Eli Lilly and Company (LLY) Earnings Call Transcript & Summary
July 22, 2020
Earnings Call Speaker Segments
Bob Bragdon
analystGood day, and thanks for joining us. I'm Bob Bragdon, Senior Vice President and Worldwide Managing Director of CSO. Organizations of all shapes and sizes have unique stories of resilience to tell about their experience responding to the pandemic. Lessons were reached beyond just pandemic response and speak to the resiliency of their organizations. Today, we're speaking with Meredith Harper, Vice President and Chief Information Security Officer at Eli Lilly & Company. Founded in 1876, Lilly is a Fortune 200 pharmaceutical company based in Indianapolis with around 34,000 employees worldwide. Before joining Lilly, Meredith served as Chief Information Privacy and Security Officer for Henry Ford Health System in Detroit. In addition to her important corporate work, she's been active with numerous industry and community organizations. Meredith, welcome, and thanks for speaking with us today.
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveThank you. Thank you for having me.
Bob Bragdon
analystSure. Can you please take a few minutes and tell us about your background and your role at Lilly?
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveSure. So as you stated, I'm the Vice President and Chief Information Security Officer for Lilly. Relatively new to Lilly, actually. I've been with the company a little bit shy of 2 years. Next month, it will be 2 years for me. And prior to that, I had a really great opportunity at Henry Ford Health System to build their privacy as well as their security program over the last 16 years prior to coming here. But I've been in health IT longer than that. I've been around for about 26 years in the health IT space, have really enjoyed the experience as I've seen our industry grow and evolve over a period of time. It's been quite exciting. Starting from a help desk tech, an application developer or project manager, program manager, types of analysts, business analysts, things of that nature. So I've done a lot of roles within the IT space. And had a really great opportunity right after we did Y2K and the world didn't blow up like we thought it would do. We survived that, and we were able to start to look at things that were more regulatory-driven. And the next big thing for us at that time was HIPAA. So that's how I got into the privacy side of the world. And then security as a part of HIPAA became a part of my world as well. And so that's been a great opportunity again to marry those 2 disciplines together with risk as well as compliance, as well as legal, and really try to see how all of those pieces enable the business to move forward. So whether it is a provider-based organization, whether it's a pharmaceutical company, or any other type of provider or insurance company, I've had an opportunity to work in those spaces. So it's been a great 26 years. And hopefully -- I don't have another 26 more in me, but hopefully, I will spend a good deal of my time at Lilly and really be able to do some great things there as we continue to build our security program, which is, of course, paramount to everything we do within our space as we develop medicines for everyone around the world.
Bob Bragdon
analystThat's great. I'd like to take a look at your response to the pandemic across 4 areas if we could, people, partners, business operations and finally the community. How did you address the people needs of Lilly through all this?
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveWell, of course, people are important to us. It's the lifeblood of our organization, it's the way that we operate, we manufacture, we support our health care providers and things of that nature. But our employees are incredibly important to us. Our patients are incredibly important to us. So we wanted to make sure that we were ahead of the game and ahead of the curve when it came to doing anything that we needed to do to protect our team members. So early on, we did some assessments at the end of February, the beginning of March, and made a decision, probably one of the first within the Indiana market to decide to send our employees home to work. So we prepared within the last 2 weeks leading up to the beginning of March to say, what will it take for us to protect our team members or give them access to things that they need to work within their home environment, help them secure and protect those environments as much as we possibly can. And then allow them to continue to do the great work. Because at the heart of it all, we still have patients to serve. At the heart of it all, we still have medicines to make. And so how do we do it in the most safe and secure fashion that we possibly could? So we were a forerunner with that. And I'm very proud of the fact that we took that stance early on. So we have been working from a home environment for the last -- I want to say since March 8 or 9, we've been in this home environment. And I think for the foreseeable future, it's our goal to stay in this environment until we get to a point where we feel that we can safely return our team members to not only our corporate centers, but other centers around the world. So we're really making sure that our patients and our employees come first when it comes to that.
Bob Bragdon
analystThat's great. It sounds like you've done some pretty interesting things to support your business partners as well through this. Can you talk about that a bit?
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveYes. So like any other global company, we have partners around the world. We have a presence within our India market, and we have team members there that actually work for Lilly, not necessarily from a contract perspective only, but also these are actual Lilly employees that work for us. And so we wanted to make sure that we're taking measures there as well. So we had some very unique challenges that we had to address as it related to devices and whether our team members had the right equipment to be able to do what they needed to do in their work environments. And so we kind of was up against the gun to try to get devices shipped in time to those individuals so they could take those devices home and they could continue to work. And then we also worked with some of our key strategic partners to ensure that they were ready beforehand. So it wasn't a conversation we waited until it was the ninth hour to say, okay, now what are you guys doing, but we're having those strategic conversations along the way as we were preparing our work-from-home plan. We were also asking a lot of our large strategic partners, what are you doing? What are you doing to ensure that, that contingent workforce and that contract workforce that we have, have all of the things that they need to do their jobs? And then also, again, from a security perspective, how are we securing that information because we have critical data that's needed to perform those roles, how are we doing it in a more secure manner? So again, we didn't wait. We planned this out over a period of time. And again, very proud of how we executed against that to the point where we have been performing at a great rate here. Within our information security organization, specifically, we've been able to continue to move forward our agenda because we did plan early on for what we were going to do in the future.
