Reading the Cyber Tea Leaves for RSAC 2027
What do thousands of cybersecurity practitioners actually care about — and where is the industry really headed? Laura Koetzle, Head of Community Research at RSAC, joins Alan Shimel on Techstrong TV to walk through the newly released Volume 6 report and preview the road to RSAC 2027. A 20-plus-year Forrester veteran and RSAC Program Committee member since 2013, Laura explains how her team mines Call for Submissions, session attendance and exhibitor data to separate what security professionals say they care about from what they actually spend their time on. The conversation covers AI’s continued dominance and its likely evolution toward governance, risk and compliance, why senior leaders are hunting startups again at levels not seen since 2022, Brazil’s surprising rise as the second-largest country contingent at RSAC, and how a 700-to-8,000 explosion in cyber companies is reshaping the vendor landscape. Laura also previews the RSAC 2027 Call for Speakers window opening late July or early August.
Transcript
Hey everyone, welcome back to Techstrong TV. It's getting near that time of year. It's July.
It won't be long now, I assume, until we start hearing about call for speakers and other good news coming up around RSAC 2027. I can't even believe I'm saying 2027 already, but here we are. Let me introduce you to Laura Koetzle.
Laura's been with us a few times. She's head of community research at RSAC, and we're going to talk to her about what's going on there. But first, let's welcome her.
Hey, Laura, it's great to see you. Thanks so much for having me. It's nice to see you, too.
All righty. So Laura, I mentioned you're head of community research, and I know we've asked you this before, but not everyone who's watching this watched other videos of you. Give the folks a little bit of your background.
Sure. So the community research program is essentially RSAC's program, so that's the company that runs the conference that all of us in cybersecurity go to, hopefully every year. I'm not going to tell you how long I've been going because it makes me feel entirely too old.
And what we do- Mm-hmm ... in the community research program is use all of the data that everyone shares with us in preparation for the conference to figure out what's going on in the cybersecurity industry. Because it gives us a really good window into what everybody's priorities are, what the latest technology is, what the newest problems are, and so on and so forth.
And so we try to give everybody predictions and recommendations on the basis of all of those things that people share. As for me, I've spent rather longer than I care to admit, doing research about the cybersecurity industry. I worked for Forrester Research for many, many years before coming to RSAC, although I've been on the program committee for the conference since 2013, so I have read a lot of call for speaker submissions.
Wow. I would imagine you have. Not to put you on the spot, but is there any date that call for speakers is scheduled?
I know it's usually in July. This year the conference is, what- It'll probably be around the end of July because the- Yeah ... 2027 conference is only a week later.
Is a little later, isn't it? Yeah. It's like April 5th to the 8th.
It's only a week that way. Yeah. It's only a week, so- Yeah.
Well, the only reason I know is my wife's birthday is April 7th. She usually comes out with me to RSA, and we go to Napa, and I remember saying last year that, "Hey, it's going to be your birthday, and we'll celebrate your birthday out- Yes ... " So that's why I know it's April 5th to the 8th.
Yeah. Um. But call for speakers should be about the same time, so- Crazy little things ...
look for an announcement for- Yeah ... everybody who wants to submit, and you should. Couple weeks.
Yeah, at the end of this month or maybe the first week of August. Love it. Let's segue or pivot a little bit though, Laura, and come back to community research.
You guys recently, you've been putting out research reports now for some time. Volume six was recently released. Well, you could explain it better than I can.
What's in volume six, Laura? Sure. So volume six is what I affectionately would call the post-conference report.
So essentially what we've done is taken everything we learned from what everybody did and focused on at the conference, and seeing what that tells us about what's liable to be important over the next 12 months. So because the research that we put out prior to the conference typically reflects what did people submit, what are people's plans, what are their priorities, and this particular report that came out two weeks ago-ish, is more about, okay, what did they actually do? Because as anyone who's ever done any social science research can tell you, what people say they do and what they actually do are sometimes not the same.
