Video summary
Sumedh Thakar, President and CEO of Qualys, addresses the critical challenge facing modern security teams: vulnerabilities are being discovered, weaponized, and exploited far faster than organizations can assess and remediate them using traditional methods. The core issue is not merely a lack of resources but an inability to effectively prioritize which risks matter most to the business amidst this explosion in volume. Thakar argues that while we cannot fix every vulnerability due to resource constraints, security leaders must build confidence in their prioritization strategies by focusing on three key layers: identifying threats with actual exploitability within specific environments rather than just theoretical existence, and determining whether a flaw leads to significant business loss. This approach allows organizations to ignore millions of low-impact findings and concentrate only on the small percentage that pose genuine danger.
To address these speed and accuracy challenges, Qualys has evolved its vulnerability management strategy from simple scanning-and-fixing models into an autonomous framework capable of "zero-day remediation," where issues are resolved within 24 hours without causing system outages. This is achieved through three pillars: scanless detection using agents to find issues instantly, validation via safe payloads that confirm exploitability before attempting fixes, and intelligent remediation that applies patches or alternative mitigations like configuration changes only when necessary. A major hurdle in this process has been the fear of downtime during patching; however, by leveraging frontier AI models trained on billions of historical deployments, Qualys can now predict patch reliability scores with high accuracy, ensuring that updates are applied without requiring reboots and minimizing operational disruption while still neutralizing active threats.
Beyond immediate remediation, Thakar emphasizes the urgent need for robust AI governance to manage "shadow AI" where unauthorized or unmonitored models operate within enterprise environments. As businesses race to adopt artificial intelligence, they must gain visibility into who is using these tools, what data is being processed, and whether guardrails are in place to prevent leaks of sensitive information like employee salaries or proprietary code. The proposed solution involves a comprehensive discovery inventory that tracks hardware components, model locations, and training data sources, coupled with testing mechanisms to ensure models do not generate harmful outputs. This governance layer transforms AI from an uncontrolled risk into a strategic asset by establishing clear policies that prevent unauthorized usage while ensuring compliance with regulatory requirements regarding where and how these powerful technologies are deployed.
Ultimately, the goal of integrating advanced security operations is to shift from reactive dashboard tourism to proactive Risk Operations Centers (ROC) that translate technical findings into business language for executive leadership. Instead of presenting isolated metrics like vulnerability counts across different clouds or identities, an ROC harmonizes all risk factors—including cloud misconfigurations, identity threats, and AI risks—into a single view aligned with the organization's financial appetite. By quantifying potential losses in dollar terms based on historical ransomware payout data for specific industries, security teams can justify their spending to boards by demonstrating that investing one million dollars now prevents a ten-million-dollar loss later. Thakar concludes as an optimistic "frontier AI optimist," believing that democratizing access to these advanced models will allow defenders to stay ahead of attackers who also use AI, provided vendors deliver solutions that are accurate, fast, and cost-effective rather than charging customers by the token or offering mere marketing fluff.
Read the full video transcript
Hey, welcome back to the cube. We are
approaching the end of day two here at
Black Hat 2026, but the conversations
are still going strong around the fact
that vulnerabilities can be discovered,
weaponized, and exploited much faster
than organizations can assess and
remediate them. So, we do see that
security teams are struggling with the
volume and speed of change. Um, that's
really outpacing these traditional
approaches. And at the crux of that
problem really is their ability to sort
of prioritize what to fix and then take
the appropriate action. Um but there
certainly is, you know, some hope here
in terms of kind of evolving this um
this approach to making better cyber
security um risk decisions. Sitting down
with me um today is Sume Takar,
president and CEO of Qualus. Sumar,
thanks so much for joining the cube.
>> Thank you very much for having me.
>> Absolutely. So before the cameras were
rolling, we were talking about kind of
some customer conversations. I know you
said you've been getting some really
great feedback. Yeah. And it's
consistent with what we're hearing from
a lot of um CISOs, which is that they're
trying to build confidence. Yeah.
>> In terms of understanding that they're
prioritizing the risks that matter the
most to their business.
>> Are you hearing that too? And if so,
what do you think is the missing link
there?
