ServiceNow, Inc. (NOW) Earnings Call Transcript & Summary

January 30, 2023

New York Stock Exchange US Information Technology Software special 55 min

Earnings Call Speaker Segments

Aaron Bennett

executive
#1

So welcome, everyone. we're going live on ServiceNow with Snyk. My name is Aaron Bennett. I'm Tech Clients' manager here at ServiceNow, I'm proud to welcome the Snyk team, plus one of our own to present to you this community webinar. So Marco Morales, Wendy Swank. Welcome, and I'll turn it over to you. And go ahead and feel free Wendy, Akhila to talk about the results of our poll.

Akhila Managoli

executive
#2

Wendy, do you want to take that?

Wendy Swank

executive
#3

Sure thing. Okay. So -- our first question, what brought everyone to the webinar today, looks like we have a good balance of our press release, which hopefully everyone did see on the 24th. We issued a great press release that really shows the journey of ServiceNow and Snyk from being a client of Snyk, now our partners and investment news as well. So that was very exciting. Looks like our second question, are you leveraging Snyk and ServiceNow today, a good mix of about 15% of the audience leveraging Snyk 45%, leveraging ServiceNow; 9%, leveraging both and 30% neither. So -- this is a great opportunity for those of an either camp to learn more about what we're doing together, you'll see the strengths of ServiceNow, the strengths of Snyk, but of course, the better together solution is the real power here who'll win the big football game? This is kind of sick and 45% said what game? Well, all right, so we've got to have some additional enablement here. We have 27% on the Chiefs. I think they have won too much, and I'm a Patriots fan, so I'm sure people will say, don't say that,patriots have won too much, but really have been looking terrible this year, naturally. The Eagles 27% all right. Even on the teams but -- surprising part is the what game ? All right. So with that...

Marco Morales

executive
#4

We welcome the disinterest in. absolutely.

Wendy Swank

executive
#5

Of course.

Marco Morales

executive
#6

Why don't you go ahead and introduce yourselves once to get this thing going.

Aaron Bennett

executive
#7

Sure. I'll leave it. Wendy, why don't you go ahead and since you've been talking.

Wendy Swank

executive
#8

Excellent. Well, thank you again all for joining. My name is Wendy Swank. I'm located outside of Boston, if my team affiliation didn't give it away. I'm Alliance Manager here at Snyk working with our strategic partner, ServiceNow and working very closely with Aaron and Akhila and a lot of the other ServiceNow folks very happy to be here today. Marco, why don't you go?

Marco Morales

executive
#9

Yes sure. My name is Marco Morales. I'm a Partner Solutions Architect at Snyk, and I'll be doing the Snyk side of the demonstration. I am from Chicago. I presently live in Philadelphia, so I'm supposed to be rooting for the Eagles.

Akhila Managoli

executive
#10

I'll go next Marco. Hi, everyone. I'm Akhila Managoli. I'm a [indiscernible] architect for Alliance team from ServiceNow work closely with Aaron and of course, on the partnership on Snyk with Wendy and Marco and I'm from Bay area.

Marco Morales

executive
#11

Okay. So today, we're going to be in the next, say, half hour or so, we're going to show you a couple of slides to introduce and give you context. Our goal today is to describe the latest and the new and improved or however you want to call it, integration Snyk has with ServiceNow. So we'll show you some of the things, and then we'll do some demoing to show you how people use Snyk to provide context. Some of you may not be developers, some of you may be, but it's going to be, here's how a developer uses Snyk and then how it plugs into ServiceNow. So we are brand new as of January 24, we have a new app on the ServiceNow store. We do this over a period of several months. We're really excited. We want to start conveying certain ideas that we're going to hit home a couple of times during this presentation or at this demonstration. First is that we're going to help you all your entire team track and manage vulnerability. So what's happening is with today's DevSecOps teams, sometimes people don't have full visibility. So we want to help your entire team track and manage those vulnerabilities. We also want to give with this enhanced visibility, the chance for your team to make decisions a little bit faster, which we believe. And we also want to pull on the idea that this is a unified view across your entire team, including your application security team, security professionals, which may have been previously disconnected. This whole idea here is to give everybody a view so that you can all understand the risk of what your vulnerabilities are. And I'll show you a couple of examples of what that means. Let's start introducing Snyk. So Snyk, It's a developer security platform. If you've seen any demonstration or visited our website, you'll see and hear us talk about we're a developer first. Really, what that means is we try to work within the day-to-day workflow from developers. We try to provide all these tools and experiences for their benefit. So they feel very comfortable using our products. We have more than one. We have Snyk code, which is for what people use when they write code -- some people call that SaaS or software application security testing, that is one of our products. We also have Snyk open source, which is going to be the primary emphasis in this webinar. Open source are the libraries that developers may bring in as they build and create software. We also have other products for a Snyk container. This question does come up often. We are not covering that today. But is for those people who create containers. We have Snyk IaC infrastructure as code. We have Snyk cloud for cloud deployed assets. Again, we are going to emphasize Snyk open source. I know that people have other questions, but you'll see a lot of the conversation only around this solution here. Why Snyk? So this is why should you care? So we have a bunch of different assets out here. And I'm going to speak to a couple on numbers. So Snyk has the world's largest open-source library database, and that's pretty cool for us. We have more vulnerabilities in our database than any other company, which we find is really helpful because oftentimes, we've learned and the example here in the middle that some vulnerabilities hit our database first before anybody else at a pretty good rate. We also offer ideas around how to help your teams work with low false positives. Many of you have seen a phone book, a very large number of vulnerabilities. We're trying to limit this as much as possible. And we also want to provide you and your team the right context and guidance so that they know how to solve and address these vulnerabilities. It's one thing to be told, you have an issue here. It's anotherone that we told here's why it exists. And as the third thing for us to tell you here is how you fix it. And we'll show you a little bit of that today. Where do we fit in? So this comes up often in terms of where does Snyk fit in? How does it work? I am a security professional. We want to emphasize that we are primarily in the application space. Many of you may be familiar with perimeter or networking defenses, Snyk is not that -- and those are great solutions. We have partnerships. We were friends with them. We respect them, but we are primarily around the software application that you and your teams to develop. At this point, I'd like to turn it over to Akhila to give you an overview briefly about ServiceNow.

