Integrating Agent AI into Enterprise Risk Management with Dilip Bachwani
Dilip Bachwani, CTO at Qualys, shares his insights on risk management and the importance of a unified platform. The discussion highlights the integration of Agent AI into enterprise risk management, focusing on pre-breach strategies. Challenges with generative AI in cybersecurity are addressed, emphasizing the need for reliable responses. The potential for AI agents to operate autonomously is explored, along with concerns about job impacts, concluding with a positive outlook on technological advancements.
Transcript
Hi everyone. We're back here at Qualys Rock on conference day two afternoon. You know, this, this next gentleman.
He's always one of my highlights when I do interviews here at the, uh, Qualis events. Uh, uh, I'm gonna let him introduce himself and he can tell you about what he does. It's my friend Diwani Dilip.
First of all, welcome back. It's good to see you again, my friend. For those of you, for those of the people out here not familiar, tell them a little bit about your role at Qualis, your background.
Sure. I'm Dilla Wan. I'm the CTO here at Qualys.
Uh, responsible for all our global engineering, cloud operations and customer support and success. Been here almost coming up to 10 years. Yeah.
So I'm very familiar with everything that we've done. Took 10 years, right? Very proud of everything that we've done.
You should be, Uh, I think we are positioned really well. Um, the concept of risk management and having a single unified platform that can drive that is coming together really well. It's resonating really well.
Yeah. And then of course, agent AI and all the, we We're talk about ai. Yes.
But before we get into the agenda, ai, lemme just take a moment. You know, 10 years is a long time in any job in today's world. Yes.
In the world our parents grew up in. You might work in one job your whole life, but, and not today. Most people jump around and it, and it's not just you.
I, I was just talking with, um, who's also coming up on 10 years now. Mm-hmm. Uh, spoken to a lot of the, and, and I'm, I think I'm doing the, the thing, the qua, what used to be the security conference, probably four or five years now, I've seen the same faces over those years.
I think that's a, it's something to be proud of. It talks to the culture here, but I think it's also a reason for the success because you need, you need that sort of tribal knowledge. Mm-hmm.
Right? Yeah. To, to share and to build on.
I see it different than you, right. 'cause I sit here and I talk to a lot of companies, and it's so many of these companies. It's a game of revolving chairs, revolving, you know, and the music stops who's there next.
And so they wind up losing a lot of tribal knowledge. They, a lot of debt gets built up. So congratulations to you and the Quas team for that continuity.
You mentioned the Gente ai. Mm-hmm. I'm pretty sure we didn't talk about Agen AI last year or the year before that for sure.
Yeah. But that's all we seem to talk about here. Qualys made several announcements around it.
Let's start there. First, let our audience know. What were the announcements?
What, what's the news on Agent AI from, uh, Qualys? So, you know, last year we had, we kind of talked about how we were thinking about enterprise tourist management. And the, the idea behind it is just the way you have a soc, which everyone in cybersecurity is familiar with.
We have kind of defined this category of a rock a risk operation center. A SOC is post breach and a rock is pre breach. So the idea behind the rock is you take care of your health and hygiene, you take care of your vulnerabilities, your misconfigurations focus on what's important, reduce your risk.
And if you do that, then hopefully you won't have issues on the SOX side, right. You won't have beaches. So rock is the concept, rock is the category, right?
Enterprise tourist management is our implementation of the rock, where we are saying we will bring signals across from college products, but not just call products. We'll also bring signals from all third party products. So we are right now building a lot of connectors.
We have a lot of 'em out there. So if you are, as an example, doing vulnerability management with qualis, maybe you're doing misconfiguration, uh, compliance configuration with quas, but you're doing endpoint with someone else. Maybe you are doing CNAP with someone else.
That's okay. We understand that no one customer is going to go with one vendor for all their security needs. Um, different vendors have different strengths.
So what we are seeing is we will take our findings and move, bring those into ETM enterprise risk management using connectors. We will also bring findings from different security vendors that you are using into ETM. So vulnerability management might be us.
Maybe CNA is us, SAS is someone else. That could be someone else. Container security endpoint, whatever that is, bring it together.
Then we do a lot of analysis on that. We apply our threat intel on all those findings. We apply business context on all those findings, and then we kind of reduce the overall volume that we got to something that's really manageable.
Sometimes less than 1%. Right? And we say, if you focus on these vulnerabilities first, then you're reducing your risk significantly.
Not saying that you don't take care of the rest, but helping you prioritize, really helping you prioritize. Right. Condensing it down.
That's one part. Now the other part where AIA is coming into play is we've been doing AI for a while. You and I have talked about this.
Sure. Right. Uh, I think when generative AI came out from a cybersecurity standpoint, it was not as reliable because you would ask a question, the response is, predictive Might get what you Might get, you might Not, might get it.
Right. Right. And my challenge was that if I'm, if I have a CISO saying, what are the top five vulnerabilities I should focus on in my environment?
And it gives a result. And if he asks the same question again, as long as the underlying data has not changed, it should give the same result. But with generative ai, that was not really possible.
It's just how the technology works. Right Now with Agent TKI and MCP servers coming out, we can have our responses be more grounded. Mm-hmm.
So just the way across all the 400 services that we have in our platform, everything exposed via APIs, now we are exposing all the core capabilities of the platform as MCP servers. Now, when you ask a question to our cyber risk assistant, it interprets that question and then says, which MCP server do I go to? And that will determine which API to call and constrained by authentication and authorization of the individual making the call.
Right. So it's the same as making an API call at that point. Well, and it gets to the, well, there's a lot of similarities between the ag agent and the API.
