Palo Alto Networks, Inc. (PANW) Earnings Call Transcript & Summary

January 15, 2024

NASDAQ US Information Technology Software conference_presentation 43 min

Earnings Call Speaker Segments

Wendi Whitmore

executive
#1

All right. Good morning, everyone. Thank you so much for joining us today. We appreciate that people are still filtering in from the keynote sessions. We're excited to kick things off with you today at our Big Ideas Session. So my name is Wendi Whitmore. I lead Unit 42 at Palo Alto Networks. For any of you who may not be familiar with Unit 42, we're really the eyes and ears on the ground. So we conduct investigations, we have threat intelligence analysts and then we've got threat hunters all throughout the world who are working on behalf of our teams and all of our clients in a variety of spaces throughout the world. So that said, I'm really excited today to have this outstanding group of leaders who have so much industry experience that they're going to be able to share with you today. So Carrie, I'd love to kick it off to you first and have you introduce yourself and tell us a little bit of your background.

Carrie Tharp

attendee
#2

Great. I'm Carrie Tharp, I lead up Strategic Industries at Google Cloud, looking after all of our customers across a range of industries. But my background is in retail and consumer. So I spent my career as a Chief Digital Officer, Chief Marketing Officer, Brand President at places like Neiman Marcus and Fossil Group. So spent a lot of time thinking about protecting my payment systems, my network, my customers' data. And at Google, I work with our teams to bring the best of our capabilities forward to customers like Kroger and Ulta to make sure that their innovation road map is safe and secure.

Wendi Whitmore

executive
#3

Great. Thank you, Carrie. Really looking forward to your perspective here. And Nicole, would love to turn it over to you.

Nicole Beckwith

attendee
#4

Absolutely. So my name is Nicole Beckwith. I manage threat operations for the Kroger Company. And within that team, we have threat intelligence, threat hunting, detection engineering and insider risk and fraud. So a little bit going on there. And my background, I've been at Kroger for about 3 years, before that was in law enforcement, did incident response and digital forensics for the State of Ohio and the secret service.

Wendi Whitmore

executive
#5

Awesome. Thanks, Nicole. Definitely looking forward to hearing what kind of threats you're seeing. Diane, over to you.

Diane Brown

attendee
#6

Good morning. So I am Diane Brown, and I have the honor and privilege of leading the IT risk management team at Ulta Beauty. We're a team of about 40 people right now, and we cover everything except fiscal fraud and physical -- I mean, fiscal security and fraud. Everything else, we do identity management, access management, compliance, threat intelligence, cybersecurity, you name it, we do it. And I've been with Ulta for 16 years. And one of the things that -- our newest addition to our portfolio is, of course, Cloud and with the digital transformation and how that is coming into our organization. And I think that's one of the things that I love to talk about our journey and how we've gotten where we are today.

Wendi Whitmore

executive
#7

Awesome. Thanks, Diane. I'm definitely a big fan of your organization. So I know we're all looking forward to hearing more. So you brought up digital transformation. And, well, let's start there. But I will say that there are so many aspects on the retail landscape that are unique, I think, to your industry, right? Relative to not only all the cyber criminal and digital threats we face, but certainly, the physical threats that you have in terms of opportunities for shrink and everything else in the stores themselves as well as online in the cyber criminal aspects of that. So we're looking forward to kind of touching base on a wide variety of those. But Carrie, let's start with the digital transformation, and I'd love to hear what you're seeing across the industry and then really what you see moving forward?

Carrie Tharp

attendee
#8

Yes. So I think over the last decade plus, all of our experience have become data-centric. And so it's no longer just about protecting payment systems and kind of your e-commerce transactions, but starting to think about how you protect and secure all of your consumer data across every new experience that retailers are looking to bring to the market. So that's where we see people thinking about classic threat detection, looking for those bad actors. But then when you expand to the physical world and the types of experiences there, AI is beginning to offer new opportunities. For example, in loss prevention, so being able to recognize with vision, kind of common actions that are happening, aggregate that data. We're working on looking at data consortiums to help across multiple retailers so they can recognize patterns. So when they come to the store, they can address those appropriately, which leads to better customer experience. So I think all of us have been to a store where they're out of stock of something that might have been caused potentially buy prime and so making sure you're just meeting the expectations of all the great loyalty programs that are coming out, different promotions that you have and ensuring that bad actors aren't getting in the way of that experience. But I'd love to hear from Diane and Nicole about the types of experiences they're thinking about as well.