>> Yeah. Yeah, that's a great point. I
think the qu the question is why are we
talking about prioritization? if we
could fix everything we would have just
done it right and so I think in many
ways this is not a new issue uh for the
last few years everybody's been
struggling with not having enough
resources to fix everything the problem
just has exploded even more with
frontier uh models right so it's not
like we had enough human resources
anyway to fix everything and so now the
questions are coming even more which is
I cannot fix everything so by nature I
need to prioritize and so then the
question is how do you prioritize and
like to what you ask is how do I build
confidence in the prioritization right
and I think there's sort of like couple
layers of prioritization here is just
the basic prioritization based on the
threat intelligence if things are
actually being even exploited there is a
lot of theoretical vulnerabilities out
there that are have no way to be
exploited the second prioritization
comes from u you know is this import is
this actually exploitable in my
environment so while a vulnerability
could be very exploitable
out there uh CISOs have put defense in
depth. They have put other controls like
a firewall like an EDR uh which actually
can block these exploits. So the second
prioritization comes from can I actually
run these exploits to confirm that they
are exploitable. So now you can reduce
the findings even more. And then the
last part is yes even if it is
exploitable is it something that leads
to an a big loss to my business or no.
And so I think what we see is that you
might have millions of vulnerabilities
but only 1% of those actually are
exploitable and then u only a small
percentage of those actually lead to a
business loss.
>> Right. It's a great point. We can't kind
of waste time chasing like you say these
vulnerabilities that aren't going to
impact our business at the end of the
day.
>> Um so I understand that Qualus has had
an announcement on um kind of the
vulnerability management and scanning
front. Now vulnerability management
traditionally has relied on scanning.
>> Yes.
>> Um but can you talk through you know why
that approach isn't working anymore and
maybe kind of you know some of those
gaps that Qualis saw that you know
needed to be addressed.
>> Well thank you for that question. I
think uh it's very interesting because
I've been at Qualis for 23 years. I was
one of the original engineers that work
on the platform and at that time
vulnerability management was two pieces
scanning and then fixing. uh and as the
volume of vulnerabilities exploded last
many years, you kind of now have three
pillars of vulnerability management. Can
I detect quickly? Can I uh prioritize
quickly? And then can I fix quickly? And
in response to the mythos model, every
CISO is having to explain to the board
what is your approach to AI based
autonomous exploitation and the response
cannot be we're going to hire more
people. So you have to have a response
that basically grounds yourself in
saying we will have some form of
autonomous response and I think that's
where um the the fixing is the part that
gives you the most bang for the buck
then you have the prioritization which
helps you reduce what you need to fix
but your scanning has become even so
more important because if you're not
able to find the issues in the first
place what are you trying to fix and so
those three pillars of quick detection
which we call scanless scanning and
agent insta Second is validation of
exploits with agent val. And then the
third is uh the ability to actually
remediate vulnerabilities not just patch
but remediate with different approaches
which is agent sarah. So all these three
agents together are giving us hope that
today we have the ability to go from
detection to remediation in what I call
a zero day remediation. In the first 24
hours we can get things fixed. It is
possible today. Technology exists and
we're excited to bring that to our
customers.
>> Yeah. So zero day remediation um can you
walk through I guess maybe
>> some of the the challenges right that a
customer might encounter as they're
trying to make this a reality I mean
it's definitely a lofty goal.
>> Yes it the good news is is doable. You
know we have 150 million patches we
deployed in the last 12 months out of
those 40 million today are already
autonomously deployed without any human
intervention. So what is the push back
for remediation? The push back always is
well what if the system goes down. So
that's the push back on patch management
from remediation. And so where we have
focused on is to say well how can we
build confidence that you can patch
without worrying that it's going to be
an outage. So the first part of that is
how do we help you make sure that if you
want to reduce the possibility of an
outage fix the least amount. So that's
where this hyper prioritization is
important so you can get down to only 1%
that you fix. Second becomes well is
there an alternative without a patch
that I can apply a configuration fix
that will prevent the exploit and I have
more time to patch later. So what we
have done is leveraging these frontier
models ourselves. We have created uh
ability to create mitigations where you
can actually maybe just change the
permission of a file maybe you disable a
service but with that the potential of a
compromise becomes a lot less and you
don't have to patch right away. And the
third and the last piece there is to
build confidence in the IT team's
ability to deploy the patch without
worrying about an outage. We took the
half a billion patches that we have
deployed in the last few years where we
see every roll back, we see every uh
error that we get and we build an MLAI
based patch reliability score. What that
allows us to do that as soon as a vendor
releases a new patch, we can actually
tell you this is a high reliability
patch and does not need a reboot. So you
feel higher confidence that I can
remediate in zero days because it's a
high reliability patch and I do not need
a reboot and so with that we can you
know look at the end we are managing
risk. So it's not that we have to fix
everything but if we can take enough off
the table the potential of a compromise
goes down significantly. So auto
remediation can fix 20 30% of your stuff
but that 20 30% can really reduce the
potential of an entire chain of attack
happening successfully.
