Showing posts with label business value. Show all posts
Showing posts with label business value. Show all posts

Saturday, February 22, 2025

Data-Driven Data Strategy

One of the things I've been pushing for years is the idea that data strategy should itself be data driven. In other words, if we are claiming that all these expensive data and analytics initiatives are driving business improvement, let's see the evidence, and let's have a feedback loop that allows us to increase the cost-effectiveness of these initiatives. This is becoming increasingly important as people start to pay attention to the environmental cost as well as the monetary cost.

This idea can be found in my ebook How To Do Things With Data and my articles for the Cutter Journal, as well as on this blog.

I doubt anyone will be surprised by Gartner's recent survey, showing that although over 90% of the respondents acknowledged the importance of being value-focused and outcome-focused, only 22% were measuring business impact. So they clearly aren't eating their own dog food.

And the same thing applies to the current hype around AI. Tech journalist @LindsAI Clark asks will we be back in another 10 years wondering who is measuring the business value of all that AI in which organizations have invested billions?

I think we already know the answer to that one.

Lindsay Clark, Data is very valuable, just don't ask us to measure it, leaders say (The Register, 21 Feb 2025)

Richard Veryard, How To Do Things With Data (LeanPub) 

Richard Veryard, Understanding the Value of Data (Cutter Business Technology Journal, 11 May 2020)

Wikipedia: Eating your own dog food

 

Wednesday, March 03, 2010

From Collaboration to Business Value?

#AIIM @noelrath @jmancini77 via @dhinchcliffe @skemsley .

Dion and Sandy retweeted a list of 8 Ways to Make Sure That Collaboration Adds Business Value on John Mancini's blog, possibly authored by Noel Rath of HP. I just wanted to add a few critical comments here.


1 -- Collaboration is part of a process.


One way of looking at this argument is to say that it is the business processes that deliver business value. Therefore the only way for collaboration to deliver business value is through the business processes - for example, helping people to communicate more efficiently and to make more effective decisions - or perhaps helping the supervisory level of management to control and audit what is going on.

But we can think of this in two ways. One is to think of "collaboration" as some stuff that gets plugged into an existing process, plus some additional control mechanisms to prevent people actually using this stuff in ways that might produce "adverse business consequences". This approach may well result in a more complicated and only slightly more effective process.

Alternatively, we can think of "collaborative" as a radically new way of architecting and regulating processes - based perhaps on a cybernetic paradigm (for example Stafford Beer's Viable Systems Model), with the potential to optimize the business value obtained from the transformation.


2 -- Control is essential. 

3 -- Records management is a discipline. 
8 -- Records management should be back-end driven. 

The article asserts that control of information processes is critical to reduce risk, and that it is the role of information specialists to ensure that collaborative technologies support the business and do not introduce unintended consequences. I suspect that this refers to a fairly narrow conception of risk, defined in terms of uncertainty of outcome, which is what people worry about in fairly simple business situations. For more complex situations, we also need to think about ambiguity (uncertainty of meaning) and ambivalence (uncertainty of intention). Collaborative intelligence can be extremely valuable in helping to address these higher uncertainties, but this kind of intelligence doesn't thrive in the wrong kind of control environment.

4 -- Consider content sources and types.
5 -- SharePoint collaboration.

These two points are more about technical design rather than business value, so I don't want to comment further.

6 -- Educate.
7 -- Consider the knowledge worker.

The article advocates "educating" the knowledge worker to get more productivity out of them, but doesn't want to overload the knowledge worker with the responsibility of deciding what is important for the business. Sounds like a Theory X management style to me.


Overall then, the article is mostly about records management. No doubt people who are scared by the idea of genuine collaboration and organizational intelligence will be attracted by this kind of half-hearted approach, but it doesn't have much to do with my notion of collaboration or my notion of business value.

Thursday, October 29, 2009

Ecosystem SOA

The SOA world is finally catching up with some of the ecosystem ideas that I published in my 2001 book on the Component-Based Business (see my Slideshare presentation) and developed further in several articles and presentations for the CBDI Forum over a number of years.

