Techstrong TV October 15, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Wait, turn out. Oh, we we're live? Yes.
We, we are live on. Okay. Okay.
Three, two. Hey everyone. We're back here.
Live at Qualys is Raan conference. If you've been watching our stream all day or this morning, I've explained what Rock on stands for Right. Risk Operations Conference.
But I wanted to go to the very top to get you an explanation of why Rock On. Right. For many of you who've been following Techstrong and the security industry in over the years, the Quala Security Conference QSC was kind of a staple.
A lot of us have gone to it, and, you know, whether you went to the one in Europe or North America, or the one near at RSA or whatever, Quas Security Conference, now we're doing Qualys Rock on. Let me introduce you to my friend Summed Kar Summed is the CEO of course, of Qualis, but he's the guy who made it Qualys Rock on Summed. Welcome.
It's great to have you here, man. Oh, Thank you very much. I always enjoy doing this with you.
Always a pleasure, man. So, look, I gave him this much. Yeah.
Give me the whole story on Rock on, You know, if you remember last QSC, we talked about the concept of a risk corporation center, and then notion of like evolving a rock out of the soc Yep. So we can really focus on proactively managing risk. And, um, you know, it was, it was a new idea.
Like we did patch management a few years ago. Didn't know how it was gonna go. The feedback was phenomenal.
People loved the idea of the rock. Um, and we started to kinda see this like appetite for people wanting to have a conference that was really focused on cyber risk management overall, rather than a, a tool specific or a technology specific, or a vendor specific thing. Uh, and so I felt we can expand this audience.
We can, um, it takes a village for risk management. It's not just the guy who's scanning, it's, it's really bringing the CIO team, bringing the CFO as part of the business conversation. How do you report to the board?
So the idea of the risk operations conference was, look, at the end of the day, you know, as I talked about in my keynote dashboard, tourism is not getting us anywhere. We need to get things operationalized and fixed. And so having a conference where people would come talk about, um, risk management and how to operationalize it end to end agnostic of the tool, um, was really well received by folks.
And that's why we came up with the ROC, the ROCK conference, because this will continue to grow and, uh, give people a forum to come and discuss proactive risk management rather than just always being in reactive, uh, detection and response. Uh, and that's why super excited about Rock On. I am too.
And, and I, I'll tell you something. First of all, I think it's brilliant because it lifts what was in essence a user conference Yes. To a whole different plane.
Yeah. Which is, it is the risk operations conference. And, and I think one day we'll look back, Sue and say, oh, yeah, they did the first one in Houston.
Yes. It was a smaller one. Yes.
This will take on its whole, you know, there was a time where the RSA security conference was just about the rsa. Yes, exactly. Yeah.
Encryptions Right. Now, of course, it's different. As someone who's been in security 30 years, it's always been about the risk.
Yes. And, and managing risk. Yes.
We just don't seem to remember that all the time. But it's always been about it. And, and so again, I I, I think it's a great, great thing for there.
You mentioned a couple of other things though, and I, I want to jump into those. Number one, it was a great keynote this morning. Thank you.
I, I think, and again, this is something that was so important to me as a person, as a security person, was the concept that we gotta get out of being the bad news generator, especially in vulnerability management. Yeah. The bad news generator, we gotta get out of saying, oh, I've got a hundred thousand vulnerabilities with, you know, 10,000 CVEs, and Oh, I got my work cut out for me.
Yeah. Right. One of the biggest things, I, I was talking to our keynote from this morning.
Yeah. And, um, I, I get Get what? Get, and we, and we spoke about that was, you know, he was a CISO when CISO's first started becoming, but that was the CISO's job to convert security talk to business talk.
Yeah. And businesses talk risk. Yeah.
Right. And so, again, I think it's such a great thing for us as an industry to say, Hey, we, we can't keep doing this chicken little thing. Yeah.
The sky's falling. The sky's falling. We need to talk to the board, to the exec team to the business.
In business terms. You used the term digital tourism Dashboard. Tourism Dashboard tourism, excuse me, dashboard tourism.
I'll be honest with you, I almost spit my coffee out. Um, talk to me, what, explain to our audience, what do you mean? You know, I think we've sort of come from this thing of, well, cybersecurity is about visibility.
And, and I think we invested so much in visibility. We sort of almost over rotated on visibility. And so today, when you ask anybody, oh, my security posture view, and then you have one for SaaS and one for cloud, and one for on-prem and one for user identity.
But it's all just dashboards that show you the bad news. And so if you ask somebody, what's the posture view? They have one dashboard from code scanning, one from cloud, it, it doesn't make sense to, from a business perspective, right.
Because if you take a mobile banking application for a bank, it's using capabilities across each of those tools. But they don't come together and tell you, oh, what's my risk to my mobile banking? Yeah.
You can get your code top 10, you can get your cloud top 10, you can get your identity top 10. What does that mean to the business? And so I felt like we've spent so much effort in building dashboards, and then things don't end up actually getting fixed.
Yeah. Because we don't know what to do after that. People don't listen it, teams don't.
So this idea that we gotta, we gotta move at the speed of AI and, and, you know, be able to actually make an impact means we have to get away from building dashboards and taking selfies with these dashboards into, I don't really need a dashboard. I just need to get stuff fixed. I need a dashboard of what was fixed rather than a dashboard of what's broken.
So that's where, you know, that's resonated really well with our customers. They love this idea that we, we don't want more dashboards. We just want to fix things.
I gotta tell you from my heart, it's not just a security issue. Yeah, No, it's true. You Know, we sales not mentioning names, but Salesforce could use this lesson.
Yeah. How many dashboards and and it's like, because I think we've gone to this notion that we need a custom view for every single person in the organization. Oh, you're a CIO, you get this view, you're A-C-I-S-O, you got that view.
This guy gets this view, this team gets that view. Right. You can't collect enough stickers for all these dashboards.
And they're all, there is usually only one truth. Yeah. Right?
Yeah. Yeah. Just how many ways do you want to color it?
Um, so again, major kudos to you on that. Thank you. I I, and as I told you before, I'm going to be using that over and over and over.
Go for it again. So we'll, we'll get to use it. Here's another thing.
Was talking to a friend of mine who's just starting a company. They just got their seed funding around risk. Yeah.
I said, are you going to do security? He said, no, we're doing risk. Yeah.
For those of us out here who are saying, wait a second, risk is security. Security is risk. Yeah.
Yes and no. How, how do you delineate between the two? I I mean, look, the, if you look at a company, a company has many different risks.
That's financial risk. There's risk to sales, there's risk to product development. And cybersecurity is one risk factor for a company, because cybersecurity is about managing the risk to your digital infrastructure.
If something happens to digital infrastructure that'll impact the business, that's the risk you need to manage. Right? And so, uh, yes, cybersecurity has always been risk management.
They're not really separated. It's just that the way we have been looking at it is initially we came from best practices, right? If I lock all my doors and windows, I'm safe.
So let's focus on doing everything to lock my doors and windows. But then you start to get to the point where you're like, I spent 500,000 making sure all my doors and windows are locked, but what my, what was my possible loss was only $50,000 in the drawer. So now you're suddenly saying, wait, wait.
Like my attack surface is big, but what am I gonna lose? Is not that big. So should I be spending so much money on that?
So at the end of the day, like any risk management, like your car, you are a car insurance, a fraction of your overall car's value should be your car insurance. Yeah. It's the same with cybersecurity, right.
There's a fraction of your IT spend should be spent in protecting, and what is that fraction? And that has to be tied to how much risk you have of losing money. And that conversation has not happened for a long time.
People just kind of come from best practices. But now I think it is the time where we feel like people just cannot fix everything. And so, which means that you are taking an inherent risk by not fixing it, by not fixing things on time, you're digging an inherent risk.
So why not be deliberate about the risk you take? Right. By actually measuring and quantifying and focusing and being proactive saying, this risk, I'm going to fix this, I'm not going to fix, versus today is just slipping away from you.
And so you're taking a risk. Yeah. I, I agree with you again there.
I, I think what happened, it's almost, you know, you sometimes, like people start doing things, and I don't wanna pull religion into it, but people do things because it was traditional to do in religion. Right. And they almost forget the reason they were doing it.
So we lock the doors and windows because that's what we do. Yeah. Not, you know, you have to keep your doors and windows locked.
Right? Right. Not that keeping my doors and windows locked means they can't steal these glasses or something.
And what's it worth for the glasses? We, as an industry, I think we, we went out in the woods on that a little bit and Totally, Yeah. And that's the, that's the evolution, right?
I think the reason this was not a big deal in the past was because we were not approaching cyber budgets to the point where people were like, I mean, how much more can we give spending? Like, what's the limit? The problem with risk management is if you don't define how much risk you are fighting and infinite at risk, you can spend any amount of money and still not feel safe.
Yeah. So that's where the last couple of years, the number of issues coming up has exploded. The speed at issues are being exploit, being exploited, and the budgets are not keeping up.
And so then the question comes, well, if we have a limited budget, limited people, what should we focus on? We cannot fix everything. So that's where, what we should fix on what causes risk.
Now, is it just the risk of somebody coming through the door? No. It's the risk of what would happen to the business if somebody came through the door is the, the real challenge.
Right? And so I think, uh, I feel like it's, it's a maturity journey right now. And we are all sort of coming in with having spent a lot of money on all kinds of tools.
And now is the opportunity to say, how do we tie it back to the business so we can have a business conversation. Security should not be the bad news better. And, and the cost center, they can actually be an enabler back to the business by reducing the things that we are fixing, giving time back to the IT and dev team so that they can contribute positively to the company's top line.
You know, 25 years ago, 23 years ago, I remember asking my team to come up with like a ROI calculator. You'd probably think the same thing. And for the longest time, kind of the dogma in security has been, there is no ROI calculator.
It's, it's impossible to measure the ROI of security, but you can't measure the ROI of risk. Yeah. And I think, again, that is something that's like game changing where we can say, Hey, you know, if you spend X amount of dollars, you're gonna reduce your risk by Y.
Yeah. And here's your exposure, right? I mean, we, That's exactly what it is, right?
Is like, basically you're saying that your cybersecurity spend is going to reduce risk. And the ROI ON cybersecurity is how much risk did you reduce for the organization? That's it.
Right? I think in the, some of the previous attempts at, at quantifying and ROI have been too tactical where people start to put a, a dollar value on a server and a dollar value. I mean, and that doesn't scale.
Yeah. At the end of the day, you have a business, the business is generating certain amount of money. You may have a subsystem of that business that, you know, generates half of that.
And so now you can break it down in, in the top five, top level, you know, sort of revenue generating, um, applications or business entities. And then you can align the risk, right? Well, what if there is a ransomware attack, how much would I lose?
And then if I know how much I would lose, then how much would I spend to reduce the possibility of how, how much, how much I would lose, right? So that conversation is what we are enabling, and that's why having the risk operations conference here is really about, uh, expanding the persona. We had a board cha, uh, panel right now, right?
Mm-hmm. Where board members talked about how they look at cybersecurity, CSO talking about risk. We have a panel later for CIOs.
We have cyber insurance. We have a lot of conversation around expanding the conversation around cybersecurity as a risk management, beyond just, I got these many cvs and I gotta fix them. I got it.
I want to pivot a little bit and talk about something else. So as the CEO of Qualys, you know, it has a certain visibility within the Yeah. Marketplace.
Do you feel, so are, are you the missionary on this mission? Is, does the rest of the industry gather around and say, yes, this is what we need to do? Yeah.
We gotta get away. I mean, Yeah. It's a dead end if we don't Right, right.
Understand, right. There's more vulnerabilities than ever. There's more bad things than ever.
Yeah. AI's accelerating it. You gotta get off the hamster wheel at some point.
Look, I think, I, I don't know about the mission or not, or missionary or not. I think the way I look at it is like, uh, not so much about the industry, but our customers are telling us in different words what the challenge that they're facing. So they don't say, I need a rock, but they say, I'm facing budget.
