Mayuresh Ektare on Translating Security Risks Into Financial Terms and the Rise of Agentic AI | ROCon 2025
Mayuresh Ektare discusses enterprise risk management and the need to translate security risks into financial terms and the importance of both reactive and proactive measures. The role of a Risk Operation Center in risk telemetry is emphasized, along with challenges in managing cybersecurity tools and the potential of agentic AI for decision support. The session wraps up with thanks and future engagement anticipation.
Transcript
Hey everyone. We're back here live at Qualys Rock on conference in Houston. We are, uh, we've been going all day on this.
I hope you've enjoyed our coverage. We'll be going for the rest of today, through tomorrow. Well, we will take a break tonight, but we'll be back tomorrow with a full day.
Um, for my next guest, I'm happy to have back, we, we actually interviewed him last year, if you remember, at the qua security conference. I want to introduce you to May, Ash. Ari, I get it.
Yeah. Thank you so much for Thank you. Having me here.
May rash. It's my pleasure to have you here. Um, as I mentioned, we, you were here with us last year and, you know, different one may say a different, uh, a different, uh, conference name, but still, nevertheless the same kind of stuff.
Um, ish. Let's start with this. Why don't you introduce yourself to the audience, give them your role here at Qualys and maybe a little bit of your background.
Certainly. So ish, I lead the products for enterprise true risk management here at cos. I'm the VP of products there.
Uh, been in the cybersecurity industry for 25 plus years and really came to cos to drive this strategy of transforming our business towards really this holistic risk management strategy that we have defined back in San Diego About a year ago when we first met, uh, we had just launched the availability of enterprise tourism management and since then we have seen tremendous success in the market industry. Uh, there are over hundreds, uh, plus customers who are using the solution now. Millions of assets and findings being tracked and managed within enterprise release management.
So we have seen a phenomenal eruption of the solution in the industry. Absolutely. Absolutely.
Um, you know, ish, I've had a year to sort of percolate on this as I'm sure you, you've had. Yep. I, I think inherently there's something appealing to the security teams of the world that say, Hey, instead of measuring how secure we are or how good a job we're doing by how many vulnerabilities we, major vulnerabilities we close, or by how many patches mm-hmm.
We, we applied or, or, you know, some kind of metric like that, that we're actually, uh, translating our risk and security to dollars and cents to the organization. And that that was always sort of a missing translation. That's right.
It's like at some point we decided, look, to secure the house, we have to lock the windows and doors. Right. So we gotta lock all the windows and doors.
Well, for the last 20 years, we've just focused on locking all the windows and doors. That's right. Almost forgetting that we were doing that to secure the house.
I had this conversation with Ed earlier to, to me, this whole concept of a, a risk operations of a rock true risk gets back to why are we locking the windows and doors? Precisely. Yeah.
What's so valuable that you wanna protect Exactly. And, and if it's not so valuable, maybe we shouldn't be jumping through all these hoops for something that's just not valuable. Exactly.
Exactly. So, you know, uh, for security professionals understanding, um, what we are protecting is equally important. Not just that controls that we are using to protect our organization, but actually the value that is at risk, you know, it is critical for security professionals to really understand that.
And that is essentially the risk driven approach towards managing the security controls. There are two parts to security, the reactive and the proactive. Right.
You know, uh, the reactive side is mostly, um, a wartime exercise, and there is a proactive side, which is a peace time exercise, you know, which is, uh, more about cyber hygiene, making sure that those doors and windows are locked. Right. You know, there, it's not an active burglar or a thief that is trying to break in.
It is really more about every night before going to bed, you wanna make sure that all the doors and windows are locked, right? So, uh, these functions are sometimes, you know, independent, the personas, the people who are actually dealing with these situations are different people, you know. So, uh, risk operation center really allows, uh, the proactive security folks to really take into consideration every single, uh, risk telemetry across your entire attack surface and really distill it down to, uh, uh, a, a scoring mechanism that would allow you to understand the actual risk that you might face by not having a certain door or a window locked or unblock.
Love it. You've had a year to play with this now or to think on it to grow with it, to, you know, get comfortable with it. That's Right.
What is your, like what's your, what what's been your learning from last year to this year? Yeah, um, great question, by the way. So what I really see is, uh, you know, CE programs are evolving.
You know, we all started with, um, vulnerability scanners. You know, these are like two decades ago now. Vulnerability scanning was sort of, um, a year, uh, you know, migrated or I would say, uh, upgraded towards risk-based vulnerability management then came along CE programs.
Uh, and now what we actually see is CE is just one part of it, but there is an adjacent area which is, um, uh, you know, CRQ cyber risk quantification, right? Or think of, uh, automated compliance. Those are all coming under the same umbrella.
Right. You know, and risk operation center sort of provides that function, a single pane of glass to support all of these different use cases. As part of this, uh, journey, what we have also seen is there are, uh, typically three independent teams in any large organization and infrastructure security or vulnerability management team, cloud security team, and the application security team.
Each one of them has tools of their own choice. Yeah. Um, you know, programs of their own processes of their own.
We see more mature organizations sort of putting them under a single framework for holistic risk management. And that is essentially a definition of what a rock is. Yeah, absolutely.
