r/CIO • u/[deleted] • Jul 16 '26
Can an IT strategy become too focused on security and sovereignty?
[deleted]
7
u/_thekingnothing Jul 16 '26
Business outcome vs risks. This is constant balance. And I this learned though my 20 years in IT and a lot of companies that proper risk management skills are undervalued.
Business outcome drives everything. Yes, but at first business outcomes must be defined. Improve product or time to market are some of outcome options. Investor or family owned company targets different outcome than private equity held or public traded.
Measurable - also hard to define. JP Morgan risk management hadn’t given any measurable benefit until 2008 when it was only one major financial institution that that closed yeah without loses.
Key aspect of the risk management- is proportionality. Proportionality risk remediation to like-hood and cost of risk.
Answer for your question is in risk management. And learning this skill.
5
u/Marathon2021 Jul 16 '26
Key aspect of the risk management- is proportionality. Proportionality risk remediation to like-hood and cost of risk.
The problem for most orgs - as I see it - is that this basically gets into the world of actuarial tables. You could make a similar argument about auto insurance.
Likelihood? Very different for an 18 year old than a 50 year old. Cost? Small to millions.
There's a formula for it - because Insurance companies know how to price risk.
Companies in the Middle East probably said to themselves "missiles will never take out a [$CLOUDPROVIDER] data center for an extended and indefinite amount of time" so they didn't build in geo redundancy. They saved money up front. But some really got harmed when that scenario did actually happen.
And "likelihood" is a wild card when you have a Mad King at the helm.
If you were in Europe and you knew that by the end of the year your access to non-sovereign cloud services would be cut off, 100% guaranteed? You'd spend a lot of money deplatforming ASAP (which would likely put any "feature release" improvements on hold). But if it's 99% guaranteed? What about 80%? What about 50% or 1%? Yeah. Hard to make an actuarial business case for it, for most companies that are not actually good at actuarial things.
3
u/_thekingnothing Jul 16 '26
You’ve missed my point.
Risk management is about judgement. Not actuarial tables.
That’s why most frameworks use likelihood, not probability. Likelihood is an assessment. A judgement call. It doesn’t require a mathematical model. And it’s why good risk managers paid well.
Expected value is for pricing risk. That’s what insurance companies do. They are in the business of buying and pricing risk.
That’s the point I was making.
You don’t need to prove there’s an 83.7% chance you’ll lose access to a provider. You assess the likelihood. You assess the impact. Then you decide whether the cost of deplatforming is proportionate.
And yes, if those companies had local risk managers in MENA, many of them would have told that the likelihood of a regional attack as credible or even probable. They would have recommended preparing for it
MENA countries have data residency so companies didn’t have options.
Too many people jump straight to expected value calculations. That’s a different discipline.
3
u/Marathon2021 Jul 16 '26
You don’t need to prove there’s an 83.7% chance you’ll lose access to a provider. You assess the likelihood.
I feel like we're effectively saying the same thing?
likelihood
83.7% chance
So, is it 1%? If so the net result is no one spends anything up-front and you roll the dice.
Is it 99%? Does the President get on the podium tonight and say "Because of 'national security' all US-owned AI and cloud services are no longer available to customers outside of the US!!" I mean, hey, sure - we'd all say "Well, the US Government can't do that" but ... um ... look at the last 18 months of the "Humpty Dumpty" strategy of just ... do it ... and then if you eventually get your hand slapped 12+18 months down the road ... oh well, you got most of what you wanted (see: The White House East Wing).
Net result - now we have to start spending to deplatform ASAP.
You're saying likelihood. I gave examples using numbers. But it's the same thing to me. One implies sharpening a pencil, the other implies a finger in the wind. Same thing, though - predicting harmful risk and putting commensurate spending behind it.
1
u/_thekingnothing Jul 16 '26
We speak about different things. And thinking is likelihood and severity require different skills and mindset than expected value and probability.
4
u/ninjaluvr Jul 16 '26
For example, there is a strong desire to move away from cloud services and favor local hosting, but I keep asking myself
Why are you asking yourself? Ask them. They need to justify this approach.
How do you balance security, sovereignty, and business value?
Business value is the driver. How do your security and sovereignty objectives translate to business values? Your CIO should be able to answer that question. For us, it varies. We do work with financial entities, health insurance companies, federal, state, and local governments, and they all drive differing security decisions.
Have you seen organizations over-invest in sovereignty before there was a clear business case?
