Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

How ING Scales Banking with Hybrid Cloud

Red Hat
10/06/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


the one that we have to talk about is AI. You love that experimentation, you want to encourage that experimentation, but in a safe and compliant environment. So obviously we take digital sovereignty and compliance seriously. Why shouldn't you? Our strategy is basically to stay compliant by design. It's a principle. It is a bit part of our DNA not being locked in. We retain that freedom to deploy workloads where it makes most sense. So Marco, ING is a global bank with of course a strong European focus. You serve millions of customers all around the world and you enable them, right? You enable your customers and your partners to be successful. Tell us a little bit about your technology environment, your platform that helps them be successful at what they do. Yes, indeed. Our tech environment is engineered to serve more than 40 million clients and roughly 7,000 partners. We do ensure 24-7 availability for our customers. To achieve that, we build heavily upon our resilient infrastructure, but we also, through our architecture, provide a global unified customer experience. In doing so, we maintain, obviously, our strong security and being compliant, which is essential. For our partners, we have built an open banking platform with standard APIs and a developer portal that enables them to integrate and innovate with our systems and obviously through our secure gateway. Right, right. Well, it's obviously critical to make sure that partners or customers are successful in doing their role and are able to innovate, to keep growing. But along with this sort of growth, oftentimes creeps in complexity, right? Inevitable in our business. And we both know that complexity is the enemy in IT. Over the last few years, what steps have you taken to streamline this complexity, to make yourself more agile, to allow for these customers and partners to keep innovating? Complexity is indeed perhaps the main enemy. We tackled our massive tech landscape, so to say, by relentlessly streamlining and standardized simplifying for that matter. And in doing so, we have decommissioned redundant local systems in the last couple of years, which we're now accelerating, by the way. We found our path, so to say, to decomplexify. This is also what we call our scalable tech approach. Our whole strategy is around the scalable tech approach, consolidating onto global platforms, simplifying our architecture, eliminating duplication, and basically all the buzzwords make sense, but really drive consistency across our countries. We are a federated organization. We have, let's say, made impact in the past with ING Direct, but in doing so, created a federated organization. So now we need to simplify and basically get rid of that legacy onto our new or our global enterprise stack with some best practice design patterns. In doing so, we are reducing complexity. We have seen the proof points already around now that we have found this path. We have built reusable capabilities. So now you see the speeding up, reducing of cost and reducing complexity. But the starting and end point for that means is global reuse and simplicity first. So if there is a capability already available, being built, it starts with reusing or consuming that specific capability. Well, it's a really interesting thing that you talked about there, right? So you've got this global approach that you take, and then you said you have federated structure. Yeah. And presumably, you've got to sort of balance innovation, right, because you want each group to work faster, and then, well, you don't want to create more complexity if each one of them is working differently. So I guess, you know, two-part question. One, how do you balance, right, between the global and the federated? And then two, you know, does cloud help you here, like either private cloud, public cloud, hybrid cloud? Like, how does all of that interplay? That is a valid question. And indeed, also a bit the problem to solve, you might say, because you look at our, let's say, our tech landscape about 10 years ago, it was really, everything was different. Hardware, software, middleware, patterns, everything. But agility is really in our DNA, so to say. So how, indeed, your question, how do you keep that agility, that creativity, and still move to a, not so much a federated stack, but a unified stack? And for that, indeed, we use, we have a multi-clouds approach. We have an open standard strategy to indeed maximize the flexibility. You want to keep that creativity in, although you are basically on the same strategy and the same platform. So these platforms are also built cloud agnostic, so to say. So we run our containerized Kubernetes clusters, obviously, so applications can move around, switch around easily. And for that, we prefer also open source tools and a standard APIs. So no proprietary solutions here or minimize as much as possible. As you can see, we would be big fans of that approach. Right? I sort of can imagine that. Let's talk about that then for a little while, right? So you've talked about open source, open standards, commitment to that within ING. Obviously, there's this idea of agility and is that compatible with vendor lock-in and what trade-offs do you sort of have there? How has that really impacted the culture at ING? Is this now something that's within the DNA? Is this something that you're constantly always working on? Yes, indeed, it is a bit part of our DNA, not being locked in. Also considering a little bit the geopolitical challenges that we face nowadays, it's probably even more helpful not being locked in. Our platform is also designed to be cloud agnostic. For example, indeed, we run on containerized Kubernetes clusters. So our application can move around easily between, well, basically different clouds or premises without rework. Very, very important, obviously. So we prefer open source tools and standard APIs and let our engineering choices prevail, if you might say it like that. This also ensures portability, especially in the challenging times that we're in. So by using industry standards like standard container orchestration, we retain that freedom to deploy workloads where it makes most sense. And I think, or we think, that this approach also keeps our technology architecture agile. So we love creativity, we love autonomy. So we don't want to be constrained by one single vendor. So this flexibility works, but obviously within the guardrails, essentially. And