Paul Lepage
Analyst · RBC Capital Markets. Your question please
Thanks Anuj and good morning, everyone. I'd like to take some time today to talk about our approach in managing cybersecurity risk, provide you with an update on the incident response in our dealer management software and technology services operation, CDK Global and share some thoughts on how we're strengthening our protocols across all our operating companies. Managing cybersecurity is and always will be part of our sound business practices and good governance framework for all our operations. This starts with the right culture. We've always had a safety-first mindset across all of our operations. This mindset increasingly encompasses an equal emphasis based on physical safety and information security. Cybersecurity reviews are a key part of diligence prior to acquiring a business. And this extends to the management of our portfolio of companies. Post acquisition, we established an oversight committee to ensure adherence to cybersecurity programs and standards, including the National Institute of Standards and Technology or NIST framework to guide how our operations manage, respond and reduce cybersecurity risk. We also engage leading third-party industry experts to assess the effectiveness of foundational cybersecurity controls, which includes scan for potential vulnerabilities, ongoing network monitoring and the review of overall threat detection capabilities. Where it's needed we support our operating companies with technical tools, processes and resources to address the potential gaps and to assist in remediation activity. However, the frequency and sophistication of cyber incidents globally has intensified. To put this in perspective, more than 2000 cybersecurity incidents are reported daily. And last year alone, cyber incidents affected over 20% of the S&P 500 companies. As we disclosed, CDK Global was impacted by a cyber incident during the quarter. CDK as a reminder is a leading provider of cloud-based software to automotive dealerships. It's a trusted partner to its customers, providing mission-critical services that enable automotive dealers to run their business more efficiently. We privatized the business two years ago and have been focused on the execution of our value creation plan, which includes investing approximately $500 million in product and technology, R&D, infrastructure and modernization of the software stack. Immediately after detecting unauthorized activity on its network CDK mobilized its incident response team and shut down its systems to contain the threat. The cyber attack was orchestrated by a highly sophisticated threat actor that infiltrated CDK's IT infrastructure. With the assistance of leading third-party experts, CDK moved to quickly begin restoring its systems with a focus on putting its customers first, limiting the disruption to customer operations and remediating the impact as quickly as possible. Within two weeks, CDK was able to bring substantially all its dealer customers back on to its core dealer management system. And within three weeks the business has restored substantially all its major applications and third-party system integrations. CDK continues to be focused on being a best-in-class partner to its customers. This includes supporting them as their businesses get back to normal operations, providing one-time billing credits and rebuilding trust. As a market leader, the business is continuing to invest in its systems and technology to protect against evolving cyber threats. It's also working to support the industry including making free tools and resources available for any dealer to help them assess their security frameworks, evaluate risk and enhance employee cybersecurity training. On behalf of Brookfield, we want to thank all CDK customers and partners for their support and patience during the outage. With that, I'd like to turn the call over to Jaspreet to review our financial results.