Hanademi

When technology decisions outlive projects · V7

24 slides · 8 min · 2026-08-01 language
ENES
theme
LightDark
view
DeckTableTalk
brand
HanademiPlatzi
When technology decisionsoutlive projectsMade for Freddy Vega, by Hanademi
Cuando las decisionestecnológicas sobreviven a losproyectosMade for Freddy Vega, by Hanademi
Most large IT projects miss the valuepromiseShare of 5,400 large IT projects exceeding budget, schedule, or predicted value expectations.Made for Freddy Vega, by HanademiSources: Bloch, M., Blumberg, S., & Laartz, J. (2012). Delivering large-scale IT projects on time, on budget, and on value.McKinsey & Company.Unitshare of projects56%Value shortfall45%Over budget7%Behind schedule
Large technology projects fail in more than one way. Budget and schedule matter, but the biggest reported miss was value: 56% delivered less than predicted. Decision continuity must therefore preserve the original objective, not only the latest delivery plan.
La mayoría de los grandes proyectos de TIincumple la promesa de valorProporción de 5.400 grandes proyectos de TI que excedieron presupuesto, calendario o expectativas devalor.Made for Freddy Vega, by HanademiFuentes: Bloch, M., Blumberg, S., & Laartz, J. (2012). Delivering large-scale IT projects on time, on budget, and on value.McKinsey & Company.Unidadproporción de proyectos56 %Déficit de valor45 %Sobre presupuesto7 %Con retraso
Los grandes proyectos tecnológicos fallan de más de una forma. El presupuesto y el calendario importan, pero el mayor incumplimiento reportado fue el valor: 56% entregó menos de lo previsto. Por eso la continuidad de decisiones debe conservar el objetivo original, no solo el último plan de entrega.
Three terms carry the argumentMade for Freddy Vega, by HanademiEnterprise ArchitectureThe discipline connecting strategy, operations, data, applications, andtechnology decisions.Decision contextThe reason, evidence, constraints, owner, and consequences behind a choice.Technical debtFuture work created when short-term technical choices make later change harder.
Enterprise Architecture is used here as an organizational discipline. It connects choices across business goals, systems, data, and operations. Decision context explains why those choices exist, while technical debt names part of the cost when that context disappears.
Tres términos sostienen el argumentoMade for Freddy Vega, by HanademiArquitectura EmpresarialLa disciplina que conecta estrategia, operaciones, datos, aplicacionesy decisiones tecnológicas.Contexto de decisiónLa razón, evidencia, restricciones, responsable y consecuencias detrás deuna elección.Deuda técnicaTrabajo futuro creado cuando decisiones técnicas de corto plazo dificultan cambiosposteriores.
Aquí, Arquitectura Empresarial se usa como una disciplina organizacional. Conecta decisiones entre objetivos de negocio, sistemas, datos y operaciones. El contexto explica por qué existen esas decisiones, mientras la deuda técnica nombra parte del costo cuando ese contexto desaparece.
Three frameworks connectdurable records with decisionsand controlled change.The standards serve different purposes, but all treat architecture or configurationinformation as more than a list of assets.Sources: International Organization for Standardization. (2011). ISO/IEC/IEEE 42010:2011 systems and software engineering: Architecturedescription.; Johnson, L. A., Dempsey, K. L., Ross, R. S., Gupta, S., & Bailey, D. (2011). Guide for security-focused configuration management ofinformation systems. NIST Special Publication 800-128.; The Open Group. (2022). The TOGAF Standard, 10th Edition.
An asset inventory is a photograph. A decision record is the history explaining how the organization reached that state. ISO 42010, NIST SP 800-128, and TOGAF each connect records with concerns, decisions, baselines, or controlled change.
Tres marcos conectan registros duraderoscon decisiones y cambio controlado.Los estándares tienen propósitos distintos, pero todos tratan la información dearquitectura o configuración como algo más que una lista de activos.Fuentes: International Organization for Standardization. (2011). ISO/IEC/IEEE 42010:2011 systems and software engineering: Architecturedescription.; Johnson, L. A., Dempsey, K. L., Ross, R. S., Gupta, S., & Bailey, D. (2011). Guide for security-focused configuration management ofinformation systems. NIST Special Publication 800-128.; The Open Group. (2022). The TOGAF Standard, 10th Edition.
Un inventario de activos es una fotografía. Un registro de decisiones es la historia que explica cómo la organización llegó a ese estado. ISO 42010, NIST SP 800-128 y TOGAF conectan registros con preocupaciones, decisiones, líneas base o cambio controlado.
