Mitigating Crisis Events with ServiceNow
foreign [Music] we'll show you how servicenow is helping organizations like yours mitigate major security events threats don't care about business silos costs or complex regulations in fact this environment is perfect for threat actors to exploit in the last three years we heard from hundreds of businesses that made it through covid they recognize that rapid digital transformation was necessary for Innovation these efforts often exposed sometimes even created Silo technology and processes resulting in not only data challenges but also in 2021 Global Banks incurred 20.3 billion dollars in operational loss so while companies are saying yes to transformation the price of LAX compliance is almost intolerable the only way to manage threats like cyber attacks third party risks and the complexity of growing regulations that are straining your risks and security teams is to take a comprehensive approach this means making better use of detection and monitoring process Automation and investing in a true integrated risk platform to quickly identify security threats and then respond to them before they do irreparable damage let's see how one company pgl bank has embedded risk and security across their organization to manage these threats firsthand meet Sarah pgl bank's Chief Information officer her security teams have come a long way from the bad old days when the vulnerability team would run scans and then document everything on spreadsheets then they'd have to throw things over the wall for the operations teams to fix and hopefully receive an email saying the patches were applied or other security analysts would have to spend hours days or even longer working on incidents because of all of the manual steps required Sarah and her team quickly realized they needed a more efficient way to address security incidents and vulnerabilities in order to reduce their overall risk exposure moving to the servicenow platform provides a single source of Truth and a modernized foundation where data connects people and processes everyone in the company can leverage that data and risk and security teams can work stronger better and faster in the morning Sarah opens the CIO dashboard now available on the servicenow store this dashboard offers a Consolidated view of the security incidents vulnerabilities patching activities as well as configuration compliance Sarah notices some critical vulnerabilities and reaches out to Carla the banks vulnerability manager for more information using servicenow's vulnerability manager workspace Carla can track infrastructure vulnerabilities Cloud container vulnerabilities application vulnerabilities and Cloud configuration issues all from a single location and she's able to manage and assign task for mediation work out to the relevant parties and monitor the patching through to completion for example here's one of critical vulnerability our old friend log forshell carlak created a custom view or watch topic to monitor how the organization has been managing this particular vulnerability there's already a remediation effort in place which means the bank is already on its way to patching the affected systems Carla confirms this to Sarah who's confident that her team are meeting their slas Sarah is relieved but she's also looking months down the road can her small security team keep up with the ever-growing attack service and Regulatory complexity without hampering Innovation that's where Andrew the director of risk and resilience comes in he logs into this risk workspace every day he says the best offense is a good defense and thanks to Sarah's vision and support they've successfully established a Common Language so that risk and security work better together here you see the library of regulations the risks and the controls to make reporting easy and scalable so when Sarah wants to know what the overall risk to the company is regarding the vulnerability of the server that had that P1 they can jump on a zoom and open the heat map workbench they search for the risks that have to do with vulnerabilities we see vulnerabilities are tracked at the server and at the business service level initially they are both inherently High however we can also look at the residual risk where they have different risk profiles now if Sarah asks if these risks are trending up or down we don't have to send an email or wait for answers we can immediately see the risk at the server level has remained low diving in deeper with the 360 view we can see there are six controls in place and these controls are continuously monitored with three indicators you can see on a weekly basis they are performing authenticated vulnerability scanning and on a quarterly basis they are performing internal and external penetration testing thus ensuring a solid mitigation of risk compared to the trend at the business service level which is trending yellow with only one control in place it looks like the risk owners could evaluate the strength of the controls a little bit more clicking into the service record we can see that digital banking is a critical service that's provided to external customers we see several relationships like the dependency on the Windows Server as well as all the regulations and policies this service is beholden to so they send a risk assessment for the risk owner to select more controls and mitigate this risk further all this data sits on the platform so as more assessments are completed everything Aggregates and data is Unified by the common risk and compliance Library we get a clearer picture of our overall risks and where to prioritize as the world changes companies are finding themselves susceptible to new threats think of the next log 4J or the risks of AI or even macro self like an economic downturn Andrew has a clear view of the stability of pgo bank's most critical services he can see changes in failed controls changes in Risk profile or a spike in outages incidents or change requests he's able to view the stability and recoverability of pjo bank's critical Services Andrew can spot assets that don't have business continuity plans if any were not recoverable in a recent Dr exercise in addition to risk and control Effectiveness Andrew and his team are ready when Regulators asked to see service resilience from the people process supplier or technology pillar View we've been talking about how pgl Bank proactively manages their attack service now let's switch gears a bit and talk about how they quickly react and recover when a crisis event like a ransomware attack occurs Sarah just got a text about an ongoing ransomware attack against her organization so she contacts her head of cyber security Adam to find out what's going on Adam logs into the major security Incident Management workspace and sees that The Incident Commander has everything under control we can see a lot of information right from the landing page including the affected assets users and locations time since the incident started and when it's expected to be resolved and the number of teams working on the incident a critical piece of effectively working a major security incident is ensuring that leadership is in the loop and aware of the current status of activity the built-in reporting functionality allows the team to quickly compile an executive report and then share it directly from the dashboard collaboration between the different team members working on the crisis event is also critical major security Incident Management automatically spins up Microsoft SharePoint folders for storage of artifacts and important documentation as well as Microsoft teams channels to allow the various team members to communicate and all that team's communication is saved right here on the dashboard lastly and perhaps most importantly The Incident Commander needs to ensure everything is being responded too quickly and accurately as the various security incidents and vulnerabilities are being remediated and that tasks are being assigned and managed appropriately the visual task board helps them do just that we can see that patch is already being scheduled firewall blocks are in place legal and public relations are involved and a disaster recovery plan has been activated let's take a look at how pgl bank's business continuity manager does just that John the business continuity director and the red team are on it two plans have been activated the customer support continuity plan to notify customers and Implement manual workarounds until service is restored and the application failover plan and you can see all the tasks here in order of execution they've completed the first two and two are in progress they are on their way to recovery crisis averted by transforming the processes and workflows they use to handle Enterprise security and risk customers similar to pgl bank have seen their security analysts perform three times more efficiently an 85 percent reduction in the time to contain vulnerabilities an eighty percent reduction in open vulnerabilities and a whopping 8 700 hours saved in identifying assigning and remediating vulnerabilities using automation all with the help of servicenow
https://www.youtube.com/watch?v=DEGe5RkRG3I