I'm facing issues explaining the, my budget as to my CFO. And you start drilling down into that and you start realizing. And so for me, I believe when, like Qualys has always done this, we were the first in SaaS and cloud, uh, Before there was a cloud, right?
I was the first one to come up with patch management with VM and where everybody said, it's not gonna work. So it's the same with the Risk Corporation Center. I think the response from our customers have been, especially at the CSO level, has been this is exactly where we need to go.
And so, um, we see them rallying, right? You, you talk to Rich Ierson, I mean, he does these board reporting workshops and we have like oversubscribed on CISOs wanting to come have the conversation. So I feel like that's the right approach just because of the feedback we are getting from our customers.
And we are always gonna be visionary from that perspective. Uh, we're always gonna be disruptive to try something that nobody has tried before. And, you know, it, it's worked out for us many times in the past.
If we stay the course, we believe in what we are doing, and we listen to our customers. And I think the feedback so far from risk operations, uh, and the fact that there are over 400 people here at Rock on our First Rock on has more people than we had at QSC last year. Right?
Yeah. So that tells me that we have, it was really interesting today, right? I had a customer come and he has been a policy user, and he introduced two other people from his company that came with him.
And he said, Hey, this is my SecOps guy, and this is my risk operations guy. Really. So that is exactly what we, That's who you want Envision is.
This is a conference that is bringing your risk team and your operations team together. You have a common language of what we should do, why we should do something. What's the auto wire?
How do we measure ourselves from the investment that we're making? Love it. Sumit, every security company I talk to says I want to talk to the ciso, the CISO's, our customer.
But here's the fact there's like a hundred or more security professionals for every ciso. Do you view, do they have to learn to talk the language of risk? Or do they rely on their CISO to be their translator?
If you'll Yeah. I, I think if you really look at every person working in cybersecurity is actually doing risk management for the company. They just don't know or think of it like that.
'cause the whole function is about risk management. And so, um, the evolution of this is that the CISO cannot be successful if the team that they have is not also not aligned to that same idea and the concept that, hey, we need to triage what we need to do based on the risk to the organization. And, and we just cannot fix everything.
Right? And the team is getting burnt out, and we are not having the success, and we just don't get to everything. And so, like I said, there is an inherent risk we're taking.
We just don't know what the risk we're taking. 'cause we didn't get to what we're getting to. So I, I think that that's where the conversation is really twofold.
We, we got to get the people who are administering cybersecurity, um, to think higher level in terms of business and value and why we should, because communication is very important. One of the things I talk about is, is communication. How do we communicate today?
We give the IT team 10,000 cvs to fix. They don't like it. They complain, they still do it.
They come back, we communicate by saying, thank you very much. Great job. Here's 10,000 more.
Right? Versus saying like, Hey, by the way, by fixing these 200, you actually are the hero who reduced the risk of losing $10 million by 80%. So that is why we do need to make sure that, you know, this, this revolution of risk operations center is actually something that touches the people who are administering cybersecurity programs, um, engineering, cybersecurity programs, um, as well as CISOs who are then translating that into business speak.
Absolutely. I got two more areas I want to question y Yeah. Number one, as I said before, a friend of mine's opening this company with risk.
Mm-hmm. You know, they're risk management, but not necessarily security. Yeah.
Do you foresee the rock becoming for more than cyber? It's, it's managing risk, not just cyber risk. Right?
I don't know that right now, but I do think that, uh, the, the rock will become the key piece for cyber risk management that will interface with the rest of the company's overall GRC function, right? Right. So if you're tracking environmental risk, you are tracking political risk, you're tracking military conflict, uh, risk supply chain risk for your business, then, um, the risk operation center will give you the visibility that you need.
Um, you know, I think if you asked me 20 years ago if you would be doing patch management and risk operation center, I would've said no. So I don't know where we go from here, but I do think that the, the risk operations and operationalizing risk is a common thread no matter what risk it is, right? No matter what risk it is, you have to, uh, quantify it.
You have to figure out how much you're gonna spend to reduce that risk that actually makes sense to the business. And there's a certain amount of risk you just have to accept. And having a framework that does that is great.
But today we are really focused on digital risk and cyber and, um, you know, maybe it expands. We don't know the future. I think GRC is an area right?
For disruption. But what do I know? Um, one last thing.
Yeah. You mentioned the Gentech AI up there today. Yes.
Who's not mentioning AgTech ai, right? Yes. How real is it?
What do you think about it? When could are Qualys customers see it? I think it, in a way, it's a good that everybody's mentioning about it, which means it's real in many ways, right?
Like if you just have one vendor saying, oh, this is completely, that, that doesn't scale, uh, and people don't take it seriously. I think that what we are seeing is that attackers are using Agent D ai, there's no doubt about that, right? They are taking, uh, open source code and they're putting it through AI engines to, to find exploits that they can write.
And AI is creating those exploits. And so that's why in the recent manian report you saw that the average, uh, time to exploit is, is negative one, which just means that more exploitations are happening before a patch comes out. And so the only way to respond today is to be able to do, leverage the technology like agent AI to respond at the speed at which they are attacking us.
If they are using AI to say, create an exploit by looking at this code and run it against these 500 companies. And you are sitting there saying, create my Jira ticket, you know, go through seven approvals for Jira ticket. Let me test my patch for like two weeks.
And then, then you're do you're toast, right? Yeah. And so I think agent ai, but it is also important to understand that, you know, you're not letting agent ai, uh, lose on and doing everything in on a completely automated way.
That's why today with what we talked about is a concept of a human and AI collaboration that coming, that is coming together so that the human security analysts actually are augmented with cyber, uh, risk analyst, uh, that are, you know, AI agents that are helping them do a lot of their tasks analysis. You know, I maybe we've seen this in financial, uh, uh, analysts with financial analysts use AI to do research on a company so they don't manually go and do that. But that AI research is coming in and it's the same way, right?
Like if you're an analyst, you need to get rid of, take care of Patch Tuesday. If you have an assistant that's gonna, you know, come and, uh, do that for, you know, so It's human in the loop. Yeah, I understand.
I understand. We're outta time. They're giving me all kinds of hand signals here, summed.
But I wanna mention one thing for our audience out here. And that is, you know, in addition to the two days Yes. Of the conference itself.
Uh, rock on is actually four days. There's two days of training, which are sign up while you can, 'cause they don't charge for 'em. It's free Training.
Yeah. We, we believe in free training. Yes.
And they have standing room only here in Houston. And so I know you're planning on other rock ons perhaps in Europe. There was one.
Was one in Brazil or something? Something. Yes.
There's one in Mumbai in, uh, one month Mumbai. Look, I don't know how long he'll offer that for free. If it was me as CEO, you'd be paying for them.
But if you could go get training for free, get to the next rock, check it out. I don't Wanna say ever, but until I'm CEO, we are gonna offer free training. You Heard it here first my friend.
Thank you so much. Thank You very much. It was a pleasure.
Sum Tar Car, CEO Qua here at Rock On. We're live and we're in Houston. We'll be back in just a bit.
Hey everyone, we're back here live in Houston for Qualys Rock on. Um, if you've been following along, you know what Rock On means and what it stands for. If you just saw my previous interview with Quala, CEO, sum, sum, uh, Dakar, you know, risk Operation Conference, and why we transitioned from Quala Security Conference QSC to this concept of a risk conference and, and what a great success it's been from the feedback of customers, partners, business associates, people I think inherently understand that security was always about managing risk.
And we kind of lost our way somewhere in there. But we're coming back to it. I want to introduce you to Mae Mitchell.
May is the CMO at Qualys may welcome to Text Drunk tv. It's great to have you on here. Thank you so much.
Thanks for having us. So we're gonna talk about Rock On, we're gonna talk about marketing and go to market, but before we talk about any of that, share with you, share with you with our audience, if you will, a little bit of maybe your history of your story of your journey. CMO public company.
There are a lot of people out here saying, I'd like to be like her. Great question. Thank you.
No, it's, it's a pleasure. Um, I just started Qualys, um, 90 days ago. Really?
Oh, okay. Yeah, yeah, yeah. I live in the Bay Area.
Um, and my entire career has been in cybersecurity, large companies, small companies. And I've been, been very, very fortunate, um, to where I am today. Um, I've been to companies like McAfee Sure.
To Symantec, to, um, Cylance. I read that to Cylance. Yeah, yeah, certainly.
And, um, and then it eventually got me to Qualys, but I've always known Qualys for about my entire career. Um, and the opportunity, um, just kind of came about. I wanted to work for a company that was, um, you know, they really needed two things when I was speaking with Summed.
And, um, 'cause there's many different CMOs and, um, depending on the journey of where the company is. But he needed A-A-C-M-O who could, uh, really create that one, go to market motion with marketing, sales, and channel sales, come together, integrate in one motion. And the second thing was to help build the flywheel of our growth through the power of the, uh, partner ecosystem.
So when he set those two things, I mean, those are really two of my core strengths and, um, which led me here and which is why I'm thrilled to, um, uh, be leading, um, the marketing organization at Qualys. Well, congratulations. Thank you.
I knew you were new. I didn't know it was only 90 days, so, congratulations. And I'm, quite frankly, I'm glad to see the have a CMO here who's running with things.
I, I, I, like you have spent my career in cyber. I co-founded a, a cyber company in 2001 and, uh, in vulnerability management. And I, you know, one of our competitors was this crazy French guy named Philippe.
Yeah. Who was telling people we're gonna store your vulnerability data on our servers. There was no cloud then.
And I would talk to the customers and say, you're gonna let him? Yeah. Well, he turned out to be crazy like a fox.
And, you know, I knew Philippe for many, many years. I knew summed for many, many years. And as I transitioned into my media business, I, I've always admired Qualys as well.
Yeah, that's fantastic. You know, um, I, uh, met Philippe. Okay.
When I started out my career, this is early 2000, um, we both met at a checkpoint, um, partner event. Oh, Opsec. Opsec, yeah.
Yes. Um, that was the best partner program. I Was absolutely.
Yes. Absolutely. Be before they, before they started acquiring other Companies.
Yeah, I Know. But I, I remember meeting, uh, Philippe. He had a little tabletop, and I was an attendee there.
I was working at McAfee at the time, and we just started having this conversation. We stayed in touch over the years. And, um, you know, he had called me when I was at Cylance and I was, we were just going through, we were going through a growth spurt and then certainly through an acquisition.
And then that's when he introduced me to Ed. Um, it was like, fall of 2019, really. But, uh, yeah.
It's, it's like I said, the cyber community is really not that big, especially in the Bay Area. Six degrees. Yeah.
Six degrees of separation. No doubt about it. I wanna, if it's okay with you, I want to turn now to this concept of rock con.
Yes. I gotta be honest with you, cement took full credit for it. He said, you know, this was his idea to transition certainly to this risk.
He signs my, my paycheck, my expenses. He does towards My bonuses. Does, yes.
All credits are Ed. Right. Um, but talk, if you don't mind, share with the audience the concept of a risk operations conference versus what was a user conference?
A very successful user conference. Yeah. But it was a user conference.
Yeah. Yeah. It's, um, certainly it's a, it's a transformation, right?
I think A QSC, um, you know, all power to the executives at, at Qualys, the customers. Um, and, and by the way, I have met phenomenal customers here. Every single person I spoke to in the last three days, they absolutely love this conference.
And they absolutely love the products at Qualys, you know? Mm-hmm. Um, produces, but it's always been more about just Qualys.
Everything is about Qualys. And, um, and it's all always started with the product training. Okay.
And more of the practitioner technical level, the transformation of risk and what the means to, um, whether you're speaking to, um, you know, the legal department speaking to, um, a marketing department or board members or, or finance. It's a conversation. And in order for you to have that conversation, you have to have the right data.