Without institutional context, AI accuracydegraded by 38%.This study comes from Atlan AI Labs and should not be treated as a universalbenchmark.Sources: atlan.com.
AI makes the memory problem visible. Atlan AI Labs reported 38% accuracy degradation when agents lacked institutional context across 522 queries. A repository that preserves assets but loses reasons and constraints leaves both people and machines guessing.
Sources
Sin contexto institucional, la precisión deIA se degradó 38%.Este estudio proviene de Atlan AI Labs y no debe tratarse como un indicador universal.Fuentes: atlan.com.
La IA vuelve visible el problema de la memoria. Atlan AI Labs reportó una degradación de precisión del 38% cuando los agentes carecían de contexto institucional en 522 consultas. Un repositorio que conserva activos pero pierde razones y restricciones obliga a personas y máquinas a adivinar.
Fuentes
One in 6 large IT projects averaged 200%cost overrunsFour reported risk metrics across 1,471 large IT projects, including the catastrophic project group.Made for Freddy Vega, by HanademiSources: Flyvbjerg, B., & Budzier, A. (2011). Why your IT project may be riskier than you think. Harvard Business Review.The categories are different reported risk metrics and should not be added or averaged.Unitreported percentageAverage cost overrun27%Catastrophic projects16.7%Their cost overrun200%Their schedule overrun70%
The average hides a dangerous tail. Across 1,471 large IT projects, average cost overrun was 27%, but one in 6 projects averaged 200%. That group also averaged nearly 70% schedule overrun, so decision continuity helps manage risk but cannot guarantee delivery.
Uno de cada 6 grandes proyectos de TIpromedió 200% de sobrecostoCuatro métricas de riesgo reportadas en 1.471 grandes proyectos de TI, incluido el grupo de proyectoscatastróficos.Made for Freddy Vega, by HanademiFuentes: Flyvbjerg, B., & Budzier, A. (2011). Why your IT project may be riskier than you think. Harvard Business Review.Las categorías son métricas de riesgo distintas y no deben sumarse ni promediarse.Unidadporcentaje reportadoSobrecosto promedio27 %Proyectos catastróficos16,7 %Su sobrecosto200 %Su retraso70 %
El promedio oculta una cola peligrosa. Entre 1.471 grandes proyectos de TI, el sobrecosto promedio fue 27%, pero uno de cada 6 proyectos promedió 200%. Ese grupo también promedió casi 70% de retraso, por lo que la continuidad ayuda a gestionar el riesgo, pero no garantiza la entrega.
The Algorithm reports undocumentedcompliance decisions in 67% of itsassessments.This is a self-reported assessment rate from The Algorithm, not an independentlymeasured market prevalence.Sources: the-algo.com.
Supplier handoffs can lose more than technical detail. The Algorithm reports compliance-relevant architectural decisions missing from 67% of its post-integrator assessments. The figure comes from the assessing organization, but it shows why continuity must cross supplier and project boundaries.
The Algorithm reporta decisiones decumplimiento no documentadas en 67%de sus evaluaciones.Esta es una tasa de evaluaciones reportada por The Algorithm, no una prevalencia demercado medida de forma independiente.Fuentes: the-algo.com.
Las transiciones entre proveedores pueden perder más que detalles técnicos. The Algorithm reporta decisiones arquitectónicas con implicaciones de cumplimiento ausentes en 67% de sus evaluaciones posteriores a integradores. La cifra proviene de la organización evaluadora, pero muestra por qué la continuidad debe cruzar límites de proveedores y proyectos.
Agile evidence supports adaptation, noterased objectivesCounts reported in the study, not causal effect estimatesMade for Freddy Vega, by HanademiSources: Serrador, P., & Pinto, J. K. (2015). Does Agile work? A quantitative analysis of agile project success. International Journal of ProjectManagement.; Does Agile work? - A quantitative analysis of agile project success.1,002Projects surveyed2Success dimensions reported0Causal experiments
Traceability must not freeze scope. The study covered 1,002 projects, reported 2 success dimensions, and included 0 causal experiments. Preserve the objective and the reason for each change while adapting to evidence.
