CIO CIO

독일 IT 사용자 협회, EU 집행위에 브로드컴 민원 제기··· “심각한 경쟁 위반”

협회는 브로드컴의 번들링 전략이 이중의 부정적 효과를 낳는다고 언급하며, “실제로 필요하지 않은 추가 제품까지 의무적으로 구매해야 하는 상황은 ‘질적 번들링 효과’를 낳는다. 또한 필요한 수량보다 더 많은 라이선스를 구매해야 하기에 ‘양적 번들링 효과’도 생긴다”라고 지적했다. 결국 고객이 필요하지 않은 제품을 필요 이상의 수량으로 구매하게 되는 이중 부담을 진다는 설명이다. VOICE 책임자들은 브로드컴의 비즈니스 관행도 비판했다. 이에 따르면 기존 라이선스 계약이 끝나가는 고객들은 협상 과정에서 심한 압박을 받고 있다. 예를 들어 브로드컴은 고객에게 전환에 필요한 시간을 주지 않거나 계약상 합의된 갱신 옵션을 거부하고 있으며, 고객의 대응 시간을 최소화하기 위해 의도적으로 문의 응답을 지연시키는 전략을 쓰고 있다고 협회는 지적했다. 카우프만은 “이런 심각한 공정 경쟁 위반 때문에 VOICE는 EU 집행위원회에 정식으로 민원을 제기했다. 소프트웨어와 클라우드 시장에서 공정한 경쟁이 이뤄지길 바라지만, 안타깝게도 불공정 관행으로 인해 반복적으로 위협받고 있다. 이에 맞서 싸울 것”이라고 말했다[email protected] source

독일 IT 사용자 협회, EU 집행위에 브로드컴 민원 제기··· “심각한 경쟁 위반” Read More »

IT leadership in the AI era: Lessons from some of Asia’s top companies

The rapid advancement of artificial intelligence (AI) is reshaping whole industries, economies and leadership paradigms. In the AI era, IT leaders must evolve beyond traditional management styles to embrace innovation, agility and ethical responsibility.  Great IT leadership today requires a combination of technical expertise, strategic vision and emotional intelligence to navigate disruption and drive digital transformation.  Asia, the fast-growing economic body and home to some world’s fastest-growing digital economies, offers invaluable lessons in IT leadership. Companies like Tencent, Alibaba,  TSMC, Samsung and Softbank, in Asia have demonstrated how visionary leadership can harness AI for competitive advantage.  source

IT leadership in the AI era: Lessons from some of Asia’s top companies Read More »

2025 CIO 현황 보고서 발표··· “CIO, 전략적 AI 조율가로 부상”

PNNL은 클라우드 기반 IT 아키텍처와 인프라 현대화를 지속적으로 추진하고 있으며, 사이버보안 투자도 확대하고 있다. 이는 2025 CIO 현황 조사에 응답한 많은 CIO들과 공통된 목표다. 올해 조사에 따르면 CIO는 인프라 및 애플리케이션 현대화 전략 수립(32%), IT 프로젝트와 비즈니스 목표 정렬(31%), 비즈니스 프로세스 재설계(26%)에 많은 시간을 투자하고 있었다. 변화 주도 역시 주요 역할 중 하나로, 응답자의 25%가 이 업무를 담당한다고 응답했다. 이처럼 전략 중심의 역할이 확고해지면서 CIO들은 올해 더 많은 시간을 전략 수립에 할애하고 있다. 비즈니스 혁신 주도(27%), 전략 개발 및 고도화(27%), 시장 동향과 고객 니즈 분석(22%)이 대표적이다. 특히 향후 가장 많은 시간을 투자할 계획인 분야로는 AI/ML 관련 프로젝트가 75%로 가장 높았고, 사이버보안(65%), 제품 개발 및 혁신(56%), 데이터 분석(56%)이 그 뒤를 이었다. CIO.com 전략에 집중한다고 해서 기존 운영·전환 업무가 사라지는 것은 아니다. 응답자의 38%는 여전히 보안 관리, IT 운영 및 성능 개선에 시간을 할애하고 있었다. 인프라 현대화 전략 수립(32%), 비즈니스 목표와의 정렬(31%), 프로세스 재설계(26%) 역시 주요 업무로 언급됐다. source

