What to Look for in Billing and Accounting Software
It becomes increasingly difficult to manage a business when financial documents are scattered in different documents. There are invoices, payments, taxes, and inventories that have to be updated on a regular basis. Manual procedures may result in errors that will require time to correct. A good billing and accounting software can help manage these processes in one place. The accuracy of the financial records, saving time and making routine tasks easier to accomplish for everybody are the main benefits that any business can obtain. The use of software is beneficial for small businesses and big enterprises since it helps reduce paperwork and improve financial record management. Some companies even combine their accounting software with call center software and keep the information about customers, invoices, and the history of services provided at hand during each call.
Features Useful for Daily Business Processes
First of all, one needs to consider whether the software does all the necessary business-related functions. Full-fledged billing and accounting software will be able to perform invoicing, payments, purchase processing, and financial reports preparation without using several applications. An inventory management system may be helpful because it automatically updates the stock after every transaction made.
GST billing, tax calculation, and customer accounts management are time-saving features as well. In companies where customers contact them by phone, the application can be integrated with call center software. It will enable customer support specialists to see the information about invoices and payments while talking to customers.
User-Friendly and Scalable
Ease of use is one of the primary characteristics that software should have. Employees will be able to master the software easily without spending months on training thanks to a user-friendly dashboard. The clear menu structure, organized reporting, and convenient navigation will help staff perform their tasks more efficiently.
Business requirements are subject to change over time. There can be an increase in the number of employees, expansion of branches, and an increased customer base. The chosen software should be able to accommodate all these changes without needing to be replaced completely. It is good for growing businesses to have multi-user support, cloud storage, automated backups, and data protection. At the same time, if the business uses call center software, the integration of both is important.
Reports, Security, and Integration
The owner of the business must receive reports on time to make decisions. A good billing and accounting solution must have reports on sales, purchases, profit, cost, tax, and overdue payments. Reports at real time give an opportunity for managers to control the activity of business without delay until the end of the month.
The security of financial records is an important issue too. The business information is kept in financial records, and it is necessary that the system provides protection of data via user permissions and data backups. It is good when integration with other solutions is provided. Companies integrate accounting platforms with inventory systems, CRM, payment gateway, and call center software.
Conclusion
The selection of the correct billing and accounting software is not just about generating invoices. It is about choosing an application which will help your business run smoother, maintain proper records and save a lot of time. Software which has the ability to generate reports, manage inventory, deal with taxes, has security measures in place and is easy to navigate will definitely make your life easier.
In addition, the software which integrates with other business tools is highly beneficial. The integration with call center software, for example, will allow customer service employees to have access to all the billing information instantly and be able to give better service.
Remote Access Trojans are the family of malware I see most often in my research. Sure there are infostealers and denial-of-service bots galore out there, but it always seems to come back to the ‘basics’, the one that slips by unseen by user and security software alike, leaving behind backdoors and persistent traffic feeding data to the control-and-command actor. And more and more often, they’re hiding in GitHub repositories.
The first of the two reports on the topic in my news feed today is an overall study of how GitHub and GitLab are being exploited. Cofense took a look at data spanning from 2021 to 2025, and found a significant rise in abuse among open source repositories and/or cloud native services. Fully 45% of attack campaigns happened in 2025 alone, nearly equaling the amount collected in the previous four years. Within those attacks, most of them were targeting GitHub, with just 5% aimed at GitLab (which tracks for me as a researcher; I hardly ever hear about GitLab campaigns). 58% delivered credential phishing, while 42% contain malware. Sometimes those overlap and do both. The malware seen is almost invariably some form of RAT.
The second comes from Aikido, and is a more specific breakdown of an ongoing campaign using GlassWorm. I’ve covered the Shai-Halud offshoot before (here and here), and it is still using the same tactic now, where it infects OpenVSX extensions to propagate itself. The current iteration of the malware is impersonating WakaTime, the popular developer time-tracking tool, and ships a Zig-compiled native binary alongside its JavaScript code, inserting a persistent dropper (one of its hallmarks) into the extension. From there, it infects every Integrated Development Environment (IDE), the software that works to provide users with consistent experiences as they use disparate tools. This campaign is affecting both Windows and macOS.
