Johnson Controls International plc (JCI) Earnings Call Transcript & Summary
January 21, 2025
Earnings Call Speaker Segments
John Defterios
analystAnd welcome to this critical session here, Davos 2025, the 55th year of the World Economic Forum. The crisis, the confidence in cyberspace. That's the mission of the 45 minutes we have together. I'm John Defterios. I'm a senior fellow here at the World Economic Forum. I'm a professor of business at NYU, Abu Dhabi and I spent my last 10 years of my time as a correspondent with CNN as emerging market senator based in Abu Dhabi and the connectivity we see from the Gulf here to Europe, United States and obviously, Asia. We want to welcome our viewers on the live stream here or watching. This is an excellent session because in the last 2 years of the Global Risk Report for the World Economic Forum, we've seen that the cybersecurity and cyber threats rank either four or five in the world rightly so. But I would say, as a former journalist, it doesn't earn its fair share unless there's a crisis that happens. We kind of think it's business as usual, companies are ready to respond, but with the on-take of artificial intelligence now and then over the next decade and then phasing into quantum computing, it's going to be more of our common vernacular, and I don't think the world is ready for that, and we want to redress what it means. But at the center of our discussion today is not only dealing with cyber threats, but it's also the impact that cyber threat does have. And then obviously, what impact it has potentially on a brand and reputation going forward. I want to thank the team that runs cybersecurity, the World Economic Forum. I've had a chance to work with them for the last 2 years. They hold an annual gathering for themselves in November. They put out an outlook report in the last week, and we'll make reference to it here in the discussion. If you'd like to do social media and provide some feedback here on this session, the hashtag is WEF25, and we're going to be taking questions from the floor about 15 minutes out. We invite those watching us on the live stream to do the same. Let me welcome George Kurtz. He is the Chief Executive Officer and Founder of CrowdStrike, Inc. Welcome to you. Öykü Isik is a professor of Digital Strategy and cybersecurity at IMD Business School. She focuses not only on the response by leaders in the cyber space and technology, but also the impact it has on brands. So it's great to have you. And George Oliver, Chairman and Chief Executive Officer of Johnson Controls. The two of you, G1 and G2, as I said in our pre-meetings, have dealt with major cyber incursions, and they've learned a lot through that exercise. I'm going to ask them about it, but also they can share their leadership and what was required after having a cyber threat. And Öykü, it would be great to have you weigh in on what it takes to be a leader today and how much should be devoted in terms of time and attention to cyber and then what impact it does have on our brand. I think it's a phenomenal topic that they've undertaken here. To provide some context, we have a cyber report that was put out in the last week here for the World Economic Forum. And they also did polling from that cyber security gathering that they had at the end of 2024, which I'll make reference to for those watching on the stream and here and live in the audience. I want to reference a recent report from the World Economic Forum in collaboration with the University of Oxford. It defines cyber resilience as the organization's ability to minimize the impact of significant cyber incidents on its primary goals and objectives, and we can bring that graphic up here. And what we're looking at here is the incident absorbing it as a chief executive or as a company and then the recovery. You can see that the recovery stretches out almost on a flat line here. What we're looking for and what I'd love to glean from the panel is like that V-shape recovery, the preparedness, the resilience that you try to build into an organization here. And I made reference to the global cybersecurity outlook report in 2025 it was just released last week. Supply chain interdependencies represent the greatest challenge. The report identifies six components. And if we can bring that up on the screen, please, that companies need to contend with in this world of cyber complexity. Geopolitical tensions, which are on the rise, and we heard from the European Union President today talking about this fractured world and how to respond. Cyber crime sophistication and many actors in play here. Supply chain interdependencies that made reference to that initial survey. Regulatory requirements, AI and emerging tech, which I talked about in my opening comments, Cyber skills gap, which I think is interesting. Only 13% of companies feel like they have the right cyber skills internally. There's a shortage of talent worldwide. Women in cyber is a big issue, which I think Öykü could address. And then 33%, 1/3 of the company said cyber espionage and a loss of IP as their top concerns. I made reference to the fact that both CrowdStrike and Johnson Controls had cyber incidents. So I think it's excellent to you only to come on the stage and talk about it. So George, as a CEO, take us through it. So what's it like to manage something that hits a company that has a very good reputation, the scale of the incursion surprise you? And then how did you deal with it as a CEO? And how did the organization respond and look at you and say, what do we do next?
