Qualys CEO on AI, Cyber Risk and Why You Can’t Fix Everything
Sumedh Thakar, President and CEO of Qualys, has stopped pretending that any amount of spending can guarantee safety.
President, Chief Executive Officer & Director, Qualys
Search every verified Sumedh Thakar interview, podcast appearance, and on-the-record quote — each transcript cross-checked by AI and human review to confirm speaker identity. Sumedh Thakar, CEO of Qualys, has been discussing the evolution of vulnerability management and the role of autonomous remediation in cybersecurity. In a June 2026 interview, he argued that the speed of attacks has compressed response times, making it necessary for CISOs to balance operational risk with security risk. He said that metrics such as "average window of exposure" (AWE) and "window of weaponization" (WOW) are becoming more important than traditional mean-time-to-respond figures. Thakar also stated that automation in remediation is already in use, noting that Qualys customers have deployed millions of patches autonomously with few outages. In a separate appearance, Thakar addressed the idea that organizations cannot "patch their way through" threats, asserting that no single security control—including patching, zero trust, or firewalls—can solve the problem alone. He emphasized the importance of defense in depth and hyper-prioritization, citing Qualys data that less than 1% of vulnerabilities are exploitable. Thakar also spoke about the potential for AI to eliminate zero-day vulnerabilities if developers can find exploits before attackers do. Outside of cybersecurity, Thakar participated in a fireside chat with Major League Cricket players, announcing that Qualys would continue sponsoring the SF Unicorns team for two more years and expressing enthusiasm for promoting cricket in the United States.
“Cyber security is a risk management exercise for the company at the end of the day and so we don't have unlimited budgets we can't fix everything we can't go after everything. And so this was not as big of a thought process when we had lesser infrastructure just a few thousand servers and people had 90 days to fix beca...”
“The most important thing for success of AI is actually the humans in your organization the best and your smartest people are going to get the best value out of the use of AI in any field whether it's your cyber or finance or any of those things and so I think it is very important that we continue to focus on making sur...”
“You cannot patch your way through Mythos but you cannot zero trust your way out of mythos. You cannot DDR your way out of Mythos. You cannot firewall your way out of Mythos. The reality is that your defense in depth and the layers of defense and having them working really well have never been more important than now.”
“Some form of autonomous remediation as a roadmap is absolutely essential today to make sure that we are giving the confidence to the business that there is a plan in place that will allow us to respond to autonomous AI based attacks with autonomous capabilities in the different security controls that we have.”
“In theory, if every software development shop had access to a model like this, whether it's open source or one of the commercial models, they will be able to find all of their vulnerabilities and exploits before the attackers do. Which means in theory you may not have any more zero day vulnerabilities because the attac...”
“Autonomous remediation is not the future. Autonomous remediation is already here and the forward-looking organizations today are already deploying millions and millions of patches autonomously with almost no outages.”
“Just about 5 years ago, we had 60 days to patch your vulnerabilities after a patch came out, you had exploitation was taking quite a bit of time. And I think more recently it's now gone down to um you know it was negative 1 day in 2024 negative 7 days uh which just means on an average for the exploitable vulnerabilitie...”
“88% of the weaponized vulnerabilities were patched much slower than what they were exploited. But what is even more interesting is that even in the cases where you have over 70 days of a head start between a vulnerability being announced and a patch being available to the exploitation happening, people are still taking...”
“Less than 1% of all the vulnerabilities in the in your environment are actually exploitable. And when we ran a bunch of our and Shalesh will talk about this today, the ability for Qualus to actually uh send a payload and exploit the vulnerability safely in your environment... We found that less than 20% of those vulner...”
“Cyber security is a risk management exercise at the end of the day. It is 7 to 8% of your IT overall budget and you're spending that money to reduce the risk of a monetary loss at the end of the day. So I'm not I know some of you took picture of that first slide where we had like 6.5 times increase in the CVEes. Hopefu...”
“40 million of those 150 million are already autonomous patches with zero human touch being used. Customers are saying if it's a laptop and it's a Chrome vulnerability, don't even scan for it. Just automatically apply an update. So the customer is able to tell their board that on our employee endpoints we will never hav...”
