Qualys – Transforming Cybersecurity with ROC | Black Hat 2025
Sumedh Thakar, President and CEO of Qualys, speaks with Alan about the ROC (Risk Operations Center), which focuses on proactive risk management tailored to business needs. The emphasis is on shifting from reactive to proactive strategies in cybersecurity. AI enhances the ROC by automating tasks and introducing specialized cyber risk agents. A marketplace for these agents promotes customized solutions, aiming to improve decision-making and collaboration in managing cybersecurity risks.
Transcript
Hey everyone, it's Alan Shimel. We're back here on the show floor at Black Hat. It's Thursday, and the, the show floor is alive.
It's buzzing, it's crowded. Just about every booth seems to have crowds around them. It's crazy.
Speaking of crowds, I'm here at the Qualys booth and they've got crowds coming for a couple of different reasons. First of all, it's about rock. We're gonna talk about rock more in a second, but if that's not enough on this side, they have a, uh, a virtual reality, augmented reality set up to play cricket.
I'm gonna be using it later. Look on social media. Maybe I have a future in the cricket world, who knows?
But anyway, let me introduce you to my friend Sumedha Ed. Always a pleasure, my friend. Good.
See, always a pleasure's. Been really fun talking to you guys. Yes, Sumit, of course, is the CEO of Qualys.
Uh, summed. First of all, congratulations on a fantastic, uh, presence, a black hat, not only here at this beautiful booth, but I, I've seen Qualys throughout the week here. Yes.
At, at private events, shared events, really reaching out to the ranked father, 20,000 people here Yes. And getting them in. So With the team.
Thank you. Thank you. Yeah.
And I think that's really because we are, we're really hitting their pain point and talking about their day to day rather than giving them some big marketing spiel about Right. Some magic that we have. Right.
I mean, people are just struggling with operationalizing things, and we're here to help, and that's what they really like and why you see so much noise around what Qualis is doing. Absolutely. Hey, just a quick plug.
Yeah, of course. This video is just a, uh, uh, a for tell of where we're gonna be. October, I think it's eighth to the 10th.
Yes. In, In Houston. Houston.
For, For the Quala security conference. Yes. So we'll be live there too.
So stay tuned for that. But summed, the last time I spoke to you was in San Diego. Uh, 'cause I think you were sick at RSA, you got sick.
Yes. You lost your voice. You can imagine with the, the number of people.
I was sick too there. I don't know what Yeah, I, I remember. Anyway, but we spoke in, in, uh, San Diego, and you guys had just rolled out something and I, I don't know if people could see it.
It's the rock. Yes. ROC.
Yes. So that was about 10 months ago, 11 months ago now. Right?
Yes. For people who maybe aren't familiar with the term rock or ROC, let's start there. So Yeah, what is a rock?
That's a great question because what is cybersecurity? Cybersecurity is a risk management exercise, right? So we're not here to like, fix everything and, you know, do everything.
It's really look at the risk and then align what we are doing in cybersecurity to protect the loss that the business can have. And so, what we found out that a lot of people who are doing the soc, right, which is a security operation center, but it is to detect breach after somebody's in your network. But when you talk about risk management, tying it to business, we were seeing people struggle because they have 10 dashboards, one dashboard for, uh, code scanning, one dashboard for cloud security, one for container.
And they cannot really tie to business. So the big need for people was, we are getting too many findings. How do we operationalize our risk management exercise without spending too much money?
And so that's where we introduced the concept of a rock, which is a risk operation center similar to a soc, but it is about proactive management of risk, but not just risk from a technical perspective, but also risk from a business perspective. And so that has resonated really well with the CSOs because the boards don't want to hear CVEs and all that. The boards want to hear dollar value loss, potential risk, uh, resilience.
And so it's been great feedback last few months. And so that has evolved. And now we have a visual here.
We have actually set up a risk operation center. And, you know, we, unlike a soc, which is typically like dark and all of that, right? This is proactive security.
So we've given it a bright look, and we are seeing customers wanting to implement something that like this as a proactive mechanism to operationalize the risk management, not just from Quas, but across multiple different tools. And that's been really, really exciting for us to see what we have been able to do and how now we're leveraging some of the new technology as part of the rock. Sure.
We're gonna get into that new technology as you euphemistically called. Yes. You know, it, it kind of brings me back to my early days in security when security was about risk.
Yes. We knew it was. Yes.
