Back
Sumedh Thakar
President, Chief Executive Officer & Director, QUALYS INC

Cyber Risk Management in the AI Era | Sumedh Thakar (Qualys CEO)

🎥 Apr 30, 2026 📺 Qualys, Inc. ⏱ 65m 👁 7 views
Cyber risk is changing faster than most organizations can respond. At ROCon EMEA, Sumedh Thakar, President and CEO of Qualys, outlines a new approach to cyber risk management in the age of AI—where vulnerabilities are increasing, exploitation is accelerating, and traditional remediation models are no longer keeping pace. As AI-driven discovery and exploit development compress timelines, the gap between detection and remediation continues to widen. In this session, Sumedh breaks down why measuring mean time to remediate is no longer enough—and why organizations must instead focus on reducing...
Watch on YouTube

About Sumedh Thakar

Sumedh Thakar, CEO of Qualys, has been discussing the evolution of vulnerability management and the role of autonomous remediation in cybersecurity. In a June 2026 interview, he argued that the speed of attacks has compressed response times, making it necessary for CISOs to balance operational risk with security risk. He said that metrics such as "average window of exposure" (AWE) and "window of weaponization" (WOW) are becoming more important than traditional mean-time-to-respond figures. Thakar also stated that automation in remediation is already in use, noting that Qualys customers have deployed millions of patches autonomously with few outages. In a separate appearance, Thakar addressed the idea that organizations cannot "patch their way through" threats, asserting that no single security control—including patching, zero trust, or firewalls—can solve the problem alone. He emphasized the importance of defense in depth and hyper-prioritization, citing Qualys data that less than 1% of vulnerabilities are exploitable. Thakar also spoke about the potential for AI to eliminate zero-day vulnerabilities if developers can find exploits before attackers do. Outside of cybersecurity, Thakar participated in a fireside chat with Major League Cricket players, announcing that Qualys would continue sponsoring the SF Unicorns team for two more years and expressing enthusiasm for promoting cricket in the United States.

Source: AI-verified profile updated from Sumedh Thakar's recent appearances. Browse all interviews →

Transcript (46 segments)
M
Moderator0:00
As a defender, I can't help but ask myself the question: with so much coming at us, how do I focus on what's really important? Hopefully throughout the day, we're going to weave an answer to that question. But think about it. With so much going at us, how do we really focus? Our next presenter really doesn't need an introduction, but I will introduce him as well. Our president and CEO, Sumedh Thakar. Sumedh, please welcome on stage.
S
Sumedh Thakar0:34
Oh, I don't need this here. It's my extra protection in case. All right. Well, thank you very much. That was a great talk by Sarah. I think resilience is the most important thing. And I think what really struck me was the three wise monkeys that she presented. And that's the theme of the conference today. So I'm the first one to go on stage and I have two other monkeys following me.
Okay, let's talk about, I guess no conference is complete these days without the conversation of AI. So I think we have to hit that one. But thank you very much for everybody coming. I think we have a lot of people here from outside of UK as well. So good morning for everybody. Sava ciao. I don't know. I tried to do the Greek thing but that didn't really, it was not my thing. I couldn't do it. Okay. So, we have to start our conference with a mandatory FUD. So, any cyber conference cannot start without that.
I think all of us are pretty familiar with the volume of vulnerabilities has been going up like crazy which makes sense because we have just been deploying a lot more software than we ever have and having been a software developer for a long time. I know more software means more bugs. I have done my share of contributing towards bad code and my team encouraged me to take a management job so I could stop coding and that's why we are here today. But I don't think that this is surprising if you don't know the numbers that we have put up here. Doesn't matter because you're feeling it every day. So it's a feeling that matters.
Okay. I think what's changed, I would say a little bit more surprising in some ways and not in other ways is the fact that it's not just the volume of the issues and the vulnerabilities that has been increasing. The time it is taking for them to exploit these issues has been decreasing quite significantly. So just about 5 years ago, we had 60 days to patch your vulnerabilities after a patch came out, exploitation was taking quite a bit of time. And I think more recently it's now gone down to, you know, it was negative 1 day in 2024, negative 7 days, which just means on an average for the exploitable vulnerabilities in that year, more and more of them are getting exploited quicker than patches are being available. And this has definitely changed quite a bit when I joined Qualys 23 years ago, and I've been trying but I couldn't get another job. But we used to have gold star standard customer who would scan once a quarter and then they would give their IT team 90 days to fix everything, right. What has changed is that people are not scanning once every 90 days. Hopefully you're not scanning once every 90 days. But what has not changed is that it is still asking 90 days to fix the issues which is something that we don't have and we cannot afford anymore these days, right. And we love to measure MTR so people will point to MTR which really doesn't mean anything in today's world because the meantime to remediate for 90% of your vulnerabilities might look really good but it's that 1% which you don't have the good MTR is really the question.
Now what we do know is that not every vulnerability is exploitable. In fact, majority of them are not. So trying to focus on MTR of fixing vulnerabilities is not really the future. So as is true with our industry, we have come up with a few new acronyms that we would like to throw out there which is WOW and AWE. So what is the window of weaponization that the attackers are leveraging and what is your average window of exposure for vulnerabilities in that category? At the end of the day that is really the most critical thing. So it's not shock and awe. It's actually you look at your AWE and then you're shocked and then you say WOW.
