The ITSPmagazine Podcast

Autonomous Remediation Is Already Running at Enterprise Scale | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Sumedh Thakar, President and CEO at Qualys | Hosted by Sean Martin

Episode Summary

Ninety days to fix a vulnerability turned into ninety seconds, and the window between disclosure and exploitation now closes faster than most teams can staff for. This conversation covers what shifts when detection, prioritization, and remediation stop waiting for someone to approve each step.

Episode Notes

Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams.

So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it.

Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first.

How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities.

He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop.

His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC.

This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing

GUEST

Sumedh Thakar, President and CEO at Qualys
On LinkedIn: https://www.linkedin.com/in/sumedhthakar/

RESOURCES

Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas

Qualys: https://www.qualys.com/

InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure

Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection

The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center

Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings

KEYWORDS

Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management

Episode Transcription

Autonomous Remediation Is Already Running at Enterprise Scale | A Brand Briefing at Black Hat USA 2026 with Sumedh Thakar, President and CEO at Qualys | Hosted by Sean Martin
[00:00:00] Sean Martin: Sumedh, pleasure to see you.
[00:00:12] Sumedh Thakar: Thank you very much.
[00:00:13] Sean Martin: Always love what Qualys is up to, and I'm excited to hear what's happening here.
[00:00:16] Sumedh Thakar: Same, same here. We're excited. We always love to innovate. That's the way we do things, so, uh, looking forward to every Black Hat.
[00:00:23] Sean Martin: Yeah. So I'm sure people know who you are.
[00:00:27] Sumedh Thakar: I hope so.
[00:00:28] Sean Martin: I hope so as well. Uh, but maybe just a quick word about your role
[00:00:32] Sumedh Thakar: Yeah.
[00:00:33] Sean Martin: as CEO at Qualys. And what that means to you at the moment.
[00:00:35] Sumedh Thakar: Yeah, I, I, uh. I'm the CEO now, but I've been at Qualys for 23 years. I started as one of the initial, uh, software engineers on the scanner back in the day when people used to scan once every 90 days and gave 90 days for it to fix everything.
Now we're talking about 90 seconds, but it's been a great journey and I'm excited to lead Qualys from a innovation perspective, uh, changing with the industry and helping customers [00:01:00] create solutions that really make their life a lot easier.
[00:01:02] Sean Martin: Yeah. Yeah. Qualys has been a leading innovator for this industry for sure. Dating back many, many years. Of course. Yes. And, uh, you haven't stopped, so what are you, what are you seeing in the market that leads you to how you look at innovation?
[00:01:18] Sumedh Thakar: Yeah.
[00:01:19] Sean Martin: At Qualys today.
[00:01:20] Sumedh Thakar: It, it's interesting. In many ways, the basics of cybersecurity have not changed, even though the new technology that keeps coming changes.
But no matter whether it's a brand new technology that comes, whether it was virtualization, it was cloud, now it's AI. It's going to be quantum in the future. The basic questions that cyber teams have remain the same. Where's my stuff?
[00:01:39] Sean Martin: Right?
[00:01:40] Sumedh Thakar: Nobody knows. Right? So that's the big challenge. Second is, once I kind of figure out my inventory, um, what is my assessment of my inventory?
Third thing that comes out of that is no matter who you are, you will never be able to fix everything that comes out of an assessment, which means that prioritization is important, whether it's AI or [00:02:00] cloud prioritization becomes important. And then at the end of the day, you can do all of that and you can build dashboards and like I like to say, you can have dashboard tourism, but if you don't fix it, it's of no use to you.
So. Ability to remediate is, is always been there. I think what has changed now is the speed at which all of this is needed because the speed that technology is enabling attackers to use frontier models and to be able to do things that actually, um, are, are helping them get quicker and faster. And so it's just a, it is a game of cat and mouse.
[00:02:31] Sean Martin: Yeah. When I was building software, it was always the dashboard. Where's the, where are the reports? Where are the
[00:02:35] Sumedh Thakar: Yeah.
[00:02:36] Sean Martin: That's not gonna help you in 90 seconds.
[00:02:38] Sumedh Thakar: Yeah. It's not because. Today, if you look at the CISA BOD asking, uh, uh, government agencies to fix things in three days, if you look at, uh, uh, people talking about zero day remediation, can I get things fixed in the first 24 hours?