Akhila Managoli

executive
#12

Thank you, Marco. I was just thinking where to start with ServiceNow, right? I don't know. I'll just start from the beginning. So I don't -- we have a lot of people on the webinar. I don't know how much you know about ServiceNow. So historically, we know that ServiceNow -- is noted as IT ticketing solution, right? But over the past few years, folks have seen just how much more ServiceNow has done and is doing. So it's the ServiceNow starts with the now platform and its breadth of capabilities. All of which we can leverage in various industries we serve today. It could be Finserv, it could be health care, it could be many other industries and also the verticals we serve, like solutions portfolios we serve, like IT service management, IT ops management, it could be security operations, risk and the latest one to add to our [ feather ] is the ESG, the HR service delivery and so much more. And as we say, ServiceNow helps the world work better. That's what ServiceNow stands for. But as Marco was sharing in today's presentation, we are going to limit to vulnerability response. So as I was talking about security operation, the vulnerability response module is part of that at the broader SecOps module, which really helps organizations to manage their attack service management. So when it comes to attack service management, you might be familiar, there are multiple different kinds of vulnerabilities and organization that makes pose to. There's infravulnerability, there is cloud vulnerabilities, there is, as Marco was talking about container. And all of that, the vulnerability response module supports basically by bringing in the data from integrating with multiple scanners you bring in the data to service the platform. And then on top of it, you can add the features are part of the well response module Comingle all that and which makes the remediations fastest for the target teams. But again, dwelling -- just going a level deep within that is application vulnerability response, which is part of the broader well response, which focuses mainly on the application vulnerabilities. So within application vulnerabilities, if you were to think there are multiple different kinds of vulnerabilities, there is SAST, which is a frequently started application testing, security testing and theres DAST, which is dynamic application security testing and there is software composition analysis. So with Snyk and ServiceNow integration, we are going to bring the software composition analysis results found from Snyk platform in to the ServiceNow vulnerability response module. And you might be familiar that developers tend to use the open source components in their code, which is a very, very familiar concept. That said, that exposes so much risk and that the open source components does have multiple vulnerabilities inbuilt into them and how do we mitigate them? And Snyk is one of the top planning tools that is known for SCA vulnerabilities, and Snyk -- integration of Snyk with ServiceNow brings all the data for you in a much handable fashion within the Service of platform and makes developers' life really easily. Marco, can you go to the next slide? Yes. So I touched base on this already a little bit. As you see application vulnerability response expandable SAST, DAST, SCA, pen test and furthermore and could be -- a security in today's -- right? So we -- for today's conversation, we'll be focusing on software composition analysis results of integration with Snyk and ServiceNow. Marco, you want to take it from here?

