International Business Machines Corporation (IBM) Earnings Call Transcript & Summary

July 18, 2024

New York Stock Exchange US Information Technology IT Services special 55 min

Earnings Call Speaker Segments

Unknown Executive

executive
#1

Thank you for joining us for today's IBM TechXchange Webinar. I'd just like to go over a couple of housekeeping things before we begin. [Operator Instructions]. Later today, will be sent a link to the on-demand recording [indiscernible] link to the IBM TechXchange Community where you can connect directly with our experts. So without further ado, I will hand it over to today's presenters.

Richard Hogan

executive
#2

Excellent. Thank you very much, [ Porsha ], and thank you, everybody, for joining us today. Where we are going to go through with the help of Microsoft, a few things around our service that is going to help our clients secure the Microsoft Cloud State and using some of the Gen AI tools that are available. And also to go through Microsoft's [ future ] about how this actually fits together and what they're looking to do over the course of the section. So just to cover off that. So brief intros then I'm going to pass across to Sameh Younis from Microsoft, and then I'm going to hand over to John Velisaris, who runs our product and service on TDR [indiscernible]. Then we'll cut through some actions that you can take if you're interested in learning more about our partnership and our services. And then hopefully, if we've got time, we'll have a brief Q&A session at the end where you can ask any questions you might have on that. And in fact, if you want to during the course of the session, you can use the Q&A option to ask questions, and we'll cover those off at the end or if they might be same person for that particular section, we'll go through that as well then as well. Okay. I'm going to kick off just with a sort of brief overview of as a partnership with Microsoft from an IBM perspective. And I get asked this question quite a lot because I mix Microsoft full transparency ex-Microsoft. People do ask me sometimes, why have you gone to IBM. They're not partner with Microsoft. They actually compete with Microsoft. And I think that's an interesting statement because IBM is one of the biggest and best partners with Microsoft has, but we -- no one knows about it. It's sort of like a secret in the market that partnership actually exists, and we are that closely aligned. In fact, we even had a joint press release a couple of weeks ago that was talking about how we're going to be collaborating even further going forwards. From a slightly security perspective, we focus primarily on two or three elements within that. So cyber threats, cyber trust and cyber risk. Today, we're going to be talking mainly about the threat management piece, so around how we leverage Sentinel and Defender to help secure our clients space. But we are obviously seeking that broader reach consultancy across above that. Obviously, leveraging the Microsoft investments that you currently have or maybe looking to have, but also integrating other tools and services across the board, both from IBM or from other partners as well. As I said, we are actually one of the large partners out there from a cybersecurity perspective, we've got 1,300 certified resources, 14 SOC services across the globe, support the clients. We're a member of MISA, which is the Microsoft Intelligent Security Association. And the TDR service that John will be talking about later on is actually a verified service by Microsoft. And we'll talk, what that means a little bit later on. We have advanced specializations in the security pieces. And as you can see from this, we are jointly collaborating with Microsoft on a number of engagements, clients, offerings, technologies, et cetera. So I think from my perspective, it's a really interesting time to be part of IBM and to be working within this partnership. And without further ado, because I'm conscious, I want to actually cap this to session with the people that can talk about the sort of details of this much better than I can. I'm going to pass it across to Sameh Younis from Microsoft, who will go through the sort of Microsoft viewpoint around the threat management and AI. Sameh, over to you.

