Visualização normal

Hoje — 10 de Setembro de 2026Stream principal
  • ✇Security | CIO
  • IT consulting has a big AI problem
    AI adoption is shaking up the big IT consulting market, with some IT leaders starting to question the need for the multi-year transformation engagements that have been large advisory firms’ bread and butter. Organizations are increasingly using AI tools to assist with large digital transformation projects such as cloud modernization and mainframe migrations, with the AI cutting the time and effort needed to achieve the goal. At the same time, the speed of evolution in t
     

IT consulting has a big AI problem

10 de Setembro de 2026, 07:01

AI adoption is shaking up the big IT consulting market, with some IT leaders starting to question the need for the multi-year transformation engagements that have been large advisory firms’ bread and butter.

Organizations are increasingly using AI tools to assist with large digital transformation projects such as cloud modernization and mainframe migrations, with the AI cutting the time and effort needed to achieve the goal. At the same time, the speed of evolution in the AI space has led some IT leaders to question the value of two- or three-year engagements.

Some observers have suggested advancements in AI will devastate the large IT consulting model, and McKinsey, Deloitte, Ernst & Young, and KPMG have all announced layoffs in recent months. Others suggest big IT advisory firms are here to stay, although they may need to adjust their business models to change with the times.

Representatives from Deloitte, EY, and Accenture didn’t respond, or declined to respond, to questions about the impact of AI on their businesses. But Edwin Miranda, founder of AI consulting firm konsultora, doesn’t think his larger competitors are going away anytime soon.

“I don’t think the large consulting firms simply disappear,” he says. “They still have enormous advantages in industry expertise, global delivery, complex integration, procurement, regulation, and the ability to operate inside very large organizations. What AI is attacking is the traditional operating model behind the engagement.”

In the past, a large IT consulting project would involve weeks or months of research, analysis, documentation, with large implementation teams doing the work, he notes. The cost of a large IT transformation came from the human labor required to move information from one stage of the engagement to the next.

“AI compresses a lot of that work,” he says. “Research that took weeks can happen in hours. Large document sets can be analyzed before the first meeting. Software can be prototyped while the operating model is still being discussed.”

In addition, AI agents can assist with development, testing, documentation, and coordination, and small senior teams can now produce a level of output that previously required a much larger pyramid, he notes.

“That doesn’t eliminate consulting; it changes what the client should be willing to pay for,” Miranda adds. “The value moves away from the volume of people assigned to an engagement and toward judgment, architecture, implementation, governance, and measurable business outcomes.”

The heart of the value proposition

Some observers see a dimmer outlook for the IT consulting industry. As AI adoption builds, the technology is eroding the core value proposition of big consulting firms, says Paul DeMott, CTO at digital marketing agency Helium SEO.

“Clients are running their own data analysis using off‑the‑shelf AI tools, so it is valid for them to ask why they should pay premium rates for work they can now do internally,” he adds. “AI commoditizes exactly what consultants charge a premium for, which is synthesizing data and translating insights into recommendations.”

With some big firms laying off staff, the traditional model of throwing junior consultants at problems seems to be breaking down, he says.

“Think about it, if AI can do the grunt work faster and cheaper, what exactly are those junior staff doing?” DeMott says.

DeMott sees some potential clients moving toward smaller, more specialized providers and others changing how they use large firms.

“Clients are not necessarily abandoning them outright, but they are pushing back on scope, duration, and cost,” he says. “The large firms still have relationships and brand equity, but those advantages are getting thinner by the quarter.”

Multi-year transformation on the ropes

In addition, big consulting firms are changing the way they hire because of AI, notes Brad Belzak, founder of AI-native advisory firm Acuity Global Partners. Until about two years ago, some generalist IT skills, a data engineering background, decent soft skills, or some trend analysis awareness would be enough to get a job at the large consultancies, he says.

“Frontier models ended that almost overnight,” adds Belzak, a former consulting employee at both Deloitte and EY. “First AI, then agentic AI, then highly trained specialized models absorbed the work that generalists with light coding skills used to do.”

Recruiters at the big consulting firms now want what he calls deployable talent, he says: engineers and analysts with product development histories who know how to read and manipulate data to solve client problems.

“Coding matters less than it did,” he adds. “The premium is on people who can take messy data, structure it, and turn it into an answer. The pyramid of generalists underneath them is gone.”

IT leaders at client companies, meanwhile, are demanding shorter, more modular engagements, Belzak says. Ninety-day sprints are becoming more common.

