<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paul Matthews &#8211; iStart leading the way to smarter technology investment.</title>
	<atom:link href="https://istart.co.nz/istart-author/paul-matthews/feed/" rel="self" type="application/rss+xml" />
	<link>https://istart.co.nz</link>
	<description>iStart technology in business leading the way to smarter technology investment - A/NZ ERP, CRM, BI, HR, eCommerce software research, trends and buyer&#039;s guides.</description>
	<lastBuildDate>
	Tue, 06 Oct 2026 09:19:01 +0000	</lastBuildDate>
	<language>en-nz</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>What you need to know about GDPR</title>
		<link>https://istart.co.nz/nz-opinion-article/what-need-know-gdpr-anz/</link>
				<comments>https://istart.co.nz/nz-opinion-article/what-need-know-gdpr-anz/#respond</comments>
				<pubDate>Mon, 28 May 2018 23:27:59 +0000</pubDate>
		<dc:creator><![CDATA[Jennene Kelly]]></dc:creator>
		
		<guid isPermaLink="false">https://istart.co.nz/opinion-article/what-need-know-gdpr-anz/</guid>
				<description><![CDATA[<p>GDPR went live on 25 May - but how does it affects you?...</p>
<p>The post <a rel="nofollow" href="https://istart.co.nz/nz-opinion-article/what-need-know-gdpr-anz/">What you need to know about GDPR</a> appeared first on <a rel="nofollow" href="https://istart.co.nz">iStart leading the way to smarter technology investment.</a>.</p>
]]></description>
								<content:encoded><![CDATA[<section class="vc_section_wrapper"><div class="wpb_row row-fluid">
	<div class="span12 wpb_column column_container">
		<div class="wpb_wrapper">
			
	<div class="wpb_text_column wpb_content_element ">
		<div class="wpb_wrapper">
			<p>So what&#8217;s all the fuss about? It&#8217;s actually a really significant change to the rules around personal data, and <strong>it really does affect you</strong>.</p>
<p><strong>Here&#8217;s a quick summary:</strong></p>
<ul>
<li>The EU says the changes attempt to &#8220;harmonize data privacy laws across Europe, protect and empower all EU citizens data privacy and reshape the way organisations across the region approach data privacy.&#8221;</li>
</ul>
<ul>
<li>One of the more controversial impacts of the new rules, and the reason it has such a world-wide impact, is what they call the &#8220;<strong>extra-territorial applicability</strong>&#8220;.  This means that it applies to all companies worldwide who are <strong>dealing with information about people residing in the EU</strong>, even those simply offering goods or services to EU citizens. It hits everyone and it&#8217;s huge.</li>
</ul>
<ul>
<li>One of the key changes is around <strong>consent</strong>. Basically if a company is going to store or process personal data such as names, email addresses and the like, it needs to have explicit consent. The small print in the middle of a <strong>10-page &#8220;terms and conditions&#8221;</strong> aren&#8217;t enough &#8211; it has to be in complete <strong>plain English</strong>.</li>
</ul>
<ul>
<li>The method of consent has to be recorded as well and proper records kept. This is significant &#8211; for example, if you have a mailing list you need to be able to show when people opted in and how.</li>
</ul>
<ul>
<li><strong>The fines are huge too</strong>. Companies can be fined up to <strong>4 percent of their annual global turnover</strong> for breaches, with big fines for even seemingly minor issues.</li>
</ul>
<ul>
<li>Companies must now also tell people if they&#8217;ve had a <strong>breach</strong>. We&#8217;ve seen a heap of this lately &#8211; people&#8217;s information being stolen and companies keeping it quiet to try to avoid reputation damage. Do that now and it could cost <strong>2 percent of global revenue</strong>.</li>
</ul>
<ul>
<li>Other changes are familiar to kiwis, such as the right to obtain (free of charge) any information that is <strong>being held about them</strong>. That&#8217;s been a part of NZ&#8217;s Privacy Act for a long time, although the EU law goes further.</li>
</ul>
<ul>
<li>There&#8217;s heaps more as well, such as the controversial &#8220;<strong>right to be forgotten</strong>&#8221; This basically gives EU citizens the right to have Google, for example, remove references to them on searches. And again, the rules apply globally &#8211; not just to EU companies.</li>
</ul>
<ul>
<li>The new rules also put into law the concept of &#8220;<strong>Privacy by design</strong>&#8221; for software developers. Basically software developers have to show they&#8217;ve built privacy into software from the ground up, not just tagged it on in the end. This has been a long time coming.</li>
