Citigroup Inc. (C) Earnings Call Transcript & Summary
July 16, 2020
Earnings Call Speaker Segments
Hunter Muller
attendeeNext up is Ajoy Kumar, leading the panel on securing the future of work. Ajoy, welcome.
Ajoy Kumar
attendeeOkay. Good afternoon, everyone. Can you hear me okay?
Hunter Muller
attendeeYes. We got you.
Ajoy Kumar
attendeeAwesome. Thank you very much. I'm having a bit of a technical problem, so I wanted to be sure that you can hear me okay. So thank you, Hunter, for handing over to me. I have 4 panelists with me: Alissa, I have Roota, I have Mandar and I have Beni, and we are going to discuss the future of the secure workplace. And we have heard so much discussion from our panelists a bit earlier on where they have been talking about the digital transformation, and we heard the profound quote from [ Mark ] that he reminded us what [ Satya ] had said about the digital transformation that has taken -- has basically sped up in such a meaningful way that there is no going back, and that has been the sentiment that I have been hearing in the panel discussion. So with that, the way I plan to run the panel is that I'll have each of the panelists basically just give an introductory statement, and then I will go through the Q&A with them. So with that, Alissa, I'll start with you. Why don't you take a minute to talk about yourself and the things that you're interested in?
Alissa Abdullah
attendeeSure. Hi, everyone. I am Dr. Jay, Dr. Alissa Abdullah. I am the Chief Security -- Deputy Chief Security Officer for Mastercard. And as you all probably know, we are responsible for ensuring that transactions occur between partnerships, between individuals, financial institutions, governments, businesses, that they're able to realize their largest and greatest potential by making transactions safe and secure and [ simple and smart ]. And so that's kind of what our purpose is at Mastercard. When we think about securing the future of work and how that plays a role in what we do or kind of what I do at Mastercard, I think about the fact that now I think we are -- everyone is a more compassionate work employer, right? We are a more compassionate employer and a more compassionate workforce. What I mean by that, we were taking Zoom calls, and we're enabling the dog to walk in the background or the kids to walk around in the background and things like that, but there's a security perspective to that as well. And so even though now we're more compassionate about what our companies or what our employees are doing, we have to maintain the security stance and make sure the controls are in place and make sure the data is secure and make sure the data is safe. And it's really [ gotten proved ] now that the end point is not necessarily a hardware device, that the end point is actually, probably, the piece of data. It's not even the person anymore, it's the data. So we now, when we think about securing the future of work, it's really the securing of data. I don't think much has changed other than our first hunger and level of consumption of how we plan on doing that. A lot of the projects that we've seen in the security space are those that we've been asking for, for a while. Now it's really more real because we have people sitting at home in remote environments, and I think all of our peers, whether the CIOs, CXOs, CDOs, whatever your X is in the middle of there, all of our peers are now saying, yes, we got to make sure that, that security project [ moves on ] and happens right away. So I think when we think about securing the workforce of the future, you'll see a lot of the projects that we -- that have kind of been in our back pocket now coming to the forefront and being very, very important and now finally getting budgeted.
Ajoy Kumar
attendeeVery good to hear that, Alissa. Thank you for the introduction. Roota, you want to go next, please?
Roota Almeida
attendeeYes. Sure. So pardon the background noise. The landscaper guys just walked in so -- as I started speaking. So hi, everyone. Hope you're all doing well and staying healthy. I am Roota Almeida, I am the Chief Information Security Officer at Delta Dental of New Jersey and Connecticut. Our goal at Delta Dental is to ensure that your beautiful smile stays healthy and intact and your data stays protected while we ensure your smile stays healthy. So that's our tagline that I would like to use. And I'm really glad to be here. Thank you, HMG. Thank you, Hunter. Definitely, during these times of uncertainty, I would like to know and discuss with my fellow panelists how can one explain when things don't go as we assume. But even better, sometimes, how do we explain when things go as per your assumption, and it actually defies all the assumptions. So during these uncertain times, as Alissa mentioned, there are a few things that were accelerated from our goal and perspective in our environment, which is always good, as is the new saying that you never let crisis go to waste. So definitely, that paid off. And the goals or the strategic initiatives that were either put in the back burner or were slowly being enhanced are now picking up pace, and we are ensuring that we are working in this new agile environment by supporting our workforce.
