logo

NJP

ServiceNow SecOps Mini-Series: Security Operations Suite | Share the Wealth

Import · Mar 11, 2022 · video

all right everybody go ahead and jump right in here i do apologize today uh today's topic and share the wealth is a little less develop on a little less in demo a little bit more slide where so we always enjoy that right so first and foremost welcome everybody let's take us through the uh road of servicenow security operations introducing it to you guys at a very high level and then throughout the share of the wealth so that we have scheduled every friday in january we're going to dive in and actually work through some of the sweet operations and sweet tools that we can use and i do mean that as sweet and sweet all right so if you haven't already noticed on every friday on your your agenda you do have a share of the wealth that is a suck ops miniseries uh we're going to cover today really give you the view of what it is and why it's there and what you're going to hear the customer problem statements and how servicenow looks to solve that from there we're going to take a deep dive into two of the main product lines within servicenow security operations suites throughout the next sessions and excitingly enough we're actually going to see a little bit of the world of eric's home environment and work through some security and vulnerability scenarios in eric's home lab and yes i do have some actual very critical vulnerabilities that we can work through and fix and i promise you they are real it's a little bit exciting or is the least exciting as security can be all right so in order to understand why servicenow's security operations we have to take a step back and we have to talk about security operations agnostically so uh the the first thing that i'll mention right is this is a uh knowing it's half the battle you're absolutely right appreciate that so you're going to hear the term secops as an abbreviation we've all seen kind of industry terms right buzzwords out there we've seen secops we were security operations we've seen devsecops we've seen devops we've seen all these little whatever you want to call it ops through cloud and cloud ops out there as well so what's important to understand is that within the idea of security operations or secops this was born from some folks out there in the security world who saw what devops was doing where uh we were really looking to bridge the gap between the development world and the daily operational world and said hey this looks like a great thing for security operations so why don't we start to leverage some of the tools that are out there and why don't we build these platf some sort of an orchestration or or a correlation platform that then lets us bridge all of this and make things better for the security world so the key thing to hone in on even though we'll talk about it in the world of service now and there is a product or a platform that goes with this um the real thing to realize is what's underneath that security operations really drives the collaboration of or seeks to drive the collaboration of right the security world where your security world on from the high to the low really focuses on how do we catch how do we prevent how do we detect and it really starts to lose focus it's very easy as a security practitioner to lose focus of the other side of the house okay we found an issue now we're tasking the operative people uh the the server owner asset owner except tasking them with going and fixing it but we've lost sight of how they're doing that so we look to bridge that gap and bring that whole world in we also look the one statement that you'll see here on this slide right very important statement the culture right the key thing is security operations is more than a platform a process it's a culture and with a lot of organizations even in 2020 2021 2022 even in the world that we see here and know of all the attacks and and data breaches even for those organizations it is a culture change and it's a hard change for a lot of people to make your security people are security they don't want to give that up your operations people do what they do best and they don't want to be told what to do so anytime we walk into an organization talking about security operations we are seeking to do much more than implement a tool in a process we're seeking to help change culture by doing so we have made the whole business now aware and we've made the problem the whole business's problem and to that end why so at t and ponemon put out a cost of data breach report for 2021 already this was published end of year um kind of in the the early december timeline and what this really points to is just some interestingly alarming numbers we would like to think as many times as we've heard all these breaches in the news we've heard all of these hey it can be fixed we can make it better we would like to think that we would start to see an improvement over time and then you factor in the pandemic and the move to remote we've been in that long enough that you would think that organizations would have been able to shift and cover their security needs for remote workforce they haven't and that's really a big deal right 2021 saw a total cost of breaches increased 10 over 2021 and we can imagine over time there as well one chart that i did not grab out of this report that was quite interesting is we actually saw a decreasing cost in 2019 right before pandemic so we think and feel like maybe we were headed on a little bit of a trend but as anything else in the operations and security world things change quickly right along with that another interesting stat of why we need a focus on security operations the full suite is that 