RSAC 2026 Day 3: AI in SOC, Cyber Trends & The Truth About Agentic AI – RSAC26 #3
AI in cybersecurity is everywhere, but is it actually delivering results?
In this RSAC 2026 Day 3 intro, we break down the biggest cybersecurity trends shaping the industry, including AI in the SOC, agentic AI, and the growing pressure to prove real value from security investments.
From market predictions to real-world challenges, this discussion covers:
Why AI in the SOC may not be living up to expectations The reality behind agentic AI hype vs practical use The “lemonade problem” in cybersecurity data quality Why organizations struggle to measure security ROI How tech debt is accelerating with rapid AI adoption The future of AI identity, trust, and reputation models Why 2026 may be the year of “prove it or lose funding”
If you're a CISO, security engineer, or IT leader, this RSAC 2026 breakdown will help you understand where cybersecurity—and AI—is really headed.
Subscribe for more cybersecurity insights, RSAC coverage, and expert interviews.
To view all the RSAC Conference 2026 coverage by CyberRisk Alliance, visit: https://securityweekly.com/rsac
Beyond the Audit: Making Cyber Risk Continuous, Quantified, and Actionable – Travis Wong – RSAC26 #3
Most companies assess cyber risk once a year and call it done — but for organizations managing dozens of subsidiaries or portfolio companies, that's a costly blind spot. In this RSA interview, Resilience's VP of Customer Engagement explores why measuring risk in dollars (not color-coded charts) changes the conversation at the board level, and why the organizations best positioned to prevent losses are the ones treating cyber risk as a continuous discipline rather than an annual exercise.
Resilience Arc: https://4526209.fs1.hubspotusercontent-na1.net/hubfs/4526209/arcone-pager.pdf
See it in action. Request a demo at https://securityweekly.com/resiliencersac.
Read the interview summary from SC Media here: Resilience’s Travis Wong on making cyber risk continuous, quantified, and actionable
Travis Wong is the VP of Customer Engagement at Resilience. He leads the Security and Risk Services and Customer Success teams and brings over 15 years of experience in risk management consulting, helping clients assess, measure, and manage their risk effectively.
Trends Revealed in Fortinet’s FortiGuard Labs 2026 Global Threat Landscape Report – Aamir Lakhani – RSAC26 #3
Fortinet’s Global Director of Threat Intelligence and Adversarial AI Research explores the trends revealed in the latest Global Threat Landscape Report from FortiGuard Labs, including a surge in AI-enabled cybercrime. As AI optimizes and accelerates attack techniques, here’s how cyber defenders should respond.
Segment Resources:
This segment is sponsored by Fortinet . Visit https://securityweekly.com/fortinetrsac to learn more about them!
Read the interview summary from SC Media here: Aamir Lakhani on trends in Fortinet’s 2026 Global Threat Landscape Report
Aamir Lakhani is a cybersecurity researcher and practitioner with Fortinet and FortiGuard Labs, with over 15 years of experience in the security industry. He is responsible for providing IT security solutions to major commercial and federal enterprise organizations. Lakhani is considered an industry leader in support of detailed architectural engagement and projects on topics related to cyber deference, mobile application threats, malware and advanced persistent threat (APT) research. Previously, Lakhani designed cyber solutions for defense intelligence agencies, and has assisted organizations in defending themselves from active strive-back perpetrated by underground cyber groups. Lakhani’s areas of expertise include FortiGuard, fundamentals of network protection, cyber defense, mobile application threats, malware and APT research.
Securing AI Agents: Managing Runtime Risk in Enterprise AI Systems – Jimmy White – RSAC26 #3
As organizations deploy AI agents and automated workflows, security challenges are increasingly emerging once these systems interact with APIs, enterprise data, and business processes in production.
In this segment, Jimmy White, VP of AI at F5, discusses why AI security often breaks down at runtime and how organizations can gain visibility and control over AI behavior. He will also discuss two new initiatives announced at RSA Conference – F5’s partnership with Skyfire to enable secure identity and transactions for AI agents, and a collaboration with Forcepoint that connects data discovery and classification with runtime protections to help organizations secure AI systems across their full lifecycle.