Ajoy Kumar
attendeeThank you, Roota. Hey, Mandar, would you like to build on what Roota said and how basically we should not let a good crisis go to waste because that goes well for everyone, right? Whether you are a CIO or a CSO or any other -- in other scenarios, that basically is a universal thing that I really like. So Mandar, with that, I'll hand over to you.
Mandar Rege
executiveGreat. Again, thank you. So just by way of introduction, my name is Mandar Rege. I'm with Citi, and I manage technology risk for the Global Consumer Bank. Just a quick disclaimer before I start, standard language, all opinions of mine do not reflect Citi's environment or Citi's opinion. So just coming to this question of the workplace of the future, if you had asked me this question 6 months ago, I would have shared this sort of dream aspiration of we will have virtual teams, commuting time is going to go down, work from anywhere, anytime you feel like. And then 6 months down, consequently, the future is now. So this is all still very much unfolding, so I'm not saying we've hit all those things that we would expect to see over the next few years, but it's amazing. And to Roota's point, the crisis accelerating a lot of change that we've been trying to get in place, whether it is about people adopting virtual technologies and making it a part of what they do on a much more enhanced basis than we used to have. We are seeing a lot of that. The ability to tap talent. Today, we are finding that people are much more open to the idea that I can have someone -- instead of our typical hubs, we can tap into people in any location because it really doesn't matter. And where people had a reluctance, it has forced them to get over that reluctance. So it has opened up a number of things that we didn't have in the past. So again, like I said, the future is now, and we are seeing a lot of things that may not have happened suddenly coming together because people were forced to get there.
Ajoy Kumar
attendeeThank you, Mandar. Thank you very much. Hey, Beni, on to you. What's your thought on what Mandar said, would you build on like how the future is here? And what do you think has happened to the cybersecurity during this COVID-19 pandemic? Do you think we have improved our posture, do you think we have gone down? So I'd like to you to introduce yourself and also give a comment on the state of the cybersecurity during COVID-19.
Beni Lopez
attendeeSure. Thank you. And I'm Beni Lopez. I'm the CEO of Softek North America and also the Managing Director for the Industrial Segment. So I mean, we're a global company, right? We're in 18-plus countries, I believe, in 3 continents. So to your question, it really depends on where you're talking about. In some cases, we're saying that COVID has only uncovered some not that very great practices for some of our clients, so we are focusing on taking care of fundamentals, to be honest, with some of them. In other places, there are very specific areas where we're helping them improve. And if there was 2 areas where I would focus is on how this has changed or evolved has been definitely the end product. Because whatever patterns we were following before or whatever structure or infrastructure we had before is completely shifted from your secure environment to somewhere else. So you need to have a different set of procedures and tools and add AI to monitor those behaviors because now you need to catch funny behaviors differently because now you have a more -- excuse me, can you hear me okay by the way?
Ajoy Kumar
attendeeThere's a bit of static, but generally, you're audible.
Beni Lopez
attendeeAll right. I'm sorry about that. So what I was saying is that the end point is definitely one area where we need to enhance how we manage it because the patterns are different now to what they used to be. And the second area is that we never ever forget that the most relevant aspect that we have to take care of are people, people behaviors and people awareness and people -- ability to productively and securely deliver the work. So we sometimes focus or we see clients focusing too much on the technology, which is very relevant. We must never forget that this is a end-to-end process where people are at the center of it, to make sure that they are keeping guard -- keeping their guard up and making sure we sustain, everything's secured, given the whole environment that we live in right now.
Ajoy Kumar
attendeeGot it. Thank you, Beni. Thank you for those points. Maybe we'll expand a little bit more on the technical side that you brought up towards the end point security. So given that our threat landscape has increased because our attack surface has increased, the end point which was traditionally within a building that we could trust now is [ brought ] for -- all over the globe, right? We have all supply chains. There are people working from all corners of the world, and they are working from homes. Even like in our offshore locations, we sort of like had a protective controls. And those things like those traditional controls are being in building and monitoring cameras, those are all gone. So what are the specific steps you are taking to sort of like protect the future workplace, where there will be a need to work from anywhere, anyplace, anytime? So how are you catching that? I think Beni is switching the headphones. Anyone else, Mandar, Roota, Alissa, anyone? Would you like to chime in on that?