So you have context to your environment and all the assets and how you prioritize that based on your business workflow. Um, and then quantify it. But, so that's the purpose of the risk operations conference, is to educate individuals, not just the technical folks, but bring the business people involved.
They may be a Quas customer or they may not be. 'cause we have a lot of people that have signed up for this conference and, um, they wanna learn more about it. They wanna have that conversation.
How do I get started? And so that's really the beginning of today. And we are gonna take this around the world.
Our next one is in Mumbai, India. Yes. Dead Months, right, India.
Yes. Correct. Um, but we've been able to still, like, this year is really the first year we're transitioning it.
We've had general sessions in the beginning. We've had more, um, panel discussions. It's not all about Qualys speaking this afternoon is a breakout of more technical and business.
But here's the thing. It's not just Qualys people speaking. It's, we are gonna have customers come up on stage and learn about their experience.
And that's probably the most important thing, is to really learn about the use cases across all verticals. And then how does that translate? How can someone take those nuggets and then translate it out to their organization?
So that's today, tomorrow, tomorrow is gonna be more panels. It is. Tomorrow's actually, we're hosting a panel of our, uh, managed, um, rock partners.
There's gonna be five partners up on stage, and they're gonna talk about service delivery options to help a customer, um, through implementation and throughout the lifecycle of their purchase. Love it. Yeah.
Good stuff. Let me ask you another, go to another area if it's okay. You mentioned when you originally spoke with Sumit about this job, looking for a person who was gonna be able to create one go-to market motion.
Yep. Partners, end users, et cetera. Let's talk about the go-to market Qualys.
Certainly If, if you would, you know, our audience, our audience are technical people, but they're everything from C level down. But on the tech side, they're cyber people. They're Quas customers.
What's the go-to market for these? For the whole? Yeah, certainly.
Um, first and foremost, um, I think the, the, there's statistics out there that the 30% of companies survive 30%. This is according to HBR, right? 30% survive because C level alignment.
Okay, that's something to think about. C complete C level alignment up at the top. 2 x conversion rate.
Really, And that's significant. So, um, part of that is the collaboration between marketing, sales, and channel sales. You have to collaborate, you have to speak the same language.
You have to understand the ideal customer profile. So once you understand what that is, um, who, you know, what customer segment are we going after? Is it the enterprise?
Which is really what Quas is all about. We're gonna go after the enterprise customers. The way we define that is 5,000 employees and above.
And we're also, we also cover the mid-market as well. We have to think about what are the business problems that those customers, um, tend to have. Who is the core decision maker?
The persona, and then who are the influencers on an average, um, you may be touching maybe 15 to 20 people within a buying center. That's according to Gardner. That's a lot of people to touch, just to get to that person that says, yes.
Right? This is the technology we want. Now help me justify that to ask for a budget.
Okay? Um, which is a whole, many, many steps. Pieces of content that they touch is probably 20 distinct pieces of content.
So that's another key strategy of go to market as well, is creating that narrative for a business buyer as well as a technical buyer. And if you put your customer hat on, you think about different stages that you go through. Awareness.
I don't have a problem. I'm gonna sleep at night. Um, but I get invited to a lot of dinners.
Okay? They get to invite, they go to dinners because their friends are inviting them peer-to-peer conversation, right? And they learn about better ways.
If I could solve all these AI born cyber attacks, and, you know, if my budget's only increasing maybe 2% year over year and there's a better way of solving it and staying ahead, then I'm gonna learn about it. 'cause that's awareness phase, different type of content and different story that you tell. The next one is consideration.
Hey, this qua stuff makes sense. I've been hearing a lot about it. They may go to chat GPT and ask, what are the top three solutions that can help me with, um, to quantify my risk?
Okay, we better show up as one of the top three, right? Um, again, different pieces of content. Then you go to the next phase.
And that is evaluation. Um, how does this solution work with my existing environment? My environment works.
I may not have Qualys, but how do I get feed from third parties solutions? Okay. Um, I may have a sim already, um, from Microsoft or from Splunk.
Does that work with that? Because it's very difficult to take a solution out to bring another one. And CSOs aren't really gonna risk their job in doing that.
It's very disruptive. They're risk averse. Yes, exactly.
Um, and then the next phase is purchase. I'm ready to buy. I've got all the references I need.
I've already spoken to industry analysts. I think the budgeting may make sense based on opex, but how do I justify it still? How do I, how do you help me with the SOW to go to, um, legal and finance to have that conversation?
So we help along that way, marketing along with sales. We have a job to do in every single one of those phases. Marketing, we create the narrative.
We educate the buyer with digital ads. Come see us at a city or near you, or come join a webinar to learn more. Sales has a play.
And cha our partners have a play as well. Absolutely. They gotta follow up on the leads.
When they follow up on the leads. What are their assets that they could use to have that engaging conversation to pull the buyer all the way through? Love it.
Yeah. I wish more marketing people were as well versed on this as you, because we always, for instance, we always try to tell our sponsors at Tech Junk, you want a customer that touched your content 2, 3, 4 times. Absolutely.
Or different pieces of content. Yep. Right.
Just a one time a hit and run. You know, it's, it's a start. But you need to educate them and you, It's constant education.
And you gotta write it in a way. I mean, look, in today's world, no one has time to read. Okay.
And so I like, for myself, I like, I, I like infographics. How many Friends? Infographics are great.
People love them. Yeah. Shorter videos, the social media.
Absolutely. I mean, this is the world we live in. That brings me to my next point, Nate, which is, everyone talks about ai, right?
It's all about ai. It's all about agent generative. And, and, and quite frankly, marketing is one of the biggest areas that is being, being disrupted.
Right? I have a lot of friends in marketing who are afraid of losing their jobs. Yep.
But they're not, they're not embracing it. So they could be a better marketing person. They're hiding from it.
Yeah. Which I don't think is a success formula, but as you sit here at the CMO, how do you see the role of AI transforming, inspiring, changing, Yep. Your go to market.
Yep. Um, one of the, one of the things that um, I always encourage everyone is continuous learning. Okay?
Think about yourself first. Um, how do you, as a leader, how do you create that environment to encourage your employees to develop new skills or maybe an area? You gotta have the courage.
You gotta have the courage to speak up. Say, you know what, that's something that I wanna learn more about. And I may not.
That's something what I really like about Qualys. 'cause we provide that environment, um, to encourage the employees to start learning things. When I think about ai, uh, what we're doing in marketing is, um, we're thinking about areas where, if you think about your job, you know, seven days a week or five days a week, just write down what are you doing every single day?
How much time are you spending on each one of these tasks? How much time do you spend thinking strategically versus executing ly, because you have to do both. Okay?
So just think about those things and then what would life be like if we can automate some of those things? You as an individual, you and your team, and then collectively as a marketing organization. And that's what we're doing.
We've actually implemented certain those areas. And plus the marketing organization and the structure is evolving. There are certain positions that are very instrumental that has transformed that I think that, um, you know, certainly could leverage a lot of ai, um, content creation.
We can all get better in every single function, whether you're in product marketing, content strategy, campaign development, um, communications functions, the growth marketing functions, field activation to the buyer, to the partner. We can all get better in, uh, creating more content. Customer market is a big thing.
'cause we have over 10,000 customers and we are constantly looking for happy customers who wanna share their story. So it's not cranking out 30 distinct pieces. It is about taking one anchor piece.
Like we have this great, um, threat research department. Mm-hmm. So that could be 40 pages.
No one has time to read 40 pages. So we, that's like a core anchor piece once a year. And we're gonna create derivatives of that.
And every quarter, some trends that we're seeing, maybe trends that we're seeing by vertical, and then we're gonna publish that. Customer stories could be, um, really simple. We interview a customer and then we can have AI interview and then translate that in five different languages.
That's Amazing, isn't it? The emails that we do for follow up pre, during and post events, and we have SLAs on this too. Um, and, and that's where AI can help.
Now, this is just marketing. You then take that same content for consistency, and then the BDR team can use the same AI tools for consistency, lead scoring, the nurture. You can also take that and feed that to your channel partners for the campaign kits.
So you now see the glue to tie the entire go to market into one motion. So those are the things that we're doing. We're just starting like in the areas that we really can add more, um, speed.
Get the flywheel going. Yep. I agree.
I mean, we, we, you know, at Techstrong, we obviously work with a lot of Right vendor, you know, sponsors. So we, we call that the long pole in the tent, right? That one report, that one report can feed a campaign for six months.
Yes. You could do a webinar from it. You could do infographics off of it.
You could do customer testimonials. And there, and, and with ai, really, you, you, I don't wanna say you're not gonna use a human, 'cause I'm not here saying AI's taking people's jobs. You need a human in the loop.
Yep. But with ai, there's really no excuse that you can't do these kinds of things repeatedly. Absolutely.
Over, over and over. And have more consistency than we ever did in, in marketing and go to markets. Right.
And I, I, I think the problem is a lot of people, quite frankly, are afraid of their jobs. They don't want to tell you what they're doing repetitively. 'cause they'll be replaced.
Yeah, I agree. It starts at, you know, I, I said a key word in, in terms of like leadership. Yeah.
I learned a lot of my leadership skills when I was at Symantec and, um, you know, John Thompson. Yeah. Yeah.
And, and so they invested heavily into leadership, whether you're a first line manager or a VP level and all that. But, um, I think about the core attributes and make a really strong leader, you know, and I think about creating an environment where you could encourage, um, individuals that have courage to step up. You know, like it's a okay to acknowledge what you do great at, right.
The areas that, you know, your core strengths, but also you've gotta create that environment that you can raise your hand. So you know what, I wanna learn more. And that's what we're trying to do here, is I think a lot of people just don't know.
How do you leverage ai? You know what I'm saying? Yeah.
Well, it's, it's still new and, and it's, and a lot of people are leading with fear versus curiosity. Let's call it as a CEO at my company, I, I've encouraged people to experiment. You're gonna make some mistakes.
It's gonna do some stupid things, but you're gonna learn more from that than you do maybe from just using it. But experiment, use it. Use it for video, use it for writing, use it for marketing.
Just use it and see what, what we can do it. It's, but I think that's an individual, like you said, how each individual looks at it. It's an individual choice.
I see it as an opportunity. It is an opportunity. Absolutely.
And I, and I say this a lot, um, by the way, I'm a big advocate of, um, women in the cha uh, women in the channel, women in in Cyber Uhhuh, women in tech and all that. And I sit on, on a ton of panels and talk about this topic. But I do say this because it's been a numbers game.
We know the statistics of women in tech has been, you know, it, it's like 22%. But Is it that high? I was, I thought 15 In tech.
And then women in leadership is, is single digit, right? Seven. So I say this, if you wanna get ahead right now, think about ai, think about something that you can learn right now.
Um, and then you can get ahead and, um, across your peers and everything. So I love it. I agree with you.
May a hundred percent we're about outta time. I want to thank you for coming on. You bet.
Good luck. Best of luck with Paul. We'll, I'm sure we'll be talking more 'cause we cover Quas all year round.
Super. Not just at these rocks. And, um, I'd love to hear more about what your experiences are with ai, with the go to market and with Rock.
'cause as I told Summed, what started as a user conference could very quickly become the, that tip of the spear for a movement around returning back to risk management and Security. Absolutely. We're looking forward to, um, next year's event here in the Americas.
Yeah. And um, you know, it, it'll be more open, you know, up, up to folks that are with our, with us or with not, you know, and that's, this is just the start of it. Absolutely.
Alright. Hey, we're gonna take a break. We are live here in Houston at Qualys Rock on, uh, we'll I think ne we're probably late 'cause we ran a little late, but, so we'll be back on in about two or three minutes.
Until then you're watching text. Hi everyone. We're back here live at Qualys Rock on inaugural rock on right here in Houston.
And, uh, you know, we've been having a great day of, of interviews so far. Let me introduce you to my next guest. His name is Jonathan to, yeah.