Segment Resources:
F5 Application Delivery and Security Platform (ADSP) https://www.f5.com/products/f5-application-delivery-and-security-platform
F5 AI Guardrails and F5 AI Red Team https://www.f5.com/go/solution/f5-ai-security-with-guardrails
F5 Distributed Cloud Bot Defense https://www.f5.com/products/distributed-cloud-services/bot-defense
F5 Labs Research https://www.f5.com/labs
For more information about F5, please visit https://securityweekly.com/f5rsac.
Read the interview summary from SC Media here: F5’s Jimmy White on managing runtime risk in enterprise AI systems
Jimmy White is a technology and AI leader focused on building secure, scalable platforms at the intersection of AI, infrastructure and cybersecurity. He currently drives AI and engineering strategy at F5, where he’s leading efforts to secure AI systems and modern application environments. Previously, he served as Chief Technology Officer and President at CalypsoAI, helping scale the company’s AI security capabilities, and has held senior engineering and security leadership roles at organizations including Qualtrics and FireEye/Mandiant. With many years of experience across software, security, and high-growth product teams, Jimmy is passionate about translating emerging AI innovation into practical, enterprise-ready solutions.
Why Passkeys Are Ready for Prime Time in Modern Banking – Ashish Jain – RSAC26 #3
Authentication has long required an uneasy tradeoff between strong security and smooth user experience. Banks have relied on a mix of passwords, OTPs, SMS codes, voice calls, and push notifications each with its own vulnerabilities and user experience challenges. Passkeys, built on FIDO standards, finally deliver a phishing resistant, high assurance, passwordless experience that improves both security and usability. This interview segment explores why passkeys are ready now for even the highest risk banking use cases, why banks should be moving quickly to adopt them, and how OneSpan delivers the most complete, secure, and enterprise ready passkey solution on the market. With Gartner predicting that by 2027 more than 75% of workforce authentication and over 40% of customer authentication will be passwordless, the shift is accelerating and the institutions that move early will gain a meaningful security and UX advantage.
Segment Resources:
FIDO Alliance – Passkeys & Phishing Resistant Authentication https://fidoalliance.org/passkeys/ https://www.onespan.com/products/digipass-s3-authentication-software https://onespan.widencollective.com/dam/assetdetails.assetdetailstab.metadatapanel.metadatainlineeditor:eventlink?inav=false&t:ac=asset:52a52e9e-d01e-4d61-ac3d-0312a1ccc7f3/$N/assetversion:cb1303d2-6361-4fd7-af91-8e70c3c0c918
This segment is sponsored by OneSpan. Visit https://securityweekly.com/onespanrsac to learn more about them!
Read the interview summary from SC Media here: OneSpan’s Ashish Jain on why passkeys are ready for prime time in modern banking
Ashish Jain is OneSpan’s Chief Technology Officer. Widely regarded as one of the top digital identity experts in the industry, Ashish brings over two decades of experience leading product management, engineering, and operations teams at global organizations. He most recently served as Chief Product Officer at Arkose Labs, an enterprise fraud management and account security company where he led the development of the platform to help address consumer fraud and identity challenges for many Fortune 1000 companies. Prior to his role at Arkose Labs, Ashish served as Head of Identity at eBay, where he led the global engineering team to build the identity, risk, and trust platform to support onboarding, authentication, KYC, fraud, and abuse protection for 180+ million eBay customers and third-party developers. Before joining eBay, Ashish was Vice President of Workspace ONE at VMware, where he spearheaded the development and patenting of a solution that integrated identity and mobile device management, one of the core tenets of Zero Trust Security.
How AI-Driven Development is Reshaping the Application Risk Landscape – Idan Plotnik – RSAC26 #3
AI coding assistants are dramatically accelerating software development, generating more code and more change than security teams were built to handle. In this interview, Idan Plotnik discusses how AI-driven development is reshaping the application risk landscape and why traditional vulnerability management models can’t keep up.
Segment Resources:
This segment is sponsored by Apiiro. Visit https://securityweekly.com/apiirorsac to learn more about them!
Read the interview summary from SC Media here: Apiiro’s Idan Plotnik on how AI-driven development and the risk landscape
Idan is a serial entrepreneur and product strategist, bringing to Apiiro nearly 20 years of experience in cybersecurity. Previously, Idan was Director of Engineering at Microsoft following the acquisition of Aorato where he served as the founder and CEO.
