Exploring Cyber Threat Intelligence with April Lenhard | RSAC Conference 2025
April Lenhard from Qualys discusses her role as a principal product manager in cyber threat intelligence. With a background as an Intel analyst and a teaching position at George Washington University, she highlights Qualys’s expansion into threat intelligence. The risk operations center combines threat intelligence with asset management to assess risks. AI enhances governance, risk, and compliance, serving as a tool to augment human capabilities.
Transcript
Hey everyone. We're live back here, live at RSA conference today, closing out our Wednesday coverage, uh, day three of RSA. Um, our next guest is from Qualys, a company you all are familiar with.
I assume all of you are familiar. We covered them enough here. Um, her name is April Lenhart.
And April, first of all, welcome to Tech Drunk tv. I know it's your first time here with us. It's great to have you on.
Great to be here. You Certainly look very different than most other Qualys executives we've, we've interviewed over the years, so it's fantastic to see you. Um, April, why don't we start with what your present position is at Qualys, and if you wouldn't mind, tell us a kinda little bit of your career path, you know, what your story is.
Yeah, absolutely. So I'm a principal product manager at Qualys, and my, the main thing I focus on is cyber threat intelligence. So at Qualys I'm going to be working on really bringing cyber threat intelligence to the fore, working across all of our different products, seeing where we already have cyber threat intelligence and really bringing that out into a new product.
In my past, I've worked as an Intel analyst and from there moved into cybersecurity, working as a product manager at all different companies each time, really working on kind of nation state level actors and looking at how to bring out cyber threat intelligence across the industry. When you were an Intel analyst, I assume was for the government, some sort of agency or something, or Private company As a contractor, really. Yeah.
And doing kind of the same thing, uh, geopolitical threat analysis. Um, I was the person who would walk into a metro and say, what is a physical threat vulnerability analysis look like? So when I then transitioned over to cybersecurity, it was like, oh, hey, this is what red teaming is, right?
Yeah. So I knew it from the physical side and then got to do it on the cyber side. Excellent.
What a great story. And then you're also an adjunct professor at George Washington. Is it Georgetown or George Georgetown.
George Washington. George Georgetown. Yeah, Georgetown.
George Washington has a great pre-law program. George Washington University, but so does Georgetown too, actually. Uh, but that's fantastic.
And what do you teach there? It's at the, uh, security studies program, and it's called Cyber Threat Intelligence and National Security. The goal is for students who don't have a really technical software engineering background or computer security background who want to know more about, again, those nation state level actors, those apps, they get to dive into the world of cyber threat intelligence.
I love that. April, I, if you don't mind, I want to, as I said, most of our audience knows Qualys, worldwide leaders started really out in vulnerability management and vulnerability detection and now vulnerability remediation, uh, threat intelligence. Uh, there's, there's many facets to the Quali Qualys product line at this point, but let's, let's talk a little bit about cyber threat intelligence.
Now, Qualys, I think they had a research team, a cyber research team for a bunch of years. Yes. But in the last two, three years, they really tried to turn up the threat intelligence knob because they want to integrate it into the, the dashboard view right?
Of, of Quala QBR and everything. Um, as part of your mission, what are you gonna do to the existing offering that raises that bar? So I love that you brought up the analyst team.
The threat research unit at Qualys is over a hundred analysts. It's a very, very big team, and my goal is to really accentuate the work that they're already doing and really just bring it to the forefront so people can really get a better sense of what our analysts are doing on a day-to-day basis and really contextualize that information. So we're going to be able to see really quickly with any vulnerability or with any misconfiguration, um, what are the industries involved?
What are the threat actors involved? What are the locations, uh, both from the victimology side and from the attacker side, really bringing all of that information so it's really quickly and easily, uh, easily accessible. Absolutely.
And I think that is the mission for Qualys, right? It's 'cause I, I remember speaking to them, whether it's Qualys own cyber risk, uh, threat intelligence feed, or even harnessing and plugging in the third party feeds. It's, um, it's a valuable addition to the kinda risk dashboard, if you will, that they're, they're, um, developing.
The other thing I wanted to mention is, you know, we were at the qualis QSC, I wanna say it was in Austin this summer, maybe it was right before summer. And um, they, you know, they introduced this whole rock Yes. Like concept of a rock.
Yeah. Not a sock. A rock.
Yeah. And again, that's another area where the thread intel right, gets, that's how you know it, it makes its way to, to operators, right? Yeah.
Who can use and act on that. Absolutely. So the risk operations center of rock is the idea that big enterprise threat management, you take all of your intelligence, you take all of your unified asset management, and now on top of that, you're also going to bring in essentially the probability of how does it affect me?
How does it affect my business? How does it affect not just kind of overall the industry, but how does it take my business into account? So you're looking at across all of the different assets that you have as a company, and you're then saying, how does that specific, how does those specific assets that I have, how do those relate to the major CVEs that we're seeing?