2025 CIO 현황 보고서 발표··· “CIO, 전략적 AI 조율가로 부상” Read More »

Why Zero Trust architecture is superior to traditional security models

Today’s threat landscape is marked by increasingly sophisticated cyberattacks. Ransomware incidents grew by 18% in 2024, while the Dark Angels cybercrime group walked away from a single attack with a payout of $75 million. Ransomware-as-a-service is growing in popularity and zero-day attacks continue to be unleashed at a rapid pace. There is a clear rise in phishing, and the malicious use of artificial intelligence (AI) is bypassing traditional security measures. All of this sets a hazardous stage for any organization trying to keep itself safe. Business decision-makers and IT leaders are now well aware of the effects of these risks. From disrupted operations and regulatory non-compliance to legal fees and customer churn, the impact of falling prey to any cyberattack is significant. Security teams are under immense pressure to adopt strategies and systems that stave off evolving risks. The successful ones choose zero trust architecture rather than the network-centric, perimeter-based security models that are unequipped to face the threats of the digital era. Traditional security models: What’s the risk? With a perimeter-based architecture, security, and connectivity revolve around a trusted network that is extended to users, devices, sites, clouds, and applications. This network extension is done in order to provide users and other entities with access to the IT r sources connected to that network. Naturally, this produces a sprawling flat network that is vulnerable to cyberattacks. So, to protect it, organizations deploy appliances like firewalls and virtual private networks (VPNs) in an attempt to establish a security perimeter that keeps bad things out and good things in. This network-centric architecture was designed for a simpler, on-premises-only, bygone era. It is not well suited to our digital world with its work-from-anywhere users and its countless cloud applications hosted off-premises. In fact, when organizations cling to this old-school architecture while embracing remote work and the cloud, it creates significant problems. And even when tools like firewalls and VPNs are deployed as virtual appliances in the cloud, the underlying methodology and its fundamental flaws remain the same. By nature, perimeter-based architectures: Expand your attack surface: Endlessly extending your network to users, apps, devices, clouds, and locations, and using tools with public IP addresses, like firewalls, results in a ballooning network with countless entry points ripe for exploitation. Failure to prevent compromise: Perimeter-based security solutions like firewall appliances struggle to inspect encrypted web traffic at scale, perform cursory traffic scanning ratherthan full inspection, and ultimately enable threats to pass through defenses. Enable lateral threat movement: Once malicious entities have made it past your defenses and accessed your network, they can move laterally throughout it and accessthe resources connected to it, expanding the reach of their breaches. Are unable to stop data loss: As mentioned above, network-centric tools struggle to inspect encrypted traffic; additionally, they are not designed to secure data leakagepaths like SaaS apps, endpoints, private apps, and more. As such, they are often unable to stop data loss. In addition to these four major weaknesses, network-centric models have other challenges. First, they increase IT complexity through stacks of networking and security appliances, which, regardless of whether they are deployed as hardware or virtual appliances, contribute to convoluted IT infrastructure. Next, managing a complex fleet of point products and appliances requires a significant amount of time from administrators. This, when combined with the technologies’ purchase prices and the expensive private connections needed for traditional networking, leads to significant costs. Finally, when traffic has to be backhauled to a distant data center or virtual appliance for security and connectivity, the added latency harms user experience and, as a result, impedes productivity. Zero trust architecture: Why it’s the modern security standard Zero trust represents a stark departure from the perimeter-based model and is a fundamentally distinct architecture. It successfully decouples security and connectivity from your network through a cloud native platform that acts as an intelligent switchboard and delivers secure any-to-any connectivity as a service at the edge—without extending network access to anyone or anything. As such, zero trust avoids the excessive permissions and implicit trust of traditional models that connect entities to the network. Granular, least-privileged access directly to IT resources is enforced through context-based policies that assess risk and respond accordingly. It’s a more intelligent approach to security that lacks the manifold weaknesses of firewalls and VPNs. Zero trust architecture enables you to: Minimize your attack surface: Direct-to-app connectivity circumvents the need for endless network extension, while firewalls and their public IPs are eliminated. Instead of inbound connections, zero trust uses inside-out connections (a connector sitting in front of the app reaches out to the zero trust cloud, which then stitches the connection together). All of this shrinks your attack surface and, as a result, the potential for a breach to ever begin. Prevent compromise: Zero trust is delivered through a proxy-based architecture that performs full traffic inspection in order to stop attacks in real time. With a cloud native platform that boasts a high degree of performance, it can even inspect encrypted traffic at scale; this is critical because more than 95% of web traffic today is encrypted, and more threats are hiding within said traffic than ever before. Eliminate lateral threat movement: As mentioned previously, zero trust provides least-privileged access through direct-to-app connectivity. When no entities areconnected to your corporate network as a whole, no one (and no thing) can move laterally within it, access its various connected resources, or expand the blast radius of a cyber breach. Stop data loss: When zero trust is delivered through a high-performance, cloud native platform, you can fully inspect all of your traffic, including encrypted traffic at scale, and prevent data loss therein. Additionally, comprehensively securing any-to-any connectivity while ensuring granular, least-privileged access to data means that a zero trust platform can secure sensitive information and any possible leakage path. Beyond these four core benefits of zero trust, the architecture provides additional advantages that eliminate other issues inherent to perimeter-based architectures. First, zero trust secures any-to-any connectivity with a breadth of functionality, circumvents

Why Zero Trust architecture is superior to traditional security models Read More »

MS도 합류··· 구글의 A2A 프로토콜, AI 에이전트 분야의 공용어 될까?