Marco Morales

executive
#13

I was on mute. Thank you. So today, we're going to show you how we cover these assets here. It is a new app. We're excited. We want to show you how we provide visibility, and let's now start getting into a demonstration of the everyday workflow of a developer and how this gets absorbed and fed into ServiceNow. So if I'm right, this next slide, again, we're here better together, Infinity. This is fantastic stuff. But the part here is we're going to show you Snyk, I'll do that for about 5, 10 minutes. And then Akhila is going to pick it up with how this information is picked up in ServiceNow. So from here, I'll transition over to a different tab. I'll have more than one tab that I'll navigate into to just give you a feel of the everyday life cycle of a developer. So first and foremost, I want to just draw attention to a public GitHub repository that Snyk host. And we have a number of deliberately vulnerable applications. We have them with different languages. This one happens to be node. We have a job and other ones, but we provide these as public assets for you and your team to inspect and try out. One thing we do recommend is that you do not, again, do not run this in a production environment. These are deliberately vulnerable because we run exploits. Today, I'm going to leverage some of these vulnerabilities to just show you how it works and how it works within Snyk. Next what I want to do is show you an IDE I've made the fonts big and high contrast for your benefit. So you can see, if you like small finds and dark mode, we'll do that at a different time. But for today, we'll just look at it in a nice and easy in an easy view. So what I have here is the actual clone repositor, I created a fork and I have it in my environment. And what I want you to appreciate it if you're a developer or not is we try very hard at Snyk to give the developers an in-line experience. And if I do this right, all the stuff that I'll show you is going to stay within the IDE -- of course, your developers can go elsewhere. But when your development team is writing their code and using open source. One thing I forgot to mention during the presentation is we've discovered that anywhere between 70 and 90% of the total application payload in modern applications is actually open source. So that means developers may be running 10% to 30%, but they bring in a lot of open source, and that's where this example comes in. So I'm a known developer. I have certain files to file in the middle, which is package Jason, is something most know developers are filming with and they'll say, "I know what this means. On the left, what I've already done is I've navigated into the Snyk extension on Visual Studio Code. You may be wondering, do we support others? The answer is yes, we do have IntelliJ and Eclipse. But in my day-to-day, I tend to use Visual Studio code because it just hemps to be of my benefit. If you look at my screen closely, you'll see I have the open source security panel open. But I've closed the code security and the code quality, which are around the other products. Again, I want to emphasize one more time. We're only looking at Snyk open source for this ServiceNow integration at this time. So developer has this information. They're looking at it and they manage their own work within their life cycles. Maybe they make changes whenever they can or maybe they use ticketing systems. But the idea that Snyk is trying to support is we will give your development team all the information they need as they're doing the work so they can triage and do the right thing. -- you'll see the letters like C for critical, H for high. These indicate high and critical severities for vulnerabilities. There is a lot more that we're going to dive into, but these are all signals for your development teams to know what am I working with? What am I looking at? I've highlighted 1 as [Jason package] because it happens to be a critical, it's like the second one, but I [ better ] than handle bars. The information we have here you will notice is going to be available in a variety of formats. Here is 1 of the IDE. Later, I'll show you the UI on the web application. What we try to do is we try to provide people as much context as possible, including the CBE database entries, which are public assets that contain all this information, anyone can look at it. This is a way for you. If you're curious or you just want to know more, can click into and study them. But at your fingertips here, you have a number of things like we described the problem. We tell you what they do in this case, a version upgrade. And you can then choose to operate within your team's workflow, your SDLC to address this issue. And one of the things I do want to show -- and your team will have different ways of using this information if they want to use pull requests and so on. We support all those things. A question that sometimes comes up is what repositories that we support? We support all popular Git repositories. This happens to be based from GitHub, Gitbucket and GitLab. Those are all equally find on-premise or host that are also good. What I'm going to show you here is some developers do like using the command line. I already have it in my history. I'm going to run a Snyk scan for open source, and it's only going to look at the critical issues. It takes a few seconds, I get my results. This kind of information is useful for those teams that I'll make this big -- this kind of information is useful for those teams who have members who really enjoy or like using the command line, maybe they use Jason output or maybe they include this into their build operation for any number of pipelines that we do support. This, again, I hope you can see, helps you see how a developer can do all of this work to manage their workload within their IDE environment. They don't have to leave it and they can do everything as they know and they love. Next, I'll transition over to a more global view, which has the same information in our UI. Snyk is a hosted application. I have -- there's organization structure we have these things called groups and projects we really think about it, it's like a nested [filtering ] type of structure. The application I have happens to be forked under my name, and the information we have here is in graphical format and UI, same kind of information that you have with the ID. Where this helps people is if you and I are working the same team, maybe I don't have my laptop or maybe I just want to open up a browser, -- or maybe I'm a leader or someone doing a drive by. And I just want to visually inspect the status of my teammates to other activities without having to do all the IDE work and other things. This is available for them. Package Jason, if I click into it, is going to give me the same information. But in a more familiar UI-centric way that most people are accustomed to when they use these different tools. I can talk through all the different fields that we use to help your teams prioritize, but really, the biggest point here is you can probably start to deduce that much of what we've been doing is around the structure to help developers work, help them collaborate, help them do all this work so that they are best equipped to address software vulnerabilities. AppSec is probably on the side wondering when can we see, when can we do stuff? And Akhila will show you that in a couple of minutes, but I want to close out with just a few more points. The details I'd like to show you here kind of go along the lines of how we provide the explanation to developers. But one of the things we know is really important and it's used in the ServiceNow side of the demo is that we have a concept of a priority score. What we learned over time is that sometimes people use 1 dimension like a CVSS score to prioritize. What Snyk has done with this Intel database and other proprietary and open information as we've used information on us, does this vulnerability have a known exploit in this case, to mature exploit. Doesn't this vulnerability have a fix available. You can imagine if there is an exploit that is known and there is a fix that's available, your priority score should get bumped up. The filters on the left, help you do some of the right things, if I were to click on critical to limit to just 3 and see which ones are fixable or whatever the numbers are here. This really helps you and your team figure out I can solve something very soon. You can see there's nothing that's fixable, but partially fixable is other stuff that we had hoped. Again, this part of the dental is -- I didn't do this track, but you can see the intention behind it. This is the kind of information we want to have your development team have at their fingertips so they can do the right thing. The last thing I'd like to show is something about dependencies. If you recall on the IDE screen, I had a small list of -- I'll make this terminal small, I had a small list of direct dependencies that me and my team listed -- you can see there's probably about 30 in this list. If I navigate over into the UI, you'll see that I have over 700. So this is something that's really important for those teams because transitive dependencies are really critical for how we do this. What happens is I use open source software, but the providers of that open source software may use other packages as well and then you get this lovely tree. When we look at the details behind the vulnerables, you'll see that tree spelled out as this brings and this brings in another thing and so on. And that's available to your team for you to use. In closing, I'd like to demonstrate that -- we've done our best so far, and we will continue to try to empower your development teams to address software vulnerabilities as they encounter them and manage it in their own time. Now Akhila is going to show you how we give access to the application security folks in ServiceNow visibility into what's happening. Akhila at this time I'm going to transition over I'll stop my share and let you pick it up.