So what really does matter if you're looking at, you know, not getting too specific into things as an organization in general, if we are at a point where we are generally keeping our AWE, which is our average window of exposure, smaller than the window of weaponization, then we are in a better place. If it's the opposite where the window of weaponization is smaller than the average window of exposure, then we have to mind the gap, right? That's really what it comes down to at the end of the day. And so, that's I think the most important thing at a high level to be focusing on and not the specific counts of vulnerabilities because again, you know, risk is never kind of zero. So you have to be able to figure out which ones matter the most and so we'll talk a little bit about that which is kind of your risk management but at the end of the day the only way you can get your, okay so of this two metrics one is controlled by us and one is not. Well okay maybe WOW is definitely not controlled by us we want the AWE to be controlled by us but it is actually kind of controlled by it right now. So I think that's also true that while you would like to bring the window of exposure down by being able to remediate things quicker and that's really the simplicity of it, right? Is if you can remediate things fast enough and on a proper cadence you're going to be in a good place. So the one we don't control about we don't have to worry about it. The WOW, you know attackers are going to do what they're going to do now. They're decreasing the WOW with AI etc. But we have the ability to control our average window of exposure and that's really what we're going to talk about. Now of course it costs money and that's part of the conversation we're going to have is how do we get that equation correctly. Now it's, you know, generally physics right the WOW is reducing your AWE is changing. So what is the physics of remediation? That physics of remediation is the thing that matters the most which unfortunately is pretty broken right now.
And this was an interesting report our team put out a month ago talking about and you can download this copy so feel free to take a picture of that QR code if you would like a selfie with me that's five quid later. But it really highlights kind of what the challenge that we are seeing in the industry right now where the physics of remediation is pretty broken and I'm going to put a couple excerpts from that report here but I think this generally, you know, we always hear this like ah if you had given me enough advanced notice we wouldn't have this issue and what these numbers highlight is that 88% of the weaponized vulnerabilities were patched much slower than what they were exploited. But what is even more interesting is that even in the cases where you have over 70 days of a head start between a vulnerability being announced and a patch being available to the exploitation happening, people are still taking over 170 days to fix the things that matter the most.
And unfortunately, the devices that are supposed to protect us the most, which is your firewalls, VPNs, routers are the worst performers when it comes to that in terms of patching. So, we have a gap with the physics. We have a head start that we're not really focusing on and our frontline defense is becoming kind of the most challenging thing today.
Now I am so proud we got through seven slides without talking about Mythos. Anybody who has not heard about Mythos here, you might be at the wrong conference. And you know we're not going to focus too much on that but you know it is not just that I think other frontier models are just not too far behind. In fact a lot of the research our team has done that even the SLMs actually have been able to detect a bunch of these things that these larger models are detecting. So what that's going to mean is not just that you're going to have a ton of new vulnerabilities being detected, you're also going to have and I think that's probably the more interesting thing is the ability to create exploits. So of course the corresponding is Glasswing. So I assume that if you know all the vendors who are as part of that Microsoft, Google, Cisco, Palo Alto and others, those vendors that were part of this are the ones that have the most exploitable vulnerabilities on the CISA KEV catalog.
So I'm not so sure it's a matter of pride as much as the fact that they are on the list which because of 43% of the CISA KEVs are from these vendors. We're glad we don't have a single KEV from on any of the Qualys software. So, we do generally good with our patching, but what that means is that you're going to have a bunch of announcements coming where they're going to, you know, announce a bunch of new vulnerabilities and a bunch of patches that will need to be deployed as well. And on top of that as the access to these kind of models get democratized you are going to be able to run this against your own source code as well and the source code that's not publicly available. And you will find more vulnerabilities and you will need to patch those internally for yourself pretty quickly as well. And that's where of course attackers have already been starting to use a lot of these models and similar models. So it's going to be that cat and mouse game now. So we have to be prepared for it.
I think resilience as you talked about is very important. And I'm very convinced that we are resilient as a human race. We got through COVID all fine. From a technology perspective, all the doomsday predictions of planes falling out of the sky and all of that at Y2K, those who are old enough to remember that we survived Y2K. And I have no doubt that with the right focus as an industry and as a technology, we're all going to figure out how we're going to survive this. But we have to do some things to make sure that we are prioritizing and focusing on protecting ourselves. Which again comes down to, you know, there is this kind of a feeling and conversation you always hear from marketing teams for vendors that talk about oh the attackers have to be right only once. And defenders have to be right every single time. And that's not actually accurate or true because nobody just hacks into one system and suddenly everything is compromised. I mean if you have that you have a whole different problem which has nothing to do with cyber security, right. So typically and this is why I take as an example because what they talked about with Mythos is that they were able to chain four individual exploits to create a compromise. It wasn't just one thing gave them access. Those obviously are not public. So we're going to talk about an example here today which is ProxyShell. If you those who remember it was three different individual vulnerabilities that had to be chained to be able to get access. Now each individual one by itself did not really go for a system takeover, right they had to first come in bypass the front end then they had to downgrade your system into exchange admin tokens right so then they leverage those tokens for a lateral movement and drop the web shell and if all once all of those were done that's when you had a successful compromise. And by the way, patches had been available for a lot of these almost on the same day.
