While digital innovation is vital for any organization’s survival, growth, and profitability, such innovation introduces increased complexity and risk. How are you securing your company’s current and future existence, manage cybersecurity risk, and build resiliency to enjoy the benefits of innovation? How are you defining your strategy for building resilience in these uncertain times and crafting security programs to respond to emerging threats and sophisticated attacks? How are you architecting security and risk solutions for your business to take calculated risks and maximize digital potential?
Watch this webinar to get answers to the pressing questions including:
-
- Transform: How to transform Digital Resilience from IT to a Business Function?
- Build: How to build a vision of enterprise resilience that will allow the organization to continue to move forward inspite of growing security risk?
- Respond: How to anticipate and respond to the digital threats by improving security capabilities and implementing the right technologies?
- Balance: How to balance keeping the business secure while enabling it to take calculated risks?
Contributors
-
- Scott Hicar, Chief Information Officer, Benchmark Electronics
- Anu Varma, CIO – Communications Solutions Segment, TE
Explore More
-
- Steps to Delivering Relevant, Resilient, and Reliable Digital Services
- Enabling an Efficient and Resilient Business of IT
- Building an Elastic, People-Centric Business, Focused on Now
- Building a Disruption-Proof Bottom-Up IT Culture
- Supporting Business Reinvention to Alleviate Global Disruptions
- Preparing Your Company for Digital Disruption
- Enterprise Cloud IT+ Big Changes = Disruption & Innovation
Transcript
Sanjog Aul [00:00:14]:
Hello and welcome to the CTN webinar. The topic for today is building resilience against Digital disruptions during heightened uncertainty. Interesting topic, timely. And that’s why we are covering it. It’s made possible by Everbridge. So big thank you to you folks. I’m Sanjogal, your host and moderator for this webinar. And just so you know, this is going to be like a workshop, candid, conversational and collaborative.
Sanjog Aul [00:00:44]:
That’s how we’re going to run it. And we will talk about different things. I will get into it, but first a question for all of you. And the reason I bring this up is because I’m going to try to tie into the topic itself. And this is also for, by the way, for the panelists as well. So if you were to be a professional athlete and known to be that professional athlete, which sport would you choose? And attendees, they can chat and give us their inputs. And panelists, you of course can talk cricket. Okay, so Satish says cricket.
Sanjog Aul [00:01:29]:
Okay. Anyone from our panelists, James Scott, Rob Anu.
Anu Varma [00:01:36]:
I would say basketball, because I love the basketball, Go Bucks. But I’m short, so I don’t know that that’s the right choice, but that’s what I would say.
Scott Hicar [00:01:48]:
Yeah, I would say that I am physically limited on my professional. I mean, I wish I would have tried for that if I would have been physically capable of any of those things. But I think if I’m looking forward career wise, I think curling is still an opportunity for me professionally because it looks like a sport that if I just really dedicated myself, I think I could really kind of. I’ve never done it before, but I think it’s one of those things where I don’t think I’m outside the reach of the Olympic team, even at this age and sort of size.
Sanjog Aul [00:02:19]:
Interesting. Very interesting. Yeah. So the reason I wanted to take this question, at least put it out there, is because a professional athlete requires skill, they require stamina, and they also require patience. So we almost, in our roles as technology leaders and security leaders, we have to be able to show these faculties for us to be able to run this sport. There are no games, there are sports being played. And which is, of course, you have to build resilience with all the disruptions that are happening. So the kind of things that we would like to touch here is can digital resilience be the responsibility of business or can we at least push business to take responsibility, or should it be an it’s job? Then how do you go about building a vision of enterprise Resilience so that organizations can continue to build great things and innovate in spite of the growing security risks.
Sanjog Aul [00:03:22]:
Then at the same time, we have to also be able to anticipate. We don’t have a crystal ball, but can we do something with respect to this resilience building where we can anticipate risks and respond to these threats and which could be digital threats or other kind of threats that may be coming our way? And finally, we would have a way to strike a balance. Can we truly strike a balance where you say, okay, business, I will give you a stable and secure environment, go do your thing, but also allow you to have a sandbox and take some calculated risks? All of that is the outcome business is looking for and it’s our job to build resilience. But what holds us back? What are those top challenges which hold us back from building resilience against digital disruptions with all this uncertainty that’s looming? That’s what we are here to talk about. And I have got a few athletes for you. We have James Johnson, who is the Chief Information Security Officer for John Deere. We have Anu Verma, Chief Information Officer for TE Connectivity, Scott Hickar, Chief Information Officer from Benchmark Electronics, and Rob Zelinka, Chief Information Officer from Jack Henry and Associates. So, hello team.
Sanjog Aul [00:04:36]:
How are you folks?
Anu Varma [00:04:37]:
Good.
Sanjog Aul [00:04:38]:
Doing great. What people do is just so that the audience members and also panelists, you are aware, we will try to first go through all the top challenges that you are facing and audience may be facing and they would like to share and then we will get into the solutions. So let’s start with you, James. If you were to pick your top challenge which prevents you from building resilience for your organization for any such disruptions that may be happening, including the digital innovation centric disruptions, what would that be?
James Johnson [00:05:20]:
Yeah, first of all, thanks for the opportunity. It’s great to be here with this group of panelists and I’m excited about the conversation today. As far as challenges go, I don’t think my challenge will be different than a lot of other big companies that are in the same space. I think for me, I look at resilience and what it means is discipline, right? It’s are we disciplined in what we’re doing when it comes to controls? Making sure we have controls assurance and then doing things to make sure we have visibility into our critical infrastructure, critical systems. And so the biggest challenge I think at times is just keeping up with the pace of change in technology in our environment. Just a good example would Be as you’ve gone to the cloud, right? The skills you need to manage a network are going to be different than the skills you need to manage network in the cloud. Firewalls, code, security, basically these are all things that as you shift to the cloud, you have to adapt your skillset and it makes resilience more challenging. So talent and training, it always comes back to that.
James Johnson [00:06:14]:
Do we have the right people with the right skills and the expertise, not just amateurs. You have to be expertise or experts when you’re dealing with things like the cloud where it’s Internet facing all the time.
Sanjog Aul [00:06:24]:
And when you talk about talent, are you assuming that all that talent should be in house and they are captive or you’re saying get me the talent. No matter what modality, get me the.
James Johnson [00:06:34]:
Talent is what I would tell you is more the approach. We’ve done a lot to build talent internally at Deere, but we’ve also done some things where we’ve hired some great people from outside as well.
