Techstrong TV October 16, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, Everyone. Well, we're back after lunch break here at Qualys Rock on day two, coverage wrapping up. We still got, I don't know, six more, I think really good interviews.
Well, five, not counting Sayeed here. Let me introduce you to Sayeed. Abbasi.
Sayeed, welcome to Text Drunk tv. Thank you So much. Thanks for having us.
Pleasure to have you on here. Saed. Let's start with a little bit about you, if you don't mind, share with our audience, kind of what, what your role here is at Qualys and what you do and what's your passion.
For Sure. For sure. Definitely.
My name is Saed Ab Boi. I, uh, work with, uh, research unit. Uh, I'm a senior manager for security research and I oversee our research and also, uh, work that we do for Zero Day Hunting as well as building detections, cutting edge research for finding uncovering vulnerabilities, as well as, uh, we will help with, uh, uh, gathering all the trade intel that it require for our customers to help them with their prioritization and things like that.
Uh, majority of our work is related to, uh, finding a new vulnerability, building detection for those, and as well as provided timely and accurate way for them to identify it and plan for it going forward. Excellent. You know, Sayed, we, you, you talk shop, we're here at this conference.
There's a lot of Quas customers and, you know, different Quas people, and, uh, sometimes you forget that not everyone watching at home knows what all of these terms mean. So let's, let's take true confirm, for instance, right? That's name we get, you know, that we gets batted around here.
Let's start with explain for our audience, what do we mean by true confirm. Perfect, true confirm. Uh, first of all, the TRU at the beginning of that, it means that it came from quality research unit initiated from our team, which we already have a 120 plus white hat expert that we are work, they're working with one mission to stay ahead of adversaries.
And, uh, this was a idea that we bring up and we had similar capability inside our, uh, vulnerability management platform. And the whole idea behind this true confirm was at some point when there is a vulnerability that is super important to our eyes, but how can we convey that message? How can we convey that message to our customers in order to prioritize that, right?
We need to provide them with the proof and the validation that yes, this is fire, right? This is the vulnerability that they have to prioritize. And with that mindset, we take a look at how we can do that because we want to give them the point of view.
We are not gonna ask them to go install this agent, go give us this, uh, option profile credential, get us approval for this or that. We wanna give them something that when there is the vulnerability that is super important, critical and weaponizing the world, we provide them with the capability that they can run a scan, find out that if that vulnerability is exploitable or not, then the video it works is the feature inside ETM and inside ETM, they can bring up all their vulnerability data. It could, it could bring from v from Defender, you name it, or even V MDR r We populate all of these vulnerability and we shortlist the one that we are able to apply true confirmed check on it.
And the moment that we shortlist that, they are able to run a scan and we mimic exactly the way that the attacker approach these vulnerabilities the same method, but we run a safe check. By safe check. It means that in the attacker's mission is to get the code executed there, download the malware, do something malicious.
We are using the same approach, but we swap the content with something that is more safe and it doesn't harm the machine. All we do is we confirm that the method, the approach is exactly the same as the approach that the anti care take, but we are not harming the machine. We are not harming the production environment.
All we do is we check to make sure that if that vulnerability exists in that environment or not. Uh, if you like, we can discuss a little about how we do that, that that's also, uh, is a area that it could be, uh, interesting for the audience, but we can take it later. Sure.
Um, you know, I, I'd like to jump into that, but I'd like to talk for you to talk about that in the context of kind of today's changing threat environment where these things are, first of all, exploits for vulnerabilities. Are they used to be a time you, you would find the, this is vulnerability to the exploit that's gotten like this AI just doing more, finding more vulnerabilities using AI to attack these vulnerabilities. How does that all feature in here?
Yeah, perfect. They are, uh, very aligned, right? What we are seeing that the pace of exploitation are so fast, like recent data from Manian that they came the time to exploit, it was negative one, right?
From five days of last year, that was across 112 vulnerability. And what does it mean negative one, right? It means that out of 112 vulnerability that they were interacting, it was so many cases that the attackers were first to weaponize those vulnerability and the patch came later and it was so many that eventually end up being the negative number and bring down from five days negative one.
And by that, we need a way to provide the team something that undeniable, a proof, the exact way to tell them that we run this scan how we done it, and this is the result. And we already know that you have to, uh, go and fix this on a priority. And the way that we do it with true confirm is we are running experiment and we don't need to have a CVE even assigned to these vulnerabilities similar to our cases of cases of zero day.
The way that we approach that is we are sending a prop to the, to the target or the scanner, assign a unique ID to that request, and then that request is exactly similar to a exploit, but we are asking to do a read only action or make a external connection like HCB post or a DNS check to a external service that belong to us, belong to true confirmed service, right? And then once the target make that connection, the scanner from ETM start looking and communicating with that, uh, true confirm of service, and they say, I launch a scan, I assign this ID the target, if it's vulnerable, should come back to you with this type of requests, with this specific id. Have you seen that?
And if that happened, what we're gonna have, we are gonna go back to the scanner. We're gonna say that, okay, we found the vulnerability, it is exploitable, go back to ETM, update the prioritization, bring up The top The, to the top from whatever it was, and provide the proof of the exploitation and the, the biceps. You know, the problem is, is if everything is a top priority, nothing's a top priority.
A hundred percent, you are a hundred, right? So when you move on up, sometimes that means you gotta move on down, right? You can't just have everything at red all the time.
It's always been a problem. Yes, this has Been a Problem. Yes.
That, that is, uh, another aspect of true confirm. Exactly. We run these tests on a only certain vulnerabilities, bio estimate, it might be around 3000 vulnerability that could have such a capability that they're super important and we are able to do this externally.
8 or something high, but you can bring it down, fix it later, because we confirm at least externally exactly the way that the does it. And it is not exploitable. You can do it later on, but eventually they have to update it.
They have to patch it, but well, you're gonna give them some time, Patch it, re remediated something we gotta do. Um, wanted to talk to you about how does this all play into the rock, The role, uh, it, it provide couple of key pillar to the each organization. One, it provide the context.
We add thread intelligence, we provide industry data, we provide the active remediation and things like that. And this is part of the thread intelligence part that we bring to the picture. We enrich every single cv, every single thread with all the details.