Mind the Gap: Confidence, AI, and the Future of Exposure Management – Chris Wallis – RSAC26 #3
Former ethical hacker, now founder and CEO of Intruder, Chris Wallis explores whether AI can bridge the divide between finding vulnerabilities and understanding real-world attack context as exploit windows continue to shrink. This conversation dives into the structural "confidence gap" uncovered in Intruder’s 2026 Security Middle Child Report, where executive risk appetite is increasingly decoupled from front-line operational reality.
This segment is sponsored by Intruder. Visit https://securityweekly.com/intruderrsac to learn more about them!
Read the interview summary from SC Media here: Intruder’s Chris Wallis on confidence, AI and the future of exposure management
Chris Wallis is the founder and CEO of Intruder. With deep experience in both offensive security and defensive operations, Chris has worked hands-on with global banks, major financial institutions, and critical national infrastructure, securing some of the most targeted and high-risk environments in the world. This blend of attacker-led insight and real-world defense crafted Intruder’s practical approach to finding and fixing the vulnerabilities that matter before they can be exploited.
Why More Technology Hasn’t Made Us More Secure – John Anthony Smith – RSAC26 #3
Despite massive investment in cybersecurity tools, organizations remain vulnerable because their existing technologies are often misconfigured, poorly integrated, and disconnected from real operational risk. This keynote argues that complexity, human decision‑making, and gaps in execution—not a lack of products—are what truly empower attackers, especially as modern environments like cloud and SaaS expand the attack surface. Real security comes from simplifying, aligning, and expertly orchestrating what organizations already own, shifting the focus from buying tools to achieving disciplined, resilient outcomes grounded in breach reality.
This segment is sponsored by Fenix24. Visit https://securityweekly.com/fenix24rsac to learn more about them!
Read the interview summary from SC Media here: Fenix24’s John Anthony Smith on why more technology hasn’t made us more secure
John Anthony Smith, Founder and Chief Security Officer of Fenix24, is a leading information security expert with deep cybersecurity experience in healthcare, financial services, and legal industries. He has overseen infrastructure for over 400 companies and currently serves as a vCIO and trusted advisor to companies worldwide. With more than 16 years of breach response experience, he is a staunch advocate for tougher sanctions on nations harboring cybercriminals and is dedicated to locating, investigating, and prosecuting cybercriminals.
No Device, No Access: The Future of Zero Trust Security – Rob Allen – RSAC26 #3
As credential-based attacks continue to dominate headlines, many organizations are realizing that identity alone is no longer a sufficient control. This conversation explores the shift toward device-based access enforcement and why tying access to both user and device is becoming critical. We’ll discuss how this evolution is reshaping Zero Trust strategies across modern environments.
Segment Resources:
https://www.threatlocker.com/tl-capabilities/zero-trust-cloud-access https://www.threatlocker.com/tl-capabilities/zero-trust-network-access https://www.threatlocker.com/press-release/threatlocker-launches-zero-trust-network-and-cloud-access-to-stop-credential-based-cyberattacks
This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlockerrsac to learn more about them!
Read the interview summary from SC Media here: ThreatLocker’s Rob Allen on the future of zero trust security
Rob Allen, Chief Product Officer of ThreatLocker, is an IT Professional with three decades of experience assisting small and medium enterprises embrace and utilize technology. He has spent the majority of this time working for an Irish-based MSP, which has given him invaluable insights into the challenges faced by businesses today. Rob’s background is technical – first as a system administrator, then as a technician and an engineer. His broad technical knowledge, as well as an innate understanding of customers’ needs, made him a trusted advisor for hundreds of businesses across a wide variety of industries. Rob has been at the coalface, assisting clients in remediating the effects of, and helping them recover from cyber and ransomware attacks.
Beyond IOCs: A Framework for High-Impact Cyber Threat Intelligence – Samuel Hassine – RSAC26 #3
In a time where the ability to turn intelligence into decisive action is a true competitive advantage, organizations must move beyond reactive alert triage to a proactive, threat-informed defense. This segment explores how unifying threat intelligence with adversarial attack simulation enables a Continuous Threat Exposure Management (CTEM) framework that replaces hype with measurable outcomes. We will discuss why these are no longer just technical security conversations, but critical business strategies that provide the board and C-suite with the clarity and confidence to reduce risk and focus resources where they matter most.
