Full Show Notes
Segment One

RSAC 2026 Day 4: AI Security, Agentic AI & Cybersecurity Must Move Beyond Monitoring – RSAC26 #4

Key Moments
  • 0:00 - RSAC 2026 Day 4 Kickoff & Final Takeaways
  • 0:44 - Surviving RSAC: 20 Years of Cybersecurity Evolution
  • 01:16 - Agentic AI Everywhere – Conference Theme Recap
  • 01:30 - ChatGPT Summary of RSAC 2026 Trends
  • 02:10 - Rise of AI-Native Security Startups
  • 02:40 - AI Disruption & Companies That Won’t Survive
  • 03:00 - Identity, Cloud & AI Supply Chain Risks
  • 03:20 - From Visibility to Actionable Security
  • 04:18 - Why Monitoring Alone Is No Longer Enough
  • 04:44 - Continuous Control Management vs Monitoring
  • 05:10 - Human-in-the-Loop AI & Autonomous Security مستقبل
  • 05:51 - Small Language Models vs Large Language Models
  • 06:21 - Multi-Model AI Strategy in Cybersecurity
  • 07:21 - AI Models Becoming a Commodity
  • 07:50 - Real Talk: Cybersecurity Industry Myths Exposed
  • 08:58 - Why 100% Security Is Impossible
  • 09:14 - Cyber Hygiene vs Shiny AI Tools
  • 10:09 - Foundational Security Still Matters
  • 10:22 - Automation vs AI – What Actually Matters
  • 11:13 - Finding Real Innovation at RSAC Expo
  • 11:31 - MCP Security: The Next Firewall for AI Agents
  • 13:05 - AI Supply Chain Risks & Skill File Security Challenges
  • 13:58 - Future of AI Security & Natural Language Risks
  • 14:24 - What’s Next After RSAC 2026
  • 15:17 - Building Cybersecurity Ecosystems & Community
  • 15:27 - Final Thoughts & RSAC 2026 Wrap-Up
Segment Two

The Making of Midnight in the War Room – Mickey Bresman – RSAC26 #4

Key Moments
  • 0:00 - RSAC 2026 Interview with Semperis CEO Mickey Bresman
  • 0:31 - Cybersecurity Documentary “Midnight in the War Room” Overview
  • 01:10 - Inside the Cybersecurity Industry: Government, Hackers & Defenders
  • 02:10 - Real Stories from WannaCry, CISA & Cyber Leaders
  • 03:13 - Breaking the “Hacker in a Hoodie” Myth
  • 04:00 - Diversity & Career Paths in Cybersecurity
  • 05:00 - Mental Health & Burnout in Cybersecurity Roles
  • 06:17 - Why This Documentary Matters for the Industry
  • 07:00 - Encouraging New Talent into Cybersecurity Careers
  • 08:08 - Skills Gap & Non-Technical Entry into Cybersecurity
  • 08:56 - Behind the Scenes: Making a Cybersecurity Documentary
  • 10:00 - Real Cybercrime Stories & Personal Risk for CISOs
  • 11:00 - The True Cost of Cybercrime & Ransomware Attacks
  • 11:47 - Critical Infrastructure Attacks & Colonial Pipeline Impact
  • 13:11 - When & Where to Watch the Film (Black Hat Premiere)
  • 14:27 - Future Sequels & Expanding Cybersecurity Stories
  • 14:50 - Final Thoughts & RSAC 2026 Coverage
Guest
Chief Executive Officer at Semperis

Mickey Bresman is CEO and co-founder of Semperis, the identity-driven cyber resilience and crisis response company.

Beginning his technical career in the Navy, Mickey’s comfort zone is on the front lines helping organizations thwart and respond to cyberattacks. The long-time cybersecurity expert and entrepreneur has an extensive track record of driving revenue growth and scaling organizations across the globe. Prior to founding Semperis, Mickey held the position of CTO at YouCC Technologies, a Microsoft Gold Partner integration company. As a cybersecurity thought leader, Mickey has been quoted or featured in many major publications, including Forbes, Fortune, Wall Street Journal and others.

Semperis recently surpassed $150M in annual recurring revenue, a milestone that fewer than one in every 1,000 venture-backed enterprise software companies achieves. The company was recently recognized by Cohesity as its 2025 Security Partner of the Year, one of Dun’s 100 Best HighTech Companies, recognized by Inc. Magazine as one of its Best Workplaces for four consecutive years and has been named to Deloitte’s Technology’s Fast 500 for the sixth consecutive years.