Let me give you example. 8 in the backup server. Normally in non rock environment, you will see something like that just a lot in rock because we brought, brought all these enrichment and enhancements from, uh, the context and also the intelligence.
We will provide you the full picture. We are gonna tell you that this is the whole disaster and recovery that you have in past. You take 11 days to fix it, which is not good enough.
And then we're gonna enrich it with the data similar to, uh, industry data. And we're gonna say that you are, for example, in a manufacturing and these couple of ransomware gang that they're abusing and building detect, uh, building exploit for that. They're targeting your industry.
And even we tie that to, uh, the dollar value, that how much pain you're going to get if that vulnerability eventually get, uh, exploited. And we talk, uh, tie it to the money, uh, and business side and all kind of enrichment like this, which are gonna be game changer because just having the fact that this vulnerability is something that we, we have seen in the past, and we're gonna give you the start that okay, there are 10 other exact same, uh, vulnerability in the same product in, then you have a full context. And then based on that, you can make a decision how you operate it.
Because you have the asset, you have the intelligent with the actual vulnerability, you have the context with the threat, uh, actors, how they do it. And then with this enrichment, you can, uh, make a better decision. Actually, all of this goes inside the true lens part of a rock.
And, uh, it provide the full visibility for our customers and they can leverage it for their prioritization because all it matters as sum made yesterday in the keynote mentioned, is to have the right threat intelligence to focus on the handful of vulnerability that is most impactful for your environment. And forget about the rest. You can do it later on.
But today, what you're gonna do, we are gonna provide you with the full picture on how to approach every single one of those. I love it. Saed, you know what I love most though?
I love people who are passionate about their job. And I'm glad to see your passion comes. Thank You so loud And clear.
Appreciate that. Keep doing it what you do, man. Of Course.
Thank you So much. Appreciate, appreciate it. We're live here at Rock On.
We're gonna be back with more of our, uh, wrap up afternoon coverage. We still have, I don't know, five, six people to come. So stay tuned.
You're watching Text Drunk tv. Thank you. Hey everyone.
We're back here at Qualys Rock on continuing day two afternoon coverage. Our next guest is also with Qualys, a product manager. Um, I'm sorry, one second.
A new Kapil Kapil. Yes. A new, I remember interviewing a new last year at, uh, qua Rock.
It wasn't, it was Qua Security conference Yes. In San Diego last year. Yeah.
But it's been a full year. It's been a Melissa, what you've been doing over the year. Well, we have been building the industry's First Rock for all our customer base.
It's the first in, uh, risk operation center. And since I work in policy audit, I have been working on how you can operationalize rock from day one, leveraging policy audit. We also did a launch of policy audit.
It used to be called Policy Compliance before. And this year we rebranded and relaunched with a new lot more new capabilities that helps customers to be audit ready and that's why policy audit. Got it.
Um, let's talk a little bit about compliance and rock, right? Because at first, at first blush, they don't really necessarily go together, right? I'm, I'm looking at my risk compliance is almost a separate reporting thing, right?
The GRC and, and all of that. But they're connected. They're, they are connected.
Let's talk about that connection and how ROCK is helping people with their compliance. Yeah, so compliance and executive reporting is the seventh pillar. That is the seventh Chevron of Rock and compliance is no longer just a check box.
You know, you assist your compliance and prove it to auditors one time. But now most of the evolving frameworks, they have a check that you need to be continuously assessing, and it should be risk-based assessment and compliance. When it comes to compliance, it should always be proactive rather than reactive, that you are acting when there is a risk combined.
So how policy Auditor compliance helps is it helps you assist with the unified asset inventory pillar of Rock, where it, uh, proactively finds out all the technologies that have been running in your default non default locations, helps you to prioritize and for response, provides the remediation capabilities to fix your failed controls. And with the executive compliance based reporting, you can provide those reports to auditors. And like I said in my chart, misconfigurations are like the leading cause of security breaches.
And at the same time, audit failures have a real root cause that is related to missing evidence. And both of them have the same root cause. That is a policy that is on paper, but not in practice.
And whether it's the risk of audit failure or risk of misconfiguration, both can be prevented if you implement your rock from day one with policy audit. That's how we we connect policy, audit, or compliance piece to the rock today. Sure, sure.
You know, when we look at compliance, there's talk and then there's compliance. Yes. It, it looks like what we're seeing is a lot of compliance coming out of states, you know, California, Illinois, what have you, and then of course the European Union has compliance.
Mm-hmm. And then there's sort of non-government compliance, the PCI four. Oh yes.
Right. A good example from the, uh, payment card industry. How does, for the people out here who do this for a living, right?
How do you stay on top? Well, I spoke to a lot of customers yesterday and I was really surprised that there are still a lot of them doing manual processes, spreadsheets. They do, I think most do, I mean, that's commendable.
If they're putting so much hours efforts, there's always chance of failures. And now with more and more evolving requirements mandates, it's not like a one time audit. Uh, year, if you're a big enterprise, you have five to seven audits, and if you're doing it manually, everything is critical.
That means you are on a constant fire drill, continuous audit mode, and you don't even have visibility on what you're fixing. What is the end result? You are just scanning for compliance producing these reports.
So, uh, how policy audit helps is it gives you a audit readiness score from day one. So you don't have to wait for your mandates to come or evolve. 0.
We do the mapping for, uh, for our customers. We automatically map the new requirements to compliance objectives to the reporting. So they can just rely on the tool to automatically update the reports.
They can go into the system generate audit readiness report and see where they stand today. They don't have to slog for months and months of spreadsheet, and they don't even know the end result. That is scary.
And at the same time, they're not even managing the risk of misconfigurations that comes from compliance, which is, as per the Verizon report, one of the leading cause of security breaches. And it can be prevented if you have your checks and policies in place. Love it.
Um, you haven't mentioned AI very much though, and AI has really been a big change this year. Yes. How does that play into Compliance Rock and everything else?
So, quality ETM platform is moving toward agent to AI yesterday. We showcase that we are now launching our own agent marketplace. There's a AI agent that is Agent Chang for audit readiness and reporting.
