All right, hello all. Welcome to the next in line of the Splunk Webinar series. This one is based on the State of Security Report. The webinar is actually called "Writing the Rules Securing Trends Shaping APAC in 2025." For those of you who don't know me, my name is Harry Chich adjian. I am the Financial Services Industry Advisor for Splunk. And today, joining me are my esteemed guests and co-hosts. We have Nathan Smith, who's the Head of Security for APAC in Splunk. Hey, Nathan. Morning, Harry. Thanks for having me. Thank you. And also Craig Magee, Chief Technology Officer for Splunk and ANZ. Morning, Craig. Morning, Harry. How are you? Fine. Thank you. Excellent. Today's agenda, just quickly, I'm going to cover it off. We'll be looking across some of the regional challenges, talking to some of the regional challenges that we're seeing across all of APAC. Then we'll be diving a little bit into the State of Security Report itself and just go through some of the key findings. Then we'll go through what we consider to be some key considerations from the report and some recommendations. Then we'll dive into a bit of an industry observation and perspective as well across the region. And then lastly, we'll leave you with some final thoughts. We're going to start off with some of the regional challenges. And I was wondering if Nathan, you'd maybe want to just start off with this one. Yeah, thanks, Harry. Look, the great part of being a part of Splunk is we get to talk to lots of different customers, and we tend to find there's lots of commonality amongst the concerns and challenges of organizations that we deal with, and really, if I look at, I guess, from a security lens point of view, we still have a huge challenge in visibility across organizations. So we tend to find it's very rare that an organization will have complete visibility across all their cloud environments, across their hybrid environments, across their IT/OT, which ultimately leads to gaps in their visibility, which can lead to potential areas that threat actors can exploit. We also magnify that with the challenges around many organizations still having silos in their organizations. As much as we would love to have this concept of everyone kind of utilizing the same platforms and the same information, we still generally see a lot of different silos. Data in particular is siloed across most organizations. I think maybe in Japan, I think it was, I read in a report that we've got that about 52% of organizations still have data silos as a major concern across their environment. So not only do we not have teams talking to each other, but we also have data in completely different areas and often not accessible by others. So a huge problem in that space, and then maturity generally across most organizations is kind of varying levels of maturity across different industries, to different sizes of organizations, to different countries within the region, but what we generally start to see is that there's a lot of maturity gaps, and a lot of people will focus on trying to baseline and get things as much as they can in place. But generally speaking, either they don't have the skills or the budgets or potentially the experience to fill in some of the more complex gaps they have in their cyber maturity, but look, definitely from my point of view, love to hear Craig's perspective on this as well, because he talks to a lot of organizations across the region as well, but also from a very different lens to what I talk to them about. Yeah, thanks, Nathan, and everything you said is 100% correct. In the dealings that I have daily with C-suites or boards, probably in my career, never probably seen such a lens put around cost control at the moment. We've all had our budget challenges, and we've all been asked to take sort of a percentile from our budgets. But this is probably becoming more pressure on the budget side and the cost side of the house than probably what I've seen. And what's also happening that I'm noticing as well. AI obviously is starting to gain significant momentum across technology shops and from business usage, but budgets aren't increasing. So what's happening? We've got that perfect storm where budgets are being challenged or executives are asking for cost opportunities, cost out, but at the same time using that same budget and that same envelope of funding to fund AI activity. So it is that perfect storm around how do you take money out of your budget, get synergies, get some savings, but use that around some of the new AI capabilities that are coming as well. And I've been brought up around some pretty clever people in technology. And one of the sort of mantras and theories that I've always been brought up with is around trying to simplify and standardize the technology environment. I think most people who have run large technology shops or been in technology for some period have probably done something similar. But with the advent of AI, we're seeing this, what I would term, shadow AI. So it's similar to what we saw around the credit card economy in technology or shadow technology or shadow IT. We're seeing the shadow AI. And that's becoming more prevalent, particularly at this point in time in large organizations where you might have a finance organization, a legal organization, a technology shop inside that organization. And they're all doing their own things in relation to AI. They're all chasing their own business problems. They're trying to chase their own technology solutions around AI. And what we're doing is now creating AI solutions throughout many AI solutions throughout organizations. So AI governance is becoming critical and imperative in any organization. Being able to provide