Dilip Bachwani, Qualys | Qualys QSC22
Dilip Bachwani, CTO and VP of Cloud Platform at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to discuss the challenges of container security and lifecycle management.
Transcript
This is texturong TV. All right. We're back here in Las Vegas for qualisqsc 2022.
I don't know if you if you want you probably wouldn't remember but if you watched last year's Wallace QSC, we had this gentleman on I think you had just recently got into the role. Was it last year? I I was speaking up.
Engineering operation. Yeah, so it's it's dilip box 20 which one but 20 and actually you can tell them you roll now. Okay, I'm delibachwani.
I'm heading engineering operations and support at Wallace. I've been at qualis for over six years now. Yes.
Came to koalas to initially build its data platforms as we were transitioning as a company. From the four five six products. We had to the 20 plus products that we have today.
It's a different mindset in how you do things. Yeah, and it was it wasn't just the amount of products. If I remember correctly, it was really sort of a devops transformation where the way these products were developed, you know, and maintained was moving more to a modern infrastructure microservices devops, you know less of that waterfall release every two.
Yeah twice a year or what have you and So let's let's start there first. How's that transformation been going? It's well, it's coming along really?
Well, we've made a lot of progress, you know, we've largely moved from our monolithic systems to microservices. We have over 300 microservices today. We have that.
I hundred platforms running at very large scale. I think last time I was here. I'd shared some numbers but today.
I believe we shared it in our keynote too. But our elasticsearch clusters have about 13 trillion data points. Oh my God, that's hyperscale.
That is hyperscale. Right and this is all in-house. We've built our own.
Skill set to run these platforms. But really it's not it's not the platform so much ultimately it's the value that you build on top of the platforms. Right?
It's the products and capabilities that we are building that are enabling our customers in their Journeys. Well, so I take it little the product the platforms enable you right because you could think about building scalable applications that service thousands tens of thousands of customers, but if you don't have a platform to support them. It's useless right?
You can't you it's shoveling sand against the tide. so it's important I think that oh, right, you know to have that base but that now becomes the enabler for all of these great products and it you know, it kind of boggles my mind because I know quality for 20 23 years whatever it's been 24 years and you know, they had a vulnerability scanner and now they're at how many different products it's 20 something. It's if you look at individual products, it's over 20, but what we've also done is we've said you know, how do we combine some of these products and enable customers on their Journeys?
So as an example when you take vulnerability management, you said qualis had a scanner. Yes, we did vulnerability management. We had a scanner we had agents right we have about 80 million agents out there now.
But it's not just about running this scam. It's also about visibility to assets right? So what we've done now is as an example with quality MDR.
You get full asset visibility across your active managed unmanaged Assets in your data center public Cloud hybrid Cloud multicloud anything container assets. Get that visibility then you run the scan. Then after you run the scan, what do you prioritize on what's important from a risk standpoint for your organization?
That's the true risk that we talk about now, right and then we've integrated patching into the workflows so you can have automated zero touch patching right? So when when you look at everything I just mentioned you can look at those as well that are four five different modules. More or you can look at it as vmdr.
Right which is the vulnerability management. How do you run the whole program? And that's what is coming together.
Now what we announced today with total Cloud as an example is another example of that to say how do we enable customers as they're on their Cloud Journeys? So instead of getting caught up in the buzzwords of cnap and CIA and this and that what do they really want? Right and what they want is as they're moving from the data center to the cloud.
As they're moving to container workloads. How are we moving with them on that Journey? But how are we making it easy for them?
Because the problem domain still stays you still need good hygiene. You still need compliance. You still need the right kind of configuration.
areas that we are very good at very strong at Right, and that's what we are enabling now. Right, we have the products but we are packaging them also in a manner where customers can say. Well, I think this gives me a complete holistic picture a single unified View.
And to your earlier Point built on a single platform, right? We have a truly unified platform. I tell this to everybody.
Right. It's the underlying infrastructure and the data is the same and that is enabling. So that's the beauty of a platform too, you know.
There's an argument to be made. Of the 20-something products the qualysis and it's not just qualities of any of these products products themselves can be very much become features. It's just a feature and we could and what's today's product?
It's tomorrow's feature. It's subsumed. Within a bigger platform and it's truly the platform because once you have that platform, you can keep adding features whether you want to call them a separate product how you package it sell it.
It's an more features. We're adding on top of the platform so that again the enablement of it. Qualis is a great example of it.
It's You know I came here to build it. I can tell you qualysis phenomenal example of it. Yeah, absolutely platform that can give you that breadth of coverage that breath of capabilities at scale that's still a big scale and that you know, that's something I think that's separates Wallace from any of the others.
We don't have a lot of time but I want you to just quickly touch on total Cloud. We had Prashant here earlier just right before you you know, and it's his baby. You could tell his pride and fashion.
Yes, and it but from your point of view. What do you what do you see with it? See, I mean it ties back to a little bit.
What on what I was saying earlier. Organizations as they're moving from the data center to the cloud. Right.
So when you move to the cloud you want to do workload protection? You want to do infrastructure and entitlement right? You want to look at your posture?
And what has happened is for each of these things now there are different terms. and there are different products and different vendors trying to sell each one of these right and it's making at least in my view and you know, I think production at the same sentiment. It's making everything more noisy.
Right and what we are trying to do with total cloud is we are single let's keep the buzzwords aside. What problem do we really want to solve? Right we want to make it easier for our customers as they are moving to the cloud to understand what your posture is.
What do they need to do from a hygiene standpoint? To take care of that posture. So they're safer in their envonne, right?
And that's where we launched total cloud and a big piece of that is flex scan. Where we are saying? You can scan in different ways.
So as soon as an asset comes up you can do an api-based scan, which is quick. Yeah. But for that same asset, you can also deploy an agent and you can get a more comprehensive.
It can continuous scan that is happening. For that same asset we can also do a network base camp because there are some vulnerabilities and checks that you can only do outside party as an example, right? You can also do a snapshot base can but you just take a snapshot and then you do the evaluation after and what we will do is we will do all these cans we will process the data on our platform.
And then we'll give you this comprehensive view of what your security products the whole thing across the whole thing. Right? Absolutely.
And I think that's what people want. First of all they don't want one solution for on-prem another solution for cloud another solution for cloud native another solution for SAS or endpoint. They want a platform.
That's one platform absolutely security and I can tell you that because while I'm responsible for engineering at qualis, I'm responsible for all Global Cloud operations. So I'm a user of what we do it you're on dog food. We have a drum authorization.
We have our platforms that run in the data center on bare metal on virtualized infra in public clouds in all public clouds. So when I look at my own security posture. For me if I'm whether I'm running in the data center whether I'm running on containers whether I'm running on the cloud.
I don't particularly care. I still want to know what my vulnerability posture is across my footprint a great what my compliance sponsors across my footprint. And what should I prioritize and focus on across my footprint because ultimately it's the weakest link that you should focus on.
Or the risk for your environment that you should focus on right and that's where the unified platform the unified view obviously is making a difference. Actually. We have to bring our next guest star.
Pleasure seeing you again you thank you so much amazing. I was praying stuff. We'll continue this conversation.
Sounds good. Thank you very much. All right, we're here in Las Vegas.
We have one more interview for today. So stay tuned. It's coming up in just one moment.





