Enterprise True Risk Management with Mayuresh Ektare at QSC24
At the Qualys Security Conference (QSC24), Mayuresh Ektare introduced Enterprise True Risk Management (ETRM), a new platform designed to help organizations proactively manage and mitigate risks through a Risk Operation Center (ROC). The ROC complements existing SOC and NOC functions by centralizing risk data and enabling a coordinated response to prevent security incidents before they occur.
Transcript
This is Textron tv. Hey, everyone. We're back here live in San Diego for the Quas Security Conference, QSC.
In case you didn't know what QSC stood for. Um, I want to introduce you to my Rush Atari. We're gonna, well, I'm gonna have Mayesh introduce himself in just a moment, but I wanna just note for your, uh, for all of you out there, we're gonna talk today about the, uh, brand new product that, uh, Qualis introduced today at the Qua Security Conference.
And it's called Enterprise True Risk Management. And it's the concept of a rock, right, a risk operation center. However, Mayesh was nice enough to volunteer to come back tomorrow, and he's gonna be a guest along with another Qualys executive on, uh, our text on gang, which plays every day.
So if you tune in the texture on gang tomorrow morning, you'll see Ash again. And we're gonna talk more about the concept of a rock, but for now, may Rash. Thank you.
Thank you for both today and tomorrow. Oh, Thank you, sir. Much.
Um, but let's start with a little bit about you, your background, your position with Qualis. Certainly. I, I am the VP of Product Management here at Qualys.
Um, I lead the, uh, enterprise tourist management offering that we just launched and announced. It is, uh, generally available now, uh, for everyone to use. Uh, truly excited.
I've been in the cybersecurity industry for the past 20 plus years now, and there hasn't been a time that is so fundamentally, uh, revolutionizing the, uh, you know, security posture management, uh, area, uh, uh, that the enterprise tourist management is really reshaping right now in the industry. You talked briefly about a risk operation center. Now, risk Operation Center is a philosophy, right?
Um, uh, that really needs to be adopted holistically inside an organization and enterprise product risk management platform from QS is the means a tool to enable the concept of a risk operation center, and we will dive deeper into it. Yeah. So I wanted to talk a little bit about, you know, I, I've looked like you've been in security a long time, and there's always been friction between risk security and then it Yep.
Because for a long time, security wasn't part of it. It was part of risk. Risk came more out of like the CFO outta the business side of the house.
It, it didn't like risk or security, let's face it, right? They were just slowing them down. Now we've seen security become more aligned with it and more integrated into it, and they're sort of dragging risk along, right?
So already, you know, when we talk about things like Iraq, we already have a sock knock, right? Where sock has been integrated in a knock in a lot of places. Do we need a rock?
Should it be integrated into sock knock? And is it the same people operating the rock that operate the sock that work in the knock? It sounds like a Dr.
Seuss book, But that's how, that's how cyber security industry is. We have so many acronyms out there, right? uhhuh, but, um, a great point, um, uh, you know, teeing it off of the keynote that we just saw earlier at QC here, um, from a disaster recovery perspective, there is a boom, what happens before the boom and after the boom knock and SOC are really focused, what happens after the boom?
Right? You know, how do you really, um, figure out what your responses for an attack that has already happened? Yes.
Right? Uh, obviously there are multiple different signals that you need to aggregate, um, uh, correlate to identify that needle in a haystack that will point you to, this was a root cause of my attack, so that you can create a coordinated incident response needed in the organization. What is missing right now is a similar coordinated response to prevent the attack from happening in the first place.
And that is the position rock really takes today in the industry. The response is extremely fragmented when it comes to the alphabet soup that we were talking about, right? There are a bunch of security posture management tools out there.
Each one of them generates the top 10 things that the team should be working on. And if the team starts focusing on them, they're gonna be chasing hundreds and hundreds of things, right? What is really needed in the organization is put all those signals into a centralized platform, apply threat intelligence so that you can bubble up the risk that matters to your organization.
Mostly overlay business context because, you know, a vulnerability can be, Uh, You know, interpreted differently based on where it appears to be. Vulnerability in your production environment is a lot different than a vulnerability in a developer's workstation. Yes, certainly.
So that business context really determines how what you really, uh, have as an action plan to remediate that risk. The concept of a risk operation center is really enabling organization to bring in diverse risk telemetry into a single fold, so that you are now in a position to really create a coordinated response for risk mitigation as opposed to incident response. So, uh, another thing that I would definitely mention is a rock is not a replacement for a sock or a no, it is complimentary.
You know, you def absolutely need, uh, the sock and the knot, but you also need a rock. Because unless you identify the things that you are gonna do to eliminate the risk, these are the things that are going to inform how do you consume your security posture data while you're responding to threats in real time, right? The aggregated data set that you have around security, posture management, it's going to assist your SOC teams and the lock teams to do a better job of identifying that needle in a haystack.
So one of the, one of the things that I've liked about the Qualys product line for many years, even when Qualys Guard first came out a long time ago, was the idea of customizable views for different people in the organization. The risk manager has a different set of priorities and a different dashboard, so to speak, than the security person who's helping manage risk, right? Who's helping identify risk.
Wow. That that jobber, if you will, that security guy who's there to knock down the risk or, or at least to see where this risk coming from, what we can do to mitigate, he has a different view than maybe someone from the IT team or, or, you know, from someone from the knock, right? Right.
But all of these people's need insight and view, you know, line of sight into what is in that rock. Right? Now, I realize this is a brand new product, it's just released, but do you have that depth already of different views for different personas?
Absolutely. Absolutely. And, uh, you, uh, uh, pointed out, uh, the really important thing, you know, the, uh, the purpose behind creating a single source of truth around the risk data is to consume that data for multiple different outcomes.