That's, you can assign autonomous task, it, just ask it to create your risk prioritization plan or ask to onboard assets or detect technologies. It can do all those tasks autonomously for you. So you don't have to do, you can just schedule those tasks.
You can directly talk to the agent, you can even create your own agents. That's how we are leveraging it across the platform to uplift it for customers so they don't have to do these reporting and they, the team can spend time on other tasks. Excellent.
Anu, thank you for coming on and getting us up to speed. What else can you share with the audience that you'd think they'd be interested in? Yeah.
Uh, so I'm very excited to talk about ETM audit. That's our vision. Okay.
Um, Sumit showcased in his demo yesterday, a little bit of preview through agent, and I showcased it in my demo today. ETM audit is on top of ETM, which we're going to build as the vision for ETM and how policy audit helps you with technical control, audit readiness to be audit ready, prevent the risk of your misconfiguration and audit failures. We are uplifting it on ETM, where we already have customers, connectors, third party data coming in, quality data coming in, and we are going to provide audit readiness for customers for both of their technical as well as procedural controls automatically.
2 itself. You might have a control that ask, do you have patch in place? Do you have vulnerability scan results?
Do you have cloud scan results? Now, whether you have third party tools or connectors, we will automatically map that using AI and generate the evidences and reporting for customers. It Love.
That's really exciting. Thank you. You know what?
I hope to see you next year and we'll continue this conversation, but in the meantime, keep doing what you're doing. You're obviously doing a good job. Thank you.
Thank you. Nice seeing you. Hey, we're here live at Houston's, uh, Qualys Rock Con.
We're gonna be back. We, we've got a few more interviews coming your way. You're watching Tex Drunk tv.
Hey everyone. We're back here at Rock on, uh, Qualys security event in, uh, Houston. And wrapping up our day two coverage with some really good conversations.
I want to introduce you to our next guest first. Uh, he's been on with us before. He's Hemanchu Kapal.
That's Correct. Hemanchu. First of all, welcome back.
It's good to see You. Thank you. Thank you for having Me.
Thank you. Why don't you, if you don't mind, tell the audience a little bit Uhhuh about your role at Qualys, maybe a little bit about your career path. Sure.
Absolutely. Hi everyone, my name is Hemanchu Kapal. I'm the Vice President for product management in Quales.
I completed my 10 years in Quales this August. Wow. This has been an excellent journey so far.
I started in support and then move on to product management and then grew up the ladder, and now I'm managing the whole product management from India. Very cool. And, and, you know, Quales was way out ahead moving a lot of their r and d and engineering to India.
Yeah. More than 10 years ago, I bet. 15 years ago or something.
Almost 15. Yeah. Um, so in, in, in terms of project management though, whether you're in India or the US or the Moon Uhhuh, project management is project management.
Right. Good. Let, let's talk about some of the projects Uhhuh you've been working on and Sure.
I I I know you also presented here in a panel today, right? Yeah. Talked a lot about identity, correct?
Correct. And of course, identity is one of the, the frontiers. Yeah.
One of the battlegrounds really for what we're seeing in security. Right. Talk to us about some of the challenges you're seeing there and Sure.
And what you guys are doing at Qualys to help with that. Uhhuh. Absolutely.
This is a very passionate topic for me. So when, what we see is, and even if we see it from the Verizon DBI report, 80% of the breaches require are due to credential abuse. More than 34% of the attacks which are happening are a combination of vulner, misconfigurations and identities.
Until now, most of the industries do are treating identity in a silo. Either they have a identity context or they have a asset context, but never together. And that is where Qualys is coming into picture.
I know that we might be a little late in the identity game, but we are doing it in a more holistic manner. So what we are doing is now you can ingest all of your identities across active directory. I maybe if you're using some other ISPM solutions that such as sustainable or Pink Castle, all of the data can come into Q for you to get one unified vision of your entire entity landscape on top of it.
We are, we are the only one who's gonna provide whether your identity is being getting sold in the dark web or not. You are externally exposed or not. If you are, that's a big red flag.
You should immediately change your password, immediately, change the credentials, et cetera. That is a unique value that we are adding on top of it. What we are doing is we'll be providing a true risk score for each of your identities as well.
Because similar to assets, and nowadays the number of identities which each company has is huge. It's massive. You need prioritization, otherwise your team is gonna get burnt out.
Yes. That is where we, we come in, we check which misconfigurations are applicable for your identities, whether multifactor authentication is enabled or not, whether the password is weak or not, whether the identity is exposed externally or not. Using a combination of all of these risk factors, we are gonna provide a quantitative score to each of your identities called as identity true risk.
This risk, this true risk score is gonna get bubbled up to your business tourist score and you'll get one holy grail for the prioritization. That's the unique value that we are adding. Excellent.
And, and last but not the least, our mission has been not only to provide the inventory of the risk, but to remediate as well. So even for identities, we are providing a close loop remediation. You can do patching, you can do password resets, you can enforce MFAs, you can run your custom scripts, you can do mitigation, isolation, all as part of the same solution.
That's impressive. Yeah. You know, it's interesting, a lot of people out here, they, they hear Qualys, they, they understand vulnerability management.
Yeah. Remediation. Yeah.
They understand now risk management Yeah. And all of that. They don't necessarily think identity management.
Correct. Correct. But I think I, that's part of having the, the platform.
Yes. Right. Is is doing that.
I wanna dive in a little deeper on zero trust. Sure. Right.
Zero trust is a, a concept that the security industry has embraced. Yeah. All over.
Absolutely. As it relates to identity though, uhhuh, what you guys are doing at cos talk about zero trust in there. Sure.
Absolutely. I, I think that's a very interesting question. So, in the past, if you see CISOs are only concerned about, uh, endpoints and network, over a period of time internet exploded, people started migration towards cloud.
And that is where ZTNA came into picture. So even when, even when ZTNA, when you're merging applications and networks together, every single entity still requires a separate authentication. This is where we see that the identity is indeed a new parameter.
Even within ZTNA, you need to manage separate identities. So ZTNA is very helpful from the application and the network perspective, but you still need identity management on top of it. Absolutely.
Yeah. A absolutely. But is there a, a zero trust or ZTNA Uhhuh Philosophy for identity management?
