Submind YouTube summaries
Thumbnail for Sumedh Thakar, Qualys | Black Hat 2026

Sumedh Thakar, Qualys | Black Hat 2026

Watch on YouTube

Video summary

Sumedh Thakar, President and CEO of Qualys, addresses the critical challenge facing modern security teams: vulnerabilities are being discovered, weaponized, and exploited far faster than organizations can assess and remediate them using traditional methods. The core issue is not merely a lack of resources but an inability to effectively prioritize which risks matter most to the business amidst this explosion in volume. Thakar argues that while we cannot fix every vulnerability due to resource constraints, security leaders must build confidence in their prioritization strategies by focusing on three key layers: identifying threats with actual exploitability within specific environments rather than just theoretical existence, and determining whether a flaw leads to significant business loss. This approach allows organizations to ignore millions of low-impact findings and concentrate only on the small percentage that pose genuine danger. To address these speed and accuracy challenges, Qualys has evolved its vulnerability management strategy from simple scanning-and-fixing models into an autonomous framework capable of "zero-day remediation," where issues are resolved within 24 hours without causing system outages. This is achieved through three pillars: scanless detection using agents to find issues instantly, validation via safe payloads that confirm exploitability before attempting fixes, and intelligent remediation that applies patches or alternative mitigations like configuration changes only when necessary. A major hurdle in this process has been the fear of downtime during patching; however, by leveraging frontier AI models trained on billions of historical deployments, Qualys can now predict patch reliability scores with high accuracy, ensuring that updates are applied without requiring reboots and minimizing operational disruption while still neutralizing active threats. Beyond immediate remediation, Thakar emphasizes the urgent need for robust AI governance to manage "shadow AI" where unauthorized or unmonitored models operate within enterprise environments. As businesses race to adopt artificial intelligence, they must gain visibility into who is using these tools, what data is being processed, and whether guardrails are in place to prevent leaks of sensitive information like employee salaries or proprietary code. The proposed solution involves a comprehensive discovery inventory that tracks hardware components, model locations, and training data sources, coupled with testing mechanisms to ensure models do not generate harmful outputs. This governance layer transforms AI from an uncontrolled risk into a strategic asset by establishing clear policies that prevent unauthorized usage while ensuring compliance with regulatory requirements regarding where and how these powerful technologies are deployed. Ultimately, the goal of integrating advanced security operations is to shift from reactive dashboard tourism to proactive Risk Operations Centers (ROC) that translate technical findings into business language for executive leadership. Instead of presenting isolated metrics like vulnerability counts across different clouds or identities, an ROC harmonizes all risk factors—including cloud misconfigurations, identity threats, and AI risks—into a single view aligned with the organization's financial appetite. By quantifying potential losses in dollar terms based on historical ransomware payout data for specific industries, security teams can justify their spending to boards by demonstrating that investing one million dollars now prevents a ten-million-dollar loss later. Thakar concludes as an optimistic "frontier AI optimist," believing that democratizing access to these advanced models will allow defenders to stay ahead of attackers who also use AI, provided vendors deliver solutions that are accurate, fast, and cost-effective rather than charging customers by the token or offering mere marketing fluff.
