Navigating Cybersecurity with Dino DiMarino at QSC24
Transcript
This is Techron tv. Hey, everyone. We're back here.
Live in San Diego for Quas Security Conference, QSC 24 Americas. It's been a great two days. We're getting near the end here.
Wrapping up. We saved one of the best guys here for last Dino De Marino. Yes, sir.
Originally from Ottawa, but now hailing outta Wesley, Massachusetts. Okay. What school's in Wesley?
Uh, you got, um, actually, uh, you've got Wes Wesley College Wesley, which is where, uh, Elizabeth Shu went, by the way. Yes. Uh, at Babson College, which I, You know, they have their thing going on today, I think.
A MD Yeah, yeah, yeah. And then Babson College, which is now one of the top college, Is the top, top liberal liberal lots or, and Yeah. No, I, I know right there.
Yeah. So Right in hometown now. Very cool.
Home town. Yeah. All right.
Half then. So Dino is the Chief Revenue Officer for, for quas, correct? That's right.
Yeah. You know what? So people are gonna say, oh, a sales guy.
I am shutting it down. But there's a lot of sales guys who have a lot of tech chops. Yeah.
Tell us about your chops, especially Here. Yep. Yeah, if you think about the, uh, well, my chops, I'll explain more importantly my team's chops.
So we have a pretty unique go-to-market model here. We do have folks that are in business development and sales, but probably over half of my team, um, are ex practitioners, ex solution engineers, uh, ex solution architects in some, you know, cases implementation folks. So, you know, the ethos of the company has always been to drive as much value for our customers as we can.
Um, we're a profitable organization, so by proxy we've had to make some trade offs as to where we want to invest, and we've sort of really valued the technical aptitude of our, our sellers, uh, so that they can provide as much value to customers as we can make sure that the technology is well adopted, utilized, et cetera. So. Sure.
So we actually interviewed, I, is it Kevin O'Keefe? Yeah. Yeah.
Extension Of our team. Ex ex practitioner. You got it right.
He was a customer. Yep. And that's how he came on board here.
And you, we had a really good chat with him about the VMDR and, and stuff like that, so, yep. If that represents, I guess that's A great example of it, Of what you got. Yep.
A hundred percent. And for me, I think a part of the, I like to think part of the reason Summa, our CEO hired me is, uh, an appreciation for the category, which is cyber, the problem space that we're trying to solve, uh, and the technology that, you know, we're building evolving every single day. Right.
A lot of which we, we talked about the last couple days at QSC. Talk to me a little bit about your background before Qualys. Sure.
Yeah. So I've been in, in cyber for, uh, 15 years now. Um, so, you know, started my career at, at Dell, then moved to a company called EMC, again, OUTTA Massachusetts Before Dell bought them or after, Uh, before Dell bought them.
That's right. Um, That's how you wound up in mass. Yeah.
And then, uh, Hawkinton. That's right. I've been there.
And then I ended up, uh, sort of moving divisions into RS a's security division, which is part of EMC. And, uh, OMRI was running Canada and then had a bunch of different management roles, moved to the US in 2013, and then worked for a company called Mimecast. So mid-market security company.
Mm-Hmm. Uh, Snyk, which is one of the world's I know them very Well too. AppSec companies And Sure.
com, so we absolutely, obviously cover Snyk quite a bit. Yeah. A lot of similarity in what we're trying to do with enterprise true risk and what Snyk is trying to do, uh, as it relates to developer security, and then have been at Qualis about 18 months now.
So it's been a great journey. Very cool. Excellent.
Well, Qualys look, as someone who's been in the security industry 30 years, right? Qualys represents sort of a unique play in security, right? They look, they're one of the foundational players in the vulnerability space.
Yep. But they've made a really great transition to vulnerability plus, if you will, right? Yeah.
Agents endpoints, all different AppSec kind of stuff. Risk. Yeah.
And I, you know, if you ask me what was, what's the one word to describe this year's QSC, it's risk. Amen. So let, let's talk about that.
How does, how does that translate to you talking and your team talking to customers trying to change the conversation, saying, Hey, your board doesn't care about how many critical vulnerabilities you have or how many patches you did, or they wanna know dollars and cents. Yep. What's my risk?
How do you, how do you sell that? I think we, um, we do sort of acknowledge that, uh, you know, first of all, vulnerability management is and will be a key pillar to anyone's program. Right.
But, uh, but ultimately it's a, it's an operational, uh, operationally centric technical. It's, It sits down here. Yes.
