SlideShare a Scribd company logo
1 of 39
Ian Watson
Head of DevOps
Email : ian.watson@callcreditgroup.com
Twitter : @purplemarauder
Continuous Delivery
vs
Copious Regulations
Can you really achieve Continuous Delivery in the
highly regulated world of financial services?
Is it easy to achieve Continuous Delivery in the
highly regulated world of financial services?
We needed to change
Searching for unicorns
Who is watching?
Goal: regulate the use of “personal data”
DPA
(Data Protection Act)
Goal: Europe-wide regulation of the use of “personal data”
GDPR
(General Data Protection Regulation)
Goal: Protect Cardholder Data
PCI DSS
(Payment Card Industry Data Security Standard)
Goal: Make financial markets work well – for individuals, for business, large and
small, and for the economy as a whole
FCA
The Financial Conduct Authority
Let’s do this!
CONTINUOUS
Delivery
What does this mean for technology choices
“Cloud” is just outsourcing
Our aim is to avoid imposing inappropriate barriers to firms’ ability to outsource to innovative
and developing areas, while ensuring that risks are appropriately identified and managed.
No one ever got fired for buying…..
Hybrid might be the answer
(Not so) Safe Harbour
How much meta data?
Continuous Delivery drives excellent
behaviours from a regulatory compliance
perspective*
*as well as a few really useful side effects like, speed, quality and reliability
Segregation of Duties
Corollary
Enterprise DevOps
=
Specialisation + Collaboration
How autonomous is an autonomous team?
Traceability
Traceability
Security
Patching
Auditability
(standardisation)
Auditability
(immutable Infrastructure)
Treat all your data as if you are likely to be
audited as a regulated body…
….even if you’re not
Achieving Continuous Delivery in Financial Services

More Related Content

What's hot

Top 10 Reasons to Learn Blockchain | Blockchain Training | Blockchain Tutoria...
Top 10 Reasons to Learn Blockchain | Blockchain Training | Blockchain Tutoria...Top 10 Reasons to Learn Blockchain | Blockchain Training | Blockchain Tutoria...
Top 10 Reasons to Learn Blockchain | Blockchain Training | Blockchain Tutoria...Edureka!
 
BizDay: Designing the Future of Payments, Mastercard
BizDay: Designing the Future of Payments, MastercardBizDay: Designing the Future of Payments, Mastercard
BizDay: Designing the Future of Payments, MastercardR3
 
The State of Blockchains Q1 2018
The State of Blockchains Q1 2018The State of Blockchains Q1 2018
The State of Blockchains Q1 2018Outlier Ventures
 
Pah, Micro Lending with Blockchain technology
Pah, Micro Lending with Blockchain technologyPah, Micro Lending with Blockchain technology
Pah, Micro Lending with Blockchain technologyI AM Consulting
 
U.s. banking giant jpmorgan expanding blockchain payments to 220 banks
U.s. banking giant jpmorgan expanding blockchain payments to 220 banksU.s. banking giant jpmorgan expanding blockchain payments to 220 banks
U.s. banking giant jpmorgan expanding blockchain payments to 220 banksBlockchain Council
 
Discover the power of blockchain with r3 corda platform
Discover the power of blockchain with r3 corda platformDiscover the power of blockchain with r3 corda platform
Discover the power of blockchain with r3 corda platformI AM Consulting
 
Blockchain Applications in Auto Finance
Blockchain Applications in Auto FinanceBlockchain Applications in Auto Finance
Blockchain Applications in Auto FinanceWhite Clarke Group
 
Fintech App Ideas to Consider in 2021 for Startups
Fintech App Ideas to Consider in 2021 for StartupsFintech App Ideas to Consider in 2021 for Startups
Fintech App Ideas to Consider in 2021 for StartupsQSS Technosoft
 
Data theft in india (K K Mookhey)
Data theft in india (K K Mookhey)Data theft in india (K K Mookhey)
Data theft in india (K K Mookhey)ClubHack
 
