Transcript
Now, in this session, what you're going to hear from is myself, Shane Westcott, Security Technology Evangelist here at Ivanti. Been around for a long time, 21 years, and working with all of our security solutions. Not really focused on ITSM, but so that's why I have with me the very wonderful Iren. Kieran, can you intro yourself? Thanks, Shane, Kieran, Shelley. I am an ITSM and EXM specialist in the team, and I'll be helping Shane look at how we develop the process once we understand the risk. Correct, because I do need a lot of help when it comes to things to do with ITIL, ITSM, all that sort of stuff, as I often say. My wife's an ITSM expert because she's been dealing with me, problem and incident, for 44 years. But I'm just very happy she hasn't decided to upgrade her ITIL skills to include change, so I'm still around. But apart from that, I don't know anything about ITSM, so Kieran is here to help me out. What our job today is to try and show you how Ivanti, in its form today with our Neurons platform, is enabling the IT team much better integration with the security teams so that your solution can provide the elements that allow your teams to innovate and automate. And that's what we're all about. We're the only ones in the market that have a platform like this tightly integrated with the background in security, the many, many, many years of security that we have to back us up, and also the many, many years of ITSM, ITIL management, service management that we have to back us up. So, without further ado, let's get into it. One of the things we're going to do today is we're going to show you the view from two separate teams. The first team is going to be basically the CISO and his team that looks at security risk. Now, risk is what it's all about, and at the end of the day, what organizations need to do is make sure that their risk level strategically aligns with their risk appetite. Some organizations have a lot of appetite for risk, so they're okay with things being a bit risky here and there. They'll have their own mechanisms and strategies to wrap around that acceptance of risk. But what we need to make sure is that our organization has those aligned. If you have a CISO who is very adverse to risk, but the rest of the business is okay with risk, those two ends need to come together. They need to meet. We need to try and align those risks, and risk is all about the most important assets and the highest risk to those assets. We're going to make sure that those are the ones that we address first, and then we can work our way down the chain. What we want to get to is a graph that looks like this, and exposure management is all about being proactive about that, making sure that we can categorize those risks. We can discover what they are. We have that linked into the discovery of all our assets, and we can make sure that everything is aligned. Isn't that right, Kieran? Absolutely, Shane. Cool. I'm learning as you speak. That's good to hear. I'm glad I'm adding value. And, you know, we can be intentional about what risks we want to accept or mitigate. And as we'll show today, I'll show on the platform from a CISO's view, one of the things that's very helpful for a CISO is where we've accepted risk. We need to roll around back to that acceptance in 30, 60, 90 days, whatever the timeframe is, to make sure that the risk acceptance philosophies we had 30, 60, 90 days ago still apply. Good example, got a server. Yes, there's a risk. Yes, it's a high-value asset, but it's behind 15 firewalls. Nobody can touch it. Do we accept that? Great. But we need to go and check that because in 30, 60, 90 days' time, maybe somebody's moved the server, somebody's reconfigured the firewalls, and now there is a risk because there's a hole in those firewalls to get through to that service. We need to check those things. Having an automated process to do that is something I see time and time again that people don't have, and it's one of the things our platform brings to people of great value. So when we're trying to align this risk to risk appetite, what we've got to do, there's a few steps that we can take there. First one is assess. You've got to discover what's there. You've got to consolidate your data. Everyone typically has multiple points of sources of truth and multiple points of discovery of vulnerability data. So you might have a vulnerability scanner. You might have a patch engine. You might have an EDR solution that runs on the endpoint. You might have, you know, Microsoft Defender there as well. So you might have Terrible Rapid 7 Qualys. You might have Microsoft Defender. You might have CrowdStrike. All of these things will discover assets and also discover the risks that are there, the CVEs that are there, as they're called, the common vulnerability and exploits, those areas there that are important to know. So what we're going to do is consolidate those. We need to put things in simple view so people can see what's there. Then you need to work out how do you prioritize that. It's the most important assets, the highest risk to those assets, and we need to go and chase things like active exploits first. From there, we can move to the compensate phase where we work