CyberRisk TV Live from RSAC Conference 2025 Day 3 Daily Intro – RSAC25 #3
Jeff Man, host of Paul's Security Weekly, and Mike Shema, host of Application Security Weekly, kick-off our RSAC 2025 coverage for Day 3 with a daily intro including must-see presentations, networking shenanigans, and other fun and exciting things that you'll want to check out during your time at the event!
Mitigating Access Risks in Critical Infrastructure Organizations – Joel Burleson-Davis – RSAC25 #3
Organizations in mission-critical industries are acutely aware of the growing cyber threats, like the Medusa ransomware gang attacking critical US sectors, but are wary that implementing stricter security protocols will slow productivity and create new barriers for employees. This is a valid concern, but organizations should not accept the trade-off between the inevitability of a breach by avoiding productivity-dampening security measures, or the drop in employee productivity and rise in frustration caused by implementing security measures that might mitigate a threat like Medusa. In this conversation, Joel will discuss how organizations can build a robust security strategy that does not impede productivity. He will highlight how Imprivata’s partnership with SailPoint enables stronger enterprise identity security while enhancing efficiency—helping organizations strike the right balance.
This segment is sponsored by Imprivata. Visit https://securityweekly.com/imprivatarsac to learn more about them!
Joel Burleson-Davis is the SVP of Worldwide Engineering, Cyber at Imprivata where he’s responsible for building, delivering, and evolving the suite of Imprivata’s cybersecurity products that include Privileged Access Security, Access Compliance, and AI-powered analytics solutions. Prior to joining Imprivata, Joel was Chief Technical Officer at SecureLink, the leader in critical access management for organizations in need of advanced solutions to secure access to their most valuable assets, including networks, systems, and data. While at SecureLink, Joel was responsible for the overall technology and operational strategy and execution, including direction and oversight for Product Development, Quality Assurance, IT and Cybersecurity Operations, Compliance, and Customer Success.
Before SecureLink, Joel held Systems Engineering, IT Consulting, and Instructor positions while serving as one of the founding members of The Linux Foundation certification committee, a global committee of key Linux subject matter experts. Joel earned a Master of Liberal Arts degree in Systems Theory and Technology from St. Edward’s University, and a Bachelor of Arts degree in Philosophy and Religious Studies from Texas Lutheran University.
AI Impacting Phishing and How Zscaler is Protecting its Users – Deepen Desai – RSAC25 #3
With the power of zero trust and AI, Zscaler help organizations strengthen and automate IT and security, reduce costs, and minimize complexity. Zscaler helps reduce the attack surface, block threats via full TLS inspection, and eliminate lateral threat movement.
This segment is sponsored by Zscaler. Visit https://securityweekly.com/zscalerrsac to learn more about them!
As Chief Security Officer at Zscaler, Deepen Desai is responsible for running the global security research operations as well as working with the product group to ensure that the Zscaler platform and services are secure. Deepen has been actively involved in the field of cybersecurity for the past 20 years and is also responsible for driving new cyber innovations at Zscaler. Prior to joining Zscaler, he held security leadership roles at Dell SonicWALL.
Cyber resilience in the face of evolving threats and post-quantum computing – Jordan Avnaim – RSAC25 #3
As cyber threats become increasingly difficult to detect and the technology to combat them continues to evolve, organizations must be prepared to move faster than ever. Looking ahead, the rise of post-quantum computing will bring both new opportunities and challenges, further reshaping the cybersecurity landscape. With the launch of Entrust’s Cryptographic Security Platform (announcement coming April 16th) as a backdrop, Jordan can discuss why all organizations – large and small – must prioritize post-quantum preparedness before it’s too late. He can also address emerging fraud technologies (e.g., deepfakes, GenAI) and fraud attacks (account takeovers, synthetic identities, impersonation), which are drawing more attention to the need for cyber-resilient methods, such as post-quantum cryptography, to protect against new fraud risks in the digital future.
This segment is sponsored by Entrust. Visit https://securityweekly.com/entrustrsac to learn more about them!
Jordan Avnaim serves as Entrust’s CISO. With more than 20 years of experience leading information security functions and influencing change and enterprise digital transformation, Jordan is helping scale and mature Entrust’s information security program for both corporate and commercial portfolios. Prior to Entrust, Avnaim worked for The Capital Group Companies, where he was responsible for leading various information security, technology risk and technology audit functions over his tenure. Previously at Deloitte & Touche, Avnaim led delivery of specialized security and risk consultative services to C-suite executives and clients across the globe.
