Jen Easterly, RSA Conference, and the Future of Cybersecurity Leadership | Security Boulevard Podcast Ep. 16
The appointment of Jen Easterly as CEO of the RSA Conference marks a pivotal moment for the cybersecurity industry. In this episode of the Security Boulevard Podcast, Tom Hollingsworth, Alan Shimel, and Fernando Montenegro discuss what this leadership change signals for the broader security community.
The conversation examines the evolving role of CISA, the growing influence of venture capital on cybersecurity startups, and why public-private partnerships remain essential as threats grow more complex. The panel also explores how AI is reshaping cybersecurity, what upcoming industry events reveal about market direction, and why practitioners must stay informed about funding, policy, and technology trends to remain effective.
Transcript
Welcome to Security Boulevard, the cybersecurity podcast from The Future Room Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms.
Before we jump into this week's episode, let's meet today's panel, and I'm gonna start with our friend, Alan. Alan, it's good to see you again. Tom.
Great to see you. We are, uh, happy to be, I'm happy to be here today. It's a little cold down in Florida.
The iguanas are dropping outta the trees, but, um, happy to be on Security Boulevard today. I, I love that that is the measure of how cold it is in Florida is things are falling out of trees. Uh, yes.
Another place that it's generally pretty cold is in Canada, and that means that we're joined by our friend Fernando. Fernando, it's good to see you. Thank you.
I was squinting about the a it's cold in Florida. I, I, I appreciate it. I totally do.
I'm originally from Brazil, and I understand how in a warmer climate, sometimes what might be considered cold in for them. It's not necessarily cold for places that are more used anyway. Sorry.
Uh, Fernando Montenegro leads, uh, security research with the, with Foot Room, and, and it's such a joy to be with, with, with you guys again. So even if I'm a little bit cold, we had to deal with, uh, with about the foot of snow or so, uh, a couple of days ago and snow broke actually, so, yay. Fine.
Uh, I'm Tom Hollingsworth. I'm the event lead for security at Tech Field Day, and I'm happy to be here as well, even if I am a little bit chilly. But the good news is that today's topic is rather hot.
Uh, so let's jump in because you may have seen news, uh, in the last week or so, uh, that Jen Easterly has been appointed as the CEO of the RSA conference. Um, this is really interesting because, uh, she was formally a part of, uh, csa, uh, the, uh, government Cybersecurity Organization. Um, she is a very well-known person in the security space.
Uh, she's provided a lot of leadership over the years. Uh, she's a graduate of West Point. She spent 20 years in the Army.
Uh, she's held some very senior roles there. And then she transitioned into a post where she was advising the US government on, uh, cybersecurity matters. Um, she was, um, she left that post and she was gonna take a point, a post at West Point that, uh, disappeared, I guess we'll put it that way.
Uh, but now, uh, RSAC has decided that she should be the person to kind of lead the way that that conference is going. com talking about this and giving some of your thoughts about why you think this is a good thing for RSAC. Absolutely.
Tom Jen Easter, easterly led csa. She just wasn't just a part of it. She was the director of it.
And for those of you out there who may or may not be familiar with csa, it's not just an organization that, uh, advises the US government in many ways. It sets the tone, it sets the mark, it sets the, the road for how the US government should do cyber and more than the US government, what I think was really unique and special about csa, and it, and it extended even before Jen took over, when my friend Chris Krebs led cisa before Jen was a unique government private public government corporate partnership to safeguard our critical infrastructure here in the us, whether it be government infrastructure or private infrastructure, talking about electric grids in public, uh, uh, public water, and, you know, truly critical infrastructure communications. And so, CI's role was, you know, for a relatively new organization, right?
CI's role was, I think, very oversized. And, and the charter was big. The, the, you know, they cut it to, they cut the CSA budget and moved that money to ice, basically.
Um, Jen was, uh, Jen and well, as well as most of cisa leadership was axed. And then, as you mentioned, Tom, she was appointed a chair at West Point. And, you know, I'm gonna be a little less diplomatic than you.
It wasn't eliminated for political reasons. It was deemed they didn't wanna have her on. But this is where you gotta admire Jen Easterly.