George Kurtz
attendeeYes. So first, great to be here. Just to maybe reframe it, we didn't have an incursion, we had an outage. So July 19 was an interesting day, I guess, for us and the rest of the world, as you might imagine. And when something like this happens, you have to go back to your muscle memory, right? And we actually do work with a lot of companies that have cyber intrusions and we have that muscle memory. So we activated our crisis response team. We knew what the issue was. We were able to roll back the issue really within probably 70 minutes, but there's complexities in the operating systems to be able to recover some of those systems. Therefore, you had a much bigger outage. So once that was unfolding, then you kind of see the scale of it. And part of the challenge, I'm not sure everyone sort of remember or has a good appreciation, but there was another technology outage, a different company that had an outage at the same time. So what we needed to do was we needed to deconflict what was our issue, which we know how it happened, and we rolled it back. And we had to deconflict that from what was happening with another service provider, right? Because all you hear is outage. So what's ours, what's there's. In any event, we couldn't control that piece. But what we wanted to do was to be front and center. And there were two things that really came to mind. Number one, first was the customer, putting the customer first. We have -- you can see the scale of our customer base, right? We wanted to make sure that we got to our customers. We were working with them to roll it back. And there's things that we did to automate the rollback for them, but just the complexities of the operating system, there were manual things that had to take place as part of that. We needed to be able to get out and educate and tell people what it was they needed to do. And the hard part, some of it required physical interaction. So you had to have key strokes and people have to type things in. And there's a lot that went into it, even though it was a relatively simple set of commands for people that don't understand what -- how to do that, it takes time. But you have to get that information out. So one of the key things for me was take care of the customers. And the second piece, as this was unfolding is we need to let the world know this wasn't a cyber attack because people didn't know, right? And this is where basically we said, look, I've got to get on TV. And this is within a few hours.
John Defterios
analystEven people don't watch TV anymore. That's part of the challenge as well.
George Kurtz
attendeeWe need it to be on TV. Well, first thing we did was we got on Twitter. And we announced it. And then we had continuous updates, right? And this is -- this sometimes going to be hard because you've got teams of lawyers, teams at PR people, teams -- you go on and on as a big company, right? And you have to make a decision. And it's not easy in the first few hours without having all of the facts, and it's a bit of the fog of what's happening. Again, what's ours, what's theirs. How do we make sure we get the right message out. But for me, it was really important to be able to get the message out. It wasn't a cyber attack. We knew what the incident was. We rolled it back very quickly and then we were in the recovery mode, working with customers. And I think that really helped to settle a lot of folks down and then the heavy lifting of making sure that we can bring systems back online was an ongoing effort.
John Defterios
analystI'm going to circle back about your leadership because I want to bring in G2 as we said here, George Oliver, am I correct in saying you're going to retire is pretty soon? What a way to go out, right? Because you had a very big side of -- is that the first major crisis that you dealt with at Johnson? And then -- and I'd love to get the other George's input on this. As a CEO, like what's the first thought that goes through your mind when you get hit that hard? And I'd love to get Öykü's view on leadership and how do you prepare for a new era of a challenge that probably wasn't in our vernacular 10 years ago.
