No results found.
No results found.
No results found.

Podcasts

Episode 384 Deep Dive: Sumedh Thakar | Mythos Turned 30 Days Into 24 Hours.
byKBI.Media

When Mythos hit in April, the security world split between panic and hype. Sumedh Thakar, President and CEO of Qualys, joins KB to make the calmer case that Mythos accelerated an old threat rather than inventing one. They get into why zero-day vulnerabilities now need zero-day remediation, the misread that Mythos runs on your own code while your vendors use it too, the board conversation it reopened, tokenomics and budget pressure, and how much a CISO should really hand to the machines.

About Sumedh:
As a cybersecurity visionary, Sumedh is passionate about making the world’s digital journey safer. His education and early experiences as a coder led him to Qualys, where he rose from engineer to president and CEO. He joined Qualys in 2003, shortly after the company’s founding and in an era when organizations started using the cloud but didn’t know what to call it. His contributions and leadership helped propel Qualys to its current success in cybersecurity.

Sumedh became president and CEO in 2021. In 2019, he was named president, and prior to that, he was chief product officer, driving the company’s vision of making enterprise security more efficient and disrupting the VM space with integrated capabilities like patch management and cybersecurity asset management. A “product fanatic and engineer at heart,” Sumedh was instrumental in dramatically expanding the original Qualys platform’s scope, integrations, and automations. He also scaled the company’s engineering talent internationally with a global 24×7 follow-the-sun product team. He is a co-inventor of five U.S. patents for cybersecurity technology in Qualys offerings.

Previously, Sumedh was an engineer at Intacct, an early cloud-based financial and accounting software provider. He also worked at Northwest Airlines developing complex algorithms for its yield and revenue management reservation system. He has a bachelor’s degree in computer engineering with distinction from Savitribai Phule Pune University.

Keywords: Mythos, AI security, cybersecurity, zero-day, autonomous remediation, vulnerability management, CISO strategy, board reporting, Qualys, Sumedh Thakar, patch management, true risk, exposure management, AI attacks, first-party code

No results found.
AI in Defence – a Partner, Not a Quick Fix

AI in Defence – a Partner, Not a Quick Fix

​AI has been making waves for years now. It has moved from the pages of science fiction into the control rooms of our defence and security agencies and critical infrastructures, watching over networks and inspecting traffic. Why wouldn’t it be when it promises to work faster than humans and spot the tiniest anomaly possible? For defence and cybersecurity, where every second counts, this is a tempting offer. The Transition to AI The push toward AI stems from the needs and demands of the cybersecurity space. Threats are now multiplying at a rate ...
No results found.

Business News ↓

Fujitsu Establishes Cyber Defence Lifecycle Strategy for AI Era

Fujitsu Limited today announced the establishment of a cybersecurity strategy to continuously evolve corporate cyber defence capabilities in response to the advancement of generative AI and the increasing complexity of enterprise systems. This strategy implements cybersecurity not merely as an operational measure after IT system construction, but as a cyber defence lifecycle that encompasses strategic planning,...

Why Security Leaders Must Become AI Enablers and Not Gatekeepers

For much of the past decade, the Chief Information Security Officer has been judged on one primary outcome: preventing cyber attacks from happening on their networks. Success meant reducing risk, avoiding breaches, and ensuring compliance, even if that occasionally meant slowing down ambitious technology projects. That definition of the role is now being challenged by artificial intelligence. Across Australian...

How Security Teams Move From Gatekeepers to Enablers

The pace of AI development and rise of AI agents is changing what CEOs and executive boards expect from their security teams. Business leaders now want them to move from gatekeepers to enablers, helping companies move faster than competitors while managing costs and keeping their grip on risks. These expectations may sound unreasonable to some, particularly as AI expands the attack surface and multiplies threats,...

70% Australian of Office Professionals Have Used AI Tools or Services at Work Despite Not Being Allowed Under Company Policies

AI use in the office has now become so widespread that non-technical employees are quickly growing more confident in their AI expertise. In fact, a significant majority of Australian office professionals (75%) believe they understand how to use AI for their job better than the team responsible for managing AI at their company, according to a survey of 250 Australia office professionals who work at companies with a...

The Quantum Countdown Has Started: Why Australian Organisations Can’t Wait for the Threat to Arrive

Quantum computing is steadily moving from research into applied capability, and with it comes a structural shift in how organisations should think about security. At the core of that shift is cryptography, the encryption methods that protect data, secure communications and underpin digital trust across everything from banking systems to everyday online transactions. For decades, this foundation has been treated as...

AI Proving Grounds: Building Cyber Readiness for an AI-Driven Future

Introduction Imagine enlisting in a branch of the U.S. military to be told on the first day of basic training that your unit only conducts live-fire training exercises in active combat zones. No blanks or multiple integrated laser engagement systems, no secure, controlled training environments. Just live ammunition against hostile combatants in enemy territory. Such a scenario would never happen due to the immense...

ASD Didn’t Just Retire the Essential Eight. IT Retired the Checklist Mindset

Introduction Can you prove it, right now, on demand? That's the question the Australian Signals Directorate has just made every Australian board answerable to. ASD didn't just retire the Essential Eight. It retired the idea that a fixed checklist is what good security looks like. The mechanics matter. ASD and the Australian Cyber Security Centre set a 12-month deprecation period for the Essential Eight. Full...

