I've Been in Tech for over 25 Years. Here's What Still Surprises Me

July 1, 2026

Client
Industry
written by

I got my start in technology the way a lot of people did in the 1990s – someone found out you knew how to build a computer, and suddenly you were the neighborhood IT department. It started with friends and family, then referrals from people I had never met who needed a machine built. I was sourcing components, assembling systems, and selling them to people in theirhomes and to the small businsses I was already doing networking for. Eventually I discovered pretty quickly that there was a lot more to this thanputting the right parts in the right order.

What I got to witness during those early years was something that I don't think we fully appreciated at the time: the moment computers stopped being standalone devices and became interconnected ones. The shift was gradual until it wasn't. One day you had a PC sitting on a desk doing exactly what you told it to do, no more and no less. Then slowly, almost imperceptibly, the network became as important as the machine itself. And then the network became more important.

My first role in a large enterprise environment made that clear in a hurry. All of a sudden I was looking at a 128k frame relay circuit connecting an office in Venezuela, a Dual ISDN line running to Australia, and dozens more across the US and the rest of the world, and the entire business was threading through these connections in real time. In a Data Center Operator role, I got to see the full picture – how systems were built, how they were backed up, how they talked to each other across the globe. And I got to watch an organization pull off something that felt almost magical at the time: just-in-time manufacturing, end to end, with vendors, distributors, and customers all connected and coordinated so that shelves stayed stocked and nobody's production line sat idle waiting for a part. The network wasn't just supporting the business anymore. The network was the business.

Of course, the flip side of that connectivity is vulnerability. You can't link everything together without also creating  for things to go wrong. I moved into a sysadmin role at a university around this time, which is a particular kind of education in itself. The scope of responsibilities in a higher education IT environment is hard to explain to someone who hasn't lived it. Firewalls, routers, switches, wireless, physical servers, virtual servers, storage, backups, patching, security, Active Directory, LDAP, identity lifecycle management, and data center power and cooling – that was a Tuesday. It teaches you two things very efficiently: how to do a lot with limited resources, and exactly which systems people notice the moment they stop working. Spoiler: it's never the ones you hope.

By the time I moved into consulting and started getting a look inside hundreds of different companies' data centers, we were deep into the first big wave of cloud migration. AWS was promising developers a world wher  e they could spin up infrastructure on their own, without having to submit a ticket and wait for those slow infrastructure people to get around to it. I'll skip ahead to the end of that particular story, which is that it wasn't cheaper. But that was fine, because by then the narrative had shifted to agility and DevOps, which I'm told is worth the price premium.

After consulting for about a decade, I shifted focus to data protection right around the time ransomware stopped being a niche concern and became something executives were getting asked about in board meetings. Then 2020 happened. The pandemic compressed what might have been years of gradual remote work adoption into about six weeks of "figure it out," and the combination of speed and necessity left a lot of gaps that attackers were very happy to walk through. We spent the years that followed patching those gaps with better processes for deploying new systems, offline backup copies that bad actors couldn't reach even after getting into the environment, and a whole lot of security awareness training. The fundamentals of how attacks work have evolved dramatically since the days of malicious files showing up in AOL Instant Messenger, but the game itself hasn't changed. Hackers find a way in, administrators close it, hackers find the next one. The technology changes around that loop, but the loop itself just keeps turning. Today AI is helping security teams find threats faster than ever, which is genuinely exciting, but you have to remember that the people on the other side of that firewall have access to the same tools.

Now here's the thing that actually surprises me, after all of it. Not the pace of change, which is relenless. Not the scale of threats, which is staggering. What surprises me is how consistent the cycles are.

Think about where computing power has lived over the past fifty-plus years. In the 1970s, you had terminals connecting to a mainframe. All the real work happened in the data center. Then personal computers came along and moved enormous amounts of processing out to the desktop. The datacenter went from being the engine to being more of a filing cabinet – somewhere to store what you'd already created. Then all that distributed data became asprawl problem, so we invented virtual desktop infrastructure and thin clients to pull the processing back to the data center where we could manage it. That worked for a while, until everything started moving to SaaS and the cloud, and users wanted full laptops again because the applications weren't running in the company data center anymore. Now we've got all this data scattered across cloud environments, endpoint devices, and third-party platforms, which has created enough of an analytical nightmare that organizations are rebuilding centralized data warehouses and data lakes just to get their a rms around it. Early AI development in the mid-2010s largely started on developer workstations. When teams outgrew that and needed to collaborate and scale, it moved to the cloud. When those teams’ managers discovered what it costs to process data at full scale in the cloud, they started figuring out how to run it on-premises again.

The pendulum keeps swinging. It swings from centralized to distributed and back. It swings from on-premises to the cloud and back. Security attacks shift to whatever surface the latest technology has opened up, and defenses follow. Consolidation creates cost problems, sprawl creates management problems, and we solve each one by moving toward the other until that becomes a problem too.

It's not that any of these directions are wrong. They'renot. Each swing of the penduum represents real innovation and real progress. Thedata center we're returning to now is nothing like the one we left, and AIrunning on-premises in 2025 would have been unrecognizable to the developerswho started those models on their desktops ten years ago. The destinationchanges even when the direction feels familiar.

What I've learned to expect, after more than twenty-five years of watching this, is that whateer direction the industry is moving with the most enthusiasm and the least skepticism is exactly the direction we'll be walking back from in a few years. Not because the technology fails, but because we push it until we find the limit. And then we find the next limit in the other direction.

That's the part that still surprises me: not that it happens, but how reliably it happens. The technology changes completely. The cycle doesn't.

Author: Patrick Ruffino | Infrastructure Solutions Architect

 

More Success Stories