Himanshu Kathpal on Integrated Identity Management and Zero Trust Security
Himanshu Kathpal’s discussion focuses on integrated identity management and the challenges of credential abuse and misconfigurations. They discuss Qualys’ unique solutions for identity risk scoring and remediation. The conversation highlights the zero trust security model and the importance of identity management within it. Future developments aim to secure both human and non-human identities, addressing the needs of CISOs for consolidated risk management solutions.
Transcript
Hey everyone. We're back here at Rock on, uh, Qualys Security event in, uh, Houston, and wrapping up our day two coverage with some really good conversations. I want introduce you to our next guest first.
Uh, he's been on with us before. He's Haman Kapa. That's correct.
Hemanchu. First of all, welcome back. It's good to you.
Thank you. Thank you for having me. Thank you.
Why don't, if you don't mind, tell the audience a little bit about your role, Quas, maybe a little bit about your career path. Yeah, Absolutely. Hi, everyone.
My name is Iman Kapa. I'm the Vice President for product management in QLEs. I completed my 10 years in QLEs this August.
Wow. This has been an excellent journey so far. I started in support and then move on to product management and then grew up the ladder, and now I'm managing the whole product management from India.
Very cool. And, and, you know, Qualys was way out ahead moving a lot of their r and d and engineering to India. Yeah.
More than 10 years ago I thought. Yeah. 15 years ago, almost 15.
Yeah. Um, so in, in, in terms of project management though, whether you're in India or the US or the Moon Uhhuh, project management is project management. Right?
Very, very. Let, let's talk about some of the projects Uhhuh you've been working on. And I I I know you also presented here in a panel today, right?
Yeah. Talked a lot about identity, correct? Correct.
And of course, identity is one of the, the frontiers Yeah. Or one of the battlegrounds Yeah. Really for what we're seeing in security.
Right. Talk to us about some of the challenges you're seeing there and Sure. And what you guys are doing at Qualys to help, uh, that, uh, absolutely.
That this is a very passionate topic for me. So what we see is, and even if we see it from the Verizon DBI report, 80% of the breaches require are due to credential abuse. More than 34% of the attacks which are happening are a combination of vulner, misconfigurations and identities.
Until now, most of the industries do treating identity in a silo. Either they have an identity context or they have an asset context, but never together. And that is where Quas is coming into picture.
I know that we might be a little late in the identity game, but we are doing it in a more holistic manner. So what we are doing is now you can ingest all of your identities across active directory. I maybe if you're using some other ISPM solutions such as Tenable or Pink Castle, all of the data data can come into QS for you to get one unified vision of your entire entity landscape on top of it.
We are, we are the only one who's gonna provide whether your identity is being getting sold in the dark web or not. You are externally exposed or not. If you are, that's a big red flag.
You should immediately change your password, immediately, change the credentials, et cetera. That is a unique value that we are adding on top of it. What we are doing is we'll be providing a true risk score for each of your identities as well.
Because similar to assets and vulner, the number of identities which each company has is huge. It's massive. You need prioritization, otherwise your team is gonna get burnt out.
Yes. That is where we, we come in, we check which misconfigurations are applicable for your identities, whether multifactor authentication is enabled or not, whether the password is weak or not, whether the identity is exposed externally or not. Using a combination of all of these risk factors, we are gonna provide a quantitative score to each of your identities called as identity true risk.
This risks, this tour score is gonna get bubbled up to your business tour score and you'll get one holy grail for the prioritization. That's the unique value that we are adding. Excellent.
And, and last but not the least, our mission has been not only to provide the inventory of the risk, but to remediate as well. So even for identities, we are providing a closed loop remediation. You can do patching, you can do password resets, you can enforce MFAs, you can run your custom scripts, you can do mitigation, isolation, all as part of the same solution.
That's impressive. Yeah. You know, it's interesting, a lot of people out here, they, they hear Qualys, they, they understand vulnerability management.
Yeah. Remediation. Yeah.
They understand now risk management Yeah. And all of that. They don't necessarily think identity management.
Correct. But I think I, that's part of having the, the platform. Yes.
Right. Is doing that. I wanna dive in a little deeper on zero trust.
Sure. Right. Zero trust is a, a concept that the security industry has embraced.
Yeah. All over. Absolutely.
As it relates to identity though, uhhuh, what you guys are doing at pollis, talk about zero trust in the Absolutely. I, I think that's a very interesting question. So, in the past, if you see CISOs are only concerned about, uh, endpoints and network, over a period of time internet exploded, people started migration towards cloud, and that is where ZTNA came into picture.
So even, even when ZTNA, when you are merging applications and networks together, every single entity still requires a separate authentication. This is where we see that the identity is indeed a new parameter. Even within ZTNA, you need to be managed separate identities.
So ZTNA is very helpful from the application and the network perspective, but you still need identity management on top of it. Absolutely. Yeah.
Absolutely. But is there a, a zero trust or A-Z-T-N-A uhhuh philosophy for identity management? I think that is where the industry is going.
There's no set philosophy for identities yet, uh, in terms of ZTNA, like we have for infrastructure and networks. But I think with more and more attackers leveraging identity or credential abuse rather than vulnerabilities, that that part is also gonna flourish. We will be having some more concepts, some more philosophy around C-T-T-N-A for sure.
Let me throw something farther out at you. Sure. Everybody talks about agent ai.
Yeah. Deploying all these. Yeah.
There some people say we're deploying digital workers. Digital Workers, correct. That's The word.
Yep. What about their identities? That is a excellent question.
So what we have done now is in the first phase of our launch, we are covering all the human and non-human identities. But our team, our threat research team is currently analyzing how can we collect the identities of these agent care agents? This is the future.
Everything is moving towards them. And if their identities are not secure, if you do not have the inventory, the control on their identities, it's gonna lead to bigger issues. So this is definitely what we see as the future and will be added to our products in the near, uh, in the, in the short term.
I love it. Yeah. Poman show.
We seem to have run through everything, all these mugs that we had here. What else can you share with our audience? What, what are you getting excited about?
We Are getting excited about getting this consolidated picture for our CISOs and our customers. I mean, I have met like hundreds of CISOs in the last two years. Every single CISO is saying that they want the toxic inset combination.
They do not want the laundry list of one everyday separately identity separate. Team is configuration separately. Everyone is looking to understand what carries the most risk for the environment.
And this is where I believe qualis is coming into the picture. So imagine you might have a system on which you're doing vulnerability management really well. All this patches are applied.
There is zero critical vulnerability from the myopic view of vulnerability management. The system is 10 on 10, but the system has a password as 1, 2, 3, 4, 5, 6, and is now used to connect to cloud database server. Yeah.
Holistic risk. This, as it carries, is huge. Yeah.
This is what CISOs wants and this is what quality providing. So we are really, we are really excited about providing this holistic visibility across all the three major, uh, risk factors, whatever it is, identities and misconfigurations. I love it.
That's what those are the big three. Excited. Exactly.
Excellent. Hey, I wanna thank you for coming on. It's always Thank you so much, my friend.
You're great. Thank you so much. Keep doing what you do.
Hopefully we'll see you soon. Yeah, Absolutely. Thank you.
Thank you. Hey, we're, hold on. We gotta what?
Okay. We gotta undo your microphone. But before we do, let me, we'll be right back with more here.
We're live on, uh, text drunk tv.