George Oliver
executiveSo I think it would be helpful to talk a little bit about Johnson Controls so you get an idea of what our infrastructure is like and the journey that we've been on. So Johnson Controls are about $28 billion globally. We operate in 100-plus countries. We're very distributed. And we're a company that has been made up of a lot of acquisitions with a lot of multiple systems that have come together into one. And so we've been on a journey on how do we take all of those systems streamline, get to one ERP, get to one operating system with similar type systems deploying. And we've been on a journey. And cybersecurity has been a key element of that. So as we're addressing technical debt, how do we make sure that when we look at our infrastructure, we have over 100,000 devices, 100,000 users and hundreds of thousands of applications. And so just to give a simple lesson, it's all about response. It's sensing at the device level, it's understanding access and understanding where the people that are coming into our network, where they're operating and then it's about applications and access to applications. So where all of that was being built and making sure that we're resilient. So when we had the incident or the -- there's always incidents and they're typically managed and contained. It's all about response,it's sensing and response, no matter what level the infinite is. And you'll find that whether it be a device or whether it be where someone's user credentials got compromised, there's going to be events. It's the ability to be able to sense and respond. So we did get an attack and we're able to respond pretty quickly. It did impact some of our network. And what I would say the most important thing is being -- is planning for what -- in the event that if you do have an event, not only from a technical standpoint, what's the response? But from a leadership standpoint, how do you respond? And what are your business continuity plans. And so immediately, it was on a weekend, you get notified that some of our systems were compromised and then you got to work. And it's easy to kind of try to self, do a self-assessment or you can stand up and lead. And so that day, we had our full extended leadership team across the globe activated, really assessing to make sure we understood exactly what was compromised, what is our plan. And the -- as we work through that, we continue to operate. And so we continue to stay focused on customers. The other thing is this idea of as you -- as George said, as you learn, you maintain transparency with your constituents. Because that's from a trust and respect and maintaining relationships, it's important. So right from the board to customers and making sure that as you're working with customers, you're keeping them informed relative to now where we are, relative to being able to continue to support them with critical services. We're building solutions company. So we do a lot of service, maintaining our customers' environment on a real-time basis. So that's important. So that really played out well for us. And then we stood up our leadership team on a daily basis and also engaged parties. So when you have a lot of technology like we do deployed, we maintain strong relationships with all of our partners. And so we not only activated our internal team and leadership with our business continuity, but also engage all of our technology partners to make sure that we, number one, understood, assess the incident and making sure that then we were working together to be able to effectively address it on a -- what I would say on the critical path to make sure that we're in a position with speed to be able to mitigate the risk and ultimately continue to operate. That's what we did. So I was extremely proud of it. It was a -- what I would say is, and then we can talk a little bit more about this in the discussion that cybersecurity is going to be part of the culture, and it's going to be embedded in everyone's behavior.
John Defterios
analystWhere every company, would you suggest because you're a very connected company, obviously, that's right the same.
George Oliver
executiveBecause you always are a training and you're always putting together processes so that you mitigate any risk and any exceptions. But as you get into any type of incident, you understand, okay, was it a device, was it a user credential, was it access that wasn't -- once you get into them, you make sure that you create redundancies and then automation and the work that we're doing with CrowdStrike is a lot of the sensing and then the automation, so that then you have intelligence not only from a device but from a user standpoint. And then you can -- it's all about response. When you see something that's not right. How do you then respond. So part of that was when you go through this, then every leader in the company becomes an expert because not only are they -- they're involved previously, but really getting to that level of detail. And when we have, we have 100,000 colleagues across the globe. Then from a leadership standpoint, making sure that they're totally aligned and behaving with their actions, whether it be their access or how they're using devices so that they're ultimately making sure that all of the securities that we have in place being fully consumed and put to work. And so for us, it was as we look back, it was a test of our culture, our ability to be able to respond and activate a global team. And really continue to be able to operate the company while we're mitigating the incident and ultimately getting back to full operation. So I was extremely proud of the team and really a lot of our partners have stood up with us to make sure that every step of the way they were playing their role in supporting us to mitigate what we saw as being the contributing factors.
John Defterios
analystOkay. You raised a great point. It's a great leaping off point to Öykü. First, can you spend 10 seconds to tell the audience what your specialty is because it will help us in terms of your context of your research, Öykü?
Öykü Isik
attendeeYes, of course. As a professor of IMD business, we actually exclusively do executive education. So first of all, it's a privilege to listen to two leaders talking about their experiences. This is what really makes a big difference. And my research is really on about Chief Information Security Officers and behaviors of organizations when it comes to dealing with cyber attacks.
John Defterios
analystPerfect. Okay, good. We have this case where you could have a prisoner's dilemma because you're in the game together, right? And you have this trust built up and then you face a strike and then that cohort starts to look at you and say, "Okay, I put all my trust in you and there was a failure". And then there could be panic from that partner or as George was explaining, everybody rallied to the cause. So what does your recent research advise future-looking CEOs because we know that threats are rising, and we'll get into this discussion about the developed and the developing world, right, and those vulnerabilities a little bit later. But -- and also that brand narrative that I addressed in my opening comments about rebuilding trust very quickly during an incident because we want that V-shape to rise quickly. Go ahead.
Öykü Isik
attendeeI love that visualization, the V-shape and we talked about shrinking the V, right.
John Defterios
analystPretty good team that we work with.
