Qualys CEO Sumedh Thakar on trust, AI and the real cost of a breach
Years ago, when internet banking first arrived in India, Sumedh Thakar watched his father refuse to use it. The convenience was obvious, the queues at the branch were long, and still his father chose to stand in line to withdraw cash rather than trust a screen. “I would ask him, why is he not using it, it’s so convenient, and he was always like, well, I don’t know about this whole password thing, and what if the password is stolen,” recollected Thakar, President and CEO of Qualys. That small act of refusal stayed with him, and it eventually settled into a conviction that has shaped how he runs one of the largest cybersecurity companies in the United States.
“It made me realise the importance and significance of cybersecurity to secure our future in the digital journey that we are on. Because without the trust in these digital systems, nobody’s going to use those systems,” explained Thakar. The lesson has only grown sharper as the tools of identity have changed. Passwords were once the front line, and a stolen one could be reset within minutes. The systems that have replaced them offer no such forgiveness. “If a password is stolen, you can reset your password. But if your biometric identity is stolen and your thumbprint is stolen, you cannot grow another thumb,” he added.
Trust is the thing that makes any technology work
That early realisation gave a somewhat accidental career its sense of purpose. Thakar joined Qualys 23 years ago with little certainty about where the field, or the company, was heading. “When I had joined Qualys early on, I wasn’t quite sure where this field is going to go and if SaaS was going to take off,” said Thakar. He stayed, and over the following decades watched cybersecurity move from the margins of corporate spending into the centre of the boardroom. The through-line, in his telling, was always trust. People adopt technology when they believe it will hold, and they abandon it the moment they do not.
Thakar has watched that trust get tested across market after market. In countries such as Brazil and India, biometric identification has become the everyday method of verifying who someone is, which raises the stakes of any compromise far beyond an inconvenient afternoon spent resetting logins. His view is that the significance of the work compounds with every step the world takes towards being fully digital. “As long as we are on a digital journey, this is going to be something that is going to be chased by attackers, and it’s going to be important for corporations and governments and individuals to safeguard themselves,” he said.
The pattern of attack and defence stays the same while everything underneath it changes
Nearly two and a half decades at one company have given Thakar a long view of how little the underlying contest really shifts. He has lived through client-server systems, virtualisation, the arrival of the cloud and now the rise of AI, and he is already confident about what follows. “The technology keeps coming. As technology’s adopted, the attackers do go after that technology, and that’s almost a given. I’m pretty sure that in a few years it’s all going to be about quantum,” said Thakar. Each wave brings its own excitement and its own panic, and each time the basic sequence of the work survives intact. “Whether it is cloud, it’s the same process. Whether it’s AI, it’s the same basic steps. How you do it, maybe some of the nuances change,” he explained.
What has genuinely changed is how organisations think about the money they spend defending themselves. Budgets are finite, threats are endless, and somewhere along the way the fantasy of fixing everything collapsed. Thakar describes the moment of stepping back and seeing the whole thing plainly. “Cybersecurity is a risk management exercise for the company at the end of the day. We don’t have unlimited budgets. We can’t fix everything,” he said. That recognition changes the character of the job. It becomes an exercise in judgement about which risks to carry, which to remove, and which to hand to someone else.
Cyber has become a calculation, much like buying insurance
The calculation Thakar describes has three moving parts. There is the work of reducing risk through tools, people and process. There is the acceptance, conscious or otherwise, that some danger will always remain, because nothing brings it to zero. And there is the transfer of whatever is left to a cyber insurance company, so that the residual exposure sits somewhere it can be absorbed. He explains the logic with an example anyone can picture. “It’s like any insurance. If you have a $50,000 car, you’re not going to spend 50,000 on buying insurance for that car,” he added.
For years, he argues, the industry behaved oppositely, lurching from one emergency to the next. He calls it whack-a-mole, the habit of pouring budget at whichever vulnerability happens to be dominating the news that week. The direction he sees now moves towards something steadier and more deliberate, an operationalised approach that Qualys runs through what it calls the Risk Operations Centre, a place where the business view of risk and the technical view of it finally sit side by side. The friction between security teams and the rest of a company, he admits, has proved remarkably durable through all of this. “The pushback on implementing any cyber controls is always perceived as getting in the way of doing business. You’re making me patch, I have to do two-factor authentication, why do I have to do that,” said Thakar.
Digitisation has dragged every industry into the security conversation
What has forced the change is the simple fact that almost every business now runs on technology, including many that once had no reason to care. Thakar reaches for an example that would have sounded absurd a decade ago. “If you were just driving a truck from one place to another, that was not a big cyber issue for you. But now that technology is being used to auto-drive these trucks, and you have GPS targeting and managing your fleet with technology, any attack on that infrastructure now is significantly more important, even if you’re a trucking company,” he explained. A freight operator has become a software business, and a software business can be brought to a halt.
The consequences of that shift are not always where people expect them. Reputational damage, Thakar notes, tends to fade faster than anyone assumes, because customers rarely walk away from a provider after a breach notification, however many arrive in their inbox. The real pain shows up when the systems stop. Recent outages at a retailer and a car manufacturer demonstrated that an inability to trade in a fully digital economy costs far more than an awkward headline. The organisations he respects now ask a more pointed question, which is how to match their cyber spending to the loss scenarios that are genuinely likely for their own business, and how to reduce the damage from those specific failures.