</ul>
<p>So some really important things to think about from a IT Professional perspective as well, even if you&#8217;re not based in the EU.</p>
<p><span style="color: #ff9900;"><a style="color: #ff9900;" href="https://gdpr-info.eu/" target="_blank">View the full regulations here</a></span></p>
<p><strong><br />
<a href="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg"><img class="alignright size-medium wp-image-10147" src="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg" alt="Paul Matthews" width="148" height="200" srcset="https://istart.co.nz/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg 148w, https://istart.co.nz/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg 150w" sizes="(max-width: 148px) 100vw, 148px" /></a>ABOUT PAUL MATTHEWS//</strong></p>
<p><span style="color: #ff9900;"><a style="color: #ff9900;" href="https://www.linkedin.com/in/nzpaulm" target="_blank">Paul Matthews</a></span> is chief executive of the Institute of IT</p>

		</div> 
	</div> 
		</div> 
	</div> 
</div></section>
<p>The post <a rel="nofollow" href="https://istart.co.nz/nz-opinion-article/what-need-know-gdpr-anz/">What you need to know about GDPR</a> appeared first on <a rel="nofollow" href="https://istart.co.nz">iStart leading the way to smarter technology investment.</a>.</p>
]]></content:encoded>
							<wfw:commentRss>https://istart.co.nz/nz-opinion-article/what-need-know-gdpr-anz/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
							</item>
		<item>
		<title>IITP welcomes new software procurement model</title>
		<link>https://istart.co.nz/nz-opinion-article/iitp-welcomes-new-software-procurement-model/</link>
				<comments>https://istart.co.nz/nz-opinion-article/iitp-welcomes-new-software-procurement-model/#respond</comments>
				<pubDate>Fri, 19 Jun 2015 04:27:31 +0000</pubDate>
		<dc:creator><![CDATA[Jennene Kelly]]></dc:creator>
		
		<guid isPermaLink="false">https://istart.com.au/?post_type=opinion-article&#038;p=11711</guid>
				<description><![CDATA[<p>Recently, the MBIE and the NZ Police launched a Request for Proposals for the development of a a mobile 111 app and related technology. But, writes IITP CEO <strong>Paul Matthews</strong>, this was no ordinary RFP…</p>
<p>The post <a rel="nofollow" href="https://istart.co.nz/nz-opinion-article/iitp-welcomes-new-software-procurement-model/">IITP welcomes new software procurement model</a> appeared first on <a rel="nofollow" href="https://istart.co.nz">iStart leading the way to smarter technology investment.</a>.</p>
]]></description>
								<content:encoded><![CDATA[<section class="vc_section_wrapper"><div class="wpb_row row-fluid">
	<div class="span12 wpb_column column_container">
		<div class="wpb_wrapper">
			
	<div class="wpb_text_column wpb_content_element ">
		<div class="wpb_wrapper">
			<p>IITP has been working behind the scenes over the last few months helping MBIE develop a new approach to software procurement for a new project to develop an Emergency Response System, which will include an app and related technology. While this is a one-off and not technically a pilot or trial for the new approach outlined below, if the project is successful, we believe we&#8217;ll see further developments in this space and probable wider adoption.</p>
<p>So what makes this procurement different?</p>
<p><strong>Qualifications-based selection</strong><br />
The procurement process for the project is based on a variant of Qualifications-based Selection.</p>
<p>On paper, QBS is considered to more compatible with Agile development than traditional procurement processes and has been highly successful in other industries overseas when dealing with complex and higher-risk projects, similar to the characteristics of bespoke software. The US federal government has used QBS for complex engineering projects for many years and in NZ, a variant of QBS (called the &#8220;Alliance Model&#8221;) is used for large and complex roading projects where innovation is needed and the detailed requirements are unknown at the start.</p>
<p>Under QBS, the entire focus of the procurement is to find the best provider(s) to work as a partner on the collaborative development of a solution. Price isn&#8217;t considered, and in fact is explicitly excluded from consideration during the RFP phase. The only consideration is who would be best able to work with the client and deliver a solution, based on factors such as previous experience and proven results. Importantly, the client is procuring a partner to help develop a solution, not a product.</p>
