ServiceNow, Inc. (NOW) Earnings Call Transcript & Summary

October 3, 2023

New York Stock Exchange US Information Technology Software special 55 min

Earnings Call Speaker Segments

Operator

operator
#1

Welcome, and thank you for joining us for today's event. [Operator Instructions] Now let's get started.

Jon Williams

executive
#2

All right. Thank you, everybody, for joining us this morning for our webinar Drive cyber resilience with enterprise case management. My name is Jon Williams. I'm a Senior Product Marketing Manager here at ServiceNow, and I work in the Security Operations business unit. And today, I am joined by Karl Klaessig, Karl?

Karl Klaessig

executive
#3

Everyone. I'm Karl Klaessig. As Jon mentioned, I lead product marketing for ServiceNow, focusing on our security operations solutions. So security instant response and vulnerability response.

Jon Williams

executive
#4

All right. So for our agenda today, we're going to be covering the threat landscape. We're going to go through how we can learn enterprise case management can help us to triage and prioritize expedite investigations, response and remediation and then how we can respond to threats centralized operations and accelerate our response to those threats. And then lastly, analyze, report and mature and how we can scale our team capacity and increase our expertise -- and then we're going to go into a customer story. So you can see how that's worked real world for one of our customers. And then lastly, we're going to be covering a Q&A. Right now, I'm going to be showing us an overview video that was provided to us by Karl Klaessig. So here we go.

Karl Klaessig

executive
#5

Welcome, everyone. I'm Karl Klaessig, Director of Product Marketing here at ServiceNow. I focus on our security operation solutions. So really excited to talk to you about enterprise case management today. With all of the challenges we face in our enterprises today with doing more with less, so being able to make sure that we meet the obligations and the opportunities for business growth as well as maintain our costs. enterprise case management is a way we could do that, help you ensure you can do that securely. So some of the big areas that we can really focus on and make you realize is that there is so much we can do that we can help with our automated workflows. So many times, your teams are working across multiple business units in the enterprise, we can actually automate those workloads, make them more efficient, make them scalable, they've been able to be redundant and able to be replaced and expanded on a regular basis because we all know the volume of threats is growing exponentially. So as we speak with many of our customers, they often drive to realize the efficiencies. And so many times, we hear our customers mention numbers around 10x and 50 and 60 times their capabilities for scaling to meet some of those vulnerabilities and threats. And oftentimes, those efficiencies would enable them to be resilient. And that's what we help them do. When we think of the risks and threats out there being resilient to those yet still looking out for the growth of the business and the efficiencies of the business, that's what enterprise case management can do. Thank you, Karl. So anyway, that was an into design to kind of give you a taste for what we try and do as an enterprise case management approach to addressing today's threats, right? And we're going to spend a few minutes now before we get into that deeper is why are we meeting? Why are we having this conversation. We all know there are plenty of reasons. And these are just some recent highlights to pull out from some [indiscernible] and some other data breach reports. And they're ridiculously compelling, right? And we all know that every year, when we look at this, we run across it more and more, and it comes from everwhere. And obviously, as we increase cloud as we increase our development capabilities on the fly, all of these different things. We're that much more vulnerable, so to speak, and that much more able to potentially be breached, right? So as I mentioned in the video, we run that gamut of how much is too much and how do we keep things secure yet making sure we're investing in the right technologies for our customers and our organizations to continue to meet that level of support, that level of growth, et cetera. So -- and this, again, creates an opportunity for a threat. So that's the double-edged sword that we all walk through every day. So that's the point of kind of sharing some of this with you. And at the end of the day, we always used to -- I've been started out in the log management days when essentially it was a black box in the corner where it was a silo. And that's wherever all your security data got dumped into. And Lord knows, you had very little that you could pull out of it. So it's amazing what we can do today. But it's an example of the fact that silos don't work, right? Because obviously, threats will try to get in and bad actors try to get in every area of your organization or enterprise that they can. So with security in mind, you can't address it from a silo. It's not possible anymore. You have to be prepared to collaborate across those teams in view throughout the enterprise. So that's just a real focused reminder. We see more and more as we talk with our customers, that, that collaboration is a key driver for them. That's what's enabling them to stay ahead of what are some very complex and in-depth threats that really will go ahead and try and permeate anywhere they can. And that ability to be nimble and work with the other teams and make sure that not only are we responding but we're also learning from that and being able to go ahead and address policies and et cetera. That's all what makes the difference. So again, threats don't care about business silos a strong statement in this day and age. What we're going to focus on, like I mentioned, is with our security workflows with ServiceNow security operations, we focus on 2 areas of incidents and vulnerabilities. We're going to focus a lot today on the incident area, which is our security incident response solution. That's what you'll hear Jon and I talk about focusing on what do we do with enterprise case management that can really help drive that cyber resilience. So a reminder here is just looking -- when we look at everything that goes on, it was giving you that those bucket items of all the activity and all the data and all the workflows and all the automation and the learning that goes on, that is driven by these buckets of activity, so detection, correlation, vulnerabilities. Our threat intelligence that's so critical across the board for us to understand for prioritization and assess the potential impacts, right? The solutions intelligence that gives us actually an understanding and an assessment of what the exploits can be. And then ultimately, one of the most important aspects of this discussion and of this flow of activity is orchestration. So being able to take all that, understand where you need to focus your team's efforts, who needs to be involved across the enterprise and how to orchestrate that response before it impacts your organization. So this just is to kind of set a baseline of the different activities that we'll touch on today. And when we look at that learn how enterprise case management can help, that's what Jon is going to talk to you about now. We're going to walk through triage and prioritize the response to threats to analyze, report and mature. And in essence, that triage and prioritize, that goes back to that visibility. Let's make sure we have visibility to everything we need to. That respond to threats means that we know the different folks that we need to tie in across the organization to do an effective response, a complete response. And then when it comes to the analyze and reporting, it's not just the ability to go ahead and say, okay, how did we do, it's being able to understand how we can improve. Gee, what things are working incredibly well, we're going to keep that going. These are areas we need to work on. We need training, we need tools, we need to collaborate with other teams a bit better, whatever it may be. So Jon, I'm going to turn you loose on going through the polling question now.