Bob Bragdon
analystThat's great. So without the ability to manufacture, Lilly would be challenged to take care of people or partners. How did you enable the business to continue operations?
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveYes, so our manufacturing environments, once we got to the point where we were sending a lot of our business sales force and employees like that, we sent them home to work. We had to take a look at our manufacturing environments. We still had to produce. Again, we have 40 million patients that we're serving around the world. We still have to make sure that they have their insulin, we still have to make sure they have their medicines. So we took a look at the structure of our manufacturing sites and tried to figure out how do we incorporate social distancing in a manner that will be protective of the employee. Because remember, that's kind of the heart of who we are, it's our employees. And how we institute social distancing standards, how do we make sure that we are sanitizing in a way that will protect them as they're continuing to work the lines to produce those medicines. So we worked with our manufacturing facilities, we worked with our manufacturing operations to ensure that those measures were put in place. And we implemented those around the world in all 14 of our manufacturing sites. And so we were able to keep that pipeline going. We were able to protect our supply chain, we were able to continue to produce those medicines. We haven't missed a beat, honestly, when it's come to that. And that's truly what our patients rely on us for, right, to be able to continue to provide them with those life-saving medicines. So we made sure that we were doing everything we could to be able to shift schedules, to shift distances, anything that we could do to really help that move forward, we were on the ground with our manufacturing sites to be able to do that.
Bob Bragdon
analystExcellent. So the fourth area, tell us a little bit about how Lilly supported the community through this?
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveIt's been amazing. And again, patients. This is who we get up every day and we do this work for our patients. And so one of the things that we noticed that there was a financial and economic hardship to a lot of our patients as they were going through this COVID crisis along with us. Some of them were not able to afford their medicines, say, for example, their insulin. We had individuals who were having challenges with that. So Lilly decided that we were going to implement a cap on our insulin. So $35, that's what you would pay for your insulin, whether or not you had insurance or not, it didn't really matter to us. We wanted to make sure that, that medicine was affordable. We wanted to make sure that our patients had what they needed in order to sustain their lives. And so that was one way that we came to the aid of our patients and the community at large. Again, we wanted to make sure that they had everything that they needed. We have some other opportunities as well to be able to partner with 17 other organizations to be able to support COVID work moving forward. So we did -- up until this point, have been able to donate about $1.6 million towards efforts to be able to address the COVID crisis, along with some of the other clinical and therapeutic work that we're doing to be able to address testing. We've set up testing sites within the state of Indiana. We went into an agreement and a collaboration with our governor to be able to produce campaigns for the community to give them more information about COVID, how to address it, how to protect themselves. So we've been a really strong community partner. And again, we're very proud of that. What company would decide to step out and say, at our own expense, we're going to develop testing. At our own expense, we're going to stand up labs to actually run those tests. We are going to open it up to some of our first responders, give them the ability to get the test that they need, so they can continue to serve our community. We're going to do that at our own expense. We're not asking anyone to reimburse us, we're going to repurpose some of our labs to be able to do that. And so we were able to stand up drive-through testing as well, which was a heroic effort. Over a 3- week period, we were able to stand up this testing facility and have been able to test thousands of people at this point for COVID. So we've tried to figure out, as a company, how do we become part of the solution. And how do we do it in a way that is not a burden on not only our community but our patients or anyone else. So very proud of the work that we've done there. I can say specifically from a security perspective, as we were looking at that, I was so impressed with the way that our team responded. We got in there, we worked with our technical teams, we were able to stand up applications where people could actually go in and register themselves to get a test. We had facilities that they could come to at our corporate center where they could do fully drive-through, which was amazing. I had several of my team members who actually volunteered to do some of the processing of the tests. So they might have been the individual who was the runner. So they [ ran tests ] back to the lab, so the lab could actually run those tests. So I was really impressed with the way that my team, even though we do serve in a more technical and enabling capacity, they wanted to get their hands and their feet dirty, too, and they wanted to get into the game. And so the volunteer hours that we've seen, 1,200 hours -- 1,200 people volunteering along that stretch of time, very impressive and very happy and proud of my company.
Bob Bragdon
analystFantastic. I'd like to close with a couple of big picture questions, if I could. First, where do you think security is falling short? And what can we do to correct that?
