Insights about VMDR and True Risk with Kevin O’Keefe at QSC24
Kevin O’Keefe shares insights from the QSC24, detailing his role in customer support and the value of Qualys products. He highlights the true risk score and VMDR capabilities that enhance asset management and cybersecurity. Kevin discusses the quick deployment of Qualys solutions, shares success stories, and emphasizes the need to prioritize vulnerabilities for better operational efficiency.
Transcript
This is Techron tv. Hey everyone. We're back here live in San Diego for our day two coverage of Quala Security Conference.
Having a great time today, I want to introduce you to our next guest here. His name is Scott O'Keefe. This Kevin O'Keeffe.
Kevin O'Keefe. Was Scott the last guy? Yes.
Yes. Okay. We've moved on from Scott before then.
We can Change my name. That's what it is. Uh, no, but it's Kevin O'Keefe.
I apologize, Kevin. No worries. There's the interesting thing though, this job's trying to tell us he's from Brazilian.
Kevin, say your name. Kevin O'Keefe. Does that sound like a Brazilian accent to you?
No, I we're going to guess he's over in the uk. Kevin. Um, well, why don't we do, first of all, welcome to Text Drug tv.
Thank you, fat. Why don't we start off with what do you do at Qualys? Yeah, so my job is to help with our customers and our sales team.
So what, you know, I used to be a customer for five years before joining Qualys as as a sales solutions architect. And now I help our customers actually see the value in Qualis and then help them implement it and make sure that what they're buying and getting full use out of that value. So in my day, we used to call those people sales engineers, but that's outta, that's outta style now.
Yeah. We, we like to call 'em something different. You know, we like to be different in qu No problem.
Well, I think everyone's calling them something different. 'cause sales engineers kind of, it was like pinning the tail on the donkey, putting you a sales tag on you and you running really in sales. You're there to help their success.
Yeah. Yeah. It's up to the salespeople.
If it's a good product, it sells itself. Right. Luckily for us, Qualys is there.
Yeah. Um, you know, it's interesting. I've been, uh, been familiar with Qualys for pretty much their entire time.
25 years in business, was a competitor at one time, friend of the company. Um, and then covering it as a media person all these years, this particular QSC was very focused on risk, right? The new true risk score, truist management, uh, really starting to move security back in with risk.
And that's a great thing. We discussed it in a dozen different interviews, but we haven't spent a lot of time talking about sort of that traditional Qualys offering. Right.
That started with something called Qualys Guard. Yeah. Years and years ago.
The base vulnerability and then they've added a lot on, right. The agent patching, uh, you know, the, the whole I and I forget the acronym. Is it q uh, not VMDR.
So VMDR. And then that includes a whole suite of products. So certificate view, container inventory, cloud inventory, uh, you've got your global, uh, asset view and then you can also get, uh, your cybersecurity asset management on top of that as well.
Absolutely. And all of this, I mean, this is the, the bread and butter, if you will, of the Qualys offerings, right? You could put your true risk score on top and some of the other things they got going on, AI and all that.
But really that, I would imagine that is kind of what attracted you to Qualys. And then that's what I initially implemented, uh, back in my previous company back in 2014, implementing the original Qualys, you know, agent getting that deployed and then building upon that. And it, you know, Qualys just keeps releasing more and more additions, giving you more and more capabilities year by year.
I got it. So Kevin, you are the first person to talk about that in two days here with us. Bring us up to speed.
What, what are some of the new developments around that? Well, so we, we have a lot of new developments in with the ETM launch that we're doing, being able to bring in data from across all of our customers and third Party, Depending what it is. But what a lot of our customers do is actually they have the VMDR, but don't use it to its full potential.
So being able to actually use the ability to be able to inventory all your certificates, being able to see how your configuration is, uh, set up. All of this is included in the VMDR offering, and that's our job to help our customers actually exploit that capability and get that value back into to Quas. Being able to actually show the value back to the business of what they can do with the platform.
You know, it's such a massive tool nowadays. We can't expect our customers to know everything. No.
And that's where we are there to help them bring that and then show them what we are releasing. Even though it's an old product. VM VMDR been around for 25 years now we're celebrating our 25 years, but it's actually showing them that even on that old, old, uh, old module, we can still bring out new toys, new things to keep customers interested and help customers.
You know, it's also a symptom of the security industry. Yeah. I've been in the security industry 30 years.
We, we tend to focus on the shiny new trinkets, the new toys we want to get budget for, but bread and butter is still bread and butter. Meat and potatoes is meat and potatoes. And we, we can't lose sight of the fact that if you've got something like, like this that's worked all this time, a yes, you still, you shine it up, you continue to evolve it and improve it and keep it current.
But b the basic, um, skillset and the basic value doesn't go out of style because there's some shiny new thing you wanna focus on for a second. And As security professionals, we are, like I say, very prone to just going, oh, shiny over there when in actual fact, let's get our foundations set to correctly. Let's get that done correctly.
And that's where I like to pull our customers back and go, whoa, let's pull back. Let's get the VMDR set up correctly. Let's get our basics, our fundamentals.
