THE WIRE
SECURE-24 / NTT ACQUISITION COMPLETED · APRIL 2018SAP MIGRATION FACTORY ON AWS · ANNOUNCED JUNE 2020

ENTERPRISE / THE OPERATORS

Secure-24 and the Trouble With a Fast Report

When a business report finishes suspiciously quickly, someone may open a support ticket. Secure-24 built a business around the machinery behind such moments - and NTT bought the company to help run enterprise applications worldwide.

A support ticket usually means something has gone wrong. At Secure-24, a customer could open one because a report had run so quickly that the result seemed doubtful. The company’s CIO, Scott McIsaac, described that peculiar response in a storage case study. Users had become accustomed to waiting. Remove the wait, and suspicion rushes into the vacancy.

The useful version
  • Secure-24 operated the enterprise applications businesses could ill afford to lose.
  • Its distinctive work combined application expertise with repeatable infrastructure and security processes.
  • NTT completed its acquisition in 2018. The Secure-24 brand’s public profile now points to NTT.

There is a small lesson here for anyone buying enterprise technology: familiar inconvenience can masquerade as normality. A slow report becomes the time to get coffee. An awkward maintenance window becomes a calendar ritual. Eventually the workaround looks like part of the product. Secure-24 made its living in the space between what enterprise software promised and what people needed it to do on an ordinary working day.

The cloud still has a basement

Secure-24’s territory was managed IT operations, application hosting and cloud services. Think of the systems that record orders, run financial processes and support enterprise planning. Its portfolio included SAP and Oracle software, alongside Microsoft, Epic and other business-critical applications. This was a business selling the expertise to operate software that customers already depended upon.

The customer list described by NTT spanned manufacturing, finance, pharmaceuticals, healthcare, insurance, government and transportation. Such organizations have different needs, but a shared objection to discovering that nobody owns the awkward problem between the application, database and infrastructure. Renting computing capacity does not settle that objection. Someone must understand the whole arrangement well enough to investigate it.

Secure-24 occupied that specialist layer of the market. Its alternative might be a large managed services provider, or a customer’s own operations team. The useful comparison is the scope of responsibility: which applications are supported, who handles changes, what recovery means, and how an incident moves from detection to a decision. A handsome cloud diagram supplies very few of those answers.

First the customer had to stop waiting

Kraton Performance Polymers provides a concrete example. Its infrastructure manager, Randy Rucker, initially questioned the cost and workload suitability of flash storage. Then SAP Business Warehouse slowed down and users complained. He returned to the discussion, considered other customers’ results and tested the technology. In one data-import task, Kraton reported a fivefold improvement. The persuasion came from an application people used, rather than an abstract promise about hardware.

That distinction matters when assessing the company’s differentiation. In this historical example, the provider was updating the equipment beneath an existing customer’s applications. The customer did not have to become a storage specialist to benefit. The reported improvement is specific to that task and environment; it supplies a useful question for another buyer, rather than a universal forecast.

A narrower, better question
01Application
Does the business task work?
02Operations
Who maintains and investigates it?
03Infrastructure
What runs underneath?
Buy from the top down. A server specification cannot answer an application question.

An assembly line, with exceptions

The operational story is less photogenic than a new data center, and more revealing. Secure-24 used Puppet to manage thousands of Linux servers. Configuration automation let the team define a desired state and enforce it repeatedly, instead of relying on individual administrators to make and remember changes.

“It’s the assembly line”Sean Millichamp, Engineering Architect

Growing complexity pushed the company from Open Source Puppet to Puppet Enterprise. Testing, stability, access controls and visibility helped justify the switch. Customer-specific security settings could be enforced and changes recorded. The trick was to repeat the process while preserving necessary differences between customers. Automation that forgets those differences merely makes the wrong decision more efficiently.

A buyer can copy the discipline without copying the provider: write down the intended configuration, establish who can change it, and retain a record of what happened. The advantage disappears if nobody agrees on the intended state. Before discussing the clever machinery, agree on the instruction it is supposed to follow.