The biological approach to creating business and software services is radically different to the solution-driven approach, and is based on biological and ecological metaphors.
  • First we identify an ecosystem, which may contain both human users and existing artefacts.
  • Then we identify services that would be meaningful and viable in this ecosystem.
  • Then we procure devices that enable the release and delivery of these services into the ecosystem.
I previously defined Three Types of Requirements Engineering, and we can map these onto different styles of SOA.


Solution-Driven (Specific)
Solution-Driven (General)
Evolution-Driven
Identify Business Problem


Identify "Users"


Negotiate Requirements


Define Solution
Identify Domain


Identify Domain Experts


Define Requirements


Design Solution Kit
Identify Ecosystem


Identify Services


Procure and Release Devices
Experimental SOA Enterprise SOA
Ecosystem SOA


(Some people use the term Web Oriented Architecture (WOA) for what I'm calling Ecosystem SOA.)


If we regard these as phases of maturity, then we can have a straightforward roadmap from left to right, as in for example the CBDI SOA Roadmap. However, some organizations may need to tackle these styles of SOA in parallel rather than in sequence.





A service portfolio plan for Enterprise SOA can be based on an enterprise model that identifies the capabilities of the enterprise and clusters these into domains. In the CBDI Forum's SAE methodology, the domains are classified as Core and Contextual according to a matrix derived from Geoffrey Moore. (Note how the domains migrate around the matrix over time.) See for example my blogpost Tesco outsources core eCommerce.

undefined

A similar model, derived from Amin and Cohendet's book Architecture of Knowledge, explicitly describes Core and Periphery in terms of knowledge intensity. In other words, the reason something is classified as Core is because it encapsulates some important (strategic) knowledge.



For example, an insurance company knows more about insurance than about cars, so when providing car insurance it may decide to partner with other organizations that know more about cars than about insurance. This results in a composition of insurance-related services and car-related services (for example, determining the insurable value of a used car). Such compositions can be either directed (in other words, composed by a single dominant player) or collaborative (in other words, emerging from the interaction between multiple players within the ecosystem).

For example, an online retailer knows about her products and services, but doesn't wish to become an expert in credit card handling, or to be responsible for data protection and security, so she delegates these concerns to a specialist provider that knows more about these matters.

Similar considerations can apply to industry consortia, such as ACORD (for the insurance market). ACORD can define generic service-based assets (such as models, schemas, interfaces and so on) for insurance. However, insurance companies will also wish to use generic service-based assets to cover requirements that are not insurance-specific, such as customer management or complaints handling, where ACORD may not be able to add any knowledge-value, and it would be appropriate for ACORD to regard these as peripheral to its own activities rather than core.




So one approach to Ecosystem SOA is to push out from the enterprise into the ecosystem. John Hagel calls this Inside-Out Architecture, which he contrasts with Outside-In Architecture. (See my post on Outside-In Architecture.)


An Outside-In Architecture starts with a model of (the flows of) knowledge and value in the ecosystem as a whole. The strategic question for an enterprise is how to find way of both contributing value to the ecosystem, and drawing value from the ecosystem, through the provision of ecologically viable services.



For example, a telecoms company might reasonably consider that its core competence is something to do with communications. So a positional strategy would drive it to a dominant position in the middle of a large communication ecosystem, providing a platform of services that add value to a diverse range of communication activities by other people. The dominant position would allow it to negotiate a strong share of the value generated.

However, respect for the ecosystem would lead it to leave sufficient value to third parties to maintain the economic health of the remainder of the ecosystem. Instead of a simple positional strategy, a relational strategy (based on mutual trust with ecosystem partners) should produce a more sustainable and ecologically sound ecosystem.



Service Ecosystem from Richard Veryard


Related post: Ecosystem SOA 2 (June 2010)

Friday, May 15, 2009

Customer Orientation

@adamshostack objects to something I quoted from Clayton Christensen: Understanding your customer isn't enough.

What Christensen is saying, and I absolutely agree with this, is that understanding the customer is the wrong level of analysis (granularity). What we need to focus on is the job the customers are trying to get done when they use your product or service.

Adam thinks this is "fascinating & wrong. W/o understanding customer orientation, you can't from job" (via Twitter).

