Buzzing Topics and Trends: RSA Conference 2023 Preview | Predict 2023
At Predict 2023, the panel discusses and dissects key trends that emerged in their review of a record 2,400+ submissions entered in the annual Call for Speakers program.
Transcript
Thanks for joining. Today's session at the end of a really great day of content here at predict 2023. I am pretty Glade senior director of content for RSA conference and I'm delighted to be joined today by four of our program committee members for RSA conference 2023.
So for background in context, we have around a hundred and fifty different program committee members across all of our various content development efforts for RSA conference, and these are leaders within their field who offer their time expertise and perspective to select and guide the content that makes it to the RSA conference stage and their work was definitely cut out for them this year because we receive more than 2400 submissions which is a which is a record number for us and to save you from any inbound questions in chat notifications will be going out around January the 23rd to those who submitted to be speaking at conference this year. Our four guests today worked with their counterparts to review and debate and ultimately select the sessions that will appear on their tracks in April and I'm excited to dig into the trends that they consider to be most important in 2023 in their respective areas of focus issues that are likely on your minds as well. So Diana, let's start with you since we just heard a great panel on supply chain as part of today's event, which of course is a growing discussion across our industry and was reflected in the submissions that you and your teammate reviewed for the protecting data and the supply chain ecosystem track in particular.
I know that you reviewed a lot of submissions in and around how organizations are thinking differently about managing open source code. That was a big theme. Can you speak to some of your thoughts on what you see happening here and why it's such an important trend.
Yeah, thank you so much and and at first like to call out my amazing track partner, Edna Conway because this was absolutely such a team effort and she just a wonderful wonderful human being to work with. So, thank you Edna. And thank you Brita.
But so some Trends there's so many there's so much to impact. I'm just gonna pick three that I think we're really kind of created this or meta set of Trends around data and supply chain. And the first one was around moving from concept to implementation because it very often in security.
We'll talk about we need to do this we need to do that, but then actually the rubber hits the road is is when people start learning from how we're doing it and as bombs, for example, and I'm gonna talk about those a little bit more later but as problems which are the materials Everybody was talking about it a couple years ago after the executive order, but what we were seeing was people who had actually been implementing it and I wanted to come back and share. This is what we've learned. So we really loved this this focus on implementation not just concept.
Concepts still matter things that are coming down the pike so matter and in that space you saw a lot of really great content around the regulatory impacts and how things are changing and what that's going to bring to supply chain and data security some real standouts here where the chips and science Act of 2022 which is talking about how you know, we build semiconductors how we buy them and trying to lift the the US supply chain dependence on other countries for it. So, how's that going to impact and semiconductors are in all the technology that we use another big one shrimps too, which is a ruling from the court of justice is the EU that invalidates the EU us privacy roller Safe Harbor. So what does that gonna mean to organizations gonna be really impactful so looking at those those pieces and then interestingly that we've gone and I'm actually here for I'm kind of happy.
There's a little bit of like a Back to the Future and around a couple of areas and two that stand up day to leaks security and day to life cycle management. As we move to the cloud as we start training Ai and ML on massive amounts of data data Lake security has come back up but in a very real very immediate way and suddenly people are caring about Data Destruction again data Maps managing data retention and how this impacts our tax service and I am so excited because it's such a critical part of a security program. They could have been a little bit deprecated the past few years.
It's coming back up and it's really critical in this space. Excellent. So Jennifer you had some similar kinds of trends that pulled through on the devsecops and applications security track returning to that open source Trend which we saw there clearly.
This is on our community's mind. What did you see and what can RSA conference attendees? Look forward to learning more about in the world specifically of open source security.
Yeah. We did see a lot of those. So just a little background.
I'll do a just an introverta because I don't know I'm new or to being part of the program committee and I've loved it and I'm going to also give a shout out to my track partner Chris Romeo. So I lead application security and endpoint security at Target. I'm In Minnesota where you can see the Whether behind us, we're in the January snow time I suppose and I'm really looking forward to seeing you all in San Francisco in a couple of months where hopefully it's warmer.
And I'm really excited about our track. We are seeing a lot of Open Source submissions. We sell three times the submissions this year than we saw last year.