La evidencia ágil respalda adaptación, noobjetivos borradosCantidades reportadas en el estudio, no estimaciones de efectos causalesMade for Freddy Vega, by HanademiFuentes: Serrador, P., & Pinto, J. K. (2015). Does Agile work? A quantitative analysis of agile project success. International Journal of ProjectManagement.; Does Agile work? - A quantitative analysis of agile project success.1.002Proyectos encuestados2Dimensiones de éxito reportadas0Experimentos causales
La trazabilidad no debe congelar el alcance. El estudio cubrió 1.002 proyectos, reportó 2 dimensiones de éxito e incluyó 0 experimentos causales. Conserva el objetivo y la razón de cada cambio mientras te adaptas a la evidencia.
PMI's observational gap links maturity withstronger outcomesReported strategic-objective achievement by benefits-realization maturity, with a 40-point gap between highand low maturity.Made for Freddy Vega, by HanademiSources: Project Management Institute. (2016). The strategic impact of projects: Identify benefits to drive business results.;Establishing Benefits Ownership and Accountability | PMI.Unitobjectives achievedHigh maturity83%Medium maturity62%Low maturity43%
PMI reported a 40-point difference between high and low benefits-realization maturity. The pattern supports testing objectives after deployment rather than treating launch as success. It does not prove maturity caused the gap because leadership, funding, selection, and delivery capability may also matter.
La brecha observacional de PMI vinculamadurez con mejores resultadosCumplimiento reportado de objetivos estratégicos por madurez en realización de beneficios, con una brechade 40 puntos entre madurez alta y baja.Made for Freddy Vega, by HanademiFuentes: Project Management Institute. (2016). The strategic impact of projects: Identify benefits to drive business results.;Establishing Benefits Ownership and Accountability | PMI.Unidadobjetivos cumplidosMadurez alta83 %Madurez media62 %Madurez baja43 %
PMI reportó una diferencia de 40 puntos entre la madurez alta y baja en realización de beneficios. El patrón respalda comprobar objetivos después del despliegue en lugar de tratar el lanzamiento como éxito. No demuestra que la madurez causara la brecha porque también pueden importar liderazgo, financiación, selección y capacidad de entrega.
DORA linked heavy approvals with poorerdeliveryDORA's 2019 survey compared heavyweight external approvals with peer review and automated controls.Made for Freddy Vega, by HanademiSources: Forsgren, N., Smith, D., Humble, J., & Frazelle, J. (2019). Accelerate State of DevOps 2019. Google Cloud.The supplied evidence reports direction, not a numeric effect size.Unitgovernance approach1Peer and automated0External approval
Registration becomes harmful when it turns into bureaucracy. DORA associated heavyweight external approvals with poorer delivery than peer review and automated controls. The goal is authoritative, automated evidence with clear ownership, not paperwork for its own sake.
DORA vinculó las aprobaciones pesadas conpeor entregaLa encuesta DORA de 2019 comparó aprobaciones externas pesadas con revisión entre pares y controlesautomatizados.Made for Freddy Vega, by HanademiFuentes: Forsgren, N., Smith, D., Humble, J., & Frazelle, J. (2019). Accelerate State of DevOps 2019. Google Cloud.La evidencia suministrada reporta dirección, no un tamaño de efecto numérico.Unidadenfoque de gobernanza1Entre pares y automatizada0Aprobación externa
El registro se vuelve dañino cuando se convierte en burocracia. DORA asoció las aprobaciones externas pesadas con peor entrega que la revisión entre pares y los controles automatizados. El objetivo es evidencia autoritativa y automatizada con responsabilidad clara, no papeleo por sí mismo.
DORA's elite teams recovered 2,604x fasterReported performance ratios between elite and low performers in DORA's 2018 survey.Made for Freddy Vega, by HanademiSources: Forsgren, N., Humble, J., Kim, G., Brown, A., & Kersten, N. (2018). Accelerate State of DevOps 2018. Google Cloud.Unitperformance multipleDeployment frequency46Recovery speed2,604Lower failure rate7
Operational control and delivery speed are not natural enemies. DORA's elite performers reported 46 times more deployments, 2,604 times faster recovery, and a sevenfold lower change-failure rate. Readiness should be built into delivery rather than added as a slow external gate.
Los equipos élite de DORA se recuperaron2.604 veces más rápidoProporciones de desempeño reportadas entre equipos élite y de bajo rendimiento en la encuesta DORA de2018.Made for Freddy Vega, by HanademiFuentes: Forsgren, N., Humble, J., Kim, G., Brown, A., & Kersten, N. (2018). Accelerate State of DevOps 2018. Google Cloud.Unidadmúltiplo de desempeñoFrecuencia de despliegue46Velocidad de recuperación2.604Menor tasa de fallos7
El control operativo y la velocidad de entrega no son enemigos naturales. Los equipos élite de DORA reportaron 46 veces más despliegues, recuperación 2.604 veces más rápida y una tasa de fallos siete veces menor. La preparación debe integrarse en la entrega en lugar de añadirse como una aprobación externa lenta.