5 Blockchain Trends Everyone Should Know About
5 Blockchain Trends Everyone Should Know About5 Blockchain Trends Everyone Should Know About
5 Blockchain Trends Everyone Should Know AboutBernard Marr
 
The rise of decentralized autonomous organizations
The rise of decentralized autonomous organizationsThe rise of decentralized autonomous organizations
The rise of decentralized autonomous organizationsOliviaJune1
 
A4: Kasetsart University | FinTech and Contracts (2018)
A4: Kasetsart University | FinTech and Contracts (2018)A4: Kasetsart University | FinTech and Contracts (2018)
A4: Kasetsart University | FinTech and Contracts (2018)Kullarat Phongsathaporn
 
Blockchain, DAO, Holacracy and HR Organsiation Design
Blockchain, DAO, Holacracy and HR Organsiation DesignBlockchain, DAO, Holacracy and HR Organsiation Design
Blockchain, DAO, Holacracy and HR Organsiation DesignJaspreet Bindra
 
Hoard Pitch Deck
Hoard Pitch DeckHoard Pitch Deck
Hoard Pitch DeckJason Davis
 

What's hot (20)

Top 10 Reasons to Learn Blockchain | Blockchain Training | Blockchain Tutoria...
Top 10 Reasons to Learn Blockchain | Blockchain Training | Blockchain Tutoria...Top 10 Reasons to Learn Blockchain | Blockchain Training | Blockchain Tutoria...
Top 10 Reasons to Learn Blockchain | Blockchain Training | Blockchain Tutoria...
 
BizDay: Designing the Future of Payments, Mastercard
BizDay: Designing the Future of Payments, MastercardBizDay: Designing the Future of Payments, Mastercard
BizDay: Designing the Future of Payments, Mastercard
 
The State of Blockchains Q1 2018
The State of Blockchains Q1 2018The State of Blockchains Q1 2018
The State of Blockchains Q1 2018
 
Pah, Micro Lending with Blockchain technology
Pah, Micro Lending with Blockchain technologyPah, Micro Lending with Blockchain technology
Pah, Micro Lending with Blockchain technology
 
U.s. banking giant jpmorgan expanding blockchain payments to 220 banks
U.s. banking giant jpmorgan expanding blockchain payments to 220 banksU.s. banking giant jpmorgan expanding blockchain payments to 220 banks
U.s. banking giant jpmorgan expanding blockchain payments to 220 banks
 
Lirax
LiraxLirax
Lirax
 
De Fi and the future of finance
De Fi and the future of financeDe Fi and the future of finance
De Fi and the future of finance
 
Discover the power of blockchain with r3 corda platform
Discover the power of blockchain with r3 corda platformDiscover the power of blockchain with r3 corda platform
Discover the power of blockchain with r3 corda platform
 
Digital currency
Digital currencyDigital currency
Digital currency
 
Blockchain Applications in Auto Finance
Blockchain Applications in Auto FinanceBlockchain Applications in Auto Finance
Blockchain Applications in Auto Finance
 
Fintech App Ideas to Consider in 2021 for Startups
Fintech App Ideas to Consider in 2021 for StartupsFintech App Ideas to Consider in 2021 for Startups
Fintech App Ideas to Consider in 2021 for Startups
 
Data theft in india (K K Mookhey)
Data theft in india (K K Mookhey)Data theft in india (K K Mookhey)
Data theft in india (K K Mookhey)
 
5 Blockchain Trends Everyone Should Know About
5 Blockchain Trends Everyone Should Know About5 Blockchain Trends Everyone Should Know About
5 Blockchain Trends Everyone Should Know About
 
Global Trade
 Global Trade  Global Trade
Global Trade
 
The rise of decentralized autonomous organizations
The rise of decentralized autonomous organizationsThe rise of decentralized autonomous organizations
The rise of decentralized autonomous organizations
 
Fintech.
Fintech.Fintech.
Fintech.
 
