Q: You recently joined Qualys as CISO after serving in that same role at Fiserv. How do you plan on using your experience to advocate CISO needs for Qualys' customers?
As Fiserv's CISO, I was responsible for the enterprise cyber security strategy. My priorities were ensuring the availability and performance of the payment platforms, and the integrity and trustworthiness of E2E transactions. As financial services companies must maintain extremely high security and compliance standards, I also oversaw PCI DSS assessment delivery, operational risk mitigation, internal penetration testing, vulnerability scanning, and web application security.
Furthermore, in 20-plus years in IT security, I've developed expertise in threat intelligence, architecture, roadmap development, framework alignment, orchestration and workflow integration. I've also worked extensively with executive managers, IT leaders and legal counsel to provide precise visibility into new business opportunities and their associated cyber risks.
So at Qualys I will leverage all of that experience to help our customers' CISOs in a number of important areas, including:
- Building security into the fabric of their digital transformation, which all companies are pursuing to remain competitive. CISOs must seize the opportunity to insert security teams in new facilitator roles into these initiatives at their organizations. That way, CISOs will raise the security team's level of partnership, engagement and influence with the business, and security will no longer be the group that — citing afety concerns object, delay or even attempt to block initiatives. By evolving from IT defenders to business enablers, CISOs will ensure digital transformation efforts are not only effective but also secure.
- Assisting our customers with DevSecOps, at whatever stage they're in with their adoption of this agile and collaborative process for secure application development and delivery.
- Helping CISOs achieve instant and complete visibility across all of their IT assets, and effectively respond to cyber threats. Speed, efficiency and visibility are the themes and priorities that go-forward CISOs will align their efforts with.
Q: What do you see as some of Qualys' biggest strengths in helping enterprises enable digital innovation in a secure manner?
Digital transformation technologies and processes – such as cloud computing, IoT, BYOD, containers, Agile development, continuous web application integration and delivery, mobility – have erased the boundaries of traditional network perimeters. To prevent breaches, organizations must quickly and constantly collect and analyze enormous amounts of IT asset data in these now hybrid and more complex IT environments. Meanwhile, hackers' attacks are getting more vicious and sophisticated.
In this new perimeter-less, hyper-connected world, enterprise security software designed for client-server environments falls short. It's too slow, costly, rigid and functionally narrow. In response, CISOs have had to scramble to plug the information security gaps, diving into a noisy and confusing enterprise security market, crowded with obsolete and niche solutions. It's not uncommon for an enterprise InfoSec team to end up with 30-plus heterogeneous, siloed products that don't interoperate, and are expensive to maintain, and difficult to scale and manage.
The Qualys Cloud Platform has been designed for these new challenges. With it, CISOs can consolidate, simplify, modernize, and enhance their security and compliance posture. The platform is highly scalable, extensible and centrally managed, and has a suite of more than 10 natively integrated solutions for IT security and compliance. It gives customers continuous, comprehensive "single pane of glass" visibility and intelligence into all IT assets and their vulnerabilities — on premises, in the cloud, and at endpoints.
The platform constantly collects, assesses and correlates asset and vulnerability information, helping organizations prioritize their security and compliance remediation across their threat landscape. In short, the Qualys platform is in a leading position to not only provide the real-time visibility needed to respond to risks, but also the flexibility, coverage and scale that businesses need to protect any device on any environment.
Q: As a Diamond Sponsor of Black Hat USA 2017 what is your company's main focus at the event?
In addition to our existing security and compliance solutions for challenges like vulnerability management, web application security, IT policy compliance, third-party IT risk management, asset management, DevSecOps, cloud and threat prioritization, we'll be showcasing our newest products and helping to educate attendees on how to reduce the number of consoles and point solutions needed to gain security across these modern IT architectures and environments.
For example, we have a new solution called Container Security that basically lets customers address security for containers in their DevOps pipeline and deployments. It does that across cloud and on-premises environments.
Another new product is File Integrity Monitoring, which is now in public beta. It's designed to cut the cost and complexity of detecting policy and compliance changes, as mandated by increasingly prescriptive regulations.
We'll also be showing Indicator of Compromise Detection, which is also in public beta. It detects activity and behavioral changes on the endpoint. So customers get a continuous view of suspicious activity that may signal a variety of issues.
Then we have Secure Configuration Assessment, which is a new add-on to our Vulnerability Management app. It lets customers expand their VM program with configuration scanning capabilities and simplified workflows. That way they can assess, report, monitor and remediate security-related configuration issues based on the Center for Internet Security benchmark.
For customers looking to secure their public cloud workloads, we'll be showing our security and compliance solutions for Azure, Amazon AWS and Google Cloud. We have agreements and integrations with all three companies, so you can deploy our virtual scanner appliance and our Cloud Agents to monitor your workloads on all three platforms.
Last but not least, we'll be talking about how you can use a variety of Qualys products to boost and improve your DevSecOps environments, including our Web Application Scanning and Web Application Firewall solutions.