Autonomous Remediation Is Already Running at Enterprise Scale
Qualys CEO discusses autonomous remediation for enterprise security at Black Hat USA 2026.
Summary
Qualys President & CEO Sumedh Thakar highlighted the shift towards autonomous remediation in enterprise security at Black Hat USA 2026. He emphasized the need for speed, with remediation expectations now measured in seconds or hours, driven by AI-powered threats and CISA directives. Qualys's approach focuses on AI-speed detection, hyper-prioritization, and autonomous remediation, including AI-driven patch reliability scoring and automated patching, with a global company successfully deploying 40 million patches autonomously.
Full text
Table of ContentsWhy Does Speed Now Decide the Outcome?What Do the Three Pillars Look Like in Practice?What Should CISOs Carry Into the Boardroom? The following is a guest blog by ITSPmagazine, based on their interview of Qualys President & CEO Sumedh Thakar at Black Hat USA 2026. Sumedh Thakar has watched the same clock compress for 23 years. He joined Qualys as an early software engineer on the scanner, when organizations scanned once every 90 days and gave themselves another 90 days to fix what turned up. At Black Hat USA 2026 in August, the now President and CEO of Qualys measured the current expectation in different units. Ninety seconds. Why Does Speed Now Decide the Outcome? Because the questions have stayed steady while the time to answer them has collapsed. Thakar walks through the sequence security teams keep running: Where is my stuff? What is my assessment of it? What do I prioritize? What do I actually fix? Layering dashboards on top produces what he calls dashboard tourism, when nothing gets fixed. He points to the CISA directive requiring government agencies to remediate within three days, and to the zero-day conversations organized around a 24-hour window. Neither target is reachable by handing findings to a person watching a screen. When a board asks how the organization will fight autonomous, AI-driven exploitation, Thakar says the answer cannot be a plan to hire more people. What Do the Three Pillars Look Like in Practice? Qualys organizes its answer around three pillars. AI-speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper-prioritization tests which findings are actually exploitable in a given environment, rather than scoring them theoretically. Autonomous remediation applies the fix without routing it through a human first. Detection has to move first, since a three-day detection cycle makes a 24-hour remediation target moot. Prioritization then narrows the field. Teams were barely fixing 5% of what they found even before frontier models raised the volume, and Thakar argues that running an actual exploit against existing firewall and EDR controls cuts a theoretical 1% down to roughly 20% of that 1%. On remediation, the order is to fix the least that achieves the outcome. A mitigation or compensating control that avoids a patch, reduces risk without touching the software. Where a patch is required, Qualys built a patch reliability score using AI, so an agent can judge whether a patch is dependable and reboot-free before applying it. The volume behind that argument is substantial. Qualys has deployed over half a billion patches, 150 million of them in the past 12 months, and 40 million of those went out autonomously with no human intervention. Thakar described a global company with 450,000 employees, many of them consultants on the move, running the Qualys agent for autonomous patching. When Google Chrome releases a patch, the agent downloads and applies it rather than running a vulnerability scan and populating a dashboard first. What that team reports to its board is not a count of vulnerabilities. It reports a maximum exposure window of four hours from the time a patch is released. Thakar expects the monthly patch cadence to give way as disclosures accelerate. Qualys recently released InstaScan, which he describes as scanless scanning, delivering a finding within an hour of a vendor disclosure. What Should CISOs Carry Into the Boardroom? Risk expressed in business terms. Thakar positions the CISO as a business partner rather than a technology owner, responsible for giving the board and the CEO visibility into potential loss, current spend, and whether risk sits within an acceptable appetite. For a $500 million business, the questions are: What would a breach cost? What will it take to bring an $80 million exposure to an acceptable level? How much of the remainder transfers to cyber insurance? His shorthand for the operating model is the Risk Operations Center (ROC) alongside the SOC. For the entire conversation, watch or listen to the full Brand Briefing from Black Hat USA 2026. Related