that naturally leads me to start thinking about empowering developers and developer experience. What are you doing at ING to ensure your developers have that agility, have the tool that they can be successful? Across ING, I think we have roughly around 50,000 employees, but 18,000 out of them are, let's say, techies, engineers. So that's a substantial part of ING. So obviously we take the experience of our developers seriously, empowering them to engineer, to unleash their creativity, so to say, while ensuring compliance. That is probably another cornerstone. And one is the standards, technology standards. The other one is the experience of our developers. In the last couple of months or the last year, we have created a unified engineering platform, which we call One Engineering System, in an area that is headed by Danny Wijnand, a personal friend, but a great colleague, R. Steve Jobs, so to say. And it provides an integrated, self-serviced platform with golden paths and a single developer portal. I really love it, and I'm also pretty sure that he worked together with you guys on that, also to learn from the industry and really take it to the next level. It gives our developers autonomy to build and deploy quickly with all the best practices and security controls baked in. To give you an example, our ING Resource Manager, so to say, it automates infrastructure for each of our policy guardrails. Our teams get what they need, basically minutes instead of hours. And with that, we also shift compliance, basically left. Yeah, it is baked in our systems right now. The controls are there. It provides all the trails, for example, not specifically my cup of tea, but it takes away a little bit of toil and the heavy lifting for our engineers. It's baked into the system, so they basically can engineer with confidence. So, Marco, whether it's developer experience or it's technologies for Kubernetes or cloud native authorization, automation, we've had the pleasure, right? I personally, the entire Red Hat team, I've had the pleasure of working with you, with Danny, many others at ING, become successful. And we've loved this collaboration. What's the ING perspective on the work that you've done with Red Hat? What are the areas that you feel like we've really excelled in together? From a tech perspective, we already mentioned Danny. I know he's a big fan. He works closely together with you in, let's say, developing this one engineering system. A little bit from a distance, but also my personal reflection, a really good collaboration open, transparent. We share a lot. We share insights, what's new, what's happening, what can we learn from the ecosystem? These are some of the problems to solve. And I love the open conversations that we have around that. And every time when I have a discussion with you, I always get out with at least one or two new ideas to add to the pile of ideas. So I love the collaboration that we have. So talking about collaboration, talking about areas to work together on, the one that we have to talk about is AI. Obviously. And everyone in the industry is talking about it, right? There's everything, right? With regard to the huge amount of productivity that will potentially unlock for folks. All these stories about token maxing and using a lot of AI. And then there's some fear and concern around AI. What's your stance, Marco, and representing some of the ideas that ING has, how do you think about AI? Where are you on that journey? Although we are already two or three years in this journey, and it started earlier, especially also in our data analytics area, but to a certain extent, it just started. When AI really sort of hit us, it was 2022, I think, when Chad GPT was bought or sold, a lot of people in ING were already experimenting with it. New technology, great. Let's make our hands dirty. In fact, we were probably using machine learning from a long time, right? Indeed, indeed. So a lot of people were already working with that. On the one hand, you want to stick to that freedom, this creativity. On the other hand, and that was badly needed as well, some cartwheels. You love that experimentation. You want to encourage that experimentation, but in a safe and compliant environment. That's also what we have been creating, that what we call an emerging technology area, sort of a funnel of innovation, what's coming our way. Currently, yes, it is AI. Yes, we have built our Google-hosted Vista platform that basically enables every use case that is around. The current use case are a bit more on optimization, you might say, in customer engagement, or recently we went live with our mortgage application. But to a certain extent, it has only begun. If you move to an agent-first kind of organization, what would that mean for your way of working, your operating model, new businesses that might evolve? So that is a bit where we are today. Yes, we have created a Vista platform, what we call our Vista platform. It enables innovation or working with AI. We encourage it through hackathons, but also through this, let's say, this funnel of new technologies coming our way, and let's see, let's do that in a structured way. Where can we find some proofs and then industrialize? And that is a bit where we are today. Yeah, well, Marco, you asked a very interesting question. You said, what if we moved to an agent-first organization? And at Red Hat Summit, we explored these themes, right, around security, agent ops, this idea of guardrails, red teaming, all of these aspects that become really, really important, right, when we think about agents and an agentic AI environment. Security, though, is paramount. What are your thoughts on that? Yeah, we discussed the digital sovereignty, security, compliance, especially in the regulated environment like finance. I would say security compliance is embedded, it's in our design, in each and every layer. We follow a, basically, a zero-trust networking model, secure by default principles. For example, all our internal APIs are authenticated, data access strictly governed. Next to that, consciously invest in cyber defense, monitoring IT risk controls in place. But in practice, you also want to open up. That is also part of our architecture. So you also want to have guardrails in place like access controls or observability, for that matter, automated compliance checks. But at least for us, this feels like we are in balance. On the one side, all these mechanisms in place. On the other side, for example, our DevEx, embracing new technologies, it still allows us to move fast, but also safe. We