Qualys Security Conference

Qualys Security Conference

Qualys Security Conference

QSC Mumbai

De-risk Your Business

With so many disparate tools to measure and manage risk these days, it’s harder than ever to quantify the impact of cyber risk on your businesses. Join us in person to find out how today’s security leaders are evolving from enumerating risk to eliminating it. You’ll hear from industry-leading thought leaders, Qualys customers, and product experts on the latest strategies and tactics being used to measure, communicate, and eliminate cyber risk to drive better business outcomes.

Keynote Speakers

Sumedh Thakar
President and CEO, Qualys

Major Gaurav Arya (Retd)
Indian Army veteran, writer and public speaker

Featured Speakers

Shantanu Bapna
Assistant Manager - Cybersecurity, Adani Digital

Abayavidya Rengahari
Group Manager, Information Security, Infosys

Ashish Bapana
Senior Manager, LTIMindtree

Shailesh Athalye
Sr. VP, Product Management, Qualys

Kunal Modasiya
VP, Product Management, Attack Surface Management & AppSec, Qualys

Mayuresh Ektare
VP, Product Management, Enterprise TruRisk Management,, Qualys

Eran Livne
Sr. Director, Product Management Endpoint Remediation, Qualys

Himanshu Kathpal
Sr. Director, Product Management, Platform & Sensors, Qualys

Sandeep Potdar
Sr. Director, Product Management, VMDR, Qualys

Pranjal Sharma
Senior Product Manager, Web App & API Security, Qualys

8:00 AM – 8:45 AM Registration & Beverages
8:45 AM – 9:00 AM Introduction & Welcome Address Debashish Jyotiprakash, Managing Director, India and ASEAN, Qualys
9:00 AM – 9:45 AM Cybersecurity in the Age of Geopolitical Tensions Major Gaurav Arya (Retd), Indian Army veteran, writer and public speaker

In a world increasingly interconnected and vulnerable to cyber threats, understanding the geopolitical dimensions of cybersecurity is crucial. This session will explore how nations and organizations can navigate the complex interplay of geopolitics and cybersecurity, leveraging Major Arya's insights from his military and corporate experience.

9:45 AM – 10:30 AM If Everything Is Critical, Nothing Is: Unveiling a New Approach to Cyber Risk Management
Sumedh Thakar, President and CEO, Qualys

Sumedh Thakar’s bio

10:30 AM – 11:05 AM A Look Under the Hood - Qualys Enterprise TruRisk Management Mayuresh Ektare, VP, Product Management, Enterprise TruRisk Management, Qualys

Join us for an insightful session, where we'll delve into transforming your risk management strategies. Learn how the Qualys Enterprise TruRisk Platform can enhance your enterprise's approach to risk by providing a unified, comprehensive view. We’ll cover practical strategies for integrating and leveraging Qualys tools to streamline risk assessments, improve threat visibility, and strengthen your overall risk management framework. Whether you're looking to optimize your current risk management processes or seeking innovative solutions, this session offers valuable insights to help you effectively measure, communicate, and eliminate risk across your organization.

11:05 AM – 11:35 AM Break & Experience Zone
11:35 AM – 12:05 PM Qualys Platform - Continuing a 25 Year Journey of Relentless Innovation Shailesh Athalye, Sr. VP of Product Management, Qualys
Shailesh Athalye’s bio


Unlock the full potential of your cybersecurity strategy. Join us to discover how the Qualys TruRisk Platform will transform your approach to managing assets, risks and remediations across the hybrid environment. In this session, you'll learn about upcoming innovations that will shift your current cyber strategy from simply managing assets, risk and remediations to a comprehensive approach. By aggregating these security findings and delivering actionable, enterprise-wide insights, Qualys empowers organizations to align cyber risk with business goals in a cost-effective, strategic manner.

