logo
Open-source Java migrations rise as audits cost firms USD $500,000+

Open-source Java migrations rise as audits cost firms USD $500,000+

Techday NZ16-07-2025
New research from Azul and the ITAM Forum has revealed that 27% of enterprises spend more than USD $500,000 annually addressing software licence non-compliance, as organisations face increased audits and consider open-source solutions to mitigate risks and costs.
The joint global survey, which gathered responses from 500 IT asset management (ITAM) and software asset management (SAM) professionals across six continents, highlighted that 73% of enterprises have experienced an Oracle Java audit in the last three years. Nearly 80% have either migrated or plan to migrate to open-source Java alternatives, underscoring shifting priorities in software asset management.
Compliance challenges
A significant portion of survey participants, 37%, identified compliance and the management of excessive licensing as their chief challenge. Complex software architectures, particularly in hybrid cloud environments, have expanded the task of maintaining compliance and tracking usage. Twenty-five percent of respondents cited complex configurations as a barrier to effective tracking of application deployment and usage both on-premises and in the cloud.
Other reported difficulties include aligning different organisational teams - such as IT, software development, legal, and procurement (27%) - as well as grappling with resource constraints (24%), rising prices for renewals and maintenance (24%), and uncertainty regarding evolving licensing rules or changes in vendor policy (23%).
Audit processes and disruption
Despite these challenges, 74% of respondents stated their organisations manage licence discovery and software audits primarily in-house. This self-reliant approach introduces its own set of difficulties, including maintaining accurate records of software use (26%), decoding complex licensing terms (23%), and generating accurate licensing compliance metrics (23%).
Auditing is now a regular feature for many, with 81% of organisations conducting licensing audits at least twice yearly, and 25% reporting continuous auditing practices. A quarter of participants said their organisation faces frequent financial penalties and legal actions as a consequence of software licensing non-compliance.
Audits carry operational and financial consequences, with more than 30% of survey participants noting unexpected disruptions, such as organisational disturbances, unforeseen budget impacts, decisions to change vendors, and delayed projects.
Oracle Java pressures
Licensing complexity is particularly pronounced with Oracle Java, according to the survey. Ninety-six percent of respondents expressed concern over Oracle's pricing and licensing policies, especially regarding the employer-based pricing model. The study noted a trend of organisations investing in new monitoring solutions and audit processes to ensure compliance and avoid Oracle licensing costs.
Faced with these pressures, 79% of organisations have already switched from Oracle Java, are migrating, or intend to migrate to open-source Java alternatives. For those considering migration, the main motivations are security and reliability (51%), followed by cost reduction (42%) and simpler compliance (40%). Of those who have completed migration, 57% identified security and reliability as their leading concern.
Participants anticipate notable cost savings by moving to open-source Java, with 66% estimating they could save at least 40% compared to Oracle Java licence costs. Only 1% expected not to see any financial benefit from such a transition. "The results highlight a fundamental mismatch between the complexity of modern software licensing and the resources organizations rely on to effectively manage software compliance," said Martin Thompson, founder of the ITAM Forum. "ITAM and SAM professionals are becoming increasingly vital as organizations increasingly recognize that poor license management can result in significant financial penalties and operational disruptions. They must have the resources and executive buy-in to ensure compliance and successful license management." "The data reveals a concerning trend where the increasing complexity of vendor licensing and pricing has turned routine upkeep into recurring six-figure compliance exercises. When 73% of enterprises have been audited and one in four now spends more than $500,000 a year cleaning up license issues, the cost of merely staying compliant with software licensing and pricing is unsustainable," said Scott Sellers, co-founder and CEO at Azul. "Specifically, when it comes to the uncertainty of Oracle's ever-shifting Java licensing terms, organizations shouldn't have to burn ITAM resources, interrupt projects, or absorb surprise penalties just to run their applications. Moving to open-source alternatives lets them break free from the audit treadmill, regain budget and focus on delivering value."
Market growth
The global ITAM market has experienced significant growth, rising from USD $1.15 billion in 2019 to USD $1.49 billion in 2023, representing a 6.9% compound annual growth rate. The SAM market subset is forecast to grow at 16% annually through 2029. Factors behind this expansion include the mounting proportion of IT budgets spent on software - averaging 29% - and increasingly complex licensing models due to cloud and virtualisation, alongside heightened regulatory compliance demands.
The survey demonstrates that ITAM and SAM professionals are navigating an environment of escalating complexity and exposure, as the scope of asset management shifts from simple inventory control to a vital component of risk mitigation, cost control, and strategic technology decision-making.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Metaforms raises USD $9m to revolutionise market research
Metaforms raises USD $9m to revolutionise market research

