
With two major peer-reviewed publications already to his name this year, enterprise architect and researcher Srinivas Kakarla is proving that his 2023 output was no high-water mark – it was a launchpad. His 2024 research targets two of the most expensive and most dangerous blind spots in cloud ERP today: the security architecture of cloud-native deployments, and the runaway cost structures that are quietly eroding the business case for hyperscale migration.
The cloud ERP era promised simplicity. What arrived instead was a new category of complexity – one dressed in the language of agility and scalability but hiding, beneath the surface, a set of structural risks that many enterprise organisations are only now beginning to reckon with. Chief among them: the security posture of cloud-native ERP environments that were migrated fast but hardened slowly, and the cost structures of hyperscale deployments that were designed for capability but budgeted for optimism.
Srinivas Kakarla has spent the better part of 2024 doing what he does best: turning hard, underexplored problems into structured, replicable frameworks. His two publications this year – one addressing the security and compliance architecture of cloud-native ERP, the other tackling cloud cost governance for enterprise workloads – land at a moment when both subjects have become urgent board-level conversations at organisations worldwide. The timing, as ever with Kakarla’s research, feels less like coincidence and more like calibration.
PUBLICATION ONE – SECURITY & COMPLIANCE ARCHITECTURE
“Security Hardening and Compliance Automation in Cloud-Native Enterprise ERP Deployments: Zero-Trust Principles, Role-Based Access Governance, and Audit Trail Architecture”
Published: April 2024 | Peer-Reviewed Research Article | Srinivas Kakarla
THE CONTEXT
When enterprises migrate their ERP systems to the cloud, they inherit a security assumption that is both widely held and dangerously incomplete: that the cloud provider’s native security controls are sufficient for enterprise-grade ERP protection. They are not. The access governance requirements of a large SAP deployment – with its layered role hierarchies, sensitive financial and HR data, cross-system integration touchpoints, and stringent audit obligations – exceed what any cloud platform’s baseline controls were designed to address.
The consequences of this gap are visible in a growing body of incident reporting and regulatory enforcement action. Misconfigured access roles granting excessive privilege. Audit trails that are incomplete, tamper-susceptible, or too scattered across services to be coherently analysed. Compliance postures that look sound on paper but buckle under the scrutiny of a regulatory examination. These are not theoretical risks – they are documented failure modes appearing with increasing regularity in cloud ERP environments at organisations that invested heavily in migration but underinvested in security architecture.
THE RESEARCH
Kakarla’s April 2024 publication addresses this gap head-on. The research applies the principles of zero-trust security architecture – the model that demands verification at every access boundary, assumes no implicit trust within the network perimeter, and requires continuous validation of identity and context rather than one-time authentication – to the specific structural characteristics of cloud-native ERP environments. In doing so, it produces something the field has lacked: a rigorous, ERP-specific interpretation of zero-trust that translates the model’s abstract principles into concrete architectural decisions.
The treatment of role-based access governance is particularly substantive. SAP environments are famously complex from an access control perspective: role proliferation, segregation-of-duties conflicts, and the challenge of maintaining least-privilege access across a system that spans procurement, finance, HR, and supply chain functions are perennial pain points for security and compliance teams. Kakarla’s framework addresses these challenges at the architectural level, proposing governance structures and review mechanisms designed to maintain access integrity across the full ERP lifecycle rather than treating it as a point-in-time remediation exercise.
“Zero-trust is not a product you buy – it is an architecture you build. Kakarla’s research gives cloud ERP teams the blueprint they have been missing.”
Equally significant is the research’s attention to audit trail architecture – the technical and procedural mechanisms that ensure every access event, data modification, and system interaction is logged, protected, and available for retrospective analysis. In a cloud-native context, where log data may be distributed across multiple services, stored in different systems, and subject to varying retention policies, constructing a coherent and tamper-evident audit record is a non-trivial engineering challenge. The architectural patterns Kakarla develops for this purpose represent a meaningful advance over the ad-hoc approaches currently prevalent in the field.
THE IMPACT
The practical implications of this research are far-reaching. For organisations currently operating cloud-native SAP environments, it provides a diagnostic framework: a structured lens through which to evaluate the security posture of their deployment and identify the highest-priority hardening actions. For those in the planning stages of cloud ERP migration, it offers something more valuable still – a design methodology that can be applied before deployment, avoiding the expensive and disruptive retrofit work that security gaps invariably require once a system is in production.
From a regulatory perspective, the timing of this publication is acute. The global regulatory environment for enterprise data security is tightening rapidly. Financial regulators across North America, Europe, and Asia-Pacific have all intensified their scrutiny of cloud-based ERP deployments in recent years. The compliance automation dimensions of Kakarla’s framework – which address not only what controls are required, but how their continuous operation can be verified and evidenced – are directly responsive to this regulatory trend. For organisations facing the prospect of external audit, this research offers both methodological guidance and an intellectual foundation for their compliance narrative.