Jon Williams

executive
#6

Yes. So kind of keeping what Karl just talked about in mind, we have a poll question here, we'd like you to answer just to kind of get a feel of the audience and what's top of mind for you. And so that is what is your key area of focus. So we have the triage and prioritize. We have our response to threats and we have our analyze, report and mature. And we also have all 3. So if you want to just take a minute here and select that -- so we could just kind of get a feel of what everybody is thinking about and what areas are really a focus for you or maybe for your organization. We'll give you a minute here to respond to that. And then while you're doing that, I just want to remind everybody that there is Q&A. So if you have any questions throughout, make sure that you're typing those into the Q&A box so that we can make sure we get to those here at the end. And then also, we have on-demand webinars, which will provide a slide here at the end of the webinar. So make sure you're looking at those. They're a great resource. We also have our community, which you can join. There's a lot of good stuff out there, a lot of good content that we provide, so make sure that you're looking at that.

Karl Klaessig

executive
#7

And adding to that, Jon has recently done 1 on the reporting aspect, you heard me touch on it, and we'll talk some more about that later, but I encourage you to visit that. That's an excellent insights into the value of that. Okay. How are we looking at our poll, Jon.

Jon Williams

executive
#8

We're about 50% responded. Give it a couple more seconds, and then we're just going to go ahead and move forward. All right. So looking at the responses, it looks like that's good. All 3 is probably right up there, which ideally it should be, right? And that's good because as we're going to talk through this webinar especially with the solutions that we provide, we can really touch on all 3 of those. And so you'll see that as we go through this. But that's good to know that, that is the priority for most. So I need to go ahead -- yes, thank you. So now I'm going to jump into our triage and prioritize. So expediting investigation response and remediation. And so -- in order to do that, we first have to ingest the data that we want or that we need. And in order to do that, we have -- we provide many different methods to do that because data injection, obviously, unless it's in the platform, we can't do anything with it. And so within ServiceNow, we provide a number of different methods for doing that. We have our e-mail and e-mail parsing, which -- and then we have our user reported phishing. And that's one of the, I would say, one of the more basic ways of getting it in. but it can be configured and customized. We have event management through events and alerts. So connecting with one of your other platforms or third-party tools to bring those events in. And then we have our API through rest and so where you can actually connect and bring those in through API. And that's actually -- we provide a tool to help you configure that which is really nice, really good automated way of doing it and configuring the data specifically from the third party that you want to bring in. And then lastly, we have our log data. So all of those are great ways to ingest the data. But then once we get the data in, we need to start looking at it, right? And so now that's when we get to knowing when our threats are going to change and new threats occur. So we have all this data, we need to actually get visibility into it, right? We need to know how that is affecting us, how it's affecting our business, and how that's affecting our businesses risk and resilience. And so in order to do that, we need to be able to continuously monitor that. And so through that, we need to gain visibility into our threat exposure. We need to identify the security changes in real time, and we need to be able to accurately assess that business impact, right? We need to be able to tell not only that this is a threat but we need to be able to identify exactly how it's affecting our business because that's going to help us with our next step, which is prioritize. And get us to the point where we're addressing the most critical needs first and the most critical threats first. And so next, we have our know which incidents are most critical. Again, so now we have the data in. We've identified which is most affecting our business or our assets. And now we need to know which ones are most critical because we need to prioritize those, right? We need to make sure that our most likely low manning is actually addressing the highest priority first. And so to do that, we need that business context and incident severity, which is going to help us to accelerate that prioritization, right? And so this is all done automated through the system, through the platform, we can help you by automating that process so that your analysts can know what are most critical right off the bat. They don't have to go through and rack and sack these manually. And so that -- we do that by aligning the right data, prioritizing business criticality and then we can identify stakeholders early, which is also very important when we talk later on about major security incidents. And then lastly, focus on the incidents that matter most. Again, most critical first, making sure we're getting rid of those threats that are most costly to the organization. And by doing that, we can reduce incident triage time by 50% and investigation times by 40%, which is huge -- which is very huge for, again, teams that are probably very [ low manned ].

Karl Klaessig

executive
#9

