Video: Re-Integrate | Duration: 1924s | Summary: Re-Integrate | Chapters: Welcome and Introduction (32.66s), Challenges in Compliance (302.58s), Automation Enables Growth (485.80502s), Product Updates Overview (627.105s), Task Management Enhancements (959.98505s), SharePoint and ServiceNow Integrations (1089.0901s), Custom Framework Integration (1189.93s), Abtiga Showcase Feature (1313.9701s), Party Risk Management Updates (1530.1599s), Upcoming Feature Releases (1636.54s), Closing Remarks and Outlook (1781.39s)
Transcript for "Re-Integrate": Hello, everyone, and welcome to Optiga's summer product launch event, Reintegrate. I'm Laura Vieiro, product marketing manager here at Abtega. And, yes, I'm the one behind all of those emails in your inbox. But believe me, I wouldn't have flooded you if I didn't truly believe that this event is a must watch for all of our partners, customers, and forward thinking security providers out there. So big thanks to the several 100 of you who have decided to join us today. We're really glad to have you. So as you know, reintegrate is about bridging the gap between security and compliance, two words that are often split. And we've got a really packed agenda today that covers all the biggest challenges that are affecting you today and how we're solving for them at Aptida. So let's get right to it. So we will provide some context on the state of the service providers market, and we will lay out the three biggest challenges that we see arising in the current environment, which are informed and supported by our new report on the state of continuous compliance, which is an asset we just released. And you can actually find it on the document section on the right hand side of the screen next to the chat. We will reference this report over and over during the event. Next, we will discuss how these challenges can be solved and share a few examples of partners who have turned these challenges into opportunities and made their practices more scalable, profitable, and differentiated. And as usual, we will close with a bang by unveiling the latest product innovations that tackle those very challenges and that help you drive recurring revenue, margins, and client retention, the three north stars that guide everything that we build. But before we dive into the heavy serious stuff, let's talk fun. Following our severance team that just very narrowly avoids IP rights, we have hidden a few compliance handbooks in this presentation. So pay attention to the screen because when you see one, you need to take a screenshot to be able to win one of our awesome prizes. So take your screenshot and email it right away to reintegrate@optiga.com. That is reintegrate@optiga.com with no dashes. So why would you care about Easter eggs in the place? Right? Well, these are the cool prizes we're giving away today. We'll send the five respondents a limited edition reintegrate t shirt that has this cool design you can see on the screen inspired by the show, obviously. And anyone who finds all the Easter eggs will also enter a raffle to get a $150 gift card from Apple that you can, for example, use the word Apple TV subscription and catch up with the show. And by the way, they are not sponsors of this event in any way, shape, or form. We just like their products. And we're giving away three of these gift cards. And finally, one lucky winner will get a Meta Quest three s that will allow you to live in split realities and have a ton of fun while you do it and doesn't require any surgery. And by the way, if you want to get a t shirt right away, the easiest way to win one is by taking a screenshot at any point during the event and sharing it on your LinkedIn tagging up Tika. With that, we'll just send you a t shirt directly. And now let's get into the meat of today's event. So let's start off with some context. At our last product launch event, we noted a slowdown in cybersecurity spending driven by the pandemic and economic uncertainty. And while the pandemic can seem, well, far away at this point, economic uncertainty and instability, not so much. The market is not expanding as it used to. And at the same time, big players like CrowdStrike are entering the service provider space, making it more competitive than ever. Consolidation is also on the rise with larger firms acquiring smaller providers to expand their offerings. And our latest report supports this picture as well. It found that 90% of providers struggle to differentiate in this market, And it's due to brand awareness, high competition, as we just mentioned, and a lack of productized offerings. So the question here becomes, how do you stand out in a shrinking, increasingly competitive market? And what's really behind the issues that many providers face to differentiate? The big trend that we identified in our report, where by the way we surveyed 152 providers of all sizes, is an overreliance on manual work and legacy tools. I don't think this will surprise anyone. Our report revealed that despite a more widespread adoption of compliance software when compared to 02/2024, 83% of providers, 83%, still rely primarily on manual processes to manage security and compliance programs for clients. And three out of five say this, they spend too much time on manual tasks. And manual work limits scalability, consistency, and service quality. It also leads to fragmented delivery, making it much harder to link compliance efforts to security activities. More than 70% of providers said