She never stopped leading. She never stopped leading, even in the face of that intimidation in the face of those political enemies or whatever you wanna call, she kept leading. She kept talking, she kept speaking, she kept appearing, she kept advocating for this community.
And that's just the person that RSA needs. The RSAC needs, the RSA community and conference needs. Right?
About two, three years ago, um, Hugh Thompson and his VC firm, I forget their name off the top of my head now, Crosspoint Crosspoint, Crosspoint Ventures Capital, they spun RSAC out as an independent organization and the chart. And since that time, they've, they've really, you know, laid out a, a vision for what they want RSAC to be more than just a once a year gathering of the industry in San Francisco. They wanted to be truly the security community, a continuous security community.
And I couldn't think of a better person to make that happen and, and kind of plant the flag and be visible out there leading this than Jen Easterling. I'm, I'm, I'm a fan of hers too. Um, and, uh, uh, the thing I would add is that tying that community angle, right?
First of all, uh, I apologize if I say the RSA conference, it's gonna take a while to get used to RFAC conference. So RFA community conference, I'll get there. But, uh, uh, for, for many, uh, listeners and viewers know that it's been the, the, the Foundational security conference for, for years in the industry, right?
Starting with cryptography. And, uh, it's poignant because, uh, it touches, I I agree with Alan, like it's, I I think she has a very wise choice for this, because she's had a role in cryptography specifically, right? She's had a role in, uh, the broader, uh, uh, public policy.
Of course, she's had a whole in private sector, right? She was with Morgan Stanley for, for, for a few years, right? Before taking over csa, right?
And so I think that, uh, that she is, uh, like I said, and, and, and, and then enlightened choice for this type of, of, of role. And I think that I'm, I'm not gonna get too much into the broader politics of it, but I'll say this. I think that we're at the stage in the evolution of this industry where, yes, there are political ramifications one way or another.
Fine, but broader than that, cyber has one. That's a, that's a thing that I've, that I've, uh, I've, I've mentioned a few times on, on this podcast and elsewhere, is that you all, you all remember Mark Andreessen's, uh, paper from, or think from 2011, software is eating the world. Yes, it did.
It ate the world. And, and, and yes, sometimes there was indigestion, right? And, uh, I think that this is, um, uh, we, we live at a time, we live in a time where the interplay between, uh, technology and the rest of the world, we can't tell apart or almost can't tell it apart anymore.
I'm just putting the, the, the, the finishing touches on a paper I'm writing on cyber physical systems, right? Which, uh, which it's basically the evolution of IT and OT security, we still, how we are, how we're fusing these systems together. And it's so clear that it requires us to reach across the public private partnerships to reach to, to, to work with governments, to understand regulation, to work with private sector, to understand constraints, to work with, uh, with vendors, to, to have the right incentives in place, right?
To, uh, to move this industry forward. And, and, and Tom, I'm just, Jo, I'm just in my mind here joking about all the, the, the economic terms one can drop in the context of incentives and externalities and so on. I, I'll, I'll refrain from that for a second.
The, the thing to me though, it kind of going into what you guys have said is there is a huge value in having an organization like CISA around to kind of take that burden off of the government, because let's be fair, everyone knows that the government moves at the pace of a stunned snail and molasses on the best of days. But that's kind of the way that the government is supposed to do things, right? They have to, there are certain rules that they have to do to, to figure things out and to be able to implement policy and, and procedure and things like that.
So to have an organization like CISA that was sitting there saying, well, no, we need to be a little bit more proactive. We need to get out there in front of these things. If you'd have asked me two or three years ago, uh, you know, back when Krebs still ran the organization, um, I, I think that this is, this is a great thing, right?
Like, like they're, they're leading the way. They're transforming the way that people look at cybersecurity, but more importantly, they are being honest with all of us about where the deficiencies are. They're saying these areas need to be beefed up.
These are the people that are creating problems for us. The issue is when the leadership above you doesn't want to hear that, or, or worse, when the leadership above you gets really mad that you make an empirical statement of fact that they disagree with, and they have the power to cut off your paycheck and your funding and everything like that. So even though I kind of started this segment by being a little neutral, now that I'm giving you my opinion, I think it's pretty stupid personally, because you can't pretend that people aren't telling you bad news is coming, and then when the bad news shows up go, I don't know how anyone possibly could have foreseen this and Jen Easterly sitting over there going, yeah, I don't know how anybody could have possibly told you that this was going to be a horrible idea.
