Mike Williamson

288 Followers
425 Following
1.4K Posts

Digital Transformation = Agile + APIs + AppSec

Security Architecture, Programming.

bloghttps://mikewilliamson.wordpress.com
githubhttps://github.com/sleepycat
Code: Worktree.cahttps://worktree.ca/sleepycat/

RE: https://mastodon.social/@tdpauw/116709030423523606

"Yet, at the boundaries, the organisation must adapt and respond to changes in the environment. Therefore, it has to be open to environmental signals. As such, at its boundaries, it is an open system."

...

"While Emery & Trist define the external textures and Thompson explains the organisational structure to survive the environment and isolate the core work, Jay R. Galbraith articulates organisation design using a micro-level dimension: the flow of information."

I present to you the oval of enterprise sadness.

The meetings required to not just experience this, but realize it's a pattern is not something I would wish on others.

#kubernetes

Breaking up monolithic "cloud" teams has been something I've found myself arguing for lately.

Most of the orgs I've worked for have a "cloud" team, which is actually an IaaS team.

I've tried illustrating the gap between traditional IaaS and modern PaaS/CaaS/FaaS.

The governance, tools, skills and ways of working are all different enough that a single monolithic "cloud" team isn't likely to cover them both.

At the working level: Be a good example of whatever paradigm you're in.
Execs: Please don't put the same people in charge of multiple (largely opposite) paradigms.

#gcdigital

For those not familiar with the #integrationDatabase (anti)pattern:

"On the whole integration databases lead to serious problems because the database becomes a point of coupling between the applications that access it.

This is usually a deep coupling that significantly increases the risk involved in changing those applications and making it harder to evolve them. As a result most software architects that I respect take the view that integration databases should be avoided."

https://martinfowler.com/bliki/IntegrationDatabase.html

bliki: Integration Database

An integration database is a data store for multiple applications, thus integrating them through data storage. This leads to excessive coupling that makes change risky and expensive.

martinfowler.com

Putting the #Enterprise into
the #EnterpriseSystem

I ran across this paper about #ERP systems. The idea that these things are just a giant integration database explains so much.

http://facweb.cs.depaul.edu/jnowotarski/is425/hbr%20enterprise%20systems%20davenport%201998%20jul-aug.pdf

#DevOps #Team #structures Characterization and Implications

"We describe a taxonomy of team structure patterns that shows emerging, stable and consolidated product teams that are classified according to six variables, such as collaboration frequency, product ownership sharing, autonomy, among others, as well as their implications on software delivery performance."

https://ar5iv.labs.arxiv.org/html/2101.02361v1

DevOps Team Structures: Characterization and Implications

Context: DevOps can be defined as a cultural movement to improve and accelerate the delivery of business value by making the collaboration between development and operations effective. Objective: This paper aims to hel…

ar5iv

#Compliance does not equal security. It did not when I was in industry, and it does not from my seat where I am today. We must pursue a relentless focus on operational resilience, which is a byproduct, a dynamic fit for purpose cybersecurity posture,” she said.

#DoD #security
https://breakingdefense.com/2026/06/dod-cio-implores-industry-to-put-a-greater-focus-on-foundational-cybersecurity/

DoD CIO implores industry to put a greater focus on ‘foundational cybersecurity’

“Compliance does not equal security. It did not when I was in industry, and it does not from my seat where I am today," DoD CIO Kirsten Davie said.

Breaking Defense

RE: https://hachyderm.io/@trondhjort/116684930565655979

“Projects and products are not different delivery methods; they are different theories of what a problem is.” Are you executing a solution, or solving a problem? They’re different activities!

I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

Their agents will.

You gave a stranger with no soul and no skin in the game the keys to everything you own.