the standards, the guardrails, and the frameworks around how, when, and where you should use AI and what controls you need to put in place around AI and the data that feeds all the AI models. So these are some of the things that I'm seeing, Nathan. So moving on to the next slide. Thanks, gentlemen. So let's actually have a look at the three key findings of the report. So I want to just give you a brief overview of how the research was conducted. And it's very similar to previous years. Splunk partnered with Oxford Economics, and they surveyed over 2,000 security leaders across nine different countries and 16 different industries. So it was very cross-collaborative. This global cross-sector collaboration provided that unique, rich view into what those real-world challenges were innovating and shaping today's security operations, right? So the goal of the research, as always, is quite clear. Just understand how security operation centers in this instance are evolving amidst that complexity. As well as just the expanding threats and the accelerating sort of technology change. And as Craig mentioned, particularly AI. So let's explore the three key areas. I think let's start off with many organizations are still sort of their security tech stack has grown organically, which has obviously led to a bit of a patchwork of loosely integrated tools. So nearly 60% of the SOC leaders reported that more time is actually spent in managing those tools than really responding to the threats. And this isn't just a resourcing issue. It reflects on a broader architectural problem, I think. And that whole lack of interoperability across the tools creates friction, increases that workload for the analysts, and just drains operational bandwidth, I should say. And if we don't think and rethink tooling as an integrated platform strategy, rather than just a collection of best-of-breed solutions, I think we'll continue to pay that compounding cost in terms of agility, visibility, as well as talent retention. The next one is all about alert overload. And it's probably one of the most pervasive inefficiencies across SOCs. Analysts are inundated, as we obviously know, with high volumes of alerts, many of which are false positives or lack actionable context. Almost half of the respondents in this year's report basically said they struggled to triage alerts effectively, and it still continues to happen. And this isn't just simply an alert volume issue. It's actually about prioritization, but it's also the whole signal fidelity issue. So when alerts lack that enrichment or correlation, teams lose their trust in the systems, which is, once again, another factor for leading to alert fatigue and potential threat misses. So if we can't improve that whole signal-to-noise ratio, then we'll obviously compromise both the speed and the confidence of our responses or the SOCs' responses. And then finally, there's data management gaps. It still remains quite a critical challenge for investigative workflows. So data silos, I beg your pardon, inconsistent access controls, lack of federation strategies continue to hamper incident response. Over half of the security leaders say investigations are still slowed by not having the right data at the right time. Without that cohesive data governance and that real-time access across the environments, that threat visibility remains fragmented still, especially in the hybrid environments and multi-cloud infrastructures. So the implications are still very severe: longer dwell times, slower remediation, and higher breach risk. So while we've touched upon, I suppose, three major sources of inefficiencies as highlighted by the report, I'd like to ask Nathan what he's seeing when he's engaging with some of our APAC clients and their industries. Nathan? Yeah, thanks, Harry. Yeah, look, obviously, you've caught out quite a few really key areas in there. Probably the other area that we start to see is the challenges around most organizations, beyond kind of managing the tools and the data sets. It's also the vendor relationships as well. And the complexity of what your vendor or how integrated your vendors are into your environment can often cause challenges. You might be outsourcing components of what you're doing, which once again may be better cost-wise, but may create some inefficiencies in how you respond to particular incidents. We're definitely seeing a challenge around teams in particular. So you mentioned before around kind of the some of the challenges around alert fatigue. We tend to see there's a real sort of industry-wide challenge around people starting to sort of quietly quit. They're getting burnt out ultimately with the workloads that they have and the challenges and the pressures they have in their roles. So we end up starting to see people leaving the industry and then backfilling them is difficult. There are technologies and tool sets which we'll talk about later, which might help that. But ultimately, there's a few challenges in that space. Craig, from your point of view, what's your thoughts around some of the efficiency or inefficiencies you're seeing? Yeah, Nathan, I think you've touched on some of those as well. But some of the inefficiencies that we're seeing today have been inefficiencies that technology organizations have had for a long time. And they're probably being the pot of gold at the end of the rainbow everybody's been chasing and trying to fix for a long, long time. The fact that a lot of tools don't integrate, it's because we buy discrete, siloed, individual, disparate tools. And sometimes there's reason and rationale. But if we want to provide insights and analytics and organizational historical data and be able to educate