So I think people are really excited about application security devsecops. We know in the trend continues that modern software is assembled more than it is written. And so we see a lot of open source and supply chain conversations coming into the devsecops track, which we're really excited about Diana when I heard you talking what I'm thinking is I think the lines between tracks is blurring and I think that's good really.
It's no longer like I'm gonna app SEC person. So I'm gonna go to this app set track. We saw a lot of stuff about Cloud security.
What is it is an application security or is it Cloud security? And so I I think that what we're starting to see the convergence of some of these Topics in the overall ecosystem security, which I think is exciting. That's the kind of conference that I like going to with RSA and you get so much um diversity of content.
So yeah, I we can talk a little bit more about appset in the future, but certainly open source security. We've got a couple of tracks or sorry a couple of sessions earmarked to talk about different things that I think will be complimentary to what they're talking about in other tracks that are also related to open source and supply chain. Now yet interesting when we construct the tracks as a whole we find you people people don't tend to sit on one track and stay there the whole time they're moving between things and that's that's the magic if you will of RSA conference.
It's that big giant water cooler for the industry where someone who cares deeply about law can bump into someone who's a developer who may not naturally cross paths and yet their perspectives are so important. It's that it's that big diversity that does help influence and impact how we think about things. So it is interesting to see the crossover between between the tracks.
Yeah, I agree. Yeah. So shifting gears a little bit Roderick your part of the analytics intelligence and response team and there again, we're some really fascinating different submissions that we thought that we saw one.
I wanted to dig into here a little bit was the medically across tracks. This was not just a hackers and threats it wasn't Just with words what's going on in the Ukraine? Because what's happening there?
It's impacting supply chain. It's impacting policies. It's impacting.
You know, what what we're accepting from where so can you speak a little bit to what you reviewed and why you think this is so important for our industry to take note, you know, certainly recognizing this is this is a changing situation. Absolutely, you know I this was a great time with my two program for me Partners Christine Pamela as well. We had lots of debates about these and we had lots of Ukraine Russia talking tracks.
A lot of them were around advanced persistent threats, although what's going on currently with current cyber attacks, but with all things war and were related those things change over time. We don't know what this war is going to look like six months seven months eight months from now, so we were really, you know, looking at you know, those apt threats, you know, those big ones that everybody in the world should be worried about some of the trend that we thought about too is automation as well too. That's now where strings those attack vectors Industries and Manufacturing those impact the entire world.
So we really had to dive deep and find ones that would really benefit are really our Global Community our say when people get there but it's a huge topic lots of great things and focus points apt right before you'll probably see that in the theme run but what we talk about about those that's right intelligence into response track. Yeah, and I know we there were so many we very easily could have had a whole conference right just about the Ukraine Russia situation. And I know it was really really really difficult for your team in particular to to narrow down to just what you thought was the most pertinent for people to be to be listening to absolutely we could have a whole day worth of Russia Ukraine.
I think you'll get enough to work with for I think next year to years to come with these with words. Yeah, and that was another one. It was interesting looking at we've got sessions on the on the law track that relate to and that reflect on what's going on Russia Ukraine, we have sessions in the strategy and architecture tracks.
So it's another one of those, you know, we kind of had the five mini themes. If you will that that threaded throughout conference, you know web 3 and the metaverse was one that came through everywhere ransomware came through in multiple different areas. The Russia Ukraine situation zero trust popped up in lots of areas.
And then the last one for lack of a better term. I've kind of called it Humanity. What are the things that we're doing and looking at within our industry things like human trafficking making miners safe for engagement in the metaverse and such.
So so there was some really interesting sub themes that came up across tracks as our as our different teams worked on things but Cloud but Cloud Sean, let's pull you into this conversation here, you're part of this this cloudy team which which is which is interesting because the cloud is not just one thing. It's it's everywhere anymore. Right?
It's not just infrastructure. It's impacting policy. It's impacting compliance.
We saw lots of submissions that cross lots of different areas directly. Where is cloud going at RSA conference 2023? You know, it's it's quite interesting.
I think and this is I think this is my fourth year on the program committee. And of course, I have to highlight my other two co-chairman and that is Rich and Anna they've done they did a great job this year with me and the thing that I just think that I remark on is from Jennifer's perspective of it's the convergence. So a lot of organizations now, right and Originally, there was the the very Cloud first organizations.