Read the full video transcript
Hey, welcome back to the cube. We are approaching the end of day two here at Black Hat 2026, but the conversations are still going strong around the fact that vulnerabilities can be discovered, weaponized, and exploited much faster than organizations can assess and remediate them. So, we do see that security teams are struggling with the volume and speed of change. Um, that's really outpacing these traditional approaches. And at the crux of that problem really is their ability to sort of prioritize what to fix and then take the appropriate action. Um but there certainly is, you know, some hope here in terms of kind of evolving this um this approach to making better cyber security um risk decisions. Sitting down with me um today is Sume Takar, president and CEO of Qualus. Sumar, thanks so much for joining the cube. >> Thank you very much for having me. >> Absolutely. So before the cameras were rolling, we were talking about kind of some customer conversations. I know you said you've been getting some really great feedback. Yeah. And it's consistent with what we're hearing from a lot of um CISOs, which is that they're trying to build confidence. Yeah. >> In terms of understanding that they're prioritizing the risks that matter the most to their business. >> Are you hearing that too? And if so, what do you think is the missing link there? >> Yeah. Yeah, that's a great point. I think the qu the question is why are we talking about prioritization? if we could fix everything we would have just done it right and so I think in many ways this is not a new issue uh for the last few years everybody's been struggling with not having enough resources to fix everything the problem just has exploded even more with frontier uh models right so it's not like we had enough human resources anyway to fix everything and so now the questions are coming even more which is I cannot fix everything so by nature I need to prioritize and so then the question is how do you prioritize and like to what you ask is how do I build confidence in the prioritization right and I think there's sort of like couple layers of prioritization here is just the basic prioritization based on the threat intelligence if things are actually being even exploited there is a lot of theoretical vulnerabilities out there that are have no way to be exploited the second prioritization comes from u you know is this import is this actually exploitable in my environment so while a vulnerability could be very exploitable out there uh CISOs have put defense in depth. They have put other controls like a firewall like an EDR uh which actually can block these exploits. So the second prioritization comes from can I actually run these exploits to confirm that they are exploitable. So now you can reduce the findings even more. And then the last part is yes even if it is exploitable is it something that leads to an a big loss to my business or no. And so I think what we see is that you might have millions of vulnerabilities but only 1% of those actually are exploitable and then u only a small percentage of those actually lead to a business loss. >> Right. It's a great point. We can't kind of waste time chasing like you say these vulnerabilities that aren't going to impact our business at the end of the day. >> Um so I understand that Qualus has had an announcement on um kind of the vulnerability management and scanning front. Now vulnerability management traditionally has relied on scanning. >> Yes. >> Um but can you talk through you know why that approach isn't working anymore and maybe kind of you know some of those gaps that Qualis saw that you know needed to be addressed. >> Well thank you for that question. I think uh it's very interesting because I've been at Qualis for 23 years. I was one of the original engineers that work on the platform and at that time vulnerability management was two pieces scanning and then fixing. uh and as the volume of vulnerabilities exploded last many years, you kind of now have three pillars of vulnerability management. Can I detect quickly? Can I uh prioritize quickly? And then can I fix quickly? And in response to the mythos model, every CISO is having to explain to the board what is your approach to AI based autonomous exploitation and the response cannot be we're going to hire more people. So you have to have a response that basically grounds yourself in saying we will have some form of autonomous response and I think that's where um the the fixing is the part that gives you the most bang for the buck then you have the prioritization which helps you reduce what you need to fix but your scanning has become even so more important because if you're not able to find the issues in the first place what are you trying to fix and so those three pillars of quick detection which we call scanless scanning and agent insta Second is validation of exploits with agent val. And then the third is uh the ability to actually remediate vulnerabilities not just patch but remediate with different approaches which is agent sarah. So all these three agents together are giving us hope that today we have the ability to go from detection to remediation in what I call a zero day remediation. In the first 24 hours we can get things fixed. It is possible today. Technology exists and we're excited to bring that to our customers. >> Yeah. So zero day remediation um can you walk through I guess maybe >> some of the the challenges right that a customer might encounter as they're trying to make this a reality I mean it's definitely