Thank you, Jon. So when you look at that, what Jon went through was basically getting that data in there, right, and making sure that we have the right insights to be able to prioritize and to be able to what we'll see pulling the threat across is respond accurately as well and respond appropriately. That's everything that will go on. It's interesting when you look at threat intelligence and other reference points, they really play a part across the whole process. They help understand where we need to prioritize. They will help also understand how to respond and what to orchestrate and who to pull in. So you'll see us touch on that with Mitre and other things, as Jon and I are talking and those are really areas that are interestingly enough that will thread all the way across. So let's dive in a bit with the response. So one of the things, of course, are your libraries. We have a very healthy playbook library. And the idea behind them, of course, is scalable repeatable actions. We actually build them off a library of actions. And that actions library essentially enables you to go ahead and build out playbooks according to your needs. Any of the ones that we have are very configurable, customizable, et cetera, as you would expect. And you can easily use that playbook of actions, so to speak, that actions library to go ahead and be able to build out playbooks for your particular needs. That really gives not just the flexibility and customization of course, that we're all looking for in playbooks, but the ability to have some of those typical actions that you would anticipate doing right in the library and ready for you to drop in. So that's a real asset, particularly when you're trying to make the most use of some of the different levels in your team and being able to drive some of that automation that Jon has been hinting at and that we touched on earlier. So -- and again, all of this is right out of the box. This is part of it, you can pull it in and get going and make use of those -- that actions library [ away ] and build out the appropriate playbooks or customize the ones that we have there for you. So again, great opportunities to start to build out for that response. Now I mentioned threat intelligence and MITRE ATT&CK a minute ago. And one of the ways that I always like to think about MITRE ATT&CK -- it's such an excellent tool for all of us. And we've done a real excellent job on focusing with our -- collaborating with our own customers on how do we get the most out of MITRE ATT&CK and some real depth integrations went in there. And the reality is that it's almost like playing the game of chess. In other words, if I knew exactly what my opponent was going to do next and what their typical response will be given in the game, heck, I could win every game, right? And that's the opportunity we have with MITRE is being able to have those insights to know what are the typical tactics and techniques and then be able to go ahead and respond appropriately according to those tactics and techniques. So it's a real boom and a real asset to go ahead and make sure that you can address that type of approach and have those type of insights to make the most of your teams and to be able to make sure that you're doing the right responses. And -- all of that, of course, is very critical, as you heard Jon and I both mentioned here a couple of times on being able to collaborate. Well, collaborating across the teams and dropping those silos never as easy as it sounds. We know that, right? We understand that. And we've really worked hard to make that almost seamless for our customers with our major security incident management. So it's a capability within the solution within security, it's a response that enables you to go ahead and set up for such as a major incident such as like we might have with ransomware and et cetera, where you can go ahead and assign different folks that should be involved. And in many cases, that can be everyone from someone in legal to HR to IT to risk, et cetera. You can actually pull all those folks in to be able to coordinate the response and manage this incident and be able to have those collaboration workflows built in. So Microsoft Teams, you can go ahead and put in Microsoft SharePoint and make sure you have all your evidence management. You can go ahead then and check on the task. Anyone in those can go ahead and go in and be able to see what the status of the incident is, those involved. Go ahead and check on their task. Have I completed it? Where are at with this? Do we need to go ahead and expedite this because this needs to be done now, all kinds of opportunities in there to go ahead and culminate into a very strong response that represents the different teams that should be involved to effectively respond. So that's where major security against [ event ] management plays a strong role for us. So very exciting for many of our teams. And I'll tell you, I've even seen a customer use it proactively and let me clarify it. They've actually templed it out a major security incident management incident and are ready to just put in the appropriate data and link the appropriate people at any time, plus the ones they already have working. So it's that type of thing that you can actually set up to go ahead and be ready to go. And again, we all know in this day and age, the more of that we can do, the less impacts the organization we're going to have from any type of threat. So Jon, you know what a big thing it is with our reporting and our analysis and our performance analytics. Like I mentioned, Jon did a great job if you want to see more of this in depth, but Jon dive in, looking forward to having you go through this.