that spreadsheets were a major source of inefficiencies even when paired with automation tools. So the bottom line here, if your operations are bogged down by manual workflows, it is hard to deliver outcomes, act fast, or build repeatable service models, all of which are essential to stand out in this market. Another point of friction for many providers is a lack of productized scalable offerings. As an example, the majority of providers still deliver their services, especially compliance services via advisory models. So while 80% of providers offer compliance services, only a fraction do so via productized managed offerings. And those who do are, one, more confident in hitting revenue goals, and two, more likely to drive recurring revenue. But why does this matter? Because prioritization brings predictability, differentiation, and scalability, especially when security and compliance are integrated through technology that unites both sides of the equation. And the big challenge that we identified goes hand in hand with the previous two, and it's not being able to connect services to impactful business results for clients. In other words, demonstrating ROI. When it comes to showing ROI, 40% of the providers that we interviewed rated themselves as average or below in this area. And why does this matter for differentiation? Well, in a competitive market, it's not just about the services that you offer. It's about proving impact. And providers that can't tie their services to measurable business outcomes struggle to win and retain clients. And unsurprisingly, providers with more automation and prioritized offerings are also the ones better equipped to report outcomes and showcase value. In fact, 755% of providers using mostly automated approaches said they excel at differentiation. And those offering standardized tech powered services report strong ROI and more consistent results. And finally, all of these challenges like manual work, lack of prioritization, and limited outcome visibility also contribute to the disconnect between security and compliance. But when done right, bringing them together can become a powerful differentiator. It drives real ROI and strengthens your value proposition. Because if you don't stand out, you become a commodity. And commodities are the to be replaced or underbid. But enough enough doom and gloom. Let's shift gears here and see how you can turn these challenges into wins. So regarding the challenge, what is super clear to us is that automation unlocks scalability and differentiation. So as I mentioned earlier, 75% of providers using blended or mostly automated approaches report a much higher ability to differentiate. A good example here is our partner GDL group. By using Optiga to streamline assessments across multiple frameworks, they cut delivery time by 50%, allowing them to serve many more clients without hiring more staff. And when it comes to productized offerings, providers offering managed compliance services report stronger recurring revenue and are more confident to hit MRR and ARR goals. Take our partner, Foresight Cybersecurity, as an example of the power of prioritization. After building managed compliance offerings powered by Abtiga, they saw a 110% growth in managed service compliance customers, a 40% increase in profitability per engagement, and a 45% boost in average client ROI. Pretty impressive. So in short, prioritizing security and compliance services with the right technology enables recurring revenue, and longer and more successful client relationships. And it allows you to more easily integrate security and compliance delivery. And to tie it all together, providers that invest in both automation and prioritized offerings can prove value at scale. And a great example of this is CyberSecOps. After integrating Optiga into their offerings, they streamlined compliance delivery and gave clients real time visibility into their security posture. They were also able to layer security services on the compliance work that they were already doing for customers, creating ongoing relationships and increased client value. And the result for them was a 260 increase in client retention, with 90% of clients transitioning from assessments to full programs. So with all that context in mind, I'll hand it over to our chief product officer, Rahul Bakshi. He's going to walk you through the powerful new features we are unveiling today and how each one is designed to tackle the challenges we just explored. RB, take it away. Thanks, Laura, for the great overview and for setting the stage for this update. I'm excited to share our summer release updates with you. The team continues to build momentum on every front, automations, new capabilities across risk, security and compliance, new modules, and new UX UI, and a whole lot more. We have a ton of new value that has been released and coming available this summer. From improved automation to new risk scoring and new frameworks, let's dive in. At AppTiva, reintegrate isn't just a theme, it's a commitment, a commitment to closing the gap between security and compliance, between what's promised and what's delivered, and between the challenges you face today and the scalable solutions you'll need tomorrow. I don't know about you, but I see a lot of posts on LinkedIn by well respected security and compliance leaders who continue to reference how compliance and security are two separate worlds. The reality is they don't have to be that way. Yes. There