentation

      This phase involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Step 4.1

      Build your roadmap

      Activities
      • 4.1.1 Pick your path
      • 4.1.2 Build your roadmap
      • 4.1.3 Visualize your roadmap (optional)

      This step will walk you through the following activities:

      • Review the different options to solve the identified pain points then build out a roadmap of how to get to that solution.

      This step involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Outcomes of this step

      • A strategic direction is set
      • An initial roadmap is laid out

      Choose the right path for your organization

      There are several different paths you can take to achieve your ideal future state. Make sure to pick the one that suits your needs as defined by your current state.

      A diagram of strategies. At the top is 'Current State', at the bottom is 'Future State', and listed strategies are 'Maintain Current System', 'Augment Current System', 'Optimize', and 'Transform'.

      Explore the options for achieving your ideal future state

      CURRENT STATE STRATEGY
      Your existing application satisfies both functionality and integration requirements. The processes surrounding it likely need attention, but the system should be considered for retention. MAINTAIN CURRENT SYSTEM
      Your existing application is, for the most part, functionally rich, but may need some tweaking. Spend time and effort building and enhancing additional functionalities or consolidating and integrating interfaces. AUGMENT CURRENT SYSTEM
      Your ERP application portfolio consists of multiple apps serving the same functions. Consolidating applications with duplicate functionality is more cost efficient and makes integration and data sharing simpler. OPTIMIZE: CONSOLIDATE AND INTEGRATE SYSTEMS
      Your existing system offers poor functionality and poor integration. It would likely be more cost and time efficient to replace the application and its surrounding processes altogether. TRANSFORM: REPLACE CURRENT SYSTEM

      Option: Maintain your current system

      Resolve your existing process and people pain points

      MAINTAIN CURRENT SYSTEM

      Keep the system, change the process.

      Your existing application satisfies both functionality and integration requirements. The processes surrounding it likely need attention, but the system should be considered for retention.

      Maintaining your current system entails adjusting current processes and/or adding new ones, and involves minimal cost, time, and effort.

      INDICATORS POTENTIAL SOLUTIONS
      People Pain Points
      • Lack of training
      • Low user adoption
      • Lack of change management
      • Contact vendor to inquire about employee training opportunities
      • Build a change management strategy
      Process Pain Points
      • Legacy processes
      • Workarounds and shortcuts
      • Highly specialized processes
      • Inconsistent processes
      • Explore process reengineering and process improvement opportunities
      • Evaluate and standardize processes

      Option: Augment your current system

      Use augmentation to resolve your existing technology and data pain points

      AUGMENT CURRENT SYSTEM

      Add to the system.

      Your existing application is for the most part functionally rich but may need some tweaking. Spend time and effort enhancing your current system.

      You will be able to add functions by leveraging existing system features. Augmentation requires limited investment and less time and effort than a full system replacement.

      INDICATORS POTENTIAL SOLUTIONS
      Technology Pain Points
      • Lack of reporting functions.
      • Lacking functional depth in key process areas.
      • Add point solutions or enable modules to address missing functionality.
      Data Pain Points
      • Poor data quality
      • Lack of data for processing and reporting
      • Single-source data entry
      • Add modules or augment processes to capture data

      Option: Consolidate and integrate

      Consolidate and integrate your current systems to address your technology and data pain points

      CONSOLIDATE AND INTEGRATE SYSTEMS

      Get rid of one system, combine two, or connect many.

      Your ERP application portfolio consists of multiple apps serving the same functions.

      Consolidating your systems eliminates the need to manage multiple pieces of software that provide duplicate functionality. Reducing the number of ERP applications makes integration and data sharing simpler.

      INDICATORS POTENTIAL SOLUTIONS
      Technology Pain Points
      • Disparate and disjointed systems
      • Multiple systems supporting the same function
      • Unused software licenses
      • System consolidation
      • System and module integration
      • Assess usage and consolidate licensing
      Data Pain Points
      • Multiple versions of same data
      • Duplication of data entry in different modules or systems
      • Poor data quality
      • Centralize core records
      • Assign data ownership
      • Single-source data entry

      Option: Replace your current system

      Replace your system to address gaps in your existing processes and various pain points

      REPLACE CURRENT SYSTEM

      Start from scratch.

      You’re transitioning from an end-of-life legacy system. Your existing system offers poor functionality and poor integration. It would likely be more cost and time efficient to replace the application and its surrounding processes all together.

      INDICATORS POTENTIAL SOLUTIONS
      Technology Pain Points
      • Lack of functionality and poor integration.
      • Obsolete technology.
      • Not aligned with technology direction or enterprise architecture plans.
      • Evaluate the ERP technology landscape.
      • Determine if you need to replace the current system with a point solution or an all-in-one solution.
      • Align ERP technologies with enterprise architecture.
      Data Pain Points
      • Limited capability to store and retrieve data.
      • Understand your data requirements.
      Process Pains
      • Insufficient tools to manage workflow.
      • Review end-to-end processes.
      • Assess user satisfaction.

      Activity 4.1.1 – Path to future state

      1+ hour
      1. Discuss the four options and the implications for your organization.
      2. Come to an agreement on your chosen path.

      The same diagram of strategies. At the top is 'Current State', at the bottom is 'Future State', and listed strategies are 'Maintain Current System', 'Augment Current System', 'Optimize', and 'Transform'.

      Activity 4.1.2 – Build a roadmap

      1-2 hours

      1. Start your roadmap with the stakeholder presentation. This is your mark in the sand to launch the project.
      2. For each item on your roadmap assign an owner who will be accountable to the completion of the roadmap item.
      3. Wherever possible, assign a start date, month, or quarter. The more specific you can be the better.
      4. Identify completion dates to create a sense of urgency. If you are struggling with start dates, it can help to start with a finish date and “back in” to a start date based on estimated efforts.

      Record this information in the ERP Strategy Report Template.

      Note:
      Your roadmap should be treated as a living document that is updated and shared with the stakeholders on a regular schedule.

      Preview of the strategy roadmap table on the next slide.

      Download the ERP Strategy Report Template

      ERP Strategy roadmap

      Initiative Owner Start Date Completion Date
      Create final workshop deliverable Info-Tech 16 September, 2021
      Review final deliverable Workshop sponsor
      Present to executive team Oct 2021
      Build business case CFO, CIO, Directors 3 weeks to build
      3-4 weeks process time
      Build an RFI for initial costings 1-2 weeks
      Stage 1 approval for requirements gathering Executive committee Milestone
      Determine and acquire BA support for next step 1 week
      Requirements gathering – level 2 processes Project team 5-6 weeks effort
      Build RFP (based on informal approval) CFO, CIO, Directors 4th calendar quarter 2022 Possible completion January 2023
      2-4 weeks

      Activity 4.1.3 – Build a visual roadmap [optional]

      1 hour

      1. For some, a visual representation of a roadmap is easier to comprehend. Consider taking the roadmap built in 4.1.2 and creating a visual.

      Record this information in the ERP Strategy Report Template.

      Preview of the visual strategy roadmap chart on the next slide.

      Download the ERP Strategy Report Template

      ERP Strategy Roadmap

      A table set up similarly to the previous one, but instead of 'Start Date' and 'Completion Date' columns there are multiple small columns broken up by fiscal quarters (i.e.. FY2022: Q1, Q2, Q3, Q4). There is a key with a light blue diamond shape representing a 'Milestone' and a blue arrow representing a 'Work in progress'; they are placed the Quarters columns according to when each row item reached a milestone or began its progress.

      Step 4.2

      Wrap up and present

      Activities
      • 4.2.1 Communication plan
      • 4.2.2 Stakeholder presentation

      This step will walk you through the following activities:

      • Build a communication plan as part of organizational change management, which includes the stakeholder presentation

      This step involves the following participants:

      • Primary stakeholders in each value stream supported by the ERP
      • ERP Applications support team

      Outcomes of this step

      • An initial communication plan for organizational change management
      • A stakeholder presentation

      Effectively communicate the changes an ERP foundation strategy will impose

      A communication plan is necessary because not everyone will react positively to change. Therefore, you must be prepared to explain the rationale behind any initiatives that are being rolled out.

      Steps:

      1. Start by building a sound communication plan.
      2. The communication plan should address all stakeholders that will be subject to change, including executives and end users.
      3. Communicate how a specific initiative will impact the way employees work and the work they do.
      4. Clearly convey the benefits of the strategy to avoid resistance.

      “The most important thing in project management is communication, communication, communication. You have to be able to put a message into business terms rather than technical terms.” (Lance Foust, I.S. Manager, Plymouth Tube Company)

      Project Goals Communication Goals Required Resources Communication Channels
      Why is your organization embarking on an ERP project? What do you want employees to know about the project? What resources are going to be utilized throughout the ERP strategy? How will your project team communicate project updates to the employees?
      Streamline processes and achieve operational efficiency. We will focus on mapping and gathering requirements for (X) mega-processes. We will be hiring process owners for each mega-process. You will be kept up to date about the project progress via email and intranet. Please feel free to contact the project owner if you have any questions.

      Activity 4.2.1 – Communication plan

      1 hour

      1. List the types of communication events and documents you will need to produce and distribute.
      2. Indicate the purpose of the event or document, who the audience is, and who is responsible for the communication.
      3. Identify who will be responsible for the development and delivery of the communication plan.

      Record this information in the ERP Strategy Report Template.

      Preview of the Communication Plan table on the next slide.

      Download the ERP Strategy Report Template

      Communication plan

      Use the communication planning template to track communication methods needed to convey information regarding ERP initiatives.

      This is designed to help your organization make ERP initiatives visible and create stakeholder awareness.

      Audience Purpose Delivery/ Format Communicator Delivery Date Status/Notes
      Front-line employees Highlight successes Bi-weekly email CEO Mondays
      Entire organization Highlight successes
      Plans for next iteration
      Monthly townhall Senior leadership Last Thursday of every month Recognize top contributors from different parts of the business. Consider giving out prizes such as coffee mugs
      Iteration demos Show completed functionality to key stakeholders Iteration completion web conference Delivery lead Every other Wednesday Record and share the demonstrations to all employees

      Conduct a presentation of the final deliverable for stakeholders

      After completing the activities and exercises within this blueprint, the final step of the process is to present the deliverable to senior management and stakeholders.

      Know Your Audience

      • Decide what needs to be presented and to whom. The purpose and format for communicating initiatives varies based on the audience. Identify the audience first to ensure initiatives are communicated appropriately.
      • IT and the business speak different languages. The business may not have the patience to try to understand IT, so it is up to IT to learn and use the language of business. Failing to put messages into language that resonates with the business will create disengagement and resistance.
      • Effective communication takes preparation to get the right content and tone to convey your real message.

      Learn From Other Organizations

      “When delivering the strategy and next steps, break the project down into consumable pieces. Make sure you deliver quick wins to retain enthusiasm and engagement.

      By making it look like a different project you keep momentum and avoid making it seem unattainable.” (Scott Clark, Innovation Credit Union)

      “To successfully sell the value of ERP, determine what the high-level business problem is and explain how ERP can be the resolution. Explicitly state which business areas ERP is going to touch. The business often has a very narrow view of ERP and perceives it as just a financial system. The key part of the strategy is that the organization sees the broader view of ERP.” (Scott Clark, Innovation Credit Union)

      Activity 4.2.2 – Stakeholder presentation

      1 hour

      1. The following sections of the ERP Strategy Report Template are designed to function as the stakeholder presentation:
        1. Workshop Overview
        2. ERP Models
        3. Roadmap
      2. You can use the Template as your presentation deck or extract the above sections to create a stand-alone stakeholder presentation.
      3. Remember to take your audience into account and anticipate the questions they may have.

      Samples of the ERP Strategy Report Template.

      Download the ERP Strategy Report Template

      Summary of Accomplishment

      Get the Most Out of Your ERP

      ERP technology is critical to facilitating an organization’s flow of information across business units. It allows for seamless integration of systems and creates a holistic view of the enterprise to support decision making. ERP implementation should not be a one-and-done exercise. There needs to be an ongoing optimization to enable business processes and optimal organizational results.

      Build an ERP Strategy and Roadmap allows organizations to proactively implement continuous assessment and optimization of their enterprise resource planning system, including:

      • Alignment and prioritization of key business and technology drivers.
      • Identification of ERP processes, including classification and gap analysis.
      • Measurement of user satisfaction across key departments.
      • Improved vendor relations.
      • Data quality initiatives.

      This formal ERP optimization initiative will drive business-IT alignment, identify IT automation priorities, and dig deep into continuous process improvement.

      If you would like additional support, have our analysts guide you through other phases as part of an Info-Tech workshop.

      Contact your account representative for more information.
      workshops@infotech.com 1-888-670-8889

      Research Contributors

      Name Title Organization
      Anonymous Anonymous Software industry
      Anonymous Anonymous Pharmaceutical industry
      Boris Znebel VP of Sales Second Foundation
      Brian Kudeba Director, Administrative Systems Fidelis Care
      David Lawrence Director, ERP Allegheny Technologies Inc.
      Ken Zima CIO Aquarion Water Company
      Lance Foust I.S. Manager Plymouth Tube Company
      Pooja Bagga Head of ERP Strategy & Change Transport for London
      Rob Schneider Project Director, ERP Strathcona County
      Scott Clark Innovation Credit Union
      Tarek Raafat Manager, Application Solutions IDRC
      Tom Walker VP, Information Technology StarTech.com

      Related Info-Tech Research

      Bibliography

      Gheorghiu, Gabriel. "The ERP Buyer’s Profile for Growing Companies." Selecthub. 2018. Accessed 21 Feb. 2021.

      "Maximizing the Emotional Economy: Behavioral Economics." Gallup. n.d. Accessed 21 Feb. 2021.

      Neito-Rodriguez, Antonio. Project Management | How to Prioritize Your Company's Projects. 13 Dec. 2016. Accessed 29 Nov 2021. Web.

      "A&D organization resolves organizational.“ Case Study. Panorama Consulting Group. 2021. PDF. 09 Nov. 2021. Web.

      "Process Frameworks." APQC. n.d. Accessed 21 Feb. 2021.

      Saxena, Deepak and Joe Mcdonagh. "Evaluating ERP Implementations: The Case for a Lifecycle-based Interpretive Approach." The Electronic Journal of Information Systems Evaluation, 29-37. 22 Feb. 2019. Accessed 21 Feb. 2021.

      Customer Relationship Management Platform Selection Guide

      • Buy Link or Shortcode: {j2store}529|cart{/j2store}
      • member rating overall impact: 9.2/10 Overall Impact
      • member rating average dollars saved: $14,719 Average $ Saved
      • member rating average days saved: 32 Average Days Saved
      • Parent Category Name: Customer Relationship Management
      • Parent Category Link: /customer-relationship-management
      • Customer relationship management (CRM) suites are an indispensable part of a holistic strategy for managing end-to-end customer interactions.
      • After defining an approach to CRM, selection and implementation of the right CRM suite is a critical step in delivering concrete business value for marketing, sales, and customer service.
      • Despite the importance of CRM selection and implementation, many organizations struggle to define an approach to picking the right vendor and rolling out the solution in an effective and cost-efficient manner.
      • IT often finds itself in the unenviable position of taking the fall for CRM platforms that don't deliver on the promise of the CRM strategy.

      Our Advice

      Critical Insight

      • IT needs to be a trusted partner in CRM selection and implementation, but the business also needs to own the requirements and be involved from the beginning.
      • CRM requirements dictate the components of the target CRM architecture, such as deployment model, feature focus, and customization level. Savvy application directors recognize the points in the project where the CRM architecture model necessitates deviations from a "canned" roll-out plan.
      • CRM selection is a multi-step process that involves mapping target capabilities for marketing, sales, and customer service, assigning requirements across functional categories, determining the architecture model to prioritize criteria, and developing a comprehensive RFP that can be scored in a weighted fashion.
      • Companies that succeed with CRM implementation create a detailed roadmap that outlines milestones for configuration, security, points of implementation, data migration, training, and ongoing application maintenance.

      Impact and Result

      • A CRM platform that effectively meets the needs of marketing, sales, and customer service and delivers value.
      • Reduced costs during CRM selection.
      • Reduced implementation costs and time frame.
      • Faster time to results after implementation.

      Customer Relationship Management Platform Selection Guide Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Customer Relationship Management Platform Selection Guide – Speed up the process to build your business case and select your CRM solution.

      This blueprint will help you build a business case for selecting the right CRM platform, defining key requirements, and conducting a thorough analysis and scan of the ever-evolving CRM market space.

      • Customer Relationship Management Platform Selection Guide — Phases 1-3

      2. CRM Business Case Template – Document the key drivers for selecting a new CRM platform.

      Having a sound business case is essential for succeeding with a CRM. This template will allow you to document key drivers and impact, in line with the CRM Platform Selection Guide blueprint.

      • CRM Business Case Template

      3. CRM Request for Proposal Template

      Create your own request for proposal (RFP) for your customer relationship management (CRM) solution procurement process by customizing the RFP template created by Info-Tech.

      • CRM Request for Proposal Template

      4. CRM Suite Evaluation and RFP Scoring Tool

      The CRM market has many strong contenders and differentiation may be difficult. Instead of relying solely on reputation, organizations can use this RFP tool to record and objectively compare vendors according to their specific requirements.

      • CRM Suite Evaluation and RFP Scoring Tool

      5. CRM Vendor Demo Script

      Use this template to support your business's evaluation of vendors and their solutions. Provide vendors with scenarios that prompt them to display not only their solution's capabilities, but also how the tool will support your organization's particular needs.

      • CRM Vendor Demo Script

      6. CRM Use Case Fit Assessment Tool

      Use this tool to help build a CRM strategy for the organization based on the specific use case that matches your organizational needs.

      • CRM Use-Case Fit Assessment Tool
      [infographic]

      Further reading

      Customer Relationship Management Platform Selection Guide

      Speed up the process to build your business case and select your CRM solution.

      Table of Contents

      1. Analyst Perspective
      2. Executive Summary
      3. Blueprint Overview
      4. Executive Brief
      5. Phase 1: Understand CRM Functionality
      6. Phase 2: Build the Business Case and Elicit CRM requirements
      7. Phase 3: Discover the CRM Marketspace and Prepare for Implementation
      8. Conclusion

      Analyst Perspective

      A strong CRM platform is paramount to succeeding with customer engagement.

      Modern CRM platforms are the workhorses that provide functional capabilities and data curation for customer experience management. The market for CRM platforms has seen an explosion of growth over the last five years, as organizations look to mature their ability to deliver strong capabilities across marketing, sales, and customer service.

      IT needs to be a trusted partner in CRM selection and implementation, but the business also needs to own the requirements and be involved from the get-go.

      CRM selection must be a multistep process that involves defining target capabilities for marketing, sales, and customer service, prioritizing requirements across functional categories, determining the architecture model for the CRM environment, and developing a comprehensive RFP that can be scored in a weighted fashion.

      To succeed with CRM implementation, create a detailed roadmap that outlines milestones for configuration, security, points of implementation, data migration, training, and ongoing application maintenance.

      Photo of Ben Dickie, Research Lead, Customer Experience Strategy, Info-Tech Research Group. Ben Dickie
      Research Lead, Customer Experience Strategy
      Info-Tech Research Group

      Executive Summary

      Your Challenge

      Customer Relationship Management (CRM) suites are an indispensable part of a holistic strategy for managing end-to-end customer interactions. Selecting the right platform that aligns with your requirements is a significant undertaking.

      After defining an approach to CRM, selection and implementation of the right CRM suite is a critical step in delivering concrete business value for marketing, sales, and customer service.
      Common Obstacles

      Despite the importance of CRM selection and implementation, many organizations struggle to define an approach to picking the right vendor and rolling out the solution in an effective and cost-efficient manner.

      The CRM market is rapidly evolving and changing, making it tricky to stay on top of the space.

      IT often finds itself in the unenviable position of taking the fall for CRM platforms that don’t deliver on the promise of the CRM strategy.
      Info-Tech’s Approach

      CRM platform selection must be driven by your overall customer experience management strategy: link your CRM selection to your organization’s CXM framework.

      Determine if you need a CRM platform that skews toward marketing, sales, or customer service; leverage use cases to help guide selection.

      Ensure strong points of integration between CRM and other software such as MMS. A CRM should not live in isolation; it must provide a 360-degree view.

      Info-Tech Insight

      IT must work in lockstep with its counterparts in marketing, sales, and customer service to define a unified vision for the CRM platform.

      Info-Tech’s methodology for selecting the right CRM platform

      1. Understand CRM Features 2. Build the Business Case & Elicit CRM Requirements 3. Discover the CRM Market Space & Prepare for Implementation
      Phase Steps
      1. Define CRM platforms
      2. Classify table stakes & differentiating capabilities
      3. Explore CRM trends
      1. Build the business case
      2. Streamline requirements elicitation for CRM
      3. Construct the RFP
      1. Discover key players in the CRM landscape
      2. Engage the shortlist & select finalist
      3. Prepare for implementation
      Phase Outcomes
      • Consensus on scope of CRM and key CRM capabilities
      • CRM selection business case
      • Top-level use cases and requirements
      • Completed CRM RFP
      • CRM market analysis
      • Shortlisted vendor
      • Implementation considerations

      Guided Implementation

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

      The CRM purchase process should be broken into segments:

      1. CRM vendor shortlisting with this buyer’s guide
      2. Structured approach to selection
      3. Contract review

      What does a typical GI on this topic look like?

      Phase 1

      Phase 2

      Phase 3

      Call #1: Understand what a CRM platform is and the “art of the possible” for sales, marketing, and customer service. Call #2: Build the business case to select a CRM.

      Call #3: Define your key CRM requirements.

      Call #4: Build procurement items such as an RFP.
      Call #5: Evaluate the CRM solution landscape and shortlist viable options.

      Call #6: Review implementation considerations.

      Info-Tech offers various levels of support to best suit your needs

      DIY Toolkit

      Guided Implementation

      Workshop

      Consulting

      "Our team has already made this critical project a priority, and we have the time and capability, but some guidance along the way would be helpful." "Our team knows that we need to fix a process, but we need assistance to determine where to focus. Some check-ins along the way would help keep us on track." "We need to hit the ground running and get this project kicked off immediately. Our team has the ability to take this over once we get a framework and strategy in place." "Our team does not have the time or the knowledge to take this project on. We need assistance through the entirety of this project."

      Diagnostics and consistent frameworks used throughout all four options

      INFO~TECH RESEARCH GROUP

      Customer Relationship Management Platform Selection Guide

      Speed up the process to build your business case and select your CRM solution.

      EXECUTIVE BRIEF

      Info-Tech Research Group Inc. is a global leader in providing IT research and advice. Info-Tech’s products and services combine actionable insight and relevant advice with ready-to-use tools and templates that cover the full spectrum of IT concerns.
      © 1997-2022 Info-Tech Research Group Inc.

      What exactly is a CRM platform?

      Our Definition: A customer relationship management (CRM) platform (or suite) is a core enterprise application that provides a broad feature set for supporting customer interaction processes, typically across marketing, sales and customer service. These suites supplant more basic applications for customer interaction management (such as the contact management module of an enterprise resource planning (ERP) platform or office productivity suite).

      A customer relationship management suite provides many key capabilities, including but not limited to:

      • Account management
      • Order history tracking
      • Pipeline management
      • Case management
      • Campaign management
      • Reports and analytics
      • Customer journey execution

      A CRM suite provides a host of native capabilities, but many organizations elect to tightly integrate their CRM solution with other parts of their customer experience ecosystem to provide a 360-degree view of their customers.

      Stock image of a finger touching a screen showing a stock chart.

      Info-Tech Insight

      CRM feature sets are rapidly evolving. Focus on the social component of sales, marketing, and service management features, as well as collaboration, to get the best fit for your requirements. Moreover, consider investing in best-of-breed social media management platforms (SMMPs) and internal collaboration tools to ensure sufficient functionality.

      Build a cohesive CRM selection approach that aligns business goals with CRM capabilities.

      Info-Tech Insight

      Customers expect to interact with organizations through the channels of their choice. Now more than ever, you must enable your organization to provide tailored customer experiences.

      Customer expectations are on the rise: meet them!

      A CRM platform is a crucial system for enabling good customer experiences.

      CUSTOMER EXPERIENCE IS EVOLVING

      1. Thoughtfulness is in
          Connect with customers on a personal level
      2. Service over products
          The experience is more important than the product
      3. Culture is now number one
          Culture is the most overlooked piece of customer experience strategy
      4. Engineering and service finally join forces
          Companies are combining their technology and service efforts to create strong feedback loops
      5. The B2B world is inefficiently served
          B2B needs to step up with more tools and a greater emphasis placed on customer experience

      (Source: Forbes, 2019)

      Identifying organizational objectives of high priority will assist in breaking down business needs and CRM objectives. This exercise will better align the CRM systems with the overall corporate strategy and achieve buy-in from key stakeholders.