Sanjog Aul [00:06:43]:
Okay Anu, what’s your top challenge that keeps you up at night?
Anu Varma [00:06:49]:
I think the thing about our current state is that it lives everywhere. We don’t get to own it. The IT organization doesn’t get to own it. Digital lives everywhere. That means innovation lives everywhere. Finding to your point, Sandhya, earlier is finding that balance of allowing our business to do the innovation that they need to solve the problems for our operations, for our engineers, for our customers, and yet we need to create that balance of governance on top of that, right? So when I go out, when I used to go out pre Covid to our operations and I would almost always come across something somebody had built that they were so proud of. Hey, we’ve attached a sensor to this machine and we’re doing a closed loop manufacturing and we’re loading the data into Azure cloud and it’s like, oh, fantastic innovation by the way, let’s talk about this Azure cloud. Let’s talk about this innovation, right? And the security that goes with it.
Anu Varma [00:07:48]:
So finding that balance of allowing the business to do what they need to do, because this is fantastic innovation, I don’t want to shut it down, but I do want to be aware of it. I do want to have some governance on it so that I can make sure that we’re doing things properly and that it’s secure and that means that the IT organization has to move at the pace of the business and we have to be able to go through that governance process quickly as possible, right? To not be seen as blockers.
Sanjog Aul [00:08:15]:
So Anu, so Think about this. The business outcome, what they’re expecting, and they pay you a million dollars and your security counterparts a million dollars to get this going. Is where they say, okay, help me keep the fort secure and help me. Give me the room to play, right? And when you and your security counterpart or whosoever else that you end up partnering with, when you’re trying to help build that balanced approach, which means you have to be able to have them do the things. And if something goes south, right? And if you’re experimenting, things will go south. There will be disruptions. No matter what, they have to be able to bounce back. So if you can help them anticipate, and because of which, you bounce back better, or you just make them like a SWAT team, that no matter what happens, you bounce back.
Sanjog Aul [00:09:08]:
That is the kind of capability they would expect. But if you are given that task to build that capability, what holds you back?
Anu Varma [00:09:15]:
No, I think the challenge is, are you engaged at all levels of the business? Right. We’re a company, 80,000 employees, 140 countries, operations everywhere. Getting down to the plant. When you get down to, like, a plant level, right, you have all kinds of vendors coming in saying, hey, let me solve this problem for you. Let me solve this problem for you. And that’s exciting for our operations, right? They have hard KPIs that they’re running to. They’re always trying to optimize their plants. They’re excited by those opportunities.
Anu Varma [00:09:44]:
Do they think always about security as they’re doing it? Do they think about, hey, let me check in with somebody, make sure that I’m protecting the company as I’m doing that? That’s where I think the gap is for me. I know we don’t want to talk about solutions, but it is really that human firewall that we need. No matter how much of infrastructure and security you put there, it’s that human firewall that is ultimately your point of failure sometimes, right?
Sanjog Aul [00:10:14]:
Scott, what’s up with your situation, your company and your challenges with this regard?
Scott Hicar [00:10:21]:
I was just thinking a new. I was just thinking about one of our strategic hardware. It was an upgraded hardware. The engineers are excited. This is their manufacturing 4.0, you know, roadmap. And I remember the conversation with the. With that manufacturer, and they said, you know, in our security team, the engineering guys called me, hey, we had a problem. Your security guys are, you know, not.
Scott Hicar [00:10:40]:
Not helping. I’m like, oh, what’s the problem? And the vendor says, yeah, we just need to have any. Any access. Because really, we just want to be able to get to this equipment from, you know, our. And it’s going to have a lot of data. We’re going to have a wonderful, we are not going to get anywhere on this conversation. And it was good because those two teams needed to learn that they need each other. Right? The manufacturing equipment team and the cybersecurity team realized they have to have a tighter relationship and that’s part of the evolution here.
Scott Hicar [00:11:09]:
I would say that if you take that and you extrapolate it, our balance between allowing innovation and change and pouring, we pour change in through our enterprise architects and our manufacturing engineers and people that are trying to evolve our operations. And we are seeing this massive amount of undesired change coming from patching and security and cyber. And look what we’re all doing right now on this Java exploit event. And those are competing forces, right? We only have so much capacity to change and if we have to consume it all with just managing patches and volatility that’s coming from an ever increasing rate of security updates, well, then we’re going to, we’re going to consume sort of the risk. We can allow for transformational change in sort of security and insurance and, you know, protecting the base and we’re going to kind of use it all up over there.
Anu Varma [00:12:01]:
Right?
Scott Hicar [00:12:01]:
And so that’s really what I’m concerned about these days is just how much of my change capacity has got to be dedicated to retail and bug fixing from sort of the speed and speeds and feeds of patching that’s coming out. Right? It’s really a challenge to, you know, because you’re really at the end of the day trying to be operationally stable and safe at the same time.
Sanjog Aul [00:12:20]:
So is it a bandwidth issue? You’re saying, can you throw money at it to solve it?
Scott Hicar [00:12:26]:
It’s an expertise issue. I think the problem in the vendor world is that nobody wants to be the next SolarWinds. And so they are throwing, throwing patches out faster and faster where there used to be. If you think a couple years ago you’d say, oh well, these patches are out, they’re in their dev environments, they’re in their sandboxes. You can test them, you can see if it’s going to be interoperable. There was a little bit of soak time happening and now what’s happened really fast is that because nobody wants to be holding the hot potato, the vendor base is just throwing the patches in, saying, look, if we break a customer a little bit, that’s better than being our brand being broken down like a solar winds did. And that just means, for us, that means less understanding of all of this change that’s coming, but at the same time a necessity from a security perspective to apply as much as we possibly can, right? So just the soak time and the interoperability and the vendor testing time is diminishing. And so that just puts the risk on us and the operating theater to say, yeah, we’re applying things that probably haven’t been fully soaked in the community and therefore we’re going to find disruption, right? We’re going to find things that break more frequently.
Scott Hicar [00:13:37]:
And again, given the velocity and volume of patching, it’s just going to be kind of the nature of it. I don’t think you can people your way out of that. I don’t think the vendors, I know what the vendors are doing. They’re like, look, I’m not going to be SolarWinds, I’m not going to be responsible for a massive breach. Look what Oracle’s now got to deal with Java, that’s a live example of what’s happening right now. What are they going to do as a response? They’re going to start end of life in Java versions. They’re going to say, we don’t support that anymore. That’s, you got to get out of that.
