Payal Mehrota, Qualys | Qualys QSC22
Payal Mehrota, senior director VMDR TruRisk at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to discuss why organizations should be taking a risk-based approach to mitigating threats.
Transcript
This is texturong TV. Hey everyone. We're back live in Vegas at qualysis QSC.
Conference 2022 at the Venetian. We're having a great conversation today. We're gonna continue our conversation about koalas a vmdr and the new true risk capabilities in there.
I want to introduce you to this woman. Her name is payal. Mahal Ultra better I did it right.
I apologize right? It's pile meditra. Thank you.
And thank you for being on textrung TV with us. We should start with a little bit about your background. You require us sure.
Definitely. So I'm Pyle meritra. I'm based out of Boston Massachusetts been with qualis for about listen two months, but been in the risk in compliance space for about eight years and in software development and soft engineering for about 18 years.
Wow. Yeah, so I came to little bit about myself. So I came to United States.
I'm originally from India, but came to United States 23 years ago did my masters here and started working and and been in the security space for a very long time? Yeah longer than you shouldn't have to admit to but okay. I've been in longer though.
Yeah, so As I said, we were talking earlier about college VM gr. And you know, I think the idea of a comprehensive vulnerability management solution is something look I was friends with Philippe for 20 years. Okay.
It's something we spoke about for years in this business. And many have tried right Carlos is done a really good job with vmdr. It's it's end to end vulnerability management all the way through and and and trying to automate it which is I think something we still haven't.
For whatever reason the audience doesn't adopt automated patching easily. Yes. we have to work harder at that but this new true risk is is I think another great.
Addition to the to the capability. He spoke about it a little bit but let's hear your take on it sure. Definitely so in in any organization right where the big or small they're always, you know, if you have laptops so you have machines right?
There's always going to be some software installed right? That means they would go either end of life or they would have updates right and we need to keep updating them. Otherwise, we would have, you know, a security holes in them and constantly a lot of the vendors.
Keep updating this software because there are bugs right that hackers and attackers can can use to get into your environment. So what true risk is doing is instead of you going and saying I want to patch everything what I want to remediate everything. We're telling them based on what we know right?
And we collect a lot of data. We know a lot more things about your environment. We know a lot more things about your assets your machines your systems, right because we're installed on them.
So that's the real data if we can analyze that data and we can give you a simple list of things and say good you these things first because they mattered the most for your risk posture. That is what true risk is trying to do, right so taking a lot of data. Analyzing it in the backend coming back because everybody likes numbers right because it's easy.
It's visual right? You can remember or thousand is is a big number. It's a bad right three hundred is is it may be a good posture right much better.
Right? And we all used to the FICO score 250 to a 900 so we know you know, so So and we can visualize these things. So that's where true risk brings in the value of bringing the data together and analyzing you and telling you what to do.
you know in talking to my whole earlier one of the things that came out with true risk is that look the cve scoring system it you know, it was a good start. Yes, but it that way but if everything is critical then nothing is critical exactly. Right?
Right. And so what we're trying to do with true risk or what koalas has tried to do is saying look everything isn't necessarily critical right? Let's try to put real risk in here and that's what these numbers are.
But you know what I find interesting is the koalas platform Is a hyperscale platform right? It's it's very scalable you. You couldn't do a true risk without having the scale because the numbers we're talking about to put all this together.
Yes is is really hard give our audience if you can't some Idea of that scale. Yes. Definitely so we left about two one trillion data point right in order to process this huge amount of data and along with what's in your environment because customers vary right?
We have large customers. We have small customers. We have medium customers depending upon what how number of assets they have in their environment you're taking data from those assets and you're taking data from all the threat intelligence and the intelligence that we have in an environment processing all of that.
is Is is incredible to come up with a single number? Right? That is what it is and telling you it's trending it's raining up or is it trending down?
Why is it trending up because we saw a lot of open ports, right? We saw some certificates that have expired right or we saw end of life software. So that means we need to go fix them providing that insight into and and that can only happen when you're analyzing a lot of data.
You have to have the scale. You need to have the skill and that's the platform. Yeah, no doubt, you know, but this also kind of fits into one of the themes that we've heard here over the last few days and that is about making security simpler for the people at home for our practitioners for the security folks not just security for the devops teams and the developers and the business folks right security has got well Securities always been hard Frank.