will always be those that are focused on check the box, and that's fine. But when the program is run properly, security and compliance go hand in hand. Maybe not like peanut butter and chocolate, but close enough. And that's why before we dig into what's new, we wanna take a moment to show you where we stand on the features we announced at our last launch event. Here's a quick snapshot of what we announced back in March and where those features stand today. New assessment manager. Phases one and two are live, which includes the new list view and new assessment creation workflow. We'll demo phase three in o which is the biggest update and will be rolled out in the next few weeks. Integrations. Microsoft Defender for Cloud has been live since March, and our ServiceNow integration is going live by the end of this month. We'll also show a bit more on how this new integration works later today. Enhanced dashboards. These have been live since February, providing you with a three sixty degree view of your clients and allowing you to get super granular and visualize what's happening at the framework level. New and improved content. We've incorporated CMMC 2.13, the final version of CMMC, CJS v six, NIST AI, RMF 100 dash one, and we're about to incorporate the NIST AI 600 dash one generative AI profile and a few other frameworks I'll announce later. Data ingestion updates. We now allow the ingestion of custom assessments and risk registers. And very recently, you're also able to upload your own vendor risk manager questionnaires and vendor lists. More on that in just a Task two .o. We're in the final stages of our complete tasking overhaul. I'm gonna show you in the the two big updates that we're rolling out in the next couple of weeks around one to many tasking and bulk uploads, and we'll show you when this project will wrap up and the value it delivers. The new scoring system. The main progress here has been our vendor risk manager. I'll demo what's about to be released in a Scoring across the platform is a bigger initiative that will span until the end of the year and will give you all the flexibility and customization around scoring that you can possibly imagine. With that, let's go over all the product innovations we have for you today. As we covered earlier, working more efficiently through automation is one of the secret weapons that forward thinking providers use to differentiate in a crowded market and to scale their practice and margins without increasing headcount. And being a software platform, most, if not all, of the features we release are aimed at improving your workflows, so you can move as fast as possible and with the least amount of friction. And as you know, we're going through a full platform redesign that's laser focused on making it faster and even more intuitive, and the module we rebuilt was our most crucial assessment manager. We demoed the new assessment manager in March, and we've rolled out two modules with the and most impactful, which is the ability to take an assessment end to end with the new UI coming up in June, July, where you'll be able to perform bulk uploads, drag and drop, take bulk actions, and many more of new functions. Let's take a look at what we released and what's around the corner. We start with list view, which includes new views including draft and archive. We also have the ability to search and sort by column. When we go to create new, we can quickly set up a new assessment and customize how you want to look and feel, including recommendations, auto tasking, and risks as examples. You can click next to assign users to the categories if you choose and launch or save as draft. Let's go back to our list view and find a draft assessment that we want to take. We're gonna activate this assessment, and from there, it's start the assessment. And this is the new stuff releasing in June, July. We'll start with category summary view, where users can understand the status of each category, identify the number of subcategories and questions within each, understand the user or users assigned to the categories. As responses are defined in the assessment, users can see the program score and percent complete score accordingly. Finally, you can import assessment question responses in bulk, saving time in addition to scoring the program and running reports, all from a single screen. From here, we'll click on view. We can see all questions, quickly enter responses, drill down into each category, and see the associated details, documents, last activity. Hover over provides more details as needed across the UI. Users can click into a question to add key data, such as notes, recommendations, risks, tasks. You can also manage documents and drag and drop data from a library of assets in the platform. In addition to all that you see here, we're also adding bulk responses. As you can see, this new functionality will dramatically reduce the time to take an assessment. We've seen 25 to 40% improvements in user testing. Great stuff. We're excited to release it, and we're excited to get your feedback. Another area where we focused on enabling our partners and customers with automation is security and compliance program management via our tasking system, which saves you time, makes it more effective when prioritizing work, while enabling you to manage your program centrally. As you may recall, we released some new functionality in Q4 of last year and Q1 of this year, task recurrence in Q4, enabling