Johnny Shaieb on Vulnerability Management with IBM & Qualys at QSC24
Johnny Shaieb, the chief architect of vulnerability management at IBM, shares insights on the client ecosystem and the evolution of vulnerability management tools. He highlights the significance of digital communication and the establishment of a risk operations center. The discussion covers managing vulnerabilities throughout their lifecycle and features of the Qualys tool, which combines related CVEs and creates remediation recipes.
Transcript
This is Textron tv. Hey everyone, we're back. We're live.
We're in San Diego at, at this point it's better than being in Florida. Amen. And, um, we've got Johnny s shy up here.
Did I say that right, Charlie? Perfect. All right, perfect.
Johnny's with IBM. You know what? I don't want to, why don't you tell them?
Yeah. Um, my name is Johnny Re I'm the Chief Architect of Exposure Management at IBM. And I've been with IBM for like 21 years.
So, and, uh, our specialty is really understanding the client ecosystem, the battlefield. And really the battlefield is a digital symphony of zeros and ones harmoniously communicating across devices, assets, people, processes, trains, planes, automobiles, power plants, nuclear actors. It's exhausting.
It is. And what's really interesting is being able Beepers, walkie talkies. Oh Yeah, yeah.
Baby monitors the whole nine yards. Right. Everything Pacemakers.
Oh no. But, um, it's really interesting to, you know, watch the evolution of, of Qualys over, you know, 25 years of going from the traditional vulnerability management tool to the assessment business of policy compliance, then to da scanning with web application scanning. And now we're in a whole new evolution of orchestration.
Yes. And I know it's called patch management, but it's really more like vulnerability remediation, fixing the elements of a vulnerability that native operating system tools, and I'm not gonna name them, will halfway fix. And what's interesting about this year is being able to ingest multiple data sources, third Party data sources, third Party data sources to get into this new paradigm.
The rock Yeah. Risk operations, you know, center. Center.
Yeah. And just, you know, my first thing is, well, we got the soc, we got the, no, do we need a rock? I want to go back a second.
Your title was Chief Architect of Exposure Management. Exposure Management, which is, we were talking offline is formerly vulnerability management. Formerly vulnerability management.
But That's a good way of looking at vulnerability management, exposure management. It's a maturity journey. Yeah.
It makes a lot of sense now that I think about it. You know, you talked about patch management too. We were talking offline.
I've been around this game a long time. First time I ever saw patch management at scale was a company down your way called Citadel Hercules. Yeah.
If you remember, that's a blast from the past, right? Yeah. I feel like we're on, uh, Casey case of, but you know, Citadel Hercules had the APA or darpa, Uh, that's right.
Contract for, for DOD and that kind of made them a defacto standard. And back at the time it, you know, it was better than whatever else we had. Kind of almost.
But it really wasn't, looking back on it, it was far from perfect. And I think you said something that is, you didn't actually say this, but it's what you were getting at, which is there's more to remediation, there's more to vulnerability management than applying a patch. Yeah.
You know, it's about pushing left to action the right way. Right. And really vulnerability management, exposure management is about managing the lifecycle of a vulnerability from its birth to its final remediation.
And there are a very few amount of tools on the market that can do that. And what's kind of cool about, not kind of, but very cool about Qualys, IT clubs together multiple related CVEs into into one QID Yep. And then is able to create recipes, if you will, for that specific vulnerability.
And what's also interesting too, about Qualys and other tools, but specifically Qualys, it allows the service provider to provide value add on top of the value that, that, that Qualys provides. Case in point, um, for the longest time, uh, vulnerability platforms, we're not able to integrate with like a ServiceNow remedy in Jira. Right.
And what, what, how are vulnerability management teams scorecarded by being able to reduce the number of vulnerabilities, The Number of Risks, such a pain I've man, do I remember those days opening a remedy ticket for a vulnerability. And so now the vulnerability management team is able to take everything that they learn about assets, network, location, internal external DNZ asset, criticality, critical, high, medium, and low. And the most important thing who their remediation team is.
And now in enrich ServiceNow, JIRA and Remedy. And, uh, that's probably to me, you know, in the partner meeting yesterday, to me that's the most important thing, being able to define that battlefield, who are the players of that battlefield to where you can ultimately drive down vulnerabilities. Yep.