<p>The downside of QBS is that it favours providers with experience, thereby making it a little harder for those without a track record to be selected. However, given its use for complex or higher-risk projects (in this case, emergency service software), this ain&#8217;t a bad thing. Innovative providers without the breadth of necessary experience can still get a look-in however, with the RFP explicitly allowing consortia or alliances and the requirements being applied to a consortium accordingly.</p>
<p><strong>Outcomes-based collaborative approach</strong><br />
The requirements of the final product aren&#8217;t specified in the RFP other than in fairly general terms including a couple of bottom-line features and outcomes. The intention is to take an outcomes-based approach; MBIE and NZ Police don&#8217;t have a monopoly on good ideas, and the whole structure is designed to support and encourage innovative thinking from potential partners.</p>
<p>As outlined above, the intention is to find the best partner or partners, and to then work with them on designing a potential solution. The clients can then harness the experience, ideas, and innovation of the industry, rather than killing innovation by attempting to specify exactly what the solution will look like upfront. There are also workshops planned where potential partners can explore possibilities and fairly freely discuss opportunities and options &#8211; prior to the RFP closing.</p>
<p>By talking in terms of outcomes rather than specifications, potential partners are free to do something really special, without the restrictive bounds of traditional procurement. The hope is that this will lead to an outside the box solution, possibly quite different &#8211; and superior &#8211; to what the client might have been thinking initially.</p>
<p><strong>Proof-of-concept &#8220;bake-off&#8221;</strong><br />
The selection process ranks respondents based on set criteria designed to find the most compatible partner which can show it can deliver results, rather than procuring a product or solution.</p>
<p>Via the QBS process, the 2-3 most compatible partners are selected and will then participate in a proof of concept &#8220;bake-off&#8221;. The client will work collaboratively and directly with each partner to start to put some ideas on paper, with the partner designing what the outcome and solution might look like as a concept.</p>
<p>The partners will then present their proof of concept and one will be chosen to develop the solution. However all partners in the bake-off will be paid whether selected or not, assuming they see the process through and deliver on the proof-of-concept requirements, via a &#8220;grant&#8221; of $75,000 each.</p>
<p>The client then negotiates the development terms, including cost, with the preferred partner. If terms can&#8217;t be reached, the client will likely commence negotiations with the next-placed provider and, assuming an agreement can be reached either way, development of the full solution will commence.</p>
<p><strong>Agile approach</strong><br />
Compatibility with Agile development is implicit in the design of the process, and while Agile is certainly not mandatory, compatibility has been considered at every stage of the RFP and development process.</p>
<p>We know two things about Agile and procurement: (1) it generally leads to far better results in software development, for example with Standish finding it leads to 1/3 of the project failures of traditional waterfall-based methodologies, and (2) genuine Agile is not particularly compatible with traditional &#8220;price and specs up front&#8221; procurement.</p>
<p>We also know that when price-up-front is mandated, it almost never equals the cost of a project at completion, especially for complex projects. So why do we continue to use it as a selection criteria in software procurement? We believe the evidence shows we&#8217;re far more likely to see good results by worrying about cost only once we actually know what the solution is really going to look like, with providers focused on innovating rather than selling during at least the initial phases.</p>
<p><strong>Focus on the people delivering solutions</strong><br />
While not unique to this RFP, strong emphasis has been put on the actual people who will be involved in delivering the outcome, including their track record, background, knowledge, qualifications and experience.</p>
<p>From IITP&#8217;s perspective, it has to be about the people; people and teams deliver solutions, not brands. We&#8217;re very pleased to see this focus and while there isn&#8217;t a requirement for Chartered IT Professional NZ accreditation from respondents, we would certainly hope to see people at that level involved in leading the project.</p>