Scott Hicar [00:14:01]:
So they’re going to compress the life cycle of a particular release so they can say, it’s not our fault. And that just means for us, again, operationally, we’re going to spend more of our capacity managing that where we want to be spending that capacity, transforming operations and obviously creating more efficiency and value on that side. So I think it’s just going to be a difficult, it’s a difficult reality we’re all going to work through.
Sanjog Aul [00:14:26]:
Rob, what are you facing?
Rob Zelinka [00:14:29]:
Yeah, so I’m a big fan of the NIST framework because it’s not just for security or cybersecurity. It can really help you to drive business outcomes. So, for example, I think we’re in a period of time right now where we have to identify the risks that face our organizations. And most of us share common risks. Some of us have unique risks. Those risks are potentially financially impacting, reputationally impacting. You know, if you’re the victim of a ransomware attack, chances are it makes front page news. None of us want to ever be there, but every now and again we might end up in a place we don’t want to be.
Rob Zelinka [00:15:07]:
And how we manage through that situation really defines us organizationally. You know, once we’ve identified those risks, then we have to protect against those risks. For me, foundationally, it always starts with people. No matter how much we automate things, people still buy from people. We’ve all heard the stories about companies that sell cars without a salesperson. It’s all done online. Sounds like a great thing until something breaks down. And it’s usually not a human that’s broken down.
Rob Zelinka [00:15:39]:
It’s a process that’s failed along the way. And you just need a human to make it right. So, you know, the ability to respond quickly. I think the differentiator every business has in today’s modern world is speed and agility. How quickly can you respond? How quickly can you adapt and change direction if you have to? And then when something truly bad happens, how do you recover from that understanding that, you know, you may have spent years, decades, building your reputation, all for it to be disrupted in a mere matter of minutes, hours, days? So for us, I always start with people. I want to make sure that our most important asset, precious asset we have, they’re doing okay. We’ve created an environment that is safe for them, that they feel they can share their challenges. The world is very, very challenging right now, both personally and professionally.
Rob Zelinka [00:16:34]:
We’re all now, I shouldn’t say all, but most of us are working remote for a period of time longer than any of us probably planned to. It’s become our new norm, and yet we’re still trying to balance all that’s thrown at us from a work and a life perspective. Once you’ve created that safe environment for your people, now you also have to augment your capacity. You’re going to do a gap analysis. You’re going to determine there are skills that you need on your bench. We were talking before the session began about technologies that are 10, 20, 30 years old. They’re still in the background, and there’s a lack of subject matter expertise simply because people are retiring or sadly, in some cases, they’ve passed on. And yet we’re still running a business on those antiquated technologies.
Rob Zelinka [00:17:21]:
So those are the things that keep me up at night. Sandrag and the things that I’m really hyper focused on.
Sanjog Aul [00:17:27]:
So would you say legacy debt is what’s giving the heartache?
Rob Zelinka [00:17:33]:
To some degree, yes. But so too is the modern stack. Again, going back to some of the conversations that we had earlier, James pointed out some of those legacy stacks aren’t as vulnerable to security abnormalities, largely because they’re out of sight, out of mind. However, the modern stacks are very attractive, for lack of a better word. The cool kids are Building in those stacks, it gives you that speed and agility that I spoke to earlier, but it comes with an inherent risk. And so you have to perpetually be on your A game. Securing, protecting, defending in those environments. Again, no one wants to be the next company that is on the front page of the Wall Street Journal on the lead story for the nightly news.
Rob Zelinka [00:18:21]:
And that’s really, really what we’re fighting against today.
Sanjog Aul [00:18:26]:
Okay, so James, coming to you, your comment was around talent, right? And we had been talking about talent. Seems like a big theme here. So what have you done to crack this problem? Because security people ask an arm and a leg for the salary and or rates and they are few and far between. And some people say I have all the skills, but frankly, you’ll need skills which are already getting antiquated because something new has come up. So are you just playing the chasing game or you come up with a solution which will allow you to get some control on this madness?
James Johnson [00:19:04]:
I want to point out, I guess first and foremost, it’s not just about security talent, right? Where we’re getting the most traction is training our engineers and our developers to think like an adversary or to think like a security professional. And what we find is they’re a lot smarter than a lot of our security people. I mean, we’ve got great people, don’t get me wrong, but they know where the code is, they know where there could be issues, so we can teach them how to think and give them the right tools. And we’ve gotten a lot of traction from that, from that standpoint. So I would tell you, we’re trying to raise the bar across our entire development team and our software engineers. As far as security talent we’ve been doing is picking a couple of universities where we really want to build a program, right? And so we’ve got people on site that are kind of the Sherpas or the Shepherds, if you will, that have been with dear for many years and they’re kind of the parents at the office and they teach people about the culture they share, about how John Deere’s traditions are so that people connect with them with the message and also the mission. We’ve also tried to put really cool work there. So we’re not putting SharePoint permissions there.
James Johnson [00:20:07]:
We’re not putting basic file share management. We’re putting things like cloud vault management, security by design, so secure coding, those types of things with those programs. And so we then go after the freshmen and the sophomores and the undergrad programs, get them aligned to the mission, they get to work part time during the school year, they get to work as interns over the summer. We get to their senior year and we’re up against big companies that have big names and we’re still winning, getting our unfair share of talent because they like the mission, they like the team, and they understand the processes. So that’s how we’ve done it. And we’ve got a pretty good. We’ve seen probably in the last seven years, probably 10 folks that have gone through all the different progressions and now are either on our cloud security team or our coding teams. They’re in good places doing good work in security.
Sanjog Aul [00:20:55]:
So given whatever you’ve done, where would you say still the gap is, which you would love to see filled?
James Johnson [00:21:04]:
That’s a good question. I think that the gap really for us is getting those folks from the beginning of the program to the leadership level. So how do we get them enough experience across the company and even outside of security? We want well rounded leaders in security. So the challenge at times is getting to go, to leave the group and go somewhere else for a little while, get some experience on the business side and come back.
Sanjog Aul [00:21:30]:
Okay, so Scott, you want to jump in?
