Eran Livne on AI-Driven Vulnerability Management and the Future of ETM
Eran Livne talks about his role at Qualys, discussing a new vulnerability solution for customers. The conversation covers changes in the cybersecurity landscape, the growing role of AI in automating processes, and its impact on patch management. Predictions suggest AI will become standard in remediation practices, influencing job roles. The ETM vision is presented to enhance risk correlation and remediation efforts, emphasizing collaboration for the industry’s future.
Transcript
Hey everyone. We're back here live at Qualys Rock. On my next guest is Iran niv Nay.
If you've watched our coverage of past Qualys, uh, who's security conference, then you've seen us interview Iran before. He's delightful guy to talk to. Smart.
He works in the Quais endpoint remediation division or section. Iran, welcome back to Tech Drunk tv. It's good to see you.
Thank you very much. So, well let, let's talk a little bit about you first. I probably asked you this last year, but I'm gonna ask you to repeat it.
Tell our audience, how did you come to be where you are here at Qualys? Uh, I, I, I had my experience in security goes way back and basically five years ago, it was actually really interesting, five years ago, our current CEO, which was the CPO back then, right? Uh, hired me to help him build our remediation arm.
So basically he had a great idea. Let's have a vulnerability, uh, solution. Also help our customer not only find all those vulnerabilities, but actually solve them.
Now what's interesting is back in the day, nobody believed that it's even possible, right? Vulnerability guys are doing vulnerabilities, security and IT guys, it guys and all second Security guys don't do patching. Never do patching.
No. And fast forward five years and basically we were able to build a, uh, an amazing solution and have tons of customers. And I dunno if you, you know, but a month ago, I think GIG released their rather that compare other patch solution and we're one of the top leaders really this squadron Yeah.
Compared to literally every legacy solution out there. So we are very proud of the journey that we had in the last, uh, five years. I'm proud of, of what you've done in the last five years too.
Thank you. Right. As someone who, uh, I think I told you this, I had founded a, uh, cyber, we called its InfoSec company in Boulder, Colorado in 2001.
We came out with a vulnerability management solution in 2003. And we, we, we created, we spent some fortune, a fortune on a workflow, took the vulnerability what needs to be done and we tried to get it to order me. People, people wanted to shoot us.
Yeah. They did it. They wouldn't, no, no, no, no.
Different different team. You gotta go get them. I remember I went to, uh, at the time it wasn't called Citi, I think it was called Citibank, you know?
Mm-hmm. But it's Citi today. I met with one of their three global CIOs and I said, why wouldn't you wanna do this?
And he said, look, it takes us 90 to 120 days from the time we receive a patch until we fully test it and implement it. Yeah. Because we won't patch something.
'cause it's liable to break something worse. Than's already broke. Yep.
Which to me made no sense. But that was the state of the world. Then the fact that you are having this success means the world's changed.
The World has changed significantly. And during these five years, and I can tell you five years ago your story was 100. You know, 100% to the point.
Now because everything happening in cybersecurity, we can see more and more security team either taking control and actually those are the guys that click the button or what they're doing. They use tools. Our tool, or I cannot vouch for other tools, but use our tool in combination, what they have today.
So we basically it are using our tool to help them get better result, replacing or not replacing what we have. Because Qualys was never about let's get rid of all the IT solution out there. We don't, we don't compete with them.
What we're trying to help you is fix the risk or help you with the risk. So the security team ga a tool that can help them fix the risk and they can show their IT counterpart how to do that, how to simplify this entire process. But that's important.
It's part, we build it as part of the IT team's processes. We're not asking to do anything new, just making the life much, much easier and sharing information between those two teams. And it just made sense.
Absolutely. And now our security teams are the ones that are helping us push it to the IT team or not push it, work together with IT teams to get this thing happen. That's a huge change in loss.
Absolutely. It's a, it's monumental. Yep.
Really. But you know how business is, what have you done for me lately? Since last year?
AI is everything. Yep. We're, we're autonomously doing stuff.
Now we have autonomous agent agent, ai, generative ai, everything. MPC servers. How is this?
I mean, one, they say, look, this is great. This takes us to the next level. Now we could, you know, in a workflow kind of way, just really automate the heck outta this.
Mm-hmm. What do you see? I tell you the truth.
I spent a lot of times when, when the inter stock, you know, the buzz started like a year ago, a little bit more trying to figure out what I can actually, how I can actually use AI to actually provide value. Because back in the days, if you remember, two years ago, one and a half years ago, everybody was building like a, a chat, chat, Chat bot. Chat bots.
Exactly. Just doing chat. Same thing they can do today with a click.
Just let's do it the chat because that looks better on, uh, you know, that's a great marketing and I, I didn't, I didn't follow that route. I, I want to find something that I can actually use AI and accomplish something that I couldn't do before. And one of the things that we are actually releasing now in Q4 is we use AI to do what it does best to make sense out of tons of data.
