September 09, 2026

00:42:34

Episode 384 Deep Dive: Sumedh Thakar | Mythos Turned 30 Days Into 24 Hours.

Episode 384 Deep Dive: Sumedh Thakar | Mythos Turned 30 Days Into 24 Hours.
KBKAST
Episode 384 Deep Dive: Sumedh Thakar | Mythos Turned 30 Days Into 24 Hours.

Sep 09 2026 | 00:42:34

/

Show Notes

When Mythos hit in April, the security world split between panic and hype. Sumedh Thakar, President and CEO of Qualys, joins KB to make the calmer case that Mythos accelerated an old threat rather than inventing one. They get into why zero-day vulnerabilities now need zero-day remediation, the misread that Mythos runs on your own code while your vendors use it too, the board conversation it reopened, tokenomics and budget pressure, and how much a CISO should really hand to the machines.

About Sumedh: As a cybersecurity visionary, Sumedh is passionate about making the world’s digital journey safer. His education and early experiences as a coder led him to Qualys, where he rose from engineer to president and CEO. He joined Qualys in 2003, shortly after the company’s founding and in an era when organizations started using the cloud but didn’t know what to call it. His contributions and leadership helped propel Qualys to its current success in cybersecurity.

Sumedh became president and CEO in 2021. In 2019, he was named president, and prior to that, he was chief product officer, driving the company’s vision of making enterprise security more efficient and disrupting the VM space with integrated capabilities like patch management and cybersecurity asset management. A “product fanatic and engineer at heart,” Sumedh was instrumental in dramatically expanding the original Qualys platform’s scope, integrations, and automations. He also scaled the company’s engineering talent internationally with a global 24×7 follow-the-sun product team. He is a co-inventor of five U.S. patents for cybersecurity technology in Qualys offerings.

Previously, Sumedh was an engineer at Intacct, an early cloud-based financial and accounting software provider. He also worked at Northwest Airlines developing complex algorithms for its yield and revenue management reservation system. He has a bachelor’s degree in computer engineering with distinction from Savitribai Phule Pune University.

Keywords: Mythos, AI security, cybersecurity, zero-day, autonomous remediation, vulnerability management, CISO strategy, board reporting, Qualys, Sumedh Thakar, patch management, true risk, exposure management, AI attacks, first-party code

