
The Hidden Cost of Fragmented IT Operations in Financial Institutions
The Hidden Cost of Fragmented IT Operations in Financial Institutions

Financial institutions are expected to deliver digital services quickly while maintaining security, resilience and regulatory control.
Behind every customer-facing application is a large technology environment that must be provisioned, configured, patched, secured, monitored and maintained. These activities often span servers, networks, cloud platforms, middleware, applications and security tools.
When each activity relies on separate scripts, manual instructions and team-by-team handovers, the problem is not limited to slower IT operations. It creates fragmented execution: the same task may be performed differently across systems, environments or teams.
One administrator may apply a patch successfully while another system is missed. A server may be hardened according to the approved baseline, but the same control may not be applied consistently in a disaster recovery environment. A network change may be completed correctly, yet its records remain scattered across tickets, emails and device logs.
As the technology estate grows, these small gaps become a larger operational, security and compliance risk.
Where Manual IT Operations Create the Greatest Pain

The need for automation extends beyond a single use case. It affects the full technology lifecycle—from building an environment to keeping it secure and responding when something goes wrong.
1. Patching becomes slow, inconsistent and difficult to track
Financial institutions may need to patch large numbers of operating systems, applications and infrastructure components. Manual coordination creates several challenges:
Teams must identify affected assets across different environments
Testing, approval and deployment may involve multiple handovers
Maintenance windows can be missed or used inefficiently
Some systems may be updated while others remain exposed
Evidence of completion may be spread across different tools and records
The risk is not only that patching takes too long. It is that the institution may not have a clear and current view of what has been patched, what failed and what still requires action.
Automation can turn approved patching procedures into repeatable workflows. It can help coordinate pre-checks, deployment, validation, exception handling and reporting while retaining the necessary approval gates.
2. Security hardening and compliance controls may drift over time
Security baselines define how systems should be configured, including services, access controls, ports, packages and other technical settings. Applying these standards manually across a mixed environment is difficult to sustain.
Even when systems begin with the same approved configuration, emergency fixes, maintenance activities and local changes can gradually create differences. This may lead to:
Inconsistent security controls across similar systems
Greater exposure to misconfiguration
Repeated manual compliance checks
More remediation work before audits
Difficulty proving that the approved baseline was applied consistently
Ansible automation can express approved configuration and hardening requirements as reusable playbooks. The same content can be used to apply controls, check the current state and remediate identified gaps. This supports consistency and evidence collection, but it does not make a system compliant by itself. The institution must still define the correct policies, approvals, risk decisions and oversight.
3. End-to-end provisioning is delayed by team handovers
Provisioning a banking environment rarely means creating only a server. A complete workflow may also require operating-system configuration, network settings, security controls, middleware, monitoring, backup policies and access permissions.
When every team performs its part separately, development and business teams may wait days or weeks for an environment. Manual handovers also make it harder to ensure that development, testing, production and disaster recovery environments follow the same approved design.
End-to-end automation can coordinate these steps in the correct sequence. Teams can use governed, reusable workflows to deliver standardised environments more quickly while maintaining role-based access, approvals and central visibility.
4. Network changes remain repetitive and error-prone
Financial institutions operate networks that connect branches, data centres, cloud services, applications and security zones. Common tasks such as configuration updates, access-control changes, backups and compliance checks may need to be performed across many devices.
Without centralised automation, network teams may face:
Repetitive command-by-command changes
Differences between device configurations
Longer maintenance windows
Limited pre-change and post-change validation
Difficult rollback when a change causes an issue
Fragmented evidence of what was changed
Network automation can help standardise approved changes across supported technologies, capture configuration states, perform validation and produce clearer execution records. Human review remains important for high-risk changes; automation makes the approved procedure more repeatable.
5. Operations teams react slowly to alerts and incidents
Monitoring platforms can generate large numbers of alerts, but an alert alone does not resolve the underlying issue. Operations teams may still need to collect information, identify the affected system, follow a runbook and carry out repetitive remediation steps.
This delay increases recovery time and consumes skilled employees’ attention. It can also create inconsistent responses when different people handle the same type of incident.
An event-driven approach connects trusted alerts to predefined automation. For suitable low-risk scenarios, the platform can gather diagnostics, open or update a ticket, restart an approved service, apply a known remediation or escalate the issue with richer context.
AI-assisted operations can add value by helping identify patterns or prioritise events, while governed automation carries out approved actions. This distinction is important: AI may support analysis, but production changes should remain controlled, traceable and aligned with the institution’s policies.
Why These Problems Matter to the Business

Fragmented manual operations create consequences beyond the technology department.
Slower delivery of digital services
When infrastructure, access and network changes take longer, application teams cannot build, test or release services at the expected pace.
Greater operational risk
Inconsistent execution increases the possibility of configuration errors, incomplete changes, service disruption and longer recovery times.
Higher security exposure
Delayed patches and uneven hardening may leave known weaknesses unresolved across parts of the environment.
Increased audit and compliance effort
Employees spend time collecting records from tickets, emails and tools to demonstrate what was done. Missing or inconsistent evidence creates additional remediation work.
Limited use of specialist talent
Engineers spend valuable time repeating routine procedures instead of improving architecture, resilience, security and service performance.
BNM RMiT: Why Consistency, Control and Evidence Matter