out are we going to remediate this? Are we going to mitigate it? We've got some other way to mitigate that. So maybe it's that mitigation is we put it behind 15 firewalls. Remediation is typically all around patching, blocking ports, securing services, those sorts of things. Or do we just accept the risk? And as I said, once you've accepted that risk, you want that to go into a automated mechanism where it will then come back in 30, 60, 90 days and you can check it again. And, of course, it's all about repeat. So regular cadence. How often do we do this? Let's make sure the updates that we can give the execs are simple to consume. And automated reminders of accepted risks is something that I've spoken about a couple of times. Without further ado, let us go and join our CISO on his typical day in the life. Now, up in Brisbane, I was wearing the hat of a CISO. And even though I do still have some additional hats in my bag, I have taken the liberty of not wearing one, Kieran. So you'll be happy about that. Yep. It wasn't my finest hour wearing a Krispy Kremes hat. I get that. I get that. But, hey, not everyone can say they wore a Krispy Kreme hat. So, yeah, it's one of those things. Let me not go onto that screen first. Let me go onto this one. Right. Okay. So here is where our CISO starts his week. He's a bit like me. I like to have little reminders in my calendar. They're not appointments. They're just reminders to me to do stuff, right? So I'll have reminders in my calendar every week to do, hey, you've got to spend this time to go and do X or Y every week. So the CISO comes and he says, right, okay, I'm just going to click on the link here. That's going to be my first point of call. And that's the cool thing about our Avanti Neurons for Risk-Based Vulnerability platform is that you can very simply create a link to a particular dashboard. The person you send that link to could have access to that dashboard. Maybe you want them to modify the dashboard. Maybe you don't. But you've got the ability to do that. No limit on the number of users. So you could have every employee in your business having access to some dashboards or information or whatever just from a viewing point of view. So the CISO comes in, and this view here I really like because everyone can understand it. It's sometimes quite difficult in the security world to get security elements that can be easily explained to non-security people. The cool thing about this, if you understand what a credit score is and how it works, you can understand the view here. Everyone knows a credit score sort of goes from 350 to 850 or so. If you're down in the 350s, you've had too many payday loans, and if you go to a bank to get a loan, they'll say no thanks. If you're up in the 700s plus in the 850s, then everyone's happy to throw money at you because you've got a really, really good credit rating. This is exactly the same. So the lower number, more risk. The higher number, less risk. So CISOs can understand this really easily, but the best thing is other execs can understand it as well once they understand that the higher numbers are good and low numbers are bad. And we can see here what we've done. What I'm going to do is show you these views CISOs are using, and then I'm going to explain how we got to that view. So you can see the end result, but then you can see what steps did we take to actually get to that view. So you can see here we've got a few different groups. There's a group called Crown Jewels. Now, thankfully, the Crown Jewels is extremely well looked after at the moment, 850. So that tells me there's almost no vulnerabilities there on that Crown Jewels, and that's exactly where we want to be. The Linux servers there, the Linux servers, also in pretty good nick, right? So whoever's looking after those Linux servers, and I think there's a guy called Agdal, he's pretty good. So if I have something I want fixed, I'm probably going to give it to that guy and say, hey, can you help me out here and go and fix this? Because we've got a bit of a challenge. Now, if I look at an overall view, the default group view will show me everything. The system, all assets, again, will show me everything. And all hosts, again, will show me everything. We're only looking at vulnerabilities here that are associated with an asset or network assets. We're not talking about application vulnerabilities. The system will handle both. And as an example, Ivanti, because we do a lot of code development, things like that, we will have something like 10 different scanners sending data into our platform of RBVM for our personal tenant so that we can monitor it ourselves. Okay, so he's got a few things there. Groups are critical host findings. He's got seven. He's got three critical and high-risk groups there. So those sort of things can be things that he might want to drill into. He might want to go and have a look at. You see that finance group in the top left, the finance BU? That's just the business unit so that the finance people can look at their own assets. So the head of the finance BU will have a login, and he can look at that particular view of his group. And he can have a look at those sorts of things that are not being remediated