I think that is where the industry is going. There's no set philosophy for identities yet, uh, in terms of ZTNA, like we have for infrastructure and networks. But I think with more and more attackers leveraging identity or credential abuse rather than vulnerabilities, that that part is also gonna flourish.
We will be having some more concepts, some more philosophy around CTNA for sure. Let me throw something further out at you. Sure.
Everybody talks about agent ai Yeah. Deploying all these. Yeah.
You know, some people say we're deploying digital workers, digital Workers. KA Say that's the same thing. That's the Yeah.
What about their identities? That is a excellent cushion. So what we have done now is in the first phase of our launch, we are covering all the human and non-human identities.
But our team, our threat research team is currently analyzing how can we collect the identities of these agent care agents. This is the future. Everything is moving towards them.
And if their identities are not secure, if you do not have the inventory, the control on their identities, it's gonna lead to bigger issues. So this is definitely what we see as the future and will be added to our products in the near, uh, in the, in the short term. I love it.
Yeah. Pocho, we seem to have run through everything, all these notes that we had here. What else can you share with our audience?
What, what are you getting excited about? We are Getting excited about getting this consolidated picture for our CISOs and our customers. I mean, I have met like hundreds of CISOs in the last two years.
Every single CISO is saying that they want the toxic inside combination. They do not want the laundry list of one every day separately. Identity separately is configuration separately.
Everyone is looking to understand what carries the most risk for the environment. And this is where I believe quality is coming into the picture. So imagine you might have a system on which you're doing vulnerability management really well.
All those patches are applied. There is zero critical vulnerability from the myopic view of vulnerability management. The system is 10 on 10, but the system has a password as 1, 2, 3, 4, 5, 6, and is now used to connect your cloud database server.
Yeah. But holistic risk, this is, it Carries is huge. Yeah.
This is what CISOs wants and this is what Quas are providing. So we really, we are really excited about providing this holistic visibility across all the three major, uh, risk factors, whatever it is, identities and misconfigurations. I love it.
That is what, those are the big three Me excited. Exactly. Excellent.
Hey, I want to thank you for coming on. It's always so much. Always my friend.
You're great. Thank You so much. Keep Doing what you do.
Hopefully we'll see you soon. Yeah, Absolutely. Thank you.
Thank you. Hey, we're, hold on. We got, we gotta undo your microphone, but before we do, let me, we'll be right back with more here.
We're live on, uh, text drunk tv, A call. Hi everyone. We're back here at Qualys Rock on conference day two afternoon.
You know, this, this next gentleman. He's always one of my highlights when I do interviews here at the, uh, QUAIS events. Uh, I'm gonna let him introduce himself and he can tell you about what he does.
It's my friend Diwani Dilip. First of all, welcome back. It's good to see you again, my friend.
For those of you, for those of the people out here not familiar, tell them a little bit about your role at Qualys, your background. Sure. I'm wan I'm the CTO here at Qualys.
Uh, responsible for all our global engineering, cloud operations and customer support and success. Been here almost coming up to 10 years. Yes.
So I'm very familiar with everything that we've done. Took 10 years. Right.
I'm very proud of everything that we've done. You Should be, Uh, I think we are positioned really well, uh, the concept of risk management and having a single unified platform that can drive that is coming together really well. It's resonating really well.
Yeah. And then of course, agent AI and all the new Capabil. We're talk again.
We're ai Yes. But before we get into the agent ai, lemme just take a moment. You know, 10 years is a long time in any job in today's world.
Yes. In the world our parents grew up in. You might work in one job your whole life, but, and not today.
Most people jump around and it, and it's not just you. I I was just talking with, um, who's also coming up on 10 years now. Mm-hmm.
Uh, spoken to a lot of the, and, and I'm, I think I'm doing the, the thing, the Qualys, what used to be the security conference, probably four or five years now, I've seen the same faces over those years. I think that's a, it's something to be proud of. It talks to the culture here.
Mm-hmm. But I think it's also a reason for the success because you need, you need that sort of tribal knowledge, right? Yeah.
To, to share and to build on. I see it different than you, right. Because I sit here and I talk to a lot of companies, and it's so many of these companies, it's a game of revolving chairs revolve, you know, and the music stops who's there next.
And so they wind up losing a lot of tribal knowledge. They, a lot of debt gets built up. So congratulations to you and the Qualis team for that continuity.
You mentioned AG agentic ai. Mm-hmm. I'm pretty sure we didn't talk about AG agentic AI last year or the year before that for sure.
Yes. But that's all we seem to talk about here. Qualis made several announcements around it.
Let's start there. First, let our audience know. What were the announcements?
What, what's the news on Agen AI from, uh, Qualys? So, you know, last year we had, we kind of talked about how we were thinking about enterprise tourist management. And the, the idea behind it is just the way you have a soc, which everyone in cybersecurity is familiar with.
We have kind of define this category of a rock a risk operation center. A SOC is post-breach and a rock is pre-B breach. So the idea behind the rock is you take care of your health and hygiene, you take care of your vulnerabilities, your misconfigurations focus on what's important, reduce your risk.
And if you do that, then hopefully you won't have issues on the SOC side. Right. You won't have beaches.
So rock is the concept, rock is the category, right? Enterprise tourist management is our implementation of the rock. Where we are saying we will bring signals across from COS products, but not just co products.
We'll also bring signals from all third party products. So we are right now building a lot of connectors. We have a lot of them out there.
So if you are, as an example, doing vulnerability management with Quas, maybe you're doing misconfiguration uh, compliance configuration with qualis, but you're doing endpoint with someone else. Maybe you're doing C napp with someone else. That's okay.
We understand that no one customer is going to go with one vendor for all their security needs. Um, different vendors have different strengths. So what we are saying is we will take our findings and move, bring those into ETM enterprise risk management using connectors.
We will also bring findings from different security vendors that you are using into ETM. So vulnerability management might be us. Maybe CNA is ISAs, SAS is someone else.
Das could be someone else. Container security endpoint, whatever that is. Bring it together.
Then we do a lot of analysis on that. We apply our threat intel on all those findings. We apply business context on all those findings, and then we kind of reduce the overall volume that we got to something that's really manageable.