Non-strategic and a board, you know, boards are probably aware of vulnerability management and sort of the high level concepts of it, but they're much more, uh, in tune with risk. Right. I'll tell you something.
In still Secure company, I had started back in early two thousands, we had a vulnerability management tool called Van Vulnerability Assessment and Management. After talking to a lot of our customers internally, we called it the bad news generator. Yeah.
Because that's what it was. Yes. We would scan these things and say, Hey, good news, here's 2 million no findings.
Right. Here's 2 million vulnerabilities. Get busy.
Yeah. Um, people, you know, the board didn't really appreciate that. Yeah.
And I think they want to know ultimately, 'cause I sit in our board meetings, right? Are we getting more secure and do we have less risk than we did a quarter ago? Or are we moving in a different direction?
Absolute, something changed, right. Uh, that's material that we should talk about. Or, you know, are we simply getting better visibility and still now need to sort of burn down that, And you really want me to authorize you to increase your budget by 20%, Which is, that's been a huge change, I'd say since Covid has wound down, as, you know, budgets, we estimate and, and we've got IDC and others sort of validating, you know, they're only going up, but inflation maybe plus three to 5%.
So the, the number of toys that, that are various competitors and peers can sort of sell to a CISO are, are gonna come under much more constraints. So quantification of risk is gonna be, we think, the absolute game changer. Not just for Qualys, but for CISOs to, No, I think that's what the industry has to go.
Well, and you just hit on something that really, look, I've been around for the rise of the ciso You have too. Yeah. 15 years, right?
The average CISO life expectancy was about 18 months Almost as bad as the CRO. Yeah. Well, not quite as bad as the CROI could tell you stories about CROs, man.
Well, man. But anyway, but no, seriously, the ciso, he come in, he either architect the, the stack, the security stack, and they'd say, thanks very much. You can now be a security admin, or you could hit the road, but I'm not paying you as a c-level.
Um, or he could learn to talk business talk. And the problem was, even if he learned to talk business talk, he couldn't translate. Yep.
There was no translate, there was no Rosetta Stone. Yep. To translate security to business talk.
And here's what I think, I think meeting with all of our customers and prospects and partners, um, this week, CISOs have been asking for what we call enterprise truist management. They just didn't know we were gonna call it that for years. Like, to their credit, they knew what the problem was, at least the more forward-leaning ones.
It's just the technical capability to deliver it has been a pretty difficult task. And so the fact we've been able to adjoin what we've, what we're driving with ETM around the various technical components to sort of aggregate the telemetry you need to now actually have a business conversation, not a new concept, but the, um, as I like to tell people, it's easy in principle, hard to execute. And so we're pretty proud of the fact that we're able to build these Absolutely pieces together.
I'll tell you something, Dino, maybe eight years ago, 10 years ago, I did a panel at R-S-A-I-I moderated it was how to talk to your board Yep. About security. And I had, uh, I had a couple of analysts and I, and I had a couple of CISOs, I think there were four people on there, so maybe three in one, three CISOs and an analyst.
And, and the consensus was they were advocating dumbing down. Look, the board's never gonna understand what we gotta tell 'em. We gotta dumb it down.
So we just tell 'em things are very good or very bad. You know, it's red, it's green, it's yellow. I got a dashboard for you.
And you know what, that went over like a Led Zeppelin. Yep. Right.
I mean that the board doesn't, that didn't translate to them. They didn't have a translation tool that allowed them to translate security risk to dollars and cents risk. Yep.
And I think that that's the, the golden key here. Yep. A hundred percent.
And being able to then acknowledge that while, you know, reputational risk is always, you know, something that should be top of mind And you can't put do, it's hard to put dollars, put Dollars. Yep. But you can, you can now start to understand the operational risk cost, et cetera.
And then you spend your time on the things that are maybe more qualitative versus quantitative. But up until now, people have just been trying to stitch together just millions Of, I'm telling you, the red, yellow, green kind of nonsense. Right.
It's Just, it just gets overly abstracted, I guess is the challenge. It's dumbed down. And people on boards are not dumb.
They may not be security experts. Yeah. But they're smart people.
Yeah. And you, if you talk their language to them and, and that, look, I, I, I will tell you I've managed a few sales teams in security in my day. It's hard finding people who could talk that language to them as well.
Right. And, and I'm happy to talk to you about this, right? So you go into your average organization, you got your technical champion.
Yep. You've got your business champion, and then you've got your kind of financial stakeholder, the guy who signs a check. Yep.