>> Absolutely. because we're seeing that,
right, that these, you know, AIdriven
adversarial attacks, they can chain
together these vulnerabilities. So, it's
a great point and um you know, I'm glad
that you called out sort of um how
you're validating the the um the
confidence, right? Because that is
something that we're seeing security
teams, especially if they're trying to
integrate AI as part of their processes,
which is necessary to do in order to
keep pace.
>> Um you know, they're kind of they're
needing to understand that they can
trust the AI. So are are you building
confidence with customers?
>> Exactly. Right. I think that's where the
the combination of um uh the data, the
analysis, the inference and the AI
models and like you know because we
built the harness. So we're we are part
of glass swing. We are in Daybreak. So
we are basically collecting and
leveraging these models of AI to build
mitigations and to build safe exploits
for customers because as you saw with
open AAI hugging phase like that that
whole thing it they don't care the
autonomous AI does not care about this
the system shouldn't go down. It'll try
10 different things. One of those could
bring the system down. So how do we
leverage this AI capability to build out
exploits that are safe with higher
confidence for the customers so that
they can test themselves without having
to worry about an outage. The same thing
for the mitigation high confidence
mitigations that are tested that are
created by reverse engineering exploits
through AI and then giving those to the
customers. So they have much higher
confidence remediation that they can do
and all of it is based on not just using
AI as is out of the box but building
confidence around the AI capabilities so
that you can use those for remediation.
>> That makes a lot of sense and sed can
you talk uh maybe just double click a
little bit more in terms of how you're
validating these vulnerabilities I know
you kind of mentioned that a moment or
two ago. Yeah, I I think a very simple
way to look at that is, you know, if
there's a bunch of different doors that
are there and, you know, the traditional
approach of prioritizing will tell you
maybe these 20 doors could lead to a
compromise, right? Uh I think what we're
now focusing on is saying like hey we're
just going to try to open those 20 doors
and we'll tell you by the way only five
of those open and that we are doing so
that now you have a much focused
approach and that's where that exploit
validation comes in where it's not a
complete red teaming exercise
>> but what we can do is when you see a
vulnerability we send a safe payload a
safe payload could be as simple as
saying hey can you resolve this DNS name
if we see the DNS resolution come
through we don't need to update your
system write anything we can tell we
could compromise it
Now that gives you a higher confidence
in saying like hey by the way my
controls didn't work. I got a qu I got
actually an exploitation that happened.
So that becomes my priority versus if we
send a payload edr blocks it firewall
blocks it and it doesn't execute then
you have more time. So that again
reduces the potential of an outage
because you're not fixing everything
you're fixing the one that works. And so
that's where we do a lot of the
validation by running very very safe
ways to actually test if the exploit
worksh
um kind of area you had an announcement
um this week my understanding is around
AI governance. we've been hearing kind
of a big focus on runtime and sort of
how do we put these you kind of
described a harness how do we put the
right guard rails in place because um
enterprises are just racing to try to
adopt AI
>> and so for our security teams they need
to not get in the way of that they need
to enable that so can you talk to you
know I guess maybe what you're seeing
customers struggle with from that
perspective
>> I mean I think we're at the early
innings of AI and so I think the initial
challenge is shadow AI right and how do
you figure out what's in my environment
And I think it's almost like not having
a shadow AI problem is a business
problem which means that you're not
actually using AI in the business which
is not good for business. So I think
today it is very important that every
business actually is using AI and then
you know we kind of were at the
beginning where everybody wanted to do
shadow AI because they're like I want to
know who's using AI so I can block them.