Segment Resources:
Blog: https://filigran.io/our-blog/ CTEM blog: https://filigran.io/ctem-but-without-the-hype-turning-intel-and-validation-into-outcomes/ Github: https://github.com/FiligranHQ Filigran Community: https://filigran-community.slack.com/ Filigran Academy: https://academy.filigran.io/ Get a tailored demo: https://filigran.io/book-a-demo/
This segment is sponsored by Filigran. Visit https://securityweekly.com/filigranrsac to learn more about them!
Read the interview summary from SC Media here: Filigran’s Samuel Hassine on a framework for high-impact cyber threat intelligence
Former Head of Cyber Threat Intelligence at the French Cybersecurity Agency (ANSSI) and Director of Cybersecurity Strategy at Tanium, Samuel Hassine is the CEO and the co-founder of Filigran, a fast-growing European CyberTech developing cutting-edge solutions for cyber threat management.
The Agentic SOC: Autonomous AI Analysts at Machine Speed – Edward Wu – RSAC26 #3
SOC teams are overwhelmed with the sheer number of alerts and have historically been reactive. Edward will discuss how Dropzone’s Agentic SOC deploys autonomous AI agents that investigate every alert, respond to emerging threats, and proactively hunt attackers - without a human bottleneck. He’ll explain how agent collaboration, deep recursive investigations, and self-agency expand SOC capacity by 10x without additional headcount.
This segment is sponsored by Dropzone AI. Visit https://securityweekly.com/dropzonersac to learn more about them!
Read the interview summary from SC Media here: DropZone AI’s Edward Wu on autonomous AI analysts at machine speed
Edward Wu is the founder & CEO of Dropzone AI, creator of the world’s first autonomous AI SOC analyst that force-multiplies cybersecurity teams with armies of AI agents. Previously, Edward spent eight years at ExtraHop Networks, leading AI/ML and detection engineering and developing behavioral network attack detection. He also worked on automated binary analysis and software defenses at the University of Washington, Seattle, and UC Berkeley. Edward holds 30+ patents in applied AI for cybersecurity and is a contributor to the MITRE ATT&CK framework.
The Guardrails are Gone: The Onus for AI Security Is On the Enterprise – Marc Manzano – RSAC26 #3
AI model providers are increasingly stepping back from enforcing guardrails, putting the responsibility for AI security squarely on enterprises. But most organizations don't yet have the visibility to meet that responsibility, facing a blind spot across the broader ecosystem of AI systems already operating in their environments. Closing that gap requires unified visibility across both AI systems and the cryptographic infrastructure they touch, so security teams can assess risk and act on it in one place.
Segment Resources:
https://www.sandboxaq.com/press/sandboxaq-report-ai-adoption-outpacing-ai-security https://www.sandboxaq.com/press/sandboxaq-launches-aqtive-guard-ai-spm-to-stop-the-rapid-spread-of-shadow-ai-across-the-enterprise
Visit https://securityweekly.com/sandboxaqrsac to discover how enterprises are taking control of their AI security with AQtive Guard AI-SPM by SandboxAQ.
Read the interview summary from SC Media here: SandboxAQ’s Marc Manzano: The onus for AI security is on the enterprise
Dr. Marc Manzano leads the cybersecurity group at Sandbox. His current research interests include post-quantum cryptography, lightweight cryptography, fully-homomorphic encryption, the intersection between machine learning and cryptanalysis, performance optimizations of cryptographic implementations on a wide range of architectures, and quantum algorithms. Manzano holds a Ph.D. in Computers Network Security, which he earned under the supervision of the University of Girona (Spain) and Kansas State University (United States). He earned an MSc in Computer Science from the University of Girona (Spain), while he did research stays at UC3M (Spain) and at DTU (Denmark). He initiated his research career while finalizing his BSc in Computer Engineering at Strathclyde University (UK).
Over the past ten years, Manzano has led the development of many secure cryptographic libraries and protocols. Manzano was formerly a Senior Staff Software Engineer at Google, and before that, he was the Vice President of the Cryptography Research Centre at the Technology Innovation Institute, a UAE-based scientific research center. Prior to that, he held several positions where he was responsible for implementing pivotal cryptographic components of a variety of secure communication products, including an electronic voting platform.
