Shailesh Athalye on Aligning Risk Management With Business Impact at Qualys | ROCon 2025
Shailesh Athalye discusses his role in managing risk operations at Qualys. The focus is on mapping risk to business operations and financial impacts. Different teams interpret dashboards in various ways, prompting a need for a unified dashboard that aligns with company goals. Qualys shares its internal risk management practices and insights on compliance with FedRAMP.
Transcript
Hey everyone, it's Alan Shimel and we're back here at Qualys Rock on in Houston. Of course, rock On is risk operations, uh, conference, and we're here to talk a little risk operations with y'all. Let me introduce you to Shalesh.
Yeah, you got it right. All right. If you've watched our prior coverage of prior Qualys conferences, like the Quala Security Conference, QSA, you've seen Sheesh talk with us before, but sheesh, most people probably, if they did, they don't remember.
Tell us about you, your position at Qualys, a little bit of your journey coming here. Yeah, absolutely. Thanks so much for having me.
Again. It's always a pleasure to talk with you and your audience so quickly. Charle, I look at the products, go to market strategy and now solution architect team for Qualys.
My job is essentially to make sure that what I'm hearing from customers is translated as product capabilities and then see to it that our teams are working with customers in making these capabilities map to their use cases and they're successful. Absolutely. You know, Shilesh, we've done a lot of interviews today and a lot of it obviously around managing risk and risk operations.
One of the areas I wanted to you to expand on was this is more than security, right? This is about more than security. Part of this whole reason to do this is to map the risk and, and the, I I don't wanna just take it to dollars and cents.
Yeah. But to wrap, to, to map the dollars and cents Yeah. Of this risk Yeah.
To business operations and how, not just security remediation, better vulnerability management, et cetera, how not just security, but all kind of business operations Yeah. Plays into this risk, right. And risk management.
Yes. So talk, if you don't mind Yeah. Talk a little bit about, you know, mapping that.
Yeah, absolutely. I, I think one of the parts what, uh, risk Operation Center does is trying to move the conversation away. Like Sumit talked about it from how many vulnerabilities do I have, or how many patches do I have?
Or do have I implemented MFA, et cetera, to actually what is the impact of me having less number of vulnerability on business operations and the business value. Now, how we are looking at doing that is essentially seeing that, you know, one on one side of the spectrum, like you talked about it, that there are business operatives or executives, they wanna see everything from what's my dollar value, what's my business impact, how much I'm spending on cyber insurance, and what is impacting them. Now, what impacts them is a simple checklist, is my patch management policy effective or not?
Is my ransomware prevention working or not? Is my permission management working well or not? Now, what we are doing bottoms up with our security audience is to not get overwhelmed with this dollar value and all these policies, we are bubbling up the contributing factors of this true risk, such as if you have, let's say, 10% of ransomware vulnerability, then look like Mr.
Customer, you could be in your cohort of lower 50% of customer base. That would mean when we compare all of these cohort of insurance policies and the breaches related records look like there is a 10% chance of you getting a material breach. And that means your patch management or vulnerability risk management process is of lower maturity.
So that's why your truist needs to come in, in 200 to 300 range, so that all of these upstream systems will provide the result to your executives how both of our improvements would result into me having lesser chance of a breach, lesser chance of me losing money. So that's how we are trying to tie the cyber risk and exposures to the higher level dollar value and its impact. That was the best, uh, explanation we've had today.
So you wouldn't enter, apply straight that one. You know that That's one chance of looking into products and actually owning that area. Yeah.
Good for you. Um, you know, sum, Matt and his keynote today mentioned the phrase that I left. Actually, I spit my coffee outta my mouth, but I told him I'm gonna steal it and use it.
Huh. And that is this, uh, dashboard tourism. Yes.
Right. Or dashboard terrorism even too. Um, you know, and that is, everybody has their own unique view on a dashboard, right?
Yeah. And so whether you're on the security team, the executive team, the dev team, the ops team, the DevOps team, right? We are all, we're all looking at different views of the same underlying data.
Yeah. And, and I think it becomes like, uh, it's almost like a Tower of Babel where we all talk a different language. Yeah.
And I don't understand what you talk about, but your people do. And my people understand what I talk about, but not what you talk about. And you know, I think part of the, of the mission for for Rock Yeah.
Is to make sure we're all talking a similar language. Yes. An understandable language.
Yes. Right? Break down the silos that exist even in security.
There's so many silos, let alone once you go outside of security. Yes. Talk about that mission.
Yeah. That, that's interesting. Alan, you said that at the end of the day, I, I know that was, was really well put by Sumit, you know, as, as an interesting witty command.
