The Future of Cyber Risk Reduction with Sumedh Thakar | Qualys QSC 2023
Sumedh Thakar, president & CEO of Qualys, discusses the future of cyber risk reduction, as well as the importance of aligning cyber security outcomes to business outcomes.
Transcript
This is Techron tv. Hello and welcome back to the Quas Security Conference for Americas. We're here with Quass, CEO, ed Thacker, and we're talking about the intersection of cybersecurity, IT and business.
'cause Well, there's a lot going on in ma. Major changes are afoot, shall we say. Uh, Thank you very much for having me.
If you don't mind, walk us back a little bit. I think a lot of folks come into this business and especially the business side, and they look at this and say, how did we get here? This is kind of a mess.
They're like, the security people don't speak the same language. The it people don't speak the same language. The business people don't know what these folks are talking about.
And, and they think the it and the cybersecurity people are actually the same people and they assume, discover that they're not, how did we get here? And then what's the, what is the way out? Yeah.
A lot, lot of, uh, assumptions being made from all sides. Right? And I think it's, uh, you know, it is really interesting because it sort of sprung up upon us a little bit because of the, the digital transformation that every business has gone through.
And so I think having been in vulnerability management for all these years, you know, there was a time when you would scan your 5,000 assets once a quarter and that was good enough, right? And today what has happened is that every single business is digital, which means everybody's writing their own software, everybody's installing more software, everything is becoming digital and software oriented. So it it's just a matter of time that you're gonna have more vulnerabilities, more misconfiguration, and more risks coming out.
And so now that every business, a big part of that business is digital, the risk coming to that digital side of the business is really becoming a key business risk, right? So for a bank, it is a le much less risk of a, uh, you know, somebody going armed robbery in a, in a branch, individual branch versus one of their central servers being attacked. And the damage that is gonna have is a huge risk to the business.
And so, uh, I think we were kind of chugging along, uh, just doing what we were doing and, uh, as an industry and as, as we have sort of gotten, uh, the last few years with, with so much more software being deployed, uh, the concerns around how do I understand the risk that is coming to my, my business from cybersecurity? And how do I articulate that in a way that makes, uh, sense to the board, to the CFO to the business? Uh, I think this is something that's a, is a coming a new area, which we haven't really dealt with in the past.
Uh, and I think that's really what has changed, uh, coming into this. You mentioned this in the keynote and it kind of made me smile and laugh because, you know, for the last few years, security people were demanding that they wanted to talk to the board and they wanted to talk to the CEO. And yes, now they've had those conversations and they're shaking their heads.
So how do we enable the security people to have those conversations more effectively? 'cause I don't think the board is gonna know any more about security than they already know. And I think that's, that that's what everybody's learning is the la you know, a few years ago CISO wanted a seat at the table at the board and, and wanted to be reporting to the CEO.
And I think we've gone through that transition. And as more and more of that has happened, they're realizing pretty quickly that the board doesn't understand what they're talking about. Because most of the time they are going in and speaking the language of technology and cybersecurity risk and or rather just cybersecurity events.
Um, and the board really looks at it from a business side of financial equation and they're saying, well, how much am I spending in cybersecurity? How much risk do I have? Uh, and, and none of those conversations are happening.
And so most of the time the CISO are going in and giving project updates like we implemented multifactor authentication. Well, so the question is, okay, so you spend $2 million in two years, how much safer are we? And, and that's a question that they're not able to answer.
And so now that is sort of causing this, well, what's the right language to speak? So I can articulate that to my board, to my management on what is the risk to the business? How much am I spending to take down that risk?
And what's an acceptable risk for me to have from my digital footprint that, that I have in my environment? You also touched on what I believe is the core frustration is we are spending more money on security than ever, but the number of vulnerabilities are still out there. They're not patched in a timely manner.
And what happens is we get attacked and then everybody sits there and goes, but I thought we just spend $5 million on cybersecurity. Yeah. So how do we bridge that divide in a way that people perceive that there is an ROI both for cybersecurity and the IT side?
'cause they're looking at that as well and saying, guys, how come you keep getting the same hits over and over again? That's a great question, Brooke. It's, it's, uh, it's very simple.
Statistically more software means more vulnerabilities and, but we have the same number of people in the security team. Uh, and so just because you have more vulnerabilities, it's not translating to I need to spend more. So what is happening is that, uh, you, everybody's getting to the point where they have too many vulnerabilities being detected and they're trying to figure out and put all their energy and patching and fixing things as fast as possible.
6 billion detections that we did in the last 12 months, uh, based on CVS ass, almost, uh, 80% were classified as high end critical. And so people are trying to patch and fix those, you know, a large number of their vulnerabilities when the reality is that a very small percentage of those really are exploitable and are being actively exploited by threat attackers. So when you are in the situation where you have a, a budget crunch or you have, uh, limited resources that you need to focus on the things that are really gonna make an impact to you improving your security, that's where the prioritization is becoming very important, right?