I think pharmaceutical sales and marketing provides an excellent example of why Christensen is correct. As I have explained before, a typical twentieth-century business model involved drug company representatives making personal visits to doctors. To support this kind of model, you collected lots of information about the doctor - not just professional (size of practice, specialization, and so on) but also personal (ethnic group, sexual preference, ages of children, golf or squash). The drug company employed a range of representatives of different types, and selected the appropriate rep to visit a white gay squash-playing doctor.

The trouble with this business model is that it is not aligned with the products and services of the drug company. Doctors increasingly regard these kind of sales visits as a complete waste of time; even if they accept the hospitality of the drug companies, they have learned to be resistant to the sales messages.

What the drug company needs to focus on is how to provide more value to the doctor. For this purpose, you don't need information about the doctor, you need information about what the doctor actually does. In particular, you have to understand the decision process in which the doctor thinks about prescribing particular drugs to a particular patient, as well as the collaborative process in which the doctor and other healthcare practitioners discuss alternative courses of treatment with a patient.

Understanding the doctor is missing the point. The opportunity to create business value comes from understanding the work of the doctor. Different doctors may have different styles and habits, and may approach similar cases in different ways (although this is increasingly constrained by procedure and protocol imposed by health authorities or health insurance companies). That's the right level of analysis.

One technique we use for this analysis is business process modelling. But we're not interested in the company's own processes, we're interested in the customers' processes, and in the variations in these processes. Business survival depends on providing products and services that add value to these customer processes, so it's the customer processes we need to understand. Not the customer as a passive and indivisible entity (as in many CRM systems) but as an active bundle of behaviour and capability and purpose.


See also Clayton Christensen on jobs needing to get done (via Anders Sundelin).

Related post

Misunderstanding CRM and big data (November 2014)

Update: I have removed links to tweets by Chris Lawer and Gunnar Peterson, who were part of the original conversation, because the URLs in their tweets now point to irrelevant and NSFW content.

Saturday, May 02, 2009

Will Libraries Survive?

Following my post on Library Collaboration, Anders Jangbrand commented
"Book available on net do not have same limitation. No phys copies. Will libraries survive?"

That's an excellent question for two reasons. Anders always asks good questions, but another reason I like this one is because I am already working on an answer. But first a little history. 

In the dim and distant past when I first learned data modelling, one of the standard exercises in books and training courses was to model a library. These were of course models of the library as an information processing system. Before computing, libraries were managed with cabinets full of hand-written cards. There would be one or more cabinets containing the library catalog, there would be cabinets for members' names and addresses, outstanding loans, reservations, books awaiting repair, and so on. 

So it was an apparently straightforward task to model this lot; but there are some hidden traps for the beginner. For example, BOOK sometimes means the book title (as when you reserve a book) and sometimes means the physical copy (which is what you borrow and return). When I teach data modelling, I generally give students the freedom to fall into these traps so I can show them how to get out again. 

(Some libraries identify each physical copy individually, while other libraries merely count the physical copies of a given book title. The physical copies are distinct in the real world, but may be indistinguishable in the library's card or computer systems. Information strategy includes making this kind of choice. See Business Concepts and Business Types to see how this is handled in the CBDI SAE method.) 

The great advantage of using a library as a teaching example was that most people had used libraries and had some idea how they operate. However, some people started to think that the example was a bit old-fashioned, so they developed a Video Rental example instead. Video rental has pretty much the same information processing structure as a library, so all they needed to do was take the library example and change some of the words on the diagrams. And nothing much changed when video tapes were replaced by DVDs, although there were some minor complications if you wanted to handle both tapes and discs during the transition period. 

 The traditional library is indeed threatened, but it will probably outlive video rental, which is threatened by much the same forces to an even greater extent. If we want to manage these forces, we need to move away from an information processing model onto a different kind of model. 

Libraries and video rental operate a very similar information processing model. But if we want to think about the survival of libraries and video rental, we need a model that shows how libraries and video rental are different from one another, and to what extent libraries or video rental can play a valuable role in the service economy of the future. 

