Category: Strategy

  • Working with an IT Provider

    Working with an IT Provider

    For many businesses, especially those under 200 staff, your IT provider is one of your most critical vendors. They hold the keys to all of your data, and when IT stops, the business stops. Despite that, most businesses I speak to take a very light touch to managing this relationship. Often the job sits with the ‘accidental IT leader’. This is someone whose real role sits in operations or finance, but because they’re so good at keeping things running, they’ve been handed a few extras. IT is one of them.

    Usually the original agreement has expired, or it never had much detail to begin with, so it no longer reflects what the provider actually does for the business today. The monthly or quarterly check-ins stay focused on the operational. Tickets, outages, the printer on level two.

    So how do we know if we’re doing enough for the organisation when it comes to IT?

    Firstly, let’s not focus on perfect – I’ll write some more in the future about dialling in technology for your organisation. Most organisations would be well served to start with the basics; are you and your provider on the same page about what is actually happening? And are they following best practices?

    One of the reasons for the uncertainty is that IT, like law or accounting, carries a serious information asymmetry. Your provider has likely spent years learning their trade, and there’s no clear guide for you, the customer, on what good looks like. But unlike law or accounting, IT doesn’t come with strict professional standards or consumer protections to fall back on.

    So to break down some of that asymmetry, I want to share what I see in organisations where this relationship is working well, and some of the signs that things might be off track.

    What good looks like

    • You meet regularly with your account manager, or perhaps even the business owner.
    • You get the sense they understand how your business works, and how their services support it.
    • You receive written reports that show evidence of the work being done, in a form you can actually read and interpret.
    • Your agreement is detailed, current, and you’ve read it.
    • And at some point, you’ve had an independent set of eyes assess your security, or confirm the services you’re paying for are the right fit.

    Signs things might be off track

    • You can’t find a copy of the agreement at all. Or you can find it, and it’s under two pages, with no service level agreements and little detail about what the provider actually delivers.
    • No one meets regularly with the person who manages your account.
    • Your meetings are full of technical jargon, and you leave confused or frustrated.
    • And the only checks you’ve seen on security or performance have come from the provider themselves.

    None of these are reasons to panic, but they are signs to dig a little deeper.

    Take action

    We’ve built a tool that helps organisations understand what’s really happening in their IT, and whether they and their provider are on the same page. It’s called the Lumenas End-to-End IT Check. It produces a shared responsibility view showing what your provider covers, what sits with you, and where the gaps are. All in a short report you could take to your CEO or board.

    It takes one hour of your time, and not knowing the answers going in is the whole point. We’re looking for accidental IT leaders who want more clarity. Two weeks from now, you could have a clear picture of where things stand and how to move forward, in board-ready language, without needing a technology degree to read it.

    Find out more here, or email hello@lumenas.com if you’d like to speak with us about how to get more from technology in your organisation.


    This piece was originally published here on Linkedin as part of the Leading Digital series from Longitude Advisory.

  • Ice Cream Shop or Military Base?

    Ice Cream Shop or Military Base?

    Cyber security can often feel like a game of absolutes — either we’re secure or we aren’t. But it’s more complicated than that. The answer is almost always that we’re somewhere in between.

    Cyber risk, like all other risk, exists on a spectrum. We have to decide how much risk we can tolerate, then apply treatments and other mitigations to close the gap. Determining that tolerance is one of the most important technology decisions boards and executives make — it informs the whole cyber security program.

    But how do we know what our risk appetite is?

    One discussion exercise I run with organisations helps find the answer. Everyone in the room gives a number from 1 to 5 describing the organisation’s ideal cyber risk posture. One is an ice cream shop. Five is a military base.

    The purpose isn’t to land on some point in between that describes us perfectly. The purpose is to have an open conversation about the kinds of risks we face, the ways we use technology, and how much tolerance the business has for disruption.

    Take the ice cream shop. We’re probably taking digital payments and using some systems for ordering ingredients and managing staff, but we aren’t storing sensitive customer data. If we go offline, we can keep operating on cash, or take payments from a backup mobile terminal. Cyber hygiene still matters, but security may not be a major area of investment. Even at the low end the basics are non-negotiable — the scale starts from one because no one is at zero.

    Now think about the military base. Security is top of mind. We’re storing extremely sensitive information, and we need assurance that it hasn’t been accessed without authorisation or altered. The success of our information systems can be a matter of life and death — we rely on them for far more than information storage, from accessing controlled stores to communicating time-sensitive orders and managing access by identity and clearance. Here there’s serious investment in a layered security program that is continuously monitored, reviewed, and improved.

