Advancing Cyber Threat Intelligence and AI-Driven Vulnerability Management with April Lenhard
April Lenhard discusses her role in cyber threat intelligence at Qualys. She highlights the threat research team’s achievements and the importance of reducing Mean Time to Remediation (MTTR) and Mean Time to Detection (MTTD). The conversation covers strategies for prioritizing vulnerabilities and the impact of AI on enhancing cybersecurity efforts, concluding with thoughts on AI’s future in the industry.
Transcript
Hey everyone, it's Alan Shimmel. Welcome back. You know, it's been an amazing couple days here at Qualys as Rock Con.
We're Rock Con Risk Operations Conference, and we, but all good things come to an end. This is gonna be our last interview here this year, but we've saved the best for last in some way. Let me introduce you to April Lenhardt.
If you are a, uh, a tech drunk TV aficionado. You might have seen April talk at hour, uh, RSA coverage. Last, I guess it was last May, was RSA or April, something like that.
Yes sir. Maybe it was April and April, but, um, April, first of all, welcome back to Text Junk tv. Thank You.
It's great to have you, uh, for the, you know, not, I was kidding about the aficionados. Most people have no idea you were on in April, or not of course, but tell them a little bit about your background and and what you do here at Qualys. Yes.
So I've been in cyber threat intelligence for about a decade. I started as an intelligence analyst actually. Mm-hmm.
And my goal at Qualys is to bring cyber threat intelligence to the fore. And really what that means is we have a threat research unit of over 120 analysts. And my goal is to make sure that that work is really shown really clearly to all of our customers.
Absolutely. And, and you know, I, I'm not going to embarrass you or anything, but the, the call research team has actually won a couple of awards lately. PO Pony, PO Pony Pony Awards.
Pony Awards, yes. Uh, as well as other awards and stuff. I mean, they're really doing some phenomenal work and, you know, awards are nice, but the work they do is actually really good, important kind of stuff.
So, so it is important, you know, April, I, I was, uh, started a security company in 2001 venture backed security company. And we were in vulnerability management network access control. And I remember going to, at the time, I think it was still called Citibank, it wasn't Citi yet, it was Citibank.
But talking to one of their global CIOs had three global CIOs and he told me that it took them 90 to 120 days from the day of a patch Tuesday release to actually apply to remediate. Yeah. And I remember thinking to myself, that's crazy.
90. 'cause even back then, 90 to 120 days was forever. Right.
But he said, you know, they would rather make sure they don't break anything else than rush to fix even the most serious vulnerability. It's when I knew security had issues, we had issues. Now that GAP is, you know, commonly referred to today as the, uh, meantime to remediation.
Right, right. And, and a and a lot of our security metrics and, and how we measure performance of security teams are built around at MTTR talk. Talk to me a little bit about MTTR, how your work at Qualys helps that and what Qualys is doing to kind of close that gap.
It's not, let me just say a friend, I don't think anyone waits 90 to 120 days anymore, but what do we do? You know, what, what is the average gap and what are we doing to close it? To your point about qualysis threat research unit being exceptional, one of the statistics that I'm really proud of and that I was happy that I just got to talk about during my talk is that 20% of all quas customers are able to actually remediate CSEC Kev vulnerabilities before they hit csec kev.
That's great. And so one of the big things with that is that the re remediation time is low because of how quickly we are able to kind of enumerate these vulnerabilities. One of the big ways that True lens, which is the product that I'm working on, is able to help that remediation, is by really helping you triage what is the most important things to remediate.
So we're all surrounded by a plethora of different alerts, different metrics, some that are not super actionable. Right. And so my goal is to really help kind of kind of funnel the different things that you could potentially action to say, Hey, what of these are relevant to your industry, to your business?
And then from that say, Hey, these are the specific things that you need to work on. And from there, your remediation time can go away down if you are really focusing on the things that really specifically matter to you. One of the other things that we're doing is we're able to give a view into the industry that you're in and say, what is the average remediation time?
So instead of just looking across all of any industry, uh, any vertical, and you know, how well is is an oil and gas company doing compared to a mom and pop shop compared to a finance institution, we can specifically say, if you are a large size oil and gas company, how well are you remediating compared to your peers? Because you might think that you're doing great because you remediated this one vulnerability in 15 days. And come to find out your peers all remediated it in three days.
Right. So then you might need to know, okay, hey, I gotta change how we're doing this. But if you don't have those statistics, you can't really change because you're, you're not really sure what you're, you're going against.
Right. Absolutely. And so this is a big way to, to be able to, to change how you remediate.
Absolutely. I got a hard question for you. So how do we, how do you take MTTR?