A4: Kasetsart University | FinTech and Contracts (2018)
A4: Kasetsart University | FinTech and Contracts (2018)A4: Kasetsart University | FinTech and Contracts (2018)
A4: Kasetsart University | FinTech and Contracts (2018)
 
Blockchain, DAO, Holacracy and HR Organsiation Design
Blockchain, DAO, Holacracy and HR Organsiation DesignBlockchain, DAO, Holacracy and HR Organsiation Design
Blockchain, DAO, Holacracy and HR Organsiation Design
 
Ethereum Smart Contracts 101 with Cryptizens.io
Ethereum Smart Contracts 101 with Cryptizens.ioEthereum Smart Contracts 101 with Cryptizens.io
Ethereum Smart Contracts 101 with Cryptizens.io
 
Hoard Pitch Deck
Hoard Pitch DeckHoard Pitch Deck
Hoard Pitch Deck
 

Viewers also liked

CD and the curse of legacy
CD and the curse of legacyCD and the curse of legacy
CD and the curse of legacyBanos Solomou
 
Talk at the International Conference on Biomedical and Health Informatics (BH...
Talk at the International Conference on Biomedical and Health Informatics (BH...Talk at the International Conference on Biomedical and Health Informatics (BH...
Talk at the International Conference on Biomedical and Health Informatics (BH...Marco Altini
 
Seedling Capabilities
Seedling CapabilitiesSeedling Capabilities
Seedling CapabilitiesSeedling Inc.
 
1.2 liderazgo y la dirección por competencias
1.2 liderazgo y la dirección por competencias1.2 liderazgo y la dirección por competencias
1.2 liderazgo y la dirección por competenciasS4 Ingenieros Consultores
 
Hawaii Judge Watson's Motion To Stop Trump's Travel Ban
Hawaii Judge Watson's Motion To Stop Trump's Travel BanHawaii Judge Watson's Motion To Stop Trump's Travel Ban
Hawaii Judge Watson's Motion To Stop Trump's Travel BanHonolulu Civil Beat
 
Evaluacion del riesgo cuantitativo (oel) y categorizacion de la exposicion oc...
Evaluacion del riesgo cuantitativo (oel) y categorizacion de la exposicion oc...Evaluacion del riesgo cuantitativo (oel) y categorizacion de la exposicion oc...
Evaluacion del riesgo cuantitativo (oel) y categorizacion de la exposicion oc...Azierta
 
Internet Week 2016 脆弱性スキャナによる対策支援の課題 Vuls
Internet Week 2016 脆弱性スキャナによる対策支援の課題 VulsInternet Week 2016 脆弱性スキャナによる対策支援の課題 Vuls
Internet Week 2016 脆弱性スキャナによる対策支援の課題 VulsKota Kanbe
 
冬のLock free祭り safe
冬のLock free祭り safe冬のLock free祭り safe
冬のLock free祭り safeKumazaki Hiroki
 
Serverless Azure
Serverless AzureServerless Azure
Serverless AzureMark Allan
 
Unravelling the dynamics of instructional practice: A longitudinal study on l...
Unravelling the dynamics of instructional practice: A longitudinal study on l...Unravelling the dynamics of instructional practice: A longitudinal study on l...
Unravelling the dynamics of instructional practice: A longitudinal study on l...Quan Nguyen
 
Architecting a Next Generation Data Platform
Architecting a Next Generation Data PlatformArchitecting a Next Generation Data Platform
Architecting a Next Generation Data Platformhadooparchbook
 
Wir brauchen eine neue, agile Führung - 10 Thesen - Heinz Peter Wallner 2017
Wir brauchen eine neue, agile Führung - 10 Thesen - Heinz Peter Wallner 2017Wir brauchen eine neue, agile Führung - 10 Thesen - Heinz Peter Wallner 2017
Wir brauchen eine neue, agile Führung - 10 Thesen - Heinz Peter Wallner 2017Heinz Peter Wallner
 
The 8 Performance Roadblocks Holding Businesses Back and What to Do About Them
The 8 Performance Roadblocks Holding Businesses Back and What to Do About Them The 8 Performance Roadblocks Holding Businesses Back and What to Do About Them
The 8 Performance Roadblocks Holding Businesses Back and What to Do About Them WINNERS-at-WORK Pty Ltd
 