Öykü Isik
attendeeExactly, exactly. So -- and there are two things that Josh talked about may. The muscle memory. I love that reference because that only happens if you think detailed enough of scenarios and if you practice enough, right? And George talked about how it's part of the culture and how quickly you were able to continue working right, servicing your customers. So first half of that V absorbing the incident. That's a great example of that. So you were prepared, the culture was there. So you were able to despite the incident were able to operate. And the other one, the significant part of the resilience is that we actually can practice this enough so that we can, after absorbing, recover from the experience. I think there were two really good examples of long-term thinking and answering your question. The necessary shift from more traditional short-term cybersecurity thinking to a long-term resilience building thinking is I think these examples is greatly represented here.
John Defterios
analystBut who would have thought 5 years ago that the brand would suffer if you don't respond. I mean, George was saying, look, I was ready to communicate, both of you said, I had to communicate to my partners, my customers and then you had to say, "I need to get ahead of the curve here". Go ahead, Öykü.
Öykü Isik
attendeeBecause you talk about trust, right? How do we build trust. And the first question that comes to mind, especially -- there are, of course, anecdotes we can learn from when it comes to doing research, it all comes down to how do I quantify trust. What do you mean to us? Is it the financial health of the organization? Or are we talking about finding a way to measure the reputation of the organization. What we know from -- if you look at just from a financial health perspective, to be honest, we don't know much. We only have very little research on this because very difficult to collect reliable data at large scale to really understand. And the research are all over the place. But when you look at trust from a reputation perspectiven then we know for sure, minor incidents. We tend to actually forget organizations do recover from minor incidents relatively quickly with minimal stock value impact. But for major incidents, we do have evidence that it really takes quite a bit of time to recover back. But I want to add something here that most people don't think about which ties back to preparation is that what type of incidents we're talking about makes a difference. And we know this from research. So if it's an internal, insider threats then the perspective, the trusts on the organization really decreases. If this is an external threat, there's a threat actor, then really, it is less of a trust issue on the services of the organization. So if it's negligence, then the question arises around the culture of the organization, for instance.
John Defterios
analystGood. Both of your comments, led me to believe if you had to do this again, what would you have done differently? And there's always that question that comes up because you have businesses that need to sell cyber safety and security and fortifications. And when do you know you have the right tools? Go ahead, George.
George Kurtz
attendeeWell, you never want to be in a position, but you have to prepare for it, right? And this is what we're talking about. We help a lot of companies go through incidents, and we drill ourselves. And this particular one, it's hard to put this in the playbook of what happens, right? But we used the same, again, muscle memory to be able to roll things out and activate our teams. I think as you go through any of these, there's always areas where you can pick out and go, "okay, we could have done that better, we could have communicated this or you come up with various scenarios. But I think, by and large, something like this in any incident, if you are upfront, if you're transparent, if you communicate not only one time, but frequently, and this was a big part of our response was we immediately said internally, and then we've said externally. We will tell everyone as much as we know as soon as we know it. And basically, we had a whole portal that we stood up, right? And then as we knew things, you just went to the portal and you got updated, right? So I think that really served us well.
John Defterios
analystAnd as the business has been hurt, as a result of it now, would you say the CrowdStrike brand suffered?
George Kurtz
attendeeI think the trust is even up more. I mean, I'm walking around Davos, I run into the CEOs of many of our companies and they said, I had one organization. So we actually use CrowdStrike in our responses as the prototype for how you should respond. That was just last night. So I think -- again, everyone's going to have their own opinion, but I think our customers have looked at it and I think anyone in business or IT realizes things happen, and it's really how you respond. And we want to be known for our response to this not necessarily the incident that actually happens. So that's the way we would look at it. And again, could we do things better? I'm sure. But I think overall, with trust and transparency and communication, we did the best we could with what we had in front of us.
John Defterios
analystÖykü?
Öykü Isik
attendeeMay I quickly add here, because we really do know that during the incident, communication is the biggest differentiator. And being transparent, honest and owning up to it does make a big positive impact on the image of the organization. But I wonder what you think about the possibility that in your case, product stickiness and vendor lock in, how much that play in, right? Clearly, for smaller organizations, this may maybe lead to or customers leaving. But I wonder if you -- if there is a way for you to kind of measure the impact of that?
John Defterios
analystJust so you can [indiscernible]. That's a great question. We're going to look at the vulnerabilities of SMEs in our next round. So I'm glad you brought it up. Go ahead, George.
