{"id":31044,"date":"2019-12-18T15:03:10","date_gmt":"2019-12-18T15:03:10","guid":{"rendered":"https:\/\/www.intelligentcio.com\/africa\/2019\/12\/18\/what-lies-ahead-for-applications-in-2020\/"},"modified":"2019-12-18T15:03:14","modified_gmt":"2019-12-18T15:03:14","slug":"what-lies-ahead-for-applications-in-2020","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/africa\/2019\/12\/18\/what-lies-ahead-for-applications-in-2020\/","title":{"rendered":"What lies ahead for applications in 2020?"},"content":{"rendered":"\n<p><em>Vincent Lavergne, RVP of System Engineering at F5 Networks<\/em>, <em>suggests some New Year&#8217;s resolutions for IT leaders to ensure successful transformation in 2020. <\/em><\/p>\n\n\n\n<p>Without wheeling out all the usual clich\u00e9s, 2019 has been\nanother whirlwind of disruptive innovation and opportunity \u2013 with plenty of\nchallenges to tackle and circumvent along the way.<\/p>\n\n\n\n<p>The threat landscape mutated with predictable unpredictability, multi-cloud app deployments are becoming mainstream fixtures and DevOps methodologies started exerting a newfound influence on business plans.<\/p>\n\n\n\n<p>The big question is: what happens next? What anticipated app-centric trends will change the game and tear up the rulebook (again)?<\/p>\n\n\n\n<p><strong>Digital Transformation takes hold<\/strong><\/p>\n\n\n\n<p>2020 will see more organisations shift away from aspirational sloganeering to substantively embrace what can and should be a seismic step-change.<\/p>\n\n\n\n<p>Inevitably, business leaders\nwill get more involved in application&nbsp;decisions designed to differentiate\nor provide unique customer experiences.<\/p>\n\n\n\n<p>Expect a new generation of applications that support the scaling and expansion of businesses\u2019 digital models to emerge. This will include taking advantage of cloud-native infrastructures and\u00a0driving automation through software development.\u00a0 <\/p>\n\n\n\n<p>Further down the line, Digital Transformation efforts will likely be AI-assisted, particularly as they leverage more advanced capabilities\u00a0in\u00a0application platforms,\u202ftelemetry, data analytics and ML\/AI technologies.<\/p>\n\n\n\n<p>End-to-end instrumentation will enable application\u00a0services to emit telemetry and act on insights produced through AI-driven analytics. We anticipate that these distributed application services will improve performance, security, operability\u00a0and adaptability without significant development effort.\u00a0<\/p>\n\n\n\n<p><strong>The era of Application Capital <\/strong><\/p>\n\n\n\n<p>Applications are now firmly established as the main conduit for\ncompanies to develop and deliver goods and services. They have become modern\nenterprises\u2019 important assets.<\/p>\n\n\n\n<p>Even so, most still only have an\napproximate sense of how many applications they have, where they\u2019re running, or\nwhether they\u2019re under threat.<\/p>\n\n\n\n<p>This will soon change.<\/p>\n\n\n\n<p>To manage Application Capital effectively, it is essential to establish a company-wide strategy that sets policy and ensures compliance. This includes addressing how applications are built, acquired, deployed, managed, secured and retired. At a high level, there are six distinct and unavoidable steps that need to take place: build an inventory, assess the cyber-risks, define application categories, identify the application services needed for specific activities, define deployment parameters and clarify roles and responsibilities.<\/p>\n\n\n\n<p>The primary aim of an application\nstrategy should always be to enhance and secure all digital capabilities \u2013 even\nas their reach and influence shift and expand.<\/p>\n\n\n\n<p><strong>Collaboration\nis key<\/strong><\/p>\n\n\n\n<p>The technical minutiae DevOps methodologies and associated tools got a lot of publicity in 2019. <\/p>\n\n\n\n<p>2020 will be all about getting the culture right, marrying\ntheory with best practice and unlocking new levels of productivity without\nupsetting the operational apple cart.<\/p>\n\n\n\n<p>Culture is not optional. Team structure alone dramatically\nchanges pipeline automation, with traditional single-function teams often falling\nbehind their contemporary, DevOps-driven counterparts. <\/p>\n\n\n\n<p>Consequently, we will see more collaborative team\nstructures and alignment on key metrics that give NetOps additional means to\nfocus on what the business requires: faster and more frequent deployments.<\/p>\n\n\n\n<p>DevOps has a 10-year head start on NetOps in navigating and overcoming obstacles around certain types of integration, tools and skillsets. Collaborative teams can explode the status quo by promoting standardisation on tools that span from delivery to deployment (like Jenkins and GitHub\/GitLab).<\/p>\n\n\n\n<p>DevOps should not \u2013 and cannot \u2013 end with delivery. That\nmeans deployment functions \u2013 along with a complex pipeline of devices and\napplication services \u2013 must be automated. This won\u2019t happen without effective cultural\nrealignment.<\/p>\n\n\n\n<p><strong>The return of the data centre<\/strong><\/p>\n\n\n\n<p>Conflating\nthe adoption of SaaS with IaaS caused speculation that cloud was cannibalising\nIT. Pundits warned that data centres would disappear. <\/p>\n\n\n\n<p>The\nrumours were exaggerated. Data centres are still being built, expanded and run\naround the globe. The cloud hasn&#8217;t managed to \u2013 and likely never will \u2013 kill\nthe data centre.