DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

The Future of Digital Defense: Qualys CEO Sumedh Thakar on Risk, AI and the ROC

Qualys CEO Sumedh Thakar’s vision puts business risk, AI-assisted defense, and the proposed Risk Operations Center at the center of cybersecurity operations.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Qualys CEO Sumedh Thakar’s central argument is that cybersecurity teams should prioritize business risk, not simply count vulnerabilities or alerts. In a July 10, 2025 episode of Tech Talks Daily, he discussed the shift from attack-surface management toward risk-surface management, the proposed Risk Operations Center (ROC), and AI’s changing role in defense. The ideas offer a useful way to think about security decisions, but the interview presents a vendor leader’s strategic view—not independent proof that a particular model or product has solved enterprise risk.

The interview and its central argument

The discussion appeared in Tech Talks Daily as “Qualys CEO On Risk, AI, And The Future Of Digital Defense,” published July 10, 2025. The roughly 34-minute episode featured Sumedh Thakar, Qualys president and CEO, during a visit to the United Kingdom for the company’s QSC conference. Its topics included compliance, cloud security, AI, leadership, and how security teams can make better use of limited attention. Listen to the episode on Apple Podcasts.

Thakar joined Qualys as an early software engineer before becoming CEO. That technical background is relevant to his emphasis on integration and automation, although the interview’s claims should still be understood as the perspective of a security-vendor executive. He frames cybersecurity as a business risk-management exercise, not just a technical effort to find and fix defects. Thakar’s risk-management framing.

Why counting vulnerabilities is not enough

Security teams commonly track vulnerabilities, assets, alerts, audit findings, and remediation times. These measures can reveal workload and trends, but they do not by themselves show which problem is most likely to harm the business. A vulnerability’s priority depends on factors such as whether the affected system is reachable, whether exploitation is feasible, what controls limit access, what data or process the system supports, and whether a fix can be deployed safely.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Risk-based prioritization does not mean ignoring lower-severity findings. It means sequencing work according to likely business impact and practical exploitability. For example, a high-severity flaw on an isolated development server could be less urgent than a moderately rated issue on an internet-facing identity system used by a finance team. That is an illustrative comparison, not a reported incident.

Thakar’s distinction is between an attack surface—the assets and entry points an attacker might target—and a risk surface, which adds context about what those exposures could mean for the organization. The latter asks which exposures are realistically exploitable, which assets matter most, and which mitigation will reduce the most risk for the effort required. He describes the distinction in this interview excerpt. It is a useful framing, not a universally standardized category.

What a Risk Operations Center would do

The ROC is best understood as an operating model for connecting technical findings to business decisions, rather than simply a new name for a Security Operations Center (SOC). Thakar’s ROC framing includes deciding which risks to mitigate, accept, or transfer. A separate interview description discusses that approach in terms of moving from SOC to ROC. The Business of Cybersecurity episode.

In practice, a risk-focused operation would need to connect these activities:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration
  1. Establish visibility: identify hardware, software, cloud resources, applications, identities, and other assets.
  2. Validate exposures: find vulnerabilities, misconfigurations, missing patches, and insecure services, then determine whether they apply and are reachable.
  3. Add threat context: assess exploit availability, active exploitation, attack paths, and the effect of existing controls.
  4. Map business impact: connect assets to owners, services, data, and operational processes.
  5. Prioritize and act: assign remediation based on likely impact and feasibility, and automate only changes that are safe to automate.
  6. Govern residual risk: document decisions to defer or accept a risk, and consider transfer or other mitigations where appropriate.
  7. Report for decisions: give executives a view of material exposures, ownership, progress, and unresolved decisions—not merely counts of activity.

The model depends on more than software. Without reliable asset ownership, business-impact information, connected workflows, and authority to assign or accept risk, a ROC could become another dashboard rather than a change in outcomes.

AI can accelerate defense—and create new risks

The episode presents AI as both a complication to risk profiles and an opportunity to speed analysis, automation, and cloud-security work. AI can help correlate findings, summarize risk, suggest remediation, and support investigations. It can also lower the cost of producing phishing messages or malicious content, while introducing new models, APIs, data stores, and automated agents that need access controls.

