logo

NJP

Resilience now more important than ever?

Import · Apr 20, 2021 · video

[Music] our focus for 2020 even before the pandemic was to explore all avenues to turn the servicenow security organization into a well-oiled and efficient machine our investment has been less about headcount and more in doubling down on automation on scaling and identifying efficiencies and opportunities for efficiencies across our teams so what we did is we thoughtfully evaluated our most important internal partners such as i.t cloud development and others and examined our engagement models and associated roles and responsibilities so who are the decision makers and where can we leverage the power of our workflow engine in new ways to create improvements and automation to aid those decisions we also carefully examine our security products both those that were serviced now built but those from our partners and others and we ensured that our integrations between these products and our infrastructure were really tight and that we're utilizing these products to their full potential and spending a large portion of time with our security business unit to ensure that their roadmap will meet both the security needs of us and our customers over the next 12 months and beyond cyber resiliency is one of the most common topics for any security program this year security teams are being asked not only on their current preparedness capabilities but how those capabilities would stand up in an industry-wide cyber pandemic our priorities for 2021 are to continue to assess and improve our crisis response capabilities and partner with our customers to accelerate their program readiness as well as our own at a tactical level when we think about cyber resiliency at servicenow we're concerned about things like our employees being fished or spearfished the robustness of our backups single points of failure across our infrastructure the security posture of our vendors and how well common security principles like least privilege are adhered to this is a very common list and if you look at it like a checklist then it's going to become very lengthy very quickly mindset around security resiliency is the key to automate anything and everything to foster a continuous cycle of self-assessment so for example if you do have endpoint protection in place how do you know that it's truly effective until you have tested it in the same way as would an attacker consistency is also a foundation for preparedness which is why we look to our platform as a basis for everything we can we understand our platform we know it works and we have opportunities to create many resiliency-based workflows over the next 12 months an approach that we take and recommend to cyber resiliency especially in today's resource type climate is a few methods a good place to start is to get some of your smart people together and not just security people but technical leaders across your company and threaten all your business virtually wipe all your architecture and don't forget about including your customers and your partners think up some major cyber pandemic scenarios both industry-wide and possibilities that are targeted against your company directory and use these as use cases this will quickly identify those most important single points of failure those critical parts of your infrastructure and those legacy systems that you might often prefer to ignore then test your assumptions if you have a red team then use them if not find a credible vendor with actual hands-on experience prioritize the results and build out a resiliency remediation timeline assess these deliverables against your current portfolio of existing work if you do have a risk registry or a grc product compare the data between the two if it's different the perhaps your cyber priorities need to be reset with the resources that you currently have available and you can also always look to your partners and customers for validation for help and to share notes that's something that we do here at servicenow all the time [Music]

View original source

https://www.youtube.com/watch?v=sL-H4cHKMxo