His friends call him jt, so I'm gonna take the liberty of calling him jt. Jt welcome. Thank you.
The text on tv. Yeah. Thanks for having Me.
Good to have you on, man. Yeah. Um, you know, I didn't even give him your title or anything.
I'm gonna throw it back at you. Why don't you share the camera right here. Okay.
Alright. Tell him about your title and, and give us a little bit of your journey to Sure. I don't want to give the cat outta the bag Yeah.
But how you got here. Sure. Uh, yeah.
Um, I'm the CSO at Qualys and, uh, you know, how did I, how did I get here is a, a long winding, uh, story. Probably like most, uh, spent time in the military as an intelligence officer. Um, you know, and, and, and that's, while it was not cyber related, right.
You know, there's enough overlap where you find this common interest, I would say, of finding the needle in the haystack. I mean, that's what threat intelligence and, you know, trying to find it. Uh, obviously I was dealing with like, human stuff, right?
But, but you know, it relates pretty well to cybersecurity. And, uh, you know, ended up, uh, just kind of going to that next career, which was an IT auditor. Uh, then I got into security operations, pen testing.
You know, I kind of just kept finding my way around and at some point someone said, you're, you're pretty good at managing people, so you should do that. And started managing people. Became the CISO for the state of Colorado.
Uh, so, so spent, uh, you know, over a decade with the state of Colorado, um, spent five years with Microsoft running the detection and response team. Uh, so primarily just responding to ransomware attacks and nation state attacks and, and, you know, really got back to the, you know, running large teams, but just technically deep, you know, engagements. And then, uh, summed gave me a call and said, Hey, I, he and I had known each other.
He is like, I, you know, I'm looking for a CISO and really wish you'd come back and, you know, help us on the future of the company as well. So I said, let's do it. I love Qualys.
Yeah. So listening to you tell your story, you know, it's a funny thing to grow older. Yeah.
I'm remembering we discussed this Yeah. In San Diego. Yeah, That's right.
You were At Qualys. Yep. You had gone Yep.
And came back. That's right. That's exactly right.
Right. And I remembered the Colorado story. Yep.
Yeah. It's all coming back to me now. Still Live in Colorado.
Do you? Yeah. Yeah.
It's good for you. Yeah. Try to Beautiful A to, To, so Yeah, it's, You guys had snow already.
We did, Yeah. Up in the mountains. Yeah.
I saw my, it's nice And I mean, honestly, it's, I love the weather. I love Fall Falls. Beautiful.
You know, I, I spent some years near Boulder, actually. I have a place in, uh, superior, right? Lewisville.
Oh, yeah, yeah. Absolutely. And I started a security company out of Boulder.
Oh. Called, still Secure, going back early two thousands. Yeah.
Um, so yeah. I I, it's beautiful. Yeah, it's beautiful there.
And it's a good, I feel like Colorado has a great security community. It just, a lot of people don't know about it. It's a little bit smaller than like Silicon Valley or, yeah, Well, no, whatever.
But it's not Silicon Valley. But you know, the, so I was there when the Boulder thing was really rocking on Yeah, right. Tech Techstar was launched.
That's right. You know, Brad Feld is a, a friend of mine and Brad, you know, Foundry and Mob. Mob.
Actually, my company was in the Mobius incubator. Oh, okay. Gotcha.
Yeah. Right on top of old Chicago there on 36. Oh yeah.
Great Place. But, uh, and so it was an exciting time Yeah. To be in that community.
Yeah. It really was. Yeah, it is.
Yes. Um, but JT let, let's talk a little bit about what's going on here. You know, it's, it's no longer the QSC, Right?
It, it, it's moved up, I think Yeah. From being a user conference for a vendor to a, a conference about Risk Operations. That's right.
Your job is the ciso Well, you have a lot of hats as the ciso, but one of your jobs is to talk to the boards Yeah. The exec teams at, you know, the literally thousands of Quas customers. That's Right.
Yeah. How is the conver, you know, I had this conversation with Ed. Yeah, Yeah, yeah, yeah, yeah, yeah.
How is that conversation like, Hey, I'm not here to talk bits and bites with you anymore. Right, right, right. Not gonna tell you how many major critical vulnerabilities you have.
I'm not gonna tell you how many intrusions you have or how many patches gotta be done. Right. I'm here to talk about risk management.
Absolutely. How's that play? Yeah.
You know, I, I think it's great for boards. Um, and I would say this started right when I rejoined Qualys. You know, I think, you know, we were using some old school, you know, kind of heat map, you know, very technical like KPIs and, and you know, it's always a little bit of a dance with board members.
But you, you know, there's a time where I just finally kind of sat down and does this make sense? Right. Are you, are you able to understand, you know, kind of the risk?
And, you know, we had a really good conversation that, you know, while a lot of it, they sort of got, they had a difficult time like piecing together how, if I'm making a budget request or when I present a strategy, you know, how was that tying back to, to risk and, and how we're measuring the risk appetite. And so, you know, we started from there and, and then really, you know, dug into, honestly a little bit of the parallel was working with my CFO and saying, okay, obviously, you know, you're also dealing with risk and financial risk and currency risk. And boards seem to always get that like, like, like they understand it or risk that you're not gonna meet some sales target.
Get it. And then really kind of the light bulb was, well, it all comes down to dollars and cents, right? I mean, board members are trained, like read the income statement, the balance statement.
And, and so, you know, the idea and, and, you know, working with Summed was, you know, we, we kind of need this, this financially minded like product that can translate to what a board or A CFO would, would understand, like what they're already used to. And, you know, so from there it was really just about, uh, quantifying the risk according to, you know, our applications and the assets that, that we depend on to run our platform. And, and, you know, it, it took us, you know, it took us a couple quarters to, to get it right.
But at the end of it, uh, the board was happy, summed was happy, and, and then he said, well, listen, I think we're onto something. Like, like you should go talk to others CISOs, and you know, we should, we should see how they're presenting today and see if this way of doing it is, is something that they would find valuable. And obviously it's been tremendous.
Just, yes, this is exactly what we need. You know, you're right. My board members don't always understand, you know, when I say, you know, we have a thousand critical, right.
What does it mean? Like, what, what should I do with that? You know?
So, so yeah, that's, that's kind of how we got here. It was kind of our journey with our board and working with other CISOs and um, you know, we still have work to do, but I think it is like we're really on to something and we're bringing it here to rock con. Yep.
Yeah. You know, one of the questions I asked Sum and I'll similarly ask you is, do you envision this conference being something bigger than just Qualys, where you'll have other vendors who are risk management? Yeah.
Even security risk management. That's right. GRC.
Yeah. You know, there was a time where the RSA conference was just about encryption. That's Right.
Yeah. It's obviously not anymore. Yeah.
And not just, and when I talk about that, I don don't mean it just at this conference, JT Yeah, yeah. I mean the, the industry sort of galvanizing around, Hey, we, we need to talk Yeah. Risk instead of critical vulnerabilities.
Yeah, Absolutely. I mean our, that is our goal and our desire, um, as part of the renaming and, and even if you see how we're like designing the tracks now there's business tracks. 'cause 'cause cybersecurity is a business problem.
Absolutely. You know, And I think oftentimes in the past we've just technology, technology, technology. And that's a component, but a huge component is the business aspect.
Yeah. You know, and so, you know, I think we wanna open this up and, and, and even like my internal teams and how we're organized, you know, we've gotta bring GRC together with security operations, you know, with all of the other groups. 'cause oftentimes we do work in silos.
You know, I mean, in your own team and, and, uh, Especially in security. Yeah. It, it's, it is one of the weirdest things that you, you know, and, and, you know, we're on the same team, but somehow you didn't share this risk because it wasn't your area.
It, it's a, it's a weird dynamic and we hope to break that down too. Right. It doesn't matter if you're GRC vulnerability management team doesn't matter quite Exactly.
Yeah. com in 2013 because I bought into that whole, some people say it's Kumbaya, but that whole thing of breaking down silos, right. Of bringing Dev together with ops.
And from my point of view, coming from security, I was like, we could bring security together with ops and SecOps. Yeah. You know, and Dev and I, I, you know, you could see a, a future where risk management becomes that unifier, if you will.
Right. Oh, oh, absolutely. That, that grand unifier across all of these different silos.
Yeah. Um, going back to your talking with your boards and CISOs mm-hmm. And exec teams, they're buying into this, right?
Yeah. They, they're, they understand and I think inherently they understand it. 'cause there's something inherently when you hear the story, you're like, duh.
Right. Yeah. I lost sight of that.
Right. Right. It's of course, it's about the risk.
Yep. Um, How do you, where, you know mm-hmm. Ai Yep.
It's Times person of the year or whatever. Right. How does AI affect this?
Where does it go from here with ai? Yeah. Um, listen, I think AI is, uh, we were talking about our friend, the Cloud Security Alliance.
It's what cloud used to be, right? I mean, I remember, and, and maybe I talked about this last time, but I still remember New is the CSO for the state of Colorado. This is many years ago now.
Um, and the CIO at the time said, we're gonna go cloud first. And I can't tell you what the uprising was, both in our employees, other executive, the cloud's the worst. It's gonna ruin us.
How on earth are you gonna share your, I mean, and, and it, you know, it was my job to help settle that down, really get to the real risk of it. Yep. But I feel like we're right there again, with ai.
Um, and for those that maybe didn't live through that experience of the cloud may feel new and scary. Uh, but honestly, I think we're in the same boat. Listen, we need some frameworks that we can all agree to and work within.
Um, you know, we need to be able to manage the risks. Absolutely. There are risks involved.
Um, but once you really get into ai, and, and this, you do need to get into the technology, right? You need to really understand, you know, what is an MCP server and why, how's it coordinating the calls? And it takes a little bit to learn it, but it's not like any other, same as any other technology.
It's a tool tool. At the end of the day, I tell people this. Yeah.
Especially younger people. It's a tool. It's a tool.
Humans are great tool use. Yeah. That's what's made us Yeah.
Reach if you think we've reached a height of civilization, but, right. Um, but you know, it's from being tools. It'll be interesting to see how it plays out.
Yeah. It's gonna be a fun ride. I mean, I have no doubt that it's gonna be a couple of interesting years and we're gonna have a few bumps in the road.
I'm sure that, uh, there'll Be learning experiences Or, or gonna be learning experiences. That's right. Alright.
Yeah. Jt, thanks so much, Matt. Thanks for having me.
Jonathan, tell CISO here at Qualys, actually, to be fair, you, you have more than just CISO in your title. Yes. Yeah.
SVP Customer Solution Strategy as well. That's it. We're live at Rock On.
We're gonna be back. We got more for you today and a full day tomorrow. You're watching Textron tv.
Hey, everyone. We're back here. Live at Qualys.
Is Rock on Conference in Houston? We are, uh, we've been going all day on this. I hope you've enjoyed our coverage.
We'll be going for the rest of today through tomorrow. Well, we will take a break tonight, but we'll be back tomorrow with a full day. Um, for my next guest, I'm happy to have back, we, we actually interviewed him last year, if you remember, at the qua security conference.
I want to introduce you to Maya Ash. Ari, I get it. Yeah.
Thank you so much for Thank you. Having me here. Mayesh, it's my pleasure to have you here.
Um, as I mentioned, we, you were here with us last year and, you know, different one may say a different, uh, a different, uh, conference name, but still, nevertheless the same kind of stuff. Um, Maresh, let's start with this. Why don't you introduce yourself to the audience, give them your role here at Qualys and maybe a little bit of your background.
Certainly. So Mare, I lead the products for enterprise true risk management here at Qualys. I'm the VP of products there.
Uh, been in the cybersecurity industry for 25 plus years and really came to QS to drive this strategy of transforming our business towards really this holistic risk management strategy that we have defined back in San Diego. About a year ago when we first met, uh, we had just launched the availability of enterprise tourism management. And since then we have seen tremendous success in the market industry.
