Information Services Group, Inc. (III) Earnings Call Transcript & Summary

July 21, 2020

NASDAQ US Information Technology IT Services special 52 min

Earnings Call Speaker Segments

Jolene Goh

attendee
#1

Good morning, everyone. Welcome to Lookout and ISG joint webinar on Rationalize IT Spend to Optimize Cybersecurity Posture. I am Jolene Goh, Sales Manager from Lookout. Let me do a quick introduction of our speakers and the company they represent before we got into the webinar. Our first speaker is Don Tan from Lookout. Don brings with him over 17 years of technical, sales and management experience in the cybersecurity industry in Asia. He currently holds the post of Senior Regional Director, where he is responsible for the business in Asia Pacific region. Founded in 2007, Lookout is focused exclusively on mobile device and mobile app security and is a founding member of Post-Perimeter Security Alliance. With 190 million users globally and having the largest corpus of analyzed mobile codes in existence, Lookout is the market leader in the mobile security space. Our next speaker is Deepraj Emmanuel, Director of Asia from ISG. Deepraj has extensive experience in successfully driving differentiated strategy and execution for some of the largest initiatives in Asia, focusing on helping organizations plan and undertake a risk-averse approach to large complex technology-enabled business transformations. ISG is a NASDAQ-listed leading global technology research and advisory firm founded in 2006. They focus on helping companies achieve operational excellence and faster growth. It's trusted by 75 of global top-100 enterprises, with 1,300 professionals across 21 countries. For this webinar, we have prepared some interesting topics for you. We will go through the world as we know it, the future, where -- just give me a minute, sorry. I think I jumped a little bit too quick. Sorry, let me go back to this one. So for this webinar, we have prepared some interesting topics. We will go to The world as we know it, The new future, Where do we go from here? And at the end of the webinar, we will provide you with some key recommendations as a takeaway. We will have a Q&A session at the end of the webinar. Hence, if you have any questions, please feel free to put them into the question box, and we will answer them at the end of the webinar. Without further ado, let me hand over the presentation to Don.

Don Tan

attendee
#2

Thank you, Jolene, and a warm welcome to everyone on the call today. I know you have many choices and selections of webinars you can attend, and we are delighted to have you join us on this call.

Deepraj Emmanuel

executive
#3

Very warm welcome as well. Thank you so much, all of you, for coming to the webinar. I really appreciate the time that you are giving to us today. So Don, how have the last couple of months been for you?

Don Tan

attendee
#4

Deepraj, it seems like the current situation with COVID and lockdowns and generally just the complete halt to the economy has impacted all of us at all different levels. The virus per se has wreaked havoc throughout the population and economy. And it kind of changed the world we know it. The world today seems a whole lot more volatile, uncertain, complex with tons of ambiguity. And as much as on a personal level, I think this has caused quite a fair bit of anxiety, both for individuals and businesses. So I think this is a fair statement that most of us can relate to.

Deepraj Emmanuel

executive
#5

Absolutely, Don. So as we look to the current shelters-in-place, we look at things opening up. A lot of it is now starting to sink in. A lot of people are getting accustomed to what has been widely now defined as a new norm or the new reality. I think what is important is to really sort of focus on whether this is something that is here to stay.

Don Tan

attendee
#6

Again, to that point, Deepraj, I think, like, all life-changing events, if you remember, SARS back in the early 2000s, 9/11, how that has changed the travel industry, introduced new regulations as we crossed through immigration, I think COVID is going to be a big life-changing event. There will be definitely certain elements of it that will stay. And I think what will happen is, it's definitely going to redefine how we live and coexist, whether is it between social interactions, between friends and family or business communications and even, for the matter of fact, how we learn, right? And I think one of the biggest sticking point, the biggest issue that most of us face is I think it's a lack of clear separation between work and life, right? What used to be a 30-minute to 60-minute travel to work has now become a 3-step process from your bedroom to your study. And again, this has brought forth a whole lot of convenience as well. Having the ability to work from home now then allows us to also adopt or accelerate the adoption of a lot of these new technologies that are out there. It has redefined what it means by eating out. We kind of order out and then eating in, right? Of course, it has also made it so much more convenient when it comes to buying daily necessities or just essentially quite a luxury item.