George Kurtz
attendeeYes. I think when you look at this, I mean, we're a public company. We talked about our retention rates, right? They're 97-plus, which is fantastic. So even after the incident, I think when you -- to your point about the product and the stickiness, I mean the good news is we've got the best product in the market. So customers like it. And I'll just tell you a quick story of a customer. It was a large financial services company. We went through what happened, why it happened, why it won't happen again. And they said, "Look, you've got 10 years of trust deposits in the bank, 10 years of trust deposits. And on the 19th, you had to withdraw. But net you're positive, net you're way positive.
John Defterios
analystThat was nice from a financial services company to say it and put it in that.
George Kurtz
attendeeAnd it was -- but they went to -- he -- this system went to the board and said these -- if it wasn't for CrowdStrike, they recovered pretty quickly. If it wasn't for CrowdStrike of 10 years of protecting them, it would be a much different story. And this is, again, building trust over time. And I think that has really helped us out with a great product.
John Defterios
analystRight. I don't want to get into Midwestern values, but the company is based in Milwaukee and Wisconsin. For those who know, I know America, that's where they value it. I'm from the West Coast. So it's a little bit different mindset of like Blue Sky thinking.
George Oliver
executiveI would like to contribute to that the last question about the two things that come to my mind because we -- cybersecurity, of course, is a top priority across all companies. And then it's more about how is that then built into your operating system. So that all of the key metrics, response times, if there's any exceptions around, sensing up devices or any as far as the strategy around user access, really the CEO, at least should understand that. I mean understanding what their network is, how that's configured. And then from a cybersecurity metrics, they should be embedded in their operating metrics across the company. And that allows every leader to really understand how they lead cybersecurity, right? Typically, I think historically, it's been more of an IT type of metric. So I would say, number one, making that front and center, really understanding your infrastructure and network, how that's made up with devices, users, applications and then the whole strategy is sensing and then reacting. So then when there is anything unusual in the most simplest form. And the second is, and I think this is where George comes in, George one comes in, I purposely and I'm an engineer so I can consume technology, and we're going through all of the reviews and felt that we had all of the best technologies and capabilities deployed. What I learned was that technology development is so rapid. And now with the threats being much more sophisticated because of AI and other capabilities that be versed on the state of the industry. And so I spent time with a number of other CEOs in the cybersecurity to make sure that I fully understood as far as our -- the work that we had done to build our security, I understood then how does that compare to what you'd consider the next generation kind of best-in-class. And I think that's helped the organizations so that as we're prioritizing where we're now deploying resources and the like. It's, I think, pretty clear to everyone now why we are doing what and when.
John Defterios
analystOkay. And my question on values, what do you learn about the values of your organization during the crisis?
George Kurtz
attendeeWell, I mean, for us, as we've gone through a transformation, it was a test of leadership. And when you're the CEO, it's -- when you get that notice that you've got an incident and then you quickly scope in, and it's significant. You can reflect and -- but I think what happened was we immediately did what we all did best was a lead and engaged right from the day it happened to business continuity, daily understanding, okay, how we're going to operate where we had some challenges, how we're going to operate around. And it was seamless. Meaning every day, every business leader with their teams, the workarounds or some additional capabilities that we could activate. And so that was a real-time learning shared, kind of a standup meeting, just as you're assessing and acting. And I think from that standpoint, you then have the -- now the combined knowledge and you're acting real time and you're communicating to customers and ultimately, employees and partners. And what you want to do is instill confidence that, okay, everyone is going to have an event, how do you manage that. How do you respond. What is the leadership that you demonstrate. And I think for us, as we've worked with a number of partners and advisers working through this, we got high grades at our team, was prepared and we acted and continue to run the company fairly well while we're mitigating the risk.
John Defterios
analystOkay. Good. I want to bring up the next set of data here. We have about 16 minutes left. Looking at this cyber inequity, and that would be from a large company that has budget and can play with this into your supply chain with small organizations that probably don't have the budgets too. And that's the trust that we wanted to talk about. But also I would like to have you address the developed versus the developing world, right? Because everybody likes to tap that growth of emerging markets, but do they have the capabilities to be your partners. So if you can look at the surveys here, the key challenge, 54% of large organizations highlight supply chain challenges as the greatest barrier to achieving the cyber resilience. How do you test your supply chain as one question I want to have you consider? And then furthermore, 71% of Cyber leaders at the Annual Meeting in November of the Web Cyber Security Group. Small organizations have already reached a critical tipping point when they can no longer adequately secure themselves against the growing complexity of cyber risk. SMEs, of course, represent about 50% of growth or 50% of jobs around the world, no matter where you are in the economy. So George, where are some examples on lessons how to successfully rebuild trust with the stakeholders, but how about everybody in your supply chain, how do you make sure that they're up to snuff think it applies to both you and then, okay, you can weigh in with the research and recommendations on that.
