
Autonomous Remediation Is Already Running at Enterprise Scale | A Full Sponsor Brand Briefing at Black Hat USA 2026 with Sumedh Thakar, President and CEO at Qualys | Hosted by Sean Martin
About this episode
Sumedh Thakar joined Qualys as an early software engineer on the scanner, back when a 90-day scan cycle came with another 90 days to fix whatever it found. Twenty-three years later he leads the company, and the number he uses now is 90 seconds. At Black Hat USA 2026 he walks through what that compression asks of security teams.
So what has actually changed? The questions have not. Where are my assets, what is my assessment of them, what do I prioritize, and what do I fix. Thakar points at the clock instead, citing a CISA directive that gives government agencies three days and zero-day conversations built around a 24-hour window. Layering dashboards on top of that produces what he calls dashboard tourism when nothing gets fixed at the end of it.
Qualys organizes its response around three pillars. AI speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper prioritization runs an actual exploit to see whether firewall and EDR controls already block it, cutting a theoretical 1% down to roughly 20% of that 1%. Autonomous remediation applies the fix without routing it through a human first.
How far along is autonomous patching already? Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out with no human intervention. Thakar describes a global company with 450,000 employees running the agent for autonomous patching, where the board metric is a maximum four-hour exposure window from the time a patch is released rather than a count of vulnerabilities.
He expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which Thakar calls scanless scanning, delivering a finding within an hour of a vendor disclosure. A patch reliability score built using AI lets an agent judge whether a patch is dependable and reboot-free before applying it on a laptop.
His closing advice to CISOs is to show up as a business partner. The board and the CEO need visibility into potential loss, current spend, and whether risk sits inside an acceptable appetite. For a $500 million business that means pricing what a breach would cost, funding the reduction of an $80 million exposure, and transferring what remains to cyber insurance. His shorthand for the operating model is the ROC alongside the SOC.
This is a Brand Briefing. A Brand Briefing is an on-location conversation recorded on site at Black Hat USA 2026, putting a spotlight on the guest and their company and pairing it with the editorial reach of ITSPmagazine. Learn more: https://www.studioc60.com/performance/#briefing
GUEST
Sumedh Thakar, President and CEO at Qualys
On LinkedIn: https://www.linkedin.com/in/sumedhthakar/
RESOURCES
Black Hat USA 2026 event coverage: https://www.itspmagazine.com/black-hat-usa-2026-cybersecurity-event-coverage-in-las-vegas
Qualys: https://www.qualys.com/
InstaScan announcement: https://www.qualys.com/company/newsroom/news-releases/usa/qualys-launches-instascan-to-detect-vulnerabilities-within-minutes-of-disclosure
Agent Insta and scanless detection: https://blog.qualys.com/product-tech/2026/08/03/instascan-agent-insta-scanless-detection
The Risk Operations Center with Enterprise TruRisk Management: https://blog.qualys.com/product-tech/2024/10/09/qualys-launches-enterprise-trurisk-management-the-industrys-first-cloud-based-risk-operations-center
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
▶︎ Get your own Brand Briefing at an upcoming event: https://www.studioc60.com/buy-brand-briefings
KEYWORDS
Sumedh Thakar, Qualys, Sean Martin, brand briefing, brand story, brand marketing, marketing podcast, Black Hat USA 2026, autonomous remediation, patch management, vulnerability management, hyper prioritization, AI speed detection, scanless scanning, InstaScan, risk operations center, cyber risk management, zero day remediation, CISO, exposure management
Get every episode summarized
Each time The ITSPmagazine Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The ITSPmagazine Podcast

Marketing Volume Held Steady. Scrutiny Went Up. | Lens Four by Sean Martin | Rea...
The ITSPmagazine Podcast

Executives Can Now Invite Their Lawyer, Banker, and Dog Walker Into a Verified C...
The ITSPmagazine Podcast

Executives Can Check a Country's Risk and a Caller's Identity From the Same Blac...
The ITSPmagazine Podcast

A Secure and Compliant Business Is the Destination. Steel Patriot Partners Maps...
The ITSPmagazine Podcast