Sameh Younis

executive
#3

Thank you, Richard, and welcome, everyone, and thanks for the IBM team for having me today. A great partner, IBM is one of the biggest global partner that we have at Microsoft. Again, my name is Sameh Younis, I'm a Senior Security Solution Architects. My role is to enable partners on security across the Americas region and happy to be here with you today. Today, I'm just going to walk you through some of the Microsoft point of view, on security and our approach to security are generally speaking. All right. To start off, like I really can't find more place to start off other than today's headlines just to showcase the impact from ransomware, [indiscernible] and even the use of cyber as a weapon of war. Security is the most fundamental and defining challenge of our time. And in the digital world, it has become a basic need, much like food, water and shelter. Without enough security, we put financial future business future, geopolitical future, even physical safety at risk. We see security headlines daily, talking about ransomware, talking about Data Leaks [indiscernible], you name it. And we start to see also in the news, the use of AI as a tool in cyberattacks, which means for us that we have to stay ahead and use AI in cyber defense as well. Just to want to share with you some of the numbers that we have. Just to give you an idea, like here, we're talking that every second cyber criminals are getting smarter, faster and more sophisticated. And no one is immune of these risks. Data breaches are not a matter of, if, or even when, but the reality is how often it happens and how long it will take to detect it, 4,000 password attacks per second, which is 8x more than what we had in the previous year. AI enabling almost 50% increase in phishing attacks, attackers leverage AI, a lot, especially around phishing because that's the easiest type of attack is to steal someone password. Security teams struggle with dozens of different security tools. It's not only that, but we have a shortage in terms of the professionals that can fill in those security rules. According to ISC, we currently estimated that we are short in 4 million unfilled cybersecurity positions, which is a great opportunity also for us and for anyone who's just started because it's a field that's really fell short in terms of the skills required. At the same time, we, as defenders, we are facing with the challenge that enterprises are transforming. So it doesn't really look the way it's always had before. And with the evolving perimeter and the odds are all again today is a defender. Now it's a distributed range of diverse system. So it's no longer contained within your on-premise network and secure risk firewall. But just the fact that hybrid work becomes a reality now across all organization. So your perimeter has extended beyond your on-premise network. And we see now that we have to do more work into protecting not just the network but the identities, the endpoints, your data, generally speaking, the use and leverage of cloud applications in addition to your workload and network. So with all of that said, when we look at today's organization, we find that most organizations are using a large number of tools, probably between 50 and 80 security tools, probably coming from 8 to 12 different vendors. So no wonder that defenders job becomes so hard and there is too much time wasted in navigating between these tools, matching the data between the tools, trying to make sense of all the signals that you get across all of these tools. Attackers only have to be right once, but defenders have to be right 100% of the time, all the time. So it's really a great challenge. And with that challenge, that's why at Microsoft to be recognized the consequences of these problems of having too many disparate tools. And so we position all of our thousands of different engineer are working hard to close the gap and give you a well-integrated platform out of the box, one integrated tool set that combines the capability of probably 50 or more different tools, one comprehensive solution starting with [ Identity ] Device Management with Microsoft Entra and Intune to threat protection and Cloud Security with Microsoft Sentinel and Microsoft Defender and Data Security Compliance Privacy with Microsoft Purview and Microsoft Priva. And together, this integrated solution is designed to [ army ] you with the industry's most comprehensive security for multi-cloud. And finally, with our newest product, all of this can be touched together through Generative AI, which is Copilot for security that will allow you to drive intelligence out of all of these systems and provide you with immediate answers using Natural Language. Our platform it's not just for Microsoft. Our platform spans all clouds that you use, whether you are using Azure, whether you're having on-premise systems, Google, Cloud, AWS, and we support almost all platforms, Windows, Linux, Mac, iOS, Android. So we support all platforms, all clouds through our Microsoft stack. So at Microsoft, we recognize that we need to position you at an advantageous going ahead of the adversaries ahead of attackers. And we have been preparing for this AI era. Like, in fact, our tools like Sentinel and Defenders, they've been using AI for the last decade. And what we have added with Copilot for securities, it's just the Generative AI parts that allow you to talk to the system using Natural Language. So our tools collectively provide you with unmatched threat intelligence, this is the most complete end-to-end protection for your environment. It's an industry-leading AI for security that goes beyond traditional AI and into Generative AI. It's simultaneously delivering innovative tools for the safe adoption of AI so that's important. As our organization now start to adopt AI, whether as Chatbot AI, like OpenAI, ChatGPT, Microsoft Copilot and so forth. But you need to have the right security, you need to have the right governance in your environment. And that's what Microsoft tools provides you to enable you to have a safe adoption of those AI tools. Usually, when we talk about AI and especially Generative AI with Copilot for security, we start facing some questions from customers, especially those customers already contracting or have a contract with an MSSP like our folks here like at IBM Services. And we hear like some common terms that I just want to discuss it and talk frankly about those. For example, with Copilot for security can replace or reduce the