Scott Hicar [00:21:33]:
Well, I had a question actually for James and probably a new as well, given it’s ge. How are you doing with your software engineers? You know the other weird thing going on in the world, right, is the open source community was going to be egalitarian. We all contribute code, everybody gets more efficient and now they’re bad people dropping trojans out there, like, you know, like, like traps for people to pull that through. And you know, all of a sudden you’re, you know, now. And so for our engineers, we have a very small amount of design engineers, but they’re, they’re conflicted, right, because the concept of using open source and velocity and kind of efficiency is really competing against, well, how do you trust it? What can be trusted out in GitHub? And so how are you guys progressing those conversations in New York? Because I imagine you both have very large devices development organizations that don’t naturally think this way.
Anu Varma [00:22:25]:
Scott, if I may correct you, I’m not with ge, I’m with TE Connectivity. So that, so that isn’t a current problem of mine, but from a past life, I will tell you it is a problem, right? This was a company that we were selling software, you know, What I will tell you though, is that that group is a lot easier to govern than our citizen developers that are sitting in our business. Right. At least you can get your arms around that group, you can put guidelines, you can control them a little bit and you can evaluate what you’re going to do and evaluate the risk and mitigate for it. The citizen developers is a whole can of worms. That’s very different.
James Johnson [00:23:06]:
Right, I’m going to go back to pro processes and training and tooling. So again, we’re trying to give developers the visibility into what’s in their code, right? Giving them the ability and really trying to put the alerts that we generate or the security issues where they work. So we’re not creating some third party vulnerability tool that they have to go log into to see. We’re trying to find ways to actually write the alerts into GitHub so that they see when they compile code. Here’s some things you need to fix before you actually put this into production. I will tell you it’s not easy and as we continue to change tools at times it becomes challenging. But that’s really been the goal is to give them, enable them and empower them with the right knowledge and also the right visibility into what their issues are. It is a problem, no question about that.
James Johnson [00:23:50]:
It’s a great question, Scott, that you asked because open source, we could discuss that probably all day but visibility has been very helpful for the developers.
Sanjog Aul [00:24:00]:
So I know, coming to your challenge, what are you doing to crack it, what all you’ve tried, what’s working, what’s not working?
Anu Varma [00:24:08]:
You know, one of the things that we’re doing is I’m drumming a beat that says security is not it’s issue. Security is everyone’s issue. And so what we’re doing now is quarterly communications around security. So we do things like we do phishing tests. Right away, scorecard, those phishing tests by business unit, we can say, hey, here’s how many bites there were on these phishing attacks. And you know, if we have more than three, we’re putting people through training. And what I’m finding is between business units there’s this competitiveness that’s forming, right? Oh wow, you know, I scored much higher than somebody else. I’ve got to, I’ve got to do something in my business unit.
Anu Varma [00:24:52]:
The other thing that we’re doing is we were putting together quarterly security content and you know, to teach our business about what, what risks are sitting out there, what they need to do, how they can be that human firewall. And what we’re doing now is trying to get our leaders to give those updates out to their staff. So in a town hall, it’s a general manager that would be talking about this. It would be, you know, a CTO talking to the engineering group. It wouldn’t be an IT update coming. And to really start getting the culture transformed around security is not just something that it needs to think about. Security is something that every one of us needs to think about. And on the innovation end, what I call the field innovation that’s happening, the citizen development.
Anu Varma [00:25:37]:
One of the things we’d like to do, for example, in China is, you know, is we have kind of a China Operations Council that can. We want to surface up this innovation, we want to celebrate it so that people will share it. And then we give the opportunity for our operational leaders in China to say, hey, you know, some of these tools that have been created out there, those are great. They can vote on them. And then we can say, you know, it will take a look at the top three innovations and maybe we’ll scale that for the enterprise and make those enterprise solutions. And it’s a way of surfacing up the activity that’s happening in the plants and celebrating it in a way. But, but then it also gives us that governance lens. Right.
Anu Varma [00:26:19]:
It gives us the ability to see it all, inventory it, check it, and then look at opportunities where it can be scaled. So some of those things that we’re looking at, it’s really around pervasive security thinking throughout the organization, not just sitting in it.
Sanjog Aul [00:26:36]:
So as you’re drumming that are people hearing to the degree you’d like, or there is some creative ideas you’re looking at so that people start, you know, heeding your advice and, or joining and with you as the Pied Piper.
Anu Varma [00:26:50]:
Yeah. There’s a balance between frightening everybody completely. Right. To, you know, hey, we can still work. And, you know, the news helps. Right. There’s a lot of. Every time there’s a ransomware attack, every time there’s some news, our leaders are paying attention to all of that.
Anu Varma [00:27:06]:
Right. So it’s really about. You don’t want to be the fear monger. Right. But. But the risks are real. One of the things that we did recently is a tabletop exercises around a risk scenario within a plant. You know, this is it ot this is industry 4.0.
Anu Varma [00:27:27]:
Something happens that plant. It’s, you know, we have to shut down everything in that plant to. It’s a ransomware attack. And we brought in all kinds of business leaders on a, on a tank tabletop exercises to say, what would you do if that happens? And immediately everybody starts thinking about their doctor. Right. Oh, I just Take out my disaster recovery stuff and I would just start working manually. That doesn’t always work, right. So we just went through a scenario where we moved our, we had a major project, we moved our data center over.
Anu Varma [00:27:57]:
We had planned a massive shutdown across the company. When that happened, everybody built up their inventory, everybody planned for it, they communicated with their customers, everybody was ready, they executed their VR. It went beautifully, very successful project. But when you have a security attack, a cybersecurity attack like that, you’re not, you don’t have time to prepare and you don’t have time to build up inventory. You have time to get all that together. And so what was eye opening for a lot of the business leaders was in that tabletop exercises like, oh, you know, that wouldn’t work for me. This is what I would have done, but that wouldn’t work for me. And it got us thinking, thinking about how do you prepare for the unknown? Because you might not know what’s going to happen, but you kind of have to have some sort of structural way to be prepared to deal with it.
Anu Varma [00:28:46]:
And how will you develop that process and communicate and educate folks, Right? So when it does happen, you’re reacting quickly.
Sanjog Aul [00:28:53]:
And to that answer, James, Scott and Rob, have you come across any creative idea or you’ve experimented a little bit where you are able to get the business and your operational and other field staff to all start thinking to prepare for the unknown versus either coming across as selling fear or you’re saying you’re wasting my time.
