Qualys Risk Operations Center pitch centers on faster vulnerability response
Qualys outlined a detection-to-remediation workflow at Black Hat, while key questions remain about controls for automated patching.
By Dominic Okoye · Staff Writer
· 3 min read
Qualys used Black Hat USA 2026 to promote its Qualys Risk Operations Center, a proposed workflow connecting scanless detection, exploitability validation and automated remediation. The company says the model is meant to help security teams reduce exposure as AI-assisted vulnerability discovery accelerates, though its product performance claims have not been independently established in the material reviewed.
Sumedh Thakar, Qualys’ president and chief executive, described the approach as three linked stages: AI-speed detection, “hyper-prioritization” and zero-day remediation, according to SiliconANGLE’s report from the event. Qualys separately described the same structure in product videos and Black Hat social posts.
How does Qualys Risk Operations Center work?
Qualys says its workflow starts with an asset inventory and its InstaScan scanless-detection capability, which it says can identify newly disclosed exposures without waiting for a conventional network scan. The company then proposes ranking findings with threat intelligence, the importance of the affected asset and evidence of whether an attack path works in that customer’s environment.
That last element is the consequential one. According to SiliconANGLE, Qualys says its TruConfirm process sends safe payloads to an identified vulnerability to test whether controls such as firewalls or endpoint detection and response tools block the path. A successful DNS-resolution response is treated as evidence that the flaw can be exploited; a blocked payload may move the issue down the queue.
Qualys says customers can then choose among software patches and patchless responses, including mitigation, uninstalling software or isolating an asset. Its Agent Sara product is intended to run remediation in waves, while Agent Val is meant to verify the outcome and provide audit evidence. Qualys also cites patch-reliability scoring and rollback options as safeguards for phased deployment.
Why vendors are pushing closed-loop remediation
Multiple vendor reports describe AI-assisted vulnerability discovery as increasing pressure on response operations. Palo Alto Networks’ Unit 42 said its NOVA research system examined 3,915 open-source projects in two months and reported 14,090 confirmed vulnerabilities, figures that remain vendor-reported research results. Trend Micro says its ÆSIR platform combines automated analysis with human researchers and had identified 21 CVEs across several AI infrastructure platforms since mid-2025.
The implication for operators is less about counting every CVE than establishing a controlled loop: find an exposure, determine whether it is exploitable in the relevant environment, select a proportionate response, then verify that the risk was reduced. Qualys’ CEO told SiliconANGLE that only a fraction of vulnerabilities are exploitable and fewer create business loss, an assessment presented without a supporting study in the report.
Where automated remediation has limits
A true zero-day is a flaw unknown to the vendor that has no patch available. In that case, remediation cannot mean installing a vendor update; isolation, compensating controls or virtual patching may be the practical near-term options. A known, disclosed vulnerability with an available update is a different operational problem.
Fast action also does not remove production safeguards. Nozomi Networks argues that compatibility testing, safety review and maintenance windows can make immediate deployment unsuitable, particularly in industrial and operational-technology settings. The unresolved test for Qualys and similar platforms is whether automation can retain those controls while shortening the time between detection and verified mitigation.
This story draws on original reporting from SiliconANGLE.