← Back to The Backroom
video|The Inspire Series

Transformation in Banking with Andy Baker

Absa Group CTO Andrew Baker on transforming a big bank's technology, why cloud and open source are reshaping the industry, and why email and PowerPoint are cancerous for organisations.

Colin Iles·
Share

Key Takeaways

Absa Group CTO Andy Baker on why cloud adoption is an organisational problem, not a technology one: the security sandwich, the shift from vendor ELAs to Absa's own open source repos, team-based pay over PDPs, and why he refuses to use email or PowerPoint.

  • Absa has run AWS workloads for three years, mostly out of Ireland, with AWS completing three availability zones in Cape Town this year
  • Absa's security sandwich embeds security engineers with development teams from day one instead of a pre-launch CISO sign-off
  • Following Barclays' divestment of Absa, the bank moved from vendor ELAs to open source, and now runs about 30 public repositories under Absa OSS, including Spline and k8gb
  • Absa's k8gb Kubernetes load balancer was built in-house after ten vendors were approached to solve the problem and all failed
  • Absa's first cohort of principal engineers, roughly half a dozen people, went through an interview process that included designing a Twitter-scale system on AWS in a day
  • Baker says he does not read email at all and champions a chat channel and Fuzzy Felt over PowerPoint for planning change
5 min read

In this Inspire Series conversation, sponsored by iOCO, Andrew (Andy) Baker, CTO of Absa Group, argues cloud adoption is fundamentally an organisational problem dressed up as a technology one, and that the real gains come from durable teams, open source, and training people rather than consultants. Baker covers Absa's shift to AWS in Cape Town, the "security sandwich" embedding security engineers into product teams from day one, and why he thinks email and PowerPoint have no place in a modern organisation.

The finance-team mistake: why pre-committing cloud spend backfires

Baker's clearest warning is aimed at CIOs with finance backgrounds who negotiate large pre-committed cloud deals. He compares it to handing a supermarket three years of grocery bills up front: you get a discount, but the money is locked up and can't be redeployed. He calls this "actually an engineering problem, not a finance problem," because cloud's value is the ability to change spend in a minute, not lock it in for years. Absa has run AWS workloads for three years, mostly out of Ireland, and this year AWS finished building three availability zones in Cape Town, which mattered because undersea cable outages had already exposed the risk of a single region. Baker breaks the cloud benefit into three layers: infrastructure (Nitro and Xen hypervisors, which he rates ahead of on-premise equivalents), the human layer (removing the toil of pulling cables and changing firewall rules), and software (newer services like Aurora, DynamoDB, and Lambda). The goal, he says, is to free everyone to work on customer problems rather than the plumbing of running a bank.

The security sandwich: putting security engineers inside the team, not at the end

The biggest lever Baker points to for reducing risk in cloud projects is refusing to separate security from delivery. Absa's "security sandwich" embeds security partners with development teams from day one, instead of bringing in a CISO to sign off right before go-live. The alternative, he says, is a familiar failure mode: a team is ready to launch, asks a CISO to approve it, then spends three months explaining what they built while pressure mounts to ship anyway. Baker says AWS tooling, Shield, WAF, CloudTrail, and CloudWatch, gives Absa DDoS resilience and estate-wide monitoring it could never build on premise, standing up to two to three hundred gigabyte attacks. He cites the Capital One breach as a reminder that cloud security depends on configuration, not the platform itself.

Upcoming Virtual Event

Financing Africa's $45bn Used-Car Market

Thursday, 6 August 2026

With Etop Ikpe, Autochek

Register

The open source pivot: from ELAs to Absa's own public repos

Baker traces Absa's open source strategy to Barclays' divestment of the bank a few years before this interview, which let Absa repatriate services centralised in London. Before that, Absa's estate ran on enterprise license agreements (ELAs) with three or four large vendors, a model Baker says produces "vendor affinity" more than good products. Two projects proved the alternative: Makola, an Africa-estate payments platform built on open source Kubernetes, and Absa's DebiCheck implementation, whose one vendor-supplied piece caused the most problems. Absa now publishes about 30 public repositories under Absa OSS, including Spline, a Spark lineage engine used by banks in Europe and the US, and k8gb, a Kubernetes global load balancer that ten vendors were approached to build and all failed before an Absa engineer in Prague wrote it instead. The switch let Absa hire South African engineers in rand rather than pay vendors for software that was itself built on open source. Baker says winning internal backing came from demos, not persuasion: he took risk, audit, and compliance colleagues to see open source running in production rather than asking them to sign off on paper, and credits an early sponsor, a CIB colleague named Ricard Southy, who backed the first DebiCheck project despite real risk: "if it goes wrong, the worst thing that will happen is I get fired."

Team-based pay over PDPs: why Baker won't do personal development plans

Baker rejects individual performance development plans (PDPs) for team-based goals and rewards, arguing PDPs create an incentive to manage your relationship with your manager rather than contribute to the team. Absa's pay has a rough uniformity at team level: high-functioning teams are paid more, teams needing support get more supervision, and Baker says the market corrects pay errors because underpaid people with in-demand skills leave. He has introduced a "principal engineer" track, a technical career path parallel to management, so senior engineers are recognised without being pushed toward management, which he calls "a taxation of energy." Absa's first cohort, roughly half a dozen, went through an interview that included a day designing a Twitter-scale system on AWS. Teams also get a weekly "clean day" split between automating technical debt and mandatory annual certification.

Why isn't Baker worried about challenger banks?

Baker is not especially concerned about single-product challenger banks like Envel, an AI-driven banking startup, or the upcoming Zero Bank from Michael Jordaan, the former FNB CEO. The real disruption risk, he argues, is the shift from "digitized" banks, paper-free processes bolted onto an existing bank, to genuinely "digital" banks that are multi-geography and multi-product from the ground up. The unresolved industry blocker to that shift, in his view, is self-sovereign digital identity and consent, since POPIA and GDPR gesture at consent without solving the underlying identity problem.

Why does Baker say he doesn't use email or PowerPoint?

Baker says he doesn't read email at all and finds it "vexing and taxing," and he is equally dismissive of PowerPoint, arguing change plans dressed up as clean Gantt charts and milestones misrepresent how messy real organisational change actually is. His alternative is a chat channel and, borrowing from a low-fidelity exercise he encountered at Stanford, literally using Fuzzy Felt for planning, on the theory that low-fidelity tools make people less precious about a fixed idea.


CI

Colin Iles

Colin hosts invitation-only executive roundtables and founder interviews across Africa's tech and financial services sectors. Learn more

The Backroom

Get conversations with senior leaders delivered to your inbox.

For B2B Sponsors

Put your brand where senior leaders are paying attention.

Sponsor an invitation-only roundtable or fireside interview. We handle the audience, the production, and the content.

Book a strategy call