Rob Zelinka [00:29:20]:
This is an area where I really like to toot my own horn. I think our company, our culture is one where it’s built on what we call the three C’s and A T, communication, collaboration, consistency and transparency. And so we have created a business relationship manager function within the technology organization that reports up into me. Those people are embedded into the lines of business. They’re attending their staff meetings so they understand the pain points, they understand the struggles, the challenges, the, the strategic imperatives. And as you might imagine, from business unit to business unit, there’s some level of consistency. And so we seek areas where those consistencies exist and we focus on them and drive the outcomes together in partnership with our colleagues across another line of business. I learned something a long time ago, Sanjog during as you know, I’m from Chicago originally and there was a decade or more of me getting on the train and going from the Chicago, downtown Chicago out to the suburbs where I lived.
Rob Zelinka [00:30:30]:
And a wonderful Indian lady taught me something really valuable. And here’s it was around a pretty casual conversation. I said to her, yeah, in my house, the man is the head of the household. Who’s the head of the household in your house? And she said, yep, the man is too, but I’m the neck. And I looked at her kind of curiously and I said, what do you mean you’re the neck? She goes, I make the neck. The neck makes the head move whatever direction it needs to go. The reason I share that, and this is critically important for I would submit, most organizations, the neck of any organization is your middle tier managers and leaders. And if those people aren’t subscribed to your vision, your strategy, they don’t understand it, or worse, they’re not hearing.
Rob Zelinka [00:31:14]:
Doesn’t matter how good of a job you’re doing at the executive level, you’re ultimately set up to fail because the execution of that strategy happens several layers below you.
Sanjog Aul [00:31:25]:
Okay, so Scott, talk about your organization. In fact, I have a comment from Satya. So he’s written a long comment. Let me see if I can even unmute him for him to Satya. Do you want to speak about what you just wrote?
Satya [00:31:48]:
Yes. Can you hear me?
Sanjog Aul [00:31:50]:
Yes, we can. And what’s your background? Just give us your title and your company.
Satya [00:31:53]:
So I’m the CIO for Skyworks. Skyworks is a semiconductor player and we are in the 5G space. So this is very informative. I actually joined this particular webinar because of what’s happening within my organization. We just instituted a new function within it called it Resilience. The intent of this tower is basically the crux of what you folks are actually talking about today. So what I had written was that the way that we see it is that organizations are seeing this as an offense and defense approach. The defense is what Cybersecurity is.
Satya [00:32:33]:
So CISOs today are actually trying to defend the organizations. They’re trying to thwart these attacks and they’re protecting the actual surface area of the organization and all of that. Now, the other side to that is the offense, which is what it resilience is all about. How quickly can you resurrect your systems? How quickly can you get your systems up and running within these stipulated RPOs and RTOs that we have put together? So I think it’s only a matter of time before SEC also gives out a directive to organizations to say that, look, attack is actually inevitable. Your company is going to get attacked. We all are dealing with the log J issues today, so attack is imminent. With that happening, is your organizations ready to resurrect your systems. How good are your BCDR strategies within the organization and how good is your IT resilience? I think that is the one that we are all struggling and as I hear some of you talk, it’s like Alcoholics Anonymous for me.
Satya [00:33:32]:
We all have the same issues, we’re dealing with the same problems when we share the misery and fun to do that. But this is great. And I mean we’re not alone in this, right? So that’s the thing as to how many of you, of you, when I talk about you, I’m talking about all these like panelists that we have your great stuff that you’re actually sharing today, but how many of you have IT resilience as its own power within your organization?
Scott Hicar [00:33:56]:
So maybe I’ll, maybe I’ll kind of follow on to that, Sandra, because it’s, it’s actually, yeah, it’s actually a great way to describe it. You know, we would. What we’ve done organizationally is created kind of a. It’s really three people that, that drive resilience. Right. It’s, it’s our operational. You know, we have a leader for IT operations. His job is uptime and availability of all of our sites, our factories.
Scott Hicar [00:34:19]:
You know, he’s driving availability. He owns restoring from a disaster and making sure we’re ready at the sites. We have our cybersecurity leader who is, you know, protecting. Right. You know, they want to lock everything down. They’re you know, in. And then the third leg of the stool is really the IT architecture organization who is pouring change in through the top. And honestly, all three of those make up our resiliency organization.
Scott Hicar [00:34:45]:
And we balance those, we balance that out. There’s a lot of good tension amongst them. You know, hey, I’ve got new stuff to put in that’s going to help us with cybersecurity. Oh, operationally I need a change control window. It’s going to be risky to the factories. Those three. We probably meet all day long, you know, every day, constant chat streams as we work through. You know that.
Scott Hicar [00:35:06]:
So it’s a three legged stool as we describe it to our executives and the three leaders of it. We actually meet with our CEO on a regular basis and just talk about, talk about the balance points. You know, our security organization owns patching. A lot of teams don’t, you know, sometimes security is much more of an audit function. Ours is operational. They own the patching, they own the planning, they own the testing. Their operations is their customers. And yeah, I know I got to take all this Stuff in.
Scott Hicar [00:35:31]:
I want to know it’s tested, I want to know it’s ready. I want to know what the risks are in an architecture. Organization is constantly sort of deploying the new capital and refreshing. And so, you know, I really like the balance we’ve got amongst those three leaders and kind of how they work through this with their teams. But I think you branded it really well by saying that’s really the resiliency model that we’re driving.
Rob Zelinka [00:35:53]:
Yeah.
Anu Varma [00:35:53]:
I think similarly, I would say, you know, the other piece of this is really measuring ourselves on that. Right. And reporting that out on our scorecard and because it’s such a critical metric for the business. Right. Is how are we managing that resiliency and protecting the business. So that’s what we do as well. We don’t have a separate pillar in Satya. And I like that idea of somebody kind of owning that, but definitely it’s a key measure by which we run our organization.
Sanjog Aul [00:36:24]:
All right, so thanks so much, Satya, for sharing your input and calling us Alcoholic Anonymous. I love that. Right. Thank you. All right. Thank you so much. All righty. So now coming to you, Scott, about your bandwidth issue.
Sanjog Aul [00:36:39]:
So of course you responded to Satya’s comment, but come to your top challenge about you trying to build the bandwidth and be able to balance as more is thrown at your way that the pace of change. So now that’s not going to stop, right?
Scott Hicar [00:36:57]:
Yeah.
Sanjog Aul [00:36:58]:
What are you doing? So that you can keep your head above water and not only play that game of keeping your head above water, you should start feeling comfortable. So your team starts feeling comfortable and there is a progressive movement. So are you doing something specific to that end?