Nicole Beckwith

attendee
#9

Sure. So it's interesting that you touched on the customer experience, right, because first and foremost, that's what we care about the most at Kroger, and I'm sure Ulta Beauty as well, both in-store and the digital online experience. The pandemic was a really good example of how we got to use Cloud to accelerate that experience. And it was a really fast shift from in-store to have to scale at speed. And one of the ways that we were able to do that was through utilizing our Cloud partners and resources such as Google.

Diane Brown

attendee
#10

So Carrie touched on the topic of data and how important data is. And it's very interesting over the years. I mean the big thing back 10, 15 years ago with credit cards. You're trying to get a hold of somebody's credit card in order to make fraudulent transactions. But now they're more interested in the loyalty, like, they were talking about getting a hold of somebody's loyalty points and being able to purchase products and commit fraud in those different ways. And I think one of the good things about the Cloud and what we've done in the digital transformation process is we have ways now that we can actually make it better for the guest experience. So now they can go out there, they can do buy online, pick up in-store. We can do -- ship from -- ship to your home, ship to door -- store to door, we call it. When you want it to go in, our inventory is not there and how we can get you -- still get you the product that the guest wants. But because of that, we've had to take that digital transformation and as a security person, as you know, it's one of the things that we always are afraid of is taking that step into the digital world because we want to protect that data because as with all -- as Nicole was saying, we always put our guests at the center of everything we do along with our associates. And I think that's the biggest thing is how do we take what we know and love today in the security world and use that now in this digital transformation process.

Wendi Whitmore

executive
#11

So, Diane, I think staying on that topic, I'm really curious what you're seeing like the benefits that you're identifying in terms of removing some of the friction to those end consumers, right? I imagine there's a lot of benefits in the digital journey, but there's likely a lot of challenges as well. I'm curious if you could share a little more insight into that side of your role?

Diane Brown

attendee
#12

So we just finished a platform refresh of our e-commerce system. So this one is very near and dear to our heart. We actually went live in August of this year. And that's where we're really trying to make a difference because one of the things with our guest services' department, when the customer calls up and says, you're not protecting my data, you had a data breach, somebody got my loyalty points. And then you have to explain to that person, it's not that they got your loyalty points. Your user idea has been in a lot of breaches and the fact that the bad guys out there have your user ID, they have your password and they're able to get onto our systems. So we've actually tried to find ways from a secure perspective to get people not to be dependent on people anymore. We know people are the weakest link to security. And so we're really focusing now on how we can do more to protect them, but not make them think that they did anything wrong because that's the thing you don't -- you have the friction, you don't want friction at checkout. And so we're really looking at how to make things easy from like when do you invoke multifactor? Do you always have to invoke multifactor? Or can you make it when somebody's account has been compromised because we get all that. From the -- when they think about threat intelligence these days, they can get all that data. And so the business is actually at that now where we're looking at those decisions and how to make them -- so there is less friction, but it's also been easier because more and more retailers are doing it. So it's becoming more of the norm. And I think that was the biggest challenge from the friction side is you don't want to discourage the guest from the checkout, but we have to get better protecting them because sadly they're not going to protect themselves.

Wendi Whitmore

executive
#13

Right, such a challenge. Nicole, I'm interested in your perspective here relative to the landscape as it relates to groceries and all of that kind of platform that you guys are seeing at Kroger.

Nicole Beckwith

attendee
#14

We see similar to what Diane mentioned, a lot of the account takeovers and it is because -- I hope none of you reuse passwords, right? Nobody -- no one here has ever done that.

Wendi Whitmore

executive
#15

I don't.

