By Alex Henthorn-Iwane, Senior Vice President of Marketing, Gluware
Network automation has traditionally been built from the bottom up. An engineer finds a repetitive task, writes a script or playbook to automate it, and then moves on to the next opportunity. As the practice matures, individual scripts become workflows, workflows become platforms, and more of the network comes under automation.
This is good engineering, but incremental improvements in engineering efficiency are difficult to present as meaningful business outcomes.
The business expects engineering organizations to get better at their jobs. Reducing a four-hour task to four minutes is inarguably valuable, but it is also the kind of continuous improvement expected from every technical organization. The more important question is what the improvement allows the organization to accomplish.
A CISO wants to reduce the company’s exposure to security threats. Operations leaders want the business to keep running through infrastructure changes. Compliance teams need confidence that required controls remain in place and evidence that demonstrates their status. Business leaders want infrastructure to support growth without costs and risks rising at the same rate. They also want a security posture that strengthens customer confidence rather than becoming an obstacle to winning business.
Those are the outcomes network automation should be designed to deliver.
The business outcomes of network automation
Technical progress matters. Accurate inventory, standardized configurations, automated changes, drift detection, operating-system management, audits, and validation are all necessary capabilities.
But they are not the final result. They should lead to business benefits that people outside the network organization can understand:
- Lower security risk. Find relevant exposures, respond before they can be exploited, and verify that the risk has been addressed.
- Greater business continuity. Make necessary changes without causing avoidable outages or interruptions.
- Compliance that can be sustained and demonstrated. Keep required controls in place and produce evidence responsively without excessive displacement of business as usual (BAU) work.
- Growth without proportional cost growth. Support more locations, infrastructure, and business change without expanding the operations team at the same rate.
- Stronger customer confidence and revenue opportunity. Turn a demonstrably strong security posture into an advantage when competing for business.
Lee Harper, Enterprise Administrator at leading engineering consulting firm Terracon shared their network automation journey in a presentation at AutoCon 3, showing what these outcomes look like in practice.
Lower security risk
Vulnerability remediation is often described as a configuration-change problem. A network team automates the commands required to address a vulnerability across several types of devices and measures how much faster it can deploy them.
The business has a larger problem to solve. It needs to know which devices are affected, determine which are actually exposed based on their configuration and operational state, apply the appropriate remediation safely across different platforms, and verify that the exposure has been eliminated.
According to Harper, when Terracon introduced Gluware in 2019, the engineering consulting firm began building an accurate inventory of its network, standardizing operating-system versions and configurations, and using configuration and live-state audits to assess its infrastructure. These capabilities helped the team determine whether a newly disclosed vulnerability actually affected its environment instead of spending time chasing every possible exposure.
They also changed how quickly Terracon could respond. As Lee Harper, Enterprise Administrator at Terracon, explained, after automating their network:
“We’re able to roll out new firmware to patch for a vulnerability in a single night. Configuration changes, likewise, in a couple of hours.”
The measurable security result appeared in an external assessment. Harper added that Terracon’s annual cybersecurity-insurance audit findings declined from more than thirty-four to nine in two years, and that in regards to their insurance provider,
“Right now, we are one of their favorite customers because we’re not a risk for them.”
The inventory, audits, templates, and automated changes were engineering achievements. The business outcome was lower exposure and a substantially improved risk assessment from the company’s cybersecurity insurer.
Greater business continuity
Speed alone is not a sufficient measure of successful automation. A vulnerability patch delivered in minutes is not a success if it takes offices offline. A network change completed overnight is not a success if an undocumented change disrupts the business the next morning.
Terracon used lab testing and Gluware configuration-drift comparisons to see what third-party updates would actually change before deploying them in production. That became particularly important in its SD-WAN environment, where updates sometimes included poorly documented configuration changes.
Harper said this process had:
“Saved us a number of times from potentially catastrophic effects of undocumented changes.”
Terracon could make significant infrastructure changes while reducing the chance that an unexpected change would interrupt business operations.
For network engineers, the mechanism was better testing and post-change validation. For the business, the outcome was continuity: employees could remain productive, offices could remain connected, and infrastructure modernization could proceed with less operational risk.
