Connected Devices - Challenges and Solutions - Recorded July 20th 2023
Welcome to our digital service Forum bi-weekly call today we're going to have a bunch of people that are out in the field working on connected devices and talk about some challenges and solutions and what's really cool is we're going to start to dive down into industry specific challenges so I'm looking forward to learning a lot about this myself it's an area that I don't get to see a lot before we start we always did a little bit of level setting just with what the group is because a lot of times depending on the topic people might be here for the first time so if you are here for the first time if you could drop your name in chat and just tell us where you're from the the group the the URL at the bottom here is a link we tried to put everything through the group in one spot at one point we were getting all over the place so right now we have this one page that lists all the resources for the group there's that Zoom registration that most of you found because you're here today there's going to be a forum home page and this way if our presenters like the presenters today want to share some of the content that they presented they can put that on the Forum and this way the video will be there and the information it was so it could be a little bit of code or presentation or maybe even a blue paper our YouTube channel holds all these recordings so you can always go back even even go back I think up to a year and see all of our bi-weekly calls for the last year and then the last one is there's a shared instance out there it's a little beat up right now I'll be honest with you but uh we share a lot of configurations on there because a lot of times people don't want to be sending around update sets so they'll just set their demo up on that shared instance and say look if you want it just go there and see what we did so if you send me a a request I'll give you an admin login to that shared instance and uh I do a lot of my demos off there when I present so this way you you could see the configuration firsthand as an administrator and decide whether you want to pull some of it or all of it over into your instance so I'm going to post this in the um just so you have it I'm going to post this in the comments and that'll give you that'll give you a hook into everything so you you can go to that one page we created this group at the beginning because a lot of my customers were they were confused about the common service data model and cmdb kind of the core of Service delivery and what we realized that a lot of people needed this data needed this configuration or the metal model right to do their digital transformations so our mission changed a little bit instead of just cmdb stuff which it was when we had our first two members back in 2018. it's become more about enabling people to drive digital Transformations which is really inevitably what they were trying to do when they were looking at all the cmdb stuff so we try to get share as much of the customer work and as much as the servicenow information as we can with you so that it's again out on that Community mostly is where you'll get that our whole team this the Enterprise architecture team that's the team that I'm on our team is the one who hosts these meetings so we're out trying to get our customers to speak with us and come in so that we can have really useful content for you and the main way that you get information here is going to be this bi-weekly call so as long as you're on the bi-weekly call you'll get most of what we're doing we might do like a sidebar thing like a little workshop or something from time to time but if you come to these bi-weekly calls it's going to be the bulk of it and it goes from really business level stuff to to really down in the down in the weeds cmdb stuff so just make sure you take a look at the content each week when I post it out there you know that one's for me or that one's not for me so today what we're going to do is we're going to talk a little bit about the problems around connected devices we have some Specialists on from our health care some Specialists on from our utilities and Manufacturing and then some of our product team on here to help you talk about what the solutions are that are available today so for all of our content today I want to hand it over to Sir jit he's going to kick us off I think you can just take share away sergeant yeah everybody okay to hear me okay yeah Yes sounds good okay let me go full screen uh I'm sharing okay as well yep that looks great all right well good morning everybody um and uh afternoon evening for wherever you are let me start by just doing a little bit of an introductions we have three speakers today and I apologize I should have put all the names on this slide but my name is surjit aluwalia I'm part of our Enterprise architecture team I work alongside with John and others here at servicenow and um I've been at service now for a little over a year have been working in the healthcare space supporting Healthcare customers actually globally for over a decade um we also have Jasmine Rogers and Robert rash who are going to partner with me and talk a little bit about um you know connected and we're going to focus on OT devices let me give them the floor just for a minute to introduce themselves Jasmine yeah hi everyone uh Jasmine Hodges I am the senior outbound product manager for all things Healthcare and Life Sciences in the industry product that we've built revolving the vertical so really really nice to meet everybody today and look forward to discussing clinical device management folks uh Robert rash I'm the outbound product manager for otm the operational technology Management Solutions here at servicenow been here about three years at servicenow I've been working in the manufacturing space in the plant floor for probably about the 25. I'm very excited to talk to everyone today about the solutions that we have operational Technologies appreciate it wonderful great so just to expand on the agenda a little bit before we dive in um like I said we're going to focus a little bit on OT devices um I'm gonna spend a little time just talking about the challenges you know um especially if you think about it from an Enterprise perspective I'm going to do a little bit of a deeper dive around workflows talk about the Cyber challenges in addition to just the brake effects maintenance and support um and then Jasmine is going to talk to you a little bit about what are we doing and our Solutions in the healthcare space um and then at the tail end we'll have Robert talk to you about um you know what what and how are we doing this in the manufacturing space utilities and and hopefully you'll see that we are all uh you know the challenges are pretty similar as well as you know the solutions are pretty similar as well okay somebody's trying to call me right in the middle of this okay Okay so let's dive into the healthcare space a little bit and you know