Boost Compliance with Global Data Privacy Laws through a Joint Solution from ServiceNow & RadarFirst
okay perfect we're given a couple of minutes there so hi everyone good morning good afternoon good evening from wherever you're joining from again I'd just like to thank you all for joining us on today's webinar which is to boost compliance with global data privacy laws through a joint solution from service now and radar first so let's jump into it firstly just have to cover off uh a sip Safe Harbor notice just quickly cover this off um we like to try and be as transparent as possible when we can come to any future statements when we discuss our products but being a public traded company we do have to make sure that we do align to um make sure that you guys know that they are future statements they are subject to change so please don't make any purchases and decisions on any forward-looking statements however saying that we do try and be an open and as honest as we can so you know if you do ask any questions we will or we're happy to be as open as we can with regards to any forward-looking statements on the product so um we have a lot of webinars going on at the moment so you may see this now on the the service on sorry on the service now community and today's session is actually part of a series of sessions on live on service now these are created event Series where we're trying to connect you with service now partner experts Andel peers to basically see and help you deploy your products achieve the uh your value faster as well and so you can access this schedule by scanning the QR code that's handly on the screen right now and and we'll also post it in the uh chat for you as well we'll post a link there so you can access all those webinars going forward as well so with that we'll go to next one again just a few housekeeping points as we go through today's webinar you will be on mute but please use the chat feature add in any points that you want there we also have a Q&A uh feature at the bottom that you'll see on the zoom uh features please ask your questions through there we'll have we'll have time at the end to go for all the questions we do also have some team in the background that will be going through and answering any questions as they can on the fly but we'll allow some time at the end so don't worry about that as as well it is being recorded as I said it'll be shared on the service now community so this will be there along with all those other webinars as I've just mentioned from the series and also after the event you'll be prompted with a short survey so when you close down the webinar a short survey will pop up please take a moment just to share your feedback it helps us to develop any future topics that you want to see uh any future product features as well that you want to see and it's a real valuable source of information for us at service now so we'll jump again to next one so my name is Andrew Bowden I feel like I should have said that at the start to be honest nice to meet you all um I'm the risk outbound product manager here at service now I'm also joined today by Travis Cannon who is the director of integration Solutions at radar first Travis I'll hand it over to yourself if you want to say a quick hello thank you Andrew hello everyone pleasure to be here with you today as Andrew said I'm director of integration Solutions at radar first I've been with the company for 10 years and I'm excited to be here and talk about our new inter ation with service now excellent thanks Travis so yeah for today's uh kind of webinar I'll be taking you through just kind of setting your mind about what actually is privacy management within service now so just to kind of set the scene into before we jump into the integration with radar first privacy Management in service now allows our clients to get a full understanding of where they sit with a privacy management compliance sorry where they sit with their privacy management and in particular their compliance to regulation so they can go through and understand on a granular detail where data exists within the Enterprise you know through automated data Discovery they're able to engage the first line with privacy impact assessments and bring that all into one place through reporting through dashboards to you know show how they're compliant with the everchanging world of data privacy so I come from and Mia I'm based here in London so we have to comply about you know uh gdpr but also the new Californian um CCPA new states in the US bringing out data regulations and so it's an everchanging environment so here are again a few more nice um points that we have within our data privacy solution where again you can assess dat data privacy specific risks regulations policies controls have that um data Discovery aspect in terms of out of the box Solutions with service now or maybe third party solutions that go out and scan your infrastructure and bring that bring back where that sensitive information is you can actually see as well a nice screenshot on the page right now of a processing activity a nice overview in terms of the compliance of different controls that nice risk heat map as well in terms of understanding your risks with regards to those different activities you can go do go through and conduct some privacy impact assessments privacy risk assessments and apply um continuous controls to monitor those uh risks and controls sorry going forward you can also um create issues remediation tasks and Monitor and track privacy regulatory changes through your regulatory change management product as well but let's jump into kind of why we're here today so we're here today to discuss our new radar first integration and that is one of the new features that have been released in our Washington release so another one that I just wanted to call your attention to though because you know it's one of many new features that have come out in Washington we do also have a one click email Communications and PDF reporting for compliant privacy compliance case so a quick export out into a pre-formatted PDF report that you can send on to the regulator if you need to or internally within your own organization and then again attach that directly to the previous case record in service now and then also in an innovation lab release so for a few select customers we're also looking at personal data rights requests which is there to enable their darar or data subject access requests program and how you can colate all that information together those activities all in one place in terms of going to collect that data you know if they want to be deleted or forgotten