Shailesh Athalye, Qualys | Qualys QSC22
Shailesh Athalye, SVP of product management at Qualys, joins Alan Shimel at Qualys Security Conference 2022 to discuss Qualys’ Unified Cloud Platform. Alan and Shailesh also touch on the biggest challenges faced by security teams today.
Transcript
This is texturong TV. Hi everyone. We're back here in live in Vegas for the quality QSC show day two, you know, we've had some amazing Keynotes yesterday and again today we some great sessions as well.
There's a seesaw session going right you shoot that. I actually wanted to catch it looked really good. But I want to introduce you to someone who spoke.
Well, he's been with us at RSA. He was with us last year at the USC show. It's silish athlete.
Close for pronounce it right Alan. Well that practice Yeah it off. Thank you.
Stylish. Welcome back. How have you been are doing great great to be back.
This is my third interview on Alan show. Yes. This is my 10th year in qualis and my 10 security conference at quality for you.
Yeah, congratulations. That's great. So you actually had a chance to speak yesterday.
I believe it was immediately following sumed, you know, correct, you know, most of the people watching this we're in here, right? Why don't we tell them a little bit about what you you're Talk was about right. So so sumits talk was all about like how there's a need to bring in Automation and speed to simplify security and to help customers reduce risk faster.
And my talk followed after that how qualities platform and it's integrated capabilities Health customers do that. Right? Like how can customer get more security?
In the investment what they're doing? As well as how they can break the siled they have today to reduce the risk faster. So that that was all the talk about I think the talk concentrated more on look at the end of the day.
Security teams need to do four things, right like in in their day-to-day world to reduce risk. They need to find all their assets what they have bring in the business context for it. They will do everything possible to me to get the risk for it.
That's meaning like they would be doing vulnerability configuration management devops management and they would be doing everything possible to detect the threats and respond to it and then compliance as a checkbox of making sure like whatever they are doing in all three areas. They're showing the report to their auditors. The talk was all about how quality platform brings all of these capabilities to gather with the context so that your team's spend less time in Excel sheets Because by the way, no security analyst signed up for cyber security job thinking like they're gonna work in excess.
It's more and how companies can save that time and reduce the risk faster. That was all the talk about. actually so first of all, I would just change one little thing.
Sure. I think when you doing security, right, which is what you're talking about compliance is a buy product of that. Yeah, other than just a check mark.
Yeah byproduct, right if you doing security right you are compliant. But I want to really go in another Direction sure. It's great the way you laid it out.
Even I even I could do it right but In order to do that, you need a platform, right? You know, you mentioned the koalas platform Security today is so complex and there's so many data points and there's so much to worry about You need that platform. That's the great enabler, right?
The I think what you know, and it's come across the last two days here. the koalas platform is I call it hyperscale, right? I don't call it.
I didn't make that name though hyperscale obviously our real name, but there are only there are a few companies in the world like hypers you can get to that level sure, you know, as you mentioned some of them even use koalas, right but How does the scalability of the platform enables end users like who are watching us to make their simplify their security? Absolutely great. Great question Alan.
So I would say from the benefits perspective two parts, right? We all talk about. Technology people needing to uplift the conversation to race that conversation of risk is only possible.
If you're getting the comprehensive data from all the sources possible. So the first part of the platform is we provide multi-sensor approach for customers. Then a lot of talks from startups from companies like a agent less better agent-based better snapshot better this bit what qualis provides is a multi-sensor approach.
We think that you need all sensors. You need to get attackers perspective. So you need Network scanner you need agents to get comprehensive data.
You need snapshot to know your SCA and the open source libraries. You need to know even your SAS connectors to pull the data from SAS. So qualis platform gets this comprehensive data in the platform where we have gone through our own digital transformation.
That's the most overused word if I may use that but what it means is we have changed the technology to use bare metal kubernetes so that we use the New Age Technology to index all of this huge data to create the data Lake and on top of that we have Provided the modules or the capabilities like the asset management and giving that context of what is my asset? And if it is important or not. If it is a database machine or not if it's a production machine or not, then giving that context ahead for doing the vulnerability management and then not just doing the detections that I have 4 million vulnerabilities, but what's the risk of that the four million means?
I need to only look into maybe 132 vulnerabilities which are posing risk to this product and database so giving this context from asset side to one ability to race. So the platform does this hard of yard put in Hardware yards to provide the insights and context for customers. Additionally.