Nicole Beckwith

attendee
#16

So we do see that often. And we're trying to find ways with the multifactor as well to ensure that, that data stays safe, but you don't have to log in every single time because none of us like that. So using biometrics, facial recognition, how can we enable 2-actor authentication, but not have to utilize it every single instance. What detections can we put on the back end, impossible travel. For example, if Diane logs in from Texas one day and then she logs in from London in an hour, are we detecting on those sorts of things. So it's all about defense and depth, obviously, enabling the business, enabling the customers to be able to shop the way they want with the payment cards that they want. Do you want to do Tap to Pay, do you want to use Apple Pay? So making sure that we give the customer those options that make it an easy and frictionless experience.

Wendi Whitmore

executive
#17

Thanks, Nicole. Carrie, you've got a unique perspective, right, across from your previous experience, working firsthand in these organizations. And now I imagine seeing across a wide variety of organizations in this space. So I'm curious what are some of the more common themes you're seeing that these organizations are facing related to challenges.

Carrie Tharp

attendee
#18

Yes. I think I'll talk a little bit forward looking and you guys can share a little bit about kind of right now in the moment. One, I think, you guys both had a theme of this dynamic tension between the desire for conversion and friction-free and security. So there's probably always the CDO sitting on the other side saying, "I don't want any payment friction whatsoever ," but you have to do that trade-off of kind of what's at risk. At Neiman Marcus, for example, our promotional gift cards could actually have hundreds of thousands of dollars on it. So the risk was extremely high. And so we took that very seriously. And the end consumer often didn't even know when they were victimized. And so part of what we're looking into the future from an AI perspective is using generative in 3 key themes. So it's going to help with talent, toil and threats. So, one, the bad actors now are going to have more tools at their disposal to create challenges for all of you out there. So how do you stay ahead of that? Generative AI, first on that threat, T that I mentioned, is going to help you detect those threats sooner. So you catch it earlier into kind of whatever that issue being created is. Then on toil, so generative AI, when you think about security workflows can be very manual. You might not have all the resources to be looking at everything that your organization is dealing with at a given moment. And so generative will help you synthesize, summarize and look at those threats and determine what to do and then it also helps with the talent problem. So you may not have all the resources you need coming into your organization. And so this really democratizes the access to being able to deal with cybersecurity threats. So when you're kind of using language models to simplify what's going on and shorten the workflow, your youngest analysts can now engage more like a senior analysts. And so how do you get your hands wet in those technologies? From a Google perspective, we have Mandiant and Chronicle that have been looking at automation for quite some time, but we're bringing new capabilities to market like our security it's called Sec-PaLM 2. We're now calling it [ Sec LM ] that's trading on -- this is a data problem. So trading on kind of the world's largest data set. We see everything that's happening to our customers. But if you also think about aggregate threats we see at Google. So we're understanding everything that's happening in Gmail. So trying to go in and access that information and then use it across websites. I had to explain to my CEO at one company, what Daisy-changing your passwords were. He was like, oops, I obviously do that. And so understanding all of that, building it into the models helps supercharge our own teams because I think it's almost exhausting as the security team, perhaps to try to keep up with everything that's happening. And so how do you now use AI as a part of your team to protect your corporate assets and your consumer data.

Wendi Whitmore

executive
#19

Yes. I think AI, obviously, is at the top of everyone's news and at the top of mind. On the generative AI side, we're really seeing a lot of activity on the attacker front as it relates to how can they social engineer better and more effectively their verbal communications and written communications. And we've seen a number of organizations where they're specifically targeting help desks and those type of organizations who will be able to imitate legitimate users and then be able to get 2-factor authentication and circumvent that. So Nicole, with your background, in particular on the threat side, right, and you're a law enforcement side, the intersection of that, I think, is really nowhere greater than an industry like retail. I'm curious like at the level with which you're tracking threats and incidents, what's working and what are you seeing within Kroger?

Nicole Beckwith

attendee
#20

Sure. Well, I think with AI, you bring up a great point. The barrier to entry is much lower when threat actors are using generative AI. So we worry about speed at which we can not only detect the attacks, but protect against them, right? And so I think it's another tool in our tool belt to be able to utilize to protect the company even better. But you brought up social engineering, and we see that not only with e-mails, but help desk attacks and phone calls to the stores, to store associates. So a little bit of the intersection there between the physical and the cyber threats as well. But I think AI is here to say, obviously, is going to be embedded in everything we do. And we just have to use it to further what we do as a company to protect. And developers, for example, they use it to write better code. If I didn't know Rust and I needed to write something in the Rust language, I can use generative AI to kind of help me out, right? So with that also is the data protection piece of the puzzle. So how do we protect Kroger data so that it's not leaking into these platforms and into these models and becoming part of the data set? So there is a protective aspect to that as well.

