Qualys Patch Management with Dilip Bachwani at QSC24
Dilip Bachwani and Alan’s conversation centers on the evolving relationship between cybersecurity, IT, and risk management, emphasizing the importance of addressing real, business-critical risks rather than simply fixing every vulnerability. Dilip highlights how Qualys Patch Management and a more holistic, risk-based approach are transforming the industry’s understanding and handling of security challenges.
Transcript
This is Textron tv. Hi everyone. We're back here in San Diego for QSC, uh, having a great first day talking about all different aspects of security and what's going on here.
My next guest, he's been with us, I don't know every QSC we, since you joined the company, I think. I think the first time I interviewed you, I just joined. Mm-Hmm.
Um, it's Dilip Bai. Mm-Hmm. And Dilip, I forgot your title, but it's the Chief Product Officer or Chief Technology Officer.
Chuck, That's exactly it. And, um, first of all, welcome, welcome back. It's great to see you.
It's good to be here. Yeah. It's a good QSC so far.
Really nice crowd. Really nice turnout. Some great conversations, great presentations and sessions.
If you ask me, the big story this year is risk, it's about risk risk management, the, uh, launch of the Qualys Rock Risk Operation Center. Yeah. And we were talking, we've both been in security a long time.
We were talking about the evolving relationship between risk security and it. Yes. It's almost like you could be friends with one, but then you can't be friends with the other.
Right. You alone, your kids. You had that kind of thing.
You can't be the three of you together, but we need the three of them together. Give me your take on where, where is the market, not just Qualys, but what's the state of the industry when it comes to risk security and it Yeah, It's a good question. So, you know, for a long time, let me start with for security and it, I'll come to risk.
It was always thought that security sits here. It sits here. Yeah.
And the security team is running the VM scans, passing, passing it on to the IT team, and the IT team is fixing everything. We sometimes, Excuse me, you're right. Sometimes right now what has happened is, and you know, cos is a good example of this.
We launched Qualys Patch Management about four years back. I remember. And when we launched it, we were told, well, a security vendor doesn't actually do patch management.
It's the IT teams, it. And our take was, what do you do after you run a VM scan as an example, the next thing you do is patch. So we built the product, we launched the product.
We've obviously tightly integrated that into the overall security ecosystem. But just to tell you how close security and IT is coming together since the beginning of this year to now to last week, we went back and we looked at numbers. Mm-Hmm.
And Qualys patch management has deployed 78 million patches. My God, that's a lot of patches. That's a big number.
Right. And that just tells you that it's, when you are thinking about risk, you can't say something belongs here to security, something belongs to it. You just have to think of risk in a more holistic way.
And you know, that, that actually brings me to the whole idea behind risk insecurity, right. Because for a long time what was happening was you run all these scans, you check for your vulnerabilities, your misconfigurations, and then you have this endless game of fixing and patching these vulnerabilities when in fact, what you really should be doing is focusing on what's the most important thing to fix. Uh, and the way we think about it, and we actually spoke to about 150 CISOs before we really sat down to build enterprise service management, our risk operation center, just to say, here's how we are thinking about things.
That just because you have a vulnerability doesn't mean you have to patch that vulnerability. Right. In fact, when you look at, you know, this, the entire breadth of vulnerabilities that are out there, there's a very small subset that actually has an exploit for it.
Right? Right. Or you could have a vulnerability, uh, that could be exploited outside in, but it doesn't apply to you.
Mm-Hmm. So we said, why don't we look at everything in a much more risk centric way and combine data about the asset, about the business con context, about, uh, threat exposure, all of that. And then say for a particular asset or for a particular business entity, which comprises a set of assets, what are the most important things that you can focus on or you should focus on?
Mm-Hmm. And what that boils down to is you really have to focus on about 10% of, you know, what's really at risk here. And you don't have to, at least initially you don't have to go chasing things where it won't make that much of a difference.
So we, we now see, uh, that the industry is converging on the concept of risk. That everything doesn't have to be fixed. You have to say, how does it apply to me?
What's my risk posture? And let me focus on that first. ETM enables that.
Right? Right. It's not, ETM is not just about qualis products, bringing qualis products together and giving you a unified view of risk for Qualys.
We are going further and we are saying, we'll take all third party products, we'll bring everything in and then we will give you a real unified view of your enterprise risk, your business risk. Right. Uh, to me, as somebody who also runs operations at Qualys, and obviously working very closely with our security teams, we are FedRAMP compliant.
We have FedRAMP moderate, we are getting FedRAMP high now in the next couple of months. I mean, thinking of everything in a risk risk centered way, it obviously makes a lot of sense. Sure.
And we are benefiting from it too. You know, I had a good conversation this afternoon with Mahesh, um, cha Chara, I think he's the president of, uh, Mulberry. Correct.
The insurance, the insurance company. Yes. Cyber insurance.
And what he was saying is, look, they could take that risk score because you know, when you go get insurance, I don't care whether you're getting cyber insurance or homeowner's insurance, have you ever made a claim? Yes. How long old is your roof?
Do you have storm proof windows, whatever, and you Yes. No. Yes.
No. Yeah. And based upon that, an insurance company says, all right, well this is how much coverage you're gonna get.