the business around what we're seeing, what technology organizations are seeing, we need to make sure that those tools do integrate. The number of vendors that we've got, and again, it's understandably how that happens and why we have so many vendors in our technology shops. But again, we've all been trying to consolidate the number of tools and the number of vendors we've had for a long, long time. But these statistics are still high, and they're still rating as one of the most inefficient parts of a technology organization. And with that comes the level of spend. So the more technology organizations we have in a technology shop, the more cost, the more tools we have, and the ability or inability to integrate those. And what's becoming more, and we'll talk a little bit more about this, is what's becoming more important is the ability to leverage and share data. That is becoming more challenging with the more tools that we have and the more technologies that we have. So again, Nathan, I think it's really, it's a little bit interesting for me. This is since I've started in technology some time ago. These have been sort of the holy grail activities that we've been chasing, but they're still coming up today as a problem across technology organizations. So Nathan, can you do the next slide? Give us a view around where you're seeing and what you're seeing in relation to AI. Yeah, thank you. Look, obviously, the inefficiency aspect is a challenge for every organization. But where there is inefficiencies, there's also opportunity to be more productive and improve. And really, the area I think that most organizations are looking towards now is this real trend towards where they can use artificial intelligence to hopefully make them more efficient and more capable in what they're doing. From a security point of view, of course, that means that those things like alerts and challenges around too many alerts, we can now start to utilize some of the capability that you have within artificial intelligence to start to not only be able to respond, prioritize, and triage these particular alerts. There's also a real shift towards how AI can start to make the ease of entry for people coming into the environment a little bit lower. So if you think about people coming in, not necessarily knowing a technology, but having AI to help guide them in their experience of how they get to be more efficient and more capable, we're definitely seeing those types of artificial intelligence capabilities being adopted pretty readily across most organizations. We're starting to see more organizations in the region start to sort of dip their toe in the water of how do we really start to use AI in response and investigation in security. Once again, that comes with a little bit of a challenge in that artificial intelligence is still reasonably new when we look at the capability. It's not really something that you'd be looking at using a generalized tool from an artificial intelligence point of view or generative AI. But you might be looking at more domain-specific, more focus on security as an example and security challenges and indicators they need to address. But what that does often lead to is that in security, you're kind of always trying to make sure that you are responding to the right alerts at the right time. In AI, there are the challenges that artificial intelligence still does have hallucinations. They're not 100% perfect. And then you also need to have operators and analysts who understand the challenge so they can determine whether what the information they've got is incorrect or not incorrect. So we start to see more focus around trying to see where AI can help make teams more efficient today with the technologies that we have today. And then if we look towards the near future where we start to see more agentic or autonomous type activity, that'll start to really change the dynamic of how you look at utilizing AI for your productivity in your environment. So no longer will you be in a position where you will be completely reliant on human resources and the availability of human resources. You can now start to think about how you spin up autonomous agents depending on requirements. And also what type of persona you want to have them do, whether it's. Level- one triage, whether it's level- two investigation, whether it's more threat hunting, or whatever it might be. So there's some really good things, I think, coming that will help address some of those challenges, and to Craig's point, once again, these challenges have been around for a long time, and we hope that we will improve those challenges with newer technologies and newer innovations that are coming, and I think AI has great potential in that space, but of course, security is one lens. AI has been utilized across organizations in all different sorts of ways, and I'd love, Craig, to hear your view on how organizations are looking to utilize AI to make them more productive, not just in security, but across other lines of business. Yeah, no, thanks. It's one of those evolving spaces that. In my time and my career, I don't think I've seen something change the industry as quickly as AI. And it's been led from the boardroom, from the executive table. It's really interesting to watch a boardroom CEO or managing director say, "I want AI." It's really interesting to see them get under the covers of that and, well, what do you actually want and need in the context of AI? So I think what most boards are now looking for is they see AI can be a differentiator for them in their technology, in their business space. So they're looking at how do we implement, and there's the productivity tools and everything that people are looking