I offered this slide a few years ago now I think everybody would agree Healthcare has been in at an inflection point you know in health in in terms of challenges and digital transformation for some time now you know costs of healthcare especially in the US you know exceeding four trillion dollars and that is unsustainable um you know I put this slide together basically saying you know if you're a Healthcare System you know you really need to be thinking about digital transformation if not you know there's Acquisitions mergers other types of you know things that may not be desired that might happen I'll share a recent example um you know we were talking to a health system and I was talking to them and they were like you know we're literally losing and this is this year right a million dollars a day right um their challenges are how do how do we reduce costs and this is a medium-sized Health Care System right little over a dozen hospitals they've got challenges around and how do we reduce 150 million dollars um in costs you know relatively quickly we're talking six months a year if not sooner and at the same time they're they're looking at how do we double ourselves in four years how do we improve our caregiver experiences you know reduce the the turnovers happening how do we improve patient um outcomes patient experiences they're transitioning to value-based care because a lot of the reimbursements are happening that way and you really take a look at you know the old Paradigm new paradigm there's new service entrance security starts becoming interesting especially as everything becomes digital um you know you have um you know essentially first mover innovator advances dare I say in the new paradigm now we have chat GPT right we all have to think about especially from a healthcare standpoint and I definitely need to get up that one in there okay so for talking about OT devices and I want to take a little bit for a second into okay so let's talk a little bit about the specific challenges challenges in the provider space you know we talk about cost which trumps pretty much everything these days right but what are some of those those next layers that providers are focused on securing data devices you know it's no longer an I.T problem you know we've got OT devices now connecting to the network I'll talk a little bit more about that in a minute here experiences remain top of mind right caregiver experiences care team experiences and and of course the healthcare system is now changing where the patient is at the center of everything right or the individual and how do you really improve their experiences regulatory challenges have only continued to increase and primarily because they're also trying to figure out what is this new digital world and you know how does that change the landscape of what compliance is and how do we keep people safe right and and that's a big focus on the right hand side some business initiatives right how do you move to anytime anywhere care these are you know top of mind for the Business Leaders I talked about value-based care bundle payments the the entire landscape of fee for service you know you go in you take some services for healthcare you pay for it as it's changing that mindset is changing too how do I number one prevent you from getting to a hospital in the first place but more importantly keeping you healthy and improving the quality measures which then result in more money and I might just say you know reducing inefficiency you know everything in healthcare at the end of the day is about a workflow right um in different places different departments um we're going to talk a little bit about the challenges for OT workflows security workflows maintenance workflows today and some of our Solutions so we keep going so a little bit more of a deeper dive so let's talk about connected medical devices right and we'll talk about other types of connected devices as we talk about the other verticals why is this trend increasing right so a lot of us are familiar with you know Affordable Care Act if you've been in the healthcare space also known as Obamacare right that that around 2010 time frame everybody was okay we got to deploy emrs meaningful use stage one get everything digital less than 20 percent of Healthcare Systems had any kind of EMR right just a decade ago today more than 90 of them are going to say hey we have an EMR deployed but you know I think the struggle has been okay now we got it deployed now what right how do we bring value out of it how do we use it for basic decision support alarms you know meds workflow how do we take it even further and do clinical and interoperability Advanced decision support really helping leverage the digital Technologies to be able to deliver care and when you start getting the onion what's really needed is not just the health record that needed to be digitized but all the OT devices your X-ray machines your lab results you know all the devices that have all that rich data how do you tie it with that health record and you bring all that together before the you know seven minute eight minute encounter a physician has with a patient and the you know the the medical staff is almost demanding right they need these devices connected they need that data connected and you can see an approximate five-year growth on a chart that I put I think this is from markets and markets around just how much each of these devices just continue to grow the connected devices and and and then we'll talk a little bit about what does that really mean you know in terms of workflow challenges in terms of cyber challenges just gonna build this slide out um you know you connect these OT devices and then you're like okay so you know what what new things do we have to worry about right with these devices we know about the complexity um you know there's a multi-bender environment out there when it comes to medical devices and there's workflow challenges right so there's that complexity you have this whole um idea around I.T skills you know once you start connecting these devices to the network they are just like computers right servers desktops mobile devices all those wonderful you know risks challenges opportunities benefits they all start becoming real when these devices start connecting and the interesting thing is you know historically the clinical engineering teams in hospitals have focused on they know how to fix circuit boards maybe even fix a broken handle for a city CD scanner scanning machine but they're not really comfortable with what what is this I.T and what is this network right and the IT organizations are exactly the reverse right there's they're always guarded against okay well this is FDA regulated we better be really really careful you know we're comfortable with switches and routers and computers so there's that reverse skill set you know Gap and then you have challenges of you know we have old systems old machines I don't know how to patch them because the operating system is too