Maximizing IT Investment with Phil Harris | Qualys QSC 2023
Phil Harris, research director for GRC at IDC, discusses a report on the remarkable return on investment (ROI) from the Qualys platform. The report indicates a staggering 403% ROI for companies utilizing Qualys, emphasizing its significant impact on IT and information security.
Transcript
This is Textron tv. Hello and welcome back to the call security conference for the Americas. We're here with Phil Harris, who is research director for GRC at IDC, and we're talking about a report that they did on the ROI return from investment in the Qualys platform.
Hey Phil, how you doing? I'm great. How are you?
I'm well. Welcome to the show. Thank You.
So what left out at you about this report? I mean, there's a lot of numbers and a lot of data I'm sure, but the big takeaways, Well, the big this, there's a couple of big takeaways. One is, um, the return on investment from acquiring, you know, the VM Qualys VMDR to how it really impacted the organization is that over a 400, 3% ROI, um, derived by companies having acquired Qualys.
To me, that was, that was, uh, really significant because it, it, it meant that Qualys is having a significant impact on it, on information security and the people. So oftentimes, you know, organizations will buy a widget or some platform and it, uh, it does its job, but it doesn't really impact the productivity of the people. Um, and especially in cybersecurity, you know, we've got enough to do in cybersecurity.
And so to have a product like this improve the productivity of people in the organization, um, enabling them to do other more high priority activities in a company, it's phenomenal. Having been a CSO myself, you'll want people to be, you know, have the ability to do other things other than just chasing vulnerabilities around Mm-Hmm. What is it that you guys are measuring?
'cause sometimes there are hard benefits and soft benefits. So when you do a report like this, what do you guys look at? Well, you look at, um, the time that people spend, um, doing remediation in an organization, uh, the time it takes them to detect and the time it detect, you know, the time between detecting and remediating, that's a sign that can make a significant difference.
Ideally, you wanna detect and mediate as close as possible, but sometimes depending on the solution, you're, you're, you're far apart in that area. Um, it also, the cost of the platform makes a huge difference in that. Um, you know, you'll spend, you know, as for an example, $200,000 on, uh, on Qualys, but the return on investment becomes significant in that your people are more productive, your systems are down left are are down less often.
Uh, your applications are running, uh, more, more, uh, efficiently. Um, and, uh, and you're reducing risk overall. And so there's a number of those types of factors that go into the figuring that out.
And, you know, we interviewed a number of Qualys customers that, that helped us derive those values. Mm-Hmm. They say being in security is a lot like being in the army.
It's hours and hours of toil and boredom punctuated by a few moments of sheer terror. Um, what is your sense of, like, it seems with security people, there's a lot of fatigue. So, you know, how does a platform make a difference, you know, in your CISO experience to the fact that, you know, there is so much drudgery and that kind of lulls people into a false sense of security and then something bad happens?
Yeah. Uh, and, you know, uh, vulnerability management, right? And risk management are probably the, the two biggest key areas that drive people crazy.
In most organizations, it's hard to remediate all your vulnerabilities. There's usually battling between IT and security. And even if it is remediating, they're remediating some stuff, not everything.
So you're left wide open with a number of different vulnerabilities. And so security is having to chase all this stuff down. They get breached, chase it down.
Oh, it was a, an an unpatched vulnerability. Uh, and so bringing in a platform that could actually, uh, do the, the detailed work of identifying where these things are, prioritizing them based on some, some risk scoring to figure out, okay, is this a, is this a low risk platform with a high risk vulnerability? Do we remediate that now or do we do that later?
Or is this a high risk platform with a low risk vulnerability? It's helps you help the system, helps make those decisions to bubble that up so that the security personnel, it personnel can make informed decisions faster without having to scroll through pages and page that fatigue is, uh, it's becoming untenable. Well, no pun intended.
Untenable un yeah, untenable. Um, because there's so much coming at you every day now. Mm-Hmm.
As you kind of think through this process of the relationship between security and the rest of the IT organization, one of the issues you always hear about is like, well, we don't want to patch that 'cause it might break. We don't think we have that, or it's not running that application in production and we have all these issues and then we go back and forth and we argue for two plus days or whatever it is. Um, can we change that conversation and can the security people take more control of maybe the patch process or, and automate some of that?
Or, and where's that line between what can you automate and not automate Well, um, automation is interesting. So to start with that, you've gotta be able to trust the platform, trust the decision that it's making in order to audit, to have it automate the remediation. So trust is a big factor.
And I think the, the more intelligent, uh, these capabilities, like in the quass technology, you're using AI and a lot of algorithmic decisioning, it becomes easier to trust the technology to do the remediation, take baby steps along the way. And eventually there's more and more and more that gets remediated. Um, what was the first part of your question?
Um, can the security people take more? Yes. Responsibility.
And, you know, I 'cause it, people are a little sensitive about stuff being done. I know they're, you know, I, cybersecurity teams are gonna have to take responsibility and here's why. 'cause there's just so many vulnerabilities out there.