Segment Three

Attack Surface Just Got a Copilot – Rob Juncker – RSAC26 #4

Key Moments
  • 0:00 - Introduction to RSAC 2026 & Mimecast
  • 0:19 - Mimecast Evolution Beyond Email Security
  • 0:39 - From Email Security to Human Risk Management
  • 01:46 - Why Humans Are the Biggest Cybersecurity Risk
  • 02:10 - Rise of Agentic AI & Non-Human Identities
  • 02:37 - Should AI Agents Be Treated Like Humans?
  • 03:15 - AI Behavior, Hallucinations & Risk at Scale
  • 04:24 - Real-World AI Bot Behavior & Security Lessons
  • 05:20 - AI-to-AI Communication Risks Explained
  • 06:10 - Prompt Injection Attack Example (Real Case)
  • 07:41 - Security Guardrails vs Human Training
  • 07:58 - The “AI Security Triangle” Framework
  • 09:04 - Behavior Monitoring for Humans vs AI Agents
  • 10:20 - Detecting AI Activity at Machine Speed
  • 11:10 - Shadow AI & Unsanctioned Tool Risks
  • 12:03 - Can AI Guardrails Be Updated in Real Time?
  • 13:04 - Preventative vs Reactive AI Security Controls
  • 14:20 - Automating AI Behavior & Governance
  • 14:55 - Future Risks: Rogue AI & Mass Automation
  • 15:12 - Final Thoughts on AI Risk Management
Guest
Chief Product Officer at Mimecast

Rob Juncker is Chief Product Officer at Mimecast, where he leads strategy and product management across the global portfolio. With 25+ years in security, IT, cloud, and mobile, he serves as a trusted advisor to enterprise CISOs and Fortune 500 security leaders, helping organizations shift from reactive threat response to proactive human risk management.

As former CTO at Code42 (acquired by Mimecast in 2024), Rob led the teams that built the Incydr insider risk management solution, transforming the company from an on-premises backup product to a cloud-delivered cybersecurity platform. He previously held senior R&D roles at Ivanti and VMware, driving innovation at the intersection of security, cloud, and enterprise IT.

Segment Four

Securing the Next Billion Users: Why the Browser is the Front Line for Agentic AI – Ramin Farassat – RSAC26 #4

Key Moments
  • 0:00 - Introduction to RSAC 2026 & Menlo Security
  • 0:20 - Securing the Next Billion AI Users
  • 0:53 - Why AI Agents Will Outnumber Humans
  • 01:42 - Browser Security for AI Agents Explained
  • 01:53 - Shift from Read-Only to Read/Write AI
  • 02:10 - The Visibility Problem with Agentic AI
  • 02:47 - Detecting AI Agents in the Environment
  • 03:03 - Registering and Tracking AI Agents
  • 03:39 - Applying Security Controls to AI Agents
  • 04:06 - Human vs AI Security Controls Compared
  • 04:40 - Authentication & Authorization for AI
  • 05:02 - Preventing Data Leakage from AI Agents
  • 05:22 - Risks of Agent-to-Agent Spread
  • 05:50 - AI Communication Beyond the Browser (MCP)
  • 06:10 - Securing MCP with Browser-Based Controls
  • 06:41 - Converging AI Communication Channels
  • 06:51 - Getting Started with AI Security Strategy
  • 07:37 - Dev vs Security Teams Collaboration
  • 08:10 - Automating AI Agent Registration & Control
  • 08:49 - Managing Dev vs Security Conflicts
  • 09:19 - Using AI to Secure AI (Automation)
  • 10:05 - Moving from Detection to Autonomous Action
  • 10:38 - Building Trust in AI Security Systems
  • 11:07 - Why Proactive AI Security Matters
  • 11:22 - Future of AI Security & Compliance
  • 11:50 - Data Sovereignty Challenges with AI
  • 12:28 - Managing Global Compliance for AI Agents
  • 12:55 - Final Thoughts on Securing Agentic AI
Guest
Chief Product Officer at Menlo Security

Ramin Farassat is the Chief Product Officer at Menlo Security, where he leads the company’s product strategy, management, and design. He is an Executive Product Leader with a proven track record of scaling SaaS platforms, driving Al-led innovation, and delivering sustained enterprise growth. Ramin bridges boardroom strategy with day-to-day execution – aligning product direction with market opportunity, investor priorities, and operational excellence.

