DocuSign, Inc. (DOCU) Earnings Call Transcript & Summary
July 21, 2020
Earnings Call Speaker Segments
Bob Bragdon;CSO;SVP/Managing Director
attendeeGood day and thanks for joining. I'm Bob Bragdon, Senior Vice President and Worldwide Managing Director of CSO. Organizations of all shapes and sizes have unique stories of resilience to tell about their experiences responding to the pandemic, lessons to reach beyond just the pandemic response and speak to the resiliency of their organizations. Today, we're speaking with Emily Heath, the Chief Trust and Security Officer at DocuSign. At one time or another, we probably all use their solutions, and as a global business, with 500,000 customers and hundreds of millions of users in over 180 countries, Emily has her hands full. Emily, my friend, it is so good to be speaking with you today.
Emily Heath
executiveIt is an absolute joy and a pleasure as always, Bob.
Bob Bragdon;CSO;SVP/Managing Director
attendeeEmily, please introduce yourself and tell us about your background and what you're up to now.
Emily Heath
executiveOf course. So as Bob said, I'm the Chief Trust and Security Officer at DocuSign. I joined DocuSign about 7 months ago or something like that, so fairly new to DocuSign. A little bit about my background, just very briefly. So I haven't always been a CISO. I started my career as a detective in England for many years. I used to investigate fraud. So I used to investigate people like, [indiscernible], the multimillion-dollar investment frauds. I did had a ton of investigations with the FBI and the SEC and people like that. It's interesting because the people in England who I was investigating at the time was stealing money from people in the United States, which is funny that I ended up here. I found myself into a career in technology. There was actually nothing to do with security. It's a cocktail conversation for another day. But I actually used to run ERP teams, developers teams, infrastructure groups, a PMO, and I actually found my way into security more from the compliance side rather than from the kind of more traditional network security side. So I've been a CISO now for many years. Prior to DocuSign, I was at United Airlines. And before that, I was at AECOM, a company that's an architecture engineering construction company.
Bob Bragdon;CSO;SVP/Managing Director
attendeeExcellent. So you've been in the job, like you said, since last October, right? A heck of a time to shift gears.
Emily Heath
executiveYes. I know.
Bob Bragdon;CSO;SVP/Managing Director
attendeeWhat were your priorities going into the job? And have they changed at all because of the pandemic and its impact on the work environment?
Emily Heath
executiveYes. So coming into any new company, I think any CISO always has their hands full for the first few months, just getting to know the lay of the land, getting to know the landscape. Every company is an ecosystem these days because we've all got so many third parties, and we're connected to all kinds of people and data goes everywhere. So my top priority at any company has been a lot of listening and a lot of observation in the beginning and learning to really get my arms around who this company is and what matters to us the most. So I'd say building off of the great work that's already been done, the amazing thing was there's already great security program at DocuSign when I got here. So it's how I can leverage the platform that had already been built and build that even further so that we can scale. So I think in terms of priorities that comes to me, I use the concept of visibility all the time because it's really important to security professionals that we understand every connected everything to our environment. So understanding the attack surface, understanding where all the assets are and who manage them and who has access, the priorities of that and making sure that we are proactively monitoring our environment so that we could detect evil very quickly, was the #1 priority coming in. And it would be going to any company, to any organization. That's probably the central core of any good program is that you understand what your attack surface is and then try and reduce it as much as you can. So that hasn't changed since COVID came along. It's still the #1 priority, and still the thing that the team is working on. So in terms of the working remote, working at home and the whole COVID situation, that actually didn't change the priorities for us much at all. We have a number of programs that we've decided on prior to this whole COVID world happening, and we're still working on those things. So it really didn't shift our gear very much. I think the planning, I was very fortunate in that, at least I've got a chance to spend a few months in the office and meeting in person because we step up relationships with people. It's hard for folks coming into a new organization who never actually met people in person. I have a couple of people on my team that have hired into my leadership team who I've never actually met in person. It's been fully remote interviews and trying to build teams. That's why it's challenging, but it's taught us to do things a little differently. But the core fundamental priorities haven't changed.
Bob Bragdon;CSO;SVP/Managing Director
attendeeTalk about the new normal.
Emily Heath
executiveYes, really.
Bob Bragdon;CSO;SVP/Managing Director
attendeeSo you also run crisis management at DocuSign, and this was certainly the acid test to have responsibility. Talk about your role in managing crises and what you did as the pandemic kicked in.