for example so that's coming in Innovation lab as well for Washington now again just to kind of explain how radar first fits together with the Privacy case management solution um within service now and we'll go through this as well actually in a demo shortly employees can raise privacy cases uh either through the employee Center so you know from a proactive standpoint to say there's been a breach you know we accidentally exposed some customer data or we can also through an API integration so through third party Solutions or through in service now itself maybe through a security incident response so the security operations team have noticed there's been a breach they can go through and do that breach assessment and then raise a pracy case from there as well now here you can see that we've got you know the different steps through that workflow like triage resolve post case review and close and sometimes you know you have to bring in a lot of different aspects of the business in terms of HR legal it employee so what we're looking to do with our radar first integration is to really speed up that investigative time you know instead of going from weeks days for example to literally M minutes and seconds for you to understand what risk does this POS to the business what risk does it pose to those exposed individuals data and then what to do from there in terms of remediation plans going forward and also notifications you may need to give to The Regulators as well so with this let's quickly ask you guys a question itself so poll coming up so how is your organization complying with the evolving state federal and International Breach notification laws so that poll will be launched now so you'll see we've got a few answers here so with a privacy Tech solution uh you're looking to do it with a GRC or irm Tech solution you maybe have your own solution in development at the moment you may be manually using uh you know spreadsheets or Word document for example to kind of keep a breast of all those different regulations that are coming out or what you're doing or you know being completely honest you're looking for help as well so we'll give a few um more seconds for people to answer those I'll quickly just run through the question again for anyone who didn't hear so how is your organization complying with the evolving state of federal and International Breach notification laws so you're doing it with a privacy specific Tech solution you're doing it with a GRC or irm Tech solution you have a solution in development you're manually uh using spreadsheets or you know word or PDF documents or again the final one there being honest we're looking for help with this situation at the moment okay so let's um we'll end the poll there that's been out there for a minute or so um so some interesting results I can see a spread of a few Tech Solutions few a lot of people using manual or you know using spreadsheets as well so I'm sure they'll hopefully see a benefit of the solution that we're going to uh demo to you today um but thank you very much all for sharing that with us and with that I will hand over now to Travis to go through the radar first solution and more detail over to you Travis thank you Andrew um and thank you everybody who responded to the bull question we we appreciate uh your responses there uh hopefully uh for those of you who are looking for a solution or maybe doing this process manually um we can show you a way to address this um so let's jump into this so really from radar first side you know we see this and you'll see this in the demo we see there kind of three big challenges especially when it comes to making sure that we're complying with you know the various breach notification laws that are out there one um they're always changing as Andrew kind of alluded to we're constantly seeing new regulations come up we're seeing changes all the time um and this often has some down you know some follow-on consequences right we see uh some inconsistent notifications going on um you may be assessing under the wrong regulations um and this can lead to kind of missed deadlines if you're not assessing properly if you're not keeping up with these regulations uh this can result in in missed deadlines which can then have further consequences maybe penalties or fines or other consequences that may exist so three really big challenges and I really kind of want to walk you through how we can solve these challenges and how we can make this a little bit better so if we go to the next slide you'll see you know obviously every Enterprise has a bunch of different risks that they're experiencing um and there can be huge financial impacts for missing uh deadlines and not adhering to breach notification laws um we know the cost of data breaches is increasing uh the cost of notifications are increasing uh everything pretty much across the board is increasing and this is only moving faster and faster as time goes by so this kind of exponential increasing uh you know amount of risk especially if it's dealt with or try you're trying to manage your breach notification through a manual process um becomes unsustainable and really what we're talking about with service Nows privacy case management and radar first uh helping provide a breach analysis is really how do we automate that how do we make your organization more resilient allow you to be faster at coming to the correct decision uh and then ensuring kind of the operational efficiency of your organization so let's go to the next slide and talk about where most organizations are today and how they try to address this which is usually through a manual process as we kind of saw in the poll results um and usually that is cumbersome usually what we see is you know an investigation starts there may be different departments there may be a assessment that's reformed it kind of goes back we see this very complicated kind of manual process that may have evolved over time to try and respond to all the different breach notification laws that are out there and demand manage these incidents Um this can be very cumbersome especially if you have a large instant volume if you have again changing regulations if you're trying to keep up with what's going on uh out there in the world or um if you have short notification timelines it may take you a long time to kind of get through this and this inefficiency creates a risk to your organization and that's what we want to try and help you solve and get rid of so what we want to do is take you to the next slide which is to apply as much automation as possible and to really help streamline this process manual processes can adapt