“The multi-year transformation made sense when the technology underneath it moved slowly,” he adds. “That world is gone. If your roadmap takes three years, the tools you scoped in month one are obsolete by month 18.”

IT leaders hiring consultants should focus on outcomes instead of headcount, he suggests.

“You’re not buying people anymore; you’re buying results,” he says. “That five-year contract might now be a six-month contract, and if the short-term outcomes generate wins, it gets extended.”

Consulting firms can still fill IT staffing needs, but their time on site may be shorter, he says. “Think embedded, on-demand engineers and analysts who come in, solve the problem, and move on, whether you’re a startup or a mature company,” he adds.

Accelerant and expertise

Aelin Golsarry, founder and CIO AAG Technology Consulting, doesn’t believe AI will kill large consulting firms, but it will make some of their services more difficult to justify. Still, AI can’t do all the work involved in large digital transformations, she says.

“AI should make a lot of the work required to get through a transformation faster, but it doesn’t make the transformation itself happen faster,” she adds. “People still have to make decisions, change processes, implement technology, and actually adopt it. AI doesn’t make any of that disappear.”

Golsarry, who as a CIO hired large consulting firms in the past, advises IT leaders to think clearly about what they’re buying when engaging with consultants.

“They should ask, ‘Do I need 30 consultants, or do I need three people who have seen this problem before and know how to fix it?’” she says. “I’d be looking at the expertise of the people actually doing the work, what outcome I’m paying for, and whether the firm’s use of AI is making the engagement faster and more efficient for me or simply making the engagement more profitable for them.”

Consulting isn’t going away, Golsarry adds. “Companies will always need expertise they don’t have internally,” she says. “What I think is going away is the assumption that more people, more hours, and a longer engagement somehow means you’re getting more value.”

Antes de ontemStream principal
  • ✇Security | CIO
  • A spreadsheet is not a strategy
    Picture the meeting. A slide goes up, a number goes down and somewhere in the room, someone claps. The line item is a renegotiated managed services contract, a hardware order trimmed to “just enough,” or a headcount freeze that quietly became a headcount decrease. Whatever it is, it looks great in the deck. The CFO nods. The COO nods harder. Everyone agrees this was smart. Three months later, something breaks — an incident nobody can escalate fast enough, a part that
     

A spreadsheet is not a strategy

27 de Agosto de 2026, 08:00

Picture the meeting. A slide goes up, a number goes down and somewhere in the room, someone claps.

The line item is a renegotiated managed services contract, a hardware order trimmed to “just enough,” or a headcount freeze that quietly became a headcount decrease. Whatever it is, it looks great in the deck. The CFO nods. The COO nods harder. Everyone agrees this was smart.

Three months later, something breaks — an incident nobody can escalate fast enough, a part that doesn’t arrive in time, a senior engineer who finally takes that recruiter’s call. Nobody connects it back to the slide. The slide was right. The spreadsheet said so.

This is the part where I’d like to gently suggest that a lot of very smart people are managing to the cell instead of managing to the outcome — with total confidence, because the cell is the only thing anyone asked them to optimize.

To be clear, this isn’t a jab at the leaders doing it. I’ve done it. I have a Six Sigma certification and a well-worn habit of measuring things, and measuring things is good — right up until the measurement becomes the mission. The problem was never the spreadsheet. It’s mistaking it for a map.

Outsourcing: The invoice goes down, and so does everything you can’t put a price on

I’ve watched this failure mode play out more times than I can count. Across nearly three decades in infrastructure — as chief technology architect at GE Medical Systems (now GE Healthcare), integrating roughly 300 acquired companies into a 420-location footprint — the pattern held: The moment a relationship with the people who actually knew a system got treated as a line item instead of an asset, the organization lost something the spreadsheet never had a row for.

Vendor and MSP contracts are the cleanest modern example: Savings are easy to show, losses are easy to miss. You cut the line item. What doesn’t show up anywhere is the on-call engineer who used to just know — the environment, the history, the thing that broke in 2019 — replaced by a support queue and an SLA that’s met on paper while your business is down in practice.

None of this is the vendor’s fault — they’re delivering exactly what the contract asked for. CIO.com’s own reporting on the hidden costs of outsourcing makes the same point from the other side: Ineffective knowledge transfer and high vendor-side attrition can permanently erode institutional knowledge the client never gets back. The contract took away flexibility. The person who used to just fix it — the one who wore six hats and closed the gap on a Tuesday afternoon — gets replaced by a role with a scope of work. Scopes of work don’t wear hats. A five-minute favor becomes a change request, routed through a ticketing system, against a rate card. You didn’t just outsource a function. You outsourced your ability to handle it — and bought back a slower, costlier version of the same fix, one billable hour at a time.

