Dive into supply chain resilience with Interos and ServiceNow
so if everybody's ready to go we'll get get this kick started um we've got about a half hour here so um hello and welcome to today's edition of the servicenow ask the expert series my name is roz morville and i'm a product marketing manager in risk and compliance for servicenow in this session we're going to dive into supply chain resilience and we're going to learn about a new integration from our partner ontarios and how actionable insights the risk intelligence and continuous monitoring capabilities can be realized in your own vendor risk program this can make you help you make better supplier decisions through broader and deeper insights into your suppliers financial operational esg geopolitical restrictions and regulations and cyber risk and we're planning on going for about 30 minutes as i said and before i introduce you to the speakers just let me remind you of some of the upcoming sessions that you can register for so throughout march and into april uh if you want to just progress the next slide we've got a few uh risk topics that we're going to allow you to choose from and we're really excited to bring you some new sessions on policy and compliance management risk management privacy and another session in a few weeks on vendor risk management specifically and you can register for all of these sessions in the servicenow community shortly they'll be coming up there and you can just search for the sessions and we'd be happy to have you join those as well and with that i'll introduce our speakers um so many of you may be familiar with jorge jorge garcia has been in the security and risk space for several years he served in a variety of roles with a large array of clients providing security identity third party risk operational risk solutions to his customers and as one of the really early adopters of soar tools um jorge strongly believes that workflow can be embedded in all aspects of security and risk to help you reduce attack vectors and mitigate risks faster and he's really been succeeding to that end as the principal product manager here at servicenow for our brm products so welcome jorge and joining us from antaros are um robin karen and david taylor david is the senior director of strategic solutions for interos and in this role he leads the company in solutions consulting business intelligence and i.t strategy robin is the vice president of alliances for ontario's and he's mainly responsible for arteriosus sorry in terraces uh channels and alliances globally and he has the mandate to create great value for our mutual clients so i'm delighted to pass this to robin who's going to dig in and talk about interos and tell us what they bring to the market so robin if you want to take it away thank you roz um thank you everybody on the call um quick kick off here about the company first actually thank you servicenow for being our customer uh thank you servicenow for being our vendor our supplier um our go-to-market partner and our investor so we've got the full suite of possible relationships there past couple of years i suppose even the past couple of months you can't be awake without seeing various dimensions of risk whether that being a global pandemic that seems to be resurging in certain parts of the world right now or or cyber attacks or obviously geopolitical unrest so the need for visibility into the resilience of the supply chain i think is it's a home point that we we need to be able to anticipate and then mitigate risk next slide so how do we help so uh jennifer bessegli our founder and ceo started in tyros in 2005 overnight success first 14 years was a consulting company helping the u.s government understand supply chain resilience during those 14 years people were performing searches and research and analysis to understand discover and ultimately define the taxonomy of risk that now since 2018 when we had an investment from kleiner perkins we've translated human effort into technology using artificial intelligence and machine learning data based on the data set created by the humans in those consulting engagements and now the platform is performing those same features and capabilities to find areas that infer risk next last slide so what do we do well using ai we map the supply chains of the world the relationships between companies the buyer supplier relationship not limited to also competitors uh investors russian oligarchs that buy a chunk of a company that you need to know about for restricted parties and sanctions so we're mapping relationships today around 350 million companies are mapped in our relationship graph two we monitor all and every one of those entities across as ros said a holistic view of risk across six pillars david will show you more details and we provide therefore the platform to monitor and model what if this happened where is their concentration where is their risk and what can i do about it and ultimately the integration with servicenow allows you to do something about it so we're a platform of insights that with integration to servicenow allows us to have action taken through the workflow through configuration and mapping into controls that ultimately you can mitigate and do something about the risks that the interiors platform provides relationships monitor on a continuous basis and integrate with servicenow to take action that's it from me over to jorge thank you robin and thank you everyone for attending so there's two trends that we're seeing in the market from a servicenow perspective um amongst you know various number of ones but um one is a reliance on content providers or risk intelligence feeds to start automating the process of understanding and ultimately mitigating risk within your supply chain and then the second that we're seeing is a broader risk landscape where in the past or historically our customers were um assessing and trying to understand informational security risk they are broadening that to understand esg uh resiliency geopolitical reputational financial and so what this integration does to us servicenow and to our customers and why it's so exciting is because rather than having to integrate and go out and try to find six different companies that give you these risk factors by this you know through this integration we