View Full Transcript

Episode Transcript

Sumedh Thakar [00:00:00]: If attackers are reverse engineering patches to create exploits and attack you within the first 24 hours of a new patch coming out, you don't have the 30 days that you used to have to fix critical patches. VO: From KBI Media, I'm Karissa Breen, and this is KBKast. KB [00:00:18]: My guest today is Sumedh Thakar, President and CEO of Qualys, and one of the clearer voices on what Mythos actually did to enterprise security. We talk about why he believes Mythos accelerated An old threat rather than inventing a new one. The strange twist that the same models could make zero days disappear while your vendor's patches come at you faster than ever. And what a CISO is now expected to walk into a boardroom and say. VO: Before we get into it, do me a little favor and hit follow wherever you're listening. It genuinely helps the show reach more people who need to hear these conversations. Alrighty, let's get into it. KB [00:01:04]: So, Sumedh, I want to start by— now, I know things change every day in our industry, and there's been some changes lately, but give us a bit of an update on the lay of the land in the Mythos world and where's it at as of today. Sumedh Thakar [00:01:18]: You know, I think a lot of the security world changed and blew up when, uh, the whole Mythos thing came about. In, I think, April. And I think what has happened since then is that the realization that this is not necessarily a one-off and not necessarily restricted to a particular company or a technology. I think what has happened post-Mythos is just that overall realization that ability for AI to perform a lot of the breach-related activities a lot more quickly and a lot more autonomously is here to stay. And this is not a you know, flash in the pan, that this is something that we all have to adjust to this new reality of attackers leveraging AI. And, you know, we have to find ways that are going to address this not as a short-term thing, but as a continued change in the way that we're doing some of our security programs. KB [00:02:08]: And when you say flash in the pan, do you think when MITRE emerged in the early days, do you think people in the industry thought, oh, it'll fade? Or what were sort of the sentiments there? Sumedh Thakar [00:02:20]: I think it ranged, you know, quite in the pendulum was swinging all the way from people who were like, oh, this is not a big deal. You know, it'll go away. Maybe people didn't understand all the way to people who were absolutely panicked about it. And, you know, that this is the end of the world type thought process. I think where we have landed on right now is more sort of in the middle where there is a huge reality to what these models, not just Mythos, but other models are able to, are going to be able to do. But also the fact that there are ways that we as defenders can actually leverage actually similar technology or same technology in many ways to be able to defend against this change in the threat. I wouldn't say it's a new threat. It's a change in the way the threat is coming at us. Sumedh Thakar [00:03:02]: And so I think today, now we are more settled on sort of understanding that we have to fight this AI speed with defenders also using AI speed. And as a CISO, When you are being asked by the board, you know, how are you going to defend against AI-based autonomous exploits? Your response cannot be, we are going to hire more people. Your response has to be something that is aligned with saying, we are going to fight autonomous AI exploitation with autonomous AI-based autonomous remediation capabilities. KB [00:03:33]: And Sumedh, do you remember when, not even that long ago, boards were sort of asking the question on like, are we doing AI? And now we've introduced the mythos concept. Has their sort of stance sort of changed, would you say? Because now it's a little bit of a different ballgame to originally what we were talking about with AI entering into the equation. Where does your mind sort of go? Sumedh Thakar [00:03:54]: Yeah, I think when you look at it at the board level, you know, the board obviously is concerned not just about cybersecurity, but overall as an organization. Is the organization leveraging AI to advance business is sort of the primary thing, right? And then, How do you protect that business from AI-based threats is the second thing that they're asking. And so, it's kind of funny in the way that, you know, we have seen this evolve where initially customers were like, I need to find out who's using AI in the company so I can block them. And then in a few months that pivoted to, oh, I need to find anybody in the company that is not using AI so I can take action against them. Right. And so, I think we have seen that happen. And then we are also sort of seeing this like, oh wait, I actually over-rotated on AI and now I'm Running out of tokens, out of my budget. And so, a lot of the conversation at the board level is happening around AI definitely has the ability to help your organization get a competitive advantage and move faster. Sumedh Thakar [00:04:49]: And in some cases, you as a company might not survive if you don't leverage AI. On the other hand, there are also concerns about, you know, how do you calculate ROI? Are you actually investing in the right ways to get the right benefit? And then, Mythos, one thing that it did do was almost every board member heard about it. And so the question they are asking their security team is, well, what does that mean to the organization and what are we going to do to fight against that? So I would definitely say that this is one of the things that Mythos has done is definitely created a board-level conversation again, to make sure that the company is protected against the risk that is coming from AI-based attacks. KB [00:05:31]: And when boards say, what does this sort of mean? And I know that when this first came out, people that I was talking to were saying like, well, we don't really have answers. So how are security CISOs and friends really answering that question considering there wasn't like a, well, this is the solution, this is how we move forward, so to speak? Sumedh Thakar [00:05:51]: Yeah, you know, I made this point a little bit earlier that it's not necessarily that a new threat, so to say, has come about. What has happened is the same threat of using vulnerabilities and misconfigurations to hack you, which has always been there. What Mythos-type models have done is that they have accelerated that quite significantly. And so in many ways, the response to that is also not necessarily a new response. You know, the best way for you to protect yourself against any exploitation is to make sure that you fix your misconfigurations and you patch your systems. It's just that