Uh, there are over hundreds, uh, plus customers who are using the solution now. Millions of assets and findings being tracked and managed within enterprise tourism management. So we have seen a phenomenal adoption of the solution in the industry.
Absolutely. Absolutely. Um, you know, my, I've had a year to sort of percolate on this, as I'm sure you, you've had some time.
I, I think inherently there's something appealing to the security teams of the world that say, Hey, instead of measuring how secure we are or how good a job we're doing by how many vulnerabilities we, major vulnerabilities we close, or by how many patches mm-hmm. We, we applied or, or, you know, some kind of metric like that, that were actually, uh, translating our risk and security to dollars and cents to the organization. And that that was always sort of a missing translation.
That's right. Right. It's like at some point we decided, look, to secure the house, we have to lock the windows and doors.
Right. So we gotta lock all the windows doors. Well, for the last 20 years, we've just focused on locking all the windows and doors.
That's right. Almost forgetting that we were doing that to secure the house. Right.
I had this conversation with earlier, earlier to, to me, this whole concept of, of risk operations of Iraq, true risk gets back to why are we locking the windows and doors? Precisely. Yeah.
What's so valuable that you wanna protect Exactly. And, and if it's not so valuable, maybe we shouldn't be jumping through all these hoops for something that's just not valuable. Exactly.
Exactly. So, you know, uh, for security professionals understanding, uh, what we are protecting is equally important. Not just that controls that we are using to protect our organization, but actually the value that is at risk, you know, it is critical for security professionals to really understand that.
And that is essentially the risk driven approach towards managing the security controls. There are two parts to security, the reactive and the proactive. Right.
You know, uh, the reactive side is mostly, uh, a wartime exercise. And there is a proactive side, which is the peace time exercise, you know, which is, uh, more about cyber hygiene, making sure that those doors and windows are locked. Right.
You know, it's not an active burglar or a thief that is trying to break in. It is really more about every night before going to bed, you wanna make sure that all the doors and windows are locked, right? So, uh, these functions are sometimes, you know, independent, the personas, the people who are actually dealing with these situations are different people, you know.
So, uh, risk operation center really allows, uh, the proactive security folks to really take into consideration every single, uh, risk telemetry across your entire attack surface and really distill it down to a, a, a scoring mechanism that would allow you to understand the actual risk that you might face by not having a certain door or a window locked or unlocked. Love it. You've had a year to play with this now, or to think on it to grow with it, to, you know, get comfortable with it.
That's Right. What is your, like what's your, what what's been your learning from last year to this year? Yeah, um, great question, by the way.
So what I really see is, uh, you know, CE programs are evolving. You know, we all started with, um, vulnerability scanners. You know, these are like two decades ago now.
Vulnerability scanning was sort of, um, a year, uh, you know, migrated or I would say, uh, upgraded towards risk-based vulnerability management then came along CE programs. Uh, and now what we actually see is CT is just one part of it, but there is an adjacent area, which is, um, uh, you know, CRQ cyber risk quantification, right? Or think of, uh, automated compliance.
Those are all coming under the same umbrella. Right. You know, and risk operation center sort of provides that function, a single pane of glass to support all of these different use cases.
As part of this, uh, journey, what we have also seen is there are, uh, typically three independent teams in any large organization and infrastructure security or vulnerability management team, cloud security team, and the application security team. Each one of them has tools of their own choice. Yeah.
Uh, you know, programs of their own processes of their own. We see more mature organizations sort of putting them under a single framework for holistic risk management. And that is essentially a definition of what a rock is.
Yeah, absolutely. Uh, you know, it's always been an issue in security, right? The average organization, depending what study you listen to, 36 different products, 60 something different products, it's impo, it's hard enough to do security.
Just security's hard to try to manage 50 plus different security products and make them talk to each other and work together. Yeah. I mean, it, it, it's kinda like a tower of Babel, right?
When no one talks the same language when we really should be talking the language of risk. That's the common language here. That's right.
That's Right. Yeah. One thing that we didn't really touch on last year, probably too much, was this notion of ai ai.
Hmm. It's been the story though, and continues to be the story. That's right.
So, um, and, you know, agent AI capabilities are also, uh, pretty rapidly evolving. The fuel for agent AI is really the data. And what we have also seen now is cybersecurity is also a data problem.
Like you rightfully mentioned, you know, there are dozens of tools. What are these dozens of tools doing? They're actually generating telemetry, risk telemetry, you know, I oftentimes call most of the security posture management solutions as point and shoot weapons.
You know, it is almost like a weapon you pointed at an asset. And out comes the list of findings, right? But what do you do with that finding?
That is data, that is raw data. That data needs to be, uh, consolidated, correlated, uh, you know, overlaid with additional intelligence that you need to, to make sense of. And we really see now, uh, such aggregated dataset as almost like a digital twin of customers infrastructure that you can use for, uh, querying so that next time you have a celebrity vulnerability, you know, you're not chasing 10 different dashboards, exporting data, correlating them to understand the exposure.
But you already have this centralized inventory, not just of your assets, but the risk telemetry as well, which can be, uh, you know, uh, deployed to understand the exposure. Coming to agentic ai. Agentic AI is really interesting because, uh, it's not just, uh, um, uh, you know, generative ai like prompt driven interfaces, but there is an action associated with that as well.
You know what, uh, DKI really promises is autonomous decision support, which is what security teams lack today. You know, uh, over the last decade, we all have had, um, uh, you know, workflow automation. Now, agent DKI should not be confused with workflow automation, which are, uh, you know, predefined rules that you simply want to orchestrate, right?
Uh, that has been there in the past. What Is, to me that's more like BPA kind of stuff. Precisely, precisely.
With the agent. TKI, what we are actually bringing to the front is, uh, autonomous decision support with ever changing threat landscape with newly discovered findings and vulnerabilities are these cyber risk agents in a position to make a decision and suggest a remediation strategy that you can implement at scale, so that you are not, uh, employing humans to really match the speed of detections, right? Uh, as opposed to, uh, uh, you know, having, um, uh, cyber risk agents actually perform some of these tasks, offload it to the, uh, AI as systems, and really have humans focus on those advanced critical areas that, you know, a agent AI is unable to process.
I love it. I love it. Just wanna look at our notes here, my Maria, and make sure we, we've covered, um, I, I think, look, looking at this, I want to return back to rock.
Look, it's new, it's a new concept. Well, it's an old new concept, right? Risk management, but you're asking companies to change.
Change is never easy, Never easy, Right? So, how are, like when you talk to customers, how are they operationalizing this change? Right?
They may buy in, it sounds great, I'd like to do it, but how do I get there? Yeah. So you the great point, by the way.
So, you know, in theory it all sounds great, uh, but also what's happening behind the scenes is that, uh, customers were all trying to implement a rock without calling it a rock, right? Right. Um, I haven't seen a single, uh, fortune 500 that do not have a cybersecurity data lake.
What they do is they manually export the data from each one of those cybersecurity posture management tools, dump it into the, uh, security data lake, try to stitch it somehow. Uh, and these, the, these activities are all performed manually, right? So it's not like a rock didn't exist in the concept.
It is now that CO is actually bringing it to the forefront that you really don't need to build this in-house on your own, right. You know, in a cyber segregated data lake. But, uh, time has come for, you know, a commercial solution to really address this burning need in the industry, to consolidate the data, make these tools speak the same language, and really make sense of this fragmented data that resides in our organizations.
Like I was mentioning earlier, three programs, vulnerability management, cloud security, and application security. These are all coming together. And, you know, these three programs actually employ dozens of tools.
Just take into consideration application security. You have got static code analysis, SCA infrastructure as code, dynamic code analysis, pen testing tools. Right.
You know, so This Is an ever-growing number, right. You know, and how do you make sense of it? Because vulnerability in a code will eventually make its way into production, and that production application is gonna be deployed on a server somewhere.
So you need to have a com comprehensive view, not just code to cloud, but also the infrastructure that that application is deployed on. The only way to have this holistic view is by bringing this data together in a risk operation center. Whether you call it a rock or not does not matter.
Right? What you're doing with the data is the other name. It Still smells the same.
Yeah. It's a quote Shakespeare, huh. Anyway, Mar Rash.
I want to thank you for coming on and talking with us today. Continued success. Keep us posted.
Let's not wait till next year to see to talk more with you. Maybe we could see you, I don't know. We'll be at RSA in March.
Yeah. Or yeah. Some of security conference or another.
Absolutely. Thank you for all you do. Thank you for so much for having me.
All right. We're gonna continue live here at Qualis Rock on. You're watching Techstrong tv.
Hey everyone. We're back here live at Qualys Rock. On my next guest is Iran Lne.
If you've watched our coverage of past Qualys, uh, who's qualis security conference, then you've seen us interview Iran before, he's delightful guy to talk to. Smart. He works in the Qualys endpoint remediation division or section.
Iran, welcome back to Tech Drunk tv. It's good to see you everyone. Thank you very Much.
So, well let, let's talk a little bit about you first. I probably asked you this last year, but I'm gonna ask you to repeat it. Tell our audience, how did you come to be where you are here at Qualys?
Uh, I, I, I had my experience in security goes way back. And basically five years ago, it was actually really interesting, five years ago, our current CEO, which was the CPO back then, right? Uh, hired me to help him build our remediation arm.
So basically he had a great idea. Let's have a vulnerability, uh, solution. Also help our customer not only find all those vulnerabilities, they'll actually solve them.
Now, what's interesting is, back in the day, nobody believed that it's even possible, right? Vulnerability guys are doing vulnerabilities, security, and IT guys, it guys and all second, right? Security guys don't do the patching.
Never do patching. No. And fast forward five years and basically we were able to build a, uh, an amazing solution and have tons of customers.
And I dunno if you, you know, but a month ago, I think GIG released their rather, that compare other patch solution. And we're one of the top leaders really in this squadron Yeah. Compared to literally every legacy solution out there.
So we are very proud of the journey that we had in the last, uh, five years. I'm proud of, of what you've done in the last five years too. Thank you.
Right. As someone who, uh, I think I told you this, I had founded a, a cyber, we called it InfoSec Company in Boulder, Colorado in 2001. We came out with a vulnerability management solution in 2003.
And we, we, we created, we spent a fortune, a fortune on a workflow, took the vulnerability what needs to be done, and we tried to get it to order me. People, people wanted to shoot us. Yeah.
They did it. They wouldn't, no, no, no, no. Different different team.
You gotta go get them. I remember I went to, uh, at the time it wasn't called Citi, I think it was called Citibank or, you know mm-hmm. But it's Citi today.
And I met with one of their three global CIOs and I said, why wouldn't you want to do this? And he said, look, it takes us 90 to a 120 days from the time we receive a patch until we fully test it and implement it. Yeah.
Because we won't patch something. 'cause it's liable to break something worse. Than's already broke.
Yep. Which to me made no sense. But that was the state of the world dead.
The fact that you are having this success means the world's changed. The world has changed significantly. And during these five years, and I can tell you five years ago, your story was 100.
You know, 100% to the point. Now, because everything happening in cybersecurity, we can see more and more security team either taking control and actually those are the guys that click the button or what they're doing. They use tools.
Our tool, or I cannot vouch for other tools, but use our tool in combination, what they have today. So we basically it are using our tool to help them get better result, replacing or not replacing what we have. Because Quas was never about, let's get rid of all the IT solution out there.
We don't, we don't compete with them. What we are trying to help you is fix the risk or help you with the risk. So the security team get a tool that can help them fix the risk and they can show their IT counterpart how to do that, how to simplify this entire process.
But that's important. It's part, we, we build it as part of the IT team's processes. We're not asking to do anything new, just making the life much, much easier and sharing information between those two teams.
And it just made sense. Absolutely. And now our security cameras are the ones that are helping us push it to the IT team or not push it work together with the IT teams to get this thing happen.