everyone to more efficiently and effectively set up and manage recurring tasks across the platform. In Q1, to make it easier to understand the changes in your tasks and what is up next, we released a new daily digest of tasks where you can see new, updated, overdue and any key changes to those respective tasks at a glance. With that, we're excited to announce the ability to manage tasks across multiple controls and frameworks, further improving your time to value through automation and leveraging the power of Harmony. Let's take a look at how you can create tasks across multiple controls and frameworks, a functionality we're calling one to many tasking. Now when creating a new task, you can select as many sub control assignments as you need so you could link that task to all relevant sub controls in the same or different frameworks. As you see, it's also a quick change to unlink any of these tasks. The best part is that when you have harmonized programs for two or more frameworks, you only have to set up the task once. When you create a task and link it to one sub control of any of those frameworks, it will also be created in the equivalent sub control of the other map frameworks. You can easily access any sub controls associated with the task from the list view over here. This makes managing tasks across frameworks and sub controls night and day easier, saving you valuable time and making your tasks even more reliable. And there's more. In June and July, expect to see task2.0 take its victory lap when we release configurable reminders and a revised workflow automation that broadens the power of tasks across the Aptiva platform, making it easier to connect tasks across risks, party risks, controls, and reduces the time of the platform. For those of you that bring your own tasks into the platform, our PM team has also made it super simple to upload any type of tasks, recurring or not, with just a few clicks. This revised workflow also further interweaves security and compliance for you and your customers. Now as I always say, we can't talk about automation across the platform without talking about integrations. And many of the security providers we work with operate in the Microsoft ecosystem, so I'm sure you'll love this one. We're getting ready to launch an integration with SharePoint that'll help you save time and avoid duplicative work by bringing evidence collected to AppTida and a natural extension to what you're already doing in SharePoint. To set it up, you simply need to map any relevant SharePoint folders to Opteka's document repository or to the specific control that should continue that evidence, and the system will update the info information automatically every day. This folder to control mapping gives you granular control over what evidence syncs and where. Now you have a true source of truth as you have the evidence repository and the connected score status of that evidence and as it changes, truly underscoring compliance your way in the platform. We'll have this available in q three. If anyone's interested in learning more or being part of the early access, please reach out to your customer success manager or sales contact. Now as I mentioned earlier, for organizations that manage their ticketing workflows via enterprise tools such as Jira and ServiceNow, Aptiga has expanded its integration portfolio to include ServiceNow. This helps you avoid duplicative work, save time, and benefit from enterprise workflows that don't need to be altered. This integration ensures tasks automatically flow into ServiceNow, enabling users to complete their security or compliance work and update Aptiga programmatically. You simply need to add your credentials into the integrations panel in the Aptiga platform, map your status, and start syncing tasks bidirectionally. We're rolling this out before the end of the month, so please let your success manager know if you'd like to get it enabled for your account. Now we've also discussed the crucial role of productizing your offerings for service differentiation and stickiness. In that vein, having access to a wide range of frameworks and standards with cross map controls is a great way to add more value to your customers and help them meet compliance requirements along with security best practices. At Apptiga, we have a dedicated content team that's constantly adding new frameworks to the library, updating and improving existing content, and ensuring the mappings across frameworks are accurate and up to date. In the coming weeks, we'll be rolling out the frameworks, assessments and task packs for NIST AI six zero one, generative AI profile, PCI four zero one, a new CJIS assessment and task pack, and we'll be updating NYDFS five hundred twenty twenty three, the CJIS framework and the task packs for NIST 853 and ISO 42,001. These will all be templates that you can access via our library, but as you all know, standard frameworks don't always fully align with your internal policies, industry specific requirements or evolving strategies. With custom framework data ingestion, we give you the flexibility to define your own compliance path and keep your unique style while automating key compliance steps for you and your clients. Custom framework ingestion means you can work beyond standard frameworks and import your own control sets tailored to your business or industry. You can also adapt your custom frameworks as you grow by uploading new versions of your own frameworks as your organization's