Transcription
Hello and welcome to UC today. My name is Kieran Develin and today's session we'll be exploring how AI features are being activated inside communications platforms faster than governance models can keep up. This means risk increases when controls differ across different UC and CX tools or when different teams own different parts of the stack. Naturally, leaders need a practical approach to standardizing policy, monitoring, and accountability. And that is precisely what we're going to tackle here today.
I'm delighted to be joined by William Rubio, chief revenue officer at Cultur, and Ela Papoga, vice president and senior fellow at Frost and Sullivan. Ela and William, thanks for joining us.
>> Thanks for having us, Kieran.
>> Yes, thank you very much, Kieran. Looking forward to the session.
Before we dive into the session, why don't you tell us a little about yourselves and your career journeys? William, we'll start with yourself.
>> Yep. So, uh, chief revenue officer at Call Tower. Been, uh, with Call Tower, actually almost about 13 years to the day. That's funny enough. I think somebody reminded me the other day that it was my anniversary, but uh, been in the industry for about 30, uh, plus years overall. And, you know, at Call Tower, we're a pretty unique organization. We are a cloud communication service provider and uh we work pretty much everything what we consider to be best and breed both on the UC and also on the contact center side working with the likes of Microsoft, Cisco, Zoom, uh 59, Genesis um and a few others as well. Uh we do that roughly in about 80 different countries that we're able to go ahead and support. Uh so a lot of different challenges that we come up with with compliancy and uh you know and also sovereignty, data sovereignty and so forth. But uh definitely looking forward to the uh session today.
>> Um I'm Ela Pupova. Um as um you introduced me, I'm the uh VP of connected work research at Frosten Sullivan. I've been with the uh with the company and in the industry for about 26 years. I cover primarily cloud communications and collaboration solutions. Um more specifically I've been focusing on the telefan side the UK um kind of part of the stack. I uh monitor different trends and I advise both the vendor side and the um end user organizations on best practices in delivering or deploying cloud communications and collaboration. Uh one of the key trends in the industry is the um integration of unified communications with contact center and as we call it CX solutions today. So I dabble in that as well. Uh and I work closely with individuals who um specialize in in CX. Certainly um AI is one of the key topics uh we look at today. AI adoption and the related risks. So I look forward to this conversation.
>> Absolutely. And let's start with precisely that point, Ela, because we are seeing AI features lit up inside UC spaces and contact centers faster than most IT teams can write policies for them. From your vantage point, when organizations just turn on these capabilities without a concrete map, what are the biggest blind spots, the hidden risks that catch leaders offguard?
Well, the there are plenty um obviously um you know AI is penetrating organizations through a plethora of different solutions and uh although the majority of those get approved by it, some of those are coming through you know personal use and um that certainly creates all the typical challenges of you know shadow IT um where you you lack any governance or compliance um tools or policies to um uh monitor um usage and um and and you know prevent vulnerabilities. But even um when it approves the adoption of these solutions um part of the challenge is that um IT departments themselves don't always have the AI skill sets that are required to properly manage these uh technologies and that's something that actually we see in our surveys of IT decision makers who uh report that you know um that they're struggling to keep up with technology development especially uh AI advancements. So um that is one of the challenges. Uh the other challenge is obviously that AI is penetrating organizations through multi- vendor solutions that um are you know have their own different architectures and vulnerabilities and monitoring tools and administration um uh tools and organizations are struggling to kind of manage each of those individually and make sure that once they're um part of the same environment, you know, the data flows and the uh and generally the um interop across these platforms, you know, uh supports a unified, you know, governance and and unified policies across all of those solutions. So there are different uh levels of of vulnerabilities. Um and um I say I'd say that less than 20% of organizations are actually prepared to deal with those from you know a policy skill set and uh overall preparedness point of view.
>> and and William I think Ela makes a really pertinent point especially about the the multi- vendor state because I think that's very relevant to today's discussion because most organizations don't just have one platform they have a messy multi to vendor state that spans UC, CCast, recording, analytics, and increasingly AI. How does this platform sprawl multiply the compliance risks we've just talked about? And why do traditional governance models break down in this environment?