The first point to note here is that the book plays a much more varied role in people's lives than the video, even today. The vast majority of DVDs are either feature films or collections of TV programmes, consumed as entertainment, and video rental essentially caters for this market. Books are also consumed for entertainment, but they are also used for reference, study, research and other purposes, and most libraries support a broad range of purposes. If we want to forge a sustainable role for the library of the future, we need to engage with these purposes, and possibly explore some newly emerging purposes as well. 

Some people may argue that the business model should be technologically neutral. Anything you can do with a book, you can do with a DVD as well. For example, if you want to learn Spanish, it shouldn't matter whether you borrow a book from the library or rent a DVD. But until video rental gears itself up to support this kind of market, there will continue to be a real difference in the business model between books and DVDs. 

The next point to note is that we can open up the idea of the consumer. A lot of people like to read books in groups. The whole group reads the same book (see ambiguity of BOOK above), and then the members meet once a month to discuss the books. This represents an interesting opportunity for the librarian - to provide services to the whole reading group rather than to individual readers. For example, if the library has a dozen copies of a recent novel, then this novel can be offered to the local reading group for next month's meeting. 

Now suppose we have a network of a couple hundred libraries around the region, supporting a thousand reading groups between them. Recent novels can circulate around the libraries in sets, to support the needs and interests of the reading groups. 

 See what we've done here. All sorts of interesting business opportunities emerge by these two conceptual shifts. Firstly changing the concept of READER from individual to reading group (and creating a new composite service for the whole group). Secondly changing the concept of LIBRARY from single library to a network of libraries (and creating new kinds of collaborative process). 

Once we've identified these conceptual shifts, we can go back into the information processing model to work out the practical logistics. But the point I'm making here is that conceptual shifts of this kind (and the business opportunities that are associated with them) don't appear unless you step outside the information processing perspective and look at the business through a different lens. 

Of course I haven't quite answered Anders' question yet. But I'm working towards an answer ...

Friday, May 01, 2009

Library Collaboration

University libraries typically have a major resource scheduling problem, as I mentioned in my post on Collaboration and Context.

"Let's suppose that in the first week of February, sixty students suddenly want to read Kant. The university library possesses twenty copies of Kant's Critique of Pure Reason, so most of the students will have to wait or share. By the end of February, nobody wants to read Kant any more, and the twenty copies sit idle on the shelf until the same time the following year."

My first impractical idea for solving this problem was to get collaboration between the library and the teaching staff. Would it be possible to coordinate the teaching, so the students don't all need the same books at the same time? (Anyone who has worked in a university will know why I reckon this is impractical.)

My second idea might be a little more practical: to get collaboration between university libraries. Perhaps fifteen universities can share two hundred copies of Kant and ship them around as required. Possibly not as much scope for efficiency as my first idea, but it may be easier to implement, as it only involves librarians cooperating with other librarians rather than with professors.

However, the most plausible idea for solving the problem is to involve the paying customers - the students. In many countries higher education is subsidized by the state, but students and their parents are now being asked to pay a much higher contribution, and this makes them stakeholders in the economics of the university and the quality of its services.

So instead of thinking of this kind of business improvement purely as an optimization problem based on a series of information transactions, we need to think of it as a problem of power and influence - how can the interests of the students be mobilized to achieve better distribution of scarce resources.

Friday, April 17, 2009

Motoring as a Service

Listening to Power Drive, a BBC radio programme on electric cars. (I heard the live broadcast yesterday evening, and I have now downloaded the podcast from the BBC website to listen again).

I fully expected to hear the voice of Shai Agassi, and I was not disappointed. Until a couple of years ago, Shai was the rising star at SAP: the founder of Netweaver, the champion of service-oriented architecture (SOA) within SAP, frequently talked of as a future CEO. Then he suddenly quit the software industry to work on electric cars.

Shai was one of the first software executives to get the concept of business as a platform of services. (See my post dotBiz from January 2005). He is now talking about motoring as a service, with what he calls a platform-based approach to create a new business model. Shai's company Better Place is building a network infrastructure for rapid charging and battery replacement. (Coverage from about 17 minutes into the BBC programme.)

Shai makes five important points about a service-based approach to motoring.