at. But it's around really all comes down back to data and how, in business terms, how do we use the data that we have? How do we use the AI models to give us better visibility and transparency of what our customers are looking for? What do they buy? What are their, when do they buy it? How do they buy it? As examples. So I think it's changed dramatically, very quickly at the boardroom. And around, again, I want AI, but it's not really being done in a lot of organizations in conjunction with governance. And as we talked about earlier, that's the number one thing that needs to be, it needs to lead any AI deployment in any business, whether it be technology or any organization. You need to make sure you've got governance wrapped around AI. So I think it's the notion of AI, if you're not on the bus in the context of AI, you're soon going to be under the bus. Everybody's looking at it. Everybody wants it. There's a lot of people who don't know what they're chasing and what problem they're trying to solve with AI. I think that's the number one thing that I sort of have conversations with the board and the C-suite is understand what problem you're trying to solve with AI before you go and start buying different tools again and complicating your technology environment because there isn't a one-size-fits-all AI tool for every single AI problem. So there's a law of diminishing returns at some point around how many tools you can implement into your environment to solve the problems that you have. But be very, very clear as a business leader, as a technology leader around what problem you're trying to solve and around how you're going to do that. And again, make sure you've got the governance wrapper around that. And when we start talking around AI, Nathan, and again, I'm seeing a lot of org structure change in organizations to stand up behind AI. So it's no longer happening under the covers. We're seeing roles with explicit people associated with AI in their job title. What are some of the skill gaps and what are you starting to see as the future in technology and around security and AI? Yeah, thanks, Craig. Look, definitely, if we think about just what we spoke about in the technology changing and the fast pace in which it's changing, we will see the types of skills that we have working, particularly in security operations centers, change. We won't see it go away completely. We're never going to have, in my view, a completely automated, fully autonomous environment. There'll still be a need for humans involved in the process, but if I look at today, the focus today primarily for most organizations is triage. You're spending all day just trying to catch up with what's in front of you, and you don't necessarily have the capability or the time necessary to spend on maybe some of the more important kind of high-level skills that you need to help you try and be more efficient in your security operations center, so as an example, we think about things like detection engineering, so writing detections, being able to leverage threat intelligence and information that's most current for your industry or for your region, and be able to write detections based upon potential challenges that you might have. Today, it generally falls to very mature organizations in a security team that would do this. Really, as we start to move forward and as technology like AI and automation start to take on more of those lower-level capabilities, the skill sets that you will need in your environment will definitely change, so we're definitely going to see more focus around people being able to build detections that are relevant for your environment. There's going to be more of a focus around how we build the security flow or security by design within the development of new applications and assets and technologies, and then, of course, we're seeing governments really push compliance, particularly around AI and other areas as well, so we're going to have more people focused on how we adhere to the regulatory requirements that we have across our different industries and organizations, and if we think sort of a little bit further forward beyond maybe the next couple of years into the next five, and we start to think about if we're really utilizing agentic AI effectively, you're going to start to have agentic agents talking to agentic agents, so maybe you've got a security operations center tool that's talking to an endpoint, to a firewall, to a network device, to an identity device. They're all communicating among themselves, and really, what you'll start to have in your environment will be more people focused on making sure they're governing those environments and those interactions, so making sure that these types of capabilities are creating more challenges or more gaps or more threats to your environment, so making sure that there's people who are maybe more focused on the tool sets you have that are more autonomous as opposed to individual rules-based type technology we have today. So skill sets are definitely going to change. I think organizations that are planning a strategy for the next 3-5 years need to consider what does my skill set look like in five years' time because I'm probably not going to be hiring level- one analysts anymore. But at the same token, that creates problems of, well, how do I train people? So we have to start to think about what strategies will we put in place, what people will we look for, what type of personas will we be looking for. That complements the capabilities and the technologies that we are also looking to procure as a part of our next three- to five-year strategy. And Harry, maybe if we think about the reasons why we have those challenges. And