Chipotle Mexican Grill, Inc. (CMG) Earnings Call Transcript & Summary

July 28, 2020

New York Stock Exchange US Consumer Discretionary Hotels, Restaurants and Leisure conference_presentation 19 min

Earnings Call Speaker Segments

Bob Bragdon

attendee
#1

Good day and thanks for joining us. I'm Bob Bragdon, Senior Vice President and Worldwide Managing Director of CSO. Organizations of all shapes and sizes have unique stories of resilience to tell about their experience responding to the pandemic, lessons of reach beyond just pandemic response and speak to the resiliency of their businesses. Today, we're speaking with Dave Estlick, the Chief Information Security Officer of Chipotle Mexican Grill. Founded in Colorado in 1993, Chipotle has over 85,000 employees and more than 2,600 restaurants in the U.S., Canada, U.K., France and Germany. Before joining Chipotle last December, Dave was a CISO of Starbucks for nearly a decade, and prior to that, held senior security roles at PetSmart and Amazon. Dave was also a 2020 inductee of the CSO's Hall of Fame. Dave, welcome, and thanks for sitting down with us today.

David Estlick

executive
#2

Thank you, Bob. Pleasure to be here.

Bob Bragdon

attendee
#3

Maybe I could ask you to begin by taking us through your Chipotle's pandemic experience.

David Estlick

executive
#4

Yes. I mean I think for COVID-19 and -- there are two high-level lessons that I think that were highlighted at Chipotle and kind of applied to the broader landscape. One is how your organization has dealt with prior crisis. So Chipotle was in a position where they had not only gone through tabletop exercises but had issues that they needed to work through over the past several years. And as a result of that, had instituted processes and procedures throughout the organization focused on health and wellness. So as we were hit with this particular crisis, we were well positioned already from a process and procedure standpoint at our restaurants for checking employee health before they came in on the use of antibacterials. So from an industry sector perspective, many of our competitors and peers have had to figure out how to address those under this particular crisis, where that was some problem that was already solved. So I think the experiences in the past and how your organization dealt with those was key. And secondly in this one, specifically, was how your organization was positioned from a digital transformation perspective. So how much -- how far along on that journey were you? And I think the companies that had begun making those investments a few years earlier found themselves much -- in a much better place to respond and adapt to the changing environment as opposed to those that maybe were early in the journey or it was a future plan.

Bob Bragdon

attendee
#5

Yes. Yes. Let's follow with that thread a little bit. Every business' experience of COVID-19 has been different. But how have you seen an organization's progress towards digital transformation affect their ability to respond? And what does that mean for them long term?

David Estlick

executive
#6

Yes. So -- I mean this really was a defining moment, a divining moment, if you will, for organizations. Those that were further along could very quickly adapt to the changing environment, the changing workplace and what they had to -- it allowed them to focus less inwardly from a technology perspective and more about how are they going to support the business because there were changes unilaterally throughout the enterprise. Those that were further behind now had to figure out how to accelerate programs that maybe were in early stages or hadn't even begun planning yet. So I think the former group, this was maybe more of a springboard effect. The latter group, this is really an anchor around the organization.

Bob Bragdon

attendee
#7

Where are you seeing weak spots to be in an organization's resiliency plans when it came to the pandemic in this case?

David Estlick

executive
#8

Yes. I think most organizations had a business continuity, disaster recovery and crisis plan. I think what this highlighted was in several organizations that wasn't holistic enough. So the plan really focused on the experiences of the past, which were more around either geopolitical and social unrest or acts of God, weather. And so it was focused on losing a field office or a center of operations or a data center, it wasn't losing everything holistically all at once. So I think what we saw internally is strained capacity which leads to the second part of it, on your suppliers, vendors and third parties that you rely upon. How well were they positioned to be able to address this as well. So even the video conferencing vendors, they were strained at capacity because all of a sudden, organizations moved to whatever they were operating on, whether it was Microsoft Teams or Cisco Webex or Zoom. All of a sudden, they got a burst in demand and how well were they positioned to be able to adapt to that.