Multi-Channel Impersonation: Why Legacy Controls Are Failing – Bobby Ford – RSAC26 #3
As social engineering expands past just email to include text messages, chat apps, social platforms, and live video calls, traditional point solutions are struggling to keep up. In this segment, Bobby Ford explains how AI-powered impersonation and deepfake-enabled campaigns are exposing critical gaps in legacy defenses, and why organizations must evolve toward a unified social engineering defense platform that connects Digital Risk Management and Human Risk Management. He’ll outline what modern security programs need: real-time cross-channel visibility, behavior-driven detection, and strategies designed around how people actually communicate and make decisions today.
Segment Resources:
https://www.doppel.com/blog/new-hrm-capabilities-built-how-attacks-actually-happen https://www.doppel.com/blog/why-every-brand-needs-impersonation-attack-response-plan https://www.doppel.com/product/simulation https://www.doppel.com/product/brand-protection https://www.doppel.com/product/security-awareness-training
Visit https://securityweekly.com/doppelrsac to learn how Doppel helps organizations defend against AI-powered impersonation, phishing, and multi-channel social engineering threats with a modern Human Risk Management approach.
Read the interview summary from SC Media here: Doppel’s Bobby Ford on why legacy controls are failing
Bobby Ford is the Chief Strategy and Experience Officer at Doppel, an AI-native social engineering defense platform backed by Bessemer Venture Partners and a16z. A globally recognized cybersecurity leader, Bobby has nearly 30 years of experience and has served as CISO for Abbott Laboratories, Unilever, Exelis, and Hewlett Packard Enterprise. Since joining Doppel in July, Bobby has played a pivotal role in shaping the company’s strategy during a defining period of expansion and innovation.
Hard Truths: The Lies We Keep Buying in Cybersecurity – Andrew Rubin – RSAC26 #3
Cybersecurity isn’t broken because of a lack of technology—it’s broken because the industry avoids hard truths. Fear still drives budgets. AI is oversold as a cure‑all while foundations remain weak, and CISOs are held accountable without the authority to change outcomes. In this conversation, Illumio CEO and founder Andrew Rubin breaks down what must change to build real resilience—because the next breach won’t just impact the business, it could end a career.
For more information about Illumio, please visit: https://securityweekly.com/illumiorsac
Read the interview summary from SC Media here: Illumio’s Andrew Rubin: The lies we keep buying in cybersecurity
As Founder, CEO, and Board Member of Illumio, Andrew is responsible for the overall strategy and vision of the company. With deep expertise in Zero Trust, segmentation, network security, and regulatory and compliance management, Andrew is the Executive Sponsor of many of Illumio’s largest customers worldwide, including Citi, HSBC, Salesforce, and Microsoft. Andrew frequently participates in panels, articles, and podcasts for leading industry events and publications. Andrew was named to Goldman Sachs’ “100 Most Intriguing Entrepreneurs” seven times as part of its Builders & Innovators program and received Ernst & Young’s Bay Area Entrepreneur of the Year 2024.
Andrew serves as a Board Member of Emigrant Bank, as well as an advisor to several cyber and technology start-ups, and is an active angel investor. Andrew graduated from Washington University in St. Louis with a BSBA in Finance, and he is both a guest lecturer on entrepreneurship and a National Council member of the Skandalaris Center for Entrepreneurial Studies at the university.
RSAC 2026 Day 3: AI Security Trends, MCP Risks & The Future of Cybersecurity – RSAC26 #3
RSAC 2026 Day 3 delivered powerful insights into the future of cybersecurity, with a strong focus on AI security, agentic AI, and emerging risks like Model Context Protocol (MCP).
In this discussion, Joshua Marpette and Matt Alderman break down key trends from the expo floor, including the rise of AI-driven security tools, the challenges of securing MCP and APIs, and the growing need for visibility, automation, and real outcomes in cybersecurity programs.
They also explore why agentic AI is dominating the conversation, how market consolidation is impacting startups, and what the shift toward autonomous security systems means for the future of cybersecurity professionals.
Key topics covered:
The security risks of Model Context Protocol (MCP) Why AI security is evolving beyond hype The shift from alerts to automated outcomes Cybersecurity market consolidation and startup survival Human vs AI roles in the future of security
If you're tracking cybersecurity trends, AI threats, or RSAC 2026 highlights, this conversation gives you a clear, real-world perspective on where the industry is heading.
To view all the RSAC Conference 2026 coverage by CyberRisk Alliance, visit: https://securityweekly.com/rsac