Segment Five

Browser in the AI Era: Apply Controls Where the Work Happens – Arunesh Chandra – RSAC26 #4

Key Moments
  • 0:00 - Welcome to RSAC 2026 Interview
  • 0:20 - Enterprise Browser Trend Explained
  • 0:34 - Why Enterprise Browsers Are Growing Fast
  • 02:01 - Consumer vs Enterprise Browser Differences
  • 02:14 - Browser as the Primary Security Surface
  • 03:43 - Why Big Tech Is Investing in Enterprise Browsers
  • 04:19 - Browser as a New Security Endpoint
  • 05:33 - The Role of Browsers in AI Security
  • 05:46 - Shadow AI Risks in the Workplace
  • 07:30 - Browser as the AI Control Plane
  • 07:58 - Microsoft Edge for Business Security Controls
  • 08:09 - Visibility Into AI Tool Usage
  • 09:51 - Granular Control vs Blocking AI Tools
  • 10:01 - AI Policies Compared to Firewall Rules
  • 10:53 - AI-Driven Threat Speed & Attack Surface
  • 12:12 - Standardizing Browsers to Reduce Risk
  • 12:53 - AI Tool Discovery & Web Filtering Challenges
  • 14:07 - Managing Approved vs Unapproved AI Tools
  • 14:47 - Final Thoughts & Key Takeaways
Guest
Head of Product, Microsoft Edge for Business at Microsoft Edge for Business

Arunesh Chandra is the Head of Product for Microsoft Edge for Business, where he leads the browser’s growth and adoption across commercial organizations on both desktop and mobile. His work sits at the forefront of enterprise security, compliance, and the browser’s emerging role as a critical control point in the AI era. With deep expertise in endpoint security, data protection, and browser manageability, Arunesh helps organizations—from small teams to global enterprises in highly regulated industries—tackle emerging risks like shadow AI and establish the secure enterprise browser as a consistent, scalable foundation for security and compliance.

Segment Six

​The New Era of DNS Resilience: Breaking down the newly finalized NIST SP 800-81 – Craig Sanderson – RSAC26 #4

Key Moments
  • 0:00 - RSAC 2026 Interview Introduction
  • 0:25 - Why DNS Security Matters Now
  • 0:48 - NIST DNS Update (SP 800-81 Rev 3) Explained
  • 0:56 - Key DNS Security Improvements & Best Practices
  • 02:08 - Encrypted DNS (DoH, DoT, DoQ) Overview
  • 02:59 - DNS Regulations & NIS2 Impact
  • 03:48 - DNS Risks in Critical Infrastructure
  • 05:16 - What is Protective DNS?
  • 05:31 - DNSSEC vs Protective DNS Explained
  • 07:06 - Using DNS as a Cybersecurity Control
  • 07:39 - Real-Time Threat Intelligence with DNS
  • 09:01 - Moving Beyond Whack-a-Mole Security
  • 09:26 - Reducing Attack Surface with DNS Intelligence
  • 09:55 - Preventing Phishing with Protective DNS
  • 11:26 - Real-World Example: Government DNS Protection
  • 12:03 - Why Organizations Should Adopt Protective DNS
  • 12:42 - DNS as a Security Service Mindset Shift
  • 13:26 - Breaking Silos: Network vs Security Teams
  • 14:12 - DNS Attack Risks & Domain Takeover Threats
  • 14:49 - Final Thoughts & Key Takeaways
Guest
Principal Cyber Security Strategist at Infoblox

Craig Sanderson is the Principal Cyber Security Strategist at Infoblox. Craig has over 25 years of experience in the CyberSecurity industry with a broad array of roles ranging from consultancy, security architecture, business development and product management. Over the last seven years, Craig has been responsible for creating the vision, strategy and delivered the execution of the Infoblox BloxOne Threat Defense solution. He continues to be passionate about the role that DNS can play in delivering world class cyber security with a particular emphasis on how DNS can become the foundation for national and governmental Protective DNS solutions.

Segment Seven

ArmorCode: AI Exposure Management and Governing Shadow AI – Mark Lambert – RSAC26 #4

Key Moments
  • 0:00 - Welcome to RSAC 2026 Interview
  • 0:20 - What is ArmorCode?
  • 0:44 - Unified Exposure Management Explained
  • 01:19 - Breaking Down Security Silos
  • 01:24 - 350+ Integrations for Full Visibility
  • 02:01 - Centralized Security Data & Context
  • 02:47 - Correlating Vulnerabilities Across Tools
  • 03:35 - Enriching Data with Threat Intelligence
  • 04:27 - The Challenge of Risk Prioritization
  • 04:34 - Can AI Replace Exposure Management Tools?
  • 05:03 - Build vs Buy in the Age of AI
  • 06:08 - Introducing Anya Agentic AI Framework
  • 07:12 - Governance, Auditability & AI Workflows
  • 07:50 - Buy + Build Approach Explained
  • 08:20 - Solving Tool Sprawl in Cybersecurity
  • 08:33 - 2026 AI Risk Management Report Insights
  • 09:44 - Key Differentiators vs Other Platforms
  • 10:17 - Agentic Workflows & Platform Architecture
  • 11:00 - Customer-Driven Product Innovation
  • 12:20 - Expanding Use Cases: AppSec, Vulnerability Mgmt
  • 12:48 - What’s Next: AI Exposure Management
  • 13:52 - AI Code Growth & Rising Vulnerabilities
  • 14:36 - Complex Vulnerabilities & AI Development Risks
  • 15:45 - Final Thoughts & Closing
Guest
Chief Product Officer at ArmorCode

Mark Lambert is the Chief Product Officer for ArmorCode, a leader in unified exposure management. Mark has built products for more than 20 years, and helped organizations streamline the delivery of secure, reliable and compliant software applications across the enterprise, embedded and IoT markets.