38 of breach cost overall was in lost business so there's your financial driver right there yeah we can look at this chart and we can see you know that another 29 was cost of detecting and and escalating the response of those we can see that there's a cl a significant cleanup or post breach response cost to this as well but the largest driving cost was in the loss of business so obviously losing business is never a good thing for an organization and if a huge you know average of cost over that we want to look to tighten that up we also saw in 2021 44 of 21 2021 breaches uh did actually include a breach of customer identifying information pii being that of things like name address phone number uh location data consumer purchase data all the way down to actual financial data like bank account credit card identity theft related data and not only did 44 of those breaches contain that type of information but there was able to be put an average number of cost per each record so my data out there in the consumer breach world has an average record cost across the entire industry at 180 dollars per type of data my credit card number is worth 180 dollars to somebody my social security number is worth another 180 dollars and if we think about that for a moment the cost of my data now skyrockets obviously that's a high target asset somebody's really wanting that information and last but certainly not least in terms of the bad we saw an increase in time of identification and resolution of these breaches so what i wasn't able to detail out is uh there's actually a life cycle to each of these breaches we have the time in which it took to detect that it was occurring we have the time to time to identify how it's occurring where it's occurring we have the time to respond to that to shut it down etc and we'll see that as we get into some of the product offerings within servicenow that these have a face to them but if we take all of those phases and we take a look 2019 we we saw an average uh from point of action or point of occurrence to point of fixing and stopping the breach this is not the total time because we have post breach issues we have things like reporting the breach if you're in a regulated industry reporting out to uh investor psych investor stack we have things like importing uh or reporting out to healthcare organizations that continues on even beyond this 200 plus a day cycle the simple fact here is it's taking longer where we should be seeing the the data transformation the orchestration life cycles uh improving this we're not we we went from 279 days to the point of containing and stopping the breach to 287 days in 21 and i'm sure we can all surmise some of the reasons pandemic remote workforce etc interesting little stat that also gives us the why of security operations oops drop back here might be a little bit hard to see it's hard to scale some of these charts and images but if we look at this uh chart in the lower right hand corner as well we can see a time period versus cost to high low and average regulated industries and what we see across the board is regulation equals uh increased attention in data health care phenoms uh some of those types of industries that have a higher level of regulation they're regulated for a reason and the bad actors want that data as well so your high and low regulation industries see a very high burden of cost right at the beginning of that breach zero to three months three to six months and six to nine months so if we talk about that first nine months of breach life cycle a very large burden of cost is seen in that and then we we start to see an increase also the longer this goes so we can very quickly surmise and see time time time time and time the sooner we can identify and fix the sooner we can if breach occurs the sooner we can eliminate our cost or reduce cool so i gave you the bad news everything is getting worse we're seeing more breach we're seeing higher cost of reach higher complexity of breach how do we look what and what were some of the things that industries across the board did that helped us reduce those zero trust a big buzzword a lot that we could talk about in what xero trust really is it's a very security minded trust no one multi-factor or some of those architectural things so about 1.6 million um reduction in average life uh life cost of a breach but the one big number that is really where and why we talk about security operations as a process and as a platform in service now is this one right here adding ai and automation controls reduced costs for industries that had well-built automation controls by 80 or more average of 80 this is security automation this is servicenow and interestingly enough when we start after we've reviewed the why and we start to see what servicenow offers we'll see that one of the things that servicenow helps us do is frame our process around incident response and vulnerability remediation so at t and ponemon found if we take a look for those organizations out there that have an incident response plan and tested it we can see those that have this all the way over here on the right obviously our actual highest cost in breach cost neither uh these organizations in this realm had no incident response team had no plan and had not tested the plan best of scenario here and if we take a look 1920 and 21 we see with no plan our costs are rising with plans our costs are decreasing as we make those processes more efficient so we can see the bad and we can see the good having a plan knowing what's going on in your environment and having a plan for being able to reduce this life cycle helps us reduce costs significantly and helps us reduce our complexity significantly so why is