Deepraj Emmanuel

executive
#7

That is really interesting, Don. I mean I think, fundamentally, we also need to examine whether this is setting a new global culture.

Don Tan

attendee
#8

Well, as I said earlier on, right, I think COVID-19 is a life-changing event. Most -- some experts are saying is once in a lifetime. But there will be certain elements that will ramp up emphasis. But I think the biggest question is, is this -- is everyone really worried? Right? At various levels or, I would say, at various age groups, what you're going to have is the fear of change, as the older part of the population tend to resist things from happening and learn something new, but I think what COVID has really done is to kind of throw us off the deep end and give us the push needed.

Deepraj Emmanuel

executive
#9

And Don, do you think that this basically affects how enterprises are also behaving today?

Don Tan

attendee
#10

Deepraj, that's a very, very good question, I think, top of every executive mind and all management today, as they think of how lockdowns today have brought the economy to a complete halt, and this is something that has never been seen before, how it's impacted earnings from a top line perspective and how companies are trying to strive to see how they can accommodate this falling top line. Executives are currently thinking hard to see what they can do to spend less and still remain competitive, right? And I think one of the key things that is very different from what we have seen over the course of time is that one of the key pivots we have is cloud and mobile technology and that might just be the silver bullet that we need, right? For years, companies have been dabbling with a motion of allowing employees to work remotely and giving them the necessary flexibility. Pressured with cost reductions. I think this lockdown gave the push that most companies needed. The pandemics have kind of shown that companies can operate effectively virtually with no physical footprint. And they're starting to realize that -- and think that -- do I really need expensive real estate in order to function?

Deepraj Emmanuel

executive
#11

That's interesting, Don, because then I would say that the social experiment that you talked about earlier has not become a pretty big enterprise experiment as well, correct?

Don Tan

attendee
#12

Exactly. It feels like this time that most of us don't really have a choice, whether be it individually or from a company perspective. And I think that this will redefine how we work and play. But I think what I wanted to know from you is based on your experience and the customers that we have been talking to in the industry, what do you think the future holds for us?

Deepraj Emmanuel

executive
#13

Absolutely, Don. So fundamentally, what we see, I think this is something which I personally do believe we will overcome. This is just another bump in the road like there've been so many. I'm hoping against hope this period of the pandemic will come to an end. But I think what we need to definitely focus on is the fact that the culture that is being established during these times might definitely stay. And that is something that we do need to adapt to. We need to be able to align to what is the new world, the new norm looking like.

Don Tan

attendee
#14

Right. And I think you're right. If you remember earlier on in the previous slide, I talked about how cloud and mobility might potentially be the pivot point. In fact, the trend has been around for a while now, at least the last 10 years. It has kind of laid the foundation for us whereby most companies have some shape or form of their data in the cloud, if not all. And again, from a -- this is not something that's broad-based. You see the smaller companies starting to adapt to this more aggressively and much larger organizations starting to accept this, right? From a user perspective, you then have users now spending more time on their mobile devices. And this has accelerated tenfolds, especially during this period. And you see utilization of mobile device has now become the focal point of life, right, not just from a personal aspect of things, but from a business perspective as well. And what's really scary is these devices are exclusively connected through a shared medium. What that means is that unlike the traditional cable to PC approach. There's not really cable that you can plug to your phone. What essentially this means is that the corporate perimeter has disappeared.

Deepraj Emmanuel

executive
#15

Sorry, did I hear you right? Did you just say that the corporate perimeter had disappeared?