      A strong CRM platform supports a range of organizational objectives for customer engagement.

      Increase Revenue Enable lead scoring Deploy sales collateral management tools Improve average cost per lead via a marketing automation tool
      Enhance Market Share Enhance targeting effectiveness with a CRM Increase social media presence via an SMMP Architect customer intelligence analysis
      Improve Customer Satisfaction Reduce time-to-resolution via better routing Increase accessibility to customer service with live chat Improve first contact resolution with customer KB
      Increase Customer Retention Use a loyalty management application Improve channel options for existing customers Use customer analytics to drive targeted offers
      Create Customer-Centric Culture Ensure strong training and user adoption programs Use CRM to provide 360-degree view of all customer interactions Incorporate the voice of the customer into product development

      Succeeding with CRM selection and implementation has a positive effect on driving revenues and decreasing costs

      There are three buckets of metrics and KPIs where CRM will drive improvements

      The metrics of a smooth CRM selection and implementation process include:

      • Better alignment of CRM functionality to business needs.
      • Better functionality coverage of the selected platform.
      • Decreased licensing costs via better vendor negotiation.
      • Improved end-user satisfaction with the deployed solution.
      • Fewer errors and rework during implementation.
      • Reduced total implementation costs.
      • Reduced total implementation time.

      A successful CRM deployment drives revenue

      • Increased customer acquisition due to enhanced accuracy of segmentation and targeting, superior lead qualification, and pipeline management.
      • Increased customer satisfaction and retention due to targeted campaigns (e.g. customer-specific deals), quicker service incident resolution, and longitudinal relationship management.
      • Increased revenue per customer due to comprehensive lifecycle management tools, social engagement, and targeted upselling of related products and services (enabled by better reporting/analytics).

      A successful CRM deployment decreases cost

      • Deduplication of effort across business domains as marketing, sales, and service now have a common repository of customer information and interaction tools.
      • Increased sales and service agent efficiency due to their focus on selling and resolution, rather than administrative tasks and overhead.
      • Reduced cost-to-sell and cost-to-serve due to automation of activities that were manually intensive.
      • Reduced cost of accurate data due to embedded reporting and analytics functionality.

      CRM platforms sit at the core of a well-rounded customer engagement ecosystem

      At the center is 'Customer Relationship Management Platform' surrounded by 'Web Experience Management Platform', 'E-Commerce & Point-of-Sale Solutions', 'Social Media Management Platform', 'Customer Intelligence Platform', 'Customer Service Management Tools', and 'Marketing Management Suite'.

      Customer Experience Management (CXM) Portfolio

      Customer relationship management platforms are increasingly expansive in functional scope and foundational to an organization’s customer engagement strategy. Indeed, CRMs form the centerpiece for a comprehensive CXM system, alongside tools such as customer intelligence platforms and adjacent point solutions for sales, marketing, and customer service.

      Review Info-Tech’s CXM blueprint below to build a complete, end-to-end customer interaction solution portfolio that encompasses CRM alongside other critical components. The CXM blueprint also allows you to develop strategic requirements for CRM based on customer personas and external market analysis.

      Build a Strong Technology Foundation for Customer Experience Management

      Sample of the 'Build a Strong Technology Foundation for Customer Experience Management' blueprint. Design an end-to-end technology strategy to drive sales revenue, enhance marketing effectiveness, and create compelling experiences for your customers.

      View the blueprint

      Considering a CRM switch? Switching software vendors drives high satisfaction

      Eighty percent of organizations are more satisfied after changing their software vendor.

      • Most organizations see not only a positive change in satisfaction with their new vendor, but also a substantial change in satisfaction.
      • What matters is making sure your organization is well-positioned to make a switch.
      • When it comes to switching software vendors, the grass really can be greener on the other side.

      Over half of organizations are 60%+ more satisfied after changing their vendor.

      (Source: Info-Tech Research Group, "Switching Software Vendors Overwhelmingly Drives Increased Satisfaction", 2020.)

      IT is critical to the success of your CRM selection and rollout

      Today’s shared digital landscape of the CIO and CMO

      Info-Tech Insight

      Technology is the key enabler of building strong customer experiences: IT must stand shoulder to shoulder with the business to develop a technology framework for customer relationship management.

      CIO

      IT Operations

      Service Delivery and Management

      IT Support

      IT Systems and Application

      IT Strategy and Governance

      Cybersecurity
      Collaboration and Partnership

      Digital Strategy = Transformation
      Business Goals | Innovation | Leadership | Rationalization

      Customer Experience
      Architecture | Design | Omnichannel Delivery | Management

      Insight (Market Facing)
      Analytics | Business Intelligence | Machine Learning | AI

      Marketing Integration + Operating Model
      Apps | Channels | Experiences | Data | Command Center

      Master Data
      Customer | Audience | Industry | Digital Marketing Assets
      CMO

      PEO Media

      Brand Management

      Campaign Management

      Marketing Tech

      Marketing Ops

      Privacy, Trust, and Regulatory Requirements

      (Source: ZDNet, 2020)

      CRM by the numbers

      1/3

      Statistical analysis of CRM projects indicates failures vary from 18% to 69%. Taking an average of those analyst reports, about one-third of CRM projects are considered a failure. (Source: CIO Magazine, 2017)

      92%

      92% of organizations report that CRM use is important for accomplishing revenue objectives. (Source: Hall, 2020)

      40%

      In 2019, 40% of executives name customer experience the top priority for their digital transformation. (Source: CRM Magazine, 2019)

      Case Study

      Align strategy and technology to meet consumer demand.
      INDUSTRY
      Entertainment
      SOURCE
      Forbes, 2017
      Challenge

      Beginning as a mail-out service, Netflix offered subscribers a catalog of videos to select from and have mailed to them directly. Customers no longer had to go to a retail store to rent a video. However, the lack of immediacy of direct mail as the distribution channel resulted in slow adoption.

      Blockbuster was the industry leader in video retail but was lagging in its response to industry, consumer, and technology trends around customer experience.

      Solution

      In response to the increasing presence of tech-savvy consumers on the internet, Netflix invested in developing its online platform as its primary distribution channel. The benefit of doing so was two-fold: passive brand advertising (by being present on the internet) and meeting customer demands for immediacy and convenience. Netflix also recognized the rising demand for personalized service and created an unprecedented, tailored customer experience.

      Results

      Netflix’s disruptive innovation is built on the foundation of great customer experience management. Netflix is now a $28-billion company, which is tenfold what Blockbuster was worth.

      Netflix used disruptive technologies to innovatively build a customer experience that put it ahead of the long-time video rental industry leader, Blockbuster.

      CRM Buyer’s Guide

      Phase 1

      Understand CRM Features

      Phase 1

      1.1 Define CRM platforms

      1.2 Classify table stakes & differentiating capabilities

      1.3 Explore CRM trends

      Phase 2

      2.1 Build the business case

      2.2 Streamline requirements elicitation for CRM

      2.3 Construct the RFP

      Phase 3

      3.1 Discover key players in the CRM landscape

      3.2 Engage the shortlist & select finalist

      3.3 Prepare for implementation

      This phase will walk you through the following activities:

      • Set a level of understanding of CRM technology.
      • Define which CRM features are table stakes (standard) and which are differentiating.
      • Identify the “Art of the Possible” in a modern CRM from a sales, marketing, and service lens.

      This phase involves the following participants:

      • CIO
      • Applications manager
      • Project manager
      • Sales executive
      • Marketing executive
      • Customer service executive

      Understand CRM table stakes features

      Organizations can expect nearly all CRM vendors to provide the following functionality.

      Lead Management Pipeline Management Contact Management Campaign Management Customer Service Management
      • Tracks and captures a lead’s information, automatically building a profile. Leads are then qualified through contact scoring models. Assigning leads to sales is typically automated.
      • Enables oversight over future sales. Includes revenue forecasting based on past/present trends, tracking sales velocity, and identifying ineffective sales processes.
      • Tracks and stores customer data, including demography, account and billing history, social media, and contact information. Typically, records and fields can be customized.
      • Provides integrated omnichannel campaign functionality and data analysis of customer intelligence. Data insights can be used to drive new and effective marketing campaigns.
      • Provides integrated omnichannel customer experiences to provide convenient service. Includes case and ticket management, automated escalation rules, and third-party integrations.

      Identify differentiating CRM features

      While not always “must-have” functionality, these features may be the final dealbreaker when deciding between two CRM vendors.

      Image of clustered screens with various network and business icons surounding them.
      • Workflow Automation
        Automate repetitive tasks by creating workflows that trigger actions or send follow-up reminders for next steps.
      • Advanced Analytics and Reporting
        Provides customized dashboard visualizations, detailed reporting, AI-driven virtual assistants, data extraction & analysis, and ML forecasting.
      • Customizations and Open APIs
        Broad range of available customizations (e.g. for dashboards and fields), alongside ease of integration (e.g. via plugins or APIs).
      • Document Management
        Out-of-the-box centralized content repository for storing, uploading, and sharing documents.
      • Mobile Support
        Ability to support mobile devices, OSes, and platforms with a native application or HTML-based web-access.
      • Project and Task Management
        Native project and task management functionality, enhancing cross-team organization and communication.
      • Configure, Price, Quote (CPQ)
        Create and send quotes or proposals to prospective and current customers.

      Features aren’t everything – be wary of common CRM selection pitfalls

      You can have all the right features, but systemic problems will lead to poor CRM implementation. Dig out these root causes first to ensure a successful CRM selection.

      50% of organizations believe the quality of their CRM data is “very poor” or “neutral.”

      Without addressing data governance issues, CRMs will only be as good as your data.

      Source: (Validity 2020)
      27% of organizations report that bad data costs them 10% or more in lost revenue annually.
      42% rate the trust that users have in their data as “high” or “very high.”
      54% believe that sales forecasts are accurate or very accurate.
      69% attribute poor CRM governance to missing or incomplete data, followed by duplicate data, incorrect data, and expired data. Other data issues include siloed data or disparate systems.
      73% believe that they do not have a 360-degree view of their customers.

      Ensure you understand the “art of the possible” in the CRM landscape

      Knowing what is possible will help funnel which features are most suitable for your organization – having all the bells and whistles does not always equal strong ROI.

      Holistically examine the potential of any CRM solution through three main lenses: Stock image of a person working with dashboards.

      Sales

      Identify sales opportunities through recording customers’ interactions, generating leads, nurturing contacts, and forecasting revenues.
      Stock image of people experiencing digital ideas.

      Marketing

      Analyze customer interactions to identify upsell and cross-sell opportunities, drive customer loyalty, and use customer data for targeted campaigns.
      Stock image of a customer service representative.

      Customer Service

      Improve and optimize customer engagement and retention, leveraging customer data to provide round-the-clock omnichannel experiences.

      Art of the possible: Sales

      Stock image of a person working with dashboards.

      TRACK PROSPECT INTERACTIONS

      Want to engage with a prospect but don’t know what to lead with? CRM solutions can track and analyze many of the interactions a prospect has with your organization, including with fellow staff, their clickthrough rate on marketing material, and what services they are downloading on your website. This information can then auto-generate tasks to begin lead generation.

      COORDINATE LEAD SCORING

      Information captured from a prospect is generated into contact cards; missing data (such as name and company) can be auto-captured by the CRM via crawling sites such as LinkedIn. The CRM then centralizes and scores (according to inputted business rules) a lead’s potential, ensuring sales teams coordinate and keep a track of the lead’s journey without wrongful interference.

      AI-DRIVEN REVENUE FORECASTING

      Generate accurate forecasting reports using AI-driven “virtual assistants” within the CRM platform. These assistants are personal data scientists, quickly noting discrepancies, opportunities, and what-if scenarios – tasks that might take weeks to do manually. This pulled data is then auto-forecasted, with the ability to flexibly adjust to real-time data.

      Art of the possible: Marketing

      Stock image of people experiencing digital ideas.

      DRIVE LOYALTY

      Data captured and analyzed in the CRM from customer interactions builds profiles and a deeper understanding of customers’ interests. With this data, marketing teams can deliver personalized promotions and customer service to enhance loyalty – from sending a discount on a product the customer was browsing on the website, to providing notifications about delivery statuses.

      AUTOMATE WORKFLOWS

      Building customer profiles, learning spending habits, and charting a customer’s journey for upselling or cross-selling can be automated through workflows, saving hours of manual work. These workflows can immediately respond to customer enquiries or deliver offers to the customer’s preferred channel based on their prior usage.

      TARGETED CAMPAIGNING

      Information attained through a CRM platform directly informs any marketing strategy: identifying customer segments, spending habits, building a better product based on customer feedback, and identifying high-spending customers. With any new product or offering, it is straightforward for marketing teams to understand where to target their next campaign for highest impact.

      Art of the possible: Customer service

      Stock image of a customer service representative.

      OMNICHANNEL SUPPORT

      Rapidly changing demographics and modes of communications require an evolution toward omnichannel engagement. Many customers now expect to communicate with contact centers not just by voice, but via social media. Agents need customer information synced across each channel they use, meeting the customer’s needs where they are.

      INTELLIGENT SELF-SERVICE PORTALS

      Customers want their issues resolved as quickly as possible. Machine-learning self-service options deliver personalized customer experiences, which also reduce both agent call volume and support costs for the organization.

      LEVERAGING ANALYTICS

      The future of customer service is tied up with analytics. This not only entails AI-driven capabilities that fetch the agent relevant information, skills-based routing, and using biometric data (e.g. speech) for security. It also feeds operations leaders’ need for easy access to real insights about how their customers and agents are doing.

      Best-of-Breed Point Solutions

      Full CRM Suite

      Blue smiley face. Benefits
      • Features may be more advanced for specific functional areas and a higher degree of customization may be possible.
      • If a potential delay in real-time customer data transfer is acceptable, best-of-breeds provide a similar level of functionality to suites for a lower price.
      • Best-of-breeds allow value to be realized faster than suites, as they are easier and faster to implement and configure.
      • Rip and replace is easier, and vendor updates are relatively quick to market.
      Benefits
      • Everyone in the organization works from the same set of customer data.
      • There is a “lowest common denominator” for agent learning as consistent user interfaces lower learning curves and increase efficiency in usage.
      • There is a broader range of functionality using modules.
      • Integration between functional areas will be strong and the organization will be in a better position to enable version upgrades without risking invalidation of an integration point between separate systems.
      Green smiley face.
      Purple frowny face. Challenges
      • Best-of-breeds typically cover less breadth of functionality than suites.
      • There is a lack of uniformity in user experience across best-of-breeds.
      • Data integrity risks are higher.
      • Variable infrastructure may be implemented due to multiple disparate systems, which adds to architecture complexity and increased maintenance.
      • There is potential for redundant functionality across multiple best-of-breeds.
      Challenges
      • Suites exhibit significantly higher costs compared to point solutions.
      • Suite module functionality may not have the same depth as point solutions.
      • Due to high configuration availability and larger-scale implementation requirements, the time to deploy is longer than point solutions.
      Orange frowny face.
      Info-Tech Insight

      Even if a suite is missing a potential module, the proliferation of app extensions, integrations, and services could provide a solution. Salesforce’s AppExchange, for instance, offers a plethora of options to extend its CRM solution – from telephony integration, to gamification.

      CRM Buyer’s Guide

      Phase 2

      Build the Business Case & Elicit CRM Requirements

      Phase 1

      1.1 Define CRM platforms

      1.2 Classify table stakes & differentiating capabilities

      1.3 Explore CRM trends

      Phase 2

      2.1 Build the business case

      2.2 Streamline requirements elicitation for CRM

      2.3 Construct the RFP

      Phase 3

      3.1 Discover key players in the CRM landscape

      3.2 Engage the shortlist & select finalist

      3.3 Prepare for implementation

      This phase will walk you through the following activities:

      • Identify goals, objectives, challenges, and costs to inform the business case for a new CRM platform.
      • Elicit and prioritize key requirements for your platform.
      • Port the requirements into Info-Tech’s CRM RFP Template.

      This phase involves the following participants:

      • CIO
      • Applications manager
      • Project manager
      • Sales executive
      • Marketing executive
      • Customer service executive

      Right-size the CRM selection team to ensure you get the right information but are still able to move ahead quickly

      Full-Time Resourcing: At least one of these five team members must be allocated to the selection initiative as a full-time resource.

      A silhouetted figure.

      IT Leader

      A silhouetted figure.

      Technical Lead

      A silhouetted figure.

      Business Analyst/
      Project Manager

      A silhouetted figure.

      Business Lead

      A silhouetted figure.

      Process Expert(s)

      This team member is an IT director or CIO who will provide sponsorship and oversight from the IT perspective. This team member will focus on application security, integration, and enterprise architecture. This team member elicits business needs and translates them into technology requirements. This team member will provide sponsorship from the business needs perspective. Typically, a CMO or SVP of sales. These team members are the sales, marketing, and service process owners who will help steer the CRM requirements and direction.

      Info-Tech Insight

      It is critical for the selection team to determine who has decision rights. Organizational culture will play the largest role in dictating which team member holds the final say for selection decisions. For more information on stakeholder management and involvement, see this guide.

      Be prepared to define what issues you are trying to address and why a new CRM is the right approach

      Identify the current state and review the background of what you’ve done leading up to this point, goals you’ve been asked to meet, and challenges in solving known problems to help to set the stage for why your proposed solution is needed. If your process improvements have taken you as far as you can go without improved workflows or data, specify where the gaps are.
      Arrows with icons related to the text on the right merging into one arrow. Alignment

      Alignment to strategic goals is always important, but that is especially true with CRM because customer relationship management platforms are at the intersection of your organization and your customers. What are the strategic marketing, sales and customer service goals that you want to realize (in whole or in part) by improving your CRM ecosystem?

      Impact to your business

      Identify areas where your customers may be impacted by poor experiences due to inadequate or aging technology. What’s the impact on customer retention? On revenue?

      Impact to your organization

      Define how internal stakeholders within the organization are impacted by a sub-optimal CRM experience – what are their frustrations and pain points? How do issues with your current CRM environment prevent teams in sales, marketing, or service from doing their jobs?

      Impact to your department

      Describe the challenges within IT of using disparate systems, workarounds, poor data and reporting, lack of automation, etc., and the effect these challenges have on IT’s goals.

      Align the CRM strategy with the corporate strategy

      Corporate Strategy Unified Strategy CRM Strategy
      Spectrum spanning all columns.
      Your corporate strategy:
      • Conveys the current state of the organization and the path it wants to take.
      • Identifies future goals and business aspirations.
      • Communicates the initiatives that are critical for getting the organization from its current state to the future state.
      • The CRM strategy and the rationale for deploying a new CRM can be and should be linked, with metrics, to the corporate strategy and ultimate business objectives (such as improving customer acquisition, entering new segments, or improving customer lifetime value).
      Your CRM strategy:
      • Communicates the organization’s budget and spending on CRM.
      • Identifies IT initiatives that will support the business and key CRM objectives.
      • Outlines staffing and resourcing for CRM initiatives.
      CRM projects are more successful when the management team understands the strategic importance and the criticality of alignment. Time needs to be spent upfront aligning business strategies with CRM capabilities. Effective alignment between sales, marketing, customer service, operations, IT, and the business should happen daily. Alignment doesn’t just need to occur at the executive level, but also at each level of the organization.

      2.1 Create your list of goals and milestones for CRM

      1-3 hours

      Input: Corporate strategy, Target key performance indicators, End-user satisfaction results (if applicable)

      Output: Prioritized list of goals with milestones that can be met with a new or improved CRM solution

      Materials: Whiteboard/flip charts, CRM Business Case Template

      Participants: CIO, Application managers, CMO/SVP sales, Marketing, sales or service SMEs

      1. Review strategic goals to identify alignment to your CRM selection project. For example, digital transformation may be enhanced or enabled with a CRM solution that supports better outreach to key customer segments through improved campaign management.
      2. Next, brainstorm tactical goals with your colleagues.
      3. Identify specific goals the organization has set for the business that may be supported by improved customer prospecting, customer service, or analytics functionality through a better CRM solution.
      4. Identify specific goals your organization will be able to make possible with a new or improved CRM solution.
      5. Prioritize this list and lead with the most important goal that can be reached at the one-year, six-month, and three-month milestones.
      6. Document in the goals section of your business case.

      Download the CRM Business Case Template and record the outputs of this exercise in the strategic business goals, business drivers, and technical drivers slides.

      Identify what challenges exist with the current environment

      Ensure you are identifying issues at a high level, so as not to drown in detail, but still paint the right picture. Identify technical issues that are impacting customer experience or business goals. Typical complaints for CRM solutions that are old or have been outgrown include:

      1.

      Lack of a flexible, configurable customer data model that supports complex relationships between accounts and contacts.

      2.

      Lack of a flexible, configurable customer data model that supports complex relationships between accounts and contacts.

      3.

      Lack of meaningful reports and useable dashboards, or difficulty in surfacing them.

      4.

      Poor change enablement resulting in business interruptions.

      5.

      Inability to effectively automate routine sales, marketing, or service tasks at scale via a workflow tool.

      6.

      Lack of proper service management features, such as service knowledge management.

      7.

      Inability to ingest customer data at scale (for example, no ability to automatically log e-mails or calls).

      8.

      Major technical deficiencies and outages – the incumbent CRM platform goes down, causing business disruption.

      9.

      The platform itself doesn’t exist in the current state – everything is done in Microsoft Excel!

      Separate business issues from technical issues, but highlight where they’re connected and where technical issues are causing business issues or preventing business goals from being reached.

      Before switching vendors, evaluate your existing CRM to see if it’s being underutilized or could use an upgrade

      The cost of switching vendors can be challenging, but it will depend entirely on the quality of data and whether it makes sense to keep it.
      • Achieving success when switching vendors first requires reflection. We need to ask why we are dissatisfied with our incumbent software.
      • If the product is old and inflexible, the answer may be obvious, but don’t be afraid to include your incumbent in your evaluation if your issues might be solved with an upgrade.
      • Look at your use-case requirements to see where you want to take the CRM solution and compare them to your incumbent’s roadmap. If they don’t match, switching vendors may be the only solution. If your roadmaps align, see if you’re fully leveraging the solution or will be able to start working through process improvements.
      Pie graph with a 20% slice. Pie graph with a 25% slice.

      20%

      Small/Medium Enterprises

      25%

      Large Enterprises
      only occasionally or rarely/never use their software (Source: Software Reviews, 2020; N = 45,027)
      Fully leveraging your current software now will have two benefits:
      1. It may turn out that poor leveraging of your incumbent software was the problem all along; switching vendors won’t solve the problem by itself. As the data to the right shows, a fifth of small/medium enterprises and a quarter of large enterprises do not fully leverage their incumbent software.
      2. If you still decide to switch, you’ll be in a good negotiating position. If vendors can see you are engaged and fully leveraging your software, they will be less complacent during negotiations to win you over.
      Info-Tech Insight

      Switching vendors won’t improve poor internal processes. To be fully successful and meet the goals of the business case, new software implementations must be accompanied by process review and improvement.

      2.2 Create your list of challenges as they relate to your goals and their impacts

      1-2 hours

      Input: Goals lists, Target key performance indicators, End-user satisfaction results (if applicable)

      Output: Prioritized list of challenges preventing or hindering customer experiences

      Materials: Whiteboard/flip charts, CRM Business Case Template

      Participants: CIO, Application managers, CMO/SVP sales, Marketing, sales, or service SMEs

      1. Brainstorm with your colleagues to discuss your challenges with CRM today from an application and process lens.
      2. Identify how these challenges are impacting your ability to meet the goals and identify any that are creating customer-facing issues.
      3. Group together like areas and arrange in order of most impactful. Identify which of these issues will be most relevant to the business case for a new CRM platform.
      4. Document in the current-state section of your business case.
      5. Discuss and determine if the incumbent solution can meet your needs or if you’ll need to replace it with a different product.

      Download the CRM Business Case Template and document the outputs of this exercise in the current-state section of your business case.

      Determine costs of the solution

      Ensure the business case includes both internal and external costs related to the new CRM platform, allocating costs of project managers to improve accuracy of overall costs and level of success.

      CRM solutions include application costs and costs to design processes, install, and configure. These start-up costs can be a significant factor in whether the initial purchase is feasible.

      CRM Vendor Costs

      • Application licensing
      • Implementation and configuration
      • Professional services
      • Maintenance and support
      • Training
      • 3rd Party add-ons
      • Data transformation
      • Integration
      When thinking about vendor costs, also consider the matching internal cost associated with the vendor activity (e.g. data cleansing, internal support).

