Challenges within the Cybersecurity Landscape with Dino DiMarino | Qualys QSC 2023
In this conversation between Mike Vizard and Dino DiMarino, CRO at qualys, the focus is on the dynamic challenges within the cybersecurity landscape. Dino emphasizes the economic pressures organizations face, leading to tool fatigue, and the need for a cultural shift in cybersecurity programs. The discussion delves into the role of CISOs and the recent SEC ruling on their accountability, highlighting a necessary change in how risk is collectively viewed.
Transcript
This is Techron tv. Hey folks, we're at the Qualys Security Conference Americas with Dino de Marino's, the Chief Revenue Officer, and we're gonna be talking about what's going on the marketplace because, well, as we all know, it's interesting times out there. Dino, welcome Michelle.
Mike, great to meet you. Thanks for having me. What are you hearing from customers these days?
There's clearly a lot of economic pressure. Some sectors not so much, but in others there are clearly issues that people are trying to deal with, and yet the bad guys don't have economic issues, so they continue to launch attacks regardless. So how do we kind strike a balance between the level of risk we're seeing and what we need to actually secure?
Yeah, no, Mike, it's a great question. So I think what we're seeing right now is, um, organizations, especially in cybersecurity programs, are dealing with a lot of what we call tool fatigue. Multiple dashboards, multiple pieces of technology that is now causing pause for chief financial officers as they look to, you know, get budgets approved next year.
They're challenging their cybersecurity teams to do more with the same or more with less. It's certainly a huge economic, uh, conversation going on that I don't think we've had in the past, you know, decade or so. You know, separately you've got this, uh, this silo or divide that's been occurring between, you know, CTOs that build software, the CISO who are trying to de-risk said software, and then also the IT teams that own and manage all the assets that, you know, we use every day.
And the challenge we see is that organizations now, especially with the SEC, um, ruling on the CISO from SolarWinds, are gonna have to rethink how they look at risk as a collective. So there's almost a, a culture change, a sea change that we think needs to happen because CISO's are to be held definitely accountable as it relates to how the SEC is looking at publicly traded organizations and the accountability to the ciso. But in many cases, they don't have the power to de-risk the business side, both with the applications companies build and the ones that they host to run their business on a day-to-day basis.
Is that speeding things up or slowing things down? 'cause in my experience, sometimes you got more stakeholders and they all have an opinion. So it can be months before they sort things out.
How do we make this faster because we don't have the time? Yeah, it's a great, great question. I think that a, a couple things.
So artificial intelligence introduces, I'd say opportunities for us, you know, as the, the defenders, the stakeholders who are trying to run businesses and keep 'em secure. But as you mentioned earlier, opens up opportunities for the adversaries, the attackers as they're using it to get into networks on a day day-to-day basis. So for me, I think part of this is technology.
Obviously there's an element of that, how can technologies like Qualys and many of our integration partners derive faster, better outputs, more accurate outputs and clear delineation of risk. But I do think to your point, there has to be cultural change and just different conversations occurring that is going to take time. But I do think it's some cases regulation legislation, uh, and you know, when we see what happened with, with SolarWinds specifically, our expectation is it's gonna force a conversation that's been lurking in the background for, again, over 20 years in cybersecurity where the CISO needs to have more control on his or her destiny to help protect the organizations that they work for.
There's ACO involved in this conversation somewhere. And yep. That's all about the math.
You mentioned all the tools that people have. Can I rationalize some of those tools to help pay for new tools? How does that work?
Yeah, I guess earlier I was stating the problem. I think the opportunity, uh, the solution to it is sort of platform consolidation. Um, no, Qualys were certainly one of the, the platforms that we think could really help, um, enterprises get a much better handle on their risk.
But there's others that we integrate with and others that organizations that we work with every day have integrated, uh, to try to drive just better simplification of their operation. So we see, you know, with over 3,500 cybersecurity companies, right, when you think of all the startups, many of which are providing features to customers, we do see customers now saying, look, based on the pressure from the board, from the CFO, we're gonna be looking at platform capability. We're gonna be looking at, you know, best of suite versus best of breed in order to solve our business challenges.
Because in a lot of cases, more tools actually increases complexity in many cases could lead to more data loss breaches because of the gaps between these various technologies. So definitely that sea change, I think started about six to 12 months ago with a lot of the economic pressure that we're seeing in the market Are budgets changing? And I'm asking the question because for years it was a one to 2% of revenue and security was one to 2% of that.
Yep. Is security now a bigger percentage of that? Is it a bigger percentage of the budget?
I mean, or do we have more dollars to play with at least? Yeah, I think, um, you know, I, with with our teams from a go-to-market perspective, internally, you know, we say there's a bit of schizophrenia depending on the vertical, right? So it really depends, right?
So let's just as an example in banking, you know, I think worst case it's doing more with the same or more with the same plus inflation. Um, and other verticals like think about software companies, there's been a lot of pressure, especially for publicly traded ones where I think some CSOs are asked to do more with a little bit less. So I think it very much depends on which business you're in, the economic climate you're seeing that they're faced.