Uptime's survey estimate points toprocedures, not just peopleReported human-error outage prevalence and contributing causes in Uptime Institute's 2023 analysis.Made for Freddy Vega, by HanademiSources: Uptime Institute. (2023). Annual outage analysis 2023.The first value concerns organizations; the final two divide reported human-error causes.Unitreported share85%Process contribution40%Organizations affected15%Other causes
Operational acceptance is more than transferring software. Uptime Institute reported that nearly 40% of organizations had a major human-error outage. Among those causes, 85% involved ignored procedures or deficient processes, making operational knowledge part of the solution.
La estimación de Uptime señalaprocedimientos, no solo personasPrevalencia reportada de interrupciones por error humano y causas contribuyentes en el análisis de UptimeInstitute de 2023.Made for Freddy Vega, by HanademiFuentes: Uptime Institute. (2023). Annual outage analysis 2023.El primer valor corresponde a organizaciones; los dos últimos dividen las causas reportadas de error humano.Unidadproporción reportada85 %Contribución de procesos40 %Organizaciones afectadas15 %Otras causas
La aceptación operativa es más que transferir software. Uptime Institute reportó que casi 40% de las organizaciones sufrió una interrupción grave por error humano. Entre esas causas, 85% involucró procedimientos ignorados o procesos deficientes, lo que convierte el conocimiento operativo en parte de la solución.
Authoritative registers are becomingoperating infrastructureDated land, waste, and public-asset registration programs from Rwanda, Scotland, and Jeonnam Gwangju.Made for Freddy Vega, by HanademiSources: un.org.; legislation.gov.uk.; asiae.co.kr.Unitcalendar20092013Jul 20, 20262009–2013Rwanda land registration2026Scotland waste systemJul 20, 2026Jeonnam asset system
Authoritative registration is moving from recordkeeping into operating infrastructure. Rwanda registered 11 million parcels from 2009 to 2013, Scotland established one mandatory digital waste-record system in 2026, and Jeonnam Gwangju scheduled its map-based asset system for July 20, 2026. The common lesson is persistent identity, ownership, and lifecycle history.
Los registros autoritativos se convierten eninfraestructura operativaProgramas fechados de registro de tierras, residuos y activos públicos de Ruanda, Escocia y JeonnamGwangju.Made for Freddy Vega, by HanademiFuentes: un.org.; legislation.gov.uk.; asiae.co.kr.Unidadcalendario20092013Jul 20, 20262009–2013Registro de tierras de Ruanda2026Sistema de residuos deEscociaJul 20, 2026Sistema de activos deJeonnam
El registro autoritativo pasa del archivo a la infraestructura operativa. Ruanda registró 11 millones de parcelas entre 2009 y 2013, Escocia estableció un sistema digital obligatorio de residuos en 2026 y Jeonnam Gwangju programó su sistema cartográfico de activos para el 20 de julio de 2026. La lección común es identidad persistente, responsabilidad e historial del ciclo de vida.
Haryana reports paperless propertyregistration completed within 48 hours.The claim comes from an announcement article and should be treated as a reportedimplementation example, not an independently audited service benchmark.Sources: outlookindia.com.
Authoritative registration does not have to mean slow paperwork. Haryana reports a paperless, blockchain-secured property registry that completes registration within 48 hours and integrates it with mutation. The example shows how persistent records can become part of the transaction itself.
Haryana reporta un registro inmobiliariosin papel completado en 48 horas.La afirmación proviene de un artículo de anuncio y debe tratarse como un ejemplo deimplementación reportado, no como un indicador de servicio auditado de formaindependiente.Fuentes: outlookindia.com.
El registro autoritativo no tiene que significar papeleo lento. Haryana reporta un registro inmobiliario sin papel y protegido con blockchain que completa el trámite en 48 horas y lo integra con la mutación catastral. El ejemplo muestra cómo los registros persistentes pueden formar parte de la transacción.
High-risk flaws reached 74% of auditedcodebasesShare of 2023 audited codebases containing open source, any vulnerability, or a high-risk vulnerability.Made for Freddy Vega, by HanademiSources: Synopsys. (2024). Open Source Security and Risk Analysis Report.Unitshare of audited codebasesContains open source96%Any vulnerability84%High-risk vulnerability74%
Shared software makes dependency risk a portfolio problem. Synopsys found open source in 96% of audited codebases and vulnerabilities in 84%. High-risk vulnerabilities appeared in 74%, making ownership and consumer traceability essential.