<p><strong>Intellectual Property</strong><br />
The government will be granted a permanent license to use any IP generated during development, however the resulting IP will be owned by the partner. This means the partner can freely turn it into a broader product or service and go forth and export &#8211; sell it to other Governments, bundle it into other offerings, evolve it into something else, or even open-source it if they&#8217;d prefer.</p>
<p>The long and short is that rather than it being seen as a one-off, our hope is that the project will turn into something far larger and contribute to the development and growth of the NZ industry.</p>
<p><strong>A major step forward</strong><br />
We believe the approach taken is a major step forward in the procurement of software in New Zealand, and we&#8217;re seriously impressed with the collaborative approach and focus on industry-supported innovative procurement from MBIE.</p>
<p>Is the model perfect? Probably not. But it&#8217;s a real and serious step towards addressing many of the well-documented problems with software procurement by government. We see this as a real opportunity for our industry and strongly encourage innovative app developers to seriously look at being a part of it, either on their own or in partnership with cloud, infrastructure or other providers.</p>
<p>View the <a href="https://www.gets.govt.nz/MBIE/ExternalTenderDetails.htm?id=13029503" target="_blank">summary on GETS</a> here.</p>
<p><em>IMPORTANT NOTE: This article is for information only, and should be considered good faith opinion only. IITP is commenting on the process contained in the RFP released yesterday, and is not procuring the solution &#8211; that&#8217;s MBIE and NZ Police. Thus, where anything written here differs from the detail in the Request for Proposal, please consider the RFP correct.</em></p>
<p><strong>ABOUT PAUL MATTHEWS//</strong><br />
<a href="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg"><img class="alignright size-full wp-image-10147" src="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg" alt="Paul Matthews" width="150" height="202" srcset="https://istart.co.nz/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg 150w, https://istart.co.nz/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg 148w" sizes="(max-width: 150px) 100vw, 150px" /></a><span style="color: #ff9900;"><a href="https://www.linkedin.com/in/nzpaulm" target="_blank"><span style="color: #ff9900;">Paul Matthews</span></a> </span>is chief executive of the Institute of IT</p>

		</div> 
	</div> 
		</div> 
	</div> 
</div></section>
<p>The post <a rel="nofollow" href="https://istart.co.nz/nz-opinion-article/iitp-welcomes-new-software-procurement-model/">IITP welcomes new software procurement model</a> appeared first on <a rel="nofollow" href="https://istart.co.nz">iStart leading the way to smarter technology investment.</a>.</p>
]]></content:encoded>
							<wfw:commentRss>https://istart.co.nz/nz-opinion-article/iitp-welcomes-new-software-procurement-model/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
							</item>
		<item>
		<title>Time to call in the pros</title>
		<link>https://istart.co.nz/nz-opinion-article/time-to-call-in-the-pros/</link>
				<comments>https://istart.co.nz/nz-opinion-article/time-to-call-in-the-pros/#respond</comments>
				<pubDate>Sun, 29 Mar 2015 22:27:44 +0000</pubDate>
		<dc:creator><![CDATA[Jennene Kelly]]></dc:creator>
		
		<guid isPermaLink="false">https://istart.co.nz/opinion-article/time-to-call-in-the-pros-2/</guid>
				<description><![CDATA[<p>The Institute of IT Professionals NZ (IITP) CEO <strong>Paul Matthews</strong> explains what the Chartered IT Professional accreditation is and why we need it…</p>
<p>The post <a rel="nofollow" href="https://istart.co.nz/nz-opinion-article/time-to-call-in-the-pros/">Time to call in the pros</a> appeared first on <a rel="nofollow" href="https://istart.co.nz">iStart leading the way to smarter technology investment.</a>.</p>
]]></description>
								<content:encoded><![CDATA[<section class="vc_section_wrapper"><div class="wpb_row row-fluid">
	<div class="span12 wpb_column column_container">
		<div class="wpb_wrapper">
			
	<div class="wpb_text_column wpb_content_element ">
		<div class="wpb_wrapper">
			<p>In 1907 a group of engineers and bridge builders in Quebec, Canada, embarked on an ambitious project to build the longest bridge in the world. But before the bridge was completed it was to cost almost 100 human lives.</p>