and the things that are in there. And he can do his own management of his own little group if that's what he wants to do. But again, I'll show you how we've cut that up quite easily. The other thing, if I go back to my little calendar here and click on the other link, this is the CISO's prioritisation link. Now, you can access this a number of ways. I've just shown you how to get it out of a calendar link just for the sake of convenience. So he clicks on that link, and it will then go into what we call these prioritisation funnels. And you can see here we've got an open findings funnel right over here on the left, sort of in red. And then you've got a closed findings funnel, which shows me what has been closed, right? You can see that on the left-hand side of the open findings funnel, we've got trending at 89. And when we say trending, that means those particular vulnerabilities are critical, and they're also being actively exploited. Ivani has a rating called a VRR. And with that VRR, that vulnerability risk rating up here, what we do is we measure the risk. We measure what's being actively done. We have 150 or so odd sources that come in to create that rating, and we do a calculation and all that sort of algorithm work on it to make sure that that shows a live view of the risk of particular vulnerabilities. The ones that are down here that are in trending are actually really, really important. So we can say, well, we haven't closed very many of those. We've still got lots of them open. So I might want to get into those and have a look at them. I can have a look at these 89 host findings that are in here that are very critical. And so I've just clicked on that. We'll see how that goes. We've got those 89 there. Let me just go back to that and just click that properly, because I obviously clicked on the wrong thing there. Let me click on that. And there we go. That's better. So we've got 89 coming up here, and what I might want to do is I might do something simple like say, you know what, this page here, this top page, I'm going to go and select all in the page, and I'm just going to go and do actions assign. And I might say, you know what, that guy, Abdul, has been really, really good. So I'm going to assign these ones to that particular guy there. And apply that. And what I've just done there is I've manually made a decision and said, you know what, these assets here are important to me. I want Abdul to go and work on these ones and get them sorted out. Now, when Abdul gets those assigned to him, he'll get a notification from the system saying, hey, you've just been assigned some new work. You need to come in and have a look. He can go in and look at only his work. So that will work with him. The other way I can do that is I can do that in an automated way, and I'll show you a little bit of this now because I've gone through a couple of things. I want to show you what the CISO can see. What I want to do now is go in and show how we do that. Integrations is at core. We've got a whole bunch of integrations from different things. I talk about CrowdStrike there. I talk about Tenable, you know, Rapid7, Qualys. They're all in there. Microsoft Defender will be in there as well over here, Defender for Endpoint. They're all sources that can bring data in. All of the application ones is there. You've got all the ones for code development like Schnick and BlackDuck and all those other sorts of things. We've got integration and ticketing systems. Today, we're going to show the integration into Ivanti Neurons for ITSM. So we've got that in there. If you're one of those ServiceNow customers, you've got that in there as well. Asset management integration, we have a couple of things there. We've got some compliance things in there. And patch management, we're integrated with our Ivanti Neurons for patch management solution. Okay, so working very well there so far with those integrations. Pretty simple to set up. You just point them at the URL, put the login details, and whatever else is needed for those ones, and away you go. If you've got something that is generic and not from one of those ones that are listed, you've got the ability to do a generic upload. Again, relatively simple CSV data, map the fields. It will save that as a template. So the next time you bring data from the same source, it will just automatically be mapped. It will say, hey, is this the same as this other mapping? Yes, it is. You go. That's very cool there. The other thing that we do to create those views is we run what we call playbooks. Okay, I'm going to see so operating system playbook. So let's have a quick look at that. And what you can see is the different rules I've got in Windows 10 rule, server 2019 rule, end-of-life server rule, and a Linux rule. So let me have a look at the Linux rule for one of the things. So what this Linux rule says is this rule is going to add hosts to the Linux server target group. And the filter it's going to use to do that is view filter values, one of operating system Linux kernel 2.6. So if it finds that there is a Linux kernel 2.6, it is going to add that into the Linux view. Now it's going to add the server in there. Okay. So those servers will go into that