So revealed preference through what people do at the conference is actually really interesting because it tells you what they're going to spend their very scarce time, what they're at while they're at the conference on. So if I were to give you the kind of top level summary, the kind of couple bullet points are, this one will surprise no one, AI and ML security was the most focused on topic by a ways, by people in all kind of groups in the cybersecurity industry in 2026. Which makes complete sense given the amount of change and amount of ferment, both in the world of kind of frontier models in general, and also of the application of those technologies to the world of cybersecurity.
And the- Got it ... one of the things that people immediately pick up on when they read the report as well, is we're saying, okay, that will continue to be super important throughout the next 12 months, and indeed, we think at the 2027 conference. The slight difference that you'll see is that whereas in 2026, basically everyone from CISOs all the way through to very new people in the field focused the most on AI and ML security.
" So that's kind of the whole arc of what we think is going to happen, both what did happen at the conference and what we think will happen over the course of the next 12 months and through 2027. And then the couple of other things that stand- Interesting ... that stand out Are the kind of senior leaders prioritized, kind of focusing on startups more in 2026 than they ever have?
Or look, well, ever is a strong word, but at least since 2022. And then I suppose one could do research further back, but that gives you a sense of how things have gone for the last several years. And that's noteworthy because everybody's looking for new solutions.
For all of the kind of usual chorus about how we are completely oversaturated with technology and providers in cybersecurity, clearly people are still looking for new stuff, if you look at what they actually do when they're at the conference. And then the other things that stick out are, believe it or not, the second-biggest country contingent at RSAC, and this has been true at least since 2023, is from Brazil. Now, if you looked at a map recently- Really?
Yeah. You know Brazil isn't next door, right? I actually did the calculation just to see how long on average do they have to fly for to get to San Francisco.
And it's- Oh, no, it's a flight. Yeah. Yeah, I live in South Florida, and so Brazil's a popular place, but it's a far, I think it's six hours from Miami.
Yeah, it's 16 hours from San Francisco to São Paulo. Oh my God. So, they're flying 32 hours each way to come to our conference, which is wonderful and a huge investment of time and money to come.
" And what's interesting about that for global companies is that if you're looking for new places to find talent, because we are always looking for new talent in this industry, we never have enough people, Brazil's actually a great place to look because it's one of the few places where the gap between kind of the number of cybersecurity positions available and the number of people taking them has narrowed over the last couple of years. Like everywhere else, it's grown, as in we have more positions than people, at least in the kind of gross aggregate. So, interesting place to look.
It also gives you some kind of attractive arbitrage opportunities on labor cost if you're based somewhere higher cost than Brazil. And it's also kind of an attractive lifestyle destination for staff looking to live somewhere without blizzards in the winter. So, it can be a great place to look for talent.
Well, there is that. Right. So you got local talent that is growing- Absolutely ...
" So, you can- Yeah ... you can take your pick of kind of which solution you're going for. Nothing against North Dakota, of course, though.
No, but it is very cold there. But Laura, nothing against North Dakota, for all our friends out there in North Dakota. But I get it.
You know what? I've got a few just points. So you're right, I did think AI sucked the air out of the room of every conversation.
But that wasn't just at RSAC, I think that was everywhere, and continues to do so. And with good reason, right? Yeah, no, absolutely.
But it's directly tied into the second point, which is why we're seeing an explosion of these startups. And keep in mind, when you said you've been going to RSA a long time, I've gone a few years myself. And I remember when the buzz at RSA was, "Oh my god, there's 700 security companies, venture-backed or public security companies.
We can only support 300 at most. " And then that number went to about 2,000 and then 4,000. I think last year or the last number I saw was between 7 and 8,000 venture-backed or public security cyber companies, or companies that have cyber as a significant part of their business.
So, the market never is saturated, it seems, even though we claim it is. But I've also, Laura, I've lived through the dot-com era. I've lived through the dot-com bubble.
