logo

NJP

Over buzzwords Real Talk Transformation & Automation

Import · Apr 20, 2021 · video

[Music] when embedding security and risk processes into digital transformation initiatives a common first step and a crucial first step for any cso is to ensure that security is top of mind we're all going through a digital transformation of some kind but what that means to you and your level of maturity and the timeline of your journey it differs from company to company digital transformation does not necessarily introduce more or less cyber risk but different types of risks for example if you're embracing public cloud do you have the expertise to leverage the large ecosystem of cloud native security capabilities are you focused on traditional risk or are you considering potential new risks whether you're lifting and shifting or building new cloud applications and workflows it's funny i spoke once with this this very large financial services institution and they were in the midst of this multi-year billion dollar digital transformation their security organization told me that they had all their cyber risks clearly defined understood button up and taken care of and so this kind of this had me paused because while you can plan ahead any level of change of that magnitude is going to introduce unknown factors and those unknown factors may well translate to different cyber risks and this is why i strongly believe that initial step of a digital transformation journey is to ensure that your security strategy aligns and supports it you can't transform without automation nor can you scale introduce efficiencies reduce costs long term and break down silos that are often some of the root causes that weren't a digital transformation in the first place for our security program servicenow all of those in the organization are enabled to seek out manual workflows and to destroy that is to automate and digitize wherever possible for an example to elevate our security analyst experience we try to make it as simple and fast as possible and we do this by using workflows for productivity gains such as automated phishing campaigns uh management of these phishing campaigns and reporting or effective automated assignment of vulnerabilities and or grouping of incident close codes and notes to reduce high rate false positives these type of examples have such tremendous impact on the operating efficiencies of a security program but it also reduces that manual repetitive work that provides little in the way of career advancement and job satisfaction for analysts a security organization that embraces automation at all angles is more effective but also a far happier organization than it would be otherwise as we accelerate into 2021 we ensure alignment with our company's business objectives the top three for servicenow is managing our customers service availability security and performance all of which are critical for our business and our brand and the trust that our customers have in us our first step is to ensure our security activities align to these three tenants and this is great for me as cso for servicenow to be successful security has to be successful as well and we have recognized that one of the best ways that we can protect our customer data is by using our own products wherever possible creating workflows to solve simple security problems and creating custom applications to address unique security challenges for example workflows to support the many frameworks and benchmarks that we have in place nist for continuous controls monitoring and automated evidence collection minor support for security operations bsim for application security integrations bug bounty work and much more given that we are service now our future plans are to workflow anything and everything if manual work exists it has the potential to be workflowed whether by us our industry partners and peers or even our competitors automation is the key to the future and a crucial focus for us to service now a great start is to go and check out our security bu roadmap and you'll see that continue to expand and grow and it's a direct influence and many cases a map of what is going on with the internal servicenow cso security organization you

View original source

https://www.youtube.com/watch?v=HztyN8fa2Q8