If attackers are reverse engineering patches to create exploits and attack you within the first 24 hours of a new patch coming out, you don't have the 30 days that you used to have to fix critical patches. So now the response really from a CISO perspective to the board really is going to be about, those type models are enabling much faster exploitation, and which creates a risk that probably was not as prominent in the past. And our response to that at the end of the day is, you know, it's just physics, right? If they're attacking you faster, you got to fix it faster. Sumedh Thakar [00:06:59]: And so now the reality is that how do we balance our ability to remediate these vulnerabilities quicker with the risk of creating outages, which is the big reason why people in the past were a lot more resistant to patching, is like, well, what if I patch something for security reasons and my system goes down? So, Now you are going to have to sort of figure out how to balance that equation. But at a high level, you know, zero-day vulnerabilities have to now be addressed with zero-day remediation, which is the ability to remediate in the first 24 hours. KB [00:07:31]: And would you say that people— is there areas that people still don't quite grasp about Mythos? Because I know that there were just conflicting opinions on what people thought. And like you said earlier, that was a flash in the pan. Is there anything still that perhaps in any fidelity people are missing? Sumedh Thakar [00:07:47]: You know, I think that there's definitely still ongoing questions and we're still at the point where a lot of countries and companies and organizations don't have access to these models from Anthropic and OpenAI for different various reasons in the way that they're being rolled out, et cetera. So we continue to kind of get questions around that because these people have heard about it, not seen it. But also what is emerging is that there are open source models also that need a little bit more work but are capable of creating similar outcomes. I think there has been some misconception about, like, you know, somehow people not necessarily always understanding the difference in the fact that Toast is there to look at your own source code to be able to find issues so that you can actually fix those for yourself, which is the first-party code that we have, but not necessarily something that, you know, you can run against some other company's code because you don't have access to that. So, The risk that you have to balance is how do you leverage a model like Mythos to improve your own code, which nobody else has access to, which is why I'm hopeful because I feel like that's zero-day vulnerabilities in theory could go away if everybody used a Mythos-like model and fixed it. So, you know it before attackers do. But then all of your third-party code, which is anything that you run from Linux, Windows, all these packages that you run from third parties, they are also using Mythos. So, they are also finding issues in their code and they are pushing out patches really fast. Sumedh Thakar [00:09:14]: And big issues compared to the past. So you need to have both where you are fixing your own code rapidly, but also you're addressing your vendors creating advisories with patches that you need to patch very quickly. The threat is moving less now towards, you know, the attackers know something I don't, to attackers are reverse engineering the patches to create exploits to hack me through a patch that's already available, but I was too slow to apply the patch. So that's where more of that risk is shifting now. KB [00:09:44]: Okay. So staying with that for a moment, as you said before, companies were hesitant to do the patch in case there was an outage and the system goes down. Then obviously, as we know, people are talking about like continuous business. We can't afford any downtime. So how does that conundrum sort of balance out? Because you kind of need to do one thing before doing the other. And yes, there's still risk to both of them, but how would you say companies are approaching this? Sumedh Thakar [00:10:09]: Look, I think the word you use is the most appropriate word, which is risk, right? At the end of the day, there is no 100% solution for anything. And so all it is about hedging your risk and balancing that particular risk. And, you know, obviously the reason why we are not patching everything that comes out is there continues to be a fear of an outage. And in the very like broader picture, 50,000 feet, I would say that we need to move into a world where Our applications are resistant to patching and we don't have to worry about outages where you can patch anything and everything. And there are built-in mechanisms that will balance out in case there is an issue, right? We are not quite there yet, I would say. However, compared to 20 years ago, now a lot of people moving into the cloud with containerized environments and pods and cloud backups and different regions. We are in a better place to manage any outages. You know, you could easily take out a node and the The application will still continue to function, et cetera. Sumedh Thakar [00:11:05]: But a lot more has to be done to get to the point where we can patch everything without ever having to worry about an outage. So that's technology changes that need to happen. So I won't address that necessarily right now, but in the short term right now, we still continue to balance that fear in how do I fix quickly and autonomously, or at least reducing the fear of an outage, right? And that's kind of where, first of all, if you want to fix things quickly and autonomously, Fix the minimum things, right? The less you fix, the less chance something will go wrong. Second is, are there alternatives to patching that can still block an exploit from working? And then the third thing in my mind is, are there mechanisms— and again, where use of AI/ML that we have been working on— are there mechanisms that give me higher confidence in applying a patch because I can predict that this patch is not going to create issues versus I can predict that based on everything that we have seen, a particular new patch that came out has a higher chance of creating issues. And so that gives customers the ability to have enough things to balance out the risk of creating some sort of a mitigation and a patch while feeling like, hey, this patch is high reliability and does not need a reboot. So I feel better about applying it quickly, and I think the risk of this is going to be low versus you might say, look, I think the risk of this is going to be very high. I need to do some manual work. The good news is that when you're working with risk, you don't have to necessarily fix every single thing. Sumedh Thakar [00:12:31]: I think if you can