George Kurtz
attendeeWell, I think when you look at supply chain, this is one of the areas you saw the stats of risk. And I know we talk about it a lot, the interconnectedness of the world. I don't think it's fully appreciated. It's almost -- when you have these visuals, dollar bill is really thin, but $1 billion goes up to the moon kind of thing. Like you really don't know how interconnected the world is until you have an issue. And when you look at supply chain, which is one of the biggest areas of risk right now, you've got small companies that make one little part, one little bolt, one little something for a spacecraft or the government or what have you. And they're all connected. And typically, what we find when we do incident response for companies is there's a lot of large companies that do the right thing. They spend the money. And then it's a third party. And you don't hear about the third party because there are 10 people or 100 people. Nobody knows who they are. Nobody want to talk about it. They want to talk about the company that has an incident. So that's one of the biggest areas I'm sure you can reflect and comment on that. And making sure that, that is locked down is incredibly important. And overall, just assessing where the real risk is and where the dollars need to be spent. From a smaller company perspective, they have a lot of risk, right? And they have a lot of risk, whether that's ransomware or whether it's supply chain into a larger organization. And this is why AI and even managed services are so effective because you can basically -- and even a small company, we can bring the same technology that we bring to the largest banks, to a small company at a very efficient cost price points So that's the way we do it.
John Defterios
analystThere's the other threat of the deep fake, like somebody takes over to your board and they hold a Board meeting and they kind of hijack your narrative for 24 hours if you're not careful, right? So that's complexity for a leader. Is it not, Öykü? What's your...
Öykü Isik
attendeeAbsolutely.
John Defterios
analystAnd this whole idea of trust that you could be completely bought into a deep fake. And so -- that changes the game quickly.
Öykü Isik
attendeeAnd I think sometimes I still do hear from leaders of SME, small organizations that makes me think that there's still lots of awareness work to be done there as well. One manager of SME shared about the ransomware incident they experienced and how this experience brought the team to that made them a team at the end that's almost thankful to the experience saying that I had zero preparations in place before I experienced this. Now I am a team, a real team with the rest of my organization. And we actually have processes and policies in place to deal with this. So it makes me think that maybe sometimes still this thinking "oh,I might be flying under the radar" can still be a thing for SMEs. But coming back to leadership skills, I think it still applies whether a large corporations or SMEs still being able to decide under pressure, having emotional intelligence and composure, being honest and accountable. All these characteristics, better for international corporations or SME's I think the same.
John Defterios
analystGood. George, do you mind Oliver dealing with this issue? If you're a global company and there's vulnerabilities of a developing world that they want to grow. They even admitted they don't have the skill sets inside your short of the cyber...
George Oliver
executiveWe have a very complex supply chain. It's global. We have all size suppliers that we do try to mitigate risk by having multiple suppliers, dual sourced and regionally developing suppliers. So there's all kinds of supply chain strategies. But what I would say, what we've learned is that as we're assessing suppliers, we go through supplier assessments and then you can tell when you go through an assessment, the ones that actually understand it and are proactive in what they're doing to protect their infrastructure and maybe ones that are not. And so we have a role to play that #1, we now make sure that's part of their assessment. And then as we can educate and help and assist, then we obviously make our teams accessible to do that. And I do agree with George that when I think if -- we're the ones that maybe don't have the depth of expertise within their company, then it's going to be very difficult for them to manage themselves. So I do believe -- and I think what we're trying to do, and I get lots of inbound calls from other CEOs as far as how we dealt with it and how we responded. And I think the biggest thing is this, we want to help everyone, right? You want to -- we all want to make sure that we're all learning through this journey we're on, helping other companies, helping suppliers. So there's a huge education that we're -- I think everyone is going through because this is becoming much more sophisticated and then demanding it. And what will happen is you're going to have to -- either suppliers are going to have that core capability or not? And if that's going to propose any significant risk to our ability to be able to continue to execute, then we'll probably have to look at other -- which we do on a real-time basis. Even though everyone seems to want to get down to the resources, you can't afford not to put the resources to work. Because that -- think of it as more insurance than it is once you have an event, then all of that is for not anyways.