Well now everyone in some way shape or form is in Cloud some organizations, maybe have 98% of their workloads in the cloud other organizations are going there. So what we're seeing is is fewer hybrid. Um type Cloud talks a lot.
And I mean a lot of zero trust, um app access Cloud on talks. We saw quite a few around the around kubernetes and containers. So using kind of that code modularity for infrastructure and being able to have a modular infrastructure across across your footprint.
So that multiple teams can work in in on the applications. Obviously a really great thing that's happening right now in that's one of the trends in Cloud, but the other thing that I that I not This year and Roderick you're going to be super happy about this. I think is that now we're really starting to see a lot more traditional security approaches apply to Cloud native.
So we're seeing we're seeing a forensics in in Cloud submissions. We're seeing how do we how do we exactly handle a breach because it is different. It's a different beast when you don't own all the infrastructure and you can't just take all of the outside snapshots and you don't have you maybe don't fully own the network that you're that you're you're riding on and so some of that traditional security thought is now being is now going Cloud native if you will, so we're not taking the same things that we did in from from a non-premise perspective and we're we're but we're now turning them into a more Cloud native security posture.
Which is an interesting thing for me. It is indeed and I know you and I have discussed and this was this was pretty you joining the program committee, but we almost several years ago blew up the cloud track because it was like, oh, yeah. This is this is kind of everywhere.
It's ubiquitous. Do we really need something and and you the the cycles that this has gone through because yes, the cloud is everywhere and yet there's some very Cloud specific conversations that are helpful to have and the maturity of what's coming through in this track just in the last five years the change of what's there is pretty exciting to see it is it's it's a wonderful thing. So yes, you know, so cloud is is kind of a part and parcel to all of our tracks but there are enough distinctions of the CSP and CSE so cloud service provider and cloud service customer interactions that that go across that definitely necessitate having That deep dive into those relationships going over some of the some of the new Frameworks things like things like caveat that is a new a new effort that the CSA and miter are working together on for having kind of a miter defend or a miter attack Matrix applied to the cloud.
So all of all the things like that definitely still need a home. Things Cloud Diana, let's pull you into this conversation because again, all these fuzzy lines between all of you which is why I love working with all of you at small scale and a large scale with our program committee as your team looked at submissions. There was that Bubble Up supply chain is not just widgets the cloud.
It's a big role here. Take us into this. Yeah, I love that you're pointing out the widgets because that's where I think a lot of people get sort of caught up.
They hear supply chain and still it's it's changing. It's moved in the past few years, but the you know, certainly even three five years ago, you'd say supply chain and people would say but we don't make widgets so we don't have a supply chain you do you have a supply chain everything you buy all the harder or the software but now you're in this very complex Multiverse supply chain is the cloud and some examples of how that comes into play with, you know, data security and supply chain security thinking about what we're able to aggregate. On the internet now in the collagen of the amount of content that we can bring together and then how we can use it if anybody has dipped their toe into chat GPT and I think but I think you said something like don't go there unless you want to get into the rabbit hole for hours or something.
He's that was such a very spot on but if you haven't used chat GPT, it is a an AI that you can ask natural language for answers and even ask it to do things like write code Snippets for you and it appears to be hyperintelligent what it is. It's taking all the data on the internet and being able to bring it back to you in a way slice it and dice in a way that feels very natural language you feel is almost like you're interacting with an intelligent being Now that's all public data. But Ai and ml has to be trained on data and that means that a lot of the data gets trained on.
It's either it's private or it's been anonymized but as we know when we look at data lakes and how different pieces of data can be reassembled even after they've been separated. There's a lot of risk here for data leakage and data coming out, you know, their failure modes of things like, you know, model inversion for example, and and membership inference that you can get the data out of that of those Lakes at or out of that model out. AI model so our ml model so, you know, that's a really big one for organizations to think about we're bringing all the data together.
But are we protecting it properly and if we share our data out if we're using models out of a zoo or is that going to be safe for us? So that's a big one. I'm glad I'm really was really happy to see there's focus on that and the track because it's an important thing to look at another area the low code and the no code tools.