Akhila Managoli

executive
#14

Thank you, Marco.Just a second, I'm just bringing -- already. That was very detailed walk-through of Snyk platform and how users can look at the vulnerabilities within Snyk platform and the additional features of that all of that. So the good news is now we have seen how Snyk scans the application vulnerability and reports it for you and we can go see all the data there. But -- and with this integration with the SCA integration with Snyk and ServiceNow, we can bring in most of that data back to ServiceNow platform and make it visible for you, and as I was sharing, along with that, we can make use of the application vulnerability features we have, like risk or risk rating assignment rules, combined with all of that, which helps you the security teams and the developers to prioritize, which vulnerabilities they want to be fixing first, not only that, the post and remediation steps can be automated based on the process that you follow, right? All that is feasible and possible on ServiceNow platform. And I'll just take a step back before I start deep diving into the data, I'm showing on my screen. So what are the benefits of using application vulnerability response module itself? You can find and prioritize the application vulnerabilities faster, and we can remediate the vulnerabilities and the visibility across the team. And we can automate the prioritization and risk management using the configurable risk or calculators and rules. And we can -- the response activity can be driven much, much, much faster and efficient with -- by development teams. And not but of the least, pinpoint development issues proactively. All this is possible just using the application of vulnerability features. Now -- now I'm going to show you the data you're seeing already. This is the data we have brought in from the integration. So the integration itself makes use of the OAuth authentication. And once you authenticate, there are import jobs in place when you run them, they put -- bringing the data into the platform. Of course, there's lot of promising that's happening, all of that is in place, and collating and making sure that there's no duplication. All of that is already in place. So once all that happens, the record gets created in application vulnerability item table, which is the application of vulnerable response. As you see the stores you're already seeing here as Snyk, so I'm going to deep dive into this data a little bit here now, and you see the risk of populated risk rating the state and the remediation target, if it's already was set. So let's take a look at 1 of the A-Bit. A-Bit is nothing, but a unique combination of vulnerability to endpoint. That's what and A-Bit is. But in application vulnerability, it's a vulnerability existing on a unique application release. So what is the benefit of this integration, right? The Snyk and ServiceNow integration. You will have an ability to bring the projects from Snyk, which you're seeing already here. I'll walk you through that also in a little bit into ServiceNow platform as application releases and [packages] and stand applications. And you'll have an ability to bring issue from Snyk into ServiceNow as vulnerabilities, application vulnerable items and packages, and you will have ability to link application release and scan applications using the well-known CI lookup pro that I've provided within the platform. And also additionally, based on how your operation operates, you can also add additional CI lookup pro if need be. And not -- and finally, everybody needs -- the organizations need the data visualization. So that's already in place, which is a very friendly dashboard, which the remediation teams can utilize really well. So as you see here, I'm going to highlight the application release and you see the package -- and as I said, A-Bit is a unique combination of a vulnerability, which is already a C here which the CV with that number on on a packet that was found in a Snyk platform. If you were to start a little bit on this record you would see something while a source link. Source Link is a drill-down link, which will take you back to the Snyk platform for this particular application vulnerability, if you were to -- were seeking additional context, so many times, what I've seen is the remediators in this case, its development team or the security team, if they were looking at this vulnerability if they need additional context, they have to log in back to Snyk platforms separately and then start looking for this particular application release and vulnerability. But here, we made it easy for you. Just this link will directly take you to the vulnerability found, where you can get additional count is that you're looking for. Along with that, it also shows you the vulnerability summary and the recommendation how as Marco was talking about Snyk desk provide recommendation on many of the vulnerabilities that are found already, how this can be remediated. So all of this data above and combined with the features of vulnerability response like calculating risk and risk codes, which will help developers prioritize vulnerabilities at a faster rate and the assignment rules you might be seeing here, so they are predefined assignment rule. It manages to assign to a specific assignment group based on the configuration that's already set in place, which is exposed to end user to do that. So along with all of that, you can also drive all these prioritization based on the CMDB that's already populated with the application release data. So in a nutshell, Snyk data in -- data along with ServiceNow application vulnerability response module helps developer and the security teams remediate the vulnerabilities at a much faster rate. With this Marco I'll stop sharing and get back to you.

Marco Morales

executive
#15

Thank you. At this time, I don't think we have any more slides to show, but we'll be happy to show screens if people have questions. I think there are a couple of questions. Wendy, do you have any guidance tuition we should address first?

Wendy Swank

executive
#16

Yes. So let's start with no particular order. I'm just going through ones that we got in the chat that were excellent, I think, for the whole audience to hear First one being, how do I find the app? Is it free or not? Marco, I can take this, but I did post the link in the Q&A section, our app is live in the ServiceNow store today. It is free to download, you will need certain entitlements on either the ServiceNow and Snyk side in order to leverage. But the app is in the store today, just head over to the store, you can type Snyk right into the main navigation search bar and go ahead and download that.

