Quantify risk using RiskLens and ServiceNow
okay hi all uh glad to be here today and really talking about this story about how you can use risk lens and servicenow together to quantify your risk and I I'm very privileged to have Rob and Joe joining in from brisklands and uh I'll start by quickly introducing myself I am part of the product management team at service now responsible for everything around risk so so all of the roadmap strategy and the feature development is what comes into my area of responsibility I'll let Rob Andrew also quickly introduce themselves before we go on to the actual agenda yeah thank you so much uh pleasure to see you all my name is Joe I'm a director of sales here at riskland so my responsibility within the business is managing a team that helps our customers operationalize the fair methodology and build quantitative cyber risk programs so uh excited to chat a little bit more about our partnership with servicenow and how our customers use the two systems in parallel to quantify cyber risk Rob will hand it to you yes thanks Joe hello everyone my name is Rob Esslinger I'm a risk transformation advisor with risk lens my role is working with Joe and the rest of the risk lens sales teams to help organizations understand how quantitative analysis can be introduced to their current risk management processes and gain additional value and insight into cyber risks and Enterprise risks in general from a financial perspective thanks Robin Joe so so it's a packed agenda today we're gonna do a bit of an introduction about the service now risk management solution we'll also get to know the risk links I uh solution and what they do but majority of the time will be on the demo where we can demonstrate how risk lens and service now can work better together right to provide the insights that customers are looking for to manage their risk effectively and in case you have questions you have comments please feel free to post them on chats we'll definitely take them up during logical proof points some housekeeping points you'll be you all of you will be automatically muted please use the Q a feature to ask questions throughout the sessions the sessions will be recorded and shared on the service log Community after the session and after the session ends you may be prompted to filled out a short survey we really appreciate all of your feedback there so so you must have seen this from us right uh the world works with service now that's our purpose so we want to make the world work better for everyone in this all so the vision within the rift bu is really to seamlessly embed risk and compliance into digital experiences and workflows so people and organizations can work better so so you'll see this happening across our portfolio of products where we embed risk and compliance workflow into the first line use cases or workflows and that reduces the friction that customers or users will generally have when managing their risk and compliance so unlike other platforms service law is actually born in the first line workflows if you look at some of the key capabilities that are required in a risk management platform it's really have is around having a very comprehensive risk and control libraries having a very strong risk assessment engine managing your Kris and kcis your internal and external risk events issues and finally reporting right so so all of this is provided by servicenow So within the servicenow application you can manage your Consolidated list of risk and controls you can create the hierarchies of these you can also associate risk to uh metrics as well as issues that helps you give visibility into what is happening in these risk and controls throughout the organization using the very advanced advanced risk assessment engine so you could associate uh risk assessments to pretty much anything in service now right so you can assess risk related to let's say ID assets you can assess risk related to operational risk or vendor risk or any other type of risk and when you do this you can actually do a very comprehensive rcsa to do your inherent assessment your control assessment as well as your residual burst now when you assess these risks you are not just assessing it from a qualitative standpoint but also a quantitative standpoint or even a hybrid approach of both so this is a very unique differentiator to servicenow platform where we provide a very comprehensive risk assessment engine and the beauty of this engine is it could actually within a single instance catered to multiple risk assessment templates or methodologies you have in your organization I'm gonna do a deep dive into this in a moment but just from a summary perspective it helps us cater to not just one specific use case but across the platform multiple irm use cases similarly on the metric side we have now have metrics which helps us monitor your Kris and kcis making sure all of your top risks are monitored more closely and in case there's a change or there's early alerts you could actually proactively take action on them from your loss perspective or risk events from a broader story perspective you it helps you manage your losses make sure you are tracking them you're using that information to identify control gaps and strengthening your overall framework to uh make sure whatever risk are there those are mitigated at a very low impact or a uh let's say less catastrophic manner from issue management perspective you would see a very comprehensive capability to make sure all your control Gap are being plugged in and these control gaps are now making sure the risk is further getting reduced and finally from a reporting perspective it uses the now platform reporting engine to provide very holistic reports as well as there are specific uh algorithms like some things like roller or wrist roll-up uh or maybe some of the Basel reports that are available for our financial customers in the risk event module that helps you not just uh automate or digitize your workflow but also helps you on the reporting side of things making sure things are reported in the manner they are supposed to so now one of the things you would see is what we don't do in the service now platform is quantitative analysis of a risk while you can actually assess it or capture the quantitative output but the entire quantitative analysis of it to understand okay what's the projection looking like what the distribution is and that's where risk lens helps us do that and we'll show this so for