It leaves the organization vulnerable, it leaves the executives vulnerable, it leaves the board of, uh, the board of directors vulnerable, all because there's a possibility something might not work. Some, it's a possibility, right? And so it rightfully so wants a stable environment.
Uh, the problem is if you don't patch for a long time, your environment's gonna be unstable, right? Mm-Hmm. So the more you can accelerate the patching, so it's happening more frequently, and the more unco your environment will become more stable.
Right? By virtue of that. 'cause you're not having to bring in, you know, 10 years worth of vulnerability fixes, uh, which may in fact break a server.
And to your point, you're more damned if you don't. You are. Today we have a, I would call it an event driven process, right?
When we patch things, somebody sits around and says, yep. On Sunday, two months from now, we're gonna patch everything. Yep.
Does that need to be more of a continuous process? 'cause it seems like the vulnerabilities are introduced on a regular basis. Developers download something, stick something up there and updates.
So the, the environment is highly dynamic, but the patch process is, you know, yeah. Shall we say occasional? Yeah.
Does this need to get fixed? Yeah, it needs to improve. Uh, you know, as an example, the, the one gentleman I think was Cintas.
The, the presentation he did, um, he's gotten it down to, uh, a, you know, a way, a place where he's patching endpoints daily. Mm-Hmm. Why not?
It's an endpoint and you can patch it daily. The likelihood of something breaking very remote servers, you can really decrease the window between patches, you know? Um, and it's gotta happen because one of the key things that attackers like to do, a stockpile vulnerabilities that nobody knows about, they stockpile 'em.
Mm-Hmm. So the more you wait between the window, uh, the more new vulnerabilities show up because they're releasing the stockpile vulnerabilities. So you gotta shrink that window and, and remediate as soon as possible.
It's, it's one of those things that you just have to keep doing and keep doing and keep doing. Um, and the more you can get it to a point where it's rinse and repeat, the less of a headache it is for IT professionals. They've got other things to deal with, rather than having to screw around with patching cybersecurity teams too.
They've got a lot of things they need to be doing. And to have what I call noise happen all the time, and you're kind of hearing all this noise, this vulnerability noise, it distracts from the overall priorities in the organization. Mm-Hmm.
The report you did focused on the math of the cybersecurity return on investment, I think a lot of cybersecurity people struggle to prove the value of security in the first place. It's almost like trying to prove a negative, right? Yeah.
So what's your best advice to folks about how to have that conversation with the business? 'cause a lot of the conversation here today has been about how do you engage in the business and keep them engaged? Yeah.
Um, keeping getting the business engaged, uh, can be one of the most, uh, helpful things you could ever do as a cybersecurity professional. I did that years ago when I worked at Schwab. I got the business engaged in the whole risk management program and they were excited about it.
Um, because the more they, the more upfront you are with things that they wanna do, and you can help them understand what the risks are of what they want to do sooner, rather than at the tail end when they're ready to go to production, the happier they're gonna be. And, uh, and not only being able to get, meet their ti tight deadlines, but also to be comfortable comforted in the fact that their technology is being implemented with security. So, and it, it's a, it's a process.
It takes a while. It, it took me over a year to get the business to that level, but it, it's just trust building over time and having a conversation and educating and uh, and really, and really getting, uh, uh, and from the business mindset why it is their concern. What is it about us in security that has you, you know, all of a sudden freak out?
You get nine times outta 10 of it. It's a per perception problem. And, uh, and well, like I say, perception is nine 10 of the law, right?
So the more you can dispel the perception issue with the business, the happier they're gonna be and the more accepting they're gonna be. Mm-Hmm. What should the role of the security team be?
Exactly. Because a lot of times when there's a breach, they get blamed, but it's not their fault, per se. It's usually somebody else did something.
So, and yet we seem to, you know, roll out the CISO and put them on the firing line, the first thing. Yeah. Yeah.
Um, and now this is beginning to transition, but CISOs have typically been behind the gun. You know, they're given a certain amount of budget to do a certain amount of things, and they can only, do you know what they can do with the budget they have? They can't do everything.
But yeah. When something happens because somebody didn't patch a server, 'cause they don't have control over that process, right? Then they get blamed that there's a security breach and all cybersecurity teams can do, um, up until these, these days today, all they could do up until these days is just monitor and report and hope that it will go ahead and, and fix.
Um, now what's happening is because the board and executives are getting more involved and wanting to understand how secure are we, the CISO has to be able to, to tell that story. How secure are you in order to do that, they need more budget, they need more people, they need more technology like quais to be able to come in and help to remediate the environment. Um, and, you know, essentially, uh, dealing with a lot of the drudge work that it has had to deal with over the years, right?
We remediating vulnerabilities doing risk assessments and things like that. So cybersecurity teams need to take an elevated role. Mm-Hmm.
A lot of security teams are often accused of being tool happy. Yeah. They have too many tools.
And so if you're gonna go ask for more budget, the first question that shows up is, well, what did you do with the existing budget? So, um, how do you explain that to folks and, and do we need to go rationalize some of the tools before we go ask for more money? Tool rationalization is absolutely essential.