Carrie Tharp

attendee
#21

I think that's a really good theme because we haven't really addressed it yet. And a big question a lot of our customers have about exposing your data to a lot of the models that are now out there in the market. And so I think that's kind of a new area for everybody that's in the security space to be thinking about. I think there's a lot of press of companies, countries, various folks exposing their proprietary data into some of the models out there in the world. And so thinking about the entire platform that your organization is using, even if it's related to topics that don't seem like, there's something that the security team should be looking at. It's a new area to think about holistically because you certainly don't want any of that IP out training models. From a Google perspective, we don't train our models on our customer data. So your interaction effectively with the models is private. That's not necessarily true as your teams and chief digital officers and data officers are playing with some of these new capabilities. So definitely, for those new things for everybody to learn about and kind of understand what the new risk is to their enterprise IP.

Wendi Whitmore

executive
#22

No doubt. I think organizations across every industry, right, likely all of us are struggling with, how do our employees use AI in the sense of what data are they inputting into LLMs, where is that data located, how do we ensure that sensitive data, right, is not -- that shouldn't be in there is not input? So, I guess, Diane, on that note, before we kind of shift back to how you're reacting to them on a consumer basis, I'm just curious from an internal policy perspective, how has the onset of generative AI been within Ulta and just getting your employees secure and ensuring that they're not putting data that they shouldn't be?

Diane Brown

attendee
#23

So I have the advantage. I am on the GenAI Governance Committee.

Wendi Whitmore

executive
#24

That's great.

Diane Brown

attendee
#25

It's one of those things where whenever you have a topic that there aren't a lot of people familiar with, they're like, "Oh, we got to have a security person. We got to have a security person. We don't know what they're going to do, but gosh we have to have a security person out there because we know they'll tell us what not to do. So -- and I think -- so that was the first step. I think one of the challenges as an organization that we have to your point is, they're so focused, like Ulta. We're really focused on trying to get it right at the beginning this time because we know it is our data. And if we do that wrong, it could be detrimental to the company and with all of us here. And I think part of the challenge is trying -- for especially retailers and some may not as big as the Googles and the Microsofts in the world is, we have to try to get this group of people together. We get attorneys involved always because that's easy -- lot of the times, that's the easiest thing to do, but we're struggling as organizations to get started. And as always I tell my team, you're never going to finish if you don't start. And so we're really trying to get started, and we've actually reached out to -- we had a conversation with Microsoft this week, and we've also reached out to Google and our account executives would say, can you tell us how you're doing it? Because you guys got it. You're selling it, so you must have something that we don't have yet. And it's really -- it was really amazing with that conversation with Microsoft, how much they're willing to share, and I'm sure Google [indiscernible] saying when we have that conversation with them, but it's how do you get started? Because similar to our journey in the Cloud, and we were behind from a security perspective, the business was -- wanted to roll fast. If we were behind and we had -- we took a long time to play catch-up. This is something you can't play catch-up on, you have to get out there in the front of it. So AI has been around for a long time. Series been around. Lexis has been around. People actually put a label on it at that time because that's kind of GenAI. You can talk to it and they'll tell you what you want to know. And so GenAI has been around, but now we've just made it a lot easier for people to, like Nicole was saying, train my developers, give my staff, okay, we're seeing this type of IOC. And these are the IP addresses, where should we put a block? What country should I block? And there's a lot of really good wealth. But in order for us to do that, we have to have that guidance upfront because people are looking for guidance. They want to know what they can and cannot do. And I think that is where companies are really struggling is getting that documented and in place and educating their employees on how to get that done.