this a problem i know powerpoint animations are so 1990s but i have to we can see as that as that graphic builds and this is a very very very small slice of the tool set there are many tools there still even today are a ton of tools out there that do security and they all do something well tools like splunk tanium firewalls that are out there um you know checkpoint firewall carbon black they all do one slice of the security stack very well taken point right carbon black is a great endpoint detection tool it's it's on all of our our mobile devices laptops etc and it reports back with bad things that happened to the laptop but it doesn't tell us about the rest of the infrastructure so that's where things like palo alto checkpoint cisco etc come in but the complexity of this each of these are specialized each of these have their own method way of alerting prioritizing and causing action it's a lot of noise and because each of these are very specialized each of these tend to target towards the security teams not those that fix stuff and i can tell you from living in that world as an operations specialist i didn't like when a security person came to me and told me something i did was wrong i didn't like it at all and as we add this stack each of these does something well but it does its own little thing in its own little silo we tend to add a complexity of time and again as we saw time of resolution is increasing and that's not good and then we can also get the sensor this starts to leave out our operation stack again those that fix it so i'm a security specialist and i'm implementing carbon black in our environment carbon black root you know alerts that there's a virus on a laptop or a potential bad link that has been introduced or clicked where is that alert go nine times out of ten in an organization that's going to the person that deployed the tool or the group or or you know the group or business unit that's responsible for that tool and in a budget and finance world that's security so we've already just siloed our environment so a lot of noise servicenow now comes in starts to organize categorize group and ultimately integrate all of these different tools into the servicenow stack allowing us to make action quickly on it we're all service now we all understand the benefits of servicenow so i don't necessarily have to go into all the benefits of workflows automations uh cmdb integration which is very key to the secops platform but we very quickly see that what does this let us do every arrow in here is pointing to servicenow we take all of that noise we funnel it into the business intelligence tool factor of servicenow and we do stuff with it all right so we've arrived we've talked about security operations bridging the gap between the security world and the operations world we've talked about the fact that all of these organizations out there are struggling with a lot of noise and a lot of tools and each tool does something very well but it leaves the rest out so now let's talk about servicenow it's what we're all here for anyways so servicenow stack if we've seen the newer latest greatest way of marketing the platform right we're a platform of platforms and across that from a marketing perspective we service now has started to group these into four main workflow segments of the platform it employee customer and creator security operations falls within the itworkflow world and offers these particular tools graphic here intentionally designed by what we tend to see the most so the three main pieces sir security incident response vulnerability response and then the up and coming of configuration compliance all of these interact with each other and with the platform as a whole in a variety of ways we'll see that on our journey this month but the key to hone in on is that these are all under this premise or industry concept of soar soar is a term that if we look back at all the slide where we've gone through so far and we've talked about all of the complexity all of the noise and yet all of the benefit of orchestration and automation that's exactly what the sore premise or concept is security automation orchestration and response now i want to take a moment and hone in on these terms we all know what security is but automation orchestration and response in the security world is not the technical of it yes we can leverage tools and platform to automate yes we can leverage tools and processes to orchestrate however in the security world as stanley has has very nicely mentioned in our our chat right knowing is half of the battle soar seeks to provide knowledge that the premise here is providing a place not many places but a single place to go and look providing the information right out front to me and letting me or a process resolve and remediate quicker so within our security stack our operations suite stack welcome to mouseware 101 there within our our stack the three main products that are offered or tend to be interacted with incident response vulnerability response integration compliance and then we have the way we do it we have the ability to leverage event management a bridge over to the itoms stack utilizing the internet management engine that's underneath all of this to help us correlate the noise if needed we have the ability to leverage solution management within vulnerability to help us know how to fix quicker and then we have the idea of red intelligence where we can bring in preventative knowledge and data feeds all of this is built on a stack of none of this is any good if we can't bring the data in and if we can't visualize it so we also have some excellent content packs built for performance analytics as well as some pre-built integration bundles