Los fallos de alto riesgo llegaron al 74% delos códigos auditadosProporción de códigos auditados de 2023 con código abierto, alguna vulnerabilidad o una vulnerabilidad dealto riesgo.Made for Freddy Vega, by HanademiFuentes: Synopsys. (2024). Open Source Security and Risk Analysis Report.Unidadproporción de códigos auditadosContiene código abierto96 %Alguna vulnerabilidad84 %Vulnerabilidad de alto riesgo74 %
El software compartido convierte el riesgo de dependencias en un problema de portafolio. Synopsys encontró código abierto en 96% de los códigos auditados y vulnerabilidades en 84%. Las vulnerabilidades de alto riesgo aparecieron en 74%, lo que vuelve esenciales la responsabilidad y la trazabilidad de consumidores.
A compromised update reached18,000 customers, but confirmedimpact was narrower.The exposed customer count and confirmed follow-on cases have different scopes andshould not be combined into one conversion rate.Sources: U.S. Government Accountability Office. (2022). Cybersecurity: Federal response to SolarWinds and Microsoft Exchange incidents.GAO-22-104746.; Smith, B. (2021). SolarWinds: The next chapter. Microsoft On the Issues.
SolarWinds shows why exposure and impact need separate records. The compromised update reached about 18,000 customers. Confirmed follow-on compromise affected roughly 100 companies and nine US agencies, so architecture must trace potential consumers and verified harm separately.
Una actualización comprometida llegó a18.000 clientes, pero el impactoconfirmado fue menor.El número de clientes expuestos y los casos posteriores confirmados tienen alcancesdistintos y no deben combinarse en una sola tasa de conversión.Fuentes: U.S. Government Accountability Office. (2022). Cybersecurity: Federal response to SolarWinds and Microsoft Exchange incidents.GAO-22-104746.; Smith, B. (2021). SolarWinds: The next chapter. Microsoft On the Issues.
SolarWinds muestra por qué la exposición y el impacto necesitan registros separados. La actualización comprometida llegó a unos 18.000 clientes. El compromiso posterior confirmado afectó aproximadamente a 100 empresas y nueve agencias estadounidenses, por lo que la arquitectura debe rastrear por separado consumidores potenciales y daños verificados.
Salt's survey estimate separates APIproblems from breachesShare of Salt Security respondents reporting API security problems, increasing attacks, or an API-relatedbreach in 2023.Made for Freddy Vega, by HanademiSources: Salt Security. (2023). State of API Security Report, Q1 2023.Unitshare of respondents94%Security problems48%Increasing attacks17%API-related breach
Shared APIs create both reuse and shared exposure. Salt Security reported problems across 94% of respondents and increasing attacks across 48%, while 17% reported an API-related breach. Ownership, versions, contracts, consumers, and security status therefore need persistent records.
La estimación de Salt separa problemas deAPI y brechasProporción de participantes de Salt Security que reportaron problemas de seguridad de API, ataquescrecientes o una brecha relacionada con API en 2023.Made for Freddy Vega, by HanademiFuentes: Salt Security. (2023). State of API Security Report, Q1 2023.Unidadproporción de participantes94 %Problemas de seguridad48 %Ataques crecientes17 %Brecha relacionada
Las API compartidas crean reutilización y exposición común. Salt Security reportó problemas en 94% de los participantes y ataques crecientes en 48%, mientras 17% reportó una brecha relacionada con API. Por eso propiedad, versiones, contratos, consumidores y estado de seguridad necesitan registros persistentes.
Technical debt alone reached an estimated$1.52 trillionCISQ estimates for US operational failures, technical debt, and unsuccessful development in 2022, USDtrillions.Made for Freddy Vega, by HanademiSources: Krasner, H. (2022). The cost of poor software quality in the US: A 2022 report. Consortium for Information & Software Quality.UnitUSD trillionsOperational failures$1.8Technical debt$1.5Failed development$0.3
The downstream cost of poor software quality is enormous in CISQ's model. It estimated $1.81 trillion from operational failures, $1.52 trillion in technical debt, and $260 billion from unsuccessful development in 2022. These national estimates show scale, but they do not measure the cost of one organization's missing records.