actually make it easy on me right because i only deal with one partner but it also makes it easier on our customers to make sure that we can incorporate all of these different data points through your third-party risk management process right and so if you are solely interested in cyber but are growing your program to now incorporate financial risk then this is a great opportunity for you to uh before a great starting point for you to be able to do those things the third threat and something that you'll see from this partnership in the future and something that makes me excited is the fact that there's also a need to understand concentration risk as well as your overall more holistic supply chain risk right and mapping that supply chain is a large undertaking that most of our customers just don't have a good grasp on right they have a good grasp on their third parties they have somewhat of a grasp on their fourth parties but once you go beyond that it is very very difficult to manage um and even identify who those vendors and who those suppliers are and so through this partnership and through the ability of mapping the tiers to our supplier records or company records or vendor records we will provide with um visibility into concentration risk we'll provide visibility to resiliency right because if one of your vendors in your supply chain goes down how would that impact you and how would that impact your customers um and then as robin alluded to right if there's any geopolitical sanctions things of that nature would also provide visibility into it so this integration is and this partnership is extremely exciting and i think it's going to provide a lot of benefit to our customers um with that said david i'll pass it off to you just um great thanks jorge and i am quickly going to stop sharing and then re-share my screen very good everybody should be able to see a dashboard page um first off i want to kind of talk a little bit about enteros what it is that we do to kind of layer in on what robin said and also highlight some of the capabilities uh within the platform and how that ties into action within servicenow and really springs boards that automation what you're viewing here is a demo sandbox of my environment and uh to robin's point around mapping monitoring and modeling the overall supply chain our customers provide us their direct tier ones third parties that's what you'll reference here at the tier one table over on the kind of bottom left-hand side of that card by providing that information because enteros discovers relationships based off of publicly available data commercially available data data we buy to procure data that we pick up within the the news realm as well we're able then to take those tier one relationships so tier one equals third party and expand that based off of our database our data lake itself into tier two and tier three and that means fourth and fifth party so to jorge's point visibility down in the sub tiers are are typically very minimal in traditional standards but being able to leverage the data at our fingertips that enteros truly believes this as a big data problem that we're able to then highlight relationships in the sub tiers we score the ecosystem from a zero to 100 scale so you'll see here that this is a 71 and then you'll see that the higher the number the better so green red yellow green and then the lower number would be going towards that red risk we also in that middle card look at a multi-factor view of risk so not just cyber not just finance but we look at operations cyber esg geopolitical finance restrictions so the data we buy and procure from public domains applies to not only relationships identification but also to multi-factor risk assessment and i'll get into that methodology and ontology to kind of give you an idea of what that looks like now lastly over on the far right um our customers use us to segment and create groups whether it's by product line or line of business or program or whatever that might be so that then these can be filterable actions for me to ask questions of the data things like for this particular procurement process bid do i have any weak financial performers in the sub tiers or for this particular group of cloud hosting providers look out to the fourth and fifth party and see if anybody has a high cyber risk as an example this gives us situational awareness and visibility into the relationship so that we can proactively mitigate and work with servicenow to assess and automate around what that call to action will be now if i scroll down robin hit a really good point around the monitoring aspect so we we map we build out multi-factor risk assessments and we continuously monitor so not only from the public domain around data coming into the platform support relationships and multi-factor risk we also listen for key classifiers across all of our domains so that when a warehouse fire occurs or a cyber breed so ransomware attack a bankruptcy occurs in that public domain we're able to then pick that up append it to an entity and alert you to tell you hey in tier three there has been a cyber breach and this is how you're connected to it so that when our customers go look into the details of see the impact they can quickly go in and identify the risk concentration points and use that for action and mitigation we also pick up relationships on this as well so if we see announcements of partnerships or joint ventures or um you know dissolved relationships we picked this up in the public donor as domain as well and use that to append and round out our graph to identify those additional relationships now i want to pivot from this and actually jump into a profile screen of a supplier so i mentioned that tier 1 suppliers are third parties they're loaded into the system so let's just for for uh this use case talk about you know cisco is a supplier of a company running in terrorist as an example it's a third party for each one of these entities we actually score across multi-factor risk so here i can see that cisco is actually a tier one a tier two and tier three because as you can imagine it's hyper connected between other relationships of businesses as well and then we actually score across these various risk factors the way our scoring methodology works is it allows you to see the risk factor