all of you just a rehydration of what a risk assessment is so risk assessment is really a subset of your risk identification your risk analysis and risk evaluation put together so during as part of your rcsa exercise that customers do they would identify a risk they would assess the inherent control and residual risk and then put in mitigating actions to say okay what should we do in order to manage this risk better so this holistic picture gives you a clear visibility into what your risk assessment is now in terms of the benefits from a qualitative analysis perspective the first key benefit that are seeing customers uh get uh get is really from a more from a identification analysis perspective a lot of times this is your starting point when you're kick-starting let's say a new uh business or maybe a new initiative in your organization you want to make sure whatever are your business objectives you identify document these risk across and then actually uh to an extent analyze them to say okay if there are existing controls in place what those controls are and then to an extent assess them right very qualitatively you can assess the inherent assessment you can assess the effectiveness of the controls and then see where the residual risk are it helps you filter the noise to make sure the risk that actually needs to be managed are managed well and this really May or helps the organization keeps Focus us on in terms of the number of risks they are managing right so you don't want to spend all your effort in doing let's say quantitative analysis of all of your thousand risk right but you want to focus on those top hundred that you have in your organization and you can actually analyze them better the third bullet point is really around simplicity so a lot of times when you're kick-starting your risk journey and you want the employees to be able to do this assessment themselves qualitative is much easier for the employees to do because they don't require extensive training it's very very communicative in nature so so they don't need any special skill set of it and finally even from a reporting standpoint because when you're reporting it to Senior Management uh a lot of times it starts with something like a heat map where you can plot these risks across but obviously Senior Management is always looking for the dollar losses and that is where the data from risk lens will help you club that across so it's really a hybrid approach in terms of the reporting there you know doing a bit of a deep dive on the risk assessment the specifically the ARA so so if you look at it from a story perspective this is what we cater to from an irm perspective so if you are an organization who is having multiple methodologies uh with it depending on the context that you are assessing right ARA will help you do that so you can assess multiple kinds of entities which could be your business application which could be a business process lines of business or a company right and you can do like a full-fledged rcsa exercise on each of these but at the same time if you want to understand how the impact is across let's say these business application to this business process to the lines of business to the company system does a roll up of these now one unique factor is we just don't rely on manual assessment but if there is data within servicenow or outside service now you could also use something like automated assessment factors to actually automate and make sure these risk assessments are more continuous and they are not outdated so this is where the unique differentiation of the ARA comes into picture where it can provide you a very comprehensive risk assessment engine which can help you cater to variety of your risk assessment needs so with that I'll pass the ball to the risklands team to walk us through some of their Journey yeah thank you so much let me food cars do you mind sharing your screen again please yeah yeah sure sure thank you very good I appreciate the uh the context in the background of course so to transition a little bit into maybe from a quantitative perspective where risk lens and a quantitative approach to risk management and specifically cyber risk management fits in I think it's important to maybe zoom out and uh maybe start with from a market standpoint and a problem standpoint what is it that has even led to the formation of quantitative risk management as a discipline and an approach and if we have to summarize uh sort of the main problems the main problem that clients look uh to solve for when they start quantifying cyber risk um it simply comes down to communication and decision making and from a market standpoint um as I'm sure you've all witnessed you know throughout your careers and you know your your times and your various uh organizations as the spotlight on cyber security has gotten significantly bigger over the last five 10 15 years what it's done is it's oftentimes changed the Dynamics for csos and their teams and this representation here is meant to Showcase sort of the conversations and the Partnerships that csos and and their respective security teams would have with key Partners throughout the business and you'll notice a lot of the questions that these folks have are very difficult to answer in the traditional methodologies rather traditional ways whether it's a high medium a low or one through five or just in the technical jargon of a complex and dynamic world that is cyber security and from a challenge standpoint um this is really the main thing that clients are looking to address it's how can we Foster better conversations with key stakeholders throughout the business to operate as good stewards of organizational resources and ultimately make better decisions so we can more cost effectively help the business understand the risk that they're exposed to but then also more cost effectively allocate our security resources so that we can demonstrate the value of uh you know the work and the projects uh and the uh you know really just the division that a particular security team may have or be implementing within uh their organization so this is sort of the uh you know really the problem in the market conditions that have led to us even forming as a business and quantitative uh approach being formed as a discipline who charge you mind stepping to the uh the next slide so we can get into maybe the solution a bit so these are our outputs um from the platform mapped to common questions that we see clients wanting to