old right Microsoft won't support it or Linux doesn't have support for an old implementation what do you do right these are millions of dollars and I'm going to talk a little bit about security and security challenges um you know it's it's safe to at least mention here you know some of these you know ransomware attacks in in challenges in fact I think the next one is really Financial challenges they can wipe you out right we've had Healthcare systems that you know have had over 100 million dollar impact you know one ransomware attack you know not only creates Financial challenges but also it has a brand challenge you know and and all the other risks that come along with it um you can see some of these numbers are huge right um sometimes these devices are mobile and they're connected and they you know they disappear or people are searching for them might I say you know nurses and sometimes care teams like to hold on to these devices you know because they want they need it for their patients and that creates an interesting challenge for Healthcare Systems the FDA is obviously you know continues to try to get ahead of this and say net new devices you got to make sure you have a security plan or or you're not getting the the approvals um in class one class two class three devices so it's a big Financial implication patients a couple more slides I'm going to dive a little bit deeper around how a healthcare organization deals with this or the challenge they have on a day-to-day basis and then I'm going to hand it over to Jasmine here to talk a little bit about our approach our solution how are we thinking about this and solving for it at an Enterprise level right that's what you um expect from service now and that's the approach for taking so this slide talks about you know step one you know in the OT space in in hospitals first order or business you need to get a good inventory of all your devices and you've got a number of of um you know solid Solutions here you know many of us have heard of Medicaid order arms you know they do a pretty good job now of detecting and really collecting the inventory of all the the devices especially the connected ones um and once you have a good handle on that then you're like okay I gotta do multiple things with it number one I got to do break fix support maintenance and this is historically what clinical engineering teams have done right now they've got to worry about this added Nuance of security especially since the devices are connected and then you're trying to figure out okay what is that security challenge mean how do I create patching for the devices where I can apply a security patch and I'll show you a conceptual workflow in the next slide what that means um if I cannot patch that's where step two comes in I gotta work with my it team I got to put some networking compensating controls you know put some firewalls maybe some access controls um you know segmentation micro segmentation because these devices at the end of the day do need to send data between the device and the health record you just want to prevent anything bad things like bad URL or access or telnet or FTP which don't which you know is not something that a CT scanner should be doing right so you've gotta you've got to block those things and then you know the challenge goes beyond just security it's around trust a lot of Healthcare Systems will tell you they're worried about you know patient safety you know with so many literally over a thousand pumps in the hospital trying to make sure that you know the the injection of medicine is not tampered with and how do you create trust and integrity those are some of the things how organizations are dealing with one last slide to set the stage here for OT and the challenges and this one is a little bit of a conceptual workflow cyber management right you get a an abnormal flow or an alert or an alarm from your Security operation Center and you're like okay what does that mean you know for my OT devices do I have a vulnerability if I do I need to go check with the OEM and I have literally hundreds of oems right in my hospital um and there may be a multitude of systems that might have vulnerabilities then if I get a a notice from them saying you know here's a patch it's validated you need to deploy it if it's a day Zero vulnerability you know you have urgency to it how do you create workflows around getting it deployed syncing it up with support and maintenance then if it's in you know there are Legacy devices involved what does that mean get it involved build you know Network Solutions to protect the devices while all of this is happening you got to make sure you're complying with HIPAA you're you know managing audit challenges so I mean this stuff gets complicated quite fast right and I might add there's a lot of disruption because at the end of the day the the hospitals have to care for patients while they're doing all this so I think I set up the challenge pretty good now the question really becomes what are we doing about it and how are we planning to support our customers through this journey I'm going to invite you Jasmine to take it from here absolutely so taking a look at you know with all of that being said what are we actually solutioning around uh this mean for medical device management uh well if you're familiar with servicenow you know that since our Inception we've been doing it Asset Management true end-to-end asset management and so what we're doing now in that context is we're taking everything that our customers know and love everything we've been doing for quite a long time and we're verticalizing it and we're applying it to this specific problem in this specific solution here so everything from uh you know in a clinical engineering setting being able to procure devices being able to receive them bring them on board deploy that asset in the field appropriately configured against you know The Specific Instructions or needs revolving that device in the clinical setting it's residing in and of course making sure that within that we're maintaining and managing the science and security and also any type of vulnerability response that we need to be making making sure that throughout that process everything is also auditable and compliant and we're able to identify and manage any uh you know risks Associated throughout that process we also want to make sure that there's a heavy Focus as well on handling all of the servicing of that device so not only just the typical you know corrective maintenance that might be occurring in an actual hospital setting but even extending to the devices that are extremely mobile or are more remote because they reside in a sort of Care at home setting so making sure that you know not just from a repair perspective but also from an ongoing maintenance servicing perspective managing recalls and those you know pose a lot of vulnerability and risk to both the organization and to you know ultimately the patients that are being that are interacting with