I've lived through the recession of 2018, of 2008, '09. I've lived through COVID. And when I say I lived through, I've been in the industry during these years.
At every point, at every layer, boundary layer, when we enter a new era, innovation flourishes, new ideas, new ways of doing things explode like a Cambrian explosion of life, right? And, I think that's what we're seeing right now. I interviewed someone this morning before you.
This guy's a four-time entrepreneur, cybersecurity. Had three great exits to major companies, well-known. An Israeli cyber company.
Just started his newest company. They just came out of stealth with, I think, 70 million in, they call it a seed round. That's the other crazy thing.
A $70 million seed round. A seed round used to be 7 million was a great seed round. Right.
Now it's 70 million. But, so look, I think we're going to see more of this in 2027. I think the whole Mythos thing and Glasswing and all the repercussions out of that is still a rat and a snake working its way through.
Right? I think there are a lot of people who are going to have ideas around this, how to use this to make better security, to do better remedi. I think the focus is going to change.
And it already has. From finding vulnerabilities to fixing or remediating or mediating them. And that's going to create a whole bunch of new activity too.
So I am bullish on the cyber industry. Can't wait to see what the Sandbox and the innovation programs look like this year. Yeah.
So I think the signals you got and that you put into this report are dead on. Dead on. Yeah.
I think I too have occasionally fallen prey to the, "Surely this cannot go on," in the past. Right. And it inevitably does.
Like you say, recessions and COVID and other things cause dips and so on. But fundamentally- Oh, a blip. It's a blip ...
yeah. Yeah. Yeah.
Fundamentally, the kind of innovation continues and something really interesting comes out the other side. The thing that you pointed to with the $70 million seed round, though, isn't an anomaly. That's been an increasing trend recently with companies getting these- Yeah ...
gigantic "seed" and series A rounds. And so what you do see- Yeah ... is a bunch of concentration of investment, right?
So people like the person you were interviewing, who's a successful four-time exiter already, they're kind of getting the lion's share of the funding in a lot of ways. And so it's a little harder for newer entrepreneurs to kind of get seen and heard and get funded than it used to be. Is- Yeah ...
I don't have lots of statistics to back that up, but that's certainly what I've observed, just watching what the funding environment has been like over the last- Yeah ... 12 months or so. But again, that's one of the great things about the Innovation Sandbox and the other innovation programs that Cecilia runs, right?
Cecilia Marignie. There are a lot of first-timers. There are a lot of- Yeah ...
new blood. I remember interviewing, I interviewed the fellow, I think he was from UK, from the company that won last year. I interviewed him at RSA.
Oh, from JordAI. Yeah. They're based in the UK.
Yes. Yeah. Look, everyone looks like kids to me, but they look like kids, right?
It's their first time and I was so happy, and it was a great thing. I'm looking forward to it. Laura, we're running low on time.
Where can- Yeah. We love serial entrepreneurs, but we also love first-time founders- Absolutely ... in Sandbox.
They make the world go round. Yeah. Exactly.
It takes a community, as they say, hence the C in RSAC. Hey, Laura, where can people get Volume Six? So you can just go to the RSA Conference website, and if you go to the library and you click on research, it'll be the first thing that you see.
So grab one of those. And Alan, I can also give you the link if we can put it somewhere when we run this interview. Yes.
We'll put it in the notes if you want to mail it- Perfect ... in to us or whatever. We'll go from there.
Absolutely. Laura, so great seeing you. Keep up the great work.
I'm sure we'll be talking a lot more between now and next April 5th to the 8th. So, this is just starting, this is the beginning, not the end. I know.
We're already preparing. And I look forward to it. It's like- We are.
We are ... April 2027, it's right around the corner. I got you.
All right. Hey, great seeing you. Have a great summer.
Likewise. We'll be in touch. Talk to you soon.
Have a good one. Laura Koetzle. Bye.
All right. Bye-bye. We'll be right back on Techstrong TV.