ServiceNow Series E113: Tommy LaMonte, Principal Consultant at Thirdera
[Music] the oldest podcast is brought to you by all this International supplying your expert Ai and digital transformation staffing needs across the U.S and Europe today you are listening to our servicenow Series where we interview the best and brightest of the industry to share their story advice and views on the exciting world of servicenow and digital transformation [Music] hi everybody it's Mark Kelly here Chief customer officer and co-founder of all this hope you doing really well today and our guest on our servicenow podcast series is Tommy Lamont Tom is a principal consultant at tedera and he's an experienced I.T professional worker and today are servicenow security and risk practice Tommy thank you very much for joining us on the podcast today yeah Mark no problem excited to be here before we jump into your role at tradera could you share us a little bit about your background and how did you actually come into the world of servicenow sure so I started out in the world of service now as a customer admin I was at a servicenow customer who was just in the process of moving off a legacy tool to implement itsm for servicenow before it's doing that I kind of went around the IT world a little bit and hardware and networking area but um you know really started my servicenow journey there um you know I started out with pretty basic admin stuff quickly started picking up you know I wanted to saw the power of the tool wanted to start improving things make things better at the business so really just jumped in and started uh making some updates in that itsm space starting to improve some efficiencies spent about four years doing that at the customer uh and from there kind of started to look at the Consulting area for some more challenges I wanted to see some more things see what the platform could do um so it's probably about seven or eight years ago now I jumped into the Consulting world um and I really like being in Consulting because I get to see not just that one company as a customer but all different customers what they're doing with the platform what problems they're having what problems they're looking to solve um so starting out in Consulting I kind of focused on that itsm area for a while there and then about five or six years ago really got into the setups and risk area those are two have really interested me I've always been interested in kind of the uh integration aspect of things some of the more technical areas of security operations so I really enjoyed working in the secups and in Risk area and helping customers on their Journey there because it's a really it's a use case on this platform great great example of someone coming from just that kind of administration Journey moving up getting into your hands into a few different layers of rtsm and then later spending five six years in security and really Building open expertise and your most notable role which is your current role intern era tell us a little about your role's responsibilities there yeah so at third era I'm a principal consultant uh what that actually means is I spend about half my time doing uh project delivery actual implementations configurations and the other half helping out on the pre-sale side um so what I really like about this role is I get to see a lot of conversations through all the way from that first introduction to a customer talking through you know where they are on the platform today maybe their brand new customer looking to implement service now take them through kind of Road mapping their Journey what they should be focusing on uh during their projects or whether it's an initial implementation or one uh subsequent one to implement something like vulnerability or security incident and then a lot of the time I'll even end up assigned to one of the projects that I handled the pre-sale side so I get to then go in workshop with the customer really dig down deep into their processes figure out where we can improve things show them what servicenow can do to help improve some of their processes take them through all that configuration through through delivery right to go live and then get to actually see that uh solution go live in production so um I really like doing that because you know not only do I get to see it through from the start to the end it gives me some kind of unique perspective on uh when I'm starting to talk to some of these customers hearing some of their challenges and really able to visualize how this might go through through the full project delivery um and that really helps you know figuring out right from the start where should they focus on you know are they uh you're gonna look to go and write with a big bang of doing a giant project to integrate everything or more often a lot of the time they're gonna find some some key things that they're struggling with and I can really focus in on that with them getting those workshops open that up and and explore the best way we're going to make that process better for them tell me for companies that are embarking on implementing service now what factors do they need to take into consideration when looking to build a robust value-added roadmap particularly on the security side yeah so this is a really interesting area because I do get into a lot of conversations with customers um you know especially new customers uh they see servicenow you can do so much with it of course not just security but itsm which it kind of classically started out with HR legal everything um and it's it's easy you know you want to do it all right away you see how much you can do and you want to really get in there um but what can happen then is you end up spending forever and kind of the requirements and even pre-sales phase talking through what you might want to do um so what I try to do is really guide to like where where are you spending a lot of time as a business are there some highly Millennial processes um what are what are pain points um you know on the I.T side a lot of the time will identify things like an onboarding process needs to be automated on the security side there's there's frequently a lot of really manual tasks that um you are you have like security analysts for example working on and these are generally pretty highly trained um you know frequently Engineers working through uh problems to make sure businesses are secure they have a huge tool set to work with um but a lot of the time that leads to them you know spending time manually transferring things between tool sets emailing it to people um to get get things fixed get information back so it really helps to figure out you know what are those scenarios where we have very skilled people spending a lot of time just emailing doing administrative type activities and start to focus in on there from there we can take a look at all right what can servicenow do here how can we start to automate uh some of these processes and really it comes down to applying use cases to your automation right so not just taking the platform reference thing um oh this is great we can go automate everything but let's look at what use cases we're actually working at and then uh we can start to align you know kind of what value we're going to see there and have a lot of Direction when we're going into uh take on some of these efforts yeah and this is a great example of the working and Consulting you can see a variety of different Industries where those use cases are being applied and then you can look at some of these problems or challenges and think okay how can we automate because you've got that peace of mind of knowing is it's done before we go to a little bit more detail Tommy tell us about some of the challenges security issues that you help customers overcome yeah so uh like I said before with security specifically you typically it's on top of mind for everyone so companies are generally willing to invest right but they want to make sure they're investing in something that's going to have an outcome of the company being more secure um so usually we