particular group. Okay. And we can then notify things as well. We've got options there. So in this case, I'm going to email this guy and say, hey, more Linux work for you. Okay. So I'm going to send him an email and say, I've just added more Linux findings in there. So, you know, there's more Linux work for you to do. Okay. We've got Windows 10 rule as well. And, you know, end-of-life servers, that would be good for someone to do as well. So that's that. See, so the finance business unit is one I looked at. That's a very simple rule. And all that one does is if I turn it off because it's enabled at the moment. So let me disable that rule. Let me just go back and quickly disable that rule. Once it's disabled, I'll be able to show you the guts of that rule and how it works. There we go. Okay, cool. Let me go in here, here and here. And again, I'm going to add a host to the group called finance BU. But the filter I'm going to use is this finance BU filter. And when I look at those filter values, it's exactly group ID, blah, blah, blah. Okay. So those hosts have to be matching that rule set that I've got in there. And once I've got that rule set matched, I'm going to drop them into that group called finance BU. Now, in that case, I just grabbed a bunch of random servers and put them in there. In this case, am I going to notify someone? No, I'm just going to do it. The cool thing here is if we just have a quick look at all the different options we've got here for our actions, things like assigning findings, unassigning findings, all of those sorts of things can be done with a playbook automatically. And typically what you would do, you would ingest the data at, say, 10 o'clock in the morning. You'd run all your playbooks at 10.15 or 10.30. So the new data comes into the system, it settles, and then the playbooks run over the top and do all the automation. What we're trying to do is we're trying to save the SecOps people's work from sitting there and just randomly managing, manually cutting data up and all that sort of stuff to create or help create dashboards and things for people. We want that to happen automatically. You can update things like business criticality. In our language here, criticality five is supercritical, criticality one is not. So you can update those things, remove them from the group. You know, due dates and SLAs can be set, all sorts of things. Update the IP address type from internal to external. Can it talk to the internet or not? All of that stuff can be done with a playbook, which is very, very cool. I've showed you a bit about the Linux group. I've showed you a bit about the Finance BU, the business unit. That is some of the things I wanted to do. One of the things that I mentioned before was around workflows. And how do we handle workflows when what we're talking about is we are talking about workflows that are around accepted risk. So here's one here, and I can just click on this workflow. What happens here is somebody says, hey, I've got a risk here. We found a vulnerability associated with an asset. But basically what I want to do is I want to actually accept that risk. OK. And again, it's the same example I use. Use this workflow where machines at risk are behind multiple securely designed firewalls. This workflow is for accepted risk where we have a compensated control of machines behind isolated firewalls. So all the data is in there. If you've got a particular risk system, you can put some attachments in there. I've got a little picture of what firewalls look like in there. But that might be an export from another risk acceptance system. I know I've done that for a couple of customers before. And that will go in there. That's being requested. OK. Of course, I'm the CISO, so I could potentially approve that. If I am the approver, I can have a look at different things. I could reject it, rework it, copy or update it, whatever I want to do. OK. So I've got the ability to manage that workflow. Now, what that workflow will do is at a certain stage down the track, that will expire on November the 14th. And at November the 14th, it's going to notify people and say, hey, this workflow has expired. You need to get back in and have a look at it. So it helps us manage those risks, but also helps us cycle those risks around. So we're constantly going to check, is that still accepted as a risk? So one of the key things I wanted to show you is that acceptance of risk and how that works. OK. Let's look at a couple of quick other things. Let's clear out our filters there for a minute. We'll just clear them out. I might go and just very simply, just so you get the whole picture of the workflows, I might grab three little settings here and go map, unmap findings. I can put them into a modification type. I can add findings in here, select a workflow. I'm going to accept the risk. OK. There's my accepted risk there that I've got previously. So I just click on the button and I'm able to confirm by going confirm. Confirm the risk and modify. OK. I've just put those three elements into my accepted risk. So just to show you how that works, I'll actually get action by people. And then that slips up to the CISO who's going to look at it and say, yeah, I accept or