Yes. The, the idea with the agen ai, of course, is that it could do this autonomously. Correct.
Where, let's call the API call or the API integration more of a, a dumb Yeah, yeah. Kind of integration where you actually gotta kick it. Correct.
Or the, and so let me, I got two things to go over this with you. Number one is, do you envision a future where the Qualys agent sits on a different cmap on a different sim on a different product, and autonomously is gathering this information that it feeds back to true, true, uh, ETM? So when you say agent, you mean the cloud agent or the agent?
AI agent? I'm talking about an agent, AI agent. AI Agent From other security Companies.
No, that's, I mean, down the road. Right. Um, I think, I think that's where we're headed.
I think initially what is happening is organizations are first building agent AI agents using their own internal NCP servers. Right. Or agent to agent protocols.
Right. Now that will expand into exposing your MCP server. Yes.
So others can call you. And that's, and that's what's now by the same token, it could be another company's agent that Yeah. You know, because at the end of the day, I think this We'll call as an example.
Yes. Yeah. We're all gonna have as individuals, as companies like an army, a fleet of agents, they're not all gonna be from Salesforce or ServiceNow or Qualys or, or what have you.
Right. How well those agents interact with each other. Yes.
Who manages that. Correct. What information, I mean, these are all the devils in the details that need to get worked out still, but, but that is the where the future is.
Yes. I mean, there are use cases where, you know, we've taken open source large language models and we've said for our security use cases, how do we tune it to our use cases? And we've done that.
Um, we do have, um, generative AI and agent AI now completely embedded across the fabric of the platform. So, so we are using a mix of in-house. Uh, we are also using other, uh, frontier models, large language models that are available on public clouds.
Mostly because this space is innovating so fast that if something new comes out, if it's in a public cloud, I can immediately tap into it within hours. Right. If I have it in house, it's taking me more time.
And, and we do want to be ahead here. Uh, you know, we feel we are onto something, uh, that are very few organizations that have come up with this concept of integrating agent a i into the platform and then building cyber risk. Digital employees cyber risk assistance.
Right. Cyber risk agents. Right.
And the way we are doing this is we are saying, we know security teams are resource constrained, but now here are all these cyber risk agents, which are all, there are all These resources, Autonomous agenda. Right. And you can delegate work to them.
They will go off and do it of course. With the right kinds of guardrails. Right.
Right. Um, which is important right now. So Let me ask you the 64 billion or $640 billion question, when does this vision become real, like available to people out there now?
So the out of the box agents, they are ready right now. In fact, um, during this conference at our demo boots, uh, folks who are trying out the product and looking at these agents, uh, they're actually using the real product. The way we will, we are looking at this, is we are building a, a whole bunch of out of the box cyber risk agents that will automate specific workflows, independently do things, whatnot.
Those will start getting rolled out over the next month, two months, and then keep coming out. The next thing we will do is we will give you the ability to build your own cyber risk agent. Right.
Where you can, using a, using a cyber risk assistant, a chat mechanism. You interact with the platform, you identify a body of work, and then you say, now I want to take this and I want to automate what this does, or take actions based on this and I want to do it at a regular cadence. And then you can have your own out of the box agents.
Think of it as an employee. You hired A digital worker and You're asking him And you've trained it, Just go ahead and do it. Absolutely.
Yeah. So yeah, this is not six months out. It's here Now.
There's a percentage of people who are watching in this at home Yeah. Or at work. And they say, great, it's gonna take my job.
What do you think about that? I don't think so. Um, and it, it's not just cybersecurity.
No, no. This is not a cyber, it's This is everywhere. Right.
Everything. I don't know if you saw the, uh, there's a YouTube video came out from that company figure AI that makes the robots. Did you see the newest one?
Version three? It folds close, it delivers packages, it works at the hotel reception desk. Yeah.
It's everything. Yeah. It's everything.
So this, this obviously is innovation that will change the world. Yeah. I believe in that.
Yeah, Me Too. I think we should all believe in that, uh, instead of resisting it. Yep.
I think the way to think about it is how will it complement what we do? Uh, internally, as an example, we are using coding copilots, right? We are seeing productivity gains.
I mean, clearly we can see that, uh, anywhere from 20% to 50%. But what I'm also finding is, as an example, the best productivity gains are coming from my best engineers, my top most engineers. So this is not about, I don't want to invest in people because you need very talented people to actually also work with these kinds of tools.
Right. So in some contexts it will augment, it'll compliment, you know, it will make you that 10 x person. There will be instances where it will automate entire roles.
Yeah, for sure. Um, but it will open up other opportunities, Lots of them. And history is full of that.
Right. And that's exactly lesson Comes Out, lesson of history comes, right? Yeah.
It always creates more jobs than it takes opportunities. Yeah. And what I tell That you can't think about today, I tell people a similar thing to what you just said, which is if you embrace this, embrace it, internalize it, understand it, it will make you more valuable.
For sure. If you resist it, ignore it. Yes.
Yes. And what will be will be then. Yeah.
That's not a good place to be. No. So Yes.
Hopefully I'll, well maybe certainly next year I'll see you at this hopefully. But hope maybe before then it will continue this conversation because this is changing so rapidly in three months. Let's see where we are.
Yeah. Di always a pleasure. Thank you for another Great, thank you for having me conference here.
Thank you. Thank you. We're gonna take a break.
I think we've got one or two more interviews coming your way, uh, this afternoon. We're wa we're live in Houston at Qualys. Rock on.
You're watching Text Drunk tv.