score 0 to 100 it coupled with the company i scores what's the overall score of this entity at any point i can jump into further details of as an example cyber for um cisco in this type of use and i can dive further into what we define as sub factors so what are we pulling in not only from a country level detail because oftentimes especially things like in operations and geopolitical country level information is very ripe to predict and show you risk that happens within regions typically not out there on the firm level but the when we're looking at cyber we also have the the firm level detail of things that we might get from like dns security or data loss or threat intelligence and as i go further in the details of this analysis of a vendor as it pertains to a particular risk factor i can get down to the most granular level of the attribute and see for each one of these attributes whether it's phishing sites or c2 server one of our you know premium support or premium models data sources here in this case is coming in and forming us from risk recon so that's an example of the way to be able to assess risk as it pertains to a particular factor but i can also do that across all of these factors dive further into country level risk and firm level detail as well now that's the that's the modeling piece the 0 to 100 what incorporates the the this from the source to the score that shows me visibility out at a particular supplier or vendor in question the next piece are the relationships again i'm just looking at one entity so i can actually start from that business itself and based off of the the graph database that enteros has look downstream who are their suppliers based off of what enteros knows that's available within the sources that we're procuring and i can see that as i scroll through each one of these vendors have different scores on them as well and i can jump into their profile pages just like i did with cisco and then i can even see two hops away as well and the connection between tier one and tier two where it becomes extremely powerful is when i'm able to even then take this to the next level where i can flip this around and say based off of this integration and view where um am i connected to entities and where is cisco within the tiers as pertains to my ecosystem so this is a tier one supplier again that means third party and if something were to occur how connected am i to cisco systems and through whom so now the days of asking an assessment of all vendors to fill out the same information i could get very hyper focused on through servicenow trigger action about this assessment for these types of for these vendors because i know relationships exist now that's one vendor that's one uh supplier in this ecosystem where we have thousands of tier one suppliers that then we want to map and extend relationships so then when i take this to another level and i look at things like geographic concentration i'm starting from the third parties so the tier ones and i can see here that i have 26 tier ones in this ecosystem and then if i begin to start layering in these these filters for further visibility i could say you know what based off those tier ones show me all the tier twos and then even more so show me all the tier threes and you'll see that based off that initial set of information i can see the footprint of my connections to businesses worldwide and the various different areas i might be concentrated within key regions of the world as we all know things going on within the region of ukraine uh today i'm able to quickly be able to jump in and see you know of my relationships out to the tier uh three level you know where am i connected into key areas of the world that might have particular uh conflict going on that could impact me or shutdowns that might occur because another wave of covid or operational dependencies based off of capacity limitations within region by doing this i'm able to then really get focused into key areas and key regions and i can even further refine this by the groups i've defined as well as key industries to focus on so that gives us some idea into geographic concentration and i can always get to a subset list of the suppliers that are within region now that's one way of showing geographic concentration and relationship interconnectivity another way of defining this is what we define as the relationship visualization what you're seeing here is a breakdown of tier 1 tier 2 tier 3 suppliers or then those each orbits kind of as they work out they're color coded based off of risk you can see over on the right hand side of the scale which we had it set on and right now i'm looking at the overall i score but i can focus just on finance or just on restrictions geopolitical or esg this allows me to get further into the details of key areas of risk but at this time what i'm asking is for the score across all of my relationships color code by risk also show me you know based off of the size of that node how many buyers and suppliers how many connections do i have to this particular entity now based off this high risk i then can select the entity itself and jump in and see that i am hyper connected through tier twos through tier ones back to me as an organization and dive once again just like i did for cisco into that supplier profile and see how i'm connected to this entity so this truly gives me visibility into the sub tiers to allow for streamlined visibility and proactive assessments assessments now being cognizant of time what does all this mean to take action upon well when i toggle over now to servicenow i'm able to identify the information that is being pulled in from enteros so not only looking at the overall dashboard of all the companies that through our connector with servicenow are being monitored and updated within the servicenow vrm module but then also jump into the key areas and key suppliers such as that cisco like we were defining and see exactly what enteros is saying about this entity itself the scores that are being used to rank them i actually can dive back into enteros by opening the enteros and deep linking back to the supplier page where i can then look at the sub tier visibility and events being monitored and what this really means next is all that information and all the data around risk and relationships and