Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Zions Bancorporation
Brian Timmeny, Chief Technology Officer
Continuous Digital Modernization


As an organization considers the culture and process by which continuous modernization will occur, it must balance the overall pace of transformation while simultaneously contemplating the risk profile the company may accept. Moving quickly toward new technologies and paradigms, such as the public cloud, comes with associated risks that must be managed throughout the journey. At the same time, slower adoption of new technology solutions and the security that comes with these new suites will also increase organizational risk by introducing a rising exposure to external threats.
Modernization Focused Upon Critical Business Processes. Continuous modernization should center on the core business processes imperative to running the organization. While experimentation with new technologies is important, inclusive of the cultural benefits it provides, it is important to always remain focused on the rationale for modernization. It is to continually improve the service we offer our customers through constant and deepening insights.
Co-Existence.The journey to continuous modernization requires a foundational understanding that an organization will always exist on a continuum of technology modernization. Our continuous modernization focuses on this suite of applications that protect the organization's most important business processes. While past transformations may have considered a single upgrade or technology enhancement, today, the enterprise must focus on a constant and relentless modernization that moves new technologies into the ecosystem while simultaneously deprecating aging technologies over time.
With this paradigm in mind, an organization must ensure an appropriate architecture that will allow for the ongoing co-existence of applications. The process of co-existence and traffic routing may begin by building out a pattern of decoupled applications established through a common data layer separating every application interaction. A common data fabric allows for data to be shared (e.g. via APIs) commonly across several application suites. This layer is also what allows a single transaction to be routed across two applications at the same time. This means that data may be sent for processing to a legacy application and concurrently to a modern application counterpart. This paradigm may apply to an application upgrade, newly introduced functionality, or an entirely new application ecosystem.
Prior Generation Application Containment. Within the world of application modernization, not all suites will modernize at the same pace. Using the same architecture principle of decoupling, we can also ensure that our longer-running legacy technologies are contained behind a digital wall. These legacy applications, such as the mainframe, must also be modernized to such a level that we can still ensure that any interaction with these assets is done through the common data fabric, ensuring a digital (i.e., API) connected experience. This also serves as the foundation by which we can eventually rearchitect these applications and replace them through a co-existence strategy.
Build Cloud Grade Controls. As we embark upon the journey toward next-generation application suites, the cloud is a natural starting point in our modernization efforts. The cloud offers a wide array of services not easily replicated at a lesser scale or on-premise. While the cloud offers scalable capabilities, such as large-scale data storage, artificial intelligence, and machine learning, it is also important to remember that the cloud exists in the public domain. While assets can certainly be protected, and often with better execution than can be accomplished on-premise, the organization must now ensure these controls are correctly defined, implemented, and monitored.
To ensure the success of a continuous modernization program, there must be a common repository where controls are defined and held. This allows for a common definition of our standards through a common repository (i.e., service and controls catalog) that can ensure every asset in the organization is protected and continuously monitored.
By doing this, the organization can be ensured that the most important security controls remain in place. This will consider items such as data encryption, data obfuscation, and tokenization, all to ensure that customer and sensitive data is protected throughout the service delivery lifecycle.
Establish Continuously Integrated Applications. Once the control repository has been established, at least the early versions with key controls, the journey toward continuous integration may begin. While this article will not contemplate the full benefits of continuous integration, it is important to note that the integration pipeline is instrumental in enforcing the security controls discussed. During each deployment of an application, including its surrounding integration fabric, each applicable control related to an asset deployed must pass the implementation standard before it would be allowed to promote into a test or production environment.
By doing this, a standard suite of basic controls is established. These basic controls ensure that any asset deployed to the cloud or a shared data center meets these minimum criteria.
Implement Cloud Grade Monitoring. As security and additional controls are established, real-time monitoring must also be put into place. While the integration pipelines will ensure that an application remains in compliance at the time of deployment, real-time monitoring must be put into place to ensure ongoing compliance. Monitoring must be put into place with modern solutions, those compatible with the cloud for monitoring the infrastructure, operating, code, application, data repositories, and integration levels. This level of monitoring ensures that deployed applications remain within a healthy profile and compliant with standards that keep both the enterprise and customer data safe. Should the health profile degrade, appropriate action can then be taken. Depending upon the severity of the incident, appropriate alerting and escalation, or application action up to and including real-time shutdowns, may occur.
Protecting Customer Data. A foundation of every modernization journey is to ensure that we limit any risk to our most sensitive data, also focusing on our customer information. For this reason, as we modernize, we must at the same time link this journey to every data repository (within the scope of our modernization efforts) within our ecosystem. This signifies that we must ensure that data anywhere in the enterprise is encrypted as a basic building block. Any data utilized in a test where production-grade data is required must be obfuscated. And any production data must be tokenized within the lifecycle of our most important transactions. Ensuring that our data is safe and within the standards, we establish as a prerequisite to consider an application “cloud ready.”