That's a huge change in last Year. Absolutely. It's a, it's monumental.
Yep. Really. But you know how business is, what have you done for me lately?
Since last year? AI is everything. Yep.
We're, we're autonomously doing stuff. Now we have autonomous agent, agent ais, generative ais, everything. MPC servers.
How is this? I mean, one, they say, look, this is great. This takes us to the next level.
Now we could, you know, in a workflow kind of way, just really automate the heck out of this. Mm-hmm. What are you seeing?
I tell you the truth. I spent a lot of times when, when the inter start, you know, the bus started like a year ago, a little bit more trying to figure out what I can actually, how I can actually use AI to actually provide value. Because back in the days, if you remember, two years ago, one and a half years ago, everybody was building like a, uh, chat, chat, Chat, chat bot.
Chat bots. Exactly. Just doing chat.
Same thing they can do today with a click. Just let's do it to chat, because that looks better on, uh, you know, that's a great marketing. And I, I didn't, I didn't follow that route.
I, I want to find something that I can actually use AI and accomplish something that I couldn't do before. And one of the things that we are actually releasing now in Q4, is we use AI to do what it does best to make sense out of tons of data. So I'll give you a great example how, how we're using it.
One of the biggest problems every customer has cross the board IT and security is, and actually that's the main reason why people are not patching or people are not taking actions. The main reason is, as you said, the fear of something breaks. Remember you gave this example, your example was 120 days.
It takes for, right. The reason is they're afraid if something breaks, the bank was afraid that some money generating application will stop working. How we trying to solve it is we trying to increase the confidence of those guys, of the IT guys that if you deploy the patch, you don't have to worry.
Nothing's gonna work, nothing's gonna break. And the first step that we are taking towards this amazing goal that we are investing heavily on is helping the customer understand if there's already a problem on this specific patch. The entire internet is, you know, there's tons of chats in Reddit and in Twitter and all over the place now we use AI to check all this information.
All the, literally all the internet using our proprietary algorithm to, so we need to know where to go, but we summarize everything and we basically give a score, what about this patch? If you deploy this patch based on everything that we saw in the internet, can it go wrong or not? And if it does go wrong.
So it's not just good to tell them, Hey, don't deploy theirs. We, we actually find, I don't know, 10% of the patches do have a problem. We also offer mitigation.
So if you cannot deploy the patch, because we know it'll break something, we give them alternative. So instead of deploying the patch, you can deploy this thing that will reduce the risk without the need to deploy the patch. So we're trying to tackle two things, predict if something will go wrong, but also give them alternatives.
Again, trying to help them solve risk. That's our goal. Absolutely.
When do you think agen AI becomes the norm? The default in, in these remediation patches? I think that most vendors are working on that right now.
I think that in the next year, not not long term, I think it's very soon within The year. Yes. But the problem with the gent ai, everybody defines it differently.
Okay. What I'm talking about the gent ai, I'm talking about how do we help our customers do two things. First, be able to predict better and be able to, automation is different because automation and civil and all those guys are solving the more automation complexity.
They've Been doing it forever. But what I want to do is I want to help them. If something goes wrong, how do I recover quick?
How do you back it, Back it out and scale. When we have a customer with 10, 200,000 devices and a patch failed on 50 K, this, This is the CrowdStrike. That's exactly the CrowdStrike.
And you need to fall over and you need to be able to roll back and fix these things as soon as you can. 'cause you have a very short maintenance wind Yeah. That you can operate on.
Absolutely. That's where I see the biggest, uh, uh, contributor of, uh, agent. Let me ask you a question.
I'm talking now for all the people out here who work in either cyber or it, but they're patching, they're remediating there, and they look at this and say, it's gonna take my job. Maybe I, I don't think it'll take the job. That's my personal belief.
First of all, the tool that we currently build are helping them do their job better. And I think what will happen is instead of them being able to deploy 10 or fix 10 vulnerabilities, they'll be able to fix 1000 vulnerability in the same maintenance window that they used before. Which mean the same person now is gonna go and do much more.
But you still need this person. You still need the human, The AI will do more, but you still, now it's in scale. So the person will need to, to be able to manage much more in the same time.
Okay. Using ai. Excellent.
Iran, besides ai, what else do you see coming down the pike for, uh, automated remediation? So one of the cool things that we're working on, except if we're building tons of features to make the product better, you know, and help our customer life easier. And, but, but one of the big thing that direction we're taking, are you familiar with our ETM vision?
Right? So we basically take data from other vendor and we can give you one picture of all your risk. Yep.
What we're doing, we are actually opening to, on the other po uh, direction, meaning once we find this risk, my goal again, to help you solve the risk, if you have an IPS in place, checkpoint Palo, whatever you have, and that thing can all already mitigate vulnerability that you have on an asset, we are gonna help you do that also. So even if you don't use the Quas agent, you don't use quas. We'll do the matching, we'll do the mapping and allow you to use other incumbent solution that you have to combat and reduce the risk.
Okay. And that's a huge, huge project for us because that basically makes it, it lives much easier. Now, if you cor sorry.
If you correlate that with the risk risk prediction that we have, you can figure out, oh, I have a risk here. This patch may cause problem. Let's use my IPS to reduce the risk until I can fix the patch or the environment.
Sorry. Please. I love it.
The ETM is is out now? I think now. Yes.
It's out now. Yeah. Yeah.
Alright. I think we covered just about everything. Yeah.
It's good to see you. It's good to see progress. Let me ask you one other thing.
Yeah. Please. What do you think about calling the conference rock on versus, oh, I like It.
CI like it. It's, it's changed. It's hard for us to get used to as Quas members that been doing it for some time, but I think it's a great idea.
Me too. But that's where we're heading. It's good seeing, seeing you Iran.
Let's not wait till next year. Hopefully we'll see you before. Yes.
Alright. Iran, Liv Nay. He, he runs the endpoint remediate.
I don't know what your official title is, but I know he's the endpoint remediation guy. I'm the Remediation guy. Help our customer fix things.
Abso the fixer. We're live, we're at Houston Qualys. Rock on.
We'll be back in a minute. Hi everyone. We're back here.
Excuse me. We're back here live. I hope so.
Um, at the Qualys Rock On Risk Operations Conference and continuing our coverage from, well, it's day one of the conference, but there's actually been two days of security training prior to this. And I, I heard from my friend, Qualis security training was standing room only sold out. Y you know, there's 400 people here, I think something like half or more signed up and took the security training as well.
So kudos to all of those people who are upskilling themselves and keeping current with the greatest stuff. Speaking of upskilling and keeping current with the greatest stuff, let me introduce you to Christie Looter. Mm-hmm.
Did I get it right? Yes, You did. Christie is with HCA, but we're gonna let her tell her story beyond that.
Christie, welcome to Techstrong tv. Thanks for coming on. Thanks For having me.
Our pleasure. Um, introduce yourself. My name is Kristy Schluter and I have been in healthcare it for over 25 years.
Uh, I started out as a hospital technician that did break fix for the nurses and the doctors. And now I am managing a vulnerability, uh, management team for HCA Tough job. Yes.
A very tough job, but a lot of fun. Yeah, it is. I, uh, yeah.
I told this story before I, I had started a security company outta Boulder, Colorado in 2001, co-founded in 2003. We came out with a vulnerability management solution. It was so eye-opening for me going to all these customers.
You know, we never said it publicly, but in the office we used to call it the bad news generator because all it did was generate bad news and people would get, you know, they were never thrilled. But, but back then it was a different world. We would scan once a year and we'd give you like a phone book.
And I, you know, I said phone book the other day, Christie and I realized that half my audience probably has no idea what I'm talking about. But Anyway, phone books were these big fat books that used to get delivered to your house every year, the Yellow Pages and so forth. And they were this thick That's about how thick Oh yeah.
Yearly vulnerability. I remember 'em. Yeah.
You remember. So, but of course it's changed a little since then. Back then we, you couldn't even talk about automated remediation.
Right, Right, Right. Everything. I, you know, I, I remember going to one of the top, like a top Fortune five, fortune 10 company, a big bank.
Mm-hmm. You know, Microsoft Patch Tuesdays. Oh yeah.
Right. It would take them 90 to 120 days to roll out a patch Wow. From Patch Tuesday because they said they'd rather live with the vulnerability than potentially break something else.
I never got it then. I don't get it now. But I think the world's changed a little bit.
But, um, you know, we, I forgot. HCAI think most of our audience is familiar with HCA, but they're probably one of the biggest medical services, health services Yes. Provider in the country now, aren't they?
Yes. We're one of the largest healthcare companies, uh, in, in the world. Uh, we have 190 hospitals and over 2,500 points of care facilities.
So there that's a lot. Plus we have Gayland College, Including WebMD down my way in South Florida. Right.
They always make a big thing. WebMD an HCA affiliated Company. Yep.
Um, but all getting aside, you know, being a healthcare company provider has its own set of challenges from a security point of view, because HIPAA becomes a real big consideration. PII, you know, the date or, well, You've also got GDPR because we're in Europe, so we have to abide by regulations too. That's So you are what we call a highly regulated industry.
We are. Right. There're few for justice.
But, um, you know, talk, you've been in this a while now. Yes. Talk to us about the evolution of how you approach vulnerability management.
Vulnerability remediation. I assume you use the Qualis solution. Yes, we do use Qualis Talk.
Talk to us about how it's kind of changed over the years. Well, Over the years, uh, you know, things have changed. The landscape has changed.
And, you know, not only do we have to be careful with patching devices, but we've got medical devices that are connected to patients. So it's very important that, you know, we test and we make sure that everything is validated before we roll it out to everything. So the zero days, I mean, there's a lot of work behind the scenes in order to get those vulnerabilities remediated, because you have to test because patient safety is number one.
Yeah. So give us an idea. You know, so when I was doing this a hundred years ago, right?
We didn't have threat intel and we didn't have some of the research labs, like the Qualys security research team mm-hmm. And stuff like that. How do you, is it just purely testing a patch on a machine?
Or do you kind of take the holistic view of looking at the whole, Well, you need to look at the holistic view. 'cause you need to see where, where the threat attacks could happen. Seeing all of those doors and being able to work with different cybersecurity teams to, to help you prioritize.
It's not just how bad is the vulnerability, but if somebody were to utilize that, what are the steps in? So making sure that you look at all of those points, bring those in, and then also work with your executive management. Absolutely.
Um, what about remediation? Are you using the automated remediation yet, or no? Uh, Not really.
Uh, we have a a a whole team that is just dedicated to remediation. Yeah. I, I, I think being in a highly regulated industry, it's, it's a bit of a, it's maybe a hill too far or hill too high, I guess is the word for you guys at, at this point, Christy, I wanna ask you about ai.
Okay. Right. All of a sudden, this past year, now everybody's using ai.
Yeah. Everybody Bud's word. Yeah, it is.
So how, how is that affecting your team? Uh, it's, it's got good points. It's also got some scary points.
Uh, but our company has taken the approach of we're being very cautious and making sure that we do this right. Mm-hmm. So it's more of measure twice, cut once.
So that's the approach that we're taking with ai. Excellent. So is this your first Qualys conference?
It is not. You've been, I, yeah, I've been several times. But it was all before COVID.
That was when it was, uh, Qualys Security Conference. QSC. Yes.
Yes. So now of course, it's Qualys Rock Con. It's about risk operation.
Right. How has the emphasis on managing risk versus just blindly patching everything or, you know, scanning and making your list and checking it twice? How has that changed how you guys approach vulnerability management?
Oh, yeah. Yeah. Oh, it, it's a industry standard.
I think the whole industry is going towards that, what we call exposure management slash ctm, uh, continuous threat exposure management. Yep. All of the industry is going that way.
And I think, you know, just Qualys is getting in line with that industry standard. And I think that it's the way we're all going. You know, I, I was, I was talking to the Quas, CEO summed mm-hmm.