I don't, one of the two. The other thing we can do with this, we have what we call collection views, which works in the same way, except with the collection views, it's an automated process. So they can automatically do things like dropping into a workflow, but also you could generate tickets. Just in the same way as I've clicked here to put them in a workflow, I can say action, create ticket and create a new ITSM ticket. OK. They have a tag type here. I could say, OK, this is for remediation. Tickets from demo. That'll do. I'm going to get an SLA date. I've got Kirin selected there, which is pretty cool. I've got to make sure that I get it from the right. Help me out here, Kirin. Which one is I? I have to select a source. That's right. There we go. That's the right one. Correct. Everyone needs someone who knows stuff about ESM around them. Cool. So I can then submit it and that is going to generate some brand new tickets for Kirin system on the back end. Now, if I have that set to a collection view, then what I've got the ability to do is I can have that actually done as a... Sorry, I clicked on the wrong thing there. I can have that done as an automated process there. So these ones here have been subject to that collection. And if I scroll down here, you will see the collection down here called My Secure Enclave. I can click on that. And it'll show me what's happening with those. You've got the ticket configuration. So I've set that up automatically. As soon as a new finding matches that collection, and this is an ongoing dynamic thing, as soon as it matches that collection, it will automatically generate a new ticket when it comes in. So you won't even have to touch it. If it matches the filter, the filter is linked to a collection. The collection is configured to automatically do tickets. It will automatically create tickets. Now, you can put limits around there and you've got limit settings in here to see all the ticket settings in here. How many do you want to do per day? I've got 50 tickets per day. Last thing you want this to do is generate because something stuffs up or somebody misconfigures it to generate 10,000 tickets a day. That will not be good. So, yeah, Kiran would know what it's like to have 10,000 new tickets in a day, wouldn't you? Not a good position for the service desk. Not a good position for the service desk. It will generate not some inclusion between the two teams, but certainly a little bit of exclusion. One group may not get invited to the Christmas party if that happens, I think. The other thing I might want to do, and just to finish off, I'm just going to show you some integration with our patch management settings here. So I've got some patch group views in here. I can show you that we've got an RBVM demo patch group there. So what I could do is I could say, you know what? What I want to do is I want to go and find where these things are. I want to go and have a look at, you know, maybe some patches potentially. I can have a look at the patch view here. It's showing me quite a few things that are rattling around. I've got some bits and pieces here. So what I could do is grab a couple of these, and I could, you know, select those, and from those, I get some actions, so I can assign them to users to go and work on those sorts of things. That's great. I could also go into where we have those patches, and I've already set up a particular view. So if I go back over here into my findings, I can go to user group, and I can grab patch view in here. That's pretty good there. So I could grab a couple of these, and again, as an action, I could say add to patch group. It'll go and query things. RBVM demo. I've got three findings selected. Patch count is zero there, so let me just grab some ones which will have a patch group, and again, it's quite easy to do things. So if I say filter patch and say has patch is exactly true. Oh, all that data, I'm going to get a false there. Okay, cool. Let me get rid of that one and just add this filter in, and again, you're seeing how it works live, which is pretty cool. Has patch is exactly true. There we go, and click on add. Okay, so these things are now going to show 778 findings when there is a patch, okay? So I can grab a few of those. I could grab the whole page if I want to, select all in the page, yep, and then go to actions again. Add to patch group. Add to my RBVM demo patch. Add that to the patch group. 15 findings are going to be there. What we can do then to finish that off, just to hopefully in the wonderful world of demos, show you where that meets the other side. I'm now connected into Ivanti Neurons. Ivanti Neurons is our platform that includes the ability to do lots and lots of great things with patch, and you can see that's now gone from a number removed to 12 have been added. So 12 patches have come down. I can go and view those if I want to in Patch Intelligence, which is our great system there for looking at everything to do with patch. You can see they're actually empty. These are actually really old patches, so when I click on include superseded, you'll see that they come up, right? So those patches there are patches that I've just added from RBVM. So I've found out what I need to