2019 Deloitte Power & Utilities Conference Power is not static December 3-4, 2019 Bits, Bytes & Barrels” webinar
2019 Deloitte Power & Utilities ConferencePower is not staticDecember 3-4, 2019
Bits, Bytes & Barrels” webinar
To cloud or not to cloud: the future of the
ERP
Eli Black, Senior Manager, Deloitte & Touche LLP
Copyright © 2019 Deloitte Development LLC. All rights reserved. 3
Contents
The journey is now more desirable 5
Understanding the journey 10
Preparing for the journey 15
Copyright © 2019 Deloitte Development LLC. All rights reserved. 4
The journey is now more desirable
Copyright © 2019 Deloitte Development LLC. All rights reserved. 5
Many organizations take advantage of trends underway, but being reactive is not enough to power your organization’s future!
What is the Finance Department’s role?
Cloud is dominating enterprise information technology
• Why is this important?
• When will we see the full potential?
Conventional analytics are insufficient
• Is your organization capable of evolving?
• What will help drive new questions?
Digital experiences are the foundation of the future
• What is the digital world of tomorrow?
• What does it take to engage customers and employees?
The Cloud, analytics, and digital accelerators are driving innovationThe future of business transformation is here
Copyright © 2019 Deloitte Development LLC. All rights reserved. 6
Disruptive shifts are prompting executives to ask fundamental questionsCompanies should work methodically to stay ahead of new innovations
Cloud is changing how to build, procure, and maintain and support functions
Agile is increasing collaboration between the business and IT
Rapid advances continue in process automation and cognitive / AI / ML
Talent is increasingly sourced from the open economy
Exponential proliferation of technologies are requiring greater tech fluency
Disruptive shifts
How will the workforce be reimagined and recomposed?
How will leadership enable the culture to embrace new ways of working truly digital?
How will work shift as process automation and cognitive rebalance the workforce?
How should the workplace change in order to improve collaboration?
What will the future operating model look like to better integrate with the business?
Org & talent implications
Copyright © 2019 Deloitte Development LLC. All rights reserved. 7
Cloud is the fabric underpinning how technology services will be consumedA mindset shift is already underway transforming organizations
NEW NORMAL…
$206B Estimated 2019 global spend on cloud services1
NOT JUST IN IT…
>50% IT spend occurring outside of the IT department2
ROOM TO GROW…
By 202580% of enterprises will have shut down their traditional data center3
Data Center & Cloud workload comparison
Sources: 1: Gartner press release Sept. 2018, https://www.gartner.com/en/newsroom/press-releases/2018-09-12-gartner-forecasts-worldwide-public-cloud-revenue-to-grow-17-percent-in-20192: IDC, April 2018, https://www.idc.com/getdoc.jsp?containerId=prUS437224183: Gartner ‘Prepare for the Death of the Data Center”, May 2018
0%
50%
100%
2006 2016 2021
Copyright © 2019 Deloitte Development LLC. All rights reserved. 8
More Cloud implementation costs can be capitalized under new accounting guidanceCapitalization guidance on Cloud computing arrangements has changed
The rules are changing with new accounting guidelines for capitalization of Cloud implementation costs under a service arrangement effective January 1, 2020. Companies can now follow the same guidelines as capitalizing costs for developing or obtaining internal-use software. Thus, capitalizing more costs allows the spreading of these costs over a longer horizon, making the move to Cloud more desirable.