Emily Heath
executiveYes, absolutely. So my role at DocuSign is a little different than a more traditional CISO role. I have all of the usual cyber stuff, all of the usual kind of information security and governance risk-type stuff. I also have visible security and I also have the crisis management function of physical security and also trust services, which is how we engage with our customers. So it's a multifaceted role. But when the pandemic hit, I very much have to put my crisis manager hat on. So I lead the COVID-19 task force at DocuSign. So the minute this crisis started to hit, which actually was around RSA time. I remember being with some colleagues at RSA, and in the morning, one of the days during RSA, weekend in the afternoon after lunch was just spinning up the COVID-19 task force. So I co-chair it with our Head of People, Joan Burke, who runs our people, in our HR department. And we've been running the task force since February. So we very much brought people in from different parts of the organization, so different levels of the organization as well. But people who have specific subject matter expertise, like the folks that run our events. Obviously, we have to pivot very quickly and do virtual events like this with the other companies. So we took the view from the task force of everything from how it impacts the business, how it impacts our events, how it impacts employees and brought a test force of people together. And at the time, we were meeting multiple times a day when things started to get challenging. And then we continued to meet daily up until, I would say, about a month ago, maybe 2 -- maybe 6 weeks ago, and now we meet twice a week, but it's still the same core task force, and we still keep our eye on all of the illness statistics and how it affects the areas where DocuSign has office locations. So we have got office locations in 22 countries around the world, and we're monitoring each one of these locations to see what the statistics look like and see if there's any possibility of ever opening up anytime soon. So there's a number of things that the task force did. We did a really nice thing for our employees. We gave everybody a DocuSign Care's allowance of $1,000 to go -- do whatever you need to do to make yourself and your family comfortable. If you've only got 1 iPad and you've got 2 kids, go buy another iPad for your kids. So there's been no arguing. If you needed it to go order a new monitor or you needed a new keyboard, then go buy those. If you need to take out for a week because the kids are driving you nuts, then go get take out for a week. We basically let them spend it on anything. And it really helped the employees feel a little love as we were transitioning to closing down the office, everybody working remote and then planning for what the new normal is. I would say for us, we were fairly lucky in that we already were a Zoom shop. We already have Slack. We already have a lot of remote workers. So it wasn't too much of a heavy lift to get on the 4,500-ish people set up and running. Perhaps we had a few more VPN requests and things like that. But for the most part, we were extremely fortunate because I know a lot of companies are not like that. But we're very fortunate that we were pretty equipped to work remotely. I will say it's a lot more challenging to plan to come back to the office, which is what we're doing now.
Bob Bragdon;CSO;SVP/Managing Director
attendeeI've heard that. I've heard that from a lot of businesses.
Emily Heath
executiveYes. It really is. And shutting down the office was not a decision that we took lightly, but coming back is exponentially harder. This -- we pulsed our employees a couple of weeks ago, and there's little to no desire for anyone to want to come back, wearing a mask, socially distant, 6 feet apart, all people in an elevator or facing the corners. We just don't want to work in that environment. So we told our employees to stay home until the end of the year, and we'll figure out what we do after that when it's safe.
Bob Bragdon;CSO;SVP/Managing Director
attendeeSo look broader now outside the organization, how do you see security transforming itself in the wake of COVID-19? Do you think, at the end of the day, it's going to be a net plus or a net negative?
Emily Heath
executiveI actually think it will be a plus because what the COVID-19 situation has done has made us all think a little differently or maybe thinking a way that either affirms or reaffirms what we were originally thinking was a priority. So I think whenever you challenge to deal with a different situation and turn a problem upside down back to front and inside out, that can only make you better. So I think as security professionals, we're maybe rethinking or thinking again to make sure that we're focusing on the right things. I think as a security community, it will make us stronger. I think concepts around Zero Trust, concepts around how you get a -- from an identity all the way through to how people can access things and everything in the middle, that is now a core part of everybody's conversation because it's interesting to me because when you think about your security strategy, the only thing that's really changed is that the people and the endpoint is in a different place. And everything else should be pretty much the same, but how you get people now from a home Internet provider into your environment to do their work securely and effectively without performance impact and anything else is, I think the thing that we're all thinking about. So I think it can only be a good thing. I think it will strengthen the way that we see security, in particular, access and identity because those are the new normals for us. Even if we have a vaccination next week, there's going to be a long period of time, I think, before people are fully back to an office. I've heard a lot of companies are going to adopt more of a flexible work environment. So it will give a lot of people a lot more flexibility to be at home 2, 3 days a week. Some companies have already stated that they're going to be 100% remote after this. So it's a reality that we all have to deal with. So I believe it's going to make us stronger.