JIT procurement: A factory formula applied to a business that isn’t a factory

Just-in-time assumes something that doesn’t exist: A crystal ball good enough to see today’s need and whatever shows up next. I learned that the hard way at GE Medical Systems, when a new customer opening a facility wanted several hundred patient-critical bedside monitors customized to match a color scheme from their marketing department. Our processes were built entirely around clinical function — the thing that keeps a patient alive — and nothing accounted for a hospital wanting its equipment to match its brand. It came in from left field. We had no SKU for “must match burgundy.”

We ended up standing up a new department — Specials — because the existing process had nowhere to put a request like that. Building the flexibility after the fact was expensive. But it became a real differentiator: As far as I know, we became the first and only medical device manufacturer with a dedicated specials department. It told customers something that mattered more than paint color: They came first, and we’d find a way to say yes.

The lesson wasn’t “predict better.” It was “build systems with teeth” — flexibility designed in, not bolted on after reality shows up sideways. Dell and HP figured this out decades ago: You can order a PC built to your exact spec and have it shipped in days, because their systems were engineered for change. Most IT organizations still build for demand they can already see, then treat every surprise as an exception instead of the job itself.

This wasn’t a one-off: Supply chain analysts at SupplyChainBrain noted that during the 2021 chip shortage, many manufacturers found their lean JIT models weren’t built to flex under real disruption. “Just in time” only works until the time arrives and the thing isn’t there.

Headroom is savings, too — paid out in advance instead of on the back end, which is why it never gets credit. Nobody puts “the department we didn’t need to build in a panic” on a savings slide, because avoided cost doesn’t announce itself the way cut cost does. The expense of headroom is visible and immediate; the expense of its absence is invisible until it isn’t. It’s an incident report.

The hour that reads as free

I lived a version of this at GE Medical Systems. We built life-critical patient care products in a market crowded with giants — Philips, Siemens, HP — where nothing shipped until it cleared FDA review. On one release, scope crept weekly because sales kept promising new capability to close deals, and no one above us would draw a line around what “done” meant. What we got instead of a defined scope was a war room: Catering, a fridge stocked with Mountain Dew, enough M&Ms to open a candy counter — everything money could buy to keep engineers at their desks around the clock, except the one thing that would have actually helped: Someone willing to tell sales no.

We hit the deadline. The product cleared FDA review. When it shipped, there was no “great work,” no pat on the back — just the quiet message that this was expected of us. We won on the software. We failed on the people. That’s sunk-cost thinking in its purest form: Once a team’s extraordinary effort becomes the baseline, the extraordinary disappears the same way the ordinary already had.

Salaried time reads the same way on every spreadsheet I’ve seen since: Already paid for, so effectively free. Nothing stops it from being spent — on the meeting that could’ve been an email, on the ticket queue treated as bottomless, on “just have IT handle it” as the default answer. Burnout doesn’t have a line item either, until it shows up as attrition, and attrition finally does, at which point everyone acts surprised. It’s not small: Gallup estimates disengaged employees cost the global economy trillions a year — roughly 9% of global GDP, sitting outside any single department’s budget. The spreadsheet didn’t lie to you. It just never had a cell for the thing that mattered most.

The ledger nobody built

Zoom out from these three stories and the pattern is the same: Reporting structure decides which questions get asked. When technology reports through a CFO or a COO, the question every quarter is “what did this cost us today?” Almost never “what did this cost us to keep?” An organization that only asks the first will keep hiring smart people to answer it well — in exactly the wrong direction, forever.

None of these leaders are bad at arithmetic. Most are excellent at it. The tragedy isn’t the math — it’s the ledger: Precise, defensible calculations against books never built to hold the costs that matter most, and calling it leadership. I’ve seen this enough times to give it a name: The leader who runs a technology organization strictly by the numbers handed to them, gets good at it and never gets fired for it — not because they succeeded, but because the failure never had a cell to live in. The spreadsheet balanced. The building didn’t burn down that quarter. They got promoted.

That’s the actual scandal, worth saying to the room and not just the page: A CIO who has never once been wrong on a savings initiative hasn’t been managing technology. They’ve been managing a spreadsheet, and calling the absence of visible damage “success.”

Before the next savings initiative gets a round of applause, three questions worth asking honestly, out loud, in front of people:

  1. What does this cost that will never appear on an invoice — and am I certain, or just unbothered?
  2. Who inherits that cost, and will I still be in this seat when the bill comes due?
  3. If I can’t put a number on it, have I decided it’s zero — and whose job was it to notice first?

