Sumedh Thakar on Proactive Risk Management and AI’s Role in Cybersecurity | ROCon 2025
Sumedh Thakar focuses on evolving risk management strategies from traditional to proactive methods. Cybersecurity is a key aspect of business risk management, highlighting the need for effective communication of risks to stakeholders. The event discusses the future of risk management, expanding beyond cybersecurity, and acknowledges AI’s critical role in addressing cybersecurity threats. ROCon also provides free training sessions and plans future events to enhance attendee learning.
Transcript
Hey everyone. We're back here live at Qualys is Racon conference. If you've been watching our stream all day or this morning, I've explained what ROC on stands for Right Risk Operations Conference.
But I wanted to go to the very top to get you an explanation of why ROC on. Right? For many of you who've been following Techstrong and the security industry over the years, the call security conference QSC was kind of a staple.
A lot of us have gone to it and you know, whether you went to the one in Europe or North America, or the one near at RSA or whatever, Quas Security Conference, now we're doing Qualis Rock on. Let me introduce you to my friend Summed car. Summed is the CEO of course, of Qualys, but he's the guy who, who made it.
Qualys. Racon summed. Welcome.
It's great to have you here, man. Well, Thank you very much. I always enjoy doing this with, Always a pleasure, man.
So look, I gave him this much. Yeah. Give me the whole story on Raan.
You know, If you remember last QSC, we talked about the concept of a risk corporation center and the notion of like evolving a rock out of the soc Yep. So we can really focus on proactively managing risk. And, um, you know, it was, it was a new idea.
Like we did patch management a few years ago. Didn't know how it was gonna go. The feedback was phenomenal.
People love the idea of the rock. Uh, and we started to kinda see this like appetite for people wanting to have a conference that was really focused on cyber risk management overall, rather than a, a tool specific or a technology specific, or a vendor specific thing. Uh, and so I felt we can expand this audience.
We can, um, it takes a Village Forest risk management. It's not just the guy who's scanning, it's, it's really bringing the ICIO team, bringing the CFO as part of the business conversation. How do you report to the board?
So the idea of the risk operations conference was, look, at the end of the day, you know, as I talked about in my keynote dashboard, tourism is not getting us anywhere. We need to get things operationalized and fixed. And so having a conference where people would come talk about, um, risk management and how to operationalize it end to end agnostic of the tool, um, was really well received by folks.
And that's why we came up with the ROC, the Rock conference because this will continue to grow and, uh, give people a forum to come and discuss proactive risk management rather than just always being in reactive, uh, detection and response. Uh, and that's why super excited about Rock On. I am too.
And, and I, I'll tell you something. First of all, I think it's brilliant because it lifts what was in essence a user conference Yes. To a whole different plane.
Yeah. Which is, it is the risk operations conference. And, and I think one day we'll look back Sue Cement and say, oh, yeah, they did the first one in Houston.
It was a smaller one. Yes. This will take on its whole, you know, there was a time where the RSA security conference was just about the RA Yes, exactly.
Yeah. Encryption right. Now, of course, it's Chris.
As someone who's been in security 30 years, it's always been about the risk Yes. And, and managing risks. Yes.
We just don't seem to remember that all the time, but it's always been about it. And, and so again, I I, I think it's a great, great thing for there. You mentioned a couple of other things though, and I, I want to jump into those.
Number one, it was a great keynote this morning. Thank You. I, I think, and again, this is something that was so important to me as a person, as a security person, was the concept that we gotta get out of being the bad news generator.
Yeah. Especially in vulnerability metric. Yeah.
The bad news generator, we gotta get out of saying, oh, I've got a hundred thousand vulnerabilities with, you know, 10,000 cvs and Oh, I got my work cut out. Right. One of the biggest things, I, I was talking to our keynote from this morning.
Yeah. And, um, I, I get, get to what here, and we, and we spoke about that was, you know, he was the CISO when CISOs first started becoming, but that was the CISO's job to convert security talk to business talk. Yeah.