Roota Almeida
attendeeYes. I think -- so with the new way of working, it is safe to say that in the near future, not everybody is going to come back to the workplace. There will be something like a hybrid work environment where there will be some folks working from home permanently or working from home most of the days of the week and some folks coming in to work. So definitely, it's going to be a hybrid environment. And to support that, I think from a security perspective, there needs to be a shift in the focus. So more on -- focus on education, awareness around remote working, the dos and don'ts, what's the acceptable use policy, what's your remote working policy for users as they are shifting to different work environments. Also awareness around general pandemic-related attacks that are happening. And every day, you see something new is happening, it's good to keep your users aware of what's going on. So when they do see something, get a funny-looking e-mail, they know what to do with it or rather not to do anything with it and delete it. Also one thing that we did notice when we moved to the new environment is a tweaking of some of our security alerting algorithms to support the new way of working and to limit their false positives and save valuable time for our security team. Because [ you want ] certain alerts coming, hey, somebody logged in from here or there, which is now their new norm, so to speak, and not logging in daily from a office environment. Definitely enhanced security monitoring and alerting, what kinds of alert you, as a team, was get -- you used to earlier that might not be relevant right now. There could be certain physical security aspect of it that you can shift your focus into something else. Also learn to support changes in working style and employee experience that enable employees to work more transparently and collaborate effectively. So definitely, I think that the investment in enhancing the security posture and supporting remote work from a business process and security perspective, whether the investment is happening now or it was happening as you moved through the pandemic response, it definitely is going to pay off.
Alissa Abdullah
attendeeI said I wanted to expand on that just a little bit only because we were working in a space where we were building for efficiency, and now we're building for resilience. There's a -- as we've all heard, an opportunity where the pandemic, we may all shut back down all over again, and so we have to be ready to ebb and flow and flex as appropriate. And so if you think about it from that perspective or from a security perspective, where we're trying to make sure in previous times that we were really, really efficient. And now we have to think about being really, really resilient and that those things that we put in place, whether it's end point security, whether we're talking about data classifications or securing the data, those things that we put in place don't get rolled back, that they stay in place and that we are able to throttle as needed based on what the level of response and things like that are going to happen in the future in terms of this pandemic.
Roota Almeida
attendeeI think we lost Mandar -- I mean we lost Ajoy. We have Mandar. So yes, you can go.
Mandar Rege
executiveI think that's part of our test of resiliency. So I think we can continue the conversation. But I want to go back to something Beni mentioned. I think this is turning our way of managing a little bit, not maybe on its head, but it is significantly changing the way we are managing the environment. Some of the examples, Roota, you brought up. We cannot use those same indicators of a compromise or a concern as we used to because it's turned our network, what I would call, inside out. As opposed to the old way of our network, of course, you had remote connectivity and so on, but the bulk of our capability was -- were people were in offices. You had workstations you knew fairly well. You had your pipes you knew fairly well and you had your end points. Now it's gotten to the point where you only know one end point, which is your server. But the other end point, and even the pipe that it's going to get you there, you have no control and sometimes even limited understanding. So for us, being a global company, if we are working -- there's a big difference even in the pipe between the capability of bandwidth I would have here in the U.S. or even in parts of the U.S. versus what some of my team members or counterparts may have in Asia or some other area where they may not have that same sort of capability. And then really looking at the security aspect, being able to now provide a lot of people whose jobs were never meant originally to be -- to have that sort of flexibility, how do you manage that? I mean we've done things like turning off the ability to print entirely. So there's been a lot of that, firstly, knee-jerk reaction. A lot of it is not sustainable. So I think this is not just a ones-and-done. I think we are going to also learn from this as we go along because some of the controls we put in place as an immediate step, we are going to have to revisit them because those are not sustainable. So if we want the business to continue to evolve, we are going to have to figure out how we do things differently whether it is the human aspect or the technology aspect.
