CIOReview’s new leadership contribution from Kia America technology leader Subba Kethu makes a useful corrective to the usual modernization rhetoric: legacy is not automatically a liability. For CIOs managing Windows estates, SAP landscapes, IBM i systems, dealer networks, and cloud applications at the same time, the central challenge is not choosing between old and new. It is changing the right components without destabilizing the business processes that still earn revenue every day.
Kethu, identified by Infosys and Hyundai Motor Group as a digital transformation leader and Head of IT at Kia America, argues that modernization should be measured against business outcomes rather than the amount of infrastructure retired. That is a more disciplined standard than a wholesale “cloud-first” mandate, particularly in enterprises where years of embedded business logic sit behind order management, finance, supply chain, customer service, and dealer operations.
The point matters because the systems routinely dismissed as legacy often hold the rules that newer applications depend on. Replacing them can be worthwhile, but it is not inherently transformative. A poorly sequenced replacement can turn a stable, understood platform into a costly multi-year migration while creating new security, integration, and continuity problems.
Kethu’s framework starts with an observation familiar to almost every enterprise IT team: a platform can be old without being obsolete. An IBM AS/400-era workload, a mature ERP implementation, or a heavily customized line-of-business application may be difficult to staff and integrate, yet still be remarkably reliable at executing the transactions that matter.
That distinction should shape modernization plans. The question is not merely whether an application runs on dated infrastructure or contains old code. It is whether it blocks a concrete business need: faster dealer service, real-time inventory visibility, secure remote access, easier deployment, usable analytics, or a more resilient recovery posture.
For Windows administrators, this often means separating the modernization of the experience layer from the modernization of the transactional core. A dealer portal may move to a browser-based application hosted in AWS while retaining integrations with an on-premises ERP system. Microsoft 365 and Copilot deployments may improve employee workflows without requiring a simultaneous rewrite of every back-office database and workflow engine.
That staged approach is less glamorous than a replacement announcement, but it recognizes the operational truth. The core system is usually not the enemy; undocumented dependencies, brittle interfaces, inconsistent data ownership, and unsupported infrastructure are the real risks.
Infosys has publicly described one example of Kia America digitizing a formerly paper-based vehicle-delivery process through its eDelivery platform. According to Infosys, the system was designed to standardize and digitize delivery activities for dealers and customers, illustrating the more practical form of modernization: improve a visible process while avoiding unnecessary disruption to every system around it.
Too many cloud programs still begin with an inventory exercise and end with a hosting decision. That may reduce data-center dependency, but it does not automatically produce better software delivery, stronger resilience, or lower operating costs. Moving a tightly coupled application from a virtual machine in a corporate data center to a virtual machine in the cloud can preserve every existing operational weakness while adding consumption-based spending.
A stronger program asks what cloud changes in practice. Can development teams deploy more safely? Can an application recover in another region? Can customer demand surge without an emergency procurement cycle? Can remote staff access a business service without exposing the internal network? Can teams instrument performance and security consistently across applications?
That is where enterprise Windows teams have an important role. Identity architecture, endpoint compliance, privileged-access controls, network segmentation, patching, backup validation, and logging cannot become afterthoughts because workloads move to Azure or AWS. In a hybrid environment, the control plane becomes more complicated, not less.
Microsoft’s own documentation on Azure Copilot underscores the point: tools that can surface information or take actions against Azure resources operate within a user’s existing permissions and policy boundaries. The value of those tools therefore depends on identity hygiene, least privilege, role design, and accurate resource governance. AI does not compensate for an overly broad administrator role or an unowned subscription.
The best cloud migrations are consequently selective. Customer applications, integration services, analytics platforms, disaster-recovery capacity, and modern collaboration tools may gain clear value from cloud services. Stable workloads with predictable demand and limited integration requirements may not need to move immediately. A mature roadmap can hold both conclusions at once.