  • Establish a separation between car and battery - when you reach a charging spot, you swap your empty battery for a fully charged battery.
  • Don't solve mileage problem by bigger batteries but by better infrastructure - put charging spots closer together.
  • We're getting the infrastructure right before we expect people to buy the cars.
  • Motorists pay for real service (mileage not car)
  • Shift the industry, not one car at a time. Car-makers should be able to make more profit with electric cars than gasoline-based cars.

The business model is copied from the mobile telephone business. The consumer has a choice between a pay-as-you-go model and a contract model. You can buy a low-mileage contract or an unlimited mileage contract. If you are willing to sign a 24 month contract, you get a better deal for your miles, and you may find a supplier willing to give you a free car.

Of course, this is only economically viable if you can get a large-scale adoption of the new technology. Shai talked about computer simulation models they are using to calculate the business case for a whole country (in terms of reduced oil imports) and to plan the distribution of capacity.

"You're still a software person at heart." says the interviewer and Shai agrees. "At the core of this is a huge software system", he says.

See also Shai Agassi: A bold plan for mass adoption of electric cars (TED Talks)

Thursday, April 09, 2009

IT Innovation at Small Bakery

Can your IT department innovate like this bakery? asks Mark Raskino (Gartner) via Sally Bean. Mark describes an East London bakery that uses Twitter to notify its customers whenever freshly baked bread comes out of the oven.

The system involves a specially designed wall-mounted device that the bakers can operate with one hand, while holding a tray of bread with the other.

Mark clearly doesn't think most IT departments would be comfortable with this kind of system. So I asked Mark and Sally who would lead that kind of innovation in a typical IT department. Would it be the business analysts? The enterprise architects?

The trouble is that many people in those kind of IT roles have been trained to value abstraction and adaptability above everything else, and to avoid thinking about mundane technology when building pure business models. But how often does that kind of abstract thinking produce concrete innovations like this bakery? In many organizations it is quite the opposite - technology-driven opportunistic change to the business model is discouraged because it runs contrary to prevailing thinking. And as Mark points out, corporate IT departments don't like purpose-designed hardware. This system is not designed for adaptability, it is designed to improve the business.

So this project was driven by a marketing agency. Business innovation may depend on the latest technology; but wouldn't it be a disgrace if it turned out that the most innovative companies are those too small to have an IT department?

Wednesday, March 25, 2009

Straight-Through Processing 3

Where have all the agents gone? asks Seth Godin. He is talking about travel agents, stock brokers, real estate, and so on.

"The problem with being a helpful, efficient but largely anonymous middleman is pretty obvious. Someone can come along who is cheaper, faster and more efficient. And that someone might be the customer aided by a computer."

Straight-through processing - sometimes seen as one of the potential sources of value from service-oriented architecture - is a mixed blessing, as I've pointed out before. There is always a danger of disintermediation, especially if the added value provided by the middleman appears trivial or easy to replicate. As Seth Godin points out, if you are just providing an anonymous human approximation of Google, don't bother - Google does it better.

In some industries, the middleman had become lazy - taking a cut for not doing very much. My local travel agent never gave me any useful information or advice, merely handed out brochures from the travel companies and struggled with the complexities of the booking system; so I stopped using them. And in the financial markets there are still companies that think they deserve a percentage of your pension fund in return for pressing a few buttons now and again.

In the past companies like these have often been able to take advantage of a strategic position in some larger process, extracting "rent" but without creating value. And there are doubtless still many niches in the system ecosystem that can be exploited in this way.

However, service ecosystem niches that allow companies to draw rent without creating value are going to be short-lived, and rightly so. In hard times, the percentage should only go to companies that are providing genuine value. (Actually the same principle applies all the time, but people are more motivated to follow this principle now than they have ever been before.) And ecosystem SOA should help us to make sure of this.

Then business strategy in a dynamic service ecosystem should not be based on finding and maintaining positional advantage, but on creating and maintaining genuinely productive relationships.


Previous posts

Tuesday, February 17, 2009

From Espresso to Instant

Starbucks is changing its business model. Or as CEO Howard Schultz tells the Huffington Post, Staying Real in an Instant. Starbucks will be selling shots of instant coffee, for under a dollar a cup. The UK price is said to be around 60p.