information that is at my fingertips i can then leverage it to create automation and workflow based off of these normalized scores that might be augmented with additional sources in the servicenow side and take action and proactively send assessments based off of this risk i'll pause there jorge would you like to chime in on anything i might have missed yeah so one thing that is important to note here is this only highlights what we called our classic ui but as some of you may be aware we've completely revamped our user interface and our user experience we've created user specific or persona driven workspaces and so if you are a vendorist manager you are a supplier relationship manager your procurement manager and you want to be able to ingest this information you can still do so from this view but we also have created as i said a persona-based workspace where much more modern and specifically addressing risk and supplier use cases very good thanks jorge robin i know you're monitoring the chat anything that we would like to to cover so we have does it contain vendors attestation reports like sock one and sock two i think that's probably a jorge answer more than us um yeah so so uh that's a question for entero so we we are looking at um how do we how are we able to get some of that information from other partners as well right um whether it's best practices questionnaires or certifications but um interrupts maybe that's a question for you as well yeah so we constantly you know procure data and identify information so as that pertains to things like cyber as a for instance we pull in information from risk recon so we saw that threat intelligence and that didn't fix identification at that point we're working on certifications that if they're published out there that we can append to an entity as well as part of our definition going forward if that was something that is stored as well as potentially even a certification on a vendor inside of servicenow we can obviously marry the two thank you yeah i was referring to the report itself so thank you will help second question is how many vendors uh we support today about 350 million companies um across 425 million company locations so your question is if we cannot find our supplier what should we do a i'm hoping it's pretty rare because there's not that many companies more than 350 million in the world of any size um but let us know if there's something that you don't find in the platform that's we have premium support and folks that uh that know how to solve that problem pretty well it's quite rare but if it happens we we will help you out then they were the two questions that we have one more here we go the question is i think there are questions about license things so didn't come up actually saw a couple of others as well um can i control what notifications i get based on the type of risk that's most important to my company yep yeah exactly so i highlighted a little bit about the event monitoring piece on that dashboard component but you can also subscribe to alerts and monitoring per domain based off of groups so exactly that i can create a group and say you know what these are cloud hosting providers i want to monitor this for cyber versus these are critical tier one suppliers that i want to monitor for uh financial solvency and bankruptcy and things along those lines so i can pick and choose through a preference center around what to monitor and how to consume those alerts and you're right robin there was an additional question about how much does it cost and i think that's a two-part press question for both of us to answer it it is um so i'll talk about interiors um it's obviously it's a licensed commercial platform it's a sas product we reside on aws um and effectively it's driven by the number of third parties that you wish to continuously monitor and score and integrate back to servicenow the integration pipe per se doesn't have a separate cost to it but you do license and of course you license service now as well i'll refer to roz on that yeah no problem uh i can just take this um it's available immediately for download for free as robin said in the servicenow store so um definitely um we're not putting additional cost just based on your licenses for each of the uh products and i should point out so we license based on the number of third parties the platform already has tens of hundreds of millions of fourth and fifth there's no license fee associated with the extended supply chain that's included but by virtue of having that visibility to the fourth and fifth parties and even beyond and i think falling on that train is there a way to research a new supplier that's not in my specific supply chain great question so you see the instance with your direct tier one suppliers or the third parties but we also have a search capability across all the 350 million that robin mentioned so i can quickly search i can sort by industry i can sort by country identify the exact entity i want and i can subscribe to that entity and add it to any group or ecosystem that i choose so ad hoc search as well as bulk loading of suppliers great so i think we can jump back to the slides if any more questions come in we can continue to answer those but we are coming up against our half hour so i want to make sure that i'm cognizant of respecting people's time today as well but there are some additional resources that we can put up there for you to link to if you're interested in learning more about specifically about risk about servicenow vrm obviously the community is a great place to go and we do post all of our ask the expert sessions on youtube so if you're interested in this or another session they're available on youtube as well so i think we can just if you as i said if you want to get started today um it's immediately available for download and if you need uh to contact in interos both the um general email contact for enteros is there for partners at enteros.ai or we were robin was kind enough to share his email address for any specific questions as well so thank you guys so much for joining us today thank you david robin jorge for the great session um really powerful solution and we really hope to see all of you again soon so thank you so much thank you thank you very much
https://www.youtube.com/watch?v=VMF5_mwmuEo