customer reliance on MSSP? We don't think that this is true because Copilot for security is not meant to replace the human factor, it meant to augment the human expertise. MSSPs, by definition, especially with IBM services, they bring a wealth of experience with a talented team of experts. They have developed processes and add-on tools for handling multiple different scenarios. This allow -- having Copilot for security will allow your MSSP to have a more faster reaction, more faster detection and MSSP will still infuse their knowledge that they build over time to manage your services. So it's not a replacement for MSSP having Copilot. It's more of an empowerment for the MSSP expertise. Other methods that we keep hearing about is Copilot. We have an SLA contract, for example, with MSSP, why do I need to have Copilot for security? So SLA is a contract, so it's only a financial backed baseline agreement on how long something can take before an action or resolution is completed by the MSSP. When it comes to threats to an organization, you really want to ensure that you not just have a contractual agreement, but you want to sure that there is immediate deduction, that there is a fast response and faster remediation. So any advantage that you can put into the equation like having an AI tool like Copilot for security, it really reduces the time between the different phases of triaging, responding, or remediating, which will overall reduce the cost and will limit any potential damage from any attack. So that's an important, very important point. So it's not really a double investment per se because threat actors continue to intensity their incorporation of AI. So you need your Defender also to be empowered with AI. So same as exactly, you implement as a customer. Even though you have MSSP, you still implement tools for endpoint production, for example, for tools, for identity production. Why you implement these tools if you have MSSP? Because that's what empower your MSSP to deliver and deliver faster. So same thing. We want to also implement the AI tool to further empower your MSSP to act on these threats. So in essence, the whole concept behind not just Copilot for security, but all different Copilots that Microsoft deliver across all our platform is really to argument the human expertise and the human ability to do planning, the human wisdom, the creativity, to augment it with faster access to knowledge, efficiency, speed, precision, all the things that comes from an artificial intelligent product. So you're better off having both. You need the human factor and you empower the human with Copilot. You need your MSSP and you need to empower your MSSP with better tools. But it's not just about your MSSP because by having Copilot for security, you're also empowering your whole IT organization because Copilot for security is not just focusing on security surprisingly. But anything that's within IT. It can also integrate with all of different tools and can be leveraged by other IT roles outside even security team. So device administrators can leverage security Copilot to understand what types of policies being implemented on devices, device compliance and so forth. Your compliance officers can leverage Copilot to understand any risk to the environment, any personnel issues or insider risk issues and so forth. Your data security administrator can leverage this also to understand the potential data. This is all because Copilot really connects to a multitude of different systems and being able to intelligently drive correlations between those systems. So again, it's not just the security, it's not just to help the MSSP, but actually, it empowers every role within your IT organization to become better to become more efficient. So really, like once you look at the whole security suite, the use of AI in our security suite, the addition of Generative AI on top of the suite with Copilot as an example. You get to the point where you start tipping the scale now in favor of Defenders like yourself with those unmatched threat intelligence, the most complete end-to-end production, the industry-leading AI for security and the tools for safe adoption of AI. Just holistically, you will achieve lots of savings once you understand the ins and out and you go through all the details around this platform in terms of not just the efficiency and the intelligence, but the cost savings, the vendor management all of these whole [ 9 yards ]. We're already seeing 60% savings by consolidating the batch work of different vendors into one comprehensive security solution, and we see 72% to reduce the likelihood of a breach with Microsoft Security Solution versus having multiple different solutions. I just want to end my talk here with talking about the IBM services. So we really happy to work with them because IBM is one of our top partners when it comes to security. They have achieved the highest partnership and designation level that we have, which we call it the Microsoft verified MXDR solution. So that's the highest badge that we issue for any of our partners, which means that the IBM solution has been verified by Microsoft Architecture, Microsoft Engineering. It was proven to be an end-to-end solution, providing services 24/7 for monitoring, hunting and response, having the capacity and the capability and the skill to deliver the proper onboarding and [ push ] management, ability to integrate disparate sets of data into their services and providing the fully managed offering. But it's not just about dissolution, it's about the execution of that. So with those verified partners, will have to make sure at Microsoft that they have a proven execution, they have achieved specializations in terms, which is another designations that we have. They have to be an active member of the Microsoft Intelligent Security Association, which on its own requires also have a large set of prerequisites. And not only that, but we have to verify and confirm with the customer references that they have. So overall, I think this is one of the best solution around the world. Any time you see this batch with a Microsoft verified managed XDR solution you know that Microsoft has verified the [indiscernible], the quality of the solution. These are few partners around the world. And I think with what IBM has implemented in their solution will give them an edge. So I will leave this to the Microsoft team -- the IBM team to walk you through their solutions and I'm sure you will love it same way as I love it. Thank you.