Startup Sales Stack Report 2017
Startup Sales Stack Report 2017Startup Sales Stack Report 2017
Startup Sales Stack Report 2017Nic Poulos
 

Viewers also liked (20)

CD and the curse of legacy
CD and the curse of legacyCD and the curse of legacy
CD and the curse of legacy
 
1.2 ensayo sobre ''directivos chilenos''
1.2 ensayo sobre ''directivos chilenos''1.2 ensayo sobre ''directivos chilenos''
1.2 ensayo sobre ''directivos chilenos''
 
Talk at the International Conference on Biomedical and Health Informatics (BH...
Talk at the International Conference on Biomedical and Health Informatics (BH...Talk at the International Conference on Biomedical and Health Informatics (BH...
Talk at the International Conference on Biomedical and Health Informatics (BH...
 
Seedling Capabilities
Seedling CapabilitiesSeedling Capabilities
Seedling Capabilities
 
St. Louise: Healer, Sister, Friend
St. Louise: Healer, Sister, FriendSt. Louise: Healer, Sister, Friend
St. Louise: Healer, Sister, Friend
 
1.2 liderazgo y la dirección por competencias
1.2 liderazgo y la dirección por competencias1.2 liderazgo y la dirección por competencias
1.2 liderazgo y la dirección por competencias
 
Modelo de la Estandarizacion
Modelo de la EstandarizacionModelo de la Estandarizacion
Modelo de la Estandarizacion
 
Hawaii Judge Watson's Motion To Stop Trump's Travel Ban
Hawaii Judge Watson's Motion To Stop Trump's Travel BanHawaii Judge Watson's Motion To Stop Trump's Travel Ban
Hawaii Judge Watson's Motion To Stop Trump's Travel Ban
 
Evaluacion del riesgo cuantitativo (oel) y categorizacion de la exposicion oc...
Evaluacion del riesgo cuantitativo (oel) y categorizacion de la exposicion oc...Evaluacion del riesgo cuantitativo (oel) y categorizacion de la exposicion oc...
Evaluacion del riesgo cuantitativo (oel) y categorizacion de la exposicion oc...
 
Internet Week 2016 脆弱性スキャナによる対策支援の課題 Vuls
Internet Week 2016 脆弱性スキャナによる対策支援の課題 VulsInternet Week 2016 脆弱性スキャナによる対策支援の課題 Vuls
Internet Week 2016 脆弱性スキャナによる対策支援の課題 Vuls
 
冬のLock free祭り safe
冬のLock free祭り safe冬のLock free祭り safe
冬のLock free祭り safe
 
Serverless Azure
Serverless AzureServerless Azure
Serverless Azure
 
mep 01/2017
mep 01/2017mep 01/2017
mep 01/2017
 
Unravelling the dynamics of instructional practice: A longitudinal study on l...
Unravelling the dynamics of instructional practice: A longitudinal study on l...Unravelling the dynamics of instructional practice: A longitudinal study on l...
Unravelling the dynamics of instructional practice: A longitudinal study on l...
 
Lingüística del texto
Lingüística del textoLingüística del texto
Lingüística del texto
 
DCS & SCADA
DCS & SCADADCS & SCADA
DCS & SCADA
 
Architecting a Next Generation Data Platform
Architecting a Next Generation Data PlatformArchitecting a Next Generation Data Platform
Architecting a Next Generation Data Platform
 
Wir brauchen eine neue, agile Führung - 10 Thesen - Heinz Peter Wallner 2017
Wir brauchen eine neue, agile Führung - 10 Thesen - Heinz Peter Wallner 2017Wir brauchen eine neue, agile Führung - 10 Thesen - Heinz Peter Wallner 2017
Wir brauchen eine neue, agile Führung - 10 Thesen - Heinz Peter Wallner 2017
 
The 8 Performance Roadblocks Holding Businesses Back and What to Do About Them
The 8 Performance Roadblocks Holding Businesses Back and What to Do About Them The 8 Performance Roadblocks Holding Businesses Back and What to Do About Them
The 8 Performance Roadblocks Holding Businesses Back and What to Do About Them
 