Don Tan

attendee
#16

Yes. So this has been happening for a while now. It's not something new. And the hackers and the bad actors know about this, right? And this has been reflected in the exponential growth in mobile-related incidents that we have seen in the last couple of months, right? So how we look at things is, we believe that the world we live in has changed. We have been changing for a while now. What really set the ball in motion was when BlackBerry first introduced the phone and then that kind of accelerated later on with the introduction of the first iPhones, right? As companies started embracing mobility, they have kind of evolved the way they interact with their users, trying to drive more efficiency, productivity by giving them the ability and flexibility to work from anywhere and any place. And what we have also seen, right, interestingly, in the last couple of years, this effect has also trickled down to how businesses engage with their customers. In fact, I believe that we are now living in the pit of the next digital revolution whereby we are experiencing broad-based growth and adoption and consumption of mobile technology, right? And you are even seeing -- and for the first time ever, you are seeing companies that have appeared that are exclusively on a mobile device. What I mean by that is that we are exclusively interacting with their customers and engaging with their customers through a mobile application. The likes of whether be it Uber, Grab, Foodpanda, and, of course, there are some more to come.

Deepraj Emmanuel

executive
#17

But that sounds like quite a good thing, isn't it, where all of these different facilities are available to a lot of different customers. Is there something -- is there a reason why you're actually highlighting this specifically?

Don Tan

attendee
#18

Yes, you see, Deepraj, the problem is this, as companies chase revenue, the big focus of any company essentially is to make money, right? And I think you can agree with me on that. But the focus on the business is to make as much as I can. But unfortunately, through the mad rush, as they start adopting technologies that can enable and drive their business, security has always taken a backseat, right? That means that I'm not going to do anything until something happens. And most companies fail to understand that this initiative has exponentially broadened their cybersecurity risk surface. Traditional legacy security policies might no longer apply, right, because we have always -- from a security standpoint, companies have always built a layered approach. And the main goal of focus and the main goal of protection behind it is always that main walls of your office or your company, right? And it's always under the notion and assumption that users are going to be protected behind these layers of security there have been. Failing to see this early might be implications that might later lead on to something much bigger. And so let's take a quick poll and kind of see what our audience thinks about this. All right. And the question is, do you have security software installed to protect your mobile devices, whether is it personal or corporate-owned? And Deepraj, as we wait for the results to come in, based on your interactions with some of the biggest companies in the region, how do you see the impact of corporate IT spend versus security rationale?

Deepraj Emmanuel

executive
#19

That's a very interesting question, Don. Fundamentally, I think there has been a significant change in behavior in the way how a lot of corporates are actually aligning their security spend in line with their overall IT spend. I think, fundamentally, a lot of companies are being very careful. There is a lot of pressure on driving excessive cost savings. But maybe it's important that we sort of look at this with a wider lens and maybe look at some of the key behaviors that we're seeing globally and in the region as well. So this is really interesting. I'm looking at the poll results. And effectively, I think, to answer the question, do you have security software installed to protect your mobile devices, 60% of our audience today have said no, and 40% have said yes. And you see, this is very key because it sort of just reinforces some of the points that you were making earlier, Don. There is a whole lot of focus on trying to make sure that the way of moving forward is to be able to survive, to save, to be able to scale the storm. But then I think the question really is, are we missing out on some of the key elements that do require focus from a security and from a risk posture. So I think what would be very useful is if we could actually just maybe get onto a bit more detail on what we are seeing with a number of different organizations at play. The bigger picture is that the focus is to survive rather than transform, and the focus is to be able to have reduced IT spend across all sectors, some very excessive, some trying to still sort of run their core functions. But what we've seen is that, to a certain extent, there could be certain perceptions that are driving decisions being made. And when that actually is quantified to be able to determine what is essential spend, then sometimes the focus just becomes to reduce cost. It's not necessarily to look at new business models in the wake of the current global crisis. And effectively, I think while we are looking at a number of employees and customers being empowered digitally to access their core functions and perform their duties, the consideration of the risk factorial, that is at a minimum. I think this is something which we are seeing constantly. Is that something that you're seeing as well?