      Internal Costs

      • Project management
      • Business readiness
      • Change management
      • Resourcing (user groups, design/consulting, testing)
      • Training
      • Auditors (if regulatory requirements need vetting)
      Project management is a critical success factor at all stages of an enterprise application initiative from planning to post-implementation. Ensuring that costs for such critical areas are accurately represented will contribute to success.

      Download the blueprint Improve Your Statements of Work to Hold Your Vendors Accountable to define requirements for installation and configuration.

      Bring in the right resources to guarantee success. Work with the PMO or project manager to get help with creating the SOW.

      60% of IT projects are NOT finished “mostly or always” on time (Wellingtone, 2018).

      55% of IT personnel feel that the business objectives of their software projects are clear to them (Geneca, 2017).

      Document costs and expected benefits of the new CRM

      The business case should account for the timing of both expenditures and benefits. It is naïve to expect straight-line benefit realization or a big-bang cash outflow related to the solution implementation. Proper recognition and articulation of ramp-up time will make your business case more convincing.

      Make sure your timelines are realistic for benefits realization, as these will be your project milestones and your metrics for success.

      Example:
      Q1-Q2 Q3-Q6 Q6 Onwards

      Benefits at 25%

      At the early stages of an implementation, users are still learning the new system and go-live issues are being addressed. Most of the projected process improvements are likely to be low, zero, or even negative.

      Benefits at 75%

      Gradually, as processes become more familiar, an organization can expect to move closer to realizing the forecasted benefits or at least be in a position to recognize a positive trend toward their realization.

      Benefits at 100%

      In an ideal world, all projected benefits are realized at 100% or higher. This can be considered the stage where processes have been mastered, the system is operating smoothly, and change has been broadly adopted. In reality, benefits are often overestimated.

      Costs at 50%

      As with benefits, some costs may not kick in until later in the process or when the application is fully operational. In the early phases of implementation, factor in the cost of overlapping technology where you’ll need to run redundant systems and transition any data.

      Costs at 100%

      Costs are realized quicker than benefits as implementation activities are actioned, licensing and maintenance costs are introduced, and resourcing is deployed to support vendor activities internally. Costs that were not live in the early stages are an operational reality at this stage.

      Costs at 100%+

      Costs can be expected to remain relatively static past a certain point, if estimates accurately represented all costs. In many instances, costs can exceed original estimates in the business case, where costs were either underestimated, understated, or missed.

      2.3 Document your costs and expected benefits

      1-2 hours

      Input: Quotes with payment schedule, Budget

      Output: Estimated payment schedule and cost breakdown

      Materials: Spreadsheet or whiteboard, CRM Business Case Template

      Participants: CIO, Application managers, CMO/SVP sales, Marketing, sales, or service SMEs

      1. Estimate costs for the CRM solution. If you’re working with a vendor, provide the initial requirements to quote; otherwise, estimate as closely as you’re able.
      2. Calculate the five-year total cost for the solution to ensure the long-term budget is calculated.
      3. Break down costs for licenses, implementation, training, internal support, and hardware or hosting fees.
      4. Determine a reasonable breakdown of costs for the first year.
      5. Identify where residual costs of the old system may factor in if there are remaining contract obligations during the technology transition.
      6. Create a list of benefits expected to be realized within the same timeline.

      Sample of the table on the previous slide.

      Download the CRM Business Case Template and document the outputs of this exercise in the current-state section of your business case.

      Identify risks and dependencies to mitigate barriers to success as you look to roll out a CRM suite

      A risk assessment will be helpful to better understand what risks need to be mitigated to make the project a success and what risks are pending should the solution not be approved or be delayed.

      Risk Criteria Relevant Questions
      Timeline Uncertainty
      • How much risk is associated with the timeline of the CRM project?
      • Is this timeline realistic and can you reach some value in the first year?
      Success of Similar Projects
      • Have we undertaken previous projects that are similar?
      • Were those successful?
      • Did we note any future steps for improvement?
      Certainty of Forecasts
      • Where have the numbers originated?
      • How comfortable are the sponsors with the revenue and cost forecasts?
      Chance of Cost Overruns
      • How likely is the project to have cost overruns?
      • How much process and design work needs to be done prior to implementation?
      Resource Availability
      • Is this a priority project?
      • How likely are resourcing issues from a technical and business perspective?
      • Do we have the right resources?
      Change During Delivery
      • How volatile is the area in which the project is being implemented?
      • Are changes in the environment likely?
      • How complex are planned integrations?

      2.4 Identify risks to the success of the solution rollout and mitigation plan

      1-2 hours

      Input: List of goals and challenges, Target key performance indicators

      Output: Prioritized list of challenges preventing or hindering improvements for the IT teams

      Materials: Whiteboard/flip charts, CRM Business Case Template

      Participants: CIO, Application managers, CMO/SVP sales, Marketing, sales, or service SMEs

      1. Brainstorm with your colleagues to discuss potential roadblocks and risks that could impact the success of the CRM project.
      2. Identify how these risks could impact your project.
      3. Document the ones that are most likely to occur and derail the project.
      4. Discuss potential solutions to mitigate risks.

      Download the CRM Business Case Template and document the outputs of this exercise in the risk and dependency section of your business case. If the risk assessment needs to be more complex, complete the Risk Indicator Analysis in Info-Tech’s Business Case Workbook.

      Start requirements gathering by identifying your most important use cases across sales, marketing, and service

      Add to your business case by identifying which top-level use cases will meet your goals.

      Examples of target use cases for a CRM project include:

      • Enhance sales acquisition capabilities (i.e. via pipeline management)
      • Enhance customer upsell and cross-sell capabilities
      • Improve customer segmentation and targeting capabilities for multi-channel marketing campaigns
      • Strengthen customer care capabilities to improve customer satisfaction and retention (i.e. via improved case management and service knowledge management)
      • Create actionable insights via enhanced reporting and analytics

      Info-Tech Insight

      Lead with the most important benefit and consider the timeline. Can you reach that goal and report success to your stakeholders within the first year? As you look toward that one-year goal, you can consider secondary benefits, some of which may be opportunities to bring early value in the solution.

      Benefits of a successful deployment of use cases will include:
      • Improved customer satisfaction
      • Improved operational efficiencies
      • Reduced customer turnover
      • Increased platform uptime
      • License or regulatory compliance
      • Positioned for growth

      Typically, we see business benefits in this order of importance. Lead with the outcome that is most important to your stakeholders.

      • Net income increases
      • Revenue generators
      • Cost reductions
      • Improved customer service

      Consider perspectives of each stakeholder to ensure functionality needs are met and high satisfaction results

      Best of breed vs. “good enough” is an important discussion and will feed your success.

      Costs can be high when customizing an ill-fitting module or creating workarounds to solve business problems, including loss of functionality, productivity, and credibility.

      • Start with use cases to drive the initial discussion, then determine which features are mandatory and which are nice-to-haves. Mandatory features will help determine high success for critical functionality and identify where “good enough” is an acceptable state.
      • Consider the implications to implementation and all use cases of buying an all-in-one solution, integration of multiple best-of-breed solutions, or customizing features that were not built into a solution.
      • Be prepared to shelve a use case for this solution and look to alternatives for integration where mandatory features cannot meet highly specialized needs that are outside of traditional CRM solutions.

      Pros and Cons

      Build vs. Buy

      Multi-Source Best of Breed

      Flexibility
      vs.
      architectural complexity

      Vendor Add-Ons & Integrations

      Lower support costs
      vs.
      configuration

      Multi-source Custom

      Flexibility
      vs.
      high skills requirements

      Single Source

      Lower support costs
      vs.
      configuration

      2.5 Define use cases and high-level features for meeting business and technical goals

      1-2 hours

      Input: List of goals and challenges

      Output: Use cases to be used for determining requirements

      Materials: Whiteboard/flip charts, CRM Business Case Template

      Participants: CIO, Application managers, CMO/SVP sales, Marketing, sales, or service SMEs

      1. Identify the key customer engagement use cases that will support your overall goals as defined in the previous section.
      2. The following slide has examples of use case domains that will be enhanced from a CRM platform.
      3. Define high-level goals you wish to achieve in the first year and longer term. If you have more specific KPIs to add, and it is a requirement for your organization’s documentation, add them to this section.
      4. Take note of where processes will need to be improved to benefit from these use-case solutions – the tools are only as good as the process behind them.

      Download the CRM Business Case Template and document the outputs from this exercise in the current-state section of your business case.

      Understand the dominant use-case scenarios across organizations to narrow the list of potential CRM solutions

      Sales
      Enablement

      • Generate leads through multiple channels.
      • Rapidly sort, score, and prioritize leads based on multiple criteria.
      • Create in-depth sales forecasts segmented by multiple criteria (territory, representative, etc.).

      Marketing
      Management

      • Manage marketing campaigns across multiple channels (web, social, email, etc.).
      • Aggregate and analyze customer data to generate market intelligence.
      • Build and deploy customer-facing portals.

      Customer Service
      Management

      • Generate tickets, and triage customer service requests through multiple channels.
      • Track customer service interactions with cases.
      • There is a need to integrate customer records with contact center infrastructure.
      Info-Tech Insight

      Use your understanding of the CRM use case to accelerate the vendor shortlisting process. Since the CRM use case has a direct impact on the prioritization of a platform’s features and capabilities, you can rapidly eliminate vendors from contention or designate superfluous modules as out-of-scope.

      2.5.1 Use Info-Tech’s CRM Use-Case Fit Assessment Tool to align your CRM requirements to the vendor use cases

      30 min

      Input: Understanding of business objectives for CRM project, Use-Case Fit Assessment Tool

      Output: Use-case suitability

      Materials: Use-Case Fit Assessment Tool

      Participants: Core project team, Project managers

      1. Use the Use-Case Fit Assessment Tool to understand how your unique business requirements map into which CRM use case.
      2. This tool will assess your answers and determine your relative fit against the use-case scenarios.
      3. Fit will be assessed as “Weak,” “Moderate,” or “Strong.”
        1. Consider the common pitfalls, which were mentioned earlier, that can cause IT projects to fail. Plan and take clear steps to avoid or mitigate these concerns.
        2. Note: These use-case scenarios are not mutually exclusive, meaning your organization can align with one or more scenarios based on your answers. If your organization shows close alignment to multiple scenarios, consider focusing on finding a more robust solution and concentrate your review on vendors that performed strongly in those scenarios or meet the critical requirements for each.

      Download the CRM Use-Case Fit Assessment Tool

      Once you’ve identified the top-level use cases a CRM must support, elicit, and prioritize granular platform requirements.

      Understanding business needs through requirements gathering is the key to defining everything about what is being purchased, yet it is an area where people often make critical mistakes.

      Info-Tech Insight

      To avoid creating makeshift solutions, an organization needs to gather requirements with the desired future state in mind.

      Risks of poorly scoped requirements

      • Fail to be comprehensive and miss certain areas of scope
      • Focus on how the solution should work instead of what it must accomplish
      • Have multiple levels of detail within the requirements, which are inconsistent and confusing
      • Drill all the way down into system-level detail
      • Add unnecessary constraints based on what is done today rather than focusing on what is needed for tomorrow
      • Omit constraints or preferences that buyers think are “obvious”

      Best practices

      • Get a clear understanding of what the system needs to do and what it is expected to produce
      • Test against the principle of MECE – requirements should be “mutually exclusive and collectively exhaustive”
      • Explicitly state the obvious and assume nothing
      • Investigate what is sold on the market and how it is sold. Use language that is consistent with that of the market and focus on key differentiators – not table stakes
      • Contain the appropriate level of detail – the level should be suitable for procurement and sufficient for differentiating vendors

      Prioritize requirements to assist with vendor selection: focus on priority requirements linked to differentiated capabilities

      Prioritization is the process of ranking each requirement based on its importance to project success. Hold a meeting for the domain SMEs, implementation SMEs, project managers, and project sponsors to prioritize the requirements list. At the conclusion of the meeting, each requirement should be assigned a priority level. The implementation SMEs will use these priority levels to ensure efforts are targeted toward the proper requirements and to plan features available on each release. Use the MoSCoW Model of Prioritization to effectively order requirements.


      Pyramid of the MoSCoW Model.
      The MoSCoW model was introduced by Dai Clegg of Oracle UK in 1994.

      The MoSCoW Model of Prioritization

      Requirements must be implemented for the solution to be considered successful.

      Requirements that are high priority should be included in the solution if possible.

      Requirements are desirable but not necessary and could be included if resources are available.

      Requirements won’t be in the next release, but will be considered for the future releases.

      Base your prioritization on the right set of criteria

      Effective Prioritization Criteria

      Criteria

      Description

      Regulatory & Legal Compliance These requirements will be considered mandatory.
      Policy Compliance Unless an internal policy can be altered or an exception can be made, these requirements will be considered mandatory.
      Business Value Significance Give a higher priority to high-value requirements.
      Business Risk Any requirement with the potential to jeopardize the entire project should be given a high priority and implemented early.
      Likelihood of Success Especially in “proof of concept” projects, it is recommended that requirements have good odds.
      Implementation Complexity Give a higher priority to low implementation difficulty requirements.
      Alignment With Strategy Give a higher priority to requirements that enable the corporate strategy.
      Urgency Prioritize requirements based on time sensitivity.
      Dependencies A requirement on its own may be low priority, but if it supports a high-priority requirement, then its priority must match it.

      2.6 Identify requirements to support your use cases

      1-2 hours

      Input: List of goals and challenges

      Output: Use cases to be used for determining requirements

      Materials: Whiteboard/flip charts, Vendor Evaluation Workbook

      Participants: CIO, Application managers, CMO/SVP sales, Marketing, sales, or service SMEs

      1. Work with the team to identify which features will be most important to support your use cases. Keep in mind there will be some features that will require more effort to implement fully. Add that into your project plan.
      2. Use the features lists on the following slides as a guide to get started on requirements.
      3. Prioritize your requirements list into mandatory features and nice-to-have features (or use the MoSCoW model from the previous slides). This will help you to eliminate vendors who don’t meet bare minimums and to score remaining vendors.
      4. Use this same list to guide your vendor demos.

      Our Improve Requirements Gathering blueprint provides a deep dive into the process of eliciting, analyzing, and validating requirements if you need to go deeper into effective techniques.

      CRM features

      Table stakes vs. differentiating

      What is a table stakes/standard feature?

      • Certain features are standard for all CRM tools, but that doesn’t mean they are all equal.
      • The existence of features doesn’t guarantee their quality or functionality to the standards you need. Never assume that “Yes” in a features list means you don’t need to ask for a demo.
      • If Table Stakes are all you need from your CRM solution, the only true differentiator for the organization is price. Otherwise, dig deeper to find the best price to value for your needs.

      What is a differentiating/additional feature?

      • Differentiating features take two forms:
        • Some CRM platforms offer differentiating features that are vertical specific.
        • Other CRM platforms offer differentiating features that are considered cutting edge. These cutting-edge features may become table stakes over time.

      Table stakes features for CRM

      Account Management Flexible account database that stores customer information, account history, and billing information. Additional functionality includes: contact deduplication, advanced field management, document linking, and embedded maps.
      Interaction Logging and Order History Ability to view all interactions that have occurred between sales teams and the customer, including purchase order history.
      Basic Pipeline Management View of all opportunities organized by their current stage in the sales process.
      Basic Case Management The ability to create and manage cases (for customer service or order fulfilment) and associate them with designated accounts or contacts.
      Basic Campaign Management Basic multi-channel campaign management (i.e. ability to execute outbound email campaigns). Budget tracking and campaign dashboards.
      Reports and Analytics In-depth reports on CRM data with dashboards and analytics for a variety of audiences.
      Mobile Support Mobile access across multiple devices (tablets, smartphones and/or wearables) with access to CRM data and dashboards.

      Additional features for CRM

      Customer Information Management Customizable records with detailed demographic information and the ability to created nested accounts (accounts with associated sub-accounts or contact records).
      Advanced Case Management Ability to track detailed interactions with members or constituents through a case view.
      Employee Collaboration Capabilities for employee-to-employee collaboration, team selling, and activity streams.
      Customer Collaboration Capabilities for outbound customer collaboration (i.e. the ability to create customer portals).
      Lead Generation Capabilities for generating qualified leads from multiple channels.
      Lead Nurturing/Lead Scoring The ability to evaluate lead warmth using multiple customer-defined criteria.
      Pipeline and Deal Management Managing deals through cases, providing quotes, and tracking client deliverables.

      Additional features for CRM (Continued)

      Marketing Campaign Management Managing outbound marketing campaigns via multiple channels (email, phone, social, mobile).
      Customer Intelligence Tools for in-depth customer insight generation and segmentation, predictive analytics, and contextual analytics.
      Multi-Channel Support Capabilities for supporting customer interactions across multiple channels (email, phone, social, mobile, IoT, etc.).
      Customer Service Workflow Management Capabilities for customer service resolution, including ticketing and service management.
      Knowledge Management Tools for capturing and sharing CRM-related knowledge, especially for customer service.
      Customer Journey Mapping Visual workflow builder with automated trigger points and business rules engine.
      Document Management The ability to curate assets and attachments and add them to account or contact records.
      Configure, Price, Quote The ability to create sales quotes/proposals from predefined price lists and rules.

      2.7 Put it all together – port your requirements into a robust RFP template that you can take to market!

      1-2 hours
      1. Once you’ve captured and prioritized your requirements – and received sign-off on them from key stakeholders – it’s time to bake them into a procurement vehicle of your choice.
      2. For complex enterprise systems like a CRM platform, Info-Tech recommends that this should take the form of a structured RFP document.
      3. Use our CRM RFP Template and associated CRM RFP Scoring Tool to jump-start the process.
      4. The next step will be conducting a market scan to identify contenders, and issuing the RFP to a shortlist of viable vendors for further evaluation.

      Need additional guidance on running an effective RFP process? Our Drive Successful Sourcing Outcomes with a Robust RFP Process has everything you need to ace the creation, administration and assessment of RFPs!

      Samples of the CRM Request for Proposal Template and CRM Suite Evaluation and RFP Scoring Tool.

      Download the CRM Request for Proposal Template

      Download the CRM Suite Evaluation and RFP Scoring Tool

      Identify whether vertical-specific CRM platforms are a best fit

      In mature vendor landscapes (like CRM) vendors begin to differentiate themselves by offering vertical-specific platforms, modules, or feature sets. These feature sets accelerate the implantation, decrease the platform’s learning curve, and drive user adoption. The three use cases below cover the most common industry-specific offerings:

      Public Sector

      • Constituent management and communication.
      • Constituent portal deployment for self-service.
      • Segment constituents based on geography, needs and preferences.

      Education

      • Top-level view into the student journey from prospect to enrolment.
      • Track student interactions with services across the institution.
      • Unify communications across different departments.

      Financial Services

      • Determine customer proclivity for new services.
      • Develop self-service banking portals.
      • Track longitudinal customer relationships from first account to retirement management.
      Info-Tech Insight

      Vertical-specific solutions require less legwork to do upfront but could cost you more in the long run. Interoperability and vendor viability must be carefully examined. Smaller players targeting niche industries often have limited integration ecosystems and less funding to keep pace with feature innovation.

      Rein-in ballooning scope for CRM selection projects

      Stretching the CRM beyond its core capabilities is a short-term solution to a long-term problem. Educate stakeholders about the limits of CRM technology.

      Common pitfalls for CRM selection

      • Tangential capabilities may require separate solutions. It is common for stakeholders to list features such as “content management” as part of the new CRM platform. While content management goes hand in hand with the CRM’s ability to manage customer interactions, document management is best handled by a standalone platform.

      Keeping stakeholders engaged and in line

      • Ballooning scope leads to stakeholder dissatisfaction. Appeasing stakeholders by over-customizing the platform will lead to integration and headaches down the road.
      • Make sure stakeholders feel heard. Do not turn down ideas in the midst of an elicitation session. Once the requirements-gathering sessions are completed, the project team has the opportunity to mark requirements as “out of scope” and communicate the reasoning behind the decision.
      • Educate stakeholders on the core functionality of CRM. Many stakeholders do not know the best-fit use cases for CRM platforms. Help end users understand what CRM is good at and where additional technologies will be needed.
      Stock image of a man leaping with a balloon.

      CRM Buyer’s Guide

      Phase 3

      Discover the CRM Market Space & Prepare for Implementation

      Phase 1

      1.1 Define CRM platforms

      1.2 Classify table stakes & differentiating capabilities

      1.3 Explore CRM trends

      Phase 2

      2.1 Build the business case

      2.2 Streamline requirements elicitation for CRM

      2.3 Construct the RFP

      Phase 3

      3.1 Discover key players in the CRM landscape

      3.2 Engage the shortlist & select finalist

      3.3 Prepare for implementation

      This phase will walk you through the following activities:

      • Dive into the key players of the CRM vendor landscape.
      • Understand best practices for building a vendor shortlist.
      • Understand key implementation considerations for CRM.

      This phase involves the following participants:

      • CIO
      • Applications manager
      • Project manager
      • Sales executive
      • Marketing executive
      • Customer service executive

      Consolidating the Vendor Shortlist Up-Front Reduces Downstream Effort

      Put the “short” back in shortlist!

      • Radically reduce effort by narrowing the field of potential vendors earlier in the selection process. Too many organizations don’t funnel their vendor shortlist until nearing the end of the selection process. The result is wasted time and effort evaluating options that are patently not a good fit.
      • Leverage external data (such as SoftwareReviews) and expert opinion to consolidate your shortlist into a smaller number of viable vendors before the investigative interview stage and eliminate time spent evaluating dozens of RFP responses.
      • Having fewer RFP responses to evaluate means you will have more time to do greater due diligence.
      Stock image of river rapids.

      Review your use cases to start your shortlist

      Your Info-Tech analysts can help you narrow down the list of vendors that will meet your requirements.

      Next steps will include:
      1. Reviewing your requirements
      2. Checking out SoftwareReviews
      3. Shortlisting your vendors
      4. Conducting demos and detailed proposal reviews
      5. Selecting and contracting with a finalist!
      Image of a person presenting a dashboard of the steps on the left.

      Get to know the key players in the CRM landscape

      The proceeding slides provide a top-level overview of the popular players you will encounter in the CRM shortlisting process.

      Logos of the key players in the CRM landscape (Salesforce, Microsoft, Oracle, HubSpot, etc).

      Evaluate software category leaders through vendor rankings and awards

      SoftwareReviews

      Sample of SoftwareReviews' Data Quadrant Report. Title page of SoftwareReviews' Data Quadrant Report. The Data Quadrant is a thorough evaluation and ranking of all software in an individual category to compare platforms across multiple dimensions.

      Vendors are ranked by their Composite Score, based on individual feature evaluations, user satisfaction rankings, vendor capability comparisons, and likeliness to recommend the platform.

      Sample of SoftwareReviews' Emotional Footprint. Title page of SoftwareReviews' Emotional Footprint. The Emotional Footprint is a powerful indicator of overall user sentiment toward the relationship with the vendor, capturing data across five dimensions.

      Vendors are ranked by their Customer Experience (CX) Score, which combines the overall Emotional Footprint rating with a measure of the value delivered by the solution.

      Speak with category experts to dive deeper into the vendor landscape

      SoftwareReviews

      Icon of a person.


      Fact-based reviews of business software from IT professionals.

      Icon of a magnifying glass over a chart.


      Top-tier data quality backed by a rigorous quality assurance process.

      CLICK HERE to ACCESS

      Comprehensive software reviews to make better IT decisions

      We collect and analyze the most detailed reviews on enterprise software from real users to give you an unprecedented view into the product and vendor before you buy.

      Icon of a tablet.


      Product and category reports with state-of-the-art data visualization.

      Icon of a phone.


      User-experience insight that reveals the intangibles of working with a vendor.

      SoftwareReviews is powered by Info-Tech

      Technology coverage is a priority for Info-Tech, and SoftwareReviews provides the most comprehensive unbiased data on today’s technology. Combined with the insights of our expert analysts, our members receive unparalleled support in their buying journey.

      Logo for Salesforce.
      Est. 1999 | CA, USA | NYSE: CRM

      bio

      Link for their Twitter account. Link for their LinkedIn profile. Link for their website.
      Sales Cloud Enterprise allows you to be more efficient, more productive, more everything than ever before as it allows you to close more deals, accelerate productivity, get more leads, and make more insightful decisions.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:
      • Breadth of features
      • Quality of features
      • Sales management functionality
      Areas to Improve:
      • Cost of service
      • Ease of implementation
      • Telephony and contact center management
      Logo gif for SoftwareReviews.
      8.0
      COMPOSITE SCORE
      8.3
      CX SCORE
      +77
      EMOTIONAL FOOTPRINT
      83%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 600
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of a Salesforce screen. Vendor Pulse rating. How often do we hear about Salesforce from our members for CRM? 'Very Frequently'.
      History of Salesforce in a vertical timeline.
      *Pricing correct as of August 2021. Listed in USD and absent discounts.
      See pricing on vendor’s website for latest information.
      Logo for Salesforce.