A Browser-First Approach to Modern Workspace Security – Pejman (Pej) Roshan – RSAC25 #3
The modern workspace, increasingly reliant on cloud-based applications, browser-first access, and AI integration, faces significant security challenges that outpace the capabilities of traditional tools.
Legacy solutions, including VPNs and even early ZTNA implementations, are proving vulnerable to sophisticated attacks leading to data breaches and operational disruptions. The fundamental shift in how we work demands a new approach, one that closes the gaps left by the platform approach.
We need the ability to 'trust nothing and click on anything with zero risk.' We need to take zero trust beyond the network that we operate and control.
Future of Browser Security Webinar with Google: https://www.menlosecurity.com/resources/2025-prediction-the-future-of-browser-security-lessons-from-the-pioneers
Browser security report: https://www.menlosecurity.com/resources/state-of-browser-security-report
Global Cyber Gangs report: https://www.menlosecurity.com/resources/global-cyber-gangs-supported-and-sheltered-by-state-sponsors-and-getting-smarter-every-day-report
Everywhere Access White Paper: https://www.menlosecurity.com/resources/everywhere-access-the-zero-trust-revolution-for-hybrid-work-white-paper
This segment is sponsored by Menlo Security. Visit https://securityweekly.com/menlorsac to learn more about them!
Pejman (Pej) Roshan leads Menlo Security’s Marketing organization. Pej has more than 25 years of product and marketing experience, successfully leading to-to-market teams for pioneering companies of all sizes, including Agito Networks, ShoreTel, Teridion, Cisco Systems, Aruba Networks, Xilinx and VMware. Throughout his career, Pej has had roles in IT operations, IT planning, marketing, product management and executive roles.
Pluralsight’s Bri Frost Talks Emerging AI Threats – Bri Frost – RSAC25 #3
Emerging technologies like AI and deepfakes have significantly complicated the threat landscape of today. As AI becomes more integrated into our lives, everyone - not just cybersecurity professionals - needs to develop security literacy skills to keep themselves, their organizations, and their loved ones safe. Luckily, there are countermeasures to spot and identify AI and deepfake-related threats in the wild. In this segment, Pluralsight's Director of Security and IT Ops Curriculum, Bri Frost, discusses how AI has changed the cybersecurity industry, how to spot AI and deepfakes in the wild, and the skills you should know to defend against these emerging threats.
Pluralsight's AI Skills Report
This segment is sponsored by Pluralsight. Visit https://securityweekly.com/pluralsightrsac to learn the skills you need to defend against the latest cyber threats!
Bri is a renowned expert with 7 years of experience in the field of Cybersecurity and IT, bringing a unique perspective to the table. As the Director of Security and IT Operations Curriculum and Research at Pluralsight, Bri is instrumental in developing the cutting-edge cybersecurity and operational curriculum and content strategy. With a wealth of knowledge as an author of Pluralsight training content, she infuses a “red-team” or attacker-focused mindset into her teachings to grasp security concepts and defense strategies effectively. Bri holds a bachelor’s degree in InfoSystems and Technologies and is certified with Security+ and Pentest+ credentials.
How OpenText is Redefining Threat Detection Without Overloading Security Teams – Stephan Jou – RSAC25 #3
Stephan will discuss OpenText Core Threat Detection and Response, a new AI-powered solution designed to quickly spot and neutralize threats across an organization’s attack surface without the need to overhaul existing security stacks. He will also provide insights into the most dangerous threats facing enterprises today along with practical steps to mitigate them.
- https://www.opentext.com/products/core-threat-detection-and-response
- https://www.prnewswire.com/news-releases/opentext-launches-next-generation-opentext-cybersecurity-cloud-with-ai-powered-threat-detection-and-response-capabilities-302381481.html
This segment is sponsored by OpenText. Visit https://securityweekly.com/opentextrsac to learn more about them!
Stephan Jou is Senior Director of Security Analytics at OpenText Cybersecurity and currently leads efforts to apply AI and analytical methods for cybersecurity use cases. Jou was CTO and co-founder of Interset, where he developed a leading-edge cybersecurity and In-Q-Tel funded project that uses machine learning and behavioral analytics, prior to being acquired by Micro Focus and then OpenText. Previous to OpenText, Jou has been at IBM and Cognos where he led the development of over ten products in the areas of cloud computing, mobile, visualization, semantic search, data mining, and neural networks.