The savings will still show up in the deck. If nothing else shows up beside it, that isn’t restraint — it’s the tell.

  • ✇Security | CIO
  • IBM partners with OpenAI to drive enterprise AI deployment
    IBM will embed OpenAI frontier models and products such as Codex and ChatGPT embedded into IBM’s AI consulting services platform, IBM Consulting Advantage, as well as expanding the companies’ existing collaboration in the cybersecurity realm, they announced Thursday. Joint initiatives will include the creation of industry-specific products for financial services, government, telecommunications, and retail, as well as serving key enterprise domains such as finance, procu
     

IBM partners with OpenAI to drive enterprise AI deployment

14 de Agosto de 2026, 08:38

IBM will embed OpenAI frontier models and products such as Codex and ChatGPT embedded into IBM’s AI consulting services platform, IBM Consulting Advantage, as well as expanding the companies’ existing collaboration in the cybersecurity realm, they announced Thursday.

Joint initiatives will include the creation of industry-specific products for financial services, government, telecommunications, and retail, as well as serving key enterprise domains such as finance, procurement, customer operations, and HR.

IBM will join the OpenAI Partner Network and engage forward-deployed engineers and consultants trained through the network to help clients accelerate their AI implementations. It will also create a dedicated OpenAI practice, certifying thousands of consultants and engineers via the Partner Network, it said.

There will be three focus areas in the new partnership: helping organizations transform their businesses to integrate AI into their daily work, assisting clients in modernizing legacy applications through a combination of OpenAI products and IBM’s expertise, and an expansion of an existing cybersecurity collaboration combining OpenAI frontier AI capabilities with IBM Autonomous Security.

Everyone, it seems, is engaging forward-deployed engineers to help enterprises build systems around their AI models: OpenAI announced its initiative, OpenAI Deployment Company, on May 11, a week after Anthropic launched its efforts. Microsoft and AWS too have jumped into the ring.

But, said Info-Tech Research Group distinguished analyst Mark Tauschek, “This is becoming table stakes. The consulting firms that have the horsepower and technical talent to partner with a frontier AI lab to do this are all picking their horses. Anthropic has some, Microsoft has some, and of course OpenAI has some. There will be more announcements like this to follow, and while it’s good PR for both IBM and OpenAI, it’s certainly not differentiating.”

Enterprises will choose the consulting firms that work with their AI vendor of choice, he noted, although he does think that Microsoft had the initial advantage because they were able to quickly provide thousands of skilled FDEs.

“But,” he said, “this is a horse race, and it’s going to be a tight one.”

Capita fined £14m for data protection failings in 2023 cyber-attack

Hackers stole personal information of 6.6m people but outsourcing firm did not shut device targeted for 58 hours

The outsourcing company Capita has been fined £14m for data protection failings after hackers stole the personal information of 6.6 million people, including staff details and those of its clients’ customers.

John Edwards, the UK information commissioner who levied the fine, said the March 2023 data theft from the group and companies it supported, including 325 pension providers, caused anxiety and stress for those affected.

Continue reading...

© Photograph: Dado Ruvić/Reuters

© Photograph: Dado Ruvić/Reuters

© Photograph: Dado Ruvić/Reuters

  • ✇Arstechnica
  • After $380M hack, Clorox sues its “service desk” vendor for simply giving out passwords Nate Anderson
    Hacking is hard. Well, sometimes. Other times, you just call up a company's IT service desk and pretend to be an employee who needs a password reset, an Okta multifactor authentication reset, and a Microsoft multifactor authentication reset... and it's done. Without even verifying your identity. So you use that information to log in to the target network and discover a more trusted user who works in IT security. You call the IT service desk back, acting like you are now this second person, and y
     

After $380M hack, Clorox sues its “service desk” vendor for simply giving out passwords

23 de Julho de 2025, 16:46

Hacking is hard. Well, sometimes.

Other times, you just call up a company's IT service desk and pretend to be an employee who needs a password reset, an Okta multifactor authentication reset, and a Microsoft multifactor authentication reset... and it's done. Without even verifying your identity.

So you use that information to log in to the target network and discover a more trusted user who works in IT security. You call the IT service desk back, acting like you are now this second person, and you request the same thing: a password reset, an Okta multifactor authentication reset, and a Microsoft multifactor authentication reset. Again, the desk provides it, no identity verification needed.

Read full article

Comments

❌
❌