throughout some strategic partnerships all right so we talked about here the platform the product and the parts of the platform all of those are what seek to utilize security operations within service now to make it everybody makes security everybody's problem so the next few slides are intents they're intense because that's what security is what we can start to see within each theme of our product driven right into our center line here security incident vulnerability and configuration compliance is a very wide reaching interaction we know that service now has interaction across many points or business units within the organization right we can talk about configuration we can talk about asset we can talk about you know incident or the itsm stack etc all of that interacted with here but our key key and core concept is that we allow security vulnerability to respect all of those others interact with all of those others complement all of those other all of those others so that we get a quicker response and you'll notice here right all of our slidewear so far all of the what is secops why is it what is cost is all driven around the fact that there could be a breach so our security operation stacks centers around security incident and incident response where all of these others feed that data and i think that's how that's key to understanding what is security operations and service now yes we can we can sell and deploy vulnerability response by itself yes we can sell and deploy configuration compliance by itself or security incident by itself but truly when we go back and we look at all of those cost and reduction of cost if we don't have the stack or at least a view and roadmap of the stack as a whole we're going to struggle to show a customer and show a business where they're really saving money and i absolutely promise you over the next uh next three sessions we will get into each of these and we will see what these really do for us so we take a look at each of these parts um we start to talk about again honing really in on security incident response right and we start to see that we leverage process what is a security incident a security incident is what we hear in the world as a breach however a security incident does not actually have to have been a breach i lost my password i think my password was compromised we know it never happens we never find any users in the operations world that have their their password tucked under a keyboard my data has been compromised it can be all of those um automated tool sets splunk crowdstrike when you talk about carbon black that do all of the detection all of those are incidents the mere fact that we see as a maybe healthcare organization we're seeing a targeted attack whether it breaches or not on a specific health care application we may have is an incident so we have an opportunity here to leverage the other parts of our platform that we talk about risk management vulnerability threat etc to determine the process of making that a not breach incident in the event that it does breach we also have playbooks that we can work on and processes that we build much like you will see in your standard incident world to move these through quickly and efficiently so i think the key here and the reason why we talk about security incident first is because that's where our cost really comes in that is our threat to our organization that is what we try to avoid but it's also what we want to know about no organization is immune not even your home network not to raise alarms and not to make everybody run and put their tin foil hats on but the fact of the matter is i can sit here and scan my own or have these types of tools here at home and see port scans attempts to connect attempts for remote execution of code even on my own personal home internet link with low bandwidth nobody is immune to that attack so it is important to provide visibility and it's important to provide planning and response and we'll notice here the blowout of security incident the real driving factor is the response once we have identified through the integration processes how are we responding we're going to be able to take feeds and tell you based on these feeds how many other incidents in our environment have we see this ip address this port scan this targeted asset we can see the external of that as well for healthcare we can subscribe to healthcare data feeds that now tell us how many other healthcare organizations is this us or is this healthcare as a whole and therefore how do we respond we can also feed vulnerability response into this where now when we talk about security incident we talk about something happening actively against or in our environment vulnerability response is now seeking to prevent those from being exploited vulnerabilities are not necessarily incidents and they're not necessarily breaches because there's not necessarily always an activity against it a great example of that is the print nightmare vulnerability of early 2020. print nightmare was a case specific to microsoft and it was a case where there was a weakness an improper configuration or code base in the windows print spooler environment that allows uh somebody to inject code and take controlling command of your environment or your windows devices when it was published there was no known active attack against that vulnerability so it was not a security incident so if we can identify that we can patch that very quickly we can prevent the incident from even being taking place or the risk of it being scanned for and tried against in our environment that's vulnerability how do we deal with vulnerabilities because vulnerabilities are the proactive preventative steps the very