John Velisaris

executive
#4

Thank you Sameh. Sameh, we did have a question come in while you were speaking, and I don't know the answer. It's asking about coverage. You were talking about the different platforms you support. The question was, do you support IBM Power Systems where they're running an IBM operating. I do know we can get logs to Sentinel from power systems, but I don't know if there's a Defender that's compatible with the operating system. And if you don't know, that's okay, but that question came in.

Sameh Younis

executive
#5

We don't have a Defender that's compatible, but definitely, we can inject the logs from the system into our solution. And I will have to check if there is a connector out of the box because we have hundreds of connectors that comes out of the box. But even if it's not out of the box, you can always develop a custom connector and start ingesting from any system no matter what it says.

John Velisaris

executive
#6

Terrific. Thank you, Sameh. I'll move us on to TDR then. Hi, everybody. My name is John Velisaris. I'm with IBM Cybersecurity Services. I'm the portfolio Manager for our Threat Portfolio. And since as Richard mentioned threat today, I got the ask to come and tell you more about that. So thank you again for joining us today. I think let's start with some value points. Sameh threw some out lower potential of a breach happening, the lower cost in acquiring a full Microsoft solution. We'll throw some other value points out here. We do have a TCO 1 because we agree that bottom point there are 50% reduction in your total cost of ownership. You know what, well the Microsoft solution does, I'll speak to that data point first, what the Microsoft solution does is I've seen security operation centers that have 50% of their capacity towards threat management and 50% towards system engineering. That's exactly what you don't want, right? You want most of it going towards your threat management. You want those issues with system engineering to be taken care of. You want to buy out-of-the-box integration, you want to buy -- when you do need to do custom integration that to be easy and based on open-source standards, right, so that you spend less time working the technology supporting the SOC and more time doing the security operation center activities that the business and reduce the riskiness. But the other data points we have here are organizations that use AI and automation typically save 108 days in breach response time. We do if -- and many of you may know where this comes from, it comes from the IBM cost of a data breach report. The new one is coming out very soon. So just as an aside, look for that. We'll be publishing the new costs in the data breach report very soon. But organizations that use and practice, incident response plan, maybe test that plan in our cyber range or demand centers with those immersive experience, again, they can lower their breach response time significantly. Number two, proactive security can lower your security incident cost by [indiscernible]. And what this does proactive security does in that commitment to it is it takes away that low-hanging fruit. Sameh was totally right that all the attackers have to do is be right once, the Defenders have to be on all the time. Well, if you don't lower that attack surface using proactive security, right, there's just more that the SOC needs to cover more that the security team needs to look out for, makes it much harder, right? So proactive security is a definite plus. And that data point came from the cost of the data breach report as well, too. So these points of value should lead you to say those sentimental principles, and they are. So IBM Threat Detection and Response Services or what we call TDR is based on three main components. The first one is unifying threat detection and response and apply AI, right? Sameh was talking about support for multi-cloud, hybrid cloud, all of those things, the SOC needs visibility into all the properties that it needs [ to act ], all the areas in which it is defending the business, right? And if you don't have that unified capability, and I'm not just talking about visibility, I'm talking about unified workflow as well too, right? It just becomes doubly hard to stay ahead of the advanced threats. And then when we talk about AI, this is one of our accelerators. I'll tell you a little bit more about it. But one of our accelerators is a watsonx-based AI that can automatically handle all alerts, not all alerts, but up to 85% of all alerts with AI. And so that's kind of that point of triage. Again, I'll tell you more of that a little bit later. So unifying threat detection and response is the first pillar of TDR. The second one is that practicing proactive security like we talked about, right? This is not the same every day. Every day you wake up, there's a new threat to the business. And that can be an external factor creating that increased risk profile or it can be a business. Sameh talked about business transformation, right? So if the business is saying, "hey, we're going to roll out AI", right? And customer service, right? That AI can be attacked at the data layer, at the infrastructure layer, the SOC team doesn't have visibility into AI prompts. So your risk is changing every day. And the last thing you want to do is wait to test your security controls with a hacker, right? You want to get ahead of that and make sure that those security controls are tested well