Showing posts with label monolith. Show all posts
Showing posts with label monolith. Show all posts

Daily Tech Digest - October 11, 2026


Quote for the day:

“Leadership is the art of getting someone else to do something you want done because he wants to do it.” -- Dwight D. Eisenhower

🎧 Listen to the audio debrief on YouTube

▶ Play Audio Digest

Duration: 24 mins • Perfect for listening on the go.


Resilience is an evidence problem

According to Mathieu Rigotto in Resilience Forward, organizations must fundamentally change how they approach security, moving away from outdated patch by severity models to strategies driven by actual evidence. With malicious actors now exploiting vulnerabilities within days or even before patches are released, traditional security methods are no longer fast or effective enough to protect systems. Consequently, major authorities and new regulations like the European Union's NIS2 and Cyber Resilience Act demand that organizations actively prove their resilience rather than simply listing the controls they have in place. This requires a shift toward identifying whether system vulnerabilities are genuinely exposed and actively exploited. As a result, the role of a Chief Information Security Officer is evolving from being the solitary owner of security to acting as the provider of concrete evidence. Furthermore, company boards can no longer delegate risk acceptance entirely; they must define clear tolerances for operational disruption and take full ownership of critical decisions. To adapt successfully, businesses need to assign clear human ownership to digital assets to prevent costly delays in fixing issues. Ultimately, resilience is not just a final destination or a compliance box to check. It remains an ongoing claim backed by constant proof and regular testing.


Palo Alto reports legacy OT systems, fragmented security tools undermine critical infrastructure cyber resilience

Palo Alto Networks’ recent State of Critical Infrastructure Cybersecurity report reveals that 60% of critical infrastructure organizations experienced a major security breach in the past year, with half facing physical safety consequences. Surveying over 1,600 security leaders globally, the findings underscore that fragmented security tools and outdated operational technology (OT) leave dangerous visibility gaps. Specifically, 68% of organizations lack complete, real-time visibility into all their OT assets, while a reliance on legacy, unpatchable systems is seen as the greatest single security risk. Using an average of seven disparate security tools creates costly operational complexity and slows down incident response times. While threat actors are rapidly utilizing artificial intelligence to exploit vulnerabilities at machine speed, defense capabilities are lagging. A vast majority of leaders worry about advanced AI-powered attacks, yet technical constraints hold back widespread AI adoption for defense. Additionally, IT and OT security operations remain disconnected for 74% of organizations, largely due to incompatible technology and conflicting priorities. To build true cyber resilience and bridge the growing gap between attackers and defenders, organizations must prioritize unified visibility, integrate their IT and OT workflows, and streamline their security toolsets to minimize blind spots and automate responses effectively.


How CIOs can climb out of the AI governance chasm

According to a recent report from InformationWeek, chief information officers (CIOs) are facing an increasingly urgent challenge: establishing robust AI governance to keep pace with rapid employee adoption. An overwhelming 84% of surveyed CIOs indicated that internal teams are building AI applications faster than their IT departments can effectively oversee them. This governance gap threatens not only the quality and security of enterprise products but also the potential business value these tools offer, especially as most organizations currently lack comprehensive controls. A major concern for IT leadership is managing AI-related costs. Without clear visibility into workloads or centralized repositories for tools, enterprises risk redundant efforts and spiraling expenses. Data quality further complicates the landscape, as AI tools that pull from outdated or inaccurate information can easily produce "hallucinations" or flawed code. Additionally, "shadow AI"—where employees deploy unapproved or untested AI agents—presents significant security and data leakage risks. To combat these issues, leaders emphasize the need for cross-enterprise collaboration and straightforward governance policies that employees can easily understand and follow. Addressing these operational, financial, and security challenges promptly is critical, as a substantial portion of CIOs feel their job security hinges on demonstrating measurable AI success in the near future.