Hmm. Really? You can't get rid of leaders like Jen and Chris and a lot of those other senior leadership people who are now gone just because you disagree with them.
In fact, I'm gonna give everybody out there a little a tip. Um, if you're going to evil overlord school, which I am, and I know a lot of other people are, always have somebody around you that's willing to tell you the truth, just make sure they know they need to leave after they do. So you don't get angry and you're like, drop them into a bad of boiling sharks or whatever.
But somebody has to at least be the, the voice of reason in the room, right? It's like, you remember the Roman triumphs. There was always somebody in the chariot reminding the generals that famous fleeting, and they're all gonna hate you tomorrow.
You've got to know that you, you can't live in a, in an idealized world where yeah, nothing bad could ever happen to the us. We're the, the biggest, baddest kid on the block, and yet we still get hacked all the time because it turns out we're also the juiciest target on the block. So I think that the kind of leadership that Jen can offer the industry is that perspective of what happens when policy fights against other policy, when facts are fighting fantasy, and how do you square those things inside of an organization?
Because if you think that this is just a discussion between a government agency and the executive branch, I would like to see what happens when the CISO runs headlong into the CEO and the chairman of the board at any organization where they're like, you can't tell people that our security is bad, the stock price might go down. Yeah. The, I I, I, I was, uh, when, when you brought up that the, the thing my mind immediately went to, uh, world War Z or me being Canada World War Z, right?
The, the, the, the zombie movie. And, and I remember that I mentioned this because in the context of what they call the man rule, right? So the, the, the idea that somebody has to think outside the box, right?
And to a large extent, I see, um, I see CISA in the United States, uh, other agencies in other countries. I'm speaking from Canada here, right? Um, there is this, and, and this is why I go back to why I think her, uh, assignment or her, uh, position in, in the RSAC organization is, is so interesting.
It's because from an economics perspective, right? How to solve an, uh, an externality or, or how to solve a problem where the consumer themselves are limited in what they can do, right? Is that you solve it further upstream as much as possible, right?
So what, uh, what CISA and other agencies do in terms of helping with guidance for, uh, resource strapped organizations is so interesting. The cis a, uh, cals the known and exploitive vulnerabilities, for example, right? Um, I'm also reminded of, uh, Wendy Nader's concept of, uh, the, the cybersecurity poverty line, right?
In, in that, how do we help organizations get better? Uh, how do we when they don't have the resources to do as much? So I think that this is a role that I, that, Alan, to your point, if, uh, the RFAC organization is, is more of a year round thing, it helps with this kind of broader message year round, right?
Um, so yes, I think that, uh, uh, I'm navigating the, the, the politics carefully here because we do have audiences on, on, on both sides. I have an opinion too that I think that I would like to see more collaboration, not less, but, um, but, uh, uh, sorry, I lost my train of thought here. I think that, that there's a, a lot of positives in this, in this assignment.
So I've got a few thoughts here, Tom and Fernando, on what you both said. First of all, in, in regard to the role of CSA within the government, I, I think, I think it speaks volumes that the fact of the matter is the last two directors of csa, as I mentioned before, and Tom you mentioned Chris Krebs, Chris was fired, fired in 2020 for saying that the election was not fixed or fraud. And the president at the time fired him as a result.
And as a matter of fact, same president has directed the Department of Justice to investigate Chris, whether you want to call it retribution or whatever, but to continue harassing him. Jen Easterly and sister were fired 'cause she was a Biden administration primarily. They, they purged the Biden administration to put loyalists in there.
At the same time, they degraded the budget and scope of the agents. That's that. You, you can't look backwards.
You can only hope that as we go forward, the necessity of sisa, like organizations win the day. And, and we do put priorities in place there with that. In terms of RSA, uh, Fernando, you pointed out today, it seems the US government is still on their attribution kick with this.
And as now directed, and I don't know if this is true or not, we just saw a report on LinkedIn has directed us agencies to pull out of the RSA conference. Who loses? Well, at some level, we all lose because we should have one community, which is kind of the message behind RSAC.