take even 30%, 40%, 50% of the risk off the table with autonomous remediation or quick remediation, the overall breach possibility goes down significantly because despite what people say that attackers have to be right only once and defenders have to be right every time, that's not true because just an exploit does not mean a breach. An attacker has to create an exploit. Go to the next system, create another exploit, use some misconfiguration. They have to go through 5 steps. If autonomous remediation with high-reliability patches can take out 20%, 30%, 40% of those, you have a very high chance that you might have fixed something along the way, which will block the attacker from getting to a full breach. KB [00:13:11]: And you said before, looking at, like, minimum things that people can start doing, and I know you and I have discussed before about prioritization of those risks and vulnerabilities, for example. So now that's even more prominent than before because, like you said, we can't do all of the things necessarily at once, but there could be some easy, quick fixes perhaps that people could do and then move on. Sumedh Thakar [00:13:30]: Yeah, that's a great point. Look, I think, again, I go back to the term risk, which is, you know, at the end of the day, we have been in this world the last, I don't know, almost 5, 6 years or even more than that, where we already do not have the resources to fix everything that the scanners are finding. I'm most— I don't know any company that's fixing everything because the volume of software has gone up so much. And so, there are a lot of theoretical attacks that are part of the detections that have no meaningful way to materialize in the real world. So, prioritization is not an option. And when you prioritize, you're essentially hedging risk. You're saying, look, I think that these are the highest-risk items, and I'm just going to fix those, and I cannot fix everything. So that was already kind of happening before Mythos came about. Sumedh Thakar [00:14:15]: Now, it's become even more important. And so what we were typically seeing that, you know, less than 1%, or at least let's say 1% of the total vulnerabilities detected in an environment were truly exploitable by attackers. But now, with the number of findings going up, even that 1% becomes a huge number. And so we have come up with theoretical scores, typically CVSS, EPSS, you know, all kinds of classifications to come up with a theoretical score. However, most organizations and any good organization's security program should have defense in depth, which means they have a firewall, they have an EDR, they have other things that can block the exploit. So just because you have a vulnerability that has a very high score does not mean that it might actually be exploitable. And so the next level of prioritization now is coming to not just say, I have a theoretical score, but can I go further to take that 1% and actually run the exploits ourselves safely? So that we can come out with a way to say, you know, and what we saw in our tests when we ran what we call true confirm capability, where we are actually running safe exploits, only 20% of that 1% were actually exploitable because a lot of the other stuff got blocked by EDR, got blocked by your firewall. So I think, you know, there is an opportunity here to hyperprioritize to what I call the true risk, and the true risk only comes if you actually are able to exploit that vulnerability in your environment with all the settings that you have. Sumedh Thakar [00:15:43]: And so number one for autonomous remediation is hyperprioritize with exploit validation. KB [00:15:48]: Okay, that's interesting. So just staying with that for a moment. Now, when you said it might not be exploitable, do you think historically this is where things got a little bit interesting because everything was very manual? We'd have to sit around and manually decide, versus now it's a little bit more autonomous. The machines are making the decisions and have those quick fixes. which then as a byproduct creates more assurance and more confidence, to your point. So then overall, that risk should start to go down holistically from what you're saying. Sumedh Thakar [00:16:16]: I mean, I think if you look at the process that has existed till now, a lot of it has been rooted in people being busy and politics and blame game and stuff like that between IT and security teams, right? I think that's always been part of that. And so the typical model has been like, you know, the security team will scan, they will have 10,000 CVEs, they will like Throw that 10,000 CVEs over the fence to the IT team. IT team hates it. They have so many other things to do, but their bonus is tied to it. So they will fix it very grudgingly. Then they come back, and the security team says, wow, what a good job. Here's your reward. And they give them 10,000 findings more. Sumedh Thakar [00:16:49]: And now we're in a world where instead of being driven by counts and instead of being driven by compliance standards requiring certain counts and stuff like that, the reality of the fact is that You could fix 10,000 things and make absolutely no impact to your risk, or you could fix 11 and actually bring your risk down by half. And so that is pushing everybody more towards now that risk-based prioritization is not an option. And so now when you are moving to risk-based prioritization, you can do a theoretical risk prioritization based on threat intel. You can further refine that by adding business context, just because a system has a high risk. But if it's not critical to your business, you don't want to focus on fixing it right now. And then further, by running validations, exploit validation. So with that, you are actually anchoring yourself on the true risk is what we are highlighting rather than a theoretical risk based on scores. And so you might highlight something as a super high-risk score, but when you test it, it got blocked. Sumedh Thakar [00:17:50]: So it's not a real risk for your organization because an attacker may not be able to get to it right away. You should still fix it, But you don't need to fix it in the first 24 hours. And I think this approach is enabling better conversations with the IT team because now the security team can basically say, you don't need to fix 10,000 things, but if you fix these 11 things, you will be the hero that brought down the risk of an $80 million loss by 50%, which is a much better conversation than, here's 10,000, thank you very much, your reward, another 10,000. So, I think a lot of this is not just the technology, but also procedural and political changes in the organization that are happening where everybody's realizing that we need to get to remediation quickly and we need to cut through a lot of the