Today, almost every IT organization uses public cloud, as the businesses require the flexibility and scalability of cloud services to respond to the rapidly shifting and unpredictable economic conditions. Cloud technology allows organizations and individuals to easily access computer programs and other information remotely.
There is a huge difference between digitization and digitalization. However, both the terms are interconnected. Digitalization is transformative. It changes how companies interact with their customers and their revenue streams. But when we talk about digitization, it means turning physical data into digital data.
Sandeep Sengupta, CISA, Certified Ethical Hacker, Lead Auditor
The security and risk management leaders are handling the recovery and renewal phases from the past two years and they must consider forward-looking strategic planning assumptions when allocating resources and selecting products and prioritizing services and initiatives. Let’s see what the industry leaders think about it.
As many companies are keeping their data on cloud, at home, at premises and in personal devices, they are struggling to keep the data secured and meet compliance. Sandeep Sengupta, CISA, Certified Ethical Hacker, Lead Auditor said that they help companies keep their digital infrastructure secure as vCISO (virtual CISO).
Meanwhile, Sanjay Kumar Das, WBCS (Executive) State Information Security Officer, West Bengal & Joint Secretary, Dept. of Information Technology & Electronics, Government of West Bengal, describes digital future as a broad term having wide connotation. As the world went from going digital to being digital in the pandemic, it is unclear whether a new existence will arise in the future beyond the realms of digital. He said, “With metaverse bringing the progressive reality into the grasp of common mass, the infrastructure in every organisation would be geared up for technology laden, reality dominated and UX (user experience) verified service-delivery.” He also acknowledges the work of the West Bengal Govt for investing greatly in emerging technology, supported by implementable policies and development of a start-up centric ecosystem.
For Arindam Singha Roy, CIO, Information Technology at Adda Group, digital future preparation is not an easy task as a decade old company. He emphasizes on developing digital capabilities in all the activities, people, culture, and structure, which are in sync and aligned toward a set of organizational goals. He quotes, “We adopted digital technology that has transformed processes, talent engagement, and business models which are integrating with digital strategy with the company’s overall strategy. With the aid of technologies like data analytics, AI & automation, cloud we started our digital transformation.”
Starting their digital transformation journey from 2017 with a 5-year plan, Bibhas Sen Choudhuri, DGM IT at Ambuja Neotia Healthcare Venture states that the company has measured and prioritised the functional requirement where it requires the transformation and gradually implemented the same. Keeping the transformation journey on hold for the financial year 2021-2022, the company fulfilled some sudden requirements at the time of COVID-19. He says, “Now, in current financial terms again we are on track to our digital transformation journey. Upgradation of our major applications from on premises to cloud or on SAS, Next Gen Firewall, Central Backup, Mobile App, all applications are converted to web based and others. These are some initiatives which we have completed.”
Talking about the organisation’s cloud implementation strategy, Sandeep Sengupta, CISA, Certified Ethical Hacker, Lead Auditor, says, “Our data is mostly on cloud, be it accounting, email, drives, collaboration, etc.” He also says that every organisation uses the cloud infrastructure for easy access and easy backup.
On the other hand, Arindam Singha Roy states that the process starts with designing a cloud strategy that optimizes the business outcomes, including speed, resilience and agility embraced with distributed cloud to enable hybrid cloud architectures. He further explaines the process and adds, “Grow public cloud skills internally and consider creative recruiting strategies to bridge the talent gap. Then not all applications and services can be moved to the public cloud. Mission-critical applications ought to stay on-premises .Where some are maintained on-premises on a private cloud, some need to be abandoned as they are no more valuable.”
Whereas, Sanjay Kumar Das quotes, “The State Govt of West Bengal has its State Data Centre (WB-SDC) which is Tier-III compliant and presently hosting all critical citizen-centric applications. The WB-SDC boasts of a hybrid cloud with end-to-end virtualisation. It is under continuous augmentation by upgrading its resources and platforms. The Kubernetes powered WB-SDC is capable of scaling on-the-fly. Edge data centres are in the process of being set up at various corners of the State ensuring on-boarding public applications en masse ensuring latency-less citizen services covering the last mile.”
With most of its current infrastructure being hosted in cloud, Sen Choudhuri says, “There are few more application like HR & Payroll, IVF Clinic solution which are running on premises at present but we have a plan to move these application in cloud in this financial year or latest by 1st quarter of next financial year.”