<p>On August 29th the partially built bridge collapsed, killing 75 workers and injuring another 11. A Royal Commission of Enquiry found a lack of experience of the type and size of bridge and clear mistakes had caused the disaster and held the designer and consulting engineers responsible. Construction began on the bridge once more in 1916, but disaster struck again, when the central span was being raised into position, and fell into the river killing 13 workers.</p>
<p>The managers had been made aware of the problem that caused this second collapse a full six weeks prior by the engineer responsible for the construction of the centre section, but hadn’t taken any action. All in all, 88 people lost their lives to predictable failures.</p>
<p>So what does all of this have to do with IT and technology today?</p>
<p>It was after this double tragedy that the concept of the Professional Engineer was born. Engineers realised that they couldn’t continue to have such devastating failures caused by inexperience or not following reasonable standards of practice. And they could no longer tolerate decision-makers ignoring their professional advice.</p>
<p>A similar sentiment has been growing in the international IT community since 2008, when the national tech professional bodies from Canada, the UK, Australia, South Africa, Japan and elsewhere came together to discuss whether it was time for the IT profession to also put in place minimum competency standards. Since then, all of these countries, and many others have done just that.</p>
<p>In New Zealand’s case, the road towards the Chartered IT Professional accreditation that was officially released in February began when the IITP (then called the NZ Computer Society) released a 2008 discussion document outlining a range of problems in the industry and calling for the profession to form independent competency standards to address them.</p>
<p>As well as continual significant failures in major IT projects in both the public and private sectors, some of the issues highlighted included the global IT skills shortage; significant reduction in technology undergraduates and in the percentage graduating; negative perception of IT as a career amongst youth; and lack of retention of skilled individuals in New Zealand.</p>
<p>In other words, our bridges were falling down and we needed to do something about it. New Zealand’s response, run by the Institute and named IT Certified Professional (ITCP), was released in late 2009 to great success.</p>
<p>Up until that point, IT was almost the only vocation or profession remaining without a set of independent benchmarks outlining the minimum expected standards of skills, knowledge, ethics and professionalism for people operating the field. And we’re not just talking about the established professions such as accountants and lawyers here. Almost every area you can think of, from plumbers to librarians and architects, has minimum standards in the form of an overarching professional certification. The reason for such accreditations is that there is a real difference between someone who knows what they’re doing and someone who doesn’t. Professionals have the right to differentiate themselves and a responsibility to come together within professional bodies and define minimum standards.</p>
<p>In February the IITP converted the ITCP to the Chartered IT Professional NZ, issued under license from the UK-based BCS, the Chartered Institute for IT. It also introduced a new Certified Technologist accreditation for those in the first few years of their career. The reason for the change is to increase the recognition of Kiwi IT professionals both in New Zealand and around the world, and to provide credentials that are immediately recognisable by the public.</p>
<p>Those accredited have committed to adhering to standards of professional conduct and ethics and have agreed to be professionally accountable if they don’t. In return, they have the weight of the entire profession behind them when they say that a project can’t proceed because if it does, the bridge will fall down.</p>
<p><strong>ABOUT PAUL MATTHEWS//</strong><br />
<a href="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg"><img class="alignright size-full wp-image-10147" src="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg" alt="Paul Matthews" width="150" height="202" srcset="https://istart.co.nz/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg 150w, https://istart.co.nz/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg 148w" sizes="(max-width: 150px) 100vw, 150px" /></a><span style="color: #ff9900;"><a href="https://www.linkedin.com/in/nzpaulm" target="_blank" rel="noopener noreferrer"><span style="color: #ff9900;">Paul Matthews</span></a> </span>is chief executive of the Institute of IT</p>