Jou holds a M.Sc. in Computational Neuroscience and Biomedical Engineering, and a dual B.Sc. in Computer Science and Human Physiology, all from the University of Toronto. He has held advisory positions on NSERC Strategic Networks and is involved in setting goals for NSERC Strategic Research Grant research topics in the areas of analytics and security for Canada, was an invited participant in 2018’s G7 Multistakeholder Conference on Artificial Intelligence and in 2020’s consultation with the Privacy Commissioner of Canada on the regulation of AI for data privacy, and has contributed to security and AI publications such as the Verizon’s “Data Breach Investigations Report” and the European Liberal Forum’s “European Cybersecurity in Context.”
Dynamic Defense: Mastering Cybersecurity in the Post-Breach Era – Karl Van den Bergh – RSAC25 #3
In the post-breach world, speed and clarity are essential for effective cybersecurity. Security teams are inundated with vast amounts of data, much of which is not actionable. To combat cyber threats—and level the playing field—defenders need precise intelligence to identify attacks, dynamically quarantine threats, and prevent cyber disasters, highlighting the power of the security graph.
Segment Resources: Supporting article - https://www.forbes.com/sites/tonybradley/2025/04/14/rethinking-threat-detection-in-a-decentralized-world/
RSAC News - What Illumio will be showing https://www.linkedin.com/feed/update/urn:li:activity:7317592725325770755/
More detail on Illumio Insights (announced April 14, showing at RSAC) - https://www.illumio.com/illumio-insights
This segment is sponsored by Illumio. Visit https://securityweekly.com/illumiorsac for information on Illumio Insights or to sign up for a private preview!
Karl Van den Bergh is a seasoned technology executive with over 25 years of experience in marketing, product strategy, and business leadership across startups and billion-dollar enterprises. As Chief Marketing Officer at Illumio, he drives global marketing strategy, including brand positioning, demand generation, and go-to-market execution, helping to accelerate the company’s leadership in breach containment and Zero Trust Segmentation. Previously, as CMO at Gigamon, Karl led a comprehensive marketing transformation that established the company as a leader in the deep observability market, significantly increasing growth and brand recognition. His career highlights include leadership roles at DataStax, TIBCO, and Jaspersoft, where he delivered innovative strategies and built high-performing teams. Karl holds a Master’s in Computer Science from Imperial College London, is fluent in multiple languages, and was honored as Cybersecurity Marketer of the Year in 2024.
Ransomware gangs are evolving – Are you evolving your defenses at the same speed? – Tony Anscombe – RSAC25 #3
The ransomware landscape is rapidly changing. ESET global research team has been closely following ransomware gang disruptions, new players and how the RaaS business model continues to evolve. In this segment, Tony Anscombe will take a look into recent research, hacks and attacks, and explore how the industry and businesses are responding to combat financial risk and mitigate threats.
Segment Resources: Recent research on Welivesecurity that is digging into the evolving ransomware ecosystem: https://www.welivesecurity.com/en/eset-research/shifting-sands-ransomhub-edrkillshifter/ ESET’s last threat report: https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2024/
This segment is sponsored by ESET. Visit https://securityweekly.com/esetrsac to learn more about them!
Tony Anscombe is the Chief Security Evangelist for ESET. With over 25 years of security industry experience, Anscombe is an established author, blogger and speaker on the current threat landscape, security technologies and products, data protection, privacy and trust, and Internet safety. His speaking portfolio includes industry conferences RSA, Black Hat, VB, CTIA, MEF, Sector and the Gartner Risk and Security Summit.
The Death and Rebirth of Vulnerability Management – HD Moore – RSAC25 #3
Despite becoming a checkbox feature in major product suites, vulnerability management is fundamentally broken. The few remaining first-wave vulnerability scanners long ago shifted their investments and attention into adjacent markets to maintain growth, bolting on fragmented functionality that's added complexity without effectively securing today's attack surfaces. Meanwhile, security teams are left contending with massive blind spots and disparate tools that collectively fail to detect exposures that are commonly exploited by attackers. Our industry is ready for change.
Jeff and HD will explore the current state of vulnerability management, what’s required to truly prevent real-world incidents, new perspectives that are challenging the status quo, and innovative approaches that are finally overcoming decades old problems to usher in a new era of vulnerability management.
Segment Resources: * runZero offers a fully functional, free 21-day trial that converts into a free Community Edition license. Get started here: https://www.runzero.com/try/ * Read more about runZero's recent launch, including new exposure management capabilities: https://www.runzero.com/blog/new-era-exposure-management/ * Watch a two-minute summary and deeper dive videos here: https://www.youtube.com/@runZeroInc * Tune into runZero's monthly research webcast, runZero Hour, to hear about the team's latest research findings and additional debate on all things exposure management: https://www.runzero.com/research/runzero-hour/
Try runZero free for 21 days by visiting https://securityweekly.com/runzerorsac. After 21 days, the trial converts into a free Community Edition license that is great for small environments and home networks.