And businesses talk risk. Yeah. Right.
And so, again, I think it's such a great thing for us as an industry to say, Hey, we, we can't keep doing this chicken little thing. Yeah. The sky's falling.
The sky's falling. We need to talk right to the board, to the exec team, to the business. In business terms.
You use the term digital tourism Dashboard. Tourism dashboard tourism, excuse me, dashboard tourism. Yeah.
I'll be honest with you, I almost spit my coffee out. Um, talk to me, what, explain to our audience, what do you mean? You know, I think we've sort of come from this thing of, well, cybersecurity is about visibility.
And, and I think we invested so much in visibility. We sort of almost over rotated on visibility. And so today, when you ask anybody, oh, my security posture view, and then you have one for SaaS and one for cloud, and one for on-prem and one for user identity.
But it's all just dashboards that show you the bad news. And so if you ask somebody what's the posture view? They have one dashboard from code scanning, one from cloud, it, it doesn't make sense to, from a business perspective, right.
Because if you take a mobile banking application for a bank, it's using capabilities across each of those tools. But they don't come together and tell you, oh, what's my risk to my mobile banking? Yeah.
You can get your code top 10, you can get your cloud top 10, you can get your identity top 10. What does that mean to the business? And so I felt like we spent so much effort in building dashboards, and then things don't end up actually getting fixed.
Yeah. Because we don't know what to do after that. People don't listen it, teams don't.
So this idea that we gotta, we gotta move at the speed of AI and, and, you know, be able to actually make an impact means we have to get away from building dashboards and taking selfies with these dashboards into, I don't really need a dashboard. I just need to get stuff fixed. I need a dashboard of what was fixed rather than a dashboard of what's broken.
So that's where, you know, that's resonated really well with our customers. They love this idea that we, we don't want more dashboards. We just want to fix things.
I gotta tell you from my heart, it's not just a security issue. Yeah, that's true. You, we sales not mentioning names, but Salesforce could use this lesson, how many dashboards?
And and that's like, because I think we've gone to this notion that we need a custom view for every single person in the organization. Oh, you're a CIO, you get this view, you're A-C-I-S-O, you got that view. This guy gets this view, this team gets that view.
Right. You can't collect enough stickers for all these dashboards. And they're all, there is usually only one truth.
Yeah. Right? Yeah.
Yeah. Just how many ways do you want to color it? Um, so again, major kudos to you, Onna.
Thank you. I I, and as I told you before, I'm going to be using that over and over and over. And so we'll, we'll get to use it.
Here's another thing. I was talking to a friend of mine who's just starting a company. They just got their seed funding around risk.
Yeah. I said, are you gonna do security? He said, no, we're doing risk.
Yeah. For those of us out here who are saying, wait a second, risk is security. Security is risk.
Yeah. Yes and no. How, how do you delineate between the two?
I I mean, look, the, if you look at a company, a company has many different risks. There's financial risk, there's risk to sales, there's risk to product development. And cybersecurity is one risk factor for a company, because cybersecurity is about managing the risk to your digital infrastructure.
If something happens to digital infrastructure that'll impact the business, that's the risk you need to manage. Right? And so, uh, yes, cybersecurity has always been risk management.
They're not really separated. It's just that the way we have been looking at it is initially we came from best practices, right? If I lock all my doors and windows, I'm safe.
So let's focus on doing everything to lock my doors and windows. But then you start to get to the point where you're like, I spent 500,000 making sure all my doors and windows are locked, but what my, what was my possible loss was only $50,000 in the drawer. So now you're suddenly saying, wait, wait.
Like my attack surface is big, but what am I gonna lose? Is not that big. So should I be spending so much money on that?
So at the end of the day, like any risk management, like your car, a car insurance, a fraction of your overall car's value should be your car insurance. Yeah. Is the same with cybersecurity, right.
