SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Computer network digital shields security locks ai humanoids monitoring threats

Qualys launches Agentic AI agents to streamline cyber risk ops

Tue, 5th Aug 2025

Qualys has introduced new Agentic AI capabilities on its platform, which extend autonomous risk management through a marketplace of AI agents designed to streamline cyber risk operations for organisations.

The latest development from Qualys sees the addition of a marketplace of Cyber Risk AI Agents into its platform.

These agents deliver real-time risk insights across multiple attack surfaces and prioritise exposures based on business impact. According to Qualys, these AI agents autonomously remediate issues at speed and scale, supporting the operations of a Risk Operations Centre (ROC) and aiming to help organisations reduce both risk and operational costs.

As organisations face a rising volume and sophistication of cyber threats and more complex attack surfaces, Qualys asserts that traditional methods have struggled to keep up with the volume of exposures. The new approach, using self-orchestrating AI agents, aims to mitigate manual bottlenecks that leave security teams facing lingering exposures.

Tyler Shields, Principal Analyst at Enterprise Strategy Group, commented,

"Cybersecurity has never been able to keep pace with the volume of enterprise exposures due to human-scale prioritisation and remediation. Integrating Agentic AI into the Qualys platform marks a major leap - from reactive response to real-time risk reduction. With autonomous remediation and intelligent prioritisation, this type of innovation enables faster risk reduction, more efficient resource usage, and greater accuracy in recommended actions. This evolution shifts security teams from tactical responders to strategic agentic AI orchestrators, bringing us closer to a future of self-healing cybersecurity."

Embedded AI for risk-centric automation

The AI capabilities are now embedded in Qualys' Enterprise TruRisk Management (ETM), which already functions as a core element of the company's ROC framework.

Qualys states that ETM aggregates exposures for organisations to measure, communicate, and reduce cyber risk in line with business value. The integration of Agentic AI introduces pre-built AI agents that automate threat prioritisation and remediation approaches aligned with an organisation's specific risk appetite and operational context.

Included with the update is the Cyber Risk Assistant, a prompt-based interface that assists security teams by navigating risk management processes, providing context-aware insights across millions of exposures, and facilitating autonomous operations within risk management workflows.

Capabilities of the AI agents

The Qualys marketplace features ready-to-use AI agents offering several functional advances for security teams:

  • Continuous risk insights: AI agents continuously discover external attack surfaces, assess risk in the context of emerging industry threats, and prioritise risks according to each organisation's unique assets and operating environment.
  • Adaptive remediation: Agents, such as the Microsoft Patch Tuesday Lifecycle Agent, identify and correlate prioritised vulnerabilities with available remediation options, reducing both the cost and the time required to address security vulnerabilities. These agents focus on reducing mean time to remediation (MTTR) in response to threat actors' rapid exploitation of newly identified vulnerabilities.
  • Customisation: Security teams can design custom, no-code AI agents tailored to specific business needs and risk management processes. These agents can be trained and reused to support scalable and repeatable automation tasks within an organisation's unique operational context.

Sumedh Thakar, President and Chief Executive Officer of Qualys, said,

"Qualys Agentic AI, embedded into Enterprise TruRisk Management is transforming how organisations manage cyber risk and powering a smarter, more agile Risk Operations Centre. It's ushering in a new era where CISOs can augment their security teams with intelligent AI agents that perform autonomous analysis and take decisive, high-impact actions to reduce risk faster, more strategically, and with greater efficiency."

Operational focus

According to Qualys, the new Agentic AI functions can automate and streamline various stages of risk reduction, contributing to overall improvements in cost efficiency and effectiveness for security operations teams.

The company states that these AI-driven solutions are intended to address industry-wide challenges in risk management stemming from increasingly complex infrastructure and the proliferation of cyber threats, with particular emphasis on aligning remediation efforts to business-critical priorities.

Follow us on:
Follow us on LinkedIn Follow us on X
Share on:
Share on LinkedIn Share on X