ultimately, it comes back to there are still huge threats that are happening today across the globe. And only recently, we've seen a major airline in Australia who was breached by a third party. Once again, socially engineered, third party had access to private information. I think there was about six million or so individuals that were affected by that particular breach. But we start to see that it doesn't really matter how big you are or how small you are, you're a target. Yeah, yes, there's more focus maybe in critical infrastructure. Maybe you're in banking and finance, maybe you're in public sector. There's definitely sectors which are highly targeted. But the reality is every single industry has some form of challenge when it comes to cybersecurity. And ultimately, you've got your financial gain type people. Your ransomware type organizations are still out there. They're still affecting every stretch of the organization across every region. We saw a major distributor as well get impacted by ransomware. A major IT distributor affected their ability to deliver IT infrastructure across the globe. All falls back to a ransomware breach. We've seen ransomware hit insurance organizations and others as well. And ultimately, that will not go away because it is a good way to make money, but there are things that we can start to put in place that will hopefully start to maybe minimize that risk as we go. We're definitely going to see, and we're definitely seeing across the region, if I think of Japan, Australia, and Singapore, insider threat, insider risk is really becoming very much top of mind. We've spent a lot of time as organizations focusing about keeping bad people out from outside getting in. But the reality is there are definitely, unfortunately, times when people who are considered to be trusted inside your environment, whether it's maliciously or whether it's accidentally, they can cause data breaches for you. So there's more focus on how we have a greater level of control in that space, a greater level of visibility. And of course, we've spoken a little bit before around compliance. The reality is compliance is only going to continue to grow. We're certainly seeing across the region a lot of focus on regulatory people pushing. The maturity levels of organizations going up. That then flows back to security teams needing to make sure that they are actually putting the right tools in place and monitoring their ability to be audited at any moment. So once again, we'll start to see more people focusing on how do we protect ourselves from being a potential breach or a violation around compliance as well. So we're definitely seeing lots of threats, and we're not just limited to these four. There's lots of different threats depending on the industry that you're in. But we're really seeing a real challenge in that. These threats are going to continue to grow. And these are kind of the downstream impacts. And the reality is we need to sort of think a little bit before this in what type of strategy we put in place. And Craig, it'd be great to sort of get your point of view around what type of strategies are organizations implementing initially to try and protect what they're doing across their organization. Yeah, nice. Look, again, these are downstream or upstream impacts that are being caused by not necessarily organizations managing their data properly. Every single one of these is data-related. So whether it be, I think what I'm watching at the moment, more and more organizations from a strategy perspective and to the point and the example you shared earlier is around where is my data? I think there's a conversation right now happening that has been happening, but how do I get my arms around all of my data sources? I think that's number one. Number two is who has access to that data, both internally, third-party provider. I think it's becoming more and more important, particularly around things like insider risk that you also spoke about. So the notions that organizations have been chasing this problem for quite some time. We had big data projects. We had everybody creating data lakes. We had all of those. That was really about organizations strategically trying to solve these problems and around trying to get their arms and legs around their data proliferation challenge that all organizations have. So I'm watching that the vernacular, data lakes, whatever it may be, big data, have all disappeared overnight and all both being replaced by the vernacular of AI. So I think everybody now, from a strategic sense, would hold a view that AI can help in this space. I probably hold that view as well. I think AI is the next step in the maturity curve around helping us with these external business threats that we have. But we've got to get more strategic control of our data assets and who has control of them in-house and who, what third parties also have control of those data sources as well because that's becoming more imperative as we've just seen. And one of the things that just to echo that point is that data silos across organizations has been prevalent for many, many a year. When you have data silos, it's impossible to draw insights, conclusions, or take analytics and have findings from that data. So that comes back to what we talked about earlier around multiple tools, multiple technologies, multiple vendors. But it's also about different data silos in those different tools, different data silos in different parts of organizations. So if you were to think around security and a SOC function of security that's once upon a time has always been standalone for reasons that may be related to security. It may be for reasons related to control. It may be related to