Scott Hicar [00:37:15]:
Yeah, Well, I talked about the structure. Right. So I like the structure we put in place and the ownership and accountability. We obviously adjust those as we see. So that’s working really well from a structure perspective. From a load perspective, the challenge is really, again, our capacity for change is somewhat finite. Right. And so the more we’re using to deal with foundational security and making sure we’re safe.
Scott Hicar [00:37:40]:
Right. It’s kind of Maslow’s hierarchy of needs. Are we safe? Well, until we’re safe, we can’t feel good about doing some of these other things. And so that conversation, and then we’re actually trying to keep our deployment development organization, our, you know, our applications organization that is really driving the business transformation agenda, somewhat isolated from all of this background activity that has to happen to sort of protect the base and to protect the ability for us to drive the Kind of meaningful change we want. So we’ve also sort of told them, hey, look, you don’t really need to be in every one of these meetings. Yeah, you’re going to involve in the patch, the patch process. You need to be there to validate your systems and things work. But I don’t want your guys spending their time, time dealing with this side because if they do, they’re going to.
Scott Hicar [00:38:20]:
We’re just taking precious capacity away from our ability to evolve the company. So I don’t think we have an answer for it. I think it’s just a balancing and, and obviously the conversation we have with our, you know, with our executive team is just a work, you know, we’d love to be spending 70% of our time on transformational work because of cyber and how much we are way behind that now across the board. And one of the other things we’re doing really is trying to understand the true cost of cyber now so we can communicate that. Because, you know, if I think about our factories and the amount of time we do patching and scanning and software, life cycles, end of life and quicker because they don’t want to be accountable. And so we’ve got to drive upgrades quicker and hardware refreshes are quicker. I think somewhere there’s, you know, more, at least a third, maybe somewhere between 30 and 50% of our organization’s entire amount of time is spent now in just keeping the company safe across all the work streams. We haven’t got a great number for that, but it’s one number I want to develop in 22 so that we can really talk to the fact that keeping the company safe has become an inordinate amount of our budget well outside the cybersecurity team’s budget.
Scott Hicar [00:39:28]:
It’s really an operational budget as well to run this way. And I’d be interesting to hear others feedback on kind of being able to come carve that out more holistically.
Sanjog Aul [00:39:39]:
Would you say that you’ve created the measures or the dashboard or the metrics of some sort? Because what you measure is only what you can improve. And if you could show, okay, this is how the business is running and this is how it is taxing your workforce, whether it security, et cetera. And then you got these disruptions, they are coming and these are snowballing. So then your cry for help has substantiation. You know, the numbers are driving your business case versus you screaming @ the top of your lungs, is that what you’ve done?
Scott Hicar [00:40:09]:
People measure what you’d expect, uptime, availability, of the, of the service, which is it our security organization measures against. You know, they have about a 20 all of our sites times all of the security work streams. They have a scorecarding mechanism we use for that. We obviously measure. Yeah. But one of the things that’s interesting to measure now is just how many changes we’re deploying in a patching window. X changes times x amount of servers and infrastructure. The velocity of amount of patches applied continues to go up exponentially.
Scott Hicar [00:40:39]:
The reality is we will break things in that process. That much change, that much velocity, combined with the fact that the industry, the custom vendors are not doing interoperability testing like they used to because they can’t wait, is meaning that not only do we have a higher velocity in volume of patches, but we have less. Less quality in them, I guess is a good way to describe it. Right. They’re finding quality out in the market. They’re finding in our backyard if we have an interoperability problem as opposed to finding it in their backyard. So we do chart that as a risk to the company. Right.
Scott Hicar [00:41:13]:
And so it’s interesting actually, our COO mentioned as we in our last discussion, he’s like, wow, should we just start thinking about as we schedule our factories in line, should we be thinking about not trying to work right after big patching window? Like, you know, is that just asking for trouble? We’re gonna have a bunch of idle workers around because something’s not gonna take my. Yeah, you know, we haven’t seen that yet. And maybe we, you know, we, you know, see what happens in the next year or so, but it may be an eventuality where we just need to have, you know, internal soak time, you know, into the. Built into the factory schedules because we know we’re putting just a lot of change in. Right. That is becoming less and less producer.
Sanjog Aul [00:41:53]:
So the other panelists, given what Scott mentioned, would there be any unique type of measurements and or business case development so that either more bandwidth is offered or if there was a way to streamline things so that Scott’s problem, if we speak about this a year from now would be less of a problem or will not be a problem. Any thoughts, any ideas?
Rob Zelinka [00:42:21]:
Well, I think there are always KPIs and metrics scorecards for whatever it’s worth. From my vantage point. What’s important is that we’re all tracking towards the same KPIs. Jack Henry has grown both organically and through M and A over the years. And so we almost at times appear to be several different companies operating under one umbrella. And every now and again you find out that while you think you’re all subscribed to the same strategy and the same mission, invariably you find out that maybe you have some conflicting agendas. And ultimately the KPIs that one business unit is driving for is different from another. So to address that, we’ve championed a campaign where again, leveraging one of those pillars of collaboration is putting a center of excellence together to establish those KPIs that are meaningful not just to the company, but to our customers, to our shareholders, and then tracking ourselves against our progress against those.
Rob Zelinka [00:43:27]:
It’s helpful to see how we perform against those KPIs. And then that also leads us to where we need to make additional investments, course correcting where necessary. And I think most companies probably find themselves in a similar situation where getting everybody rowing in unison towards a common goal and objective is challenging, especially in the world we live in today where it’s moving so fast.
Sanjog Aul [00:43:55]:
So anyone who gets a million dollar or thousand dollar an hour consulting to support Scott, what would you have given him as a tip besides what he’s already doing?
Scott Hicar [00:44:07]:
I was just saying it’s okay because it does create a sense of job security. Right. That’s great. I don’t know if I really want to solve 100% of it. Maybe we’ll wait for the robots to do that for us.
Sanjog Aul [00:44:21]:
There you go. There you go.
Anu Varma [00:44:23]:
I think you asked before we started Sanjog, we had the conversation on does security sit within the IT organization and are outside of it? Right. Is that the model of the future is that security doesn’t necessarily sit. And I shared with you, the last company I was in, CISO sat outside IT and it was the execution arm. I think that balance may allow you to spend on cybersecurity without affecting the cost to serve of it. Right. And treat security as its own entity. You know, a risk like you do a risk of compliance. Right.
Anu Varma [00:45:03]:
Treat it as its own entity with its own budget within the organization. Similar to my point earlier around, you know, security is everyone’s problem. Right. Why is. Why is it carrying that big budget for it? I wondered if that’s an approach and I don’t know if any of the panelists have that. James, I think you said you were in it.