And it wasn't even part of the IT team a lot of times. Yes. It it worked into the risk team through to the CFO.
Yes. And, and that, that risk team, and maybe it is from the CFO or Chief Risk Officer, you see now they have a home at the Rock too. It's, yes.
So the nice thing about the ROCK is if that's where you are, yes. The ROCK has it for you. If you're a traditional security person, right, you could use the rock.
Yes. If you're an IT person, you could use the rock, right? So it really is a very versatile, And it is true, because if you're an IT person, what you do, if you're a security person, what you do, all of that needs to be rolled up into what you as a company are trying to achieve from a cybersecurity, uh, practice, right?
Yeah. And so you don't, you want everybody to speak the same language and the rock aligns the, the operators and the IT people and the management all together in a single language. So you're not doing efforts, you're not fixing CVS that don't matter to risk.
You are really focusing on what CVS matter to risk and fix those as an example. Right? So the ROCK is really for everybody.
It's, it's creating outcomes for the leadership to communicate to CFO and A board. It's creating capabilities for the security team to communicate with the IT team. And it has capabilities for the IT team to go and fix things.
At the end of the day, you need to be able to measure risk, communicate the risk, and eliminate the risk. If you measure it but cannot communicate, it's a waste. If you communicate it, but nobody's fixing it, that's a waste.
So the ROCK is about measure risk, uh, communicate risk, and eliminate risk. And that's really one of the feedback that we're getting, that we're talking a our technology and vendor agnostic language, which is what everybody wants to hear. So the old meatloaf song, two outta three, a bed doesn't apply here.
You need all three. Yes, exactly. Absolutely.
But all, all, kidding. Isiah, you're a hundred percent correct there. Let's fast forward.
So you announced this in San Diego. Yes. You've been getting a lot of feedback, iterating, reiterating, fast feedback loops, and of course, at San Diego last year, I, I don't know if we were really talking ai, but Yeah.
You know, you can't walk from here to there without tripping over AI at this show. Yes. AI's had its influence on the Rock too.
Talk to us about that. Yeah. You Know, it's, uh, here at, at, uh, black Ad with every vendor.
You know, everybody's talking about AI as part of that. And you know, me, I'm, I'm a technologist. I've been doing this for a long time, and, and I don't, we didn't really talk much about AI for a reason, because, you know, generative AI was nice and helpful, but truly making it something that can give outcomes is agenting AI and use of AI in the Risk Operation Center has been super exciting.
So that's why we're talking about it now. And not last year when everybody else was talking about generative ai, because yeah, chatbot is good, but is that what you want to do? Spend time chatting, chatting, chatting.
So what we've been able to do really exciting is that, look, the success of a rock is about achieving the small tasks that have to be achieved in terms of, uh, discovery, in terms of re uh, prioritization, in terms of remediation. And those building blocks make for the success that you get with the risk operation center. And a lot of that we found out can be really automated well, with the use of Agentic ai.
And, um, by doing that, we can help CISOs augment their risk team by having specialist agents in the product. So we have created this concept of a cyber risk agent, which has a persona. They have a name, they have a, a, a, you know, a character, uh, assigned to them.
Uh, they have a skillset. And so you can go in and you say, look, my Risk Corporation Center today needs focus on ransomware triage. And instead of going and getting a consultant to do that, you can now just say, employ, uh, agent Sarah, who is a risk operations specialist for, um, ransomware vulnerabilities.
And she will come in and she will look at end to end the entire, um, cycle of what is needed to figure out, uh, what we need to do to come up and say, here's what you need to do. Right. And so, uh, creating a marketplace of cyber risk agents that you can pick and choose based on what you want to achieve now without having to go and wait to hire somebody, they come on board and all of that.
That's super exciting part. And so, uh, the, the agent marketplace that we have created allows us to provide out of the box agents, we, where we know specialists, we have trained them, uh, customers can create their own agent. So if many customers wanna do something very specific, and in the future, we look at, uh, our partners providing agents in the marketplace.
So if you want to create, uh, create an action directly out of the risk operation center to fix an identity in Okta, or to fix a bucket through Wiz or AWS, we can now do that by providing an agent who is a wiz expert in the risk operation center. Right. So that's the future.
That is kind of what we're looking at. And so a lot of people here talk about, you know, they have AI embedded and it's no, we cannot see it and just trust us. For us, what we have done is truly made democratized the use of agentic AI by making it available, visible, giving it a bit of a personality and allowing people to use it.