      “Salesforce is the pre-eminent vendor in the CRM marketplace and is a force to be reckoned with in terms of the breadth and depth of its capabilities. The company was an early disruptor in the category, placing a strong emphasis from the get-go on a SaaS delivery model and strong end-user experience. This allowed them to rapidly gain market share at the expense of more complacent enterprise application vendors. A series of savvy acquisitions over the years has allowed Salesforce to augment their core Sales and Service Clouds with a wide variety of other solutions, from e-commerce to marketing automation to CPQ. Salesforce is a great fit for any organization looking to partner with a market leader with excellent functional breadth, strong interoperability, and a compelling technology and partner ecosystem. All of this comes at a price, however – Salesforce prices at a premium, and our members routinely opine that Salesforce’s commercial teams are overly aggressive – sometimes pushing solutions without a clear link to underpinning business requirements.”

      Ben Dickie
      Research Practice Lead, Info-Tech Research Group

      Sales Cloud Essentials Sales Cloud Professional Sales Cloud Enterprise Sales Cloud Ultimate
      • Starts at $25*
      • Per user/mo
      • Small businesses after basic functionality
      • Starts at $75*
      • Per user/mo
      • Mid-market target
      • Starts at $150*
      • Per user/mo
      • Enterprise target
      • Starts at $300*
      • Per user/mo
      • Strong upmarket feature additions
      Logo for Microsoft.


      Est. 1975 | WA, USA | NYSE: MSFT

      bio

      Link for their Twitter account.Link for their LinkedIn profile.Link for their website.
      Dynamics 365 Sales is an adaptive selling solution that helps your sales team navigate the realities of modern selling. At the center of the solution is an adaptive, intelligent system – prebuilt and ready to go – that actively monitors myriad signals and distills them into actionable insights.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:

      • Business value created
      • Analytics and reporting
      • Lead management

      Areas to Improve:

      • Quote, contract, and proposals
      • Vendor support
      Logo gif for SoftwareReviews.
      8.1
      COMPOSITE SCORE
      8.3
      CX SCORE
      +84
      EMOTIONAL FOOTPRINT
      82%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 198
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of a Microsoft screen.Vendor Pulse rating. How often do we hear about Microsoft Dynamics from our Members? 'Very Frequently'.

      History of Microsoft in a vertical timeline.

      *Pricing correct as of June 2022. Listed in USD and absent discounts.
      See pricing on vendor’s website for latest information.
      Logo for Microsoft.
      “”

      “Microsoft Dynamics 365 is a strong and compelling player in the CRM arena. While Microsoft is no stranger to the CRM space, their offerings here have seen steady and marked improvement over the last five years. Good functional breadth paired with a modern user interface and best-in-class Microsoft stack compatibility ensures that we consistently see them on our members’ shortlists, particularly when our members are looking to roll out CRM capabilities alongside other components of the Dynamics ecosystem (such as Finance, Operations, and HR). Today, Microsoft segments the offering into discrete modules for sales, service, marketing, commerce, and CDP. While Microsoft Dynamics 365 is a strong option, it’s occasionally mired by concerns that the pace of innovation and investment lags Salesforce (its nearest competitor). Additionally, the marketing module of the product is softer than some of its competitors, and Microsoft themselves points organizations with complex marketing requirements to a strategic partnership that they have with Adobe.”

      Ben Dickie
      Research Practice Lead, Info-Tech Research Group

      D365 Sales Professional D365 Sales Enterprise D365 Sales Premium
      • Starts at $65*
      • Per user/mo
      • Midmarket focus
      • Starts at $95*
      • Per user/mo
      • Enterprise focus
      • Starts at $135*
      • Per user/mo
      • Enterprise focus with customer intelligence
      Logo for Oracle.


      Est. 1977 | CA, USA | NYSE: ORCL

      bio

      Link for their Twitter account.Link for their LinkedIn profile.Link for their website.
      Oracle Engagement Cloud (CX Sales) provides a set of capabilities to help sales leaders transition smoothly from sales planning and execution through customer onboarding, account management, and support services.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:

      • Quality of features
      • Activity and workflow management
      • Analytics and reporting

      Areas to Improve:

      • Marketing management
      • Product strategy & rate of improvement
      Logo gif for SoftwareReviews.
      7.8
      COMPOSITE SCORE
      7.9
      CX SCORE
      +77
      EMOTIONAL FOOTPRINT
      78%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 140
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of an Oracle screen.Vendor Pulse rating. How often do we hear about Oracle from our members for CRM? 'Frequently'.

      History of Oracle in a vertical timeline.

      Logo for Oracle.

      “Oracle is long-term juggernaut of the enterprise applications space. Their CRM portfolio is diverse – rather than a single stack, there are multiple Oracle solutions (many made by acquisition) that support CRM capabilities – everything from Siebel to JD Edwards to NetSuite to Oracle CX applications. The latter constitute Oracle’s most modern stab at CRM and are where the bulk of feature innovation and product development is occurring within their portfolio. While historically seen as lagging behind other competitors like Salesforce and Microsoft, Oracle has made excellent strides in improving their user experience (via their Redwoods design paradigm) and building new functional capabilities within their CRM products. Indeed, SoftwareReviews shows Oracle performing well in our most recent peer-driven reports. Nonetheless, we most commonly see Oracle as a pricier ecosystem play that’s often subordinate to a heavy Oracle footprint for ERP. Many of our members also express displeasure with Oracle as a vendor and highlight their heavy-handed “threat of audit” approach. ”

      Ben Dickie
      Research Practice Lead, Info-Tech Research Group

      Oracle CX Sales - Pricing Opaque:

      “Request a Demo”

      Logo for SAP.


      Est. 1972 | Germany | NYSE: SAP

      bio

      Link for their Twitter account.Link for their LinkedIn profile.Link for their website.
      SAP is the third-largest independent software manufacturer in the world, with a presence in over 120 countries. Having been in the industry for over 40 years, SAP is perhaps best known for its ERP application, SAP ERP.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:

      • Ease of data integration

      Areas to Improve:

      • Lead management
      • Marketing management
      • Collaboration
      • Usability & intuitiveness
      • Analytics & reporting
      Logo gif for SoftwareReviews.
      7.4
      COMPOSITE SCORE
      7.8
      CX SCORE
      +74
      EMOTIONAL FOOTPRINT
      75%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 108
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of a SAP screen.Vendor Pulse rating. How often do we hear about SAP from our members for CRM? 'Occasionally'.

      History of SAP in a vertical timeline.

      *Pricing correct as of August 2021. Listed in USD and absent discounts.
      See pricing on vendor’s website for latest information.
      Logo for SAP.

      “SAP is another mainstay of the enterprise applications market. While they have a sound breadth of capabilities in the CRM and customer experience space, SAP consistently underperforms in many of our relevant peer-driven SoftwareReviews reports for CRM and adjacent areas. CRM seems decidedly a secondary focus for SAP, behind their more compelling play in the enterprise resource planning (ERP) space. Indeed, most instances where we see SAP in our clients’ shortlists, it’s as an ecosystem play within a broader SAP strategy. If you’re blue on the ERP side, looking to SAP’s capabilities on the CRM front makes logical sense and can help contain costs. If you’re approaching a CRM selection from a greenfield lens and with no legacy vendor baggage for SAP elsewhere, experience suggests you’ll be better served by a vendor that places a higher degree of primacy on the CRM aspect of their portfolio.”

      Ben Dickie
      Research Practice Lead, Info-Tech Research Group

      SAP CRM - Pricing Opaque:

      “Request a Demo”

      Logo for pipedrive.


      Est. 2010 | NY, USA | Private

      bio

      Link for their Twitter account.Link for their LinkedIn profile.Link for their website.
      Pipedrive brings together the tools and data, the platform focuses sales professionals on fundamentals to advance deals through their pipelines. Pipedrive's goal is to make sales success inevitable - for salespeople and teams.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:

      • Sales Management
      • Account & Contact Management
      • Lead Management
      • Usability & Intuitiveness
      • Ease of Implementation

      Areas to Improve:

      • Customer Service Management
      • Marketing Management
      • Product Strategy & Rate of Improvement
      Logo gif for SoftwareReviews.
      8.3
      COMPOSITE SCORE
      8.4
      CX SCORE
      +85
      EMOTIONAL FOOTPRINT
      85%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 262
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of a Pipedrive screen.Vendor Pulse rating. How often do we hear about Pipedrive from our members for CRM? 'Occasionally'.

      History of Pipedrive in a vertical timeline.

      *Pricing correct as of June 2022. Listed in USD and absent discounts.
      See pricing on vendor’s website for latest information.
      Logo for Pipedrive.

      “A relatively new offering, Pipedrive has seen explosive growth over the last five years. They’re a vendor that has gone from near-obscurity to popping up frequently on our members’ shortlists. Pipedrive’s secret sauce has been a relentless focus on high-velocity sales enablement. Their focus on pipeline management, lead assessment and routing, and a good single pane of glass for sales reps has driven significant traction for the vendor when sales enablement is the driving rationale behind rolling out a new CRM platform. Bang for your buck is also strong with Pipedrive, with the vendor having a value-driven licensing and implementation model.

      Pipedrive is not without some shortcomings. It’s laser-focus on sales enablement is at the expense of deep capabilities for marketing and service management, and its profile lends itself better to SMBs and lower midmarket than it does large organizations looking for enterprise-grade CRM.”

      Ben Dickie
      Research Practice Lead, Info-Tech Research Group

      Essential Advanced Professional Enterprise
      • Starts at $12.50*
      • Per user/mo
      • Small businesses after basic functionality
      • Starts at $24.90*
      • Per user/mo
      • Small/mid-sized businesses
      • Starts at $49.90*
      • Per user/mo
      • Lower mid-market focus
      • Starts at $99*
      • Per user/mo
      • Enterprise focus
      Logo for SugarCRM.


      Est. 2004 | CA, USA | Private

      bio

      Link for their Twitter account.Link for their LinkedIn profile.Link for their website.
      Produces Sugar, a SaaS-based customer relationship management application. SugarCRM is backed by Accel-KKR.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:

      • Ease of customization
      • Product strategy and rate of improvement
      • Ease of IT administration

      Areas to Improve:

      • Marketing management
      • Analytics and reporting
      Logo gif for SoftwareReviews.
      8.4
      COMPOSITE SCORE
      8.8
      CX SCORE
      +92
      EMOTIONAL FOOTPRINT
      84%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 97
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of a SugarCRM screen.Vendor Pulse rating. How often do we hear about SugarCRM from our members for CRM? 'Frequently'.
      History of SugarCRM in a vertical timeline.
      *Pricing correct as of August 2021. Listed in USD and absent discounts.
      See pricing on vendor’s website for latest information.
      Logo for SugarCRM.

      “SugarCRM offers reliable baseline capabilities at a lower price point than other large CRM vendors. While SugarCRM does not offer all the bells and whistles that an Enterprise Salesforce plan might, SugarCRM is known for providing excellent vendor support. If your organization is only after standard features, SugarCRM will be a good vendor to shortlist.

      However, ensure you have the time and labor power to effectively implement and train on SugarCRM’s solutions. SugarCRM does not score highly for user-friendly experiences, with complaints centering on outdated and unintuitive interfaces. Setting up customized modules takes time to navigate, and SugarCRM does not provide a wide range of native integrations with other applications. To effectively determine whether SugarCRM does offer a feasible solution, it is recommended that organizations know exactly what kinds of integrations and modules they need.”

      Thomas Randall
      Research Director, Info-Tech Research Group

      Sugar Professional Sugar Serve Sugar Sell Sugar Enterprise Sugar Market
      • Starts at $52*
      • Per user/mo
      • Min. 3 users
      • Small businesses
      • Starts at $80*
      • Per user/mo
      • Min. 3 users
      • Focused on customer service
      • Starts at $80*
      • Per user/mo
      • Min. 3 users
      • Focused on sales automation
      • Starts at $80*
      • Per user/mo
      • Min. 3 users
      • On-premises, mid-sized businesses
      • Starts at $1000*
      • Priced per month
      • Min. 10k contacts
      • Large enterprise
      Logo for .


      Est. 2006 | MA, USA | HUBS (NYSE)

      bio

      Link for their Twitter account.Link for their LinkedIn profile.Link for their website.
      Develops software for inbound customer service, marketing, and sales. Software includes CRM, SMM, lead gen, SEO, and web analytics.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:

      • Breadth of features
      • Product strategy and rate of improvement
      • Ease of customization

      Areas to Improve:

      • Ease of data integration
      • Customer service management
      • Telephony and call center management
      Logo gif for SoftwareReviews.
      8.3
      COMPOSITE SCORE
      8.4
      CX SCORE
      +84
      EMOTIONAL FOOTPRINT
      86%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 97
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of a HubSpot screen.Vendor Pulse rating. How often do we hear about HubSpot from our members for CRM? 'Frequently'.

      History of HubSpot in a vertical timeline.

      *Pricing correct as of August 2021. Listed in USD and absent discounts
      See pricing on vendor’s website for latest information.
      Logo for HubSpot.

      “ HubSpot is best suited for small to mid-sized organizations that need a range of CRM tools to enable growth across sales, marketing campaigns, and customer service. Indeed, HubSpot offers a content management solution that offers a central storage location for all customer and marketing data. Moreover, HubSpot offers plenty of freemium tools for users to familiarize themselves with the software before buying. However, though HubSpot is geared toward growing businesses, smaller organizations may not see high ROI until they begin to scale. The “Starter” and “Professional” plans’ pricing is often cited by small organizations as a barrier to commitment, and the freemium tools are not a sustainable solution. If organizations can take advantage of discount behaviors from HubSpot (e.g. a startup discount), HubSpot will be a viable long-term solution. ”

      Thomas Randall
      Research Director, Info-Tech Research Group

      Starter Professional Enterprise
      • Starts at $50*
      • Per month
      • Min. 2 users
      • Small businesses
      • Starts at $500*
      • Per month
      • Min. 5 users
      • Small/mid-sized businesses
      • Starts at $1200*
      • Billed yearly
      • Min. 10 users
      • Mid-sized/small enterprise
      Logo for Zoho.


      Est. 1996 | India | Private

      bio

      Link for their Twitter account.Link for their LinkedIn profile.Link for their website.
      Zoho Corporation offers a cloud software suite, providing a full operating system for CRM, alongside apps for finance, productivity, HR, legal, and more.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:

      • Business value created
      • Breadth of features
      • Collaboration capabilities

      Areas to Improve:

      • Usability and intuitiveness
      Logo gif for SoftwareReviews.
      8.7
      COMPOSITE SCORE
      8.9
      CX SCORE
      +92
      EMOTIONAL FOOTPRINT
      85%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 152
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of a Zoho screen.Vendor Pulse rating. How often do we hear about Zoho from our members for CRM? 'Occasionally'.

      History of Zoho in a vertical timeline.

      *
      See pricing on vendor’s website for latest information.
      Logo for Zoho.

      “Zoho has a long list of software solutions for businesses to run end to end. As one of Zoho’s earliest software releases, though, ZohoCRM remains a flagship product. ZohoCRM’s pricing is incredibly competitive for mid/large enterprises, offering high business value for its robust feature sets. For those organizations that already utilize Zoho solutions (such as its productivity suite), ZohoCRM will be a natural extension.

      However, small/mid-sized businesses may wonder how much ROI they can get from ZohoCRM, when much of the functionality expected from a CRM (such as workflow automation) cannot be found until one jumps to the “Enterprise” plan. Given the “Enterprise” plan’s pricing is on par with other CRM vendors, there may not be much in a smaller organization’s eyes that truly distinguishes ZohoCRM unless they are already invested Zoho users.”

      Thomas Randall
      Research Director, Info-Tech Research Group

      Standard Professional Enterprise Ultimate
      • Starts at $20*
      • Per user/mo
      • Small businesses after basic functionality
      • Starts at $35*
      • Per user/mo
      • Small/mid-sized businesses
      • Adds inventory management
      • Starts at $50*
      • Per user/mo
      • Mid-sized/small enterprise
      • Adds Zia AI
      • Starts at $65*
      • Per user/mo
      • Enterprise
      • Bundles Zoho Analytics
      Logo for Zendesk.


      Est. 2009 | CA, USA | ZEN (NYSE)

      bio

      Link for their Twitter account.Link for their LinkedIn profile.Link for their website.
      Software developer for customer service. Founded in Copenhagen but moved to San Francisco after $6 million Series B funding from Charles River Ventures and Benchmark Capital.

      SoftwareReviews’ Enterprise CRM Rankings

      Strengths:

      • Quality of features
      • Breadth of features
      • Vendor support

      Areas to Improve:

      • Business value created
      • Ease of customization
      • Usability and intuitiveness
      Logo gif for SoftwareReviews.
      7.8
      COMPOSITE SCORE
      7.9
      CX SCORE
      +80
      EMOTIONAL FOOTPRINT
      72%
      LIKELINESS TO RECOMMEND
      DOWNLOAD REPORT 50
      REVIEWS
      Vendor scores are driven by real-world practitioner reviews via SoftwareReviews. Composite, CX, EF and NPS scores pulled from live data as of June 2022. Rankings and ”strengths” and ”areas to improve” pulled from January 2022 Category Report.
      Sample of a Zendesk screen.Vendor Pulse rating. How often do we hear about Zendesk from our members for CRM? 'Rarely'.

      History of Zendesk in a vertical timeline.

      *Pricing correct as of August 2021. Listed in USD and absent discounts
      See pricing on vendor’s website for latest information.
      Logo for Zendesk.

      “Zendesk’s initial growth was grounded in word-of-mouth advertising, owing to the popularity of its help desk solution’s design and functionality. Zendesk Sell has followed suit, receiving strong feedback for the breadth and quality of its features. Organizations that have already reaped the benefits of Zendesk’s customer service suite will find Zendesk Sell a straightforward fit for their sales teams.

      However, it is important to note that Zendesk Sell is predominantly focused on sales. Other key components of a CRM, such as marketing, are less fleshed out. Organizations should ensure they verify what requirements they have for a CRM before choosing Zendesk Sell – if sales process requirements (such as forecasting, call analytics, and so on) are but one part of what the organization needs, Zendesk Sell may not offer the highest ROI for the pricing offered.”

      Thomas Randall
      Research Director, Info-Tech Research Group

      Sell Team Sell Professional Sell Enterprise
      • Starts at $19*
      • Per user/mo
      • Max. 3 users
      • Small businesses
      • Basic functionality
      • Starts at $49*
      • Per user/mo
      • Small/mid-sized businesses
      • Advanced analytics
      • Starts at $99*
      • Per user/mo
      • Mid-sized/small enterprise
      • Task automation

      Speak with category experts to dive deeper into the vendor landscape

      Icon of a person.
      Fact-based reviews of business software from IT professionals.
      Icon of a magnifying glass over a chart.
      Top-tier data quality backed by a rigorous quality assurance process.
      CLICK HERE to ACCESS

      Comprehensive software reviews to make better IT decisions

      We collect and analyze the most detailed reviews on enterprise software from real users to give you an unprecedented view into the product and vendor before you buy.

      Icon of a tablet.
      Product and category reports with state-of-the-art data visualization.
      Icon of a phone.
      User-experience insight that reveals the intangibles of working with a vendor.

      SoftwareReviews is powered by Info-Tech

      Technology coverage is a priority for Info-Tech, and SoftwareReviews provides the most comprehensive unbiased data on today’s technology. Combined with the insights of our expert analysts, our members receive unparalleled support in their buying journey.

      Conduct a day of rapid-fire vendor demos

      Zoom in on high-value use cases and answers to targeted questions

      Make sure the solution will work for your business

      Give each vendor 90 to 120 minutes to give a rapid-fire presentation. We suggest the following structure:

      • 30 minutes: company introduction and vision
      • 60 minutes: walk-through of two or three high-value demo scenarios
      • 30 minutes: targeted Q&A from the business stakeholders and procurement team
      To ensure a consistent evaluation, vendors should be asked analogous questions, and a tabulation of answers should be conducted.
      How to challenge the vendors in the investigative interview
      • Change the visualization/presentation.
      • Change the underlying data.
      • Add additional data sets to the artifacts.
      • Collaboration capabilities.
      • Perform an investigation in terms of finding BI objects and identifying previous changes, and examine the audit trail.
      Rapid-fire vendor investigative interview

      Invite vendors to come onsite (or join you via video conference) to demonstrate the product and to answer questions. Use a highly targeted demo script to help identify how a vendor’s solution will fit your organization’s particular business capability needs.

      Graphic of an alarm clock.
      To kick-start scripting your demo scenarios, leverage our CRM Demo Script Template.

      A vendor scoring model provides a clear anchor point for your evaluation of CRM vendors based on a variety of inputs

      A vendor scoring model is a systematic method for effectively assessing competing vendors. A weighted-average scoring model is an approach that strikes a strong balance between rigor and evaluation speed.

      Info-Tech Insight

      Even the best scoring model will still involve some “art” rather than science – scoring categories such as vendor viability always entails a degree of subjective interpretation.

      How do I build a scoring model?

      • Start by shortlisting the key criteria you will use to evaluate your vendors. Functional capabilities should always be a critical category, but you’ll also want to look at criteria such as affordability, architectural fit, and vendor viability.
      • Depending on the complexity of the project, you may break down some criteria into sub-categories to assist with evaluation (for example, breaking down functional capabilities into constituent use cases so you can score each one).
      • Once you’ve developed the key criteria for your project, the next step is weighting each criterion. Your weightings should reflect the priorities for the project at hand. For example, some projects may put more emphasis on affordability, others on vendor partnership.
      • Using the information collected in the subsequent phases of this blueprint, score each criterion from 1-100, then multiply by the weighting factor. Add up the weighted scores to arrive at the aggregate evaluation score for each vendor on your shortlist.

      What are some of the best practices?

      • While the criteria for each project may vary, it’s helpful to have an inventory of repeatable criteria that can be used across application selection projects. The next slide contains an example that you can add or subtract from.
      • Don’t go overboard on the number of criteria: five to 10 weighted criteria should be the norm for most projects. The more criteria (and sub-criteria) you must score against, the longer it will take to conduct your evaluation. Always remember, link the level of rigor to the size and complexity of your project! It’s possible to create a convoluted scoring model that takes significant time to fill out but yields little additional value.
      • Creation of the scoring model should be a consensus-driven activity among IT, procurement, and the key business stakeholders – it should not be built in isolation. Everyone should agree on the fundamental criteria and weights that are employed.
      • Consider using not just the outputs of investigative interviews and RFP responses to score vendors, but also third-party review services like SoftwareReviews.

      Define how you’ll score CRM proposals and demos

      Define key CRM selection criteria for your organization – this should be informed by the following goals, use cases, and requirements covered in the blueprint.

      Criteria

      Description

      Functional CapabilitiesHow well does the vendor align with the top-priority functional requirements identified in your accelerated needs assessment? What is the vendor’s functional breadth and depth?
      AffordabilityHow affordable is this vendor? Consider a three-to-five-year total cost of ownership (TCO) that encompasses not just licensing costs, but also implementation, integration, training, and ongoing support costs.
      Architectural FitHow well does this vendor align with our direction from an enterprise architecture perspective? How interoperable is the solution with existing applications in our technology stack? Does the solution meet our deployment model preferences?
      ExtensibilityHow easy is it to augment the base solution with native or third-party add-ons as our business needs may evolve?
      ScalabilityHow easy is it to expand the solution to support increased user, data, and/or customer volumes? Are there any capacity constraints of the solution?
      Vendor ViabilityHow viable is this vendor? Are they an established player with a proven track record, or a new and untested entrant to the market? What is the financial health of the vendor? How committed are they to the particular solution category?
      Vendor VisionDoes the vendor have a cogent and realistic product roadmap? Are they making sensible investments that align with your organization’s internal direction?
      Emotional FootprintHow well does the vendor’s organizational culture and team dynamics align to yours?
      Third-Party Assessments and/or ReferencesHow well-received is the vendor by unbiased, third-party sources like SoftwareReviews? For larger projects, how well does the vendor perform in reference checks (and how closely do those references mirror your own situation)?

      Decision Point: Select the Finalist

      After reviewing all vendor responses to your RFP, conducting vendor demos, and running a pilot project (if applicable), the time has arrived to select your finalist.

      All core selection team members should hold a session to score each shortlisted vendor against the criteria enumerated on the previous slide – based on an in-depth review of proposals, the demo sessions, and any pilots or technical assessments.