Bob Bragdon;CSO;SVP/Managing Director
attendeeI was speaking to someone the other day, and they were talking about how they've -- they find that their SOC is very effective working from home, but the idea of splitting the SOC and having some people at home and some people in the office wouldn't work because they're all -- they're in one place working on one platform. You're either -- and a whiteboard in front of you. Or you're all in one place, trying to do it electronically and whiteboard and do the same thing. But the 2 dynamics, they found weren't really working very well if they -- everyone wasn't in the same place. So I think there may be some parts of the business they are going to be a little more difficult to say, let's put them on a rotation to have some come in and some not.
Emily Heath
executiveThat's right. It's -- absolutely. I think a lot of people are dealing with this. It's almost harder to have some people in the office and some people remote [indiscernible] all to be remote. But it's interesting, when I was at AECOM, we had a fully virtual G-SOC, global SOC, and I know they still do. So that environment was something that we have to learn that just as we were building out the SOC because we have people all over the world that were -- follow the sun 24/7 and same other organizations I have been at and it's the same here at DocuSign. We've got people in locations all over the world. So there's a natural handoff to when you're going to follow the sun model. But it is very different when you've got some people in the office. And I think the one thing we can all agree on that we miss more than anything is a whiteboard. Anyone who knows me and has worked with me knows how much I value my whiteboards. And I've been resisting the temptation of putting one right here behind me.
Bob Bragdon;CSO;SVP/Managing Director
attendeeThat's great. You've said some pretty important CISO roles from AECOM to United Airlines and now in DocuSign. Have those roles been different? Or haven't they?
Emily Heath
executiveI mean, I think that the concepts are the same, but the most important thing as a CISO is to understand our business. Every company is different and what matters to each company is different. So you tailor your security program around what matters to you the most. I mean if you think about a company like AECOM, they probably have a lot of blueprints and drawings and architectural diagrams of World Trade Center and airports and football stadiums and things like that, that were super important. So it would be a part of what would drive the program. At a company like United, obviously, there's a lot of data elements, but really, the program is driven around people. You've got a human life aspect to what you do with an airline, it's very different. At DocuSign, we're very much a data-driven company. We hold a lot of people's secrets. And people use us for a lot of sensitive documents that we hold on their behalf. So our platform, our software and our data is really important to us. So I think what changes is how -- once you've identified who your company is and what matters to you the most, the things that change are the approaches you may take to focus on those areas. But fundamentally, it's -- security is security and the attacks -- the attack vectors are the same. The access might be slightly different because of what it is they're trying to get, and that's why things like attribution is so important. It's really important for us all to understand, too, is trying to attack our environment so that we can make some more well-informed proactive decisions. But the underpinnings, I'd say, are very much the same, but the programs will be slightly tailored differently based on what matters to you.
Bob Bragdon;CSO;SVP/Managing Director
attendeeYes. All right. Final thought. Your best advice to CISOs and aspiring CISOs on what they might want to be focusing on in the coming months.
Emily Heath
executiveI think a bottom beyond everything right now is leadership. What we need is leadership in many, many forms. We're working in some challenging times, and our teams are working in some challenging times. So I think the time we spend, we can never underestimate how important it is for CISOs to be a leader and aspiring CISOs to be leaders. It's a huge, huge part of our job. People need us more than ever right now. I feel like we have to be even more human with our teams than ever because we're in this situation. We're all remote. There's so much to go through. I feel like it's really important as leaders for us to drive some change around the Black Lives Matter movement. It's really important that we are seen to take action because words and actions really matter. There are some things that, for example, we're doing in my own team where we're removing racial nomenclature like blacklist and whitelist from our vocabulary. We're going back through all of our documentation and changing that because it's not the world that we live in, and we're in leadership roles, and it's up to us to inspire some change. So I think where leadership is needed right now from CISOs, from aspiring CISOs because of the environment that we live in, is take a stand, take action and drive change. Let's certainly talk about it, and let's continue to talk about it. But more importantly than anything, let's make a difference because we're really paving the way for the up-and-coming leaders that are coming through the ranks right now, and I would love them to be in a healthier work environment. I'd love them to be in a healthier, more secure position, and that comes with being bold and taking leadership.
Bob Bragdon;CSO;SVP/Managing Director
attendeeGreat. Emily, as always, it was a pleasure to sit down and hear your insights. Thanks for speaking with us, and stay well.
Emily Heath
executiveAny time, Bob, any time. Great to see you.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete DocuSign, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →For developers and AI pipelines
Programmatic access to DocuSign, Inc. earnings transcripts and 248,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.