But ultimately, I think the federal agencies lose a lot more than the rest of us, because if they isolate themselves, if they go to a pre CSA thing of being up on an ivory tower without integrating into the community, without understanding learning, cross pollinating ideas, theories, technology. No, no. Government is an island today.
No nation is an island today. No person is an island today, right? Today, more than ever, we need a strong cyber community.
We need a strong public private partnership. It's sad that it has to come to this. It's sad.
However, I know Hugh, I know Linda Gray. Martin, I know Brita, glad I know the people behind RSA, they, they're not stupid people. They, they didn't go into this with blinders on or blinkers on, not realizing this may have be a potential repercussion, but I think they're in it for the long game.
This too shall pass. And, and that's my take on it. Well said.
Let's Move on to some happier news. And by happier, I mean, some people are getting paid. Um, one of the things that Alan brought up when we were doing some research for this show is the fact that there are a lot of cybersecurity companies that have recently emerged from stealth, and they are driven by ai, specifically AI penetration testing, ai identity security, and AI agent platforms.
And I know that we've discussed this quite a bit on some previous episodes of Security Boulevard so far, talking about the need for securing agents, how agents are gonna provide security in different areas. But I always go back to what does the Smart money say? And in this case, the smart money, which is, you know, tens if not hundreds of millions of dollars are investing in companies like Novi and Seven AI and Opti to provide these kinds of services.
Betting big on what that next, uh, company that's gonna have a groundbreaking security offering is gonna be. So I kind of want to toss this out to, to you guys a little bit. Do you think that these companies are doing some great research knowing that they're just on the cusp of some amazing breakthrough?
Or is this the typical startup mentality of, I've just gotta keep the runway going long enough for somebody to buy me? Look, I, you know, I've been involved with VCs for many years before I did Techstrong, I spent 20 years plus in the VC back startup world. I have good friends in the VC space.
The VC model is not a do good a charity model, right? They're in it for the money. And if they're investing this kind of money, and, and let me just quantify when I say this kind of money seed rounds of $80 million, $50 million seed rounds, a good seed round used to be $4 million, $3 million, a good a round, $12 million.
These people are raising 50, 80, and a hundred million dollars in seed money. That's like before market fit even money. So, you know, we're talking about a big amount of money.
And you know what you would think by rational smart people, smart money, as you said, Tom, so they see a huge return here. And, and the VC window keep in mind is not investing for 20 years. Now, they're not even investing for 10 years.
They wanna see a return of three to five years, seven at the outside. They gotta close that fund down in seven. So if you're seeing this kind of investment by these folks, you, you have to assume that they see, you know, a decent return within three to five years.
You know, um, when you're talking about 50, 80, a hundred million bucks, a decent return is not a pittance either. You're talking billions of dollars probably, right? Well, the VCs talk about 10 baggers, 10 Xers.
That's, you know, Fernando, I see you wanna say something? Go ahead. Yeah, no, I, I, I, I, I, uh, similar to you, I've, I've, I've been around and, and, and I like to track the, the, the money where it goes and, and so on.
And, um, what I find is that there is a, uh, I always say that VC money is like rocket fuel, right? And it, uh, it works wonderful if you put it in a rocket, right? If you happen to not be putting it in a rocket, that might not be the best thing, right?
And, and we've seen tremendous, uh, we've seen tremendous, uh, uh, businesses that grow sometimes bootstrap, right? Uh, and, and they, they grow to certain five, and and that's fine. And, and they may have, uh, and they may deliver value that, right?
Um, the thing on my mind about the, the, the current, uh, the current funding is that it's very much we are, we as an industry, like we, we we're funding the startups because they need to absolutely move fast on things, and they need to move fast on things without that. They need the runway. They, they need to be able, they, they need the runway to, to, for the tech to mature, but they need to move quickly so that they do capture the kind of early mover advantage, right?
And at, at Tuum, there are three trends that we're majorly tracking, right? We're, we're tracking the modernization of security operations, the modernization of security infrastructure, and the modernization of security governance. Those are the three main ones.
