Compliance and Cybersecurity with Anu Kapil at QSC24
Anu Kapil, Senior Product Manager at Qualys, shares key insights on compliance and cybersecurity. She highlights the importance of understanding customer needs and adapting to evolving risks. Continuous audit readiness and automation are emphasized to reduce human errors. The discussion covers complex compliance requirements, Qualys solutions for efficient reporting, and tailored pricing models.
Transcript
This is Textron tv. Hey everyone, we are back here. We've got just coming to the end of our, uh, Kuala Security Conference coverage here this year in San Diego.
It's been a great two days. Our next guest is Annu Capel. Yes.
Got it. Right. Yeah.
Okay. Annu is with Qualys, but Annu, tell us a little bit about your current position at Qualys and maybe a little bit about yourself, your history. Yeah.
So I work in Qualis. I'm the Senior Product Manager for policy compliance. I have been with s for over eight years.
I've worked in engineering roles, and eventually I transformed to product side Compliance is my passion. I would say. I have worked in compliance for almost eight, nine years now in Qualis.
And, um, being the product manager for compliance, I get this opportunity to interact with customers, understand their pain point, and ensure what innovations or what capabilities can we bring in the product so that their use cases are uff surprised and the product is used by customers and they are happy with it. So, yes. Um, I have an engineering background and I'm learning cybersecurity each and every day as it's evolving and changing.
And, you know, that's an important thing. We, we were just talking to, uh, Dino de Marino Yes. The, uh, the, uh, c Chief Revenue Officer about, you know, how he's had not only him, but the whole team has had to kinda relearn how to talk about things like risk and compliance and because security is changing, it's not static.
Yeah. Right. I talking earlier to Jerry Hughes from one of your partners Compass about changes in PCI, you know.
Mm-Hmm. That's some big changes coming through. Yes.
Um, you just presented here though Mm-Hmm. On the stage. If you don't mind, tell our audience a little bit about what you presented about.
So, uh, today my talk was around how you can be audit ready from spreadsheets and be, uh, continuously audit ready. We all know as soon as we hear audits, it's more like a fire drill. Everything is in a sense of urgency.
Everything has to be done right now, right there, but we don't have to wait for audits. We can be continuously audit ready with policy compliance. And it's compliance is no more a checkbox corner those days.
Compliance is more of a business enabler because if a organization fail and audit, it's the business risk. Business operations could come to a standstill. It's threatening to an enterprise.
So they need to be continuously audit ready. And it's not like when you have an audit, then you get all your documents, do it in a manual way. It's a lot of cost, time, effort to organizations.
So basically they need a tool which helps them being audit ready continuously all the time. So they're not surprised. They don't have to go out, look for more siloed processes, solutions, spreadsheet, and move to a more, um, automated streamlined solutions and have those comprehensive reports ready, which can be given to the auditors at any time they ask for it.
You know, I've always believed that if you do security well Mm-Hmm. You, you walk, you will be compliant. Right.
Because I've never met a compliance regulation that wasn't that line with best practices for security. Yep. And so if you do your security well, you'll be compliant.
And if you do your security well and you're compliant, you shouldn't worry too much about an audit. Mm-Hmm. Because it it all, it, you know, when you do it right, it all lines up correctly.
Sounds good in practice. Yep. Right.
Doesn't always work that way. Um, so it, it is important to have something that helps you automate that. I, I will tell you as the CEO here at Techstrong, you know, we get, we're not big enough to really go through a, a huge audit per se, but what happens is a lot of our vendors, a lot of our sponsors are Mm-Hmm.
And so they send us their third party compliance and, and it, it's like an audit kind of thing where you gotta show them proof of your, of your compliance, of your policies, of your, you know, everything. And we don't have anything Mm-Hmm. Like Qualys, uh, uh, compliance audit.
Yep. And, um, it is such a major lift in our organ. I feel bad because I don't fill it out though.
I'm probably the best one to fill it out. I know it well. Yeah.
But I, I, I pass it off to a guy on our team named Greg, Greg Arnold and his, this poor guy, he has to pour through the spreadsheets and the, you know, the instructions Mm-Hmm. And get all this information. And it takes for us, sometimes it takes weeks Mm-Hmm.
To really gather it. It is. I I don't know why we haven't gotten a solution like yours yet, to tell you the truth.
Yeah. Because it would make my life easier. That's true.
You know, because like I said, we're not that big Mm-Hmm. It shouldn't be that big a problem. And we do do decent fact of the matter is us, like many companies Mm-Hmm.
We, we outsource, we sas everything. Yep. 9% of what we have is not even, we're not, it's not us.
Right. Our data is stored there, but it's, so what we have found, the the right thing to do is write to your third party. Right.
