Cyber risk management redefined through AI-speed detection and zero-day remediation Qualys Inc. President and CEO Sumedh Thakar unveiled a three-pillar cyber risk management approach at Black Hat USA 2026, combining AI-speed detection with agentless scanning, hyper-prioritization via exploit validation, and zero-day autonomous remediation to compress the window between vulnerability discovery and weaponization. Thakar noted that while organizations may face millions of vulnerabilities, only 1% are exploitable, and a small fraction lead to business loss, underscoring the need for prioritization. Qualys also introduced TotalAI, an AI governance platform providing visibility into AI models and GPU usage, and emphasized the Risk Operations Center as the strategic hub for enterprise cyber risk management. Cyber risk management redefined through AI-speed detection and zero-day remediation As many organizations struggle to survive by rebuilding their cyber risk management with expediency in mind, Frontier AI is turning newly discovered vulnerabilities https://siliconangle.com/2026/05/27/cogent-security-launches-autonomous-vulnerability-response-tools-ai-assisted-exploits-outpace-scanners/ into usable weapons within hours. According to Sumedh Thakar https://www.linkedin.com/in/sumedhthakar/ pictured , president and chief executive officer at Qualys, this need to compress the window between vulnerability discovery and weaponization is a sentiment he hears in nearly every conversation at Black Hat 2026. The problem isn’t necessarily the volume of vulnerabilities, but that the human resources were never sufficient to combat the exploited ones. Thakar presented a three-pillar approach: AI-speed detection with agentless scanning, hyper-prioritization through exploit validation and zero-day autonomous remediation. All three operate in tandem to solve the vulnerability in hours. “If we could fix everything, we would have just done it,” Thakar said. “You might have millions of vulnerabilities, but only 1% of those are actually exploitable, and then only a small percentage of those actually lead to a business loss.” Thakar spoke with Krista Case https://www.linkedin.com/in/krista-case/ at Black Hat USA https://www.thecube.net/events/informa-tech/black-hat-usa-2026 , during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed Qualys’ new scanless scanning capability, its AI governance platform TotalAI https://blog.qualys.com/product-tech/2026/07/29/ai-governance-evidence-gap-totalai and why the Risk Operations Center https://siliconangle.com/2026/08/04/servicenow-debuts-six-autonomous-security-products-built-armis-veza/ has essentially become the strategic home for enterprise cyber risk management. Disclosure below. Cyber risk management evolves from dashboards to the Risk Operations Center Qualys’ exploit validation https://siliconangle.com/2026/08/04/armorcode-targets-runaway-ai-costs-four-new-remediation-agents/ works by sending safe payloads against identified vulnerabilities. This tests whether defenses like firewalls and endpoint detection and response tools will block the attack path. If a DNS resolution comes back, the vulnerability is confirmed exploitable and moves to the top of the queue. If the payload is blocked, the organization has more time. The validation layer, combined with an AI-generated patch reliability score, provides security teams with the confidence to push autonomous patches without worrying about an outage. “We send a safe payload. A safe payload could be as simple as saying, can you resolve this DNS name?,” Thakar said. “If we see the DNS resolution come through, we don’t need to update your system or write anything. We can tell we could compromise it.” On AI governance, Thakar said the conversation has changed from blocking shadow AI to understanding it. Organizations that have no shadow AI problem likely have a business problem, meaning they aren’t using AI at all. Qualys’ TotalAI platform provides security teams with visibility into where AI models and GPUs are running, tests models for inappropriate outputs, monitors what data is being used for training and helps build policies to govern sanctioned AI infrastructure. “No matter what new technology comes, the question will always be the same: where do I have it, can I assess it, can I prioritize it,” Thakar said. “If I don’t get it fixed, what was the point of this dashboard tourism?” The Risk Operations Center is Thakar’s answer to the fragmentation issue that leaves CISOs unable to answer a simple board question: how much dollar-value loss am I exposed to on my most critical business unit? Cloud risk, identity risk, misconfiguration risk and vulnerability risk currently reside on separate dashboards with incompatible scoring scales. The ROC pulls all of that into a single, normalized view, maps it against business context and translates technical findings into the financial language boards are familiar with. “That’s like when you get car insurance. You have to say, ‘I’m going to pay $1,000 to insure a car that is worth $50,000’,” Thakar said. “If you don’t know what the car is worth and you don’t know what you’re trying to protect, then you are taking infinite risk.” Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Black Hat USA https://www.thecube.net/events/informa-tech/black-hat-usa-2026 : Disclosure: TheCUBE is a paid media partner for Black Hat USA. Sponsors of theCUBE’s event coverage do not have editorial control over content on theCUBE or SiliconANGLE. Photo: SiliconANGLE A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network , where technology leaders connect, share intelligence and create opportunities. 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links. About SiliconANGLE Media SiliconANGLE https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552 , theCUBE Network https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da , theCUBE Research https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f , CUBE365 https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6 , theCUBE AI https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683 and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.