Opens in a new tab
vmblog logo 2024 wht (updated)

Qualys Unveils Agentic AI Capabilities at Black Hat 2025: CISOs Embrace Platform Consolidation and Proactive Risk Management – VMblog QA

Share: 

David Marshall | Published: September 8, 2025

 

At Black Hat 2025, Qualys made a significant splash with the unveiling of new Agentic AI capabilities on their platform, drawing strong interest from CISOs and security leaders seeking more efficient ways to manage cyber risk. The company’s booth became a hub for discussions around their Enterprise TruRisk Management (ETM) platform and the innovative Risk Operations Center (ROC) concept, which addresses the growing challenge of exposure management in an increasingly complex threat landscape. According to Kunal Modasiya, Senior Vice President of Product Management, GTM & Growth at Qualys, attendees were particularly excited about the marketplace of cyber risk agents with rating and ranking systems, as well as the ability to create custom agents tailored to unique organizational needs and workflows.

The conversations at Black Hat revealed a clear shift in the cybersecurity industry toward platform consolidation and proactive risk management. While many organizations continue to struggle with managing overwhelming numbers of exposures and filtering through security noise, Qualys’ approach of quantifying risk through dollar values and providing a unified risk language across enterprises resonated strongly with security professionals. The event validated Qualys’ strategic direction, particularly around agentic AI adoption and the growing recognition of identity as a critical attack surface, setting the stage for what Modasiya predicts will be a transformative year ahead with rapid AI adoption in security solutions and a fundamental shift from reactive firefighting to proactive fire prevention strategies.

++  

VMblog:  Now that the dust has settled from Black Hat 2025, what was your main showcase at the event and how did it resonate with attendees at your booth?

Kunal Modasiya:  At Black Hat, we unveiled several new Agentic AI capabilities on the Qualys platform. It was well received. The people we talked to all expressed excitement around our new agentic AI capabilities. They appreciated the concept and practical use cases for this technology. Many who visited our booth really liked the idea of having a marketplace of cyber risk agents – with its rating and ranking system – to help build trust. They loved the ability to create your own agent to respond to each organization’s own unique needs and workflows, as well as the natural language capabilities that allow you to speak to the cyber risk assistant and ask questions.

In our conversations with customers, we know that managing exposures, identifying, prioritizing and remediating cyber risk is a very manual process today. The Risk Operations Center (ROC) augmented by agentic AI instantly solves a key pain point by bringing in operational efficiency in risk management workflows.

VMblog:  What was the most common question or challenge that visitors brought to your booth, and how did those conversations shape your understanding of the current threat landscape?

Modasiya:  Many customers are drowning in exposures and dealing with too much noise. We commonly heard that people are looking at ways to most effectively prioritize the right cyber risk signals and do it in the most streamlined way. We also saw lots of interest and questions around the newly announced agentic AI technology, how it works, and wanting to see it in action.

VMblog:  Can you share any standout moments or interactions from your booth experience? Were there any “aha moments” when demonstrating your technology to attendees?

Modasiya:  Many booth visitors were interested in the platform play – having the entire enterprise all speak the same language of risk based on TruRisk, Qualys’ proprietary risk quantifier. One moment that stands out is a conversation I had with a CISO who wanted to know what we did. I explained how the Qualys Enterprise TruRisk Management (ETM) platform builds out from a risk lens and how each module helps find and define risk within his environment. He found it fascinating how we’re adding all the diverse contexts and marrying all the different types of vulnerabilities and risk across the enterprise into a single feed, providing quantifying factors to risk through dollar value. It really showed how needed and important the innovations we’re bringing to market are for CISOs and organizations to help manage their risk.

VMblog:  How did the quality and engagement level of booth traffic compare to your expectations, and what types of security professionals were most drawn to your solutions?

Modasiya:  As with previous years, we saw many “trick-or-treaters” – booth visitors and attendees that were more interested in the freebies than the solutions. However, notably, with our message around helping CISOs manage risk, we also saw an uptick in interest and booth traffic from many CISOs, directors and security leaders asking questions and wanting demos. Qualys’ value proposition resonated strongly with them, leading to great conversations around how we could partner together.

VMblog:  What were your three biggest takeaways from Black Hat 2025, both from the sessions, to the keynotes, to the conversations happening on the show floor?

Modasiya:  

  1. There was a lot of conversation and buzz around the platform play and consolidation; having a single pane of glass. Customers desire it and vendors are working to provide it, to varying degrees of success.
  2. AI is in almost all security tools
  3. But AI security is still the wild, wild west and we’re seeing many micro brands growing in that field            

VMblog:  From the buzz on the show floor to the hallway conversations, what emerging threats or security challenges seemed to be top-of-mind for most attendees this year?

Modasiya:  The major theme revolved around how to both secure AI workloads and leverage AI for security. People were concerned about ransomware and specific threats. They wanted to know how to proactively identify the most critical risks for their environment and mitigate or remediate before attackers can strike. It’s important to note that while most were concerned about the security challenges that AI would bring, each person experiences cyber risk differently, depending on their organizational exposures and unique environments.

VMblog:  Did any industry announcements at the show surprise you or validate your own strategic direction?

Modasiya:  The wide adoption of agentic AI as a defense mechanism validated our own direction and use cases for the technology. We also saw the rise of identity as a critical attack surface to be managed, spotlighted by some of the big acquisitions announced at the show.

VMblog:  What specific feedback did you receive about your solution that either confirmed your market positioning or opened your eyes to new use cases?

Modasiya:  We’re seeing really good responses from customers doubling down on Qualys -taking on more product lines like ETM and TruRisk Eliminate to reduce risk and growing within the Qualys platform. It’s heartening to see that our customers trust us to have their backs. Many customers came up to meet us, see the new features on display, and talk about consolidating their security stack with Qualys.

VMblog:  How did the reception of your Black Hat presence compare to other major security events you’ve participated in this year?

Modasiya:  In our experience, Black Hat is the most productive security event, with the perfect mix of practitioners to decision makers. The event allows us to engage in productive security conversations at the highest level. As such, Black Hat is a strategic big tent event for Qualys. Of the external events on the market, it’s our flagship security event that we participate in, with the biggest spend.

VMblog:  Based on what you learned at Black Hat, are there any immediate adjustments you’re making to your go-to-market strategy or product messaging?

Modasiya:  We are accelerating our go-to-market activities around our ETM solution, which is at the heart of the ROC, based on the interest we’re seeing. We showcased the ROC experience at our booth to let people see how it would operate. We’re helping organizations establish their own ROCs, leveraging the Qualys ETM solution.

VMblog:  Looking at the conversations and connections made at Black Hat, what trends do you expect will shape the cybersecurity industry over the next 12 months?

Modasiya:  We expect to see a rapid adoption of AI within security solutions to streamline workflows and augment what security practitioners can achieve. There’s also going to be growing interest from the security community in taking a more proactive stance toward cyber risk management. With this shift in focus from firefighting to fire prevention, we’ll see a corresponding shift in budgets from reactive to proactive solutions that improve the security posture, making defenses more robust before a breach even happens. Lastly, we’ll see a rise of the ROC as the epicenter of proactive cybersecurity.

VMblog: Would you consider your Black Hat 2025 participation a success? Do you plan on sponsoring Black Hat USA 2026? What would you do differently for next year’s event? 

Modasiya:  Yes, Black Hat 2025 was fruitful and rewarding for us and we have already signed on for Black Hat in 2026. Next year, we’d look to continue and double down on in-person customer interaction, which always yields useful and interesting feedback.  

##