quickly enough to the rate of change that's occurring inside of the Privacy World um so we want to think about how do we apply tools and not just implementing some process or some better uh kind of protocols but how do we deploy purpose-built tools to help scale to meet these challenges and again to create that operational efficiency within your organization so so what does that look like Andrew showed this slide a little bit earlier and we're going to walk through this on the demo that really means again kind of leveraging those purpose-built tools and applying them in a thoughtful way within your organization so that you can get that efficiency what we and just going to walk you through is how a case gets started inside a service now how that kind of matures and how you go through the investigation and triage process and then he's going to show you how the radar first integration actually ties into that and then I will show you a little bit more depth about the radar integration and kind of give you a little bit more uh information on that itself but really this whole process the whole goal of this is to take your response time you know instead of being you know hours or days we want to take you down to minutes or seconds so that you can get the right answer and respond appropriately for your organization now the next slide of course what are we talking about when we're talking about a radar assessment and helping automate that well this is a really good question we affectionately refer to the this is our is our brain slide for obvious reasons but if you think about an assessment and when you're profiling an incident and trying to understand is this notifiable or not there are a lot of factors that go into that you know obviously when did it occur what are the data elements involved which jurisdictions are you talking about what are the different kind of risk factors such as the category was the information encrypted who received it all of those things have to come together so that you can perform an assessment and make a determination on what your notif ification obligations are the nice part with radar first is that we've automated this entire process so we have all of the breach notification laws turned into software and at the click of a button or literally in service now at the click of a button um we can provide you with that assessment and show you what your notification obligations are so that you know exactly how to respond appropriately to the incident um on the next slide you could see obviously we support regulations around the globe we have have full Global coverage of all breach notification laws around the globe um obviously all the states here in the United States as well as most of the federal laws here in the US but also gdpr uh and and Beyond so you have full Global regulatory coverage and the entire purpose of this is really again to help you assess those incidents and then show you that assessment help you identify what is the risk of harm to those individuals what are my notification obligations and what are those deadlines that I have to here to to make sure that I'm being compliant with breach notification laws so that's really what radar first is bringing into the service now platform and helping again automate all of that for you and make kind of take you out of that manual world or those spreadsheets and make it an automated process so that you can respond efficiently um just a little bit more on the next slide as you can see obviously uh you know as I said we have Global coverage um we have a lot of organizations that use our software uh we've been helping assess incidents now for i' I've been with the organization for over 10 years so we've been helping organizations around the globe really ensure this uh and just to kind of give you an idea of who we are and kind of the the the talent and the amazing capabilities that we bring to all the organizations that use our our application so with that I'm going to hand it over to Andrew who's going to walk us through a quick demo and then I'll be back in just a moment to show you a little bit more with radar first excellent thanks Travis I'll launch the demo now okay so let's jump into the demonstration so just cting your mind back to the slide what we'll first do is look how we can raise a new privacy case so this could be through the employee Center but you could also have it for an API integration uh simply through thirdparty Solutions or actually an internal integration so to speak within another service now solution so this for example could come from a security incident response if a user wants to go through and investigate more details about the security incidents they can go through create a breach assessment and from that a privious case but for now let's go through and raise a privacy case from the employee Center as an end user employee would okay so now I'm in the employee Center here you can see obviously all the Great Links and um tiles that I can choose to go for password reset system status any of the tasks I have maybe from a gc's perspective GC assessments but if I go up to top here and select risk and compliance here you'll see where I can go through and I can actually report a privacy case so report privacy violation or complaint here I can click through and I can fill in all the descriptions you can see title description case type which privacy case case subtype I can go through and add all these data in however if I also have gone through and you know maybe created one in the past but didn't have enough information to send it off at that time I can save it as a draft so here I can view that draft and here you can see details of a priv is case where somebody accidentally left their work laptop on a train you can see here how it contained sensitive customer data financial data including client information what types of information or personal information attributes were involved any additional information s key stakeholders who own this application potentially who've been impacted I can also add any attachments as well but for now that's all the details I need so from here I could submit that privacy case so once that's now been submitted let's go through and see from a end user perspective from the Privacy teams perspective from the second line how we can go through action that and get more details and then effectively see how we can get some more great information from radar first from that integration and help us on our way okay so now I'm logged in as Josh Warner one of our members of the Privacy team and here you can see I've navigated to the Privacy case management workspace