Nicole Beckwith

attendee
#26

Right? Just to pivot off that for a second as well, too, because just walking around this conference, almost every booth has a reference to AI, right? And so we know it's out there. We know it's fair to say. But now I feel like this year is the year of show me the value, right? So we know it can do all these things with HR and business processes that we can help the supply chain and endless number of things that AI can do for a business, especially for retail. But what is the value? And how do I implement that safely, securely and enable the business while also protecting it and the data that's in it as well?

Carrie Tharp

attendee
#27

I think that's a theme I didn't mention earlier. We see a lot of our customers starting on internal use cases first. So it gives you kind of a safe, secure environment to test out generative on kind of internal associate chatbots, on your core functions and in the security space. So then those governance councils or, however, your team has kind of orchestrated the oversight, then start to get feedback, you can identify more risks and threats and it's kind of a nice way to wade yourself in Because in retail, everybody has been using AI for a long time. We've had recommendations engines. A lot of them weren't generative, but you have teams and people and processes that have been thinking about it. It is now just kind of an expansion of that capability. And so flexing a couple of new muscles. We also see people have very different teams engaged in generative. So when you think about prompt engineering, we're seeing retailers, as an example, bring in their UX and UI team. And just teams that think about the problem differently who might not have thought about some of these different factors. And so kind of getting everybody up to speed on what to be thinking about from a data privacy and protection and then a cybersecurity element. So it's kind of new and old, but an expansion of skill set for everybody to think through. And it's important to call out because you don't want to think, oh, this is just like what I was doing before, which was a lot of closed loop AI in your digital experience and now language models really exposing you to a much broader corpus of data and list of threats.

Wendi Whitmore

executive
#28

Carrie, you bring up an interesting point about just kind of the intersection of skill sets needed now. And so, Diane, I want to turn that question back to you, just in the sense of organizational structure, retail, I think, is unique because oftentimes you have loss prevention, who is also at the intersection of cybersecurity professionals who in many other industries would be siloed off, right, completely. So I'm curious, are you seeing now a need organizationally to combine also AI skill sets? Are there any kind of new skill sets maybe you're bringing on to the team that are critical to really effectively protecting your enterprise?

Diane Brown

attendee
#29

Ulta has an advantage. We bought a company about 5 years ago called Quasi and we've been using AI. If you ever go to our Ulta app, you can try on makeup, you can try all different hairstyles, and that's all AI-driven. And that was from this company. So we've already been playing in that area. So from an AI perspective, we have controls because it's really hard to put controls in place, but very sophisticated mature program when it comes to that. The problem is when it comes to the GenAI side of it and we were talking about the governance piece of it, it's because -- I think, the organizations are going slow to put in those guardrails for people. People don't want to wait, as we know with the -- how technology is today, everybody has a cell phone, everybody has a computer. People aren't waiting for that guidance. And that's the scary part that we need to find the skills to find -- to learn how to investigate that. Because one of the things when AI -- this whole GenAI first came out, it was -- a few of our vendors reached out and they're like, "Oh, we can protect you from GenAI " I'm like, okay, show me how, but they really can't. They're just taking basically what they have and restructuring just a little bit. So, therefore, your skills like you were talking about that now rely back on your risk management teams and also our data governance team, we are in lockstep with our data governance team and how to educate them. But -- and that's where we hope we rely on. At some point, we realize we need our partners, we need the Googles, the Microsofts, the Palo Alto people to help us. That's what we need because you've been playing -- you've been doing this as part of your tooling for a long time and that's where, I think, a lot of us are looking for that guidance, to your point, is what skills do they need? I mean I have very good threat hunters. I have great investigators, but is there a different skill they need to be able to identify that type of traffic across your network.

Wendi Whitmore

executive
#30

Right, right. You're spot on just in terms of kind of not only the ecosystem, right, that needs to exist and that you depend on and any organization does, but really the fact that we like to say, cybersecurity is a team sport, right? It relies on so many different skill sets to get the job done. So, Nicole, I'd love to hear what your perspective is at Kroger, just in the sense of how are you organizing your team? Are there new skill sets that you're needing to bring on? Are there new challenges that your team is facing?