these devices or you know utilizing these devices as a part of the services that they're receiving and then of course all the way to the decommissioning so making sure that we are following the appropriate steps and of course still maintaining compliance in terms of how we're disposing those uh properly and securely making sure that we're taking into account any of the environmental impacts that um you know may be associated with that device could be potentially refurbished and so ultimately all that being said with that end-to-end medical device management making sure that we're able to not only just optimize the device operations but also reduce the total cost of ownership those costly trends that we just went through and ensuring that these devices are at their maximum availability for patients in both the explicit care settings but also the course at home so looking into the specifics of how that's informing our strategy here so ultimately we want to drive back to these three pillars here so of course we want to make sure that we're providing value in terms of efficiencies making sure you're able to stay compliant not just of course within an organization but especially with those you know industry entities that uh you know require certain levels of compliance in different areas and then ultimately making sure that you know we're driving higher patient engagement because our clinicians are able to not spend time looking for chasing down devices but having everything appropriately available to them in service and maintained on a consistent basis so really these five pillars that we're looking at built on top of our now platform are the five areas that we're looking to provide this type of value and it really drive back to those three pillars here and then in addition to that strategy you know this is really all of the different areas that we're taking into account these are questions that you know or or responses that are coming from both our customers and from the market based off of these trends that we've gone through that are informing the strategy so this can be everything from you know a visibility perspective just knowing what devices do we actually have what what do we know about this what do we have historically uh making sure we can truly provide that end-to-end out of the box solution with servicenow in terms of that clinical device management from a security and vulnerability perspective making sure that our devices are secure from any threats um and and we're compliant as well with any of the security requirements that we have to abide by as well and then from a maintenance perspective both making sure that we can maintain our preventative maintenance schedules as well as also take into account the nuances and the consistency necessary for the alternative equipment and maintenance procedures of course from a Regulatory Compliance being able to understand and meet the industry-specific regulatory requirements that revolve around these devices um and then of course some of performance optimization making sure that our devices are in service and at their Optimal Performance and optimal utilization as well in terms of those devices and then lastly of course just making sure from a servicing perspective that we have the ability to document and audit all of our repair checklists that we're following all of our standard either organizationally defined procedures or manufacture defined procedures as we're servicing these Assets in and out of service yeah just a quick comment I might add um Jasmine you know think about Enterprise um challenges you know consistency across it and OT because in a lot of these things we've been doing um in the I.T space and now extending it to it it really helps make things a lot more efficient from an Enterprise standpoint so just wanted to add that block and then we take a look at what the ecosystem looks for this solution right so we're leveraging uh Integrations for device Discovery with uh different medical device specific uh Discovery tools so we have different partners like medigate for scout Dependable armis that we're utilizing via what we refer to as our service graph connectors to be able to connect those back into the platform and not only of course they know what devices we have and model out the associated details but also tie those directly back into any necessary device workflows that are also of course informed by additional integration so we have the ability to integrate with equity for sort of that data normalization we have recall management that we can integrate to as well in that context and then of course you know making sure that we're able to manage you know the different parts ordering or part modeling via Integrations with Part Source and manufacturers as well and then of course for those non-connected devices are also very important to know you know what we have where we have it and still continue to keep track and also tie it back to these main device workflows that we have we have the ability to of course intake anything any sort of manual tracking that may be sort of current process for these devices as well as you know RFID tagging and scanning to be able to still maintain an appropriate outlook on what we have in terms of those non-connected devices as well and so ultimately all of that being said this is what's informing our overall servicenow solution here so really this is the full stack of everything we have to offer so all of our core platform capabilities that you know as a customer you may may be utilizing currently and then of course layering that on top of the you know standard it workflows and the IT Asset Management aspect that we've verticalized and evolved into Enterprise asset management and that you know iomt setups capability that is industry specific here and then of course for my servicing and customer perspective we want to make sure that we've layered that on top of customer workflows so now we have our Healthcare cmms offering where not only able to you know service maintain and manage those clinical devices but also you know make sure that you're maintaining all of the associated service management details necessary as a part of that process uh so with that I will turn it over to Robert thank you ma'am uh well the uh we'll have a conversation around Manufacturing I'm sorry oh sorry um I was just going to take a quick pause John or did any Healthcare specific questions we wanted to address before we jump in or just keep going I'll just keep going there's nothing in chat right now okay back to you Robert oh thank you sir appreciate it um so I want to talk a little bit more about going down that manufacturing or industrial space right and where we see those OT devices there as well as utilities because they are very similar paths in terms of your requirements and what they you know what they're looking for from visibility standpoint right but just talk about why we're seeing that uptick in in the activity there from that side of the that