So why the uptick, and why RAT’s? The answer to both has to do with business done at machine speed, exploited trust, and the way RAT’s work in the first place. Code repositories store all the related files and documents involved in developing new software, and Git is a version control system (VCS), meaning that developers who need a specific branch of code can find it easily and make changes to it without losing any of the work done by others. It’s a way to share files by making each one instanced to the user (this being a code mechanic in gaming that allows multiple assets to be available in the same place regardless of how many people are utilizing them). In short, it makes a fully malleable copy or version. Inserting a Trojan into the files is not hard, given that most repositories are open source, or otherwise have low authorization requirements in order for them to be available to so many. And all it takes is one compromised file or line of code buried beneath layers of legitimate programming to infect whole development trees. Social engineering – abusing the users’ trust in the sites – does the rest.
Trojans, by nature of their intrinsic obfuscation within legitimate programs, can be difficult to remediate. Upon download they often rename themselves as something else, delete the data from the download folder so the user can’t find it, or are so embedded within whatever they rode in on that one cannot simply uninstall to take care of the problem. During my training, I had at least two assignments that involved locating the presence of a RAT, hunting through individual logs to find those run-rename-delete commands. It’s time consuming. It is generally easier to just release a new, clean version of compromised software than try to root out the initial infection. Reports such as Cofense and Aikido’s are most often warnings to be aware of infected packages and programs, usually with version numbers – both compromised and clean – so that users can check if they’re running an affected one. And it’s my job as your friendly neighborhood WISP to ensure that they don’t get buried under other news.
There's a currently ongoing scam pattern on Discord where a stranger pretends to mistake you for a gaming contact, then tries to initiate conversation and eventually encourages you to download a game or app — often leading to financial fraud, phishing, or malware infection.
Typical scam process:
- A random person sends a message claiming mistaken identity, saying they thought the recipient was a friend or someone they play a game with.
- After being corrected, the scammer remains friendly, introduces themselves, and discusses gaming topics or invites further chat.
- The conversation typically shifts towards an invitation to download a particular game or client, suggest testing a new "game" for money, or redirecting the victim to a website or file.
- Sometimes the game is genuine, but they want the user to download it through a link that's actually malware or a phishing site, or it may try to steal Discord credentials or personal information.
- In some documented cases, the scam's goal is to get victims to spend money on a seemingly legitimate game, with payments redirected to the scammers rather than actual game providers.
Red flags to look out for:
- Unsolicited friend requests and conversations from strangers, often with broken/awkward English or generic introductions.
- Pushing download links, beta testing offers, or requests for help with a "new project"—often promising rewards like money, game items, or Discord Nitro.
- Redirection to unofficial websites, especially for game downloads or account logins.
- Conversation persistence even after it's clear the user doesn't actually play the mentioned game.
How to avoid the scam:
- Always ignore and block unsolicited contacts who behave in this pattern, especially if they try to move you to new servers or ask you to download anything.
- Never download software or visit websites provided by strangers, even if the offer seems legitimate or comes from someone claiming to be a gamer friend.
- Be skeptical if the conversation quickly moves from apology to personal introductions and game discussions, especially when tied to external links or downloads.
This scam exploits social engineering and the trust of gaming communities. Staying alert and cautious around unsolicited invites or conversations—even those that seem innocent—is the best defense.
Client this morning: …also I really like the software you used to present this call flow, what is it?
Me: it’s called lucidchart, and I also like it. Very user-friendly and easy to update in the fly, as you saw.
Later
CC(customer)O: can you send the design doc
Me, assuming he meant the design for the call flow: yep sure *puts link to lucid in teams chat*
CCO: no the JSON document—ugh WHY is this a lucid??? We are NOT a lucid company anymore, we need to be generating with Claude because by the time the lucid is made it’s already out of date and you need to update it
Me, tired of the months of slander: well, this is a template that [other client] approved for when we build designs for their clients, and it’s really the same thing with Claude, no? Either way they need updating and the clients I’ve had like the lucid—
CCO: let’s just take this offline, I’m not going to talk to you about this now
😀 totally functional company, totally normal senior leadership getting deeply involved in every project and micromanaging how designs are done, totally absolutely normal 😀
But the same clever new attack could be used against almost anyone.
Claudie Weber is a senior program advisor at the U.S. State Department. She got in touch with me by email in May, looking to discuss “recent developments” and copying several of her departmental colleagues. That’s not unusual for people in my line of work. What was slightly less common was that “Claudie” didn’t exist, and neither did any of her colleagues with State Department addresses. The approach was part of a careful plan to break into my Gmail account. And it seems to have succeeded.