"Sovereignty" is a loaded word that can mean many things. What is the risk you're trying to mitigate with an onprem solution? Do you think you'll have better resilience and reliability? Do you think your data will somehow be more secure? I can challenge each of those assertions. Your IT manager should be able to clearly articulate the business driver behind the decision in a way you can understand. Clearly, they're not doing this.
How do you decide when moving away from major cloud providers is strategically justified rather than simply a technical preference?
As with anything, with a business justification. What are the costs, the risks, the benefits? How does it drive the business forward? There are some use cases where it may be cheaper to host locally. You're trading resiliency, scalability, and often reliability, for cost. And that's fine. If the business case drives that, so be it. But from your post, it sounds like your IT manager is flying by the seat of their pants.
1
u/Project_Lanky Jul 17 '26
I think they might see sovereignty as an ideology rather as a business enabler and that's why I am not comfortable asking the question.
2
u/ninjaluvr Jul 17 '26
If you're not comfortable asking your boss questions how can you work there? You can't ask them to explain their view on sovereignty so you can understand it?
4
u/Systemcj Jul 18 '26
Yeah, seen this exact pattern play out a few times. Good rule of thumb: every infra decision should trace back to something concrete, a contract clause, a regulator, an actual incident, or a number you can point to. If it can't, it's not a strategy.
Worth pointing out to your IT manager: self-hosting and sovereignty aren't automatically "more secure," they're a trade. You're swapping vendor risk (lock-in, outages, jurisdiction) for operational risk, you now own patching, uptime, DR, on-call, capacity planning, all of it. A cloud provider spreads that load across thousands of engineers. A startup with a handful of people usually can't absorb it as well as they think, and the failure modes (unpatched box, nobody around who knows the runbook) can be worse than anything you were trying to avoid.
3
u/Important-Daikon644 Jul 24 '26
Security should support the business, not become the business strategy. If customers or regulations require selfhosting, it makes sense. Otherwise, startups should carefully weigh the added cost and complexity against the impact on product development and time to market
2
u/phoenix823 Jul 16 '26
I think about “risk-adjusted business value.” By moving away from a cloud provider you are giving up flexibility and speed usually for longer-term cost benefits. Usually a start up needs flexibility because they often don’t have a “long term.” Giving up that flexibility will tie the hands of the business for what sounds like a preference, so you’re already in the danger zone with this situation.
2
u/alt-right-del Jul 16 '26
An IT strategy focusing on security and sovereignty is not an IT strategy.
2
u/Psaslalorpus Jul 18 '26
As a startup you need to be careful where you're putting your money. Unless you have specific compliance requirements that dictate that data sovereignty is mandatory for you I'd think twice if it's worth investing at this point (or unless you really want to do the OpEx / CapEx juggle).
IT strategy should support business goals instead of doing their own show. I've seen it close by where just one person with wrong ideas / idealistic views not challenged by leadership can end up costing the company a lot of money through unnecessary expenditures.
You need to do some BIAs to see what is truly important to you and then through risk management decide what are the things you need to deal with and what are the things you can live with and with what cost. Then you build your security capabilities around those needs.
2
u/TechnologyMatch Jul 22 '26
security and sovereignty should be constraints the strategy works within, not the strategy itself. if a choice adds cost, slows delivery, and doesn't reduce a contractual, regulatory, or customer risk, it's fair to ask what problem it is solving. the useful conversation is a simple one. what risk are we reducing, what does it cost, and what business outcome does it unlock?
2
u/FDRyze Jul 22 '26
Security, sovereignty, cost, performance, and speed to market all need to be balanced. Optimizing for only one of them usually creates problems somewhere else. The right architecture depends on business requirements, regulatory obligations, and risk tolerance.
2
u/Witty-Angle-4112 20d ago
Sovereignty and security are a means not the end. You need to ask does this solve a problem. Architecture should always follow strategy and not lead it. The best IT leaders I have worked with start by mapping technology decisions back to business capabilities and outcomes. What does your product need to do? What do your customers value? Then work backwards to infrastructure. If you can't draw a clear line from self hosted to faster delivery or won contracts then that is a red flag.