James Johnson [00:45:20]:
Yeah. So the org is interesting for me. I look at this from a standpoint of there’s the first line of defense, which is the apps, the technologies that you own, you’re responsible to maintain those. You buy a vehicle, you got to change the oil you got to make sure you keep air in the tires. That’s your job to maintain that. And to me, part of quality is making sure that your stuff’s patched and it’s running properly and it’s configured properly. The second line of defense for me is security. Right.
James Johnson [00:45:46]:
It’s our ability to look and say doing a lot of great things, but here’s some things that we see that you got some exposure on or to help during, during a crisis to be kind of the telemetry that you need, understand where your gaps are. And then the third line of defense is usually the audit function of the regulators. From that perspective, in some cases security functions own operations. Like it sounds like a Scott’s company. They, they own patching. To me, patching servers is, that’s not my role, that’s it role. They own the servers, they built the servers, they deployed the servers, their staff to maintain those. And we will definitely consult and tell them, hey, it’s time to push a patch if they want support.
James Johnson [00:46:20]:
But they should be monitoring Microsoft or Linux and looking for those updates and they don’t need to wait for somebody to tell them that you should be pushing patches. And this is just table stakes for running a business today, right. I realize you’ve got to test and make sure things work with the code, but at the end of the day, we’re best served with weakened security, at least be that second line of defense and the telemetry that we need to have in place to see the critical infrastructure that, that it and frankly the entire company. To your point, ANU is running, everyone’s running technology today, right. There’s systems, apps they purchase, software they purchased online subscriptions they’ve got, right. Everything’s out there. So it’s challenging to keep telemetry and all that and see where the risks are. But I always joke, you have to be this tall to ride the ride, right? And so if you’re going to put something on the network or you’re going to buy a service and put gear data in it, you better be ready to support that and maintain it and make sure it’s compliant, doing the right things.
Sanjog Aul [00:47:18]:
Okay?
Anu Varma [00:47:20]:
Because we have the same thing, James, our patching and stuff happens with our infrastructure group not in security, but it still doesn’t address the problem of the budget, right. A bigger and bigger chunk of the budget is going to security. And so you have that threat of technical debt that you’re building up plus the opportunity cost of the transformation that you’re not driving. Right. That problem still Exists and as the threats get bigger, you’re not going to cut security budget. Right. And that’s why I was thinking, is it a separate org, is it funded differently through the organization?
Sanjog Aul [00:47:56]:
So this is actually. Yeah, go ahead, Rob. I think this is a great segue for the topic that you brought up. Right, the tech debt.
Rob Zelinka [00:48:04]:
Yeah. So two years ago we changed the organizational structure. The organization under the CIO was upwards of 1,000 people. It was massive and we just couldn’t move fast. We could not move even efficiently. We structured all of the security related team members under the direction of the CISO. The CISO then created an office of the CISO model, just like I created an office of the CIO and the CTO created an office of the CTO. Now it’s more of a divide and conquer.
Rob Zelinka [00:48:44]:
Two years later, my organization is about 525 people. So roughly 50% reduction in resources that have moved to other parts of the organization. So you can have focus, you have a fighting chance. James talked about patching. Our product groups reside within the business units. They take on IT operations functions. So they have a duty and obligation, a responsibility for patching. It’s critically important.
Rob Zelinka [00:49:16]:
All of these things cost money. So when we say no to something, I want our corporate leadership team and in many cases our board of directors to understand what we’re saying no to, but more importantly, what we might be saying yes to. So for instance, if we’ve decided to push more investment into our cybersecurity efforts, which might be the right thing at that moment in time, then we may have to accept a greater level of risk in some of our data centers. Instead of refreshing the critical infrastructure, the generators, the UPSs, the air handlers, we may decide we can roll the dice and maybe get another year out of them. And sometimes when you roll the dice, it comes up in your favor, sometimes it doesn’t. And all of those are risks. It’s all about risk management for us. And before, I don’t know that the company really understood what they were saying yes or no to because we just trusted the person that was the leader of the technology function to just make it happen behind the scenes.
Rob Zelinka [00:50:22]:
We can’t make it happen behind the scenes anymore. We have to do it in partnership with our peers on the other side of the wall, in this case, the lines of business.
Sanjog Aul [00:50:33]:
Now this is good input. So now coming to your own challenge that you mentioned, if I remember correctly, the tech debt and so many things that you’re dealing with and living with. So have you tried to Come down with a vengeance to say, I’m going to clean the house. What are you doing? So that we don’t talk about this problem a year from now, hopefully.
Rob Zelinka [00:50:53]:
Yeah, it’s a fantastic question. So the short answer is this. Jack Henry is an extremely conservative company. Our customers like that. We’re conservative. It’s more important for us to move in the right direction than for us to move quickly and move in the wrong direction. And so maybe we’re just a tad bit more deliberate. But once we work together to sort out where we’re going, we end up getting where we need to go to the technical debt component specifically, we are going to have environments, technologies that are long in the tooth, maybe even approaching obsolescence or end of life, end of support.
Rob Zelinka [00:51:37]:
And those are just going to have to be part of our risk portfolio, whether we want them to, to or not, simply because we don’t have the resources to tackle everything all at once to continue to keep the lights on in our current business while driving transformational change. We’re doing that in parallel, and we can’t do it all, no matter how good we are, no matter how many people you throw at it, you’ve got to put a line in the sand and say, this is above the line. This is below the line.
Sanjog Aul [00:52:04]:
So just because you draw a line, and this is a question for all the panelists, almost everyone today is having these kind of technical debts, and there are some inherent risks. Are you able to go to your business and say, hey, show me the money. I will take a million dollars from you, try to secure the Ford the best I can, but I also would request you not mandate or come up with some better, stronger words to say get rid of this technical debt. Because it’s almost like introducing a bug in the system. Are we not able to muster the courage? Are we not able to get them to budge? Why is this technical debt, which specifically is creating vulnerability, is not being handled with force and. Or with conviction that if you reduce, you are improving the risk, not risk tolerance, but the ability for us to be able to handle risk.
James Johnson [00:52:59]:
So I think we have to look.
