HP Inc. (HPQ) Earnings Call Transcript & Summary

July 22, 2020

New York Stock Exchange US Information Technology Technology Hardware, Storage and Peripherals conference_presentation 22 min

Earnings Call Speaker Segments

Bob Bragdon

analyst
#1

Good day, and thanks for joining. I'm Bob Bragdon, Senior Vice President and the Worldwide Managing Director of CSO. Today, we're speaking with Sherban Naum of HP Security. I've known Sherban for a bunch of years. So we always have a great discussion about what's happening in the industry. So Sherban, thanks for sitting down with us today. How are you?

Sherban Naum

executive
#2

I'm doing well, and you?

Bob Bragdon

analyst
#3

I'm doing great, thanks.

Bob Bragdon

analyst
#4

What do you see as the greatest security challenges facing businesses today?

Sherban Naum

executive
#5

So if you look at businesses today versus just 6 months ago, right?

Bob Bragdon

analyst
#6

Probably we're going to delineate like that.

Sherban Naum

executive
#7

We're going to go right through it. I think that the biggest challenge right now is how does one extend those enterprise resources that they had behind a corporate firewall out to the remote user base and how does actually one implement audit and controls and visibility as well as asset management related to all of the users as they've moved outside of the office and into their dining rooms and dens and in basements or wherever else their new work environment. I would say that, that is the greatest security challenge because the threats themselves haven't really changed. They've increased and perhaps even the success rate has increased because of my first point, how does one extend those capabilities to a device that may not -- that's not within the corporate firewall, that's not always connected to the enterprise resources and have users that may be distracted.

Bob Bragdon

analyst
#8

So something that every business has but few seem to be addressing is technical debt, which kind of fits into this whole story, right? How does technical debt fit into a business's approach to security?

Sherban Naum

executive
#9

Well, Bob, you and I have been doing this long enough to know that technical debt and legacy systems and applications and business practices are really the anchor that has hindered a lot of these enterprises to modernize, right? You look at what the -- all the efforts around digital transformation and what the application of artificial intelligence and all these other machine learning capabilities have been doing. And those industries and enterprises within each of those industries that as they've been modernizing, they've been able to survive these monumental shifts of the enterprise. While, if you look at it -- when you think about it the sheer cost of migrating some of these legacy systems or maintaining them and upgrading them and the like. And as enterprises are looking to new platforms in the cloud and artificial intelligence, the other things I noted, really comes down to sort of a root of trust discussion, right? It comes down to least privilege in reducing their exposure and protecting their high-value assets while allowing their users to be successful and operate their business. So I think technical debt is one that I just don't see many -- if you've been in business for longer than 3 years, you've got technical debt.

Bob Bragdon

analyst
#10

You've got a technical debt, yes.

Sherban Naum

executive
#11

It's just what it is. And the vast majority of these large enterprises, the shift to this digital transformation and modernization of their enterprise, it really is around moving to a modern architecture. It is around trying to determine what are the business needs, how does the IT support those business needs, and then how does security play a role and actually enabling the IT OPs and business OPs to operate in a secure environment.

Bob Bragdon

analyst
#12

But it's tough to -- I mean, we're really talking about ripping and replacing, if you want to get rid of technical debt, right? Nobody does that these days, right? Or very few.

Sherban Naum

executive
#13

Well, I think that a rip and replace or bringing a forklift model just doesn't -- it doesn't scale, right? It's just not going to work. I do think that however, a lot of these enterprises that have been successful and have actually grown over these past 3, 4 months, they've adopted modern architectures. They've looked to move and migrate a lot of their systems where scalability and elasticity are the model -- are the modern architecture and way of doing it. And then as they move to this modern architecture, the way I look at it security is if you can -- if you move to a modern architecture, while still enabling and in the context of security protecting that legacy, then you stand the chance to survive the next 6, 12, 18 months' worth of business ops. And then as you make those migrations to these modern architectures, where you're looking at integrity and privacy and audit and virtualization and all the things that a modern architecture requires, then you can start deprecating some of those legacy systems. And you know as well as I do. Those legacy systems aren't going anywhere for some time because they're tied to the data that drives their business, right? And so the question becomes, how do I secure the access to that data? Or better yet, how do I secure the device that is accessing the data? Because ultimately, as much as they want to know my personal e-mails, they want to get to the HP infrastructure, right, if they're [ going to attack ] me, right? They're not coming after me because I'm of interest, but I might be a conduit because I'm externally facing, I'm constantly dealing with the outside world. I interact with people all the time and I receive e-mails, random e-mails all the time. The question is, how does an enterprise modernize to support me in my new environment, my new work environment on modern architecture and on modern infrastructure without being a burden to IT, right? One of the -- it's interesting, Bob, I think you and I talked about this a couple of weeks ago. We all talk about the remote user today, right? All the systems -- in the first phase, everything was get everyone a new device, get everyone a VPN connection, dual-factor authentication and don't forget a lot of network, right? That was sort of like the very first move, and then they've realized that, well, wait a minute, people still need to connect and then do something about it. They need to connect securely. And we need to make sure that while they're sitting at home and -- or wherever they may be working, certainly not in the office, how do I provide that sort of real-time visibility into the security posture of my device and my user? And what is my user accessing? And what -- when are they accessing it? And should they be accessing? All those things come into play when it comes to the original question of an enterprise security concern today, right? We talked about also the admins themselves are remote. They're at home.