Uh, you know, it's always been an issue in security, right? The average organization, depending what study you listen to, 36 different products, 60 something different products, it's impo, it's hard enough to do security. Just security's hard to try to manage 50 plus different security products and make them talk to each other and work together.
Ah, I mean, it it, it's kinda like a tower of Babel, right? When no one talks the same language when we really should be talking the language of risk. That's the common language.
That's right. Yeah. That's Right.
Yes. One thing that we didn't really touch on last year probably too much, was this notion of ai agentic ai. Hmm.
It's been the story though, and continues to be the story. That's right. So, um, and, you know, agentic AI capabilities are also, uh, pretty rapidly evolving.
The fuel for agentic AI is really the data. And what we have also seen now is cybersecurity is also a data problem. Like you rightfully mentioned, you know, there are dozens of tools.
What are these dozens of tools doing? They're actually generating telemetry, risk telemetry, you know, I oftentimes call most of the security posture management solutions as point and shoot weapons. You know, it is almost like a weapon you pointed at an asset.
And out comes the list of findings, right? But what do you do with that finding? That is data, that is raw data.
That data needs to be, uh, consolidated, correlated, uh, you know, overlaid with additional intelligence that you need to, to make sense of. And we really see now, uh, such aggregated dataset as almost like a digital twin of customer's infrastructure that you can use for, uh, querying so that next time you have a celebrity vulnerability, you know, you're not chasing 10 different dashboards, exporting data, correlating them to understand the exposure, but you already have this centralized inventory, or not just of your assets, but the risk telemetry as well, which can be, uh, you know, uh, deployed to understand the exposure. Coming to agentic ai.
Agentic AI is really interesting because, uh, it's not just, uh, um, uh, you know, generative AI like prompt driven interfaces, but there is an action associated with as well. You know what, uh, agent DKI, uh, really promises is autonomous decision support, which is what security teams lack today. You know, uh, over the last decade, we all have had, uh, uh, you know, workflow automation.
Now, agent DKI should not be confused with workflow automation, which are, uh, you know, predefined rules that you simply want to orchestrate, right? Uh, that has been there in the past. What Is, to me that's more like BPA kind of stuff?
Precisely, precisely. With the agent. TKI, what we are actually bringing to the front is, uh, autonomous decision support with ever-changing threat landscape with newly discovered findings and vulnerabilities are these cyber risk agents in a position to make a decision and suggest a remediation strategy that you can implement at scale so that you are not, uh, employing humans to really match the speed of detections, right?
Uh, as opposed to, uh, uh, you know, having, um, uh, cyber risk agents actually perform some of these tasks, offload it to the, uh, AI assistance and really have humans focus on those advanced critical areas that, you know, agentic AI is unable to process. I love it. I love it.
Just wanna look at our notes here. My, my, I should make sure we, we've covered, um, I, I, I think, look, looking at this, I want to return back to rock. Look, it's new, it's a new concept.
Well, it's an old new concept, right? Risk management, but you're asking companies to change. Change is never easy, never easy, right?
So how are, like when you talk to customers, how are they operationalizing this change? Right? They may buy in, it sounds great, I'd like to do it, but how do I get there?
Yeah. So, uh, the great point by the way, so, you know, in theory it all sounds great, uh, but also what's happening behind the scenes is that, uh, customers, we are all trying to implement a rock without calling it a rock, right? Right.
Um, I haven't seen a single, uh, fortune 500 that do not have a cybersecurity data lake. What they do is they manually export the data from each one of those cybersecurity posture management tools, dump it into the, uh, security data lake, try to stitch it somehow. Uh, and these, the, these activities are all performed manually, right?
So it's not like a rock didn't exist in a concept. It is now that cos is actually bringing it to the forefront that you really don't need to build this in-house on your own, but, you know, in a cybersecurity data lake. But, uh, time has come for, you know, a commercial solution to really address this burning need in the industry, to consolidate the data, make these tools speak the same language, and really make sense of this fragmented data that resides in our organizations.
Like us mentioning earlier three programs, vulnerability management, cloud security, and application security. These are all coming together and, you know, these three programs actually employ dozens of tools. Just take into consideration application security.
You have got static code analysis, SCA infrastructure as code, dynamic code analysis, pen testing tools. Right. You know, so this is an ever-growing number, right.
You know, and how do you make sense of it? Because a vulnerability in a code will eventually make its way into production, and that production application is gonna be deployed on a server somewhere. So you need to have a com comprehensive wave, not just code to cloud, but also the infrastructure that that application is deployed on.
The only way to have this holistic view is by bringing this data together in a risk operation center. Whether you call it a rock or not does not matter. Right.
What you're doing with the data is The other name. It exactly spells the same. Yeah's a quote Shakespeare, huh.
Anyway, Larry Rash, I wanna thank you for coming on and talking with us today. Continued success. Keep us posted.
Let's not wait till next year to see to talk more with you. Maybe we could see you, I don't know. We'll be at RSA in March, or Yeah.
Some of security conference or another. Absolutely. Thank you for all you did.
Thank you so, so much for having me. All right. We're gonna continue live here at Qualis Rock on.
You're watching Techstrong tv.