Nicole Beckwith

attendee
#31

Sure. So with my team, particularly, we have such a diverse background. And I handpick those people for their background, right? We have HR, we have law enforcement, we have dark web, brand monitoring, marketing. And that all plays into how we protect the company. My team reaches out across multiple orgs within Kroger, one of which, as you mentioned earlier, was that physical security, organized retail crime perspective. And more and more, we're seeing a shift of cybersecurity also touches the physical security space. And so my team is regularly working with our asset protection folks, our organized retail crime folks in making sure that we understand where each other play. And so if they're seeing a threat in the store from a physical security perspective, maybe gift cards [ broad ] for example. We can see that on the back end in the cyberspace. You think about an account takeover, you mentioned loyalty payments. We see that come into the physical aspect because then it transfers to actual products in the store being stolen, obviously, and then resold online or used by the threat actor. We think about skimmers in the store as well. There's a physical aspect to those too that we have to work hand in hand with those teams and it's so important nowadays. If your cybersecurity team is not working with asset protection and your organized retail crime and physical security, you really need to start that conversation. We're regularly -- I would say, probably weekly working with those teams on those threats. So it's great to have a diverse set of backgrounds on your team, but you also have to understand where you can reach out to within your org to get those skill sets if they're not on your team already.

Wendi Whitmore

executive
#32

Right. No doubt about that. So sticking with some of your latter comments about this organized crime, right, what are some of the trends that you're seeing today in stores? Or anything new that has come up in the last, say, 6 months that has caught you by surprise?

Nicole Beckwith

attendee
#33

So I would say, obviously, the theft in the stores is a big one more Diane was talking about it.

Wendi Whitmore

executive
#34

You mean physical theft, right?

Nicole Beckwith

attendee
#35

Physical theft, correct. We were talking about it earlier. We're seeing just different pieces of store. For Kroger, it's the diapers, the Formula, the laundry detergent, alcohol. And we're starting to have to put some of those behind the counter or you transition to a lock-proof system. Diane was sharing how they do that as well. And it's unfortunate, but it's the reality of where we live today. And so how do we, again going back to the customer experience, make sure that we are protecting the bottom dollar with the company, but also not making it a bad experience in-store for our customers. So yes.

Carrie Tharp

attendee
#36

And, I think, this is one of those areas that NRF is also thinking about. So how do you apply vision and data looking at these problems. So using vision to start understanding kind of common swipe motions, how they're going after these. And so in the past, a lot of times, most retailers have a policy not to intervene. It's a safety issue for your associates. There's always somebody that wants to step in and be a hero and then you hear on the news, there's some tragic situation at retail. And so part of the challenge is a lot of times what they're stealing in an individual case is not going to be a felony. And so how do we apply data and start using vision to look at, how do we aggregate things that are happening, so it becomes a felony faster. So this is not to say we're at an end solution, but it's starting to use the technology capabilities to help retail combat some of these issues because there's certainly no sign that this is going to abate and get easier. So you're seeing kind of more crews and efforts and things that I think just in the last couple of years that we weren't dealing with as much 10 years ago. So I'm excited to see how technology can start to chip away at that element and hopefully make it a little bit easier for retail to be operating. I think it's heartbreaking from an industry perspective as you hear about store closures and where retail just can't operate in certain environments. And so how do we point technology at those problems and get to a solution faster?