Prior to ArmorCode, he held product leadership positions with Parasoft, Advanced Visual Systems (AVS) and more. Mark holds a bachelor’s and master’s degree in computer science from Manchester University, UK.

Segment Eight

Beyond the Hype: Measuring Cyber Readiness in the Age of AI – Gibb Witham – RSAC26 #4

Key Moments
  • 0:00 - RSAC 2026 Final Interview Kickoff
  • 0:20 - Meet Hack The Box Leadership
  • 0:38 - Hack The Box Community & Growth Overview
  • 01:10 - Cyber Readiness in the Age of AI
  • 01:44 - How AI Is Changing Cybersecurity Training
  • 03:25 - Evolution from Manual Hacking to AI-Assisted Security
  • 04:07 - Limits of AI in Real-World Cyber Labs
  • 05:10 - Hack The Box AI vs Human Competition Insights
  • 05:44 - 40% Speed Boost with AI Tools
  • 06:20 - Why Skilled Hackers Benefit Most from AI
  • 07:04 - AI + Human Expertise = Maximum Performance
  • 08:35 - The Risk of Skipping Cybersecurity Fundamentals
  • 09:49 - The “Missing Middle” Skill Gap Problem
  • 11:21 - Why Organizations Must Invest in Training
  • 12:16 - Building Cybersecurity Muscle Memory
  • 12:47 - Can AI Improve or Weaken Security Posture?
  • 13:35 - How to Get Started with Hack The Box
  • 14:04 - Free Training & Community Access Explained
  • 14:28 - Why Beginners Should Start Now
  • 15:05 - Learning Cybersecurity Through Practice
  • 16:07 - Final Thoughts on AI + Cyber Skills Future
Guest
President at Hack The Box

Gibb Witham is President of Hack The Box. With two decades of experience across cybersecurity, AI, and enterprise software, Gibb has spent his career at the intersection of innovation, capital, and operational execution. Prior to Hack The Box, he spent 14 years as a venture capital investor at Paladin Capital Group, where he partnered with high-growth companies at the forefront of cybersecurity and enterprise AI innovation. His portfolio experience includes multiple companies growing from early stage to category leaders with over $100M in annual recurring revenue, with several successful IPOs and strategic acquisitions.

Earlier in his career, Gibb led initiatives at IBM to build and scale its cloud and SaaS businesses in major industry verticals, following work as a strategy consultant advising Fortune 500 technology companies. Gibb holds a B.S. from Columbia University and lives with his family in Brooklyn, New York.

Segment Nine

RSAC 2026 Recap: Agentic AI Hype, Cybersecurity Trends & Startup Reality Check – RSAC26 #4

Key Moments
  • 0:00 - RSAC 2026 Day 4 Wrap-Up
  • 0:40 - Event Highlights & Celebrity Moments
  • 01:09 - Surviving RSAC: Scale & Experience
  • 01:30 - Exploring the Expo Floor & Early Stage Startups
  • 01:55 - Agentic AI Hype & Market Saturation
  • 02:38 - Lack of Differentiation in Cybersecurity Startups
  • 03:00 - Buy vs Build in the Age of AI
  • 03:26 - Venture Capital Trends & Funding Challenges
  • 04:20 - Lessons from Past Tech Bubbles
  • 05:09 - Future of Cybersecurity Startups & Valuations
  • 05:46 - The Evolution of AI Security Trends
  • 06:18 - First-Time RSAC Experience & Insights
  • 07:00 - Why RSAC Is a “C-Suite Strategy Conference”
  • 07:47 - Key Cybersecurity Trends from RSAC 2026
  • 08:16 - Networking, Meetings & Industry Connections
  • 08:22 - RSAC Social Scene & Networking Events
  • 09:02 - Conference Culture & Industry Humor
  • 10:09 - Perspectives on AI Innovation & Differentiation
  • 10:58 - Final Reflections on RSAC 2026
  • 12:20 - Expo Floor Experience: Scale & Complexity
  • 13:18 - Early Stage vs Main Expo Comparison
  • 14:12 - Startup Innovation & Future Market Leaders
  • 15:20 - Closing Thoughts & RSAC 2026 Recap

Stay in the Know, No Smoke and Mirrors – Join Our Newsletter

You can skip this ad in 5 seconds