security and compliance posture matures. And how do you create those frameworks in the place? Well, you may wanna build them from scratch or just enhance existing standards. If you do the latter, you can just blend industry frameworks you'll find on the platform with your customer requirements for full control coverage. When it comes to actually uploading those frameworks to Outriga, you can choose to do it for all or some of your tenants, depending on your customers' needs and your own preferences. Apart from being able to do things your way and more easily productize your offerings, Custom Frameworks allows you to accelerate onboarding times with clients and framework expansion as you'll be able to reuse existing content and deploy quickly without starting from scratch. Now one of the key components of a successful productized offering is demonstrating value throughout the customer lifecycle, and we have our partners back on that front. We're proud to announce one of the most impactful features for partners this year, the Abtiga Showcase. Our Showcase has been available in early release for quite some time. It is now becoming fully integrated in the Abtiga platform to enable our partners to have deeper value discussions that improve client security and compliance programs and also drive more revenue and growth in your business. This functionality is unique in that it delivers value on multiple fronts. It integrates your services into the Abtiga platform to better connect the two worlds of security and compliance while adding more value to the security compliance programs you're managing today. Let me show you how it works. Here we are inside AppTiva Showcase, which is a completely customizable, configurable interface by our partners. You can build packages that look and feel like your offerings, including documentation, images, down to the control mapping so it feels and looks just like your business. You can show outcomes of showcase on each control on the customer side, where you can show how it reflects at the control level when enabled and implications of having or not having a certain product, and also encourage them to have their service provider enable it for them to see those results. Let's see an example here. In this view, you can see a series of different capabilities that you can configure in the product itself. We're gonna pick application security as an example. There's a series of application services that you can set up and configure. These can be party products or, more specifically, could be your products, which most likely will be the case. For this demo, we're gonna pick more paths here, where you can come in and describe the product, put a description in, talk about any pricing or packaging options. You can then tie it back to the controls and sub controls, put product specifications. You can see it's a very robust interface where you can put a significant amount of detail or as little details you feel needed. Then you just simply add it to your solutions. Then we're in a customer facing view where this could be a customer looking at it by themselves or it could be one of your VC sales or technical account managers or somebody from the service provider side having a conversation with the customer, where you're reviewing the security or compliance program. And you're talking about, in this case, the need to ensure use of only fully supported browsers and email clients isn't fully enforced yet. As you scroll down, you can see that there's some solutions that can solve for this. In this example, you can say contact the service provider, which is really a customer facing view. In other situations, this could just be a a, you know, QBR that you're having with your customer, a regular checkpoint where you're talking about how they're doing on a controller or set of controls, and what their options are. In this case, it's more of a self-service where you can schedule a call with your service provider. You can request that call. After they understand the power of that service, they enable it, and you can see here that it is enabled and it's tied back to the service. So it very easily pulls it all together so you can fully understand the power and the value and how it helps the customer understand how their security maturity or compliance programs continue to move ahead as they add more services from your portfolio. Where we're different than other options that are limited in-depth and configurability is we map down to the control level, not some abstraction layer that doesn't really align with your security compliance outcomes. This is important in that it helps you really demonstrate that value down to the granular control, down to the specific control in the framework, and really improves the overall scoring and also helps you understand trend lines over time. As it becomes a key asset for every stage of your customer lifecycle, Showcase will drive deeper customer engagement and improve your overall net retention. We're excited to get into your hands, and we're excited to share more as the year moves ahead. Apart from productized offerings powered by technology like what we just illustrated with Showcase, our most successful partners are managing not only compliance but security and risk, delivering a holistic view, and driving a broader value proposition as they align these three key outcomes together. In support of that, one of the things our customers demand the most is assistance with party