Startup Sales Stack Report 2017
Startup Sales Stack Report 2017Startup Sales Stack Report 2017
Startup Sales Stack Report 2017
 

Similar to Achieving Continuous Delivery in Financial Services

Cybersecurity solution-guide
Cybersecurity solution-guideCybersecurity solution-guide
Cybersecurity solution-guideAdilsonSuende
 
The Easy WAy to Accept & Protect Credit Card Data
The Easy WAy to Accept & Protect Credit Card DataThe Easy WAy to Accept & Protect Credit Card Data
The Easy WAy to Accept & Protect Credit Card DataTyler Hannan
 
ISACA_21st century technologist
ISACA_21st century technologistISACA_21st century technologist
ISACA_21st century technologistDonald Tabone
 
Senate_2014_Data_Breach_Testimony_Richey
Senate_2014_Data_Breach_Testimony_RicheySenate_2014_Data_Breach_Testimony_Richey
Senate_2014_Data_Breach_Testimony_RicheyPeter Tran
 
Servicios financieros BT: un mercado que crece en Colombia y Latinoamérica
Servicios financieros BT: un mercado que crece en Colombia y LatinoaméricaServicios financieros BT: un mercado que crece en Colombia y Latinoamérica
Servicios financieros BT: un mercado que crece en Colombia y LatinoaméricaBT Let´s Talk Latam
 
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane CherkaouiNouamane Cherkaoui
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRMatt Stubbs
 
DutchMLSchool 2022 - Multi Perspective Anomalies
DutchMLSchool 2022 - Multi Perspective AnomaliesDutchMLSchool 2022 - Multi Perspective Anomalies
DutchMLSchool 2022 - Multi Perspective AnomaliesBigML, Inc
 
The top trends changing the landscape of Information Management
The top trends changing the landscape of Information ManagementThe top trends changing the landscape of Information Management
The top trends changing the landscape of Information ManagementVelrada
 
Top 10 Technology Trend in finance industry in 2022 (AutoRecovered).docx
Top 10 Technology Trend in finance industry in 2022 (AutoRecovered).docxTop 10 Technology Trend in finance industry in 2022 (AutoRecovered).docx
Top 10 Technology Trend in finance industry in 2022 (AutoRecovered).docxAdvance Tech
 
Information security management v2010
Information security management v2010Information security management v2010
Information security management v2010joevest
 
A brief Overview on Finance and Technology for Solving Business problem
A brief Overview on Finance and Technology for Solving Business problemA brief Overview on Finance and Technology for Solving Business problem
A brief Overview on Finance and Technology for Solving Business problemsaraahmed870035
 
Security, Compliance and Cloud - Jelecos
Security, Compliance and Cloud - JelecosSecurity, Compliance and Cloud - Jelecos
Security, Compliance and Cloud - JelecosErin_Jelecos
 
Cyber Security, User Interface, and You - Deloitte CIO - WSJ
Cyber Security, User Interface, and You - Deloitte CIO - WSJCyber Security, User Interface, and You - Deloitte CIO - WSJ
Cyber Security, User Interface, and You - Deloitte CIO - WSJSherry Jones
 
Cyber Security, User Interface, and You - Deloitte CIO - WSJ
Cyber Security, User Interface, and You - Deloitte CIO - WSJCyber Security, User Interface, and You - Deloitte CIO - WSJ
Cyber Security, User Interface, and You - Deloitte CIO - WSJSherry Jones
 
Fintech_Trends_for_2022_report_by_Erlang_Solutions.pdf
Fintech_Trends_for_2022_report_by_Erlang_Solutions.pdfFintech_Trends_for_2022_report_by_Erlang_Solutions.pdf
Fintech_Trends_for_2022_report_by_Erlang_Solutions.pdfErlang Solutions
 
Corum group: Paris Presentation
Corum group: Paris PresentationCorum group: Paris Presentation
Corum group: Paris PresentationYoussef Rahoui
 
Big data/Data Mining/IoT/Smart City
Big data/Data Mining/IoT/Smart CityBig data/Data Mining/IoT/Smart City
Big data/Data Mining/IoT/Smart Cityrashed sharif
 