I love them and you know, they are incredible. They have changed not just how non-devs can actually start to create workflows and meaningful applications for their own companies for their teams, but also on debt development teams are now using it I think about writing integration for security product, you know back in the day and it could take you days depending on what you're doing. We now with some of these tools you can and apis you can just bring them in minutes.
But that has to be not securely and and did you what are you bringing in? Have you have you understood the real risk model of it? So that's another one the cloud gives but it also adds some security at places that we need to look at and the other one is and I get Jennifer I love saying assembled because that was just so perfect.
We do we assemble our applications now so that how do we assemble them with other people's code? So and why not, you know, why reinvent the wheel, but when you're using other people's code. Is that it is a trustworthy.
How can you do it in a safe Manner? And how are you going to be able to track that going forward? So a lot of that, you know cloud is really opened up so many opportunities but we have to use them in a really, you know organized way which I just was we were so happy to see so much focus on this and that the submissions What the great the great Spider-Man quote with great power comes great responsibility, right?
So, I don't know if it's Spider-Man or if it's when the founding fathers or who said it first but Spider-Man claims responsibility, right? So Roderick, you also dipped your toe. If you will into the cloud.
I know there were some there were some really interesting submissions specific to throughout Cloud security threat intelligence and some new behaviors that we're seeing amongst threat actors. Tell us a little bit about what you were seeing here. And why why does it matter?
Yes, so for our cloudy from a threat intelligence and instant response point of view for cloud. It was really really interesting. So from Brent intelligence cloud is the next big hack for a threat actors.
That's all of our data is going it's a very rated by regions. There's multiple different Cloud providers that are out there. However actors targeting the cloud environment looking for vulnerabilities looking for shadow it the worst we hear a tax service intelligence should keep hearing about these buzzwords but it really is looking at the assets that are in the cloud environment and can you know, organizations and companies both public and private sector can they find them all can they understand when the deprecate some assets when to secure other assets that's a vulnerable like the big web of where everybody's storing their data.
Now from the incident response point of view. We look at actors being very sadly. You know, I always say that their day job is to be creative.
So we're looking at things such as like how to throw actors. Or race or wipe away artifacts from the cloud as they go through their attack pattern surface. How do we prevent that how do we go that forensic analysis for those instead of response protocols even bigger is incident response procedures in general to a 100% Cloud environment as many of the participants will understand, you know, when you're on-prem equipment you can do some work with that, you know, you save servers image are drives, but when you're in the cloud, you know, it sounds I think life understand it now your date is in the cloud and we don't know where that cloud is gonna float.
So we have to really find where that data is that and do some into the response analysis. And then of course that really brings in our soft change, you know having to do this and I really like the presentation that weren't so much about Automation and alert fatigue, but it's really was was looking at personnel and get finding good soft Personnel that can do instead of response. Can you look at the alerts also building the building?
Opacity also preventing burnout that's a really big thing. We talked about threat intelligence. No directors spinning their entire day being creative and the instant response how they clean it up.
Well your sock team is a small number of teams or humans as well, too. We're trying to prevent burnouts that knowledge. We don't want to become tribal knowledge when it become institutional knowledge and maintaining those stock for those very big.
So I really like, you know, the presenters really added to human aspect human element into the cloud environment for intelligence and a response. Yeah, so these fuzzy lines as you're listening to this out there. You probably do do see and understand there's not a lot of submissions that we receive that are reviewed in one place.
There's you know, gosh this deals with cloud and it deals with supply chain and maybe there's some flavors of devops because of that open source security element and while all of our panelists today, they're all getting along very nicely. They don't always get along so nicely behind the scenes right? These folks are competitive.
They want to make sure the best stuff appears on their track and they do get out and they debate and they fight each other for different submissions. And that is the goodness that is RSA conference because they make sure you know, these folks is representative of 150 others. Make sure the best possible content makes it to the stage.
So it's awesome. It's awesome that things are reviewed re-reviewed Twisted looked at. How can we make sure our community benefits the most and and to this point of really fuzzy lines?
Between the different review teams Jennifer just like the Ukraine Russia War spilled into almost every group. So did the supply chain conversation that we had right? So in the devops world?