So that's what led to remote code execution. But each if any one of these were patched on a timely basis in your regular patching cadence, the actual exploit would not have worked. So if we are doing enough in terms of the ability to patch on time and prioritizing the right things, we make it a lot harder for the attackers to compromise our systems. And that's the resilience and the cadence that we are talking about and as Sarah said right like we need to focus on how do we prevent them from going out is key. I would argue one way to make sure that they don't go out is don't let them come in. That's a pretty good way of doing it, right? Which again goes back to that analogy that you need your layers of defense. You know, she talked about the fortress having multiple layers and so of course you need to do a bunch around your patching, you need to do a bunch of stuff around your firewalls, etc. And if you have enough of these controls, you're going to be in a much better place than if you were had everything as a flat network. And of course, then you know there's identity and some of these other things as well. So the idea here is that if you have a proper patching cadence with right prioritization and fast enough then we can be in a place where we can truly protect ourselves. So the focus with the vulnerability deluge that's going to come is not about I need to go and fix and patch every single thing that's going to come out. That is 100% not what is going to happen because even if you wanted to do that your IT team will not let you do it and you will not get the budget anyway to be able to try and fix everything. I mean, at this point, the way they're making it sound is like everybody will have to shut down doing everything else and no feature development, no innovation. We'll just going to be spending the next couple of years fixing and patching things, which I really heavily doubt. I'm pretty confident in our resilience as an industry to go in that direction.
So, how do we reduce the AWE? Speed of remediation needs to match the speed of detection. Be better is even better, right? So, how do we make sure that we create an environment where we're actually able to get things fixed? How many times do we detect a vulnerability in four hours and then IT team asks you 30 days to get it fixed and you know we saw that with Jaguar Land Rover as well was you know the patches were available but the fear of the disruption and what it will mean and of course it doesn't help the confusion with the SAP vulnerability with the information they gave didn't help but the fear of hey what if something goes wrong is something that really drives people to push back on the remediation side of it. So that's where when I look into the future and now what is coming in terms of frontier models finding and detecting more and more vulnerabilities, I really am very convinced that the future for us is going to be autonomous remediation.
I know most of you won't believe me on that one, but that's okay. 5 years ago when I introduced patch management, nobody believed me on that either. And yet here today, we are with Qualys having deployed 150 million patches for our customers. So there are certain things that we definitely can patch. Now the question is autonomous matching. And I don't know some of you might use BigFix or other tools and you're talking about you give the IT team 10,000 CVEs to fix okay I mean and then you wonder why does IT team not like the security team I think maybe it's that 10,000 and you know what worse they hate it but their bonuses tied to that they somehow fix it they come back and you're so kind to them you tell them great job here's your gift and you give another 10,000 to them. Okay, so autonomous patching for 10,000, 50,000, 100,000 is just not an option and that's not a possibility. So let's say that maybe this is not the future, but this is the north star. This is a nice to have. I wish whenever we could scan, we could also know that this could be fixed and we would just get it fixed and nothing would break. We agree that's the north star, right? So that's the direction that we're going to go.
And to get there, what are the things that we need to have so that we can feel comfortable which the number one thing is going to be hyper prioritization. Okay. And as you'll see that in the report as well that majority of the vulnerabilities are not actually even exploitable in general and on top of that are not really exploitable in your environment because you do have controls in place. So how can we rapidly get to the point that the 20% of the 1% is what we are looking to fix and that's where we can reduce the operational risk and that's where the operational resilience comes into play. Do we have confidence in the mitigation or do we have confidence in the remediation that makes us feel like hey I feel good about leveraging automation because I know enough beforehand that this is not going to happen. Can I test the system before and after leveraging automation so that we can make sure that a patch is not going to create an issue and that's where a lot of individual tasks that are needed to be done to make sure that the remediation is sticking, it is foolproof and it's not causing any issues is the opportunity for us to use agentic AI. So again we took 15 20 slides to get to agentic AI conversation which is another achievement. So everybody starts with agentic AI is the solution for everything. But I do think that there is a specific need here that we need to look at.
Now unfortunately what we look at is we say everything is critical. Okay. I think we did some study. I believe we had like 3 billion detections and we said look let's see how many of these are CVSS 7 and above was it Shailish and it was shockingly 2 billion of the 3 billion were actually seven and above because people were not even scanning for the lower ones they're like we're not fixing the higher ones what's the point of that so now you are again back to you know hey everything is critical everything is critical and then you know what does the IT team say they're like go away or in UK you're bugger off. Okay. So you're not welcome. You're not welcome to their happy hours because you constantly tell them how everything is critical.
So there is a case for hyper prioritization and you will see this interesting information in the report. When you go through that report, there's what we looked at when we, I don't remember how many vulnerability detections we went through, but we looked at over 300,000 different CVEs and 1,500 KEVs. But the interesting thing was that most organizations are burning their patch cycles, remediation cycles on a theoretical risk when the risk may not actually be on their assets. They're just saying theoretical there is a risk and so that's where less than 1% of all the vulnerabilities in your environment are actually exploitable.