side of the organization I mean um one thing to notice right you'll see first right in 2019 we were the eighth most attacked industry right um from a cyber security perspective and uh recently we we got the honor to move up to first in the list right uh in terms of you know basically the main target for a cyber security attacks right so obviously there's an increased lens on and we see it in the news right and then media around you know some of the increased attacks in that landscape and the threat profile that that exists within you know that manufacturing industrial space why it's important right you need I think you know both uh you know Jasmine covered this right when we start thinking about downtime just from a security remediation standpoint um you know we often hear that you know a ransomware event can take you know a couple weeks to fully recover from right um if you combine that with the idea that you know we have the metric there between 250 700 000 is the average cost of an hour of downtime you know equate that to a couple weeks and then if you're taking consideration if they don't have those proper policies in place of uh security incident remediation right meaning you know in within the operational environment whether it's utilities or manufacturing right if um if you don't go through that process of safely shutting down equipment right um making sure that the area is safe and doing those all those operational tasks and playbooks that we can we can pitch in on right that obviously adds to that amount of downtime right this is just average downtime I'm just recovering from the security incident itself if you think about you know there's repair cost and that sort of thing that gets incurred along with that one right the cost can be exhibition um you would say 60 of those heavy Industries you know reported over each right obviously we know that there's you know unreported breaches back in 2019 but obviously that number is you know gaining traction every day if we look at the same lens from a utility standpoint surgery if you go to the next slide there um utilities you know we're fourth in the industry for the most attacked industry right again those folks are starting to realize that the uh you know the utilities landscape is a very good lucrative are you ready to uh to start those attacks in um and they said you know 53 at least had one or more of those breaches right which is fairly concerning from utility and critical infrastructure perspective but I think what's more concerning is 52 almost half of those could have been prevented right these are just you know simple patches that that could uh that left them open to those uh to those attacks right just simple process within their facility or within their organization can prevent those attacks um Sergey let's move on to the next one please hey Robert yes sir there's a question here does your does this device Discovery involve servicenow itom Discovery visibility or is it external tools I love it you know and John the most servicenow answer I could give is yes um because we you know and yeah I have an architecture cut slide that speaks a little bit to that but you know the OT environment right any OT environment is obviously very sensitive to active-based scans you know Michael I Tom Discovery or a solar winds or things like that um you know these are very you know uh you know I guess uh segmented and you know they're proprietary networks right for project protocols and a typical active-based Discovery just doesn't work with an OT right and um speaking from experience right they can break OT networks um and so you know we take a very hands-off approach from that active Discovery piece within within the OT environment so just like you know on the medical device side you know with Partners like RMS Force count Medicaid um you know we have a I have a few a little bit more extensive list of the partners on my architecture slide but we do leverage those Technologies because those folks are obviously experts then you know they know the difference between a device net and a profi net Network and that sort of thing and they can obviously identify those assets what they can do in the same regard this is kind of speaking to my yes answer is they can't being a passive scan just looking at passive Network traffic right they're not being very intrusive to those devices at all but they're not able to gain a lot of details when it comes to like server-based components or workstations laptops and that sort of thing they're not able to tell you what your CPU is or your amount of ram so we have a it's a very common motion that we have with customers when they're doing a deployment strategy an architecture strategy is a leverage that passive Discovery from one of those one of those vendors but they'll also leverage like an ACC or another agent-based deployment within those components to lean in a little bit more on those details right when we're when they're looking for you know installed software those sort of things that a passive scanner couldn't accomplish so we very much play in both of those spaces and we leverage obviously the reconciliation capabilities of service now to do that for us well I hope that answered your question Michael I had one more just to piggyback on that so we had have you set up any of these use cases where um like we were working on Department of Transportation and we had a control board in a street light control uh but there's this is a state government right so there there's tens of thousands of street light controller boards in all these polls is it and they were we were talking about the idea of a transient asset so it comes into service now when you need to do work on something or fix something but then it goes out of service now when you're done have have you guys broached on that topic at all oh 100 all the time that's very common motion within with an OT especially with an industrial utility space there's a lot of these assets you know from a you know from an OT perspective they'll only talk when needed they don't Generate random traffic because you know just they want to broadcast a message right they only talk again when there's a command sent to them or they need to execute something so that's very common that we run into that and that's a fantastic segue to this slide you know with that disconnected systems and data that's one of the challenges you know the big one of the barriers you know we talk about utility energy and critical infrastructure but with any OT environment or industrial environment right it's it's not just a simple you know challenge of the visibility in and of itself and being able to realize that you have that asset on your network but also the context of that asset and what it actually drives and runs and what it operates and what its dependencies are and that sort of thing hopefully that answered that question it was a great segue as well yeah thank you that was good no appreciate it appreciate it so this is a this is kind of a