A2A는 앤스로픽의 MCP(model context protocol))라는 또 다른 에이전트 간 통신 프로토콜이 주목받는 시점에 등장했다. A2A는 다중 에이전트의 오케스트레이션을 가능하게 하며, MCP는 에이전트가 도구에 접근할 수 있도록 한다. 현실 적용에서는 에이전트가 A2A를 통해 서로 협력하고, MCP를 통해 다른 시스템과 상호작용하게 될 가능성이 높다고 칼버트는 전망했다. 즉 A2A와 MCP는 서로 경쟁하기보다는 보완하는 존재다. IDC의 부사장인 밥 파커는 “이들은 서로 다른 요구사항을 충족시키며, 에이전트가 함께 작동하기 위해 서로 필요로 하는 관계”라고 설명했다. AI 에이전트는 복잡한 대규모 배포 환경에서 데이터를 이해하고 맥락화하기 위해 미들웨어를 필요로 하며, 이것이 MCP의 역할이다. A2A는 ‘에이전트 간 비동기 통신’으로 AI 산업에서 기본 프로토콜로 부상하고 있다고 파커는 평가했다. 예를 들어, M365 내의 에이전트는 A2A를 통해 앱이나 서비스 내에서 직접 통신할 수 있으며, 이는 “생산성 향상에 더 즉각적인 메커니즘”이라는 설명이다. source

MS도 합류··· 구글의 A2A 프로토콜, AI 에이전트 분야의 공용어 될까? Read More »

"지난해 정보 탈취 맬웨어 500% 증가" 포티넷

포티넷코리아가 ‘2025 글로벌 위협 환경 보고서’를 7일 발표했다. 이번 보고서는 2024년 사이버 위협 환경을 분석했다. 포티넷은 사이버 공격자들이 자동화, 상품화된 도구 및 AI를 활용해 기업의 기존 방어 체계를 무력화하고 있음을 보여준다고 설명했다. source

"지난해 정보 탈취 맬웨어 500% 증가" 포티넷 Read More »

IBM aims to set industry standard for enterprise AI with ITBench SaaS launch

The platform differs from existing benchmarking approaches through its focus on end-to-end evaluation of AI agents in dynamic IT environments. According to IBM, current industry benchmarks typically focus on narrow capabilities like “static anomaly detection, tabular ticket analysis, or hardcoded fault injection,” which don’t adequately capture the complexity of enterprise IT operations. Domain-specific evaluation with a partial credit system A notable aspect of the ITBench framework is its domain-centered evaluation metrics tailored to specific enterprise functions, which could provide a more nuanced assessment than generic AI benchmarks. “The evaluation metrics are domain-centric, tailored to the specific needs of SREs, CISOs, and FinOps,” Sow explained. “For example, SRE tasks focus on fault diagnosis, checking how well an AI agent can find where a problem started and how it spread, and mitigation, how quickly issues are resolved.” source

IBM aims to set industry standard for enterprise AI with ITBench SaaS launch Read More »

AI’s big payoff hinges on fixing fragmented data: Study

Singh urged CIOs to embrace “data product thinking” — treating high-quality, reusable data sets as business assets. When done right, this powers AI use cases that actually move the needle, like predicting local stock needs or reducing travel spend. To make AI work in real time, CIOs should build a data fabric that connects systems and embeds intelligence into day-to-day operations. Cloud-native platforms help teams collaborate across silos, while event-driven architecture lets AI respond the moment new data comes in. AI also needs to be trained on clean, enterprise-specific data, with business rules, ethics, and security baked in. A strong training framework, coupled with feedback loops, helps AI spot issues, improve processes, and stay relevant, added the study. source

AI’s big payoff hinges on fixing fragmented data: Study Read More »

CDO and CAIO roles might have a built-in expiration date

“The CDO role is likely to be durable, much due to the long-term strategic value of data; however, it is likely to evolve to encompass more strategic business responsibility,” he says. “The CAIO, on the other hand, is likely to be subsumed into CTO or CDO roles as AI technology folds into core technologies and architectures standardize.” For now, both CIAOs and CDOs have responsibilities beyond championing the use of AI and good data governance, Stone adds. They will build the foundation for enterprise-wide benefits of AI and good data management. “As AI and data literacy take hold across the enterprise, CDOs and CAIOs will shift from internal change enablers and project champions to strategic leaders and organization-wide enablers,” he says. “They are, and will continue to grow more, responsible for setting standards, aligning AI with business goals, and ensuring secure, scalable operations.” source

CDO and CAIO roles might have a built-in expiration date Read More »

6 tips for tackling technical debt

So McGurk factors that into not just his development cycle but IT operations, pulling in various tactics to create a holistic approach for managing technical debt on a continuous basis. As part of this approach, McGurk’s team documents and details the introduction of any new technical debt, which is then tracked through the organization’s ticketing system so that IT teams “can pull that all up and report it and look at it.” McGurk also considers how each piece of technical debt impacts operations in five key areas: simplicity, flexibility, continuity, security, and transparency. “When technical debt starts hindering any of those operating principles, then it’s risen to the level where we want to address it,” he explains. McGurk and his IT team consider the level of impact, the risk to the organization, and the organization’s overall strategy to then prioritize what needs attention. They then make those determinations known, thereby creating visibility into the topic across the organization. source

6 tips for tackling technical debt Read More »