CyberWire Daily

The WhatsApp impostor.

Apr 2, 2026
Sumedh Thakar, President and CEO of Qualys, a leader in enterprise security and compliance, talks about reframing cybersecurity as business risk management. He outlines creating a Risk Operation Center to drive real remediation. He explores agentic AI as a force multiplier and the need for vendor guardrails and regulatory clarity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Cybersecurity Is A Risk Management Exercise

  • Cybersecurity is fundamentally a business risk management exercise tied to potential financial loss.
  • Sumedh Thakar argues quantifyable loss drives how much you should spend on cyber and guides prioritization across changing technologies.
ADVICE

Prioritize Fixes That Reduce Maximum Loss

  • Focus remediation on fixes that reduce the most potential loss rather than chasing every detection.
  • Thakar recommends operationalizing a Risk Operation Center (ROC) to prioritize and drive actual fixes instead of dashboard generation.
INSIGHT

CISO Pain Is Proving Cyber ROI To Finance

  • CISOs' public priorities (AI, cloud, etc.) differ from their personal pain: convincing finance and the board of cyber ROI.
  • Thakar explains CISOs struggle to quantify risk reduction to justify budgets against competing lines like AI teams.
Get the Snipd Podcast app to discover more snips from this episode
Get the app