noise that we have been focusing on wasting time on. And once the security team shows that they were able to run the exploit, there is no more conversation of should we fix it or not. KB [00:18:43]: Yeah, that's a good point because, I mean, what was coming to my mind as you were speaking is with the 10,000 items to address, people could probably get to the end of that and realize and work out that did really nothing. And so, they're exhausted. They've spent all these resources. They've upset people in the company, et cetera. So, is that mindset shifting to be like, hey, we may only need to fix 11 to significantly move that needle? Sumedh Thakar [00:19:07]: Absolutely. And I think there are 2 aspects to that, right? First of all, it's a better conversation, but it also makes the security team more business-focused and oriented, right? Because You talked about the exhaustion and the frustration for fixing 10,000 items and really not making an impact. But there is a business impact because all that time that you took from the IT team and the dev team could have been used to create the next functionality that would've made $1 million for the company. So you are, as a security leader, you're giving back time to your business to actually make money by taking a prioritization approach that is truly rooted in a real risk and true risk that is coming to your organization. So, that change is happening and more of that needs to happen because at the end of the day, you want to basically run the business and not spend all your time on, you know, fixing cyber-related issues. KB [00:19:59]: And can I just ask, why weren't we sort of doing this approach before? Because at the end of the day, of course, people want to reallocate their resources and make more revenue for their business versus, from what I see it, doing busywork by the sake of just patching and fixing stuff for the sake of it. Yeah. Sumedh Thakar [00:20:14]: Sometimes you have to feel the pain before you make some changes, right? And I think the processes had been set for many years about how to do fixes and, you know, the 30 days for remediation, and people were just sort of going along with it. I will say that the move towards, you know, what we call exposure management/CTM, you know, continuous threat exposure management, was already starting to happen. People were already realizing that, you know, I need to find a better way. But many times, the regulations had not kept in sync with that, right? So, the regulation would still require to fix everything that is CVSS 6 and above. And a lot of times, those were theoretical vulnerabilities that actually did not reduce any risk, but people had to do it because of regulation. So now, with MITRE, given the speed that is needed and given the resources that are needed, that's just accelerated, that more people are now going towards, like, I need to find some form of exposure management capability, but, you know, you don't want that exposure management to become another dashboard in your dashboard tourism. You want a way for that to trigger an autonomous remediation that lets you take 20-30% of the risk off the table as quickly as you can. So, I would say that it was happening, but at a much slower pace earlier. Sumedh Thakar [00:21:27]: It's just accelerated even more now. KB [00:21:29]: Okay. So, speaking of speed, as we know, if AI can find the vulnerabilities faster, which is what we're talking about today, then humans can fix them. And I know we sort of talked about autonomous patching and remediation. Help me make sense of how is this going to be moving forward? And I caveat this, Sumedh, by saying, from people that I'm speaking to, there's still this level of relinquishing the control to the machines to do it for people. And we've heard all the instances of AI agents going rogue and these sort of things and doing things they shouldn't be. But talk to me a little bit more about this. Sumedh Thakar [00:22:03]: I don't think people realize that we don't really have an option now, right? Like, it's not that the attackers are saying, like, you know what, this organization is still unsure about AI, so let's not attack them, you know, at AI speed. You know, it's coming your way. You don't have a choice. And I mean, right since the beginning of Post-Mythos, I have been in the optimist camp here because I do think that a lot of this technology is actually very beneficial to the defenders as well. I mean, just, I will make a point at the very high level about AI is AI is able to find things faster than humans. Is that a bad thing? I don't think so. You know, like, I mean, when airplanes came, you could go from one place to another faster than a human could walk. Was that a bad thing? No, we figured out a way to actually leverage it to our advantage by being able to do, be a lot more productive. Sumedh Thakar [00:22:49]: And I think it's the same for AI. Is AI finding things faster than humans is a good thing for us and all we have to do is find those things faster or quicker and fix them before the attackers find them. And so now when you are in that mode, you don't really have a choice of, you know, kind of figuring out a way to leverage AI and balance that risk. And, you know, there are certain areas in cyber like phishing emails, you know, hackers are using AI to create unbelievably sophisticated phishing emails to the point where the only way you can detect it's a phishing email is by an AI-based system that can figure out that this was done by AI. Humans almost have no role to play in that. You cannot have a human figure out that this is an AI-generated email. And so you are in a place where there's more autonomous warfare, so to say, happening between the attackers and the defenders. And the same thing is going to extend to other areas of cyber. Sumedh Thakar [00:23:40]: You don't really necessarily have a choice. So now that you don't have a choice but to use some form of autonomous remediation, the question is, how do you mitigate that risk of relinquishing some of that autonomy to AI? What are the different things that you can do? And that's where part of what we are focused on with the True Risk Eliminator capability is to say, can I, first of all, reduce the number of things you fix so that, you know, you reduce the risks? Can we use mitigations instead of patching? So you are making very small changes that actually block. And then can we also use AI to our advantage to create something like a patch reliability score that can allow us to also have the visibility into new stuff so that we can actually make better decisions? And so today, that balance of, you don't have to be 100% autonomous or 0% autonomous. You can start with 20%, 30% things. Autonomously and then move on to other things is the only real option that people