Jump to content

Recommended Posts

Posted

I’d be grateful for any pointers as to what arrangements schools expect cloud MIS suppliers to have in place to ensure that should the supplier (or the contracted hosting party) go into administration, the data and processes would continue to be available immediately.

 

I’m not expecting Capita to go under but I am expecting to have to provide assurances that should it happen, schools’ data and processes would be safe at least until a new supplier can be selected and the data moved.

 

In the perpetual licence on premise world, customers are not immediately affected if their supplier suddenly ceases to operate; the processes and data remain accessible. In the cloud world I have yet to find an established safety net should the unthinkable occur? Whilst I would expect the appointed administrators to try to keep the business going until a buyer could be found, that isn’t something that is contractually binding.

 

I have discussed this matter now with many people including some major contributors to this forum; I haven’t found anyone that has a neat solution.

Posted

What it really needs is some kind of oversight agency setting up that works like ATOL for example.

 

All providers pay a small amount to this agency, in the event a company goes under the agency steps in keeps things going until the issues are solved.

 

That's the only thing I can think of to enable the kind of guarantee mentioned above.

 

I know holidays and airlines are a very different beast than cloud stuff but that's my thoughts on it anyway

  • Thanks 1
Posted
I’d be grateful for any pointers as to what arrangements schools expect cloud MIS suppliers to have in place to ensure that should the supplier (or the contracted hosting party) go into administration, the data and processes would continue to be available immediately.

 

"Cloud" as in designed from the ground up to run on something like Amazon Web Services, or "cloud" as in same MIS system as you'd run locally, just hosted remotly? In the first case, I'd hope the system in question would have some kind of data export option, letting me download all my data any time I wanted, probably once a day, and in some kind of standardised format that I could put in to a different MIS if I had to. I can't think of any data format that lets me do this. In the second case I hope that I can get a daily backup of the remote virtual machine downloaded locally, ready to run if needed. This seems to rather defeat the point of having it remotly hosted in the first place, though.

 

Ideally, "cloud" for a school would conceptually mean something like Amazon Web Services, but with a couple of locally-hosted black boxes that magically cache and run the cloud services you use locally, increasing local performance and providing a local instance of your data in case of remote issues. As far as I can see, this doesn't happen with standard, plain Windows-based servers, although it is possibly what Microsoft's Azure platform has facilities for.

Posted
"Cloud" as in designed from the ground up to run on something like Amazon Web Services, or "cloud" as in same MIS system as you'd run locally, just hosted remotly?

 

I suspect that regardless of how the back end is provided, Phil is talking about a hosted "MIS-As-A-Service" style system where you're not running your own MIS server on a cloud provider but you're paying a MIS provider to host your data on their system. And in that case it's actually a good point. If hypothetical example cloud services, LTD run out of money and go fizzy-pop-bang then there's a possibility the servers will be turned off with little to no warning, let alone further discussion.

 

If the server hosting your data is in the back of a bailiff van on it's way to the auction yard (and don't tell me it doesn't happen, in a previous life I've been the bailiff that closed down a techie datacentre in exactly that way) then this would make the presence or absence of a data export option something of a moot point.

 

As much as I think hosted services make sense for a few scenarios, and as much as I don't think anyone needs to fret too much about the likes of MS, Google, Amazon or Capita specifically, this is actually a point that people need to give serious thought to. Especially as there seems to be a lot of firms jumping on the hosted services bandwaggon right now, and with the best will in the world they're not all going to survive.

Posted
What it really needs is some kind of oversight agency setting up that works like ATOL for example.

 

All providers pay a small amount to this agency, in the event a company goes under the agency steps in keeps things going until the issues are solved.

 

That's the only thing I can think of to enable the kind of guarantee mentioned above.

 

I know holidays and airlines are a very different beast than cloud stuff but that's my thoughts on it anyway

 

This is broadly what I think too.

 

Though personally nothing would make me move our MIS into the cloud.