a lofty goal. >> Yes it the good news is is doable. You know we have 150 million patches we deployed in the last 12 months out of those 40 million today are already autonomously deployed without any human intervention. So what is the push back for remediation? The push back always is well what if the system goes down. So that's the push back on patch management from remediation. And so where we have focused on is to say well how can we build confidence that you can patch without worrying that it's going to be an outage. So the first part of that is how do we help you make sure that if you want to reduce the possibility of an outage fix the least amount. So that's where this hyper prioritization is important so you can get down to only 1% that you fix. Second becomes well is there an alternative without a patch that I can apply a configuration fix that will prevent the exploit and I have more time to patch later. So what we have done is leveraging these frontier models ourselves. We have created uh ability to create mitigations where you can actually maybe just change the permission of a file maybe you disable a service but with that the potential of a compromise becomes a lot less and you don't have to patch right away. And the third and the last piece there is to build confidence in the IT team's ability to deploy the patch without worrying about an outage. We took the half a billion patches that we have deployed in the last few years where we see every roll back, we see every uh error that we get and we build an MLAI based patch reliability score. What that allows us to do that as soon as a vendor releases a new patch, we can actually tell you this is a high reliability patch and does not need a reboot. So you feel higher confidence that I can remediate in zero days because it's a high reliability patch and I do not need a reboot and so with that we can you know look at the end we are managing risk. So it's not that we have to fix everything but if we can take enough off the table the potential of a compromise goes down significantly. So auto remediation can fix 20 30% of your stuff but that 20 30% can really reduce the potential of an entire chain of attack happening successfully. >> Absolutely. because we're seeing that, right, that these, you know, AIdriven adversarial attacks, they can chain together these vulnerabilities. So, it's a great point and um you know, I'm glad that you called out sort of um how you're validating the the um the confidence, right? Because that is something that we're seeing security teams, especially if they're trying to integrate AI as part of their processes, which is necessary to do in order to keep pace. >> Um you know, they're kind of they're needing to understand that they can trust the AI. So are are you building confidence with customers? >> Exactly. Right. I think that's where the the combination of um uh the data, the analysis, the inference and the AI models and like you know because we built the harness. So we're we are part of glass swing. We are in Daybreak. So we are basically collecting and leveraging these models of AI to build mitigations and to build safe exploits for customers because as you saw with open AAI hugging phase like that that whole thing it they don't care the autonomous AI does not care about this the system shouldn't go down. It'll try 10 different things. One of those could bring the system down. So how do we leverage this AI capability to build out exploits that are safe with higher confidence for the customers so that they can test themselves without having to worry about an outage. The same thing for the mitigation high confidence mitigations that are tested that are created by reverse engineering exploits through AI and then giving those to the customers. So they have much higher confidence remediation that they can do and all of it is based on not just using AI as is out of the box but building confidence around the AI capabilities so that you can use those for remediation. >> That makes a lot of sense and sed can you talk uh maybe just double click a little bit more in terms of how you're validating these vulnerabilities I know you kind of mentioned that a moment or two ago. Yeah, I I think a very simple way to look at that is, you know, if there's a bunch of different doors that are there and, you know, the traditional approach of prioritizing will tell you maybe these 20 doors could lead to a compromise, right? Uh I think what we're now focusing on is saying like hey we're just going to try to open those 20 doors and we'll tell you by the way only five of those open and that we are doing so that now you have a much focused approach and that's where that exploit validation comes in where it's not a complete red teaming exercise >> but what we can do is when you see a vulnerability we send a safe payload a safe payload could be as simple as saying hey can you resolve this DNS name if we see the DNS resolution come through we don't need to update your system write anything we can tell we could compromise it Now that gives you a higher confidence in saying like hey by the way my controls didn't work. I got a qu I got actually an exploitation that happened. So that becomes my priority versus if we send a payload edr blocks it firewall blocks it and it doesn't execute then you have more time. So that again reduces the potential of an outage because you're not fixing everything you're fixing the one that works. And so that's where we do a lot of the validation by running very very safe ways to actually test if the exploit worksh