Um, and so I think it is very much us having to be very close to our customers, understanding kind of what business dynamic they have and trying to adjust course and sort of fit within, you know, some of the, the, the, the envelopes that they're dealing with. But it's definitely, I think ROI, um, where there is an ROI, there is openness from CFOs to do something different. Cybersecurity has struggled with that.
So I think that's our job to help arm customers with much better data to justify the technology to, to rett of their business. Yeah, I've often been fascinated by this tool issue because every time you give somebody a tool, you have to hire somebody to manage the tool, and there's not enough cybersecurity people around. So a lot of people don't buy new tools.
So it seems to me we're on some sort of virtual cycle to reducing both the tools equals reduced number of people because a smaller group of people should be able to do more with a better set of integrated tools. No. Yep.
A hundred percent. So I think a couple things, going back to my point of consolidation, definitely the, the outcome is, and we actually just recently, uh, published a, um, an IDC study. So it was actually done independently by IDC, that shows we can reduce the amount of, I'll call it human effect to quala.
So the management of it relative to other solutions by 25%. So if you have a team of, you know, four people, that would mean you in theory would only need three to operate it. So that solves part of the problem.
But in many cases, it's the program that has to be run, right? There's certain things that are well above and beyond the technology. And so part of what we're talking about here at Qualys at this conference is our partners, right?
How can we have our partners, the managed services providers that sort of, you know, live and live and bleed this problem with their customers every day, leverage our technology and their services that doesn't necessarily need to add incremental headcount. 'cause the other challenge we have in cybersecurity is there's just not enough people. Um, so even though CISO can't hire more, even if they could, there aren't the people to actually bring into their program.
So it's a very interesting sort of demand supply challenge as well. Are you seeing more willingness to rely on managed service providers? Because for years, I would think maybe 15 to 20% of the market was managed services.
Is that a much higher percentage Now? What does that look like? I don't have an exact statistic.
My guess is it's, it's definitely a quarter to, you know, getting the 30, 35% of, uh, of organizations I think globally are consuming some type of managed service. We expect that to, to increase over time, right? Hard to predict kind of what that, that'll be in three to five years, but be based on all of the challenges that, you know, you and I have outlined.
I think that that's just an inevitable outcome of how CISO will have to, you know, operate their business For sure. I think there may be more managed service providers, simply because, as I understand it, you guys have the cloud service, so I don't have to go build that if I'm the MSP. So theoretically that should enable more MSPs Yeah.
To participate in the marketplace. Some of them used to be resellers or whatever, but, um, so as the economics of security fundamentally changing in a ways that we haven't quite necessarily measured. Yeah, I think that has been the biggest challenge is, uh, we've actually, I think as an industry done a good job of evolving.
I don't think we've done a great job articulating how we've evolved and justifying that. 'cause to your point, 15 years ago, managed services providers were not only providing the service, they were actually in many cases, building and hosting the technology from perpetual software vendors, you know, in sort of the previous yesterday year of cybersecurity, that has changed where our economics, you know, are much more favorable now to an MSP and to a customer. So my, my, my thinking is that you're seeing value there.
We just haven't done a great job sort of articulating how far we've come from an ROI standpoint of delivering the joint service to a customer. One of the things that happens anytime there's a lot of economic disruption is there's a lot of merger and acquisition activity, and a lot of the people who provide these one-off tools may or may not be around should customers be factoring that into their thinking. Yeah, I, I do think that, um, you know, with some of the geopolitical issues that we're seeing, um, you know, abroad, there's, there's resilience that I think organizations need to have.
So I think customers should be assessing, you know, where is the, the vendor that I'm trusting for a critical capability based, how much resilience do they have globally to support me, especially for medium to large enterprises. Um, and then, you know, conversely, if I'm dealing with a very large cybersecurity vendor, like are they simply buying technologies and telling me it's a platform or they actually had thoughtfulness and how they're integrating them so that the, the usage of said platform actually drives efficiency and doesn't accidentally create inefficiency. And we saw this again, sort of with the early cybersecurity vendors like McAfee and, and, uh, Symantec as an example, great companies, but really grew through inorganic acquisition and actually accidentally added complexity back to their customer by doing so in that manner.
Alright. You're relatively new to Qualys. I think you've been here four months or so.
Yep. Almost to the day. Yeah.
What brought you to the company? There's a lot of places to go hang your hat in the security space. Yep.
So why land here? Uh, a bunch of reasons. So, you know, first of all, uh, had a great connection with Summed, uh, Kar, who's our CEO, and his ability to articulate sort of what Qualys has done, you know, it's great brand, great heritage, and the fact that in a way we're challenging how we're thinking and how we're positioning ourselves in the market and transforming kind of what Qualys is known for, you know, as one of a world-class vulnerability management, uh, organization, to now an organization that really can give CISO the right to level of context visibility, um, and actionability around risk.