>> Yeah, I think first and foremost, when you look at and and Ela brought up some really good points. I think first and foremost, Karen, when you look at it, is is the technology there? And I think that the the answer is yes, right? Right. I mean I think from from a technology standpoint it's really there to be deployed. The tech is ready. The problem is that we also have a lot of what we call uh real world friction you know to consider within the organizations. Uh overall I think first you have the organizational challenge that you have a lot of companies that just don't flip a switch from one day to the other and say we're just adding AI tomorrow. Right? There's a lot of um bad habits that are out there uh that you have to deal with that people are saying well you know we have we've done it the way like this for the past x amount of years why do we have to go ahead and change so you behavior that becomes an issue then you also got the compliance issue right that Yan mentioned earlier in a lot of cases with you know compliance it's not really a matter of oh let's get ahead of it it's really more about the fact of if the compliance agencies are telling us to do x y and z we're going to get there to x y and So, they're always kind of playing catch-up. No one's really being proactive because they just don't know what really the compliance uh agencies are really going to throw out to them, especially when you're dealing in multiple different countries and multi multiple different regions uh of the world that you have to deal with there. And then like Ela mentioned, I think when you start talking about the IT organizations themselves internally, there's a lot of education that has to go on there because of the simple fact that uh they just don't understand in some cases the needs of the business units or the availability of the products and features that uh a lot of these platforms provide. And here, you know, here at Call Tower, that's always a big challenge because we do work with multiple different platforms and we do that on purpose because we realize that it's not a one-sizefits-all. We understand that a lot of organizations uh in a lot of cases are using multiple different platforms depending on the business unit needs. So we try to go ahead and work with them and educate them to make sure that they're driving the right business outcomes that they're looking for for the different business units uh themselves overall. So it is kind of a a give and take back and forth but uh it's definitely a challenge not just working internally within the organizations and getting buyin uh from the organizations and the different uh business units but also externally and understanding and educating yourself as to what's going to be the best platforms uh that we could work with today because most customers as we're seeing are not working with one specific platform. In a lot of cases they're working in a hybrid environment and they're working with multiple different platforms.
>> Um, let's move on to solutions. Um, well, I'd like to pick the brains of both of you, but we we'll start with yourself, Ela. What does a good control actually look like in this multiplatform reality? And then afterwards, William, how do you implement those controls like identity, access, retention without completely suffocating the innovation that AI promises? But, Elco, we'll start with you.
I will leave all the uh technical um you know discussion to to William. Um I will just say that it really starts with the organizational preparedness on a much on a a broader front so to say. I talked a lot about AI skills um and and the lack thereof. I think uh it it does begin with the organization first of all building those skills internally. uh only when you have the right type of um you know skill sets within the IT department can you begin to build the frameworks the policies and can you apply those to the selection of the solutions and the vendors that you're dealing with um and and then um ensure that you're deploying your AI powered communication solutions securely safely compliantly and so on um and once you know those solutions are in place. I cannot um emphasize enough how important it is to actually um train the act the end users because we're dealing with a lot of enduser issues in the adoption of these solutions because they kind of break the rules. They expose the organization to you know misuse of the AI tools and and therefore you know open it up to um to to to vulnerabilities. But um one of the uh issues that organizations u are looking to to uh kind of resolve with the help of their providers is obviously to um to get the support in integrating the different systems that they're adopting in a manner that allows this you know overarching control um in terms of identity D access and and um in terms of um solution management and administration um and sometimes this is really you know the burden is on the provider in in effect it's it it should always be on the provider to deliver these capabilities um to to guide the organization um toward properly you know architect arcted properly integrated solutions and to deliver um the administration capabilities that run across different solutions. Um and when I say administration, I mean those you know security and compliance controls. Um and uh I would say that few providers today are in a position to to deliver those and cold tower has been on my radar as one of the few companies that uh actually have the wherewithal to to uh you know provide this to to organizations.