So while yes, we can find and discover everything, the ability to prioritize based on threat context about what's actually being exploited, and then being able to, uh, do that based on the business context, right? So just because something is being exploited may not necessarily mean that it is on an important asset or a critical asset that is, um, you know, a five, $500 million business. And so today, what, what we're talking about with the tourist platform, et cetera, is really how do we help customers not focus on the wrong remediation, really focus on the right remediation, which is the ones that actually cause risk to the business, and start from there.
So you can prioritize. And so your limited resources can be focused on that. And once, once we are able to do that, the frustration levels will come down because now you're able to show, yes, I did not patch 20,000 vulnerabilities, but I did patch the 300 that were the most critical to our business.
And that's a measure of success that is gonna make people feel much better rather than, um, counts of detection and counts of patches. We have been scoring vulnerabilities and risks for a long time. Now, how do we have confidence in what the actual score is that we know that this is actionable?
Yeah. And that's a a lot to get the score accurate, you need a lot of inputs coming in from different, uh, sources and, uh, a bunch of them are gonna be Qualys and there are going to be other sources where we're not collecting the data so that we can get all of them in one place. And, uh, at the end of the day, the the absolute score really is not the point, right?
It is about the impact that you're having on reducing that score. So whether it's, you know, uh, the scale is a 900 or a 90 or a 9,000, the question really is what is your acceptable, uh, score in, in that, uh, scale? And how much are you willing to spend?
Because at some point you, you know, whether it's 9,000 to to 1000 or 900 to a hundred, the question is, is it worth it to spend any more money to fix the last a hundred or 200 score? Because that's high numbers that may not give you any actual meaningful risk reduction. And so today, uh, I think the, the scoring formula we have is obviously, you know, it, it's pretty open and anybody can look at that.
It's, it's fairly simple. The point more is how can I use that score to understand relative business risk and then use that to demonstrate actual impact by showing the reduction in that, in that risk, uh, and not so much the, the absolute score that we see Cybersecurity teams get beat up for being in the office of No, but in reality, they can't really make anybody do anything. Yeah.
So, um, you were talking about, you know, presenting people with a report that says, these are your vulnerabilities and put your John Hancock right here. Yeah. Is, is that practical?
Have you seen people Do that? I, so we are starting to see that. But see if you, you to go back to the history of cybersecurity, like you said, is it was sort of the office of no.
Right? And, and the reason is because that their job was just to say, here's everything bad and, and go figure out how to fix it. And, and I think that's where I talked about in my keynote, that there, there really needs to be a paradigm shift, not so much in the tools and the process, but in the approach of the people who are the cybersecurity experts.
And they really need to move from becoming a cybersecurity expert to a cyber risk expert. And today, we saw in the hall for out of the 800 people registered, like eight people actually had the title risk in their title. When reality is all of them are actually working towards reducing risk.
And so all the new next gen cybersecurity leaders, um, need to be able to communicate, need to be able to measure the risk, they need to be able to tie it to the business, communicate that risk, and most importantly, be able to be impactful in eliminating that risk. So there's days of saying that's an IT issue. Remediation is an IT problem is not really something that can continue to to work because, um, cybersecurity, at the end of the day, they are the ones who are at the forefront when a breach happens.
So they have the responsibility and they have the accountability, but then they also need the empowerment to be able to have impact on what exactly needs to get fixed and how. And so that's where with, with the ability, with our truist platform to add the eliminate capability, we are also empowering the, the next gen cybersecurity professionals to be able to be instrumental in the remediation part of it as well. Whether it's patch management, whether it's mitigating with compensating controls, et cetera.
But they, that empowers them to work with their IT teams to pretty rapidly take down the most important, uh, issues, vulnerabilities, misconfigurations, that are causing risk to the business. And I think this is imperative. We are already starting to see that, and we see that in the numbers.
Um, just in the last 12 months, Qualys agents deployed 54 million patches on customer environment, which is a huge number considering that we are a typical cybersecurity vendor who's supposed to be only detecting things and reporting things. But given the kind of, uh, excitement and feedback we see from our customers, I think this is, this is really a game changer in my mind. Do you think security people have inadvertently set themselves up to be the fall guy in all this?
And I asked the question because every time there's a breach, somebody wants to blame the security people, and yet if I made a corollary to the, every time there's a robbery, we don't fire the police chief and every time there's a fire, we don't fire the head of the fire department. So, you know, do we need to recalibrate what it is the role of the security team? Yeah, I think as, as we move more and more towards understanding and focusing on business risk reduction, I think the, the coming together of the IT and the security teams is becoming more and more important.
And, um, and I think just how still look, I mean, even if you look at it, this is a fairly new space, you know, the last 10 to 20 years where cybersecurity has become really so important. And so organizations and businesses are just trying to calibrate what's the right model that works so that they can actually have proper accountability, proper responsibility, and also the right amount of empowerment. And so we already start to see that shift with security professionals being responsible or given the empowerment to start to make those remediation, uh, uh, capabilities happen.
And so now it becomes more of a joint responsibility. So if they are the ones who are gonna go and explain that, uh, a breach happened because of vulnerability was not patched, it's not anymore because of the IT person that the vulnerability did not get patched, the security team actually has the ability and they're empowered more and more to actually go and patch that particular vulnerability. And so this is gonna be a paradigm shift.