And so his ability to articulate to that, to me got me very excited. Secondly, um, being a chief revenue officer, yes, you know, getting new customers, retaining them is critical, but this sort of technical nature and customer-centric nature of what Qualys has built and Sumit has carried on also was like a very appealing, uh, appealing piece to me. And there was tons of opportunity to drive growth, better relationships with customers.
So it was a multitude of things, but those would be sort of the top three that drove me here. What are you hearing from customers about ai? You can't walk down the street without somebody leaping out to tell you about their great new AI thing, but there was a lot of skepticism early on, and now we're seeing a lot of advances.
So what's the appetite? What's, what are customers telling you? So two things, I I wanna give you a point of view on how I think of it, but, but first I'll answer your question on what customers are saying.
I think generically they're saying, look, we, we know we need to instrument capabilities in our own environments with artificial intelligence. Again, based on all the challenges we're seeing, consolidation, you know, cost, not being able to hire. Like we need to take the mundane tasks off the operator.
And if technology like a quo list can do that, fantastic. If they can create their own capabilities, great. All the while they're equally concerned now on, or equally curious about what the attackers are doing with artificial intelligence.
Ed's keynote sort of addressed it, as did Rachel from Morgan Stanley, that we are seeing, you know, attackers now getting very savvy on how they're leveraging ai. So it's a bit of an arms race. I think we hopefully can just keep it tied for now, if you will, um, because, you know, the, the attackers in many cases don't have regulators over their shoulder because that's a big concern around artificial intelligence, uh, in general as it relates to Qualys and how we think of it.
Obviously the technology is where we start, but we're looking at how do we leverage AI to get to customers faster? How do we support them more effectively? How do we create an efficient experience?
So there's more than just the product element of ai when you think about what Qualys will be doing, it's the entire company sort of leveraging it in the right places to drive efficiency in a world class experience for our partners and customers. You mentioned the regulators. Uh, we used to think in terms of highly regulated industries and then everybody else, it seems to me everybody else is now becoming more regulated.
So is there an organization that's not heavily regulated or impacted, whether it's data privacy laws or SEC rules or whatever it is? Yeah, I I think anyone who isn't will be at some point, right? You know, so I think we're seeing that.
I think it's interesting even, you know, um, domestically we think about FedRAMP, um, which is, you know, nif, NIST's attempt to sort of drive standardization on cloud providers. And what we are seeing at Qualys, um, which is very common, I think with all of our peers and constituents and competitors, is we are now in scope of FedRAMP because we have organizations who sell to the federal government, or we have quasi agencies, uh, we have, you know, other software vendors that use our technology that are FedRAMP authorized. So you're actually seeing, I think, more and more regulation and it's actually, it's, it's, it's almost getting more deeply integrated versus less.
So I haven't seen any, you know, verticals that are, uh, completely, uh, unscathed from, from the regulatory pressures that people have to Deal with as part of that motion. We used to see security managed over here, and then we had a bunch of GRC stuff over on the other side. Yeah.
Is that converging? I mean, is that all gonna come together? We, we hope so.
Uh, for the sake of, of, uh, both our public and private sector customers globally, like Ed said it really well this morning in his keynote, when we think about vulnerability managers, they're providing a really critical service to their company. But, but in a vacuum, vulnerability management is really just a, a tactic to understand an element of risk. We think that even what we would call a vulnerability manager today should be somebody that's actually a cyber risk manager.
And so I do think the intersection point of GRC, whether that's us integrating, providing that just more elegant view to risk for an organization is critical. But even at the operator level, like a lot of these tool centric titles should be transitioning to risk centric titles, if that makes sense. So we're hoping that, you know, we're trying to drive this, this agenda because we, it's right for the industry.
Alright. You are the CRO and I know it's very glamorous, but at the end of the day, not really, people are also asking you all the time, you know, what do the numbers look like? What are the numbers look like?
So we're at the end of 2023, heading into 2024. So let me ask you for everybody here, what are the numbers looking like? What are you, how's the market?
Uh, you know, I think we're, we're happy with the results that, that we've seen thus far. I think we know we can do, we can always do more. You know, my main focus is making sure that we retain the customers we have, that they're getting as much value from the platform.
Because even our customers here will say, look, we're happy to buy more if we're seeing value from Qualys, right? So I think we do a pretty good job at it. I think we can do a better job at extrapolating value more quickly for our customers.
And there's a lot of capabilities in the product that I think is gonna make that easier. And admittedly, in, in new business land, I think every SaaS cybersecurity vendor is struggling for the reasons we highlighted earlier. So we're trying to just be very focused on being there for our customers.
If projects are getting delayed, just making sure we stay in touch with them, that our partners are sending them the right collateral. We're not too noisy, but we also don't step back too much so that when things open up and they realize they have an opportunity to bring Qualys in to help their business that we're there. But we're trying to be very pragmatic and polite.
As we know, the CISO right now are under a ton of pressure from a financial standpoint. All right, folks, you heard it here. CISO are under pressure.
That may not sound like new news, but I gotta tell you, it's more pressure than ever. Hey, thanks for coming By. Thank you, Mike.
Thanks for having me. My pleasure.