Connecting the dots from A to ZII don't disagree. You know, the, uh, the, the theme that we've seen today is, uh, this year's QSC is the return of risk risk management. Yeah.
I mean, risk has always been there, but risk management. Yeah. 'cause somewhere along the line we bifurcated out risk management from security, security worked more with IT risk maybe did it, but with this rock product, right.
The risk operation center, we're seeing security and risk coming back together, I think tighter. Right. So I heard it described earlier from, uh, I think the qua CTO about, you know, security is like onion.
That's that's perfectly correct. Where in the old days you were looking at a vulnerability from inside out. Mm-Hmm.
But now with attack exposure management, you can look from outside in and then now you have a reporting layer that can connect the dots and make it to like a Purdue style model of that attack vector chaining to say, Hey, well this thing is exposed out here. How far down can I go into the client's ecosystem? That is a special, special thing to do.
And by further enriching it with other third party, you know, whether it's Intel centric or alert centric or V centric, that's tying a lot of those important data points together to, to, to increase really the fidelity of risk. Because not all risk is the same, depending on, you know, what you're using. Right.
Well, I, I think that's another thing to keep in mind. And, and this, we got so hung up in the vulnerability world on CVE criticality levels, but they were rather arbitrary. What was a, a medium criticality to you might be a very Yeah.
Critical criticality to me. And clients still today use, some clients still use the CVSS score, right? It's a venerated score, but it's a severity score, meaning that if something were to happen, it might be this big.
As opposed to taking that intel centric data of the number of weaponized exploits, MITRE attack framework in gluing that all together to create data insights, intel, insights of risk score. Now, CISO comes and says, Johnny, tell me all the externally facing devices that are mission critical, that could be exploited through the eyes of a threat actor. That's a powerful thing to Do that, that Right.
That's much different than a CVS. Now, is there a patch or recipe ready to go and remediate? And If there's not, what can I do until there is Right.
Which is Also, so now you have the qu ability to, in, in, in cybersecurity world, it's really called, um, virtual patching. Mm-Hmm. Being able to lock down memory segments.
And I've heard that term a long Time in ports. Yeah. I'm old school og.
Right. Uhhuh being able to lock down memory in, in ports, you know, creating that invisible umbrella to, to, to protect the device. It's protect It.
Um, you know, but it, it, there's also another element to it, which I, I think makes it real too, is that everyone's risk profile is different. Everyone's risk tolerance is different. And so with, with this product, you have the ability to say, what's my, I I don't want to be put in a bucket.
I got, you know, brown hair, little hair, brown eyes is the bucket I'm in. No, I, I could really dial in my own unique profile that kind of suits me. And I think that's something that's been missing in our Yeah.
Exposures. And now with CS a m, you have the ability to create profiles. So for example, if you have like a, an external facing machine that's running Apache and some other stuff, you can create profiles of what is allowed.
So instead of going and remediating vulnerabilities, it's very similar to containers. Well, this machine drifted away from the profile and I should go and remove all this stuff instead of remediating. And I think that's a really important thing that probably is not being discussed a lot.
Yeah. That's very powerful. Why, uh, fix it when I can just remove it if it doesn't belong in that profile Anyway.
Agreed. We got almost outta time. I got one more question for you, but you, you're from IBM and you're here at the Qualis, you're obviously partners, IBM and Qualys.
Can you talk a little bit about the partnership? Yeah, we've, uh, had a partnership for a very long time. And, um, what's nice is at any point in time during business hours, I have a issue, uh, Karun or whomever he delegates to, will, will, will, will definitely help us out in a hurry.
But I, I actually built the vulnerability management practice at IBM and he and, you know, some other vendors were very instrumental on, on helping me. I didn't just think this up myself. I Well, No, it's, I have a lot of friends.
It's a big Job. Yeah. I have a lot of friends.
We get by with a little help from our friends. Right. That's right.
Surround yourself with Great friends. Johnny, it's a pleasure meeting you. I hope it won't be the last time we have you here on TechOne tv.
We're live in San Diego. I think we've got summed, uh, Kar, CEO of Qualis up next. So stay tuned.
We'll be back in just a few moments.