Is continuous monitoring operationally feasible for mid-sized Indian enterprises without large security teams?
Yes, but continuous monitoring must mean the technology is continuously collecting evidence, correlating changes, and pushing the critical issues that require action to the right owner.
A mid-sized enterprise does not need to recreate the SOC of a large bank. It needs current asset visibility, automated threat correlation, risk-based prioritisation, and clear escalation paths. Analysts should spend their time making decisions on material risks, not sorting thousands of raw findings.
The real barrier is automation debt. Many organisations still rely on periodic scans, spreadsheets, and manually assigned tickets. That worked when remediation was measured in weeks. It does not work against vulnerabilities that can be weaponised before the next scheduled review. Cloud-delivered platforms and MSSP operating models now make continuous visibility practical without forcing every enterprise to build a large internal team.

Himanshu Kathpal, VP of Product Management, Platform and Technologies, Qualys
What is the biggest bottleneck in moving from periodic to continuous vulnerability management: tooling, budget, skills, or process?
Process, particularly ownership and change authority.
Most organisations already have a vulnerability scanner. The failure usually happens after detection. Who owns the affected system? What qualifies for emergency treatment? Who can approve a mitigation at 2 a.m.? Can the security team isolate an exposed asset, or does it need to wait for three other teams? What evidence is required before the issue can be closed?
Skills come next. Running a scan is straightforward. Prioritising by active exploitation, external exposure, business criticality, and compensating controls requires a different level of operational maturity.
Tools and budget still matter, but new technology layered onto a broken process simply creates the same backlog faster. Continuous vulnerability management only works when detection, prioritisation, remediation, and validation are designed into one risk operations center. Enterprise patching is an organisation-wide strategy involving risk, business owners, technology teams, deployment, and verification, rather than a standalone scanning activity.
How is Qualys adapting its India go-to-market strategy around CERT-In’s guidelines? Are this driving localisation or partnerships?
CERT-In is changing the conversation from vulnerability detection to operational proof. It is important to distinguish between the requirements.
CERT-In’s 2022 directions mandate reporting specified cyber incidents within six hours and maintaining ICT logs securely for a rolling 180 days within Indian jurisdiction.
The 2026 AI-security blueprint adds risk-based guidance, including an indicative 12-hour window for immediate containment and patching, mitigation, or removal of exposure for known exploited vulnerabilities affecting internet-facing or crown-jewel systems.
For Qualys, this is not about creating a separate India-only product, but more about mapping the platform to the way Indian customers must operate: identify affected assets quickly, prioritise the exposures that fall inside the regulatory clock, take a patch or patchless action, and retain evidence that the risk was actually removed.
Local delivery also matters. Qualys operates an India cloud platform, and we are placing greater emphasis on regional systems integrators and MSSPs that can help customers build and run these workflows alongside their internal teams and CERT-In-empanelled auditors. The shift is to help customers establish a measurable CERT-In response process.
Does the OT/IT overlap in healthcare and manufacturing create the same AI-driven exploitation risk, or a different pattern?
The attacker economics are the same, but the remediation physics are different.
In enterprise IT, urgency is often determined by exploit availability, internet reachability, and the speed at which a patch can be deployed. In manufacturing, healthcare, and other OT-heavy environments, availability and safety can outweigh patching speed. A production controller, medical device, or clinical system cannot always be rebooted simply because a patch has been released.
That creates a different form of risk: known exposures can remain in service for months because the system is legacy, vendor-controlled, safety-sensitive, or tied to a narrow maintenance window. AI can make it cheaper to discover those systems, analyse their weaknesses, and probe them at scale. The danger is therefore not limited to a rapid zero-day attack. It also includes systematic targeting of long-lived exposures at the IT/OT boundary.
The defensive response must reflect that reality. OT programmes need passive discovery, protocol-aware and safe assessment, strong IT/OT segregation, tightly controlled remote access, configuration monitoring, and compensating controls where immediate patching is unsafe.
Qualys VMDR combines passive monitoring, out-of-band configuration assessment, and safe protocol-aware discovery across industrial environments. OT security must account for performance, reliability, and safety requirements that do not exist in the same form in conventional IT.
What safeguards prevent AI-powered remediation tools from becoming a new attack surface, for example if an attacker manipulates detections to suppress alerts or trigger harmful actions?
An autonomous remediation system must be treated as privileged infrastructure, not as a chatbot with administrator access.
Three safeguards matter most: bounded authority, verifiable evidence, and reversibility.
Bounded authority means actions are restricted by role, asset scope, risk level, and policy. Qualys TruRisk Eliminate supports separation of duties between security teams that recommend patches and operations teams that select assets, schedules, and deployment options. Access can also be limited through asset tags rather than granting platform-wide control.
Verifiable evidence means a single manipulated alert should not be sufficient to drive a high-impact change. Decisions should be corroborated using asset context, threat intelligence, configuration state, and, where supported, exploitability validation. TruConfirm, powered by Agent Val, uses production-safe exploit validation that do not access data or change the target system, while retaining human oversight at critical decision points and supports different levels of remediation automation.
Reversibility means the organisation can stop, roll back, or undo an action. Patch and isolation workflows support rollback where technically available, and automated isolation actions create activity logs showing whether the action was submitted or skipped. High-impact changes to crown-jewel, safety-critical, or production systems should remain approval-based rather than fully autonomous.
The principle is simple: automation should move quickly, but it should never operate with unlimited scope, unverified inputs, or no recovery path.
What does the next major inflection point Qualys is preparing for?
The next inflection point is that cyber risk is moving beyond the CVE.
Vulnerabilities will remain important, and attacker-side AI will continue to compress the time between disclosure and exploitation. But many of the most consequential attack paths now involve a combination of vulnerable software, sensitive data access, excessive identity privilege, cloud misconfigurations, exposed APIs, insecure third-party connections, and autonomous AI agents. that can act on their own.
An AI agent, for example, may have no vulnerability in the traditional sense. Yet it can still create serious risk if it can retrieve confidential data, invoke tools, modify systems, or operate through an over-privileged machine identity. The issue is not simply whether the software is vulnerable. It is whether the system is behaving safely, operating within approved boundaries, and leaving enough evidence to prove that controls are working. Traditional vulnerability management was not designed to measure that.
More broadly, the industry must move from managing isolated findings to understanding complete exposure paths across infrastructure, cloud, applications, APIs, identities, data, and AI. The shift is from theoretical risk to verified risk, from disconnected tools to a shared risk model, and from recommending action to proving that risk was actually reduced.
That is the direction Qualys is building toward across the Enterprise TruRisk Platform with Enterprise TruRisk Management ETM), ETM Identity, TotalAI, TotalAppSec, TruConfirm, Agent Val, and TruRisk Eliminate.