also have a nice engagement with our C-suite, and we will elaborate a little bit more on, so what is next? What does it mean, an agent-first operating model? How do you bring everything into that model? Yeah, you touched on so many themes here, right? Sorry for that. No, no, no, right? My head is full with these. It is fascinating, right? Because we start off, I feel like, a conversation around agility. You went to openness, open standards. You brought up compliance. We talked about security. We started with a lot of agentic ops and observability, and then implications around that, and so on. We talked about sovereignty. And so I feel like we covered a lot of ground. Let's just look ahead to the extent that we can, next whatever, one, three, five years. What's top of mind? What are you focusing on? What are the big initiatives for you? Where we are today, we are still in, let's say, the digital transformation, the legacy transformation. So yes, we have defined our path. We know what to do. We have our scalable tech moving into a scalable bank. And not only, let's say, the prerequisites, but also the global business solutions that you want to have in place. We defined the standards, the technology standards. We have the tools in place. But we are still a federated company, and everybody comes from a different background. So first, and mostly, finish what we have started. Relentless on that. Keep focus, keep track, show and tell. It is proving value. We are reducing double run costs, because that is also an element of the transformation that we're in. You could call it the transformation dip. Once you're in that transformation, you hit some unexpected elements as in double run cost. Old systems, new systems, in parallel, double run cost. How do you squeeze that out? The next couple of years is predominantly about accelerating that journey to be ready for the next transformation that is coming up. New operating models, new business models that derive from AI, from agents. How would that work? First of all, be ready to work with AI. Fortunately enough, we have a culture that embraces change and new technologies. That is good, but you need to be ready for that. I feel like all of these areas you've touched upon sort of lead us naturally into sovereignty and digital sovereignty. So tell us a little bit about your approach here. Do you feel like you have a strategy that others can learn from? Do you feel like you're in the early stages of this? What can you share here that would be interesting? A valid question, very actual question. And I think we can learn a lot from each other. So obviously we take digital sovereignty and compliance seriously. Why shouldn't you? Our strategy is basically to stay compliant by design. It's a principle. It's the key principle for the matter. While benefiting from that multi-cloud ecosystem, we have adopted a cloud smart multi-vendor strategy. So more sensitive or regulated data runs on our private cloud. While less critical ones, we can leverage public cloud for the matter or whatever vendor is around. It avoids over-reliance on a single vendor. So we obviously have also some internal checks. Is there an alternative, yes or no? Is there a European alternative possibly available? So constantly we make conscious choices and shift wherever it's needed. But you have a lot of good ideas. You've shared a few of them already. And then I'm sure your other leaders, your colleagues at ING do as well. What's your advice to technology leaders who are listening? What can they learn from this? What should they be thinking about? Look what's happening in the outside world, outside of your company, outside of your industry, and how to adapt, how to apply to your own environment and the problems that you face yourself. Having said that, we're all in a journey. ING is in a journey. We have always been a bit of a front runner from a tech perspective, but in doing so, you constantly create new legacy. In trying to solve that problem, be relentless, keep your eye on the ball, keep track. You will face difficulties. We have faced difficulties ourselves. Let's call it the transformation dip. Yeah, great plan. We built something new. In doing so, in integrating, implementing, you still run your old stack. So basically, you have a sort of a double run kind of situation. You need to go through it as fast as you can. So be a bit stubborn on the vision that you have, the plan that you have. A bit more flexible on the details. And every now and then, show and tell, but also be aware that not everything is shiny always. So also go all the way through the hard part of the transformation that you're in. Yeah, I love the dual aspect that you called out, which is, on the one hand, invest in making sure your future, where the shiny object is, on the other hand, do the hard work to run the bank. Transformation is hard work. Yeah, yeah, yeah, right? Keep that vision in mind, but be flexible on the implementation. As you know, Red Hat's been committed to open source for 20 plus years. And this is something that I think we share, right? This commitment to open source, open standards, collaboration. We've worked very closely together for quite a while. But looking ahead, what are the other areas of collaboration? Where else do you think that we can lean in to help you and your team become successful? Well, you in detail already mentioned it, open source, this openness. Let's extend it to the word open. This is also what I feel in the relation that we have. And I see that also in our teams. This open conversation, learn from each other, explore new technologies or new practices for that matter. And especially in our engineering space, I see that happening a lot. So I'm really looking forward to say that the next chapter in our relation with the new challenges that we are facing with this portability, flexibility that we're all looking for, especially in this VUCA world that we live in. So my hope indeed also for the future is that we continue this conversation and work together, learning with each other, making use of the ecosystem that we have together and start exploring, let's say, new frontiers. Yeah, well, it's certainly a commitment, right? We want to make sure we're continuing to invest in the foundation, right? Whether it's Linux technologies or cloud native, Kubernetes types of technologies, but then also help ensure that we're preparing you for the future and the innovation that's to come. So thanks again, Marco. This has been a delightful conversation. Likewise. Happy to have you as a partner. Thank you very much.