Now make no mistake, the detection capability and high quality detection is super important. And that's actually one of the things that's going to change with Mythos is a few years ago or maybe the last couple of years we have sort of been in this thing of like well vulnerability detection is commoditized and you know I get all these CVEs. I think with the speed and the number of vulnerabilities that are kind of come out, our ability to have absolutely high quality detections is going to be very important because your concerns are not false positives your concerns are going to be false negatives. So if you don't have the right vendor who is helping you write signatures ASAP, multiple signature releases a day, if they're not on all your endpoints and they're not actually adding these signatures quickly, then we are going to have certain amount of trouble. So high quality detection, but then hyper prioritization to look at all of the standard information that is available via threat intelligence, right? Is this exploitable? Is being talked about in the dark web etc. is very important. And if you apply those even those quote unquote theoretical ways to look at things, you're down to 1% of those vulnerabilities are actually even theoretically exploitable.
But when we say, oh, this is exploitable. It's not necessarily exploitable in your environment. So when we ran a bunch of our and Shailish will talk about this today, the ability for Qualys to actually send a payload and exploit the vulnerability safely in your environment because you have spent a bunch of money on EDR and firewalls and all kinds of other mitigating controls. We found that less than 20% of those vulnerabilities that even were marked as exploitable via threat intelligence were actually exploitable in your environment.
Of course, the simple physics is that if you try to deploy 10, if you try to fix 10,000 CVE, 10,000 CVEs could be 10,000 patches. 10,000 patches is 10,000 opportunities for things to go wrong. But if you are able to leverage the prioritization via threat intel and on top of that assessing in your own environment whether they are actually patchable or not you're talking about less than 1% of those 10,000 are actually meaningful risk to your environment. And then when you try to focus on fixing those that could just be 10 patches. So you could deploy a thousand patches and not even tickle your risk or you could deploy 10 patches and reduce your risk by 90%. That's the physics math whatever is I'm not very good in school so I'm not sure which one applies but so validating the exploit in your environment. And I know all of you are thinking like, oh man, I have to deal with those pen testers and the pentesters who think they're better than the automated vulnerability scanning experts. That's not necessarily true. And we'll talk a little bit about how there are ways to leverage automation even in this validation exercise that can give you a pretty good idea of what we're doing.
So the last piece is that even when you come down to those 10 patches, how can we have confidence in the operational resilience that applying this patch things are not going to go bad? How do we have that confidence beforehand based on what we have observed? So could we have a patch reliability score? Who do we know that deploying this patch based on how the patches for this particular vendor have performed on this particular system? I talked about the 150 million patches. We see every single rollback happening for every single patch. So it's pretty straightforward to build an AI model where you can predict if a patch is from this vendor and the system is of this particular operating system, how can we create a reliability score? But at the end of the day, if you had a score or something that was really really reliable, right, more reliable than the timings of the Elizabeth line, I think we would be in a pretty good place, right. Now, patch is not the end all be all of everything, right? Our goal as security professionals is not to really get a patch in is to mitigate the potential of the attacker being able to exploit the vulnerability. And there are other ways to do that, right? Sometimes there's a mitigation. You just have to apply a mitigation which prevents, you know, as simple as, I don't know, turn off SMBv1. Sometimes it's you update a registry key, delete an old DLL that the exploiter could have used but nobody's using that DLL. So there are many ways that you can actually mitigate the exploit without a patch as well. So a risk based approach to remediation not just risk based approach to vulnerability detection and prioritization but a risk based approach to remediation is also something that is going to be key. Can I apply a bunch of patches that have low risk and then maybe do a little bit more work on you know can I deploy in waves can I test things before but the time is compressing so it's not like we have you know days and weeks and months to test things and then at the end things could go wrong so do we have the ability to automatically roll back right so when you think of in the world of automated remediation, can we hyper prioritize down to very few things that need to be fixed? Can we first look automatically at mitigations that are low-risk that are available? If those don't really work, then can we look at minimal patching? But before we do that patching, we have a very high reliability score so that we feel confidence and then an ability to monitor the system after a patch is deployed to make sure that its CPU, memory, network, all of those things stay within the same parameters of what it was before you applied the patch. And then when things don't go well, have the ability to roll back that patch that something wasn't working well. So you roll back the patch. This resilience is very important. And the architectures of the future absolutely 100% has to be resilient to being able to do automated patching. We cannot be in this environment where we fix something and suddenly the whole system goes down. That is a now the good news is that we started down this path already few years ago with cloud. So a lot of you who have already moved your infrastructure into the cloud we already are getting the benefit of resilience that comes with the cloud being able to back up the data being able to run container pods where if one or two container images or one or two container instances you take offline doesn't mean your system is going to die. you're already in a place where you could take a couple systems offline, patch them, add them back into the pool. Your overall system is still working pretty well. So, we're going to move into this environment where resilience from your IT perspective is going to be important and people will work more and more towards I don't want to be in an environment where okay, you apply a little patch and then the whole system stops working.
So enough of the future dreams. So now let's look at where we are currently which is dashboard tourism. All the questions I get are about how can I create dashboards? How can I create a better dashboard? How can I, you know, I need to show my dashboard to somebody. We don't have the time right by the time you create the dashboard. I mean, today if you're a CISO, you hear about some new Crack Armor vulnerability. We release Crack Armor, right? I don't even want to know how we came up with that name that starts with crack. But so now you hear Crack Armor, you know, you have no idea what it is. Then you ask the team or they'll ask you then you go into five different tools do data pulls run APIs create CSV files spend a day trying to merge in Excel which is harder than patching something and then a week later you have a view on what might be impacted in your environment. Does that sound familiar? Right that's the way it goes right now and then now you have to provide a dashboard and then what like what do we do with the dashboard? Just gives you some operational cadence but doesn't really give you an idea of what really is important at the end the maximum value of your pound or your euro that you spend comes from did you get it fixed before the attacker got there if you spend 10 million pounds building out amazing dashboards and while you're getting compromised left and right, what's the point of this 10 million pounds that you spend? How do we make sure that we maximize the impact of the security program by doing the thing that matters the most, which is actually getting things remediated. But that's not how we do right now. So whenever there is a new vulnerability that comes up, we get asked for a new dashboard and then we drop everything and we start running to fix that one thing which is our risk whack-a-mole. So that's a whacker one vulnerability whacker and I think that lady in the middle is way too excited about this but that's kind of what we do and you know Log4Shell is there that was one of the biggest wasted boondoggle whatever you want to call it in the history of it where we woke up people over the weekend.