      The vendor that scores the highest in aggregate is your finalist.

      Congratulations – you are now ready to proceed to final negotiation and inking a contract. This blueprint provides a detailed approach on the mechanics of a major vendor negotiation.

      Leverage Info-Tech’s research to plan and execute your CRM implementation

      Use Info-Tech Research Group’s three phase implementation process to guide your own planning.
      The three phases of software implementation: 'Assess', 'Prepare', 'Govern & Course Correct'. Sample of the 'Governance and Management of Enterprise Software Implementation' blueprint.

      Establish and execute an end-to-end, agile framework to succeed with the implementation of a major enterprise application.

      Visit this link

      Prepare for implementation: establish a clear resourcing plan

      Organizations rarely have sufficient internal staffing to resource a CRM project on their own. Consider the options for closing the gap in internal resource availability.

      The most common project resourcing structures for enterprise projects are:
      Your own staff +
      1. Management consultant
      2. Vendor consultant
      3. System integrator
      Info-Tech Insight

      When contemplating a resourcing structure, consider:

      • Availability of in-house implementation competencies and resources.
      • Timeline and constraints.
      • Integration environment complexity.

      Consider the following:

      Internal vs. External Roles and Responsibilities

      Clearly delineate between internal and external team responsibilities and accountabilities, and communicate this to your technology partner up front.

      Internal vs. External Accountabilities

      Accountability is different than responsibility. Your vendor or SI partner may be responsible for completing certain tasks, but be careful not to outsource accountability for the implementation – ultimately, the internal team will be accountable.

      Partner Implementation Methodologies

      Often vendors and/or SIs will have their own preferred implementation methodology. Consider the use of your partner's implementation methodology; however, you know what will work for your organization.

      Establish team composition

      1 – 2 hours

      Input: Skills assessment, Stakeholder analysis, Vendor partner selection

      Output: Team composition

      Materials: Sticky notes, Whiteboard, Markers

      Participants: Project team

      Use Info-Tech’s Governance and Management of Enterprise Software Implementation to establish your team composition. Within that blueprint:

      1. Assess the skills necessary for an implementation. Inventory the competencies required for the implementation project team. Map your internal resources to each competency as applicable.
      2. Select your internal implementation team. Determine who needs to be involved closely with the implementation. Key stakeholders should also be considered as members of your implementation team.
      3. Identify the number of external consultants/support required for implementation. Consider your in-house skills, timeline considerations, integration environment complexity, and cost constraints as you make your team composition plan. Be sure to dedicate an internal resource to managing the vendor and partner relationships.
      4. Document the roles and responsibilities, accountabilities, and other expectations of your team as they relate to each step of the implementation.

      Governance and Management of Enterprise Software Implementation

      Sample of the 'Governance and Management of Enterprise Software Implementation' blueprint.Follow our iterative methodology with a task list focused on the business must-have functionality to achieve rapid execution and to allow staff to return to their daily work sooner.

      Visit this link

      Ensure your implementation team has a high degree of trust and communication

      If external partners are needed, dedicate an internal resource to managing the vendor and partner relationships.

      Communication

      Teams must have some type of communication strategy. This can be broken into:
      • Regularity: Having a set time each day to communicate progress and a set day to conduct retrospectives.
      • Ceremonies: Injecting awards and continually emphasizing delivery of value can encourage relationship-building and constructive motivation.
      • Escalation: Voicing any concerns and having someone responsible for addressing those concerns.

      Proximity

      Distributed teams create complexity as communication can break down. This can be mitigated by:
      • Location: Placing teams in proximity can close the barrier of geographical distance and time zone differences.
      • Inclusion: Making a deliberate attempt to pull remote team members into discussions and ceremonies.
      • Communication tools: Having the right technology (e.g. video conference) can help bring teams closer together virtually.

      Trust

      Members should trust other members are contributing to the project and completing their required tasks on time. Trust can be developed and maintained by:
      • Accountability: Having frequent quality reviews and feedback sessions. As work becomes more transparent, people become more accountable.
      • Role clarity: Having a clear definition of what everyone’s role is.

      Plan for your implementation of CRM based on deployment model

      Place your CRM application into your IT landscape by configuring and adjusting the tool based on your specific deployment method.

      Icon of a housing development.
      On-Premises

      1. Identify custom features and configuration items
      2. Train developers and IT staff on new software investment
      3. Install software
      4. Configure software
      5. Test installation and configuration
      6. Test functionality

      Icon of a cloud upload.
      SaaS-based

      1. Train developers and IT staff on new software investment
      2. Set up connectivity
      3. Identify VPN or internal solution
      4. Check firewalls
      5. Validate bandwidth regulations

      Integration is a top IT challenge and critical to the success of the CRM suite

      CRM suites are most effective when they are integrated with ERP and MarTech solutions.

      Data interchange between the CRM solution and other data sources is necessary

      Formulate a comprehensive map of the systems, hardware, and software with which the CRM solution must be able to integrate. Customer data needs to constantly be synchronized: without this, you lose out on one of the primary benefits of CRM. These connections must be bidirectional for maximum value (i.e. marketing data to the CRM, customer data to MMS).
      Specialized projects that include an intricate prospect or customer list and complex rules may need to be built by IT The more custom fields you have in your CRM suite and point solutions, the more schema mapping you will have to do. Include this information in the RFP to receive guidance from vendors on the ease with which integration can be achieved.

      Pay attention to legacy apps and databases

      If you have legacy CRM, POS, or customer contact software, more custom code will be required. Many vendors claim that custom integration can be performed for most systems, but custom comes at a cost. Don’t just ask if they can integrate; ask how long it will take and for references from organizations which have been successful in this.
      When assessing the current application portfolio that supports CRM, the tendency will be to focus on the applications under the CRM umbrella, relating mostly to marketing, sales, and customer service. Be sure to include systems that act as inputs to, or benefit due to outputs from, the CRM or similar applications.

      CRM data flow

      Example of a CRM data flow.

      Be sure to include enterprise applications that are not included in the CRM application portfolio. Popular systems to consider for POIs include billing, directory services, content management, and collaboration tools.

      Sample CRM integration map

      Sample of a CRM integration map.

      Scenario: Failure to address CRM data integration will cost you in the long run

      A company spent $15 million implementing a new CRM system in the cloud and decided NOT to spend an additional $1.5 million to do a proper cloud DI tool procurement. The mounting costs followed.

      Cost Element – Custom Data Integration

      $

      2 FTEs for double entry of sales order data $ 100,000/year
      One-time migration of product data to CRM $ 240,000 otc
      Product data maintenance $ 60,000/year
      Customer data synchronization interface build $ 60,000 otc
      Customer data interface maintenance $ 10,000/year
      Data quality issues $ 100,000/year
      New SaaS integration built in year 3 $ 300,000 otc
      New SaaS integration maintenance $ 150,000/year

      Cost Element – Data Integration Tool

      $

      DI strategy and platform implementation $1,500,000 otc
      DI tool maintenance $ 15,000/year
      New SaaS integration point in year 3 $ 300,000 otc
      Thumbs down color coded red to the adjacent chart. Custom integration is costing this organization $300,000/year for one SaaS solution.
      Thumbs up color coded blue to the adjacent chart.

      The proposed integration solution would have paid for itself in 3-4 years and saved exponential costs in the long run.

      Proactively address data quality in the CRM during implementation

      Data quality is a make-or-break issue in a CRM platform; garbage in is garbage out.
      • CRM suites are one of the leading offenders for generating poor-quality data. As such, it’s important to have a plan in place for structuring your data architecture in such a way the poor data quality is minimized from the get-go.
      • Having a plan for data quality should precede data migration efforts; some types of poor data quality can be mitigated prior to migration.
      • There are five main types of poor-quality data found in CRM platforms.
        • Duplicate data: Duplicate records can be a major issue. Leverage dedicated deduplication tools to eliminate them.
        • Stale data: Out-of-date customer information can reduce the usefulness of the platform. Use automated social listening tools to help keep data fresh.
        • Incomplete data: Records with missing info limit platform value. Specify data validation parameters to mandate that all fields are filled in.
        • Invalid and conflicting data: These can create cascading errors. Establishing conflict resolution rules in ETL tools for data integration can lessen issues.
      Info-Tech Insight

      If you have a complex POI environment, appoint data stewards for each major domain and procure a deduplication tool. As the complexity of CRM system-to-system integrations increases, so will the chance that data quality errors will crop up – for example, bidirectional POI with other sources of customer information dramatically increase the chances of conflicting/duplicate data.

      Profile data, eliminate dead weight, and enforce standards to protect data

      Identify and eliminate dead weight

      Poor data can originate in the firm’s CRM system. Custom queries, stored procedures, or profiling tools can be used to assess the key problem areas.

      Loose rules in the CRM system may lead to records of no significant value in the database. Those rules need to be fixed, but if changes are made before the data is fixed, users could encounter database or application errors, which will reduce user confidence in the system.

      • Conduct a data flow analysis: map the path that data takes through the organization.
      • Use a mass cleanup to identify and destroy dead weight data. Merge duplicates either manually or with the aid of software tools. Delete incomplete data, taking care to reassign related data.
      • COTS packages typically allow power users to merge records without creating orphaned records in related tables, but custom-built applications typically require IT expertise.

      Create and enforce standards and policies

      Now that the data has been cleaned, it’s important to protect the system from relapsing.

      Work with business users to find out what types of data require validation and which fields should have changes audited. Whenever possible, implement drop-down lists to standardize values and make programming changes to ensure that truncation ceases.

      • Truncated data is usually caused by mismatches in data structures during either one-time data loads or ongoing data integrations.
      • Don’t go overboard on assigning required fields; users will just put key data in note fields.
      • Discourage the use of unstructured note fields: the data is effectively lost except if it gets subpoenaed.
      Info-Tech Insight

      Data quality concerns proliferate with the customization level of your platform. The more extensive the custom integration points and module/database extensions that you have made, the more you will need to have a plan in place for managing data quality from a reactive and proactive standpoint.

      Create a formal communication process throughout the CRM implementation

      Establish a comprehensive communication process around the CRM enterprise roll-out to ensure that end users stay informed.

      The CRM kick-off meeting(s) should encompass: 'The high-level application overview', 'Target business-user requirements', 'Target quality of service (QoS) metrics', 'Other IT department needs', 'Tangible business benefits of application', 'Special consideration needs'. The overall objective for interdepartmental CRM kick-off meetings is to confirm that all parties agree on certain key points and understand platform rationale and functionality.

      The kick-off process will significantly improve internal communications by inviting all affected internal IT groups, including business units, to work together to address significant issues before the application process is formally activated.

      Department groups or designated trainers should take the lead and implement a process for:

      • Scheduling CRM platform roll-out/kick-off meetings.
      • Soliciting preliminary input from the attending groups to develop further training plans.
      • Establishing communication paths and the key communication agents from each department who are responsible for keeping lines open moving forward.

      Ensure requirements are met with robust user acceptance testing

      User acceptance testing (UAT) is a test procedure that helps to ensure end-user requirements are met. Test cases can reveal bugs before the suite is implemented.

      Five Secrets of UAT Success

      Bracket with colors corresponding the adjacent list items.

      1

      Create the plan With the information collected from requirements gathering, create the plan. Make sure this information is added to the main project plan documentation.

      2

      Set the agenda The time allotted will vary depending on the functionality being tested. Ensure that the test schedule allows for the resolution of issues and discussion.

      3

      Determine who will participate Work with the relevant stakeholders to identify the people who can best contribute to system testing. Look for experienced power users who have been involved in earlier decision making about the system.

      4

      Highlight acceptance criteria Together with the UAT group, pinpoint the criteria to determine system acceptability. Refer back to requirements specified in use cases in the initial requirements-gathering stages of the project.

      5

      Collect end user feedback Weaknesses in resolution workflow design, technical architecture, and existing customer service processes can be highlighted and improved on with ongoing surveys and targeted interviews.

      Calculate post-deployment metrics to assess measurable value of the project

      Track the post-deployment results from the project and compare the metrics to the current state and target state.

      CRM Selection and Implementation Metrics
      Description Formula Current or Estimated Target Post-Deployment
      End-User Satisfaction # of Satisfied Users
      # of End Users
      70% 90% 85%
      Percentage Over/Under Estimated Budget Amount Spent - 100%
      Budget
      5% 0% 2%
      Percentage Over/Under Estimated Timeline Project Length - 100%
      Estimated Timeline
      10% -5% -10%

      CRM Strategy Metrics
      Description Formula Current or Estimated Target Post-Deployment
      Number of Leads Generated (per month) # of Leads Generated 150 200 250
      Average Time to Resolution (in minutes) Time Spent on Resolution
      # of Resolutions
      30 minutes 10 minutes 15 minutes
      Cost per Interaction by Campaign Total Campaign Spending
      # of Customer Interactions
      $17.00 $12.00 $12.00

      Select the Right CRM Platform

      CRM technology is critical to facilitate an organization’s relationships with customers, service users, employees, and suppliers. Having a structured approach to building a business case, defining key requirements, and engaging with the right shortlist of vendors to pick the best finalist is crucial.

      This selection guide allows organizations to execute a structured methodology for picking a CRM that aligns with their needs. This includes:
      • Alignment and prioritization of key business and technology drivers for a CRM selection business case.
      • Identification of key use cases and requirements for CRM.
      • Construction of a robust CRM RFP.
      • A strong market scan of key players.
      • A survey of crucial implementation considerations.
      This formal CRM selection initiative will drive business-IT alignment, identify sales and marketing automation priorities, and allow for the rollout of a platform that’s highly likely to satisfy all stakeholder needs.

      If you would like additional support, have our analysts guide you through other phases as part of an Info-Tech workshop.

      Contact your account representative for more information.
      workshops@infotech.com
      1-888-670-8889

      Insight summary

      Stakeholder satisfaction is critical to your success

      Choosing a solution for a single use case and then expanding it to cover other purposes can be a way to quickly gain approvals and then make effective use of dollars spent. However, this can also be a nightmare if the product is not fit for purpose and requires significant customization effort for future use cases. Identify use cases early, engage stakeholders to define success, and recognize where you need to find balance between a single off-the-shelf CRM platform and adjacent MarTech or sales enablement systems.

      Build a business case

      An effective business case isn’t a single-purpose document for obtaining funding. It can also be used to drive your approach to product selection, requirements gathering, and ultimately evaluating stakeholder and user satisfaction.

      Use your business case to define use cases and milestones as well as success.

      Balance process with technology

      A new solution with old processes will result in incremental increased value. Evaluate existing processes and identify opportunities to improve and remove workarounds. Then define requirements.

      You may find that the tools you have would be adequate with an upgrade and tool optimization. If not, this exercise will prepare you to select the right solution for your current and future needs.

      Drive toward early value

      Lead with the most important benefit and consider the timeline. Most stakeholders will lose interest if they don’t realize benefits within the fist year. Can you reach your goal and report success within that timeline?

      Identify secondary, incremental customer engagement improvements that can be made as you work toward the overall goal to be achieved at the one-year milestone.

      Related Info-Tech Research

      Stock image of an office worker. Build a Strong Technology Foundation for Customer Experience Management
      • Any CRM project needs to be guided by the broader strategy around customer engagement. This blueprint explores how to create a strong technology enablement approach for CXM using voice of the customer analysis.
      Stock image of a target with arrows. Improve Requirements Gathering
      • 70% of projects that fail do so because of poor requirements. If you need to double-click on best practices for eliciting, analyzing, and validating requirements as you build up your CRM picklist and RFP, this blueprint will equip you with the knowledge and tools you need to hit the ground running.
      Stock image of a pen on paper. Drive Successful Sourcing Outcomes with a Robust RFP Process
      • Managing a complex RFP process for an enterprise application like a CRM platform can be a challenging undertaking. This blueprint zooms into how to build, run, administer, and evaluate RFP responses effectively.

      Bibliography

      “Doomed From the Start? Why a Majority of Business and IT Teams Anticipate Their Software Development Projects Will Fail.” Geneca, 25 Jan. 2017. Web.

      Hall, Kerrie. “The State of CRM Data Management 2020.” Validity. 27 April 2020. Web.

      Hinchcliffe, Dion. “The Evolving Role of the CIO and CMO in Customer Experience.” ZDNet, 22 Jan. 2020. Web.

      Klie, L. “CRM Still Faces Challenges, Most Speakers Agree: CRM Systems Have Been Around for Decades, but Interoperability and Data Siloes Still Have to Be Overcome.” CRM Magazine, vol. 23, no. 5, 2019, pp. 13-14.

      Markman, Jon. "Netflix Knows What You Want... Before You Do." Forbes. 9 Jun. 2017. Web.

      Morgan, Blake. “50 Stats That Prove The Value Of Customer Experience.” Forbes, 24 Sept. 2019. Web.

      Taber, David. “What to Do When Your CRM Project Fails.” CIO Magazine, 18 Sept. 2017. Web.

      “The State of Project Management Annual Survey 2018.” Wellingtone, 2018. Web.

      “The History of Microsoft Dynamics.” Eswelt. 2021. Accessed 8 June 2022.

      “Unlock the Mysteries of Your Customer Relationships.” Harvard Business Review. 1 July 2014. Accessed 30 Mar. 2016.

      The Complete Manual for Layoffs

      • Buy Link or Shortcode: {j2store}514|cart{/j2store}
      • member rating overall impact: 10.0/10 Overall Impact
      • member rating average dollars saved: $30,999 Average $ Saved
      • member rating average days saved: 20 Average Days Saved
      • Parent Category Name: Lead
      • Parent Category Link: /lead

      When the economy is negatively influenced by factors beyond any organization’s control, the impact can be felt almost immediately on the bottom line. This decline in revenue as a result of a weakening economy will force organizations to reconsider every dollar they spend.

      Our Advice

      Critical Insight

      • The remote work environment many organizations find themselves in adds a layer of complexity to the already sensitive process of laying off employees.
      • Carrying out layoffs must be done while keeping personal contact as your first priority. That personal contact should be the basis for all subsequent communication with laid-off and remaining staff, even after layoffs have occurred.

      Impact and Result

      By following our process, we can provide your organization with the direction, tools, and best practices to lay off employees. This will need to be done with careful consideration into your organization’s short- and longer-term strategic goals.

      The Complete Manual for Layoffs Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Prepare for layoffs

      Understand the most effective cost-cutting solutions and set layoff policies and guidelines.

      • The Complete Manual for Layoffs Storyboard
      • Layoffs SWOT Analysis Template
      • Redeployment and Layoff Strategy Workbook
      • Sample Layoffs Policy
      • Cost-Cutting Planning Tool
      • Termination Costing Tool

      2. Objectively identify employees

      Develop an objective layoff selection method and plan for the transfer of essential responsibilities.

      • Workforce Planning Tool
      • Employee Layoff Selection Tool

      3. Prepare to meet with employees

      Plan logistics, training, and a post-layoff plan communication.

      • Termination Logistics Tool
      • IT Knowledge Transfer Risk Assessment Tool
      • IT Knowledge Transfer Plan Template
      • IT Knowledge Identification Interview Guide Template
      • Knowledge Transfer Job Aid
      • Layoffs Communication Package

      4. Meet with employees

      Collaborate with necessary departments and deliver layoffs notices.

      • Employee Departure Checklist Tool

      5. Monitor and manage departmental effectiveness

      Plan communications for affected employee groups and monitor organizational performance.

      • Ten Ways to Connect With Your Employees
      • Creating Connections
      [infographic]

      Take Advantage of Big Tech Layoffs

      • Buy Link or Shortcode: {j2store}573|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Attract & Select
      • Parent Category Link: /attract-and-select

      Tech layoffs have been making the news over the past year, with thousands of Big Tech employees having been laid off. After years of record low unemployment in IT, many leaders are looking to take advantage of these layoffs to fill their talent gaps.

      However, IT leaders need to determine their response – wait and see the impact of the recession on budgets and candidate expectations, or dive in and secure great talent to execute today on strategic needs. This research is designed to help those IT leaders who are looking to take advantage employee effective talents to secure talent.

      • With the impact of the economic slowdown still unknown, the first question IT leaders need to ask is whether now is the time to act.
      • Even with these layoffs, IT unemployment rates are at record lows, with many organizations continuing to struggle to attract talent. While these layoffs have opened a window, IT leaders need to act quickly to secure great talent.

      Our Advice

      Critical Insight

      The “where has the talent gone?” puzzle has been solved. Many tech firms over-hired and were able to outcompete everyone, but it wasn’t sustainable. This correction won’t impact unemployment numbers in the short term – the job force is just in flux right now.

      Impact and Result

      This research is designed to help IT leaders understand the talent market and to provide winning tactics to those looking to take advantage of the layoffs to fill their hiring needs.

      Take Advantage of Big Tech Layoffs Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Take Advantage of Big Tech Layoffs Storyboard – A snapshot of the current talent market in IT and quick tactics IT leaders can employ to improve their hiring process to find and attract tech talent.

      Straightforward tactics you can execute to successfully recruit IT staff impacted by layoffs.

      • Take Advantage of Big Tech Layoffs Storyboard

      2. IT Talent Acquisition Optimization Tool – Use this tool to document the current and future talent acquisition process.

      To hire efficiently, create a clear, consistent talent acquisition process. The IT Talent Acquisition Process Optimization Tool will help to:

    • Map out the current talent acquisition workflow
    • Identify areas of opportunity and potential gaps in the current process
      • IT Talent Acquisition Optimization Tool
      [infographic]

      Further reading

      Take Advantage of Big Tech Layoffs

      Simple tactics to secure the right talent in times of economic uncertainty.

      Why are the layoffs making the news?

      After three years of record low unemployment rates in IT and organizations struggling to hire IT talent into their organization, the window appears to be opening with tens of thousands layoffs from Big Tech employers.

      Big brand organizations such as Microsoft, Alphabet, Amazon, Twitter, Netflix, and Meta have been hitting major newswires, but these layoffs aren't exclusive to the big names. We've also seen smaller high-growth tech organizations following suit. In fact, in 2022, it's estimated that there were more than 160,997 layoffs across over 1,045 tech organizations. This trend has continued into 2023. By mid-February 2023, there were already 108,754 employees laid off at 385 tech companies (Layoffs.fyi).(1)

      While some of these layoffs have been openly connected to economic slowdown, others are pointing to the layoffs being a correction for over-hiring during the pandemic. It is also important to note that many of these workers were not IT employees, as these organizations also saw cuts across other areas of the business such as sales, marketing, recruitment, and operations.

      (1)This global database is constantly being updated, and these numbers are changing on an ongoing basis. For up-to-date statistics, see https://layoffs.fyi

      While tech layoffs have been making the news, so far many of these layoffs have been a correction to over-hiring, with most employees laid off finding work, if they want it, within three months.

      IT leaders need to determine their response – wait and see the impact of the recession on budgets and candidate expectations or dive in and secure great talent to execute today on strategic needs.

      This research is designed to help IT leaders understand the talent market and provide winning strategies to those looking to take advantage of the layoffs to fill their hiring needs.

      Three key drivers for Big Tech layoffs

      Economic uncertainty

      Globally, economists are predicting an economic slowdown, though there is not a consistent prediction on the impact. We have seen an increase in interest rates and inflation, as well as reduced investment budgets.

      Over-hiring during the pandemic

      High growth and demand for digital technologies and services during the early pandemic led to over-hiring in the tech industry. Many organizations overestimated the future demand and had to rebalance staffing as a result.

      New automation investments

      Many tech organizations that have conducted layoffs are still in a growth mindset. This is demonstrated though new tech investments by these companies in products like chatbots and RPA to semi-automate processes to reduce the need for certain roles.

      Despite layoffs, the labor market remains competitive

      There were at least 160,997 layoffs from more than 1,045 tech companies last year (2022). (Layoffs.fyi reported as of Feb 21/2023)

      But just because Big Tech is laying people off doesn't mean the IT job market has cooled.

      Between January and October 2022 technology- focused job postings rose 25% compared to the same period in 2021, and there were more than 375,000 tech jobs posted in October of 2022.
      (Dice: Tech Jobs Report.)

      Info-Tech Insight

      The "where has the talent gone?" puzzle has been solved. Many tech firms over-hired and were able to outcompete everyone, but it wasn't sustainable. This correction won't impact unemployment numbers in the short term – the job force is just in flux right now.

      So far, many of the layoffs have been a market correction

      Tech Layoffs Since COVID-19

      This is an image of a combo line graph plotting the number of tech layoffs from Q1 2020 to Q4 2022.