work with pretty well staff teams you know they have a lot of really good really smart people um leading these efforts um and they've invested a lot in a lot of tooling right so we want our company to be secure there's tons of tools out there to help us do that and that we need to do that um and companies invest a lot in these what that typically leads to is um just companies having you know a huge uh stack of tools for security on security operations so like I said earlier that leads to these analysts um really spending a lot of time not just using the tools to solve their problems but transferring information between those tools you know taking logs out of a firewall and emailing out to a team to see if they recognize the the information and email and a firewall team to block something so you know it's a lot of manual steps there um and yeah that just leads to those security analysts not really able to focus too much on some of the more complex issues they're spending a lot of time just swivel sharing things between those tools and when you when you look Tommy at you know improving efficiency you're reducing costs or you know improving the customer satisfaction either internally or externally people may not think about you know security concerns and how they may impact these different areas but if you've got any examples that come to mind or best practice or process that you usually use that actually helps customers on this journey yeah so uh one example kind of that meets up to all of these points I just talked about right is um working through a phishing incident so fishing has been a big problem um for a long time it really came to a head I think around covid it became even more of a big problem with people being remote people were working solely at emails you can't just lean over and ask a co-worker if an email seems legitimate or not so there are a lot of targeted campaigns that really started going on and we saw this from our customers a lot of customers we worked with previously doing say security incident implementations um we're able to take that information they saw uh out of that in the original implementation report back on it and say wow we're getting a lot of phishing incidents we're spending a lot of time manually managing these figuring out you know these 10 people that reported a phishing email or is it part of a campaign or being targeted or what are the next steps there it's something like 30 of security incidents organizations typically see are are phishings that's a huge use case right there so going back to finding you know a use case to align to phishing is typically one that most organizations are going to be struggling with and just the the degree of manual time that they spend typically just depends how many users they're supporting things like universities that we work with we found you know they might have 20 30 000 people reporting phishing emails uh to them and that's that's a ton to manage um so taking that uh you know we've actually ended up doing that use case a lot and uh from there have been able to put together kind of a pre-structured approach to automating phishing so um those 30 incidents that are coming in uh that are fishing uh there's typically a pretty repeatable process you can find that you can can do to handle those from figuring out a campaign to finding out if there's malicious things in the email all the way through to you know blocking things in the firewall resetting user credentials all of that um so one of the things uh I came up with at third era here was the uh what we were calling the attentive fishing offering it's actually a certified offering on the servicenow store but really what it is is taking all of our experience of having done this lots and lots of times and helping lead customers through the best way to approach this so like I said removing that you know we just want to automate everything right that's what everyone wants to do but we're taking this specific use case taking our experience and we've done it many times and waiting customers through a specific roadmap of how are we going to go and automate this thing we know is a big problem for pretty much all companies and going to save companies a lot of time of things like like I said figuring out if we have a fishing campaign going on sending an email out to a firewall team to block things let's see how we can use the servicenow platform centralize that work and then automate all of those manual activities which which gives peace of mind to customers but you don't have to keep Reinventing the wheel because you've got a process the certified people can actually know okay we know this works we know that there's a lot of insight behind this and it's being rolled out across different areas tell me my last question to you as the platform evolves where do you see the future of service now yeah so I guess I'll answer this question in two ways first uh in the security space specific place and that's where I focus on then maybe a little higher level um so in the security space uh kind of short term what I see is servicenow is really investing in Partnerships with uh other security vendors security products um and customers are going to see a huge benefit from this because when I say Partnerships what I really mean is servicenow is reaching out and you know Finding use cases that they can have with these vendors building store apps working with Partners like us to build offerings that might combine a lot of those store apps and what that means is if you want to go automate a use case in the security space a lot of the time those tools that you already own that are not servicenow that you want to go automate on there's going to be a pre-built integration for that out on the servicenow store and that really helps you to be able to just plug things in and get up to value a lot quicker when you're working through some of these use cases um and that's kind of uh you know what we're seeing not just in security but across the platform right servicenow is trying to take that idea of not just approaching automating everything but aligning to use cases right so um you know in the security space they have the new DLP workspaces for example that's another big issue companies see and and that's a use case that we can align people to on in servicenow and servicenow has really partnered with a lot of other companies to make that easy to go and automate um across the platform you know really it is just expanding to other areas of the business right so servers now started out as an itsm tool pretty you know for the most part um and and now we're seeing you know security operations still kind of being I.T focused but expanding but also things like HR Legal Services delivery I think we're just going to continue to see that expansion um to all other areas of the business right because it's not just I.T that can benefit from a tool that can go automate manual tasks or there's manual tasks all over the business and if we can set those up in a structured workflow and again remove people sending emails back and forth that might get lost that's gonna uh really make some uh businesses run processes more efficiently I I love your approach to kind of splitting up as well it's particularly interesting times and you know in 12 to 18 one second I could see that further Evolution coming together and you've been listening to all this podcast part of our servicenow series we've had the pleasure of chatting with Tommy Lamont Tommy is a principal consultant at tedera Tommy thank you very much for your time today yeah thanks for your time too thanks for listening to this episode of the all this podcast if you enjoyed today's episode don't forget to subscribe rate and review we are available on Apple podcasts Spotify and any Android podcast of choice you can also head over to our website www.aldis.com to listen to more podcasts view our open roles and stay up to date with industry news thanks for listening and stay tuned for more great episodes coming very soon [Music] thank you
https://www.youtube.com/watch?v=JNAPEVt4w2w