risk management. So we're making some significant changes to our vendor risk manager, including renaming it to party risk management. This is going live tomorrow and represents a significant improvement in enabling you to manage your party risk. Before we get into the exciting updates around scoring, let's highlight the fact that you can now bring data into the platform in real time with limited effort. Here, a user is importing a vendor list and or questionnaires. From there, we can customize the questionnaire, how you wanna score, the type of response, and associated details. And if you wanna set up follow-up questions, you can, and then send it. After they respond, you can view the overall questionnaire score to determine vulnerabilities, gaps, and the risks so you can better gauge and manage your party risk from the platform itself. The new list view includes the overall profile vendor score. You now have the ability to see the inherent risk and residual risk score for each vendor. For example, if a vendor responds no to a question, the respective score changes based on how you define that score and impact, and you can follow that path all the way to the top line score. Users have the ability to customize response scores, including yes, no, radio checkbox, drop down, and the ability to do short and long answer. This new and powerful functionality goes live tomorrow. We're excited to release it and to hear your feedback. Thank you so much. Now the question on everyone's mind, when are all these features gonna be live on the platform? The two portions of our new assessment manager are already available on the platform, and the phase, which involves running an assessment end to end, will be released before the end of the month. After that, there will only be a couple of small functionalities that we'll incorporate in q three, but the bulk of the value will be available to you. When it comes to tasking, the one to many functionality we presented today will be released in the next week or so, and the entire tasking revamp will come to fruition by the end of the month or early July at the latest. Regarding integrations, the ServiceNow integration is in the final stages of development, so we'll make it available by the end of the month. Let us know if you're interested in getting it activated for your account. And we've already started developing our SharePoint integration, so we expect to have it ready in early q three. Regarding new and updated content, the framework we'll roll out will be the NIST AI six zero one generated AI profile and all the other frameworks will be available between the end of the month and early Q3. When it comes to custom data ingestion, it's already possible to upload vendor list and questionnaires, and the option to upload custom frameworks will be rolled out by the end of this month. The new showcase is still in development. If you'd like to contribute to this initiative, please reach out to your customer success manager or account executive. And finally, I'm excited to announce that the vendor questionnaire scoring updates and the renaming of the module to party vendor manager will be rolled out tomorrow. If you joined an Aptiga launch event before, you know we always have an extra card up our sleeve, and we couldn't end today without revealing something truly exciting we've been working on. Imagine this. You cut the time it takes to fill out a security questionnaire by at least half for you or your clients so you can focus on more strategic initiatives, support more clients, and close more business. Or you've got a Copilot, an AI VCISO, if you like, by your side that handles bulk actions, auto assigns tasks, and it answers questions about your tenants instantly. And you don't have to type in the ask. It does it for you based on how you configure the capability. And you can answer what is my client security posture or how do we compare to industry peers or anything that you can imagine related to your analytics and benefit from real customized insights in seconds. Well, you don't have to imagine much longer. This is Aptiga Intelligence, our upcoming platform wide capability that brings the power of LLMs to the most time consuming, high impact parts of your workflow. We're keeping the full reveal under wraps for now, but get ready. AppTeeg Intelligence is coming this fall, and it's gonna change the game. Well, thank you so much for the great presentation, Harvey. And thanks to our product and engineering teams for their super hard work over the past few months to bring all these awesome product features and innovations to market. If you're an Optiva partner or customer and want to get a deeper dive into any of the features that we presented today, you can contact your customer success manager, and they will coordinate trainings and demos for you. And if you're with us for the time and are curious to learn more about Optiva or how to become a partner, you can click the get a demo, button that you'll see at the top or just answer yes in the poll that we launched earlier, and we will be in touch. And finally, be on the lookout for the biggest event that we will have this year. It will happen in the fall, and it will be like this product launch but on steroids. We will have educational sessions, networking, and product updates as usual. I can't share much more right now, but stay tuned for that. Thank you all so much for taking the time out of your day to be with us, and we'll see you next time.