      Source: Layoffs.fyi - Tech Layoff Tracker and Startup Layoff Lists

      Tech Companies Layoffs vs. Early Pandemic Hiring # of People

      This is an image of a bar graph plotting Tech Companies Layoffs vs. Early Pandemic Hiring # of People

      Source: Yahoo Finance. Q4 '19 to Q3 '22

      Tech Layoffs between 2020 Q3- 2022 Q1 remained very low across the sector. In fact, outside of the initial increase at the start of the pandemic, layoffs have remained at historic low levels of around 1% (HBR, 2023). While the layoffs look significant in isolation, when you compare these numbers to pandemic hiring and growth for these organizations, the figures are relatively small.

      The first question IT leaders need to ask is whether now is the time to act

      The big gamble many CIOs face is whether to strike now to secure talent or to wait to better understand the impact of the recession. While two-thirds of IT professionals are still expecting their budgets to increase in 2023, CIOs must account for the impact of inflation and the recession on their IT budgets and staffing decisions (see Info-Tech's CEO-CIO Alignment Program).

      Ultimately, while unemployment is low today, it's common to see unemployment numbers drop right before a recession. If that is the case, then we will see more talent entering the market, possibly at more competitive salaries. But organizations that wait to hire risk not having the staff they need to execute on their strategy and finding themselves in a hiring freeze. CIOs need to decide on how to approach the economic uncertainty and where to place their bets.

      Looking ahead to 2023, how do you anticipate your IT spending will change compared to spending in 2022?

      This is an image of anticipated changes to IT spending compared to 2022 for the following categories: Decrease of more than 30%; Decrease between 16-30%; Decrease between 6-15%; Decrease between 1-5%; No Change; Increase between 1-5%; Increase between 6-15%; Increase between 16-30%; Increase of more than 30%

      Info-Tech's CEO-CIO Alignment Program

      Organizations ready to take advantage will need to act fast when layoffs happen

      Organizations looking to fill hiring needs or grow their IT/digital organization will need to be strategic and efficient when it comes to recruitment. Regardless of the number of layoffs, it continues to be an employee market when it comes to IT roles.

      While it is likely that the recession will impact unemployment rates, so far, the market remains hot, and the number of open roles continues to grow. This means that organizations that want to take advantage need to act quickly when news hits.

      Leaders not only need to compete with other organizations for talent, but the other challenge hiring organizations will need to compete with is that many in tech received generous severance packages and will be considering taking time off. To take advantage, leaders need to establish a plan and a clear employee value proposition to entice these highly skilled workers to get off the bench.

      Why you need to act fast:

      • Unemployment rates remain low:
        • Tech unemployment's rates in the US dropped to 1.5% in January 2023 (CompTIA), compared to overall unemployment which is at 3.4% in the US as of January 2023 (Yahoo Finance). While the layoffs look significant, we can see that many workers have been rehired into the labor market.
      • Long time-to-hire results in lost candidates:
        • According to Info-Tech's IT Talent Trend Report, 58% of IT leaders report time-to-hire is longer than two months. This timing increases for tech roles which require unique skills or higher seniority. IT leaders who can increase the timeline for their requirement process are much more likely to be able to take advantage of tech layoffs.

      IT must take a leading role in IT recruitment to take advantage of layoffs

      A personal connection is the differentiator when it comes to talent acquisition

      There is a statistically significant relationship between IT leadership involvement in talent acquisition and the effectiveness of this process in the IT department. The more involved they are, the higher the effectiveness.(1)

      More IT leadership involvement

      An image of two upward facing arrows. The left arrow is faded purple, and the right arrow is dark purple.

      Higher recruitment effectiveness

      Involved leaders see shorter times to hire

      There is a statistically significant relationship between IT leadership involvement in the talent acquisition process and time to fill vacant positions. The more involved they are, the shorter the time to hire.(2)

      Involved leaders are an integral part of effective IT departments

      There is a statistically significant relationship between IT leadership involvement in talent acquisition and overall IT department effectiveness. Those that are more involved have higher levels of effectiveness.(3)

      Increased IT Leadership in Recruitment Is Directly Correlated to Recruitment Effectiveness.

      This is an image of a combo bar graph plotting Overall Effectiveness for IT leadership involvement in recruitment.

      Focus your layoff recruitment strategy on critical and strategic roles

      If you are ready to take advantage of tech layoffs, focus hiring on critical and strategic roles, rather than your operational backfills. Roles related to security, cloud migration, data and analytics, and digital transformation are more likely to be shielded from budget cuts and are logical areas to focus on when looking to recruit from Big Tech organizations.

      Additionally, within the IT talent market, scarcity is focused in areas with specialized skill sets, such as security and architecture, which are dynamic and evolving faster than other skill sets. When looking to recruit in these areas, it's critical that you have a targeted recruitment approach; this is why tech layoffs represent a strong opportunity to secure talent in these specialized areas.

      ROLES DIFFICULT TO FILL

      An image of a bar graph plotting roles by difficulty to fill.

      Info-Tech Talent Trends 2022 Survey

      Four quick tactics to take advantage of Big Tech layoffs

      TALENT ACQUISITION PROCESS TO TAKE ADVANTAGE OF LAYOFFS

      This is an image of the talent acquisition process to take advantage of layoffs. It involves the following four steps: 1 Prepare organization and job ads for recruitment.  2 Actively track and scan for layoff activity.  3 Prioritize and screen candidates using salary benchmarks and keywords.  4 Eliminate all unnecessary hiring process steps.

      Guided Implementation

      What does a typical GI on this topic look like?

      Step 1 Step 2 Step 3 Step 4

      Call #1: Scope requirements, objectives, and your specific challenges.

      Call #2: IT job ad review.

      Call #4: Identify screening and sourcing opportunities.

      Call #5: Review your IT talent acquisition process.

      Call #3: Employee value proposition review.

      Call #7: Refine your talent acquisition process.

      A Guided Implementation (GI) is a series of calls with an Info-Tech analyst to help implement our best practices in your organization.

      A typical GI is 8 to 12 calls over the course of 4 to 6 months.

      Tactics to take advantage of tech layoffs

      Activities

      1.1 Spot check your employee value proposition
      1.2 Update job advertisements
      1.3 Document your talent acquisition process
      1.4 Refine your talent acquisition process

      This step involves the following participants:

      • IT executive leadership
      • IT hiring manager
      • Human resources
      • Marketing/public relations

      Outcomes of this step

      Streamlined talent acquisition process tailored to take advantage of tech layoffs.

      This is an image of the talent acquisition process to take advantage of layoffs. It involves the following fo steps: 1 Prepare organization and job ads for recrtment.  2 Actively track and scan for layoff aivity.  3 Prioritize and screen candidates using salary benchmarks and kwords.  4 Eliminate all unnecessary hiring process steps.

      Requisition: update job ads and secure approval to hire

      Critical steps:

      1. Ensure you have secured budget and hiring approval.
      2. Identify an IT recruitment partner within the IT organization who will be accountable for working with HR throughout the process and who will actively track and scan for recruitment opportunities.
      3. Update your IT job descriptions.
      4. Spot check your employee value proposition (EVP) to appeal to targeted candidates (Exercise 1.1).
      5. Write employee job ads for relevant skills and minimum viable experience (Exercise 1.2).
      6. Work with HR to develop your candidate outreach messages – ensure that your outreach is empathetic, aligns with your EVP, and focuses on welcoming them to apply to a role.

      The approval process to activate a requisition can be one of the longest stages in the talent acquisition process. Ensure all your roles are up to date and approved so you can trigger outreach as soon as news hits; otherwise, you'll be late before you've even begun.

      Your employee value proposition (EVP) is a key tool for attracting and retaining talent

      Any updates to your EVP need to be a genuine reflection of the employee experience at your organization – and should resonate internally and externally.

      Internal (retention) perspective: These characteristics help to retain new and existing talent by ensuring that new hires' expectations are met and that the EVP is experienced throughout the organization.

      External (attraction) perspective: These characteristics help to attract talent and are targeted so the right candidates are motivated to join, while those who aren't a good fit will self-select out.

      McLean & Company's Employee Value Proposition Framework

      This is an image of McLean & Company's Employee Value Proposition Framework.  It is divided into Retain and Attract.  under Retain, are the following three headings: Aligned; Accurate; Aspirational.  Under Attract are: Compelling; Clear; Comprehensive.

      Source: McLean & Company

      1.1 Spot check your EVP

      1-3 hours

      1. Review your existing IT employee value proposition. If you do not have an EVP, see Info-Tech's comprehensive research Improve the IT Recruitment Process to draft a new EVP.
      2. Invite a representative group of employees to participate in a working group to improve your employee value proposition. Ask each participant to brainstorm the top five things they value most about working at the organization.
      3. Consider the following categories: work environment, career advancement, benefits, and ESG and diversity impact. Brainstorm as a group if there is anything unique your organization offers with regard to these categories.
      4. Compare your notes to your existing EVP, identify up to four key statements to focus on for the EVP, ensuring that your EVP speaks to at least one of the categories above. Remove any statements that no longer speak to who you are as an organization or what you offer.

      Input

      • Existing employee value proposition
      • Employee Engagement Surveys (If Available)

      Output

      • Updated employee value proposition

      Materials

      • Whiteboard/flip charts
      • Job ad template

      Participants

      • Representative group of internal employees.
      • HR
      • Marketing/PR (if possible)

      Four critical factors considered by today's job seeker

      1. Be specific about remote work policies: Include verbiage about whether there is an option to work hybrid or remote. 81% of job seekers stated that whether a job is remote, hybrid, or in-person was a top factor in whether they'd accept an offer (Benefits Canada, 2022).
      2. Career advancement and stability: "37% of Gen Z employees and 25% of millennial employees are currently looking for a job that offers career progression transparency — or, in other words, a job with clear opportunities for growth. This is significantly higher than our findings for older generations Gen X (18%) and baby boomers (7%)," (Lattice, 2021).
      3. Unique benefits: Consider your unique benefits – it's not the Big Tech "fun perks" like slides and ping pong that drive interest. Employees are increasingly looking for roles with long-term benefits programs. 90% of job seekers consider higher pension contributions to be a key factor, and 85% are considering bonuses/profit sharing" (Benefits Canada, 2022). Candidates may accept lower total compensation in exchange for flexibility, culture, work/life balance that was lacking in the start-up scene or the mega-vendors' fast-paced world.
      4. ESG and diversity impact: Include details of how the candidate will make a societal impact through their role, and how the company is acting on climate and sustainability. "Nearly two in five [Gen Z's and millennials] say they have rejected a job or assignment because it did not align with their values," (Deloitte Global, 2022).

      Update or establish job ads for candidate outreach

      Take the time up front to update your IT job descriptions and to write effective job advertisements. A job advertisement is an external-facing document that advertises a position with the intent of attracting job applicants. It contains key elements from the job description as well as information on the organization and its EVP. A job description informs a job ad, it doesn't replace it.
      When updating job descriptions and job ads, it's critical that your requirements are an accurate representation of what you need in the position. For the job ads especially, focus on the minimum requirements for the role, highlight your employee value proposition, and ensure that they are using inclusive language.
      Don't be lulled into using a job description as a posting when there's a time crunch to fill a position – use your preparation time to complete this key step.

      Three tips to consider when building a job ad

      Include the minimum desired requirements

      Include the required skills, responsibilities, and certifications required. Instead of looking for a unicorn, look for what you need and a demonstrated ability to learn. 70% of business executives say they are getting creative about sourcing for skills rather than just considering job experience (Deloitte Insights, 2022).

      Strategically include certifications

      When including certifications, ensure you have validated the process to be certified – i.e. if you are hiring for a role with 3-5 years' experience, ensure that the certification does not take 5-10 years of experience be eligible.

      Use inclusive language

      Consider having a review group within your IT organization to ensure the language is inclusive, that the responsibilities don't read as overly complex, and that it is an accurate representation of the organization's culture.

      1.2 Update or build job ads

      1-3 hours

      1. Begin with a copy of the job ad you are looking to fill, if you haven't begun to draft the role, start with Info-Tech's Job Description Library and Info-Tech's Job Ad Template.
      2. Review the job accountabilities, rank each responsibility based on its importance and volume of work. Determine if there are any responsibilities that are uncommon to be executed by the role and remove unnecessary responsibilities.
      3. For each of the job accountabilities, identify if there is a level of experience, knowledge or competency that would be the minimum bar for a candidate. Remove technical skills, specific technologies, and competencies that aren't directly relevant to the role, responsibilities or values.
      4. Review the education and requirements, and ensure that any certification or educational background is truly needed or suggested.
      5. Use the checklist on the following tab to review and update your job ad.

      Input

      • Job description
      • Employee value proposition
      • Job ad template

      Output

      • Completed job ad

      Materials

      • Whiteboard/flip charts
      • Web share

      Participants

      • Representative group of internal employees.
      • HR
      • Marketing/PR (if possible)

      1.2 Job ad checklist:

      A job ad needs to be two things: effective and inclusive.

      Effective

      The job ad does include:

      The organization's logo.
      Description of the organization.
      Information about benefits.
      A link to the organization's website and social media platforms.
      Steps in the application process and what candidates can expect.

      The job ad:

      Paints an accurate picture of key aspects of the role.
      Tells a story to show potential candidates how the role and organization will fit into their career path (outlines potential career paths, growth opportunities, training, etc.).
      Does not contain too many details and tasks that would overwhelm applicants.
      Highlights the employer brand in a manner that conveys the EVP and markets the organization to attract potential applicants.
      Includes creative design or formatting to make the ad stand out.
      The job ad speaks to the audience by using targeted language (e.g. using creative language when recruiting for a creative role).
      The job ad has been reviewed by HR, Marketing, PR.

      Inclusive

      The job ad does NOT include:

      Industry jargon or abbreviations that are not spelled out.
      Personality characteristics and unnecessary adjectives that would deter qualified candidates (e.g. extroverted, aggressive, competitive).
      A list of specific academic disciplines or schools, GPA requirements, or inflated degree requirements.

      The job ad:

      Uses gender-neutral language and does not contain terms that indicate traits that are typically associated with a specific gender.
      Can be viewed and applications can be completed on mobile devices.
      Focuses on results, day-to-day requirements, competencies, and transferrable skills.
      Includes design that is accessible (e.g. alternative text is provided for images, clear posting structure with headings, color is not used to convey information).

      Sourcing: Set up news trackers and review layoff source lists

      • Set up news and social media trackers to track layoff updates, and ensure you have an IT staff member on standby to complete a more detailed opportunity analysis when layoffs happen.
      • Use layoff source lists such as Layoffs.fyi to actively track organizations that have laid people off, noting the industry, location, and numbers in order to identify potential candidates. Limit your future analysis to locations that would be geographically possible to hire from.
      • Review open-source lists of laid-off employees to quickly identify potential candidates for your organization.
      • Many organizations that have completed layoffs have established outplacement programs to help laid-off staff find new roles. Set a plan in motion with HR to reach out to organizations once a layoff has occurred to understand their layoff support program.

      The key to successful sourcing is for IT to take an active role in identifying which organizations impacted by layoffs would be a good fit, and to quickly respond by searching open-source lists and LinkedIn to reach out potential candidates.

      Consider leveraging open-source lists

      Layoffs.fyi has been tracking and reporting on layoffs since the start of COVID-19. While they are not an official source of information, the site has more than a million views per month and is a strong starting point for IT leaders looking to source candidates from tech layoffs beyond the big organizations that are making the news.

      The site offers a view of companies with layoffs by location, industry, and the source of the info. Additionally, it often lists the names and contact information of laid-off employees, which you can leverage to start your deeper LinkedIn outreach or candidate screening.

      This is an image of two screenshots of open source lists from Layoffs.fyi

      Screenshots from Layoffs.fyi.

      Screening: Prioritize by considering salary benchmarks and keywords

      • Determine a set of consistent pre-screening questions to leverage while screening candidates, which every candidate must answer, including knockout questions.
      • Prioritize by going for salary ranges you can afford: It is important to be aware of what companies are paying within the tech arena, so you know if your salary bands are within a competitive range.
      • Pre-screen resumes using appropriate keywords that are critical for the role, and widen the terms if you do not have enough candidates. Given the pool you are looking to recruit from, consider removing criteria specifically related to education or certifications; instead, prioritize skills and on-the-job experience.

      Screening is one of the most time-consuming stages of the TA process. For each open position, it can take 23 hours to screen resumes (Toolbox, 2021). In fact, 52% of TA leaders believe that screening candidates from a large pool of applicants is the hardest part of recruitment (Ideal, 2021).

      Compensation comparison reports

      Keep in mind that the market may be shifting rapidly as layoffs proliferate, so what the data shows, particularly on free-to-use sites with little data-checking, may not be current and may be overstated. Info-Tech does not provide salary analysis; however, there are publicly available reports and online websites with self-reported data.

      This list contains several market data sources for the tech industry, which may be a good starting point for comparison. Info-Tech is not affiliated with or endorsing any of these market data sources.

      Aon Global Cyber Security Compensation and Talent Survey
      Aon – Radford Surveys Radford Global Technology Survey
      Culpepper Comprehensive Compensation Survey Solution for Technology-Focused Companies
      Modis 2022 IT Compensation Guide
      Motion Recruitment 2023 Tech Salary Guide
      Mondo 2022 Salary Guide for roles & jobs across the technology, creative & digital marketing industries.
      Willis Towers Watson Willis Towers Watson Data Services - Artificial Intelligence and Digital Talent
      Willis Towers Watson 2022 Artificial Intelligence and Digital Talent Survey Report - Canada
      Willis Towers Watson 2022 Artificial Intelligence and Digital Talent Survey Report - U.S.
      Michael Page Salary Guide 2022 for the Greater Toronto Area Technology Industry
      Willis Towers Watson Willis Towers Watson Data Services - Tech, Media, and Gaming
      Willis Towers Watson 2022 Tech, Media and Gaming Executive Survey Report - Canada
      Willis Towers Watson 2022 Tech, Media and Gaming Middle Management, Professional and Support Survey Report - Canada
      Willis Towers Watson 2022 Tech, Media and Gaming Executive Survey Report - U.S.
      Willis Towers Watson 2022 Tech, Media and Gaming Middle Management, Professional and Support Survey Report - U.S.

      Work with your HR partner to streamline your talent acquisition process

      A slow talent acquisition process presents multiple risks to your ability to recruit. Candidates are likely having multiple hiring conversations, and you could lose a good candidate just by being slower than another organization. Additionally, long hiring processes are also an indicator of a high level of bureaucracy in an organization, which may turn off tech candidates who are used to faster-paced decision making.

      Reducing your time-to-hire needs to be a strategic priority, and companies that manage to do this are reaping the benefits: There is a statistically significant relationship between time to fill vacant positions and overall IT department effectiveness. The shorter the time to fill a position, the higher the effectiveness (Bika, 2019).

      Key Considerations for Optimizing your Talent Acquisition Process

      Key Considerations for Optimizing your Talent Acquisition Process

      Review the end-to-end experience

      50%

      of job seekers surveyed had "declined a job offer due to poor [candidate] experience," (Echevarria, 2020).

      Reduce the time to hire

      55%

      "of candidates believe that it should take one to two weeks from the first interview to being offered the job," (Duszyński, 2021).

      Be clear on Timelines

      83%

      "of candidates say it would greatly improve the overall experience if employers provided a clear timeline of the hiring process," (Miller, n.d.).

      Time to hire: Identify solutions to drive efficient hiring

      1. Document all steps between screening and hiring and remove any unnecessary steps.
      2. Create clearly defined interview guides to ensure consistent questioning by interviewers.
      3. Enable hiring managers to schedule their own interviews.
      4. Determine who needs to approve an offer. Streamline the number of approvals, if possible.
      5. Eliminate unnecessary background checks. Many companies have eliminated reference checks, for example, after determining that it was it was not adding value to their decision.
      6. Identify and track key metrics across your talent acquisition process.

      It is critical to partner with your HR department on optimizing this process, as they are typically the process owners and will have deep knowledge of the rationale for decisions. Together, you can identify some opportunities to streamline the process and improve the time to hire.

      4.1 Document your TA process

      1-3 hours

      1. If you have a documented talent acquisition process, begin with that; if not, open the IT Talent Acquisition Process Optimization Tool and map the stages of the talent acquisition process with your HR leader. Stages are the top level in the process (e.g. requisition, sourcing, screening).
      2. Identify all the stakeholders involved in IT talent acquisition and document these in the tool.
      3. Next, identify the steps required for each stage. These are more detailed actions that together will complete the stage (e.g. enter requisition into ATS, intake meeting). Ask subject matter experts to add steps to their portion of the process and document these in the cells.
      4. For each step in the stage, record the time required and the number of people who are involved.

      Input

      • Existing talent acquisition (TA) process document
      • Any TA process metrics
      • Info-Tech's Talent Acquisition Process Optimization Tool

      Output

      • Documented TA process

      Materials

      • Info-Tech's Talent Acquisition Process Optimization Tool
      • Whiteboard/flip charts
      • Sticky notes

      Participants

      • HR
      • IT leaders
      • Hiring manager

      Download the IT Talent Acquisition Process Optimization Tool

      Example of steps in each stage of the TA process

      Activities

      Requisition

      Source

      Screen

      Interview & Assess

      Offer

      Background Check

      Vacancy identified Posted on website Resumes screened in system Interviews scheduled Offer letter drafted Reference checks conducted
      Requisition submitted Posted on job boards Resume screened by recruited First round interviews Offer letter sent Medical checks conducted
      Requisition approved Identification of layoff sources Resumed reviewed by hiring manager Assessment Negotiations Other background checks conducted
      Job description updated Review layoff source lists Screening calls Second round interview First date confirmed
      Job ad updated Screening questions developed Candidates selected
      Intake meeting

      4.2 Refine your TA process

      1-3 hours

      1. Collectively identify any:
        1. Inconsistent applications: Activities that are done differently by different participants.
        2. Bottlenecks: A place in the process where activity is constrained and holds up next steps.
        3. Errors: When a mistake occurs requiring extra time, resources, or rework.
        4. Lack of value: An activity that adds little to no value (often a legacy activity).
      2. Work with HR to identify any proposed solutions to improve consistency, reduce bottlenecks, errors, or eliminate steps that lack value. Document your proposed solutions in tab 3 of the IT Talent Acquisition Optimization Tool.
      3. Identify any new steps needed that would drive greater efficiency, including the tactics suggested in this research. Document any proposed solutions in tab 3.
      4. For each proposed solution, evaluate the general level of effort and impact required to move forward with that solution and select the appropriate classification from the drop-down.
      5. Determine if you will move forward with the proposed solution at this time. Update the TA workflow with your decisions.

      Input

      • Existing talent acquisition (TA) process document
      • Any TA process metrics
      • Info-Tech's Talent Acquisition Process Optimization Tool

      Output

      • Documented TA process

      Materials

      • Info-Tech's Talent Acquisition Process Optimization Tool
      • Whiteboard/flip charts
      • Sticky notes

      Participants

      • HR
      • IT leaders
      • Hiring manager

      Use Info-Tech's IT Talent Acquisition Optimization Tool to document current challenges & target solutions.

      Map your process and identify opportunities to streamline

      This is an image of the talent aquisitions workflow page from Info-Tech's Map your process and identify opportunities to streamline

      Brainstorm and select solutions to improve your process

      This is an image of the Effort Analysis page from Info-Tech's Brainstorm and select solutions to improve your process

      Key considerations when optimizing your process

      • Put yourself in each stakeholder's shoes (candidate, HR, hiring manager). Think through what they need from the process.
      • Challenge assumptions and norms. It can be tempting to get caught up in "how we do it today." Think beyond how it is today.
      • Question timing of activities and events. Identify if they are occurring when they need to.
      • Rebalance work to align with priorities. Identify if work can be redistributed or condensed to use time more efficiently.
      • Distinguish when consistency will add value and when there should be process flexibility.
      • Question the value. For each activity, ask "What value does this activity add?"