Talking about their post pandemic strategy, as a vCISO, Sandeep Sengupta says that they help companies to keep the data safe, satisfy multiple compliance (as per industry), and dispose of data when needed.
Arindam Singha Roy explains 5 points on which the organisation’s security and risk management leaders are working, for constructing a successful digital risk program:
1. On-boarding digital-savvy personnel with fluency in the language of both risk and the business, operating within an agile culture that values innovation and experimentation.
2. Risk will partner with external providers , fraud detection, regulatory reporting, and many other activities. Respondents plan to use industry utilities to deal with regulatory burdens.
3. Sophisticated risk models (for instance, those built on machine-learning algorithms) can find complex patterns (such as sets of transactions indicative of invoice fraud) and make more accurate predictions of default and other risk events.
4. The risk infrastructure evolves to support several other building blocks: innovative data storage solutions, new interfaces, easier access to the vendor ecosystem.
5. Enhanced data governance and operating models to improve the quality of the data, make risk and business decisions more consistent, and ensure responsiveness to risk’s data.
Sanjay Kumar Das considers choosing a harmonious balance between Ease of Use and Security as a conscious choice on the part of the service-provider. Explaining this further, he says, “Both these are two-sides of the same coin. Until the coin is kept standing on its round-belly third face, and that too with adequate stability, rights of the users will remain compromised. Therefore, the State Govt of West Bengal has put in place Cyber Assurance Programme to ensure 360-degree whereby all public ICT infrastructures are continuously assessed for both Infrastructure Security (ISA) and Web-Application Security (WASA). Besides, internal upskilling by mandatorily training internal developers, coders and scripters in Secure Coding Practices have ensured the number of vulnerabilities are brought down drastically and increase in cyber-assurance quotient is evident.” Talking on the same point, Sen Choudhuri says, “We have started the journey and preparing ourselves for proper ISMS (Information Security Management System), Network audit and to achieve the certification ISO-27001:2013 by 2nd Quarter of 2023.”
Talking about the reason being recognized as a digitally transformed organization, Sandeep Sengupta says, “In this chaotic world of digital insecurity, we help organisations to maintain sanity, while they focus on their core business and grow.”
Arindam Singha Roy says thinks that currently the company is digitally transformed and tech-driven. “We change our operating paradigm, from being manpower-intensive to being technology-centric. From people following processes and supported by technology, to technology following processes and supervised by people. Innovative technologies which is ensuring innovative methods of decision–making, a better quality of life, and much more.”
According to Sanjay Kumar Das, Digital Transformation depends on human resources rather than on infrastructure. He elaborates, “Tools in the hands of fools lead to catastrophe. Therefore, an organisation where human resources are geared up to accept change, adapt to technology refresh and ever-ready to practice cyber-hygiene truly create a digitally transformed organisation.” Stating transformation as a continuous process, he further says, “The State Govt of West Bengal has been relentlessly making every stakeholder aware and upskill over a spectrum encompassing kids to students to homemakers to professionals to employees to law enforcers to administrators to counsellors to peoples’ representatives. This has ensured that even the marginal farmer receiving a benefit in his account is aware of the basic safeguards to safekeep his hard-earnings. The State as a community is fast approaching a digital existence where security is synonymous with efficacy of service-delivery.” With a vision of adopting new technology to provide better and quality services towards the patients and doctors, Sen Choudhuri says, “As stated above we have started our transformation journey in the year 2017, many things already been done and still the journey going on. Smart ICU, IoT Device Integration, RPA, Feedback automation, ISO certification, IT enabled out-reach clinics are the major projects we are presently working on.”
At last, talking about his organization’s overall digitalization journey, Saurabh Gupta, Group Chief Digital & Information Officer, INOX Towers focuses on: upgrading Backend system which becomes a bottleneck in the Digital Transformation, relooking the Legacy Processes with a FRESH mind, we look forward for a LEAN process and making IT processes agile for faster adoption of technology.
He further comments, “In today’s world, we cannot limit the cloud strategy to one service provider but has to diversify the IT infrastructure in a Hybrid Model (SAAS, Multi Cloud & On-prem). It is important to have a strong Cyber Resillience program in place and have the leadership team trained on managing cyber crisis.”