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveYes. So we have been probably falling short in this space for some years. And I don't know if we really have a solid solution for how we're going to address it, but here's my thoughts and my theories. So we'll go with that. As it relates to creating security talent. And I know you've probably heard this, as you've spoken to other CISOs. I think that we are great when we have the right talent in our spaces. But how are we creating that pipeline for the future? And I think that we've heard studies over the years, where by 2020, we're going to have upwards of 2 million open security roles around the world. And we don't really have a pipeline, honestly, to address that. And so we've been probably having this conversation in the security space for, I want to say, probably the last 15 years of my career, and we struggled with what do we do to get young kids engaged and excited about the world of technology or the world of security? How do we ensure that we have minorities that are involved in this space, so we can continue to have a diverse workforce? How do we recruit, how do we train and how do we educate? And I think that we all struggle with it. It's not a Lilly problem, it's more of an industry problem for us, but I do believe that if we can't figure out, as the current professionals, how to prepare the next generation of security professionals, it's going to be tough for organizations to fully protect themselves. It's going to be tough for us to be able to ensure that we're securing not only our data, our assets, our systems and ultimately, our patients. So I think that's something we're -- I think that we failed to a certain degree. And I think that we haven't put enough energy in the people part of our strategy. We think a lot about the whole triad of people, process and technology, and I think we focus a lot on the technology, of course, because that's what we do as technologists. But there's a people component that not only employs our individual team members that we currently have, but it's a people strategy around recruitment, it's the people's strategy around development, training and awareness and education. One of the things that I've tried to do, though, to say what is the one thing that I can contribute to this, so at least I can say I'm part of the solution is I've tried to partner over the years with a couple of universities to work on their curriculum committees as it relates to their cyber programs to say, here is the skills that we need for a student to come out of your university and to hit the ground running with the practical skills that they could use that are not just theory-based, but they're practical in nature. And how can I help you design a curriculum that would be useful for us in the industry. And so I had some great opportunities to do that in a couple of different instances. And so hopefully, my colleagues across this industry will start to do more of that, mentoring more, exposure more. People can't become what they can't see. So if we're not offering that opportunity for them to see and meet and engage with security professionals, they may not even know that it's an opportunity or an option. So I think that, that's 1 area where we could probably make a lot of strides if we just focused all of our energy there.
Bob Bragdon
analystYes. I agree with you so much on that. That's been an issue for so many years in security. And we see so many people trying to contribute to solve this problem, it's just such a -- it's such a massive mountain that we have to be able to climb to fill those 2 million roles, right?
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveIt is, it is.
Bob Bragdon
analystHow would you like to see security transform itself, given all the shifts you've seen in the business environment this year?
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveSure. I think that when we first started out as security departments were starting to formulate years ago, and we were standing ourselves up as a part of technology organization, Lilly was no different. Henry Ford was the same way. I think that as we look to the future of how we need to evolve, I think we have to become more of business partners versus just the technical arm of the people who as we used to say in the hospital environment that sit in the basement and just make sure that all the systems are running. So we're -- no, we no longer can really think like that. We have to make sure that we are at the forefront of those decisions. Because truthfully, when you're looking at what the business strategies are, there's nothing that we can do in our industries, no matter what industry you're in, without some level of a technology component. We're not operating in paper environments for the most part. And digital and technology is really what drives and enables the business. But those decisions have to be made in conjunction with security, in conjunction with technology or IT, if that's what you call it within your organization. You have to have them at the table. And so I think that we have to start to push ourselves to think less as technologists and more as business enablers and business partners that are working alongside the business to be able to make those decisions strategically with those things in mind at the beginning of it all. So how many of us as security professionals have been in this situation where a project has moved forward. It's been sanctioned by the board. We've started to implement, the business was involved, and then they come to security at the end and say, hey, do we have any security issues? Well -- and I think all of us have stories like that, right? So how do we move us further ahead in the chain where we're having that strategic conversation? So being more partners, which means in order for us to do that, we have to be able to know and understand our business. I just can't be the technology person. I have to understand how my medicines development unit runs. I have to understand how my manufacturing and quality organization runs. I have to know the business part of my world in order for me to consult with them appropriately and enable them appropriately. So it's going to cause us to think differently as technologists. We're just not the techie people. We really are the business integrators, if we think about it in that regard. And so that's where I would hope, over time, we will shift fully into that space. I think another area where I would like to see us grow and evolve as an industry would be around risk management. At the end of the day, we're managing risk within the organization. Security just happens to be our vein of risk. So how do we make that more a part of our structure? How do we help people to understand that every decision that we make from a technology or a security perspective is a risk decision based off of the organization and based off of the tolerance of the organization in terms of how much risk do they want to incur. I think some of us have started to make that transition into more of a risk-based framework. But have we collectively as an industry moved down that path? I think that there's still some opportunity there for us to do so. So I hope that as we continue to grow, we will see more of that infused into the work that we do everyday.
Bob Bragdon
analystMeredith, it's been a pleasure speaking with you. And we truly appreciate your insights. Thanks for joining us.
Meredith R. Harper;Vice President, Chief Information Security Officer
executiveThank you so much. This was a pleasure.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Eli Lilly and Company transcript — plus 250,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Eli Lilly and Company earnings transcripts and 250,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.