PUBLICATION TWO – CLOUD COST GOVERNANCE & FINOPS
“Cloud Cost Governance for Enterprise ERP Workloads on Hyperscale Platforms: A Framework for Rightsizing, Reserved Capacity Planning, and FinOps Integration”
Published: August 2024 | Peer-Reviewed Research Article | Srinivas Kakarla
THE CONTEXT
Cloud economics were supposed to be simple. Pay for what you use, scale what you need, and shed the capital expenditure burden of on-premise infrastructure. The reality that has emerged across the enterprise sector tells a more complicated story. Cloud spend for large ERP workloads – particularly those running on hyperscale platforms such as AWS, Microsoft Azure, and Google Cloud – has proven consistently and substantially higher than pre-migration projections. The gap between the promised economics and the actual billing statements has become one of the defining frustrations of the cloud ERP era.
The reasons are structural. Enterprise ERP workloads are characterised by highly variable compute and storage demands, complex licensing interactions, integration traffic that generates often-overlooked data transfer costs, and the kind of long-term capacity requirements that make on-demand pricing models systematically expensive. Without deliberate governance mechanisms – frameworks for rightsizing resource allocations, planning reserved capacity commitments, and integrating cloud financial management as an operational discipline – organisations consistently overspend, often by margins that materially affect the return-on-investment calculus of their cloud migration programme.
THE RESEARCH
Kakarla’s August 2024 publication is the first piece of rigorous, peer-reviewed research to address this problem in the context of enterprise ERP workloads specifically. The FinOps discipline – the practice of applying financial accountability principles to cloud operations – has developed a substantial body of practitioner knowledge in recent years. But the ERP domain has specific characteristics that generic FinOps guidance does not adequately address: the licensing complexity of SAP environments, the interdependency of ERP workloads with integration middleware and database services, and the long-term commitment horizons that sensible capacity planning requires.
The rightsizing framework Kakarla develops is grounded in the operational reality of how ERP compute and storage resources are actually consumed – the peak-and-trough patterns of period-end processing, batch workloads, and real-time transactional activity that characterise SAP environments. Rather than applying generic cloud rightsizing heuristics that were developed for stateless application workloads, the framework is calibrated to the specific demand signatures of enterprise ERP, producing recommendations that are both technically achievable and commercially meaningful.
“Enterprise cloud bills are not a technology problem. They are a governance problem – and governance problems have frameworks.”
The reserved capacity planning component of the research deserves particular attention. The decision of whether, when, and how to commit to reserved cloud capacity is one of the most consequential financial decisions an enterprise technology organisation makes in the context of cloud operations – and one that is routinely made without adequate analytical structure. Kakarla’s framework provides that structure: a decision methodology that accounts for workload stability, business planning horizons, and the specific discount economics of major cloud providers, producing commitment recommendations grounded in rigorous analysis rather than intuition.
The FinOps integration layer of the research is equally important. One of the persistent failure modes in enterprise cloud cost management is the disconnect between the technical teams who design and operate ERP infrastructure and the finance and procurement functions that own the commercial relationship with cloud providers. Kakarla’s framework addresses this organisational gap directly, proposing integration mechanisms – reporting structures, accountability models, and joint review processes – that align technical decision-making with financial outcomes in a sustainable and operationally practical way.
THE IMPACT
The financial stakes that this research addresses are substantial. Industry benchmarking consistently shows that large enterprises running ERP workloads on hyperscale cloud platforms are overspending by between twenty and forty percent relative to what optimised configurations would cost. For organisations with significant cloud ERP investments – and across the Fortune 500, virtually every organisation now falls into this category – that represents tens or hundreds of millions of dollars in recoverable annual expenditure.
Beyond the immediate cost implications, the governance framework Kakarla proposes has strategic significance. As cloud ERP programmes mature from migration phase to steady-state operations, the ability to manage, predict, and optimise cloud expenditure becomes a core capability of the enterprise technology function. Organisations that develop this capability early will find themselves with structural cost advantages relative to competitors still managing cloud economics reactively. Those that do not will face mounting budget pressure as their cloud bills grow and their governance mechanisms fail to keep pace.
THE BIGGER PICTURE: A RESEARCHER WHO READS THE ROOM
What is striking about Kakarla’s 2024 research agenda is how precisely it tracks the concerns that are dominating CIO and CISO conversations at this moment. Security and cost are not merely the two most discussed topics in enterprise technology today – they are the two topics where the gap between the sophistication of the problem and the maturity of available methodological responses is most acute.
His two 2024 publications address exactly this gap, and they do so in a way that is continuous with the body of work he has built over multiple years of research. The security framework builds naturally on his prior investigations of hybrid connectivity architecture and SAP integration security, extending that earlier work into the cloud-native context. The cost governance framework complements his earlier research on advisory governance and programme delivery models, applying similar structured-framework thinking to the financial management discipline. The cumulative effect is a research portfolio with genuine intellectual coherence – one in which each new contribution is enriched by what came before it.
For the enterprise technology community, the value of this kind of sustained, cumulative scholarship is difficult to overstate. Individual publications can offer isolated insights; a body of work offers something more durable – a conceptual infrastructure that organisations can draw on as they navigate not just the challenges of today but the challenges that will define the next phase of enterprise ERP evolution. Kakarla is building that infrastructure, one rigorous publication at a time.
With the second half of 2024 still ahead, and with a research track record that has produced meaningful contributions in every year of active publication, the enterprise technology community will be watching to see what Kakarla turns his attention to next. If his 2024 output is any guide, the answer will be whatever problem matters most – and whatever problem the field is least equipped, today, to solve without him.
