Johnny Shaieb on the Shift from Vulnerability to Exposure Management
Johnny Shaieb, Chief Architect at IBM, shares insights on vulnerability databases and the evolution of Qualys. He explains the difference between vulnerability management and exposure management, emphasizing the shift towards Continuous Threat Exposure Management. The focus is on managing risk and the importance of governance in vulnerability management. The session wraps up with a discussion about Johnny’s academic journey and future goals.
Transcript
Hey everyone. Welcome back. Hey, you know what?
We're gonna sneak one in here before lunch for you. I've interviewed this gentleman before. I'm going to, I give him a quick, uh, couple minutes here.
Johnny Scheib. Johnny, welcome man. Well, thank you so much for having me.
It's good to see you. Uh, another year back Here. Yeah.
Johnny, for people who are not familiar, give 'em a quick background on you. So My name is Johnny Scheib. I am the Chief architect in Global Delivery Lead of Exposure Management at IBM.
Mm-hmm. And, uh, one of my passions is I'm almost finishing up a PhD in cybersecurity where I'm doing the whole history of vulnerability databases and scoring. And what was really interesting last year in San Diego when we were walking down the hall and you could see like the whole history of Qualys.
Yeah, I remember that wall. Yeah. And it's by no surprise that, you know, Qualys has been around for over 25 years and so has CVE.
Mm-hmm. And so a lot of people don't recognize that Qualys was one of the original, not original, but early board members of the CVE editorial board. Yes, Yes.
I remember those days, right. That you had found Stone ei Qualys. Rapid seven wasn't even done yet.
It wasn't even born yet. Um, uh, tenable was Nessus. I don't know.
Yeah. Well y yeah, there was, there was Cisco and Microsoft, Cisco involved. Yep.
You know, Johnny, I want to, 'cause I know time is short, I wanted to ask you to quickly define for our audience, in your mind anyway, at least the difference between vulnerability management and exposure management. So this is really an interesting journey. That's why I brought up the history is because when we started, Qualys was just a tool.
And then we saw it, you know, over the years become a platform with siloed tools. And now it's a platform where you have a whole bunch of different abilities to scan multiple different scan attack surfaces that uses predictive analytics to connect to everything together. So vulnerability management is really that traditional CVE and then helping the client, uh, migrate, you know, from web application scanning to policy compliance to the next best thing.
And what's also interesting, in 2022, Gartner came out with CTM continuous threat exposure management. And one of the things that Qualys does really well is ETM being able to ingest the multiple data sources to provide the most expensive thing in vulnerability management. And that's really normalization, going and ingesting multiple data sources and enriching them.
And that's how Qualys saves time. You know, money and time with, with clients that have, you know, that are trying to define the battlefield in the battlefield has always been asset inventory, but trying to figure out where that asset inventory is, could be in ServiceNow, it could be in a remediation team, could be in Tanium, could be in Qualys, all different sorts of places. Absolutely.
That was great. I I think the audience will appreciate it. Let's now bring it over to rock to this risk operations.
'cause to me, I've been in security 25, 30 years too, Johnny, and we seem to have forgotten maybe that security is about managing risk. Yeah. It's not about eliminating every vulnerability, mitigating every exposure.
It's about making decisions about where we should make our bets. 'cause we may not be able to do everything. How does that fit into your timeline view, if you will?
Yeah. You know, like going back 25 years, uh, not until 2004 was there A-C-V-S-S score, right? So Qualys got into, um, severities of critical, high, medium, and low.
And then CVSS came in and, you know, at the time back then, it's a venerated score. But we needed to move to severity how bad something could be to the probability or the likelihood. And that's where true risk comes in.
But I had a little spin for rock. Not only does it stand for risk operation Center, but it could stand for remediation orchestration center. Wouldn't it be cool if we had this tool, which we really did, which we really do now, but to have this tool, this platform, not a tool platform that has the ability to go and identify a vulnerability, manage the lifecycle of vulnerability from its initial identification, assigning a ticket, and then being able to remediate.
Yeah. And that's really what the, the power of quality. I know like it's, you know, it's uh, very branded to risk, but it's one of the only vulnerability management platforms that allows you to fix.
But yeah, I'm trying to, all the elements Of vulnerability, Not the DVM, they, they do have a name for what they have that does that. And I just don't remember the initials, the acronym right now. The, the what?
The, the acronym for the, for the like total lifecycle. Oh, fixing SDLC. Yeah.
No, no. That's for No, just specific for Qualys. Uh oh, okay.
Product where you, do you track finding the vulnerability to re remediation to Well that, that's, that's really special because not only is of, it's a platform of risk and orchestration, but it's really a governance tool as well. And again, it's like wouldn't it be cool if you have the ability to provide that governance by assigning accountability? How do you do that by tickets?
But you can't assign that accountability tickets unless you can fix somebody's asset inventory. So what's neat about CSAM is now you have the ability to go and tag and bag assets and quals creating kind of like a poor man's database, if you will. And enriching and fixing ServiceNow.
Then what happens now you drive down vulnerabilities because you just were able to assign tickets to somebody. So now you have this risk operations center that you use for governance that you also use as, or an orchestration platform. It's the trifecta.
And you could have agents run all of that. Yeah. Johnny, we're about outta time.
Thank you. Got our next one So much. Forgive me.
Let me ask you, if we see you next year, you gonna have your PhD done or what? I will Good For you. We'll call you Dr.
Johnny then hopefully. Alright. Thank Johnny Ed here at uh Qualys Rock Con.
We'll take a break. We'll be right back.