Lou Fiorello and Vasant Balasubramanian, ServiceNow | ServiceNow Knowledge 23
Lou Fiorello, vice president and general manager for security products, and Vasant Balasubramanian, vice president and general manager for the risk business unit at ServiceNow, explain how the management of cybersecurity, governance, risk and compliance is starting to converge with IT services management (ITSM).
Transcript
This is Techstrong tv. Hello and welcome back to ServiceNow Knowledge 2023. We're here with Vice and Lou and we're talking about security, operations and risk.
Not in the platform, but on the platform, which is a fundamentally different thing. Lou, welcome to show. Welcome Or Thank you.
Thanks Mike. Thanks for coming. Pleasure.
We've seen security operations be shifted more and more towards IT departments and of course ServiceNow being in the house that ITSM built is security operations and ITSM starting to converge more and is that part of why you have this offering? What are you seeing out there? Yeah, so what we're seeing, a couple of things.
So we're seeing security teams need to interact with IT teams a lot. And historically we've seen that be, hey, email spreadsheets back and forth between teams. And what we're seeing on ServiceNow with customers that have adopted our security operations is that they're driving end-to-end workflows, right across those TE two teams.
So I'll give you a couple of examples. So like, one example is around vulnerability management or historically, you know, the security team would own a tool that assesses vulnerabilities in the landscape, right? And then they would say, Hey, put in an email, uh, together to, they might find a million vulnerabilities.
Well, a hundred thousand need to go to this team, a hundred thousand need to go to that team. And they'd send an email with a, with a big spreadsheet, right? And what we're trying to do is we're trying to break down those silos and get those teams to work to better together with a consistent workflow, right?
And where everybody's on the same page from an information perspective, what needs to be done by when, how, right? And so we're seeing that the security operations on the platform enables that better collaboration across security and IT Of course, governance risk and compliance, fondly known as GRC, is a close cousin to security. So is it similar conversation?
Are we seeing the same type of convergence starting to happen Across the board? So when you think about risk and compliance, if honestly if you do anything, there's risk, some risk related to that. There's compliance related to it.
I'm sitting in a building, I'm sure someone's worried about health and safety. Mm-hmm. Um, if I have my phone, I know my phone has controls from ServiceNow to make sure, uh, it doesn't get hacked.
So as soon as you start about talking about technology and you look at ServiceNow's footprint across technology, you go, Hey, customers are putting stuff on the cloud. Customers are putting hardware assets in place. There's risk related to, uh, opss of the products.
They have software and software applications in place. There's cyber risks related to them. And then there is also vendor risks related to them.
Cause the vendor may go out of business or they may have a huge breach, in which case we both care about this cuz data's at loss. So as soon as you have technology in place, technology supporting business, um, the, this is all critical resilience. Um, a bank that I was talking to at some point in time, their router went down or some techno network infrastructure went down suddenly for 24 hours, their customers could not get to their money.
And uh, you go, oh, that's a problem. And so this connects where so much of our life is now technology driven and ServiceNow sits at the heart of managing the technology for our customers, connecting that to risk to make sure it's super resilient. We're worry about the cyber point of view, put in place, um, uh, controls in place, put in place, vulnerability response, security incident response, and a whole bunch of things related to that connect to the top of the house, to the business services and third parties.
Everything else is related to it. That is what we help our customers do. You talked about reducing the friction, but it also seems to me that I've always had to have applications to go manage security or grc, but I built them on a separate stack.
If I put 'em on this service now platform, am I not in some way reducing the total cost of security operations because, um, not having to support an entire separate stack of software for that particular application? Well, I think, I think so. I think the answer is there's a yes part and there's a no part, right?
Like, so the, I'll do the, i'll, I'll do the yes part first, which is yes, we are seeing customers consolidate certain solutions onto the ServiceNow platform, right? It's a platform layer that can serve security use cases, it use cases, et cetera. The, but there are certain things we don't do, right?