answer I'm going to start with the top left to just very briefly work my way through um to show some examples of kind of the art of the possible um the first is how much risk do we have so very simply within the context of either you know a very discreet scenario or across you know a large um you know business unit for example a product line we'd be able to answer the question how much risk exists within a particular domain of an organization one step over would be what are our top risks so either again across an entire Enterprise within a within a business unit comparing business unit divisions to one another we'd be able to Showcase you know which risks are the most significant risks so that we can not only communicate our understanding of these to various senior leaders but also use it for prioritization so that we can ensure the activities that we're taking the projects we're funding are only targeting the risks that matter most on the top right another use case that we see clients pursue is wanting to demonstrate risk trending also compared to an appetite so as the risk landscape is changing right as we're seeing new threats emerge as we're implementing uh projects and completing uh you know new controls for example we'd be able to tell a story to various stakeholders about how we're seeing risk ebb and flow over time and then on the bottom row we see your types of losses so when someone on you know the senior executive team says okay you're telling me there's a 10 million dollar risk what does that mean in practice um would be able to very clearly articulate where those may come from whether it's fines and judgments whether it's lost productivity whether it's lost Revenue lost customers Etc then the last two here are really focused around cost benefit and decision support and if you have to sort of pinpoint this into core use cases this is one of the more common use cases that we see clients pursue it's how do we demonstrate control Effectiveness and also measure the ROI of certain controls so this is what can allow us to make trade-offs and make comparisons and that we recognize you can't necessarily mitigate every single risk and you definitely can't mitigate every single risk right now so some level of trade-off has to happen in terms of what can we live with for the time being and what risks um you know or what are the risks that we actually want to mitigate then the next level is how much do we want to spend to mitigate those to an acceptable level so rather than saying you know let's take a red risk and make it an orange risk or a yellow risk it's we've got uh you know a risk with a certain dollar amount we want to spend um you know five hundred thousand dollars on a new project and that's going to reduce our risk to uh you know a significantly lower amount so that's the sort of narrative all based on financial terms that clients are looking to enable by leveraging quantitative risk management now the last slide that I'll share if you don't mind stepping one slide forward a very common question that we hear from organizations who are are thinking about getting started is where should we begin it's you know the concept of quantitative risk management resonates um but what are the first steps that we should take to help answer this what we've done is we've worked with our our most successful clients you know large Fortune 1000 type Enterprises um and categorize the types of decisions that they use quantitative risk management to support into these three main categories and that really at its core is the reason organizations quantify risk it's more effective decision support and I'll walk through each one of these briefly just to give you some examples and some food for thought the first are strategic decisions so as you know the examples clearly outline here these are things like reporting the top risks within the organization to senior leadership board an audit committee cyber steering committee Etc and what we'll do is we'll see clients regularly update these sorts of dashboards maybe on a quarterly basis for example to help showcase not only an understanding of the risks that matter most but use that as a trending to show how those various categories of risk are changing over time one level down from there is operational decisions it's once we've got an understanding of the risks that matter most we want to make some project trade-offs for example we want to do cost benefits to understand the value of the various cyber initiatives we have on an ongoing basis we want to rationalize our cyber security budget things like this and then the last is tactical decisions and I like to think of this as rapidly assessing the uh you know high volume of things that emerge in the day-to-day life of a security professional so things like emerging threats that may pop up Auto audit findings policy exceptions and a good way to think about this is taking a thing of concern that may have just sort of uh you know arrived on your desk and wanting to understand is this a seven-figure problem or is this a four or five figure problem so these are are the three types of decisions that we see clients really want to pursue by leveraging quantitative risk management most folks will say we want to do all three but from an engagement standpoint what we'll typically do is within the context of your you know environment the challenges that you're experiencing the goals that you have Define goals based on sort of looking through these lenses if you will and then build sort of a project plan to support those goals all right oops I will hand it back to you and step through the next phase of the webinar sure thank you thanks for the wonderful introductions here and overview on the riskland side if there are any questions please feel free to post them in the Q a window and we'll definitely be well happy to answer that so with this I would like to go into a system and first start with uh a bit of a demo on the service now side and then we'll see how you could use the data in service now to actually do a quantitative analysis on the risk lens side and for that what I'm gonna do is I'm gonna impose need as an I.T risk manager here so I've already logged into the system so I'm gonna go into my workspace here so you can see as an ID risk manager I can look at the risk profile from multiple angles from multiple standpoints and what I have done for the demo today I've already created a couple of risks right so one is around data breach the other one