So I'll give you a great example how, how we're using it. One of the biggest problems every customer has cross the board IT and security is, and actually that's the main reason why people are not patching or people are not taking actions. The main reason is, as you said, the fear of something breaks.
Remember you gave this example, your example was 120 days. It takes four. Right.
The reason is they're afraid if something breaks, the bank was afraid that some money generating application will stop working. How we trying to solve it is we're trying to increase the confidence of those guys, of the IT guys that if you deploy the patch, you don't have to worry. Nothing's gonna work, nothing's gonna break.
And the first step that we're taking towards this amazing goal that we are investing heavily on is helping the customer understand if there's already a problem on this specific patch. The entire internet is, you know, there's tons of shots in Reddit and in Twitter and all over the place now we use AI to take all this information, all the, literally all the internet using our proprietary algorithm to, so we need to know where to go, but we summarize everything and we basically get a score. What about this patch?
If you deploy this patch based on everything that we saw in the internet, can it go wrong or not? And if it does go wrong. So it's not just good to tell them, Hey, don't deploy this.
We, we actually found, I don't know, 10% of the patches do have a problem. We also offer mitigation. So if you cannot deploy the patch, because we know it'll break something, we give them alternative.
So instead of deploying the patch, you can deploy this thing that will reduce the risk without the need to deploy the patch. So we're trying to tackle two things, predict if something will go wrong, but also give them alternatives. Again, trying to help them solve risk.
That's our goal. Absolutely. Absolutely.
When do you think agen AI becomes the norm? The default in, in these remediation patch? I think that most vendors are working on that right now.
I think that in the next year, not not long term, I think it's very soon Within the year. Yes. But the problem with the gent ai, everybody defines a differently, okay.
What I'm talking about the gent ai, I'm talking about how do we help our customers do two things. First, be able to predict better and be able to, automation is different because automation and civil and all those guys are solving the more automation complexity. They've Been doing it Forever.
But what I want to do is I want to help them. If something goes wrong, how do I recover quick? How do you back it, back It out and scale.
When we have a customer with 10 and 200,000 devices and a patch failed on 50 k, is this The crowd strike? That's exactly the crowd strike. And you need to fall over and you need to be able to roll back and fix the things as soon as you can.
'cause you have a very short maintenance wind Yeah. That you can operate on. Absolutely.
That's where I see the biggest, uh, uh, contributor of, uh, agent. Let me ask you a question. I'm talking now for all the people out here who work in either cyber or it, but they're patching, they're remediating there and they look at this and say, that's gonna take my job.
Maybe I, I don't think it'll take the job. That's my personal belief. First of all, the tool that we currently build are helping them do their job better.
And I think what will happen is instead of them being able to deploy 10 or fix 10 vulnerabilities, they'll be able to fix 1000 vulnerability in the same maintenance window that they used before. Which mean the same person now is gonna go and do much more. But you still need this person.
You still need the human, the AI will do more, but you still, now it's in scale. So the person will need to, to be able to manage much more in the same time. Okay.
Using ai. Excellent. Iran, besides ai, what else do you see coming down the pike for, uh, automated remediation?
So One of the cool things that we're working on, except of we're building tons of features to make the product better, you know, and help our customer life easier. And, but, but one of the big thing that direction we're taking, are you familiar with our ETM vision? Right?
So we basically take data from other vendor and we can give you one picture of all your risk. Yep. What we're doing, we're actually opening it on the other po uh, direction.
Meaning once we find this risk, my goal again to help you solve the risk, if you have an IPS in place, checkpoint Palo, whatever you have, and that thing can al already mitigate the vulnerability that you have on an asset, we are gonna help you do that also. So even if you don't use the Quas agent, you don't use quas. We'll do the matching, we'll do the mapping and allow you to use other incumbent solution if you have to combat reduce the risk.
Okay. And that's a huge, huge project for us because that basically makes it lives much easier. Now if you cor sorry.
If you correlate that with the risk risk prediction that we have, you can figure out, oh, I have a risk here. This patch will cause problem. Let's use my IPS to reduce the risk until I can fix the patch or the environment.
Sorry. Please. I love it.
The ETM is is out now I think. Yes. It's out now.
Yeah. Yeah. Alright.
I think we covered just about everything. Yeah, it's good to see you. It's good to see you see progress.
Let me ask you one other thing. Yeah. Please.
What do you think about calling the conference rock on versus Oh, I like it. I like it. It's, it's a change.
It's hard for us to get used to as Quas and members that been doing it for some time, but I think it's a great idea. Me too. But that's where we're heading.
It's good seeing you Iran. Let's not wait till next year. Hopefully we'll see you before.
Yes. Alright. Iran, Liv Nay, he, he runs the endpoint Remedia, I don't know what your official title is, but I know he's the endpoint remediation guy.
Health Remediation guy. Help our customer fix things. Abso the fixer.
We're live, we're at Houston Qualys. Rock on. We'll be back in a minute.