12:05 PM - 12:25 PM Accelerating Vulnerability Remediation process Abayavidya Rengahari, Group Manager, Information Security, Infosys
12:25 PM – 12:45 PM Proactive Risk Management with Qualys Shantanu Bapna, Assistant Manager - Cybersecurity, Adani Digital
12:45 – 13:00 PM LTIMindtree’s Journey with Qualys Ashish Bapana, Senior Manager, LTIMindtree
13:00 PM – 14:00 PM Lunch
14:00 - 14:30 PM VMDR for Multi-Cloud: A Single CNAPP Platform for VMDR, CSPM, CWPP, KCSS, CDP & SAASPM Kunal Modasiya, VP, Product Management, Asset, Web App and Cloud Security, Qualys

Kunal Modasiya’s bio

Managing risk in cloud environments is increasingly complex, with countless accounts, assets, and potential vulnerabilities spread across multiple platforms. Each asset carries unique risk factors—vulnerabilities, misconfigurations, network exposures, threats, and excessive permissions. Aggregating and analyzing this data to prioritize which assets require attention and why they are at risk within your cloud infrastructure can be daunting.

TruRisk Insights simplifies this challenge by correlating key risk indicators to highlight the most urgent threats. Its attack path visualization feature goes further, illustrating how risks can propagate across your cloud infrastructure. This approach helps security teams, cloud operations, and developers focus on the most critical issues. For example, TruRisk Insights with attack path visualization can show the potential exploitation that enables lateral movement from a vulnerable, externally exposed asset with admin privileges. This visibility equips teams to prioritize mitigation efforts where they matter most.

14:30 PM - 15:00 PM VMDR: Putting the M Back in Vulnerability Management Sandeep Potdar, Sr. Director, Product Management, Qualys
Ramesh Ramachandran, Principal Product Manager, Qualys

In today's rapidly evolving threat landscape, traditional vulnerability management practices are no longer sufficient. Cybersecurity leaders must adopt a programmatic and disciplined approach to effectively manage risks across diverse environments.

Join us for a dynamic session that will explore why it’s crucial to integrate comprehensive strategies into your vulnerability management program — across endpoints, networks, AI/LLMs, web applications, and cloud assets. This session will dive into how to:

  • Embrace Rapid Remediation: Learn why speed is vital and how to track vulnerabilities effectively to safeguard organizational assets.
  • Establish a Risk-Based Approach: Get best practices on prioritizing risks, leveraging automation, and fostering cross-functional collaboration to streamline processes
  • Enhance Efficiency and Compliance: Explore the tools to boost efficiency, increase knowledge and fortify your organizational cybersecurity posture.
15:00 PM - 15:40 PM Internal and External Attack Surface Management: Step Zero of Cyber Risk Management Kunal Modasiya, VP, Product Management, Asset, Web App and Cloud Security, Qualys

Kunal Modasiya’s bio

In today’s complex tech landscape, threats can arise from diverse sources—on-premises, multi-cloud, IoT/OT systems, and more. Yet, only 9% of organizations fully monitor their attack surface and understand their risk exposure. Join us to revolutionize your risk management approach. Discover how to:

  • Uncover Every Asset: Utilize innovative passive sensing and patent-pending External Attack Surface Management (EASM) for comprehensive asset mapping.
  • Quantify Cyber Risk: Assess risks with full context, including critical factors like end-of-life milestones and security gaps.
  • Fix Your Broken CMDB: Update your configuration management database to bridge IT and security for effective remediation.

Don’t miss this essential session to strengthen your attack surface management and de-risk your organization.

15:40 PM - 16:10 PM Patchless Patching: Enhanced Cyber Resilience With Your IT Team Eran Livne, Sr. Director, Product Management, Qualys

Eran Liven’s bio

In today’s cybersecurity landscape, prioritizing and addressing vulnerabilities is essential for every security professional, even if you aren’t deploying patches yourself. Join us to explore how Qualys TruRisk Eliminate can empower IT and security teams and transform your approach to risk management by automating patching and implementing mitigations even without a patch. Learn from real-world experiences as customers share why they selected Qualys Patch, their implementation strategies, and the impactful results they’ve achieved. This session will provide valuable insights into achieving significant risk reduction and enhancing your security posture through innovative solutions.

16:10 PM - 16:30 PM Break & Experience Zone
16:30 PM - 17:40 PM Platform Innovation Showcase

Navigating the Threat Landscape for Your Supply Chain and Custom Apps
Himanshu Kathpal, Sr. Director, Product Management, Platform & Sensors, Qualys

Recent high-profile breaches have emerged from unexpected areas—custom business applications and supply chain vulnerabilities. Many of these attacks exploited weaknesses in open-source libraries embedded in critical applications, often undetected by traditional security tools.