Internet of Things - Asked and Answered
Internet of Things - Asked and AnsweredInternet of Things - Asked and Answered
Internet of Things - Asked and AnsweredADCBarcode
 

Similar to Achieving Continuous Delivery in Financial Services (20)

Cybersecurity solution-guide
Cybersecurity solution-guideCybersecurity solution-guide
Cybersecurity solution-guide
 
The Easy WAy to Accept & Protect Credit Card Data
The Easy WAy to Accept & Protect Credit Card DataThe Easy WAy to Accept & Protect Credit Card Data
The Easy WAy to Accept & Protect Credit Card Data
 
ISACA_21st century technologist
ISACA_21st century technologistISACA_21st century technologist
ISACA_21st century technologist
 
Senate_2014_Data_Breach_Testimony_Richey
Senate_2014_Data_Breach_Testimony_RicheySenate_2014_Data_Breach_Testimony_Richey
Senate_2014_Data_Breach_Testimony_Richey
 
Servicios financieros BT: un mercado que crece en Colombia y Latinoamérica
Servicios financieros BT: un mercado que crece en Colombia y LatinoaméricaServicios financieros BT: un mercado que crece en Colombia y Latinoamérica
Servicios financieros BT: un mercado que crece en Colombia y Latinoamérica
 
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
2020 Tehnology Mega Trends - Nov. 2019 I Nouamane Cherkaoui
 
Big Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPRBig Data LDN 2017: Applied AI for GDPR
Big Data LDN 2017: Applied AI for GDPR
 
DutchMLSchool 2022 - Multi Perspective Anomalies
DutchMLSchool 2022 - Multi Perspective AnomaliesDutchMLSchool 2022 - Multi Perspective Anomalies
DutchMLSchool 2022 - Multi Perspective Anomalies
 
The top trends changing the landscape of Information Management
The top trends changing the landscape of Information ManagementThe top trends changing the landscape of Information Management
The top trends changing the landscape of Information Management
 
Top 10 Technology Trend in finance industry in 2022 (AutoRecovered).docx
Top 10 Technology Trend in finance industry in 2022 (AutoRecovered).docxTop 10 Technology Trend in finance industry in 2022 (AutoRecovered).docx
Top 10 Technology Trend in finance industry in 2022 (AutoRecovered).docx
 
Information security management v2010
Information security management v2010Information security management v2010
Information security management v2010
 
A brief Overview on Finance and Technology for Solving Business problem
A brief Overview on Finance and Technology for Solving Business problemA brief Overview on Finance and Technology for Solving Business problem
A brief Overview on Finance and Technology for Solving Business problem
 
Security, Compliance and Cloud - Jelecos
Security, Compliance and Cloud - JelecosSecurity, Compliance and Cloud - Jelecos
Security, Compliance and Cloud - Jelecos
 
The 10 successful entrepreneur revamping the future compressed
The 10 successful entrepreneur revamping the future compressedThe 10 successful entrepreneur revamping the future compressed
The 10 successful entrepreneur revamping the future compressed
 
Cyber Security, User Interface, and You - Deloitte CIO - WSJ
Cyber Security, User Interface, and You - Deloitte CIO - WSJCyber Security, User Interface, and You - Deloitte CIO - WSJ
Cyber Security, User Interface, and You - Deloitte CIO - WSJ
 
Cyber Security, User Interface, and You - Deloitte CIO - WSJ
Cyber Security, User Interface, and You - Deloitte CIO - WSJCyber Security, User Interface, and You - Deloitte CIO - WSJ
Cyber Security, User Interface, and You - Deloitte CIO - WSJ
 
Fintech_Trends_for_2022_report_by_Erlang_Solutions.pdf
Fintech_Trends_for_2022_report_by_Erlang_Solutions.pdfFintech_Trends_for_2022_report_by_Erlang_Solutions.pdf
Fintech_Trends_for_2022_report_by_Erlang_Solutions.pdf
 