There's a fraction of your IT spend should be spent in protecting, and what is that fraction? And that has to be tied to how much risk you have of losing money. And that conversation has not happened for a long time.
People just kind of come from best practices. But now I think it is the time where we feel like people just cannot fix everything. And so, which means that you are taking an inherent risk by not fixing it, by not fixing things on time, you're digging an inherent risk.
So why not be deliberate about the risk you take by actually measuring and quantifying and focusing and being proactive saying, this risk, I'm going to fix this, I'm not going to fix, versus today is just slipping away from you. And so you're taking a risk. Now, I, I agree with you again there.
I, I think what happened, it's almost, you know, you sometimes like people start doing things, and I don't wanna pull religion into it, but people do things because it was traditional to do in religion. Yeah. Right.
And they almost forget the reason they were doing it. So we lock the doors and windows because that's what we do. Yeah.
Not, you know, you have to keep your doors and windows locked. Right. But not that keeping my doors and windows locks means they can't steal these glasses or something.
And what's it worth to the glasses? We, as an industry, I think we, we went out in the woods on that a little bit and Totally, Yeah. That's the, that's the evolution, right?
I think the reason this was not a big deal in the past was because we were not approaching cyber budgets to the point where people were like, I mean, how much more can we get spending? Like, what's the limit? The problem with risk management is if you don't define how much risk you are fighting an infinite risk, you can spend any amount of money and still not feel safe.
Yeah. So that's where the last couple of years and the number of issues coming up has exploded. The speed issues are being exploit, being exploited, and the budgets are not keeping up.
And so then the question comes, while if we have a limited budget, limited people, what should we focus on? We cannot fix everything. So that's where, what we should fix on what causes risk.
Now, is it just the risk of somebody coming through the door? No. It's the risk of what would happen to the business if somebody came through the door is the, the real challenge.
Right? And so I think, uh, I feel like it's, it's a maturity journey right now. And we are all sort of coming in with having spent a lot of money on all kinds of tools.
And now is the opportunity to say, how do we tie it back to the business so we can have a business conversation. Security should not be the bad news better. And, and the cost center, they can actually be an enabler back to the business by reducing the things that we are fixing, giving time back to the IT and dev team so that they can contribute positively to the company's top line.
You know, 25 years ago, 23 years ago, I remember asking my team to come up with like a ROI calculator. You probably think the same thing. And for the longest time, kind of the dogme in security has been, there is no ROI calculator.
It's, it's impossible to measure the ROI of security, but you can measure the ROI of risk. Yeah. And I think, again, that is something that's like game changing where we can say, Hey, you know, if you spend X amount of dollars, you're gonna reduce your risk by Y.
Yeah. And here's your exposure, Right? The, I mean, we, That's exactly what it is, right?
Is like, basically you're saying that your cybersecurity spend is going to reduce risk. And the ROI on cybersecurity is how much risk did you reduce for the organization? Right?
That's it. Right? I think in the, some of the previous attempts at, at quantifying an ROI have been too tactical where people start to put a, a dollar value on a server and a dollar value.
I mean, and that doesn't scale. No. At the end of the day, you have a business, the business is generating certain amount of money, you may have a subsystem of that business that, you know, generates half of that.
And so now you can break it down in, in the top five, top level, you know, sort of revenue generating, um, applications or business entities. And then you can align the risk, right? Or what if there is a ransomware at attack, how much would I lose?
And then if I know how much I would lose, then how much would I spend to reduce the possibility of how, how much, how much I would lose, right? So that conversation is what we are enabling, and that's why having the risk operations conference here is really about, uh, expanding the persona. We had a board cha uh, panel right now, right?
Where board members talked about how they look at cybersecurity. See, so talking about risk, we have a panel later for CIOs. We have cyber insurance, we have a lot of conversation around expanding the conversation around cybersecurity as a risk management, beyond just, I got these many cvs and I gotta fix them.