um kind of area you had an announcement um this week my understanding is around AI governance. we've been hearing kind of a big focus on runtime and sort of how do we put these you kind of described a harness how do we put the right guard rails in place because um enterprises are just racing to try to adopt AI >> and so for our security teams they need to not get in the way of that they need to enable that so can you talk to you know I guess maybe what you're seeing customers struggle with from that perspective >> I mean I think we're at the early innings of AI and so I think the initial challenge is shadow AI right and how do you figure out what's in my environment And I think it's almost like not having a shadow AI problem is a business problem which means that you're not actually using AI in the business which is not good for business. So I think today it is very important that every business actually is using AI and then you know we kind of were at the beginning where everybody wanted to do shadow AI because they're like I want to know who's using AI so I can block them. Then we saw the pivot to saying well I want to know who's not using AI so I can you know send them somewhere else. >> Yes. Right. So, so now we're kind of rolling back to saying like, look, I I I need to be able to have the visibility of who's using AI, what are they doing with it, can I put some guardrails around it, where are my models, where are my GPUs? And I think I've done this long enough in cyber that no matter what new technology comes, it's always has these components which is discovery, whether it was cloud, whether it is going to be quantum in a few years, question always where do I have it? Can I assess it? I cannot fix everything. Can I prioritize it? and then at the end if I don't get it fixed what was the point of this dashboard tourism right >> we were just looking at dashboards we're not doing anything so that same thing is happening with AI so what we did with total AI is to leverage the qualice footprint customers have and created the ability for them to figure out their shadow AI what's happening on the client machines where are you running AI in the cloud environment etc so you can first get the visibility once you get the visibility we can test the models we can see if the model is doing something that it should not and then we can help you build out policies to be able to say we have some governance capability where unauthorized AI engines are not being used. You know the AI engines are not being fed data that they should not be. So it's it's something that is going to come up more and more in the next few months as priority for customers as soon as they get through the the current challenges that they have. Uh AI uh security and governance is going to be definitely something that is going to be important for a lot of customers. I agree and we're certainly seeing that as well that customers are trying to turn the lights on, right, and kind of solve the the the shadow AI piece of it. Um, when you think about kind of the stack that's needed to govern AI, what do you think are going to be maybe some of the key control points? >> Yeah, I I think there are a couple control points here that are very important. First, you know, discovery inventory, having an upgraded inventory, then you had the hardware components of AI. I think we also have to think about that some of these are not necessarily a security issue there. Some of these are just a business. How many tokens am I spending is more important sometimes than the security part of it. So the inventory is something that is going to be important after that. Do I know all my models? Where are they running? It becomes important. Um testing the models to ensure that they're not giving you answers that you should not be giving becomes important. But then the last piece that is also very important is that what data is being used to train these models becomes very important. So if I know a model is being trained, is it being trained on my employee information that should not be uh if it's a support chatbot and I ask it what's the employee salary? Is it going out and talking to an MCP server to give that information that becomes a uh control point and then at the end we are going to have to produce reports to for regulators. We're going to have to produce reports for the board to show we know where our AI is to show we have tested it to show that we have actually put guardrails around it and that we are continuing to monitor it right but at the end AI is one risk you still have cloud risk you still have identity risk you still have misconfiguration risk so all of that needs to come together in a singular risk view >> that where what what we really see today is the the building of a rock like you have the sock which is after bridge proactive risk management is risk operations center so How does AI security plug into that? And then in 3 years it's going to be you know quantum security but at the end companies has have a limited budget and where should they spend that money it's going to be based on where is the risk. If AI is the risk spend more on that if quantum is the risk spend more on that and the rock actually helps you get that visibility. >> Walk us through the rock because I know I've had some conversations with your with your team um about the risk operations center and sort of how it's complimentary >> to the security operations center. It doesn't necessarily displace it. But Sume, I'd love to sort of hear from the horse's mouth today. >> Yeah, you know, we