Jon Williams

executive
#10

Yes. So -- I mean, as soon as we've responded to our incidents, right, it's -- the job is not over, and that's where our reporting comes in. I think this is -- it kind of gets pushed to the side a lot for people and reporting is such a critical piece to this, right? Not just to know where we are and how we've done, but how we can continually improve as the slide says, we need to take these processes that we've done over and over again, we need to learn from them because even the best response can always be improved. And so by doing that, you can really -- you can improve your business processes, your teams across the board. And so that's going to really increase your quality, your productivity and your response time. And so tracking these critical process metrics and trends through our advanced reporting, so performance analytics, you can help identify process patterns, these bottlenecks. So maybe there's a point in your response that maybe could just be tuned a little bit to help increase that time to response. But then also looking at not just where you've been and where you are or where you're going, right? It's all very important. And using reporting, we can do all of that. And it's really critical that -- as soon as the incident is done, you go back and you assess and you huddle and you look at how you can improve that. So next, we have our security operations efficiency dashboard, and that's really going to be what I was just talking about, which is in improving that efficiency across the board. And so this is specific to our stock. And this is where we're going to really be able to dial in by analysts so we can actually look at analyst efficiency. We can look at team efficiency. We can actually tell you how efficient a workflow is working. So maybe you actually need to go back even further, maybe it's not the analyst, maybe it's the process that's been giving to them through the response workflow you're even further back your incident risk analysis. Maybe during that prioritized stage, you need to configure something else or change something else there. this dashboard here is going to -- and these reports are going to give you all of that so that you can make those changes to improve across the board. And it's -- again, it's really important. This is a really key tool for stock managers and even higher up than that to really look at where things are going well and then where things could be improved and not only where they could be improved, but how they can be improved which is really key for saving time for managers and yes, for managers. So.

Karl Klaessig

executive
#11

And Jon, that's a really good point because I was talking with the customer a couple of months ago. And one of the things they mentioned is they actually use that to help them understand where they might need to increase their training and focus training in certain areas based on where their team can struggle, et cetera. So I mean that was a huge boom for them to understand where they need to expand their team at times based on the expertise they have and what they were facing. So great call out, Jon.