Don Tan

attendee
#20

Well, we know that organizations are cutting down on nonessential spend. And this has impacted different industries in different ways, some more than others. But from across industry's focus perspective, I think, on cost reduction, different behaviors do drive different kind of activities. But based on your experience, Deepraj, do you think this approach is effective, especially in this new world that we live in?

Deepraj Emmanuel

executive
#21

So Don, what is really interesting to note is that when you look at how this particular approach actually works in the current global scenario, a couple of interesting points to highlight. Companies are, as you saw on the previous slide, looking at significant targets of cost reduction. And that might actually definitely help the balance sheet to look better, right? And it might appear as if you are able to sail the storm, there is continuity, and we don't disagree with that. I think the fundamental question, however, is that is it just about the cost reduction right now or is it to still be able to grow, be relevant to customers in the long term? So surviving the storm is one absolute focus point right now. But then most of the approaches that we've seen with a lot of customers tend to being more short term and these approaches can hamstring business growth. And if the optimization of the short term is not coupled with the long-term transformation in mind, then there's going to be a significant impact on a number of companies on their competitive edge that they present to their customers today.

Don Tan

attendee
#22

Okay. But if I just stick this from a personal point of view, right, like stick myself, for example, I would always go -- especially during the situation right now, I would always go and look for the best [ in the town ], right? Most of us -- or most -- maybe some of us might not compromise on quality, some might. Do you think this is something that the enterprises are also doing?

Deepraj Emmanuel

executive
#23

I believe a number of enterprises are doing this. And when enterprises do this, the effect is multifold. It can cause drastic outcomes, not -- we are not painting a broad brush here. We're not saying that every organization actually has -- is under the same lens and has the same practices, but I think we do need to look at the current behavior of a lot of organizations that we work with.

Don Tan

attendee
#24

So you are saying that enterprises are doing this, and this is a pretty strange phenomenon. Are you saying that this is something that only impacts the smaller guys? Or this is something kind of across the board?

Deepraj Emmanuel

executive
#25

So Don, what is interesting is that I don't believe it is to do with just the size of the organization. I do believe that it's really the nature of the people, the decision-makers who are basically executing some very key decisions as part of scaling the current storm. It's human nature to react. I think it is definitely more well thought out process to be able to respond to something after sufficient factor has been considered. But what we're seeing in a number of cases is what is called the heat-of-the-moment focus, right? So we see significant impulsive spend to be able to take care of specific use cases that have actually been paused because of the COVID situation. There is an adequate focus on the risk that some of these decisions might actually sort of bring in, and there's obviously an extreme focus on cost. But I think what's extremely important is that organizations need to avoid doing something like this. I'll give you a good example. Very recently, we were talking to one of the key large enterprises that we actually deal with almost on a monthly basis on a number of different engagements. See, they had their security posture pretty well lined up in the traditional set of what they were doing. And within 2 weeks, I think when the directors actually came for employees to be accessing confidential company information remotely, they had to buy a whole lot of VPN licenses because the number of licenses that they had in the past was not equal to the number of employees. Now whether it was the right or the wrong decision, that is subject to talking to the decision-makers there. But fundamentally, I think what's important to note is that a situation like this has actually taught us that we do need to keep the alignment to the security posture pretty close to heart, and the focus is not just to keep the lights on, but to be able to actually look at it more holistically. I wonder what enterprises should also do to be able to avoid something like this from your perspective.

Don Tan

attendee
#26

You see, Deepraj, the thing is this. As your -- in as your slide, as you mentioned, in the heat of the moment, right, a lot of time, anxiety drives emotions, right? And we fail to contemplate what is going to happen in the mid to long term and kind of just look at the sky above the -- where we are living, right? I think it's very important. And this not only applies to whether it's your security posture or what you intend to do with the business per se, right? But before planning a journey or before embarking on a journey, I think it's very important what every one of us need to do is to kind of pick a destination because how I look at things is that you have to know where you're going to go before you can plan your journey there. And a lot of organizations that we work with do not really consider security as the risk, at least not during the current crisis. As you said, most of them are in survival mode. And it seems to me that the focus on security posture is really -- came down a notch. The priority is not as high as it used to be, especially during times like this.