In this session, we will delve into the rising threat of supply chain risk, spotlighting recent high-profile breaches. We’ll examine the hidden risks associated with open-source software, and attendees will learn practical strategies to detect, prioritize, and remediate threats like the notorious Log4j, as well as how to implement custom detection techniques. Elevate your organization’s risk management practices to a strategic level, ensuring continuous oversight and informed, data-driven decision-making. Join us to fortify your defenses against open-source software vulnerabilities and protect your digital assets.

Identify Unmanaged Devices and De-risk Your Attack Surface
Himanshu Kathpal, Sr. Director, Product Management, Platform & Sensors, Qualys

69% of organizations said they experienced at least one cyberattack resulting from an exploit of an unknown or unmanaged asset such as software, cloud-based workloads user accounts, and IoT devices. Ultimately, these attacks stem from visibility gaps in the attack surface. This session delves into how Qualys helps you strengthen internal attack surface coverage by leveraging the already-deployed Qualys Agent to continuously monitor your network to identify unmanaged and unauthorized devices in real time. Natively integrated on the Enterprise TruRisk Platform, customers will get a consolidated view of known and unknown assets spanning all environments to measure risk and proactively reduce exposure. Whether by mandate or by choice, it behooves security teams to identify untrusted devices that connect to the network and, more importantly, discover user and business data to help enforce Zero Trust policies.

API Security - Pranjal Sharma, Sr. Technical Product Manager, Qualys

User Identity Risk - Lavish Jhamb, Senior Product Manager, Compliance solutions, Qualys

Managing the Risk of Non-Compliance - Shekhar Rana, Sr. SME, Compliance Solutions, Qualys

5:40 PM – 5:45 PM QSC Wrap Debashish Jyotiprakash, Managing Director, India and ASEAN, Qualys

Conference Highlights

Go beyond enumerating risk.

Simply calculating the vulnerabilities that cyber risk poses to your business is no longer enough. See the latest strategies and innovations leading security experts are implementing to quantify the impact of cyber risk on their businesses so they can focus on the vulnerabilities that matter most.

Explore and secure the digital journey.

Dive into the profound impact of the digital journey and explore how to build in security automation from the data center to the cloud. Industry experts and Qualys leaders discuss automation strategies, preview product roadmaps, listen to your challenges, and answer your questions.

Get inspired.

Engage with Qualys’ customer-facing teams and your peers around best practices and user case studies for applying security automation to real-world challenges.

Who Should Attend

CIOs, CSOs and CTOs; directors and managers of network, security and cloud; developers and DevSecOps practitioners; Qualys partners and consultants; or any forward-thinking security professionals.

Trident Hotel
Nariman Point, Mumbai

Qualys Security Conference will be held at Trident Hotel.

Nariman Point
Mumbai 400 021, India
T: (91) 22 6632 4343
Trident Hotel


Conference Pricing

Attendance at QSC is complimentary. This includes access to all general sessions, breakfast, lunch, breaks, and training.

Travel and hotel accommodations are not included with QSC or pre-conference training.

Trident Hotel
Debashish Jyotiprakash

Debashish Jyotiprakash

Managing Director, India and ASEAN, Qualys

Debashish Jyotiprakash is the Managing Director, India and ASEAN for Qualys and is responsible for sales, marketing, channel management and success in the region. Debashish joined Qualys in 2012 and has held various leadership roles at Qualys including Chief Technical Security Officer and managing director for India and Australia & New Zealand. Debashish is a passionate customer advocate. He helps Qualys customers leverage their investment in the Qualys Cloud Platform and its IT, Security and Compliance applications to reduce cyber risk and prepare defenses for emerging cyber threats.

Previously Debashish held head of business and sales leadership roles at leading India-based technology companies. He holds a bachelor’s degree in computer science from the Government College Rourkela, and a master’s degree in Computer Science from Utkal University / Ravenshaw College.