Sometimes less than 1%. Right. And we say if you focus on these vulnerabilities first, then you're reducing your risk significantly.
Not saying that you don't take care of the rest, but helping you prioritize, really helping you prioritize. Right? Sure.
Condensing it down. That's one part. Now the other part where AA is coming into play is we've been doing AI for a while.
You and I have talked about this. Sure. Right.
Um, I think when generative AI came out from a cybersecurity standpoint, it was not as reliable because you would ask a question, the response is predictive. You might get what you might get, you might not, might get it. Right.
Right. And my challenge was that if, if I'm, if I have a CISO saying what are the top five vulnerabilities I should focus on in my environment? And it gives a result.
And if he asks the same question again, as long as the underlying data has not changed, it should give the same result. But with generative ai, that was not really possible. It's just how the technology works.
Right Now with agent AI and MCP servers coming out, we can have our responses be more grounded. Mm-hmm. So just the way across all the 400 services that we have in our platform, everything exposed via APIs, now we are exposing all the core capabilities of the platform as MCP servers.
Now, when you ask a question to our cyber risk assistant, it interprets that question and then says, which MCP server do I go to? And that will determine which API to call and constrained by authentication and authorization of the individual making the call. Right.
So it's the same as making an API call at that point and It gets response. Well, there's a lot of similarities between the agen and the API. Yes.
The idea with the agent ai, of course, is that it could do this autonomously. Correct. Where, let's call the API call or the API integration more of a a dumb Yeah, yeah.
Kind of integration where you actually gotta kick it. Correct. Or the a And so let me, I got two things to go over this with you.
Number one is, do you envision a future where the Qualys agent sits on a different cmap on a different sim on a different product? And autonomously is gathering this information that it feeds back to true, true, uh, ETM? So when you say agent, you mean the cloud agent or the agentic AI agent?
I'm talking about an agentic AI agent. AI agent from other security Companies. No, that's, I mean, down the road.
Right. Um, I think, I think that's where we're headed. I think Initially what is happening is organizations are first building agent AI agents using their own internal MCP servers.
Right. Or agent to agent protocols. Right.
Now that will expand into exposing your MCP server. Yes. So others can call you.
And that's, and that's what's now Right. By the same token, it could be another company's agent that Yeah. You know?
Yeah. Because at the end of the day, I think We will call as an example. Yes.
Yeah. We're all gonna have as individuals, as companies like an army, a fleet of agents, they're not all going to be from Salesforce or ServiceNow or Qualys or, or what have you. Right.
How well those agents interact with each other. Yes. Who manages that.
Correct. What information, I mean, these are all the devils in the details that need to get worked out still, but, but that is the where the future is. Yes.
I wanted to go on another thing around agen ai, generative ai, I forgot who I was interviewing, but they mentioned that Qualys, they, it's using one of the frontier models, you know, underneath is, has developed an LLM Yes. Of its own. So no, we have not built our own LLM, um, Oh, well, they, We fine tuned.
Okay. An Existing LLM. Gotcha.
Um, I guess they didn't, they didn't explain it well. Okay. Explain it better for us, Dylan.
So, I mean, there are use cases where, you know, we've taken open source large language models and we've said for our security use cases, how do we tune it to our use cases? And we've done that. Um, we do have, um, generative AI and agent AI now completely embedded across the fabric of the platform.
So, so we are using a mix of in-house. Uh, we are also using other, uh, frontier models, large language models that are available on public clouds. Mostly because this space is innovating so fast that if something new comes out, if it's in a public cloud, I can immediately tap into it within hours.
Right. If I have it in house, it's taking me more time. And, and we do want to be ahead here.
Uh, you know, we feel we are onto something. Uh, there are very few organizations that have come up with this concept of integrating agent AI into the platform and then building cyber risk. Digital employees cyber risk assistance.
Right. Cyber risk agents. Right.
And the way we are doing this is we are saying, we know security teams are resource constrained, but now here are all these cyber risk agents, which are all, we Are all are these resources. Autonomous agenda. Right.
And you can delegate work to them. They will go off and do it of course. With the right kinds of guardrails.
Right. Right. Um, which is important right now.
So Let me ask you the 64 billion or $640 billion question, when does this vision become real, like, available to people out there now? So the out of the box agents, they are ready right now. In fact, um, during this conference at our demo booth, folks who are trying out the product and looking at these agents, they're actually using the real product.
The way we will, we are looking at this, is we are building a whole bunch of out of the box cyber risk agents that will automate specific workflows, independently do things, whatnot. Those will start getting rolled out over the next month, two months, and then keep coming out. The next thing we will do is we will give you the ability to build your own cyber risk agent.
Right. Where you can, using it, using a cyber risk assistant or a chat mechanism. You interact with the platform, you identify a body of work, and then you say, now I want to take this and I want to automate what this does, or take actions based on this and I want to do it at a regular cadence.
And then you can have your own out of the box agent. Think of it as an employee. You hired A digital worker and You're asking him, And you've trained it, Just go ahead and do it.
Absolutely. Yeah. So yeah.
This is not six months out. It's here Now. There's a percentage of people who are watching in this at home Yeah.
Or at work. And they say, great, it's gonna take my job. What do you think about that?
I don't think so. Um, and it, it's not just cybersecurity. No, No.
This is not a cybersecurity. It's This is everywhere. Right.
Everything. I don't know if you saw the, uh, there's a YouTube video came out from that company figure AI that makes the robots. Did you see the newest one?
Version three? It folds closed. Yeah.
It delivers packages. It works at the hotel reception desk. Yeah.
It's everything. Yeah. It's everything.
So this, this obviously is innovation that will change the world. Yeah. Uh, I believe in that.
Yeah, Me Too. I think we should all believe in that, uh, instead of resisting it. Yep.
I think the way to think about it is how will it complement what we do? Uh, internally, as an example, we are using coding copilots, right? We are seeing productivity gains.
I mean, clearly we can see that, uh, anywhere from 20% to 50%. But what I'm also finding is, as an example, the best productivity gains are coming from my best engineers, my top most engineers. So this is not about, I don't want to invest in people because you need very talented people to actually also work with these kinds of tools.