very first thing and i cannot stress this enough is vulnerabilities are against or on assets because vulnerabilities are on or against assets we have to know about assets and yes for all those configuration people in the world i am saying the term asset we can have an asset that is not directly connected to our environment that we are not 100 in control of and therefore it is not a configuration item directly in our environment we've seen that case in many to many times in the security and vulnerability world where supply chain management we bought a server we set it on the shelf because we're going to implement it in the last half of the year if we don't maintain visibility of that asset not yet deployed in our warehouse and we don't realize that the moment we turn it on we're six months out of date on firmware and somebody doesn't go through a firmware update process before they connect it to a network we've introduced an active vulnerability in our environment so asset there is a there is a method and mode technically in deploying this for relating asset to configuration item but ultimately we scan for asset and build inventory through asset management and discovery or other cmdb population tools once we have that cmdb built or at least in a modern method of known and and somewhat stacked together we are now taking a tool set that will now scan our environment qualis rapid7 a vulnerability scanner and allowing it to do just that much like discovery with servicenow scans our environment and tells us something about the device that is out there those other tools scan the environment and tell us even more about the device that is out there so we're now going to build a library of the weaknesses we know of when i say print nightmare when i say log for shell or log4j when i say java memory buffer overrun adobe pdf uh the adobe pdf protocol started to have some some there for a while right all of these are the definitional vulnerability we're going to build that library so we know what it is how severe it is then we're going to build the resulting is it in our environment and we're going to build a response process for fixing that as we can see we're relying on very top step cmdd cmdb cmdb cmdb discovery information about our devices it's important to have that when we talk vulnerability it's important somewhat in security incident as well but it's important to have that when we talk about vulnerability especially because we rely on that to do several things risk rating we rely on that to tell us who owns the device or at least we try to we know in the configuration world that can be a challenge for organizations but if we can get ownership and a picture of the device the vulnerability is on that much more quickly we can automate the assignment and tasking of fixing these so once we've built all of that and we start to actually fix our our stuff we had do have scenarios where log4shell print nightmare then became exploitable and in our environment somebody was able to exploit that or try so now we have the ability to move that over into the security incident world or we have the ability to move that into fixing via our change management process and we can see very quickly just between security incident and vulnerability leveraging the servicenow stack cmdb change uh you know asset information ownership information we can see efficiency already right there so if we go back and we remember in our product stack what's what servicenow secops is we've talked about security incident vulnerability but now we're going to talk about a couple of augmenting pieces threat intelligence is a piece of the platform that augments security incident and it can also help us in the vulnerability world threat intelligence feeds threat intelligence tools out there will populate known honeypots known bad actors things like the the virus total tool or the classic have i been pwned i can go out to have i been pwned and put my email address in there and see that i my personal email address has been a part of many large-scale data breaches so i probably need to be aware of that that is threat intelligence in a very simplistic level there are integrations and tool sets that will allow us to bring those types of data feeds in and correlate that with the data that's on a security incident or vulnerability and now when our analysts are taking a look at this and resolving it much like we think about in the standard itsm incident world the first thing that we're looking at is is what is the device what's going on with it what do i need to do about it so we're providing some enriching data what is the device what do i do about it what's being done to it is it is it a bad thing is this malware is this malicious is this exploitable we can do that in a somewhat automated fashion to allow very quick response instead of asking our security analyst to go back to one of those slides and checking eight different tools so we're going to take all of that and we're going to feed that into our security incident and allow us to see that quicker and then the last piece that i do want to talk about is a very new very new it technically has been part of the module for a while but very new in interest is our configuration compliance module configuration compliance module several of our our security tools um especially when we talk vulnerability tools qualis rapid seven tenable are starting to introduce this concept of being able to gold standard scan we're going to build a policy that's within that tool not servicenow yet that says you know when we connect and we identify that this is a windows desktop as opposed to server operating system we have a set of standard configuration points that we need to ensure