HD Moore is a pioneer of the cybersecurity industry who has dedicated his career to vulnerability research, network discovery, and software development since the 1990s. He is most recognized for creating Metasploit and is a passionate advocate for open-source software and vulnerability disclosure.
HD serves as the CEO and founder of runZero, which provides a single source of truth for exposure management across your total attack surface. Delivering in-depth visibility into every asset and exposure, runZero helps you mitigate risks faster, meet compliance requirements, and ensure you continuously discover critical insights that others miss—including unknown and unmanageable devices and elusive exposures that evade traditional tools.
Prior to founding runZero, HD held leadership positions at Atredis Partners, Rapid7, and BreakingPoint. HD has also been a frequent speaker at industry events such as Black Hat and DEF CON. HD’s professional journey began with exploring telephone networks, developing exploits for the Department of Defense, and hacking into financial institution networks.
How Adversaries are Rewriting Cybersecurity Rules: Adapting to AI-driven Attacks – David Aviv – RSAC25 #3
Adversaries are rewriting the cybersecurity rules. Shifts in the threat landscape are being fueled by attackers with political and ideological agendas, more sophisticated attack tools, new coalitions of hacktivists, and the democratization of AI. Radware CTO David Aviv will discuss how companies must adapt their cyber defenses and lead in an evolving era of asymmetric warfare and AI-driven attacks.
This segment is sponsored by Radware. Visit https://securityweekly.com/radwarersac to learn more about them!
David Aviv is chief technology officer at Radware, where he oversees the technology strategy for the company’s cloud, application, and network security solutions. In this role, David is involved in researching and developing the key algorithms and concepts that guide future product development.
Before joining Radware, David was vice president of engineering at Ofek, an Israeli ILEC. He also served in the Israeli Air Force as a senior technical leader. David has decades of experience leading the design and development of enterprise scale communication systems, with a specialty in the telecommunications sector.
David holds a Ph.D. in electrical engineering from the Naval Postgraduate School in Monterey, California, a Master of Science in electrical engineering from Tel Aviv University, Israel, and a Bachelor of Science in electrical engineering from Ben-Gurion University, Israel.
Cyera: Fastest-Growing Data Security Company in History – Yotam Segev – RSAC25 #3
Cyera is the fastest-growing data security company in history, empowering companies to classify, secure, and manage their data, wherever it is, and leverage the power of the industry’s first AI native,unified Data Security Platform. Yotam Segev, Cyera’s CEO sits down with CyberRisk TV at RSA to discuss Cyera’s skyrocketing growth, its founding story and why an increasing number of Fortune500 companies are partnering with Cyera, and the company’s latest product release: Adaptive DLP, a new AI data loss prevention solution.
Cyera Breaks World Record as the Fastest-Growing Data Security Company in History- https://www.businesswire.com/news/home/20250304885360/en/Cyera-Breaks-World-Record-as-the-Fastest-Growing-Data-Security-Company-in-History Data Security Leader Cyera Secures $300 Million in Series D Funding, Reaching a $3 Billion Valuation - https://www.businesswire.com/news/home/20241120065588/en/Data-Security-Leader-Cyera-Secures-%24300-Million-in-Series-D-Funding-Reaching-a-%243-Billion-Valuation Cyera Acquires Trail Security for $162M, Redefining AI-Powered Data Security With Comprehensive Data Loss Prevention - https://www.businesswire.com/news/home/20241017821422/en/Cyera-Acquires-Trail-Security-for-%24162M-Redefining-AI-Powered-Data-Security-With-Comprehensive-Data-Loss-Prevention Cyera Launches Data Incident Response Service to Bring Speed and Focus to Security Investigations - https://www.prnewswire.com/news-releases/cyera-launches-data-incident-response-service-to-bring-speed-and-focus-to-security-investigations-302177229.html Cyera Appoints Renowned Tech Exec Frank Slootman to Board of Directors - https://www.businesswire.com/news/home/20250325744647/en/Cyera-Appoints-Renowned-Tech-Exec-Frank-Slootman-to-Board-of-Directors
This segment is sponsored by Cyera. Visit https://securityweekly.com/cyerarsac to learn more about them!
