Our Thinking
Better outcomes start upstream
Technology performance, cost, capability and security are not isolated outcomes. They are consequences of how the organisation works.
Sequoia starts with the organisation: how it is structured, how decisions are made, where ownership sits, what behaviours are rewarded, and how technology capabilities actually operate. Understand those conditions and many apparently unrelated problems begin to make considerably more sense.
Technology has a profound benchmarking problem
Executives develop an intuitive sense for performance across most areas of the business. They know when costs look wrong, when a process is inefficient, when a team isn't performing or when an investment isn't producing an adequate return.
Technology is different.
How does a CEO know whether an infrastructure change really takes six weeks? How does a CFO know whether 300 service-desk tickets a week is reasonable? How much should a mature technology function cost? And does nothing happening actually mean the organisation is secure?
Without an independent frame of reference, poor performance can easily become accepted as normal.
The irony is that executives already possess many of the skills needed to challenge it. Ownership, accountability, incentives, governance, organisational design and performance are executive disciplines — not technical ones.
The system produces the outcomes
Organisations get very good at producing the outcomes their structures, incentives and operating models encourage.
Poor ownership creates ambiguity. Poor incentives encourage local optimisation. Weak engineering creates defects and operational work. Complexity creates cost. Fragmented accountability creates friction.
Over time, organisations often respond by building more capability to manage the consequences: more operations, more support, more security, more process and more technology.
The better question is often not how do we manage this problem more effectively?
It is why does this problem need to exist at all?
Follow the problem upstream
The starting point doesn't really matter.
It might be excessive technology cost. A project that takes too long. High employee turnover. An overwhelmed team. An outage. A security vulnerability. A cumbersome process. Or a technology investment that never seems to produce the expected return.
Follow the thread far enough and apparently unrelated problems frequently begin to converge around a much smaller number of organisational conditions.
That's why we don't treat every visible problem as something requiring its own solution. Sometimes the greatest opportunity lies much further upstream.
Technology should increase organisational capability
Technology isn't simply infrastructure the business needs to operate. Used exceptionally well, it can be one of its greatest competitive advantages.
A healthy technology organisation reduces friction, automates unnecessary work, accelerates decision-making and delivery, increases the capacity of existing teams and makes new business capabilities possible.
That changes the question from “How much does IT cost?” to “What is our investment in technology enabling the organisation to achieve?”
Two companies can both have technology that “works”. The one that exploits it more effectively can still operate faster, at lower cost and with capabilities the other simply cannot match.
Security is a consequence
Most security issues don't spontaneously appear. They are introduced.
Poor engineering. Misconfiguration. Excessive complexity. Weak ownership. Inconsistent processes. Technical debt. Poorly designed operating models.
Cybersecurity has become exceptionally good at detecting, managing and mitigating those problems after they exist. Far less attention is given to changing the conditions that keep creating them.
Healthier organisations don't simply become better at managing security problems.
They create fewer of them in the first place.
Security is also a canary
That makes security unusually useful.
A vulnerability may tell us something about engineering. An access problem may reveal weak ownership. A recurring configuration issue may expose fragmented accountability. An incident may reveal complexity that is creating cost and friction elsewhere too.
Security problems can therefore be indicators of much broader organisational health.
Instead of asking only “How do we fix this security issue?”, we can ask:
“What does the existence of this issue tell us about the organisation that created it?”
And that can lead to opportunities considerably more valuable than the security problem we started with.
Healthy organisations compound advantage
Better ownership improves decision-making. Better engineering improves quality and delivery. Better quality reduces operational effort and cost. Lower cost creates investment capacity. Better technology creates business capability. And fewer defects produce better security outcomes.
These improvements reinforce one another.
Healthy organisations don't optimise individual outcomes. They improve the system that produces them.
That's ultimately how Sequoia thinks about organisational health, technology and security — not as separate disciplines to optimise independently, but as interconnected parts of a healthier, more capable and more competitive business.
Explore the thinking
These ideas are explored in greater depth in I Call Bullshit — Why organisational health beats cybersecurity every single time, and in our ongoing Board's Eye View series for executive leaders.
I Call Bullshit →
The Board's Eye View →
Sequoia Consulting and Advisory Ltd, Company Number 15406222, registered at 2nd floor, College House, 17 King Edwards Rd, Ruislip, London, UK, HA4 7AE, under the laws of England and Wales. Click here for our privacy policy.