Some people may have thought that "espresso" was the Italian word word for speed. (It isn't - it means "pressed".) So what could be faster than express coffee? Instant coffee!

Of course the word "instant" isn't about getting the coffee more quickly either, it is about doing away with all that fancy machinery, in whose use Starbucks makes such a charade of training its baristas. (A year ago, Schultz ordered all US stores to close for a three-hour training session "as part of an effort to improve coffee quality and revive the chain's flagging fortunes" [Guardian, 26 Feb 2008].)

Shultz now claims to be responding to the increasing mobility of consumers. "Imagine a cup of Starbucks VIA Ready Brew on a mountaintop" he says, as if willing us to imagine millions of Starbucks customers on some remote and implausible trek.

But clearly his real interest is selling mass market coffee. He hopes that the Starbucks instant coffee will be not only better-tasting but also "paradigm-changing" (whatever that means), and hopes "to turn on a whole new set of coffee drinkers to the Starbucks brand". But the obvious risk is that the old set will be turned off. He acknowledges that this move is a gamble (he calls it "a considered bet"), and expects "to learn a lot ... over the coming weeks". You bet.

In what sense does this count as a new business model? Starbucks already sells ground coffee and coffee beans in supermarkets across the USA. Many rival coffee purveyors have already shifted to the Gillette model, in which the coffee machines are sold cheap or practically given away, and you make your money selling overpriced pods of coffee.

The challenge faced by Starbucks is not choosing one business model, but attempting to combine two or three different (and possibly incompatible) business models at the same time. Such composition faces questions of cross-subsidy, brand dilution or erosion. Are there any reliable rules or patterns governing the interoperability (compatibility and composition) of business models?

See also
Update

Sunday, February 08, 2009

Business Model and Financial Viability

A venture capitalist called Fred Wilson goes back to basic economics - When Talking About Business Models, Remember That Profits Equal Revenues Minus Costs. As Phil Wainewright comments "Has the world become so blind to the basics of commerce that it needs reminding of such a basic tenet? Apparently yes."

Fred is certainly not saying that all companies should try to survive on current revenues alone. Clearly there will be many companies that will continue to attract investment based on future projected revenue - that's exactly where the venture capitalist comes in. However, the viability of a start-up company is entirely dependent on the willingness of people to invest their time, energy and money against some future returns.

What Fred is saying is that these returns are ultimately based on profit rather than revenue. Start-up companies can no longer afford to employ large number of people, if that merely results in a slightly better product and slightly higher revenues. What matters to the venture capitalist are such ratios as operating leverage - how much projected revenue per employee.

Leverage rather than size. Bigger isn't necessarily better. In the recent past, many mergers and acquisitions have been justified in terms of financial engineering rather than genuine creation of value. Fred's point is that even organic growth is suspect if it doesn't make the organization more viable. Why on earth does Facebook (for example) need a thousand employees? What value are they actually going to produce?

A few years ago, we had people asking What is the Right Size of a Service? Now I think the industry is ready to ask the next question: What is the Right Size of a Service-Oriented Business? Many organizations oscillate unstably between uncontrolled growth and painful cost-cutting. It would be better to have a more stable approach to questions of size and viability, and the business model needs to help us with these questions: What is the ideal size of a given business, and how can this size be maintained?


Update: See Seth Godin on The Right Size

Saturday, January 17, 2009

Business Model Drives Security

Gunnar Petersen (What's Your Business Model?) quotes Ian Grigg (What's Missing in Security: Business - see footnote).
The bit that's missing is the business. Instead of asking "What's your threat model?" as the first question, it should be "What's your business model?" Security asks that last, and only partly, but asking questions like "what's are the risks?"
Clearly this is what I'm calling Business Model B - what is the source of value for this enterprise - rather than Business Model C - the line-and-box diagrams drawn by Enterprise Architects. See Two Kinds of Business Model.