is around France somewhere right so as part of service law platform what you'll be able to do is you'll be able to understand what the risk is capture it fully so you can capture the full details about this risk in terms of how this risk materializes for you what the impacts are so you can capture full description about this tag it to a particular ID asset so in this case it's a business application which is your servicenow ideas and business application make sure you you have somebody owning this risk so your risk owner so in this case I'm gonna self own this risk just for the Simplicity of the demo right and tag it to our corresponding Enterprise risk taxonomy so that when you do these risk assessments they can all aggregate across the platform and provide from an Enterprise risk perspective what the impact of these individual risk item is from a corporate standpoint right you could there's a you could also relate to your controls you can define a comprehensive set of library of controls these controls can also come from some of the standard Frameworks that you have like ISO 27001 or list and others and in fact you you could actually import them very easily through your UCF integration so all of these controls can be imported across into the system and then you can relate them to say okay if I have a data breach risk these are the mitigating controls in place in order to actually mitigate that across all right along with it you can also Define your Kris and kcis now in this case this is let's say a new risk that I've just documented across in the system will probably first assess this then actually go through quantification and only if it's a top risk you may want to put in Kris to actually manage this across now in case there are any losses that around this risk those will appear here so you can look at all the losses that you have incurred around this risk again this is a data that can be used for quantification so you can look at all the historical losses and how much money you have lost in order to actually manage this risk from holistic perspective the last is really the issues like I was talking about so if there are any control gaps or if there are other foreseen issues around this risk that you want to proactively fix you can define a comprehensive action plan on them and you can say this is how I'm planning to fix this all of this actually is useful when you first assess this risk so so in this case here I've already initiated an assessment but essentially on click of a button you can initiate an assessment here now in this case I already have an assessment uh for me so I I can maybe cancel the current one and initiate a new one for you right so I'm just gonna go there and do that let me pick up a different record yeah so I can go assess this risk around so I can say episode one of the risk around ransomware similarly we have a risk around did a breach so I'm gonna put myself as the risk owner as the one who's initiating the assessment the system initiates a task so this is where it's very simple to use user interface where uh it's like a self learning that your people in the first line can do so it's not just the ID risk manager who can do this risk assessment but it could be the actual application owner who has little to no knowledge about what risk is or what what he's supposed to do right so that's that's a thought process behind it it's really catered to that user so it's a very guided experience and I can see there's already an assessment that was done previously on this risk here so the system asked me do you want to copy over your previous assessment results for the demo today I'm gonna say no so that I can show you how it looks like for a new record so now you see in the left hand side you have internet assessment you have your control assessment you have your residual and finally your risk response right so so this is where you would assess the risk assuming they are no controls in place but in reality there are definitely always controls in place and you were going to assess them and which comes up your residual now in case you want to further mitigate this risk you can document what your response strategy is if you are mitigating it or accepting it as it is so that's also something you can drive and then finally as part of the response strategy you can also identify net new controls in place so we're going to look at this from an end-to-end workflow perspective but let me start by doing a quick inherent assessment and in this case here you can see it's a very simple assessment of an impact and likelihood so I can see what the different impact values are now like I said if your typically as a first line user you don't know what does insignificant mean or what does minor mean right so you can actually look at the complete uh your risk metrics to understand okay when I assess this risk from an impact standpoint what are the different criteria I need to consider right so if I'm looking at it from a financial impact perspective it should be less than three hundred thousand dollars then I can classify this either as an insignificant or a minor right so this really helps the first line get that context in and make sure the rating they are providing is actually in line with what the organization expects it to be so for now I'm gonna put both of them as catastrophic and almost certain so let's say this is a ransomware as a risk it has a catastrophic impact and these days it's almost certain that these kind of risks assuming there are no controls in place it will happen right so I do my inherent assessment I can provide additional comments to justify why I've provided both the ratings so you can provide Factor level comments or you could provide even overall comments here and then I can move on to assess my controls now before I do that one of the key things you would observe is on the era platform all of this is configurable so whatever you are seeing on the UI can be completely uh changed depending on each of the client needs so it means it's not just restricted to impact and likelihood as a factor you can change it you can say I want to do let's say a deeper assessment of financial impact reputational impact client back or maybe I want to capture the actual losses that you are incurring instead of asking for a drop down value so this is what the power of the AR engine gives you where you can actually configure your unique risk assessment template and like I said there are many servicenow customers