Jon Williams

executive
#12

Yes, absolutely. No. It can -- I mean, you can reprioritize team members, your area of focus, right? Just again, from beginning to end, it's not just any -- a single part in the process these metrics can really help you dial in the entire process. So it's just key to focus on those afterwards, learn from what you've done. And so this last one that we have here is our executive level insights. So this is the CISO dashboard. This is going to be something really important for the CISO or other key executives to help them understand where you are as a business where your security is and how effective it is. And this is something that you can provide as that SOC leadership to those higher level executives. And this dashboard does not just cover security incident response. It actually covers security incident, vulnerability, your compliance and your business risk information. So it's the whole gambit here. And so this dashboard, I've actually heard customers and partly why it was created, they will actually require a monthly or biweekly what have you report. And this is a simple -- you can even print this off and give it to those higher leadership and just let them know the status of your security program. And so yes, very, very important to look at. But it's a holistic view of your security posture in your security teams. So Sorry, Karl, are you going to say something there.

Karl Klaessig

executive
#13

No, that was well said. You summarized that well because it's just such a great tool for C-level period, like you're mentioning our -- the CEO -- CIO loves to see some of that. Your risk folks can actually get insights there. It's a great summary tool for all of them to understand in a quick glance what the status is of the security posture that you mentioned, Jon. So.

Jon Williams

executive
#14

Yes. Absolutely. All right. So just to kind of rehash the enterprise case management. So ServiceNow, what we provide with security incident response is going to help you respond to those threats from beginning to end, right? So managing your exposure visibility into your high-impact threats right, ensuring your cyber resilience so that when you're going back and you're looking at how you responded and how your processes ran, how you can continually improve that. and doing that through real-time views into your security posture. And that's going to help you continually grow as a team and continually grow your security program so that you can constantly move with the threat actors because as Karl mentioned, they're continually changing their tactics. And so it's important for security teams and security programs to do that as well and learn as you go and then drive efficiencies and accelerate your reaction time, right? So everything with security is all about efficiency. We're all running very small teams, usually. It's a very undermanned sorry, underpersoned field and so we have to work with what we have, and it's really important to drive efficiency so that we can do more with less. And that's what this is really going to help us with by...

Karl Klaessig

executive
#15

It's a good call, Jon, because when we look at this, they're -- thematically here that capacity to automate those workflows and some of the actions and thinking about the actions library, that was shared with folks earlier with playbooks, all of that allows them to scale the teams they have, right, to be able to do more and act faster and act more effectively, which drives efficiency. So that's one of the things we see when we talk to our customers, they get 2x and 3x and 4x efficiency by immediately getting some of those workflows. So you think back to the comments you were going to earlier, Jon with a 50% reduction in response time, et cetera. Those are the type of things that really drive efficiencies and results in them doing more than our team ever thought possible.

Jon Williams

executive
#16

Yes, absolutely. It's incredible. As you -- I think we build these workflows a lot of times, and we build these processes, and we think that they're probably as good as they're going to get. But as we -- as you deal with, real-world incidents. I can't say -- I can't speak this morning. You actually find places where you can add that automation in. And honestly, when you're responding to some of these incidents such as ransomware, like you were talking earlier, seconds mean everything. And so if you can automate just even the simplest of processes that maybe you just overlooked when you were building out your process, it can really be a huge time saver not just -- not just for the team but for the company, for the organization, and it all has cost benefit in the end. And so that's what you're seeing here. A lot of metrics on how you can improve and how much you can improve and what we've seen from customers using this from beginning to end. Again, it's not a singular focus, and we even talk about vulnerabilities in here as well and seeing what the risk side. So this can be done across the board. And Yes, I think it's important to really look at your processes and see where you can improve those and where you can add the automation and where you can cut down that time?

Karl Klaessig

executive
#17

Yes, Jon, and that was a good summary for outcomes, right? Because at the end of the day, that's really what it's driving around is that cost, that response, et cetera. all of that is so critical. And we're hitting every one of those marks by being able to do the simplest of things like you're describing, which is just automate some of the mundane tasks that can vary by timelines, right? So don't get me wrong, the level of complexity that you can automate is tremendous and really help simplify the complexity that you often face by automating those workflows. But it all starts with that commitment to moving some of those mundane tasks right out of the gate. So a lot of our customers immediately comment on this. Geez. I pulled this out of this poor team of 2 that were normally [indiscernible] for hours on repulling this and requesting that and suddenly was done in 5 minutes. So that's the other thing we love to hear as far as our customer success.