For professional Russia watchers such as myself, being the subject of unwanted online attention comes with the job. Crude attempts at hacking and phishing are more or less constant, and every now and then we encounter something genuinely novel or clever. Back in 2019, I blew the whistle on an online deception campaign using LinkedIn that was the first documented instance of a deepfake-generated face being used as part of such an operation. A couple of years later, a well-constructed phishing attempt had me half a second away from clicking on a deceptive link that appeared to be an appointment reminder from my actual, real, optician.
But Claudie’s efforts were different again. The operators behind the name carefully, painstakingly brought together a number of different pillars of plausibility, and unlike on previous occasions, they didn’t put a foot wrong. For instance, they plainly knew that the first thing I would do was write back to her “colleagues” at their state.gov addresses to see if they existed—but they also knew, which I didn’t, that the U.S. State Department’s email server accepts all incoming messages and won’t show you an error if you write to nonexistent people.
What followed was a slow, patient, and ultimately successful process of coaching me into opening up a backdoor to all of my emails.
The hacking of my email account has been described in detail by the University of Toronto’s Citizen Lab, an organization dedicated to protecting civil society against state campaigns of this kind, and you can read some of the email traffic with “Claudie” in their report. Google’s Threat Intelligence Group has also reported on the operation and linked it to others that they tentatively associate with the Russian Foreign Intelligence Service.
The attack used a feature in Gmail and other apps called an application-specific password, or ASP. That’s a means of creating a special password so that you can still use older or less secure apps that don’t support modern security protocols.
And that’s where the problem lies: ASPs are a widely available means of bypassing all of the security precautions that we are all told so insistently to make sure are in place, such as getting verification codes sent to our phones. The feature is supported by Microsoft, Apple, Google, and other platforms as a seemingly routine technical workaround when other security systems don’t work, with little to no user-friendly warnings about how dangerous a tool such as this can be.
Importantly, the hack didn’t exploit some technical vulnerability in the software. As Google has pointed out, there “wasn’t a flaw in Gmail itself”; instead, “the attackers abused legitimate functionality.” That is correct: The ASP setup worked exactly as intended. The attack worked by convincing me to set up a route into my account that is built in by design, rather than by outwitting the security and breaking in. In the most literal sense, this backdoor to our email accounts is not a bug but a feature.
But there’s a problem with that. The fact that there is a widely available option to bypass today’s security precautions and throw your account wide open was an unexpected discovery not just for me, but also for anybody I’ve spoken to who isn’t deep in the cybersecurity business.
So for Google to say that “there is no vulnerability connected to Google’s application-specific passwords” is, again, technically correct but potentially very misleading in terms of how easily ASPs can be exploited—as demonstrated by my case and by however many others there might be by now. (I seem to be the first person who has gone public about being targeted in this way, but I’m sure I won’t be the last.)
As Google has also pointed out, users get a notification email when they create one of these passwords. But that’s of limited use when you already know that you set one up, whether or not you were deceived into doing so.
Because everything worked as intended, there was no way that I could see that anything was wrong. To Google’s credit, it was its security systems that eventually noted that something was amiss and caused my account to be frozen. After recovering my account, I found a notification buried deep in the security settings about a login from a suspicious address—dated eight days before Google locked my account with no warning.
The way that the platforms have tightened digital security while retaining the option of using ASPs to connect is like investing in heavy new locks for your front door but leaving the side door wide open for people who don’t have the keys. Because it involved a clever new attack that could affect almost anyone, my case has created quite a bit of attention in media specializing in cybersecurity. Organizations other than Google have naturally been readier to recognize the security problem. As Sophos, another cybersecurity company, politely noted in a warning to customers on June 18: “The potential impact of creating an app password and providing it to a third party is not made clear in the creation process.”
In other words, what would really have helped was a warning during the process of setting up ASPs of exactly what they are and what they do, which would have alerted me to what was going on. Google has correctly pointed out that there is a warning along those lines in their help files. But that doesn’t help if you don’t go to those help files—because, as in my case, your attacker has kindly provided an authentic-looking manual of their own to walk you through the process.
The real heroes of this story are at the Citizen Lab—in particular, the privacy and security guru John Scott-Railton. It was John, together with Reuters journalists Raphael Satter and James Pearson, who helped me piece together what had happened when all I could see was that Google had frozen my accounts (and in one case, telling me that this was because of “policy violations”). And it was they who used their professional contacts at Google to try to help me regain control.