road map if you will and what we want to address when we talk about that investor landscape whether it be manufacturing or utilities or critical infrastructure mining right if they have those OT assets that exist within that space right we start again at that visibility level right and when we say a visibility inventory of those OT assets again it's more than just providing the customer with a list of things that exist within their space but it's also that context around it again you know we need to know what those devices run you know are they part of personnel or equipment safety right critical production critical data that sort of thing because once we start addressing these other use cases within the landscape around security incident change that sort of thing right the folks that are carrying out these remediations these plain boats need that context right they know the business impact of what they're about to do from a visibility standpoint you know is this going to cost me a few hundred dollars of downtime or is it going to cost me a few million dollars of downtown and that obviously helps prioritize and work through some of those workflows and obviously assign that work accordingly incident change is something that's coming up a lot especially on the compliance and Regulatory side of the house right they're wanting to have not only you know have visibility into that incident change and Patch management process but obviously those gates at every step of the way and being able to log the log that information very common utility space where they have to report up each step of that incident and change process to those regulatory bodies then we're going to start addressing Health right when we say health we're familiar with cmbb health OT or it asset Health do the same thing on the OT side as well so think about things like you know my motors are running properly or my belt just broke or my Transformer was performing the way it should right so applying those same ITIL processes that we've taken advantage of in the I.T side of the house but applying those to the OT side of the house bringing in that context again you know what else is this Transformer depended on what else do I need to shut down what else do I need a power has or or a schedule a maintenance window for when applying those same processes right and it's very important to to kind of take on that realization that that we you know when we're engaging with customers right that already have a good ideal process or visibility policy or a security policy or that sort of thing when they start addressing that OT landscape they're not starting from scratch right there they're not you know they're they're it's not that you know 800 pound gorilla that they believe it to be because they we already have that those policies and procedures and things that customers have built up on on the I.T side of the organization really the only thing that's preventing the roadblock to prevent is preventing them to uh to do those same playbooks and those remediation steps on the OT side it's just that operational context so that's what we're building towards give them that context so they can repeat some of those fantastic processes that they built on the I.T side organization um then we go on more to you know we like to call it the digital Factory right or um uh the digital worker if you will write some inspections checklists cleaning procedures things like that that are either you know are again you know if we think about the just the OTA landscape typically these are spaces that are you know we're just now realizing Cloud technology and iot and that sort of thing so we like to say we're at least 10 years behind the technology curve compared to I.T side of the business right so a lot of these checklist procedures and policies and Sops and that sort of thing these are clipboards they're fiscal white boards on on you know at the front of the line or that sort of thing right or they exist in someone's head on the maintenance side of the house so taking those same policies providing those uh you know those uh digitized to in a mobile interface and of course live site I asset life cycle that is a common use case that we're seeing within uh within OT as well managing that front to back life cycle of that OT asset especially some of the capital expenditure pieces of equipment and Rob before you leave this slide um with the passive Discovery how do you find the patch level how do you determine the patch level of each device uh that's from Andreas that question you know and the the tough answer is it really depends on the manufacture of the uh the device itself and the technology that's actually doing the scanning some they're not all created equal a lot of those security Partners but uh they are able to detect some details some better than others some of them are configuration based some of them are passive scan based but they do lean in on that now a lot of them can't detect what the patch level is but they can detect that there was a change change in password change in a firmware revision into that sort of thing um but from a um a patch detection or a vulnerability detection standpoint the same Integrations that we have with those security partners that give us information around the device itself also give us information around the vulnerability and that's one of the um that's one of the feature key features of otvr is not providing the customer with a list of here's all your vulnerabilities and the possible patches that are associated with them but mapping those back to the actual asset right so that we can get in front of our tests those uh those remediation steps and we actually patch that vulnerability yeah on my dad you know on the on the healthcare side um some of these tools so so the medical devices or publish um you know MDS to um I guess plant you know within the within the payload within the packet they have these mds2 um tables if you will that capture a lot of the details that that you know which operating system what type of security things like that and that is picked up by these passive tools that I think Robert talked about on the healthcare side as well and then that is one reference on the best you know known information around security for you know on on some of these devices um it's it's reverse engineered so just wanted to add that yeah so if I can add uh we are integrated with medigate and are bringing our entire uh biomed devices into the platform we are able to detect and determine the model and type of each one of our biomed devices however when it comes to determining the patch level on each one of them from a passive scan that has been proven to also be impossible so I'm trying to understand how that's performed on the OT devices and then when I say OT devices right I'm not even speaking specifically around you know drives and motors and plcs and that sort of thing um typically they'll correlate that patch management um that patch level to the version of firmware that's