Bob Bragdon

analyst
#14

Yes, yes.

Sherban Naum

executive
#15

Right? And so these are the folks that manage infrastructure, your routers and passwords and the applications and the storage. And all the elements that maintain and operate that business, they're remote. And so now are they the ones who have to be targeted? And again, to me, my whole thing around security is identify what's of high-value, the crown jewels, and protect them in an absolute way. And then extend those capabilities and protections around access control, attesting that the device is the right device, that the user is the right user, that the system actually booted the right way. One of the things we do at HP in terms of designing in security into the hardware. Leveraging the hardware, designing secure BIOS and secure firmware and measuring the boot of the device before a user even sees Windows pop up on their machine, right? So we've got to move toward a modern approach of how do I reduce risk? How do I provide least privilege of not just the users' access to the data, but the attacker user to the device and then to the data and instrument this in such a way that it is -- it's a very easy process to migrate to this modern architecture.

Bob Bragdon

analyst
#16

Do you think security needs to be invisible then? Is that what you're getting at? Or is it good to have a little bit of visibility there, some people like they get their MFA text and things like that?

Sherban Naum

executive
#17

Right. No, I think that we, as users, are the ones who -- what 95% of the time invite the adversary in. I mean we're the easiest way in, right? And so there ought to be beyond training because you're not going to train me not to click on something about my money, my family or my ride, that's just what it is. Eventually one will get through. The question is, can I design in security so that the enterprise removes me from being that final cybersecurity decision maker. Ultimately, the security decision starts with the security team and the IT leadership that truly understand the systems that have to operate to maintain their business or in the case of a government space to maintain their mission. Fine, let them make their decisions and extend those decisions to me, but do it in such a way that I'm not the one that has to make that final cybersecurity decision. So it's not necessarily invisible. But if you design it in, where I don't have to sit and wonder, is that really an attachment [ from Bob ], right? Is that really a link that Bob -- what's a Bitly, right? I don't even know what Bitly means, what is that right? Well -- and I'm in the security business. So now you look at the business user who gets Excel spreadsheets with macros, and they're getting Word documents with embedded files and the like. There's no way of making a determination if something is good or bad, 100% of the time. We know that. There's no perfect detector. So now you're expecting technologies that can't do it in detecting 100% of the known bad, you're expecting me, the user, to make that decision. So no, I don't think it should be invisible, but I think it should be seamless, right? And if you're leveraging those same properties of why people are making the migration to digital transformation and the cloud and workloads to clouds and on-demand solutions and services and applications, why aren't we looking to those very same technologies that the cloud providers are leveraging, which is all hardware and hypervisor-based technologies? Well, let's just leverage that for the user. That way, when the user is not connected to the VPN and the enterprise doesn't have real-time visibility into what I'm doing, did I click on the right thing or not. And those systems that are on my machine can act like the enterprise. They can act like those cloud providers, where suddenly I can abstract the potentially bad, provided -- throw them in a container or in a virtual machine and allow them to execute like a detonation chamber, right? And then suddenly, you're not worried about did the malware land on my laptop? Did it persist? Is it now waiting for me to connect to some certain IP address or VPN connection to move laterally, [ and then you see the ] login screen scraping and all those other fun things.

Bob Bragdon

analyst
#18

Yes. So be honest now then. Do you believe most organizations are prepared to mitigate the risks that they face?