La deuda técnica sola alcanzó un estimadode $1,52 billonesEstimaciones de CISQ para fallos operativos, deuda técnica y desarrollo fallido en Estados Unidos durante2022, billones de USD.Made for Freddy Vega, by HanademiFuentes: Krasner, H. (2022). The cost of poor software quality in the US: A 2022 report. Consortium for Information & SoftwareQuality.Unidadbillones de USDFallos operativos$1,8Deuda técnica$1,5Desarrollo fallido$0,3
El costo posterior de la mala calidad del software es enorme en el modelo de CISQ. Estimó $1,81 billones por fallos operativos, $1,52 billones en deuda técnica y $260.000 millones por desarrollo fallido en 2022. Estas estimaciones nacionales muestran escala, pero no miden el costo de los registros faltantes en una organización específica.
In summaryMade for Freddy Vega, by HanademiSources: U.S. Government Accountability Office. (2022). Cybersecurity: Federal response to SolarWinds and Microsoft Exchange incidents. GAO-22-104746.; Krasner, H. (2022). The cost of poorsoftware quality in the US: A 2022 report. Consortium for Information & Software Quality.; Forsgren, N., Humble, J., Kim, G., Brown, A., & Kersten, N. (2018). Accelerate State of DevOps 2018. GoogleCloud.; un.org.; Synopsys. (2024). Open Source Security and Risk Analysis Report.; Flyvbjerg, B., & Budzier, A. (2011). Why your IT project may be riskier than you think. Harvard Business Review.SolarWinds distributed a compromised update to about 18,000 customers, while confirmed follow-on compromiseaffected roughly 100 companies and nine US agencies.CISQ estimated 2022 US costs of $1.81 trillion from operational software failures, $1.52 trillion in technical debt, and$260 billion from unsuccessful development.DORA's 2018 elite performers reported 46 times more frequent deployment, 2,604 times faster recovery, and seventimes lower change-failure rates than low performers.Rwanda registered 11 million parcels across 26,000 km² from 2009–2013; its National Land Authority case studyreports an 80% return over 16 years.Synopsys found open-source components in 96% of 2023 audited codebases, vulnerabilities in 84%, and high-risk vulnerabilities in 74%.Among 1,471 large IT projects, average cost overrun was 27%; one in six projects averaged 200% overrun and nearly 70% schedule overrun.
The value of the research is not only what each source knew, but what became visible when their evidence was combined.
En resumenMade for Freddy Vega, by HanademiFuentes: U.S. Government Accountability Office. (2022). Cybersecurity: Federal response to SolarWinds and Microsoft Exchange incidents. GAO-22-104746.; Krasner, H. (2022). The cost of poorsoftware quality in the US: A 2022 report. Consortium for Information & Software Quality.; Forsgren, N., Humble, J., Kim, G., Brown, A., & Kersten, N. (2018). Accelerate State of DevOps 2018. GoogleCloud.; un.org.; Synopsys. (2024). Open Source Security and Risk Analysis Report.; Flyvbjerg, B., & Budzier, A. (2011). Why your IT project may be riskier than you think. Harvard Business Review.SolarWinds distribuyó una actualización comprometida a unos 18.000 clientes, mientras el compromiso posteriorconfirmado afectó aproximadamente a 100 empresas y nueve agencias estadounidenses.CISQ estimó costos estadounidenses de 2022 de 1,81 billones de dólares por fallos operativos, 1,52 billones en deudatécnica y 260.000 millones por desarrollo fallido.Los equipos élite de DORA en 2018 reportaron despliegues 46 veces más frecuentes, recuperación 2.604 veces másrápida y tasas de fallo siete veces menores.Ruanda registró 11 millones de parcelas en 26.000 km² entre 2009 y 2013; el estudio de su Autoridad Nacional deTierras reporta un retorno del 80% en 16 años.Synopsys encontró componentes de código abierto en 96% de los códigos auditados de 2023, vulnerabilidades en 84% yvulnerabilidades de alto riesgo en 74%.Entre 1.471 grandes proyectos de TI, el sobrecosto promedio fue 27%; uno de cada seis promedió 200% de sobrecosto y casi 70% de retraso.
El valor de la investigación no está solo en cada fuente, sino en lo que apareció al combinar sus evidencias.