Beni Lopez
attendeeThank you. Yes. I would say -- can you hear me okay now? Is that better?
Mandar Rege
executiveYes.
Beni Lopez
attendeeAll right. Okay. Yes. No. I would second that, that -- this is going to be an iteration of pivoting to different procedures and potentially, technologies. Because on the one hand, first, we shifted to -- everybody, in our case, 15,000 people working remotely, securely from home, activating -- having already activated hundreds of BCPs, but then we have manufacturing clients that are also asking us to get back to their facilities now that they're allowed to get back to produce stuff. Some financial clients are also asking us to get back to their facilities. So now we have a mixed environment where we have to deal with -- and never forget that this is going to continue to evolve, as you mentioned, because we not only have 100% clients or engagements working remotely, but then we have a mix of people working remotely from their homes as well as from their client facility as well as from maybe one of our delivery centers. So we need to keep evolving all these SOPs on how we're going to now -- mixing and matching different environments. And that's why I go back to my early comment of the end point having to be enhanced with AI because we need to identify multiple patterns on what is going on because -- I mean we're building as I'm sure you are or everybody's building their own apps on how to securely bring people back to work in the different whatever 4x10 strategy you may have. But at the same time, you cannot be 100% sure that they'll be using the platform so that you always know where they are, so you need to identify those [ patterns ] to make sure you know that she is working securely from home or know she's working securely from a client's facility or she may be having -- booked a seat at one of our facilities. So all of that is going to be changing.
Alissa Abdullah
attendeeSo let me ask [ you all a question ]. We had a lot of conversation about increasing -- I mean, using AI in end points, [ remove ] the niches, increase security monitoring and things like that. What are you all thinking about lowering investments? Are you all actually lowering your investments in physical security controls and IoT or anything like that? I'm finding that we probably got lower, but we will throttle as appropriate. I think we'll -- I heard earlier today, someone from [indiscernible] -- we heard someone from Nationwide, we heard a lot of folks today, I think there'll be a lot of conversation about throttling where it makes sense that moving some of our physical access, buildings and location. So I know that's one of the [indiscernible] -- that Ajoy wanted us to talk about, which is, are we lowering our investments in other areas? My answer to that is going to be no. We're not lowering our investments because we're not lowering per se, but we'll throttle as needed, keep certain invest -- we invest in our [indiscernible] and then take that investment away and do something [indiscernible]. How do you all feel about that?
Roota Almeida
attendeeYes. So I agree with you. We are not lowering our investments. What we are doing is we are putting our emphasis in different areas as things evolve, right? So more emphasis on security awareness and training, more emphasis on supporting different working styles, ensuring enhanced security monitoring. Also one other huge thing that is coming up with this pandemic is everyone is now working towards the agile delivery model. And this new delivery model, it requires continuous participation by the security teams with the modern application development methods. And if we, as cybersecurity specialists, don't have a seat at the table from the very beginning and we don't -- then it's not going to be successful. The traditional method of various different checkpoints in the process is not going to work because this is a very continuous, fast delivery model, and we need to be there as a security professional every step in the way. Security office. We need to improve our understanding of the modern software development dynamics, the techniques, so that we can support them better as they are delivering at a much, much faster pace. Also increasing cloud usage poses a moving security target for us. So in terms of security infrastructure as cloud usage increases, that is something that we need to take into consideration and understand how that cost is going to affect -- will it be higher than the traditional virtual host creating a different class of organizational risks? So these are the handful of new initiatives that come up with -- I think right now, most businesses are turning into that. And as a security organization, we need to evolve with that.
Ajoy Kumar
attendee[indiscernible]
Alissa Abdullah
attendeeWe were talking about whether we were going to lower investment. And it doesn't think -- it doesn't stop [indiscernible]. So I'll now pass it back over to you to ask more questions.
Ajoy Kumar
attendee[indiscernible] for you filling in. I really appreciate. I had like -- my iPhone shut down, so thank you for that. So I know we are almost at the end of time, so what I'll ask you to do is like one specific question I would want you all to answer and, then we'll basically -- we hand it back to Hunter. So like you guys are talking about not lowering the investments and you're continuing with like shifting your priorities and shifting your investments, which means like you will be rolling out some disruptive technologies, which are new and you all want to -- I do see a desire for you to innovate and continue going in that direction. So in this COVID times, has your tolerance gone down, has gone up? How are you treating your reputational risk with rolling out these new technologies at this time? So I'll start with you, Alissa, and we'll go across the table.