currently installed on that uh on that device and that's how they correlate those vulnerabilities that exist right and being able to match those up um it is a fairly shallow I guess a pull if you will of those folks that actually provide that patch correlation meaning you know if if I have you know this version of firmware that exists on this controller here's a list of available patches and you know links to those I think foxgard is one that are starting to build integration into servicenow I think they're obviously that's growing because that's from the utilities perspective right that's something that needs to be managed quite diligently right I think they have a 30-day window between a time a patch is released and they remediate that patch or come up with a remediation plan so it's a very short window of time so a lot of coordination efforts need to go to from level two uh actually address those yeah we can see the the patches that should be applied to each device but we don't know what the patch level of each device is in that Gap is what vulnerability means and that's what I'm asking you know for sure yeah I think I think on the on the healthcare side Andres um you know I think that that remains the company that's why I talked a little bit about the complexity right I I think it's a it's a journey to protect these devices I mean you're getting some amount of data on current state from those MDS to you know information that is published by these devices but you know once an action is taken you know how do you keep track of okay I patch this now is that being reflected in the end state of that device are the net new I think that's a journey that we are on to try to help solve and make better um and we'll you know continue to partner with folks like you to see how maybe outside of what Medicaid does you know can service now start building a map of you know all the activities and patches that have been applied in the current state that that's something we can discuss under this thanks so Healthcare I'm just curious this was the question that was I think partially answered your device Discovery is really outside servicenow and you mentioned in the notes that cmms is not going to Discovery um is there any reason why your slide does not show the item discovery for this task did you really focus on external tools to collect device information or do you use iTunes Discovery in some sense but not in this particular use case yes so yeah sometime in there from a discovery perspective medical devices have to be discovered in a very sort of special way so a lot of our typical Discovery tools unfortunately are not going to be able to perform that type of Discovery so Technologies like medigate they actually do a sort of deep packet inspection so instead of reaching directly to the device which that would set up all kinds of security alarms and it also resides on different networks it's actually monitoring the traffic and based off of what medicates technology knows from the deep packet inspection it's performing it knows what device that is it knows certain details it knows the anticipated behavior and all of those different pieces so that's why we're really reliant on and do depend on those medical device specific Discovery Tools in order to be able to perform that our typical you know Discovery or even servicenality Discovery in that case is not going to be able to discover those medical devices in a way that really needs to be done for that absolutely thank you and also in this space Have you ever encountered the order as an as a vendor or worked with ordr what they also yeah yes yes um I don't know that I can speak to the specificity of the technology but I can say that um medigate we are uh was sort of one of the initial technologies that we strategically partnered with and mitigate explicitly worked with us on building um their integration uh directly with servicenow um so I I can't speak to the you know technology itself but I can't say in terms of uh you know partnership and integration we've worked extremely closely close together um in terms of you know what we're building out for clinical device management yeah and I might add to Justin what you're saying you know I think um Medicaid order you know they've been they've been doing this discovery and cyber security space for a few years now I think Mayo Clinic uses order um and they've been using it successfully so I think our approaches you know we'll support all of these tools and the customers decide what works best for them thank you hey John I can add it a little bit if you one go ahead yeah so so we use a product called assembly and we have ixia TAPS at the edge that that captures that that data and puts it into assembly right and then we have integration points with assembly and so because to your point you can't just interrogate these devices you may take uh a critical medical device offline through an interrogation process awesome yeah yeah just a simple ping can bring your device down right if you've seen that happen so yeah totally anyway that's our experience for that's the tool we're currently yeah there's actually half a dozen tools you know that do similar things right so it's really up to you in your preference go ahead was that another question yeah this is Jeff Aldridge from Excel Energy um and you know one of our tricks about getting into rot environment is they already have some tools that are doing some of these things so if we were to add item discovery and now we're doing we're double you know potentially duplicating some of the effort that's already going on wasting time and traffic and so you know we're looking at how do we incorporate some of the things that they may already be doing to to achieve the outcome that we're trying to get to which is a comprehensive picture of what's going on in that environment It's a combination of things you might want to do to get to get to where you're going right OT customers as well right and I don't have I don't get I have a single OT customer that has just one point of ingest for the cmdb from an OT you know perspective right now it'd be great if we could just you know deploy you know a drag host at every single facility and only have Rockwell plcs but that's just not reality right you know we're going to have different environments and different networks and different Technologies and that sort of thing but um you know we we tend to go to the direction of leveraging the best of any and all discovery possibilities right you know I mentioned the ACC is one you know so we can we can get a very level landscape of of the entire environment right with you know without being intrusive right and running those active scans so I like the question I put in the chat but I mean we have industrial Defender we also have dragos in some cases we have a few other things I was I'm wondering if this could become offline but is there a list of what servicenow is currently already set up Integrations with to make this easier versus things