Gaurav Arya

Gaurav Arya

Indian Army veteran, writer and public speaker

Major Gaurav Arya (Retd) is an Indian Army veteran, writer and public speaker with twenty-nine years of experience including Indian Army, top multi-national companies, media, consulting and public speaking.
Major Arya is the founder of Chanakya Forum, a digital magazine on Geopolitics, National Security and Foreign Affairs. He is the host of the immensely popular conclave The Chanakya Dialogues.
He believes that the teachings of the Indian Army are actually very potent and functional management tools, but need to be accurately interpreted for them to be relevant in the corporate sector. This is what he brings to the table, having worked in the corporate sector for 17 years, before joining media in 2017.
As a public speaker, he speaks at national and international corporate events, and also institutional events. He talks about leadership, motivation, team building, strategic affairs, national security, capability building and more. He has spoken at various TEDx events and in October 2017, he was invited to speak at the UK Parliament on the Kashmir issue.

Himanshu Kathpal

Himanshu Kathpal

Sr. Director, Product Management, Platform, Qulays

Himanshu Kathpal is senior director of Product Management at Qualys. He has over 13 years of experience in cybersecurity and product management, with a specialization in vulnerability management, remediation, and next-generation endpoint security. Himanshu is passionate about developing security solutions that align with the company’s cybersecurity product strategy to meet customer needs, reduce the attack surface, and strengthen the organization’s security posture. He holds a master’s degree in engineering from D.Y.Patil University, Pune, as well as an MBA in International Business Management from NMIMS, Mumbai.

Sumedh Thakar

Sumedh Thakar

President and CEO, Qualys

As President and CEO, Sumedh leads the company’s vision, strategic direction and implementation. He joined Qualys in 2003 in engineering and grew within the company, taking various leadership roles focused on helping Qualys deliver on its platform vision. From 2014 to 2021, he served as Qualys’ Chief Product Officer, where he oversaw all things product, including engineering, development, product management, cloud operations, DevOps, and customer support. A product fanatic and engineer at heart, he is a driving force behind expanding the platform from Vulnerability Management into broader areas of security and compliance, helping customers consolidate their security stack. This includes the rollout of the game-changing VMDR (Vulnerability Management, Detection and Response) that continually detects and prevents risk to their systems, Multi-Vector EDR, which focuses on protecting endpoints as well as Container Security, Compliance and Web Application Security solutions. Sumedh was also instrumental in the build-up of multiple Qualys sites resulting in a global 24x7 follow-the-sun product team.

Sumedh is a long-time proponent of SaaS and cloud computing. He previously worked at Intacct, a cloud-based financial and accounting software provider. He also worked at Northwest Airlines developing complex algorithms for its yield and revenue management reservation system. Sumedh has a bachelor’s degree in computer engineering with distinction from the University of Pune.

Shantanu Bapna

Shantanu Bapna

Assistant Manager - Cybersecurity, Adani Digital

Shantanu Bapna is a skilled Cybersecurity Engineer with over 2.5 years of experience at Adani Digital Labs. Specializing in Cloud Security, Container and Kubernetes Security, Web Application Security, and Vulnerability Management, Shantanu has developed and executed comprehensive security strategies to protect digital environments from emerging threats.
He began his cybersecurity journey as an intern at Adani Enterprises Ltd., conducting internal audits based on ISO 27001 and PCI DSS standards. Currently, as an Assistant Manager at Adani Digital Labs, he focuses on application security, infrastructure protection, penetration testing, and incident response. His expertise in securing cloud environments and Kubernetes clusters using CIS Benchmarks ensures a robust security posture across ADL’s infrastructure.
Shantanu’s certifications include:
eJPT – Junior Penetration Tester, INE
Certified Network Security Practitioner, SecOps Group
Qualys Certified Specialist VMDR
Shantanu’s dedication to cybersecurity and his leadership in cloud and application security make him a valuable speaker, offering insights into the rapidly evolving security landscape.

Shailesh Athalye

Shailesh Athalye

Senior Vice President, Product Management, Qualys Inc.

As Senior Vice President of Product Management, Shailesh leads the product management team and drives the Qualys product vision helping customers assess and improve their IT, security and compliance posture. Since joining Qualys in 2012, he has worked in various security and compliance roles driving innovative solutions, including remote endpoint protection, endpoint detection and response, and SaaS security. In addition, Shailesh headed engineering, research and product management for Qualys Policy Compliance and File Integrity Monitoring, where he helped customers go beyond compliance to drive their IT GRC objectives. Before Qualys, he focused on security research for Symantec ESM and Compliance solutions. Shailesh holds a master’s in computer applications (MCA) from the Vishwakarma Institute of Technology and has various security certifications including CISA, CRISC, CISM. He is also a regular speaker at industry conferences.