Copyright © 2019 Deloitte Development LLC. All rights reserved. 9
Understanding the journey
Copyright © 2019 Deloitte Development LLC. All rights reserved. 10
The cybersecurity focus needs to shift as new risks are introduced by the CloudOrganizations are moving to the Cloud whether they are ready or not
Users became mobile but the perimeter remained the same
Organizations struggle as Cloud technologies increase the attack surface
The crown jewels remained safe if the perimeter remains intact
Copyright © 2019 Deloitte Development LLC. All rights reserved. 11
Organizations are challenged managing their Cloud migration journeyMoving to the Cloud needs to go beyond lift and shift
123
Traditional controls for managing security and compliance are not sufficient in Cloud environments
Misconfiguration and mismanagement of Cloud infrastructure is a leading threat
Cloud-native controls are needed to address Cloud specific threats and proactively protect data
Copyright © 2019 Deloitte Development LLC. All rights reserved. 12
Cloud adoption comes with cyber risk challenges that should be addressedImplementing an effective strategy will enhance governance and reduce risks
Risks and controls may not be aligned to industry standards and leading
practices
To address these challenges organizations need to
understand their responsibilities vs. the Cloud provider
Many organizations face significant challenges when migrating to the Cloud
Sophisticated threats may not be adequately modeled
to thwart well-funded skilled adversaries
Data proliferation of confidential information in the Cloud and on premises
may increase risk
Incorporation of Cloud into existing governance processes and operational workflows may be disruptive
Complex user profiles may be used by employees and contractors adding to the risk
A complex regulatory environment may hinder mapping data residency
requirements
Copyright © 2019 Deloitte Development LLC. All rights reserved. 13
Understand your Cloud governance and controls across cyber security domainsManaging cyber risk is a shared responsibility
Security in Cloud is the Company’s responsibility
Security of Cloud is Provider’s responsibility
Copyright © 2019 Deloitte Development LLC. All rights reserved. 14
Preparing for the journey
Copyright © 2019 Deloitte Development LLC. All rights reserved. 15
There are certain milestones to track in the journey to secure the CloudThe path to a secure Cloud is not straightforward
Assess Cloud risk & current capabilities
Establish broad Cloud governance
Prioritize security capabilities
Implement security capabilities
Automate security operations
Copyright © 2019 Deloitte Development LLC. All rights reserved. 16
Focus on Cloud complexities and develop a continuous monitoring strategyCloud transformation can begin with focusing on a few important areas
Increased Security
Agility
Visibility & ControlStrong Cloud governance will
enhance oversight and organizational education
Cost-Monitoring
Metrics
Managing cost is essential, identify solutions to help control
spending and monitor budgets
Clearly defined policies and controls are needed to decrease security failure
Increased agility requires a means to perform integrity checks without delaying advances
Measure quality and speed of deployments to attain the desired
benefits
Copyright © 2019 Deloitte Development LLC. All rights reserved. 17
The fundamentals remain the same, assess your people, processes, and technologiesPreparation for 2025 means addressing Cloud cyber risk trends
Notable Cloud cyber risk trends What does this mean for your organization?
Data protectionAs cloud services become common the risk of sensitive data being exposed increases.
• Develop appropriate data classification schemas• Implement effective controls to protect data• Be aware of regulatory environment changes
Application securityApplication development is outpacing organization’s ability to properly secure the data.
• Incorporate security throughout development• Implement native or third party security controls• Evaluate ability to comply established controls
Infrastructure securityIncreasing use of multi-cloud environments results in control complexities.
• Obtain visibility into services and assets deployed• Create secure default configurations• Automate provisioning of security controls
ResiliencyIncreased use of cloud to support the business is driving higher uptime but 100% availability is not guaranteed.
• Architect solutions for desired uptime• Monitor for cloud denial of service attacks• Develop incident response plan for cloud threats
Copyright © 2019 Deloitte Development LLC. All rights reserved. 18
A round of questions and answers
This publication contains general information only and is based on the experiences and research of Deloitte practitioners. Deloitte is not, by means of this publication, rendering business, financial, investment, or other professional advice or services. This publication is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte, its affiliates, and related entities shall not be responsible for any loss sustained by any person who relies on this publication.
About DeloitteDeloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a UK private company limited by guarantee (“DTTL”), its network of member firms, and their related entities. DTTL and each of its member firms are legally separate and independent entities. DTTL (also referred to as “Deloitte Global”) does not provide services to clients. In the United States, Deloitte refers to one or more of the US member firms of DTTL, their related entities that operate using the “Deloitte” name in the United States and their respective affiliates. Certain services may not be available to attest clients under the rules and regulations of public accounting. Please see www.deloitte.com/about to learn more about our global network of member firms.
Copyright © 2019 Deloitte Development LLC. All rights reserved.