Then we saw the pivot to saying well I
want to know who's not using AI so I can
you know send them somewhere else.
>> Yes. Right. So, so now we're kind of
rolling back to saying like, look, I I I
need to be able to have the visibility
of who's using AI, what are they doing
with it, can I put some guardrails
around it, where are my models, where
are my GPUs? And I think I've done this
long enough in cyber that no matter what
new technology comes, it's always has
these components which is discovery,
whether it was cloud, whether it is
going to be quantum in a few years,
question always where do I have it? Can
I assess it? I cannot fix everything.
Can I prioritize it? and then at the end
if I don't get it fixed what was the
point of this dashboard tourism right
>> we were just looking at dashboards we're
not doing anything so that same thing is
happening with AI so what we did with
total AI is to leverage the qualice
footprint customers have and created the
ability for them to figure out their
shadow AI what's happening on the client
machines where are you running AI in the
cloud environment etc so you can first
get the visibility once you get the
visibility we can test the models we can
see if the model is doing something that
it should not and then we can help you
build out policies
to be able to say we have some
governance capability where unauthorized
AI engines are not being used. You know
the AI engines are not being fed data
that they should not be. So it's it's
something that is going to come up more
and more in the next few months as
priority for customers as soon as they
get through the the current challenges
that they have. Uh AI uh security and
governance is going to be definitely
something that is going to be important
for a lot of customers. I agree and
we're certainly seeing that as well that
customers are trying to turn the lights
on, right, and kind of solve the the the
shadow AI piece of it. Um, when you
think about kind of the stack that's
needed to govern AI, what do you think
are going to be maybe some of the key
control points?
>> Yeah, I I think there are a couple
control points here that are very
important. First, you know, discovery
inventory, having an upgraded inventory,
then you had the hardware components of
AI. I think we also have to think about
that some of these are not necessarily a
security issue there. Some of these are
just a business. How many tokens am I
spending is more important sometimes
than the security part of it. So the
inventory is something that is going to
be important after that. Do I know all
my models? Where are they running? It
becomes important. Um testing the models
to ensure that they're not giving you
answers that you should not be giving
becomes important. But then the last
piece that is also very important is
that what data is being used to train
these models becomes very important. So
if I know a model is being trained, is
it being trained on my employee
information that should not be uh if
it's a support chatbot and I ask it
what's the employee salary? Is it going
out and talking to an MCP server to give
that information that becomes a uh
control point and then at the end we are
going to have to produce reports to for
regulators. We're going to have to
produce reports for the board to show we
know where our AI is to show we have
tested it to show that we have actually
put guardrails around it and that we are
continuing to monitor it right but at
the end AI is one risk you still have
cloud risk you still have identity risk
you still have misconfiguration risk so
all of that needs to come together in a
singular risk view
>> that where what what we really see today
is the the building of a rock like you
have the sock which is after bridge
proactive risk management is risk
operations center so How does AI
security plug into that? And then in 3
years it's going to be you know quantum
security but at the end companies has
have a limited budget and where should
they spend that money it's going to be
based on where is the risk. If AI is the
risk spend more on that if quantum is
the risk spend more on that and the rock
actually helps you get that visibility.
>> Walk us through the rock because I know
I've had some conversations with your
with your team um about the risk
operations center and sort of how it's
complimentary
>> to the security operations center. It
doesn't necessarily displace it. But
Sume, I'd love to sort of hear from the
horse's mouth today.