But at the end of the day, if, if you see the psyche behind the dashboard is also about why am I creating it? 'cause if I don't create it and track it, there's something I'm gonna lose. But that's something is very, very me-centric or my team centric or my org chart centric.
If you have to see even the dashboard, how, what we are trying to say is how can you actually see the dashboard which whole of your company cares about, all of your organization cares about? And that's where I think what you are trying to, yeah. Also, what is the common language, right?
Which is set by your whole of your company. And though the dollar value and the business impact is generally used as common language, there's still nuances, right? Like the public sector might not care as much as for the dollar value.
What do they care about? What's the risk to my mission statement? And I was meeting with one of the, one of the really high profile customer in dc what they care about is my mission statement is I need to manage the risk to my agents who are in the field.
'cause that's, there's no dollar value which can be assigned to their safety. So now how we look at it, okay, if, if you wanna manage the risk and reduce that risk to your agents in the field, what are the contributing factors which make this as a risk? So now how we help these bottoms up approaches of the security analyst, let's bubble up those dashboards.
Let's see to it how your dashboard now maps your company's dashboard and can we actually create one unified way to track it down? And that could be, you know, from your dashboard, how well your company's mission statement, your business value is tracked. So that's how we are looking at, you know, creating a bridge from me-centric dashboard to whole company-centric dashboard.
So all of us talk the same language, essentially. Got, got it. Excellent.
Let me bring up another. Sure. Okay.
Call you. So with this whole rocking Qualys has sort of been, some people say eating your own dog food, some people say drinking your own champagne, whatever you wanna call it, but Qualys themselves has been, have been using it and it's helped in the, uh, Qualys enterprise true risk kind of management. You know, they've been learning lessons internally is the bottom line here.
Can you talk a little bit about that? Yeah, great. Great question.
Actually it's, it's a two part answer if I may. Uh, so Rock is obviously a program and now program includes your people technology and tools and your processes around it. So Qualys is transforming its own platform to be the world's first risk operation, center driven capability or the product which will help customers tie all the Chevrons in risk operations center together.
So how can we get best asset inventory, which would become the base of your rock? How can you now get all these exposures together, which are typically used by the 70 plus What I'm hearing, Alan, like customers typically use 70 plus security products. That's what I hear too.
Yeah. They all generate their own exposure. So how do we actually bring them together?
How do they then correlate your threat feed business context so that we talk the same language so that we are able to actually prioritize the risk which matters to business and then try and reduce it and produce that report as an evidence, as an outcome to our compliance auditors. Now, as all of these chevrons, we are trying to actually cater using the ETM as a product where all these capabilities will come together, where our true risk algorithm will work on all of these data indicators. We created true risk, eliminate capability to help customers reduce the risk.
How now that would come together to help customers reduce the risks. And now at the end of the day, we are not saying that you just call this product. Well the ETM, you can just connect your other products as well.
If you like your, my, i, I don't know, maybe your SCCM product to reduce your risk, it's okay. Like just create a job from ETM in your product to reduce your risk. That's from the product side.
What we are creating now, like drinking the own champagne part. As you all know, call is the biggest FedRAMP authorized platform. Um, probably number fifth in overall IT and security spectrum.
So we have our big FedRAMP audit as well as our security teams. They all need to do, guess what? They have to all cater to each of these Chevrons in own manner.
We used to use our own inventory differently. We used to use Qualys for assessment, we used to use another tool for reporting, et cetera. As we are combining all of these data points required for say, key elements of FedRAMP, what are the key elements of FedRAMP?
We need access control related requirements, vulnerability management requirements. Now all of these are getting unified signals to go into their audit reports. So this is what being the outcome of our ETM.
So every time, you know, customer comes in, in our data center, if you actually go in sometime Alan Niche, we should take you to our data center sometime to show you that. I'd Love it. Where is it?
So It's a two places. One is in us, the other one is in India where our teams actually have three types of monitoring. One is your noc, which is network operations, right?
On the right hand side we have soc, which is security operations and the right in the center, which now sits Our Rock, which is a risk operations center. Excellent. I, you know, I may take you up on that.
Alright. What you Awesome. We'll go from there.
Esh, we're about outta time. These are only 15 minutes. I appreciate you as always coming on here.
You know, I always, I I tell you the truth, I always listen to you talk. This is probably the third time we've died and I say he's the guy who gets it right. He, I, I am sure SIRS is leaning on him for a lot of these things and you have a great handle on this.
Thank, thank you so much. Thanks For all having me. Really always good.
You and your team. Thank you. Absolutely.
We're live, we're in Houston. We still got I think one or two more interviews. Two more interviews today.
So stay tuned. We'll be back on in just a moment. You're watching Textron TV.