reasons because of just people. But then you've got that data source. And then you may have other data sources around your traditional infrastructure application monitoring, your observability landscape. And you've got those data sources. And traditionally, that data source lives in multiple locations and multiple data areas. None of those talk to each other. Never do you share data between any of the use cases. Never do you draw data from those multiple use cases to actually expose meaningful insights. It never happens. And worst-case scenario is you're storing data multiple times in multiple data repositories and not leveraging it. So the cost associated with multiple tools, multiple data silos, and the storage of all of these is exponentially growing. So there is a really big case now. Organizations are now looking at their operating model. They're looking at building out centers of excellence associated with leveraging the data sources that they have across their organization to leverage it once across many different use cases, which makes complete sense. If you want to understand from end to end, as we talked about earlier, around an insider threat, and you want to be able to track that from the data center through the application, through the network, through the cloud provider, through the hybrid environment, you can't do that when you've got silos of data. So organizations are now rethinking around how do they strategically line themselves up from an operating model and org structure to be able to provide that center of excellence capability for the organization to be able to give those insights and leverage that data across multiple organizations. We're seeing that more and more. So to just prove that point, 78% of organizations say that sharing the data has led to faster incident detection and response. That's huge because they're leveraging data. So if they have an outage, what Nathan talked about before, one of those scenarios, you have one of those scenarios. And when you've got that sort of statistic, you'd be able to get your service, your capability, your business-enabling technology available back ready for your customer to use faster because you're leveraging data is pretty compelling. So with that said, Harry, I'll hand over to yourself. Thank you, Craig. I appreciate it. Wonderful insights from both of you, gentlemen. I want to sort of put a little bit of an industry perspective to this as well and just not only what I'm seeing, but also what some of the findings of the report has highlighted. Obviously, if you look at financial services, we see that cyber teams within FSOs are more buoyant, almost twice across the industry average, actually, in relation to keeping up with cyber requirements, largely due to three key reasons, I think. Greater maturity and investment in security programs is number one, so largely driven by early adoption of cyber frameworks due to the high-risk profile associated and the regulatory scrutiny that comes along with it. Number two is the regulatory pressure as a catalyst. FSOs are actually accustomed to that more complex regulatory environment, such as emerging operational resilience obligations. Number three is a stronger alignment between business and security. Cyber is obviously viewed as more increasingly a strategic business enabler, and as such, executives understand that trust, so reputation and uptime are all directly linked to that revenue, I think, right? They're the three key reasons. While 69% of organizations across the board report that disconnecting tools creates significant operational challenges, this pain is really even more acute in the public sector. According to the report, public sector respondents are twice as likely as the average to say that fragmentation presents significant challenges. Just underscoring that whole critical need for the unified platform as well as the shared processes and the shared data in government cybersecurity environments. If we sort of pivot to manufacturing as an industry, manufacturing teams, I think they're faced with that perfect storm of issues. They clearly have high attack frequency, especially in relation to the data breaches, as Nathan was commenting on, largely due to that whole complex OT environments, weak segmentation potentially between IT and OT. They have extreme tool sprawl. The report, I believe, suggested 76% spend time on tool maintenance than threat investigations, well over that whole 46% cross-industry average. Alert noise and low contextual fidelity was particularly prevalent in the manufacturing industry as well. They experienced weak visibility into on-premises infrastructure, almost double that of the industry norm. Interestingly, despite obviously manufacturing having that heavy reliance on physical systems and legacy environments and then lastly, that whole limited use of advanced automation as well as AI, the manufacturing industry seems to be lagging in that slightly. While obviously they have that whole awareness of AI and its potential adoption is lagging behind the more mature digital organizations. I mean, across all industries, though, I suppose SOCs are constrained by, as we talked about, fragmented tools, skills gaps, inefficient detection, as Nathan rightly detected. FSIs seem to be leading the way in AI adoption and compliance, while manufacturing and public sector teams still remain burdened by that tool maintenance and low fidelity. But despite all of these challenges, nearly all sectors are prioritizing unified platforms and domain-specific AI to drive that inefficiency as well as resilience. So I'm just going to start the final sort of wrap-ups. I'm just going to add some of my final thoughts, and then I'm going