I got it. I want to pivot a little bit and talk about something else. So as the CEO of Qualys, you know, it has a certain visibility within the Yeah.
Marketplace. Do you feel, so are, are you the missionary on this mission? Is, does the rest of the industry gather around and say, yes, this is what we need to do?
Yeah. We gotta get away. I mean, Yeah.
It's a dead end if we don't, right, right. Understand, right. There's more vulnerabilities than ever.
There's more bad things than there. Yeah. AI's accelerating it.
You gotta get off the hamster wheel at some point. Look, I think I, I don't know about the mission or not, or missionary or not. I think the way I look at it is like, uh, not so much about the industry, but our customers are telling us in different words what the challenge that they're facing.
So they don't say, I need a rock, but they say, I'm facing budget, uh, I'm facing issues, uh, ex explaining the, my budget as to my CFO. And you start drilling down into that and you start realizing. And so for me, I believe when like Qualys has always done this, we were the first in SaaS and cloud.
Uh, I, You feel there was a cloud, Right? I was the first one to come up with patch management with vm Yep. Where everybody said it's not gonna work.
So it's the same with the risk cooperation center. I think the response from our customers have been, especially at the CSO level, has been this is exactly where we need to go. And so, um, we see them rally, right?
You, you talk to Rich Ierson, I mean, he does this board reporting workshops and we have like over subscribed on CISOs wanting to come have the conversation. So I feel like that's the right approach just because of the feedback we are getting from our customers. And we are always gonna be visionary from that perspective.
Uh, we're always gonna be disruptive to try something that nobody has tried before. And, you know, it, it's worked out for us many times in the past. If we stay the course, we believe in what we are doing and we listen to our customers.
And I think the feedback so far from risk corporations, uh, and the fact that they're over 400 people here at Rock on our First Rock on has more people than we had at QSC last year. Right? Yeah.
So that tells me that we have, it was really interesting today, right? I had a customer come and he has been a Polish user, and he introduced two other people from his company that came with him. And he said, Hey, this is my SEC ops guy, and this is my risk operations side, really.
So that is exactly what we, That's What you want envision is this is a conference that is bringing your risk team and your operations team together to have a common language of what we should do, why we should do something. What's the ROI? How do we measure ourselves from the investment that we're making?
Love it. Sumit, every security company I talk to says I want to talk to the ciso, the CISO's, our customer. But here's the fact there's like a hundred or more security professionals for every ciso.
Do you view, do they have to learn to talk the language of risk? Or do they rely on their CISO to be their translator? If you'll Yeah.
I, I think if you really look at every person working in cybersecurity is actually doing risk management for the company, they just don't know or think of it like that. 'cause the whole function is about risk management. And so, um, the evolution of this is that the CISO cannot be successful if the team that they have is also not aligned to that same idea and the concept that, hey, we need to triage what we need to do based on the risk to the organization.
And, and we just cannot fix everything, right? And the team is getting burnt out, and we are not having the success, and we just don't get to everything. And so, like I said, there is an inherent risk we're taking, we just don't know what the risk we're taking because we didn't get to what we're getting to.
So I think that that's where the conversation is really twofold. We, we got to get the people who are administering cybersecurity, um, to think higher level in terms of business and value and why we should, because communication is very important. One of the things I talk about is, is communication.
How do we communicate today? We give the IT team 10,000 cvs to fix. They don't like it, they complain, they still do it.
They come back, we communicate by saying, thank you very much. Great job. Here's 10,000 more.
Right? Word says saying like, Hey, by the way, by fixing these 200, you actually are the hero who reduced the risk of losing $10 million by 80%. So that is why we do need to make sure that, you know, this, this revolution of risk operations center is actually something that touches the people who are administering cybersecurity programs, um, engineering, cybersecurity programs, um, as well as CISOs who are then translating that into business speak.