AI does not make incomplete inventories or poor business context reliable. Nor does a suggested fix become safe simply because a system generated it. Automated remediation should have explicit authorization boundaries, testing or staging, maintenance-window rules, detailed logs, and a recovery path. High-impact changes—especially to identity infrastructure, production databases, industrial systems, or healthcare systems—need stronger human oversight and a workable rollback plan.

Organizations should also be able to explain how a risk score is calculated, what data informs it, how asset criticality is assigned, and how false positives are handled. A vendor score can help organize work, but it should not silently define an organization’s risk appetite.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Cloud security makes context more important

Thakar discusses cloud security as an area with continuing opportunity as AI workloads move into public and private clouds. Cloud risk is broader than scanning virtual machines for vulnerabilities. It can involve asset discovery, identity permissions, workloads and containers, Kubernetes, infrastructure-as-code, secrets, data exposure, network paths, runtime behavior, compliance, and the models and data used by AI systems.

A cloud resource being exposed does not automatically make it a material business risk. The consequences depend on what data it can reach, the privileges attached to its identities, the network controls around it, whether an exploit is feasible, and the resource’s role. Cloud assets can also appear and disappear quickly, so yesterday’s inventory or prioritization may not describe today’s environment.

Compliance is not the same as continuous risk reduction

The interview identifies compliance as an ongoing enterprise challenge. Audits require organizations to demonstrate that required controls exist, but evidence gathered at a point in time can become stale as assets and configurations change. Meanwhile, a real exposure may need attention even if it does not map neatly to an audit finding.

  • Compliance asks: Can the organization demonstrate that required controls are in place?
  • Risk management asks: Are the exposures most likely to cause material harm being reduced?

The goals overlap, but neither substitutes for the other. An audit result does not establish that an organization can detect, contain, and recover from a live incident. Conversely, a security improvement may reduce risk without immediately satisfying a particular evidence requirement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to assess the ROC idea in your organization

Before adopting a new operating model or platform, security and business leaders can test whether they have the foundations for risk-based decisions:

  • Asset completeness: Can you identify on-premises systems, cloud resources, SaaS applications, endpoints, identities, containers, and AI-related assets?
  • Business context: Do important assets have accountable owners, service relationships, data classifications, and criticality ratings?
  • Exploitability: Can teams distinguish reachable, exploitable issues from findings that are isolated, mitigated, or not present in a usable form?
  • Remediation feasibility: Are patch availability, downtime, dependencies, legacy constraints, and safer alternatives considered?
  • Risk authority: Is it clear who can approve exceptions, accept residual risk, and fund remediation?
  • Automation safety: Are automated actions tested, bounded, logged, and reversible, with human approval where consequences are high?
  • Executive usefulness: Can leaders see what could harm the business, who owns the remaining exposure, and what investment would reduce it?

These checks also expose common failure modes. Aggressively filtering alerts can obscure risks that are poorly understood or dangerous only in combination. A platform may consolidate data without consolidating products or workflows. And a broad vendor platform may not be the best fit for every specialized requirement. The interview does not establish that Qualys outperforms competitors or that ROC implementations produce better outcomes; those are questions buyers should test against their own coverage and workflows.

Leadership is part of the security model

Thakar also discusses trust, time, and communication, including the influence of Marshall Rosenberg’s Nonviolent Communication on his leadership approach. For security teams, the practical lesson is not to soften material risks, but to explain them in terms that engineering, finance, operations, and executives can act on. When teams cannot fix everything immediately, clear ownership and explicit decisions about timing and residual risk are more useful than either alarmism or a long list of unresolved findings.

What the interview does—and does not—show

The interview makes a strong case for connecting security findings to business impact: teams have finite capacity, cloud inventories change quickly, and boards need information that supports decisions. Its ROC concept organizes familiar needs—visibility, prioritization, remediation, governance, and reporting—around that objective.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is not independent evidence that the ROC is an industry-wide standard, that AI can safely remediate most vulnerabilities, or that Qualys’ products outperform alternatives. The defensible takeaway is narrower: digital defense improves when organizations can connect what is exposed to what matters, decide what to do, and govern what remains. Technology can support that chain, but it cannot replace ownership, judgment, or accountability.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
Network Security, Firewalls, and VPNs: . (Issa)
Network Security, Firewalls, and VPNs: . (Issa)
New Chapter on detailing network topologies; Increased coverage on device implantation and configuration
$57.99
SaleBestseller No. 3

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.