Like they would actually ask, uh, a team to do something. And that's been super exciting, and that's why we have had a such a big line of people waiting to come here and experience the Risk Cooperation Center. Um, so we're super excited about that.
Absolutely. I want to talk more about the third party, the platform aspect. Yeah.
But before I do, I, I want us, you know, because we didn't record, we're not streaming live. Yeah. We have the ability here.
I wanna pan, I wanna pan out, you know, we are at this RI risk operation center, and we have a slide, I think Sumit, you know, picture's worth a thousand words. Yeah, yeah. We have a slide that talks about what you're talking about.
Yes. Different agents, and the agents have names like they're people Yeah. And they, but they do specific tasks.
Yeah. And, and you, you imp you, you'd press the employ button Yes. As if I'm really hiring this digital worker.
Yes, yes. As the term I used these days. That's a good term.
Digital worker. Yes. Yes.
The digital workers. Yeah. My partner did.
My coworker. Yes. Look, this was something that I think was inherent when you first announced the Rock in San Diego last year.
Yes. Which was, it was a platform, not just for Qualys. Yes.
There was a place there for third parties Yes. To bring their, uh, solutions Absolutely. Yeah.
To the marketplace. Now, with the agent AI aspect, they could bring their agents. Yes.
And those agents oftentimes, whether you're talking about NPC servers or ADA or whatever, they could go back yes. To larger things, but the rock does really become the, the operation sector That it is. Yeah.
That's exactly what it is, right? Like, you don't look, I think this notion that, Hey, I'm a big vendor and if you replace all your existing products with my, all my products, life is gonna be beautiful. It's not real.
And nobody buys that. And yes, there is some consolidation, but at the end of the day, risk comes from different areas. And we need to democratize the risk management process, the risk cooperation process, and, uh, let give that empowerment for the teams to use the best tool they think they need to use for that specific task, but then still have a common framework and a common risk plane that then aggregates, normalizes all of those risk factors and puts it in the context, right?
As an example, A CVE discovered in a code scanner that exact same CVE discovered in a production environment are not the same risk. So how do you normalize that and then figure out, hey, what is really causing the risk? And so that was a big part of what we focused on, is like, it cannot just be on QUAS data.
We need to democratize this capability, and we need to allow partners and different risks to come in and, and give the customer. At the end of the day, what they need is that they don't really care which tools you're using. They want to know where is the risk coming from, and then what do I need to do?
Fix it. Right. I, I agree with you.
People are past the point of how many tools do I have, right? Where the tools are coming from. They want, they want peace of mind.
Absolutely. They want things that work. Right.
And there weren't things that worked together well. And also, you know, you just, you can keep yourself busy with fixing all kinds of stuff. Right.
But it's a waste of company resources. If you ask your IT team to fix 10,000 findings that actually don't matter to the risk, because that's the time they could used to innovate something else that would put your com put you ahead of your competition. You know what, I, I spoke to some of the, uh, cyber insurance people this week.
Yes. Spoke to some more of my friends, you know? Yeah.
From the industry. The fact of the matter is for all the hundreds of thousands of CVEs Yes. There's really only about a thousand Yes.
That have actually led to attacks. Right. And, and you put that in the context.
It's in, in the context of that particular business. Maybe it is exploitable outside, but maybe in your machine. It is not.
It's not. So that context is important. And I, you know, insur, no one manages risk better than insurance.
That's their business. Right. But by the way, it is, risk management is all of our business.
That is what cybersecurity is about. Cybersecurity Lost that somewhere along the Line we forgot. Right?
And insurance is a key part of risk management, right? So I think a lot of times we don't think the big picture. It's like, okay, I'm just looking at my tool.
That's not about the tool. Right. How much risk can you mitigate with tools?
How much risk can you accept? And how much risk can you transfer to cyber insurance company? That is the complete equation that we all need to be talking about.
And you know, 99% of people don't think like that. And that's where the rock is going to change. I think.
So where can people go find out more about the Rock It's com slash rock? Yep. Ash Rock slash Rock.
You heard it here, Sumit. I will see you in about, uh, two months. I, well, first I'm gonna watch you play cricket, so I'm walking over there right now.
It is always a pleasure, Alan. Thank you. You always a pleasure.
Sumit Kar, CEO, Qualys, we're here at Black Hat. We'll be back. Thank you.