Marco Morales

executive
#17

Thank you, Wendy. I'll look at the first question. The Snyk UI provides almost all the details required for vulnerability remediation, what extra does ServiceNow offer? So 1 of the -- and Akhila, you can pick it up after I start. But 1 of the things we've learned in the numerous requests we've had of customers is the ServiceNow user population, application security, security-minded folks don't always have visibility onto the day-to-day life of a developer. There is friction. There's a desire of the security folks to say, Can I see -- can I understand, do I need to push a tool down on to -- there's all these questions around understanding how the developers are managing their issues. What we're doing is, we're encouraging developers to address vulnerability as much as I can and grant visibility into the ServiceNow population. Akhila, if you want to add anything, please go ahead. I wanted to keep it short on purpose.

Akhila Managoli

executive
#18

No. No, I think you covered it Marco. Thank you for that.

Aaron Bennett

executive
#19

The next -- we've got a few coming in. So let's hit all these questions and then. We'll see when they slowdown.

Marco Morales

executive
#20

Yes. If I understood the uniqueness, won't there be collisions on package names and CVs across groups or orgs with multiple package names or the same value? So I think, Wendy, I'm going to need your help here. This question does come up. So if the same vulnerability comes up again in the same package, I believe I'm right to say you don't get duplication. But if you have 2 different packages, 2 different software applications that have the same dependency, those things do show up separately as 2 different times. Wendy?

Wendy Swank

executive
#21

That is correct. You nailed it.

Marco Morales

executive
#22

Okay. Yes. How does this work with multiple groups? So there's a lot of language here and maybe the anonymous attendee can post a follow-up. So groups can mean a lot of things. ServiceNow has probably its own term, Snyk has its own team, your company may have its own term. And so maybe what I want to hear is a clarification because we -- if multiple groups I have 2 different development teams, or multiple groups means like 2 different groups in Snyk, -- please help me understand with a little bit of a clarification on that if -- so I can better answer what do you mean by how does this work with multiple groups, unless some of the people on the phone or to call have their own perspective. Why do we sign vulnerabilities to a group? Why not group them in a sign up in ServiceNow that we do for infrastructure vulnerabilities? Akhila, I'd like to lead with your answer first, and then I'll color commentary.

Akhila Managoli

executive
#23

Group. Why not group them in a sign in service now like to do? So the assignment group is very similar Sanjiv, it's -- assignment groups rules are the broader income on the configuration side, it works very similar to both infra and application vulnerability. So there's not much of a change. So I'm kind of confused with your question, if you were to answer. Are they grouping rule functionality? Yes, they are grouping to functionalities Yes.

Marco Morales

executive
#24

Okay. Snyk also collects dependency license information. Yes, that's right. Is that information pulled into the ServiceNow platform, I see Wendy Swank my counterpart is typing an answer. I'm waiting with bated breath Wendy, if you can type it in.

Wendy Swank

executive
#25

Yes. This current integration does not pull in the license data.

Marco Morales

executive
#26

Okay. I see it disappeared too. Are there group, if I -- how do we assess where it is ? -- so I'm looking at Sanjeev's 11:31 a.m. Eastern question, are there grouping rule functionalities for application vulnerabilities, Akhila? Is that yours?

Akhila Managoli

executive
#27

Which one?

Marco Morales

executive
#28

This would be the 1 at 11:31 my time, so it's from Sanjiv.

Wendy Swank

executive
#29

That's -- I mean I asked Sanjiv question, he reposted twice. I didn't answer twice.

Marco Morales

executive
#30

Okay. How real-time are the updated ServiceNow. So there is a scheduling component, right? The -- there's a -- I'm sorry, there is a batch operation. I don't know the timing. It can be triggered by human. What is the timing on this?

Wendy Swank

executive
#31

Just to add to that, the input jobs can be scheduled daily or based whatever a different frequency. But pretty much what I've seen is organizations schedule them daily. And of the daily import job they run, the data is refreshed from and it matches with the Snyk platform to ServiceNow now at that point.

Marco Morales

executive
#32

Okay. Is the 1132 the announce attending the multiple Snyk groups comment. Is that a clarification from 1 of the previous questions was that a new type of question?

Aaron Bennett

executive
#33

I also interpret that as multiple seed deployments possibly, but like differentiated environments where you might want to pull that information into ServiceNow to get -- right.

Marco Morales

executive
#34

So when we say multiple differentiated Snyk deployments, are we talking about -- so what are we talking about? Help me understand, Aaron.

Aaron Bennett

executive
#35

So say, company A has a Snyk deployment and then they acquire company B, now they have two.

Marco Morales

executive
#36

Yes. So that's something -- that's the host of the day type of question is depending on how those 2 organizations get consolidated within Snyk, at a very simple level, Snyk has a start with 2 primary structures. A group can have many organizations. Two different companies are likely to have 2 different groups. If we combine them if the 2 companies get acquired or merger or whatever, how those companies want to maintain their assets is going to be something that affects it. If you have 2 separate groups, you're not going to combine into the same ServiceNow environment is maybe the better one. They'll be in separate locations.

Wendy Swank

executive
#37

How is the go ahead. Let's say I see a good one. We might want to hit on is Snyk provides almost all the details required for vulnerability of remediation. What extra does ServiceNow offer? Obviously, a question for Akhila or Aaron?