Why does this matter? What's what's new and different with what's happening in supply chain. Well, we saw a lot of breadth in the kinds of submissions that came in through the devsec abstract.
It was I'm trying to remember if we saw anyone mention the OS top 10, which kind of used to be when you think about application security. It was like different varieties of OST top 10 presentations, really not much of that and Roger. I like hearing what you said.
We saw quite a few people submissions. So with to influence people, how do we do that? And so I was really excited to see some talks that came through about the people element, you know, we saw some things that are about pipeline security.
Which are great that's an element. But I think what we saw in the breadth of submissions was just the breadth of how do we secure applications? And I think that's where we have so much complementary nature to all of these different tracks because you can't secure an application if you're the way that you've deployed it is insecure and and so you use the intelligence and certainly the data factors in and I think Diana you were talking a little bit about What's old is new and hygiene and there's not going to be some magical solution.
Like he kind of just have to get in there and do some asset management and partner closely with your SRE teams. And so that's what we've seen. You know, Brita.
Your question was why does supply chain matter because that's still an important element. We've been talking about assembling software. And so how do you know that these different components that you're bringing into your core application that you're going to use to access maybe your most sensitive data and you have to make sure that you have regulatory control and all sorts of things it all kind of comes together to create secure applications.
And so that's I think the kinds of submissions that we saw the things that we were really excited. We were really excited to see the volume because that shows that other organizations are as excited as we are lots of practitioner submissions, which are hands down my favorite. I learn the most from the practitioner submissions for people have said I'm in the trenches.
This was a real struggle for us and here's how we've solved. I I love learning from other companies. And so again what we're seeing I think is a lot more.
variability in the kinds of submissions and I think it's going to create a really Rich track of things that people can learn and Conference not just Brit is right. Yeah, I feel competitive that we want to build a really good track. And so when I say we're going to create a really rich track, I do expect and I know my peers are doing that in the other tracks as well.
Exactly. So actually I made it to that to that transparency and knowing what's inside. Let's explore the bomb Diana there were so many bombs so many letters of the alpha put put in front of bomb.
I never seen so many I didn't I didn't know there were some of these bombs what's going on? Yeah. No, there were there are definitely a lot of a lot of bombs and that s bomb the softer so bomb is bill of materials in case anybody hasn't heard it and there was an executive order on improving the nation's cyber security, which said we need to have asked bombs, which is a list of the dependencies in your software.
So if you think about the Mad scramble that so many organizations had to go through and log for today was was reported. You know, a lot of companies were like, we don't use love for Jay. We're not impacted.
Oh and behold a lot of the vendors that they had and they're used law for Jay. So there was this big scramble. So that's what the S bombs.
Yeah supply chain convers. Station that everyone is impacted by yes. Yes.
I know. I mean this is exactly where you know absec and and supply chain or just completely intersected in this point. But yeah, there are s isn't the only bomb out there.
There are you know data bombs now are being talked about so d-bombs of h-bombs really important. That's your Hardware bill of materials because it if you're buying a laptop from a vendor that vendor didn't create all the hardware in there, right? They sourced a lot of the hardware and then they as Jennifer they assembled your your component.
So do you know the provenance? Do you know that their bill materials for the hardware that came in data bombs around? Where this data come from as we're starting to use more and more.
I need a whole bunch of data about this or that to train my my AI for example where that data come from. Is that reasonable is that reliable? You have some here's some c-bombs which is cybersecurity Bill of material most of the time that was sort of the It's an analog to the s bomb, but I have heard some people talking about the sea bomb as a combination of weight for it the H bomb the s bomb and the D bomb because they're saying anything to see comes out of that.
Anything security related or cyber security related in these devices is going to matter. So yeah a lot of bombs going on and we did bring into this track as I said, there's some real we loved the submissions that were not just about what these are but really how organizations are doing it both themselves. How do you report out your best mom and keep your current?
How do you report get in the bombs from your partners ensure that they are current and most importantly not just first here, but we really loved that. There's an awareness of that. It's an end here kind of process.
So it may not be just you talking to your partner could be understanding your partners partners. For example, the cloud provider uses a partner but the harder they use as you start getting into that and here so, yeah, no and that's that applicability, which I love all of all of you. That's what our estate conference strives to be.