Right? And sometimes two could be one, but those are the three personas when you're talking selling risk like this new product. Who, who on that, who are you selling that to?
Well, I think, I think ultimately I'm a, I'm a big proponent of you've gotta sell at all levels. So I, I don't think it changes the fact that we need to have, you know, you know what I'll say some level of connective tissue and, and belief from the technical folks that we can help them with their day-to-day operations. I think what this does is open up the opportunity to get, hire an organization and have a value add discussion versus It allows you to come top down versus bottom up.
And you have now the ability to do both, I think. Mm-Hmm. I think the, the persona you mentioned, that's gonna be a bit unique for us.
Now, the term c FFO has never been thrown around more at A QSC or any conference Yeah. Than this one. And we have partners saying, we actually think, especially in mid-market, that we can start to have round table discussions, or even one-to-one discussions with not only CISOs but their counterparts in finance to help them sort of bridge that gap between the financial side of the house and then the cyber risk side of the house.
So we're excited about that opportunity. Absolutely. So, how old I am, this whole thing has come full circle.
When I first got into security, security was not part of it. The c Yeah. It was part of finance.
It was part of the CFO. That's who we always used to sell to. And it was a, it was hard to sell to them.
Yeah. Because they certainly, I wouldn't Wanna sell to our CFO security. It's tough.
Yeah. They all are. I've never met one of who's a pusher.
Well, that's not true. I, I, well, I don't even wanna get into it. Um, but anyway, it is, it's a very different dis discussion decision, and you're not, you're not gonna sell 'em with bits and bites Yep.
And speeds and feeds and all that stuff. You, you need to talk their language, what they understand and it's dollars and cents. Yep.
Absolutely. So that is definitely a, a change for us that, you know, it's early days as far as not the technology now that that's released, but more how we're gonna have that conversation in That learning. Well, that's my next question to you.
Does it scare you a little bit, because you're, in some ways, you're doing the missionary role here, you know what they say about missionaries, right? Yeah. Unfortunately, the cannibals eat you and then some guy comes along and picks up the scraps, right?
Yep. 'cause you, you machete through the jungle. Yeah.
The trailblazers. Yeah. I mean, are we nervous about it?
I, I don't think so. I mean, I think Sumit has had enough conversations as we've been getting ready for this launch, as have I, and many of our product leaders that you interviewed this week. I think that the, the part that maybe keeps me up at night, it's another thing CISOs hate being asked, but Mm-Hmm.
I do actually be kept, I'm kept up at night on how do we disseminate this knowledge to our technical account managers, our account executives, so that they get comfortable with it. 'cause I think if we do, we'll actually create enough separation and value from potential competitors where we will, we won't be eaten. But I think you're right.
If we don't execute on that part, which is on my shoulders to do, then, you know, certainly that is a risk, no pun intended with Yeah. You know, what we're, I get you here. We could quantify that risk though.
Can I'm only kid. My whole world Is qu I Yeah, yeah. I get it.
I get it. Um, but no, I, I, that's a thing. You know what?
But here's the thing. It is a potential game changer. And you, you know, opportunity knocks only a few times and if you don't answer the door Yep.
You never, you'll never win. So you got to like, put your one one foot in front of the next and go, go for it. Right.
Let's keep going. Yeah, Absolutely. Absolutely.
Man, I wish you the best of luck with it. Thank you very much. All right.
Dino Demarini, uh, CRO Dino Dini. DeMartino De Marino de Marino. Where they get DeMartino.
It's late in the day here in San Diego that it made a little rhyme even. That's right. Dino, thank you very much man.
I appreciate you. Alright, good luck with this. Keep us posted too.
'cause I'm, this is gonna be, you know, RSA is next, the end of April, may. Yep. We do, we do our thing there every year.
It's gonna take, I think that long to kinda see how this Yeah. You know, washes out. I'd love to hear what you're, what you're hearing and seeing and you know, Changing it.
Yeah, I think we are, I mean, in a good way. I think we are a bit beyond incubation 'cause we've been talking about this for a while. And like I said, customers have been asking for it.
They don't always ask for certain capabilities that cybersecurity comes out with to come out with. So I think you're right. I think by April we'll have some really good learnings.
Things that we're gonna change do, do differently and, and double down on for sure. Very cool. Looking forward to it.
I'm gonna get it right. Dini d Marino. Dino de Marino.
Dino, what did I say? I feel like I've, like, I'm in California and God knows what they've given to me in like food here. Alright man.
Very nice. You know man. Thank you To meet you.
Talk soon. All righty. We're out.