The Citizen Lab calls itself an “interdisciplinary laboratory” focused on research in information technology and human rights. But their investigations of digital espionage against civil society—and their efforts to protect citizens’ privacy and other rights against corporations and state agencies—are invaluable for people like me who point the finger at evildoers such as the Russian state but don’t have the support of powerful governments or institutions behind them.
Several people have asked me if I’m concerned about what the attackers will do with messages that they copied from my account. One expected next step is that whatever emails were stolen from the account will be used in a hack-forge-dump attack, where the hackers pass them to Russia’s Western proxies or sympathizers to release as a “leak” intended to discredit Moscow’s adversaries.
Back in 2023, when Scottish parliamentarian and Russia critic Stewart McDonald was similarly targeted, it took less than 48 hours after his announcement that he had been hacked by Russia for British activist Craig Murray to boast that he had obtained McDonald’s emails.
The so-called leak is usually a mixture of genuine messages and files, some that have been altered, and others that are simply invented—plus, often, malware and viruses to infect anybody curious enough to download them. The aim could be to paint me and the institutions I work with as charlatans, neo-Nazis, spies, philanderers, abusers of substances or puppies, or all of the above. But it means that there’s little point in being concerned about anything potentially embarrassing in my emails—if the hackers don’t find what they’re hoping for, then they will make it up anyway.
For now, Russia’s trolls and mouthpieces on social media are already busy with their version of who I am and what happened. There’s a consistent pattern where it takes 24 hours after something happens for their storylines to go out for dissemination—and after that, the same lines are repeated almost word for word across different media and different languages. Some real-life characters in the Russia business have also been crowing with delight at the “hilarious” hack. But that’s not much different from the background noise of lies and abuse that someone in my line of work takes for granted.
What’s far more significant in this case is how many other people around the world could be exposed to the same security risk and know nothing about it. Now that the power of this tool has been demonstrated, cyber researchers are expecting it to be used far more widely. That means that it could be abused not just against people who have made enemies in Russia, such as myself, but also ordinary users who might not consider themselves at risk. And that could be for cybercrime, low-grade snooping, or just settling scores.
In my case, the attackers put an extraordinary amount of time, effort, and patience into building the con. For whatever reason, they decided I was worth it—or maybe they were just frustrated after so many previous failed efforts over so many years.
But anyone who is not as automatically cautious as me—perhaps because they’re not in a line of work that sees them routinely targeted—could be taken in by a far less sophisticated deception campaign. We probably all have friends and relatives, especially older ones, who have been taken in by scams that, in hindsight, seemed blatantly obvious.
If they know how, then readers should check whether this kind of password has been set up on their accounts. If they are concerned, there are options such as Google’s Advanced Protection Program, which blocks this method of attack and some others. But in any case, Google and other companies should make sure that the risk of this account feature is more widely understood by ordinary users.
When attacks do succeed, it’s also important that more people speak up about them. It’s understandable that individuals who are duped in this way are sometimes reluctant to come forward and share the details. Anybody less thick-skinned than me might be embarrassed—and feel a little foolish at having been outwitted. But it’s essential to share as much as possible. Our collective security is worth so much more than one person’s individual embarrassment.
six sentences or less bc that's the kind of week it is
listening
straighten up and fly right from the nat king cole songbook, covered by sammy davis junior. i have a lot of fondness for the nat king cole songbook bc my grandmother had a lot of fondness for it, and this one was very comfortably in our (contralto) ranges. really burrowing into the comforting familiar as we enter the Cross Country Move Hellzone (tm). spotify
-
reading
lot of documentation for work bc i am trying to build a google sheet + calendar for our grants and reports such that when someone adds OR EDITS a row in the grant/report tracker it creates a new google calendar event OR UPDATES existing events. i may have to give up on that second half.
Interview With a Crypto Scam Investment Spammer – Krebs on Security
in non-work stuff, it is hysterical how many hackers brian krebs (infosec reporter/journalist/researcher) is able to interview. like when this guy was asked "yo is this your code targeting a specific mastodon server with a crypto scam" the response was
Clicking the “open chat in Telegram” button on Zipper’s Lolzteam profile page launched a Telegram instant message chat window where the user Quotpw responded almost immediately. Asked if they were aware their domain was being used to manage a spam botnet that was pelting Mastodon instances with crypto scam spam, Quotpw confirmed the spam was powered by their software.
“It was made for a limited circle of people,” Quotpw said, noting that they recently released the bot software as open source on GitHub.
we live in the stupidest possible cyberpunk future.
