Exploring Cybersecurity Solutions with Himanshu Kathpal at QSC24
Himanshu Kathpal shares his nine-year journey with Qualys, detailing the company’s platform and sensor products. He outlines the five pillars of the platform: asset management, vulnerability detection, patch management, threat detection, and compliance. The integration of sensors provides vital data insights for cybersecurity.
Transcript
This is Textron tv. Hey everyone. We're back here live in San Diego for our QSC coverage.
Continuing here on day two. Oh, it's almost noon San Diego time. It might be different where you are, but our next guest is Hemanchu Al.
Hi Everyone. Hi Hemanchu. How are you?
I'm good. How are you? Yeah, before we jump into it, Homan, what do, what's your, you're with qualis, but what's your position with qualis?
So Working as senior director of product management for Qualis platform and census. I just completed nine years last month with Quas. Nine years.
Yeah, It has been a pretty remarkable journey for me. Yes it has. Congratulations and good for you.
Good for you. Thank you. Um, you also presented two presentations here at USC this Year.
That's correct. So Before we jump into the presentations, you know your product manager platform and sensors, let's go over what those products are. Sure.
'cause we've spoken Yeah. About a lot of products. Yeah.
People may be not sure at home, right? Yeah. They're following along that they can.
What are the platform and uh, sensor products from PLIs? So Over the last few years we have extended our platform for it to become enterprise to risk platform. Now, why we call it as enterprise tourist platform because of its simplicity and everything which it offers for the ciso for every cybersecurity need that they have.
And we divide the platform into five major pillars of sections. First is asset management, where we provide complete visibility of every single internal and external facing asset. We also c MDBs because we know no one has a complete CMDB, right?
Once we identify the assets, we help customers to detect the vulner days and they detect it fast. With Q, they can detect the vulnerabilities with M-T-D-D-S less than to us. Once you identify the Vulner days.
The third pillar is, is to fix it because there's no point just detecting it. With QS, integrated patch management, you can reduce the meantime to remedy by more than 60%. The fourth pillar on the platform is now we sell customers to detect malicious and suspicious activities and we extend threat detection and response to the endpoints.
And the last pillar is compliance. Obviously once you have collected all of this data, you need to map it to the mandates and give it to the auditors in a language that they love. So I help manage all of these portfolios from from the lys platform perspective.
And all of these sections are powered by our purpose-built sensors. So Qualys has the industry's widest coverage of sensors. We have well major categories of sensors which helps you to gain data insights, gain all the key information from your cybersecurity landscape, which helps you to prevent from getting breached.
Now when you say 12 different sensors, yeah. Are they all contained within that single Qualys agent? That's The beauty of it.
All of these sensors are within the same Q platform. You do not get a disjointed solution, unlike some other tools. All of the sensors, the data which they collect gets natively correlated in the platform.
So that we provide one singular view for the customers. So we have Qualys cloud agents, which serves nine different security pillars. We have scanners which runs remote scans and we provide unified set view based on the data collected by both scanners and agents.
And as cloud security is evolving, we also have snapshots and a BAP based scanning. So if you've seen the industry, some analysts and vendors say that agent approach is better. Some say agent less is better.
Some say snapshot is better. Qualys is the only provider which provides the most comprehensive coverage. And depending on a use case, you can choose the type of sensor which you want to collect the data.
You know, one thing I didn't hear you mention was risk. Risk. That's what we talked about here for a day and a half, right?
Absolutely. How does risk play into all this? So All of these things gets natively correlated to the platform and then we map it to the true risk.
Now when we say true risk, it means it, it is a combination of basically two things. One is the risk of your vulner days and misconfigurations. So all the vulnerabilities switch sensors, scanners, agents, specific sensors collect.
We then map it to 25 plus thread feed. That includes manian, that includes Google, that includes reversing apps, et cetera. And we have one 20 plus wider engineers who then analyze that if there is a exploit available for our Availity, is there a likelihood of exploitation for our Availity?
And then we provide a QDS code, which then then cross map to the business risk of an asset because obviously can fix all of the vulner. Every single CSO is saying we have millions of vulnerability. I just want to know what matters to my business.
I just want to know what will have a downtime impact for my business, what will have an impact on my PCA compliance? And I only wanna focus on that. So then Quas maps that QDS code to the business context and provide you true risk score for your assets.
And that acts as your holy grail so that you can prioritize and prioritize even your remediation efforts on it. 'cause the thing is, most of the CISOs are not responsible for patching as well because whenever a breach happens or they miss compliance, IT team is not going in front of the board. It's a ciso, CSO is going right.
And that and that fundamentally that there's a whole issue around That industry. Absolutely. Haman, you, let's now pivot and talk about you.
As I mentioned, you had two presentations here. Share with our audience what you presented on. Okay, the first session was for census, which we briefly talked about.
So every single sensor is saying that the biggest challenge for them is to collect data comprehensively from all of the risk factors. I mean there are multiple resources today such as data centers, I ts assets, its assets, ai, workloads, cloud and continuous web application risk. And they lead to a variety of risk factors such as vulnerability, misconfigurations, unauthorized file access, E-O-L-E-S softwares.
Now how do you then ensure that they can collect all, all the required data for calculating the risk in a comprehensive manner? Because a lot of the vendors, they do not have solutions for let's say exotic operating systems. If you talk to the banks, they have these systems and they spend hundreds of thousands of dollars collecting the data from these systems because everyone is too afraid to touch it.