Jon Williams

executive
#18

Yes. And like you said earlier, it is a chess match, right? We use tools like MITRE ATT&CK to try and tell and predict how a threat actor might be moving. I can tell you firsthand from sitting in a socket, threat actors are doing the same, right? We create threat actor profiles. They know exactly -- what we're going through today, all these pain points that we see in SOCs and security teams. I promise you threat actors, they know. They know and they take advantage of it. So it's important that you can reduce those pain points, you can reduce those bottlenecks, those areas of inefficiency because that's where those threat actors are going to take advantage of. They know just as much as we know about them. And so it's a continual chess match. You just have to try and stay one step ahead of them. And using products like this -- and really, the whole security operations, you can really help benefit by doing that. And so we actually have a customer story example that we'll jump into here. This was a global financial services corporation and they actually use this solution, their challenge probably same as a lot of people, a lot of organizations. They need to establish processes and work flows to both train teams as well as mature skills, right? Overall goal of -- sorry, that arrows in the way -- teams and expand capacity, it's in the way. But their solution to that was ServiceNow Security Incident response, right, and how it delivers the automation and centralized performance dashboarding. So by providing those tools, they were able to meet that challenge and overcome it. And in doing so, they reduced their time to train new analysts by 50%, which is huge. I mean most analysts, I don't know the exact numbers nowadays, but I know it used to be about 6 months for a very basic level SOC analyst. So reducing that by 50% is massive, especially when -- again, we're talking about teams that are lacking in manning, right? The quicker we can get somebody up to speed, it's just a huge benefit overall. And the faster that they can become more seasoned analysts. But then also a 70% reduction in time to close security incidents over 6 months, which is, again, that's massive. I mean I think I would say anything over 30% would be great, but 70% is huge. That is -- again, that is using automation and really tapping into making your processes more efficient. That's how you're going to gain that time to close.

Karl Klaessig

executive
#19

And this is a customer that continues to evolve. I mean, they embraced enterprise case management experience in response with addressing a couple of key items in front of them, right, which is how do I scale my teams. And how do we go ahead and take care of some of -- like I mentioned, MITRE ATT&CK earlier, the threat intelligence or how do we get that in there and make the most use of it. They recognize some of those key things right out of the gate and they continue to evolve. I mean now they're at the level of workflows that this customer does is tremendous and what they're capable of doing with very complex responses like major security incidents is really a poster child. It's very impressive. But ultimately, as you can see here, very thematic, like Jon was just describing, like, hey, I need to be able to go ahead and automate some of this because I have a limited team. And geez, as I expand that team or expand the capabilities of certain team members I need to be able to do that quickly. I can't keep doing this for month after month, right? And then ultimately, I'm sitting here with I got a -- it always comes down to responding faster, responding, faster, responding faster, right? So again, they really did a tremendous job of embracing that enterprise case management with those core goals around I have the insights I can go ahead and scale the right teams, I can go ahead and address things in the right way with the appropriate response because I'm utilizing my threat intelligence, my automation and all those deep insights and right down to what Jon was talking about reporting, they're like, look, I want to be able to go ahead and understand who's doing what, where and when and what we can do better with, right? And bingo, that's exactly what they did. So yes, this is a really great scenario of this is what I need to accomplish with my SOC and my extended teams. Great stuff, Jon.

Jon Williams

executive
#20

Absolutely. All right. I think now we have -- yes, we have about 20 minutes or so left. I think I saw a few questions in here. So why don't we start with -- let's see. AI is big in the Vancouver version. Is it used in this capability as well and how -- so I believe AI exactly? Or are we talking about machine learning, I guess, is the question.

Karl Klaessig

executive
#21

So we use AI appropriately throughout with the data that we take in, right? And that's something that we've always done for a number of years now as an organization. We've made sure that AI is a part of, okay, do we learn from these things? In other words, much beyond what we do with basic machine learning. So when it comes to utilizing that throughout the product, we do utilize it throughout the product for those type of things, hey, what is the appropriate type of action learning is this, right? So do we -- we all walk that road of with artificial intelligence with the eye how much is too much and where does human interaction start. So one of the things that we've always recognized working with our customers because we want the same is we have the full capability even in automated playbooks that leverage a certain amount of AI, where do you go ahead and insist on human intervention. We have total flexibility throughout that process and that workflow to inject human intervention where you see fit. So that's where we -- that's where we utilize that balance of AI and human intervention because this is security we're talking about. So you have to have that. So yes, we continue to go ahead and utilize it for those particular insights and to accelerate some of those insights and identify where are those responses. But again, we always make sure human intervention is a capacity that our customers can utilize where and when they see fit. I hope that helps with that question.