to hand over to the gentlemen for their pieces of nuggets. But so for me, I suppose one final observation is driving that whole SOC evolution is that, once again, is that unifying platform and improved collaboration across teams and tools. Clearly, we've seen traditional SOCs have grown around isolated domains. Threat detection over here, perhaps incident response teams somewhere over there, and case management all over the place. But this siloed model is just breaking under the weight of the complexity, right? So the result is fragmented visibility, duplicated effort, and decision-making delays in critical moments. So analysts often have to just keep on pivoting between five or six different systems just to piece together timely response and activity. This isn't just inefficient. It's obviously quite risky. So really, from my perspective, I think the visibility and the vision, rather, is quite simple. A SOC that no longer functions as an island, but as a nerve center for that whole digital resilience. I think that's really the key where we should be heading. And achieving that requires intentional platform-based decisions, shared process design, and a cultural shift towards that whole transparency as well as collaboration. I want to stop there and maybe just hand over to Nathan, perhaps for his final thoughts. Yeah, thanks, Harry. I always go back to the old adage of visibility is really critical. If you can't see it, you can't protect it. And that is true as it was many years ago, as it is today, and as it will be in the future. We need to be more consistent in getting visibility across all of our environments. We've spoken a lot about data silos and data is everywhere. We generally tend to find that we're not great in security and getting visibility across everything. And that's particularly whether it's in IT or OT or other areas, but your multi-cloud. So making sure that we get visibility is absolutely critical. And in parallel to that, cyber hygiene, the reality is we all like to think that it's a sophisticated cybersecurity attack that gets us. The reality is a vast majority of them are from malicious attacks that have been targeted towards systems that are not patched, as an example. So making sure that we get our cyber hygiene really locked down and organized as much as we can. I understand there's definitely areas, maybe OT is an area where you may not be able to patch, but we need to put mitigating processes in place around those. And of course, as a part of that, we spend a lot of time and we've spoken a lot about the types of things that we have that are affecting us as organizations. But the reality is, as much effort and time that we put into our security, we need to make sure that our suppliers are doing the same. We know that most organizations have got hundreds of downstream suppliers as part of their supply chain, and there'll be a number of strategic ones that you'll have that deliver really critical services for you. You're only as strong as your weakest link when it comes to security. We've seen that recently, and we'll continue to see supply chain being, I guess, the area that we'll see attackers target because it's kind of an easy way into a big organization. If I can get someone who doesn't have the manpower or the budget to put the right levels of security in place, it's probably my easy way to get into someone who might have a much better security posture. So don't forget supply chain. It's a really important aspect of it. And there's a whole gamut of things that you can do in that space that we could talk for hours on. But think about what controls you put in place for your suppliers, but also how do you monitor that? How do you test it? These are really critical areas from my point of view. Craig, your final thoughts for the listeners on the call? Thanks, Nathan. Pretty easy for me. It's data, data, data, data. Everything gets driven by data, whether it's an application, piece of infrastructure, SaaS service, it's all driven by data. We've got to make sure as an industry that we protect our data, we get our arms around our data, and importantly, understand what data we have, what customer data we have, because there's different controls of the way we deal with and protect certain data. But again, as we mentioned earlier, how we have the controls around the data sources that we have so we understand who can access data sources. But more importantly, again, how do we leverage data across different use cases without building silos, without encouraging different groups to build different technology functions and create different isolated reports? That's what gets driven. How do we provide insights across the organization that provides executives with transparency from an end-to-end perspective using data? So that would be my final thought, Nathan. Thanks, Craig and Nathan, so we're just coming up to time here. Just quickly, in today's session, we've explored a whole heap of things, but in particular, how security leaders are addressing those systemic inefficiencies that plague their modern SOCs and some of the strategic skills and shifts needed to actually get there, I think. For a deeper dive, I urge you to download the full research and tactical guidance and just go through it. Of course, if you have any queries whatsoever, please don't hesitate to contact your Splunk representatives, or of course, you can come through to Nathan, Craig, and/or myself as well. With that, I'd like to thank you all for your participation along the way, and of course, I'd like to thank Craig and Nathan for their time and their wonderful insights. Thank you very much, gentlemen. Thank you, Harry. Thanks, everyone. Thank you.
Loading workspace