Posted

I think @Bananas idea is the best I've heard. I know we've (me and @PhilNeal) has spoke about what @dhicks posted and we said it does negate what the cloud is all about, not worrying about infrastructure. I mean I'm sure people like RedStor would love to offer a bolt-on backup service, but having the data is one thing, being able to use it is another. I think we need to be able to not only get the data out, but get it into another product. I think that will be the key.

 

Even if you can get at the data and get it into another MIS system pretty quick and easily, you still need to trust them to give you some notice of them going under.

Posted
How about you own your own colo blade or server with them if they go under then you can take your server or blade and run it without them and bailiffs cant take what they don't own your just using they're space :)
Posted
I would think you'd need to enter into some sort of escrow agreement to ensure that you could get access to the data and possibly the software, but realistically, I imagine you would be deeply in the do-dos
Posted
Even if you have a escrow agreement and you get your access to your data and the source code. It's still not going to help you fix a bug, I'm not sure escrow agreements are the answer unless that mythical oversight agency appears.
Posted

Flip the backup to the cloud model. Backup from the cloud instead to a meaningful Sql/whatever aware backup in a state that you can access your data in a standards based format to reattach or export to $something. BCDR plan to be drawn up by Capita on how to get going with Cloud>local or AWS/Azure, etc migration docs. I guess there should be provision for local sims software (instead of purely browser based Sims) which you can point to a local SQL DB. Or perhaps have a locally hosted mitm server which can point to cloud or manual failover to local.

 

JB.

Posted
Would the company hosting it take out some kind of insurance policy? If they go bust the policy pays to keep the services running.
Posted

In my opinion, the bottom line above everything is 'Who owns the data?', as this alone changes everything.

 

Your MIS instance, including files and database may be hosted and backed up on a third party's server and network infrastructure, however the data remains the property of the school.

 

Another way to look at it, is if you ever wanted to change MIS provider. The same rule/policy above would apply.

 

Providing you get this in writing and providing there's a procedure in place, in the event a company goes into administration or you decide to change provider and that the process involved getting data back to the school or new provider is covered, then I cannot see why this wouldn't work.

  • Thanks 1
Posted
In my opinion, the bottom line above everything is 'Who owns the data?', as this alone changes everything.

 

I was just thinking about this. I was (rather smugly) thinking "ah, we'd be okay - our MIS is a Filemaker-based database, in the case of our our providor going bust we'd still have both our data and the business logic to go with it, any Filemaker developer could take over". I then realised that we wouldn't actually have any rights to any of that code - technically, it would belong to the receivers handling any company liquidation, it's the kind of thing that probably wouldn't get sorted out for months, at least.

 

There's an obvious solution, of course - ensure your MIS is open source. In the case of a hosting company going bust, assuming you had a local copy of your data somehow, you'd just had over to another hosting company. All we need now is a open source MIS...

Posted

Phil

 

I think you question raise a lot of issues.

 

However, you show me an IT infrastructure in school, in industry , in public or private sectors that isn't dependent upon some bit of 3rd party software / hardware / network provider or service.

 

There's always a weak link in any infrastructure that leaves your organisation vulnerable .

 

I might also ask you how you define a cloud? Whether your database management server is down the corridor, the other side of school or at a remote off site data centre, then I would argue that your data is stored in a cloud.

 

I think you probably ask the question because SIMS is a 'thick client server' application and you may be under commercial pressure and industry pressure to make it run through a browser.

 

I say that with respect as I know the difficulties and culture changes you will face in moving forward.

 

In the great scheme of things we are being pushed to cloud computing and like all things in life, organisations and individuals have risks in their choice of supplier for whatever bit of their IT infrastructure they are trying to support.

 

You pays your money and takes your chance.

 

I think we probably have other issues to worry about with regards to clouds i.e. where is the cloud, who manages it, who has access to it , is it going to rain ! (but those issues are relevant if the data cloud is down the corridor)

 

I think I've rambled too much

 

Phil

Posted

@PhilNeal

 

I sent you some stuff from the latest discussion from the SIF Data Privacy group as discussed.