To the HubSpots that we use Mm-Hmm. And, and the hosts that we use and, and so forth. And they have to show their compliance because they're the ones who are doing it.
Mm-Hmm. But this is a major pain for, you know, I think it's a major pain for small companies. I think it's a bigger pain for bigger companies though, too.
Yeah, it is. It's like, like you said, security and compliance blend in together. They are kind of the sides of the same coin.
Yeah. It has to go in parallel. I know with more and more cybersecurity attacks, the more budgets are moving towards risk.
But compliance, it's important. You cannot just wake up and think you need to be audit ready. And, you know, it's not just the technical part of it.
There's always this compliance documentation. Like I spoke in my talk, usually for bigger enterprises, it takes around 22,000 man hours for just compliance documentation. That's like 30 to 40% of the framework requirements.
And then mapping it. It's, it's a challenge from start to end. So you do need an automated continuous 22,000 man hours.
Yeah. Yeah. That's for the Deloitte survey.
Yes. That's a lot of money. That's a lot of money.
Yeah. Here, and here's the good news. We're getting more compliance stuff that we'll need audit.
Right. The EU put in this Dora Mm-Hmm. I'm sure you're familiar, right?
Yes. And that's coming out. They also passed a new ai Oh yeah.
Compliance thing. There's rumors that the congress may actually get off up their butts and do something on a federal level. We have all these state Yes.
Ones now. It is, it, it's, it's increasingly Yes. So the compliance complexities are evolving.
They are getting added day by day, year by year. It's so complex that to keep up to that, if you're doing it manually, there's always a scope for human errors and it's complex. You might fail an audit or the auditor might ask for more reports.
There's back and forth and a lot of man manners cost in terms of that. So you do need an automated solution that makes your life easier rather than doing it manually with all these siloed tools, processes, excel sheet that eventually is a lot of work and might not even get you a past audit. No.
So we're in the spreadsheet. Someone once told me if your biggest competitor is a spreadsheet, you got a good business. Um, That might be true.
Yeah. I think it is. And you know what, what we use as a spreadsheet.
Yes. Unfortunately. And, uh, it, I I it's hard.
Let me ask you a question though. How do you, I mean, best practices are best practices, I guess. Mm-Hmm.
But how do you, like, do you have pre-done templates for every single compliance? Yeah. Yeah.
We do. Or virtually every compliance Mm-Hmm mm-Hmm. Regulation.
Yeah. So with policy compliance, call policy compliance, we provide these audit ready mandates, templates for security assessment questionnaires for all these mandates like nurse CIS standards, PCI, Dora, who, whatever the new AI mandates are coming in. So you just have these auditory templates you just need to fill in.
We have done the hard work of mapping the requirements to controls. We just fill the form and generate the reports, and we do all the mapping. And the report is just as it is.
It's a beautiful report that auditors love to see it instead of the spreadsheets where they have to drag and back and forth is involved. So these out of the box policies, templates, and framework mapped makes the job really easier for customers to use the solution and generate those report for auditors and be audit ready at all the times. I love it.
I don't know if you can talk about this or not, but how is the price based on how big the organization is, how much audit its you need? How do you, how do you price something? Like if I wanted to buy it, what is it gonna cost me?
Well, it depends. Uh, there are S-M-E-S-M-B enterprise packages. Okay.
So, I mean, so there's different levels. Yes. Yeah.
Depending how big your organization is. Correct. Yeah.
We, we have different packages. Licensing based, you're gonna use hybrid sensors or scanners agents. We, we get the data from everywhere with the hybrid sensors and connectors.
So it, it does everything then it does your vulnerability scans. Yes. It, you know, everything like, like A-V-M-D-R does almost.
Yes. Yes. Yeah.
And so is this a, a module within VMDR or is it standalone? It's a standalone module, but we have a tight integration with VMDR. Like the true risk now.
Yes. The data for policy compliance misconfiguration goes into the truist. So it'll show you what your TRUIST score should be up or down with the MISCONFIGURATIONS data that is coming in.
Like I mentioned that your SMB port might be open, that might lead to One Cry ransomware, and those misconfiguration might be missed if the data from policy compliance was not coming in. So it provides a real visibility of what your risk exposure is so that you could remediate that. I love it.
For people who maybe want to get more information, where can they go? com and start the trial for policy compliance with a free 30 day trial, Free 30 day trial too. What more could you ask for?
Thank you so much for coming on. I know you came literally right off the stage. They were running late.
Yeah. So I appreciate you running on here. Um, best of luck and we'll, we'll keep it posted.
We'll keep us posted on this. All right. Thank you.
All right. All right. We've got one more video to do here.
One more interview to do from QSC this year. It'll be up in just a minute. We're watching.
You are watching Text Drunk tv.