Yotam Segev is the co-founder and CEO of unicorn Data Security company, Cyera – the AI native, fastest growing data security company in history. Yotam is a cybersecurity expert with 15 years of experience in the field. Prior to Cyera, he – alongside Co-Founder, Tamar Bar-Ilan – built and ran the cloud security division for the Israeli Defense Force’s (IDF) elite Unit 8200. He served as a Senior Class Commander in the IDF’s prestigious Talpiot Leadership Academy. To date, Cyera has raised $760 million from the top VCs in the world – Sequoia, Accel, Redpoint, Coatue, Georgian, Sapphire, AT&T, Spark and Cyberstarts.
BeyondTrust’s Microsoft Vulnerability Report – Morey Haber – RSAC25 #3
This month BeyondTrust released it's 12th annual edition of the Microsoft Vulnerabilities Report. The report reveals a record-breaking year for Microsoft vulnerabilities, and helps organizations understand, identify, and address the risks within their Microsoft ecosystems.
Segment Resources: Insights Security Assessment Tool: https://www.beyondtrust.com/products/identity-security-insights/assessment
For a copy of the Microsoft Vulnerabilities Threat Report: https://www.beyondtrust.com/resources/whitepapers/microsoft-vulnerability-report
Blog re: Report: https://www.beyondtrust.com/blog/entry/microsoft-vulnerabilities-report
This segment is sponsored by BeyondTrust. Visit https://securityweekly.com/beyondtrustrsac to for a copy of the Microsoft Vulnerabilities Threat Report!
As the Chief Security Advisor at BeyondTrust, Morey J. Haber is the lead identity and technical evangelist at the company. He has more than 25 years of IT industry experience and has authored four books: Privileged Attack Vectors, Asset Attack Vectors, Identity Attack Vectors, and Cloud Attack Vectors. Morey has previously served as BeyondTrust’s Chief Security Officer, Chief Technology Officer, and Vice President of Product Management during his 12-year tenure. In 2020, Morey was elected to the Identity Defined Security Alliance (IDSA) Executive Advisory Board, assisting the corporate community with identity security best practices.
Rebuilding Digital Trust: PKI, DNS, and the Race to Quantum Resilience – Amit Sinha – RSAC25 #3
As quantum computing advances, the security foundations of our digital world face unprecedented challenges. This session explores how integrating Public Key Infrastructure (PKI) and Domain Name System (DNS) technologies can fortify digital trust in the quantum era. We'll delve into strategies for transitioning to post-quantum cryptography, ensuring interoperability, and maintaining the integrity of digital communications. Join us to understand the roadmap for achieving quantum resilience and safeguarding the future of digital trust.
Segment Resources: https://www.digicert.com/what-is-pki https://www.digicert.com/faq/dns https://www.digicert.com/faq/dns/what-is-dns https://www.linkedin.com/posts/amitsinhadigitaltrust-trustsummit-pki-activity-7315749270505037824-lUBf?utmsource=share&utmmedium=memberdesktop&rcm=ACoAAAC22mYBCeB_s0YvGTVQsGiChh7wRXa4jRg https://www.digicert.com/blog/compliance-the-foundation-of-digital-trust https://www.digicert.com/blog/digital-trust-as-an-it-imperative
This segment is sponsored by DigiCert. Visit https://securityweekly.com/digicertrsac to learn more about them!
Dr. Amit Sinha is CEO of DigiCert. Prior to DigiCert, Dr. Sinha was President of Zscaler. During his 12-year tenure, Zscaler grew from a startup to a NASDAQ-100 company and established itself as a dominant leader in enterprise security. Dr. Sinha is an independent Board Member at Zscaler and at DataRobot, an AI cloud platform company, and an advisor to several startups.
Prior to Zscaler, Dr. Sinha served as CTO for Motorola’s Enterprise Networking and Communications business, delivering Wi-Fi solutions. He was the CTO of AirDefense, a market leader in the wireless security space, leading to its successful acquisition by Motorola in 2008. Prior to AirDefense, Dr. Sinha served as Co-Founder and Chief Technologist at Engim, a Wi-Fi semiconductor company.
Dr. Sinha earned his Masters and Ph.D. in Electrical Engineering and Computer Science from the Massachusetts Institute of Technology, Cambridge, and his B.Tech. in Electrical Engineering from the Indian Institute of Technology, Delhi, where he graduated summa cum laude and was awarded the President of India Gold Medal. He has authored over 25 journal/conference papers, contributed to 3 books, and is the inventor of 39 U.S. patents granted or pending.
CyberRisk TV Live from RSAC Conference 2025 Day 3 Daily Recap – RSAC25 #3
Doug White, host of the Security Weekly News, and Mandy Logan, host of Paul's Security Weekly, recap our RSAC 2025 coverage for Day 3 with some good jokes and stories.