RFG 100 Podcast: Recent Episodes

RFG 100

Robert Frances Group's RFG 100 podcasts focus on C-level business and IT key agenda issues including architecture, infrastructure, DevSecOps, compliance, data architecture and governance, regulatory, and security issues. Through communal and inter-disciplinary discussion among RFG 100 Member executives and panelists, these podcasts will detail shared challenges, key performance indicators, strategic options, and best practice guidance is shared among participants.To find out more and participate live, visit https://events.rfg100.com if you'd like to participate as a contributor or audience member.

View Details

With tensions looming in the wake of Russia’s invasion of Ukraine, our next video conference will focus on cybersecurity. In the same vein that traditional battles employ the use of structurally damaging armament against opposing forces, cyberattacks allow nations to impose their will by destabilizing essential institutions including financial systems and governments, and key infrastructure networks. Shoring up cyber defenses must become an urgent priority for organizations given the heightened threat of a global cyber war. Russia, its allies, and other actors may increase their attacks on Western governments and organizations by employing cyberattacks, including DDoS and ransomware offensives, as the theater of war evolves. Last year, President Biden issued an executive order instructing government agencies and private organizations to prepare for such menaces by addressing lapses in their cyber defenses and enacting plans minimize impacts of any successful penetrations.

For perspective, the effects of two previous iconic cyber weapons, Stuxnet and NotPetya, should serve as due warning. The U.S. likely developed Stuxnet while NotPetya has been attributed to the Russian government. These malware bugs were initially targeted in their distribution; however, they later “escaped” into the wider world leaving numerous undesirable consequences in their wake. Should the physical war in eastern Europe escalate, it should be assumed that European and U.S. financial and infrastructure systems to rank highly on the intended target list. It is therefore imperative assume a both preventative actions and a remediatitive postures should breaches succeed.

The panelists and participants will discuss the following key cyber vulnerability management issues:

  1. Risk assessment and gap analysis
  2. Incident planning and communications
  3. Discovery and detection, including dark Web analysis
  4. Identity and access management and other prevention elements
  5. Pen testing
  6. Incident containment and other responses
  7. Third party assistance

View Details

The reality in today's data center stands in stark contrast to enterprise growth and transformation needs. Near-term capacity problems, constrained supply, and rising prices are impeding needs at data centers throughout the world. While one can order new server, storage, networking and related equipment without issue, vendor backlogs are not in alignment with business timeframes and are forcing hard decisions. The majority of vendors with whom RFG is speaking are reporting delivery times that may extend to six, nine, or even 18 months out for their most popular hardware and continued challenges related to availability sourcing, manufacturing, and shipping are intensifying. Similarly, energy scarcity and rising costs related to demand growth, carbon-neutral and net-zero environmental initiatives, and global tensions, obstruct data centers power demands. Enterprises will need to balance existing hardware and limited new hardware acquisition capabilities with limited power supply to best enable strategic growth requirements. This then begs the question: what actions can IT take to utilize existing resources more efficiently to the point where it satisfies the planned business demand?

While the issue is posed presents itself primarily in the context of growth and capacity, sustainability initiatives imposed by regulatory bodies, CEOs, internal ESG organizations, and corporate stakeholders advocating for environmental accountability must also be considered. Supply chain constraints will likely remain for at least the next 18-24 months for hardware and potentially far longer for energy supply, which has seen user costs increase between 30 percent and 400 percent in some particularly confined geographies. Discussions incorporating the board, C-level executives, line of business executive, and IT executives must deal with these new realities, prioritize desired and essential outcomes, and look to find ways to solve their business issues and satisfy their ESG commitments simultaneously more efficiently. PUE and other energy-consumption, efficiency-oriented metrics need to be added to the price/performance evaluation criteria. Holistic examination incorporating key metrics encompassing facilities, IT hardware, and power and cooling strategies must be evaluated, planned for, addressed, and routinely measured and improved upon to maximize efficiencies to accommodate shortages.

The panel and participants will discuss the following business growth/supply constraint issues:

  1. What is my current baseline and how does that compare to others?
  2. What are the best metrics to use and report against?
  3. What are good quick hits? What are the business cases for them?
  4. Where do I start?
  5. Who are the stakeholders that need to be sold?