asking them and forcing them to fix things that were not even reachable or exploitable. We spend billions of dollars trying to do that out of fear without actually properly thinking through what impacts our business the most.
Speaking of business, cyber security is a risk management exercise at the end of the day. It is 7 to 8% of your IT overall budget and you're spending that money to reduce the risk of a monetary loss at the end of the day. So I know some of you took a picture of that first slide where we had like 6.5 times increase in the CVEs. Hopefully you can take that to your management and ask for a 6.5 times increase in your cyber budget. But I think the number is more like 6.5% of your last year spend is something they'll be lucky to get. Right? So it's not like we have the money to fix everything anyway. So then you kind of have this equation where things are exploding in volume. They are coming too fast at you and you're struggling to get things remediated. Where do you focus with a limited budget? And that's where we've talked about the concept of moving from attack surface management to risk surface management.
In simple terms, what does that mean? If you have a nice house which has a tons of doors and windows and get the latest security system, thermal sensors, cameras, motion sensors, things that can like squirt water at somebody unauthorized who opens the window, right? You spend a million dollars on that one. Feel very good. You have really secured your attack surface. But if somebody did come to your house, the maximum they could have taken was $50,000 that was in a drawer in the house. So you just spent a million trying to protect $50,000. That's your attack surface versus your risk surface. So how do we move into thinking about when we are going to focus the budget the dollars into the things that are most important? You know we talked about crown jewels and really identifying the data that is the most important for you the systems that are most important for you and move to this concept of risk management which is at the end of the day there is nothing like zero risk. So how do you move to an environment where we are actually able to think in terms of how do we reduce significantly the likelihood of a compromise happening and where which business units and which systems are going to create the most amount of loss for the business that we should focus most of energy on.
And it was funny because before this conversation we were talking about this and you know Sarah was saying she was talking to somebody they came in and they said look you know we disabled EDR on all of our systems except our most critical systems. Shocking right but that's a business way of looking at it. They were like we are getting alerts constantly on a bunch of these assets that we are very confident and that's the now that's the debatable term but the idea was that we were spending more money trying to triage alerts on systems that didn't really matter to the loss that they were looking at right. I'm not recommending to anybody that they disable their EDR or anything like that but it is a way that they were thinking about it from a business perspective is where should I put my dollar in a way that is the most relevant to creating an outcome which at the end of the day is remediating your stuff and the balance is very important right.
You know we talked about people getting in and people getting out so you need to have that balance which is you know when you buy a car your car has airbags so if you hit something the airbag will protect you right but because you have car has an airbag are you going to say like, 'How about we save $100 and not get a car with brakes?' You're not. The same way if your car has brakes because you could stop when you see something. It doesn't mean you're going to get a car and say, 'Let's save money by not getting airbags in case we hit something.' Both are areas that we need to focus on. And but at the end of the day, we rely the most on the braking part of it and hope we never have to use the airbag. And that's really the risk management proactive risk management equation is let's do maximum that we can in preventing from somebody from coming in but we also still need to have ways to make sure that if they come in we can identify and take action. And then the last piece of that is how do we make sure that our business is resilient. That is a key part which is if your backups restore from backups your BCP testing is very very solid you're going to feel a lot better that even if I have a ransomware attack I can come back from my backup in no more than 4 hours and that's going to be critical. So that's at a high level when you look at the financial equation of cyber security goes into proactive risk management, reactive and then resilience is an area where people don't really think or spend a lot of money on.
Now I know we talk a lot about CVEs and vulnerabilities but when you talk about risk it goes beyond that. I mean you take any of the recent attacks that have come out it's always a combination of some vulnerability some social engineering to get credentials which is identity and leveraging misconfigurations. So, I know we're all talking about models right now that are using CVEs to chain things together, but we're not far off when somebody's going to release a model which is just leveraging misconfigurations on your systems without any CVEs to create compromises and the same with identity and then a model that leverages an identity plus a misconfiguration and a CVE to bring all of that together and that's where your risk factors overall when you look at risk really come down to your vulnerabilities, your misconfigurations, identities and now AI brings in a bit of a different perspective here because of models that are responding to things right so the question then becomes is how do you think of the risk equation in all of these terms right. I mean you could have a system that you spend all your time and money patching 100% but the C drive is open read to the whole network. Okay, so you don't have a CVE, but you're going to have a pretty bad compromise for sure, right?