Right. So in some contexts it'll augment, it'll compliment, you know, it will make you that 10 x person. There will be instances where it will automate entire roles.
Yeah, for sure. Um, but it will open up other opportunities, Lots of them. And history is full of that.
Right. And that's exactly the lesson comes out lesson of history. Right.
It always creates more jobs than it takes opportunities. Yes. And what I tell That you can't think about today, I tell people a similar thing to what you just said, which is if you embrace this, embrace it, internalize it, understand it, it will make you more valuable.
For sure. If you resist it, ignore it. Yes.
Yes. And what will be will be then. Yeah.
That's Not a good place to be. No. So yes.
Hopefully I'll, well, maybe certainly next year I'll see you at this, hopefully. But I hope maybe before then it will continue this conversation because this is changing so rapidly in three months. Let's see where we are.
Yes. Philip, always a pleasure. Thank you for another great qua.
Thank you for having me conference here. Thank you. Thank you.
We're gonna take a break. I think we've got one or two more interviews coming your way, uh, this afternoon. We're wa we're live in Houston at Qualys Rock on.
You're watching Text Drunk tv. Hey everyone. We're back here at Qualys Rock on, uh, we've got a few more interviews as we wrap up our day two shooting here of, uh, our coverage of this event.
I want to introduce you to Joe Moore. Joe, welcome to Tech Drunk tv. How are you man?
Thank you very Much. Doing pretty well. Good.
Joe, if you wouldn't mind, look into this camera right here. Let people know kind of who you are, what you do, what brought you here today. Hi, I'm Joe Moore.
I'm the Cybersecurity architect for Siemens Digital Industry Software. I've been a Qualys customer for a dozen or so years and wanted to catch up on some new, new topics. Also gave a little talk here today.
Excellent. It's a great year to catch up on new topics 'cause there's plenty of 'em. Sure has.
Yeah. Yeah. You know, I've been covering the Qualys, what used to be the Qualis Security Conference, Q-S-C-Q-S-C.
I've been doing that for five years as as here at Techstrong. You know, I'm friends with Philippe for many years before that. Um, but this is really, uh, well, a it's a new name with a new focus, but there's so much going on in our world right now, Joe, that it's absolutely, it's a crazy time.
Um, if you don't mind, you know, Siemens is a big company. I've interviewed a ton of people from Siemens, everything from the folks who do the digital twinning Yep. For boats, for ships and stuff like this.
Yep. Uh, of course the high end electronics, everything else. What, what exactly are you doing, you know, part of Siemens?
Us? So I'm In the digital industry software part. We make the software, uh, the cad cam software.
We make the product lifecycle management. We do supply chain management software. Uh, we do a lot of work in the digital twin space.
Oh, you do? Yep. Okay.
Uh, so simulation and testing, electronic design. Uh, if it's, if it's something that you can download, there's a good chance that our, our company or our division is involved in, in producing it. Yeah.
I've done several on the digital twining stuff. It's really cool stuff. It's a neat area, uh, especially seeing how that can apply outside of just the traditional manufacturing space.
Uh, we actually apply it internally. I Was say there's a place for it in security. Absolutely.
Yeah. In development. I, we talked about that before, that, uh, being able to model our software production process as, and create a digital twin of the building process for our software.
Uh, that can have implications, that can have benefits. Uh, you know, we, we use machines to convert raw materials or source code into our product. Absolutely.
com, security Boulevard, container Journal, a bunch of, uh, cloud Native now, a bunch of others. Um, just from the idea of being able to test software before it goes live and but in a real, well, it's not real. It's a digital, uh, a digital twin of the real environment.
Right. And that makes a huge difference. Now you spoke here, is this the first time you've spoken at the, uh, Quas conferences?
Yes. It's, tell Us what you, what you spoke on. Well, I talked about, uh, Siemens journey with Wallace, total AppSec and True Risk.
So we've, we've been, How long have you been using True Risk now? Two years or A couple of years. Yeah.
We were What's been, what's been your experience? Well, one of the biggest challenges we have is in, is integrating the big Siemens approach towards everything. Uh, with being a, an agile and, and very dynamic software company, uh, the big company tends to move a little bit more slowly.
Uh, so sometimes we have to drag, drag things along to, to, in order to get our pro product out the door. Um, they are coming along. It's, it's, they're getting a lot better.
Uh, Siemens is really focusing a lot on becoming a digital transformation, a digital engineering company. Yeah. So, Cool.
Um, what was the feedback from the audience here? Well, it was, it was the first session after lunch, so everyone was a Little sleepy. A little Bit sleepy carved out.
Yep. But, uh, overall it seemed very positive. Yeah.
What, what's been your biggest takeaways? Biggest takeaways? Uh, honestly it's putting in place a framework that we can use to, to help our developers secure their own product.
Mm-hmm. Uh, it's really been, it's really been key to, to give more information to our developers so that they can make better decisions before they actually finish building the code and release it for production use. Got it.
Um, you know, you know, the big, of course the big story everywhere this year is ai, LLM use Frontier Models, whatever you wanna call it. Agentic ai. Qualys made some agentic AI announcements here.
How's that affecting your world? Well, in the security world, we're still developing our maturity for ai. Uh, my team has, has a couple of people who are, who are focusing on the security threats within ai.
Um, it is also part of our, obviously our strategy going forward, uh, within the company. We are building out capabilities for AG Agent AI within our engineering software, especially within simulations space. Um, it's been a, it's been an advanced journey and, and I'm happy that I'm not the only one who understands it now.
Well, you really think everyone's getting it, or? I, There's, there's enough people that are getting it. I, I came up through a pure math background, so Oh, okay.
So you really understand. Wrote that. So I understood a while ago, and now I'm seeing actual, you know, sort of regular people come out and being able to understand it too.
It Is, it's gone mainstream, that's for sure. It gone mainstream. Yeah.
It's gone mainstream. Um, if I had to ask you to look in your crystal ball and say, Hey, Joe, when you come to the Qualis event next year, what in effect do you think this AI and agentic AI is gonna have on your day-to-day by next year? I think the way that Qualys is approaching AI to have multiple different agents or different personas that are operating in, in parallel, uh, having one chat bot do everything seems a little bit difficult.