have at this point, because you cannot continue to just say, we're going to do everything manual. But also it's not realistic to say everything is going to be fully autonomous, at least right now. It could develop that in the future, just like it has with email. But I think that's where the opportunity is right now is I think there's a lot of positive things that are coming out in terms of the use of AI. Sumedh Thakar [00:24:53]: And we have the opportunity to use this and leverage this to be in a better place in my mind. VO [00:24:57]: We'll come back to that after a quick word from our sponsor. Enterprise tech leaders know that compliance isn't just about ticking boxes. It's about risk, reputation, and revenue. That's why companies trust Vanta to streamline their security and compliance workflows at scale. With deep integrations and automated evidence collection, Vanta takes the manual audit grunt work out of the frameworks like ISO 27001, Visit Vanta.com/KBKast, V-A-N-T-A.com/KBKast, to learn more. KB [00:25:36]: And wouldn't you also say this is more of an organic, natural evolution of our cyber IT world? Because at the end of the day, no one really wants to be sitting there fixing 10,000 things manually anyway. People want to be working on more strategic stuff. So did you envision this was always sort of on the coming down the pike? anyway, in terms of cyber, but maybe you just didn't know when. Sumedh Thakar [00:25:55]: I think that's a great way to put that because, you know, I recall having been at Qualys for all these years, about 5 years ago, when I came up with this idea of like, why are we just scanning and telling people, you know, the problems in their lives? Why don't we be part of the solution, right? As I always tell the team, like, don't come to me with problems. I already have my own problems, right? Come to me with solutions. So I thought that's a great way to say like, the solution at the end of the day is to fix it somehow. If you don't fix it, that's like just dashboard tourism, right? You're just looking at stuff, not fixing it. It doesn't make you safer just by looking at dashboards. So ultimately, you have to somehow fix it. So at the time, about 5 years ago, I envisioned that some form of integrated remediation was going to be the future, and some form of autonomy and automatic remediation was also going to be part of that future. And so we continued to be sort of the only one in that space, isolated, continuing to develop that technology. Sumedh Thakar [00:26:49]: It was very exciting to see that even before Mythos came out, Qualys had already deployed 150 million patches in our customer environment. But even for me, what was exciting and surprising in many ways was that 40 million of those 150 million were already autonomously deployed without any human intervention. So this journey towards, we have too many things, we don't have enough people, we got to take some stuff autonomously, was already happening. That has been very great to see that our vision, to your point, I knew this was going to happen, just didn't know when and how, but it was coming at the speed at which things were happening, helped today set us up for being that solution where people actually say, oh, if I want to trust somebody to patch my stuff and patch it autonomously, I'm going to look at the guys who already deployed 40 million patches autonomously and have deployed about half a billion patches with no real outages for our customers. So we have perfected that technology. So I would say that yes, we knew it was going to come. We just didn't know what the timing of that was going to be. KB [00:27:50]: And a comment you made before around understanding the true risk rather than the risk. So would you say this is more of a defining moment, especially in your eyes as a CEO, for companies to really understand that? Because perhaps manually, again, people might say, hey, it has a massive impact, but the likelihood of that happening is rare. But maybe those things were confused. So therefore, to your point, people didn't really understand the fidelity of that True risk. Sumedh Thakar [00:28:14]: Yeah. I mean, look, at the end of the day, when you look at it from a business perspective, cybersecurity is a risk management exercise. And what you are essentially doing is you're spending a certain amount of money to reduce the risk of a business loss to your organization. And that's it. And so for that, what you need to be able to know is how much loss could I potentially have and what is the minimum amount of money I should spend to help reduce that loss. And that is in 3 buckets. When you talk about risk management, one bucket is how much should I spend to actively mitigate the risk with certain tools, etc.? Second part is how much should I actively accept as risk? Because risk acceptance is a key part of risk management, right? There is nothing like zero risk. You always have to accept certain risk. Sumedh Thakar [00:28:59]: And then what I cannot fix and what I cannot accept, how do I transfer that to a cyber insurance company? So that's part of what we are focused on is partnering with cyber insurance to say, look, if you're doing good on the first aspect, we can actually get a discount on the transfer aspect. So that creates a healthy equation. And so ultimately what the business and the board and everybody's looking at is not how many findings did you have or how many findings did you fix? What they want to know is just that assurance in every board meeting that with our current risk posture, are we under an acceptable risk appetite? And if we are not, what are we going to do to fix it or transfer that risk to somebody? And so really at the end of the day, and this is what we do in our board and meeting, and a lot of other CISOs are now starting to do, is be able to go into the board and say, look, we have a $500 million business. If there is a cyber issue, it can cause an $80 million loss to us. We have decided our risk acceptance level is a 400 risk score, as an example. And now that the risk score, and that I can assure you that the current risk score is below the risk appetite. That's all they want to know. Is it below risk appetite? There are no further questions. Sumedh Thakar [00:30:07]: If it is above risk appetite, what are you going to do? How much are you going to spend to get there? And so that's when, you know, when we talk about true risk is that just because you have a vulnerability doesn't necessarily mean you have a risk to the business. Just because you got a breach may not mean a big loss to your business also. It just, all of it depends on Where is the asset? What does it lead to? What does that breach lead to? How much money do you have to spend to manage that? And, you know, that's where like reputational