Bob Bragdon

attendee
#9

Well, let's talk for a minute about what you call the resiliency of Tier 0 services. Our organizations have spent years consolidating providers then as few as possible in an effort to, I guess, bring financial benefits at a lot of the supply chain. How does that affect business' response to the pandemic?

David Estlick

executive
#10

Well, I think that needs to be rethought a bit, especially in large-scale or black swan events like COVID-19. If you're highly reliant on a third party, let's say, it's for VPN connectivity, and they're unable to scale with your demand, what's your option, right? Wait until they fix and address their problems so your business can get -- become operational again? Or are you really looking at maybe in certain circumstances, depending on the criticality of the service, that we actually do have a second vendor in the mix that allows us to burst that capacity when needed. So I know it's one of the items for consideration for my organization. We'll go back and reevaluate that on the services where we saw either degraded performance or were slow to respond. Are we going to work with the single source vendor to try to ensure that we have that capacity when our business needs it? Or are we going -- and it's probably more of an, and we'll look for probably a secondary or tertiary vendor to, say, if we need to scale quickly and widely, we have the ability to do so.

Bob Bragdon

attendee
#11

Do you spread that out? I mean like not being in the pandemic right now, but just assuming that. Do you spread that out and say, I'm going to use 2 or 3 vendors, and I'm going to do -- everyone's going to get half the business. So each one is going to get 1/3 of our business. Or do you say, I'm going all-in with one, and I keep this guy and retain them over here just in case I need them?

David Estlick

executive
#12

So typically -- it's interesting because in the retail space, this is no different than payment providers. And what I've seen work in the past is there usually is a lead organization, and you will essentially -- they're going to push for exclusivity, right? They're going to watch all the business. And you say no, but the top vendor will get 90% of the traffic, guaranteed, right. 10% will fall to a secondary vendor. However, if the primary vendor has a problem, we're going to swing old traffic until that's resolved to the secondary vendor. That provides the ability -- the resiliency that you need for that critical service to your business as well as the ability for burst capacity. The added benefit is in contract renegotiation. When that comes back up, those 2 vendors are now vying for the 10%, 90%, where when you're locked in with 1 vendor, there's not a lot of motivation for them to discount that second time around the resigning of a contract.

Bob Bragdon

attendee
#13

So that's a little different than you do with, say, consulting services where you might have a consulting service on incident response retainer rather than having them in. So someone who can parachute then when there's a problem, right?

David Estlick

executive
#14

Yes. Well, I mean, even in that, I have some 0 retainer vendors on -- or consultants as part of that plan because you still can get into a situation where you have the unlikely event that you have several incidents simultaneously that you're running, or for global multinationals, that could be regionally. And for -- they suffer from the same problem of capacity, right? They only have so much headcount. And if they're unable to respond in the time that's needed, that allows me to just kind of move down that line and say, for this particular locale and this particular incident, who's best equipped? And part of that is response time.

Bob Bragdon

attendee
#15

Yes. Yes. So one of the things we've been debating is kind of what's a long-term impact toward the organization? So when you -- we're sitting around a year ago, and you're looking at all of these possibilities of risks that you're facing as an organization. Pandemic might have been that on that list, probably was for a lot of organizations. But you kind of looked at it and said, that's a black swan, right? Big impact, low likelihood, should we do anything about it? I mean let's put it up. But now I'm thinking businesses will look at those black swan events a little differently, because suddenly you have one of these things actually happen, but start layering these other things that are happening, which was like budget and resource restrictions. Now because of the economy -- economic fall, what do you think the long-term impact will be on resiliency due to the restrictions on budgets and resources?