We don't just want to talk, you know, theorize the problems the issues. The hacks the all of that but what are you gonna do about it? What actions are you going to take as an organization today tomorrow six months from now a year from now and it drives some of our presenters crazy when we ask for that apply slide at the end, but that's what our attendees want.
Right what I want to walk out of here with my list of my tick list of things to do. So, I love that. That's what you were looking at as you're looking at the the Myriad of bombs.
Um, Sean let's let's shift over into into your world here. I know when we had our large group conversation with all of our with all of our program committee that's working on track sessions. We talked a lot about about the evolution of multi-in hybrid Cloud environments and the implications then that spill over to these fuzzy lines.
We've talked about into other groups things the infrastructure group the strategy and architecture group and such. Where do you see the cloud World evolving in 2023, and and what does our audience need to That's most closely. Sure.
So, uh so multi-cloud is definitely something that many organizations are looking at and some of some of what I mentioned before the the container subsystems things like kubernetes are really empowering them to be able to be more more mobile with the code after our wonderful asset people have have assisted us with it to be more mobile with it so that they can you can literally move from from CSP to CSP. And it actually that was kind of the original one of the original ideas with Cloud was well, we're going to be very modular we're gonna be able to move from cloud service provider to cloud service provider, but what we discovered and this isn't just in the cyber security skills. What we discovered was it's Such a such a kind of that vendor lock-in because of the way that each cloud is managed is different.
But now as our workloads become a whole lot more Mobile by by using containers, we now can move those move them from from provider to provider and effectively a DNS change. So I see a lot of multi-cloud going on and being ready and able to move if needed from a hybrid perspective. I see hybrid clouds today as as a bit of a transitional architecture.
So before before it's it, you know where we're all kind of cloud first, but hybrid is something to get us from where we were to where we all see the target architecture as going and that is it that is primarily a cloud organization. 99 a hundred percent of their workloads in the cloud. So a lot of people are seeing that and the ability to to do that and so hybrid is the way to get from here to there from a standpoint of things to look at and this is it's it's interesting coming from the cloud guy, but many years ago.
There was this idea of a cybersecurity mesh or aggregating all of our data. We all thought that it was going to affect roderick's world first. And that is oh it's kind of you know, the single pane of glass operations.
That's what we're gonna do. Well, what we're seeing is with multiple SAS cybersecurity capabilities. All being ABI enabled what we're seeing is organizations building out dashboards that go and collect the data directly to give you a good idea of your overall risk of your organizational risk down to the work unit risk as well as compliance.
So a whole whole new idea of kind of compliance's code and and doing compliance from an API API Gathering perspective. I think that's the thing to watch for this coming year is going to be bringing the aggregation of all of these cybersecurity tools together and me and many of them are in the cloud. So that's why I'm definitely tracking on that.
We have a governor risk governance and management track to not represented here, but they they were busy the things that landed in their basket for for co-review. A couple years ago, we wouldn't have seen right we wouldn't have been putting something there and Cloud, but because of the what's happening, it's different different bed fellows, if you will and then and then even sean as you're talking about that I'm thinking of, you know, the rise of the biso, you know, the role of that person that's representing and understanding the business drivers as that intersection point to help with those conversations that need to happen. Absolutely, you know, the the rise of the be so many organizations are are going down the path of their entire cybersecurity organization is fully aligned with the business so many organizations that I've worked in and I've worked in The Salted with they have their Architects their Engineers are in business strategy meetings to really understand where we're going on from a business perspective so that we can make sure that we're a we're applying the right amount of cybersecurity talent to those to those challenges for the business.
Yeah. So let's I want to I want to return really quickly Roderick to a very important point that you made right which is the people the people part of things. We've had some good technology conversations process, but the end of the day people matter a lot and there were a lot of very interesting conversations particularly in AAR and as as you mentioned particularly in or on the sock, how do we help the folks in the sock who truly are the Frontline to to be in an okay place?
Can you tell us a little bit about what you're seeing there? Yeah, absolutely. You know, it's it's one of the things about Personnel that we've seen in Sean was actually correct.