Diane Brown

attendee
#37

So, I think, there's one way where AI has really -- is going to be able to help us a lot. So we actually have a bot management solution and our bot management solution was able to detect that we had some bad actors out there scanning for a very expensive hair dryer, I won't call it out by name. And they were scanning our inventories trying to find out where they were. And we were able to discern with this company's help that -- which stores they are going to go steal the products from. And this store was able to go pull those products off the shelf and prevent that loss. So here's another way that the intelligence that we get and the information that we receive in IT helped loss prevention. We're like, we're lockstep with our fraud teams because usually, there's just commonalities between the bad actors. But that -- I think that is what, from a technology -- from an IT security perspective, that's what we're looking for our vendors to help us with, is that's how you can use AI. Start taking -- you have that data, you can see what people are doing, take that data and then turn your mindset a little bit because you're about -- you're saying, okay, I'm just looking for bad actors doing x. Well, you actually have so much your point of the data out there, take that data and see what else you can do with it because it was for this company, it was actually an employee challenge. They bring all their employees together once a year, and they gave them a challenge, and they said, what else can we do with this data that we have? And they're like -- and so they sat in a room like all day long, and these engineers came up with this idea. Well, why don't we start looking for other trends? And not just think about threat, threat, threat, IOC, IOC, but look at all that data. And I think from a value perspective, I think that's where we really see a lot of help as an organization is, we can't do that ourselves. I mean, I can train somebody, but then I don't need your tools. It's like so -- but we -- and we don't have staff big enough for all that. And that's where I think we become very dependent on making sure companies like Palo and Google, that are out there always doing research. I love when people show us how much they spend in R&D. That just means you're investing in it and you're listening to us and you're making changes in your products because we need help. Organized crime, as Nicole and I were talking about, we put in those cases, but we have fragrance, she has alcohol, we have fragrance, they'll break open the cases. I mean they'll come in there with a hammer because they come in quarter to 9 at night when you close and they'll break the cases open. And it's like, what else do you do? I mean at some point, like you said besides close your stores. You start closing your -- the State of California is not going to have a single store left pretty soon because of they have such threat rate out and there's the organized crime in California is just amazing. So -- right?

Wendi Whitmore

executive
#38

Well, Diane, I think you bring up such a great point and something that's so difficult for the cybersecurity industry in general, which is kind of quantifying the actual impact that we have as security professionals to the bottom line. And so I love the story that you highlighted of, hey, our teams identified that this theft was potentially about to happen and these stores were targeted and able to remove product, right, in order -- in advance to prevent that. We have a few minutes left, and I'd love to open the floor to the audience to ask a couple of questions because we've got such a great panel of experience here. So yes, sir, we do have mic runners, but while we're waiting for them, may be you can shout out your question and I'll repeat it.

Unknown Attendee

attendee
#39

Yes. My name is [indiscernible].

Wendi Whitmore

executive
#40

Yes. So maybe, Carrie, I'll turn that to you first. So for anyone who didn't hear, the question was about just an ever-changing landscape in terms of new technologies, and is there a framework that maybe you're using in your organizations to help identify what's next, what you're taking into practice and how you're dealing with that?

Carrie Tharp

attendee
#41

Yes. I'd actually love to throw that to Nicole and Diane first because I think as kind of buyers, your framework is most important, and then I'll just add some thoughts.

Nicole Beckwith

attendee
#42

Yes. So for me, particularly, if I'm looking at a new product and solution, it is what is the value to me. So there are a whole host of new solutions out there. But what is it doing differently than what I currently have in place because if I have to spend the time in the engineering personnel on the back end to implement that tool. How do I do that and then also show value to that tool? And so for me, it has to have that plus add that bonus on the back end, once we implement it how is it going to help solve something that we haven't seen before or a gap that we haven't previously identified.

Diane Brown

attendee
#43

And also the other point to me on that one is we're looking for a multipurpose tool. That Swiss Army Knife is always I want. But I -- it's really hard when a vendor comes and they sell you one tiny piece of it, because to me it's like they're not looking at the big picture because there's more to security than just that one small piece. There is more to anything in retail. And one of the things that we're always looking for, like I said, how they can bring that extra value to the organization. And that's why I love when with the Palos and the Googles, they're always looking at companies. They're always bringing in new companies that they can help us support them. And for me especially with remote workers that is the toughest thing that we have right now as remote workers. And during our -- during COVID, we actually switched, we put in an EDR product. And that EDR does so much for us. And I didn't realize going away from a simple, like, antivirus application that was all based on signatures, go into a behavioral analysis tool could help us so much. It was just amazing. And then they continue to add little pieces to their product that you don't even know until they're like, "Oh, by the way, you can do this now." And you're like, "Oh my gosh." If you're doing an investigation on somebody, it's like, Oh yes, we can show you their whole Internet history now like, you're an EDR tool. And they're like, Yes, but they can do it now. And that's what I -- we're constantly looking for. I always tell vendors and like, if you want to sell something to me, question you should be asking is, how do you make my life easier, like Nicole was saying, if you're not going to bring value and make my life easier, I'm not interested. And if my team is going to spend 6 months rolling out your product, I don't want to do that. I don't have 6 months' worth of time to do things. So that's kind of the approach that we take.