were having really great conversations because the the sock I know I described that as snipers, right? Like they are focusing on is somebody in my environment now and how can I get rid of them? Like that's their main focus. They are not thinking 3 months, 6 months from now etc. And so what has happened is that we have done a good job in creating socks with SIM and XDRs and you know looking at uh log data etc. M >> but when you come when it comes to proactive risk management the question is you know I have cloud risk in one dashboard I have uh identity risk in a different dashboard I have on-prem risk in a different dashboard and so we are in we end up with dashboard tourism like I just have dashboards but if I ask you you have a business unit that makes 500 million a year >> what's the potential of a dollar value loss on that business unit you cannot say because every risk with a different score is in different areas right so the idea of the risk operations center is how do we elevate the conversation of risk. How do we take vulnerability as only one component of risk? Second component is misconfiguration. Third component is identity. Bring all of that harmonize all of that and then get into threat intelligence, business context, remediation and compliance. All through very focused on risk itself and then >> acknowledge that risk management exercise has three components. One is mitigation proactively. M >> second is consciously accepting a certain risk and the third is what you cannot accept and what you cannot mitigate you need to transfer to cyber insurance company so the rock will allow you to have a conversation with your cyber insurance company to say here's my sustained risk level here's the additional residual risk that is left that I cannot accept and what is the cost of transferring that risk to a cyber insurance company so the risk operation center is more of a strategic uh plan for CSOS over the next couple of years is implementing a rock so that they can answer the question that the board wants. They don't want to know the number of counts and etc. The board just wants to say is 90% of my revenue under my risk appetite >> and that's it really kind of cuts to the chase and it puts it in those board level terms. >> Yes. >> So um so you kind of referenced that you're having some great customer conversations around the rock. What are some of the points of visibility if you will um that you think security practitioners don't have today that the rock is giving them? Is it kind of connecting those points that you mentioned and >> well exactly right like so if you have an an application that's making you 500 million a year >> there's a separate tool that looks at the cloud piece there's a separate tool that looks at identity piece and separate tool that looks at configuration piece and so >> if you are asked the question like I mean you have individual visibility but if you say how much loss could I have if there is a ransomware attack on this 500 million business unit and where is that risk coming from you you cannot explain that because it's distributed across multiple tools. >> The good thing about the rock is that it takes data from existing tools, pulls it into a single uh platform, normalizes the different risk scores cuz some are on 10, some are on 100, normalizes all of that and then puts them in the context of your overall risk appetite. And so the visibility is there from an individual perspective but then when the CISO's job is to uh is to really bridge that gap between technical findings to what it means to the business and the rock really enables giving them that visibility of of having those technical findings translated into business language and explaining to the board how much dollar loss it could have and then where are we in our journey to ensure we reduce the risk of that loss. There is nothing like zero risk. So, and and I always say to people, by not doing anything, you're already accepting a risk. >> Yes, absolutely. I mean, like we were talking about, you know, businesses are recognizing that they have to accept a certain level of risk. And I think it's really powerful to be able to translate this into dollars and cents because it's really difficult to do when we think about something like a ransomware attack in your example. >> Yeah. I mean, yes and no. At the end of the day, the reason you have to put cyber in dollars and cents is because cyber is being used to protect dollars and cents. So that's like, you know, when you get a car or an insurance, you have to say, "I'm going to pay $1,000 to insure a car that is worth 50,000, right?" Like, if if you don't know what the car is worth and you don't know what you're trying to protect, then you are taking infinite risk. And so I think >> it it's it is it has always been warranted. It is becoming more and more important now that you cannot fix everything. You have to be able to explain the prioritization in the terms of saying why am I focusing on this or why am I not focusing on this because the business loss is not there. And I think we have now built up over the last 20 years enough data points um through insurance and ransomware payouts that uh we have uh data available as we partner with a company that gives us that kind of information where we can say if you are a business that is in this segment in this geographical location on an average how much ransomware payout has happened for industries in your business and so you can project from that if I have a $500 million business unit typical ransomware payout out has