are on this device to help keep them safe and secure must have antivirus must have endpoint detection tool must have most recent patch right so those are policies we define within the the scanning toolset to tell us that this device is or is not compliant with our security and safety image standard we're going to return those much like we return the results of a security or vulnerability scan and we're going to correlate and be able to do some actions on it this is a unique piece because it very easily bridges between the security operations world because our security tools are what know about have the signature of and know the compliance factor and the irm world or grc world where all of those things that i just mentioned must have antivirus must have endpoint detection must be up to date are also part of a controlled program that are in our policy and compliance module as well so we'll see a very quick idea here that this allows us to bridge the gap now to not only are we measuring our security posture but now we can start to relate this to and measure this within our risk and compliance framework as well all right head spinning a lot to take in there's a lot of complexity and a lot of puzzle pieces and a lot of things that we can do at a very high level with secops within servicenow and remember all of this is really sought out as part of that soar you know orchestrate automate and respond program so all of this each of these puzzle pieces really drive down to this slide we drive to simplify we drive to automate orchestrate and we drive to respond faster each of these pieces security incident vulnerability response configuration compliance in and of themselves are very complex if we go back and look at each one of those slides a lot of parts a lot of things to consider well we can really put it down into this flow and simplify it with how do we get the customer to this how do we get them to utilizing this and benefiting from it service awareness step one being aware of what's in your environment having that cataloged so to speak in your asset and configuration world in servicenow integrating with all of those tools many of these have plug-ins already either built by service now or built by vendor some of them may not but the great thing is the power of the platform very cliche term but we have so many different ways that we can bring that data in in a standardized fashion whether that's through you know direct rest integration whether that's through data feeds inbound email all the above we have a way to bring that data in so now we're going to take all of that data and we're going to correlate and prioritize that through through again both each of these tools and the platform already within configuration management or cmdb we can already provide the idea of this is a riskier asset because it's external this is a less risky asset because it's internal and has controls around it certain ip segments at certain locations right very um very configuration driven very asset and inventory driven there but then we can also take the data that we're bringing in from all of these security tools log4j caught attention it was a very easily exploited and very quickly exploited vulnerability so it was a very severe vulnerability however in the security world there was one very easy fix to that any of your devices that had no internet exposure or external exposure had a much much much lower risk so log4j very widespread the the the logging light the the logging library that was vulnerable was used in a lot of products and platforms so industry as a whole started screaming and going we've got a lot to fix using this method this asset is inside this asset is siloed within a certain security environment i don't need to fix that yet because i've got worse things to fix so we know about the the asset device ci we know about the severity of the security world we take all of that we prioritize it and we provide some additional data on what is the rest of the world seeing is this really that bad and then we allow a response plan and if you remember in the uh at t and pokemon report for 21 80 reduction in breach cost and then underneath that a huge reduction in breach risk by having a response plan so just like we can do in much of the other response and task driven state-driven processes within servicenow like incident and change we build out a state process we build out a response plan and we govern the tool set to force that plan to take place and we can also start to bring in automation and orchestration we can now that we know what the tool is now that we have a higher confidence level of what the the risk is and we have a higher confidence level of who owns it who fixes it what the devices that needs fixed we can now put some confidence behind automating that deployment of fix this can be something as easy as turn off a firewall rule turn off access to public side of the world right so we can orcas we can integrate with your palo alto firewalls your cisco stacks and say adjust this security rule or put a security rule in whitelist blacklists etc but you'll notice that that's step six not step two or three the complexities within your customer basis they're going to hear that buzz word of ai automate orchestrate and they're gonna want that early right we can't and we don't want to because if they don't have a confidence in their data if they don't have a confidence in informing and governing their response they're probably improperly fixing and by improperly automating the fix they may be introducing worse things if i blacklist an ip address in the wrong place i might actually shut down my business and then as with everything if we can't see what we're doing and we can't