Existing-system burdens outweighednew-development comparators by 4x to 7xMade for Freddy Vega, by HanademiSources: U.S. Government Accountability Office. (2016). Information technology: Federal agencies need to address aging legacy systems. GAO-16-468.; U.S.Government Accountability Office. (2018). Information technology: Agencies need to involve chief information officers in reviewing billions of dollars inacquisitions. GAO-18-42.; GAO-16-696 Accessible Version, INFORMATION TECHNOLOGY: Federal Agencies Need to Address Aging Legacy Systems.Unitratio within each reported cost structureFederal IT operationsversus remaining spendingOperational failuresversus unsuccessful developmentTechnical debtversus unsuccessful development4.0x7.0x5.8x0x2x4x6x8x
Federal operations and maintenance was four times the remaining IT budget. In the CISQ model, operational failures and technical debt were respectively 7.0 and 5.8 times unsuccessful-development cost.
Las cargas de sistemas existentes superaron suscomparadores de nuevo desarrollo entre 4 y 7 vecesMade for Freddy Vega, by HanademiFuentes: U.S. Government Accountability Office. (2016). Information technology: Federal agencies need to address aging legacy systems. GAO-16-468.; U.S.Government Accountability Office. (2018). Information technology: Agencies need to involve chief information officers in reviewing billions of dollars inacquisitions. GAO-18-42.; GAO-16-696 Accessible Version, INFORMATION TECHNOLOGY: Federal Agencies Need to Address Aging Legacy Systems.Unidadrazón dentro de cada estructura de costos reportadaOperación federal de TIfrente al gasto restanteFallas operativasfrente al desarrollo fallidoDeuda técnicafrente al desarrollo fallido4,0x7,0x5,8x0x2x4x6x8x
La operación y el mantenimiento federal equivalían a cuatro veces el presupuesto restante de TI. En el modelo de CISQ, las fallas operativas y la deuda técnica equivalían respectivamente a 7,0 y 5,8 veces el costo del desarrollo fallido.
The published overrun statistics require anegative residualMade for Freddy Vega, by HanademiSources: Flyvbjerg, B., & Budzier, A. (2011). Why your IT project may be riskier than you think. HarvardBusiness Review.; Why Your IT Project May Be Riskier than You Think.Unitcontribution to mean cost overrun, percentage pointsReported overall meanWeighted black-swan shareRequired residual from others27.0 points33.4 points-6.4 points-10010203040Contribution to mean cost overrun
The black-swan group would contribute 33.4 points by itself, forcing the other 83.3% of projects to contribute negative 6.4 points. The rounded figures cannot be treated as components of one weighted distribution.
Las estadísticas publicadas de sobrecostosrequieren un residuo negativoMade for Freddy Vega, by HanademiFuentes: Flyvbjerg, B., & Budzier, A. (2011). Why your IT project may be riskier than you think. Harvard BusinessReview.; Why Your IT Project May Be Riskier than You Think.Unidadcontribución al sobrecosto medio, puntos porcentualesMedia general reportadaAporte ponderado extremoResiduo requerido del resto27,0 puntos33,4 puntos-6,4 puntos-10010203040Contribución al sobrecosto medio
El grupo de casos extremos aportaría por sí solo 33,4 puntos, lo que obligaría al otro 83,3% de los proyectos a aportar 6,4 puntos negativos. Las cifras redondeadas no pueden tratarse como componentes de una misma distribución ponderada.
Disconnected applications grew 21% from2021 to 2024Apply each annual integration share to the reported application estate, then subtract the integrated countfrom the total estate.Made for Freddy Vega, by HanademiSources: MuleSoft. (2021-2024). Connectivity Benchmark Reports.; Are you still wondering why Service Design is importantfor your company? | Daniel Teixeira Santos.; MuleSoft Connectivity Report announcement - Salesforce.Unitestimated applications02004006002021202220232024IntegratedapplicationsDisconnectedapplications
The estimated disconnected estate increased from 599 to 723 applications. Its share remained near three quarters because integrated applications grew more slowly than the overall estate.
Las aplicaciones desconectadas crecieron21% entre 2021 y 2024Se aplica la proporción anual de integración al inventario de aplicaciones reportado y luego se resta lacantidad integrada del inventario total.Made for Freddy Vega, by HanademiFuentes: MuleSoft. (2021-2024). Connectivity Benchmark Reports.; Are you still wondering why Service Design is importantfor your company? | Daniel Teixeira Santos.; MuleSoft Connectivity Report announcement - Salesforce.Unidadaplicaciones estimadas02004006002021202220232024AplicacionesintegradasAplicacionesdesconectadas
El inventario desconectado estimado aumentó de 599 a 723 aplicaciones. Su proporción permaneció cerca de tres cuartas partes porque las aplicaciones integradas crecieron más lentamente que el inventario total.