>> So I I I think look Ela hit it hit it spot on right. I think it's um first and foremost it's really a balancing act between the providers such as such as somebody like call tower and the actual organization. Um we our platforms that we work with are compliant right but we can't make you compliant and I think that that's the first piece of the education that a customer has to realize that you just can't buy a platform off the shelf and think that it's going to make you compliant. you need to make sure that you have your internal controls uh within the organization so that you don't get the uh the bad actors going ahead and maybe leveraging J GPT or something like that that is exposing their organizations their computers to really have everything from a data standpoint be transferred to be shared that could be used externally uh within the organization and we run into this ourselves as struggles as our organization right I mean there's certain uh blacklisted websites that we don't allow our employees to go to and everything because we don't want that shadow uh it but I think first and foremost it's really about that education with the employees and making sure that they understand the vulnerability of when they go when they go outside of what is their daily job or what they're supposed to be using as far as their tools to make sure that they're using uh their tools correctly and and compliance is not something that it's just really a check the box right compliance is something that yes you have to strive to an organization to get to, but and then there is that maintenance and that monthly compliance uh check-ins that you have to do. So, you're constantly, you know, in a state of making sure that you are compliant. It's not something that every January you just look at at the beginning of the year and say, "Okay, we got to make sure we're compliant again, right? It's always a dynamic uh type of of item that's going on." And from our standpoint uh you know we work with those uh platforms that we see that are best in breed best-in-class on a global on a global level just because of the simple fact that there is different compliance regulatory issues from uh region to region and organizations have to make sure that they understand what those are and how an organization like call tower could help them leveraging uh some of those platforms that uh we are working with overall and Again, that's why we kind of stick to those best and breed. So, it is definitely a challenge and it is an education. Uh you got to get first and foremost the the buyin from the business leaders. You definitely always have it from the IT organization because that's a big uh a big stake in their ground that they have that they have to make sure that they have to do that. But also, you want to get the different business owners to go ahead and do that, right? And I mean everybody from marketing to sales to engineering to support. I mean it goes across the organization making sure that you're working neck andneck with your security team understanding where the vulnerabilities might be. You don't have an exposure that could really down a company. Right? We've seen that before with some organizations that don't have those controls in place and has really gone ahead and and really been a detriment to the organization. So, it's uh it's not something that you just do once, forget about it, and come back next year. It's something that is just in in constant state of flux that you have to make sure that you're educating your users and making sure that from an IT organization, you're working with your platform vendors uh to go ahead and make sure that they're continuing to be compliant and up to speed on on what's needed for the organization.
And and I wonder if we can dig into this a little bit more, William, and sticking with yourself because cultur naturally champions a accountable partner model over maybe the more fragmented best of breed approach. Walk us through a day after deployment, how does having a holistic portfolio and expert support actually prevent governance drift and keep these controls standardized over time?
>> Yeah, I think and and and that's you kind of hit it on the head, right? That's really the challenge when you're dealing with multiple different platforms that are integrating together. Um, it also opens up the opportunity that yes, you're going to maybe get the requirements that the business needs, but also how could you ensure that you're going to be compliant in the fact that you're integrating uh a lot of the platforms. And that's one of the things that we do here at call tower is that we make sure that we are working with the likes of these platforms that uh are been battle tested you know overall and then we put in even our own governance uh as well on top of it to make sure that we're helping our organizations on making sure that they are compliant but also making sure that we are minimizing uh the risk that they have. We just recently uh launched a spam filtering, you know, just on on the calling side, which is kind of more I guess basic is probably not the right word, but uh just really kind of one of the first steps in taking which is a spam filtering with a partnership that we did with Mutari. And that's something that we're doing on a global level because we want to make sure that the spam calls uh are not getting through and making sure that the customer scores from a network standpoint are not being really hit. meaning that if you are making a lot of outbound calls that these are legitimate outbound calls or if you're receiving a lot of inbound calls that you're making sure that these are calls coming in and getting to the right end users and you're kind of avoiding the whole spam thing and those are little bits and pieces that you want to make sure that are all part of the puzzle that you want to make sure and that you bring in. But it really goes down Karen again to that education piece, right? What are the the compliance regulations that you need for your industry and they change right overall? I mean these large platforms that we're talking about whether it's it's Microsoft or Cisco or Genesis or 59 uh or even Zoom and then even some of the uh smaller apps that we work with like a Parloa or a Cestech uh or working with a SMARS or something like like that or even Toll Ring. I mean these are all different vendors that we work with. It's really making sure on how they could integrate together, how you could go ahead and you could leverage those. But these platforms since they are platformwide, they're not really vertical. You know, they don't go into specific industries. They're more horizontal uh type of platforms overall because they work pretty much in every uh in every different type of industry overall. So, it's really understanding what the compliance governance is that you have to have for your organization. how call tower and how these core platforms understand those and how we could work together to leverage them to make sure that you are compliant today or getting to compliancy and then also ongoing how you could continue to do that on a month-to-month basis.