been around 10 million. Okay. >> And so now you can pull now. So do you want to spend 10 million? No. But maybe you could say look if it's a 10 million payout probably I want to spend a million to make sure that I don't have the 10 million payout. So >> I I think that that more and more of the data points are available and we're bringing it together. Uh but I think you know I'm I'm excited to continue to work in that direction. >> Yes. Yes. Certainly. So, Sad, you've kind of described yourself as a frontier AI optimist, right? And I think there's a lot of potential doom and gloom here, but reading between the lines. Does that indicate you think as an industry over the next, you know, call it >> 6 to 18 months um that we're going to, you know, have some practical learnings and really kind of make some progress in terms of our ability to prioritize and respond everything we've been talking about today. >> I I am very much of an optimistic when it comes to that. I think a little unfortunately some of the frontier rollouts have created sort of sort of halves and have nots and so there are geographies countries in industries where they don't have access to some of these models. The good news is that platforms like Qualis and some of the other cyber platforms are able to leverage these models to create more and and democratize the outcomes of these frontier AI models so that customers can leverage this within their environment without them themselves having to invest in using leveraging these models. And so I think I'm optimistic because uh yes attackers can are using AI for you know creating attacks but defenders also have access to similar technology just looking at it from a different perspective. And so one of the optimistic views that I have is in theory if every organization that writes code has the ability to run this kind of a frontier AI model on their codebase they will find all their vulnerabilities themselves and you will never have zero day vulnerabilities because the zero day happens when attacker knows something you don't but if you're running AI models you will always know >> the flip side is that then the the risk moves towards the zero day remediation because as soon as you release a patch they will reverse engineer using AI AI but the good news is that we at callers can also do the same. Once a patch is released we can reverse engineer using AI find the exploit and then use that in a positive way to create uh compensating controls and to create a testing methodology that is safe. So I do feel like AI is definitely bringing positive outcomes for cyber security for a lot of organizations and they don't necessarily themselves have to be um you know investing and running into these AI models. they should hold their partners and vendors responsible for ensuring that the right appropriate amount of AI is being used to give them an outcome which is at the end of the day what they care about >> and that's a really fair point to maybe kind of a a concluding thought so if I'm a practitioner and I'm evaluating vendors for trying to help me navigate my risk management >> there's a lot of you know >> AI washing especially if I'm in the CISO role I'm being just inundated >> what would you look for >> in a vendor to kind of sift through that noise and really make sure that you know this vendor is going to actually deliver something that's actionable. >> That's a great point. I think you know you have to before you even go look for a vendor you have to ask yourself what is the outcome I'm looking for right and can I have a solution that will find a malware is not an outcome right if I'm looking at business risk I'm looking at the for me to avoid a $500 million loss I'm going to create four layers of controls as my defense in depth and these are the four ones and then you have to be able to then look at the vendors and say are these look at the end of the day AI or not AI Right? When you're looking at a vendor, there are three things everybody's looking at. Number one, is it accurate? Because if the solution is not accurate, doesn't matter how cheap it is. Number two, that is the solution fast enough. If it's accurate but takes 6 months, it's not of no use. And then the last point is is it cost effective? So, is it actually helping me do the first two but without having to spend more money than I earn, right? And so, I think when you're evaluating a vendor, those outcomes are what you should be looking at. and the vendor who's leveraging AI the right way uh and like so for example there are vendors in our space that are charging the customer back by token now as a customer you don't want to deal with that you're looking for an outcome so what we do as an example is we create a harness in the back end that picks the appropriate model so we're not charging customers by the token so they are getting an outcome that is a predictable outcome from a cost perspective and they're getting accurate fast and cost effective ways that they can actually take the solution And that ultimately I think is what everybody should be looking at is what is my final outcome in risk management and um does this vendor help me do things that are accurate, fast and cost effective. >> Well, Summed, thank you so much for sitting down to walk us through all this today in the cube. We really appreciate it. >> Thank you for having me. It was a real pleasure. Thank you very much. >> Absolutely. And thanks so much for joining us. We'll be back in just a couple minutes with some concluding thoughts from day two here at Black Hat 2026.