do. I've added them to a patch group. That patch group can pre-populate. That patch group RBVM demo can be set up to be part of a job, and it will just run, okay? So I'm hoping that gives you a good overview. What I'm going to do now is I'm going to throw it over to Kieran. He's going to show you a bit about the backend side of the ESM side of this particular system. Over to you, Kieran. Thank you, Shane. Let me just bring up my screen. So Shane mentioned earlier, a little bit jokingly, that he's not a service management fan and has no reason to be a service management expert, and that goes for me. Security is not my thing, and if I have issues or questions around security, I come and talk to Shane. And that is typical of any organization. People work in their own areas, and that's what they're good at, and that's what they focus on. But if something needs to be brought up holistically across the business, how do we make sure that every disparate department and practice understands what's going on and what needs to happen? And this is where we come with this platform approach where the security team are managing what Shane has just shown there, looking at all those dashboards, reconciling that huge amount of data coming in and giving them actionable work to do from those dashboards and prioritizing that. If those issues and risks are going to impact the business, how do we let the relevant people know? How does the service owners know? The crown jewels, those business critical applications, are at threat or at risk. How does the risk and compliance team know that we're no longer going to adhere to certain legislation and legal compliance that we may need to sign up for depending on what vertical we are in? So this is where Shane showed the integration. He pressed the button very quickly, and he was able to send off a call to our security operations module in the service management tool to alert the security operations team to do something. And that's what service management does. It has an agreed, repeatable, reportable process so that when it needs to be triggered, everyone is doing a consistent approach to whatever comes in. And in this case, we saw that a security incident was logged against the crown jewels. So, again, I think this is what came across from Shane's system. And now, from a security operations perspective, the entire team have visibility. I can see it's been assigned to the right team. Someone's picked it up and now owns it. We've got a service attached to that, so we can trigger off notifications. We can also have service-level agreements around how timely we need to resolve this or investigate it. We can see a task has been assigned to a team as well to start looking at this. And there is a prescriptive approach to how we deal with this. It's built into the security operations platform. All the other stuff that the security team do, and we don't need to bring that up to everyone's attention. They just get on with their BAU work. But in this case, this is pretty serious. What we've had is the crown jewels, possibly CVs, what do we do about it? So, we're working on this now. Is there a sensitive data breach? Again, the team will review that and check this checkbox if they need to. Again, this may trigger a notification. Some other things may happen. But having that data, having that visibility is key. So, the security operations team can walk through that security incident and go through the various statuses and make sure it gets through to resolve so they can work on it as they need to. And, again, going back 6 months, 12 months' time, we have a history of this. We have reports we can run. If an officer comes in and says, how are you treating high-priority CVs, we can turn around and say, this is the process we're following. It happened at this date and this date, and this is the process we follow and how we remediate it. So, that's great for the security operations team that they haven't tried and test the process that they can work against to do that. However, with this crown jewels, these critical infrastructure potentially being impacted, I need to tell the risk and compliance team. How do I do that? Well, potentially, if this was high and high again and it's priority one, et cetera, we may just automate that across the risk and compliance team. I'm going to show you how I do it. I've simply got a little button here that I say, create a risk from the security operations incident, and that will go across the risk and compliance team. Now, I'll pop across to risk, and, again, security operations may live in one area, sit in one particular building. The risk and compliance team could be in another state, another country, completely down to that individual business. So, at the click of a button, I can make them aware that we have a problem, and now we can review this risk. This goes into the risk register, and, again, from a risk and compliance perspective, by coming in the morning, I see there's a new risk being added to the risk register. I can immediately investigate this. I can see where it's come from. The source may come from security incident. It may come from something else. Again, we can play around with these sources. I can get an understanding