And cos is the only vendor who worked with IBM and they provided a native, so native agent for Linx systems. The other areas which a lot of vendors miss is other vendors misses the legacy solutions. No matter how much you want to use latest operating systems, you will still have those sent to S five.
You will still have Windows xp. A lot of the banks and the ATMs in the world are running on state Windows xp. I know if, if your solution is not covering it comprehensively and in an integrated manner, uh yeah, you don't have the complete, so Let me ask you about the Windows xp.
Yeah. Yes. I'm not, you know, we Yeah.
The truth is there's still a lot of systems. Correct. But they're not supporting it anymore.
There's no more patches for it. Correct. Correct.
What do you do? I mean, you still need the visibility for it because if it's on your ATMs, that becomes like your crown jewel that has the maximum amount of money for business. If you have the visibility, then at least even if you cannot patch it, you can take actions.
Like maybe you can take it out of the network so that the impact doesn't spread. Well, you can remediate without patching remediate. Correct.
Right. You can try to isolate it Correct. So forth.
And sometimes There are some conflict changes you can do just to mitigate the risk. It's not always about patching. There are other Ways to No, it's more remediation than patch.
Absolutely. Certainly. What was your second in presentation about?
Second is supply chain. I mean software supply chain is one of the biggest risk factors as part of the risk operation center. And this is one of the biggest area where CSOs and the cybersecurity team faces challenges in n navigating.
Now from the QS perspective, we cover software supply chain into two major sections. One is OSS based risk and second is first party. I'll talk briefly on both of them.
So in the realm of modern software development, OSS achieved remarkable prominence. So if you see every single company uses OSS based softwares and more than 60% of them consider it to be running on business critical applications. Now how do you identify the risk for it?
Most of the native VM solutions do not have a, do not have coverage for OS. They cover networks, take our os, take our application. But it's a whole separate system.
Whole separate css. Correct. And then they run manual scripts and then they have to spend manual efforts, time and money to correlate the data.
And that is where the whole struggle begins. I mean, if, I hope you will remember Lock Forge, right? People spend more than 15.
I'm A little older than I look. Go ahead. That is funny.
That is funny. So people on average spend more than 50 days just to identify Log four J and that is too much. I mean, that increases your attack surface and the expiration days by a lot.
So Quas now has integrated, uh, WCA solution, which is, we call it a software compulsion analysis. So the same agent, which is already deployed, we have 110 million agents deployed globally. You can enable SWC in a single click and get deeply embedded open source software and commercial software components in a natively integrated VMDR manner so that whenever the next log 4G happens on day zero, you'll be fully prepared to tackle it.
You'll not spend 50 days just to inventory it. And we also provide 17,000 plus signatures for it so that whenever a new VULNER day comes for any OSS based software, you will be able to detect the vulner and the impact on your environment on day zero. And the best part about this is it is natively integrated with VMDR, the 25 plus, which we talked about earlier, also gets SU applied to this software composition analysis vulnerabilities as well.
So that you do not need to practice every single OSS based vulner nowadays. We can practice only what matters to your business. Love it.
Yeah. And last part of it is first party risk. I mean first party, unlike third party softwares, other softwares built in-house in your environment by your own developers.
But the thing is, if it's your own developer, it'll have a lot of security issues. It'll have outdated libraries, it'll have misconfigurations. Now there might not be publicly available exploits or vulnerability for it, but if you're using OSS based softwares, that becomes the prime, uh, uh, that becomes a prime attack for the, uh, threat actors.
You can easily be hacked with it. And that is where quais provides a solution where if you want to ingest your custom risk, for example, your developer has built an application, your pen tester came and he now analyzes that you have an unencrypted password in it. How do you detect the risk for it?
Quas now provides a solution for it if you want to analyze the risk of a having an India solution. But is it really running on your environment? Is the service really on, is the process running?
How do you identify it? So even for your custom risk and first party, the same solution can be extended. And again, it is natively integrated with VMDR so that we provide one consolidated true risk across your environment.
I love it. Yeah. A lot of, you know, I've, I've come to a lot of QSCs over the years.
Yeah. A lot of people here this year. A lot of good peer to peer stuff going on.
What's the feedback been for you? I think the feedback has been really good. Uh, so Sumit just announced risk Operation center concept and our latest, uh, model called as Enterprise Risk Management in which we are opening our platform not only to the data coming from our sensors, but literally you can now ingest data from any other sensor, uh, in the, uh, in the wild.
So even if you are using any other I iot solution, if you're using Prisma Cloud, if you're using ways, if we are using Microsoft Defenders, you can ingest that data into qualis platform. Quas will normalize de-duplicate and contextualize all of that data, correlate the data which Qualys already has and will provide you one unified true risk so that you do not need to play with Excels. You do not need to spend manual efforts or even, you do not really need to even build your own data lake because I mean, we are now launching it, but this is not a new concept.
A lot of the big concept companies have been trying to do it on over their own, but it's too expensive to build and then people comes and goes and the whole thing just crashes. Well that, that's one of the reasons to outsource that kind of thing, right? Yeah.
Correct. What about you? So basically what you told us, you sit around here at the QSC done Very much.
Yeah, not much. I little coffee now and then and that's it. Yeah.
I for you man, Uhhuh Hey, thank you for coming on our show. Of course. Thank you for having me.
Keep up the great work, man. Thank you so much for having me. My pleasure.
Haman, you al uh, senior director, product management for platform and Sensors. Thank you for having me here. Thank you.
Bye-Bye. Sit it. We gotta undo you, but we're gonna take a break first.
Okay. We'll be back. We're live in San Diego.
Stay tuned.