AI-Driven Policy Audits and Proactive Compliance at ROCon 25 with Anu Kapil
The launch of a new policy audit emphasizes enhanced audit readiness and the importance of proactive compliance assessments. Anu Kapil addresses challenges faced by customers using manual compliance processes and introduces AI integration to automate tasks. The vision for ETM audit focuses on improving both technical and procedural controls, while the future of compliance tools highlights AI’s role in automating evidence generation and reporting.
Transcript
Hey everyone. We're back here at Qualys Rock on continuing day two afternoon coverage. Our next guest is also with Qualys, a product manager.
Um, I'm sorry, one second. A new ca Kapil. Cappi.
Yes. I knew, I remember interviewing a new last year at the Qua Rock Island. It wasn't, it was Qua Security Conference Yes.
In San Diego last year. Yes. But it's been a full year.
It's been what you've been doing over the year. Well, we have been building the industry's First Rock for all our customer base. It's the first in, uh, risk operation center.
And since I work in policy audit, I've been working on how you can operationalize rock from day one, leveraging policy audit. We also did a launch of policy audit. It used to be called Policy Compliance before, and this year we rebranded and relaunched with a new lot more new capabilities that helps customers to be audit ready and that's why policy audit.
Got it. Um, let's talk a little bit about compliance and rock, right? 'cause at first, at first blush, they don't really necessarily go together, right?
I'm, I'm looking at my risk compliance is almost a separate reporting thing, right? The GRC and, and all of that. But they're connected.
They're, they are connected. Let's talk about that connection and how ROCK is helping people with their compliance. Yeah.
So compliance and executive reporting is the seventh pillar. That is the seventh Chevron off Rock and compliance is no longer just a check box. You know, you assist your compliance and prove it to auditors one time.
But now most of the evolving frameworks, they have a check that you need to be continuously assessing, and it should be risk-based assessment and compliance. When it comes to compliance, it should always be proactive rather than reactive, that you are acting when there is a risk combined. So how policy Auditor compliance helps is it helps you assist with the unified asset inventory pillar of Rock, where it, uh, proactively finds out all the technologies that have been running in your default, non default locations.
Helps you to prioritize and for response, provides the remediation capabilities to fi fix your failed controls. And with the executive compliance based reporting, you can provide those reports to auditors. And like I said, in my chalk, misconfigurations are like the leading cause of security breaches.
And at the same time, audit failures have a re root cause that is related to missing evidence. And both of them have the same root cause. That is a policy that is on paper, but not in practice.
And whether it's the risk of audit failure or risk of misconfiguration, both can be prevented if you implement your rock from day one with policy audit. That's how we, we connect policy, audit, or compliance piece to the Roth. Sure, Sure.
You know, when we look at compliance, there's talk and then there's compliance. Yes. It, it looks like what we're seeing is a lot of compliance coming out of states, you know, California, Illinois, what have you, and then of course the European Union has compliance.
Mm-hmm. And then there's sort of non-government compliance PCI four. Oh yes.
Right. A good example from the, uh, payment card industry. How does, for the people out here who do this for a living, right?
How do you stay on top? Well, I spoke to a lot of customers yesterday and I was really surprised that there are still a lot of them doing manual processes. They Do, I think most do, I mean that's commendable.
If they're putting so much hours efforts, there's always chance of failures. And now with more and more evolving requirements mandates, it's not like a one time audit a year. If you're a big enterprise, you have five to seven audits.
And if you're doing it manually, everything is critical. That means you are on a constant fire drill, continuous audit mode, and you don't even have visibility on what you're fixing. What is the end result?
You are just scanning for compliance producing these reports. So, uh, how policy audit helps is it gives you audit readiness score from day one. So you don't have to wait for your mandates to come or evolve.
0. We do the mapping for, uh, for our customers. We automatically map the new requirements to compliance objectives to the reporting.
So they can just rely on the tool to automatically update the reports. They can go into the system, generate audit readiness report and see where they stand today. They don't have to slog for months and months of spreadsheet and they don't even know the end result.
That is scary. And at the same time, they're not even managing the risk of misconfigurations that comes from compliance, which is as per the Verizon report, one of the leading cause of security breaches. And it can be prevented if you have your checks and policies in place.
Love it. Um, you haven't mentioned AI very much though, and AI has really been a big change this year. Yes.
How does that play into compliance Rock and everything else? So, qua ETM platform is moving toward agent ai. Yesterday we showcased that we are now launching our own agent marketplace.
There's a AI agent that is Agent Chang for audit readiness and reporting. That's, you can assign autonomous task, it, just ask it to create your risk prioritization plan or ask to onboard assets or detect technologies. It can do all those tasks autonomously for you.
So you don't have to do, you can just schedule those tasks. You can directly talk to the agent, you can even create your own agents. That's how we are leveraging it across the platform to uplift it for customers so they don't have to do these reporting and they, the team can spend time on other tasks.
Excellent. Anu, thank you for coming on and getting us up to speed. What else can you share with the audience that you'd think they'd be interested in?
Yeah. Uh, so I'm very excited to talk about ETM audit. That's our vision.
Okay. Um, Sumit showcased in his demo yesterday, a little bit of preview through agent and I showcased it in my demo today. ETM audit is on top of ETM, which we're going to build as the vision for ETM and how policy audit helps you with technical control, audit readiness to be audit ready, prevent the risk of your misconfiguration and audit failures.
We are uplifting it on ETM, where we already have customers, connectors, third party data coming in, quality data coming in, and we are going to provide audit readiness for customers for both of their technical as well as procedural controls automatically. So that's going to be a game changer because right now customers use hundreds of tools. 2 itself.
You might have a control that ask, do you have patch in place? Do you have vulnerability scan results? Do you have cloud scan results?
Now, whether you have third party tools or connectors, we will automatically map that using AI and generate the evidences and reporting for customers. Love it. Love.
That's really exciting. Thank you. You know what?
I hope to see you next year. We'll continue this conversation, but in the meantime, keep doing what you're doing. You're obviously doing a good job.
Thank you. Thank you. Nice seeing you.
Hey, we're here live at Houston's uh, Qualys. Roon. We're gonna be back.
We've got a few more interviews coming your way. You're watching Textron tv.