Password attack volume outpacedcredential-breach incidence by at least 8.6xIndex each measure to its 2021 value, then divide the 2023 password-attack index of at least 691 by thecredential-breach index of 80.Made for Freddy Vega, by HanademiSources: Microsoft. (2021-2023). Microsoft Digital Defense Report.; Vasu Jakkal's Post - LinkedIn.; Verizon.(2021-2023). Data Breach Investigations Report.Unitindex, 2021 equals 1000200400600202120222023Passwordattacks persecondBreachesinvolving stolencredentials
Password attacks rose from 579 to more than 4,000 per second while the breach share involving stolen credentials slipped from 61% to 49%. Threat volume and realized breach composition did not move together.
El volumen de ataques de contraseña superó al pesode credenciales en brechas por al menos 8,6 vecesSe indexa cada medida respecto de su valor de 2021 y luego se divide el índice de ataques de contraseña deal menos 691 en 2023 por el índice de brechas con credenciales de 80.Made for Freddy Vega, by HanademiFuentes: Microsoft. (2021-2023). Microsoft Digital Defense Report.; Vasu Jakkal's Post - LinkedIn.; Verizon.(2021-2023). Data Breach Investigations Report.Unidadíndice, 2021 igual a 1000200400600202120222023Ataques decontraseñapor segundoBrechas concredencialesrobadas
Los ataques de contraseña aumentaron de 579 a más de 4.000 por segundo mientras la proporción de brechas con credenciales robadas bajó de 61% a 49%. El volumen de amenazas y la composición de las brechas materializadas no evolucionaron juntos.
Poor-data effects touched an estimated1,330 survey respondentsApply the reported 95% negative-effect rate and 29% inaccurate-customer-data rate to the approximately1,400 respondents.Made for Freddy Vega, by HanademiSources: Experian. (2017). The 2017 global data management benchmark report.; The 2017 global data managementbenchmark report.Unitestimated respondentsSurvey respondents1,400Experienced negative effects1,330Suspected inaccurate customer data406
The benchmark implies about 1,330 respondents experienced negative effects and about 406 suspected inaccurate customer data. The first estimate is more than three times the second.
Los efectos de datos deficientes alcanzarona unos 1.330 encuestadosSe aplican la tasa reportada de efectos negativos de 95% y la tasa de datos inexactos de clientes de 29% a losaproximadamente 1.400 encuestados.Made for Freddy Vega, by HanademiFuentes: Experian. (2017). The 2017 global data management benchmark report.; The 2017 global data managementbenchmark report.Unidadencuestados estimadosEncuestados1.400Experimentaron efectos negativos1.330Sospecharon datos inexactos de clientes406
El estudio implica que unos 1.330 encuestados experimentaron efectos negativos y unos 406 sospechaban que los datos de clientes eran inexactos. La primera estimación supera en más de tres veces a la segunda.
Declared data-driven status stayed ahead ofestablished culture after 2021Subtract the established-data-culture share from the data-driven-organization share for each year.Made for Freddy Vega, by HanademiSources: NewVantage Partners. (2021-2023). Data and AI Leadership Executive Survey.; Can analytics make acompany better? The answer isn't as easy as you think.Unitshare of organizations, percent18202225202120222023Data-drivenorganizationEstablisheddata culture
The gap moved from zero in 2021 to 7.2 points in 2022 and 3.3 points in 2023. Organizations claimed the outcome more often than they reported the culture needed to sustain it.
La condición declarada de organización basada endatos superó a la cultura establecida después de 2021Se resta la proporción con cultura de datos establecida de la proporción de organizaciones basadas en datosen cada año.Made for Freddy Vega, by HanademiFuentes: NewVantage Partners. (2021-2023). Data and AI Leadership Executive Survey.; Can analytics make acompany better? The answer isn't as easy as you think.Unidadproporción de organizaciones, porcentaje18202225202120222023Organizaciónbasada en datosCultura de datosestablecida
La brecha pasó de cero en 2021 a 7,2 puntos en 2022 y 3,3 puntos en 2023. Las organizaciones declararon el resultado con mayor frecuencia que la cultura necesaria para sostenerlo.

The research behind this deck

Completing revised work does not prove the promised outcome arrived. This is organizational memory, not building design.

Key findings

The argument

This research is published in English and Spanish. Ver en español

La investigación detrás de esta presentación

Terminar el trabajo revisado no demuestra que llegó el resultado prometido. Esto trata de memoria organizacional, no de diseño de edificios.

Hallazgos clave

El argumento

Esta investigación se publica en inglés y español. Read in English