Mehul Revankar, Qualys | Qualys QSC22
Mehul Revankar, VP of VMDR at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to discuss the scope of today’s threat landscape, along with the biggest challenges facing CISOs today and why current solutions on the market don’t help solve the issues.
Transcript
This is texturong TV. Hi everyone. We're back here in Las Vegas quality QSC.
2022 Day 2. It's almost well. It's afternoon.
It's it's quarter afternoon here. We hope you've enjoyed our you know, first day and first morning second morning here of coverage. Our next guest is someone he's been on our show before his name is mehul rivankar.
That's right. I got it, right. Yeah.
Well, it only took me three interviews with you together, right? So we get we're making progress making progress. The whole why don't you tell people a little bit of your role equals?
So I am ahuankar. I lead our vmdr Solutions here at College have been here for about two years more than a little bit over two years, but my background is in vulnerability management compliance Automation and how do you take all of those things and reducing risk in the organization? So when here almost 15 20 years in this place now, yep, and you know what?
I'm on a mission to Explain acronyms to people because we throw them around but people who don't may not understand or what vmdr stands for vmdr is vulnerability management detection and response. That is correct. And in the koalas World on the koala's platform.
It's more than just scanning for vulnerabilities, right? Yeah, so the baby think about this is now we're probably the only vendor who does the management of vulnerabilities end to end from Discovery to paradisation to remediation to remediation attacking right. So we want to manage the life cycle of the vulnerability from the first time it was discovered to the time it was eliminated in there in the environment so vmdr as well really management detection and response and response is actually the remediation aspect of it to get rid of those vulnerabilities.
It's very comprehensive all in one solution. Absolutely and Look qualis has been around. I'm gonna say 24 25 years, maybe 26 23 years.
Yeah, 2022. So yeah 23 years. Who's always a vulnerability management company, but it was primarily about discovering vulnerabilities.
Right and but it's always been not just qualis. Frankly. The whole industry is always.
Yearned aimed to do more than just discover vulnerabilities, but to actively manage them and that goes all the way through to remediation. Okay response, right? I think one of the things that we want to emphasize if it hasn't come out is every vulnerability Discovery doesn't end with a patch.
It's not just patching right? It could be, you know, deploying some kind of from litigation or it could be applying some kind of a network ACL sure, you know, the firewall level so not everything is a patch deployment. It could be many things.
The thing I want to touch upon is historically VM vendors have been focusing on creating more and more signatures than detections for vulnerability and assessments and what we are seeing now is Less about vulnerability management and more about cyber risk management. Yes. That's the the conversation has started to shift from how many vulnerabilities do I have to how many really critical vulnerabilities do I have that I really need to prioritize to to reduce risk in the environment and the risk could be from multiple factors.
Right? So for example, it could be from your assets that are exposed to the internet. One of the number one reasons for for organizations getting compromises because of assets that are exposed to the internet with critical vulnerabilities on them and getting exploited and compromise, right?
So so there is this completely new aspect or maybe an extension of vulnerability management, which has more fun to cyber risk management which includes, you know, your attack surface your vulnerability misconfiguration. And you know, how do they all come together to actually help you reduce this if you're not organization and when we think about vmdr, this is one of the core tenants of the problems used to help you inventory everything. in internal assets that you might have or also your external assets, you know that are exposed to the internet get them into the visibility whether you know with the solutions that like external attacks of fish management bringing in and then correlating that data with the world abilities that we are seeing on the infrastructure in And extracting the really critical vulnerability, you know, are you getting expedited in the wild, you know, what's the exploit could maturity for these vulnerabilities in are these exploited by ransomware?
If so, then these are the ones you really want to focus on and and the others, you know, if you have time go after them, but focus on these these metrics or these stats for so I'll give you an example. So we looked at the data for one of these. Over the last 20-30 years, right?
So the universe of vulnerabilities is around 190,000. But if you look at the wall of these that are actively exported by malware and set actor groups and transfers. That number is less than three percent roughly 4,000 world of the 4,45 and you really want to make sure that you do not.
Skip these or do not miss out on this you do then. There's High likelihood here organization a little can't get compromise by one of this one. So focusing on that to reduce this is actually very critical.
So the organizations can start to move away from a volume-based. Vulnerability assess vulnerability Management program to a risk based vulnerability management. That's the critical solution.
I think that is and I think you hit it right on the head. Excellent, you know because what we said before the same way or remediation isn't. patching all vulnerabilities aren't necessarily created equal either correct, right, very important and and for too long in the and I've been in this industry as long or longer than you for too long the only Way we distinguish vulnerabilities was was you know, sort of Nest CVS yesterday CVS ratings, right a critical and so forth.
But that even that they did I'm not banging them for it. It's not a bad thing, but it doesn't it doesn't apply to everyone the same. So I'll give you an important statistics.
So we looked at this data for you know and serious as well for you know for what it's worth was never meant to represent the risk. It poses to the organization. It was always the design to assess the technical severity of the vulnerable.
Right? And when we looked at the data what we found out was 51% of the all the vulnerabilities are rated higher critical by CVSs. So if every other onesability coming your way is higher critical then how do you prioritize right?
So that's where we brought in the new true risk algorithm in VMware, which is our related which is our latest addition to to our vmdr risk prioritization actually and that reduces the number to seven percent really the seven percent higher critical instead of 51% So that's like an 85% reduction in the list of vulnerabilities that you really need to focus on. It is humongous in terms of a security practitioner's point of view. Sure.
You know, I really don't need to look at these 51% of the one with these are seven percent. I really need to focus on because we are we have backed that with the with the intelligence that we collect from all the exploit and threat intelligence, please hey, we know this is a getting weaponized we know this is exploited in the wild, you know, these are the ransomware that exploiting this vulnerability. So you better fix these before you go on and do something else, right so that you transition to a risk based approach other than a volume based approach and calling this true risk so vmdr with tree risk, right?
And the reason we call it through this with it is a very comprehensive risk scoring algorithm. You have actually file the patent for it because we take into account not just the vulnerability aspect of it. But you know, you might have some kind of a mitigation or compensating control on it, right?
If you for example, if vulnerability cannot be exploited if registry Services disabled then the risk score is actually low because there is no way for you to exploit it. So, you know, you have not taxed this way you don't you have this world of living but it's As mitigation control so it's a lower risk for your organization. Right?
So and even on the asset side, you know, if an asset is internal Dev or test asset versus a production asset as exposed to the internet that is high rise, right? So taking into account all these different factors that helps us assess the true risk of that asset or a world really or a groups of assets within your organization. That's why we call it true.
I love it. People at home, maybe want to get more information on this true risk. com obviously, but is there specific?
com slash throw risk Tru risk, and you are you Tru we got rid of the E because marketing team wouldn't agree. Well, no refuse a big word here right now. That's our research team as well.
It's called true. That's right unit. You don't like easy College, okay.
Anyway, or kidding aside. That's a great. It's a great thing.
I think it's something we needed in the industry. It's good for you guys. I'm glad to see this super proud of it.
And you know since we launched it, we've all you know, the product has one multiple Awards and recognition because it's something no other company has done I organization has done so good for you. Thank you so much for being on our show. Thank you as always a pleasure to see you.
So check out that's it. True. Rest Tru risk.
com. Yes, we're gonna take a break here from Las Vegas. We've got a full afternoon of interviews.
So stay tuned.