Then we build up and mature and mature, and then we get to the new shiny toys. Everybody likes their new shiny toys, but we, we've gotta make sure that everything around it is working to be able to make a successful VM program Kinda reminds me of that meme, right? Where there's a guy walking with a beautiful woman down the street and there's another woman that hogs by and you see him like this, you know?
Yeah. Be happy. Sometimes you gotta like what you got right there.
You've Got the perfect tool there. It's just being able to use it. And that's what our job Is there To help you show value.
So one of the problems with security, and again, this goes back 25, 30 years, is it's hard. Yep. Right.
Um, I I I know firsthand it's hard. How, how has Qualys made it easier to use the product now? It's, and it's gotten a lot easier.
Let, let's face it. But I, I, I think, you know, if we take patch management as an example beforehand, you know, Qualys was the tool that gave everybody nightmares, you know, gave everybody the work. Here's, here's the qu we Used to call it a bad news generator.
Yes, Exactly. You know, everybody not Just quas all the vulnerability standards, But everybody runs away from you as soon as they see you come in, as soon as they see that email ledge red comes through. Yeah.
But now where, you know, patch management was a great example of actually let's not come with you to, with problems, let's give you that solution. And that's how we're making life easier. I've got customers that have jobs to patch everything every day.
Why, why, why worry about it? Why overcomplicate it? Let's simplify this, reduce risk, and then make it easy for everybody.
I get it. I get it. Um, here's another thing.
Do you remember, you ever install a sim, have you ever had an experience doing that Solution? Yes. Sorry.
Yeah. Yeah. It'll take two years outta your life, right?
And you still won't get to the what You want and it still doesn't work. And I don't know how much value, but that's a whole nother story. Um, how long does it take the average Qualys customer to get up and running?
So actually that's a great example I've had from earlier this year where we've, we've implemented Qualys at one of the UK customers. They implemented it on the 1st of April. By the mid May, sorry.
They were already patching and already seeing a massive reduction in risks by over half of their vulnerabilities. Because first April, get that agent deployed, once they got the agent deployed, we set up the patch management jobs. And within 90 days they had over half then.
Well no boy, beginning of April to middle of May 45 days. Exactly. So ex quick ex, I always say to customers, you know, it's a customer, they always come up to us, how quickly can we deploy?
It's like, you tell us how fast you want to run, we'll run as fast as you want to run. It's so simple, you can get it done. We've had customers deploy 30,000 agents in one night.
Really, you can go that fast. It's up to the customer how fast they want to go. And we can then show that value, reduce that risk really quickly for customers.
So there's that word risk again. You know, and as I said earlier, we've been spending a lot of time today talking, or over the last two days, excuse me, talking about true risk scores and the new risk management capabilities. How tied in is that to, to the base solution already Massively tied in.
So true risk quality detention score, all of that goes hand in hand to help customers actually prioritize the vulnerabilities, the misconfigurations, the risks that they really need to go after. Um, in my presentation yesterday, I, I showed an example. 1 million vulnerabilities.
Wow. Critical and high according CBSS. That is a lot of vulnerabilities for teams to go after just using quality detection score.
They can reduce that to less than 750,000. That's two thirds of their work already been wiped off. Let's go after the stuff that's actually at risk to your environment.
Mm-Hmm. And not only will that help you in, in terms of prioritization, but help the operations team free up time to fix what is actually critical to your business rather than just doing busy work, which doesn't actually reduce risk. And that's been the bane of vulnerability remediation.
Yeah. All this time. Yeah.
Right. Unnecessary cycles spinning on things that aren't really germane to you. Help, help simplify and help prioritize.
You know, and that's what I think Wallace is really helping. We've already got that done well in vulnerabilities and misconfigurations, and now with ETM being able to bring in all those other sources, we can do that across your entire environment. I love it.
Let's talk a little bit about QSC. How many QSCs have you been to? Uh, I've lost count a lot.
10 plus easily. What's your favorite thing about the QSC? Meeting People meeting, uh, our customers, you know, and especially for myself, seeing different perspective, how the American teams work, how the different customers work.
And then also obviously meeting our colleagues and product teams. Management. It's just great hive of activity.
I, I, you know, learn ways of doing stuff or not doing stuff and being able to then go, okay, take that back and teach that to other customers or, or you know, go actually QSC, this is what we learned, you know, don't do it this way. Do it that way, don't way. And it is just great to be able to socialize and, you know, speak to other customers and be able to bring those ideas together and also help us influence our products going forward as well.
Excellent. Hey man. Kevin, we're about outta time.
I want to thank you for, I know you're busy here, meeting with customers and stuff, but thanks for coming in and talking. Oh, you're welcome. Thanks For having me.
Keep up the great work, man. When are you headed back to the UK Tonight? In a few hours time.
I'll be on that Slide. US two. US two.
We're on that redeye headed east. Yeah, same here. Alright.
Kevin O'Keefe. Thank our favorite, uh, Brazilian from the UK here. We're live at QSC.
Uh, we'll be back. We've got a full day of, of, uh, speakers and interviews. Stay with us.