who are using our era platform to do multi-phasis risk assessment so you can do a bottom-up or a top-down risk assessment you can do a risk assessment from an ID perspective which may be very different from an operational perspective so that's why that Focus has been on providing that power to you and this really helps customers from a maturity Journey perspective as well so as you grow into your risk maturity you should be able to reconfigure it without going back to like say let's say an implementation window or a technical partner to actually reconfigure your entire risk assessment templates out so that's the thought process behind giving that power to you that flexibility to you to help you you support the qualitative assessment of these risks so once you are done with your inherent assessment the system is going to move to your control assessment now I can see there are already two controls to find one is around multi-factor authentication and the other one is around the firewall which is preventing it right some of these attacks I can look at the weighting of these controls how much they are weighted and then assess each of the Via control as well so I can say let's say maybe the firewall is proving somewhat ineffective while the multi-factor authentication is probably partially effective but can be improved right and now if You observe this is where the system is auto Computing your residual risk to be high so now this is a risk that I'm not comfortable with but whenever like uh I go to my senior stakeholders like maybe somebody like a CFO or a CEO and I say this is a high risk they may ask the question around what does it mean right from a financial perspective and that is where risk lens will come in and then will help us answer the that question right so so defining that projected losses as well as the probability of those losses to get a more uh I would say mathematical judgment on them is where they will come and help us out in the sale but as part of the workflow you can now Define this is definitely a place where I'm not comfortable with so I want to define a further mitigation action to say I want to mitigate this risk across and this is where you can Define your comprehensive mitigation plan now again from a cost benefit analysis perspective if you are putting in additional measures or additional controls the Senior Management may ask for justification as to why are we doing this what the projection or the return on investment is like Joe was talking about so all of this can be then used with your risk lens platform to understand that bit so for now I'm Gonna Save it across uh just a very simple dummy task and initiate uh approval workflow now in this case I don't have approvals defined but technically speaking you can also do like a multi-level approval to make sure in case you want various stakeholders to sign up on this Iris they review it they provide their assessment on this and this is will make sure that yes this has been signed off by them now once you do this all you need to do is once your risk lens integration is configured in the system you need to go to that risk record here so I'm gonna go there and maybe open up this ransomware risk and you can see in this case here I have already requested a subscription on the risk lens side but if this was a new risk that does not have an active request that has been made on the risk lens side I would get an action saying subscribe tourist cleanse and then what the system will do automatically is it will share all of this data that we have around this risk with the risk lens platform where you can quantify this risk right understand more about this risk and once the quantification is complete the outcome of this will be available to you to make for the Judgment of for the uh decisions around this risk so the system provides you various metrics and we'll see how we arrive at these metrics but some of the key data points that you'll be able to get from the system is things like minimum law of exposure most likely lost exposure and average exposure as well as the percentile you're saying okay what the lower percentile is and what the corresponding value is and stuff like it so so this is where risk length really helps you quantify a subset of these risks now it can happen like I was saying there are multiple of these risks that I have within my entity which is serviced now itsm but I don't want to quantify all of them maybe I just want to quantify the top ones the ones where I have a high risk so you can just selectively initiate a quantitative request for them here right now once the request is raised what you will also be able to do is you will be able to track these requests so what I can go is I can look at all the requests that I have made from the servicenow platform in this view here so I can see these are the different risks that I have requested from the risk lens side and the status of these requests so they are still pending so so they uh so the data has not yet come but once the the risk lens side the analysis is completed you will see the state is getting updated and the data getting updated into the risk of fields that we have we can then use the servicenow reporting engine to again report back this data and use it for further decision making right so this is where you can track a request in case you already have let's say a request that was made previously it the system also tracks all the requests that were made in the past so you can look at okay what was the risk and what the law of exposure were what the percentile values were so it just not track your current request but all of your historical data as well right uh and integrating it is like literally like five minutes right so I actually did this today morning for example you just need to have a client ID and a client token uh to say okay what's my ID and token is and that's that's the API based integration way off over the risk lens so it's a very simple self configuration that anybody be a little knowledge on how things work technically can actually do in the system right so that's the main advantage behind this corresponding piece here so with that I'll hand it over to the risk lens team to show walk us through what how the magic is happening on the risk lens side Rob yes thank you tarsh um appreciate it um yeah so let me jump into the risk lens platform here and we'll talk in a little bit more detail in regards to that quantitative analysis that takes place and how those outputs