Akhila Managoli

executive
#38

Yes, I can add to that. So just to take a step back, it's a great indication with our SCA results to bring in intact service now. But I'm just looking from an organization from a security perspective, they might be using multiple tools for multiple different application already scanning. So -- with this, you can have your SAST, TAST and SCA everything in 1 platform. That's 1 way to look at it, right? You can see all the data. I don't know if you recall, I was showing on my screen is that we do have a software which specifically shows which so the data is coming from. So based on that you can group your different scanning imports and then remediate them at once and have a global view of what's happening within your application vulnerability for the given organization. So along with that, from the remediation standpoint, -- you can always use the additional workforce built into the vulnerability platform itself that can be leveraged to move the remediation faster. Aaron, do you want to add anything here, additional that you can think of ?

Aaron Bennett

executive
#39

I think the other answer is sort of more global. It's having that data in ServiceNow, having the audit capabilities of ServiceNow layered on to the Snyk tool without causing any kind of conflict or friction with Snyk users. So we're not taking them out of their environment to submit issues or do anything. It's all transparent. So that's essentially the biggest boost that we get is that these groups can work together without any visible conflict or friction between the 2 tools. They just continue the regular operations.

Marco Morales

executive
#40

Are we at the question from Saurabh, what do I need to have in CMDB for CI rules? I think that's your question to work efficiently and not end up with unmatched CIs?

Wendy Swank

executive
#41

It's a great question, Saurabh. And that's an ongoing struggle for all the organizations, right? So coming back to CMDB, we need to have the robust CMDB to start with for the CLO approves to work. That said, that's the first step. How can we measure the health of the CMDB. I know Aaron can really -- added more here he would be working on this different CMDB connectors them himself. But that's an ongoing problem and the solution for -- it's an ongoing work, I would say, right? -- how do I keep the health check on for CMDB and that way, I can make use of the CLO -- better so that it would end up in the unmatched CI. The short answer is to have a good CMDB populated before you start. But as I said, realistically, we have seen that it's not a easy -- it's very easier said than done. So it's a bit of lot of work there to have a good CMDB.

Marco Morales

executive
#42

Okay. After Saurabh, we had a question at my 1136 from an anonymous person. Snyk UI provides almost all the deals. We did answer that question live. And the -- and maybe we'll have to back up the video next time to answer it, but I want to keep moving with the questions. Is there any triaging functionality built on the ServiceNow side? For example, marking a finding as a false positive with the ability to ignore vulnerability, finding it so it doesn't show up as a risk anymore. I'll start the answer. I think the answer is no. We don't have that ability to trigger or change the state of issues in Snyk from ServiceNow, but please, other people please answer.

Akhila Managoli

executive
#43

No, you're right. The current available features for application vulnerabilities are either you can close or resolve. So that -- those function is available for Infra, but not for the application yet.

Aaron Bennett

executive
#44

Yes. That's more of a function of the nature of the object because obviously, if you've got a different version of an open-source repository that becomes a different entity. So you replace an object like that. You don't actually like patch the open source object. So it's a bit of a different mentality from an in typical infrastructure approach. Similarly to container vulnerabilities, we don't actually update the container. We replace it with the different container. Let's make sure we're not marking these questions off as we go, we don't miss any. So I saw that there was -- like were we on triaging functionality? If I'm going down the list of questions. I have a few more. I want to make sure that we hit the automation closure obviously, like those details are picked up. So a lot of the work in service on the going back to the question about what the extra value is. The extra value is that the developer does not have to design a superior workflow around their developer activities. They don't have to manage it. Obviously the security team is more especially focused on those sorts of workflows. And so that's what ServiceNow provides, such as like deferral process in vulnerability response.

Marco Morales

executive
#45

I think what I've seen before is people write effectively to some type of script to automate the importation. So we've done all that work for you and the reconciliation. So this is a few things you don't have to worry about anymore that we're doing so that it is done more automatically.

Aaron Bennett

executive
#46

Automating reporting visibility, rolling risk up to the greater organization that you have security results from your infrastructure, employment, your production and your coding development. Those sorts of things that would be just a headache for the developer becomes something that the security organization can do in ServiceNow. So we're going to go into triage, is there any triaging functionality built in ServiceNow side? For example, marketing finance false positive or -- ? Want to take that Akhila?

Akhila Managoli

executive
#47

I think we just answered that one.

Marco Morales

executive
#48

And the last 1 is Snyk in ITSM integration makes sense, but I'm not sure about the Snyk and VR integration. I'd like to lead with the ServiceNow team.

Wendy Swank

executive
#49

Yes I think, It's an interesting observation. ITSM, you would just have the data there. And I'm not talking about, you don't have the ability to integrate with disabilities work flow, first of all, to start with, right? It doesn't have the remediation, it didn't have the assignment rules or the risk co-risk-rating prioritization. All of that is not feasible within ITSM integration.

Aaron Bennett

executive
#50

I'll say Akhila, it's possible that it makes sense to have ITSM integration. But then you're talking about a different -- you're talking about a different objective. So if you're talking about fixing something in run time. like, say, a service outage or something like that. Then yes, obviously, we want to do that. We want to make sure that we're getting the right data from Snyk and correlating it to the right type of incident for service operations or something like that. Whereas in this case, we're strictly looking at risks created from security vulnerabilities that are ongoing, and possible or accepted risk that we have to take into production. And how do we mitigate that risk. This is -- that's sort of more of the approach of this impression. So that's a good question.