Corum group: Paris Presentation
Corum group: Paris PresentationCorum group: Paris Presentation
Corum group: Paris Presentation
 
Big data/Data Mining/IoT/Smart City
Big data/Data Mining/IoT/Smart CityBig data/Data Mining/IoT/Smart City
Big data/Data Mining/IoT/Smart City
 
Internet of Things - Asked and Answered
Internet of Things - Asked and AnsweredInternet of Things - Asked and Answered
Internet of Things - Asked and Answered
 

Recently uploaded

Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Unlocking the Potential of the Cloud for IBM Power Systems
Unlocking the Potential of the Cloud for IBM Power SystemsUnlocking the Potential of the Cloud for IBM Power Systems
Unlocking the Potential of the Cloud for IBM Power SystemsPrecisely
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 

Recently uploaded (20)

E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
The transition to renewables in India.pdf
The transition to renewables in India.pdfThe transition to renewables in India.pdf
The transition to renewables in India.pdf
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Unlocking the Potential of the Cloud for IBM Power Systems
Unlocking the Potential of the Cloud for IBM Power SystemsUnlocking the Potential of the Cloud for IBM Power Systems
Unlocking the Potential of the Cloud for IBM Power Systems
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 

Achieving Continuous Delivery in Financial Services

Editor's Notes

  1. Introduce me!
  2. Career Database Dev DBA Team Lead Head of
  3. Introduce Callcredit …this is the story of the last 2 years at Callcredit as we’ve worked to move into a DevOps way of working First a bit of background for those of you that don’t know us. CC has only existed as a company for about 15 years, when the Skipton Building society decided it would be a cunning plan to set up a 3rd Credit Reference Agency to challenge the big 2 What followed was a decade and a half of rapid growth – and it’s that velocity that had created us some amazing opportunities and challenges. So… (yes, I’m the king of photoshop…)
  4. So, with new owners and a stated aim to double the revenue of the company in the next 5 years we clearly needed to stop sprinting to stay put and start getting to a place where we’re actually moving somewhere
  5. At this point the question in a few of our heads was could we every really set up like one of the so-called unicorns? And if not exactly, could we get close?
  6. So… let’s have a look at some of the potential regulatory constraints…
  7. ICO : Responsible for regulating the use and storage of personal information, and for overseeing the implementation of the Freedom of Information (FOI) Act PCI Security Standards Council : a global open body formed to develop, enhance, disseminate and assist with the understanding of security standards for payment account security. Originally founded by American Express, Discover Financial Services, JCB International, MasterCard, and Visa  FCA – replaced the FSA in 2013 following a review of the collapse of the financial markets some years earlier. Has wide ranging powers to regulate conduct related to the marketing of financial products. Aims to put the consumer’s needs at the centre of everything
  8. Personal data means data which relate to a living individual who can be identified – (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller Fines up to half a million
  9. So this is NEW will apply in the UK from 25 May 2018 The principles are similar to those in the DPA, with added detail at certain points and a new accountability requirement
  10. Build and maintain a secure IT network; Protect cardholder data; Maintain a vulnerability management programme; Implement strong access control measures; Regularly monitor and test networks; Maintain an information security policy. If we’re not accredited we simply don’t have a business!
  11. Financial markets need to be honest, fair and effective so that consumers get a fair deal. It is our aim to make markets work well – for individuals, for business, large and small, and for the economy as a whole. Able to levy HUGE fines. Biggest so far was £284 million! Levied for bankers caught using chat rooms for fixing foreign exchange rates
  12. Let’s do this! So, we’ve got THE book, we know there’s a few constraints but we can totally make this work right?
  13. So when I first started talking about CD the general response was…nope It’ll never work for us…..
  14. But our clients don’t want that much change (CD not CD!)
  15. We can’t put our data in the cloud! Actually quite a lot of our financial clients already do just that. It’s just that there are some limitations Which I’ll cover in a bit… We have a whole bunch of old contracts around where we can store data. i.e in the UK only - what does this mean for Cloud? DPA - data has to stay in this country - safe harbour ain’t so safe!
  16. Monoliths with a tiny sliver of toxic data inside TB databases. Side effect of how quickly we’ve grown, focus on