You just cannot do that, uh, by having, uh, somebody, uh, look at a dashboard. And so some form of autonomous [00:03:00] remediation is going to be very important. And again, forget the technology, whether it's AI or this or that. I think the. Uh, when the attackers are using AI and, and you know, when your board is saying, Hey, how are you gonna fight autonomous AI based exploitation?
Your response cannot be, we are going to hire more people. Your response has to be, we are going to enable some form of autonomous remediation capability as a roadmap. And that's where that dashboard is not part of that. You gotta be able to make decisions to fix things quick and fast.
[00:03:32] Sean Martin: Yeah. Just like, you know, probably at. Hopefully do it justice, but just like Qualys initially helped security teams scale.
[00:03:39] Sumedh Thakar: Yes.
[00:03:40] Sean Martin: vulnerability management, we're in that same position now, especially looking at AI.
[00:03:43] Sumedh Thakar: Yes. Very much. It's about leveraging the technology for an outcome. Right? Right. So back then, it wasn't about the fact that, you know, SaaS and we were the first one in SaaS and cloud, it was that using the SaaS and cloud technology, we enabled a scale that was not possible.
Back then with on-prem [00:04:00] solutions, people were able to actually scan their stuff every hour, four hours. So now what we are doing is really enabling that scale, leveraging AI to say, yes, you can detect, prioritize, and get things fixed in the first 24 hours.
[00:04:14] Sean Martin: Right.
[00:04:14] Sumedh Thakar: Because of AI. Yeah.
[00:04:15] Sean Martin: Well those are the three pillars.
[00:04:16] Sumedh Thakar: Those are the three pillars. Yes.
[00:04:17] Sean Martin: Maybe, uh, maybe share a little bit about each one.
[00:04:20] Sumedh Thakar: Sure.
[00:04:20] Sean Martin: What they mean to your customers.
[00:04:21] Sumedh Thakar: Yeah. I, I, I think at the end of the day, the outcome has to be things are fixed before attackers get there. Whether you use, uh, a bunch of, uh, you know, humans, or if you're using AI, the, the goal has to be that.
So now, if you are gonna want to get something fixed in the first, uh, 24 hours, then you need to be able to detect it first, right? If your detection takes three days, that's no point, right? AI speed detection becomes very important. You cannot wait for two days to, uh, scan to run and have findings. Second pillar becomes the hyper prioritization.
[00:04:58] Sean Martin: Hyper prioritization.
[00:04:58] Sumedh Thakar: Yeah. Because even before, [00:05:00] uh, frontier models came out, people were barely able to fix 5% of what they were finding. Now with the findings going up there, it's even lower. So even that 5% is becoming a lot. So instead of theoretical, um, prioritization with scores, can you actually just run an exploit and test if your other controls are blocking it or not,
[00:05:20] Sean Martin: right?
[00:05:20] Sumedh Thakar: So that becomes a second pillar, which is kinda hyper prioritize. If it's 1% based on theoretical stuff, it's like 20% of that 1% is actually exploitable in your environment because you paid money for firewall, you paid money for, uh, EDR.
So now you have that. And then the third pillar is I need to get it remediated,
[00:05:38] Sean Martin: right?
[00:05:38] Sumedh Thakar: So once I reduce, so autonomous remediation, step number one, fix the least. More you fix, more chance something will go wrong. So hyper prioritization helps that. Second is, can I have an option with a mitigation or a compensating control that does not need a patch?
I reduce my risk further. Number three is if I'm going to have, still have to patch, can I get a confidence? Which what we do is with using AI, we [00:06:00] built a patch reliability score, so I have better confidence that this patch has a high reliability, and it does not need a reboot. Then I could actually apply it and it's, by the way, it's on a, a laptop.
I, I can do this autonomously. I don't need to have a human involved. So at the end, if you don't go fully autonomous or everything, even if 20, 30% of your stuff becomes autonomous, you have more time to focus on the rest of it, to do that quickly. So those are the three pillars. AI speed detection, hyper prioritization, and autonomous remediation.
[00:06:30] Sean Martin: So what's the impact to some of your customers? Maybe a use case or a case study if you want.
[00:06:35] Sumedh Thakar: Yeah.
[00:06:36] Sean Martin: Name or anonymous.
[00:06:37] Sumedh Thakar: Yeah.
[00:06:37] Sean Martin: Um, what are some of the results you're seeing?
[00:06:40] Sumedh Thakar: Yeah, that's a great point. Look, I think. We kind of innovated in the patch management space like four or five years ago when everybody around here was telling us that's not a good idea, right?
So, uh, fortunately I didn't really quite listen to them, but because of that, what has happened is that we have, we have deployed over half a billion patches. Uh, we, in the last 12 months, we deployed 150 [00:07:00] million patches. But the most interesting thing was. 40 million of those are already autonomously deployed with no human intervention.