 

I want to add some of my observations for discussion, lets use Capita (sorry Phil) as the example. I feel the biggest concern is not the access to the source code in escrow, because lets face it in the days, week or even months after an event, what schools or LAs have the technical ability or resource to be able to make legitimate use of that (picture Capita going under 2 weeks prior to Exams Download Day, or before the Autumn Census update is released). The concern is the sudden inability to access the data or control where the data goes. So:

 

Capita goes into administration. Administrators switch off all services that are leaking finances (servers!) until a buyer is found. Schools have no access and cannot get access to their data. Same would be true of an LA or a third party hosting service.

 

Capita is liquidated, still no access to data... possibly permanently...

 

Capita is bought by another organisation... so without choice your data now sits with, say RM, or AL. This scenario is very common and very controversial over in the US at the moment (CIA aside!)

 

I fundamentally believe this is a big issue across all sectors; that the rights of the data owners (don't get me started on the nuances of that term) are ignored. it is like your rented flat being sold to another landlord without your knowledge, and you cannot get your possessions back.

 

I believe too that the Government needs to address this issue and step in to protect the rights of the data owners. For now, contracts stipulating mitigation, timescales to remove data, adequate communication over possible takeovers etc to customers. More demanding options I presented was to have funds in escrow (the common reason for using escrow!) to provide source of funding for redundant, external servers/services for a limited period of time to allow customers to remove their information. Funds in escrow and using external services would protect it from administration and sale.

 

It would be good to think the suppliers could work together on a project to jointly protect customers, I cannot see it happening though. Better still would be an easy access facility to allow all the competitors easy access to migrate schools away in such an eventuality (but then again, any access is better than no access!).

 

Above all, awareness of this possible event should be make plainly clear to the market to allow schools and LAs to identify and assess risk of using one supplier of hosting, and ultimately the decision and responsibility must rest with them. What we all need to do is highlight the risk and make clear the consequences, the options and the mitigations so they can make informed and educated choices... Like everything else!

Posted
I feel the biggest concern is not the access to the source code in escrow, because lets face it in the days, week or even months after an event, what schools or LAs have the technical ability or resource to be able to make legitimate use of that (picture Capita going under 2 weeks prior to Exams Download Day, or before the Autumn Census update is released).

 

This is a valid point and the problem exists today with Capita.

 

 

If we take Furlong (Schoolbase) - at random, based on the information they provide in response to your survey - http://eduwareconsulting.co.uk/what_is_the_mis_survey/furlong/ - I know they use Rackspace (UK). I know Rackspace and I know it wouldn't be too difficult to negotiate something to allow the servers to keep running. I know, again, based on the responses from the survey, it wouldn't be too difficult to migrate to a.n.other MIS system. Ideally if you where doing it at scale (ie more then just a few schools) you'd broker a official deal with Rackspace and Furlong so if the dreaded day came, at least Rackspace already knows who you are and there is a proper process in place to follow. Also you'd have maybe a.n.other recommend MIS supplier or at least a backup MIS supplier -someone you know can migrate you quickly if need be.

 

Far as I see, they are just as no more risky then Capita.

 

PS: Cheers @GREED for pulling the data together - made that really quick and easy!

Posted (edited)

Because of the constant revenue streams that most SaaS applications have, if a SaaS-provider files for bankruptcy the liquidator will keep that revenue stream going because they can use it to pay off creditors. In order to do so they'll have to keep the services online. They'll shut everything else down like support, sales, marketing, but I see no reason that they'd close a revenue stream.

 

Obviously that's not the cast iron guarantee that you're after. To achieve such a guarantee I would imagine the SaaS provider would need to have some sort of hosting continuity agreement with their hosting supplier (if not the supplier themselves, then a separate legal entity), that the payment for services will be covered for some duration of time if the worst does happen, so that customers can reasonably find alternatives.

 

The most fundamental negation of risk though, is that the customer can acquire data backups on demand to their own servers, and does so periodically.

Edited by mikecampbell
Posted
Not really... because if all they have is the hosting ability would you go with them? Or stay with them? I also wouldn't see it on its own as a revenue stream, we pay capita for their service and support not hosting. Yet that it the biggest loss should this happen.
Posted
Because of the constant revenue streams that most SaaS applications have, if a SaaS-provider files for bankruptcy the liquidator will keep that revenue stream going because they can use it to pay off creditors. In order to do so they'll have to keep the services online. They'll shut everything else down like support, sales, marketing, but I see no reason that they'd close a revenue stream.