Australia’s Next Cyber Risk Isn’t Detection Failure but Decision Paralysis

Australian businesses have spent more than a decade building increasingly sophisticated cyber defences. They have invested in detection platforms and security operations centres designed to identify suspicious activity before it becomes a serious incident. Yet major breaches continue to occur with alarming regularity. The problem facing many organisations is no longer a lack of visibility. Security teams can see...

What Enterprise AI Efforts Reveal Once the Pilot Ends

Enterprise conversations about AI are everywhere, yet many initiatives still stall long before they reach real production value. From years of working alongside customers, the issue is rarely a lack of ambition, talent, or access to advanced models. AI efforts rarely fail because organizations lack vision. They slow down when teams encounter friction moving, managing, and governing the data AI depends on....

Why Enterprise AI Demands Intelligent Data Infrastructure

The promised benefits of AI continue to captivate enterprise leaders — even as many teams struggle to make AI work at scale. What’s going on? The latest foundation models are extremely capable. Sophisticated frameworks and GPU capacity are readily available. Data scientists and data engineers are eager to build new AI-powered apps. Yet AI initiatives continue to stall — or fail altogether. When I talk to enterprise...

Stop Rebuilding the Same AI Data Pipeline Over and Over

A few months ago, I worked with a customer who had just launched their third AI initiative in 18 months. Each project came from a different business unit, tackled a different use case, and used a different model. Yet, when we mapped out the architecture on a whiteboard, it looked almost identical to the previous two projects. There were new ingestion scripts, new cleaning logic, a new chunking approach, a new...

Your AI Just Became Your Biggest Blind Spot. Here’s How to Get IT Back Under Control

Every prompt your employees type into ChatGPT is a potential data exfiltration event. Every unsanctioned AI agent spinning up in a business unit inherits user permissions and starts querying, aggregating, and moving sensitive data, often with zero human oversight. And most security teams can't even see it happening. That's not a hypothetical. It's the operating reality for AI and data security teams today, and it's...

How Agentic AI Is Transforming Cybersecurity in Manufacturing

While ransomware attacks on hospitals and data breaches at financial institutions tend to get more than their share of media attention, manufacturing remains the most attractive target to persistent threat actors (PTAs) seeking to cause disruption to critical infrastructure. Manufacturers are uniquely vulnerable to cyberattacks by malicious actors. Even moderate disruption to production facilities can have lasting...

Why the AI-first Enterprise Needs an AI-first Security Model

Introduction Zero Trust gave enterprises a decade of clarity: never trust, always verify. But that model was designed for humans sitting behind keyboards, not for autonomous AI agents provisioning their own access, calling APIs, and making decisions at machine speed. The perimeter hasn't just dissolved, it's being replaced by a workforce that never sleeps, never asks permission, and doesn't always leave an audit...

Under the APRA Lens: Governing Financial AI at the Identity Layer

In April 2026, APRA wrote to every entity it regulates about artificial intelligence. The letter drew on a targeted review of large banks, insurers and superannuation trustees, and its findings were unambiguous. AI is being adopted everywhere, but governance, risk management and operational resilience sit at very different levels of maturity, and assurance practices are not keeping pace with the scale, speed and...

AI Coding Boom Raises Fresh Cybersecurity Risks for Business

Australian businesses embracing artificial intelligence to boost software development are being warned that the productivity gains could come at a significant cybersecurity cost unless governance keeps pace. Agentic AI, which comprises autonomous systems capable of generating code, completing tasks and making decisions with limited human intervention, is rapidly becoming a standard feature of enterprise technology...
No results found.
No results found.
No results found.
Security Metrics That Matter

Security Metrics That Matter

Introduction Organisations must move beyond reactive security postures and embrace data-driven decision-making as the ...
No results found.
No results found.

Markets & Trading

YOUR SECURITY NEWSFEED

The KBI Dossier

The Cybersecurity news feed delivered straight to your Inbox.

Technology News ↓

Fujitsu Establishes Cyber Defence Lifecycle Strategy for AI Era

Fujitsu Limited today announced the establishment of a cybersecurity strategy to continuously evolve corporate cyber defence capabilities in response to the advancement of generative AI and the increasing complexity of enterprise systems. This strategy implements cybersecurity not merely as an operational measure after IT system construction, but as a cyber defence lifecycle that encompasses strategic planning,...

Why Security Leaders Must Become AI Enablers and Not Gatekeepers

For much of the past decade, the Chief Information Security Officer has been judged on one primary outcome: preventing cyber attacks from happening on their networks. Success meant reducing risk, avoiding breaches, and ensuring compliance, even if that occasionally meant slowing down ambitious technology projects. That definition of the role is now being challenged by artificial intelligence. Across Australian...

How Security Teams Move From Gatekeepers to Enablers

The pace of AI development and rise of AI agents is changing what CEOs and executive boards expect from their security teams. Business leaders now want them to move from gatekeepers to enablers, helping companies move faster than competitors while managing costs and keeping their grip on risks. These expectations may sound unreasonable to some, particularly as AI expands the attack surface and multiplies threats,...

AI Is Testing the Limits of Zero Trust

For more than a decade, Zero Trust has been the defining principle of modern cybersecurity. Trust nothing, verify everything, and grant the minimum level of access necessary. In a world of users, endpoints and applications, the model made perfect sense. Then, along came AI. What began as isolated pilots and productivity tools has rapidly evolved into something much, much bigger and more consuming. AI is now...
No results found.
No results found.
No results found.
No results found.
No results found.
No results found.
No results found.
No results found.
No results found.
No results found.