TL;DR

  • ING serves 40 million+ clients across a federated global structure and is actively consolidating onto a unified, cloud-agnostic technology stack to eliminate duplication and reduce costs.
  • The bank's anti-lock-in strategy relies on containerized Kubernetes, open source tools, and standard APIs, enabling workloads to move freely between private cloud, public cloud, and on-premises without rework.
  • ING's 'One Engineering System' gives 18,000 engineers a self-service platform with compliance and security controls built in, reducing provisioning time from hours to minutes and shifting compliance left.
  • AI experimentation is structured through a 'funnel of innovation' and a Google-hosted Vista platform, with current use cases in customer engagement and mortgages, and longer-term focus on agentic AI readiness.
  • Digital sovereignty is treated as a design principle: sensitive data stays on private cloud, vendor dependencies are actively audited for European alternatives, and zero-trust security is embedded at every layer.

ING's Scalable Tech Approach

ING is a global bank serving more than 40 million clients and roughly 7,000 partners, requiring 24/7 availability and a resilient, globally unified infrastructure. Marco De Jong, Enterprise Architect at ING, explains how the bank tackled its historically fragmented, federated IT landscape by adopting what it calls a 'scalable tech approach' — relentlessly decommissioning redundant local systems, consolidating onto global platforms, and eliminating duplication. The guiding principle is reuse first: if a capability already exists, teams consume it before building something new. This discipline has already demonstrated measurable proof points in reduced cost and complexity, and ING is now accelerating the pace of legacy decommissioning.

Cloud-Agnostic Architecture and Anti-Lock-In Strategy

ING's platform is deliberately designed to be cloud agnostic, running containerized Kubernetes clusters that allow applications to move between private cloud, public cloud, and on-premises environments without rework. The bank favors open source tools and standard APIs over proprietary solutions, a stance De Jong describes as embedded in ING's DNA — and one that has become even more strategically important given current geopolitical pressures. Sensitive or regulated data runs on private cloud, while less critical workloads leverage public cloud providers. ING actively evaluates whether European alternatives exist for any given vendor dependency, making conscious, auditable choices to avoid over-reliance on any single supplier.

