Tech Debt Burndown Podcast: Recent Episodes

Nick Selby and Chris Swan

summary

View Details

Recording date: Apr 17, 2023

Download at Apple Podcasts, Google Podcasts, Spotify, iHeartRadio, Spreaker or wherever you get your podcasts.

“They’re statistical models based on language corpuses and the output of these things can be shown in some cases to be stunningly incorrect.” - Gene SpaffordGene opens with a comment about the “tendency of the industry to jump on hot trends”, and that sets the scene for much of the discussion, which goes on to touch blockchain, and of course ‘AI’.

We touch upon topics where Gene and his co-authors go into more detail in Cybersecurity Myths and Misconceptions such as where liability should be placed to better incetivise the creation of spftware that’s safe, secure and reliable. Though Gene acknowledges that we don’t (yet) even have good metrics for those terms. That leads into some discussion on whether organisations like the Open Source Security Foundation (OpenSSF) can fill some of the gaps.

Before closing we get to some discussion of the European Union Cyber Resiliance Act (CRA) and some of the consequences that might have for open source software.

View Details

Recording date: Apr 1, 2022

Download at Apple Podcasts, Google Podcasts, Spotify, iHeartRadio, Spreaker or wherever you get your podcasts.

“When you frame technical debt through the lens of strategy, it actually starts to make a lot more sense” - Jamie DobsonWith intros over we ask Jamie about his experience with cloud native transformation. He sees many companies who have made a mess of their cloud migration. They have created a lot of technical debt, which can make it difficult to innovate and can lead to security problems.

Jamie says that the best time to do a do over is when you realize that your cloud migration is not working. However, he acknowledges that this is a difficult decision to make. People often feel like they have invested too much time and money in their current system to change it. However, it is often better to start over than to continue down a path that is not working.

Jamie then talks about how to approach cloud native transformation from a strategic point of view. He says that it is important to understand the company’s goals and objectives before making any decisions about cloud migration. Once you understand the company’s goals, you can then start to think about how cloud native computing can help you achieve those goals.

Jamie concludes by saying that cloud native computing is a powerful tool that can help companies to innovate and grow. However, it is important to approach cloud native transformation in a strategic way in order to get the most out of it.

View Details

Recording date: Feb 14, 2022

Download at Apple Podcasts, Google Podcasts, Spotify, iHeartRadio, Spreaker or wherever you get your podcasts.

“Stop calling it technical debt” - Andy EllisWith intros over, Nick asks Andy about metrics, and Andy immediately responds by saying “stop calling it technical debt”. Executives have an understanding of ‘debt’, and it’s not a bad word for them, it’s what fuels everything around them. This leads into discussion of when’s the right time to ship software. Something unfinished might feel too early, but how else do you get feedback from users?

“Risk is the net present value of bad things happening in the future”

We then get into Andy’s model of deferred risk, and how that can drive a conversation about what to do now, and what to put off until later. This eventually takes us to talking about Dungeons and Dragons alignment charts, and how it’s good to have a diverse team who bring a variety of viewpoints.

Andy then gets into how people want to quantify risk, but often that’s impossible. But there are ways to position risks in a visualisation, which can help people reason about the range of risks they’re dealing with. When it comes to assigning resources to the work on risk mitigation Andy runs through some approaches that have worked for him, which include ‘borrowing’ people to get things started then ‘giving them back’ to ensure that the effort is sustained. That brings us to our close, with Nick complaining about the knives in his house being dull, even though his son makes and sharpens knives…

View Details

Recording date: Jan 24, 2022

Download at Apple Podcasts, Google Podcasts, Spotify, iHeartRadio, Spreaker or wherever you get your podcasts.

“When they have figured out what this game was really about, they figured out what should be the response” - Krysztof (Chris) DanielAfter intros we start by asking Chris why he got the @wardleymaps Twitter handle, and he explains that he was doing an entrepreneurship course that got him interested in Wardley mapping; and from that he went on to develop an online tool to help people make maps. We then chat a little about Chris’s work at the Leading Edge Forum (LEF), where he works alongside Simon Wardley.