Alissa Abdullah
attendeeOur tolerance has gone down. We're less tolerant, I will say this. We're less tolerant. We want to fail quick. We want smaller sprints because we want to learn quickly so that we can recover quickly and continue to enable the workforce. We are focusing on a lot of collaborative solutions, whether that's collaborative internally or collaborative between governments or between banking institutions and merchants and things like that. And so as we are looking at different investments we are making in different technologies we're putting in place, we want to fail fast, fail quick. Learn the lesson very early on so that we can recover quickly and have some great products to continue to [ deliver ].
Ajoy Kumar
attendeeThank you, Alissa. Mandar, would you go next, please?
Mandar Rege
executiveSure. So I don't think our tolerance has changed. A lot of the things Alissa described and sort of Roota, going agile, continuous development, all of those are things that we already had in progress. So our tolerance hasn't changed. What we have had to do, because this was not a smooth glide path into a new world, it was a very sudden change, we had to make a number of changes immediately to be able to accommodate new ways of working, new things that needed to be done within almost a matter of weeks. So those things are tracked more as exceptions. And then very quickly, we started turning them -- declining them as we went through, and we built out the technology process and the capabilities. So that's how we measured it in the sense that we didn't change our risk tolerance. There were early exceptions. And then within a few weeks as we built out the capabilities to manage those risk exceptions, we started turning them back or turning them off again. So I think to answer your question, the tolerance really didn't change.
Ajoy Kumar
attendeeThank you, Mandar. Beni?
Beni Lopez
attendeeWell, as a company, it hasn't changed. It has actually increased our not acceptance of risk because we service global clients all over of the world, so we have to make sure that now that if we've got people working from home, we need to make sure they continue to do it securely. So as a company, the tolerance has come down. We're less tolerant to how we are doing that. What we're reminding our clients now in the vast variety of industries that we service is that it's not a onetime event or it's not a onetime decision that you have to make to say, yes, let's give it a go to this new e-commerce platform because the old one is overflowing, et cetera. It has to be on the framework of your complete risk management and risk mitigation strategy. So we have to make sure we go to the right people and say, well, if you do this, this is going to be the risk. I mean we don't want to be the bottleneck to stop you from reaching your business goals, we just want to make you aware of what the risks are involved in this. And then it's your call. I mean that is how you need to navigate these type of decisions.
Ajoy Kumar
attendeeThank you, Beni. And Roota last word?
Roota Almeida
attendeeYes. In the interest of time, I'll be very short. So our tolerance level has not changed. It remains the same whether we are complete remote or a hybrid environment because our risk profile, in the sense, that risk tolerance, has not changed. So we are not going to change the way we allow things or don't allow things or we are not going to change or give a little bit of leeway on their controls because that's what governs our security strategy, and we're not going to change it just because of the pandemic.
Ajoy Kumar
attendeeThank you very much, my panelists, really appreciate and also being resilient as I lost connection, so thank you for that. So Hunter, I'll come back to you with the major massage from panelists. Our panelists say that our CSOs and our leadership team basically believes the pandemic is not going to change our behavior. It's not going to change our demeanor. We'll continue to march along and make sure that we deliver on the secure enterprise for the future. With that, over to you, Hunter.
Hunter Muller
attendeeGreat job. Roota, Beni, Mandar and Alissa, thank you so much. We do [ do CSO some ] new folks. Hey, great summit here today. The 2020 New Jersey CIO Executive Leadership Summit, HMG Live! This is probably our 30th of the year, really proud and happy to say great keynotes, great panels, what a great day. And a big shout out to New Jersey SIM for our partnership, now going on over a decade, as well as our partner companies for the summit, which includes Commvault, Rimini Street, Softek and Nutanix. Thank you for your support and engagement. Without you, we couldn't do what we do. Really appreciate. Please reach out to them and take a meeting with your local rep. Bye now.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Citigroup Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Citigroup Inc. earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.