Qualys

Qualys

Computer and Network Security

Foster City, CA 215,354 followers

Security and compliance for your global IT assets.

About us

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com.

Website
https://www.qualys.com
Industry
Computer and Network Security
Company size
1,001-5,000 employees
Headquarters
Foster City, CA
Type
Public Company
Founded
1999
Specialties
Security SaaS, Continuous Security, Network Security, IT Asset Visibility, Container Security, Cloud Security, Web Application Security, Policy Compliance, PCI Compliance, File Integrity Monitoring, Certificate Security, CyberSecurity Asset Management, VMDR, Vulnerability Management, Patch Management, and Endpoint Detection and Respons (EDR)

Products

Locations

Employees at Qualys

Updates

  • Qualys reposted this

    View profile for Richard Seiersen, graphic

    Chief Risk Technology Officer @ Qualys | xCISO: Twilio, GE, LendingClub | Author: How To Measure Anything In Cybersecurity Risk etc...

    What do serial recovering CISOs do on vacation? They present to they National Institute of Standards and Technology (NIST) Cybersecurity and Privacy Board. NIST has taken a deep interest in modern approaches to cybersecurity risk management and measurement. Which is great! But there is one problem... It can be a heady topic if disembodied from reality... Its very technical under the hood computationally speaking... And while the technical stuffs are necessary... Its my job (challenge) to keep it connected to the real world... With real world applications and war stories (lots). That is why I have opted to frame the outline as such for my friends at NIST: - Where Your (new) Job Lives - The Job Of Measuring Attack Surface - The Job Of Measuring Risk Surface - The Job Of Engaging Business Stakeholders Stay tuned for other public opportunities to participate in these discussions.... And if you happen to be a Qualys customer, prospect, or related... Feel free to DM me to arrange a briefing. #nist #ciso #cybersecurityriskmanagement #metric #informationsecurity

    • No alternative text description for this image
  • Qualys reposted this

    View profile for Richard Seiersen, graphic

    Chief Risk Technology Officer @ Qualys | xCISO: Twilio, GE, LendingClub | Author: How To Measure Anything In Cybersecurity Risk etc...

    A productively skeptical CISO quipped, "What is a Risk Operations Center and why on earth would I want one!?" My pithy zen koan like retort, "Between value creation and loss exposure lives the ROC – keeping risk within tolerance." That must be a dissatisfying answer for the concrete sequential leader. I will unpack it for you..at least in small part. First, a ROC consumes full stack, hybrid, multi-vendor "risk telemetry." IT, OT, Cloud Native… Asset, Identity, Threat, Vuln etc. (TECH NOTE: A SIEM consumes "event telemetry" and does rudimentary time series data analysis. It can be fed into a ROC Platform. ROCs do stream ingestion as part of ETL. But ROCs mainly persist data in Graph, OLAP, and some OLTP structures (last for workflow etc).  This is due to its high context, change analysis, aggregation and reporting requirements) Second...ROCs normalize similar asset types and risks (vulns, threats etc)… And rationalize disparate scores. Scores can be aggregated based on asset grouping like: Application, Crown Jewel, Business Unit up to Enterprise. Good ROC scoring is relatively noiseless… That means it is consistent when underlying heuristics are consistent… And discriminating when underlying heuristics change. (TECH NOTE: A score is an index over a set of related heuristics...think credit scoring. In that sense, all scores "aggregate" information. But their function is to rank order our "Operational Attention." Note that a score of 10 is not twice as much "score stuff" as a score of 5...it’s not a temperature, weight and etc. ) Third...a ROC prioritizes risk using both operational scores and business impact…in fact they get integrated. Business impact is tied to asset... And impact is measured in Money. This is often at the crown jewel and or business unit level – but not exclusively. ROC algorithms use monetary values to inform "importance scoring." (TECH NOTE: A ROC is not CRQ. You can think of CRQ as a capability within a ROC. A ROCs main job is to prioritize operational work in a capital and operationally efficient manner.) Fourth…a ROC without action is “Yet Another Dashboard Again” (yada yada yada) A ROC should help you buy down risk (in a capital and operationally efficient manner)...ultimately through actions. That means remediation and mitigation integrations are a must… Be it executing automated change based on policy-as-code… Or “person-in-the-middle” enabled workflow… Fifth, a ROC makes keeping risk within tolerance "Explainable to business stakeholders and achievable by operators." This post focused more on the "Achievable By Operators"...by explaining ROC components. The next post will be on "Explainable To Business Stakeholders." So stay tuned! #ciso #riskoperationscenter #roc #crq #cybersecurityriskquantification #informationsecurity

    • No alternative text description for this image
  • View organization page for Qualys, graphic

    215,354 followers

    Today we had a spook-tacular day at Qualys UK - Reading office and a costume contest at our Raleigh office as we celebrated Halloween! From creative pumpkin carving to enjoying sweet treats, our team was embracing the spirit of the season. We’re grateful for a team that’s all in, whether it’s achieving business goals or celebrating together. #HappyHalloween from Team Qualys! #LifeAtQualys

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
      1

Similar pages

Browse jobs

Stock

QLYS

NASDAQ

20 minutes delay

$159.23

31 (24.175%)

Open
153.745
Low
141.7
High
170

Data from Refinitiv

See more info on Bing

Funding

Qualys 5 total rounds

Last Round

Series C

US$ 5.6M

See more info on crunchbase