      Select metrics to measure Talent Acquisition process improvement

      METRICS INFORMATION
      Metric Definition Calculation
      Average applicants per posting The average number of applicants received per post. Number of applications / Number of postings
      Average number of interviews for open job positions Average number of interviews for open job positions. Total number of interviews / Total number of open job positions
      Average external time to fill Average number of calendar days from when the requisition is issued to when a candidate accepts the position from outside the organization. External days to fill / External candidates
      Pipeline throughput Percentage of candidates advancing through to the next stage. (Number of candidates in chosen stage / Number of candidates in preceding stage) * 100
      External offer acceptance rate Percentage of job offers extended to external candidates that were accepted. (Number of job offers that are accepted / Number of job offers extended) * 100
      Percentage of target group hired The percentage of a target group that was hired. Number of FTE hired / Target number of FTE to be hired
      Average time to hire Average number of calendar days between first contact with the candidate and when they accept the offer. Sum of number of days between first contact and offer acceptance / External candidates
      Quality of hire Percentage of new hires achieving a satisfactory appraisal at their first assessment. New hires who achieve a satisfactory rating at their first appraisal / Total number of new hires
      Vacancy rate Percentage of positions being actively recruited for at the end of the reporting period. Count of vacant positions / (Headcount + Vacant positions)

      Bibliography

      "81% of Employees Factoring Hybrid Work Into Job Search: Survey." BenefitsCanada.com, 16 June 2022.
      Andre, Louie. "40 Notable Candidate Experience Statistics: 2023 Job Application Trends & Challenges." Financesonline.Com, 15 Mar. 2023.
      Bika, Nikoletta. "Key Hiring Metrics: Useful Benchmarks for Tech Roles." Recruiting Resources: How to Recruit and Hire Better, 10 Jan. 2019.
      "Bureau of Labor Statistics Labor Market Revisions Contribute to Conflicting Signals in Latest Tech Employment Data, CompTIA Analysis Finds." CompTIA, 3 Feb. 2023. Press release.
      Byrnes, Amy. "ICIMS Insights Workforce Report: Time to Press the Reset Button?" ICIMS | The Leading Cloud Recruiting Software, 1 Dec. 2022.
      Cantrell, Sue, et al. "The Skills-Based Organization: A New Operating Model for Work and the Workforce." Deloitte Insights, 8 Sept. 2022.
      deBara, Deanna. "Top Findings from Lattice's Career Progression Survey." Lattice, 13 Sept. 2021. Accessed 16 Feb. 2023.
      Duszyński, Maciej. "Candidate Experience Statistics (Survey of 1,000+ Americans)." Zety, 14 Oct. 2019.
      Duszyński, Maciej. "Candidate Experience Statistics." Zety, 2021.
      Echevarria, Desiree. "2020 Candidate Experience Report." Career Plug, 17 Mar. 2021.
      Ghosh, Prarthana. "Candidate Screening and Selection Process: The Complete Guide for 2021." Spiceworks, 26 Feb. 2021. Accessed 22 Jun. 2021
      "Introduction - Dice Tech Job Report: Tech Hiring Trends by Location, Industry, Role and Skill." Accessed 16 Feb. 2023.
      Lee, Roger. "Tech Layoff Tracker and Startup Layoff Lists." Layoffs.fyi. Accessed 16 Feb. 2023.
      Miller, Kandace. "Candidate Experience And Engagement Metrics You Should Be Tracking." ConveyIQ, n.d. Accessed 16 Feb. 2023.
      Min, Ji-A. "Resume Screening: A How-To Guide for Recruiters." Ideal, 15 Mar. 2021. Web.
      Palmeri, Shelby. "2023 Candidate Experience Research: Strategies for Recruiting." CareerPlug, 6 Feb. 2023.
      Semenova, Alexandra. "Jobs Report: U.S. Economy Adds 517,000 Jobs in January, Unemployment Rate Falls to 3.4% as Labor Market Stuns." Yahoo!Finance, 3 Feb. 2023.
      Sozzi, Brian. "Big Tech Layoffs: What Companies Such as Amazon and Meta Have in Common." Yahoo!News, 6 Feb. 2023.
      Tarki, Atta. "Despite Layoffs, It's Still a Workers' Labor Market." Harvard Business Review, 30 Jan. 2023.
      The Deloitte Global 2022 Gen Z and Millennial Survey. Deloitte Global, 2022. Accessed 16 Feb. 2023.
      "Uncover the Employee Value Proposition." McLean & Company, 21 Jun. 2022. Accessed 22 Feb. 2023.

      Effectively Manage CxO Relations

      • Buy Link or Shortcode: {j2store}384|cart{/j2store}
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A
      • Parent Category Name: Manage Business Relationships
      • Parent Category Link: /manage-business-relationships

      With the exponential pace of technological change, an organization's success will depend largely on how well CIOs can evolve from technology evangelists to strategic business partners. This will require CIOs to effectively broker relationships to improve IT's effectiveness and create business value. A confidential journal can help you stay committed to fostering productive relationships while building trust to expand your sphere of influence.

      Our Advice

      Critical Insight

      Highly effective executives have in common the ability to successfully balance three things: time, personal capabilities, and relationships. Whether you are a new CIO or an experienced leader, the relentless demands on your time and unpredictable shifts in the organization’s strategy require a personal game plan to deliver business value. Rather than managing stakeholders one IT project at a time, you need an action plan that is tailored for unique work styles.

      Impact and Result

      A personal relationship journal will help you:

      • Understand the context in which key stakeholders operate.
      • Identify the best communication approach to engage with different workstyles.
      • Stay committed to fostering relationships through difficult periods.

      Effectively Manage CxO Relations Research & Tools

      Besides the small introduction, subscribers and consulting clients within this management domain have access to:

      1. Effectively Manage CxO Relations Storyboard – A guide to creating a personal action plan to help effectively manage relationships across key stakeholders.

      Use this research to create a personal relationship journal in four steps:

      • Effectively Manage CxO Relations Storyboard

      2. Personal Relationship Management Journal Template – An exemplar to help you build your personal relationship journal.

      Use this exemplar to build a journal that is readily accessible, flexible, and easy to maintain.

      • Personal Relationship Management Journal Template

      Infographic

      Further reading

      Effectively Manage CxO Relations

      Make relationship management a daily habit with a personalized action plan.

      Analyst Perspective

      "Technology does not run an enterprise, relationships do." – Patricia Fripp

      As technology becomes increasingly important, an organization's success depends on the evolution of the modern CIO from a technology evangelist to a strategic business leader. The modern CIO will need to leverage their expansive partnerships to demonstrate the value of technology to the business while safeguarding their time and effort on activities that support their strategic priorities. CIOs struggling to transition risk obsolescence with the emergence of new C-suite roles like the Digital Transformation Officer, Chief Digital Officer, Chief Data Officer, and so on.

      CIOs will need to flex new social skills to accommodate diverse styles of work and better predict dynamic situations. This means expanding beyond their comfort level to acquire new social skills. Having a clear understanding of one's own work style (preferences, natural tendencies, motivations, and blind spots) is critical to identify effective communication and engagement tactics.

      Building trust is an art. Striking a balance between fulfilling your own goals and supporting others will require a carefully curated approach to navigate the myriad of personalities and work styles. A personal relationship journal will help you stay committed through these peaks and troughs to foster productive partnerships and expand your sphere of influence over the long term.

      Photo of Joanne Lee
      Joanne Lee
      Principal, Research Director, CIO Advisory
      Info-Tech Research Group

      Executive Summary

      Your Challenge

      In today's unpredictable markets and rapid pace of technological disruptions, CIOs need to create business value by effectively brokering relationships to improve IT's performance. Challenges they face:

      • Operate in silos to run the IT factory.
      • Lack insights into their stakeholders and the context in which they operate.
      • Competing priorities and limited time to spend on fostering relationships.
      • Relationship management programs are narrowly focused on associated change management in IT project delivery.

      Common Obstacles

      Limited span of influence.

      Mistaking formal roles in organizations for influence.

      Understanding what key individuals want and, more importantly, what they don't want.

      Lack of situational awareness to adapt communication styles to individual preferences and context.

      Leveraging different work styles to create a tangible action plan.

      Perceiving relationships as "one and done."

      Info-Tech's Approach

      A personal relationship journal will help you stay committed to fostering productive relationships while building trust to expand your sphere of influence.

      • Identify your key stakeholders.
      • Understand the context in which they operate to define a profile of their mandate, priorities, commitments, and situation.
      • Choose the most effective engagement and communication strategies for different work styles.
      • Create an action plan to monitor and measure your progress.

      Info-Tech Insight

      Highly effective executives have in common the ability to balance three things: time, personal capabilities, and relationships. Whether you are a new CIO or an experienced leader, the relentless demand on your time and unpredictable shifts in the organization's strategy will require a personal game plan to deliver business value. This will require more than managing stakeholders one IT project at a time: It requires an action plan that fosters relationships over the long term.

      Key Concepts

      Stakeholder Management
      A common term used in project management to describe the successful delivery of any project, program, or activity that is associated with organizational change management. The goal of stakeholder management is intricately tied to the goals of the project or activity with a finite end. Not the focus of this advisory research.

      Relationship Management
      A broad term used to describe the relationship between two parties (individuals and/or stakeholder groups) that exists to create connection, inclusion, and influence. The goals are typically associated with the individual's personal objectives and the nature of the interaction is seen as ongoing and long-term.

      Continuum of Commitment
      Info-Tech's framework that illustrates the different levels of commitment in a relationship. It spans from active resistance to those who are committed to actively supporting your personal priorities and objectives. This can be used to baseline where you are today and where you want the relationship to be in the future.

      Work Style
      A reference to an individual's natural tendencies and expectations that manifest itself in their communication, motivations, and leadership skills. This is not a behavior assessment nor a commentary on different personalities but observable behaviors that can indicate different ways people communicate, interact, and lead.

      Glossary
      CDxO: Chief Digital Officer
      CDO: Chief Data Officer
      CxO: C-Suite Executives

      The C-suite is getting crowded, and CIOs need to foster relationships to remain relevant

      The span of influence and authority for CIOs is diminishing with the emergence of Chief Digital Officers and Chief Data Officers.

      63% of CDxOs report directly to the CEO ("Rise of the Chief Digital Officer," CIO.com)

      44% of organizations with a dedicated CDxO in place have a clear digital strategy versus 22% of those without a CDxO (KPMG/Harvey Nash CIO Survey)

      The "good news": CIOs tend to have a longer tenure than CDxOs.

      A diagram that shows the average tenure of C-Suites in years.
      Source: "Age and Tenure of C-Suites," Korn Ferry

      The "bad news": The c-suite is getting overcrowded with other roles like Chief Data Officer.

      A diagram that shows the number of CDOs hired from 2017 to 2021.
      Source: "Chief Data Officer Study," PwC, 2022

      An image of 7 lies technology executives tell ourselves.

      Info-Tech Insight

      The digital evolution has created the emergence of new roles like the Chief Digital Officer and Chief Data Officer. They are a response to bridge the skill gap that exists between the business and technology. CIOs need to focus on building effective partnerships to better communicate the business value generated by technology or they risk becoming obsolete.

      Create a relationship journal to effectively manage your stakeholders

      A diagram of relationship journal

      Info-Tech's approach

      From managing relationships with friends to key business partners, your success will come from having the right game plan. Productive relationships are more than managing stakeholders to support IT initiatives. You need to effectively influence those who have the potential to champion or derail your strategic priorities. Understanding differences in work styles is fundamental to adapting your communication approach to various personalities and situations.

      A diagram that shows from 1.1 to 4.1

      A diagram of business archetypes

      Summary of Insights

      Insight 1: Expand your sphere of influence
      It's not just about gaining a volume of acquaintances. Figure out where you want to spend your limited time, energy, and effort to develop a network of professional allies who will support and help you achieve your strategic priorities.

      Insight 2: Know thyself first and foremost
      Healthy relationships start with understanding your own working style, preferences, and underlying motivations that drive your behavior and ultimately your expectations of others. A win/win scenario emerges when both parties' needs for inclusion, influence, and connection are met or mutually conceded.

      Insight 3: Walk a mile in their shoes
      If you want to build successful partnerships, you need to understand the context in which your stakeholder operates: their motivations, desires, priorities, commitments, and challenges. This will help you adapt as their needs shift and, moreover, leverage empathy to identify the best tactics for different working styles.

      Insight 4: Nurturing relationships is a daily commitment
      Building, fostering, and maintaining professional relationships requires a daily commitment to a plan to get through tough times, competing priorities, and conflicts to build trust, respect, and a shared sense of purpose.

      Related Info-Tech Research

      Supplement your CIO journey with these related blueprints.

      Photo of First 100 Days as CIO

      First 100 Days as CIO

      Photo of Become a Strategic CIO

      Become a Strategic CIO

      Photo of Improve IT Team Effectiveness

      Improve IT Team Effectiveness

      Photo of Become a Transformational CIO

      Become a Transformational CIO

      Executive Brief Case Study

      Logo of Multicap Limited

      • Industry: Community Services
      • Source: Scott Lawry, Head of Digital

      Conversation From Down Under

      What are the hallmarks of a healthy relationship with your key stakeholders?
      "In my view, I work with partners like they are an extension of my team, as we rely on each other to achieve mutual success. Partnerships involve a deeper, more intimate relationship, where both parties are invested in the long-term success of the business."

      Why is it important to understand your stakeholder's situation?
      "It's crucial to remember that every IT project is a business project, and vice versa. As technology leaders, our role is to demystify technology by focusing on its business value. Empathy is a critical trait in this endeavor, as it allows us to see a stakeholder's situation from a business perspective, align better with the business vision and goals, and ultimately connect with people, rather than just technology."

      How do you stay committed during tough times?
      "I strive to leave emotions at the door and avoid taking a defensive stance. It's important to remain neutral and not personalize the issue. Instead, stay focused on the bigger picture and goals, and try to find a common purpose. To build credibility, it's also essential to fact-check assumptions regularly. By following these principles, I approach situations with a clear mind and better perspective, which ultimately helps achieve success."

      Photo of Scott Lawry, Head Of Digital at Multicap Limited

      Key Takeaways

      In a recent conversation with a business executive about the evolving role of CIOs, she expressed: "It's the worst time to be perceived as a technology evangelist and even worse to be perceived as an average CIO who can't communicate the business value of technology."

      This highlights the immense pressure many CIOs face when evolving beyond just managing the IT factory.

      The modern CIO is a business leader who can forge relationships and expand their influence to transform IT into a core driver of business value.

      Stakeholder Sentiment

      Identify key stakeholders and their perception of IT's effectiveness

      1.1 Identify Key Stakeholders

      A diagram of Identify Key Stakeholders

      Identify and prioritize your key stakeholders. Be diligent with stakeholder identification. Use a broad view to identify stakeholders who are known versus those who are "hidden." If stakeholders are missed, then so are opportunities to expand your sphere of influence.

      1.2 Understand Stakeholder's Perception of IT

      A diagram that shows Info-Tech's Diagnostic Reports and Hospital Authority XYZ

      Assess stakeholder sentiments from Info-Tech's diagnostic reports and/or your organization's satisfaction surveys to help identify individuals who may have the greatest influence to support or detract IT's performance and those who are passive observers that can become your greatest allies. Determine where best to focus your limited time amid competing priorities by focusing on the long-term goals that support the organization's vision.

      Info-Tech Insight

      Understand which individuals can directly or indirectly influence your ability to achieve your priorities. Look inside and out, as you may find influencers beyond the obvious peers or executives in an organization. Influence can result from expansive connections, power of persuasion, and trust to get things done.

      Visit Info-Tech's Diagnostic Programs

      Activity: Identify and Prioritize Stakeholders

      30-60 minutes

      1.1 Identify Key Stakeholders

      Start with the key stakeholders that are known to you. Take a 360-degree view of both internal and external connections. Leverage external professional & network platforms (e.g. LinkedIn), alumni connections, professional associations, forums, and others that can help flush out hidden stakeholders.

      1.2 Prioritize Key Stakeholders

      Use stakeholder satisfaction surveys like Info-Tech's Business Vision diagnostic as a starting point to identify those who are your allies and those who have the potential to derail IT's success, your professional brand, and your strategic priorities. Review the results of the diagnostic reports to flush out those who are:

      • Resisters: Vocal about their dissatisfaction with IT's performance and actively sabotage or disrupt
      • Skeptics: Disengaged, passive observers
      • Ambassadors: Aligned but don't proactively support
      • Champions: Actively engaged and will proactively support your success

      Consider the following:

      • Influencers may not have formal authority within an organization but have relationships with your stakeholders.
      • Influencers may be hiding in many places, like the coach of your daughter's soccer team who rows with your CEO.
      • Prioritize, i.e. three degrees of separation due to potential diverse reach of influence.

      Key Output: Create a tab for your most critical stakeholders.

      A diagram that shows profile tabs

      Download the Personal Relationship Management Journal Template.

      Understand stakeholders' business

      Create a stakeholder profile to understand the context in which stakeholders operate.

      2.1 Create individual profile for each stakeholder

      A diagram that shows different stakeholder questions

      Collect and analyze key information to understand the context in which your stakeholders operate. Use the information to derive insights about their mandate, accountabilities, strategic goals, investment priorities, and performance metrics and challenges they may be facing.

      Stakeholder profiles can be used to help design the best approach for personal interactions with individuals as their business context changes.

      If you are short on time, use this checklist to gather information:

      • Stakeholder's business unit (BU) strategy goals
      • High-level organizational chart
      • BU operational model or capability map
      • Key performance metrics
      • Projects underway and planned
      • Financial budget (if available)
      • Milestone dates for key commitments and events
      • External platforms like LinkedIn, Facebook, Twitter, Slack, Instagram, Meetup, blogs

      Info-Tech Insight

      Understanding what stakeholders want (and more importantly, what they don't) requires knowing their business and the personal and social circumstances underlying their priorities and behaviors.

      Activity: Create a stakeholder profile

      30-60 minutes

      2.1.0 Understand stakeholder's business context

      Create a profile for each of your priority stakeholders to document their business context. Review all the information collected to understand their mandate, core accountability, and business capabilities. The context in which individuals operate is a window into the motivations, pressures, and vested interests that will influence the intersectionality between their expectations and yours.

      2.1.1 Document Observable Challenges as Private Notes

      Crushing demands and competing priorities can lead to tension and stress as people jockey to safeguard their time. Identify some observable challenges to create greater situational awareness. Possible underlying factors:

      • Sudden shifts/changes in mandate
      • Performance (operations, projects)
      • Finance
      • Resource and talent gaps
      • Politics
      • Personal circumstances
      • Capability gaps/limitations
      • Capacity challenges

      A diagram that shows considerations of this activity.

      Analyze Stakeholder's Work Style

      Adapt communication styles to the situational context in which your stakeholders operate

      2.2 Determine the ideal approach for engaging each stakeholder

      Each stakeholder has a preferred modality of working which is further influenced by dynamic situations. Some prefer to meet frequently to collaborate on solutions while others prefer to analyze data in solitude before presenting information to substantiate recommendations. However, fostering trust requires:

      1. Understanding your preferred default when engaging others.
      2. Knowing where you need to expand your skills.
      3. Identifying which skills to activate for different professional scenarios.

      Adapting your communication style to create productive interactions will require a diverse arsenal of interpersonal skills that you can draw upon as situations shift. The ability to adapt your work style to dial any specific trait up or down will help to increase your powers of persuasion and influence.

      "There are only two ways to influence human behavior: you can manipulate it, or you can inspire it." – Simon Sinek

      Activity: Identify Engagement Strategies

      30 minutes

      2.2.0 Establish work styles

      Every individual has a preferred style of working. Determine work styles starting with self-awareness:

      • Express myself - How you communicate and interact with others
      • Expression by others - How you want others to communicate and interact with you

      Through observation and situational awareness, we can make inferences about people's work style.

      • Observations - Observable traits of other people's work style
      • Situations - Personal and professional circumstances that influence how we communicate and interact with one another

      Where appropriate and when opportunities arise, ask individuals directly about their preferred work styles and method for communication. What is their preferred method of communication? During a normal course of interaction vs. for urgent priorities?

      2.2.1 Brainstorm possible engagement strategies

      Consider the following when brainstorming engagement strategies for different work styles.

      A table of involvement, influence, and connection.

      Think engagement strategies in different professional scenarios:

      • Meetings - Where and how you connect
      • Communicating - How and what you communicate to create connection
      • Collaborating - What degree of involved in shared activities
      • Persuading - How you influence or direct others to get things done

      Expand New Interpersonal Skills

      Use the Business Archetypes to brainstorm possible approaches for engaging with different work styles. Additional communication and engagement tactics may need to be considered based on circumstances and changing situations.

      A diagram that shows business archetypes and engagement strategies.

      Communicate Effectively

      Productive communication is a dialogue that requires active listening, tailoring messages to fluid situations, and seeking feedback to adapt.

      A diagram of elements that contributes to better align intention and impact

      Be Relevant

      • Understand why you need to communicate
      • Determine what you need to convey
      • Tailor your message to what matters to the audience and their context
      • Identify the most appropriate medium based on the situation

      Be Consistent and Accurate

      • Say what you mean and mean what you say to avoid duplicity
      • Information should be accurate and complete
      • Communicate truthfully; do not make false promises or hide bad news
      • Don't gossip

      Be Clear and Concise

      • Keep it simple and avoid excessive jargon
      • State asks upfront to set intention and transparency
      • Avoid ambiguity and focus on outcomes over details
      • Be brief and to the point or risk losing stakeholder's attention

      Be Attentive and Authentic

      • Stay engaged and listen actively
      • Be curious and inquire for clarification or explanation
      • Be flexible to adapt to both verbal and non-verbal cues
      • Be authentic in your approach to sharing yourself
      • Avoid "canned" approaches

      A diagram of listen, observe, reflect.


      "Good communication is the bridge between confusion and clarity."– Nat Turner (LinkedIn, 2020)

      Exemplar: Engaging With Jane

      A diagram that shows Exemplar: Engaging With Jane

      Exemplar: Engaging With Ali

      A diagram that shows Exemplar: Engaging With Ali

      Develop an Action Plan

      Moving from intent to action requires a plan to ensure you stay committed through the peaks and troughs.

      Create Your 120-Day Plan

      An action plan example

      Key elements of the action plan:

      • Strategic priorities – Your top focus
      • Objective – Your goals
      • 30-60-90-120 Day Topics – Key agenda items
      • Meeting Progress Notes – Key takeaways from meetings
      • Private Notes – Confidential observations

      Investing in relationships is a long-term process. You need to accumulate enough trust to trade or establish coalitions to expand your sphere of influence. Even the strongest of professional ties will have their bouts of discord. To remain committed to building the relationship during difficult periods, use an action plan that helps you stay grounded around:

      • Shared purpose
      • Removing emotion from the situation
      • Continuously learning from every interaction

      Photo of Angela Diop
      "Make intentional actions to set intentionality. Plans are good to keep you grounded and focused especially when relationship go through ups and down and there are changes: to new people and new relationships."
      – Angela Diop, Senior Director, Executive Services, Info-Tech & former VP of Information Services with Unity Health Care

      Activity: Design a Tailored Action Plan

      30-60 minutes

      3.1.0 Determine your personal expectations

      Establish your personal goals and expectations around what you are seeking from the relationship. Determine the strength of your current connection and identify where you want to move the relationship across the continuum of commitment.

      Use insights from your stakeholder's profile to explore their span of influence and degree of interest in supporting your strategic priorities.

      3.1.1 Determine what you want from the relationship

      Based on your personal goals, identify where you want to move the relationship across the continuum of commitment: What are you hoping to achieve from the relationship? How will this help create a win/win situation for both you and the key stakeholder?

      A diagram of Continuum of Commitment.

      3.1.2 Identify your metrics for progress

      Fostering relationships take time and commitment. Utilizing metrics or personal success criteria for each of your focus areas will help you stay on track and find opportunities to make each engagement valuable instead of being transactional.

      A graph that shows influence vs interest.

      Make your action plan impactful

      Level of Connection

      The strength of the relationship will help inform the level of time and effort needed to achieve your goals.

      • Is this a new or existing relationship?
      • How often do you connect with this individual?
      • Are the connections driven by a shared purpose or transactional as needs arise?

      Focus on Relational Value

      Cultivate your network and relationship with the goal of building emotional connection, understanding, and trust around your shared purpose and organization's vision through regular dialogue. Be mindful of transactional exchanges ("quid pro quo") to be strategic about its use. Treat every interaction as equally important regardless of agenda, duration, or channel of communication.

      Plan and Prepare

      Everyone's time is valuable, and you need to come prepared with a clear understanding of why you are engaging. Think about the intentionality of the conversation:

      • Gain buy-in
      • Create transparency
      • Specific ask
      • Build trust and respect
      • Provide information to clarify, clear, or contain a situation

      Non-Verbal Communication Matters

      Communication is built on both overt expressions and subtext. While verbal communication is the most recognizable form, non-lexical components of verbal communication (i.e. paralanguage) can alter stated vs. intended meaning. Engage with the following in mind:

      • Tone, pitch, speed, and hesitation
      • Facial expressions and gestures
      • Choice of channel for engagement

      Exemplar: Action Plan for VP, Digital

      A diagram that shows Exemplar: Action Plan for VP, Digital

      Make Relationship Management a Daily Habit

      Management plans are living documents and need to be flexible to adapt to changes in stakeholder context.

      Monitor and Adjust to Communicate Strategically

      A diagram that shows Principles for Effective Communication and Key Measures

      Building trust takes time and commitment. Treat every conversation with your key stakeholders as an investment in building the social capital to expand your span of influence when and where you need it to go. This requires making relationship management a daily habit. Action plans need to be a living document that is your personal journal to document your observations, feelings, and actions. Such a plan enables you to make constant adjustments along the relationship journey.

