Between the rapid evolution of IT, the ever more pressing needs of the business and multiplying regulatory requirements, the Information System decision-makers whose functions we presented in a previous article face multiple challenges. Meeting them within a constrained time and budget is a real tour de force.

The 10 major challenges facing IS decision-makers

1. The need to pool and rationalise IS, constantly renewed by the acquisitions and the mergers of IT departments and operations carried out by organisations, in order to cut costs and increase IS reliability by limiting its complexity. This rationalisation means bringing these IS back within a common technological and organisational framework. A good example we see in the field is the complexity of Active Directory domains and their trust relationships, built up over successive mergers and acquisitions without any real effort of factorisation and simplification, leading to a “tangled” IS that is hard to maintain and to evolve.

 

2. The ever stricter regulatory framework, imposing security requirements that deeply transform IS. This framework, which originally concerned critical business functions in France, increasingly extends through European regulations such as DORA, applicable to the financial sector, and NIS2, which concerns thousands of companies in France, notably mid-sized companies (ETI) that are not always prepared for such large-scale transformations.

 

3. The acceleration of the Move to Cloud, due to the technological maturity of CSPs (Cloud Service Providers) and a larger number of large companies ready to take the step after many years of thinking, mainly in regulated sectors. The Move to Cloud must go through a real application refactoring to benefit fully from the Cloud (splitting into microservices, containerisation, relying on the CSPs’ native features…) rather than a simple replatforming. Otherwise, the company cannot claim to have made its shift to the Cloud, but merely a cost optimisation towards an IaaS provider more competitive than its historical internal operator.

 

4. In parallel, the transformation of the historical IS, or “Legacy”, which still carries many business functions and whose cost of maintenance in operational and security condition weighs ever more heavily. Paying down technical debt, long postponed, requires strategies of major transformations or gradual migrations that call for a long-term commitment from management.

 

5. Cyber-resilience, given the intensifying cybercriminal threat and state-led destabilisation in cyberspace. Organisations must keep strengthening the security of their IS and prepare to react to cyberattacks and to rebuild their IS in the event of partial or total destruction. This topic, for too long a concern of CISOs alone, is becoming a priority for CIOs and CTOs too. In the field we often meet the misconception that it can be covered by the historical business continuity and disaster recovery plans (PCA/PRA) without taking into account the reality of current threats, notably ransomware.

 

6. The transformation of uses and operating models continues under the influence of agile methods, with a transformation of application and IT delivery towards a product logic and wider adoption of DevOps practices. This transformation is unavoidable to meet the increased demands of the business, given what CSPs offer, towards the IT department and the internal operator. It can improve Time to Market, but it has pitfalls that organisations must avoid, because these methods and practices are sometimes applied indiscriminately in inappropriate contexts and can harm an overall need for security and control.

 

7. The automation of IT processes limits costs, increases IS reliability and builds a real Security By Design logic into application and IT products. In line with the DevOps approach mentioned above, breaking down the barriers between BUILD and RUN teams encourages the automation of recurring operating tasks by the teams in charge of these products.

 

8. Artificial Intelligence triggers strong demand from the business to transform their uses. These uses must be strongly governed: while AI can bring productivity gains, these must be rigorously measured. Moreover, many risks surround AI: attacks targeting models, misuse leading to breaches of data confidentiality, a decline in the quality of intellectual output through excessive use of generative AI…

 

9. Talent attractiveness is a concern for every IS decision-maker. Young graduates are increasingly demanding in terms of well-being at work, flexibility, notably regarding remote work, and corporate social responsibility (CSR), in a particularly tight market. On top of that, the appeal of the new operating models seen above pushes organisations to reorganise to show more agility and flexibility.

 

10. The decline of offshoring in favour of nearshoring, and sometimes even of bringing resources back in-house, is accelerating. Offshoring has shown its limits because, despite the apparent savings, its hidden cost can be significant: user irritation, low quality of IT deliveries, inability to go beyond a simple execution role… Nearshoring, notably within Europe, which gives access to solid skills at a lower cost, is now preferred to offshoring, allowing more physical proximity through frequent trips and periods of deep dive within the teams.

How to take on these challenges?

To meet these challenges, the organisation must transform deeply. In the field we find that, of the three major components of the IS, the organisational aspect is the biggest obstacle to such large-scale transformations. They run into various difficulties:

 

– Lack of sponsorship at the highest level;

– Lack of clarity of roles and responsibilities within the IS;

– Shortcomings in steering and communication between stakeholders;

– Lack of standardisation, maturity and convergence of IT processes.

 

To address these issues, the organisation must build or review its Information System strategy in line with the company strategy. This strategy must be made crystal clear to Executive Management so that it can grasp it and take informed decisions. Co-built with the IS decision-makers (CIO, CTO and CISO), this strategy must cover the response to business needs, the technology directions and the risk-control framework.

 

We first recommend that organisations carry out a full audit assessing the maturity level of each IS function against the company’s strategic objectives, industry standards and applicable regulations. They can then build a short- and medium-term action plan from scenarios costed in terms of price and timing, allowing executive management to prioritise the transformations to carry out within a constrained time and budget.

Reconnecting with executive management

The scale of the task for IS decision-makers has never seemed so great. It is crucial that these IS challenges do not rest on their shoulders alone, because they concern the organisation as a whole more than ever.

 

That is why their priority is to reconnect with executive management and interest it in IS challenges with a clear message. CIO, CTO and CISO must work together and break down their silos, as business, technology or security scopes must no longer be their private domains. By identifying the dependencies between their issues and speaking with one voice, they will have their legitimacy fully recognised at every level of the organisation.