Absolutely. I got two more areas I want question on. Number one, as I said before, a friend of mine's opening this company with risk, you know, their risk management, but not necessarily security.
Yeah. Do you foresee the rock becoming for more than cyber? It's, it's managing risk, not just cyber risk, Right?
I don't know that right now, but I do think that, uh, the, the rock will become the key piece for cyber risk management that will interface with the rest of the company's overall GRC function, right? Right. So if you're tracking environmental risk, you're tracking political risk, you're tracking military conflict, uh, risk supply chain risk for your business, then, uh, the risk operation center will give you the visibility that you need.
Um, you know, I think if you ask me 20 years ago, if you would be doing batch management and risk operation center, I would've said no. So I don't know where we go from here, but I do think that the, the risk operations and operationalizing risk is a common thread no matter what risk it is, right? No matter what risk it is, you have to, uh, quantify it.
You have to figure out how much you're gonna spend to reduce that risk that actually makes sense to the business. And there's a certain amount of risk you just have to accept. And having a framework that does that is great.
But today we are really focused on digital risk and cyber and, um, you know, maybe it expands. We don't know the Future. I think GRC is an area right?
For disruption. But what do I know? Um, one last thing.
Yeah. You mentioned Agen AI up there today. Yes.
Who's not mentioning agen ai, right? Yes. How real is it?
What do you think about it? When could are Qualys customers today? I think it, in a way, it's good that everybody's mentioning about it, which means it's real in many ways, right?
Like if you just have one vendor saying, oh, this is completely, that, that doesn't scale, uh, and people don't take it seriously. I think that what we are seeing is that attackers are using in the, there's no doubt about that, right? They are taking, uh, open source code and they're putting it through AI engines to find exploits that they can write.
And AI is creating those exploits. And so that's why in the recent man report you saw that the average, uh, time to exploit is, is negative one, which just means that more exploitations that happening before a patch comes out. And so the only way to respond today is to be able to do a leverage technology like agent AI to respond at the speed at which they are attacking us.
If they are using AI to say, create an exploit by looking at this code and run it against these 500 companies. And you are sitting there saying, create my Jira ticket, you know, go through seven approvals for Jira ticket. Lemme test my patch for like two weeks, and then, then you're, you're toast, right?
Yeah. And so I think agent ai, but it is also important to understand that, you know, you're not letting agent Ai, uh, lose on and doing everything in on a completely automated way. That's why today with what we talked about is the concept of a human and AI collaboration that coming, that is coming together so that the human security analysts actually are augmented with cyber, uh, risk analyst, uh, that are, you know, AI agents that are helping them do a lot of their tasks analysis.
You know, I mean, we've seen this in financial, uh, uh, analyst where financial analysts use AI to do research on a company so they don't manually go and do that. But that AI research is coming in and it's the same way, right? Like if you're an analyst, you need to get rid up, take care of Patch Tuesday.
If you have an assistant that's gonna, you know, come and, uh, do that for, you know, so It's human in the loop. Yeah, I understand. I understand.
We're out time. They're giving me all kinds of hand signals here, summed. But I wanna mention one thing for our audience out here, and that is, you know, in addition to the two days Yes.
Of the conference itself. Uh, rock on is actually four days. There's two days of training, which are sign up while you can, 'cause they don't charge for 'em.
It's free training. We, We believe free training. Yes.
And they're standing room only here in Houston. And so I know you're planning on other rock ons perhaps in Europe. There was one.
Was one in Brazil or something? Yes, there's one in Mumbai in, uh, one month Mumbai. Look, I don't know how long he'll offer that for free.
If it was me as CEO, you'd be paying for them. But if you could go get training for free, get to the next rock. I don't Wanna say until I'm CEO we are gonna go offer free training.
You heard it here first my friend. Thank you so much. Thank you.
It was a pleasure. Sum Car, CEO Qua here at Rock On. We're live here.
We're in Houston. We'll be back in just a bit.