ahead of time. Then the final piece, the final pillar of TDR is the commitment to continue its improvement, right? So with everything that security teams have to do, they are constantly under water. They're constantly firefighting. The last thing that they have time to do is run a project to increase the maturity of the SOC. And so I talked about proactive security as a way to make sure you stay ahead of those threats. You've also got to upskill your people as well too. And so what we do in the TDR service is we force you to commit to improving security operations. And once a quarter, we will be there forcing you to get better. Now you'll say, well, wait a minute, that doesn't sound right. I'll show you later about how our methodology, how we jointly develop a plan to continuous improvement, right? So it's not just doing what IBM says. It's through our partnership, you will continuously improve. The graphic on the left is just intended to put a visual to some of those concepts that we were talking about before which is using exposure management as a way to proactively reduce risk to the organization, practicing IR and bringing all of your detection, your telemetry together into a single workflow, right? So that's a visual for the three main pillars of TDR. So you may ask, well, what does that look like from a Microsoft perspective? So we've got kind of a layer cake architecture here on the left-hand side, the top part shows some of those elements of governance that I was talking about earlier, the partnership of IBM and together Microsoft capabilities, right, to stay ahead of those threats, to make sure that we're reducing business risk. So you've got the governance elements of top. Then you've got a lot of our cloud native services. This is kind of our delivery layer, you'll see that there are some unique IBM accelerators there. I'll give you more about what those accelerators are on the next slide. You'll also see in the operational layer surrounded by the red box that we use Azure Lighthouse. And so if you're not familiar with that, what that allows us to do is deliver services to you fully within your environment. So Azure Lighthouse is a Microsoft developed capability that lets us seamlessly co-deliver within your organization. So we're not introducing any new technology outside the Microsoft stack, safe for our AI. But you'll see in the operational layer there's a capability to do bring your own machine learning analytics. That's where our dispositioning AI comes in. That's where it's one of our differentiators, one of our accelerators. That's where we use an AI within the Azure construct to be able to drive that automation. And then finally, your customer environment down here, it will be -- Sameh covered all of those technologies. So I'm not going to spend a lot of time on those. But our technology layer, layer cake here also supports that cloud, multi-cloud hybrid environment, as well as, again, supporting all of that Defender stack Sentinel being key for threat detection and response activities. So the last point I'll leave, if you've read down the right-hand side, the bottom point is important there. We can deliver this service in any region around the globe. So if you want this delivered in Europe, we can deliver it in Europe, if you want it delivered in Latin America, we can deliver it there as well, too. Sameh are experts, so I skipped to that point there. So let's talk about some of those differentiators. And again, those were kind of in the middle layer of our layer cake on the last slide. And when we looked at what differentiators we wanted to invent, what we wanted to develop, IBM wanted to develop. We kind of took an expanded missed cybersecurity framework. So along the top there, you'll see our incident response capabilities, contain, eradicate, analyze [indiscernible] and so forth. So other than the recover piece. IBM has invested in a series of accelerators that work within the Microsoft platform to create that optimized variance, right, that Sameh was talking about as well. So we have an accelerator, the threat optimizer. This is around threat modeling and analytics security tools. So that helps us optimize the detection capability. We have a detection as code orchestrator so of an engine that can apply new detection capabilities, very much like kind of a DevOps model or as a security practitioner, I should probably say a DevSecOps approach, right? But yes, you don't need to spend countless hours writing new detections. We have an intelligence driven detection engine that creates new code, which can be ported into simultaneously. The AI SecOps, this is where -- this is that differentiator I told you about. And so a little more about why we use AI there. When you're looking at a countless number of alerts and Sameh covered it, I talked about it briefly. So SOC teams will never get their head above water unless they use AI unless they use automation. There are just too many alerts. There's too many new risks to the business that we're working on, right? And so when I was in a SOC, if I remembered an alert and an investigation that I conducted eight years ago, I thought, wow, I'm doing a good job, look at me. Well, what our AI engine does is it looks at every single alert from every IBM client we have across the planet on every platform. We love Sentinel, but we acknowledge that there are other technologies in the world. We look at alerts from those technologies as well too. We look at