Shobie Ramakrishnan22:12
I think on the—cybersecurity, it would be ridiculous for any company not to be prioritizing that. And you know, as I look at any enterprise risk assessment that comes up, whether you're on a board or you're looking at it as a company, it goes to the right and increasing. That's just the nature of it. I think the principle that we try to follow is really thinking about what does cyber defense mean for us. What are the threat vectors that we are most worried about? We have probably some common threat vectors like everybody else—the human vector, the ransomware, et cetera—which everybody in the world is going to be impacted by. And then there are probably things that are unique to, for example, Diego's industry and mine. For us, operating technology resilience is super important, versus probably not so much for a software technology company or somebody who doesn't have that. So I think just being really thoughtful about what are the threat vectors that you care about, and holding yourself accountable to improve not just the maturity—but one of the easy distractions is 'oh I'm here on NIST and I'm going here on NIST'—but really the controls effectiveness. So you've deployed all these controls, how effective are they truly? And then having the courage to constantly red team yourself and test. Not just talk about it, but really test to see where your strengths are. I really do want to be careful about getting too confident on this. This is really hard stuff, and none of us can be absolutely sure that we've done everything right. But being very thoughtful and intentional about the cool stuff but also the traditional things like good BCPs and good backups, like the things that Diego just talked about, is really important. And we are again back to our principles about keeping it real. We spend a lot of time thinking about it, we invest responsibly, hold ourselves accountable with external measurements, and then really make sure also that we're building the capabilities up internally and in our partners to be ready for what's coming, not just what's here already. And one of the wonderful things about cybersecurity is you're not alone. There's so many places to go for collective defense and learning from each other. And I like to tell my team when the Uber incident happened or the Microsoft incident happened, just use them to test our defenses—it's the same attack patterns that we have to defend against. So really the ability to learn from the collective consciousness is super important, because that's the only way we can take on the adversaries. In terms of other defense mechanisms, I think everyone does this as well, but thinking about AI very responsibly. We've done AI for a while, especially using AI in drug discovery including generative AI, large—we have custom large language models, et cetera—because we've invested in scientific innovation for quite a bit. But all along we've had AI policy. We established an AI policy and ethics organization five years ago, and we really, once we decided that we are scaling AI across the company, we have put an AI policy in place, we've set up an AI governance council. And probably the interesting thing that I've come to realize as I set up the AI governance council for us is to recognize how important it is to not have AI become its own thing in the company. Whether it's defense or offense or whatever, it needs to feed into existing risk mechanisms, risk tracking mechanisms, go to existing risk boards. So thereby you ensure that all your risk management frameworks are thinking about this additional risk. If you think about patient safety, what is the additional patient safety risk from adoption of AI? If you're already thinking about procurement risk, what's the additional risk? So I think leveraging the existing defense of the company and recruiting it to protect yourself against this new technology we're adopting has been a very interesting learning, and it would not have been intuitive, because everybody wants to set up a separate council and publish papers and all of that. Like we are really activating the defenses of the company, but where we need we also put expertise in. So those would be the two things I'll share. I think supply chain—Diego talked about quite a bit of it.