Jon Williams

executive
#22

Yes. I was going to say, I think it's big in prioritizing and triaging especially. But we've found with customers more often than not, they need -- they need that final set of eyes -- human eyes before they fully automate any process. So yes, we do lean on it quite a bit, but being security and the nature of it, yes, we always like to have someone on keyboard to verify. All right. So next question, how would you manage a major security incident if your active directory or teams was down or compromised? And do you have out-of-band capabilities?

Karl Klaessig

executive
#23

So I don't think we -- if I'm understanding the question right, you don't have to have either of those to continue to work the major security incident you could still use other methods of communication.

Jon Williams

executive
#24

That is correct. It's integrated and it's convenient and if it's available, it's fantastic. But to the point of the question, if it's not, so be it there are plenty of other ways, right?

Karl Klaessig

executive
#25

Yes. I mean, yes, you'll still have the ability to work the incident through there and manage and track everything I think yes to your point, those integrations just aren't going to be available to you at that point. I don't know if we've ever run into that. It's an interesting question.

Jon Williams

executive
#26

All right. Is the CISO dash a mix of [indiscernible] and reports? So the CISO dashboard is, yes. I think most of our -- I don't know if we have any dashboards that are just specifically [indiscernible].

Karl Klaessig

executive
#27

Just some very simple ones. So the majority of the reports like the CISO dashboard, the question being asked is definitely driven by performance analytics, right, particularly that capacity to customize the heck out of it. So beyond just the core reports that are in there, you can build out your own. And that's all part of the performance analytics, which concludes the reporting. So there is some base level reporting that comes in the product. But again, Performance Analytics is really what drives that.

Jon Williams

executive
#28

Oh, huge. Yes, I think most of the dashboard. So to your point, they are all going to -- if it is PA it's going to include the reports. So yes, that's a good question. But again, that's out of the box. You can actually -- obviously, you can modify, customize those as much as you want or as little as you want. But what we showed you earlier was all out of the box. So again, great reports just -- yes.

Karl Klaessig

executive
#29

This is a good question. So being asked is you have out-of-the-box playbooks, but how can we create our own like is that difficult to do? It's a great question. Do you want to take that, Jon?

Jon Williams

executive
#30

Yes. Absolutely. So yes, we do have a massive number of out-of-the-box playbooks. you can create your own. You can actually -- once you've created those, as Karl was showing you earlier, you can reuse those actions. So once you've created a playbook, you can actually share those actions, you can save those and reuse them over and over again, and it is not difficult to do. The complexity really depends on you. right? You can create as basic or as complex of a playbook as you want. But the key thing is the way we've created, it's modular in nature now, so you can reuse those throughout different playbooks rather than creating the same action over and over again, if you know you have a certain step that you perform, that action is available to you throughout. So no, it's not -- it is really not difficult to create those. And we have a lot of resources that can help you with that, documents, videos, webinars. So I strongly encourage you to -- if you're interested in creating [indiscernible] and it's something that you can even play around with. So -- and we have the ability within the playbook within that creator to generate, you can upload data so you can test your playbook and see how it would run. So really important. Hopefully, that answered it. So let's see, how can we create a custom integration for a tool if an off-the-shelf integration does not currently exist. So kind of what we were talking about earlier with the ingestion, we have a few different ways. So the API is probably the leader there. But if there's an integration or a tool that you use a third-party tool that you use that we don't have an integration for which we have a large catalog of , but you find yourself without one. We can absolutely create integrations through API or any of those other ingestion methods to bring that data in from that source. So it's, again, a lot of resources out there on how to do that, but it is not overly difficult. It's just going to depend on really on the tool itself that you're trying to integrate with.

Karl Klaessig

executive
#31

Yes. We supply the building blocks, so you can make that integration happen.

Jon Williams

executive
#32

Absolutely. All right. Let's see.

