Transforming Security Operations: Insights from Shailesh Athalye at QSC24
Shailesh Athalye, SVP of Product for Qualys, discusses the critical role of a Risk Operations Center in managing security signals. The conversation highlights the evolution of Security Operations Centers towards proactive risk management and the importance of CISOs communicating in business terms. The TruRisk platform is introduced to enhance cybersecurity management for customers with a cyber asset inventory.
Transcript
This is Textron tv. Hey, everyone. We're live back here in San Diego for QSE Qua Security Conference.
You know, we've, we've spoken to look, we've spoken to folks from IBM and we've spoken to folks from different banks and, and all kinds of different companies. We've even spoken to some of the qua people. My, my next guest is shilesh.
Right? You got it right. I've in, well, this is only the third or fourth time I've interviewed shy over the last three years.
Eventually I will get it right, because even a broken clock is right twice a day. Right, right. But anyway, shales is the SVP of product now for Qualys, and we were lucky to grab him and pull him in here for a couple minutes to talk a little bit shales.
First of all, welcome. It's great to see you again. Oh, fantastic.
To, uh, be here with you, Alan, again. I appreciate it. So look, the big story here has been the, uh, rock, right, right.
The risk operations center. We've, we've got, we've looked at it from a lot of different angles, but your SVP of product, how do you look at it? Yeah, uh, great question.
Uh, to simplify that, like, look, I'm, I'm not going to go to technicalities or too much of history. I think we are at the position where SOC was needed. You know, a bunch of tools we have on the network security side, on the asset side, they're all sending signals, and now the analysts don't know how to make sense of it.
I have signals from EDRs, I have signals from asset tools, I have signals from incident tool. Now, SOC came about as the merging of all of these signals to prioritize them. Mm-Hmm.
To lower your risk so that you can respond quickly. But again, think about SOC as after the attack thing. Now we are at the position where even the proactive security needs a mechanism where all of these indicator of compromise or indicator of exposures come together from asset management, from vulnerability and config management, from your patch management, et cetera.
And to provide customers one aggregated way to know, hey, what's my risk looks like? Right? And then how do I actually tackle that risk in a prioritized manner?
That's where I think the industry is. So we are calling it as the industry's first, uh, rock, like the SOC risk operation center. So I, I tell you, in my view, I always thought of SOC as something that came about because of sim.
Correct? Yeah. Right.
We had these, we spent millions of dollars on sims and all of a sudden we were collecting data from everywhere, from the vulnerabilities, from the in, you know, everywhere. And someone had to make heads or tails of this sense of it. And so this whole notion of the sock, and then it kind of took on a life of its own, the soc.
Right? Right. Right.
That's where security people gathered, uh, kind of put it all together at the same time. The mission in security changed a little bit, right? Yep.
Right. I think a soc, a SOC was born out of network security. And I don't know if network security is still the heart of security today.
I think you hit it on the head. We, we, um, we have to worry not just about re re reactive security, right? Yep.
But we've gotta worry about risk management. Yep. The proactive intelligence and all of these things.
Now, I've been in security a long time when I first got into security, you know, that's the way it was. Yeah. We did care about risk.
Yes. Security was risk management. Correct.
It wasn't it. Correct. So is this really the wheel turning all the way around You?
You can say that and, and how, how do I look at it? Like, look, it, the same thing happened with, uh, for financial risk management as well, right? Yeah.
But at the end of the day, what's happening is when, uh, the CFO goes in front of the street, they're not telling, Hey, what are the activities I'm doing? Hey, I'm, I'm running all of these audit function, I'm running all of these, um, other accounting function. They have to provide numbers and they have to provide how you are managing your risk of your numbers.
So I think we are taking the turn as the security industry is also maturing. They're trying to understand like, Hey, no longer I can tell my executives like, Hey, how many incidents did we have? How many alerts did we have?
How many patches we deployed has no meaning whatsoever, but what does it mean in terms of managing the risk to my business? So that's, that's one of the reasons why I think the wheel is turning. 'cause also now as the industry is maturing, probably a lot of, lot of executives in security in the risk are now getting executive position.
They're asked to come in front of the board to explain. And the interesting part is, we, we all think possibly live every day in security that board needs to learn more, but is the other way around. The security needs to talk the language of business.
Right. And that's where I think, like you rightly said, I think the wheel is turning to provide instead of me trying to, you know, do everything after math, how do I actually properly manage my cyber risk and talk the language of business to provide, like how my cyber risk fairing to secure the business? Don't disagree.
You know, I remember when CSOs first became popular, right? And CSOs, there were like two roles. One was a glorified security architect, correct?
Yeah. Yeah. He came in and they, or she mostly, he came in and they designed the stack, the security stack.
Mm-Hmm. Nine months, 18 months later, goodbye. Next person, right?
Yep. Then there was another kind of CISO who was brought in and given a seat at the table. Mm-Hmm.
And it was his job or her job, their job to translate security talk to business talk. Correct. But they didn't talk risk.