Gunnar takes an asset-based approach to building such a business model - what are the assets and how do we protect them. Gunnar has always argued that security should be proportional to asset value. I think that's a reasonable starting point, as long as we take a broad view of what counts as an asset, and whose assets are included. In particular, companies should expect to accept liability for any loss or damage to customer assets or third-party assets. See my post Services Like Laundry, where I argue that the potential liability for a dry-cleaner is based on the likely cost of replacing any damaged item, rather than just the cost of the dry-cleaning service.

But the asset perspective is not the only way of thinking about business-driven security. Consider a large retailer, deciding what policies and mechanisms to adopt against shoplifting. This will partly be based on the expected value of the shoplifted items - so the small higher-priced items may have higher levels of protection. But this should be balanced against the business process or cashflow perspective. Is it better to lock goods into cabinets, lose fewer to shoplifters but maybe sell fewer as well? Or is it better to encourage shoppers to handle the goods, resulting in more sales as well as more theft? This is clearly a business judgement, which should not be solely based on the value of the goods. [And see my post on Shoplifting]

Overall, we need a business model that defines the sources of business value. This may include a broad concept of asset, but also broad concepts of capability and viability. Then I absolutely agree with Gunnar and Ian - the security model must be driven by the business model.


Note: Ian's blog Financial Cryptography has an security certificate that is not recognized by Firefox or Internet Explorer, for reasons he explains in the comments to Gunnar's blog. Visit it at your own risk.

Note: The RESG hosted a masterclass on Security Risk Analysis and Management in January 2003. See report with my comment in the RESG Newsletter (RQ28 Feb 2003).


See also: Services Like Laundry (April 2008), Event Processing Example - Shoplifting (September 2008), Two Kinds of Business Model.(December 2008), Security Drives Business Model (January 2009),

Wednesday, November 05, 2008

Business Value from SOA - Sharecropping

This post starts by talking about the value proposition of Web 2.0, and then makes some more general points about the distribution of value in a layered system-of-systems.

A couple of years ago, Nick Carr suggested that a lot of Web 2.0 business was akin to sharecropping. The platform (MyFace or FlickTube or whatever) owns the space, and the users grow the content.

I think the most interesting aspect of this metaphor is the idea of a stratification of value, with different value proposition in each stratum. As Nick puts it "sharecroppers operate happily in an attention economy while their overseers operate happily in a cash economy".


Some people interpreted this as implying some kind of exploitation, and there have been vigorously defensive rebuttals of Carr's suggestion.

Ed and Mike both insist that there is a connection between the attention economy and the cash economy. And this connection is evident from the success of Second Life as well, where there is a reasonable stable rate of exchange between virtual money and real money. For that matter, there is even a rate of exchange between virtual crime and real crime [Woman in Jail Over Virtual Murder].

But Nick isn't denying a connection between the platform provider's value proposition and the platform user's value proposition: indeed he too insists they are connected, but also points out that they are different.


Tim Bray had previously used the sharecropping metaphor to refer to independent developers building applications on major platforms. Here too we have a complex layered ecosystem, in which different stakeholders build value in a positive-sum game, but with some significant trust issues arising from the asymmetric relationships.



Let me end my making a more general point, which I think is applicable to all kinds of layered systems-of-systems and not just Web 2.0. In a stratified ecosystem, there is at least the possibility that value is created by a platform provider, and that another kind of value is provided by the platform user, and that these two kinds of value interact in a complex way. Clearly we would like to know what kinds of stratification are most conducive to value creation, and this is a fascinating architectural question with no easy answers.

Tuesday, November 04, 2008

Business Value from SOA - Longtail Optimization

Someone who hides behind the sobriquet "Mr Web Service" has posted an interesting idea: that software-as-a-service permits small firms to optimize fine details of their business operations, where this would previously have required the acquisition and installation of expensive software.[Software as a Service (SaaS) & UK/US Credit Crunch]

The (self-interested) example he posts is route-optimization-as-a-service, which is provided by German firm DNA Evolutions as well as his own company PostcodeAnywhere.

"Who can benefit from this? SMEs in the haulage industry who can’t afford the $90,000+ price-tag on traditional software that does the job. So far they’ve got by without it… all the SMEs have got by without it. This is an extreme example, of course, because route opt can reduce journey times by 30%. A lot of SaaS apps make less obvious savings or increases in efficiency. ... Now we’re facing a recession (sorry … credit crunch…) everybody is going to be forced to tighten their belts. In short, business will have to adopt SaaS in order to remain competitive."