>> Yeah, you know, we were having really
great conversations because the the sock
I know I described that as snipers,
right? Like they are focusing on is
somebody in my environment now and how
can I get rid of them? Like that's their
main focus. They are not thinking 3
months, 6 months from now etc. And so
what has happened is that we have done a
good job in creating socks with SIM and
XDRs and you know looking at uh log data
etc. M
>> but when you come when it comes to
proactive risk management the question
is you know I have cloud risk in one
dashboard I have uh identity risk in a
different dashboard I have on-prem risk
in a different dashboard and so we are
in we end up with dashboard tourism like
I just have dashboards but if I ask you
you have a business unit that makes 500
million a year
>> what's the potential of a dollar value
loss on that business unit you cannot
say because every risk with a different
score is in different areas right so the
idea of the risk operations center is
how do we elevate the conversation of
risk. How do we take vulnerability as
only one component of risk? Second
component is misconfiguration. Third
component is identity. Bring all of that
harmonize all of that and then get into
threat intelligence, business context,
remediation and compliance. All through
very focused on risk itself and then
>> acknowledge that risk management
exercise has three components. One is
mitigation proactively. M
>> second is consciously accepting a
certain risk and the third is what you
cannot accept and what you cannot
mitigate you need to transfer to cyber
insurance company so the rock will allow
you to have a conversation with your
cyber insurance company to say here's my
sustained risk level here's the
additional residual risk that is left
that I cannot accept and what is the
cost of transferring that risk to a
cyber insurance company so the risk
operation center is more of a strategic
uh plan for CSOS over the next couple of
years is implementing a rock so that
they can answer the question that the
board wants. They don't want to know the
number of counts and etc. The board just
wants to say is 90% of my revenue under
my risk appetite
>> and that's it really kind of cuts to the
chase and it puts it in those board
level terms.
>> Yes.
>> So um so you kind of referenced that
you're having some great customer
conversations around the rock. What are
some of the points of visibility if you
will um that you think security
practitioners don't have today that the
rock is giving them? Is it kind of
connecting those points that you
mentioned and
>> well exactly right like so if you have
an an application that's making you 500
million a year
>> there's a separate tool that looks at
the cloud piece there's a separate tool
that looks at identity piece and
separate tool that looks at
configuration piece and so
>> if you are asked the question like I
mean you have individual visibility but
if you say how much loss could I have if
there is a ransomware attack on this 500
million business unit and where is that
risk coming from you you cannot explain
that because it's distributed across
multiple tools.
>> The good thing about the rock is that it
takes data from existing tools, pulls it
into a single uh platform, normalizes
the different risk scores cuz some are
on 10, some are on 100, normalizes all
of that and then puts them in the
context of your overall risk appetite.
And so the visibility is there from an
individual perspective but then when the
CISO's job is to uh is to really bridge
that gap between technical findings to
what it means to the business and the
rock really enables giving them that
visibility of of having those technical
findings translated into business
language and explaining to the board how
much dollar loss it could have and then
where are we in our journey to ensure we
reduce the risk of that loss. There is
nothing like zero risk. So, and and I
always say to people, by not doing
anything, you're already accepting a
risk.
>> Yes, absolutely. I mean, like we were
talking about, you know, businesses are
recognizing that they have to accept a
certain level of risk. And I think it's
really powerful to be able to translate
this into dollars and cents because it's
really difficult to do when we think
about something like a ransomware attack
in your example.
>> Yeah. I mean, yes and no. At the end of
the day, the reason you have to put
cyber in dollars and cents is because
cyber is being used to protect dollars
and cents. So that's like, you know,
when you get a car or an insurance, you
have to say, "I'm going to pay $1,000 to
insure a car that is worth 50,000,
right?" Like, if if you don't know what
the car is worth and you don't know what
you're trying to protect, then you are
taking infinite risk. And so I think
>> it it's it is it has always been
warranted. It is becoming more and more
important now that you cannot fix
everything. You have to be able to
explain the prioritization in the terms
of saying why am I focusing on this or
why am I not focusing on this because
the business loss is not there. And I
think we have now built up over the last
20 years enough data points um through
insurance and ransomware payouts that uh
we have uh data available as we partner
with a company that gives us that kind
of information where we can say if you
are a business that is in this segment
in this geographical location on an
average how much ransomware payout has
happened for industries in your business
and so you can project from that if I
have a $500 million business unit
typical ransomware payout out has been
around 10 million. Okay.
>> And so now you can pull now. So do you
want to spend 10 million? No. But maybe
you could say look if it's a 10 million
payout probably I want to spend a
million to make sure that I don't have
the 10 million payout. So
>> I I think that that more and more of the
data points are available and we're
bringing it together. Uh but I think you
know I'm I'm excited to continue to work
in that direction.