Yes, it's gotten harder because the job of securing has gotten harder. Yeah, so many more attack vectors and everything else. So this is a way to kind of make it simpler.
Yes, because as I was mentioning people understand numbers people understand graphs, right and you can put numbers on a graph to visualize the risk. It's business talk not security talks. It's not very exactly right.
I mean because look I've been doing this a long time. You would go to the sea level and they would ask one question. Are we safe?
Right what exactly am I gonna get hit or you know, what are the chances? We're gonna have a breach back then we didn't have this it would be like Don't and then justifying to your board or justifying to your Senior Management. Why do you need extra 10 resources on this project?
Right or the Investments that you did in the in the past six months ago? Are they paying off you want to show that you're making progress? Right or if there are areas of Investments that needed or areas of improvement that needs to end what how How can all this help it's from data, right?
You can show you can visualize the data and that's what true risk is all about. Right? So I look at this in kind of four pillars of risk, right?
The very first one is around discovery. So knowing what you have in your environment whether it's users or assets or software, right and second is around assessing it. So assessing for Problems right assessing for gaps where there is vulnerabilities whether it's misconfigurations.
You name it right and then part is once you have assess. You have your data now what you do with this data, right? You can go fix everything right?
You have to start somewhere. Right? And that's where the prioritization comes in place and that helps you.
Okay, here are the five things most critical things that you should do. First not saying don't do the others but that one has the most impact on your organization. So for example, if it's an internet facing machine or if it's a domain controller, right that means you need to take care of them right now.
You can't wait right or if it is, you know, a Dev developers machine, right or if it's a machine That's not internet facing or it's already has all the compensating controls like full this encryption is turned on or antivirus is running, you know, the the policies are all up to date then you that can be done later on. You don't have to do it at this moment, right? So that is what we're helping with the prioritization.
It's Is taking the context not many software or applications can take the contest. No, they don't know exactly exactly and then the last thing is okay. You can provide me all of this stuff.
Now what should I do? Right. So what I have been hearing from a lot of customers is because they have all these Point products right doing all of this is very hard.
Like putting they can discover things on hard. It's pretty clear. It's impossible.
It's impossible. Right because you have to marry terabytes of data together and make sense of it. But you don't they don't have the scale.
So having a platform where you can do all this is a very is very it makes it easier right and then you prioritize and the fourth pillar is around remediation, right? So then you say okay. I got to know these are my top five things.
Right and I need to go fix them right now and you give them the tools like traditionally what's been happening because they use Point products. They have to go into another two, that means they have to send this information to another team. You know, they don't report into the same org or you know, they have different responsibilities.
So, you know organizations are spending billions of dollars. On on tools, but what's the end result? What's the outcome?
Right? They're not secure exactly. They're not secure.
They're not compliant and they spend so much money, right? So this is maybe a changing the game upon. The Shelf is the president software.
We all call right and quite frankly, I think. It breeds another problem and that is it's like the boy who cried wolf. You can't go back to the board every year every six months and say I've got a shiny new Magic Bullet.
That if you give me more but I'll buy right and then six months later now that that wasn't the Magic Bullet we were looking. Yeah, I got another magic, right? The board says no enough.
I'm not you've gotten enough money make it work. Yes, and now you stuck working with something that really doesn't work. Exactly.
Yeah. No having that data driven conversation is so important and every level. Well, especially the board level because that's the language they speak they speak numbers even specifically one great thing about true risk that I should mention is, you know, it caters to all the different personas, right?
So if you are a sea, so and you want to report to the board, right? We have all the tools right it's drag and drop in your dashboard into because reporting is key in any risk management solution, right so we can do that, but we can drill down too. So if you're a practitioner, you're an analyst and you want to drill down and go fix things.
We have that view as well. So again, it's very hard to have both of these but given that we are a platform. We can do this.
Got it. Yeah, excellent. Awesome one last question our audience.
Yeah, if they want to get more information. Where did they go for this? Well, yes.
I was not where we think while it's not come and then go to True risk. Tru risk All right. Hey, we're live in Vegas.
We're gonna be back here with more quality QSC. It's just a moment. Stay tuned.