I'm, I'm, I'm involved in, and we're definitely seeing this 2026, like to go back to your three to five year thing, 2026 is one of the, one of the things we're calling now is we are definitely expecting that this is the year where we start seeing that rubber meets the, uh, reality of agentic security, agentic workflows in security operations, right? So, can I get my AI sock off the ground doing meaningful work for me in a correct fashion, right? So this is very much the time to be putting money into these type of, of, uh, of startups.
And I'm navigating carefully because like, we don't do vendor endorsements, right? So I'm, I'm observing the, the, the observing the space. I know the, the seven AI folks and, and, and some of the others, right?
So, um, this is very much a time to be doing that. And I, identity is another one, right? Mm.
Uh, we saw the, the, I mean, Palo Alto dropped $25 billion for CyberArk. The deal should close in the, in the, in the near future, right? Uh, we saw a massive funding round, massive for, uh, SAVI back in December.
I think it was 700 million, I believe. Uh, and, and, um, so identity is very much the second, uh, element that, uh, uh, I'm, like I said, I'm, I'm, I'm working on a, on a paper and cyber physical systems, and, and one of the things that pops up is just managing the, the, the explosion on identity we're past the, the, the human scale, like, I, I really like to call it for managing these things. So this is very much a time for this funding.
I think that thematically, sorry, I'm long-winded comment, but thematically, I think that, that these are very interesting areas to invest in. Well, I'll, I'll reserve judgment on the vendors themselves, right? But it it, but it is very much a time to do this.
But Alan, you raised a phenomenal point, which is this is not being done for Cherokee, right? And this is being done to position these organizations to be successful. Uh, what my message to, to security practitioners and and executives is that you have to understand the, the, the, the pricing dynamics that, that play on here.
Like, are you going to switch from a, uh, ingest based pricing for events to your sim right? To, uh, to an incident based pricing for your ai? So, oh, look, if I handle an incident, it costs X much, right?
So my, my, uh, my advice to, to practitioners is stay on top of these trends, right? These vendors and others, but understand how incentives are aligned and how the, the, the pricing is gonna change moving forward. Fernando and I realize was low on time, I'll try to move it along.
Don't assume as a security practitioner that the company that raised the most money is the best solution, right? This VCs don't operate like they're at a, a, a racetrack. And you bet on horse number seven, and I bet on horse three and let the best horse win.
The best horse doesn't always win. As a matter of fact, there's a school of thought in the VC that if I give the, my investing company, my company, that I invested in so much more resources than the next guys have, right? They will have more money to make more noise and do more marketing and more sales, even if their product is mediocre at best, right?
Because they have more money, they're gonna win. And winning here means the biggest liquidity event, the biggest return on my investment. And so sometimes you look and say, well, this company raised more company A, raised more money than company B, company A must be more valuable, company a must have better technology.
No, if that was the truth, we'd all still be on OS two war, right? Or whatever the latest OS two is. Um, it's, there's a, there's a rhyme in the madness to VC investing that sometimes gets lost.
And, and so pick the best solution for you. Oh my God, yes. Uh, there is a, uh, me in economics, there is a, uh, there's a famous paper by, uh, uh, or not so famous, perhaps by Ian Grigg called The Market for Silver Bullets, right?
Yeah. And, and, uh, the, the interesting thing there is that it explains that the market for silver bullets, and I promise not, no, not an economics lesson in the last five minutes, but it refers to a famous paper called The Markets for Lemons, right? Which was a Nobel Prize for George Akerlof and others back in 2001, I believe, on information asymmetry, which is a foundational concept, which is how do you value the quality of something, right?
And, um, or how do you discern the quality of something? And I think that this is phenomenal information, information for security practitioners. Alan, to your point, people have to discern what is the quality of what they're buying and how you are gonna do that.
And, uh, I mean, we could make an entire series on, on economics, but, uh, there is a, the, there is a concept of signaling, and the concept of screening signaling is when you as a vendor, like you signal the quality that you have, Alan, to your point, I have more money I'm gonna signal to the market that I have all of this and that. But the flip side of that is screening. As a buyer, how do you create a process that screens out the quality of what you are buying?
And I mentioned this here, this all comes full circle, because as a, as a practitioner, right? My, my advice to you is that you are being in, you are increasingly being affected by broader geopolitical events, right? This thing is increasingly important, right?