    Most of the organisations I work with land somewhere in the middle. The exercise gives us a group conversation that can challenge assumptions and build a consensus on what our ideal posture looks like. Usually we start with a few different positions in the room — some say three, some say five — and over the course of the discussion we work out why those positions were chosen. I’m yet to work with a group that couldn’t reach a consensus to carry forward into the decisions that follow.

    From there, I most organisations benefit from formalising the output of that discussion in a risk appetite statement. That can be used alongside governance activities like reviewing cyber risk assessments, developing treatment plans, or shaping an organisational cyber security program. As leaders, we can direct investment more confidently and understand the trade-offs we’re making with risk because we’ve had a clear conversation about what it actually means for our organisation.


     This article was originally published here on Linkedin as part of the Leading Digital series from Longitude Advisory.

  • Moving beyond digital transformation

    Over the course of decades, we’ve come to expect digital transformation to be a big event. These transformations are typically incredibly slow and expensive and the failure rate is astronomical. The impact on employees is serious, with each new wave of major changes adding to change fatigue, and sometimes mistrust if the transformation doesn’t deliver the proposed benefits.

    It’s time to change our approach. We can move from large-scale transformation to smaller adaptations as the world, and technology, changes around us  – instead of transformation, an evolution over time.

    Evolving to fit a changing world

    The process of digital transformation is unwieldy and exhausting – for those executing it and for those being constantly change managed. Big budgets and project management overheads see these large scale transformations embroiled in organisational politics and red tape. They also make them turn about as gracefully as a cruise ship in response to change. Perhaps the biggest challenge is that digital transformation is usually seen to have an ending. The teams roll off the program, the budget line ends, we are transformed.

    This approach is inherently flawed. The business needs continue to change, customer expectations move, and the team changes the ways they work and use technology – nevermind the changes in the technology itself!  In the old model, we let the needs continue to drift from our technological reality until it’s time for another transformation.

    There’s a different way to think about technology change. Rather than these monumental transformations, we can build organisations that are in a constant state of technological evolution.

    In organisations that embrace technological evolution, staff are adaptable, lifelong learners who embrace the opportunity to improve systems and processes as opportunities arise. Technology leaders and teams are engaged in problem solving as part of normal business, in partnership with teams across the organisation. Leaders can adapt quickly to new opportunities, like AI, because they are accustomed to evaluating new opportunities quickly and rigorously. They have guardrails for risk and a clear picture of ROI.

    In a digital evolution model, we do not wait until a system is completely broken, a process is deeply inefficient, or a risk has become urgent. We notice the early signs of drift and empower teams to adjust.

    Living governance is the key to making digital evolution possible. An organisation’s ability to continually understand whether its technology needs are changing and if its environment and tools are keeping pace, alongside clear guardrails so that teams can make change without huge overheads.

    Living governance

    The problem I run into most often is that leaders cannot govern what they cannot see and understand.

    During a transformation project, there is usually a lot of visibility. Either the internal team or a consultancy comes in and creates all the elaborate documents: current-state assessments, future-state designs, system inventories, roadmaps, risk registers, process maps, business cases.

    That point-in-time work usually ends up out of date and on a shelf very quickly.

    If we want to move from transformation to evolution, we need a living view of the technology environment. A way to see how technology connects to the things leaders actually govern: risks, vendors, costs, obligations, performance and strategic priorities.

    I’m not talking about documentation for its own sake (see the previous article on security theatre), or a technical catalogue that only IT can understand. Digital evolution relies on access to actionable information in real time, and a shared set of rules that democratise change at the lowest practical level of an organisation. It should help leaders see:

    • What has changed?
    • Is our environment fit for purpose today?
    • What about next year? Is our spend aligned with our priorities?
    • Are we within our risk tolerance?
    • What does good look like?

    If leaders cannot see the small issues, they cannot make small adjustments. Similarly, if teams need to wait for organisational leadership intervention to make adaptations, then small adjustments just aren’t practical. The small issues continue to accumulate.

    Then, eventually, the gap between the business and the technology becomes too big to ignore, and the organisation needs another major transformation. We’re back on the merry-go-round again! There’s a way to break out of that cycle.

    Digital transformation changes an organisation. Digital evolution keeps the organisation operating effectively in a changing world.

    Can you see your environment clearly enough to ask those questions and make adjustments?

  • The one thing economists love and IT hates

    The one thing economists love and IT hates

    The IT department has often been my first stop in any new job. This is because I often do pretty niche jobs, which means I need a different tech setup to most of the organisation. This has variously delighted and haunted my IT colleagues.

    In one job, I requested different permissions on my laptop so that I could update my special data science software more easily. This kind of software needs lots of little updates (often in the middle of my work) to keep functioning.