>> Yes. Yes. Certainly. So, Sad, you've
kind of described yourself as a frontier
AI optimist, right? And I think there's
a lot of potential doom and gloom here,
but reading between the lines. Does that
indicate you think as an industry over
the next, you know, call it
>> 6 to 18 months um that we're going to,
you know, have some practical learnings
and really kind of make some progress in
terms of our ability to prioritize and
respond everything we've been talking
about today.
>> I I am very much of an optimistic when
it comes to that. I think a little
unfortunately some of the frontier
rollouts have created sort of sort of
halves and have nots and so there are
geographies countries in industries
where they don't have access to some of
these models. The good news is that
platforms like Qualis and some of the
other cyber platforms are able to
leverage these models to create more and
and democratize the outcomes of these
frontier AI models so that customers can
leverage this within their environment
without them themselves having to invest
in using leveraging these models. And so
I think I'm optimistic because uh yes
attackers can are using AI for you know
creating attacks but defenders also have
access to similar technology just
looking at it from a different
perspective. And so one of the
optimistic views that I have is in
theory if every organization that writes
code has the ability to run this kind of
a frontier AI model on their codebase
they will find all their vulnerabilities
themselves and you will never have zero
day vulnerabilities because the zero day
happens when attacker knows something
you don't but if you're running AI
models you will always know
>> the flip side is that then the the risk
moves towards the zero day remediation
because as soon as you release a patch
they will reverse engineer using AI AI
but the good news is that we at callers
can also do the same. Once a patch is
released we can reverse engineer using
AI find the exploit and then use that in
a positive way to create uh compensating
controls and to create a testing
methodology that is safe. So I do feel
like AI is definitely bringing positive
outcomes for cyber security for a lot of
organizations and they don't necessarily
themselves have to be um you know
investing and running into these AI
models. they should hold their partners
and vendors responsible for ensuring
that the right appropriate amount of AI
is being used to give them an outcome
which is at the end of the day what they
care about
>> and that's a really fair point to maybe
kind of a a concluding thought so if I'm
a practitioner and I'm evaluating
vendors for trying to help me navigate
my risk management
>> there's a lot of you know
>> AI washing especially if I'm in the CISO
role I'm being just inundated
>> what would you look for
>> in a vendor to kind of sift through that
noise and really make sure that you know
this vendor is going to actually deliver
something that's actionable.
>> That's a great point. I think you know
you have to before you even go look for
a vendor you have to ask yourself what
is the outcome I'm looking for right and
can I have a solution that will find a
malware is not an outcome right if I'm
looking at business risk I'm looking at
the for me to avoid a $500 million loss
I'm going to create four layers of
controls as my defense in depth and
these are the four ones and then you
have to be able to then look at the
vendors and say are these look at the
end of the day AI or not AI Right? When
you're looking at a vendor, there are
three things everybody's looking at.
Number one, is it accurate? Because if
the solution is not accurate, doesn't
matter how cheap it is. Number two, that
is the solution fast enough. If it's
accurate but takes 6 months, it's not of
no use. And then the last point is is it
cost effective? So, is it actually
helping me do the first two but without
having to spend more money than I earn,
right? And so, I think when you're
evaluating a vendor, those outcomes are
what you should be looking at. and the
vendor who's leveraging AI the right way
uh and like so for example there are
vendors in our space that are charging
the customer back by token now as a
customer you don't want to deal with
that you're looking for an outcome so
what we do as an example is we create a
harness in the back end that picks the
appropriate model so we're not charging
customers by the token so they are
getting an outcome that is a predictable
outcome from a cost perspective and
they're getting accurate fast and cost
effective ways that they can actually
take the solution And that ultimately I
think is what everybody should be
looking at is what is my final outcome
in risk management and um does this
vendor help me do things that are
accurate, fast and cost effective.
>> Well, Summed, thank you so much for
sitting down to walk us through all this
today in the cube. We really appreciate
it.
>> Thank you for having me. It was a real
pleasure. Thank you very much.
>> Absolutely. And thanks so much for
joining us. We'll be back in just a
couple minutes with some concluding
thoughts from day two here at Black Hat
2026.