How do you take those sets of statistics and feed it into the rock to deliver to a, an executive and say, look, because we've lowered our me, um, our mean time to remediation by 20%, we've lowered our risk by, uh, x percent. How, where does, you know, is that even possible? And how does that get done within the Qualys kind of product suite?
That's a great question. So we, we incorporate mean time to remediation in two ways. The first is kind of, uh, for every individual vulnerability, we want to provide a mean time to remediation.
So we're able to get on a very granular level, what is your MTTR and what is everyone else's MTTR? Yep. We are also able to say kind of at the, at the bird's eye view, at the very strategic level, how are you doing with your remediation versus how are others doing?
So you're able to say, you know, taking aside one or two vulnerabilities, um, actually looking at everything, what does that look like? And those are statistics that you can share with the board, with different stakeholders, with investors, and those are things that you can, you can really incorporate into that workflow. I love it.
I want to turn from MTTR to MTTD meantime to detection. Mm-hmm. Well, let's first, you know, I love throwing acronyms at, at the audience, but let's, I said it's meantime to detection, but what does that actually mean When you're thinking about meantime to detection?
Think of from one of vulnerability is, is first introduced to our system. So when are we, when is the vulnerability first, first acknowledged as a vulnerability to when on your systems do you say, Hey, this asset is associated, um, with, with a problem? When do you know that there is a vulnerability?
When is there risk introduced? Um, this is a really critical metric because you need to know, Hey, um, has this been sitting on my system for years or was this only a problem, you know, a couple hours ago? Very important to know.
Absolutely important to know. Now, how, how do we, how do we measure that to quality? So because to a certain, you know, to a certain extent, well, it depends on what kind of threat intel you're getting, how vigilant you are, how well, you know, the whole, I mean, everything.
And some of it is pure dumb luck, I think, too. How do you, how do you quantify for the luck and quantify for all these things and say, okay, because you're using Qualys, your MTTD is lowered somehow. There are definitely certain aspects where if you're looking at espionage actors, if you're looking at these really long dwell time actors, you are going to then have them, of course, associated with TTPs where they will use vulnerabilities that will be in the system for a long time.
Right. But if you're looking on average, if you're looking at, uh, zero day vulnerabilities, if you're looking at kind of what we see typically in, in the daily news, the most critical thing is being able to run scans and detect these things as quickly as possible. And with Qualys, we have such a robust system, we are able to really give you kind of as small of a delta as possible, um, from from when you are first, from when we first know about it to when it's detected.
Right. And that's, that's really kind of the critical timing that we're looking at. When we say timing is everything, what we're looking at those metrics, that's what we're looking at.
I Agree with you. I agree with you. One last topic I wanna throw, and that's ai.
It's changed everything this year. How's it changing what you're doing? It's changing what we're doing in a big way.
So we are leveraging ag agentic ai, where you can ask questions like, Hey, I see all these different risks and vulnerabilities. Help me triage what to do next. Um, what, you know, Qualys, what do you see in the system in terms of the assets that I need to look at first?
And then when you have the system, how do you incorporate it with all the other products? So now instead of kind of having to do all of these disparate pieces alone, we are able to say, Hey, let's, let's automatically using Agen ai, be able to connect with all the other products you're using in the ecosystem. And then say, okay, what do we now do to, to be able to triage this?
How do we evaluate risk? What does that look like? Again, across different industries and also within my own system, what do I need to focus on first?
So Agen AI is really being leveraged strongly by Qualys as a way for us to continue improving our systems and as a way for organizations to help mature their own cybersecurity posture. Got it. I got it.
If I had to ask you sitting here next year, how much more AI agentic AI is going to be, you know, not, not it's gonna be a bigger piece of, this is I guess the conclude the, the feeling, but is it going to 10 x your, your team and, and your stuff or you know what I mean? How, how, how? Yes, it's big, but we're still scratching the surface, is what I'm saying.
We're still scratching the surface. Our, at least on the product side, what our plans are really are to try to run as quickly as possible, but as safely as possible. We are a security company, right?
Absolutely. Um, but to try to incorporate as many different uses and as many different ways, um, that we can help companies, uh, be able to leverage threat intelligence and be able to mature their own organizations. Um, and again, to, to do it in a way that is possible, probable safe.
We love it. April, I know you ca literally came off the stage, came here. I want to thank you.
Thank you for all the work you do. It's been a great Qualis rock on, and you've been a great guest to end it. Thank you so much for having April.
Maybe we'll see you at RSAA couple months March this year for sure. All righty. Hey, that's gonna wrap up our Qualis Rock on coverage here in Houston.
We hope you've enjoyed it. If you missed any of the live feed, uh, we'll, we'll have the on demand by next, I don't know, early next week. But until then, this is Alan Shimmel.
On behalf of Qualys and Tech, strong Tech, strong tv, we're out. Bye-bye.