And to wrap up, let's let's arm our tech buyers. If an IT or CX leader is sitting in a procurement meeting tomorrow evaluating a new AI enabled tool, what is the one hard question they need to ask the vendor about compliance and ongoing support that they probably aren't asking today? Elco, we'll start with yourself and then William, feel free to come in after.
Thank you.
>> That's a tough one, Kieran. Um, I wasn't prepared to to to uh formulate just one single question. Um I don't think it's it's uh that that the issue is so complex. I don't think there's one question that can cover it all. Um I I strongly believe it's actually a matter of a of a deep conversation. um you need to to first uh you know gauge your provider's um understanding of of your specific industry because as William pointed out compliance um even security more broadly defined these are not issues that um that mean the same things uh the same thing to different uh industries and different organizations. And um you need to make sure that the service provider you're evaluating uh has a deep understanding of your um industry. Whether that's healthcare or retail or manufacturing um there are very different um expectations. Government is obviously uh one of the trickiest uh verticals to serve. So that's that's where uh part of the conversation needs to happen or at least needs to focus on. Um and then um certainly one other part of the conversation is uh understanding what kind of platforms the service provider is bringing to you. Um again I'm going to piggyback on what William said. The first step is making sure that the platforms themselves are engineered um to be secure and um and support highest levels of governance and and can you know have the recording archiving and other capabilities that perhaps or integrate with those capabilities to ensure um higher levels of compliance. And then the third question in my mind is uh making sure that your service provider has a skill set to manage these platforms again as an integrated you know solution for the organization especially if the organization is looking to adopt more than one or has some of those in its estate and has to um is is adding new solutions and they need to function together again in a secure and compliant manner. So they need to um or organizations need to gauge the capabilities of the provider to um to manage those and manage them over the entire life cycle. Uh not just um at the point of implementation. Um again piggybacking off on what William said, it's not um you know all said and done uh once the solution is um you know deployed and um then you just move on and forget about it. Um technologies are evolving fast and evolving on a regular basis. Uh and with that the their security um setups change as well and you need to be up to date on the skill sets required to um to to manage the those and ensure that they're still um you know aligned with the organization's requirements.
>> Well, that's that's a really hard follow points there.
>> No, that was that was great. you to make it tougher for me. No, I think again you're, you know, you're spot on. If there is one question, like you mentioned, I don't think there's really one question that's going to go ahead and do it. I think it's it's a host of questions, but I'd say first and foremost, you got to ask about what is your technology roadmap, right? You're going to be a partner of mine, you know, hopefully for the next 3 to 10 years. And what does that roadmap look like from a compliance standpoint? Also, what does that look like from a data sovereignty standpoint? Uh overall these are basic questions that in a lot of cases are are not being asked even where does my data resol reside meaning not even just from solveny but who has access to it right is it outside uh are you sock 2 are you ISO compliant right those are just kind of check the boxes that need to be done before you could actually start engaging uh with a lot of these organizations we even ask for penetration testings with a lot of different providers that we work with ourselves when uh we're actually looking at security and looking at moving forward with a vendor and we even have our own security protocols whenever it is that we're bringing uh on a new vendor. So, we do a lot of that vetting out for the customers uh overall, but I think it's without a doubt those first basic questions uh that you do have to ask and and I keep going back to that technology roadmap because I want to make sure that when I'm partnering with somebody, I actually see what they're going to be doing over the next three at least three to five years and that they are going to be a partner uh that I can rely on and see where where they're going overall. So I think that that's first and foremost the the first thing and then the second is from a compliance standpoint how are you compliant across the different regions uh of the world making sure that you do have services if I do happen to have offices and and users across the globe how it is that you could take care and work with my users across the globe because in a lot of cases some of these organizations are more regionalized so you got to make sure that you're asking those those basic questions as well.
Fantastic. Well, I think that's all we've got time for today, but it's been a terrific session as ever with you both. So, thank you Ela and William for being here.
>> Thank you.
>> Yep. Thank you, Carrick.
And if you enjoyed this video, please give us a like and share on social media and we'll see you next time. I've been Kelvin of Today. Thanks for watching.