For years, enterprise IT has been told that cloud-first management, zero trust, and automation would simplify operations and reduce risk. In practice, many IT teams are finding the opposite: Environments are more complex, visibility and manageability are reduced, application sprawl is harder to control, and the gap between security goals and day-to-day operations continues to widen.
In this VMblog Q&A, Nash Pherson, Recast‘s Director of Product, discusses why many of these challenges have persisted despite improved tooling. In addition, recurring patterns around cloud adoption are stalling, privilege management remains difficult to operationalize, and application delivery is becoming a growing bottleneck for both security and productivity.
VMblog: Endpoint and application management have been around for decades. Why do these areas still cause so much operational friction for IT teams today?
Nash Pherson: Modern environments require IT teams to manage hundreds of applications across on-premises, cloud, VDI, and hybrid models, each with different deployment, configuration, and dependency requirements. This scale and environmental diversity create ongoing complexity that is difficult to standardize or simplify in day-to-day operations.
VMblog: Many organizations expected cloud-first management to simplify operations. Why are hybrid and comanaged environments still so common in practice?
Pherson: Organizations often rely on both cloud-native and on-premises tools because each address different operational needs. Co-management persists as teams balance legacy application requirements, infrastructure investments, and differing capabilities between platforms, which introduces coordination and policy complexity rather than a simplified approach. Newer organizations can choose to adopt only cloud-native tools, but existing organizations have every previously solved technology problem to readdress. Simply saying “we don’t have these needs anymore” is not usually an option.
VMblog: Application patching and updates consistently surface as a top pain point. What makes this area so difficult to standardize at scale?
Pherson: To fulfill their missions, most organizations have many different business areas with diverse technology needs. That complexity makes securing and maintaining everything incredibly difficult for IT to accomplish in a way that doesn’t impact business operations. And with organizations being more mobile than ever, it becomes incredibly important to have application management tools which can keep the business running and secure without manual intervention.
VMblog: How has the growing focus on zero trust and least privilege changed the way IT teams think about application management?
Pherson: Zero trust and least privilege require IT teams to control application access and execution more tightly instead of delegating broad administrative rights to end users. This shifts application management toward enforcing access boundaries, reducing risk exposure, and minimizing the operational risk of user privileges while balancing the needs of business areas to do their work.
VMblog: Where do you see the biggest disconnect between security goals and day-to-day IT operations when it comes to endpoints and applications?
Pherson: Security teams typically push for faster patching and stricter controls, while IT operations teams struggle with the operational overhead required to implement those changes consistently and the potential negative impacts on business operations. This disconnect is most visible when manual processes and tooling limitations slow remediation and compliance efforts.
VMblog: What operational pressures are IT teams under today that weren’t as prominent a few years ago?
Pherson: Vendors update applications more frequently, and attackers exploit vulnerabilities more quickly. There’s increased pressure due to shorter patch cycles, heightened endpoint security expectations, and closer scrutiny of compliance and operational resilience. These demands require faster response times and better coordination between operational and security teams now compared to what was needed in the past.
VMblog: For IT leaders looking to reduce complexity without disrupting their environment, what practical mindset or approach tends to make the biggest difference?
Pherson: Progress often comes from looking at existing complexity and slowly improving visibility, reliability, and consistency versus attempting large-scale replacement initiatives. A pragmatic focus on reducing friction in critical workflows tends to be more sustainable than pursuing wholesale change.
##