So, how do we think of that overall equation? And so now you have so many things coming at you and we don't want to do the risk whack-a-mole where we are all dropping everything and jumping to the next thing to the next thing to the next thing with this big debt of unfixed things behind us that ultimately we forget one thing that was important and one of the things with proxy shell was important that one of those CVE had a CVSS score of only six and normally you would not have fixed it if you're just focusing on seven and above but if you had the right prioritization you would have fixed that one thing which would have prevented the attack. So the idea of moving from that risk whack-a-mole to a more of an operationalized process for cyber risk management is really the future. Can I bring all the different assets, the risk factors and create a setup that allows me to actually operationalize my process rather than having and when I say operational process, I don't just mean sending an email or a dashboard to your IT team as that's not necessarily operational process, right? It is how do we think differently about how we are doing things and create something that allows us to be confident in our ability to operationally manage any risk that is coming our way, any new risk that is coming our way.
And we have kind of done some of this with the SOC on the reactive side, right? Bring all log data together, apply threat intelligence and apply SOAR playbooks so you can have some remediation. But then when it comes to proactive risk management, it's all dashboard tourism. Okay, you have a dashboard for your code scanning which is false positive as a service. Then you have a dashboard for your external ratings mafia. They're going to send you all your A's and F's and all of that. Then you have a separate dashboard for cloud security because those guys are different. You have a separate dashboard for your identity. You have different dashboards for everything. So when you just want to ask like hey what's the risk to my retail banking? It's five different dashboards that have different scores that don't really come together. So the opportunity that we see is really about moving to this idea of a ROC. So if your SOC is on the reactive side, the ROC is on the proactive side. Hence the very extremely smart name of ROC on that we came up with.
So now to be clear, ROC is not a Qualys product. So this is not something that you know we which it's something that you cannot talk about because it's a Qualys product. The ROC is very conceptually an idea like a SOC, right? Like no SOC is not a product. Similarly, we've helped define what are the key operating elements of a risk operation center which you kind of intuitively know but today these are all different silos, right? Your ServiceNow team thinks they're hot because they're doing the CMDB which is always broken, right? I think that's my retirement when somebody tells me that they actually have a CMDB that is absolutely up to date has all the assets I will be retiring at the time. So okay so step one of our risk operations center we fail because we don't have a good inventory of up-to-date inventory of our assets but you can operationalize an outcome and outcome is the most important if you can bring your inventory from multiple tools aggregate different risk factors vulnerabilities misconfigurations identity apply the threat intelligence which is again giving you the exploitability but as I said it's not necessarily doesn't mean that that exploitability is equal to exploitability once you apply the business context. Right?
So we have all these solutions that are giving you scores. Many different solutions give you scores. And let's say that you have two businesses and your solution gives you a score of 900 on a 1,000 for one business unit on another business 750 on a 1,000. Which one are you going to focus on first? Of course the 900 is like really bad. But then if we tell you that by the way the 900 score is on a business unit that makes a million dollar a year but the 750 is on the one that makes $500 million a year. Which one will you prioritize first? So all your scoring without the context of business just kind of went out of the door. You actually focus the opposite of what your CTM solution told you. That's where you prioritize the risk. You orchestrate a response. At the end of the day, this probably is the most important dollar you can spend. If you can get somehow, even if all of these steps don't work, if somehow you're fixing all the right things, that's the only thing that's going to matter because the attacker cannot use that. And then compliance reporting is important because that pays our bills, right? We got to show management we're doing all these things and we're compliant with everything. But the interesting thing is the outcome of a breach and the outcome of failing compliance are probably the same, right? The people worry most about a breach causing an outage. Of course, nobody wants their name in the news and want their company's name in the news for a breach. But on the flip side, how many of us change our provider because the provider sent out a note saying that they were breached? I know one person did he told me yesterday for the principle of it but most of us don't really so companies really focus on making sure that a breach or failing compliance does not lead to a business outage either way it's the same thing if you don't get your certification of compliance and now you have to shut down your business you have a loss same thing if your systems are encrypted for 50 days you cannot accept orders online that's a loss so it really does come down to monetary loss.
So, I know everybody goes like, well, VRM is the solution, but VRM is just another dashboard, right? And in the era of AI frontier models, VRM is pretty much dead because by the time you're using your VRM solution, your Kenna or Vulcan or whatever it is to pull data from other tools, most of these guys are pulling data once every 48 hours, once every 72 hours just to start to do the analysis. That's 3 days wasted when attackers are using AI to find and chain things together. So without having remediation capabilities, right? We had this conversation yesterday. Oh, Vulcan is great. Okay. Well, but does it actually fix things for you? Oh, no, it doesn't. So, what do you do then? You have to take the outcome of Vulcan. And then you have to go to the BigFix guys and then beg them to fix it big, right? And then as we talked about without the context of the business which is your CRQ you might be spending time fixing technical issues that are not really relevant to the business and that's why the ROC is bringing all of this together in a seamless manner where you are actually able to quantify business you're able to hyper prioritize and leverage automation. The challenge that we want to be able to see is can we fix things after detecting them within 4 hours of being detected within 3 hours within 1 hour not wait 3 days for our data to be synced from different solutions so that we can have a dashboard to create Jira tickets.