David Estlick

executive
#16

Well, I mean -- so my experience right now, and I guess if I look through that lens, what I believe is this is actually going to be a beneficial event for cybersecurity. One, from the standpoint that you described of there was always this concept or ethos within the executive team that -- well, that won't happen to us, right? That's a -- yes, that's there, but the likelihood is so low. And why are we spending time and resources to address something that we're never going to see? And you hear that play out today in just casual conversation, right? So not even around the Board table, but just talking with friends or peers, how many times have you heard people say, yes, we've never lived through something like this, like there's no playbook. We're kind of dealing with it ad hoc. And that further underscores the fact that everybody is like, yes, nobody ever thought that this was ever going to happen in our lifetimes. Yes, have the possibility is there, but we think somebody else is going to have to deal with it. So I think, at least for the executive teams, the Boards and the technical teams that have lived through this, there's probably going to be an easier conversation around risk and risk realized than we've seen in the past. The other is, and I found this really interesting. In May, the World Economic Forum have published a report about COVID-19 and what the greatest concerns for the world are and the most worrisome concerns for the enterprise, for companies. And they broke them down to economical, societal, technical, geopolitical and environmental. And the interesting point is cyberattacks and data fraud, due to the sustained shift in working patterns, it was #3 on the most worrisome for the enterprise and was the only technical concern to make the top 10. So if you take a look at that, I think as CISOs and cybersecurity professionals, recognizing that, that's top of mind. And now people understand that when they're rapidly shifting and transforming their organization, that there is a cyber aspect to that, that they're concerned about, should be a very positive indicator for all security professionals.

Bob Bragdon

attendee
#17

Yes. I put about a 5-year window on it, right? And don't forget about it, we'll go back whatever it was, whether you're doing it before.

David Estlick

executive
#18

Well -- I mean hopefully in those 5 years, though -- you're probably right. But hopefully, in those 5 years, because our voice will be amplified and what we're doing for the organization, that we'll be able to elevate the discipline in those 5 years. Similar to what we're seeing with the adoption of cloud and other things within transformation, where they're saying, we are compressing essentially a 5-year plan down to a couple of quarters. Same thing is going to happen for cybersecurity from a maturation standpoint and an influence standpoint. So I think there's a couple large themes that came out of this. One is people can work from anywhere. So as much as there was that debate within organizations on which functions and how much and what's our stance on this, we've all shown that unless there's absolutely a need for physical contact, health care and some other things. But even health care is figuring out how to do telehealth and some other things to augment that. And the other is, is that organizations can move much faster than maybe they anticipated as well, right? So -- I mean, for instance, at Chipotle, we took an initiative to bring on another -- to augment our delivery service with another provider. That was measured in months down to days.

Bob Bragdon

attendee
#19

Wow. That's fantastic.

David Estlick

executive
#20

And I mean that's a testament to everybody at the organization. But -- I mean -- and that's something that's close to home because it's within my enterprise, but I'm hearing those same stories from peers and others at companies that they're figuring out a way to move at a pace that -- outside of this particular problem, we would have said it is probably impossible.

Bob Bragdon

attendee
#21

Yes. It was funny to see all the speed bumps seem to go away, or a lot of them. That just allowed everything to flow and happen much more smoothly and quickly than it would have been if we were all still in the office. Interesting.

David Estlick

executive
#22

I think that's going to be the biggest challenge coming out of this is, is we operated one way. And now as we come, whenever that is, that we hit to the back end of this crisis and we go back to whatever assemblance of our prior experience is accepted, is how do we avoid bringing all of those roadblocks and speed bumps back into the process because we operated fine, and most organizations haven't seen a negative effect yet from that.

Bob Bragdon

attendee
#23

Dave, always a pleasure to speak with you, my friend. We really appreciate your insights, and thanks for joining us.

David Estlick

executive
#24

Thank you for having me.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Chipotle Mexican Grill, Inc. transcript — plus 250,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Chipotle Mexican Grill, Inc. earnings transcripts and 250,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.