So autonomous remediation is not the future. It's already here. And I'll give an example of a customer. They are a global company with 450,000 employees. Like I don't want to be HR for that company. Right,
[00:07:18] Sean Martin: exactly.
[00:07:19] Sumedh Thakar: But 450,000 employees globally distributed consultants always on the go and each and every one of their, uh, laptops, uh. For their, uh, employees has a Qualys agent that is doing autonomous patching. And the way that autonomous patching works is that as soon as, uh, Google Chrome releases a patch, as an example, uh, our agent will not even run a vulnerability scan and, and do all that dashboarding. It'll just download the patch and apply it because if your organization is gonna stop working because you auto applied a patch on Chrome, then you have a different problem, the security is not your problem.
So. What is interesting about that is that what they, what they show to their board is not the [00:08:00] counts of vulnerabilities or patches. What they tell their board is that we can, uh, uh, basically our exposure on the, uh, on our employee laptops is maximum of four hours from the patch that, uh, from the time of patch release to the time that they're exposed. That's a great example of how you can basically say, our job is, there is nothing like zero risk. Our job is to reduce risk and if I can show that my risk is reduced to four hours by using autonomous patching on systems that otherwise should not cause a business outage, that's a big win. Right?
[00:08:31] Sean Martin: Long way. Since Patch Tuesday every week,
[00:08:34] Sumedh Thakar: Patch Tuesday is becoming bigger and, and patches. I don't think the Patch Tuesday and waiting for a month is going to sustain. Right. We're gonna see. Uh, we are gonna say disclosures come out even faster. And that's why when we released InstaScan recently was that, can I give you the disclosure? Uh, or the, the finding within an hour of the vendor doing a disclosure.
[00:08:54] Sean Martin: Yeah.
[00:08:54] Sumedh Thakar: So that's the new technology where I call it scanless scanning. But the idea that you can actually, and that becomes [00:09:00] very important because you cannot wait.
[00:09:02] Sean Martin: I wish I had more time. I wanna dig into scanless scanning.
[00:09:05] Sumedh Thakar: Yeah. It's,
[00:09:05] Sean Martin: It's, uh, I think we, we only have a minute left, so I wanna give you a chance to maybe, uh, speak to the CISO community.
[00:09:11] Sumedh Thakar: Yeah. And
[00:09:13] Sean Martin: maybe give them a tip of something they should be prepared for for the future. I dunno if it's Frontier ready or something else that you wanna share.
[00:09:20] Sumedh Thakar: I, I think the number one thing for CISOs to re remember is that they are a business partner. And when they talk about business, it's less about the specific technology and more about the concept of risk management.
And I. Technologies will come and go, but the idea that the CISO needs to provide the board and the CEO visibility into the overall risk of loss to the business and how much they're spending and is the loss, all the risk under acceptable appetite is more important, whether it's AI or on-prem or cloud.
The question always is, I have a $500 million business. How much? Uh. Loss would I have if there was a breach, and then today is my risk level under an [00:10:00] acceptable risk appetite and the rest of it can I transfer to my cyber insurance company? Honestly, that's where CISOs should be focusing on and not the latest and greatest like magic technology that people have. Like nobody can detect the shadow AI like us, et cetera. It's about can I continuously give my board the confidence that I'm under a acceptable risk appetite? And if I'm not, I'm going to spend this much money to bring the risk of $80 million down into an acceptable level. That business partner is really what I tell CISOs. Yeah.
[00:10:30] Sean Martin: I love it. Sumedh, you're amazing.
[00:10:32] Sumedh Thakar: Thank you very much.
[00:10:34] Sean Martin: The future's bright for you and the Qualys team.
[00:10:35] Sumedh Thakar: Yes, of
[00:10:36] Sean Martin: course. And, uh, I encourage everybody to connect with you and, and your crew.
[00:10:40] Sumedh Thakar: Yes.
[00:10:40] Sean Martin: Be prepared for the future.
[00:10:42] Sumedh Thakar: Of course.
[00:10:42] Sean Martin: You ready for today? Get your own ROC. I love the ROC story
[00:10:45] Sumedh Thakar: too. Yeah. The ROC is like, yeah, it's really good. You have a SOC. How about a ROC? Right. Build a ROC.
[00:10:50] Sean Martin: Exactly. So yeah, we've had many chats, I've had many chats with the team, so I'm gonna encourage everybody to listen to those.
[00:10:54] Sumedh Thakar: Awesome. Thank
[00:10:55] Sean Martin: you. Thanks everybody for, uh, joining us and stay tuned. Uh, for more from [00:11:00] Black Hat USA 2026.
[00:11:03] Sumedh Thakar: Thank you very much.