are ultimately used to support decision making within our organization um so the example that I will walk through today is around that data breach risk that uh uttar should shown within servicenow so when you subscribe to the risk ones platform the details about the assessment get pushed across to risk lens to enable us to start that quantitative analysis process you can see the risk identifier here from servicenow as well as information regarding the purpose behind this assessment I'm going to go ahead and click into this um and you know what we we can see from um the description of this purpose here is we're concerned with uh sensitive data of some type being accessed uh in an unauthorized fashion um that could be pii data it could be Phi data it might be PCI regulated data and in many organizations there are different systems and applications that store and or process these different types of information so when we think in the context of data breach as a risk really what we want to understand is how and where that data is being stored and processed within our environment and how well that information is being protected across those systems and more often that not than not that leads to the identification of more than one loss event associated with this particular risk so through a scoping exercise you know that follows common risk management Frameworks the risk lens platform guides us through the process of identifying the various loss events that are associated with this particular risk quantifying using a data dividend driven approach to understand not only the probability that that loss event may occur but the impact of that event in financial terms how much will it cost when a certain number and a certain type of records are breached within a given system so the scope of our data breach assessment includes a number of different loss event scenarios that have been identified in terms of systems that again store this sensitive information the various threats that they may be exposed to and what our platform is enabling us to do is discreetly measure the risk associated with each of these scenarios and then give an aggregate picture of that total risk so the total risk associated with data breach in terms of of our environment and this is the data set that automatically synchronizes back to the risk registry entry within the servicenow platform so having an understanding of our total risk helps Drive decision making and prioritization in terms of which risks within our organization should we be focusing resources on uttars mentioned ransomware we would have similar qualitative or quantitative metrics to drive our risk exposure according to ransomware and depending on the financial impact and probability of those events that can help us to make a determination on whether to prioritize ransomware mitigation or data breach mitigations um from a security initiative standpoint now the top risk tab here is now able to allow us to drill into the specific details of each of those lost event scenarios so what makes up that total risk concerning data breach within our organization and we have three metrics that can inform our decision-making process in terms of the prioritization and identification of where and how we're carrying risk as it pertains to data breaching the per event loss magnitude metric tells us the amount of loss the the impact overall impact attributed to each one of these individual scenarios when it happens how much is it going to cost our business in the middle we have the probability that each of those loss events will take place and we find that it's often valuable to put this in the context of a number a lot of organizations uh have identified various thresholds um from the perspective of where loss becomes meaningful so not only can we report on the specific probability of each loss event we can report the probability of exceeding some meaningful number within the organization so in this case I have it set to five million dollars and this is the probability that each of these loss events Not only would occur but occur and exceed that five million dollar threshold and then finally the annualized loss exposure this is the normalization of the per event impact and the probability of loss it really helps us from a privatization standpoint because again it normalizes Black Swan events for example that may have a very very large impact but a very very low probability we won't lose sight of other types of risk that maybe have a much smaller impact but because of their frequency may end up hurting us more in the long run so this annualized loss exposure is very helpful again from that prioritization standpoint because it's normalizing the first two metrics But ultimately having all three of these data points is very very helpful in terms of driving our decision making in terms of how we're going to prioritize risk mitigation in this particular example it's very obvious which of these particular loss events is contributing most to this loss exposure this mobile app breach scenario Rio is really the Lion's Share of the annualized loss exposure it has the largest per event loss exposure and it has the highest probability of occurring and this is not unusual for us to see in a lot of environments where things like data breach obviously um the loss of sensitive data is very top of mind for a lot of organizations it often does not require a lot of justification on how and where you should be protecting and allocating resources to protect that data but and in some cases we may find gaps in our controls and gaps um in our policies that may be something that's raised as an issue within your servicenow instance um what quantitative or quality quantitative analysis can do is help us understand what those gaps mean in terms of financial exposure how they compare to other systems that may not have those same control gaps and ultimately again supports that decision-making process on how to Target those control Gap closing those control gaps so the next sort of component of this analysis is what to do about how do we mitigate this data breach risk if the overall number is is higher than we're comfortable with in this case we can hone in here on this mobile app breach scenario if we can reduce this particular risk that's going to really get the overall data breach risk under control and that's where our cost benefit analysis really comes into play helping us to understand from not only a collective data breach perspective