We do the patch management by providing the same Asian, which is doing now asset and wallability management to go and pass these systems for the right set of patches or remediations required for the prioritize risk. And on top of that when we provide the thread detection and response we provide with again a context so many times we hear The Incident Management teams are just bombarded with alerts, right? Why cause that EDR or thread detection and response is done in siled where the platform again does the hard yard of providing them five alerts which are important from your asset criticality which are important because you have the underlying vulnerability so that you can prioritize the right things and take an action quickly.
We made a great point on on compliance being a byproduct How We Do It? Is we provide all of these great data from the risk and vulnerabilities and asset side map it to all the Frameworks out there nist HIPAA ISO. So the compliance people can come in the platform and generate their own reports instead of them needing to use another tool or another Excel sheet.
So these are the hard yards platform Port. I mean I can share a case with you that if a service provider one of the biggest service provided in global 400,000 agents already deploy for doing the asset and vulnerability management when we hit in the pandemic Their service or the business team needed to make sure that their laptops of the employees now who are working remotely. They're patched for critical vulnerabilities within 15 days their traditional or Legacy tools wouldn't be able to send a big packets of patches.
And nobody wants to be on VPN because they need to be on the VPN of the customer but businesses wanted to make sure that they've patched within 15 days. Guess what on the same Asian. We could enable patch Management on the same day.
400k devices within five days deployed 10 million patches. 5 million in four years. We could deploy in a week's time 10 times more patches in that.
I scale. That's hyperscale. You're right.
Yeah, you said something else that made me think of something and that is you know the same way we said compliance is a byproduct of good security. I you know. we sometimes we lose sight of how important managing risk is because in many ways.
Good security is a byproduct of managing risk. Absolutely, right? I mean as silly as it sounds you could have too much security, right because you you managing your risk wrong.
And so you trying to go over and too much security. I'm not gonna say it's a bad thing, but it's a bad thing. Yeah.
Yeah how let's talk about the koalas platform and risk management because I know it's a big piece of it. Beyond the nuts and bolts of fixing a vulnerability and patching and those kinds of things. How does it give the the siso the management team insight into their risk?
Right? So and and yesterday Robert talked about this in his keynote a lot of times, you know, the technology or technical folks are more concentrating on. Hey, you know, what like I found a million while liabilities and guess what?
I fixed half million vulnerabilities. And then on the other side CSO has been asking the board like hey, I need a place with the board. I need and meeting with CEO to explain the risk and when they go in front of the board or the CEOs the questions they ask is like, okay, you deployed OCTA?
Okay, you fixed half million dollar remedies What does it mean for my business or the risks are are the or the profitability of the company? And now the problem is how can we uplift the conversation of these vulnerabilities as assets and the detections to what is my risk? And that's where I think your question was for that.
The problem today's happening is then we are solution we think is add another tool. Which will basically look into all of this and somehow magically provide me like hey, what is my risk? And that's what Paul is really things to simplify security is we need to get context from each of these areas.
And use this context and Bubble Up. What is my risk and quantify that right today? There are two problems.
The number one is the risk algorithms don't consider all the facets and factors that sort of, you know makes the CEOs and the board lose the confidence in the data. So we need to comprehensive data to go in that risk algorithm. and the second part of that is What does it mean for me if that number is 700 500 is it good or bad?
How can we tie that up with the business? So those are the two things what policies looking at doing is number one coming out with the true race Mayhem must have talked about ad yesterday. What is tourists is it ties?
What are the vulnerabilities what are the threats your businesses have? If you're in financial sectors, what are the recent threats trending in your sector buying that up with vulnerabilities tying that up with what assets you have in your environment which are critical. Anything is used by your banking application.
Your CEO wants to know that if there is a risk. Then tying that up to a score and then telling what exactly I need to do to fix it, and that is not just patches. I need to maybe work with my CIO.
To maybe change my Oracle 11g which is already end of life to Oracle 19. That's a cost and benefit conversation. So, how can we provide like no, you need to change my end of life Oracle to 19 G because look at this your risk score for your Oracle database which is used for your banking app is 700 and which is high compared to all the peers in your industry.
That's the inside What policies providing so that they can uplift the conversation and talk with their management. I love it, but you didn't really nice job, you know risk is probably one of the most overused but at least understood terms in in our cyber world, right? And that was a great explanation of it.
Hey, we're about to almost at a time here. You pumped the great work. We'd love to hear more.
We're gonna take a break here in Las Vegas though, and we'll I think we have another guest in just two minutes. So we'll be retooling. We're well live in Vegas at koala says QSC 2022.
We're here the rest of the day stay tuned.