Yeah. So I like the idea of having multiple agents that I can contact. Well, I think that's the way it's going.
Yeah. Right. Yeah.
The chat bot wasn't the ultimate interface. Right. It's having multiple chat bots who are having agent agent AI on the back end.
Right. You know, I don't wanna, I don't wanna talk to the same bot to make a travel reservation as I do for my security. Well, you know, I've, I've spoken to a lot of AI people about that.
What about the idea of a master agent? Mm-hmm. And all these other agents are like alter egos of it, or, or, you know, it, it it's the orchestrator an or that's a good word to use for it.
An orchestrator agent that, that orchestrates all these different ones. And you know, obviously you're not gonna talk to the travel agent one to do your vulnerability remediation, I would hope. Right.
But who knows? Uh, but certainly we're going to need some sort of agent management. Yeah.
The sort of concierge or Yeah. Orchestrator between, con is a good word, agent concierge. But you also see, you see the big companies, Salesforce, ServiceNow, Microsoft, IBM, they're all vying for who's gonna be your agent manager.
Right. Sure. You may not use my agents, but I could manage your agents.
Yep. And I, I think that'll, I, I was having that conversation with Dill Bawan here from Qua over. Does he think they will manage third party agents or third party manage Quas agents?
Or maybe both. Yeah. I would hope that it goes both ways that you can, you can have a standard approach Yeah.
And be able to use the best agent for, you know, the best agent is probably not going to be the same one that does the best job of creating a PowerPoint presentation. No, No. But I think that's why protocols and stuff like MCP servers, a to a, these kinds of things are important.
Right. Absolutely. To, to allow that, that communication.
Um, Joe, I think we, we kind of hit on what we had here for you, but what do you think about the concept of focusing on managing risk versus vulnerability, whack-a-mole, if you will? I think it's, it's really transformative. I mean, just like, just like the idea of, of managing risk as a factor of cybersecurity in general.
Uh, taking, taking away from cybersecurity as a purely hygienic, you know, do, do you patch, do you have all of your antivirus up to date? And turning it into a real measurement against the business risk, I think has been a, a real foundational transformation for the, for the industry. Uh, I think transforming vulnerability management in the same way makes a lot of sense.
Uh, being able to take, take your vulnerabilities and, and really identify, well, what is, what is this actually putting at risk to the business? Because, you know, if, if all that's at risk is having to put out a, a press, a different press release, that may not be a big deal. If it shuts down, if your vulnerability is one that can shut down your business for an extended period of time, that could be fatal.
Good. I, I agree with you. I, I think that's a way great way of putting it.
I'm gonna ask you one last question. If you could look into this camera. Your peers, vulnerability management professionals, security professionals, you know, this is, this conference is a bit of a oddity.
They don't charge right. For a ticket. I mean, you gotta pay your FFA or travel, you know, what have you.
But they have training they give out for free too. Would you recommend, is this like definitely put it on your, on your, uh, list or What do you say? Absolutely.
It's got a, it's got a, it's got some great technical tracks, some great business tracks, uh, that just the information you get from this conference has been, has been remarkable. Very cool. Joe, thanks for coming here on Textron TV with us.
Good luck. Luck with you at Siemens. Joe Moore.
Hey, we've got, I think one more interview before we wrap up here at, at, uh, Qualys, uh, rock on this year. Stay tuned for that. You're watching Textron tv.
Hey everyone, it's Alan Shimmel. Welcome back. You know, it's been an amazing couple days here at Qualys is Rock Con or Rock Con Risk Operations Conference.
And, you know, but all good things come to an end. This is gonna be our last interview here this year, but we saved the best for last in some way. Let me introduce you to April Lenhardt.
If you are a, uh, a text junk TV aficionado. You might have seen April talk at our, uh, RSA coverage. Last, I guess it was last May, was RSA or April, something like that.
Yes sir. Maybe it was April and April. But, um, April, first of all, welcome back to text on tv.
Thank you. It's great to have you, uh, for the, you know, not I was kidding about the aficionados. Most people have no idea you were on in April, or not of course.
But tell them a little bit about your background and and what you do here at Qualys. Yes. So I've been cyber threat intelligence for about a decade.
I started as an intelligence analyst actually. Mm-hmm. And my goal at Qualys is to bring cyber threat intelligence to the fore.
And really what that means is we have a threat research unit of over 120 analysts. And my goal is to make sure that that work is really shown really clearly to all of our customers. Absolutely.
And, and you know, I, I'm not going to embarrass you or anything, but the, the Callis research team has actually won a couple of awards lately. PO Pony. PO Pony Pony Awards.
Pony Awards, yes. Uh, as well as other awards and stuff. I mean, they're really doing some phenomenal work and Yeah.
You know, awards are nice, but the work they do is actually really good, important kind of stuff. So it, so it is important, you know, April, I, I was, uh, started a security company in 2001 venture backed security company. And we were in vulnerability management network access control.
And I remember going to, at the time, I think it was still called Citibank, it wasn't Citi yet, it was Citibank. But talking to one of their global CIOs, they had three global CIOs and he told me that it took them 90 to 120 days from the day of a patch Tuesday release to actually apply to remediate. Yeah.
And I remember thinking to myself, that's crazy. 90. 'cause even back then, 90 to 120 days was forever.
Right. But he said, you know, they would rather make sure they don't break anything else than rush to fix even the most serious vulnerability. It's when I knew security had issues, we had issues.
Now that GAP is, you know, commonly referred to today is the, uh, meantime to remediation. Right. Right.
And, and a and a lot of our security metrics and, and how we measure performance of security teams are built around at MTTR talk. Talk to me a little bit about MTTR, how your work at Qualys helps that and what Qualys is doing to kind of close that gap. It's not, let me just say for, I don't think anyone waits 90 to 120 days anymore, but what do we do?
You know, what is the average gap and what are we doing to close it? To your point about Qualys threat research unit being exceptional, one of the statistics that I'm really proud of and that I was happy that I just got to talk about during my talk is that 20% of all Qualys customers are able to actually remediate CCC Kev vulnerabilities before they hit CCC kev. That's great.