      "Without involvement, there is no commitment. Mark it down, asterisk it, circle it, underline it."– Stephen Convey (LinkedIn, 2016)

      Capture some simple metrics

      If you can't measure your actions, you can't manage the relationship.

      An example of measures: what, why, how - metrics, and intended outcome.

      While a personal relationship journal is not a formal performance management tool, identifying some tangible measures will improve the likelihood of aligning your intent with outcomes. Good measures will help you focus your efforts, time, and resources appropriately.

      Keep the following in mind:

      1. WHAT are you trying to measure?
        Specific to the situation or scenario
      2. WHY is this important?
        Relevant to your personal goals
      3. HOW will you measure?
        Achievable and quantifiable
      4. WHAT will the results tell you?
        Intended outcome that is directional

      Summary of accomplishments

      Knowledge Gained

      • Relationship management is critical to a CIO's success
      • A personal relationship journal will help build:
        • Customized approach to engaging stakeholders
        • New communication skills to adapt to different work styles

      New Concepts

      • Work style assessment framework and engagement strategies
      • Effective communication strategies
      • Continuum of commitment to establish personal goals

      Approach to Creating a Personal Journal

      • Step-by-step approach to create a personal journal
      • Key elements for inclusion in a journal
      • Exemplar and recommendations

      Related Info-Tech Research

      Photo of Tech Trends and Priorities Research Centre

      Tech Trends and Priorities Research Centre

      Access Info-Tech's Tech Trend reports and research center to learn about current industry trends, shifts in markets, and disruptions that are impacting your industry and sector. This is a great starting place to gain insights into how the ecosystem is changing your business and the role of IT within it.

      Photo of Embed Business Relationship Management in IT

      Embed Business Relationship Management in IT

      Create a business relationship management (BRM) function in your program to foster a more effective partnership with the business and drive IT's value to the organization.

      Photo of Become a Transformational CIO

      Become a Transformational CIO

      Collaborate with the business to lead transformation and leave behind a legacy of growth.

      Appendix: Framework

      Content:

      • Adaptation of DiSC profile assessment
      • DiSC Profile Assessment
      • FIRO-B Framework
      • Experience Cube

      Info-Tech's Adaption of DiSC Assessment

      A diagram of business archetypes

      Info-Tech's Business Archetypes was created based on our analysis of the DiSC Profile and Myers-Briggs FIRO-B personality assessment tools that are focused on assessing interpersonal traits to better understand personalities.

      The adaptation is due in part to Info-Tech's focus on not designing a personality assessment tool as this is neither the intent nor the expertise of our services. Instead, the primary purpose of this adaptation is to create a simple framework for our members to base their observations of behavioral cues to identify appropriate communication styles to better interact with key stakeholders.

      Cautionary note:
      Business archetypes are personas and should not be used to label, make assumptions and/or any other biased judgements about individual personalities. Every individual has all elements and aspects of traits across various spectrums. This must always remain at the forefront when utilizing any type of personality assessments or frameworks.

      Click here to learn about DiSC Profile
      Click here learn about FIRO-B
      Click here learn about Experience Cube

      DiSC Profile Assessment

      A photo of DiSC Profile Assessment

      What is DiSC?

      DisC® is a personal assessment tool that was originally developed in 1928 by psychologist William Moulton Marston, who designed it to predict job performance. The tool has evolved and is now widely used by thousands of organizations around the world, from large government agencies and Fortune 500 companies to nonprofit and small businesses, to help improve teamwork, communication, and productivity in the workplace. The tool provides a common language people can use to better understand themselves and those they interact with - and use this knowledge to reduce conflict and improve working relationships.

      What does DiSC mean?

      DiSC is an acronym that stands for the four main personality profiles described in the Everything DiSC model: (D)ominance, (i)nfluence, (S)teadiness, (C)onscientiousness

      People with (D) personalities tend to be confident and emphasize accomplishing bottom-line results.
      People with (i) personalities tend to be more open and emphasize relationships and influencing or persuading others.
      People with (S) personalities tend to be dependable and emphasize cooperation and sincerity.
      People with (C) personalities tend to emphasize quality, accuracy, expertise, and competency.

      Go to this link to explore the DiSC styles

      FIRO-B® – Interpersonal Assessment

      A diagram of FIRO framework

      What is FIRO workplace relations?

      The Fundamental Interpersonal Relations Orientation Behavior (FIRO-B®) tool has been around for forty years. The tool assesses your interpersonal needs and the impact of your behavior in the workplace. The framework reveals how individuals can shape and adapt their individual behaviors, influence others effectively, and build trust among colleagues. It has been an excellent resource for coaching individuals and teams about the underlying drivers behind their interactions with others to effectively build successful working relationships.

      What does the FIRO framework measure?

      The FIRO framework addresses five key questions that revolve around three interpersonal needs. Fundamentally, the framework focuses on how you want to express yourself toward others and how you want others to behave toward you. This interaction will ultimately result in the universal needs for (a) inclusion, (b) control, and (c) affection. The insights from the results are intended to help individuals adjust their behavior in relationships to get what they need while also building trust with others. This will allow you to better predict and adapt to different situations in the workplace.

      How can FIRO influence individual and team performance in the workplace?

      FIRO helps people recognize where they may be giving out mixed messages and prompts them to adapt their exhibited behaviors to build trust in their relationships. It also reveals ways of improving relationships by showing individuals how they are seen by others, and how this external view may differ from how they see themselves. Using this lens empowers people to adjust their behavior, enabling them to effectively influence others to achieve high performance.

      In team settings, it is a rich source of information to explore motivations, underlying tensions, inconsistent behaviors, and the mixed messages that can lead to mistrust and derailment. It demonstrates how people may approach teamwork differently and explains the potential for inefficiencies and delays in delivery. Through the concept of behavioral flexibility, it helps defuse cultural stereotypes and streamline cross-cultural teams within organizations.

      Go to this link to explore FIRO-B for Business

      Experience Cube

      A diagram of experience cube model.

      What is an experience cube?

      The Experience Cube model was developed by Gervase Bushe, a professor of Leadership and Organization at the Simon Fraser University's school of Business and a thought leader in the field of organizational behavior. The experience cube is intended as a tool to plan and manage conversations to communicate more effectively in the moment. It does this by promoting self-awareness to better reduce anxiety and adapt to evolving and uncertain situations.

      How does the experience cube work?

      Using the four elements of the experience cube (Observations, Thoughts, Feelings, and Wants) helps you to separate your experience with the situation from your potential judgements about the situation. This approach removes blame and minimizes defensiveness, facilitating a positive discussion. The goal is to engage in a continuous internal feedback loop that allows you to walk through all four quadrants in the moment to help promote self-awareness. With heightened self-awareness, you may (1) remain curious and ask questions, (2) check-in for understanding and clarification, and (3) build consensus through agreement on shared purpose and next steps.

      Observations: Sensory data (information you take in through your senses), primarily what you see and hear. What a video camera would record.

      Thoughts: The meaning you add to your observations (i.e. the way you make sense of them, including your beliefs, expectations, assumptions, judgments, values, and principles). We call this the "story you make up."

      Feelings: Your emotional or physiological response to the thoughts and observations. Feelings words such as sad, mad, glad, scared, or a description of what is happening in your body.

      Wants: Clear description of the outcome you seek. Wants go deeper than a simple request for action. Once you clearly state what you want, there may be different ways to achieve it.

      Go to this link to explore more: Experience Cube

      Research Contributors and Experts

      Photo of Joanne Lee
      Joanne Lee
      Principal, Research Director, CIO Advisory
      Info-Tech Research Group

      Joanne is a professional executive with over twenty-five years of experience in digital technology and management consulting spanning healthcare, government, municipal, and commercial sectors across Canada and globally. She has successfully led several large, complex digital and business transformation programs. A consummate strategist, her expertise spans digital and technology strategy, organizational redesign, large complex digital and business transformation, governance, process redesign, and PPM. Prior to joining Info-Tech Research Group, Joanne was a Director with KPMG's CIO Advisory management consulting services and the Digital Health practice lead for Western Canada. She brings a practical and evidence-based approach to complex problems enabled by technology.

      Joanne holds a Master's degree in Business and Health Policy from the University of Toronto and a Bachelor of Science (Nursing) from the University of British Columbia.



      Photo of Gord Harrison
      Gord Harrison
      Senior Vice President, Research and Advisory
      Info-Tech Research Group

      Gord Harrison, SVP, Research and Consulting, has been with Info-Tech Research Group since 2002. In that time, Gord leveraged his experience as the company's CIO, VP Research Operations, and SVP Research to bring the consulting and research teams together under his current role, and to further develop Info-Tech's practical, tactical, and value-oriented research product to the benefit of both organizations.

      Prior to Info-Tech, Gord was an IT consultant for many years with a focus on business analysis, software development, technical architecture, and project management. His background of educational game software development, and later, insurance industry application development gave him a well-rounded foundation in many IT topics. Gord prides himself on bringing order out of chaos and his customer-first, early value agile philosophy keeps him focused on delivering exceptional experiences to our customers.



      Photo of Angela Diop
      Angela Diop
      Senior Director, Executive Services
      Info-Tech Research Group

      Angela has over twenty-five years of experience in healthcare, as both a healthcare provider and IT professional. She has spent over fifteen years leading technology departments and implementing, integrating, managing, and optimizing patient-facing and clinical information systems. She believes that a key to a healthcare organization's ability to optimize health information systems and infrastructure is to break the silos that exist in healthcare organizations.

      Prior to joining Info-Tech, Angela was the Vice President of Information Services with Unity Health Care. She has demonstrated leadership and success in this area by fostering environments where business and IT collaborate to create systems and governance that are critical to providing patient care and sustaining organizational health.

      Angela has a Bachelor of Science in Systems Engineering and Design from the University of Illinois and a Doctorate of Naturopathic Medicine from Bastyr University. She is a Certified CIO with the College of Healthcare Information Management Executives. She is a two-time Health Information Systems Society (HIMSS) Davies winner.



      Photo of Edison Barreto
      Edison Barreto
      Senior Director, Executive Services
      Info-Tech Research Group

      Edison is a dynamic technology leader with experience growing different enterprises and changing IT through creating fast-paced organizations with cultural, modernization, and digital transformation initiatives. He is well versed in creating IT and business cross-functional leadership teams to align business goals with IT modernization and revenue growth. Over twenty-five years of Gaming, Hospitality, Retail, and F&B experience has given him a unique perspective on guiding and coaching the creation of IT department roadmaps to focus on business needs and execute successful changes.

      Edison has broad business sector experience, including:
      Hospitality, Gaming, Sports and Entertainment, IT policy and oversight, IT modernization, Cloud first programs, R&D, PCI, GRDP, Regulatory oversight, Mergers acquisitions and divestitures.



      Photo of Mike Tweedie
      Mike Tweedie
      Practice Lead, CIO Strategy
      Info-Tech Research Group

      Michael Tweedie is the Practice Lead, CIO – IT Strategy at Info-Tech Research Group, specializing in creating and delivering client-driven, project-based, practical research, and advisory. He brings more than twenty-five years of experience in technology and IT services as well as success in large enterprise digital transformations.

      Prior to joining Info-Tech, Mike was responsible for technology at ADP Canada. In that role, Mike led several large transformation projects that covered core infrastructure, applications, and services and worked closely with and aligned vendors and partners. The results were seamless and transparent migrations to current services, like public cloud, and a completely revamped end-user landscape that allowed for and supported a fully remote workforce.

      Prior to ADP, Mike was the North American Head of Engineering and Service Offerings for a large French IT services firm, with a focus on cloud adoption and complex ERP deployment and management; he managed large, diverse global teams and had responsibilities for end-to-end P&L management.

      Mike holds a Bachelor's degree in Architecture from Ryerson University.



      Photo of Carlene McCubbin
      Carlene McCubbin
      Practice Lead, People and Leadership
      Info-Tech Research Group

      Carlene McCubbin is a Research Lead for the CIO Advisory Practice at Info-Tech Research Group covering key topics in operating models & design, governance, and human capital development.

      During her tenure at Info-Tech, Carlene has led the development of Info-Tech's Organization and Leadership practice and worked with multiple clients to leverage the methodologies by creating custom programs to fit each organization's needs.

      Before joining Info-Tech, Carlene received her Master of Communications Management from McGill University, where she studied development of internal and external communications, government relations, and change management. Her education honed her abilities in rigorous research, data analysis, writing, and understanding the organization holistically, which has served her well in the business IT world.



      Photo of Anubhav Sharma
      Anubhav Sharma
      Research Director, CIO Strategy
      Info-Tech Research Group

      Anubhav is a digital strategy and execution professional with extensive experience in leading large-scale transformation mandates for organizations both in North America and globally, including defining digital strategies for leading banks and spearheading a large-scale transformation project for a global logistics pioneer across ten countries. Prior to joining Info-Tech Research Group, he held several industry and consulting positions in Fortune 500 companies driving their business and technology strategies. In 2023, he was recognized as a "Top 50 Digital Innovator in Banking" by industry peers.

      Anubhav holds an MBA in Strategy from HEC Paris, a Master's degree in Finance from IIT-Delhi, and a Bachelor's degree in Engineering.



      Photo of Kim Osborne-Rodriguez
      Kim Osborne-Rodriguez
      Research Director, CIO Strategy
      Info-Tech Research Group

      Kim is a professional engineer and Registered Communications Distribution Designer (RCDD) with over a decade of experience in management and engineering consulting spanning healthcare, higher education, and commercial sectors. She has worked on some of the largest hospital construction projects in Canada, from early visioning and IT strategy through to design, specifications, and construction administration. She brings a practical and evidence-based approach to digital transformation, with a track record of supporting successful implementations.

      Kim holds a Bachelor's degree in Mechatronics Engineering from University of Waterloo.



      Photo of Amanda Mathieson
      Amanda Mathieson
      Research Director, People and Leadership
      Info-Tech Research Group

      Amanda joined Info-Tech Research Group in 2019 and brings twenty years of expertise working in Canada, the US, and globally. Her expertise in leadership development, organizational change management, and performance and talent management comes from her experience in various industries spanning pharmaceutical, retail insurance, and financial services. She takes a practical, experiential approach to people and leadership development that is grounded in adult learning methodologies and leadership theory. She is passionate about identifying and developing potential talent, as well as ensuring the success of leaders as they transition into more senior roles.

      Amanda has a Bachelor of Commerce degree and Master of Arts in Organization and Leadership Development from Fielding Graduate University, as well as a post-graduate diploma in Adult Learning Methodologies from St. Francis Xavier University. She also has certifications in Emotional Intelligence – EQ-i 2.0 & 360, Prosci ADKAR® Change Management, and Myers-Briggs Type Indicator Step I and II.

      Bibliography

      Bacey, Christopher. "KPMG/Harvey Nash CIO Survey finds most organizations lack enterprise-wide digital strategy." Harvey Nash/KPMG CIO Survey. Accessed Jan. 6, 2023. KPMG News Perspective - KPMG.us.com

      Calvert, Wu-Pong Susanna. "The Importance of Rapport. Five tips for creating conversational reciprocity." Psychology Today Magazine. June 30, 2022. Accessed Feb. 10, 2023. psychologytoday.com/blog

      Coaches Council. "14 Ways to Build More Meaningful Professional Relationships." Forbes Magazine. September 16, 2020. Accessed Feb. 20, 2023. forbes.com/forbescoachescouncil

      Council members. "How to Build Authentic Business Relationships." Forbes Magazine. June 15, 2021. Accessed Jan. 15, 2023. Forbes.com/business council

      Deloitte. "Chief Information Officer (CIO) Labs. Transform and advance the role of the CIO." The CIO program. Accessed Feb. 5, 2021.

      Dharsarathy, Anusha et al. "The CIO challenge: Modern business needs a new kind of tech leader." McKinsey and Company. January 27, 2020. Accessed Feb 2023. Mckinsey.com

      DiSC profile. "What is DiSC?" DiSC Profile Website. Accessed Feb. 5, 2023. discprofile.com

      FIRO Assessment. "Better working relationships". Myers Brigg Website. Resource document downloaded Feb. 10, 2023. myersbriggs.com/article

      Fripp, Patricia. "Frippicisms." Website. Accessed Feb. 25, 2023. fripp.com

      Grossman, Rhys. "The Rise of the Chief Digital Officer." Russell Reynolds Insights, January 1, 2012. Accessed Jan. 5, 2023. Rise of the Chief Digital Officer - russellreynolds.com

      Kambil, Ajit. "Influencing stakeholders: Persuade, trade, or compel." Deloitte Article. August 9, 2017. Accessed Feb. 19, 2023. www2.deloitte.com/insights

      Kambil, Ajit. "Navigating the C-suite: Managing Stakeholder Relationships." Deloitte Article. March 8, 2017. Accessed Feb. 19, 2023. www2.deloitte.com/insights

      Korn Ferry. "Age and tenure in the C-suite." Kornferry.com. Accessed Jan. 6, 2023. Korn Ferry Study Reveals Trends by Title and Industry

      Kumthekar, Uday. "Communication Channels in Project". Linkedin.com, 3 March 2020. Accessed April 27, 2023. Linkedin.com/Pulse/Communication Channels

      McWilliams, Allison. "Why You Need Effective Relationships at Work." Psychology Today Magazine. May 5, 2022. Accessed Feb. 11, 2023. psychologytoday.com/blog

      McKinsey & Company. "Why do most transformations fail? A conversation with Harry Robinson." Transformation Practice. July 2019. Accessed Jan. 10, 2023. Mckinsey.com

      Mind Tools Content Team. "Building Good Work Relationships." MindTools Article. Accessed Feb. 11, 2023. mindtools.com/building good work relationships

      Pratt, Mary. "Why the CIO-CFO relationship is key to digital success." TechTarget Magazine. November 11, 2021. Accessed Feb. 2023. Techtarget.com

      LaMountain, Dennis. "Quote of the Week: No Involvement, No Commitment". Linkedin.com, 3 April 2016. Accessed April 27, 2023. Linkedin.com/pulse/quote-week-involvement

      PwC Pulse Survey. "Managing Business Risks". PwC Library. 2022. Accessed Jan. 30, 2023. pwc.com/pulse-survey

      Rowell, Darin. "3 Traits of a Strong Professional Relationship." Harvard Business Review. August 8, 2019. Accessed Feb. 20, 2023. hbr.org/2019/Traits of a strong professional relationship

      Sinek, Simon. "The Optimism Company from Simon Sinek." Website. Image Source. Accessed, Feb. 21, 2023. simonsinek.com

      Sinek, Simon. "There are only two ways to influence human behavior: you can manipulate it or you can inspire it." Twitter. Dec 9, 2022. Accessed Feb. 20, 2023. twitter.com/simonsinek

      Whitbourne, Susan Krauss. "10 Ways to Measure the Health of Relationship." Psychology Today Magazine. Aug. 7, 2021. Accessed Jan. 30, 2023. psychologytoday.com/blog

      Change Management's Role in Incident Prevention: standard changes

      • Large vertical image:
      • member rating overall impact: N/A
      • member rating average dollars saved: N/A
      • member rating average days saved: N/A

      During peak business hours, I witnessed a straightforward database field addition bring down a whole e-commerce platform. It was meant to be standard procedure, the type of “standard change” that is automatically approved because we have performed it innumerable times.

      Adding a field to the end of a table and having applications retrieve data by field name instead of position made the change itself textbook low-impact. There is no need to alter the application or the functional flow. This could have been problematic in the past if you added a field in the middle of the list and it affected the values of other fields, but adding it at the end? That ought to have been impenetrable.

      However, it wasn't.

      Before I tell you what went wrong, let me explain why this is important to all of the IT professionals who are reading this.

      Over the past three decades, industry data has repeatedly supported what this incident taught me: our presumptions about “safe” changes are frequently our greatest weakness. Upon reviewing the ITIL research, I was not surprised to learn that failed changes, many of which were categorized as “standard” or “low-risk,” are responsible for about 80% of unplanned outages.

      When you look more closely, the numbers become even more concerning. Since I've been following the Ponemon Institute's work for years, I wasn't surprised to learn that companies with well-established change management procedures have 65% fewer unscheduled outages. The paradox surprised me: many of these “mature” procedures still operate under the premise that safety correlates with repetition.

      What I had been observing in the field for decades was confirmed when Gartner released their research showing that standard changes are responsible for almost 40% of change-related incidents. The very changes we consider safe enough to avoid thorough review subtly create some of our greatest risks. IBM's analysis supports the pattern I've seen in innumerable organizations: standard changes cause three times as much business disruption due to their volume and our decreased vigilance around them, whereas emergency changes receive all the attention and scrutiny.

      Aberdeen Group data indicates that the average cost of an unplanned outage has increased to $300,000 per hour, with change-related failures accounting for the largest category of preventable incidents. This data makes the financial reality stark.

      What precisely went wrong with the addition of that database field that caused our e-commerce platform to crash?

      We were unaware that the addition of this one field would cause the database to surpass an internal threshold, necessitating a thorough examination of its execution strategy. In its algorithmic wisdom, the database engine determined that the table structure had changed enough to necessitate rebuilding its access and retrieval mechanisms. Our applications relied on high-speed requests, and the new execution plan was terribly unoptimized for them.

      Instead of completing quotes or purchases, customers were spending minutes viewing error pages. All applications began to time out while they awaited data that just wasn't showing up in the anticipated amounts of time. Thousands of transactions were impacted by a single extra field that should have been invisible to the application layer.

      The field addition itself was not the primary cause. We assumed that since we had made similar adjustments dozens of times previously, this one would also act in the same way. Without taking into account the hidden complexities of database optimization thresholds, we had categorized it as a standard change based on superficial similarities.

      My approach to standard changes was completely altered by this experience, and it is now even more applicable in DevOps-driven environments. Many organizations use pipeline deployments, which produce a standard change at runtime. It's great for speed and reliability, but it can easily fall into the same trap.

      However, I have witnessed pipeline deployments result in significant incidents for non-code-related reasons. Due to timing, resource contention, or environmental differences that weren't noticeable in earlier runs, a deployment that performed flawlessly in development and staging abruptly fails in production. Although the automation boosts our confidence, it may also reveal blind spots.

      Over the course of thirty years, I have come to the unsettling realization that there is no such thing as a truly routine change in complex systems. Every modification takes place in a slightly different setting, with varying environmental factors, data states, and system loads. What we refer to as “standard changes” are actually merely modifications with comparable processes rather than risk profiles.

      For this reason, I support contextual change management. We must consider the system state, timing, dependencies, and cumulative effect of recent changes rather than just categorizing them based on their technical features. After three other changes have changed the system's behavior patterns, a change made at two in the morning on a Sunday with little system load is actually different from the same change made during peak business hours.

      Effective change advisory boards must therefore go beyond assessing individual changes separately. I've worked with organizations where the change board carefully considered and approved each modification on its own merits, only to find that the cumulative effect of seemingly unrelated changes led to unexpected interactions and stress on the system. The most developed change management procedures I've come across mandate that their advisory boards take a step back and look at the whole change portfolio over a specified period of time. They inquire whether we are altering the database too frequently during a single maintenance window. Could there be unanticipated interactions between these three different application updates? What is the total resource impact of this week's approved changes?

      It's the distinction between forest management and tree management. While each change may seem logical individually, when combined, they can create situations beyond the scope of any single change assessment.

      Having worked in this field for thirty years, I've come to the conclusion that our greatest confidences frequently conceal our greatest vulnerabilities. Our primary blind spots frequently arise from the changes we've made a hundred times before, the procedures we've automated and standardized, and the adjustments we've labeled as “routine.”

      Whether we should slow down our deployment pipelines or stop using standard changes is not the question. In the current competitive environment, speed and efficiency are crucial. The issue is whether we are posing the appropriate queries before carrying them out. Are we taking into account not only what the change accomplishes but also when it occurs, what else is changing at the same time, and how our systems actually look right now?

      I've discovered that the phrase “we've done this before” is more dangerous in IT operations than “what could go wrong?” Because, despite what we may believe, we never actually perform the same action twice in complex systems.

      Here is what I would like you to think about: which everyday modifications are subtly putting your surroundings at risk? Which procedures have you standardized or automated to the extent that you no longer challenge their presumptions? Most importantly, when was the last time your change advisory board examined your changes as a cohesive portfolio of system modifications rather than as discrete items on a checklist?

      Remember that simple addition to a database field the next time you're tempted to accept a standard change. The most unexpected outcomes can occasionally result from the most routine adjustments.

      I'm always up for a conversation if you want to talk about your difficulties with change management.

      This site and all contents is © 2026 Tymans Group BV