Developer Experience, AI, and Zero Trust Security

With 18,000 engineers out of roughly 50,000 total employees, ING treats developer experience as a strategic priority. The bank has built a unified 'One Engineering System' — a self-service platform with golden paths, a single developer portal, and an ING Resource Manager that provisions infrastructure in minutes rather than hours, with compliance controls baked in from the start. On AI, ING has been experimenting since before the ChatGPT wave, using a Google-hosted 'Vista platform' to enable use cases in customer engagement and mortgage applications, while exploring what an agent-first operating model would mean for the business. Security underpins all of this: ING follows a zero-trust networking model with authenticated internal APIs, strict data governance, automated compliance checks, and active cyber defense monitoring — balancing openness with rigorous guardrails.

Chapters

0:00 - ING Technology Environment Overview
1:54 - Tackling IT Complexity at Scale
4:48 - Cloud-Agnostic Multi-Cloud Strategy
7:22 - Developer Experience and One Engineering System
11:13 - AI Strategy and Emerging Technology
13:39 - Zero Trust Security and Digital Sovereignty
16:47 - Advice for Technology Leaders

Key Quotes

1:54 "Complexity is indeed perhaps the main enemy. We tackled our massive tech landscape, so to say, by relentlessly streamlining and standardized simplifying for that matter."
5:55 "It is a bit part of our DNA not being locked in. Also considering a little bit the geopolitical challenges that we face nowadays, it's probably even more helpful not being locked in."
8:08 "It gives our developers autonomy to build and deploy quickly with all the best practices and security controls baked in."
13:47 "I would say security compliance is embedded, it's in our design, in each and every layer. We follow a, basically, a zero-trust networking model, secure by default principles."
17:45 "Our strategy is basically to stay compliant by design. It's a principle. It's the key principle for the matter."
19:42 "Be a bit stubborn on the vision that you have, the plan that you have. A bit more flexible on the details."

FAQ

How does ING prevent vendor lock-in while still operating at global scale?

ING runs containerized Kubernetes clusters that allow applications to move between clouds and on-premises environments without rework. The bank mandates open source tools and standard APIs, avoids proprietary middleware, and actively evaluates whether European alternatives exist for any vendor dependency. This cloud-agnostic design is treated as a core architectural principle, not an optional preference.

What is ING's 'One Engineering System' and how does it work?

One Engineering System is ING's unified developer platform, built with golden paths, a single developer portal, and an ING Resource Manager that automates infrastructure provisioning within minutes. Security and compliance controls are baked in by default, so engineers can build and deploy quickly without manually navigating policy requirements. The platform effectively shifts compliance left, embedding it into the development workflow rather than treating it as a downstream audit step.

Where is ING in its AI journey and what guardrails does it have in place?

ING has been working with machine learning and data analytics for several years and accelerated AI experimentation after ChatGPT's emergence in 2022. The bank channels new AI initiatives through a structured 'funnel of innovation' and a Google-hosted Vista platform that supports use cases in customer engagement and mortgage applications. Experimentation is encouraged through hackathons, but always within a safe and compliant environment — with the longer-term question being how an agent-first operating model would reshape ING's business and workforce.


Categories:
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Zero Trust
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • Data Protection
  • Zero Trust
  • AI & Machine Learning
  • Backup & Recovery
  • Customer Story
  • Best Practices
  • Hybrid cloud architecture
  • Vendor lock-in avoidance
  • Kubernetes and containerization
  • Developer experience platforms
  • Zero trust security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: How ING Scales Banking with Hybrid Cloud

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 10/13/2026
                      01:00 PM
                      10/13/2026
                      Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                      https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Leveraging CISA’s Zero Trust Maturity Model for an AI-Driven Landscape
                      https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-for-an-ai-driven-landscape/
                    • 11/04/2026
                      11:00 AM
                      11/04/2026
                      Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                      https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                    • 11/05/2026
                      01:00 PM
                      11/05/2026
                      HUMAN Dialogue: Redefining Authentic Trust in the Agentic Internet
                      https://www.truthinit.com/index.php/channel/2160/human-dialogue-redefining-authentic-trust-in-the-agentic-internet/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version