Autonomy is what makes AI different, and it takes manual defence off the table
Thakar refuses to treat AI as a break with history. He sees it as the latest in a long series of shifts that have unsettled people and then been absorbed. “There was somebody many centuries ago, and their job was to take a stone slab and a hammer and a chisel, and chisel the king’s message. I’m sure those people were really worried when the first ink and a feather to write on paper was invented,” said Thakar. Humanity found other work then, and he expects it to do so again. The quality that sets this moment apart, in his view, is velocity. “What I think is different with AI is the speed at which the technological shift is happening is a lot faster than what happened with cloud,” he explained.
That speed has quietly removed an option defenders used to rely on, which was to meet a rising threat by adding more people. Attackers now behave like any efficient business, using AI to find the most exploitable targets rather than hammering away at everything in sight. Meeting that with headcount is a losing proposition, and Thakar puts it bluntly. “As attackers are using autonomous ways, defenders don’t have a choice. You cannot go back to your management and say we are going to respond to AI-based autonomous exploit attempts by hiring 100 more people and doing more manual stuff. They will look for a new leader if that’s what you’re going to tell them,” he said. Email is where he sees the problem at its clearest, with AI now writing phishing messages that no person can reliably spot. “Your only option really is to use AI to go after that,” he added.
Frontier models are compressing the time it takes to turn a flaw into a breach
On the frontier AI models now capable of hunting for vulnerabilities on their own, Thakar is careful to describe what is actually new. The capability itself, he points out, is not unprecedented. “It’s not that it is doing something that humans have not been able to do, like look at code, find things, chain vulnerabilities. What it is doing is that it’s able to do that autonomously without the need for a human, and significantly faster. What would take six months for a human to find, it can find in a matter of minutes and hours,” said Thakar. He is honest, too, about the theatre around these announcements, observing that pre-IPO companies have a talent for making sure the whole world notices them.
Beneath the noise, he identifies three real accelerations. More vulnerabilities are being discovered, though only a tiny fraction ever matters inside a given environment. The gap between finding a flaw and working out how to exploit it is narrowing. And the models are becoming far quicker at chaining several weaknesses together into an actual breach. That last point lets Thakar dismantle a piece of folklore the industry repeats to itself. “There is this narrative that attackers have to be right only once and defenders have to be right every time. That’s not true, because attackers never just exploit one thing and then that’s it, they’re in,” he said. Intruders still have to work their way through an environment step by step, and it is that patient sequence AI now speeds up.
The goal is fixing problems in a day, not just finding them faster
If attacks move faster, defence has to move with them, which makes the old rhythm of weekly scans and monthly patches look dangerously slow. Thakar describes a tighter discipline built on ruthless prioritisation, one that establishes that fewer than 1% of detected vulnerabilities are genuinely exploitable, checks whether existing defences already cover them, and then remediates at speed without knocking systems offline. “We kind of need to move from zero-day vulnerabilities to zero-day remediation. Can I get my issue fixed in less than one day,” said Thakar.
Speed alone is not the whole answer, and he is quick to say so. Firewalls, endpoint detection and hardened systems all still earn their place, because the point is to make an attack expensive enough that it stops being worth attempting. “We leverage similar and better technology to protect ourselves and frustrate the attackers enough that from a business perspective it’s not worth it for them to try to hack us, or make sure that they are consuming so many tokens that it’s just not worth it,” he explained. Inside the Risk Operations Centre, Qualys now lets teams hire goal-driven digital workers, among them a ransomware analyst, to gather evidence, set priorities and carry out remediation under human oversight, doing in a week what would otherwise strain a stretched team.
People, in the end, decide whether any of this works
Thakar’s climb from engineer to manager to VP and, in 2021, to President and CEO taught him where his own usefulness runs out. “Early on, many of us try to do everything ourselves. You quickly learn you aren’t brilliant at everything, and even if you were, you don’t have the time. The shift is to hire people who are better than you in their domain, set a clear intent, remove blockers, and let them run,” explained Thakar. When he looks back at his own missteps, he traces them to a handful of failures that repeat. He was not clear enough about where the company was going. He assumed everyone shared a picture of success when they did not. He hired too late, or he hired for skills rather than for character. “Tell ten people to draw the big tree in grandma’s backyard and you’ll get ten different trees,” he added.
His closing thought pushes back against the reflex to price everything in compute. “First time in human history, the value of the human contribution is weighed in terms of tokens. Centuries ago people used to weigh a person’s value with their weight in gold, and now we’re saying, are 50,000 tokens more expensive than a person working for us,” said Thakar. He wants leaders to resist that arithmetic. “The most important thing for the success of AI is actually the humans in your organisation. The best and your smartest people are going to get the best value out of the use of AI in any field,” he explained. Across two and a half decades, the through-line has held for Thakar. Seize the opportunity in front of you, surround yourself with people stronger than you are, and keep the organisation restless enough that the next wave never catches it standing still.