For Malaysian financial institutions, these operational issues also sit within the expectations of Bank Negara Malaysia’s Risk Management in Technology (RMiT) policy document.
The revised RMiT policy document, issued on 28 November 2025, aims to strengthen the management of technology and cyber risks, improve service availability and resilience, and maintain public trust in the financial system.
Several RMiT requirements are directly relevant to the operational pain points discussed in this article:
Financial institutions must maintain current security baselines for technology components and keep them accurate and up to date.
They must continuously monitor and implement current patch releases in a timely manner.
Patch and end-of-life management must address asset identification, risk assessment, prioritisation, compatibility testing, approval, deployment, monitoring and tracking.
For rapid system development approaches such as DevOps, RMiT requires enterprise security, governance and compliance requirements to be met, including automated IT security compliance review.
RMiT’s cloud guidance also addresses controls for infrastructure-as-code, vulnerability scanning before provisioning, trusted images, access control and the management of misconfiguration risk.
These expectations do not prescribe Ansible as the only solution, and adopting Ansible does not automatically make an institution RMiT-compliant. However, governed automation can support the institution’s control environment by helping it execute approved procedures consistently, retain job records, apply role-based access and produce clearer operational evidence.
The important shift is from relying on people to remember every step to building approved controls into repeatable workflows.
How Red Hat Ansible Automation Platform Helps

Red Hat Ansible Automation Platform provides an enterprise framework for creating, controlling and scaling automation across multiple technology domains.
Using human-readable automation playbooks, organisations can define the desired sequence of activities and apply it consistently. Rather than maintaining isolated scripts for different teams, the platform can provide a shared automation foundation across infrastructure, networks, cloud, security and applications.
Key enterprise capabilities include:
Centralised execution and management of automation jobs
Reusable and governed automation content
Role-based access and controlled credentials
Workflow approvals and team-based permissions
Job logging, reporting and operational visibility
Integration across different platforms and vendor technologies
Self-service access to approved automation workflows
Event-driven automation for predefined operational responses
The value is not simply that individual tasks run faster. It is that the organisation can standardise how approved work is performed across teams and environments.
A Practical Automation Roadmap for Financial Institutions

Trying to automate everything at once can create unnecessary complexity. A stronger approach is to prioritise use cases based on volume, risk, repeatability and measurable business impact.
Phase 1: Select a focused, high-value use case
Suitable starting points may include:
Operating-system patching for a defined group of servers
Security baseline checks and remediation
Standard server or virtual-machine provisioning
Network configuration backup and compliance validation
Automated response to a recurring, well-understood operational alert
Phase 2: Build governance into the workflow
Define the owners, approval points, access permissions, testing requirements, exception process and evidence needed before automating the procedure.
Phase 3: Measure the outcome
Useful measures may include:
Time required to complete the process
Number of manual steps and team handovers
Success, failure and exception rates
Engineering hours spent per request
Percentage of systems following the approved baseline
Time required to produce audit evidence
Mean time to respond or recover for selected events
Phase 4: Reuse the foundation
Once the first workflow is stable, the institution can extend the same governance model and automation platform to adjacent use cases.
Real-World Case Study: Kreditplus, Indonesia

Kreditplus is an Indonesian financial-services provider that has operated since 1994. Over time, the organisation developed a diverse technology environment that became increasingly complex to manage. According to Red Hat’s published customer case study, this complexity affected the delivery of developer environments and made security and compliance more difficult.
Kreditplus modernised its environment using Red Hat Enterprise Linux, Red Hat OpenShift and Red Hat Ansible Automation Platform.
Ansible Automation Platform helped automate activities across the development lifecycle, including processes from development through staging and production. The initiative also supported more standardised provisioning, scaling and security-related operations.
Reported outcomes from the broader Red Hat modernisation initiative included:
Simpler and more efficient operations
A more streamlined process for security updates
Self-service access for developers instead of waiting for operations teams to deploy environments
Improved support for security and compliance requirements
A 70% reduction in licensing costs across the broader technology initiative
The reported cost reduction resulted from the combined Red Hat technology strategy—not Ansible Automation Platform alone. The case remains relevant because it demonstrates how automation can connect infrastructure operations, security requirements and application delivery within a Southeast Asian financial-services environment.
Key lesson for Malaysian financial institutions
Speed and control do not need to work against each other. When approved operational and security requirements are embedded into governed automation workflows, institutions can reduce repetitive work while improving consistency, visibility and traceability.
Building an Enterprise Automation Roadmap with Wiki Labs

Automation delivers the greatest value when it is aligned with operational priorities, governance requirements and measurable outcomes.
Wiki Labs helps organisations identify suitable use cases, develop governed automation workflows and build the internal capability needed to sustain them. Through our Consult, Build, Operate and Transfer (CBOT) approach, we support customers across the automation journey:
Consult: Assess current processes, pain points, risk priorities and automation readiness
Build: Develop reusable workflows based on approved operational and security standards
Operate: Support adoption, governance, measurement and continuous improvement
Transfer: Enable internal teams to manage and expand automation confidently
With more than 17 years of enterprise technology experience, over 100 enterprise customers and a long-standing Red Hat partnership, Wiki Labs understands the operational and governance expectations of complex Malaysian organisations.
Conclusion

The absence of enterprise automation is not only a productivity issue. It can affect patch timeliness, security consistency, infrastructure delivery, network reliability, incident response and the quality of operational evidence.
For financial institutions, the objective should not be to automate every task immediately. It should be to identify repetitive, high-impact processes and turn them into controlled, measurable and reusable workflows.
Red Hat Ansible Automation Platform can provide a common automation foundation across these technology domains. When combined with appropriate governance, approvals and human oversight, it can help institutions improve speed without weakening control.
Ready to identify where automation can deliver the greatest impact in your IT environment?
