* CA as the comeback kid
endif; ?>For a while now CA has been under a cloud that had a lot to do with past management practices and almost nothing to do with the company’s products. The new management team has been in place for more than a year now, and the company’s Analyst Summit in Boston last week gave some good indications of the way the management team is shaping the company’s future direction. Frankly, things look a heck of a lot better there than they have for a long time – not just because the old managers are gone but because now a coherent and increasingly comprehensive strategy is developing.
For a while now CA has been under a cloud that had a lot to do with past management practices and almost nothing to do with the company’s products. The new management team has been in place for more than a year now, and the company’s Analyst Summit in Boston last week gave some good indications of the way the management team is shaping the company’s future direction. Frankly, things look a heck of a lot better there than they have for a long time – not just because the old managers are gone but because now a coherent and increasingly comprehensive strategy is developing.
What will this mean? Well for one thing, it means that certain large competitors – and most of the rest of us as well – had better start paying attention soon.
Two significant developments have taken place at the company’s Islandia headquarters. First, the company has implemented a methodical acquisition strategy, making relatively small acquisitions by bringing on board point products that fill in what had been significant gaps in its product set. Within recent quarters, this has resulted in adding products in the areas of compliance management, records management and replication. This approach is exactly the opposite of what EMC and Symantec have done, but looks just like what CA did back in the day when almost everything the company touched seemed to turn to gold.
That’s how CA is putting itself together. Much more important is the new, close alignment of CA’s storage and security business units. Storage and security form the spear point of the “continuous compliance” concept that lies at the heart of CA’s corporate market strategy.
Companies now use much more that traditional areas of IT to conduct business – e-mail, e-documents, transactions, instant messaging, mobile devices, are all now part of the mix, and thus are now subject to regulatory review. CA is spreading its management capability across all these areas.
The CA approach is designed not just to deliver compliance, but to prove compliance as well. If CA really delivers on the promise, anyone dealing with COBIT, HIPAA and SOX regulations, and with the multitude of other laws, regulations and standards that affect modern business, should take interest.
Why? Because compliance means that data must be protected against unauthorized access to both active and inactive records, that adequate internal control structures must be established and maintained, and that the whole system must be prepared to validate its effectiveness whenever a regulatory agency demands that it do so.
How critical is this becoming to world business? The answer to that is that coping with these has become a major cost sink at the enterprise level; by at least one estimate, it may account for 1% of corporate revenues in some business segments. This, but the way, is a hard cost – it represents existing investment to pre-empt problems. What the long-term results of non-compliance might be – the dollar cost as well as the inconvenience of explaining to stockholders why all the management team may go to jail – is unknown, but obviously drives all this decision-making.
CA will use its FileSurf product (records management, acquired when it bought MDY) and Message Manager (e-mail and other messaging, from the iLumin purchase) to track manage and report on information wherever it is in its lifecycle. Expect CA to provide, either directly or through third parties, compliance services as well. Such services would likely cover such areas as assessment and deployment services, but periodic review services might well be part of the mix as well.
If “continuous compliance” – apparently the new mantra at CA – is to be meaningful, it will have to do several things. First, it must take the form of goods and services that can be delivered to the enterprise in a non-disruptive manner. Second, it requires technology that not only does the job as far as compliance is concerned, but that also can prove to others that the job has been done. Next, the whole compliance system must be managed efficiently and simply from a central point so that retention and other policies can be managed across an entire organization. Finally, the system must lend itself to constant updating as the regulatory sands shift beneath the corporate compliance officer’s feet.
It appears that this pretty much sums up what CA is about these days.
If the company is able to follow through on its plans, an old contender will be right back in the thick of the fight for the hearts and budgets of storage administrators. It’s been a while since anyone got excited about what CA was doing. That all may be about to change.