Um, so you can really stack rank and identify what's important to me, what do I need to patch if I don't, what are the major consequences? And you can even associate it by, you know, specific industries or sorry, uh, specific, um, parts of your business. And then within those parts of the business say, okay, if I don't take this specific CVE into consideration, how much is that going to potentially cost me?
So it's really think of a risk operations center as not just saying, this is asset management, but also here is how I contextualize it for my own business, which is really taking it a step forward. Got it. Um, now I, I realize you, you've only been on a few months and there's a lot of, a lot of plans, a lot of offerings that are still coming together, right, for sure.
That aren't public yet. Um, but what do you think to date has been your biggest kind of impact on the, you know, cyber risk intelligence or threat management for, for the Qualys product? I like to think that right now it's bringing in that contextualization piece.
Yeah. So again, just coming in as a, a subject matter expert, being able to lend the lens of this is what, as an analyst, this is what I would want to see. So very similar to how a rock, uh, brings in that extra layer of contextualization, I also want to come in and to say, this is how it would be relevant to the greater industry.
Got it. If you don't mind, I want to turn to RSA this week. Uh, you know, as usual, RSA is chock full of security people, right?
And a lot of security, 600 plus sessions, all kinds of things going on. You were on a panel I hear Monday. Yes.
Tell us about that if you can. Well, honestly, the best part was that since we were the very first session of the very first day, we had first mover advantage. So anything we talked about was just going to be repeated by everyone else for the rest of the week.
That's how these things go. And that was ideal. So our panel was on AI and GRC governing risk compliance, and it talked about everything from kind of our outlook on AI as a whole to getting a little bit more into GRC where the industry is now, and where we see it going in the future.
Um, so tell us about it. I mean, 'cause I mean, look, certainly AI is the talk of this conference as it is the talk of everything in tech today, you know, but one of the things we've been talking about here for the last two, three days is no doubt it has the potential to be huge, but how real is it, how much of an impact is it making today in, in the field of, of, of governance risk and compliance GRC? How big is AI today?
Not what it could be, but today For sure, there are a lot of ways that it's already made a major impact in terms of being able to scale up way past what otherwise a human would be able to do, right? So there's a lot that AI has already been able to contribute to as far as adding in metrics, again, adding in contextualization. However, there are definite, uh, limits to what humans are comfortable with and what companies are comfortable with deploying.
For example, we still haven't gotten to the point where you can have age agentic ai. That is where we're completely comfortable saying, you know, set all of these rules and, um, completely act on your own free will to determine if you see any new threats, block everything essentially. Like think of like a, a completely automated SOAR where there is no human involved in the process.
We have not yet gotten to the stage where we're comfortable with a human completely being removed. We still want there to be that emergency stop button. So it's fair to say that AI has really significantly contributed to having us grow in this industry, but we aren't completely there.
We haven't reached that pinnacle of saying, yeah, we can just set it and forget it now. Right. Um, well, And, and I don't know if that's a worthy goal, to tell you the truth, maybe may just maybe the, the future of ai, at least near term, short term, is just to enhance the human, not to replace the human right.
And I, I, you know, I think that's a good lesson for all of us to look at. You know, a lot of CEOs and, you know, executives get up there and say, we could cut head count. I could get rid of all my intern junior coders, I could get less security professionals.
No, that's not really what it's about. I think not today anyway. I, I think today it's more about how can I make more my people more effective?
Sure. How can I enhance our security posture that, and it's, and it's AI in conjunction with a human helping a human. I heard someone say it at an event we put on Monday, and it really struck me at this point in the day, game AI is a co-pilot, not a pilot.
Yes. I think that's a very apt way to put it. Yep.
Uh, AI is a really great tool for augmenting what you already have as a way for thinking of unique solutions to a problem if you are able to then correct it. Yeah. It's not a great way of teaching new solutions to a problem when you don't already see pathways to get there.
So in the same way, um, within GRC, it is a very good way of saying, you know, I already know how to get to the end. Show me different ways to get to that same end. It's not a good way of saying, show me, show me brand new things where I don't already know what to do.
So, Got it. Very similar. April, I want to wish you success in this new role, fairly new role at qualis.
We'll be watching to see what comes out on threat intelligence. I actually, I'll say it here, we're actually gonna be at the next, uh, QSE Qualis Security Conference, which I think is in Houston. And we'll be, you know, shooting live there.
And we'll catch up there. Thank you so much for having me on today. I really appreciate it.
Nice Meeting you. Okay. Great to meet you.
April, Len Hand, uh, Qualys, I, I forgot your title. I apologize. Principal Product manager.
Principal product manager, Qualys here on Tech Drunk tv. We're gonna take a break. We'll be back.
We've got a few more interviews to do today before we wrap up. Day three, you're watching Textron tv.