Akhila Managoli

executive
#51

For the use case we're discussing here, it fits well into the VR integration.

Wendy Swank

executive
#52

Getting a sense of the questions, Aaron and Akhila and Marco, folks on the line, and I think in general, a good observation is that a lot of people are used to the traditional infrastructure scanners, which this is not, I think it might be worth a minute of explanation of the traditional, like the calls, rapid7, those scanners.

Aaron Bennett

executive
#53

Wendy, while we talk about this, I wanted to launch the poll because it looks like there's some interest. I don't want to keep people on -- after the -- point of time if they need to break to the next meeting. So especially if you'd like some further answers on these questions, I would encourage you to answer your guests for this poll and we'll reach out and make sure we inquire for anyone. So I'll leave this open more --.

Wendy Swank

executive
#54

Thanks, Aaron. I think just a moment of explaining how this is different than the traditional or classic infrastructure scanner might help the audience as well. Marco and Akhila, if you guys want to take that.

Aaron Bennett

executive
#55

Akhila, do you want to go first? So I mean, I guess we can start with the infrastructure being the way we understand infrastructure is scanning a lot of environment. It's focused primarily on running runtime, hardware computer servers virtual infrastructure in a location and this is early cloud. That's a different thing oftentimes. Akhila, do you want to go in to how this source code analysis takes us forward in the head of that type of world?

Akhila Managoli

executive
#56

Yes, yes. So within attack service management . I think I spoke a little bit in the beginning of -- within the stock. So that it's huge, right? The attack service management is really huge, and it can be divided into multiple different areas. Infra is one area, application already is another area, and then we can get into more details of the sbombs and the API security. So that's the next up. You can start looking into expand your attack service management and get a view of that. So within Infra, you can have the infrastructure owned by the organization, which are not talking about servers, flat top end point, all of that. And it could be a cloud environment and then you can think of your coming to the cloud and containerization containers. And then within application, you can think of your -- how you can get the static security findings and the dynamic security findings and then the SCA. So there are various components of the vulnerabilities itself. So bringing all that into of 1 place and then having a unified view. I think that really helps the organizations get a bigger picture of where my organization is in terms of vulnerabilities in short.

Aaron Bennett

executive
#57

Great. Let's keep answering these questions as long as people would like to stick around. So we'll stay obviously until the top of the hour if you'd like to. -- pleased if you're -- if you have -- if theres somewhere you need to be or need a break before your next call today, answer your guess to my question so that we can follow up with any other items of interest. But let's go on to Aneels question. I understood correctly Snyk scan application repo. So about vulnerabilities in application servers used to run these applications? So I guess we want to split this -- describe this scanning approach question.

Marco Morales

executive
#58

So the way I read this question is, we do scan code repositories for sure. The -- and that is all in discussion or like I know the purpose of this webinar is to focus on Snyk open source within ServiceNow. But yes, the answer is yes, we do scan. And we do have Snyk cloud for running infrastructure I'd like to defer that conversation to a different angle and stay focus on the ServiceNow.

Aaron Bennett

executive
#59

Be out of the scope of this integration. It's possible that, that could be covered by another existing infrastructure. I think are standing right time with an infrastructure scanner. But if that's in -- say the cloud or if that's a container, it's possible that you've got coverage gap their immigration. I don't know, Akhila, you have any thoughts on that.

Akhila Managoli

executive
#60

No, I think I was looking at Sanjiv's another question here. -- sorry that's the 1 you were saying.

Aaron Bennett

executive
#61

If you want to answer Sanjiv's -- first.

Akhila Managoli

executive
#62

Yes, what Sanjiv says, what I noticed is -- is you assigned a vulnerable item to a group and not a vulnerable task, which we do in infra? Again, Sanjiv, Infra, the put is slightly different, given the number of vulnerabilities that you find, it's in millions. So -- and just addressing through vulnerable item is a nightmare for the remediation team. So what the feature that's introduced there is you group them as based on the assignment groups. So which is called as remediation task not vulnerable task in the latest version. So the remediation task is what the remediators will be looking at, but each remediation task contains multiple vulnerable items within that. But coming to application vulnerability First of all, the numbering is not that huge, and it's definitely doable and maintainable within the vulnerable item itself and the grouping intermediation is slightly different when it comes to application vulnerabilities. And hence, the assignments blue pros are worked on the vulnerable item itself.

Aaron Bennett

executive
#63

Yes. And it would probably be interesting to think about what the grouping margin would be because you've got people working on projects and like their projects would be potentially installed on thousands of containers or hundreds of machines or how we look at it. But -- it's a bit of a different approach because of where we are in the cycle deployment.

Akhila Managoli

executive
#64

Yes. In fact, I was thinking it can always go back to the application release -- can tie to that and tied to the, which is in the CMDB. And that way, you can map rundown with multiple mapping within that drilled out who is the owner of that, who is working on that uptick and things like that, that can be leveraged here.

Aaron Bennett

executive
#65

And that's what ServiceNow do as well as to build those reports based on release and start to get a picture of the performance in development. I'll turn to the next one. So Snyk has an integration with JIRA a ServiceNow a better alternative as well. I would say our default answer would be, of course, I don't know, Akhila, do you want to add any color to that?