Deepraj Emmanuel

executive
#27

That is very interesting, Don. I would assume that it should be exactly the reverse because organizations would definitely focus on the security posture in these troubled times. So why don't we do this? Let's go and ask our audience on what they think. I think it will be great to maybe just look at another poll question. And the focus of this is to really sort of look at whether you believe that the IT spending that you have in your organization today, the nature of it, the way how it is being done in this particular time might compromise your security posture. Even as our audience actually complete the answers to that, I think it's important to note it's not just a general behavioral question, where the security posture figure as an important part of what is happening in your organization. I think it's something to do with the focus on this current time because a lot of behavior has definitely changed. So we've got, again, some very interesting responses. I think we've got 75 people -- 75% of our audience who believe today that the security posture is being compromised, 25% believe that it isn't, actually. And that is something which, I think, we do need to discuss more. Don?

Don Tan

attendee
#28

So -- yes. So Deepraj, can you share -- again, I see -- and what you do every day has, I think, tons of relevant experience that you can share with everyone here, whereby you guys have helped organizations kind of navigate the uncertainty, help them kind of nail down where they need to be and how to operationalize it and execute on that. So maybe from your perspective and/or from ISG's perspective, can you kind of maybe share with all of us, where do you think we should go from here? What is the right path to think?

Deepraj Emmanuel

executive
#29

Absolutely, Don. So I think what's most important is to be able to actually look at key focus points of how we work on the alignment of the security posture with the current IT spend. Now the audience just mentioned on the call that there could be the compromise of the posture based on the current spend. And I think it's important to maybe look at that in a holistic perspective to sort of see what are the key steps that can be taken to be able to avoid that because we are not at a place where we can basically say that this can continue in the long term because the attack only happens once. And therefore, I think it's important to also look at the current scenario of the reduced IT spend. Obviously, there is reduced company revenue of a number of companies who joined us today and, therefore, there is a reduced IT spend, and there is no debate there. But it is not to say that the reduced IT spend needs to necessarily reduce the security posture. I think it's extremely important to look at a balanced approach on how organizations move forward.

Don Tan

attendee
#30

Deepraj, I think you hit the nail on the head. And the burning question I have, right, is how do you decide? What is balance? You're telling us stuff that are really pretty high level. As you have rightly pointed out earlier on, we are living in troubled times. The last thing as a company that we want to do is to spend excessively on something that might not help us at this moment.

Deepraj Emmanuel

executive
#31

Absolutely, Don. And I think what's really key is to also note that we are looking at a very, very structured approach of doing this, and we need to definitely get on to discussing how do we all collectively -- in each of our respective roles and organizations, how do we spend wisely? The left side of what you see here, the cost efficiency portion is definitely something which has been practiced by a number of people. I think everyone is looking at aggressive cost optimization initiatives, using existing IT models and relationships to fund digital enablement. That's great. But then what is most probably missing is this aspect of the security posture relevance. What are you driving as your security posture? Is it relevant in this new world? Does it actually align to the kind of use cases which are being executed in your organization today, be it with employees, with customers? And how are you able to then look at providing a robust and secure digital operating model, which is implemented to enable transformation and further customer intimacy? So to give you an example, I mean, for all of us who drive a car on the audience, the question is, at what point do you decide to change your car tire if cost was the only consideration that you had? And this is an important point to note because you see, there is always the aspect of stretching it to the very point till it actually does. But then based on this behavior, if there was an accident, the question really is, was the cost worth it, were the savings worth it? And that is exactly how this balance has to actually be put in place. We are not saying that this is decoupled. Obviously, there has to still be the continuous same aspect of security spend, but with an understanding of how this is relevant, I think it becomes quite important and, therefore, quite relevant to actually balance cost efficiency with the security posture.