This is how much it costs, but it's that moment in time. Correct. It could change next week, next month, next year, or not at all.
What they like about having the risk score like that is this is something that is a living, breathing dynamic score that then they could monitor. 'cause if they, you know, because for them information is their lifeblood. Right.
They can't, they can't manage their own risk. 'cause insurance, insurance is a risk management business. Right.
Right. What's the likelihood of having a claim? How big a claim it is?
How much do I collect in premium? Right? Yes.
What's my reserves all that? It's risk. This to them opens up for the first time.
Yes. Truly managing risk. Yes.
Day to day. Yes. Moment to moment, It absolutely does.
Because insurance today works on an outside, in principle, they look at things from outside. So to your point, roof a few things. They do a drive by.
Yep. And then they bucket you and they say, you fall in this category of customers and here is your premium. Yep.
There is no inside out view or no deep dive insight. What true risk does is fine, you can look at the outside in view, but we are actually telling you what's going on inside in our own environment. And then that could help refine your risk posture and directly your insurance premiums.
Absolutely. I I couldn't agree more with you. And look for him, it's a game changer.
But for security teams and, and risk management teams, it's also a game changer. Yes. But like I said in the earlier, it also helps bring together, again, security to risk.
Right. Because there is that inherent connection. One goes with the other.
And, and so I, I think that's a needed thing. Um, I also think one of the biggest problems we've had with security dealing with it is the security team says, all right, here's the vulnerabilities. Mm-Hmm.
Have at it. And whether you're a developer or just an ops person, you're like, why? Why?
Right. Show me, why is this bad for me? What could happen here?
You're telling me this is a medium risk, this one is a high risk. Right. Or medium severity, high severity, whatever.
But I don't really see, see it. Yes. These kinds of things help people see It does What, what what the real risk is.
Yes. And, and then no one's gonna say, oh, I don't care what the risk is, I just let it ride. You know?
No. If they see the risk, they'll want to do something. So I think it could help in there, but I think it's, this is a different way for the security industry.
Mm-Hmm. To look at risk and how it's intrinsically linked to what our job functions are and what our goals are. Yes.
I think, you know, when we look at, um, and I'm sorry to be talking, this is your interview, but you look at CISOs. Yes. Right?
What's the job of the ciso? Yeah. Is it to manage risk?
Yes. Yeah. But too many CISOs don't deal with managing risk.
Too many CISOs deal with, did I do enough scans? How do I have the right talent in place dealing with tooling Tools instead of the outcome that we should expect from the tooling. Bingo.
Yep. And, and I mean we see that too. Um, we are obviously hoping to change that conversation.
In fact, for we are a public company, right. We have pivoted to instead of telling our board about we have these many vulnerabilities, or the fact that we rolled out MFA or we rolled out this new tool or did this or that. We are now talking in terms of risk even to our board.
We are quantifying risk in terms of tasks. We are saying, here are all the platforms we have here is the risk associated with each of those platforms. Here is what we are doing to manage and mitigate that risk.
And that resonates. Right? Absolutely.
'cause that's the language they understand. Right? Now the question is, you know, the problem with being a missionary is you work hard, cutting your path through the jungle, and then someone just walks in by how this is a missionary role a little bit for Qualys, right.
Kind of trying to bring the industry back to risk. Yes. How big a job is that?
How long will it be to make it happen? You think? You know, of the, all the CSO CSOs that we spoke to, as soon as we presented this idea, and in many cases Summa was the one presenting, the immediate response was, this is a complete game changer.
That we know that we shouldn't be chasing, fixing things based on A-C-V-S-S score. We should be chasing, fixing things based on risk. What real Risk risk is to us, right.
In our environment. Not the risk to a generic No, Because you can have a vulnerability with an exploit, but if it doesn't apply to you, it doesn't apply to you. And as long as you can clearly explain that Right.
Then you're in a good place. Agree. So, I, I don't think the adoption is going to be a challenge.
In fact, I think this is going to be a real enabler, not just at the CISO level, not just at the board level, but even internally within organizations for a security team to say, okay, we have all these vulnerabilities. I'm not asking the IT team to fix everything. I'm not asking my software engineering team to go back and fix all these application vulnerabilities.
I'm going to give you a smaller subset. I'm going to tell you I want you to fix this and here's why I want you to fix it, because I'm explaining that risk to you. Sure.
Right. It's not just for outsiders, it's for internal use too. We do it internally that way now.
Yeah, Absolutely. Eating your own dog food. Right.
And that's how it has to Be. So that's, that's where the value then comes because then you can have a conversation on something that's more grounded. We want you to do this because of this reason, and conversely, we are okay if you delay doing this because we don't see a risk.
So, excellent. Yeah. Dilip, they said we, we have to stick to 15 minutes 'cause they've got a full Oh sure.
Panel for us. But a, it's a pleasure seeing you. Thank you very Much.
Good as always. Yeah. Um, B, good luck with this.
Keep us posted. We're gonna take a break here on Techstrong tv. We're, we have a lot more to go.
I think Ed is coming up. Okay, great. Yeah, Now we're in the next one, but we're here for another couple hours in day one.
Then we're back here tomorrow for another full day. So we're excited for it. You're watching Techstrong tv.
We'll be back in a minute.