Karl Klaessig

executive
#33

Someone asked about other ServiceNow products like vulnerability response, alongside in enterprise case management. So one of the great things about ServiceNow is we work off a platform, right? So enterprise case management makes use of security and some response. If you have vulnerability response and for what it's worth, many of our customers have both vulnerability response and security [ system ] response. And the focus there is absolutely, they can work next to each other and work with each other. As an example with vulnerability response as the question asked was vulnerabilities is -- a major vulnerability obviously can become a security incident. And they're very much hand-in-hand, just like vulnerability data is taken in as part of some of the integrations to understand where there may be issues and what can become an incident. So they work very strongly together. And no need of that, but you can also go ahead and securities and response, you can actually receive an alert from risk, and this has this is a potential incident and things like that. So we do a lot of making use of the shared data and the capabilities across the platform to utilize with security operations as well as other solutions.

Jon Williams

executive
#34

Yes, that's a great answer. It is -- as you saw, we -- even though, as karl mentioned at the beginning, we were going to be focusing on security incident response you saw a vulnerability in a lot of those slides, and that's because we keep those very tight tightly together because they are. They should be going hand in hand. And those teams should be working side by side in the end. So yes, good answer. Got one more question here. How can we customize the criteria for incident prioritization and the assignment processes to fit our specific business needs. So yes, that's a good point. When we talked about prioritizing and triaging, all of that is customizable within the platform. You can customize the criticality of assets of certain types of incidents, everything there is customizable so that you can tailor that to your specific business because, again, what's important or what's critical to one organization might not be as critical to another organization, right? So all of that is customizable within the platform. And again, not overly difficult to do. It's actually probably one of the first steps in setting up your incident response or your security operations is to identify all of those priorities and assign -- yes assign them numbers. So I think we have time for another one.

Karl Klaessig

executive
#35

One more question.

Jon Williams

executive
#36

Yes. How can multiple methods of ingestion be used or configured at the same time? Is this even possible? So yes, as we mentioned, there's 4, I think, that we mentioned different ways of ingestion. You can absolutely configure -- you could configure all 4 of them if you'd like. The problem with that is you end up having duplicates, so it's important to make sure that you're -- you have proper deduplication going on to make sure that you're not creating duplicate incidents from the same data -- but absolutely, if you had a source that was sending you login information and you had a source that was sending API information, again, going back to the integrations, right, different products, different third-party tools, they may operate differently. And so it's important for us to be able to tap into each of those in a different way if needed. And so you could absolutely have 4 different tools, each of them using a different method of ingestion all at the same time. So it is absolutely configurable and possible to do that. All right. Yes, I think we're going to wrap up here, Karl, unless you had anything else.

Karl Klaessig

executive
#37

No, this was great. Thank you for all the questions, folks. Really appreciate your great insights and sharing some of the things that you need to figure out. So I hope this was really helpful for you. Jon -- Jon and I are both very passionate about this. it's a hard aspect to always stay ahead of the land of threats and vulnerability. So we're always eager to see how we can help our customers with some of these tools that can really make a difference in their team's capacity as well as their team's expertise. So thanks for your time today and going ahead and listening to us and asking some great questions.

Jon Williams

executive
#38

Absolutely. And if we didn't get to your question today, we will be able to answer those offline. So no worries about that. We will make sure we get to those. But -- in closing, I just want to remind everybody about some resources that are available to you. You can register for Knowledge '23, the digital experience. There's a QR code here. you can go in and look at any of that that's available to you. Again, it's -- this is free. And then we have our knowledge '24 that's coming up. And so if you want to sign up for the latest updates, go ahead, there's a QR code here as well. May sent it through the 9th in Las Vegas. And then lastly, our webinars, our on-demand webinars, which this will be on here as well, along with a number of other great webinars. And so again, a good resource if you're trying to do things like we talked about integrations, you want to learn more about reporting anything. So -- and then the community as well. So a lot of resources available to you and make sure you're taking advantage of those. I really encourage you to look at those if you have questions. So. All right. I think that's it, Karl. Thank you, everybody, for joining us today. I hope it was beneficial. I hope everyone got something out of this. And yes, again, if we didn't get to your questions, don't worry, we will make sure we get to those after the webinar ends.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete ServiceNow, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to ServiceNow, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.