-
watching
i don't know jack about shit about cars and i don't know what the fuck jennings motorsports on youtube is talking about 80% of the time but a friendly guy with a calm voice talking through how he's going to get some cars in the worst shape you've ever seen up and running again? yes good thanks, i've blown through his entire backlog in the last week in my second monitor while i've cleaned data. this man is essentially rebuilding this rare limited edition shiny holographic car from half a frame and a panel LOOK how fucked this thing is.
love the Will It Run? videos bc the answer is almost always yes AND SOMETIMES HE EVEN DRIVES THEM DOWN HIS DRIVEWAY AND BACK even if the cars are barely holding themselves together. the horse souls in these machines can be coaxed back into resurrection with the proper burnt offerings and application of liquefied dinosaur
-
playing
the charm of Powerwash Simulator is somewhat dampened by its extremely buggy achievements bc i KNOW i could get all 40 so fuckin easy if they just WORKED. i didn't get the "main campaign completed!" achievement despite spending nearly forty hours 100%ing every job, so i think the rarity of the achievements is somewhat inaccurate, bc it's more like, did you happen to play through that level at a time when the achievement was working? despite all that, it has been incredibly effective at damping generalized moving anxiety and it's a tremendous catch-up-on-podcasts game. it's hysterical to me this was published by square enix bc this style of simulator game is usually published by Playway or a Playway company, a shadowy network of about a hundred small polish studios, many of which went public and had IPOs in order to hand over a controlling interest of the company to Playway. long history of annoying business practices such as remaking more popular games with the serial numbers filed off and making demos to gauge interest and THEN only making about one full game for every twenty demos, which is very irritating for players. not this one tho, it's in fucking brighton in the uk, no relation!
-
making
this is going to be cleaning and move prep for the next six weeks. i deep cleaned (even mopped!) my kitchen and bathroom last weekend bc it uh. really needed it, and that's the most exciting thing i did. no progress on cleaning the flip clock radio bc i do not currently have the patience to sit down with qtips and get in all the little grooves.
Previously on computer literacy: A Test For Computer Literacy
If you’re a computer programmer, you sometimes hear other programmers complain about Excel, because it mixes data and code, or about Word, because it mixes text and formatting, and nobody ever uses Word and Excel properly.
If you’re a computer programmer, you frequently hear UX experts praise the way Excel allows non-programmers to write whole applications without help from the IT department. Excel is a great tool for normal people and power users, I often hear.
I have never seen anybody who wasn’t already versed in a real programming language write a complex application in an Excel spreadsheet. I have never seen anybody who was not a programmer or trained in Excel fill in a spreadsheet and send it back correctly.
Computer programmers complain about the inaccessibility of Excel, the lack of discoverability, the mixing of code and data in documents that makes versioning applications a proper nightmare, the influence of the cell structure on code structure, and the destructive automatic casting of cell data into datatypes.
UX experts praise Excel for giving power to non-programmers, but I never met a non-programmer who used Excel “properly”, never mind developed an application in it. I met non-programmers who used SPSS, Mathematica, or Matlab properly a handful of times, but even these people are getting rarer and rarer in the age of Julia, NumPy, SymPy, Octave, and R. Myself, I have actually had to learn how to use Excel in school, in seventh grade. I suspect that half of the “basic computer usage” curriculum was the result of a lobbying campaign by Microsoft’s German branch, because we had to learn about certain features in Word, Excel, and PowerPoint on Windows 95, and non-Microsoft applications were conspicuously absent.
Visual Basic and VBS seemed like a natural choice to give power to end users in the 90s. People who had already used a home computer during the 8-bit/16-bit era (or even an IBM-compatible PC) were familiar with BASIC because that was how end-users were originally supposed to interact with their computers. BASIC was for end users, and machine code/compiled languages were for “real programmers” - BASIC was documented in the manual that came with your home computer, machine code was documented in MOS data sheets. From today’s point of view, programming in BASIC is real programming. Calling Visual Basic or .Net scripting in Excel “not programming“ misrepresents what modern programmers do, and what GUI users have come to expect after the year 2000.
Excel is not very intuitive or beginner-friendly. The “basic computer usage” curriculum was scrapped shortly after I took it, so I had many opportunities to observe people who were two years younger than me try to use Excel by experimenting with the GUI alone.