but help understand what a specific control change might do in terms of risk reduction um so I have an example associated with this data breach a mitigation report that is essentially taking the same scope of assessment as a Baseline and enabling us to attribute possible control changes maybe improving encryption on our back end maybe this is a control Gap that was shown to be ineffective in the realm of our data Bridge systems maybe improving controls around the front end of these systems would ultimately lead to a reduction in Risk but often the question is how much value are we really getting from these controls are they effective in reducing risk is the risk reduction we get from that control proportionate to the spend on that control so having risk expressed in financial terms really is powerful in informing that decision-making process which control best mitigates risk very tangible metric to show how much less loss we would have by implementing a particular control but also because we're expressing that risk reduction in financial terms we can directly compare it to the cost of implementation for those controls and have a very tangible Roi to help understand the value we're achieving by implementing this particular control in question though this cost benefit report shows us the initial Baseline this is the the current risk based on current controls um often referred to as residual risk in the context of of GRC platforms like servicenow and these additional assessments are future State residual risk positions where if we were to improve encryption uh specifically on the mobile app solution how much less risk would we have overall um from from data breach if we deployed an application firewall say something dedicated to the front end of that mobile application again how much less risk would we have but the simple sort of effectiveness of the control again isn't always the full story The the most risk reduction isn't always the best option um for a controller there's other factors that that come into play such as the cost and the time to implement certain controls and we may find that the preferred option in this case improving the encryption it may be out of reach for the organization at this time based on how long it would take to implement that change and the cost associated with it so it's very powerful to be able to suggest additional compensating controls show the effectiveness show the ROI associated with those and help the business to understand what they can do in the short term as they plan for the more effective long-term Solutions and then further just to illustrate the the concept of targeting specific areas of loss we can actually drill down on each of the treatment options to show the effectiveness in each of the scenarios in question within this context data breach and as I mentioned we specifically honed in on the mobile app reach and simply looked at deploying a very targeted mitigation for this one losses scenario involving this one particular application and showed that we can drop the annualized loss exposure significantly all of these other losses are fairly well managed within tolerance we don't need to spend extra money or resources to apply controls there we can be very targeted in terms of how and where we want to allocate those limited resources and ensure that we're getting the best bang for the buck so with with that um we are approaching the 10 minutes to the top of the hour um so I'd like to turn it back over to uh uptarsh um and uh have some q a Time thanks Rob for the wonderful demo definitely uh a lot of good insights that customers always look for right trying to justify the cost and like you said how do we enable what controls should we Implement first and what controls to implement later so I see a bunch of questions in the Q a chat and I'm gonna start by uh the first question from Aaron which is around we want to focus on a residual assessment and turn off the inherent assessment is that possible absolutely Aaron in the service now platform like I said we offer you a very configurable workflow engine in the ARA platforms you can say I only want to do residual assessment or I only want to do inherent assessment so that's all part of the risk assessment methodology where you turn things on or turn or turn off things and the beauty of this is you can turn this on let's say you for it risk assessment you can just do residual risk assessment but for operational risk let's say I want to do all three which is inherent controlled residual so you can actually configure that too in the same platform if uh the second question is around you may still address this but there are are there programmatical API methods to pull data into risk lens uh so we already offer an API where all of the information from service now is shared to risk lens uh things like the risk details The Entity where the context of the risk is is being shared to riskland's team and I know we have been working together to identify how more information things like let's say risk events or maybe the controlled performance and servers now can be shared with risk lens Rob Joe anything you would like to add on this yeah the short answer is yes there there is a full API um stack available within the risk lens platform to pull data in um across a variety of the components whether it's the data inputs to support the analysis um the ability to to export the reporting outputs to other systems so we have customers um you know that have additional reporting engines that they like to utilize things like Tableau for example um so yes there there's an application an API that exposes all of that data for both import and exported data awesome uh there's also a question around uh the mitigation task or the mitigation plan can you also add mitigation tasks to the mitigation plan to be able to follow up on all open mitigation tasks related to our risk so so right now the mitigation plan we have is a single task but a lot of customers using the configurability of the service now platform can actually enable multiple tasks and I've seen multiple customers do this from a roadmap standpoint there are plans to enable like a full-fledged planning workflow there and that's where we are also going to connect to our SPM application where such a mitigation plan can be created as a demand or maybe as an initiative and you want to manage it as a project so there's also a Better Together between the two applications we are looking at so they're