see how we're doing none of this helps the business see value and so we provide operational health security posture reports dashboards performance analytics in that as well all right so this is where it all drives to this is the servicenow plan for security operations providing visibility integrating with the tool correlating and orchestrating all of that noise getting down to a single driven record of action across any of these types of events incidents or vulnerabilities and governing the response of that thank you for uh watching my fun powerpoint slideware not a lot of real exciting stuff but you've now been introduced to the world of security operations and servicenow and the ideas and pain points of why we look to utilize this tool set to help improve our customers lives and help make it a problem across the board so with that in the remaining time we have the first thing i'll say before i open up the florida questions is it gets more exciting from here our next three sessions will dive into seeing how to bring in that data how to correlate and cut down all of our noise because it's a lot a little sneak peek just in 50 assets or devices within my home lab environment scanning just those 50 i return and and not authenticated scan right so think about that that's the real world nobody knows my user or password or way to connect i scanned without providing credentials and i returned just under 300 vulnerabilities at home i believe two or three of those were critical and exploitable so we're going to take a look at that data we're going to take a look at all of that noise 50 assets 300 vulnerabilities let's explode that to a large enterprise that has 20 000 servers and let's walk through the life cycle of a security incident of vulnerability and how we can resolve those things very quickly and we're actually going to resolve one in my environment so it gets it gets more fun and much more interactive in the days to come so appreciate it appreciate everybody hanging in there and listening to this any questions on what we've seen and what we've talked about today hey eric that was wonderful i got a question about trusted security circles like how is that really used i'm still kind of unclear on it the only thing i've heard from servicenow is that not many people participate in it and that's all i know and that's really true um we're actually working with a customer right now that has the that that's debating whether they're they would benefit so what trusted security circles really is and you'll see that in the security incident slide here right beside thread intel the intent whether or not done well is a different story but the intent is industry segment so what servicenow did is they took a lot of threat intelligence um a lot of anonymized correlation of data of incidents seen categorization of incident type of threat uh all that stuff right bad actor is it ransomware malware blah blah blah and they allow a customer to subscribe it can be bi-directional or it can be one direction subscribe to a trusted circle's trusted security circles infrastructure the servicenow has servicenow controls and maintains the parent or primary database of this within an instance stack they declare industry segment right healthcare transportation phenoms so on by declaring industry segment then the data that goes in from if they if they subscribe to this and allow their data to go right and there's some technical rule set around what that data is but to be published up it's only published and only accessible within that industry segment vice versa if if a customer subscribes to it as a way of pull data in we are only subscribing to a segment of industry now they uh servicenow allows a little bit of of a wider you know if i'm transportation i might have a phenops leg so a leg within the industry so i might want both publishing versus pulling is a little different but what am i getting out of that what i'm getting is much more data set right if we think about what ai predictive intelligence type of stuff within servicenow is that's what we're getting we're getting data sample set we're getting generalized how many incidents how many security incidents did health care within the trusted security platform see of type ransomware um of those types how many were exploitable so some of that type of uh statistical and what that lets an organization do if they subscribe to it is hone in on what to respond to right i can do a little bit of like a preemptive threat hunt to say you know in the next three months we're probably going to see an increase in x type of of attack the reason why in that case it's not as widely used inside of servicenow is a lot of threat intelligence tools are already doing it you have things like splunk threat was the one the other day i heard uh even virustotal i think as a tool set is doing a lot of like industry tagging right miter as a framework which we will probably won't touch on through the share of the wealth because it's its own beast has industry segment built into it as well so what is it it's a data it's a data conglomerate right uh that lets us see some statistics and some predictive intelligencing type of stuff within kind of the threat stack the threat intelligence threat hunt threat awareness stack all right well i appreciate everybody's time today uh hopefully we find some good value in understanding where customers are going to come from with their needs for security operations and security operations suite and as i mentioned i promise we're going to start diving in and really start to see some of this data and see what it looks like in platform thank you everybody [Music] you

View original source

https://www.youtube.com/watch?v=UiExpZwjoXc