The same goes fro Microsoft Word. A friend of mine insists that nobody ever uses Word properly, because Word can do ligatures and good typesetting now, as well as footnotes, chapters, outline note taking, and so on. You just need to configure it right. If people used Word properly, they wouldn’t need LaTeX or Markdown. That friend is already a programmer. All the people I know who use Word use WYSIWYG text styling, fonts, alignment, tables, that sort of thing. In order to use Word “properly“, you’d have to use footnotes, chapter marks, and style sheets. The most “power user” thing I have ever seen an end user do was when my father bought a CD in 1995 with 300 Word templates for all sorts of occasions - birthday party invitation, employee of the month certificate, marathon completion certificate, time table, cooking recipe, invoice, cover letter - to fill in and print out.
Unlike Excel, nobody even claims that non-programmer end users do great things in Word. Word is almost never the right program when you have email, calendars, wikis, to-do lists/Kanban/note taking, DTP, vector graphics, mind mapping/outline editors, programmer’s plain text editors, dedicated novelist/screenwriting software, and typesetting/document preparation systems like LaTeX. Nobody disputes that plain text, a wiki, or a virtual Kanban board is often preferable to a .doc or .docx file in a shared folder. Word is still ubiquitous, but so are browsers.
Word is not seen as a liberating tool that enables end-user computing, but as a program you need to have but rarely use, except when you write a letter you have to print out, or when you need to collaborate with people who insist on e-mailing documents back and forth.
I never met an end user who actually liked Outlook enough to use it for personal correspondence. It was always mandated by an institution or an employer, maintained by an IT department, and they either provided training or assumed you already had had training. Outlook has all these features, but neither IT departments nor end users seemed to like them. Outlook is top-down mandated legibility and uniformity.
Lastly, there is Microsoft Access. Sometimes people confused Excel and Access because both have tables, so at some point Microsoft caved in and made Excel understand SQL queries, but Excel is still not a database. Access is a database product, designed to compete with products like dBase, Cornerstone, and FileMaker. It has an integrated editor for the database schema and a GUI builder to create forms and reports. It is not a networked database, but it can be used to run SQL queries on a local database, and multiple users can open the same database file if it is on a shared SMB folder. It is not something you can pick up on one afternoon to code your company’s billing and invoicing system. You could probably use it to catalogue your Funko-Pop collection, or to keep track of the inventory, lending and book returns of a municipal library, as long as the database is only kept on one computer. As soon as you want to manage a mobile library or multiple branches, you would have to ditch Access for a real SQL RDBMS.
Microsoft Access was marketed as a tool for end-user computing, but nobody really believed it. To me, Access was SQL with training wheels in computer science class, before we graduated to MySQL and then later to Postgres and DB2. UX experts never tout Access as a big success story in end-user computing - yet they do so for Excel.
The narrative around Excel is quite different from the narrative around Yahoo Pipes, IFTTT, AppleScript, HyperCard, Processing, or LabView. The narrative goes like this: “Excel empowers users in big, bureaucratic organisations, and allows them to write limited applications to solve business problems, and share them with co-workers.”
Excel is not a good tool for finance, simulations, genetics, or psychology research, but it is most likely installed on every PC in your organisation already. You’re not allowed to share .exe files, but you are allowed to share spreadsheets. Excel is an exchange format for applications. Excel files are not centrally controlled, like Outlook servers or ERP systems, and they are not legible to management. Excel is ubiquitous. Excel is a ubiquitous runtime and development environment that allows end-users to create small applications to perform simple calculations for their jobs.
Excel is a tool for office workers to write applications to calculate things, but not without programming, but without involving the IT department. The IT department would like all forms to be running on some central platform, all data to be in the data warehouse/OLAP platform/ERP system - not because they want to make the data legible and accessible, but because they want to minimise the number of business-critical machines and points of failure, because important applications should either run on servers in a server rack, or be distributed to workstations by IT.
Management wants all knowledge to be formalised so the next guy can pick up where you left off when you quit. For this reason, wikis, slack, tickets and kanban boards are preferable to Word documents in shared folders. The IT department calls end-user computing “rogue servers“ or “shadow IT“. They want all IT to have version control, unit tests, backups, monitoring, and a handbook. Accounting/controlling thinks end-user computing is a compliance nightmare. They want all software to be documented, secured, and budgeted for. Upper management wants all IT to be run by the IT department, and all information integrated into their reporting solution that generates these colourful graphs. Middle management wants their people to get some work done.