So SOC and ROC have to work together. No doubt about that. I think Qualys has a pretty good ROC story. We want to get feedback from you guys but we built sort of what we call as ETM which is enterprise threat management platform. Essentially models out a ROC. Again you can build a ROC completely without Qualys as well. So no issues with that. I think that is something is a strategic priority you should be able to take to your management which is by doing a ROC we're going to be saving significantly. So what we do with our ROC of course is we start with our own data as much as possible but also opened up the platform to multiple different partners and pulling data from threat intel in real time doing our own testing confirmation is super important and hooking into your GRC solutions your CMDB to get the context of the business is sort of all built in. So ultimately the idea is with ETM you can go from discovering the asset all the way to actually remediating the vulnerability with no human intervention as an option all on a single platform without having to have multiple different tools. Of course if there are other tools it will orchestrate responses but moving you to a better model.
Now this is important because at the end of the day we are struggling when we report vulnerability counts to the board because those counts always keep going up. Then we try to report patch counts. Those also even if they go up don't mean anything to the business. So the question is can a ROC help you present the risk to the board in a way that makes sense to them? Now, normally I would make a bunch of jokes here, but since my board member is sitting here and I have to face him in two weeks, I'm going to be very careful about what I say at this point. But at the end of the day, right, like any other risk, the board just want they know there's no zero risk. They know we're spending a certain amount of money and what they want to be assured of is that your overall risk to the business from a cyber compromise is within acceptable range and that's what the ROC gives you. Can you put your business values or value at risk on this graph? Can you then put your overall current risk scores? Most important is define a risk appetite for the business. You might spend $10 million fixing a 100,000 low-level vulnerabilities and make zero impact to your actual risk. Or you can spend $35,000 fixing three things which will bring your risk down. Can you have a conversation that says look 80% of the revenue is under our risk appetite. That's good. These two businesses are $80 million. We can spend $135,000 to bring that risk down, which we can show you in the next quarterly update. And then those other ones, we're just going to increase our risk appetite because the business values are so low. So zero about vulnerability counts, identity counts or anything like that, but create a conversation of a business language that makes sense to them.
How does a real outcome of a ROC looks like in the Qualys context? This is an actual POC we did with a customer where we were able to bring data from multiple different tools for this customer including Qualys which was 62 million findings that they had but most importantly when we applied ETM and ROC we were able to bring that count down. As soon as we applied threat intel it came down to only 2% actually had any weaponization or conversation happening in the dark web then you apply the business criticality in terms of dollar value sometimes in terms of is it a database is a revenue-making application blah blah blah it came down to even more which was the sub 1% that I talk about but even more interesting is that when we ran the Qualys Confirm which is the ability for us to send safe payloads to these systems to verify if the exploit actually works in your environment that came down to less than 20% of those 1% was actually exploitable in your environment. That's the hyper prioritization. And this is the actual graph, by the way, that you get in the ETM capability. And the IT teams love that because they are always unhappy with you for how much you're giving them. You just show them this graph. Tell them how much you're not giving them. At least they feel like, okay, you're doing something right now. Just passing tickets from the scanner directly.
The board loves this because what does it tell the board? Because of the ROC capability, if you have your IT and dev teams fix anything in this one that is not here, you're literally wasting the time that they could be doing to innovate for your company. So showcasing that we actually reduce the number of things we are sending to the IT team to fix is a give back to the business in a positive way. So now you move from the complaining security team to a business-friendly positive outcome where we are giving back to the business by leveraging a risk operation center capability and then after that you got to fix it. So that's where against all sound advice from experts we launched patch management 5 years ago and now everybody else is trying to catch up on that one. But the good thing about that is that we provide multiple different capabilities to mitigate the risk. Could it be a patch? Could be a mitigation, could it be isolate the device? Most favorite for our customers is just uninstall the damn thing. Nobody's using it. 18 months, nobody's used this software and you keep patching it. If you just create at the next cycle, next month, a capability the IT team can uninstall or remove software that is not really being used, you can bring down your risk even further. That technology debt elimination is an absolutely valid way of reducing your risk. It does not just have to be a patch.
So good thing is that with the 150 million patches that we have been able to deploy, we actually somehow magically after being told don't do it, we ended up as number one on the list of GigaOmni as a number one patch management vendor. That didn't really shock me. I was kind of hoping it's 200 million, but I think Shailesh and team needs to work a little bit harder. But the thing that really surprised me was that 40 million of those 150 million are already autonomous patches with zero human touch being used. Customers are saying if it's a laptop and it's a Chrome vulnerability, don't even scan for it. Just automatically apply an update. So the customer is able to tell their board that on our employee endpoints we will never have a vulnerability exposed for more than 8 hours because of complete automation. So we talk about autonomous remediation is the future. No, it's already here. We already have 40 million patches being deployed with that with almost no rollback. And that's also helping us create the patch reliability score because when we see 150 million, we know which ones are failing, which ones are rolling back. So we have the industry's best patch reliability score as well.