They talked what you said, how many patches were deployed. They talked numbers, metrics, because the thought was business understands metrics. Now you're saying, well, no, that wasn't the right language either.
Business understands risk. Yes. And this is, so what does that mean for the ciso?
Does he, the CISO has to become the risk expert. EE exactly. I mean, what CSO needs to become expert at is at the end of the day, the investment I'm making is that resulting into securing my business better.
Like, I'll, I'll tell you an example today, like everybody's talking about ai, right? Like there's no interview. I, I hope we Sucks the oxygen out of every group.
Exactly. So now imagine that, uh, an executive goes, a tech executive goes to CO and says, Hey, could you gimme this $5 million and then I'm going to increase our top line by 5%. And then this CSO goes and tells that, Hey, could you actually gimme $5 million to make us more safe?
That has no meaning. So you can imagine where the CEO's gonna put money, right? Unless there's a new language.
What CISO talk about is if you could gimme $5 million, I'm gonna make sure that 20% risk what we have for our critical business app, which is making us a billion dollar, I'm going to take it down to 10%. So our risk to losing that revenue is going to go down by say, a hundred million, And now I'm spending the money. Yes.
That's an excellent example. Let me be devil's advocate. How do I know you're really taking it down 10%.
So, so it really good question, and that's where I think the, the rock concept come in. Picture what Quali is trying to do when we are coming out with industry's first risk operations center done through the enterprise tools management, we are saying all the investment, what you're putting in with all the security tools and all generating your, some sort of indicators of risk, let's bring those together. Let's elevate those to actually map it to calculate how your risk looks like, then map this cyber risk to what your cyber insurer asking you in a questionnaire.
What are your critical business apps you have, how much of insurance you're taking for the same what sort of risk like ransomware, data breach, PII breach, what kinda risk you have today in your environment? And then provide this mapping of what your cyber risk number looks like to your critical business app revenue number. I'll tell you a really interesting example.
Again, let's say you have five business applications. Mm-Hmm. They're all making different type of revenues.
Our own CISOs, part one, which makes the most revenue for Qualys, makes it 300 million. Even if that cyber risk for that app is say 500, 1000, even if that's lowest, then all other apps rival risk are CISO is expected to still prioritize the one which is 500 costs. It maps to the highest revenue making app.
So that's how we are trying to tie the business risk. Risk, Yeah. To dollars.
Yes. It's all about business value at risk tied to cyber risk. Love it.
Um, what's been the, I I just launched, but I'm gonna assume you spoke to a lot of CISOs and Yes. What kind of response are you getting from the, from the field, from the industry? Yeah.
Yeah. Interesting. Alan, you, you asked this question.
Uh, what what we would say is, uh, look, I mean this has been 25 years of investment. You know, what we've been putting in the platform, which has been used to build these building blocks for the cyber risk management. That's on one side.
Even for building the risk operations center or the ETM, we've been working with 25 odd CSOs over last one year to work with them to get their inputs, et cetera. In fact, the true risk name I would tell you has come from the conversation with, uh, one of the top CSOs really for 10 company, their cso, he actually provided, like everybody now uses true risk. Why don't you call your platform as Truist true Risk?
Yeah. So we've been working really closely. I think one of the aspects, what the CSOs is telling is this is something today is needed.
The reason for that is this is something what they've been missing on the proactive risk management side, but also they had tools like GRCs, you remember the old GRCs as well as their good old power bis and the dataware leaks. What they've been using, they've been not working out for, especially for the cloud related attack surface, the cloud related assets, cloud related indicators coming in. So that's where they've been looking for the professional types.
Like, you know, if we are having 70% of our, uh, rock data of vulnerabilities, then why not use Wallace's ETM to extend that power for managing the risk as well? I love it. Um, you know what, I haven't asked anyone today, and I just realized that you're a great person to ask.
So is this a standalone product or do you get it if you're already sort of a quas enterprise customer? How, how is it packaged? Yeah, great question.
Our philosophy is risk management should be the function of every CISO and CRO. So it would be available to all customers from enterprise SMEs as well as SMBs. What we require customers to have is to have qualysis provided cyber asset inventory because that forms the basis, Right?
That's the backbone of, That's the backbone of risk operat sector. And to be honest, that should be anyways, the first step thing That you're buying Enterprise level risk management program. Sure.
So customers need to have policies provided a cyber asset inventory. They do not need to have any other s solution. They can actually have any other product from other vendors.
They can still push this data from third party, uh, vendors for knowing their risk. Excellent. com look for enterprise true risk management.
That's where you get all the information. Absolutely. com/etm, you get all repositories all information on how to operationalize first risk operation center.
Love it. All right, we're gonna take a break here in San Diego. I think we have one more, uh, interview coming up today and then we have a full day tomorrow starting right with our text and gang in the morning.
We have a block there and we'll be live in San Diego all day. But for now, this Alex Shimo for Tech Drunk tv. We'll be back in just a moment.