Cybersecurity in the age of AI and smart factories 

As India aims to become a leading advanced manufacturing hub by 2035, the integration of artificial intelligence and smart technologies into factories is drastically altering the cybersecurity landscape. Hitesh Shah, Vice President and Senior Partner at Kyndryl India, explains that while AI boosts factory productivity through anomaly detection and faster incident responses, it also equips attackers with sophisticated, automated tools. A major challenge for modern smart factories is the merging of Information Technology (IT) and Operational Technology (OT). Because production systems now actively exchange data with enterprise applications and cloud platforms, a simple breach on an office laptop can escalate into a critical production shutdown or the manipulation of AI models. To combat this, manufacturers must treat IT and OT security as an integrated challenge rather than separate programs. They need complete visibility into all connected assets, legacy machinery, and new AI tools to safely segment networks and manage access. By building security directly into their digital design and cloud migration plans from the start, factories can achieve true cyber-physical resilience. Ultimately, securing these environments ensures that the intelligence driving smart manufacturing remains reliable and capable of supporting continuous, uninterrupted production.


Control over the cloud is only possible with the right management layer

As organizations navigate rising hardware costs and stringent data sovereignty requirements, the technology trend is clearly shifting from relying solely on public clouds to adopting robust on-premises solutions. Ambitious artificial intelligence projects may begin in the public cloud, but protecting critical customer information in compliance with strict privacy regulations often requires bringing essential workloads back in-house. A dedicated on-premises infrastructure can drastically reduce the total cost of ownership while keeping sensitive data completely secure and avoiding the growing risks of unauthorized shadow computing. However, simply purchasing new hardware is not enough to solve modern infrastructure challenges. To truly maintain control over increasingly complex digital environments, businesses need a highly unified management layer. A smart hybrid strategy, such as the strategic collaboration between Dell Technologies and Nutanix, allows companies to blend public and private clouds seamlessly. By integrating compute and storage under a single, centralized management interface, organizations can easily oversee all their infrastructure without relying on separate specialists for every individual platform. This unified approach eliminates isolated data silos, improves security through careful microsegmentation, and allows for strict cost controls on resource-heavy deployments. Ultimately, achieving true digital sovereignty depends entirely on simplifying management across diverse cloud environments to ensure reliable, long-term operational flexibility.


The Distributed Monolith Trap: How Microservices Become What They Replace

Many organizations adopt microservices to escape the slow updates and massive codebases of traditional software design. Unfortunately, without strict discipline, they often fall into the trap of building a distributed monolith. This happens when an application is split into separate pieces but remains tightly connected, combining the limitations of older designs with the added network instability of distributed systems. The article outlines five primary warning signs of this problem: needing to update multiple services at the exact same time, allowing different services to share a single database, experiencing cascading system failures from long chains of blocked requests, relying on circular dependencies, and forcing services to share common code libraries. To fix these core issues and achieve true service independence, development teams need a clear refactoring strategy. The most important step is ensuring every service has its own dedicated database, preventing one team’s changes from unexpectedly breaking another’s work. Additionally, teams should replace blocked communication with asynchronous event messaging, swap shared code for clear communication contracts, and use protective routing tools to stop isolated failures from spreading. By firmly enforcing these boundaries, software engineering teams can successfully untangle their connected systems and build a genuinely resilient architecture that operates smoothly at scale.


Quantum Computing’s Transistor Moment

A recent breakthrough in quantum computing suggests the industry may be experiencing its own “transistor moment.” Researchers in Germany successfully demonstrated a three-qubit Grover search algorithm using a room-temperature diamond quantum processor. According to Professor Marius Grundmann, this achievement mirrors the historical shift in classical computing from bulky, fragile vacuum tubes to scalable semiconductor transistors. Just as the transistor revolutionized electronics by allowing for miniaturization and mass manufacturing, this solid-state quantum processor operates at ambient temperatures without the need for the massive, power-hungry cryogenic refrigerators and vacuum chambers required by current leading quantum technologies like trapped-ion or superconducting systems. While existing vacuum-dependent methods still hold an edge in raw fidelity, the diamond processor achieved impressive success rates and fidelity scores using carbon-shielded nuclear spins as qubits. Crucially, fabrication techniques for these nitrogen-vacancy centers have reached a high yield, pointing toward reliable scalability. If room-temperature, solid-state quantum computing continues to improve along a semiconductor-like curve, it could drastically expand the technology's applications into mobile devices and vehicles. Conversely, this shift poses a significant threat to the billions of dollars currently invested in complex, environment-dependent quantum systems, which risk becoming obsolete as more practical, scalable alternatives mature.