And so for that, we have to make sure that we're integrating with the tools and systems that customers have in place today. That's a big part of our security strategy, right? So endpoint related tools, network related tools, um, of vulnerability scanners, uh, things of that nature that we're, I mean, we're good at workflows and assets and applying those to security problems, right?
Not necessarily that detection layer out at the different control points. So we integrate with those, but in terms of, I mean, I talk to a lot of customers that might have 20 different case management systems across 20 different security departments that is ripe for consolidation onto the platform, single offering, single case management system data isolation when needed, but enable collaboration when needed as well. So I may use you to create the policy, but the execution is still back on wherever the, the device or wherever the endpoint is.
That's Correct. Yep. Absolutely.
Yep. We hear a lot about GRC and highly regulated industries, but I think to your earlier point, one industry is not regulated these days. It seems like everybody's gonna need GRC at some point And everybody does.
Mm-hmm. So, uh, just like every industry needs technology across, and if you look at ServiceNow's customer base, same thing is true of risk and compliance. Historically, risk and compliance used to be much more prevalent in financial services, highly regulated for the longest time.
And so we saw a lot higher maturity and need from financial services customers, uh, that has evolved. Uh, we see a lot more, uh, on technology, um, particularly with data privacy, uh, technology supporting business needs, AI now coming into, uh, play and the risks related to that. Responsible ai, there's a whole bunch of things related to it retail, it all goes to not just regulation driven, but a growing maturity in the awareness of the role risk and compliance place in everything.
What are you hearing from customers about data privacy? It seems like there's a lot of legislation floating around out there. It's in different shapes and different states and in different places around the world, but it seems like it's coming in a much bigger way than it has been here thus, thus far.
Um, honestly, the, the path to data privacy started, uh, driving much higher awareness as soon as we started getting GDPR a few years ago. So the word is today at a point where data privacy as a compliance thing and getting people more access to how the data is used is all, is in a much better place than it was five years ago. However, that has evolved since to broader places where this is applicable.
I'll give you a very simple example. When we train our data models for AI privacy, there's privacy information related information in there. And so the governance related to how your AI model works includes how your governance related to the data that fed into that worked.
And so there are much broader implications on just focusing on how data is used and consumed across the enterprise and privacy implications and a whole bunch. Uh, related to that, We've been talking about AI all week here. How will AI be applied to security operations, do you think?
What should people be looking forward to? Yeah, I mean, I think there's, uh, I think we're in the early stages, but there's a huge potential, right? And I think some use cases will be more generalized across the ServiceNow platform and some will be security specific.
Like, so for example, one, I I think general use case that'll be applicable to security, but also a lot of other areas is, you know, give me, I've got a major incident, right? Could major security incident in this case, give me an executive summary of this so that I can inform the right people, right? You know, there's, and there's all kinds of records associated with, it could be hundreds, thousands of artifacts.
But summarize this for me. What's the right, what's the right information to send to my executives? I think that's a pretty simple one.
But then there's others when you look at like the security domain and the specifics around the customer environment, right? How are, how is my, is the, are similar customers responding to this type of incident? Can you summarize that in a way for me that is usable but maintains the right privacy right across the customer base?
I think there's some really interesting examples that, uh, that again, were at the early stages, um, but we're investing this year, right? So that we're gonna realize GRC can be mind numbing work. The documents can be 400 pages long that you're supposed to figure out how to comply with.
So is AI gonna help us with that? Yeah, it's definitely gonna help us with that. In fact, honestly there, this has been an area in AI that has been true for a few years now.
There are companies out there that will try to parse, uh, regulatory documents and pull out the nuggets of what's relevant. An active area of research, even in the past has been contracts. How do you extract contractual terms from documents?
And, um, even at ServiceNow, there's now an offering for called DOC and tell, which helps you start doing things like that. So there are things across the board which are summarizing information, extracting insights from data, large data sets that are, uh, or unstructured documents and lots of different data sets. Um, constantly see use cases, Security is not an easy job these days.