A move to S/4HANA, Dynamics 365, or another modern ERP platform should not be treated as a database upgrade with a new interface. It is an opportunity to decide which business processes deserve standardization, which local exceptions remain justified, and which customizations should be retired rather than rebuilt.
That work also explains why an incremental strategy is safer than a big-bang mentality. Finance close, procurement, logistics, warranty processing, dealer incentives, and supply-chain planning all involve interdependent systems and people. Every interface has an owner; every exception is a potential failure point; every cutover changes who can see, approve, and correct business data.
For IT leaders, the practical lesson is to establish a modernization portfolio instead of a single program. Some investments should protect reliability: patching, backup testing, support contracts, and identity hardening. Others should improve efficiency through integration, automation, and platform upgrades. A smaller set should pursue transformative capabilities such as AI-assisted support, predictive analytics, or digital customer channels.
Kethu calls these priorities running, improving, and transforming the business. It is a useful budget lens because it prevents innovation funding from silently cannibalizing the operational teams that keep the company running.
Retrieval-augmented generation, commonly shortened to RAG, grounds a model’s responses in enterprise documents, knowledge bases, and other approved data sources. It can make an internal assistant more useful than a generic chatbot, but it also magnifies existing information-management problems. If the source content is stale, duplicated, poorly classified, or visible to the wrong audience, the AI layer will make those weaknesses easier to discover and potentially harder to contain.
Microsoft’s guidance for Copilot Studio emphasizes the importance of data handling, compliance boundaries, and access controls when enterprises build generative answers around organizational knowledge. In practical terms, that means a RAG project should begin with source ownership and permissions, not prompt engineering.
A sensible first wave of AI work should focus on bounded tasks with measurable outcomes. Internal policy lookup, service-desk knowledge retrieval, document summarization, developer assistance, and agent-assist use cases can reveal whether the organization’s data and governance are ready for wider deployment. They also provide a clearer baseline for measuring time saved, error rates, escalation volume, and user adoption.
Kethu says Kia began its Copilot strategy with a targeted pilot before expanding through training, communication, and governance. That sequencing matters. A tenant-wide rollout may create immediate enthusiasm, but without a support model and data rules, it can also create shadow workflows, inconsistent usage, and a difficult audit trail.
For AI programs, the minimum framework should establish who can approve a use case, which data classes may be used, how access is enforced, what human review remains necessary, how outputs are logged or retained, and how a deployment can be suspended if it produces harmful or unreliable results. For cloud and application modernization, the same model should cover landing-zone standards, identity, network controls, backup objectives, architecture exceptions, and vendor accountability.
The Hyundai Motor Group’s 2026 Global IT Forum provides a parallel view of that challenge. Kethu emphasized the need for more process documentation, open problem-sharing, and a better way to share solutions across the wider organization. That is not bureaucratic overhead. In distributed enterprises, reuse depends on teams being able to find a proven pattern, understand its assumptions, and adopt it without recreating it from scratch.
The real modernization deliverable, then, is not simply a migrated workload or an AI pilot. It is a repeatable operating model that allows the next workload and the next pilot to move faster with fewer surprises.
The near-term consequence for CIOs is clear: protect the dependable systems that run the business, expose their value through modern interfaces and integrations, and retire only what no longer earns its place. The organizations that get this balance right will not be defined by how quickly they abandon legacy platforms, but by how reliably they turn existing systems into foundations for what comes next.
The point matters because the systems routinely dismissed as legacy often hold the rules that newer applications depend on. Replacing them can be worthwhile, but it is not inherently transformative. A poorly sequenced replacement can turn a stable, understood platform into a costly multi-year migration while creating new security, integration, and continuity problems.
The System of Record Is Not the Same as the User Experience
Kethu’s framework starts with an observation familiar to almost every enterprise IT team: a platform can be old without being obsolete. An IBM AS/400-era workload, a mature ERP implementation, or a heavily customized line-of-business application may be difficult to staff and integrate, yet still be remarkably reliable at executing the transactions that matter.That distinction should shape modernization plans. The question is not merely whether an application runs on dated infrastructure or contains old code. It is whether it blocks a concrete business need: faster dealer service, real-time inventory visibility, secure remote access, easier deployment, usable analytics, or a more resilient recovery posture.