One of the outcomes is, uh, reduction of that risk, which is the CSOs function. The second output of that data set could potentially be, uh, uh, you know, uh, figuring out your cyber risk quantification so that you can identify if, uh, there is a residual risk that cannot be remediated. How do I transfer that risk to a cyber insurance vendor?
Right? Uh, this is a function oftentimes owned by the CFO. Yeah.
Finally, the compliance part of it, that there could be a chief compliance officer that oftentimes owns regulatory compliance. But the point to be noted is the underlying dataset is you are looking at for generating these three, uh, outcomes is exactly the same. It's exactly the same.
You are pulling in information from a risk telemetry, from multiple different tools to create that unified single source of truth and then analyze that uniquely based on the, uh, use case that you have in mind and personas who are actually looking at that data policies. Uh, enterprise tools management solution does provide that. Uh, during the demo, I don't know if you might have seen, we provide ability for quantifying business entities so that 'cause uh, organizations can really understand, uh, should something bad happen to this business unit, what is the actual dollar value impact on my organization?
Love it. The next thing I I wanted to discuss was, um, look, we live in an ai, you talked about the boom, right? The, the problem with the boom, well, there's many problems with the boom, but one of the issues is, is the runway is ever shorter.
Yeah. Until that boom. So we don't have a lot of time.
Yeah. Now, the nice thing about a risk operation center is we're we're not reacting to, we're not reacting to a, uh, an incident. We're preparing for an incident.
And so, you know, that helps lengthen the runway before that boom, if you will. Have you done any sort of measurements around, you know, how can we lengthen this runway to, I I don't know another way to say it. You, you are absolutely right.
You know, uh, so here's a data point. Uh, time to exploit, uh, vulnerability has reduced by 70%. 70%.
That's, it's huge. Staggering, right? You know, that's staggering.
Um, there was another data point that I was looking at. Um, you know, in the cloud, uh, time to exploit is less than six hours. Uh, what it means is you don't have much time now No.
To remediate a finding or Remediate before the boom, Before the boom happens. So the best thing you can do is really create a comprehensive view of your risk data ahead of time. Understand the relationships of different, uh, assets and objects and identities in your organization so that when a, um, a zero day vulnerability or a finding comes about, you already have this single source of truth that you can ask of to understand what your exposure looks like, and have that remediation plan ahead of time, as opposed to, you know, uh, figuring out how do I pull in information from 10 different tools when I am possibly going to be under attack in next exhaust.
Right? Right. And that, that, and that is the, the necessity of a rock.
Now, I wasn't sitting here, I had a chance to walk around and we're in what they call the partner area now, but if you go in the next room, you guys have two rock set up. Yeah. I spent a little time looking at them, had nothing better to do.
Um, two, two, how many head c headcount wise, what do you need to run a rock? Great point. Um, so oftentimes CSO might think of rock as, uh, another alphabet soup and think of, Hey, do I need more investments here?
It's not, uh, uh, the, you know, organizations are doing this already today with the resources that they've got. Uh, oftentimes, you know, they are investing heavily in building out, uh, a similar single source of truth, uh, in a data lake of their own, deploying dozens of engineers to pull in data, massage it, normalize it, correlate it, you know, analyze it. So these activities that we are talking about, uh, you know, they're already happening, right?
So the investment is already going. What we are, uh, you know, suggesting is time has come for the industry to actually respond to this in a more organized way. Right?
Rather than, uh, every organization building up a risk operation center from the grounds up, uh, through, you know, uh, uh, the, you know, plumbing, uh, data sources into a data lake. Uh, that's a, that's a very, uh, uh, you know, uh, the effort intensive task. Yes, It is.
What Qualys is bringing to the table now is, uh, a platform that natively provides these connections, that natively understands the data that is going to be flowing through these connections, maps it to the data models that you have, uh, that you're going to be analyzing. And that really requires, uh, more of a strategic thinking, not investment. Uh, the investments are already happening.
Made. Made. Yeah.
And that, that's, I'll make one other point 'cause I know you got it run, but the nice thing about the Rock is already, it's not just Qualys information sources. You're already able to pull in and analyze third party information sources. Can you give us some examples?
Yeah. So today we are bringing in information from multiple different tools. Uh, examples of those could be, you know, uh, from cloud security perspective.
Uh, we have connectors with Wiz, uh, from app, you know, uh, cloud, um, service providers. We have integrations with, uh, uh, AWS. We have connections with, uh, Microsoft Defender Azure, you know, so there are, there are dozens and dozens of these integrations that are going to be pulling in the info data into Lysis platform.
Um, you know, now this list is, uh, not just limited to the integrations that Qualys has. We also have ability to push in, uh, custom data into quast because we talked about business context and how critical that is. Business context does not reside in any security tool, right?
You know, it typically resides either in your CMDB or, you know, in custom CSV file somewhere. Sure. We are exposing an ability to ingest any generic data that you have.
As long as the data exists in our organization. qualis have promises that we will provide a mechanism of pipe to ingest that into etf. I love it.
com. Is there a slash rock or something like that? com.
I highly encourage everyone to, uh, uh, you know, go to enterprise tourist management plate. com. Uh, sign up for your interest in a trial.
Our team will be in touch with you and help you, uh, really, uh, you know, understand the philosophy that we are promoting here at Qualys and, uh, you know, help you establish your rock, uh, in an organization. So thank you so much, Alan. Thank you.
And thank you f we're going to continue our conversation tomorrow. Absolutely. Talk to you tomorrow.
Check out The Rock here at, or get a piece of the rock here at uh, QSC. We're gonna take a break. We've got some content to show you.
We'll be back with our next guest in and maybe just a few minutes here. You're watching Text Drunk tv.