John Defterios
analystI want to open the floor. Thanks, George. I want to open the floor to questions. If you have a just raise your hand and we can get a microphone into your hands. And don't be shy, I'll give a breather. I've got another question on our hands here. State actors, it's getting pretty nasty out there, right? And they wouldn't call out different countries, but they do often now, right? So U.S. accusing China or Russia, the fight in the Ukraines become a cyber warfare as well. That's a pretty easy way to disrupt if you reach into U.S. Treasury Department, right, or the Federal Reserve. How nasty will this game get now with AI coming on quantum computing power? How do you see that?
George Kurtz
attendeeWell, it's already nasty. I think most people really don't see below the iceberg, right? And when you respond to...
John Defterios
analystThat is a perfect way of putting it, by the way.
George Kurtz
attendeeWhen you respond to these things, you see how prevalent it is. And when you only hear about it, when it bubbles up to something that can be sensationalized. But China is very, very active in these areas. One of the things that they're really focused on is operational preparation of the environment. So being able to prepare in case of conflict, say, South China sea for example. And this is a huge issue for -- certainly the U.S. government and other governments, right? And if these sort of things happen, there's a lot of capabilities there. But I think the hard -- we can talk about different countries and adversaries for the next hour. But I think the heart of your question is, what does it all mean and how bad does it get? Well, this -- we think about adversaries in maybe three categories and I can think about it as a pyramid. So in the top part of the pyramid, you have nation state actors. In the middle band, you've got e-crime and at the bottom, you've hacktivism. And at the very top, you've got the most sophisticated actors. And then what we see is that their techniques trickle down into the center band, which is e-crime. So you don't have to be a true expert actually to be able to execute an attack. Now when you talk about Gen AI, you've now democratized all the smart things that have been done by the nation states and now you make it available to like a multiple of adversaries that are out there. And even if you don't know what you're doing, a, you can buy these capabilities, but we see it now where an adversary maybe is not all that sophisticated. They buy a kit, they can break into a company and access broker. And then they actually have one of the GenAI tools create scripts to actually bypass the technology. So that's the biggest thing that we're going to see is, it's going to compress the speed, we talked about response, right? You had so much time now it's going to even get shorter. We track breakout time, it keeps getting smaller and it's going to democratize how many more people can get in the game of being an adversary.
Öykü Isik
attendeeJust to add to that, because I do realize also in the classroom that most executives do not really know how accessible these things are and that you can still inflict damage even though you're not an expert in this, right? So the accessibility, growing cyber crime as a service market is something that we really need to continue talking a lot about. And we know that even more damage is possible with AI. Research shows us what's possible already. And so there are things that we can start preparing for even though we don't see them out in the wild yet. So there are many different resources we can turn to, to start preparing a scenario planning for these things.
George Oliver
executiveGeorge, I think it's really just playing offense, meaning that we can be as sophisticated as they can be with AI. We now -- we do believe, and my assessment on the technology community is making incredible progress. So technology is available today. to solve -- to really be proactive to mitigate any significant risk. And so I would just suggest that how do you now take that technology and be really proactive using AI and thinking like the bad guy because I think that allows you to be agile in taking all of your data, whether it be around your devices around users around applications and become really sophisticated in how you ultimately then -- because like as George said, it's all about response. When you see anything unusual with a user or with a device, is immediately shut down. Because they're going to find a way in what you want is a sense to sensing and response that they're in the closet as I say it, so it stops the progression as they get into your network. That is probably what's most critical. I would say, based on my experience, really understanding the technology and then understanding how you get this defense in depth around all of your critical elements of your network, which then allows you to be able to create that response on anything that's unusual that could potentially be more of an impact. And I think in doing that, will be as good. And then through service providers, you have good intelligence relative to what the broader landscape looks like. And so that sharing relative to how we're proactively deploying out the technology. So I think it's very helpful.
John Defterios
analystGreat. We have questions here on the floor. Please, one here. And just if you can direct it to somebody, if you have one in specific and just let people know who you are.