Compliance that can be sustained and demonstrated
Compliance is not achieved by passing an automated check once. Required controls need to remain in place, and the organization needs evidence that demonstrates their status.
Terracon used Gluware to automate configuration checks against CIS benchmarks. Instead of relying on point-in-time inspection, the network team could repeatedly assess whether configurations continued to meet the selected benchmarks and best practices.
Harper described the outcome this way:
“We can automate the checks on this so that we make sure that not only is our code doing it, it continuously is meeting those benchmarks, meeting those best practices. And the other part of this is it’s an easy tool for attesting to that compliance.”
Reporting was equally important:
“Being able to report on all of your vulnerability remediation, all of your benchmarks, all those efforts, being able to put out a report that says, ‘yes, we are doing it, yes, we are compliant’, is another very critical tool.”
This does not establish that automation made Terracon compliant with every applicable requirement. It demonstrates a clear compliance benefit: the company could continuously check important controls and produce evidence of their status without excessively disrupting BAU work.
That is a business outcome because it reduces the effort and uncertainty involved in maintaining and demonstrating compliance. It also gives auditors, customers, and business leaders greater confidence that required practices remain in place between formal assessments.
Growth without proportional cost growth
Terracon initially adopted network automation because its four-person network team was already fully loaded. The company was growing through acquisitions, and each acquisition could add several new locations at once. Continually adding network staff was not the business’s preferred answer.
The initial efficiency improvement was dramatic:
“Our configuration changes had gone from taking the entire network team three to four days to implement to taking a single person three to four hours. So a huge return on investment there, and that was just the beginning.”
The time saving was meaningful, but Harper’s final phrase points to the larger result.
Terracon grew from more than 120 locations to more than 200. During the same period, it replaced its switching platform, reworked its network architecture, and migrated to SD-WAN. According to Harper, Terracon accomplished this without adding any headcount.
For the network team, the achievement was faster and more repeatable network operations. For the business, the outcome was cost-efficient growth. Terracon supported more than 50 percent location growth and a full network transformation without allowing network-operations headcount to increase at nearly the same rate.
Stronger customer confidence and revenue opportunities
The most consequential result appeared outside IT entirely.
Terracon’s customers care about how the engineering firm protects their data. Its ability to demonstrate a strong security posture therefore affected more than internal risk. It affected the company’s ability to compete for work.
Harper said:
“There are contracts that we as an engineering firm have been able to win because of our security posture.”
Not every network automation initiative connects directly to revenue, nor does it need to. Lower security risk, greater continuity, more sustainable compliance, and cost-efficient growth are meaningful outcomes in their own right. But Terracon’s experience shows how operational improvements can influence customer confidence and competitive advantage.
Measure the outcome, not only the activity
Traditional automation metrics still have a role. Time saved, percentage of changes automated, devices under management, and workflow execution counts help engineering teams determine whether the automation itself is working.
They should not be the end of the measurement model.
For each automation initiative, the team should identify the business problem, the operational capabilities required to solve it, and the steps and evidence that will demonstrate progression to ultimate success. Drawing from Terracon’s journey, here are sample impact/outcome questions:
- How long does it take to move from disclosure of a relevant vulnerability to verified remediation?
- Is the company’s externally assessed security risk improving?
- How many business disruptions result from network changes or unauthorized drift?
- Can the organization continuously demonstrate that required controls remain in place?
- How much growth and infrastructure change can the existing team support?
- Does the company’s security posture strengthen customer confidence and its ability to win business?
These outcomes express network automation in terms that security, operations, compliance, and business leaders can recognize.
Network teams must continue to build and operate technical machinery that much of the business will never see or understand. The business case is not the machinery. It is the measurable improvement in security, continuity, compliance, operating leverage, and customer confidence that the machinery makes possible. By framing technical progression in automation as an upward journey to high-value outcomes, network teams can win the hearts, minds, and budgets needed to achieve what everyone wants from automation.
Your organization wants what network automation can do for the business. Gluware was built as a full-stack platform to fast-forward. If you’re ready to accelerate your automation business outcomes, request a demo.