For Windows administrators, this often means separating the modernization of the experience layer from the modernization of the transactional core. A dealer portal may move to a browser-based application hosted in AWS while retaining integrations with an on-premises ERP system. Microsoft 365 and Copilot deployments may improve employee workflows without requiring a simultaneous rewrite of every back-office database and workflow engine.
That staged approach is less glamorous than a replacement announcement, but it recognizes the operational truth. The core system is usually not the enemy; undocumented dependencies, brittle interfaces, inconsistent data ownership, and unsupported infrastructure are the real risks.
Infosys has publicly described one example of Kia America digitizing a formerly paper-based vehicle-delivery process through its eDelivery platform. According to Infosys, the system was designed to standardize and digitize delivery activities for dealers and customers, illustrating the more practical form of modernization: improve a visible process while avoiding unnecessary disruption to every system around it.
Cloud Migration Is a Capability Decision, Not a Finish Line
Kethu describes a multi-cloud strategy in which AWS supports customer-facing applications and Azure supports AI and generative-AI work. Those specific implementation details come from his CIOReview contribution, but the strategic division is notable because it treats cloud platforms as enablers rather than destinations.Too many cloud programs still begin with an inventory exercise and end with a hosting decision. That may reduce data-center dependency, but it does not automatically produce better software delivery, stronger resilience, or lower operating costs. Moving a tightly coupled application from a virtual machine in a corporate data center to a virtual machine in the cloud can preserve every existing operational weakness while adding consumption-based spending.
A stronger program asks what cloud changes in practice. Can development teams deploy more safely? Can an application recover in another region? Can customer demand surge without an emergency procurement cycle? Can remote staff access a business service without exposing the internal network? Can teams instrument performance and security consistently across applications?
That is where enterprise Windows teams have an important role. Identity architecture, endpoint compliance, privileged-access controls, network segmentation, patching, backup validation, and logging cannot become afterthoughts because workloads move to Azure or AWS. In a hybrid environment, the control plane becomes more complicated, not less.
Microsoft’s own documentation on Azure Copilot underscores the point: tools that can surface information or take actions against Azure resources operate within a user’s existing permissions and policy boundaries. The value of those tools therefore depends on identity hygiene, least privilege, role design, and accurate resource governance. AI does not compensate for an overly broad administrator role or an unowned subscription.
The best cloud migrations are consequently selective. Customer applications, integration services, analytics platforms, disaster-recovery capacity, and modern collaboration tools may gain clear value from cloud services. Stable workloads with predictable demand and limited integration requirements may not need to move immediately. A mature roadmap can hold both conclusions at once.
ERP Modernization Needs a Business Case Larger Than “End of Support”
The contribution identifies SAP S/4HANA as Kia’s digital backbone for future automation and analytics. ERP modernization is among the most consequential decisions a CIO can make, because it forces an enterprise to confront process variation, data quality, custom code, and regional operating differences that may have accumulated for years.A move to S/4HANA, Dynamics 365, or another modern ERP platform should not be treated as a database upgrade with a new interface. It is an opportunity to decide which business processes deserve standardization, which local exceptions remain justified, and which customizations should be retired rather than rebuilt.
That work also explains why an incremental strategy is safer than a big-bang mentality. Finance close, procurement, logistics, warranty processing, dealer incentives, and supply-chain planning all involve interdependent systems and people. Every interface has an owner; every exception is a potential failure point; every cutover changes who can see, approve, and correct business data.
For IT leaders, the practical lesson is to establish a modernization portfolio instead of a single program. Some investments should protect reliability: patching, backup testing, support contracts, and identity hardening. Others should improve efficiency through integration, automation, and platform upgrades. A smaller set should pursue transformative capabilities such as AI-assisted support, predictive analytics, or digital customer channels.