Unknown Analyst
analystSure. Roche Navkama with AIG. George, good to see you. The question is directed maybe starting with you. You actually triggered this for me when you talked about nation-state actors in terms of threat actors, right? Just your thoughts on what you think is a corresponding public-private partnership opportunity, maybe a more kinetic partnership opportunity when you're thinking about defense and kind of the blue team.
George Kurtz
attendeeWell, that's always the big question of what can be done. And when you look at the private sector, we do work with law enforcement all the time. We explain what's happening. We found -- I mean, we didn't even talk about North Korea and some of the things that they're doing, which is really interesting. But what can be done. And I think we started with the public private sharing of information with things like JCDC where you have these fusion centers and they can share all this information, which is great. But then like what is the next step? How can governments be more active in shutting this stuff down. There was a recent example with one of the ransomwares kits, I forget which one it was, where they basically the government's kind of defanged it, right? They went out and they were able to -- you probably remember which one it was. But those are the kind of things that we look at. And then how do you disrupt their infrastructure. You have to remember, the infrastructure is actually fairly not costing dollars, but time to be able to set up and they want to reuse that, right? So if you can burn their infrastructure every time, it makes it that much more difficult for them to keep wash, rinse, repeat. We see what happens. And it literally is wash, rinse, repeat. Just give them the list of companies. So I think that's where it can be much more interesting and more offensive where you can disrupt that, and I think it in a controlled fashion.
John Defterios
analystOkay. In 30 seconds, if you can, George Oliver, our government is prepared because I know they take it very seriously at the White House, for example, they have a cybersecurity desk and they liaise between national security and natural economic counsel, but they take it seriously, but they can't potentially keep pace with the private sector, right? Just a minute, if you can, and then I'll go get Öykü's final thoughts.
George Oliver
executiveWell, I mean, on that -- I mean I don't want to assess the governments. I think at the end of the day, there's different levels of sophistication and resources that are deployed across the globe, I think for all of us, making sure that there's transparency relative to what is happening so that then they ultimately are putting their resources to work to ultimately correct -- to protect the broader environment. So I think it varies, right? I mean across the globe.
John Defterios
analystYes.. I do have those concerns, and I've shared it with the web about the Global South in terms of they have to deal with energy transition and climate change and dealing with something like this, you're trying to grow feature populations and deal with cyber threats, right? And we've seen the attacks.
George Oliver
executiveI mean I think -- I mean what I'm finding on internally with our own resource that we're putting a significant amount of resource and we're finding that from a technology standpoint, we leapfrog in some of the older, less effective technology now with a new technology. So you can do it very efficiently as you're now continuing the journey to really be proactive with the technology that's being deployed.
John Defterios
analystRight. Öykü, in 40 seconds, you have final thoughts on this and what you learned out of this from two leaders in the space.
Öykü Isik
attendeeYes. I guess we heard that is a leadership imperative. So there's a very big technology site to this. But clearly culture and leadership and awareness creation in the organization is still the pushing power behind this. And I think it's a very interesting thing to look into how can we be more proactive rather than defending ourselves. How can we proactively engage and disrupt the operations of cyber crime network on one hand, right? On the other hand, I'm thinking from an information sharing perspective, bringing SMEs up the speed, what kind of incentives can we create out there to -- so that it doesn't end up becoming only an issue of protecting myself. But how can we incentivize investing in resilience is also a good question that I have in mind.
John Defterios
analystYes, that's great. Our session was from crisis to confidence in cyberspace. I'd like to thank the panel. Akshay Joshi, your team Philippe, Juliana, thanks a lot for all the support leading up to it. I appreciate those who are online. I would highly encourage those in the audience here and online to take a look at the annual report, which came out a week ago. It addresses this wholeheartedly and you'll see where we got the data that we shared on screen here. I appreciate your candor, by the way. Most CEOs have had something, an incident, if you will, wouldn't sit up and face the music. You did it when the incident happened, but you're also willing to share the lessons learned, which I appreciate. Can we give a nice round of applause to our panel. Thank you.
Read the full transcript via the API
You're viewing the first half of this call. Get the complete Johnson Controls International plc transcript — plus 250,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.
Get the API View API docs →This call discussed
For developers and AI pipelines
Programmatic access to Johnson Controls International plc earnings transcripts and 250,000+ others is available through the
EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments,
full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.