uh underneath or sorry dashboard underneath the workspace for privacy management here you can see I've got all the details of the cases that need my attention in terms of overdue cases by overview in terms of State breach status priority can also see any Trends or you know primary causes in terms of those cases that are coming in and we can also track any issues as well related to these cases so we've currently got 10 open issues but now if I jump into some of the cases that we're currently investigating here directly from the dashboard here I can see three cases that have come in um let's have a look at this accidentally published more than 300 employees health records on the organization's internet so once I click into the case you can see a nice overview of the case here with the description the state in terms of where it is in the workflow and also the status of it so there has been a breach detected and is reportable we also have a nice timeline here in terms of um different as um different points along the case so in terms of when investigation uh PL start where we are right now so that's today's date what's coming up so we've also got a remediation plan start date here as well later in the month and we've also got actions overview in terms of the two we have where they are by State what type and any again any tracking of issues here we then can go on to the actual details here so you can see where it's um you know more details like the name the description uh who's been requested by what is the primary entity related to this so it's the HR database what personal information was um exposed and what you know does it contain it y 300 uh impacted individuals they're all employees assignment group primary origin so again here you can see it's come from the employee Center if it came from a different Source like I mentioned earlier you would have security incident response there or any other potentially third party tool you could have that coming from there and then all the scheduled dates that we need to um comply by and also the breach analysis okay so let's go through those breach analysis points in more detail underneath the breach assessment underneath here you'll see an overview of the breach assessment uh in terms of the impact summary with the impacted regions and you can also see the details here in terms of the category of um data that was lost so it's electronic the region as well jurisdictions and any impacted individuals let's go and view that in more details here as well again here nice overview we can actually see the specific details and we can also see the pi artifacts here so if I jump into the Amia one for electronic you can see it was a electronic uh data that was lost what data elements did it contain in terms of you know the employees medical information personal information any other details and what also jurisdictions are impacted so here we can see for Germany so now if I go back to the actual breach assessment what I need to understand is actually what level of risk do these POS to the organization and also to the impacted uh individuals involved and so for this I can initiate our radar first analysis so you can see on the top right initiate radar first initiate that here and now that's um being sent for an integration to radar first to be assessed and within minutes or even seconds actually you can see this right now that information will come back so if I refresh the screen here we'll now see the information on from radar first so a nice summary here in terms of all the different impacted individual uals um what level of risk did they pose to the uh organization so you can see here high risk uh with regards to these jurisdictions also where applicable we can see when we need to remediate this by so here for Germany uh potentially know like a gdpr impact we've got the date that we need to remediate this issue by um and a nice overview here I can actually view this in more detail as well directly from the Privacy case here underneath the breach assessment tab again I can see all of that information directly coming from radar first and I can also if I want to view this as a report in radar first where it can provide more information and more contextual information about how actually that risk assessment has been um created and what factors take that into account which Travis will go through shortly on a direct demonstration into radar first itself hopefully you enjoyed that demonstration of how you can see service now privac case management can also be used with radar first and how really you can see radar first uh can really cut down the time to minutes even seconds to do that uh investigation across your privacy cases that are coming in you know the great benefit is is that we're collecting all of this information and service now with regards to security incidents data coming from employee Center and we're able to stitch all of that information together in terms of you know where data sits uh what type of privacy impact or sorry privacy data has been exposed and then send the trade off first for that better analysis so keep your eyes peeled now for a demonstration from Travis going into radar first in more detail okay I'm we're GNA switch screen so Andrew if you can stop sharing for just a moment I will share my screen and I'm going to show you all radar so we're going to pick up kind of right where Andrew left off uh in his demonstration so uh what we've done now is just kind of uh clicked on the link if you will from inside of privacy case management and navigated our way over into radar first um to take a deeper look at that incident that we had that you know 300 Health employee records uh you know had kind of been exposed on the company's inter internet what we want to do here in radar first is really take a deeper look at that risk of that assessment so we come in here when you saw Andrew profiling that over on the service now side you saw individuals are identified in various different uh states and countries California Germany uh some folks out of the asia-pacific region and so what we want to do though is take a deeper look at that assessment so if we navigate into radar we can see that exact incident here we can see this was the assessing the impact of sharing 300 employees records um and we come in here and we can see the details of that here inside of radar so this is our risk assessment of this particular incident it's going to highlight for you data elements um that were tagged as being involved in that instant we can see here what the U instant uh kind of risk level was we plot this on a heat map in two Dimensions one is instance