we have to go do and pull it pull that data in manually and go through reconciliation processes other such things you also know that oh for sure actually uh um after after my last slide I'll post in the chat a link to our current list of service craft connectors that are Integrations that are available and all those that you just mentioned are on that list so if you want to go to the next item you've got it um to uh just to address you what we're doing and how we're doing it within the OT landscape and the otm product itself these are not you know I want to point out these are not you know obviously new Solutions right but one thing that we have discovered is our traditional I.T based you know Solutions because of you know what we see at OT of the challenges and the network types and the segmented networks and you know priority on the devices and that sort of thing we couldn't shoehorn our existing you know it based Solutions within the OT environment industrial or utility right there's a lot of different you know controls around the severity and the security and that sort of thing so what we've done is we've purpose built Solutions around you know visibility service management and vulnerability response based on their their I.T equivalent to address the you know that OT we like say industrial landscape whether it be manufacturing utilities oil and gas that sort of thing we pay a little bit more attention and a little bit more focus on the visibility component because obviously those you know those networks and those those process are built much different right and we need to take a special care in terms of how we contextualize those devices right but once we do get the intent is to leverage the same policies that we've done so well in it on the OT side of the house right we you know we don't have a dedicated stock team just for a plant environment right or we don't have a dedicated I.T team just to handle I.T remediations on the plant floor right but they need that context so these are uh you know again solution excuse around OT visibility OT service management and OT vulnerability response if we take a look at the next one this is kind of a very high level architecture of what that landscape looks like sure if you learn to uh to go to the next one there um no different than you know the medical devices right we do leverage heavy on the Integrations for some of the partners this is just a short list I'll include our more contextual list at the end of the uh at the end of the meeting here but these are pre-built connectors that are you know these Partners have built to scan those devices in those networks safely um and they obviously populate not only the cmdb they give us some uh some context around the equipment model itself and where these devices live and play and their responsibilities and independencies are within the plant floor um but uh they also give us an indication of the vulnerabilities that exist when it knows within those devices as well um and that's part of that OT visibility uh offering in that skew now once we again once we have that context right now we can start taking advantage of that context around how do we respond to be at least proactive to uh you know or reactive to those security incidents and how we manage you know OT incident and change you know um when we say OT incident that could be any sort of incident within a platform it could be at a device level right you know my I have a fault light on a specific component or it can be an operational level you know I have a belt break you know I had a you know my pump blow up my tank got too full those sort of things but how we take those same ideal processes and provide that provide that thinking and that that Playbook remediation steps and processes to a landscape where it really doesn't exist right again these are all paper records they're all you know manually um you know they're a three ring binder you know white boards and that sort of thing but um I think that wraps up I'll take it back to Street if there's any questions and I'll again I'll post that uh that link to the uh full list of um service craft connectors that we have available for OT all right I was unmute there um any questions that and we had some some good exchange around the challenges of collecting data on these connected devices right making sure that security updates are reflecting the current state um we got that one um I think I Tom and some of these passive Discovery capabilities I think you know the comment there might be you've got it like we said you've got to have all of the above and and build the the best known Enterprise asset management system out there current state so that you can manage the devices that came up as well anything else that we missed John in the last minute or two we could cover for the team I think we're pretty good unless anybody wants to come off mute anything that wasn't asked in the questions okay I could take the last minute and share a little bit about what we're doing next week if there's no more questions um and and search it does be able to provide all that material today that you guys uh okay so I'll make sure I put that on the community I'll send it to you and you can put it on awesome thank you guys very much that was really informative appreciate it thank you I'll just cover this briefly in our last minute so for our next meeting uh we're gonna have a special guest speaker that's uh that's an author and what we're going to talk about there's been a lot of we've had a lot of conversations around value stream mapping uh the last couple years and we're going to go ahead and especially with the new part where servicenow has value stream Management in there now for those who don't know a lot of you don't know about it yet it's on the store and you could just add that to your your base models so what we're going to talk about is value stream mapping so the actual art of creating a value stream and Mike osterling is going to speak about that so he's he's one of the authors of the value stream mapping book it's what we use here it's kind of the Bible what a lot of us uses the Bible for for Value stream mapping so it's gonna be great to have him on but also we're going to have Mark on to talk about what the servicenow plan is for doing value stream management once the map's done so those two are a lot of synergies and a lot of times you'll you'll catch somebody talking about one or the other but to have somebody talk about them both in the same meeting is what our real goal is so that we can see end to end we can think about tie-ins to csdm like we talk about a lot on here so I'm really looking forward to this one and that'll be on our August 3rd meeting so we'll send out some invites to that so that you have them okay one last call for questions on the iot stuff or any any questions on the agenda all right thank you very much everybody we'll talk to you in a few weeks bye-bye thank you bye-bye thanks folks
https://www.youtube.com/watch?v=7zhWWk_ShlE