Nick speculates that mapping hasn’t really made it to the US yet, but Chris points out that there are already vibrant communities in the US before giving an overview of the Wardley mapping technique. He then illustrates the approach using a customer case study. This gets into the customer not really knowing what they had (in terms of assets) until they went through the mapping process.

The conversation then turns to situational awareness, and whether that’s a predominantly military concept. Given that there are plenty of veterans about (particularly in infosec), why is it that situation awareness isn’t used more in companies?

We then get into how maps can be used to understand tech debt in organisations. In particular how assets in the value chain that have become debt can be examined for change. That leads into a discussion of the elements of (awkwardly named) doctrine, and where they fit into the overall strategic picture.

Before closing, discussion moves on to corporate structure, which relates to Wardley’s pioneers, settlers and town planners (PST) model.

View Details

Yosef Lehrman talks to Nick and Chris about the Executive Order on Improving the Nation’s Cybersecurity

View Details

Allan Friedman of the National Telecommunications and Information Administration (NTIA) has long been one of the world's leading proponents of Software Bill of Materials, or SBOM. With the President's Executive Order on Improving the Nation’s Cybersecurity, SBOM has begun to receive the wider attention it deserves, and Allan joins Chris and Nick to discuss SBOM and how it can help with tech debt burndown.

View Details

Eoin Woods has developed quite a bit of software, and created and dealt with quite a lot of technical debt. He is CTO at Endava, and co-author of two software architecture books. On the Tech Debt Burndown he joins Chris and Nick to talk about his role in the International Conference on Technical Debt and some of the research highlighted in the virtual 2021 edition of that conference, as well as his own personal experiences in the field.

View Details

Charity Majors joins Nick and Chris to discuss the difference between observability and metrics, some great insights into good debt (like college loans) versus bad debt (like charging stuff we want on a credit card), and thoughts on efficiency.

View Details

With the US closed for Memorial Day weekend, and the UK closed for Spring Bank Holiday, we're firing up the grills, and pausing to reflect. In the next few episodes, we'll discuss toil and build times with Charity Majors, Tech Debt burndown strategies with Eoin Woods, the Biden Executive Order with Yosef Lehrman, SBOMs with Allan Friedman, and much, much more!

View Details

On this episode, Chris and Nick are joined by Olivier Jacques, DevOps transformation principal at DXC Technology, who discusses his article, Six Strategies to Set Time Aside to Improve. The six approaches capture some very insightful observations into technical debt burndown.

View Details

Chris and Nick welcome Kenn White, from MongoDB, to discuss Mongo's enabling teams and how they cut through the BS to help engineers stay in the flow and be happier. Then they welcome Bill Pelletier, to talk about some of the unique challenges faced by medical device and Software as a Medical Device makers.

View Details

Lots of things get improved by building continuous delivery pipelines and then going back to them and iteratively making improvements. Pipelines themselves can be a place where we accrue tech debt - even at the entry point to those pipelines. So let's look at branching strategies.

View Details

How do you measure technical debt? This week, Chris and Nick discuss the metrics around technical debt, and why there are so few of them.

View Details

When Wendy Nather began work as an information security analyst, she started asking her CISO friends a question: 'If you just took a CISO job at a company that had no security, what would you buy?' The answers fascinated her. Now at Duo (Cisco), she set out to formalize research that was released as Cisco Secure’s Security Outcomes Study. Wendy discusses the process on this week's podcast.

View Details

We've been hearing about Supply Chain vulnerabilities quite a bit lately, from Solar Winds to CodeCov. How do these relate to technical debt? Ah, that's a complicated question, because each of its components are discussing complex things. In this episode, Chris and Nick try to hash it out and sort through what's important.

View Details

Episode 2: Ian Amit of Cimpress