“We became one of the first companies in cybersecurity to actually sponsor a cricket team. We were one of the first ones to have a booth with a cricket experience at the Black Hat cybersecurity conference in Las Vegas, which was really well received because looking to promote that game in the US, where I think having co...”
“We're constantly being attacked. And that's one of the key things in our field, and there is a lot of noise all the time. And you cannot fix everything. And so, that was really the conversation this morning was about so many things coming at you, you got to know when to leave something and when to really fix the thing...”
“The key is gather all the information, then use it how you feel is best used for your team on the field. It still a game of decision-making out in the middle because you said the conditions can change, but the amount of data that you require now and it's not just data on the the personnel that you're going to be playin...”
“If you get the wrong characters and the right information, I the right data, it's not going to work. If you get the right data and the right characters, that's the perfect combination. And you know, when you're picking teams and you're picking groups of players to play for you, you've you've got to make sure fundamenta...”
Sumedh Thakar, President and CEO of Qualys, has stopped pretending that any amount of spending can guarantee safety.
Go behind the scenes at Qualys headquarters as CEO Sumedh Thakar sits down with SF Unicorns stars Ravi Ashwin, Matt Short, and Sanjay Krishnamurthi for a candid conversation about Major League Cricket, leadership, teamwork, AI, innovation, and the future of cricket in the United States. From Ashwin's journey to international cricket, to Matt Short's experience captaining the Unicorns, to Sanjay's rise with USA Cricket, this discussion explores what it takes to compete at the highest level while helping grow one of the world's fastest-growing sports in America. Whether you're a cricket fan, sp…
Can organizations patch their way through AI-powered cyber threats? Or is autonomous remediation the future of cybersecurity?
Qualys CEO Sumedh Thakar joined Stephen Pritchard for The Stack to discuss how patch management is evolving as vulnerability disclosures surge.
Cyber risk is changing faster than most organizations can respond. At ROCon EMEA, Sumedh Thakar, President and CEO of Qualys, outlines a new approach to cyber risk management in the age of AI—where vulnerabilities are increasing, exploitation is accelerating, and traditional remediation models are no longer keeping pace. As AI-driven discovery and exploit development compress timelines, the gap between detection and remediation continues to widen. In this session, Sumedh breaks down why measuring mean time to remediate is no longer enough—and why organizations must instead focus on reducing…
Stumped by cyber risk? You’re not alone. At ROCon EMEA, Sumedh Thakar, CEO of Qualys, sits down with Michael Vaughan—former England cricket captain and Ashes-winning leader—for a fireside conversation on decision-making, leadership, and navigating uncertainty at the highest level. From reading the field to anticipating threats, Vaughan shares how instincts built on the pitch translate into modern cybersecurity leadership. Together, they explore what it takes to prioritize effectively, respond under pressure, and reduce risk to the business in an increasingly complex landscape. The conversat…
Sumedh Thakar, President and CEO of Qualys joins Dave Bittner on the CyberWire Daily podcast for a sponsored Industry Voices at the RSAC Conference 2026. He explains how attackers are outpacing traditional patching timelines with exploits emerging before fixes exist, and why organizations must shift to AI-driven, autonomous remediation and risk prioritization to focus on truly exploitable threats and close the growing gap between detection and response. Host: Dave Bittner ( / dave-bittner-27231a4 ) Guest: Sumedh Thakar ( / sumedhthakar ) Qualys (https://www.qualys.com/) __________ Want…
Your attackers don't wait — so why should your patches?” At ROCon25 Houston, Sumedh Thakar, President & CEO of Qualys, ...
You can't fix everything — but you can fix what matters.” In this clip from ROCon25 Houston, Sumedh Thakar, President & CEO of ...
Qualys CEO Sumedh Thakar joins me to unpack what cyber risk management really looks like when budgets are tight, signals are ...
Sign in to search the full transcript archive, filter by topic, and access every quote from Sumedh Thakar.
The summary and quote tags on this profile are produced with AI assistance from verified, first-person interview transcripts, then checked by our team to confirm the speaker's identity and the accuracy of every quote. See how we verify →