<\/p>\n\n\n\n<p>Early in 2019, an IDC executive told channel partners at the IGEL Disrupt conference that over 80% of companies they surveyed anticipated repatriating public cloud workloads. Security, visibility and performance remain common concerns.<\/p>\n\n\n\n<p>Repatriation-related\nopportunities include improving availability of multi-cloud operational tools\nand a push towards application architectures that rely on more portable\ntechnologies such as containers. <\/p>\n\n\n\n<p>The data centre is not dead. It&#8217;s just evolving. <\/p>\n\n\n\n<p><strong>Tailormade security<\/strong><\/p>\n\n\n\n<p>According to F5 Labs, the server-side language PHP \u2013 used for at least 80% of websites since 2013 \u2013 will continue to supply rich, soft targets for hackers. Situational awareness is critical to mitigate both vulnerabilities and threats.<\/p>\n\n\n\n<p>Businesses are also realising that applications encompass more than just the code that they execute. Attention needs to be paid to everything that makes them tick, including architecture, configurations, other connectable assets and users. The prevalence of access attacks such as phishing are an obvious case in point.<\/p>\n\n\n\n<p>F5 Labs analysis of 2019 breach data confirms the need for risk-based security programmes instead of perfunctory best practice poses or checklists. Organisations need to tailor controls to reflect the threats they <em>actually<\/em> face. The first step in any risk assessment is a substantive (and ongoing) inventory process. <\/p>\n\n\n\n<p>As ever, the industry will gradually incorporate emerging risks into business models. For example, cloud computing has gradually shifted from a bleeding-edge risk to a cornerstone of modern infrastructure. The risks associated with the cloud have either been mitigated or displaced to contractual risk in the form of service level agreements and audits. <\/p>\n\n\n\n<p><strong>Keeping a watchful eye on API<\/strong><\/p>\n\n\n\n<p>The word is out. Application programming interfaces (APIs)&nbsp;can\ntransform business models and directly generate revenue. Cybercriminals know\nthis.<\/p>\n\n\n\n<p>More than ever, organisations need to focus on the API layer,\nparticularly in terms of securing access to the business functions they\nrepresent.<\/p>\n\n\n\n<p>One of the biggest issues is overly broad permissions, which means attacks through the API can give bad actors visibility into everything within the application infrastructure. API calls are also prone to the usual web request pitfalls such as injections, credential brute force, parameter tampering and session snooping.<\/p>\n\n\n\n<p>Visibility is another major and pervasive problem. Organisations\nof every stripe \u2013 including IT vendors \u2013 have a notoriously poor track record\nof maintaining situational API awareness. <\/p>\n\n\n\n<p>API security can be implemented directly in an application or, even better, in an API gateway. An\u00a0API gateway can further protect APIs\u00a0with capabilities like rate limiting (to prevent denial of service attacks) and authorisation. Authorisation narrows access to APIs by allowing access to specific API calls to only specified clients, usually identified by tokens or API keys. An API gateway can also limit the HTTP methods used and log attempts to abuse other methods so you&#8217;re aware of attempted attacks.<\/p>\n\n\n\n<p>All this is of course the tip of an increasingly interconnected iceberg. Any New Year\u2019s resolution worth its salt should include a commitment to comprehensively master the development, deployment, operation, and governance of application portfolio. The best way to do this and to get visibility into the code-to-customer pathways for all applications is to leverage a consistent set of multi-cloud application services. Here\u2019s to a safe, innovative and transformational 2020.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Vincent Lavergne, RVP of System Engineering at F5 Networks, suggests some New Year&#8217;s resolutions for IT leaders to ensure successful transformation in 2020. Without wheeling out all the usual clich\u00e9s, 2019 has been another whirlwind of disruptive innovation and opportunity \u2013 with plenty of challenges to tackle and circumvent along the way. The threat landscape [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":31045,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[182,46,7383,6,183,13],"tags":[496,12096,291,12097,428,441],"class_list":["post-31044","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud","category-data-centres","category-digital-transformation","category-insights","category-software","category-top-stories","tag-ai","tag-api-gateway","tag-devops","tag-f5-labs","tag-iaas","tag-saas"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/31044","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/comments?post=31044"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/posts\/31044\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media\/31045"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/media?parent=31044"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/categories?post=31044"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/africa\/wp-json\/wp\/v2\/tags?post=31044"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}