Don Tan

attendee
#32

I really think that most companies right now are just playing a waiting game. Now not -- with emotions running high, anxiety from an exec level all the way up, right, I think not many of us or not many companies really do much during this period. And do you think this is the right approach?

Deepraj Emmanuel

executive
#33

So Don, there are a couple of things that we might actually want to consider. I mean this is really called -- what you mentioned just now is really called the do-nothing frame of thinking or the do-nothing thought process. What is interesting is that what used to be something that was assumed or what used to be taken for granted can't be done anymore. You can actually sort of look at scenarios in all of our organizations, where employees are making their own decisions on what security posture is adopted, which basically means that there is no control over the security tools, the kind of protection, whether or not there was any sort of security coverage on their mobile devices. I mean it's very important to look at some of these fundamentals before we go on to very wide spectrum decisions on how we would sort of align the security posture in each of our organizations. Think of company confidential documents being unprotected on online storage platforms, your competitors, your customers who actually have access to documents they shouldn't. And if you were to look at multiple unknown devices accessing the network just because it was actually allowed to, I mean, that beyond n number of firewalls and antivirus that is actually deployed would present a pretty good possibility of a backdoor for some of the very deadly attacks. So I think it's important to basically align that with not just playing a waiting game or just depending on status quo but to be able to really understand the risk and act on it.

Don Tan

attendee
#34

This seems like a difficult ask. You have mentioned quite a fair bit about mobile devices, and top of mind the question is, how do I even secure devices that are not controlled and, for that matter of fact, owned by us as a company? Are existing securities in place? Are security policies in place? How does that align with my IT spend? We have a plan, and that plan was worked out way before anything happened. So what you've just said here is it's rather difficult. And most of us and most companies out there, I don't think we have the flexibility to kind of change the policy as it stands, right? So my ask is -- to you is that what are the key recommendations that you have provided to help companies within the region now transform within troubled times like this when emotions are high? How do they transform? How do they save on certain costs but, at the same time, still get equal or better security posture? And basically, I'm putting -- Deepraj, what I'm trying to do is to put you between a rock and a hard place, right? How do I save more money? How do I get -- be more secure -- better or more secure than what I used to be? And at the same time, how do I transform my business so that I would be relevant in this new world?

Deepraj Emmanuel

executive
#35

Absolutely, Don. And I absolutely also do agree that we are in difficult times. Emotions do run high. There are a number of areas that we have actually highlighted earlier, which is quite real to a lot of organizations that we're actually dealing with today. Having said that, I think it's also important to look at whether there is a way of handling this. It is not just about being aware that the problem does exist. We face the risk. We might actually be compromised in some way or the other just because of the nature of our current IT spend. I think if you use a holistic approach between looking at assessing where we are and executing the right steps to be able to get to where we need to be, then we might be able to have a relevant and balanced approach to be able to take care of this situation. From an assess standpoint, in ISG, we work with our customers, we look at -- looking at a big picture review of where the IT spend, the security strategy is. There are a number of IT spend benchmarks that actually dictate. What is it that you should be saving? And how is it that the kind of cost savings that are actually being put in place affect your security posture? That doesn't just apply to the current spend but also planned services. And performing a very quick security assessment helps a lot of organizations to recalibrate their future security plan. I think this methodology definitely has helped enterprises, both mid, large SMEs as well. And fundamentally, I think what is key is that it's a very, very programmatic way of putting this in place. Don, what do you think about the security posture on mobile devices?

Don Tan

attendee
#36

Deepraj, I think the biggest misconception is that most of us think that devices are safe, right? And that is not entirely true. Based on statistics that we have ran across our corporates of 190 million users, we have seen encounter rates grow at an exponential rate. And we have seen that, in fact, grow threefold just during this one particular period.