Now, we cannot conclude this without talking about AI cuz my board is here. I need to show we're doing AI. We have AI. Okay, it's good enough. But jokes apart, I do think that this is the best opportunity for us to leverage agentic AI, generative AI capabilities mixed together to achieve the outcomes that we are trying to do. Our outcome we're trying to get is everything is fixed and remediated as fast as possible. Minimize the MTTA, right? If we can get there, we're going to be in a very good place. So that's where we have been able to leverage agentic AI to achieve this task, hyper prioritization, etc. and we took a little bit of a different approach and rather than having just a chatbot which everybody has but kind of gets a little lonely talking to the same chatbot all the time and then it starts asking you questions back right so we want to avoid that and that's where we created the concept of cyber risk agent so a cyber risk agent you have multiple agents that are very focused on achieving different outcomes that use a combination of generative AI, agentic AI and just good old SQL queries. Okay, so as an example, Agent Sarah is a Patch Tuesday agent. So it's a little bit different spelling, but she's our best agent, by the way. Everybody loves her because, you know, patch Tuesday is the bane of our existence in cyber security. We pay to buy the software and then we have to pay to find more issues in the software we paid for. Anyway, different conversation for a different day. But Agent Sarah will tell you as soon as she's automatically monitoring Patch Tuesday. As soon as the bulletin comes out, she's able to analyze your entire environment and figure out what your current posture is. If you want to do human in the loop, she will come back to you with a couple of ways that she created plans. That's where agentic AI comes into play where it's able to create couple different plans. Then if you want to leverage automation, she'll go ahead execute the plan. By the way plan does not mean she's going to start kicking off remediation everywhere. In some business unit it's going to be creating tickets. In other business unit is going to be mitigation. In some other cases is going to be patching. But ultimately she will come back and give you on a weekly basis. Hey last patch Tuesday here's the status. Monday morning you come in Slack teams you get a message. Here's the status of the last patch Tuesday. She's been monitoring it in the background and giving you proactive updates and she will tell you what worked and also what did not work and after that she's not even asking for a raise. Right? Our sales guys might ask for a little bit more but she's not asking for a raise. That's to me is the future.
And we demoed this and I make this a point because the one of the latest agents that we released at RSA is called Agent Val. Extremely brilliantly named as Agent Val for Agent Validation. So great job Shailesh. Very creative. He's the next monkey that's going up after me. So, but the key here was to demonstrate and we did this live and hopefully you're going to do this live today, but we demonstrated that from discovering the vulnerability, running an exploit, applying a mitigation and rerunning the exploit to validate it is fixed in 10 minutes with agentic AI. Of course, you can have human in the loop initially if you want to know the steps, but other than that, I don't know any other ROC solution that can take you from detecting, validating, fixing, revalidating, and then sending you the successful report in less than 10 minutes.
And that's kind of been the focus, right? So, lots of different things. So you know as I will say that if you are worried about Mythos a lot of you are worried about Mythos go hide under a rock. It's the Qualys rock of course if you are under a rock you're going to be fine. If you're playing whack-a-mole you're not going to be fine. And then again brilliantly we have a chatbot since everybody needs one. and it's very aptly named as Rocky. So again, great great creativity here in naming. We also have a CISO only mobile app. So CISOs don't have to call you whenever there is a new vulnerability. This app has the ability to give them an audio summary of the latest vulnerability that has come out in about 90 seconds. So they can hear what's going on. they can understand what the impact could be to the infrastructure but also what the impact is to your own environment and not have to do data pulls and then they feel smart. So that's always good.
So ultimately we want to be able to at a very high level and Shailesh will go a little bit more into that but I think we need to move into an environment where we're really doing hyper prioritization because we just doesn't make any sense to continue to fix anything and everything move towards autonomous remediation and of course there will be steps along the way but I see the future is really about autonomous remediation and by the way EDRs do autonomous remediation once the attacker is in the environment. Once the attacker is there, they see an attacker is there, they're starting to kill and shoot things and delete things anyway. So, we're okay with that. Once the attacker is there, but we are not okay with proactively protecting ourselves with autonomous remediation. So, that is not an option that is going to come. And then ultimately align what you're doing to the business as well, right? Because that's where you want to show how the spend in cyber security is giving maximum outcome which is preventing and protecting things.
So I know this gets a little bit boring with cyber security. So great news today. How many of you know cricket? Okay, bunch of people know cricket. How many of you think that cricket I'm talking about is the insect that you fry and eat. It's not that. It's the game of cricket. And we're excited today 5:30 we're going to have Mahendra Singh Dhoni who is the captain of ex-captain of the Indian cricket team. He's going to come here on stage. We're going to have a back and forth. I'm going to ask him about ROC. what's his first thought when I say ROC or you know what is a black hat what is a white hat so I think it'll be an interesting conversation today just to make it a little bit fun but wait I thought I was done never mind okay so dashboard tourism is not going to go away unfortunately right we're going to have to do dashboard so here is my vision which may or may not come true but instead of dashboards today that are complaining about all the problems you have. I envision an operationalized risk operation center process that gets us to the point in a couple of years or maybe even sooner where the dashboard that you're going to get is not oh you have this problem. This much is the problem. This is the score and here's the problem you should look at and you should look at this and cry and you should fire somebody. The dashboard of the future in my mind is going to be a dashboard that tells you, hey, overnight we discovered 127 issues that came up. We were automatically able to match it to your environment. Then we applied confirmation scans to validate if they were actually running and exploitable in your environment. And then we went ahead and leveraged our agentic AI auto remediation to fix 28 of those. We monitored the system. Nothing went wrong. One of them was not behaving. So we rolled back and we created a ticket for the IT team. And so now you can actually just look at this dashboard to know things are getting fixed as you enjoy your coffee or tea in the morning. That in my mind is the future. And I hope that for everybody else.
All right, I'm going to get off the stage before they yank me down. So, thank you all very much. Thank you.
M
Moderator1:05:30
Thank you, Sumedh. Appreciate that. Very nice. So for me it certainly made a dent into the question I had.