And so one of the big things with that is that the remediation time is low because of how quickly we are able to kind of enumerate these vulnerabilities. One of the big ways that True lens, which is the product that I'm working on, is able to help that remediation, is by really helping you triage what is the most important things to remediate. So we're all surrounded by a plethora of different alerts, different metrics, some that are not super actionable, right?
And so my goal is to really help kind of, kind of funnel the different things that you could potentially action to say, Hey, what of these are relevant to your industry, to your business? And then from that, say, Hey, these are the specific things that you need to work on. And from there, your remediation time can go away down if you are really focusing on the things that really specifically matter to you.
One of the other things that we're doing is we're able to give a view into the industry that you're in and say, what is the average remediation time? So instead of just looking across all of any industry, uh, any vertical, and you know, how well is, is an oil and gas company doing compared to a mom and pop shop compared to a finance institution, we can specifically say, if you are a large size oil and gas company, how well are you remediating compared to your peers? Because you might think that you're doing great because you remediated this one vulnerability in 15 days.
And come to find out your peers all remediated it in three days, right? So then you might need to know, okay, hey, I gotta change how we're doing this. But if you don't have those statistics, you can't really change because you're, you're not really sure what you're, you're going against.
Right? Absolutely. And so this is a big way to, to be able to, to change how you remediate.
Absolutely. I got a hard question for you. So how do we, how do you take MTTR?
How do you take those sets of statistics and feed it into the rock to deliver to a executive and say, look, because we've lowered our me our mean time to remediation by 20%, we've lowered our risk by, uh, x percent. How, where does, you know, is that even possible? And how does that get done within the Qualys kind of product suite?
That's a great question. So we, we incorporate meantime to remediation in two ways. The first is kind of, uh, for every individual vulnerability, we want to provide a meantime to remediation.
So we're able to get on a very granular level, what is your MTTR and what is everyone else's MTTR? Yep. We are also able to say kind of at the, at the bird's eye view, at the very strategic level, how are you doing with your remediation versus how are others doing?
So you're able to say, you know, taking aside one or two vulnerabilities, um, actually looking at everything, what does that look like? And those are statistics that you can share with the board, with different stakeholders, with investors, and those are things that you can, you can really incorporate into that workflow. I love it.
I want to turn from MTTR to MTTD mean time to detection. Mm-hmm. Let's, first, you know, I love throwing acronyms at, at the audience, but let's, I said it's mean time to detection, but what does that actually mean When you're thinking about meantime to detection?
Think of from when a vulnerability is, is first introduced to our system. So when are we, when is the vulnerability first, first acknowledged as a vulnerability to, when on your systems do you say, Hey, this asset is associated, um, with, with a problem? When do you know that there is a vulnerability?
When is there risk introduced? Um, this is a really critical metric because you need to know, Hey, um, has this been sitting on my system for years? Or was this only a problem, you know, a couple hours ago?
Very important to know. Absolutely important to know. Now, how, how do we, how do we measure that to quality?
Because a certain, you know, to a certain extent, well, it depends on what kind of threat intel you're getting, how vigilant you are, how well, you know, the whole, I mean, everything. And some of it is pure dumb luck, I think, too. How do you, how do you quantify for the luck and quantify for all these things and say, okay, because you're using Qualys, your MTTD is lowered somehow?
There are definitely certain aspects where if you're looking at espionage actors, if you're looking at these really long dwell time actors, you are going to then have them, of course, associated with TTPs where they will use vulnerabilities that will be in the system for a long time. Right? But if you're looking on average, if you're looking at, uh, zero day vulnerabilities, if you're looking at kind of what we see typically in, in the daily news, the most critical thing is being able to run scans and detect these things as quickly as possible.
And with Qualys, we have such a robust system, we are able to really give you kind of as small of a delta as possible, um, from from when you are first, from when we first know about it to when it's detected. And that's, that's really kind of the critical timing that we're looking at. When we say timing is everything, or we're looking at those metrics, that's what we're looking at.
I agree with you. I agree with you. One last topic I want to throw, and that's ai.
It's changed everything this year. How's it changing what you're doing? It's changing what we're doing in a big way.
So we are leveraging ag agentic ai, where you can ask questions like, Hey, I see all these different risks and vulnerabilities. Help me triage what to do next. Um, what, you know, Qualys, what do you see in the system in terms of the assets that I need to look at first?
And then when you have the system, how do you incorporate it with all the other products? So now, instead of kind of having to do all of these disparate pieces alone, we are able to say, Hey, let's, let's automatically using Agen ai, be able to connect with all the other products you're using in the ecosystem. And then say, okay, what do we now do to, to be able to triage this?
How do we evaluate risk? What does that look like? Again, across different industries and also within my own system, what do I need to focus on first?
So ent, AI is really being leveraged strongly by Qualys as a way for us to continue improving our systems and as a way for organizations to help mature their own cybersecurity posture. Got it. I got it.
If I had to ask you sitting here next year, how much more ai, agentic AI is going to be, you know, not, not, it's gonna be a bigger piece of this as I guess the conclude the, the feeling, but is it going to 10 x your, your team and, and your stuff, or you know what I mean? How, how, how? Yes, it's big, but we're still scratching the surface, is what I'm saying.
We're still scratching the surface. Our, at least on the product side, what our plans are really are to try to run as quickly as possible, but as safely as possible. Absolutely.
We are a security company, right? Absolutely. Um, but to try to incorporate as many different uses and as many different ways, um, that we can help companies, uh, be able to leverage threat intelligence and be able to mature their own organizations, um, and again, to, to do it in a way that is possible, probable safe.
I love it. April, I know you literally came off the stage, came here. I want to thank you.
Thank you for all the work you do. It's been a great Qualys rock on, and you've been a great guest to end it. Thank you so much for having me.
Maybe we'll see you at RSAA couple months March this year, For sure. All righty. Hey, that's gonna wrap up our Qualys Rock on coverage here in Houston.
We hope you've enjoyed it. If you missed any of the live feed, we'll, we'll have the on demand by next, I don't know, early next week. But until then, this is Alan Shimel.
On behalf of Qualys and Techron Techstrong tv, we're out. Bye-bye. Good.