Presumably a supplier goes into liquidation because their costs are outstripping their income and have been for some time. The liquidators will want to stem the losses and that means that ANY cost will be shut down, from support staff to hosting services. IMO it is extremely unlikely that in a situation of supplier going bust, the liquidators will keep services running.

Posted
In the perpetual licence on premise world, customers are not immediately affected if their supplier suddenly ceases to operate; the processes and data remain accessible. In the cloud world I have yet to find an established safety net should the unthinkable occur? Whilst I would expect the appointed administrators to try to keep the business going until a buyer could be found, that isn’t something that is contractually binding.

I would expect in teh event of the failure of the supplier as a viable business that :

 

A licence to use the software is granted to the end customer.

The supplier to have insurance in place that would guarantee a third party could operate the service for a limited time but without end user support. That third party would aim within that time to to re-provision service as a standard virtual appliance. The customer can then choose how best to host the service beyond that time, for the time they need to find another MIS and migrate their data.

 

I don't think that's a particularly neat solution but it does try to address continuity of the service while a migration plan can be put in place without duplicating the entire supply.

Posted
Not really... because if all they have is the hosting ability would you go with them? Or stay with them? I also wouldn't see it on its own as a revenue stream, we pay capita for their service and support not hosting. Yet that it the biggest loss should this happen.

 

Uh, I was by no means suggesting it was a long-term thing, obviously the customer would have to find another supplier, but it gives them time.

 

Presumably a supplier goes into liquidation because their costs are outstripping their income and have been for some time. The liquidators will want to stem the losses and that means that ANY cost will be shut down, from support staff to hosting services. IMO it is extremely unlikely that in a situation of supplier going bust, the liquidators will keep services running.

 

For SaaS providers, the actual infrastructure costs are a pittance, they couldn't possibly be making a loss on that alone. So my point was, the liquidators will shut down all operations, but they wouldn't necessarily have any reason to shut down the application if they can continue getting revenue from customers for who want to continue using the legacy system until they find an alternative.

Posted
For SaaS providers, the actual infrastructure costs are a pittance, they couldn't possibly be making a loss on that alone. So my point was, the liquidators will shut down all operations, but they wouldn't necessarily have any reason to shut down the application if they can continue getting revenue from customers for who want to continue using the legacy system until they find an alternative.

Are they? Actual examples suggest not. With e2e the administrators basically held the customers to ransom - stump up thousands * right now* or lose access to your service. With an MIS, if the administrators can't offer support, how do they offer a service? The income stream is generally from customers on a yearly renewal or conversion of sales leads. Who will be renewing for a year or singing up new customers when the business is in administration? Meanwhile the operational costs are ongoing. If the administrators didn't halt the costs, they would not be doing their job securing the any remaining assets for creditors (the most important of which is the administrators charges!)

Posted

I can't image cloud service providers run at 100% capacity, I'm pretty sure they could stomach a customer (MIS Supplier) going into liquidation and I'm pretty sure they'd happy renting it out directly for a few months. If the administration went to another MIS supplier and went, hey, fancy being our preferred new MIS supplier? Well just cover the hosting costs for a few months I'll bet you'll have a quite a few jump at the offer. The issue with be those few months of migrating away with little to no support - but this problems exists now with non-cloud products.

 

You have to remember 2e2 is a bit different to a MIS supplier. For starts, no cloud provider would want to be all over the news as the ones that shutdown schools because of a bit of cash.

  • Thanks 1
Posted
Perhaps there is a fundamental misunderstanding of the job of administrators. Generally, it is not the job of the administrators to *operate* the company, it is their job to wind it up. Generally administrators are appointed because the company is a) in debt, b) losing money and c) has exhausted it's lines of credit. The priority for the administrators is not the customers of the company, it is the creditors. When someone calls in the administrators on a supplier, your continuity plan had better not rely on the goodwill of that companies suppliers (who count as creditors) because no one calls in the administrators when they have goodwill (which is just another word for credit).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...