Cybersecurity is that much more strategic, right? And you need strong communities in part to help you with the signals that if somebody participates in that community in a, in a, in a good manner, that's a signal, right? And that community can help you create the screening criteria that you are gonna use on your evaluations, right?
So again, it, I, I know it sounds like a joke, but everything turns around economics for me, right? And, and as you observe exactly said as you observe the, the, the, the investments that, that, that be made, yes, by all means, it's an important signal, but it's not the only one. So buy what you need and we can talk about other stuff later on.
Sorry, I, I, again, I I, I get too excited about this. That's okay. We love people that get excited about what we talk about here on the podcast, but we hope that you're also getting excited about the things that we do that are not on the podcast.
Fernando, what have you got coming up that people should check out? So we just published our, uh, we just finished our data set and cybersecurity decision makers, and it lines up, uh, a lot of this, these trends I'm talking about. So I'm really excited about that.
Uh, I'm finishing my paper in Cyber Physical Systems. Uh, I promised that it'll be done today, maybe tomorrow, and sent to, to peer review and, and, and whatnot. And, um, I'm starting to plan what my, uh, my participation at RSA is going to be like.
I'm really looking forward to that. And yes, it's, uh, it's, it's, uh, it's starting to get busy for industry analysts. We get particularly busy around, uh, uh, spring and fall, right?
So, yeah, I'm, I'm, my calendar is looking. We are great. Now, Alan, what about you?
You know, it's that funny time of year, Tom. We just fi Tom. We just finished, uh, predict 2026 last week, which is our kind of look ahead to the year.
We, I think it's the first time we've done anything like this. We had Fernando and virtually the entire a futurum analyst team each doing their sessions. I think eight of them I was, I was involved in right, asking questions.
I loved it, but it was great. com. You could go get them there.
We also announced the DevOps do com winners there. And we actually had the analyst from uh, RSAC there, Fernando, giving the RSA view of 2026. Speaking of RSA, we're in full blown mode getting ready for that.
Our, uh, annual DevSecOps event at RSA, the Monday of RSA week in Moscone is coming up this year. It's around securing AI native dev, which is in many ways what DevOps or a big part of what DevOps is today. We have a great speaker lineup, including David Brynn, who's like a Hugo Nebula award-winning sci-fi author, but also a PhD at as a JPL and a, an AI prophet from the eighties and nineties even.
He's keynoting. So check that out. Um, I am taking the film crew or one of our video crews here from Textron up to Blue Origin, uh, Jeff Bezos Space Company.
And we're gonna be interviewing, we're gonna go to their headquarters here in, uh, on the Space Coast in Florida. And we're gonna do some video coverage of what's going on there. And I'm just a little boy in me is very, very exciting.
Um, but other than that, you know, it's keeping the wheels on the tech strong and working with our friends at Tech Field Day and the rest of futur Group and, you know, trying to have fun. 'cause at the end of the day, if you're not having fun, it's just a job. Well, speaking of Tech Field Day, we are going to be at RSAC this year.
We've got a great lineup of presenters so far, including Veeam and Object First, which are now the same company. Uh, and we also are gonna be hearing from Convault and several more. com, and you can see the lineup that we've got coming up in March.
But also, don't forget to check out all the great events that we've got going on. Uh, AI Infrastructure Field Day, uh, AI Field Day, uh, security Field Day, networking Field Day. We've got a lot coming up.
You can check out our calendar there. We also wanna thank you for listening to this episode of Security Boulevard podcast. If you enjoyed this conversation, you know what to do.
Head over to YouTube or open up your favorite podcast app and subscribe so you don't miss any of our episodes. We would also love it if you would leave us a rating, a review, and, and maybe a comment just so that you know, um, kind of people are reading what your thoughts are on the show. And that helps us get out to a wider audience.
com and the Future Room Group. com, our Techstrong TV website, or check out the Techstrong TV app. It'll run on Apple tv, Roku, iOS devices, uh, PlayStation, Xbox, whatever.
We'll, we'll make it work. Um, we also hope that you follow us on Security Boulevard, uh, the social media areas, you know, X, Twitter, LinkedIn, you know what to look for. Security, BLVD, that's who we are.
Uh, we hope that you are enjoying all the great content that we're putting out here and across the future and group. Thank you for tuning in. We'll see you all next week.