		</div> 
	</div> 
		</div> 
	</div> 
</div></section>
<p>The post <a rel="nofollow" href="https://istart.co.nz/nz-opinion-article/time-to-call-in-the-pros/">Time to call in the pros</a> appeared first on <a rel="nofollow" href="https://istart.co.nz">iStart leading the way to smarter technology investment.</a>.</p>
]]></content:encoded>
							<wfw:commentRss>https://istart.co.nz/nz-opinion-article/time-to-call-in-the-pros/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
							</item>
		<item>
		<title>How to avoid the IT hall of shame</title>
		<link>https://istart.co.nz/nz-opinion-article/how-to-avoid-the-it-hall-of-shame/</link>
				<comments>https://istart.co.nz/nz-opinion-article/how-to-avoid-the-it-hall-of-shame/#respond</comments>
				<pubDate>Thu, 04 Apr 2013 21:41:23 +0000</pubDate>
		<dc:creator><![CDATA[Jennene Kelly]]></dc:creator>
		
		<guid isPermaLink="false">http://testbed.istart2.com.au/opinion-article/how-to-avoid-the-it-hall-of-shame-2/</guid>
				<description><![CDATA[<p>IT security and project stuff-ups are certainly nothing new in our field. But things seem to be getting worse and sadly, most of these issues are preventable...</p>
<p>The post <a rel="nofollow" href="https://istart.co.nz/nz-opinion-article/how-to-avoid-the-it-hall-of-shame/">How to avoid the IT hall of shame</a> appeared first on <a rel="nofollow" href="https://istart.co.nz">iStart leading the way to smarter technology investment.</a>.</p>
]]></description>
								<content:encoded><![CDATA[<p>Two thousand and twelve certainly saw its share of high-profile IT gaffs. The year seemed to lurch from scandal to scandal, with the two most prominent security stuff-ups being the calamitous launch of TradeMe competitor Wheedle, taken down after just a few days amidst what had become a fever pitch of complaints about gaping security holes; and the revelation that up to 736 publicly-accessible kiosks in WINZ offices throughout New Zealand weren&#8217;t properly locked down, allowing access to sensitive documents including details of abused children.</p>
<p>Add to that the long-running and far from resolved Novopay fiasco and 2012 certainly wasn’t a good year for the reputation of our profession.</p>
<p>In fact New Zealand&#8217;s Privacy Commissioner Marie Shroff has gone as far as labeling it the &#8220;year of the data breach&#8221; and, given the above issues and others such as the ACC Pullar affair, it would certainly be difficult to argue that she&#8217;s wrong.</p>
<p>So what really happened and what do the issues of the past year have in common? Wheedle was a well-intentioned and, by all accounts, well-resourced company that promised to finally take on incumbent behemoth TradeMe in the online auction game. Backed by the founder of Mainfreight, its battle cry included claims of good technology, 40 servers on standby and millions in advertising.</p>
<p>But despite all of this, the founders seriously let themselves down on the IT front. For example, they allegedly didn&#8217;t even bother encrypting passwords sufficiently and left gaps in their website that allowed members to change other members&#8217; auction details (including reserve and buy-now prices) leaving the site open to serious abuse. In fact they made a litany of fairly entry-level coding errors and simply got the basics wrong.</p>
<p>It was later revealed that the website development had been outsourced to developers in India, presumably to save costs.</p>
<p>The WINZ kiosk situation should never have happened either. In this case, the Ministry of Social Development built hundreds of self-help kiosks to enable the unemployed to edit their CVs and search for jobs. A great idea, and for the most part they did everything right. However there were two fundamental – and basic – flaws to their execution.</p>
<p>The first was technical; the kiosks were connected smack-bang in the middle of the Ministry&#8217;s network with no separation, physical or logical. This meant that a somewhat minor oversight when locking the kiosks down (the ability to access network locations through Microsoft Word&#8217;s ‘Open’ dialog box) became a major issue, especially when it was combined with access to sensitive files such as phone logs, invoices and other information, including that of abused children.</p>