Earlier today, and he said, you know, you can't just keep scanning and finding more vulnerabilities and fixing more vulnerabilities without recognizing what's the financial impact. Right, right, Right. And does it make dollars and cents Right Now, in the case of HCA, again, highly regulated.
You do have other things to worry about. Exactly. Right.
And sometimes it does cost a little more money Yes. To protect people's PII and so forth. Right.
But is that financial kind of analysis being done here at HCA, you think In terms Yeah. Oh, Yeah. Yeah.
It's definitely been done have to today's world. Yeah. Yeah.
No, No one has that kind of, you know, you can't just Yeah. You try to fix it. You definitely have to put that in there.
Yep. Um, so one of the questions I've been asking people is, I think people in your position, CISOs, executives, managers, they understand that in order to, to get budget to convey success or failure to talk to business leaders, you need to talk the language of risk management. Correct.
But many people on your team that you manage, they're security people. Right. They talk, this is a major CVE, it's a minor CVE.
This is, you know, they talk bits and bites. Yes. Not risk.
How are you, are you telling them, Hey, you gotta learn a new language? I, I'm not really telling them that, but they're also seeing things change. So they are getting educated.
So they are reaching out. Several of my team members get educated. They're taking classes.
They're constantly staying on that, uh, education and just making sure that they're keeping with the landscape. So, uh, yeah. So they're, they're training themselves to actually be able to talk the language.
You know, we talked about ai, it's not just us who are using ai. The bad guys are using AI too. Yes.
This year we've probably seen more vulnerabilities, more attack. We see more attacks every year, but we're seeing more attacks, but we're seeing more attacks that are AI assisted, let's call it. Right.
How's that affecting you and the team? Uh, it's definitely causing us to be more aware and being able to kind of look at our thread and tell, and also work with our other cyber teams at HCA and making sure that we're all on the same page and we're seeing the same things. Because, you know, the different teams have different access to tools and all coming together.
Collaboration is key in any security program. Is it? Is, it is.
Um, what about in terms of, so vulnerability, one of the things, let me back up. One of the problems we, we've always had in security for as long as I've been in it, is we have silos. These people, the vulnerability management team, that team is the, you know, identity and access management, and then this team's endpoint security.
And, you know, there's all these different silos. How has, like looking at it from, let's call it a holistic WR risk management right point of view, allowed you to maybe work close more closely or maybe not. Yeah.
It's time to tear the silos down. And that's what we are working on. We're tearing those silos down and working together.
So it's not just, you know, cybersecurity working together, but you also have to work with it. They're the ones that knows those devices the most. Yep.
So being sure that you're staying, you know, walk step with each other as you are going through these processes is very, you know, very important part of it. Great. One last question for you.
Sure. So plans are to do more of these Qualys racon events mm-hmm. In the US all over the world.
Right. Along with the training mm-hmm. Which is free if you come to the conference, the training, the day or two before it's free.
Because for your peers in security and security people out there, what's your advice? Like, is this a must attend show or Nice to Oh, yeah. Yeah.
I think it is a must attend because if, if you're using these type of tools, it's important to know how they function and coming to these things and getting more skilled at using the tool so that you can go back and make sure that you are doing everything correctly. And, and just the most important thing is the networking. Understanding how other companies are using things That peer-to-peer stuff.
Yes. That is, and that, and that, that's insightful because it's not something you hear, you know, they talk about a session and they mm-hmm. But it is the networking, the water cooler Yes.
Session, so to speak. Yes. So they don't really have water coolers anymore.
Uh, but the water cooler sessions are, are where it's at. Yes. Yes.
That networking is just a valuable piece. Fantastic. Hey, I want to thank you for coming on.
I know it's not, you know, you got to do your thing and you're here busy. I appreciate it. Mm-hmm.
And keep up the great work at HCA. My PII is in there, so keep an eye on it. Okay.
Will do. All right. We're live here at Qualys Rock on.
We'll be back with more coverage of, of our first day of coverage here. Stay tuned. You're watching Text on tv.
Hey everyone, it's Alan Shimel and we're back here at Qualys Rock on in Houston. Of course. Rock On is risk operations, uh, conference.
And we're here to talk a little risk operations with y'all. Let me introduce you to Lesh. Yeah, you got it right.
All right. If you've watched our prior coverage of prior Qualys conferences, like the Quala Security Conference, QSC, you've seen Sheesh talk with us before. But Sheesh, most people probably, if they did, they don't remember.
Tell us about you, your position at Qualys, a little bit of your journey coming here. Yeah, absolutely. Thanks so much for having me.
Again. It's always a pleasure to talk with you. Mm-hmm.
And your audience so quickly, Shelly Charle, I look at the products, go to market strategy and now solution architect team for Qualys. My job is essentially to make sure that what I'm hearing from customers is translated as product capabilities, and then see to it that our teams are working with customers in making these capabilities mapped to their use cases and they're successful. Absolutely.
You know, Shilesh, we've done a lot of interviews today and a lot of it obviously around managing risk mm-hmm. And risk operations. One of the areas I wanted to you to expand on was, this is more than security, right?
This is about more than security. Part of this whole reason to, to do this is to map the risk and, and the, I don't want to just take it to dollars and cents. Yeah.
But to wrap, to, to map the dollars and cents Yeah. Of this risk Yeah. To business operations and how, not just security remediation, better vulnerability management, et cetera, how not just security, but all kind of business operations Yeah.
Plays into this risk, right. Risk management. Yes.
So, talk, if you don't mind Yeah. Talk a little bit about, you know, mapping that. Yeah, absolutely.
I, I think one of the parts what, uh, risk Operation Center does is trying to move the conversation away. Like Sumit talked about it from how many vulnerabilities do I have, or how many patches do I have? Or do have I implemented MFA, et cetera, to actually what is the impact of me having less number of vulnerability on business operations and the business value.
Now, how we are looking at doing that is essentially seeing that, you know, one on one side of the spectrum, like you talked about it, that there are business operatives or executives, they want to see everything from what's my dollar value, what's my business impact, how much I'm spending on cyber insurance, and what is impacting them. Now, what impacts them is a simple checklist. Is my patch management policy effective or not?
Is my ransomware prevention working or not? Is my permission management working well or not? Now, what we are doing bottoms up with our security audience is to not get overwhelmed with this dollar value.
And all these policies, we are bubbling up the contributing factors of this true risk, such as if you have, let's say 10% of ransomware vulnerabilities, then look like Mr. Customer, you could be in your cohort of lower 50% of customer base. That would mean when we compare all of these cohort of insurance policies and the breaches related records look like there is a 10% chance of you getting a material breach.
And that means your patch management or vulnerability risk management process is of lower maturity. So that's why your true risk needs to come in, in 200 to 300 range, so that all of these upstream systems will provide the result to your executives how both of improvements would result into me having lesser chance of a breach, lesser chance of me losing money. So that's how we are trying to tie the cyber risk and exposures to the higher level dollar value and its impact.
That was the best, uh, explanation we've had today. So you win a prize for that one, you Know, that that's one chance of looking into products and actually owning that area, I guess. Yeah.
Good for you. Um, you know, Sumit and his keynote today mentioned a phrase that I laughed, actually, I spit my coffee out of my mouth, but I told him I'm gonna steal it and use it. Sure.
And that is this, uh, dashboard tourism. Yes. Right.
Or dashboard terrorism even too. Um, you know, and that is, everybody has their own unique view on a dashboard, right? Yeah.
Yeah. And so whether you're on the security team, the executive team, the dev dev team, the ops team, the DevOps team, right? We are all, we're all looking at different views of the same underlying data.
Yeah. And, and I think it becomes like, uh, it's almost like a Tower of Babel where we all talk a different language. Yeah.
And I don't understand what you talk about, but you people do it. My people understand what I talk about, but not what you talk about. And you know, I think part of the, of the mission for for Rock Yeah.
Is to make sure we're all talking a similar language. Yes. An understandable language.
Yes. Right? Break down the silos that exist even in security.
There's so many silos, let alone once you go outside of security. Yes. Talk about that mission.
Yeah. That, that's interesting. Alan, you said that at the end of the day, I, I know there was, was really well put by Sume, you know, as, as an interesting witty command.
But at the end of the day, if, if you see the psyche behind the dashboard is also about why am I creating it? 'cause if I don't create it and track it, there's something I'm gonna lose. But that's something is very, very me centric or my team centric or my org chart centric.
If you have to see even the dashboard, what we are trying to say is how can you actually see the dashboard which all of your company cares about, all of your organization cares about? And that's where I think what you are trying to say also, what is the common language, right? Which is set by your whole of your company.
And though the dollar value and the business impact is generally used as common language, there's still nuances, right? Like the public sector might not care as much as for the dollar value. What do they care about?
What's the risk to my mission statement? And I was meeting with one of the, one of the really high profile customer in dc What they care about is my mission statement is I need to manage the risk to my agents who are in the field. 'cause that's, there's no dollar value which can be assigned to their safety.
So now how we look at it, okay, if you wanna manage the risk and reduce that risk to your agents in the field, what are the contributing factors which make this as a risk? So now how we help these bottoms up approaches of the security analyst, let's bubble up those dashboards. Let's see to it how your dashboard now maps your company's dashboard and can we actually create one unified way to track it down?
And that could be, you know, from your dashboard, how well your company's mission statement, your business value is tracked. So that's how we are looking at, you know, creating a bridge from me-centric dashboard to whole company-centric dashboard. So all of us talk the same language, essentially.
Got it. Excellent. Let me bring up another.
Sure. Okay. So with this whole rocking Qualys has sort of been, some people say eating your own dog food.
Some people say drinking your own champagne, whatever you want to call it. But Qualys themselves has been, have been using it and it's helped in the, uh, Qualys enterprise true risk kind of management. You know, they've been learning lessons internally is the bottom line here.
Can you talk a little bit about that? Yeah, great. Great question.
Actually, it's, it's a two part answer if I may. Uh, so Rock is obviously a program and now program includes your people, technologies and tools and your processes around it. So Qualis is transforming its own platform to be the world's first risk operation, center driven capability or the product which will help customers tie all the chevrons in the risk operation center together.
So how can we get best asset inventory, which would become the base of your rock? How can you now get all these exposures together, which are typically used by the 70 plus What I'm hearing, Alan, like customers typically use 70 plus security products. That's what I hear too.
Yeah. They all generate their own exposures. So how do we actually bring them together?
How do they then correlate your threat field business context so that we talk the same language so that we are able to actually prioritize the risk which matters to business and then try and reduce it and produce that report as an evidence, as an outcome to our compliance auditors. Now, as all of these chevrons, we are trying to actually cater using the ETM as a product where all these capabilities will come together, where our true risk algorithm will work on all of these data indicators. We created true risk, eliminate capability to help customers reduce the risk.
How now that would come together to help customers reduce the risk. And now at the end of the day, we are not saying that you just call this product. Well the ETM, you can just connect your other products as well.
If you like your, I don't know, maybe your SCCM product to reduce your risk, it's okay. Like just create a job from ETM in your product to reduce your risk. That's from the product side.
What we are creating now, like drinking the own champagne part, as you all know, call this is the biggest FedRAMP authorized platform. Um, probably number fifth in overall IT and security spectrum. So we have our big FedRAMP audit as well as our security teams.
They all need to do, guess what? They have to all cater to each of these Chevrons in own manner. We used to use our own inventory differently.
We used to use Qualys for assessment, we used to use another tool for reporting, et cetera. As we are combining all of these data points required for, say, key elements of FedRAMP, what are the key elements of FedRAMP? We need access control related requirements, vulnerability management requirements.
Now all of these are getting unified signals to go into their audit reports. So this is what being the outcome of our ETM. So every time, you know, customer comes in, in our data center, if you actually go in sometime Alan Niche, we should take you to our data center sometime to show you that.