Somebody somewhere in the C-suite is always viewing IT as a cost centre, trying to fire IT people and to scale down the server room. This looks great on paper, because the savings in servers, admins, and tech support are externalised to other departments in the form of increased paperwork, time wasted on help hotlines, and
Excel is dominating end-user computing because of social reasons and workplace politics. Excel is not dominating end-user computing because it is actually easy to pick up for end-users.
Excel is dominating end-user computing neither because it is actually easy to pick up for non-programmers nor easy to use for end-users.
This is rather obvious to all the people who teach human-computer interaction at universities, to the people who write books about usability, and the people who work in IT departments. Maybe it is not quite as obvious to people who use Excel. Excel is not easy to use. It’s not obvious when you read a book on human-computer interaction (HCI), industrial design, or user experience (UX). Excel is always used as the go-to example of end-user computing, an example of a tool that “empowers users”. If you read between the lines, you know that the experts know that Excel is not actually a good role model you should try to emulate.
Excel is often called a “no code“ tool to make “small applications“, but that is also not true. “No Code” tools usually require users to write code, but they use point-and-click, drag-and-drop, natural language programming, or connecting boxes by drawing lines to avoid the syntax of programming languages. Excel avoids complex syntax by breaking everything up into small cells. Excel avoids iteration or recursion by letting users copy-paste formulas into cells and filling formulas in adjacent cells automatically. Excel does not have a debugger, but shows you intermediate results by showing the numbers/values in the cells by default, and the code in the cells only if you click.
All this makes Excel more like GameMaker or ClickTeam Fusion than like Twine. Excel is a tool that doesn’t scare users away with text editors, but that’s not why people use it. It that were the reason, we would be writing business tools and productivity software in GameMaker.
The next time you read or hear about the amazing usability of Excel, take it with a grain of salt! It’s just barely usable enough.
Reimagining Product Innovation with a Smart Asset Finance Software
We are witnessing a paradigm shift in the asset finance industry, a shift from traditional finance and leasing to delivering a more customer-centric holistic digital experience. Customers today want the ease and convenience of doing business on a channel and medium of their choice, and your employees need a platform to collaborate and add value to the business, irrespective of their physical location.
Lessors today recognize that to survive in this digital age they need to constantly re-invent and become a more agile and smarter version of themselves. Your asset finance business needs to go beyond the restrictions and rigidity of legacy systems that are impacting your business growth. From application development to business operations- speed, efficiency, and scalability have become the cornerstones for success today. But while this leads to the belief that rethinking the technology landscape is an existential imperative, simply upgrading the “as-is” business via a new software suite or product is not enough.
To understand how asset finance leaders envision the future, how they plan to build for it, and what capabilities they need to be able to do so, we brought together a panel of industry experts, leaders and solution providers in a two-part webinar ( To watch webinar click here). As a part of the webinar, we also asked industry leaders strategies on adapting to this digital revolution. Read to find what your peers think are the top capabilities that a smart asset finance software should be able to essentially deliver.
1. The Shift to Consumption-friendly Pricing
The current shift toward more agile and flexible business models are pushing Lessors to build new products and services. Lessees today want to have the flexibility of paying only for what they consume and avoid getting into significant upfront capital investments. Under-utilized assets may come out cheaper for customers when compared with conventional leasing.
From an economic perspective, it means that lessors now will have to find ways to predict asset usage to set their price accordingly. This is because, with consumption-based leasing, it is difficult to predict what portion of the fixed expenses such as tax, insurance and asset depreciation should get allocated to every customer.
Needless to say, that this culture of product servitization is difficult to drive with manual or legacy systems. As these consumption models change the form, lessors will be left asking themselves – how
do we build core systems that provide enough flexibility and enables us to make corresponding changes as these newer consumption models develop and mature.
A smart asset finance software will provide a coherent platform ecosystem that helps you to build stability for your core business operations today while provisioning for iterations and incremental changes in the future without upsetting the entire tech stack. A centralized, platform-based approach will streamline your current operations, provide a granular level view across all stages of a customer’s end-to-end journey so that you can monitor, measure and build transparent pricing models.
2. The Rise of the Low-code Platform
Gartner forecasts low code to increase its share in application development activity to 65%, with three-quarters of large enterprises running on multiple low-code development tools by 2024. Low- code development platforms provide organizations with the much-needed agility and speed that have become the cornerstone of modern-day app development.