  17. Big difference between us and a start-up is the tech question tends to be why rather than why not. i.e. dropbox would be massively handy, but the security concerns that could allow anyone with access to sensitive to easily get it outside of our security perimeter mean we can’t easily leverage mass cloud storage.. Enter MS
  18. Long been a running discussion whether the “cloud” is actually just other people’s data centre or if it’s something far more than that, but from the view of compliance and regulation it’s almost exactly that. It’s still beholden on the company using the cloud infrastructure/services to ensure that everything they’re doing is compliant not on the cloud provider…
  19. No one ever got fired for buying…. Well, Microsoft in our case Implicit trust… A lot of effort into getting their services appropriately accredited. When we hand off responsibilities to other firms (as you necessarily do when you move to cloud.) i.e. Auditors will still be asking us about how we protect our data we can’t just assume it’s in safe hands wherever we put it without actually checking
  20. Implicit trust… MS pushing the compliance angle – they understand working with Enterprises
  21. Hybrid might be the best solution and again MS are a very neat segue in this area – Office
  22. Data has to stay in the UK EU privacy law forbids the movement of its citizens’ data outside of the EU, unless it is transferred to a location which is deemed to have “adequate” privacy protections in line with those of the EU. The safe harbour agreement that was made between the EC and the US government essentially promised to protect EU citizens’ data if transferred by American companies to the US. Declared invalid in October 2015
  23. In reaction to the safe harbour ruling? Possibly
  24. Heavy emphasis on risk management from FCA means we generally need to have appropriate support contracts in place Opensource is fine, but we do need support We have ELK instances for metrics for example and some v talented SysAdmins supporting and deploying but we still need a support contract in place nonetheless – c50k per project/product
  25. Audit audit audit! Not only do we store a lot of personal data – PII and PCI – we also store a lot of data about how that data is being used 2 types We have to audit every search – this runs into billions of rows of data. Operational metrics - We also are obliged not to store the data for too long…. Ran into a design challenge actually deleting the data!
  26. Cloud
  27. Segregation of duties The tools and practices that we employ for CD make this easy! Previously to get something deployed you’d need an operations engineer/DBA who had access to live. Now we don’t need to disturb them, but can still have the same separation
  28. So we’re moving entirely away from the way that a lot of the so-called unicorns work, since we can’t have the people that write the code being the people that deploy and support the code. But that’s OK…. In fact maybe that’s better? DevOps is all about a culture of collaboration above all right?
  29. What this does raise is the question of autonomous teams – one of the cornerstones of the Spotify-like model. So here’s our team of full stack engineers and rock star DBA’s how autonomous can they actually be? The segregation and technology constraints I’ve already talked about do mean that we can’t adopt Facebook’s never say no to the developers attitude, as we simply have to abide by regulations and someone has to be checking what is and isn’t appropriate or pre-approved. With a focus on CD what we can do is furnish the teams with everything they need to get from idea to live without hand-offs that slow us down and/or lead to misunderstandings and errors albeit with certain necessary tools and processes enforced So – autonomous-ish ;)
  30. A need for end-to-end visibility and traceability leads to automation Traceability – nothing is less traceable than a person! - we know who cut code, what was tested, - We know what was deployed when – really what, not what someone said they’d done
  31. Source control (for software & “hardware”)
  32. Security - Less people need access to the live card data environments which helps with “Implement strong access control measures” in PCI
  33. – we’re able to quickly, safely push through things like zero day security patches. Regulators like this for obvious reasons
  34. Auditability – Standardisation : Most audits are along the lines of doing what you say you are. This is a much easier discussion when everything is going through the same automated process - not just software deployments - but also server builds
  35. Immutable infrastructure And some of the new ways of managing infrastructure – containers, PaaS services that are entirely from code make the two previous items even more reliable and more obviously compliant
  36. You could worse than thinking of your data as if the FCA is likely to audit you…. Gives you sufficient information for trouble-shooting and for providing world-class service to your clients Key to learning to me is that we’re custodians of the data – it’s not ours