Sherban Naum

executive
#19

I think a lot of large organizations of the government have done a lot. I mean they really have. Obviously, it's a huge industry. A lot of monies are being spent. They've got the technical acumen, they've got the will to get it done. I think the challenges start as soon as you let me, the user, click on something, right? If you think about all the layers that are put into place, enterprises have been preparing, and they've been let down over the -- 3 decades. We didn't do this for 3 decades, right? And for 3 decades, they've been implementing architectures that say, today, I know I've got a problem. I'm going to buy a solution that solves for that problem. But architecturally, were they robust enough to survive 5, 10, 15 years? And so a lot of enterprises have been expanding a tremendous amount of their limited budget on trying to solve the problems that we know today. I mean, every vendor, all of us have these wonderful slides that show these are the things we protected you guys from, right? Everything that's known and understood and rationalized. And by the way, sometimes we're able to guess if something bad shows up that doesn't look like the stuff we've seen in the past, right? But how effective are those, 92%, 93%? These are the numbers you're hearing in the industry. So the challenge is, how do I put in a system that says, well, when you make that decision at the time you purchased the product, you bought it because architecturally, it is robust, and it can provide you that extra slide, well, we don't yet know the names of the attacks. We don't yet know what is yet to come, but it can still provide the protection because architecturally, it's a modern way of reducing the amount of risk potential to that endpoint. And I focus on the endpoint because 90% of the time, it comes to be at the endpoint.

Bob Bragdon

analyst
#20

So then what are the steps that organization should be taking to address these challenges?

Sherban Naum

executive
#21

Well, I'm on the record, too. Okay.

Bob Bragdon

analyst
#22

I didn't -- never said I wasn't going to put you on the spot.

Sherban Naum

executive
#23

That's right. That's right. I think the large enterprises and large -- the governments of -- that we work with, they're making the necessary steps. They are evaluating what are those modern ways of advancing and transforming their overall enterprise. And I think that's the first thing. The first thing is, what do you do and what keeps you in business, protect those assets dearly, right? And then how do you extend the same level of protections down to your users? I think that is happening. I think where we could help and I think where -- when you ask, are enterprises ready? Let's qualify the size of the enterprise, right? I think the real pain is being felt by the SMB market, right? The small and midsized market, they're in the business of producing something or they're delivering a service of some sort. And quite frankly, they may not have the means to hire 500 cyber experts that live around the world, doing nothing but reviewing the posture of an enterprise. They may have 1 person that has to carry the burden of IT and networking and securing and the like. And that's where I think -- one of the things that we've been working on is how do we take what we've learned and delivered to the enterprise and deliver that as a service down to the small and mid-market. And I'm seeing a lot of traction where a number of us out there that are actually trying to solve the cybersecurity problem. And we do it in a novel way, in a very differentiated way. But we're realizing that the large enterprises, they make decisions -- they put a lot of thought into it. And they have a lot of experts that can help them with that decision. And they evaluate, and they will run it and test it and make sure it operates in their environment. But how do you solve for the small and mid business, which today is suffering? Let's remember that for the past 3 or 4 months, their #1 objective was viability, right? And so now the question is, can someone that is a small and midsized business, a few hundred employees, they are doing everything they can to maintain their livelihood, the livelihood of their employees. Do they have the resources to hire a very expensive cyber expert or do they just look to an HP with what we're doing for Proactive Security around, hey, I'm going to ask you, you're experts in this, you understand endpoints, you understand how all these things work, you have technologies that work, let me just offer it as a service. And so your question is interesting because I think the large enterprises, they suffer, right? They're not -- they -- back to my earlier comments about when they bought the technology, it's sort of a whack-a-mole, right? Like I bought this thing and I'm going to try and I'm going to hope that it works in 2 years from now, which is why we've seen a cycle where it went from 10 years ago, the browser was the ultimate killer, right? The browser was bad, and then it was PDF. And then we were starting to see this move where AV wasn't cutting and you moved to a next-gen AV and then EDR and the like. We've seen these evolutions. Same architectures just on the back end, they've got more brains behind, other cyber analysts or they're looking at the cloud, to be able to enhance the overall visibility. But the reality is SMB, they may just be thinking about, I want the bare minimum because that's all I can afford. I don't have the expertise. I can't afford all these great technologies. And so maybe the large enterprises have the funding and the budget to make decisions every 2 or 3 years because their business has changed and their threat landscape has changed. But the SMB market, personally, I'd like to go focus a lot of time on the SMB market because I think that that's where -- they're struggling, let's help them, let's provide the expertise. Someone like yourself who has been doing this for so long, you understand the market, you understand the technologies. You know all of us out there that are trying to [ vie ] for business and make a difference, absolutely. But the SMB market, do they have the resources and the access to be able to make those decisions or shouldn't they be looking to experts to help them with those decisions and just implement solutions where they know my user isn't the cybersecurity decision-maker, my systems are protected as best as they possibly can. I've got the visibility into what's been affecting me in real-time, and I can continue on with the work. We have this -- we have a number of customers that call us and say you saved our bacon again. And that's not exactly the word that they use, but that's how they look at it. And they were saying, we were hit by [ MITM ], we were hit by ransomware, we were hit by all these things. Now for a large enterprise, they've got a number of systems and backup and all these things that will save them if something happens, right? But think about a small, midsized company that is going -- they're making that transition to the $100 million of revenue or the $500 million of revenue. They are growing. What would happen if all of their data were out in the street? You know as well as I do, they don't just encrypt the drive when they hit you with ransomware. They pull everything off the drive. And then they encrypt, right? So all of your personal details and your corporate IP and the like, they're all sitting on the street there, right? What is the impact there? And that's where I think we, as an industry, ought to be looking and delivering solutions that actually support the largest percentage of businesses. We all want the large enterprise, but -- don't get me wrong. But the biggest percentage of businesses out there that have these challenges are in that small to midsized market. And I think that's -- if we, as an industry, look to them and said, look, we got it, we're going to help you out. We're going to provide you with technologies that stop [ MITM ], stop the ransomware and stop all these attacks. And we're going to do it as a service. That then goes to the digital transformation, right? People are moving to as a service, people are moving to cloud, people are moving to modern architectures. And the small and mid business aren't going to be looking at AI engines and the like. What if they found a company that did? I think that's where companies are -- if they're prepared or not, I think that's the conversation which you're going to have.