This argument is making a fundamental point about the economics of scale. Whereas in the past this kind of capability only made economic sense for relatively large operations, SaaS makes this optimization capability available to small operations as well. So we are replacing the economics of scale with the economics of scope.

As Mr WebService admits, there may be some resistance to changing business practices in times of trouble (speaking words of wisdom: "Let It Be"). The total cost of deploying this kind of service is not just the cost of the software, but also needs to include the time and effort to get all the bits of the business process to work efficiently and effectively together - process design, testing and management.

So this raises the question how easy is it to use this kind of service - not just calling it in isolation but building it into an idiot-proof business process. How straightforward are the interfaces, how does this route optimization plug together with driver scheduling and vehicle refuelling and all the other capabilities? Do the different service providers have a common protocol, so I can switch easily from using the PostcodeAnywhere service in the UK and the DNA Evolution service in Germany? If I have to ship goods from Newcastle to Neuschwanstein, or from Evenburg to Edinburgh, how do I mix the two services?

Mr Webservice is probably right to identify some potential business value here, but there may be some more work to do to make this a genuine proposition for small companies.

"And when the software's cloudy,
There is still a web service for me.
Optimize tomorrow, let it be."

Tuesday, October 28, 2008

Business Value from SOA - Silo Busting

One of a series of posts exploring the business value from SOA.

A common complaint about legacy IT is that it is organized into silos. This doesn't just affect legacy systems, but it may also affect new projects.

In his classic book on the evolution of buildings (How Buildings Learn), Stewart Brand showed how the townscape often lasted longer than the buildings themselves. In an already built-up area, new buildings typically occupied the same footprint as the old building it replaced. The same is often true of new IT systems - the functionality may extend into previously unoccupied areas, but it is more difficult to make radical changes to the boundaries between systems. I have a lot about this in my 2001 book on the Component-Based Business.

But if the sponsorship and funding for new IT projects emerges from a host organization, and if the host organization is itself organized into functional silos, then it is hardly surprising when this structure is reflected in IT. This is an example of Conway's Law.

So we have long argued that new modes of IT sponsorship and funding need to be developed if an organization wishes to get maximum benefit from SOA. But what about the effects on the host organization itself?

There is now a strong pressure within the business world for silo-busting. This is nothing to do with IT, and everything to do with making business operations more effective and joined-up. Ranjay Gulati, a professor at the Harvard Business School, published an article on Silo-Busting last year (Silo Busting: How to Execute on the Promise of Customer Focus, Harvard Business Review, May 2007). He argues that "companies claim to offer customer solutions, but most aren’t set up to deliver them without specific changes in organizational structure, incentives, and relationships". I'm looking forward to reading his forthcoming book on the same subject.

A quick search for Silo Busting finds the idea applied to several areas of management.
  • Healthcare ("health care organizations suffer from internal functional barriers that get in the way of achieving the level of success that they want and need"): Leta Beam (April 2006 pdf), R. Wade Schuette (September 2006)
I also found some material from an improvisational comedy group, which trains managers to develop a silo-busting mentality (August 2003).

So this is a common theme within the business literature, and SOA offers strong support, especially for multi-channel operations.


Gulati identifies four success factors for silo-busting
  • Coordination (Structure and Process - this is the first area where SOA and BPM can help)
  • Cooperation (Sharing - this is where Web 2.0 or Enterprise 2.0 can help)
  • Capability Development (this is perhaps where improvisational comedy comes in)
  • Connection with Customers (there is a secondary role for SOA in providing joined-up customer-facing services)
But how much is this worth?

Conway's Law doesn't work in reverse. You can't just build joined-up systems and hope that the desired organizational change will follow automatically. There is always going to be a larger organizational change programme, with a significant but not exclusive role for SOA (and related activities, especially Service-Oriented Business Modelling). So it is hard to quantify exactly how much business value is created by the SOA piece. But we may be able to get some clues from the organizational change projects people are already doing ...