I think we are at the early stages of this, but as we, as we move forward in the next few years, we are going to see that it's not just gonna be the cybersecurity team, that that has to be, uh, taking the fall without the, the right empowerment. I think we're gonna see more and more cybersecurity professionals get better empowerment to actually, uh, effect remediation actions as well. How do I achieve that?
Do I take them all and lock 'em in a room and hope that they common sense will prevail? Do I take them all in a retreat somewhere and they kind of figure this out? Yeah, I, I, I think, um, if they have to pick, they'll pick the retreat, but I don't think either one of them has actually worked out.
But I think, but we do see success with a lot of our customers where they are bringing their IT team together. Um, they are explaining being, uh, really to the IT team, the benefit that they get in terms of the reduction in the stress levels that the IT team has to deal with, uh, by taking away the, the security functions, uh, that necessarily the IT team has to do. Uh, so I think it's going to be a, a matter of coming together.
We have customers that are actually giving their IT teams login into Qualys as an example. And for a lot of them, this is exciting because they are getting a chance to work with the cybersecurity tool. And so IT teams are excited.
So a lot of the soft skill is coming into play. I just met a customer and uh, and she was saying like, Hey, I, I just take out my IT team for dinner multiple times so that they actually focus on helping me fixing the right, uh, vulnerabilities. And so I think, uh, again, we're gonna see more and more of this, uh, uh, happen where as they come together, they're gonna have to find the right balance.
But the good news is that we do see that happening already where we have customers that a single customer has 400,000 assets and they are also patching those assets with the same tool, uh, which is the quass agent. Uh, but they were able to bring the IT team to the table. And so the IT team and the security team have a shared access into Qualys as an example.
So when they collaborate together and they're both keeping track of what is happening and they are actually able to make that happen. But I think at the end of the day, to achieve this business goal of reducing the business risk, uh, that these teams have to come together and do a better job of collaborating. And I, I, I see green shoots of that happening already.
Alright, You're one of the few CEOs that has an engineering background, so I'm gonna ask you this question. Of course. Is AI gonna save us from ourselves?
I think AI is gonna help a lot. Uh, but you know, just like with any other technology, I think it's not the end all be all of everything, right? I think, uh, it's interesting in certain areas where you're gonna see like email security where you're gonna have more prevalence of ai in other cases, maybe a little bit less.
But as an example in email security, uh, attackers are using AI to generate almost, uh, perfect phishing emails. And the only way you can actually detect that it's a phishing email is by using ai. And so now the human, the AI is fighting AI and the humans are eating popcorn, right?
But you know, in cybersecurity, in the space that we are in, I think there are many opportunities to leverage the learnings and auto automated model building by looking at large data sets the way Qualys has it to be able to help customers identify things that they haven't thought about, they haven't seen automatically just because they're actually able to, to use the broader dataset and the the models. And so that's one of the things that we are demoing at the conferences. Just a simple thing of the security team sees 200,000 assets, but they can't tell which of those assets are really critical, business critical.
Are they marked correctly so that they can focus on those assets? And so having seen millions and millions of assets, our AI models can help those customers identify assets that should have been marked as critical, but they have not marked those as critical. So that gives really good use cases where AI can really help us reduce that gap in doing so many things manually.
Uh, and so I think, um, we know for sure that the attackers are going to use AI and they're already using AI because they are an enterprise. They want to invest in technology so that their bottom lines are also looking, uh, better. They have to invest less and get better success.
Uh, so it of course becomes imperative that, um, it and cybersecurity teams also leverage AI as much as possible so that they can counter that ai, um, that, that attackers are using. But I do think that, uh, we will see more and more of it. But, you know, I don't think it's gonna be the end all, be all of everything that is gonna solve all challenges.
It's an arms race, it is November of 2023, we're looking into 2024. You get your crystal ball out. Where are we gonna be a year from now?
I think I see a lot more customers and just even just based on the feedback that I saw, a lot more organizations are going to pivot more and more towards a risk based approach to prevention. And, and a lot of this sort of brute forcing or compliance based fix everything, patch everything and, and, and the success, uh, a lack of success that they see is going to start to change and pivot. And I think, um, customers are looking for more of a balanced and consolidated view of multiple risk factors so that they can make effective remediation decisions for, that are driven by business outcomes rather than just, uh, you know, the severity of a particular issue, uh, and, and having to, to fix it.
And so, uh, the more we move towards that model, there is a, there's a good, uh, outcome of that which is going to be that the IT teams and the security teams will be able to do more with what they have because now they're not trying to do everything they're really trying to do and focus on the little stuff. And I think this will be a benefit to businesses where they adopt capabilities that actually allow them to narrow down things based on threat intelligence and business risk. Then, then they can effectively increase their budget in cybersecurity without hiring more people because they're actually able to do more things, uh, uh, because they're focusing on less things.
You know, ironically, All right, well a person much smarter than me once said that, um, if the process requires a heroic effort to succeed, it's fundamentally broken. So let's go and look at the processes again. Exactly.
Alright, thank you very much. Always a pleasure talking to you. All right.