What's your sense of, um, are we still gonna be shorthanded by millions of people as we move along or are we getting to the point where if more IT people are participating in security, then we'll get to the right balance. Finally, we'll still need security folks who are specialists, but it's becoming a different world where it's not just all left to the security people. Yeah, Well, so I think I, I do think we're gonna continue to see a shortage in the security skillset.
Um, but I think that, but I do actually think that ServiceNow can help with that, right? Because we can, we see in a lot of our customers with process, with workflow, with automation, right, with some of the AI capabilities that we already have in the platform, we can help the existing teams scale to higher incident volumes, right? So I think that we, but I, I, you know, I I'm not of the opinion that there we're gonna, uh, that that, uh, you know, we've had a shortage of security professionals for a while.
I don't think that's gonna go away. I, but I think you're right in that we have to get, we have to help the, the people that are there scale, and then we have to help connect and collaborate, you know, improve the collaboration between security and IT teams to drive improved efficiency. On the GRC side, do we have enough people to handle all the tasks that we're looking at?
I don't think it's a simple answer. I, for risk and compliance, the world's slightly different. So in risk and compliance, the goal, and, and I suspect that's also true in security, is you really want everyone who's doing their day job to be better at doing their job.
Yeah. So if everyone did, if I did my job in a way that was aware of security consideration, so I'm not, well, I'm careful where I use my phone, how I use, uh, where I browse to and I'm a good citizen, right? Um, we're doing business ethically to reduced the load on risk.
And compliance is everybody's role in the enterprise. It's not the risk and compliances team's job. So in that sense, those teams are essentially always working to make sure everyone else is doing it.
So over time, the teams have grown and, uh, wind and wax for different reasons, but it's not in the same way. And there's a lot of different sub domains. The people will focus on enterprise wide risk.
There are people who focus on cyber risk, there are people who focus on technology risk. That's not cyber risk. There'll be people who focus on third party risk, business continuity.
There's a lot of different domains and there's always some level of availability or per of professionals. All right guys, let's, let's tease something here. What's the next great thing coming down in security operations from ServiceNow?
Uh, well, so one of the things we just talked about in, uh, keynote this morning at Knowledge was, uh, something we're calling security posture control. So I said earlier, like ServiceNow, you know, and I'm generalizing a little bit, but we're really strong at, you know, workflows and automation and asset understanding, and this is really the marriage of those two things, right? So tell me, you know, I'm supposed to have an endpoint solution installed on these assets, is it there?
Right? And if not, you know, help me fix it. I'm supposed to have vulnerability scan coverage across my entire estate.
Do I, and if not, you know, drive the right priority to fix that. So I'm really excited about this and I think this ties in really nicely to risk and compliance as well. And the next great thing from you guys, Um, I'm gonna change that slightly and say the next thing that our customers that we see a lot of people concerned about now.
So it wasn't, it's not something that we're releasing in the fall. Um, ESG has been a hot topic and as historically people have looked at environmental, social and governance and said, we're gonna report on this. I'm just collecting a bunch of data, I'm reporting, but regulators are getting in the game.
And CS r d in the European Union was approved last fall. And so increasingly, it's not just about just putting data out there in a report, it has to be auditable. You cannot make misstatements that is a public corporation and there's regulators looking at it.
So connecting ESG to the compliance aspects of it is becoming increasingly important for a lot of our customers. And so if there's something I'm really excited about, it's leading customers to that level of maturity where they're able to drive impact with ESG data collection action in a way that's compliant and that's not greenwashing, uh, greenwashing. Cool.
Hey folks, now that we know that security and risk and compliance is everybody's job, some effort is going into making it a lot easier for everybody than it has been in the past. Gentlemen, thanks for being on the show. Thank you.
Thank you, Mike. Yeah, it's a pleasure. Pleasure.
Thank you. All right. And we'll be back in a minute.