Kethu calls these priorities running, improving, and transforming the business. It is a useful budget lens because it prevents innovation funding from silently cannibalizing the operational teams that keep the company running.
Data Readiness Is the Constraint on Enterprise AI
The contribution’s strongest warning is aimed at the current rush to deploy generative AI: modernize data before trying to scale AI. That is not an argument against copilots, agents, or retrieval-augmented generation. It is an argument for recognizing the prerequisite work that determines whether those tools become useful or dangerous.Retrieval-augmented generation, commonly shortened to RAG, grounds a model’s responses in enterprise documents, knowledge bases, and other approved data sources. It can make an internal assistant more useful than a generic chatbot, but it also magnifies existing information-management problems. If the source content is stale, duplicated, poorly classified, or visible to the wrong audience, the AI layer will make those weaknesses easier to discover and potentially harder to contain.
Microsoft’s guidance for Copilot Studio emphasizes the importance of data handling, compliance boundaries, and access controls when enterprises build generative answers around organizational knowledge. In practical terms, that means a RAG project should begin with source ownership and permissions, not prompt engineering.
A sensible first wave of AI work should focus on bounded tasks with measurable outcomes. Internal policy lookup, service-desk knowledge retrieval, document summarization, developer assistance, and agent-assist use cases can reveal whether the organization’s data and governance are ready for wider deployment. They also provide a clearer baseline for measuring time saved, error rates, escalation volume, and user adoption.
Kethu says Kia began its Copilot strategy with a targeted pilot before expanding through training, communication, and governance. That sequencing matters. A tenant-wide rollout may create immediate enthusiasm, but without a support model and data rules, it can also create shadow workflows, inconsistent usage, and a difficult audit trail.
Governance Is the Mechanism That Lets Change Scale
Governance has a reputation as the department that says no. Kethu’s argument is more useful: governance is the mechanism that lets an enterprise say yes repeatedly without reinventing security, privacy, procurement, and ownership decisions for every new idea.For AI programs, the minimum framework should establish who can approve a use case, which data classes may be used, how access is enforced, what human review remains necessary, how outputs are logged or retained, and how a deployment can be suspended if it produces harmful or unreliable results. For cloud and application modernization, the same model should cover landing-zone standards, identity, network controls, backup objectives, architecture exceptions, and vendor accountability.
The Hyundai Motor Group’s 2026 Global IT Forum provides a parallel view of that challenge. Kethu emphasized the need for more process documentation, open problem-sharing, and a better way to share solutions across the wider organization. That is not bureaucratic overhead. In distributed enterprises, reuse depends on teams being able to find a proven pattern, understand its assumptions, and adopt it without recreating it from scratch.
The real modernization deliverable, then, is not simply a migrated workload or an AI pilot. It is a repeatable operating model that allows the next workload and the next pilot to move faster with fewer surprises.
The near-term consequence for CIOs is clear: protect the dependable systems that run the business, expose their value through modern interfaces and integrations, and retire only what no longer earns its place. The organizations that get this balance right will not be defined by how quickly they abandon legacy platforms, but by how reliably they turn existing systems into foundations for what comes next.
References
- Primary source: CIOReview
Published: 2026-08-01T18:50:08.487408
Loading…
www.cioreview.com - Related coverage: learn.microsoft.com
Azure Copilot Overview | Microsoft Learn
Azure Copilot is an AI-powered tool that helps you do more with Azure.learn.microsoft.com - Related coverage: learn.microsoft.com
Enhance AI responses with Retrieval Augmented Generation - Microsoft Copilot Studio | Microsoft Learn
Discover how RAG in Microsoft Copilot Studio combines language models with enterprise knowledge to deliver reliable, contextual, and safe AI responses.learn.microsoft.com - Related coverage: techcommunity.microsoft.com
- Related coverage: cdn.techcommunity.microsoft.com
Azure AI Studio AMA Summary December 14 2023 FinalVersion
PDF documentcdn.techcommunity.microsoft.com