Ashish Bapana

Ashish Bapana

Senior Manager, LTIMindtree

Ashish Bapana leads the Vulnerability Management program at LTIMindtree, bringing over 10 years of experience, with more than 7 years dedicated to cybersecurity. Throughout his career, Ashish has successfully implemented a wide range of cybersecurity technologies and processes, including SIEM, NAC, IPS/IDS, EDR, Vulnerability Management, MDM, Data Classification, and Third-Party Risk Management (TPRM).
Ashish holds key industry certifications:

Pranjal Sharma

Pranjal Sharma

Senior Product Manager, Web App & API Security, Qualys

Pranjal is a Senior Product Manager at Qualys, focusing on Application Security, including Web Application Security, API Security, and Malware Detection Services. With a passion for developing innovative security solutions, he is dedicated to safeguarding applications from both external and internal threats. He brings extensive hands-on experience across the security landscape, having worked with a range of application security technologies and methodologies.

Eran Livne

Eran Livne

Senior Director, Endpoint Remediation, Qualys

Eran Livne is Senior Director, Endpoint Remediation at Qualys, leading a team tasked with helping customers improve their security posture through cross-platform vulnerability remediation. He has more than 20-years of product management and computer science experience working in diverse IT and security markets. In 2014, Eran founded mobile security company, LetMobile, acquired by Ivanti. Following the acquisition, he drove Ivanti’s enterprise security and endpoint security and management solutions. Eran holds a bachelor’s degree in computer science from Tel Aviv University and an MBA in high-tech business administration from Technion - Israel Institute of Technology.

Kunal Modasiya

Kunal Modasiya

Vice President, Product Management, Attack Surface Management & AppSec, Qualys

Kunal is currently VP of Product Management for the CyberSecurity Asset Attack Surface Management (CAASM), Web App and API Security product line at Qualys HQ in Foster City, CA. He is Qualys boomerang. He worked at Qualys for 3 years and incubated the XDR product line from inception. Kunal has spent 15+ years working at startups, and big and mid-size companies in cybersecurity, networking, and application security in both product and engineering roles at Juniper Networks, Extreme Networks, Sun Microsystems and Infinera. Prior to re-joining Qualys, Kunal was heading products at Israeli startup in API security and bot management AppSec space.

Jonathan Trull

Jonathan Trull

CISO & SVP Security Solution Architecture, Qualys

Jonathan Trull is a longtime security practitioner and CISO & SVP Security Solution Architecture with over 18 years of experience in the cybersecurity industry and is currently the Senior Vice President of Customer Solutions Architecture and Engineering at Qualys. His career has spanned operational CISO and infosec roles with the State of Colorado, Qualys, Optiv, and Microsoft. While at Microsoft, Jonathan led the Microsoft Detection and Response Team (DART) whose mission was to respond to cyber security incidents around the globe ranging from cyber espionage initiated by nation-state actors to ransomware attacks and included the investigation of and response to the NOBELIUM threat actor campaign which leveraged the SolarWinds supply chain. Jonathan also serves as an advisor to several security startups and venture capital firms and supports the broader security community through his work with the Cloud Security Alliance, Center for Internet Security, and IANS. He is also an adjunct faculty member at Carnegie Mellon University where he mentors and coaches those attending the CISO Executive Education Program. Jonathan is a frequent speaker at industry conferences such as BlackHat, RSA, and SANS and holds several industry certifications including the CISSP, OSCP, CCSP, and GCFA. Jonathan is a veteran of the U.S. Navy finishing his career as a Lieutenant Commander supporting the Information Warfare Domain.

Abayavidya Rengahari

Abayavidya Rengahari

Group Manager, Information Security, Infosys

Abaya is a group manager with Infosys and heads the Information Security Validation Function. Her career expands over two decades in Information Security comprising of vast areas including Vulnerability Management, Compliance Management, Application Security, Secure SDLC, Offensive Security, Security solutions evaluation, process building, evangelization and institutionalization of DevSecOps amongst others. Abaya is passionate about Vulnerability Analytics and its impact in the organization ecosystem, working on building processes and models that can bring about progressive improvements that result in continuous changes to achieve maturity in the system.