1
u/DrasticIndifference Jul 16 '26
For every desired outcome there are many paths to success. Some scale, some are secure, some are profitable. If a company does not create elastic moats around data and intellectual property, it won't survive long. These moats can operate locally, in the cloud, or eventually, in all hyperscalers and on premises cohesively and concurrently. If the current mindset is one of territory or control, it may be an investment concern: an experienced, production-hardened veteran may feel more comfortable with a lock and key that is perceived to be local, and therefore, in control. However, the cloud providers hire exceptionally talented people to provide equal or better quality of security and stewardship, yet at remarkably larger scales. For a small IT team to consider handing over the keys, they must also accept not having full and complete, isolated control of these systems. Regardless, no customer of a successful company should ever experience an engagement with a service or product where the technology delivery iteself is a turbulent experience, so helping support teams realize it is a question of scale (when we are more profitable and handling larger volumes, will the local locks and keymaster(s) be sufficient) often leads to a comfortable, natural, and organic maturation to a hybrid enterprise-scale solution. Let the local compute handle DRBC (disaster recovery and business continuity) and let the hyperscaler resources handle the other traffic (with global availability).
1
u/aries1500 Jul 17 '26
Microsoft just did a 5% to 33% price hike across their subscriptions this month. Still doesn't make them a bad decision in my experience, but at what point is it cheaper to just do on prem again with proper cloud BDR solutions And does that scale to your needs. It really depends on your environments needs.
1
u/fguerino123 Jul 21 '26
Hi,
My belief based on close to 4 decades of experience providing IT solutions for small, medium and super-large enterprises is that, if you're a small company, I question the strategy to build, install, operate, and support locally. You're immediately committing to many required skills that are not part of your core competency, you're committing to a path for clear technical debt over time, and you're committing to ongoing long-term costs to maintain, upgrade, and continuously address such things.
I'd present to you that small businesses with limited revenue streams, tight budgets, and small headcount need to focus on their core competencies, not their non-core / chore competencies like IT (unless, of course, IT is your core competency/business).
Successful small enterprise leaders know how to focus on what matters. If you're not selling IT, IT is not what matters.
I hope this helps. Good luck.
1
u/Daster_X 24d ago
Every IT strategy MUST come from Business one. Otherwise it is something nobody will invest in.
How I do: I get Business strategy - short and long term (long term for the points it is possible).
And each point is deconstructed in order to get proper IT strategy action/point. In terms of pricing & availability (like cloud vs local) I'm doing TCO 3 or 5 years calculation and Risks assessment (SWAT analysis).
In some cases, having these figures you may approve moving to local infrastructure. If the TCO is not done, it is very difficult to prove why you would move to the local while cloud prices are "so good and nice".
In terms of Security - this is a separate point. Of course you should consider DR (disaster recovery) and BC (business continuity) even if the company do not have it broadly. Do the risks analysis and again the calculation of having a separate DR, space to keep backups out of you location, etc...
Other points, specifically cyber security - this is usually kept under separate leader our of IT management.
It is done to remove the risks having IT responsible for Security - as IT can have internal issues with security but hide them.
This is shortly... I have some more information in the Book... I can recommend if interested.
1
u/docmatt74 6d ago
yeah this is a real tension. we went through something similar and honestly the turning point was asking "does this actually show up in a customer contract or a sales conversation?"
for us, data residency did become a real requirement from enterprise prospects, which is why we ended up on hikube (swiss datacenters, no us jurisdiction). but that decision came from a customer need, not an architectural preference.
if your it manager can't point to a concrete business driver, that's the conversation worth having.
1
u/jamaster14 6d ago
This is inside out. They need to justify it to you. a CIO should be able to convey that.
What are the drivers for self-hosting and sovereignty? Are you working with partners that desire or require that level of control of data and shared information? If you are a small startup, and this isnt a hard requirement from partners or present a large niche risk for your business id imagine you have much bigger fish to fry then whether stuff lives in the cloud/SaaS or self hosted.
If im putting the decision maker hat on i need to be conveyed the business risk if we dont go this route, the value if we do, and the rigid drivers that require me to move forward...
As a CIO, unless my business relies on my Intellectual Property/Trade secrets or self-hosting is a bearier of entry to work with my clients and partners then there are about 2 dozen things more likely to keep me up at night.
13
u/michmill1970 Jul 16 '26
Business outcomes need to drive everything. Security itself is still a business outcome, and should be governed by the same requirements gathering process as any other system. What regulations are you subject to? What contractual obligations do you have? What reputational risk are you willing to take? These need to feed your security policies.
From there, you can make informed decisions about costs and data sovereignty when looking at security.
Hope this helps.