Speaker

Rolf Schutten

Rolf Schutten

COO & Microsoft Azure MVP | Bridging Strategy and Cloud Execution

Operationeel Directeur & Microsoft Azure MVP | De brug tussen strategie en cloud-executie

Veenendaal, The Netherlands

Actions

Rolf Schutten is a COO and a Microsoft Azure MVP (since 2023). With over 15 years of experience in IT leadership, he specializes in bridging the gap between boardroom strategy and engineering execution. Rolf helps IT service companies scale effectively by designing modern operating models with a strong focus on Cloud Governance, FinOps, and Platform Engineering. As a speaker, he cuts through the industry fluff, delivering no-nonsense, actionable insights on how to align C-level mandates with technical reality, build a successful Cloud Center of Excellence (CCoE), and maintain engineering velocity without losing executive control.

Rolf Schutten is Operationeel Directeur en Microsoft Azure MVP (sinds 2023). Met ruim 15 jaar ervaring in IT-leiderschap is hij gespecialiseerd in het overbruggen van de kloof tussen strategische boardroom-doelen en de operationele realiteit op de werkvloer. Rolf helpt IT-dienstverleners schalen door het ontwerpen van moderne operating models, met een scherpe focus op Cloud Governance, FinOps en Platform Engineering. Als spreker snijdt hij door de buzzwords heen en deelt hij direct toepasbare, no-nonsense inzichten over het afstemmen van C-level mandaten op de techniek, het succesvol inrichten van een CCoE, en het versnellen van innovatie zonder verlies van controle.

Badges

Area of Expertise

  • Business & Management
  • Information & Communications Technology

Topics

  • Cloud Native
  • DevOps
  • Cloud
  • Kubernetes
  • Cloud Security
  • Innovation
  • Leadership
  • IT Leadership
  • Technical Leadership
  • Finops
  • Cloud Governance
  • Cloud Center of Excellence
  • CCoE
  • Platform Engineering
  • Strategy Execution
  • Operational Excellence
  • AI Governance
  • AI
  • AI Strategy
  • Operating Models
  • Compliance
  • NIS2
  • Responsible AI
  • Artificial Inteligence
  • Autonomous Agents
  • Autonomous Systems
  • Digital Workspace
  • Generative AI
  • AI Agents
  • MCP
  • Mentorship
  • Process Improvement
  • Business Leadership
  • Business Productivity
  • Services Delivery Improvement
  • Digital Transformation

Keynote — The Ungoverned Cloud: Who Really Owns Your Cloud-Native Strategy?

Cloud modernization promised enterprise speed and agility, but for many leadership teams, it has delivered unpredictable OpEx, regulatory friction (NIS2, BIO2, EU AI Act), and diffuse operational accountability. While executives often assume security, compliance, and governance are "handled by the cloud provider," the reality on the ground is starkly different: cloud abstraction hides operational complexity, but it never removes business responsibility.

When external audits reveal compliance gaps or cost overruns, the traditional executive reflex is predictable: install heavy approval boards, write 80-page policy manuals, and require manual sign-offs. This approach fails every time—it paralyzes engineering velocity, drives shadow IT, and fails to eliminate actual business risk.

This session challenges leaders to rethink cloud governance not as a bureaucratic brake, but as an operational operating system. We’ll explore how to bridge the divide between C-level boardroom mandates and ground-level engineering reality.

You will learn:
- How to replace manual gatekeeping with automated, policy-as-code guardrails.
- How to structure an enablement-focused Cloud Center of Excellence (CCoE) that empowers delivery teams.
- How to balance speed with control, achieving "regulated freedom" without surrendering ownership over your cloud, your data, or your future.

Zero Trust Networking on AKS: Implementing Default-Deny with Cilium and eBPF

Kubernetes networking still relies heavily on implicit trust. Once a workload is running inside a cluster, it can typically communicate with any other pod or service without restriction. In modern multi-tenant environments, this flat network model creates a massive blast radius: a single compromised container can instantly become an entry point for lateral movement.

Traditional IP-based firewalls and reactive network security tools struggle in dynamic cloud-native environments where pod IPs shift continuously. Zero Trust changes this paradigm by denying all traffic by default and enforcing strict, identity-aware connections at both L3/L4 and L7 layers.

This hands-on session explores how to implement Zero Trust network security natively on Azure Kubernetes Service (AKS) using Cilium and eBPF. Moving beyond simple policy demos, we’ll dive into the mechanics of eBPF-powered packet filtering and show how to transition live production workloads from wide-open networks to robust default-deny enforcement without introducing performance overhead.

Key Takeaways:
- Why IP-centric security models fail in Kubernetes and how eBPF replaces them with workload identity.
- Practical patterns for designing, testing, and deploying default-deny policies on AKS.
- Combining Cilium network enforcement with Azure-native security monitoring and traffic visibility.

Building Production-Grade AI Agent Infrastructure on AKS with MCP and Azure AI

Modern AI development is rapidly evolving from simple prompt-response models to autonomous, tool-driven AI agents. However, connecting LLMs to internal enterprise tools, databases, and infrastructure relies heavily on brittle custom integrations, hardcoded logic, and fragmented access controls. As agentic workflows scale, maintaining security boundaries and operational visibility becomes a major platform challenge.

The Model Context Protocol (MCP) offers a breakthrough open standard for dynamic tool discovery and execution. But hosting MCP servers in enterprise environments requires robust runtime isolation, identity management, and secure API boundaries.

In this demo-driven session, we’ll look at the architectural blueprint for running production-grade AI agent infrastructure on Azure. We will explore how to host Azure MCP servers on Azure Kubernetes Service (AKS), secure inference pathways using API Management as an AI Gateway, and enforce strict Zero Trust boundaries between AI models and backend data stores.

What you will learn:
- How Model Context Protocol (MCP) standardizes agent-to-tool communication.
- Architectural patterns for deploying, scaling, and securing MCP servers on AKS.
- How to integrate MCP with Azure AI services while maintaining strict governance and data boundaries.

FinOps-as-Code: Embedding Financial Guardrails into Platform Engineering

Most FinOps initiatives operate reactively: a CFO receives an unexpectedly high cloud bill, flags the cost spike, and platform engineers spend days retroactively hunting down unattached disks or over-provisioned clusters. Simply asking developers to "care about cloud costs" without providing automated, real-time feedback loops rarely changes engineering behavior.

This session reframes cloud cost management as a platform engineering discipline: FinOps-as-Code. Instead of relying on monthly audit reports, platform teams can embed financial guardrails directly into Infrastructure-as-Code (IaC), CI/CD pipelines, and Kubernetes node provisioning.

We’ll explore practical patterns for automated cloud cost control on Azure Kubernetes Service (AKS), leveraging Karpenter for dynamic, cost-optimized node management, automated policy enforcement, and shift-left cost estimation.

Key Takeaways:
- How to move FinOps from reactive monthly auditing to proactive CI/CD enforcement.
- Implementing dynamic, cost-aware Kubernetes node scaling with Karpenter on AKS.
- Practical techniques to give developers immediate cost visibility before infrastructure is ever provisioned.

Rolf Schutten

COO & Microsoft Azure MVP | Bridging Strategy and Cloud Execution

Veenendaal, The Netherlands

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top