Techday NZ

timea day ago

  • Techday NZ

Metaforms raises USD $9m to revolutionise market research

Metaforms, a San Francisco-based artificial intelligence startup, has raised USD $9 million in Series A funding to support the development of AI infrastructure for the market research industry. The funding round was led by Peak XV Partners, formerly known as Sequoia India, and included participation from Nexus Venture Partners and Together Fund. With this investment, Metaforms will expand its team, enhance its AI agents, and broaden its platform to include report generation and voice-based research capabilities. The company's integrations already extend to widely used research tools such as Decipher, SPSS, and Confirmit. Addressing industry bottlenecks The global market research industry, estimated to be worth USD $130 billion, is experiencing rapid growth. However, agencies face increasing challenges from outdated operational systems, leading to capacity issues and compressed margins. Metaforms aims to address these challenges, enabling agencies to meet client demand without overburdening their staff or turning away work. "We're thrilled to partner with Akshat and Arjun as they reimagine what a market research agency could look like in an AI-first world. Metaforms is scaling rapidly, by enabling some of the largest research agencies globally to automate workflows such as survey programming and data processing through their suite of AI agents." Shailendra Singh, MD, Peak XV Research agencies traditionally spend significant time on manual tasks such as converting survey questionnaires into code, coordinating with multiple panel providers via email, and running complex validation scripts. Metaforms' AI agents automate these processes, fitting within agencies' existing workflows and improving efficiency without replacing human expertise. The platform's functions include converting questionnaires into survey code, identifying problematic data before it impacts projects, coordinating with panel vendors, and managing quotas across multi-country studies. For many agencies, these capabilities represent the difference between being able to scale up or having to refuse additional business. Industry traction Since launching commercially six months ago, Metaforms has secured contracts with four of the world's top twenty research agencies, including Strat7. The platform currently processes over 1,000 surveys per month and counts several Fortune 500 companies among its clients. Metaforms reports a 100% expansion rate among clients who started with a single AI agent and have since deployed additional AI functionalities. "Metaforms has been incredibly successful thanks to their uniquely thoughtful approach to modernising research operations - embedding seamlessly into the workflows, tools, and platforms that researchers and agencies already use. I'm excited to continue supporting the team as they build on that momentum with this Series A." Jonathan Tice, GTM Consultant [Prev: Chief Customer Officer, Forsta] Akshat Tyagi and Arjun S founded Metaforms in 2022, driven by their own difficulties accessing professional market research as early-stage founders. They identified that agencies were limited not by a lack of demand, but by their operational bandwidth, and set out to build a platform to increase efficiency. "Our goal is simple: help great research teams spend less time firefighting and more time doing the work that actually matters," said Akshat Tyagi, co-founder and CEO of Metaforms. "When you automate the grunt work, you make high-quality research more accessible to more companies." According to Metaforms, its AI platform makes high-quality, professional-grade market research more accessible both to large global companies and early-stage startups. By automating high-volume, repetitive tasks, the platform is enabling agencies to serve clients they may previously have had to turn away, improving their ability to scale and manage costs effectively. "Metaforms is a breakout example of the India-to-global play in AI," said Manav Garg, Co-founder and managing partner at Together Fund. "They're not just automating tasks - they're rebuilding research infrastructure for the modern era. With their early traction across global agencies, Akshat and Arjun are showing what's possible when deep customer empathy meets technical ambition." Agencies such as Strat7 have reported tangible benefits from deploying Metaforms' platform. Tabita Razaila, Head of Operations at Strat7, said, "Our partnership has delivered strong ROI, thanks to Metaforms' exceptional service and prompt support." "They're solving a major pain point for the entire industry. That focus and ability to deeply understand customer needs and address that using genetic AI is the hallmark of Metaforms team. We are thrilled to back Akshat and Arjun in their journey of building a remarkable company!", said Jishnu Bhattacharjee and Arjun Gandhi, Nexus Venture Partners. Future plans Looking ahead, Metaforms has plans to triple the size of its team and further expand its agent capabilities, including the development of automated reporting, voice research, and expanded language support. The company's long-term goal is to process over 100,000 surveys per year, further increasing access to comprehensive market research across industries and company sizes. "When research agencies grow, better business decisions get made," added Akshat Tyagi. "We're not here to replace the humans in the loop. We're here to give them leverage."