damage from a cyber incident today is like, when was the last time you changed your provider because they said they had a cyber outage? I mean, cyber issue. Almost nobody changes their provider. So businesses will say, well, I mean, I'm not really losing customers necessarily, but if a cyber event causes an outage and I cannot accept orders for 15 days, that's a lot more important to me than maybe, you know, some news in the newspaper. And then I have to deal with it by paying $5 million to a regulator, right? So, there are so many things happening around risk. So, I think that anchoring on the true risk is really about what is the business loss that you could have from some of the issues that you're seeing. KB [00:31:11]: Yeah. And that's an interesting point. I was talking to another CEO literally yesterday, and they were saying, in some instances, businesses have just paid the ransom because they worked it out to say paying the ransom, it's inherently less than our business not operating for 2 or so weeks. So would you say that that business executive conversation is changing in terms of how people are approaching this? Because to your point, it could cost them more money to not operate at all for X amount of days depending on the business. Sumedh Thakar [00:31:38]: I mean, I wouldn't say it's new, and I think every organization at the end of the day is gonna make a business decision. On which way they want to go in those kinds of cases. But it just highlights what I was saying, which is at the end, it comes down to a business decision that some are making. Some may not believe that paying the ransom will actually stop this, and maybe they make them a target even more, et cetera, which is also a business decision, right? We don't want to pay it because if we pay, then we might have another ransomware attack where we'll have to pay more, which will cost us even more. So a lot of those business decisions, but to your point, it just highlights what I was saying earlier, that at the end of the day, cybersecurity is a business risk management function, and we have to be able to put everything that is happening, mythos and all of that, in the context of what does that mean to the business? And then how many incremental dollars do we need to spend to mitigate and manage that thing? And is that worth it, right? At the end of the day, you know, is somebody going to spend half of all their earnings on cyber? That's not going to happen, right? So they have a certain equation. And then if you're going to say, look, I think, you know, I was spending this much and I need to spend like 5% more, 10% more so I can protect against AI, I think that's a valid conversation. conversation to have, but now you're anchoring and saying like, look, my risk has gone up because attackers are using AI, so I need to spend a little bit more for myself to use AI so I can balance that risk equation again. KB [00:32:55]: I'm curious to get some insight from yourself, given your role. What is sort of the general— where are people's mindsets at? People that you're speaking to, customers, people in the market, where are they sort of at in this AI journey and everything that we've talked about today and just really the market moves so quickly now. I'm just curious to see what can you share with what's happening? Sumedh Thakar [00:33:16]: If you're a CISO, I think there's like a couple of things happening in your mind, right? One is sort of the business aspect of it and one is the personal aspect of it, right? And so I think the business aspect of it is like, you cannot go back to your business and say that, hey, you know, we don't believe this Mythos thing and we're not going to do anything from an AI perspective to combat what Mythos is bringing on, right? That would be very shocking to a board if the CISO says that, right? So, every CISO absolutely has to come up with an AI strategy for cyber that they need to present and provide to their board on how they're going to fight attacks that are coming from AI. So, that's still kind of on the business side. And then, at the end of the day, on the personal side, right? Like, you know, when you're looking at promotions and this and that, like, you want to be able to be the executive that is not the one that is, you know, always coming in with like bad news and saying bad things. You want to be the One who's actually able to say, hey, by the way, even in cyber, we started using AI in different aspects of cybersecurity. And that actually has enabled us to scale more, save money for the business, you know, be able to give that time back to the developers because of the prioritization we are doing with AI. So I think from a personal career growth perspective, et cetera, as well, I think it's important for CISOs to pivot more towards being a business-oriented executive and less about like you know, just, oh, we had these many issues and we fixed those type of conversation. KB [00:34:43]: And would you say CISOs have like an adequate AI strategy? Because I know it's still really early days, people are figuring it out. One minute someone's saying X to me, then they're saying Y each week. So everything's changing. Or do you think it's just going to be more of an iterative process? We may think this today or this week, but next week it may change considering on how the market moves in terms of the velocity. Sumedh Thakar [00:35:04]: Change is the only constant when it comes to IT and digitization these days, right? I think from kind of where we were to where we are now, They all know that they need to respond back with some sort of an AI-based approach. I think some of them are definitely picking maybe some low-hanging fruit off the table, right? Sometimes, my existing provider is providing me some additional capabilities that are making things easier with AI, so I'm just going to maybe buy that additional module. Like what we see as an example with our customers is saying, wait, I need autonomous remediation. You already have autonomous remediation. Maybe I can start using that on my employee laptops first, right? So they're doing that, but then they're also trying to figure out how they can bring AI as part of their overall security program across different aspects. Should they use Anthropic? Should they use OpenAI? Should they build their own harness? How much is that going to cost? Because that also has to be a part of the equation in terms of tokens and how many tokens will that end up consuming? And are you going to end up in a budget scenario where it's a variable spend that you cannot peg back to the value that you're bringing to the business? So I would say that everybody's sort of taking a two-pronged approach where they're doing some quick things to take things off the table, but then everybody's still working