XDR alert, we look at EDR alerts. So our AI takes half a second to compare that new alert to every alert we've seen across 43 different data fields in the last two years. And trust me, we see billions of events a day. When Sameh was talking about using AI to upskill and uplift analysts, this AI should play. It is doing things that human beings are not capable of. So that's huge differentiator for us that we can bring to you. The analogy that I'll move on is very similar to aircraft. For example, long ago, pilots were flying airplanes. They were doing flaps, controlling the stick, the engines. These days, computers control airplane and pilots monitor those computer systems to make sure we're safe when we fly. Our approach with AI is the same way. The security analysts should be monitoring what the systems are doing rather than trying to do all of that themselves. That analytic content library number four, again, we're generating new detections. We're storing them. We're storing threat hunts. So not just a Sentinel alerting, real-time alerting capabilities, but we have a library of threat hunts as well, too. So you'll never have to create anything on your own. Again five and six go together. They're around our automation with our playbooks. Preapproved and approval based, I'll give you a little bit more about that on the next slide. But you don't just give us carte blanche to do anything in your partner, we work together. I'll tell you more on the next slide about that. And predictive attack pattern analysis, again, changing the environment based on what we're getting from intelligence, stick algorithms to determine what threats are going to materialize for your environment and trying to get ahead of those as well as investigation. All right. So that was a quick tour through some of our accelerators that we can bring to bear in the TDR cloud-native service for. This is those/playbooks, right? And so there are some things, and I'll just let you visually consume these, if you want. But there are preapproved actions that we can take, that we can execute using Microsoft automation built into the Sentinel playbooks, as well as human beings executing functions. And then there will be a kind of that containment step is where the overlap happens, but there will be things that you want us to check with you before we do. There are higher risk containment activities that you may want us to make sure we validate our proposed response actions before we take those, right? And then there are the eradicate phases as well. If we're going to touch your business environment to remove a threat, you certainly want to be in the loop. Again, we've broken down those two types because when you know threat is identified, you want to move quickly, you want to get that mean time to respond down. And so again, we use a combination of preapproved and approved. Now are these playbooks the same? No. They're not. We engineer these jointly with you. So you're not just running the IBM playbook, you're running a pre-agreed upon series of procedures via these playbooks. The next one is the use of -- Sameh did much better job covering Copilot. And also for the sake of time, maybe I'll go a little quicker than this, but we absolutely use Copilot in delivery, right? For creating complex queries, analyze phishing submissions. Some of the sample use cases that we commonly use with our clients are there on the right-hand side and bullet points, you can consume those. But absolutely, Microsoft has developed a capability that we'll accelerate security operations. We do not want to let that lay follow, right? So we use security Copilot in the delivery of the TDR service. So you may be saying, John, this is sounding pretty good. What does that actually look like? So here's kind of a service architecture. We call it a Tierless SOC Model, but really, it's built around agility and collaboration with you, our clients, but it includes threat hunting capabilities, intelligence analysis, SOC analysts. The little -- the red stars there are where some of those accelerators materialize in service delivery, obviously wrapped around the Sentinel console here for delivery, but integrating with any ticketing management or ITSM platform that you need. So I'll pause here, if you want to grab a quick screenshot, if you're listening to this after you can pause and take a look at it here. I'm going to move on rather than walk through each step of the architecture. The outcomes, so what do you get from all this, right? Faster time to value. In the next slides, I'll briefly cover our migration, philosophy and approach. A decrease in time to deployment. Again, you'll never have to write anything, any detection ever again. We've got a huge library not only threat hunting but detection, reduce time to respond. Again, having AI handle 85% of all incoming alerts. And so you may be saying, John, hold on, I'm going to take you the task, how does it do that? Well, it looks at the alert and makes [indiscernible]. Number one, I've seen that before elsewhere in an IBM client environment. And I know it's a false positive, so you can ignore it, that's great. That saves us a lot of time. This needs to be escalated immediately. I've seen this before. It's a real threat, you need to act immediately. And then the third piece of logic that the AI can crank out is this needs to be investigated. Right now, it has all the characteristics. I haven't of a real attack, I haven't seen it before but you