Detailed Narrative
AI-Native Risk Operations Center (ROC) and ETM
Qualys is positioning its Enterprise TruRisk Management (ETM) solution as an AI-native Risk Operations Center (ROC), designed to move beyond theoretical exposure to autonomous quantification of actual exploitable risk and remediation. This approach is deemed critical in the new AI-accelerated threat landscape, where exploit timelines are collapsing, and traditional Continuous Threat Exposure Management (CTEM) solutions are considered inadequate due to their tendency to generate more findings without effective remediation. The company emphasizes that defenders must autonomously detect vulnerabilities at AI speed, validate exploitability, quantify risk, and remediate before adversaries act.
New Product Capabilities for AI for Security
At Black Hat, Qualys introduced major new capabilities. InstaScan, powered by Agent Insta, offers continuous, instantaneous, and scanless AI-speed detection, reducing vulnerability detection time from days to minutes. This innovation is integrated with Agent Val for instant exploit validation and Agent Sara for autonomous zero-day remediation. Agent Sara orchestrates continuous, vendor-agnostic patching with high reliability, achieving rollback rates below 0.5% and reducing the window of exposure from 21 days to minutes, auto-patching 60% of vulnerabilities in live benchmarking.
Security for AI with TotalAI 2.0
Qualys also launched TotalAI 2.0 to secure the AI infrastructure enterprises are building. This solution provides visibility into the full AI estate, from workforce to workload and code to runtime, through new sensors that detect shadow AI activity. It extends posture management coverage to SaaS platforms like Anthropic and OpenAI, identifies security gaps in AI code, and remediates with runtime guardrails. All AI risks, from GPU to supply chain to prompt injection attacks, are scored and prioritized through the TruRisk platform.
Customer Wins and QFlex Traction
The company highlighted two significant customer wins demonstrating the value of its platform. A Global 300 customer adopted VMDR, ETM, TruRisk Eliminate, and TotalAI in a low seven-figure QFlex annual upsell, consolidating its security stack and reducing exposure windows. A European healthcare company, previously reliant on an MSP, consolidated its vulnerability program with a six-figure QFlex upsell, gaining autonomy and reducing costs. QFlex, now generally available for enterprise customers, is proving to be a strategic lever for platform expansion and upsells.
Executive Team Changes and Strategic Focus
Sumedh Thakar announced key executive appointments to ensure continuity and accelerate strategic initiatives. Shailesh Athalye was appointed Chief Product Solutions Officer to lead product strategy and the ETM business, leveraging his deep institutional knowledge. Nathan Smolenski joined as the new Chief Information Security Officer. These changes are intended to scale the platform, accelerate ROC adoption, and reinforce Qualys' competitive differentiation and market opportunity, particularly within the growing federal pipeline.
Competitive Differentiation and Market Opportunity
Qualys believes its continuous innovation in AI for security and security for AI, coupled with growing AI-native ROC adoption, reinforces its competitive differentiation. The company sees a sharpened market opportunity, particularly with the federal government's focus on fast detection and remediation, and is confident in reaccelerating long-term growth. Management noted that while other solutions generate 'chatter' with more CVEs, Qualys differentiates by providing confidence in exploitability through TruConfirm and actual autonomous remediation.