    It’s kind of like staying at a hotel and asking housekeeping for a freshly laundered pillow frequently – but not every night – because it alleviates otherwise-debilitating neck pain. Faced with this request, IT has three options: send someone to give me a freshly laundered pillow frequently (but randomly) on short notice, give me the key to the pillow room or give me the keys to every room in the hotel in perpetuity. They chose the third option.

    Why did IT give me the forever-master key to the metaphorical hotel? I would argue it’s because they probably thought the benefits outweighed the costs. This option gives me lots of flexibility to solve my own problems. I could try every pillow in the hotel (I didn’t), check if other people had different pillows to me (I didn’t, I don’t care) or go get a new pillow from the pillow room when I needed one (which I did). Choosing this option also benefits IT because they don’t have to answer my frequent, random emails and deliver each pillow. I also thought less emails were excellent because I’m impatient and urgent requests for a single freshly laundered pillow feel a bit ridiculous, even if there’s a sensible reason.

    But this option has a cost: an unacceptably low level of cybersecurity. While I never went into anyone else’s metaphorical hotel room, it is best practice to not give out master keys to hotel guests at random.

    In this instance, IT could choose this option because we hadn’t explained our preferences regarding cybersecurity, growth or much else. But even if you don’t explain your preferences, they will be revealed to you. Revealed preferences, the practice of identifying preferences through observation is generally the best measure of economic value thus loved by economists, and the worst way of managing tech thus hated by IT.

    IT people viscerally hate learning about a client’s preferences via observation, in my experience. But it’s often challenging to get a clear statement of preferences from non-technical business leaders. So they make-do with the information they’re given and trudge along.

    Some IT providers are able to bridge this tech-business communication gap. Consistently closing this communication gap across our economies will require more IT providers to have hard conversations with their non-technical bosses and clients. Those conversations will need to be a genuine two-way exchange to be useful, with investment on both sides.

    So how do non-technical (or ‘accidental’) leaders figure out their preferences in IT? Right now, you have three options: do the hard translation work yourself, hire a consultant or fractional CTO to do it for you, or get a better MSP.  At Lumenas, we’re building tools to make this work easier for all IT leaders, whether technical or accidental.

    Let me know if you’ve got a story like mine or are worried you might be living one. I’d love to hear more about people’s challenges in managing IT so we can help solve them.


    This piece was originally published on Linkedin here.

  • Leading Digital – A Digital Mindset

    Leading Digital – A Digital Mindset

    A digital mindset

    Today we’re talking about mindset. You’re already across what an enormous impact the mindset of a leader has on the team – I’m sure you can think of the good, the bad and the ugly that you’ve seen in the past!

    So what kind of mindset should we bring to digital leadership? There are two qualities that are critical for success; curiosity and adaptability. Most organisations handle technology on a project basis. You scope a need, choose a tool, implement it, and move on. Others layer on system lifecycle management – tracking updates, costs, and risks.

    But if you want to get real value from technology, you need something more. You need to shift from a set-and-forget approach to asking “is it as good as it can be today?”.

    Most modern organisations rely heavily on Software as a Service (SaaS) tools. New features roll out constantly and the organisations that unlock the most value are learning, adapting, and evolving how they use those tools are used over time.

    Take Canva, for example. I use it almost every day, but if I was still using it the way I did when I first signed up, I’d be missing out on half its power. The same applies to the tools your organisation uses every day. The real value comes comes from how your people keep using and evolving with tools over time. That might look like slow shift in process over time, or complete recreation of processes as new technologies streamline them.

    The mindset shift starts with leadership. When leaders model curiosity, adaptability, and alignment between tech and business goals, teams follow. Keep reading for some quick questions you can ask to make sure you’re getting the most out of technology for your teams.

    Leaders have been asking…

    Asking great questions is a leadership skill you already have. Here’s some tech questions you can ask your team to maximise tech ROI and model curious leadership.

    When you want to encourage the team to safely share ideas: “What’s one digital tool we use that you think we could be getting more out of?”

    When you’re considering whether to upgrade to a new system: “Before we look for something new, have we gone back to first principles on mapping our business process to the features this system has?”

    When your teams need to take on a new business process: “How can we support this with our existing tech systems? Are there parts of this process we could streamline for the team?”

    Some of these questions take a little time to investigate, but it’s often a case of slowing down to speed up. Business processes change over time just as much as software features do, but we rarely go back to mapping the two out together. You might be surprised how much time you can save!

    Take action!

    This fortnight, choose one process your team does all the time, like onboarding a new client or managing approvals. Sit down with the team and ask: “Could our existing tools support this better?” Spend 30 minutes together exploring what’s possible and capture one small improvement to test this month.

    It’s a small step, but you’re signalling to the team that you care about saving them time and that it’s okay to suggest tech and process improvements.


    This piece was originally published in the Leading Digital newsletter here.