of the original categorization it came in as and where it currently sits at. So, again, I can see it goes up, it goes down, and the green and red arrows depict that. From a risk perspective, now I need to look at this from across the business. How is this impacting my business, our compliance, to potentially external legislation, laws, et cetera? So I need to look at my controls. So I could update the controls it may impact. And, again, looking at maybe it's a network security server or servers that are impacted. It could be cloud. It could be on-premise. But I need to have a look at this and see what actually it's going to impact. So I understand that maybe SSO is going to be impacted. So I have a control around SSO. And that bubbles up to maybe an ISO 27001. APRA may need it. All these different compliance and legislation may require this control. So this control is now under threat. So I'm just going to pop in and have a look at this control and have a read about it. I can see which team own it, what we're currently set at compliant. So maybe I need to now investigate this. If we have a server go down or we have a risk to that server, what potentially am I going to impact? It could be upstream. It could be downstream. I can see a lot of policies call on this control. So this control obviously will feed up to the policies, maybe to those high-level authoritative documents that we sign up to. And, again, what's our mitigation plans? Obviously the current risk that's in there as well. We could have a mitigation plan in play. But we're going to look at this. But the idea is that we're connecting all those dots seamlessly from kind of the cold face where Shane's team is actually getting all these CVEs and risks coming in and then bubbling up to the business to make sure they have visibility and they can have actionable information to work on when they come in. They don't have to run around searching for it. And Shane doesn't have to remember to go across and phone me or someone else in risk and compliance to say, hey, have you heard about this? Have you got any assets that may be impacted? So that was just my piece to show how it all hooks together. There's no point working on these in isolation. The idea is that we bring all these different parts of the solution together, seamless and automated and without having to build huge integrations. Just simply click the button and it just works. Back to you, Shane, to finish up. Yes, you've got to love things that just click the button and it just works. That's the best way of things. So hopefully that's given you a bit of an overview of the two links between the CSO type people who are looking at what's actually coming in from all the different data sources. We're then working out what's the best strategy for that. We're prioritising that to make sure the most important assets get done first with the highest risks. We're able to assign that in an automated way and automatically generate tickets, go across the service management side where we're able to track every little step. Now, that's a bidirectional flow. So when somebody goes in those tickets and closes them, that will then update the RBVM system as well to show that ticket is showing as closed. We'll wait until the next data screening comes in and we get that new data from the security things to say, yes, it is indeed closed, and then it will be closed off on the RBVM system as well. So, right, so what I'm going to do now is to show you a bit of an overview, just a quick slide here to show what we just showed you, to make a lot of sense of that. And you can see here, let me just minimise these guys so you get out of the way. So what we showed was the weekly reports, there's an email to the CSO, we've got reports that will come through that can be done, that we've got automated playbooks. The CSO has got an easy way to link into the latest data. Automated playbooks are prioritised. We can focus where we need to be, especially on things that are Captain Obvious, you know, this is our most important RICs. SecOps have tickets auto-created. So we showed you how to do that. Findings can also auto-create tickets with collections. We can make those go into an automated ticket. That can go through to the ITSM system and then create a security incident. And from there, the SecOps people can analyse and act. And for our GRC team, we've got the ability to add those issues to a risk register so that the whole business has got a really good view of what's happening. And down the bottom, you can see the three Ivani solutions we were using there, Ivani Neurons for RBVM, Ivani Neurons for Patch Management, and Ivani Neurons for SecOps slash GRC. So hopefully that shows you a good overview of what we were trying to get across, the link between the two systems, the automation levels. The goal here is to try and help people be more innovative and to automate what they do. We don't want people spending time on, you know, what I like to call donkey work. We want them working on strategic projects. Let the technology do the automation and do all of the donkey work for people so they can get on with their job and add lots of value to the business. Thank you very much for your time.