ver in the other is the data sensitivity we can see here that this is landing as a high-risk incident which makes sense I mean employee information was medical information it was shared you know maybe in a public environment um that would be considered kind of a high risk what we can see here is radars spefic specific guidance to this actual incident so we can see here it's you know saying yes the affected individuals do need to not be notified um California doesn't have a particular timeline to do that just uh as soon as possible without unreasonable delay uh but there is not an obligation to notify the Attorney General because it didn't affect more than 500 California residents so radar is picking up all the nuances of that particular breach notification law and showing you the exact notification obl ations now if I was to take a look at this uh from the EU perspective of the individuals that you know the 100 or so individuals that were impacted from the eu's perspective I see a slightly different story I see different data elements that are picked up as being regulated I'll see here that maybe I have a lead supervisory Authority as set as the Austrian data protection authority I need to notify them you know radar again radar is highlighting that and then because all those residents all those people impacted were residents of Germany uh maybe I would have that obligation to notify those affected individuals but again radar is showing you all of this it's showing you what your notification obligations are and again it's very similar story if we were to navigate over to you know Australia again we're going to see a very similar kind of pattern we're going to see the data that was involved we're going to see our risk uh heat map and we're going to see um the notification obligations to the individuals or if there's other government authorities what those are and again same for Japan as well just to kind of round out all the employees that were impacted in this particular incident but again all of this was done you know at the click of a button this information came in from service now uh it was assessed and then we're kind of just going into radar to take a deeper look at that assessment and maybe figure out you know are there any questions that we have about this uh at any time we can always take a step back take a look at our profile if we want to understand all the inputs that went into this all the different answers to our risk factor questions uh for our data element selections for the jurisdictions that were selected we can always take a look at this inside a radar and see you know hey do we have any concerns or issues you know is there anything else that we need to investigate um again all of this information is at your fingertips within the radar platform itself of course once you're done with this you agree with this you can then go back to service now uh and complete the rest of your privacy case investigation but really you know what we wanted to Show You is kind of what's Happening behind the scenes of that assessment you know show you the kind of the details that are really being uh looked at um so that you understand kind of what's Happening as you're getting this automated response so with that I'm going to hand it back to Andrew here and we're going to I think wrap up our last few slides excellent thanks Travis yeah so back sharing my screen so just to kind of wrap that up um in terms of the radar first integration with privacy case management and service now hopefully you can see how you can initiate uh investigate and identify uh privious cases through employee Center or through other sources within service now so incident security incidents for example um you're able to go through and do breach assessments identify and document critical details of the previous case from the various sources understanding what information has been exposed you know um where it's been exposed and having all that information flow through from service now and then you're able to hand it over to radar first where Travis can explain then what happens absolutely and from the radar first side what you're seeing you know is that risk assessment being performed really to understand what is the risk of harm to those impacted individuals um make sure that you're highlighting what all the various obligations are whether or not you need to notify the affected individuals different regulatory bodies make sure that you have a clear understanding of what those timelines are so that you can respond in a timely manner and then obviously you know suggesting you know the appropriate actions to take you know again as said whether that's making notification um or if it's you know offering credit monitoring or whatever the particular obligations are that are defined within their various breach notification laws um again all that information flows back over into service now so that you can see all of that information inside of your privacy case I'm kind of bringing this full circle you know from incident being created you know being able to triage it investigate it and then assess it find out what your obligations are and then make sure that you're completing those obligations and resolving that case as quickly as possible excellent yeah and you can hopefully see in the demos that we did that is in a matter of seconds so um that literally came straight through back in we can then kind of tie it up to analyze the causes the consequences you know do that root cause analysis why was that data exposed from that managed task across the organization so there'll be tased for security maybe fixed the issue which was the underlying reason why it was exposed HR may need to be notified you know have those slas in order to handle those data breaches and again those obligations like Travis mentioned all within service now so you get that nice full uh privacy case life cycle going to radar first getting that great information back and then handling it and remediating it going forward so with that i' would just like to say thank you very much for attending today um as we're going to wrap up today's program um or sorry webinar you will be reminded to take a short survey please feel or please um respond it literally takes a few seconds um if you can respond to that it really helps us to in terms of where we're going to present to you next maybe what the um rest of the product need to look like as well so yeah please feel free or please can you uh take that it only takes a few seconds to complete the survey and with that thanks again for joining us we'll end that there
https://www.youtube.com/watch?v=gigNxsiB6MA