Deepraj Emmanuel

executive
#37

So Don, in addition to that, I think it's also important to maybe look at some essential best practices that a lot of organizations have actually been undertaking, especially during this time. And I think one thing that the COVID era has actually done is to be able to have organizations think differently about a lot of focus areas, which were not necessarily done at that velocity, that agility before. Some of them to highlight is definitely looking at consolidating security functions with an integrated platform, reducing the number of tools and platforms that they have to be able to actually look at, specifically, where they could see cost savings in the security tool consumption as well as making sure that there is integrated protection and visibility to their security posture across the organization. What we've also seen is that the security product footprint within a particular organization is transitioning now to align to a post-perimeter world paradigm and to a number of points that you actually mentioned earlier, even from the perspective of the here and the now, what are their employees doing? What are their customers doing? I think it's important to focus on how the security posture in the new reality is still maintained and is not compromised. What we've also seen is that there is reduced spend on security tools. There's no doubt about that. But using a programmatic approach to be able to actually make the right assessment, find out the right level where a particular organization is, there could be maybe redirected spend on the right security tools and platforms in an integrated way. It does not necessarily mean that this is going to blow up the security budgets for organizations in this very cost-sensitive environment. As a matter of fact, in some cases, it actually does reduce the security spend. But at the end of the day, the focus is to ensure that there is no security compromise -- the security posture in itself is again not compromised with reduced IT spending. So I think with that, Don, let me just hand it over to you to summarize.

Don Tan

attendee
#38

All right. So in summary, I think with all life-changing events, COVID being one of them will redefine our lives. I think eventually, these will fit into a distant memory, a small image in our rearview mirror. And what I think we need to do is to really think forward. And like -- the word we have been using, pragmatic, we need to be pragmatic. We need to be able to pick a destination and know where we want to go so that we can plan a flexible journey. I would advise that we avoid making rash decisions in the heat of the moment, like, that one particular case study that you have given and also put a cap on the talk on what needs to be done and to really understand how impacts made today might limit our progress and relevance in the new world. So with that said, we are going to open the floor to questions. Feel free to key in into the panel, and please do address it to either myself or Deepraj so we know which of us and which -- that you want us to respond to your questions.

Jolene Goh

attendee
#39

Thanks, Don and Deepraj. Feel free to actually put in the questions. I would probably, like, give a few seconds to actually have the questions come in. And I got one question that is for Don. Do you think we should focus on reducing IT spend on perimeter security?

Don Tan

attendee
#40

I would -- so perimeter security will still be relevant, right? So you still need to be able to have that in place. But one thing that you might like to think about is the capacity of your perimeter defenses. And what that essentially means is this. Most of us would have -- when we first did the planning for whether is it firewalls or IPSs or web filters or what have you, right? It was planned on the concept that there's going to be a ton of users behind this perimeter that we are supposed to protect, right? And what you have heard from us today over the last 45 minutes -- I hope you guys on the call today have now realized that most of your users are now way beyond this perimeter. And what that means is that you essentially have your guns pointed in the wrong direction, okay? So to sum up, you still should have a perimeter in place and that is essential. But then again, you need to put some thought into the capacity behind it. You might not need a 100-gig firewall now. You have not that many people to protect, right? So food for thought. And I hope that answers your question.

Jolene Goh

attendee
#41

Yes. That's good. The next question that I have is actually for Deepraj. Can you talk a bit more on how ISG helped customers through this transition journey?