Modernize the Data Ecosystem. In recent years, it has become fairly accepted that data and our use of that data is one of the important differentiators to the success a business may enjoy. While modernizing the application layers is important, the data fabric (data stores, API framework) must first be modernized if we consider a data-first organization. This is not always intuitive and certainly not an easy path. By modernizing data repositories and how we integrate our applications (e.g., APIs, queues), we establish a common foundation on top of which all applications may modernize consistently.
While this modernization could be established through cloud-native service utilization, that is not a prerequisite to the strategy. Data must only be handled within a common fabric, and the security rules are implemented commonly across a common suite of the data repository and transit types.
Evolve Virtual Machines and Application Resilience. With a common data fabric in place, or at least the early phases began, applications may begin the journey toward continuous modernization. Continuous modernization aims to provide business benefits to our customers and constantly improve their experience over time. During this first phase, we can begin with the easiest move toward a cloud-ready solution that allows for higher levels of security and resilience. Virtualizing our applications allows for multiple benefits, higher levels of resilience leading to continuous availability being some of the most important. The added benefit to this strategy as the first plateau point is that it allows for a fairly easy move of our semi-modern applications, for example, those that sit upon a Linux or Microsoft server environment. With relatively low life, these applications can be moved to a virtual environment (from the physical environment where they sit today). This then allows applications to enjoy the benefits of early modernization with a comparatively low level of effort.
While virtual machines still require manual configuration efforts, they provide the next level of modernization and set the stage for future application evolution. This solution may begin on the premise, and each public cloud provider offers virtual server solutions that allow for failover from on-premise to cloud environments, opening the path toward the next evolution of modernization.
Drive Container Driven Architecture. As the foundations of a common data fabric and virtualization take root in the enterprise, the architecture roadmap now looks ahead to interim steps toward modern cloud runtimes. Containers offer the benefit of being able to run across nearly any platform that can support a standard Kubernetes environment. As each of the major clouds offers such services, this allows for an extensible manner to build out applications, leaving the choice of a cloud provider to the enterprise and avoiding early solution lock to a single cloud provider. Deployment of containers is one of the most common pipeline patterns, and together with the control framework outlined above, it offers the next level of application resilience (now in real-time) as well as image-based deployments that limit manual intervention (and the associated incidents that often arise as a result).
The journey to continuous modernization requires a foundational understanding that an organization will always exist on a continuum of technology modernization
At the same time containers begin their deployment journey on the cloud, it will be important to discuss the start of a FinOps program internally. This program will help to manage the costs of running applications on the cloud. Some aspects of the cloud-free enterprise are to pursue additional experiences, such as near-infinite scale to service our customers or processing large data sets to pursue customer insights through machine learning. However, these capabilities also come with risks in the form of elevated and unexpected costs. FinOps helps to automate these processes to establish appropriate alerts and automated processes (such as shutting down instances) to limit the financial impact when systems scale in a manner out of sync with the benefits associated with the enterprise or customers.
Define Future State Architectures. The organization will eventually become comfortable across the data fabric, virtual machines, and containers, all protected through a common control framework. The journey to move the entire organization and each of the assets associated with the critical business processes will take time. However, while this portion of the journey is underway, this is the moment when application owners should be encouraged to begin exploring the next evolution of application runtimes and serverless environments. These experiments should likely start small and outside of critical application suites and will give insight to our engineering teams while at the same time building their skills toward the next generation of runtimes beyond the container-based ecosystem. This ensures the organization is always looking around the next corner and remains focused on continuous modernization.
Create an Innovation Engineering Culture. Often when we think of an innovative engineering culture, we think only of the forward movement toward the next generation of technologies. As we consider the upskilling of our teams and the constant learning path on which we expect them to remain, this involves focusing on our legacy and next-generation technologies. In this way, the idea of innovation is not exclusively focused on moving in the direction of the future state of our technology ecosystem, but at the same time, relentlessly focusing on modernizing and rearchitecting our prior-state technology suites, deprecating them over time. This is an important concept for our teams and the idea that we are constantly re-architecting our applications. Those solutions we are implementing today will one day be the application suites we must one day evolve toward a future generation of technology runtimes.
This creates a complex culture within which our engineers must live. We can no longer expect specific and niche skills to exist for the duration of a career. Rather, any application technology skills upon which our teams are focused will evolve, as will the skills of our team members. Our culture, communication plans, and training must reflect this paradigm shift to help everyone along the journey of continuous technology modernization.
Establish Effective Communication Planning. With any transformation, an effective communication plan is critical to ensure appropriate communication with stakeholders, executive leadership, board members, and regulators. Sharing a single transformation, which often spans years, is complex. Sharing a plan for continuous modernization, one that permanently affects the shape of both projects and operating budgets will take time. This must be an iterative conversation with each group, sharing the incremental and long-term planning efforts. This context must be commonly understood and communicated across ongoing projects, investments, operating budgets, and staffing. Small steps and sharing the ongoing wins over time will be critical to ensure that the journey receives the ongoing and necessary support. Only by doing this can an organization ensure continuous modernization in service to our constantly improving customer experience.