Carrie Tharp

attendee
#44

So then I would just add really quickly on that. In the context of generative, it matters how big the corpus of information is. And so we actually lecture all the time that a bigger model is not always better, depending on the topic. But when it comes to security, it is. So Chronicle is something we've built as an example. It was built to protect Google and so can handle anything at scale and looking across all these threats. So really understanding that. And then we haven't really touched on one of the dynamics of the retail. A lot of folks are diversifying their businesses. So a lot of you have kind of banking or credit cards involved, health care embedded into kind of your value proposition in grocery. And so you're only as secure as your least secure element. And so making sure when you're looking at any of these tools, it is the -- what have you done for me lately, you show me the money type of response. But also making sure that it can handle a very complex e-com stack, martech stack and understand the different dynamics you may be introducing from the architecture of the stack itself. So really looking at -- point solutions often can be very high performance and you can get really good measures, but sometimes not always as good as looking across the whole ecosystem. So just kind of looking at the makeup of your organization and stack.

Wendi Whitmore

executive
#45

All right. Yes, one more question. Thank you.

Hope King

attendee
#46

Hope King from Axios. Just awesome topic and just awesome that you're all women just have to say that. It's really cool. I wanted to be here to hear you guys. I'm sorry, I came in a little bit late. So would it be possible just to maybe go through some of the trends of where these cyberattacks are coming from maybe in the last couple of years? And then specifically, I think you mentioned at Kroger that employees were sort of a problem when it comes to theft. Is that right? Did I hear that right? Or I'm hearing from others that maybe employees are part of the shrink issue. So those 2 questions.

Wendi Whitmore

executive
#47

Right. Perhaps, Nicole, should we start with you?

Nicole Beckwith

attendee
#48

Sure. So I'll tackle that first. No, I was not meaning to say that employees were part of the problem. I mean, it certainly is a possibility, right? So there's always that. But no, that's not the trend that we're seeing. For your other question, we're really seeing it across the board. So one of the things that we like to do is do that historical correlation and really understand where the attacks are coming from. And although I don't like to specifically say it's probably better topic for you, Wendi, and what you're seeing across all the landscape, but we do see definitely targeted threats from specific countries, from specific threat actors.

Wendi Whitmore

executive
#49

Yes. I'm happy to take that one. So I think I would categorize it in 3 ways, speed, scale and sophistication. So we're seeing increased speed in particularly the effort. So widespread vulnerabilities being now the #1 initial infection vector, which is very different than social engineering, which -- spearfishing, which has been for decades now, right? So with that then comes increased speed to like [ definition ]. So if we're talking about a ransomware attack or we're talking about data exfiltration, it's oftentimes now within hours instead of days or weeks or months. In many of these cases, I think scale really speaks to the widespread use of vulnerabilities that we see leveraged, right? So even -- it's not just nation-state actors, it's often now cyber criminals who are widespread using, like we look at MOVEit, 3CX, any of the major vulnerabilities that were exploited over the past year, and we're continuing to see that. And then on the sophistication side, it's not so much just the security teams, right? Now we're talking about help desk who need to be really well educated on how to effectively combat identity verification challenges. We're seeing these attackers specifically in the cyber criminal space, really have an understanding of business-to-business relationship. So how an Ulta or a Kroger or Google may work with their vendors who have access to certain types of systems and credentials within their environment, how they onboard those organizations, how they offer them and specifically looking for vulnerable windows within those time frames to be able to take advantage of those types of attacks. So within the retail space, and I think you add on the complexity of the actual physical attacks to stores, the need for consumers to have access to their data and be able to conduct transactions seamlessly, whether it's on the online platforms or the physical space as well. So just a huge amount of added complexity, I think, within the retail landscape. And then you're all managing the challenges of what it's like to run an organization internally and make sure all your employees accessing corporate devices and in store and other locations, right, are trying to keep all of those transactions secure at all times. So that said, we are at time. I want to thank you to everyone who joined us today. Certainly, thank you to our panelists who have provided such amazing insights into how your organizations are running and the retail landscape. So thank you, everyone.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Palo Alto Networks, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Palo Alto Networks, Inc. earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.