We always talked about that single pain in front glass for years and had never been able to be developed and everybody's using apis those apis and different vendors and sources require people to manage them, you know, and so a lot of the people aspect was what all that to listen so the see so we got a lot of you know burden in risk that there is a breach they are the first person that gets to fingerpointed either successfully defending or unsuccessfully getting breached that trickles down to the personal as well. We look at budgeting a lot of talk about, you know, Q4 and q1 by just organization that companies and different downsizing the downsizing also impacts to cyber it world as well. So when we start to lose Personnel, maybe we'll start wearing three and four and five packs, you know, and that's almost impossible to do especially with the level of sophistication and actors work together.
Are always that they sometimes have a better system than we do a better HR System than read those organizations and companies. They make sure that there's plenty of them available. They're always able to review having a 24 by 7 sock is very demanding our young and up and coming analysts and cybersecurity professionals.
They're going to school but they also need to have that that work experience and I provide their work experience, especially with no with the growing field as it is it's in very difficult to retain that Talent. They're also those those working analysts have become very proficient in know their their craft but it's soft whether it's analytics whether it's business intelligence and response. It's maintaining that we're keeping them with an organization a company and then lastly API lots of information coming in absolutely great.
But that causes alert fatigue. How do we you know develop a system a process to look at false positives and true positives and not overwhelm one or two or three people that may be in the stock. So a lot of the talk tracks went towards that you know for see so taking on that burden your middle management analysts keeping them a pipeline and growing and then our young and Junior up and coming keeping them motivated and interesting about having that burnout while also defending up a Q4 and a q1 that we just don't know what it's gonna look like for most companies.
So it's very important us track that I'm glad that a lot of participants providing. Problems work. Yeah, good tangible action Okay, so At the end of the day, they'll be more than 500 sessions at RSA conference, you know interactive traditional small group settings all of that.
I'm going to give you all a really hard job right now. We're going to go alphabetically through so Diana Jennifer Roderick Shawn in like 20 seconds or less. What are you most excited for at RSA conference?
Yeah. Okay everything I said, but I also want to add in to look out for miter system of trust. It's a standard of practice for Supply Chain management.
It was introduced at RSA last year 2022 and now we're getting into how organizations are actually implementing it. The other thing is understanding the different apps that we're using and who's making them for example is tiktok a fun way to get like cooking hacks or potential surveillance tool for the Chinese government. ah, provocative Jennifer Well, what I'm excited about from a Content perspective in the devsecops track, I think is scalability.
We've I love learning about how to do all these little pieces that are required for a successful application security program at scale. We're gonna see a lot of talks coming out of our track about how to do what we're doing at scale personally. It's the connection.
It's seeing people seeing all of you in person the cybersecurity community coming together to solve problems and share information is my absolute favorite part, and I'm excited about that. awesome project Yes, I would say let's have fun this RSA me about a fun themes superheroes and Movie themes and different takes on what intelligence be on the lookout for a lot of AI discussions about automation AI automation Cloud security. And of course that big Ukraine Russia War right there.
You know, what can we learn from that one? It's the Fantastic track. We're gonna have fun.
Have fun and learn this year. Super Sean bring us home. Yeah, you know Jennifer you keep on sealing stealing everything that I want to say.
It's the people it's it's coming together. We do all this work throughout the year and then we get to come together and we talk to each other much in the same way that that our great group of people here spoke today, but just in a circle, you know a circle of friends and and talking about hey, you know, I'm dealing with this. What are you guys doing and it's a great great environment.
It's a great atmosphere. It has been is made the completely the difference in my career making great lifelong friends at conferences like RSA and so for me, it's the people all of our tracks are always great. I'm super excited about all of the stuff we're gonna do but it's the people for me.
You know stronger together really does resonate it resonates for us as businesses or resonates for us in our development efforts, but at the end of the day, we are all people and we need each other and we definitely benefit from each other and our energy and our problems sharing and really the goodness. That is our community. So thank you all for being part of this community.
And for those of you who are joining us in this session. We really hope we will see you in April in San Francisco so that we can continue this conversation and, you know count you amongst our Network that we can continue to grow and develop and be stronger together with so thank you all for joining me today and thank you listeners as well.