Bob Bragdon

analyst
#24

Yes. And not for enough on a side note, all those SMB businesses, they're the partners -- business partners of big enterprise businesses.

Sherban Naum

executive
#25

That's right.

Bob Bragdon

analyst
#26

And that's that vulnerability channel right up into the large enterprise that the adversary is trying to take a hold -- advantage of.

Sherban Naum

executive
#27

How hard would it be if I'm trying to get into -- pick any large enterprise. And we know they spend. They have a $0.5 billion budget a year to keep that enterprise lockdown. If they have a -- to your point, a provider, a manufacturer support team. They have a law firm. If I want to know what someone's doing, I'm going after the law firm.

Bob Bragdon

analyst
#28

Yes. Yes. Exactly.

Sherban Naum

executive
#29

They're involved, right? And so as much data as the adversary has right now, who does Bob bank with, who does Bob -- who's his lawyer and all that? I'm going to go target them because Bob is an expert.

Bob Bragdon

analyst
#30

Yes. So one final question then. When you look at all the things that we've been discussing, how is HP helping to address these challenges?

Sherban Naum

executive
#31

So I came via an acquisition back in September. And when I was looking at the acquisition, I was trying to figure out like, okay, where do we land? And within days, weeks and months, I realized that actually, HP is a security company first. And I mean that when I say it. Think about the sheer volume and velocity of investments around platform security, around hardening their endpoints and their printers. And you start looking at as a security company and then they deliver their products. Now they don't -- people aren't looking at HP as a security company, but everything they do starts with call it that root of trust, meaning I understand the security posture of this device, and I'm going to maintain the integrity of that device. And so what is interesting is we at HP now are saying measure boot with a trusted BIOS. And let's make sure that device actually delivers at the time you're booting the machine, so Sure Start. When you start looking at if there is an issue, they've designed in this solution called Sure Recover, where within minutes, we can revert back to the known good image where even if the device is fully encrypted, we can undo that or Sure Run, which is one of those things that we all as the end user community adore, you want to turn something off. Well, your enterprise doesn't get by design, but Sure Run, which is designed in can do that. What we're doing with Sure Click Enterprise in terms of we stopped all those attacks. And we provide real-time isolation and then real-time identification of the entire kill chain with all the telemetry and the binary. So when you start looking at what enterprises are needing, back to my very first point. They need audit, they need control, they need visibility, the integrity of their enterprise. Those are the 4 things. By design, we've built those into the devices. So when we ship the devices, they're getting all these technologies. Yes, some of them are licensed, and there's some additional components to it. But for the most part, back to the SMB, back to those small businesses as well as some of the large enterprises, a lot of these technologies that we're delivering, we're delivering design into the device when we ship you the device. And that is a huge step forward, whereas before, we think 5 years ago, if someone needed to measure the boot cycle of a device and then actually take measurements with TPMs, all the dock we were talking about, what, 10 years ago, we were talking about TPMs, right? And there's no way of actually understanding was the BIOS modified or not. Well, now we actually -- we ship these devices with these technologies. And so I think we've seen an acceleration of capabilities because of hardware. We've seen the growth and explosion of cloud because of hardware. HP has taken hardware-based security and platform security seriously. And that's why I said HP is a security company first, where we're delivering these solutions, we can deliver out of the box to our customer [ set ].

Bob Bragdon

analyst
#32

That's great. So Sherban, thanks for sharing your insights with us. It's always great to catch up with you.

Sherban Naum

executive
#33

Looking forward to seeing you again in person.

Bob Bragdon

analyst
#34

Absolutely. Take care.

Sherban Naum

executive
#35

Take care. Thank you so much.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete HP Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to HP Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.