And how you end up in that problem space to begin with is when your security and IT teams are very tactical and, oh, I just heard there's a vulnerability out there that's a problem. Uh, I need to buy this widget to solve that problem and I'll buy the widget and solve the problem. So next thing you know, they've got 80 products running in the environment that, uh, is being managed by two poor slobs out there that have no time to do anything else.
So once you begin to transition from tactical to to strategic, you begin to look ahead at the entire environment, what kind of technology portfolio ha you have from a security perspective, really investigate it to find out what, how much overlap do you have? How much non-essential technology, how much of this stuff is 50% implemented? How much of this stuff is actually sitting on a shelf?
So you begin to start digging deeper and looking more strategically at why am I gonna buy this? What value is it gonna provide to the business? And what's, what problem is it gonna solve from a security perspective?
And then you begin to step into the world of total cost of ownership. Something I'm passionate about when you wanna approach management in, uh, acquiring budget to do, to implement a buy a, buy a product to do something, of course you gotta rationalize why you're buying the product, but you've also gotta show what is the total cost of ownership over time. It's not just year one, we spend a million dollars and that's it.
It's not, no, but, but that's what gets forgotten is the year T two through five or whatever, that's not, that's never presented. So management doesn't know that you still need money to continue to run this thing, which is where a lot of security teams fall down. It ends up being a management nightmare.
So total cost of ownership can actually help you address that. 'cause you're looking not only in year one, you're looking at years two through five, but what the cost looks like, and you're setting expectations to senior management that yes, we're gonna acquire this, here's why, but here's what it's gonna cost over time, you're setting the expectation for them that yes, you are gonna come back next year for money. Mm-Hmm.
And, and here's why we gotta manage the thing. Are CFOs getting more involved in this conversation? Because they are looking at the, you know, what they're seeing at least is an, an increased percentage of the IT budget is going to cybersecurity.
And they're coming around asking simple questions like, why is this? Yeah. They have to be involved.
Uh, ultimately the CFO is accountable for making sure that the controls are effective in the overall organizational environment. And that includes security. So they have to be involved.
Uh, and I think their involvement is growing even more. So now, one of the things that we're starting to see in, uh, security these days is this idea of risk quantification. Now, risk quantification is, is not an easy thing to do, but it's not an, you know, an arduous thing.
Some people make it hard, some people make it easy, but you're able to put dollars behind what happens if we don't fix this system? What's the potential dollar loss? What's the potential issue with, you know, if this application goes down for 10 days, what's the, what's the impact?
So it's now incumbent upon cybersecurity teams to actually talk in those terms, right? Oh, okay. So if we don't fix this application or solve this problem, the potential loss is $2 million, right?
And we spent $50,000 on the application. Hmm. You do the math.
Should we remediate or should we not? By, by presenting it in those terms, you're just making it a lot easier for the executives to get their head around it. You can't bring jargon, you can't bring details, you can't bring, you know, UMT metrics, you gotta talk in their language.
And some of those metrics are not absolute dollar costs. I mean, you don't need to be like down in the nickel No. But you have to give people a framework for understanding the conversation.
Yeah. You know, my view is, as long as you're coming within an order of magnitude, you don't have to be perfect with it. And some of the, some of the quantification technologies out there, they're not perfect, but they get you in the ballpark.
And, and at the end of the day, it helps executives understand what the real, uh, the real impact from their perspective is, okay, this goes down for 10 days, the potential revenue loss is, you know, $50 million. Wow, we can't do that. So it's, it's, again, it comes back to communicating in their language.
They just, you gotta do it right. How do they learn that language? Do they all need to go get an MBA somewhere to talk to these folks?
No, because the business people are, you know, they might know more about security than they knew last year, but they're never gonna know a whole lot. So it's up to the security people that go find a way to communicate to them. So where did they start?
Well, it, It requires a shift in, in many cases, a shift in your overall personality and how you approach executives that think like executives. You can't approach an executive from a technologist's perspective. You, they're just gonna run you out of the room.
You've gotta approach them from a business perspective. Yeah, you could get an MBA and kind of get an inkling of how you should be interacting with the executives, but it, it really involves, um, working with your organization, working with your executives, and really listening and understanding what they need, what, what do they need from you, and then giving you the ability to explain it. Now, the good news with the technology that's out there, um, in the risk quantification world, it's actually much easier to explain, right?
You don't have to be, you know, a math, you know, have a doctorate in mathematics in order to explain what impact and loss is. Everybody knows what, see, that's what they live on, impact and loss. But to be able to present the numbers in that language is what they want.
They're not expecting the CISO to be, you know, a math whizz or, you know, just, uh, I don't know. They're not expecting to see. So to all of a sudden transform into this, you know, mega executive that knows everything.
All right Folks, you heard it here. If you're gonna talk to a business person, do not geek out on them. They'll just nod their heads at you, pat you on the head, and send you on your way.
So go figure out how to have a real conversation with them. Hey, thanks for stopping by. Thank You.
I appreciate it.