Akhila Managoli

executive
#66

Personally, I have not seen that integration, so I can't comment with the JIRA integration, but going back to what I've been seeing, this the ServiceNow vulnerability response and application vulnerability response will definitely give you a much more unified view of -- if you're looking from a ratio perspective, any type of application vulnerability you have you can bring in and have 1 unified fume?

Marco Morales

executive
#67

One thing I'll add is for the JIRA integration. We see them as different solutions. JIRA is for 1 type of population. And the ServiceNow people, Akhila please correct me when I'm wrong, we see Jira as a developer-friendly, Hey, I want to manage my day-to-day code things on ServiceNow. I mean because it has a wide breadth of solutions and products. I mean they've solved a lot of other problems that are not addressable they say by JIRA. So I would say ServiceNow is the best alternative for all the problems that ServiceNow is addressing. And I'll leave it at that.

Aaron Bennett

executive
#68

Yes, it might be -- just to expand it a little bit, the JIRA might be more focused on, say, issue management, like talking about assigning market numbers-- whereas this, we're looking at a security overview of the issues that are coming into coming in through the curve when you're at process. We do have a product called strategic portfolio management that is a little bit more similar. So because this integration is not with that solution, it's probably a little bit of apples and oranges.

Wendy Swank

executive
#69

I see another question here. What are the difference between Snyk and other scanner selectable? Please tell us the benefits why we should consider Snyk in addition to Tenable which we currently. I think when you did touch upon the infra vulnerability scanners like Tenable-- qualities and others in the industry, -- so Tenable definitely is on -- it can be leveraged for IT OT on that side of the vulnerability scanning. But as Snyk is developer first platform, Wendy, Marco please again add more to that. And then with this integration, we can find a software completion analysis, specifically into ServiceNow.

Aaron Bennett

executive
#70

Just want to comment on the Snyk sort of edge when it comes to their approach Marco and Wendy?

Marco Morales

executive
#71

I'll start by saying they are different type of solutions. Snyk has this scan code container perspective, Tenable as a different one. I'm not at liberty to say like the different distinctions. But in general, we see more complementary than competitive.

Aaron Bennett

executive
#72

That's a good way to answering that question.

Marco Morales

executive
#73

And so the -- I'm sorry, I want to add just like another 30 seconds. So like -- so we've used different metaphors described like security is not just 1 thing. There's usually a lot of things and there's different models, the 7-layer or whatever the sphere model. If I use a simple example, I would say, like if you were to go outside and it's very, very cold, you would want warm boots, warm pants, warm jackets, mittens, gloves and so on. Each of these solutions is their own thing. Maybe we can be greedy and say, Snyk is a fantastic jacket, but someone else may be the fantastic mittens. And it's something that we would want you to just understand it. Like we see Tenable as something that is not really overlapping with our solution. So dress warmly, especially on Super Bowl Sunday.

Wendy Swank

executive
#74

Another point, different end users as well. So a tenable end user is going to be different than a Snyk end user. We're scanning different things.

Akhila Managoli

executive
#75

Needs. All the vulerabilities scanning themselves.

Aaron Bennett

executive
#76

Well, thanks, everyone, for the lively Q&A. I really appreciate it. We do a few more minutes. If anyone would like to ask another quick question. We will, at this time, end the poll and we will get out those results, and we'll make sure to follow up with anyone we did indicate in the affirmative that they'd like to be contacted for more questions. I think call the action for everyone who is still on the call today, please go to the store and check out with Snyk integration store.servicenow.com search for SNYK. Also, if you search for Snyk and ServiceNow, there's a couple of great -- there's an appearance in the journal with that announcement with our own CIO perspective, we made some comments on the Snyk integration. It's gotten some really great attention just because of the relationship and obviously, the exciting technology innovations that are going. So I wanted to thank everyone for your interest and for attending today. Marcos, Wendy I'll with you for any other closing comments you'd like to add?

Marco Morales

executive
#77

There's 1 more question on there. Why is Snyk given more focused over the open source and continue it, but not with Snyk code? I mean if you're talking within the context of the ServiceNow integration, this first version of the app is primarily focused on the open source. We don't want to convey that the other products are not important, but this integration is about Snyk open source.

Aaron Bennett

executive
#78

Again, like if you want to I don't know if you indicated it should like to be following up with. But if you'd like to -- I think when you Wendy and Marco -- e-mail before?

Marco Morales

executive
#79

I did not.

Aaron Bennett

executive
#80

All right. Let's Well, anyways, leave a comment on the webinar page. I don't know Wendy if you can want to put your email address on video.

Wendy Swank

executive
#81

Yes, sure thing. It's just wendy@snyk.io pretty easy.

Aaron Bennett

executive
#82

If you have any questions about the road map. Wendy is the person to ask. So obviously, if there's interest in this, we'd like to know. -- and continue to iterate on this solution. But we encourage you to first go and check out what we do have. We really think it addresses an important question for most organizations. All right. Okay. Well, I think we'll give folks 30 more seconds for other question. Again, on behalf of Marco, Akhila, Wendy, Thanks. We thank you all for attending today. This was a great session. Make sure if you miss any part of it, because you had to catch a call or anything, there will be a recording on the ServiceNow community. And we encourage you to check that out, check out the integration, check out the blogs and the other articles that have been put out recently, and we look forward to coming back and presenting on the next segment. Thanks, everyone.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete ServiceNow, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to ServiceNow, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.