<p>While somewhat unforgivable, this wasn&#8217;t even the biggest oversight. It emerged later that the Ministry had been made aware of these issues. In fact they&#8217;d hired an external security company to audit the kiosks, then simply ignored four out of the six security issues identified, including the major lack-of-separation issue that caused the breach.</p>
<p>Interestingly, a request for funds to do the separation properly had been made. It was apparently ignored and the project pushed ahead without it, probably to save costs. It&#8217;s worth noting that the cost of the two recent Deloitte reports into what went wrong is an astonishingly high $450,000 so far – and that&#8217;s before the fix has even started.</p>
<p>So again, ignoring the basics caused potentially catastrophic results.</p>
<p>Then there&#8217;s Novopay, the New Zealand Ministry of Education&#8217;s payroll solution built on Australia&#8217;s Talent2 system. Those that have worked in IT for any length of time will know there are often teething problems in the implementation of any new system, especially one as complex as a payroll system for upwards of 90,000 people in hundreds of schools across a country. Teething problems are more or less a given, which is why they are factored into the rollout plans for major new systems.</p>
<p>Already two years overdue and undoubtedly millions over budget, did the powers that be push ahead with the Novopay launch knowing there were still issues, amidst political and financial pressure to get it done? It appears the pre-launch testing showed the system wasn&#8217;t ready; only 37 percent of trial users thought it was ready to go. Yet on 20 August 2012 they kicked it off anyway, flicking the switch on all schools and all teachers in one fell swoop.</p>
<p>The promised ministerial inquiry into the resulting mess will hopefully shed light on why they didn&#8217;t roll it out to a small group of schools first to identify and resolve most issues before they became totally overloaded by a backlog of thousands of problems. Kicking things off in 50 schools would have identified most of the problems that have subsequently appeared, but in a way that meant they could actually deal to them quickly and without affecting too many people. Not only is that best practice, it&#8217;s also common sense.</p>
<p>As you can probably see, a pattern is emerging here, one that we see constantly repeated in IT. It is a pattern of standard good practice being ignored, budgets being cut and cost or political pressure leading to cutting corners with disastrous effect.</p>
<p>In short, it demonstrates a naively held view that cutting costs in the implementation of IT projects won&#8217;t have the dire consequences that we see time and time again.</p>
<p>Isn&#8217;t it about time we stopped being so foolish? So, how do you prevent your company being the next 6 o&#8217;clock news item on privacy, security or IT failing? It&#8217;s simple really: just resource and do the job properly. Play by the rules, don&#8217;t cut corners, follow established good practice and don&#8217;t be fooled into false economy and believing that saving a few bucks now won&#8217;t cost you a bunch down the line.</p>
<p>The price of doing it right is seldom more than the cost of cutting corners when all is said and done. And as Wheedle, MSD, Novopay and many others have discovered, getting it wrong in IT can come at huge expense to your wallet&#8230; and your reputation.</p>
<p><strong><a href="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg"><img class="alignright size-full wp-image-10147" src="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg" alt="Paul Matthews" width="150" height="202" srcset="https://istart.co.nz/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg 150w, https://istart.co.nz/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg 148w" sizes="(max-width: 150px) 100vw, 150px" /></a>ABOUT PAUL MATTHEWS//</strong></p>
<p>Paul Matthews is chief executive of the Institute of IT Professionals New Zealand<br style="color: #727272;" /><br style="color: #727272;" /><a style="color: #ff9905;" href="http://www.iitp.org.nz">www.iitp.org.nz</a></p>
<p>The post <a rel="nofollow" href="https://istart.co.nz/nz-opinion-article/how-to-avoid-the-it-hall-of-shame/">How to avoid the IT hall of shame</a> appeared first on <a rel="nofollow" href="https://istart.co.nz">iStart leading the way to smarter technology investment.</a>.</p>
]]></content:encoded>
							<wfw:commentRss>https://istart.co.nz/nz-opinion-article/how-to-avoid-the-it-hall-of-shame/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
							</item>
	</channel>
</rss>