I'd Love it. Where is it? So it's in two places.
One is in us, the other one is in India, where our teams actually have three types of monitoring. One is your knock, which is network operations, right? On the right hand side we have soc, which is security operations, and the right in the center, which now sits Our Rock, which is a risk operations center.
Excellent. I, you know, I may take you up on that. Alright, well I, we'll go from there.
Sires, you're about outta time. These are only 15 minutes. I appreciate you as always coming on here.
You know, I always, I I tell you the truth, I always listen to you talk. This is maybe the third time we've done and I say he's the guy who gets it right. He, I, I am sure Siresh is leaning on him for a lot of these things.
Man, you have a great handle on this. Thank you so much. Appreciate, thanks for all this having me appreciate, really appreciate you and your team.
Thank Absolutely. We're live, we're in Houston. We still got I think one or two more interviews.
Two more interviews today. So stay tuned. We'll be back on in just a moment.
You're watching on tv. Thank you. Hey everyone.
We're back here at Qualys Rock on in, uh, Houston. We've got one or two more to wrap up day one here. So, uh, bear with us.
We're glad we'd be live. For those of you watching, if this is the first one you caught and you want to see any of the other, uh, videos that we've done today, the interviews, the, the, uh, on demand versions, we'll be ready in a day or two and you'll be able to get them on Textron tv and you'll probably see 'em on LinkedIn and everywhere else. Anyway, let me introduce you to our next guest.
He's an international man of mystery. I'm only kidding. His name is Antonio Anderson.
But, uh, an Antonio works for a very large managed service provider or or service provider, service provider here in North America. And, um, you know, in order to protect the innocent, we're going to just leave it at that right now. But Antonio has a, a, a very interesting dual role, and I've seen it before with friends of mine, sort of a, both as a CIO and CISO type of thing, where they're responsible for it and information security or cyber as, as we call it, right?
And it's an interesting trend. You're not a unicorn on that. I, I've seen a lot of people doing this.
A lot of organizations move into this. What I always find interesting, Antonio, is did you come from the security side of the house and take over it or did you come from it and take over security? Well that's, that's a trick question.
'cause I grew up in telecom, Okay. Right. May not remember this little company called MCI three letters.
com era. Absolutely. So I was there, tell stories.
So MCI, WorldCom acquired MCI. Yep. MCI WorldCom was acquired by Verizon.
Yes. I lived through all of that. Right.
And my role there was it mm-hmm. Telecom IT infrastructure, consulting, building, driving technology. And then around 2007, I've always touched security, but security wasn't my primary.
Okay. Around 2007, we made an acquisition of this little company called CyberTrust. Sure.
And then I went to work for CyberTrust, that side of the house. So I was one of 12 engineers in the country and, uh, I had a big territory, so I started blending it telecom in cyber, and that's how I got into it. What a great story, man.
Good for you. I, I, I re I know all those companies. I'm old.
Um, anyway, I wanted to talk to you today, Antonio, about, you know, I call it cloud Native security. And, and that covers a lot of things, but you know, a lot of people today running containerized infrastructure, Kubernetes, managing it, maybe they got a service smash on there. And they're maybe using GI Ops to upload stuff.
And they might be running bare metal. They might be running on top of a hypervisor. They could be at the edge and or all of the above.
Absolutely. And it's a challenge because like, you know, I've been in it a long time in tech, a long time. Every new wave brings its own complexities and challenges.
Talk to me a little bit about the ch and you, you've seen this firsthand, you've lived it. Absolutely. Talk to me about the challenges you've encountered in trying to secure this, you know, cloud native type of environment.
Absolutely. Well, first of all, there are not a lot of tools available, readily available, especially for some of the things that are coming out in the newer models. Like AWS Fargate.
Yeah. Right. It's a very limited tool set that can actually get out there and give you the security or give you the information that you see.
Right. And for me, before working with Qualys to deploy cloud container security through Qualys, I had very limited visibility. The day I deployed it, my visibility went up nearly a hundred percent.
So for me, container security, to your point, it has a lot of nuance. It's serverless, it has these little things called lambdas. It's, it, it's, it's not new, but it's the wave of where everyone is going.
You very, you very seldom hear people talk about VMs anymore. Everything is containerized. Absolutely.
It, it is the default. So for Greenfield, right? New, new, you know, uh, applications, infrastructure, something like 80 plus percent is, is Containers.
Containers go brownfield. So modernization, we call it modernization transformation. It's still upwards of 50%.
Right. If people are gonna modernize, they move from a data center to the cloud one cloud to another or what have you. They're moving to containers.
They're, a lot of them are also transforming those applications from monolithic like waterfall mono to, uh, to microservice architecture. Correct. Which is a whole Different Ballgame.
Yeah, it is. I mean, it, it, it, and from a security point of view, you said there's not a lot of tools, right? There's not, it, it's a, it's a different animal.
Yes. Different animal. Let's talk a little bit about the Qualys solution for these kinds of environments.
Well, one, for one, it gives me the visibility. And that's the biggest thing. Because if you can't see it, you can't protect It.
Absolutely. If you don't know about it, you can't protect it. So for me, visibility is number one.
Now that I have visibility, I have insight. Now, some of the other things that are more structural and more fundamental to Qualys is this whole QID thing and how they're able to stack rank or prioritize the information that they're seeing, right. To help my team be more available to deal with risk that are what I would call high value risk.
Okay. Meaning if I can go and pinpoint what I need to work on immediately and take that information and act on that information and reduce the high value vulnerabilities. 'cause all about, all vulnerabilities are not built the same.
Right. And to get rid of the noise, to get to the signal. 'cause that signal to noise ratio before deploying quality was very off.
And now that I have it, I'm able to pinpoint exactly what I need to do, where the high value is, and then make it seamless to my team. Because that, that was another thing. My team, whether it was dev, engineering operations, they were not seeing the same stuff.
No. And now with Qualys, we have this seamless set of dashboards that allows us to see the same information, which makes the, the remediation effort a lot easier. We are talking the same language.
I tell you what makes it a lot easier in my opinion, is having one guy, who's it and security, because otherwise there's a lot of this that goes on, you know, and a lot of, a lot of territorial matches. Right. I, I think, you know, as a lot of people out here say, ah, he's crazy.
But no, I'm telling you, when you have a single head that is security, NIT. Right. Uh, summed the CEO of Qualys used the term in his, I don't know if you support his, uh, keynote today.
I did, I Did. Dashboard tourist. Right.
Did you catch that one? Yeah. So, and I've lived that my, and not just in security, I get it with Salesforce.
I get it with a lot of our products. You know, we, we've been so busy making individualized, customized dashboard views for every role in the organization. But your dashboard is, is so different than my dash.
It's like the Tower of Babel and none of us talk the same language. Exactly. And, and to me, that, and so these tourists go from dashboard to dashboard, you know, they visit mm-hmm.
They don't live there. And so what you are describing, where you are all talking the same language, that's key. That, that's, that's invaluable right there.
Now, I would tell you this, we didn't get there overnight. Oh, I'm sure you did. It.
It's a process. It's a process. And why I have great influence over security and it, I I don't control my dev team.
No. And I don't control my engineering team. So that rolls up to the CTO.
'cause that's all customer facing. So you got a CTO who's like a CPO as well, kind of. Right.
So that's, that's the model. Now, the C T's, the CPO and the CISO's, the CIO. So, and, and I don't report to the CT O No, I get it.
I report to general counsel. Yeah. Well you're coming.
Okay. So I You're under risk. Yeah, I'm under risk.
But they get it and my CTO gets it, but the friction is still there. Oh, yeah. Because, you know, I I, I said it Well, They're profit motivated.
Yes. Not necessarily the case. They still view you guys as a cost center.
I've been working to change that. I Just, God bless you. That's God's work.
I just, I just had that conversation right now. And this is the right time to have the conversation. Right now, security no longer is in the back office.
No, that's why it's in the boardroom. It's not in the boardroom. Because they want to hear about it.
It's in the boardroom because it can cost serious dollars. But more importantly, it's in the boardroom because it's high risk. It's this little thing called supply chain management or third party risk management, however you wanna look at it.
That brings the conversation of revenue to the table. Because right now you can't close a sales deal if your security house is not in order. You gotta have your SBOs and everything.
Yeah, absolutely. So now you have this thing, like I, I told my board last week, I just presented to my board and we have this little thing, you know, because we deal with phone numbers, phone numbers are not really considered. P-I-I-P-I-I Not as a standalone.
And they're not considered high risk targets. So that means our risk tolerance is very high. Right.
Right. And if your risk tolerance is high, typically your security controls are low down. Right.
So you don't spend a lot of money on security. That was the case prior to my arrival. Now they understand we are not selling to ourselves.
We sell it to customers. And some of our customers happen to be financial institutions. And that risk tolerance is very low.
Right Now, my security controls have to go very high. Yeah. If I wanna win business.
Absolutely. So security is no longer, um, cost center in my humble opinion. I, I don't, in my opinion, I agree with you a hundred percent.
I think that is the old way of looking at it though. Because here's the deal, and I think you hit it on the head. You cannot have products going out the door that are not security tested, that are not secure to the, to the best of reasonable degree.
Right. Now you sell to the government, the government's starting to put in, or they were talking about putting in, you know, then it had to be free of any known vulnerability if you are gonna sell to the government. Absolutely.
That's a pretty high bar. Right. Because a lot of software goes out that door with vulnerabilities in it.
Right. That's the nature of this. It Is, it is funny that you mention the government because my biggest sponsor is the FCC, the Federal Communications Commission.
Uhhuh. I meet with them once a month. We have a hard requirement to be FSMA compliant now because of that hard requirement and because of that, that no known vulnerabilities.
There are exceptions to that. Yes. But They want to know how well are you managing those vulnerabilities.
Yes. And it, it's not called vulnerability elimination. You'll never eliminate the vulnerability, but it's, it's Management manage.
It was always vulnera the same way. It was always about risk management. Correct.
I agree with you. So what do you think so far about the conference? The conference has been great.
Um, some of the things I'm learning, I deploy almost 95% of Qualys products. One thing that I realized is I'm under utilizing the capabilities. So some of the things that the product team and I have been talking about is how do our teams get together?
We already meet regularly, but now we want to get together so that we can figure out how to maximize utilization. Perfect. You are not alone in that, by the way.
I, you know, I think on the whole, so I've been at security 30 years. I started a few security companies on the whole, I think customers use 30% of the, of the buttons and dials in an interface. And you asked me about that other stuff, and it's like, yeah, we don't use that.
We don't use that. And, you know, and, and yet I've been on the product side of the house where, you know, every piece of real estate on that screen is valuable. And yeah.
Getting people to use it is what it is. Right. I don't, I don't know if God bless you for trying, but I don't know if that ever changes.
Well, that's where the influence come in. I, I think that's why I have some leverage of playing the dual role and having both teams, because my teams are interested. You know, and if you let your teams explore, right.
'cause I empower my teams to go out and learn the technology. I don't make technology decisions. My team do.
I I'm not managing the stuff. They are agreed. Now my job is to make sure that we, we have the right stewardship in place, right.
And the right financial model. But outside of that, they're the technologists. They're living in this stuff every day.
And I always tell them, if we have less than 70% utilization, we need to get that up. Otherwise we need to get it outta here. Agreed.
Man. Adrian, we're about outta time. Okay.
I appreciate you coming on here and Techstrong TV and talking to our audience. Keep up the great work. Enjoy the rest of the show.
Let me ask you one more question actually. Why are we here? Did you come in early for any of the training?
Uh, no. I, I, I arrived yesterday. Alright.
Only because I wanted to actually talk to someone who's sat through the training, but we'll find someone. Thank You. Adrian Anderson here at, uh, Qualys Rock On.
We got one more interview coming at you on a long day today, and we'll be back. You're watching Tex Strong tv. Okay.