Scott Hicar [00:53:01]:
For when we’re sort of the opposite direction because we got a really good relationship with operations. They’re actually. We’re actually helping. I mean, they want to refresh their equipment, put new capital in place. Right. It’s just a constraint on the business model of how much capital we can, you know, we can pour into the business every year. But they. We’ve actually been helpful to their case and helpful in Their prioritizations to say, you know, of this, of this sort of portfolio of things we want to invest in.
Scott Hicar [00:53:27]:
Here are the ones we think where we get the biggest cyber bang for the buck in terms of age or no longer supported or untouchable. And that’s actually helped our conversation as a company to invest our capital as wisely as we can. Knowing that sort of cyber risk mitigation is actually one of the considerations for how we prioritize our capital. So I think there’s, there’s ways to use a negative as a positive in terms of managing, you know, helping. You’re getting a win out of IT in terms of retiring old equipment, tech debt, but you’re also kind of helping the business spend money on money as efficiently as possible.
Sanjog Aul [00:54:00]:
James, you had a question?
James Johnson [00:54:02]:
I just think you have to look for win wins, right? And so it’s a great partnership between security and IT and John Deere. And from my standpoint, we leverage things. Like going to MFA was a good example of this, getting rid of some really old identity technology. And we basically burned down 1300 applications and the number of apps that survive that because people are like, have to go update the code or I can get rid of this, right? And a lot of folks made the decision that you don’t need this code anymore, let’s get rid of this application. And so I think if we can look for those opportunities for identity management, I think Zero Trust is going to be a good example too, of we need to kind of re architect or rethink about how we’re doing this and what are those big technologies, those big tools, those big processes we put in place that we can use to pivot and address as we’re rolling out something cool around Zero Trust or updating our identity solutions as a company. So we’ve tried to find those win wins, at least to John Dean.
Sanjog Aul [00:55:01]:
So one last statutory question, which I always like to ask, because we discussed a bunch of different things, right? What would you do in your position as a leader, you’re a security leader, IT leader, or a combination of the two, to fix something in yourself as a leader, quote, unquote, your leadership style, mindset, activities, actions, whatever that you do as a leader, which you feel would have a direct positive impact in your ability to help the business build resilience against the digital disruptions and tackle the uncertainties that are looming. Whosoever wants to go first, go first and don’t repeat what you’re going to fix in yourself.
Rob Zelinka [00:55:51]:
I need to do a better job of Understanding our business, that we’re in financial services. I’ve only been in it for four years and I’m still learning and it’s evolving and changing rapidly. So I really need to carve out a significant portion of my time to those efforts.
Sanjog Aul [00:56:10]:
Okay, who’s next?
Anu Varma [00:56:16]:
Apparently nothing to fix. No. I would say for me, I’m coming at it from a lens of security. And what I really need to solve for is how am I there for the business, for the innovation that they want to do. Right. And keeping that open dialogue so that they’re sharing with us what they’re doing and what they’re going after. And how do I become present for that. That dialogue? Right.
Anu Varma [00:56:46]:
Because then it’s preventative rather than reactive on the back end.
Sanjog Aul [00:56:50]:
So this is, you’re saying as an institution, you would do with all your reportees and everyone or you as an individual.
Anu Varma [00:56:57]:
Yeah. You know, one of the things that we’ve done is stop calling it shadow it. We call it bim it, which one of our security people came up with, which is business implemented and managed it. Stop calling it shadow it. It’s not derogatory word. Right. Give it a name, give it a reality that it lives in and give it a space. And then listen to it.
Anu Varma [00:57:17]:
Right. And understand why is it that they’re.
Sanjog Aul [00:57:19]:
Doing those things in this particular thing you’re going to be suggesting all your people to do, plus you also would want to do more of it.
Anu Varma [00:57:27]:
Oh, that. Yeah.
James Johnson [00:57:29]:
Yeah.
Sanjog Aul [00:57:29]:
Okay. Got it. All righty, Scott. Oh, so James, go ahead.
James Johnson [00:57:34]:
That’s fine. I think for me, it’s just, you know, I spend a lot of time on the IT side, a lot of time running through incidents. If you ask my team this question, where should James improve? It would be a very long list of things where James. But for me, it’s about listening and finding those landing zones. Where are our customers? Where’s our business going to be in the next three to five years? It’s usually too late to make an adjustment or to adapt. And so how do we find those? By talking to the business sooner, painting a better picture of where we’re going to be so we can get the right things deployed and the right tech capabilities also I think built within our teams.
Sanjog Aul [00:58:08]:
So are you working towards sensing that better or to actually have that candid conversation, closed door or open door to see, okay, where are you guys going? And then you will extrapolate or you going to lead the charge and say, we can tell you where the business is going.
James Johnson [00:58:23]:
It’s more about Listening, meeting with business leaders more often. Different leaders, too, Marketing, hr, places that maybe we don’t always talk to every day from a security standpoint, making sure you understand where they’re going.
Sanjog Aul [00:58:35]:
Got it, Got it.
Scott Hicar [00:58:37]:
Okay, Scott, for us, 2022, a couple things. One, on the inside, it’s operational tempo, right? We spent a lot of time investing, refreshing our infrastructure, capabilities and capacities. And so we’re coming through that phase as a company and now we’re really into kind of can we operate it well, you know, how can we run the Dr. Playbooks and how can we run the interest response? And how do we kind of get the team better at using all the tools and technology we have, given the, you know, given. There’s just a lot going on on the outside. It’s really being, extending our value proposition through our customers because our, you know, we’re a service company. We build electronic products for our customers. And so it’s been interesting over the last two years just to see how much, how interested they are in our resiliency and our capability.
Scott Hicar [00:59:25]:
And so we’re, you know, we’ve been getting surveys, we’re getting conversations. And so for 2022, we want to put more structure into that to start building, you know, we want our company to be viewed as a trusted partner because we’re making investments on behalf of not only keeping our company safe, but that actually keeps our customer supply chain safe as well. So we’re going to be spending time next year extending this as part of our core value proposition. Really, it’s part of why you do business with us.
Sanjog Aul [00:59:49]:
Great. What a great conversation. Thanks so much, all of you. James Johnson, Anu Verma, Scott Hacker, and Rob Zelinka, thanks so much for being our panelists and Everbridge for being our sponsor and absolutely thrilled to have all the people who attended and will be consuming this content after the fact and, and please share your feedback on the survey that will pop up once you exit the webinar. So thank you so much. We will be in touch and keep doing the good work.
Scott Hicar [01:00:16]:
Thanks for having me.
Sanjog Aul [01:00:16]:
Take care. All right, take care. Bye.