Conventional legacy systems were never built for the kind of changes, speed and flexibility that the market demands today. These monolithic systems are closely interlinked and hence, changes to a single component can impact the functioning of the whole system. This pushes organizations into a vicious cycle of development, tests and fixes, eating into precious time, efforts and resources.
A framework-based low code environment enables developers to leverage an existing set of codes, behavioural and structural models, and pre-built modules in the development environment. This allows for more automation in the development and testing process, faster development and
delivery, and lesser requirements for resources, skill sets and engineering efforts.
The right asset finance software is designed as a rich technical ecosystem built on top of the underlying framework so that changes made to functional modules don't upset the core structure. The pre-built system components and the underlying power of the framework enable lessors to configure and customize application on-demand, extend or build new applications, and make quick changes.
3. Adapt, Accelerate, Scale
With more than 60% of the respondents choosing a faster time to market and scalability as some of the biggest business priorities, it is evident that the rigid, obsolete legacy systems are going to be inadequate to meet the demands of the future. An intelligent asset finance software will help transform how you operate, speed up policy implementation and decision making while maintaining strong compliance.
Conventionally, business processes have mostly been built keeping an inward view of a company’s operations- concentrating on optimizing and automating core transactional processes and systems like accounts payable/receivable, order management, procurement etc. However, an architecture that enables companies to perpetually evolve their businesses cannot focus only on the journey that customers use in purchasing their offerings. Many asset finance companies are looking at transforming to an outward view focused on the customer experience online and offline and an IT architecture that reflects a larger journey.
Technology lies at the heart of this transformation- an agile IT ecosystem that can provide end-to- end asset-based functionalities, data intelligence and extensibility in one seamless platform to bring value across all dimensions of the leasing business. By standardizing and digitizing, companies can remove friction from processes and the time and effort taken in tedious, manual paperwork. By leveraging the power of mobility and APIs and portals, companies can deliver a superlative customer experience- by facilitating transactions from anywhere, at any time. Be a customer who wants to apply for a new lease or a vendor who wants to reduce the time to funding, it’s all down to the ease of the digital experience.
4. Data is the New Oil
Traditional asset finance organizations are realizing that advanced analytics can enable them to make better decisions quickly and consistently. By embracing data intelligence and analytics at multiple points across the asset-management value chain, asset finance leaders can transform business efficiency, from providing valuable insights to customers and help them make better investment decisions to drive changes in the middle- and back-office productivity internally.
However, to be able to leverage the power of data, the most critical step in addressing the problems of the source data. Data stored in legacy systems, siloes or spreadsheets are poorly documented and formatted and are difficult to collate and integrate. For any data intelligence strategy to work, it is important that there is a seamless flow of business data generated across all business and third- party applications, with minimal manual intervention, and that the data is centrally located and accessible to all in easy to understand formats.
Companies can then use this granular data to build pay-per-use models or leverage visualization tools to generate reports for critical business insights.
How Odessa’s asset finance software can help you
Over the last two decades, product innovation at every stage has been guided by us asking ourselves the following questions
· How do we enable our customers to scale their business and operations on demand?
· How do we help our customers deliver seamless digital experiences to their stakeholders?
· How do we empower our users with insights through real-time data analysis?
We knew that to counter these challenges, most businesses would conventionally have to opt for multiple product-based solutions, all bolted on top of each other and creating a complex
environment that is rigid and difficult to scale.
To solve this we extracted the core technology framework and put it down as the foundation layer. The basic technology framework provides a robust functional core build to global standards. On top of this foundation, we build our functional layer which hosts all our products, functionalities, and the business logic and rules. The topmost layer is a highly user-friendly and intuitive UI that allows for
integration and customization unique to your business.
The Odessa Core platform is an asset-based, cloud native, end to end management platform that can streamline your business operations, build a centralized database and provide the right platform for your teams to collaborate- saving cost, time and resources and making your business more efficient. By choosing to host your infra on the cloud you can leverage the scalability, agility and cost-
effectiveness of the cloud.
Odessa tightly integrates with a host of complementary surround capabilities for and a comprehensive digital transformation experience. Odessa Build and DevOps enable companies can
integrate their core platform with third-party applications or build, extend apps and workflows easily without any hassle. Various enablement portals make it easy for the customers and partners communities to do business with your organization. A low-code development platform for applications, mobility, data intelligence and analytics services are some features that cater to all dimensions of a leasing enterprise across captives, large customers, mid-size enterprises.
We are not just another asset finance software. We are a smarter asset finance software. Contact Odessa to learn more.