Cyber Incident Preparedness: How Companies Can Respond to Modern Threats and Build Business Resilience

The article explains how companies can strengthen their preparedness for modern cyber incidents, emphasizing that today’s attacks unfold faster, hit harder, and create far‑reaching business consequences. It stresses that a cyber incident is never just an IT problem; it immediately involves legal teams, communications, compliance, operations, insurers, regulators, and sometimes law enforcement. The authors note that attackers now use organized business models, including ransomware‑as‑a‑service and AI‑enabled intrusion techniques, which accelerate data theft and extortion. Because of this, companies must prepare well before an incident occurs by identifying decision‑makers, retaining outside experts, documenting notification obligations, and conducting realistic tabletop exercises. The article highlights that restoring systems is only the beginning. True recovery includes managing regulatory inquiries, contractual duties, customer notifications, insurance claims, litigation, and long‑term reputational impact. Vendor risk is another major concern, as attackers increasingly target widely used providers to reach many downstream customers. Boards are encouraged to view cyber risk through three lenses: cybersecurity strategy, data strategy, and business strategy. The authors conclude that genuine preparedness requires coordinated plans, trained personnel, backup leaders, and repeated testing. The real measure of resilience is whether a company can make sound decisions under pressure and continue operating while managing the long tail of a breach.


I Chose a Monolith Over Microservices — Here’s Why

In the article, software engineer Ashwini T explains his pragmatic decision to choose a modular monolith architecture over microservices for a new product, countering the common assumption that microservices are inherently superior. He argues that microservices solve specific scaling and organizational problems, but for a small team with a developing product, adopting them prematurely introduces unnecessary distributed-system complexities, such as network latency, partial failures, and complex transaction management. Instead of building a "big ball of mud," Ashwini advocates for a strictly organized modular monolith, where separate domains—like users, orders, and payments—have clearly defined boundaries and communicate through public interfaces rather than direct database sharing. This setup provides the simplicity needed to ship quickly and learn while making it easier to adjust boundaries as the domain becomes better understood. He points out that wrongly defining boundaries in a monolith just requires refactoring, whereas fixing them in a microservices setup is a massive migration project. Ashwini maintains that architecture should earn its complexity; a monolith can scale quite far, and if specific components eventually demand independent scaling or dedicated teams, a well-structured monolith makes a gradual transition to microservices much simpler.


Management of change for OT security: running visibility and remediation through MoC

In operational technology (OT) environments, security programs frequently fail because they bypass the Management of Change (MoC) process—the core governance workflow that operations teams trust to evaluate and approve modifications without disrupting physical processes. According to SC Media, treating MoC as a hurdle rather than an access control layer for physical infrastructure often leads to unauthorized actions that cause equipment damage, production loss, or safety hazards. Even seemingly benign activities like read-only network queries or passive scanning can trigger controller failures, particularly on legacy serial or fieldbus networks that lack the bandwidth of modern industrial Ethernet. To maintain stability and safety, every security action—including configuration collection, patching, network isolation, and access control changes—must run through the MoC framework. This process relies on a joint authority model where security proposes the change, while engineering, operations, and safety teams evaluate its physical and operational impact before approval. Notably, during a security incident, standard IT practices like immediate system isolation can be dangerous in an OT setting; containment must be assessed for process impact, ideally using pre-approved emergency MoC templates. Ultimately, aligning security with MoC ensures that risk mitigation does not inadvertently become the source of operational disruption.