Autonomous Remediation Is Already Running at Enterprise Scale
Cybersecurity Classified by Officially
The following is a guest blog by ITSPmagazine, based on their interview of Qualys President & CEO Sumedh Thakar at Black Hat USA 2026.
Sumedh Thakar has watched the same clock compress for 23 years. He joined Qualys as an early software engineer on the scanner, when organizations scanned once every 90 days and gave themselves another 90 days to fix what turned up. At Black Hat USA 2026 in August, the now President and CEO of Qualys measured the current expectation in different units. Ninety seconds.
Because the questions have stayed steady while the time to answer them has collapsed. Thakar walks through the sequence security teams keep running:
Layering dashboards on top produces what he calls dashboard tourism, when nothing gets fixed.
He points to the CISA directive requiring government agencies to remediate within three days, and to the zero-day conversations organized around a 24-hour window. Neither target is reachable by handing findings to a person watching a screen. When a board asks how the organization will fight autonomous, AI-driven exploitation, Thakar says the answer cannot be a plan to hire more people.
What Do the Three Pillars Look Like in Practice?
Qualys organizes its answer around three pillars. AI-speed detection compresses the gap between a vendor disclosure and a confirmed finding. Hyper-prioritization tests which findings are actually exploitable in a given environment, rather than scoring them theoretically. Autonomous remediation applies the fix without routing it through a human first.
Detection has to move first, since a three-day detection cycle makes a 24-hour remediation target moot. Prioritization then narrows the field. Teams were barely fixing 5% of what they found even before frontier models raised the volume, and Thakar argues that running an actual exploit against existing firewall and EDR controls cuts a theoretical 1% down to roughly 20% of that 1%.
This is an extract. The publication continues at the source.
Read the original at the source: https://blog.qualys.com/qualys-insights/2026/09/29/autonomous-remediation-enterprise-scale-black-hat-2026-sumedh-thakar
Officially imported this from Qualys’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Qualys — imported from official source
- Official source
- https://blog.qualys.com/feed RSS
- Imported
- September 29, 2026 15:00
- Versions
- 1 recorded
- Identity
https://blog.qualys.com/?p=42501