need to investigate this immediately, assigning this to the highest priority. And then obviously, that increased ROI. We covered that before. We have reward-based pricing models that incentivize maturity. You and we both don't want you to generate more false positives. We want you to be a mature and effective as possible. And so again, we're incentivized in our pricing structure and approach to create that outcome with you. So that faster time to value what is that transformation program. Here's our generic approach, right? We come in and we find out where you are today. We need to meet you where you are today. But then what we also want to do is think strategically. Plan for the SOC, let's lay out the design work that we need to do to get to that more mature operating model, let's set out some time lines, let's lay out a road map. And then obviously, if we need to build something new, we build it into operations and then we run that, right? So think of our transformation capability as a three-phased approach. I'll show you a little bit later how we can break that down into a series of session, but this is it. With Microsoft, so let's say you're on a non-Sentinel SIM today, and you're saying, John, how am I going to get the Sentinel? I love what Sameh said, I love what you're saying. I've seen Sentinel, it's awesome. Defender is great, that complete ecosystem I'm all in. How do we get there, right? So we conduct a series of work steps. And again, our accelerators are represented here by some of those red stars. We talk about what the SOC is covering in terms of use cases, log sources, identifying what we need to migrate. Sometimes you may want to leave some things behind. And that's okay as well to do. Then we can figure we begin doing configuration. We create acquired users interact with us from an MSS perspective, we set up long collectors. We migrate your rule and referential data. And one thing I can tell you, if you were going to migrate away from QRadar, there is only one company that can do that best on the planet, it's us. We have internal IBM capabilities that no other partner has when it comes to QRadar. We can do a seamingless automated migration from QRadar to Sentinel. Then we obviously, there's a QA step in there. We work on those automated playbooks. We plan our go-live date. We run in parallel and then we decommission that old SIM. So I also promised to break that down into a series of sessions for you. So here's more of a -- on the right-hand side, you'll see how we approach and break down specific to Sentinel and moving to the Microsoft environment, kind of that benchmarking, that assessment, that planning, the modernization opportunity. Doing a migration like this presents you an opportunity to up your game. So certainly, you want to take that opportunity. And then a lot of the -- some of the tactical components, the only other piece that I'll really call out is the incident response there, that's mission-critical, again, battle hardened, tested incident response plan. We're going to make you have it. We're going to make you practice it. Practice proactive security, right? So what do you -- when you go through these workshops and what do you get? You get that migration road map, that prioritize business risk. The list of detection content that we want to migrate. The supporting content that we want to migrate, the new workflow based on Sentinel and then the rapid road map with time lines to migrate the SOC -- your SOC over to Sentinel in partnership with us. So that's the presentation for today. I'm going to do a real quick, I think, toggle back to see if there are any QAs. I don't see any new questions popping up in the chat. So I think that will do it. Again, thank you all very much. So what did we see today. We saw Sameh presenting Microsoft's point of view as well as the tactical capabilities that they bring to bear. Sameh talked a lot about the importance of that ecosystem, that holistic approach to threat management. We talked about some of our credentials that we have within the Microsoft partnership that are super important to us. We continue to invest with Microsoft. And then obviously, I covered the TDR service that complements that move to the Microsoft security stack as well as the main tenants of our belief around threat detection and response, some of our unique accelerators when it comes to Azure. And then I showed you a little bit of how, how we get it done. So we welcome questions. Please reach out to us if you do have any questions or comments. We're more than happy to get written to engage with you. A workshop is a great way to do -- maybe take that first -- that first session that I showed you about as a working session with us. It's a great way to get started in terms of next steps. I don't see any other questions coming in. I was kind of giving you an opportunity to use the QA tools down there at the bottom to see if there were any other lingering questions, but again, together, the joint value proposition with Microsoft and IBM is a differentiated threat management, security operations capability that you can't get in any other combination. So thank you very much for all your time and attention today. We look forward to hearing from you. [ Porsha ] I think that we'll do it for the webinar.

This call discussed

For developers and AI pipelines

Programmatic access to International Business Machines Corporation earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.