Deepraj Emmanuel

executive
#42

Absolutely. So to quote an actual customer journey enhancement that we actually sort of looked at over the past 3 months on exactly this. This was a large enterprise who had a lot of focus on the perimeter security. They basically ensured that they literally build a fortress. And what was really interesting is that across the past 3 to 4 months, they had definitely been seeing a number of their confidential documents all over the place, and some were actually discovered on public forums as well. And this was interesting. So I mean they called ISG in to just try to understand what was happening. And what we did was that we organized a couple of workshops to just make an assessment on their current state, where we did a review of their IT spend, their security strategy, where have they actually deployed different tools, frameworks, platforms, and then we ran a benchmark to basically say how other organizations, which are very similar to their profile, were actually sort of spending on overall IT as well as on security during the COVID era. The results were pretty surprising to them because, at the end, they realized that they are not alone. And the starting point was, obviously, looking at how they could take where they currently stand and build what is called a target operating model on where they have to go as well. So we did a rapid security assessment, and then we came up with an implementation road map, selecting very specific tools on their behalf to be able to say, how do we transition into securing the post-perimeter world. So they are on that journey right now. I mean at the end, the business case that we actually built for them really shows them that it was a very good exercise. They are spending less, as a matter of fact, on the security, but the security posture is a lot more relevant. And effectively, across a 1-year program, they will be making specific changes and making sure that they are a lot more secure.

Jolene Goh

attendee
#43

Thanks, Deepraj. Let's give like probably 1 or 2 minutes to see whether there are other questions.

Deepraj Emmanuel

executive
#44

Jolene, I do see one question, but I can't see the entire text, which is, our company depend on free security tools to protect our assets because -- could you just tell me the last part of the question?

Jolene Goh

attendee
#45

Okay. Let me just read out the question again. Could our company depend on free security tools to protect our assets because we have very limited financial budget in this pandemic situation? Deepraj, that question is for you.

Deepraj Emmanuel

executive
#46

Sure. So I think, [ Rehmat ], to answer your question, I think, fundamentally, the definition of free, in this case, is extremely important. So it is not necessarily about downloading a particular antivirus or downloading some tool and just installing it in your environment and running it. And that's literally the easy bit. I think what goes before that is a rationale of what is this particular tool bringing to the table, what is the support that is behind this. Because the difference between us -- and you will definitely agree with that, us -- each of us individually installing something on our personal notebooks or devices and then running that vis-à-vis our companies, our enterprise doing it is that it has to be well thought of, it has to ensure that as we move forward with this particular journey, it is supported. And when there are issues, when there are escalations, then there is some level of -- there is an ecosystem in place to be able to actually take care of it. Security tools are no less. And while I think it's important to look at the due diligence of how much you are spending on it, I would definitely caution against something that comes completely free, while it may be definitely able to execute the purpose of what it is supporting, and it might run in for a while. Deploying it again in your entire enterprise might definitely be a risk because when there is an issue, when the attack vector actually changes, you will not necessarily be in a position to actually dictate whether or not that particular vendor will actually support you with the latest threat posture or if something happens, then there is no accountability to which the tool needs to be able to respond. So I hope that answers your question.

Jolene Goh

attendee
#47

Thanks, Deepraj. I think...

Don Tan

attendee
#48

I think we are at the top of the hour right now.

Jolene Goh

attendee
#49

Yes.

Don Tan

attendee
#50

Yes. So I think what we can do is maybe leave our e-mail addresses herein and then if anyone has any question and you really want to get in contact with us, please free to drop us a mail. Over to you, Jolene.

Jolene Goh

attendee
#51

Yes. Thank you, everyone, for your time. I hope the webinar is actually informative and you enjoyed the webinar. So after this webinar, we actually have a very short survey whereby you get a chance to actually win 1 of the 3 sets of Jabra Elite 65t earbuds. We hope that you actually take a minute to complete it. And with that, I'm going to just quickly put on, like, Don and Deepraj's e-mail addresses on it -- on the screen. So if you have any questions, please feel free to actually reach out to us. So with that, we will close the webinar, and we hope that you actually have a great day ahead. Thank you, everyone, for your time again. Cheers. Bye.

Don Tan

attendee
#52

Thank you, everyone.

Deepraj Emmanuel

executive
#53

Thank you.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Information Services Group, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Information Services Group, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.