Dawnguard raises USD $3m to embed security at design stage
Dawnguard raises USD $3m to embed security at design stage

Techday NZ

timea day ago

  • Techday NZ

Dawnguard raises USD $3m to embed security at design stage

Amsterdam-based cybersecurity startup Dawnguard has emerged from stealth with a pre-seed funding round totalling USD $3 million. The funding was led by 9900 Capital alongside a group of angel investors including scale-up founders and current CIOs and CISOs. This financial backing will be allocated to expanding Dawnguard's engineering team, enhancing enterprise integrations, and progressing the company's platform towards broader production deployments. Embedded approach Dawnguard has set out to introduce a new approach to cybersecurity by embedding security directly into system architecture, rather than bolting it on at later stages. This model ensures secure, compliant, and scalable systems from initial design through to deployment and beyond. "Our industry treats security as a checkbox. It's broken. We built Dawnguard because security needs to be part of the system's DNA from the start, not an afterthought. This is about aligning intent with reality, and giving teams the tools to enforce that alignment at the earliest stage and long after deployment," said Mahdi Abdulrazak, CEO of Dawnguard. Dawnguard's platform is designed to provide a collaborative canvas for engineers and security professionals, aiming to bridge the historic gap between system design and security implementation. The company distinguishes itself by not only scanning deployments or automating reviews but facilitating ongoing alignment of enterprise security goals within the architecture itself. The startup's founding team is composed of cybersecurity specialists with backgrounds at IBM, Microsoft, Amazon, and the military. CEO Mahdi Abdulrazak and CTO Kim van Lavieren lead the team, bringing substantial experience in running large-scale security operations and in applying artificial intelligence and machine learning to cloud environments. AI and automation at the core Dawnguard is building AI and machine learning engines to identify vulnerabilities during the design phase of IT projects and maintain security as systems evolve. This proactive model is intended to allow security decisions to be enforced early and consistently, addressing risks before systems go into production and responding dynamically as new vulnerabilities and threats emerge. "Dawnguard closes the gap between design and reality. We're giving teams the power to translate security intent into enforceable code so they don't have to rely on spreadsheets, static docs, or guesswork," said Kim van Lavieren. The platform targets security architects, DevOps engineers, and cloud teams. It enables users to validate cloud infrastructure designs pre-deployment, automatically generate production-ready Infrastructure as Code (IaC) using validated models, and keep enforcing security posture throughout the system lifecycle, helping to pre-empt issues and avoid post-deployment drift. Industry response and investment "Dawnguard isn't just building tech - they're rewriting the DNA of cybersecurity. In a world addicted to patching symptoms, they've chosen to re-engineer the root. That's not just bold - it's necessary," said Dimitri van Zantvliet, Dutch Railways CISO & Chair Dutch CISO Community, and a Dawnguard investor and advisor. "Hundreds of security tools overwhelm CISOs with promises of better detection, yet few tackle the root issue: design flaws in code that AI-driven threats exploit. As attacks grow smarter, defenses must shift left - embedding resilience at the codebase. We are excited to back Dawnguard, who build protection by design, not patch by necessity," said Chris Corbishley, Managing Partner 9900 Capital. Future plans Dawnguard intends to grow its platform capabilities to support increasingly dynamic operational environments. Plans include addressing the security risks presented by rapid AI-driven development methodologies and bridging the gap between quickly prototyped software and the infrastructure it runs on. The company is also working on a new operational model aimed at enabling organisations to create scalable, trustworthy systems that can better resist emerging digital threats. "With software moving faster than ever, security can't be stuck in the past," Abdulrazak said. "We're creating the platform that makes secure architecture not just possible, but inevitable." Follow us on: Share on:

Bitdefender launches advisory service to tackle security skills gap
Bitdefender launches advisory service to tackle security skills gap

Techday NZ

time2 days ago

  • Techday NZ

Bitdefender launches advisory service to tackle security skills gap

Bitdefender has introduced Bitdefender Cybersecurity Advisory Services to provide businesses with security consulting and access to specialised expertise. The service suite aims to address the operational and strategic security concerns of organisations by optimising existing security teams, identifying and closing security gaps, and providing assistance with regulatory compliance across environments such as cloud computing and third-party supply chains. The announcement highlights Bitdefender's intention to offer an integrated approach to security, spanning controls, prevention, detection, and response. A recent independent global survey of 1,200 IT and security professionals identified pressing challenges related to the cybersecurity workforce. Nearly half of respondents, 49%, reported that the skills gap in their organisation's cybersecurity capabilities had worsened over the previous year, while the same percentage indicated they were experiencing workplace burnout. The survey also indicated disparity in confidence levels between executives and middle management: 45% of C-level leaders expressed high confidence in their ability to manage cyber risk, compared to just 19% of mid-level managers. Market analysis from Gartner states, "Professional security services for 2024 had the highest market share with 35.5% or USD $27.3 billion (in current U.S. dollars). Interest in professional security services is rising due to increasing enterprise needs for third-party support, driven by skills shortages, alongside the growing demand for specialised expertise, including AI." Bitdefender's new advisory services are designed to address challenges organisations face in securing processes, technology, and personnel as attack surfaces expand. The offering also seeks to help organisations find and retain staff with skills in data laws, security leadership, and frameworks. Each client is provided with a tailored team, including a delivery manager, certified consultants, and a team lead responsible for coordinating assessments and keeping stakeholders informed of outcomes. The advisory services are structured to support Bitdefender's existing portfolios, including endpoint detection and response (EDR), extended detection and response (XDR), managed detection and response (MDR), offensive security services, or can be used as standalone offerings. Service pillars The new advisory services are categorised into three main areas: Strategy and Leadership, Risk and Compliance, and Event Preparedness. Under Strategy and Leadership, Bitdefender offers retainer-based advisory services to reinforce organisational leadership and provide comprehensive cybersecurity guidance. These services aim to enhance security teams, build strategic frameworks, and define measurable security outcomes. Bitdefender's team features experienced CISOs and security experts who bring sector-specific knowledge to their engagements. The Risk and Compliance pillar is focused on assisting organisations in navigating regulatory challenges by implementing and evaluating cybersecurity risk controls. Certified consultants assess compliance according to standards such as ISO 27001, NIST CSF, GDPR, HIPAA, and SOC 2, helping clients identify and remediate gaps. This is intended to improve business reputations and foster trust among customers and partners. Event Preparedness covers the development and assessment of incident response, business continuity, and disaster recovery plans. This service includes real-world scenario drills and table-top exercises to reinforce roles and responsibilities during potential crises, such as data breaches or natural disasters. "Effective security involves more than just technology – it includes people, processes, and regulatory compliance essential for global business," said Paul Hadjy, Vice President of APAC and Cybersecurity Services, Bitdefender Business Solutions Group. "Bitdefender Cybersecurity Advisory Services helps organisations understand their current security posture, address gaps, optimise strategies, and prioritise actions with expert guidance. These services complement our full portfolio including endpoint protection, MDR and offensive services providing a viable path to a much more streamlined and thorough cybersecurity operation." Bitdefender has confirmed the availability of the Cybersecurity Advisory Services for organisations seeking to enhance their cybersecurity programmes through on-demand, expert-led consulting and strategy.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store