Interview participant in Secure-24’s office, from a Red Hat customer video
The cloud gets an office. A frame from Red Hat’s Secure-24 customer video, where enterprise Linux meets everyday working life.

Red Hat’s customer video places another piece in the picture: Enterprise Linux, JBoss Middleware and Satellite. Secure-24 worked through technology partnerships to operate customer environments. Its expertise lay partly in assembling and maintaining those components, a profession whose successes can be remarkably difficult to photograph.

The invoice hiding inside the architecture

Hardware is only one part of the cost. Oracle’s 2015 case study described Secure-24 using Private Cloud Appliance to simplify deployment and support. It reported a 90% reduction in deployment costs and one customer’s annual licensing savings of $150,000. Those figures describe particular historical circumstances, not the price of a Secure-24 contract.

90%Reported reduction in deployment costs in Oracle’s 2015 case study.Deployment costs only. Historical company claim; not total customer IT savings.

The licensing mechanism mattered: eligible configurations could be licensed against used capacity rather than the entire system. That makes architecture a commercial decision as well as a technical one. The lesson is to price the software rules alongside the machines. Change the licensing eligibility or workload requirements, and the arithmetic changes with them.

Managed services also move work between organizations. A customer pays for agreed operations and expertise; the provider takes on staffing, tooling and infrastructure responsibilities within that scope. Evaluating the deal means comparing those obligations with the cost and capability of doing them internally. An attractive monthly figure is incomplete until the recovery, security and application boundaries are written down.

Speed needs a paper trail

Security supplied a second test of repeatability. Secure-24’s investigative team adopted IBM’s Resilient platform, now described as Security SOAR, and QRadar. Investigators helped create adaptable workflows; mock investigations informed the tool evaluation. The objective included evidence for audits and possible legal proceedings, alongside faster response.

“some of our steps have gone from hours to minutes”Brian Herr, Chief Security and Privacy Officer, in IBM’s case study

The wording is usefully precise. Some steps became faster. It does not claim every incident was resolved in minutes. A workflow still needs trained investigators and a meaningful record of decisions. The copyable habit is to rehearse the investigation before a real incident, then examine both the time taken and the evidence produced.

Service delivery had its own infrastructure. In 2014, ServiceNow announced that Secure-24 was using its platform as a shared system of record for managing and automating services. A common record makes the handoff between people visible. Without one, an organization can accumulate plenty of tools and still conduct its most important business through someone’s recollection.

Michigan expertise, a larger address book

Matthias Horch and Volker Straub founded Secure-24 in 2001. In September 2012, a Pamlico Capital-led group, including HarbourVest Partners, invested growth equity. The founders retained significant ownership, and Michael Jennings joined the management team. The transaction terms were undisclosed.

NTT agreed to acquire the company in November 2017 and announced completion on April 20, 2018. Its rationale connected Secure-24’s managed application expertise with NTT’s cloud, network and data-center services. The acquisition announcement listed approximately 600 employees and offices in Southfield and Hyderabad. Those are snapshots of the company at the transaction, rather than a present-day census.

How the scope widened
  1. 2012 Growth-equity investment
  2. 2018 NTT acquisition completed
  3. 2019 Symmetry acquisition agreement
  4. 2020 AWS SAP Migration Factory announced

In June 2019, Secure-24 announced an agreement to acquire Symmetry, another SAP specialist. In June 2020, it announced an AWS SAP Migration Factory: practices, processes and tools intended to make migration more repeatable. Migration joined the same operational idea that had shaped server management: understand the recurring work well enough to stop reinventing it.

The people required attention too. NTT highlighted Secure-24’s in-house engineering academy. Computerworld’s 2018 reporting described flexible schedules, unlimited vacation and a weekly meditation program. These historical details suggest a company investing in technical staff as well as technical systems. Neither training nor a benefits list proves service quality, but software does not acquire expertise by sitting in a rack.

Today, Secure-24’s LinkedIn page directs readers to NTT’s Global Managed Services division. Its history remains useful to anyone deciding what to outsource. Begin with the application, name the responsible people, examine the licensing, and rehearse the bad day. Then ask what a good day should look like. Occasionally it looks like a report arriving before the coffee.