going to be definitely investment in the roadmap to fix some of these things and enhance a entire experience around how we are doing your mitigation planning there foreign how configurable is the risk scoring can use mathematical models like mean median Etc uh I'm assuming it's on the service now side again and it's definitely very configurable so you're not just restricted to say impact times likelihood you can have your own custom formula as long as that is supported in the JavaScript so so as a as a tool or as a mathematical function you can use any of those functions to Define your own custom formula and the system will be able to take that along and be able to compute your risk scores there the next question is from Mario around regarding the subscribe to risk lens function uh and it talks about does this provide information from our own instance of risk lens or does this provide information from risk lens it serves with industry information regarding risk so what we are doing is uh Mario when you say subscribe to risk lens effectively you are making a request saying I need a quantitative analysis of this particular risk uh uh which needs to be done in the risk lens platform and once you take that action as you were seeing you can see that uh that action names turns to subscribe to risk lens which means there's a subscription there's an analyst just ongoing in the riskline side and this is unique analysis for your organization right so so yeah uh I I know in Risk lens you can also compare but I'll let Joe and drop comment on what we do in terms of making sure we can bring in some of the industry best practices when you're doing the quantification there on the wrestling side so so yes Mario so when you subscribe to risk lens essentially it is creating a risk assessment for you within the risk lens platform that's linked to this the risk registry within servicenow um and so once you're at that stage you can absolutely utilize um past assessment scenarios that you've done to scope into that assessment as well as add any additional loss event scenarios that may be relevant to that particular risk and once you run that assessment and and set it to its current state those results will be funneled back automatically into servicenow additionally in the future if you create additional versions iterations on the timeline for those risk assessments the most recent current data will automatically sync back and keep the servicenow instance up to date foreign there's also a question from Imran or does the risk lens integration work with Advanced risk application absolutely and run you can use the risk length integration with classic risk or Advanced risk so the key point is it is integrated with your risk object which Remains the Same across your classic risk and advanced risk so there's no reason you should not be able to use that there uh there's a there's also a question from saurabh uh and maybe Rob you can take this one how does risk lens determine the dollar figures for a specific organization is it Benchmark to Industry in general yeah it's it's both there's a combination of Industry Benchmark data available within the platform um but you're also able to model your own organizationally specific data um so in our data breach example uh the metric that's that drives the analysis process is the number of sensitive records that would be exposed in a breach event and then the type of Records whether it's pii PCI Phi you specify that as a component of the analysis it's actually attributed to the asset that that that information is stored on and then in Risk lens packages in the form of lost tables libraries of data regarding past breach events and how much organizations uh paid out in terms of regulatory fines other types of judgments from possible civil suits incident response and disclosure costs um even losses associated with providing cred credit monitoring to those individuals whose records were breached that's all packaged in the platform so it's sort of that combination of your own information with the risk lens industry data that produces those those quantifiable outputs awesome uh there's a there's a last question from suria is there any specific license model for buying and risk lens so Surya if your question is moved from so it's not perspective uh as long as you are a customer of service now irm application you should be able to use the risk lens it's not tied into any standard professional or Enterprise license but definitely it's an actual license app you will have to purchase on the risklin side and I'll let Joe and Rob comment on that yeah because you you hit the highlights in terms of uh that of course there's a you know separate licensing uh license that's required to leverage risk funds and use the two systems in tandem um we can of course speak one-on-one or feel free to reach out if you'd like to explore it in in more depth but just to really briefly describe the uh the licensing model it's essentially modular based so as I'm sure you've seen with other uh technology providers out there there's modules of functionality that are mapped to use cases and the types of decisions that you may use risk lens to pursue um and we would just license the appropriate modules based on the goals that you have for your particular use case and in your particular program foreign how different is Westlands from Monte Carlo's simulation or differentiator as I assume both are capable of doing cost benefit analysis RCA and much more would be good to understand more on this so Rob or Joe do you want to take this up yeah I'm happy to take it and Rob fill in any gaps if they're already um I mean Monte Carlo simulations uh you know a mathematical capability um risk lenses you know a technology platform that leverages Monte Carlo um to run the analysis and uh really manage the data generate the reporting that you would need to operationalize a quantitative risk management program so I would say those are the primary differences is you know risk one's an Enterprise technology platform Monte Carlo is a a mathematical technique that we leverage as you know one capability within the platform thanks Joe and I see no further questions and right on time so thank you thank you everyone for your time thanks Rob and Joe for your time today and walking us through the wonderful restaurants application um uh really glad to be here today and spending time with you all yeah likewise thank you all right
https://www.youtube.com/watch?v=8LnBT0tmNuI