through on what is going to be a bit of a longer-term AI strategy to do some testing and figuring out that they don't end up being tied to only one AI engine, that they are building a harness. That's most of the conversations that we have is people are looking to figure out a way to build a harness that allows them to have a permanent use of AI, but not the permanent use of a particular company's AI, that they can actually have a harness and orchestrate that allows them to use different engines. So I think the realization that they have to do something for AI is there, but people are still in the early part of the journey of sort of a more long-term approach that they still are designing. KB [00:36:52]: So, Sumedh, my final question to you would be, I just want to talk about cost for a moment. So what I've been hearing from folks like yourself in the last week is because of how someone said, if it's a pizza, and, you know, 3 quarters of that pizza has gone to AI for token-related, like tokenomics. Now they're saying there's going to be a lot more pressure being put on all the other vendors who've only got 1 quarter of that pizza. So there's going to be, well, how much more bang for buck can we get? So how is that sort of impacting folks at that board level, executive level to say, well, we don't have as much budget as we had before because it's gone to AI. So would you say that there's more scrutiny now on vendors in companies and where they could potentially offload some of those vendors, for example? Sumedh Thakar [00:37:35]: Yeah, I think that's a really good question because, you know, at the end of the day, when you're like a little bit more on the cyber side first, right, which is at the end of the day when you talk about cybersecurity, as I said earlier a couple of times, that it's about risk management. And so part of risk management is actually deciding we're not going to do something because the loss is not that high for this particular situation, right? And so that Number one thing is everybody's looking to sort of operationalize this concept rather than jumping one for one thing here, one thing there. So the idea of a ROC, a risk operations center for cyber, is taking hold quite a bit because that is allowing you to take the technical findings and then multiply those with the business outcomes. And so you might have a very bad score for an entity, but if the business loss is only $1 million compared to another entity that has a different score, technical score, but the loss is $500 million, then you might change that. So operationalizing that is becoming very key. And then the question becomes is how do you move to an AI-powered risk operation center, which is not just manual, right? I'm just similar, like you have a SOC for post-breach finding things is moving to an AI SOC. The same is happening for the risk operation center is what are the elements within that framework that where we can leverage AI, whether it's the AI provided by the provider, is it the AI that you are hooking into that? But ultimately you kind of have to have some sort of AI stuff. I think now when it comes down to overall business and token usage and stuff like that, at the end of the day, I think people are pretty quickly moving away from gamifying token usage by just rewarding those who are using tokens the most. Sumedh Thakar [00:39:06]: I think that's falling apart pretty quickly because people are now going back to, well, yes, you were number one in token usage, but what did you produce? What was the outcome to the company? A lot of the conversations are more pivoting towards that. And so, of course, the budgets, you know, they get in flux sometimes. Oh, we spend a little bit more here. And a little bit more there. And so now what do we do? And do we, you know, or do we go and ask for more money? But I think in general, if the company's spending overall more in AI deployment for the business, naturally as a percentage of that pie goes to security also, right? So if I'm spending a million more on AI, I'm also going to take part of that $100 million to spend on cybersecurity-related things for AI as well. You can, you know, naturally would be able to see conversations in the future pivoting more towards that kind of a thing. And then there is like a broader enterprise-level thought process also, which is, and I think that's why you see some of the ups and downs in the market, financial markets as well, where the question is, is a company going to standardize on using only one AI company's agent to do everything that they need and use tokens through them, or are we going to pivot to a model where some of your key vendors are going to provide AI capabilities built into those solutions that is giving you the outcome? And so you're not dependent only on using one enterprise AI agent, but you're using AI through your trusted vendors, right? And it's turning out in many ways that those can be cost-effective. Just as an example, you know, we were looking at an AI-based approach to train our salespeople so that when they pitch to the customers, so the AI will give them feedback. Sumedh Thakar [00:40:46]: It turned out that AI capability was a lot cheaper with our existing vendor than to try to build it ourselves through Anthropic, right? And so, I think there are these equations that are happening overall. And so, we are, I feel like we're still at that sort of an early stage, but it seems more and more that there are trusted partners and vendors that companies are pivoting towards to provide more cost-effective AI capabilities. And that's something similarly what we're doing with Qualys as well is our— to our customers, we don't charge them by tokens. They can use— if they upgrade to a certain capability, it's a fixed cost for the year, but they can use as much AI as they want. And so they don't have to worry about like, oh, am I going to run out of tokens? So your vendors also need to provide you solutions that actually where the increasing cost is pegged to an outcome and not just token usage. Token usage doesn't necessarily always spec to a particular outcome. So a lot happening in the industry, but I think in general, any vendor that is able to provide you cost-effective AI built in that is not token-based, I think is going to be the winner in the longer run when it comes to this. KB [00:41:53]: That was Sumedh, everybody. What I keep coming back to is his framing that Mythos didn't hand attackers a new weapon. Mythos gave them speed, and the only honest response is to match it. If you're a CISO listening to this, your board has already heard the word mythos, so have a response ready to rock and roll. VO: I read every reply. If you've got some thoughts on this one, send me a message on LinkedIn. KBKast - Cyber For the C-suite.

Other Episodes