Dinosaurs vs Unicorns

Dinosaurs vs Unicorns

What's it like to start a DevSecOps initiative in most companies? Yep, I think the image says it all. You're going to have a hell of a time convincing the dinosaurs that the end is near, and the asteroid is on it's way. What the industry is starting to confirm through trial and error is there are a couple things in the successful transition to DevOps/DevSecOps that will help keep your distance from the dinosaur jowls.

1 - It's a "Cultural" thing not a "Tool" Thing-a-ma-jig

Literally every company, every person, I've talked with who has had a successful DevSecOps initiative says the same thing. "Start with the cultural transformation piece. Tools are a de-coupled commodity. Cultural buy-in from the beginning is what sets the stage to being successful."

2 - Start small, very small, and show the ROI

Start with a small team, a small project, minimal risk, short time frame. Your objective is to show how your project will help the business, not to show how "cool" DevOps is. In fact, don't even use the words DevOps or DevSecOps. To paraphrase James Carville, "It's about the business, Stupid!" If you're talking about building a CI/CD pipeline as your first foray into DevSecOps, you've already jumped the shark.

Dinosaurs vs Unicorns

Cultural transformation and ROI are the two starting points to consider when trying to implement change in a dinosaur environment. Teach your unicorns to focus on a small change with a big impact. Your biggest dinosaur won't be able to stand up to that asteroid. Never forget: the business value of your project matters.

A Small Test Project

Want a small project to surface your in-house unicorns? Evaluate your applications for open source components with known vulnerabilities. You'll know immediately who gets it and who doesn't. Dinosaurs won't understand it. Unicorns will have a "holy shit!" moment and you'll be on your way to your first cultural transformation.

As always comments and feedback appreciated.


要查看或添加评论,请登录

Mark Miller的更多文章

  • Exploring the LinkedIn Algorithm: Podcast

    Exploring the LinkedIn Algorithm: Podcast

    In this episode of the DevSecOps Podcast, we’re going to go off script and explore the LinkedIn algorithm. I could tie…

    55 条评论
  • Deming | Goldratt | Kim - A DevOps Timeline

    Deming | Goldratt | Kim - A DevOps Timeline

    You can listen to Gene Kim and Mark Miller discuss the Unicorn Project on the podcast at DevSecOps Days. Edwards Deming…

    1 条评论
  • Why do trust me? Seriously, why?

    Why do trust me? Seriously, why?

    Malcolm Gladwell has a new book coming out, "Talking to Strangers: What We Should Know About the People We Don't Know".…

  • The Learning Culture: Insights into What Makes Companies Better

    The Learning Culture: Insights into What Makes Companies Better

    I just watched a remarkable video. Gene Kim and John Willis talk with Dr.

    2 条评论
  • The Value of Value

    The Value of Value

    Scrolling through my LinkedIn feed this morning I realized that 99%, or more, of what I see has no value to me. None.

    3 条评论
  • Quantity is table stakes. Quality is the differentiator.

    Quantity is table stakes. Quality is the differentiator.

    I was with my 14 year old daughter during the New York Youth Symphony rehearsal today. While watching the rehearsal, I…

  • Security Teams in DevOps? There's No Such Thing

    Security Teams in DevOps? There's No Such Thing

    Yesterday, I had an interesting conversation (recording available) with Eliza May Austin, founder of Ladies of London…

    25 条评论
  • Old habits and beliefs fail as our context shifts

    Old habits and beliefs fail as our context shifts

    There are some good takeways from Peter Morville's book, Planning for Everything: The Design of Paths and Goals. This…

    1 条评论
  • Remember books? Yes, they're still here.

    Remember books? Yes, they're still here.

    Kevin Roose from the New York Times published a fascinating article that might have you looking in the mirror after…

    6 条评论
  • People Don't Buy the Best Product...

    People Don't Buy the Best Product...

    I was flipping through StoryBrand by Donald Miller, when I saw this quote: "People don't buy the best products. They…

    6 条评论

社区洞察

其他会员也浏览了